[prev in list] [next in list] [prev in thread] [next in thread] 

List:       sardonix
Subject:    [Sardonix] help needed with DotGNU security review
From:       Norbert Bollow <nb () SoftwareEconomics ! biz>
Date:       2003-11-22 13:07:34
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hallo everyone!

At the current stage of DotGNU development, it'd be good to have
skilled "security review" help with DotGNU Portable.NET in these
areas:

 * checking the adherence of the bytecode verifier to the published
   spec and security conditions

 * range-checking of all values that need it

 * environmental security - controlling access to system facilities
   such as files, network, preferences, etc

We're interested both in documentation of problems, as well as in
documentation of things that are not problems.  Discussion of these
and related matters is welcome on the pnet-developers mailing list,
see http://dotgnu.org/mailman/listinfo/pnet-developers .

Nota bene, we're aware that Portable.NET still lacks certain security
features, especially in the area of environmental security, and we
can use help with identifying all of the places where security will
need tightening for both app usage and applet usage.

Greetings, Norbert.

- -- 
Founder & Steering Committee member of http://gnu.org/projects/dotgnu/
Free Software Business Strategy Guide   --->  http://FreeStrategy.info
Norbert Bollow, Weidlistr.18, CH-8624 Gruet (near Zurich, Switzerland)
Tel +41 1 972 20 59        Fax +41 1 972 20 69       http://norbert.ch
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE/v1+AoYIVvXUl7DIRApDTAJ9QunMybTxQqzD61M6uHiCDcBx6SwCgwtCX
4/ZyTf03qDwknVDz3U+ofcE=
=6t7x
-----END PGP SIGNATURE-----
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic