Subject: Re: FreSSH and bounds checking
To: Steven M. Bellovin <smb@research.att.com>
From: Wolfgang Rupprecht <wolfgang@wsrcc.com>
List: current-users
Date: 03/08/2002 07:45:28
Steven M. Bellovin writes:
> Hoare had a line on that, too, from around 1983 -- he likened such 
> behavior to sailors practicing ashore with life jackets, but leaving 
> them home when they went to sea.  

Understood.  With all the comments about ssh already being slow I
figured anything that added another 2x slowdown (and bloat) to the
code would raise a few eyebrows.

Even as a one-time verification tool the bounded-pointer (BP) hack to
gcc found quite a few long-standing bugs in very common utilities.  It
is not unlike malloc checkers (eg. "Purify") in that regard.  The
first time you run it you scratch your head and say "how that heck
could that bug have survived for all those years?"

-wolfgang
-- 
Wolfgang Rupprecht    <wolfgang@wsrcc.com>     http://www.wsrcc.com/wolfgang/
Coming soon: GPS mapping tools for Open Systems. http://www.gnomad-mapping.com/