« | Home | Recent Comments | Categories | »

Heartbleed

Posted on April 10th, 2014 at 15:07 by John Sinteur in category: Security, Software -- Write a comment

A consequence of this principle is that every occurrence of every subscript of every subscripted variable was on every occasion checked at run time against both the upper and the lower declared bounds of the array. Many years later we asked our customers whether they wished us to provide an option to switch off these checks in the interest of efficiency on production runs. Unanimously, they urged us not to—they already knew how frequently subscript errors occur on production runs where failure to detect them could be disastrous. I note with fear and horror that even in 1980, language designers and users have not learned this lesson. In any respectable branch of engineering, failure to observe such elementary precautions would have long been against the law.

— C. A. R. Hoare, from his Turing Award speech 34 years ago

previous post: Snowden lawyer PGP email ‘crack’ flap: What REALLY happened?

next post: Colbert Will Host ‘Late Show,’ Playing Himself for a Change