Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"though I would consider the requirements for writing really secure software quite high, so I do not think most open source projects could meet such standards. "

Data from prior work indicates it ranges considerably from significantly harder to extremely hard. The LOCK system with an Orange Book A1 development process was highly secure and gave cost breakdown. A1 assurance acyivities added around 37% or so on top of regular, labor cost. Altran/Praxis's Correct-by-Construction that does highly-assured systems with mix of Z specs, Ada, SPARK, reviews, and testing costs 50% premium on top of normal development. Just using SPARK automatically knocks out whole classes of bugs. Galois did and open-sourced CRYPTOL so people can specify algorithms in easy DSL then generate C from it. Also parser and protocol generators.

So, prior evidence shows it takes specialized skill and domain knowledge... at least two extra people unless one has both... but otherwise costs 30-50% more time. Like Cleanroom methodology, it partly achieved this by saving you time debugging and refactoring due to reduced bugs in general plus doing fixes earlier in lifecycle.

Most OSS projects dont do this stuff just because they dont know it's necessary, don't care, or don't have staff for both demanded features and assurance activities. Interestingly, there's more high-assurance products in proprietary than FOSS software despite the huge labor advantage FOSS has. That there's little of even medium-assurance work in majority of both says even worse things about IT's priorities or apathy given medium assurance cost little to nothing. Microsoft is the one exception of big, software houses via SDL and MS Research's work. For FOSS, DJB, OpenBSD, and SQLite come to mind.



Thanks for the info, did some searching based on your comment and I managed to find a report made by Altran/Praxis detailing the development process and technologies for a tokeneer ID station implementation they did for the NSA. Very interesting stuff. http://www.adacore.com/uploads/downloads/Tokeneer_Report.pdf

It really shows the amount of resources and knowledge required for actually having safe or secure systems.


Glad you enjoyed it. Remember Praxis' method next time some fool says you can't engineer software. A few companies like them do. They're now just called Altran. The Tokeneer link was good since they published the source code on AdaCore website for people to learn from. However, the highest-security thing they did was the CA below under UK equivalent of EAL6/7. http://www.anthonyhall.org/c_by_c_secure_system.pdf

Example of new one for model-to-code-to-ASM verification https://www.umsec.umn.edu/sites/www.umsec.umn.edu/files/hard...

LOCK project was pretty landmark in all that it accomplished with Sidewinder firewall & SELinux being in its ripple effects http://www.cyberdefenseagency.com/publications/LOCK-An_Histo...

The B method is one of most successful in industry. You'll definitely see the engineering aspect in this one. http://www.methode-b.com/wp-content/uploads/sites/7/2012/08/...

Cleanroom was early one in 1980's (start at p13) https://www.sei.cmu.edu/reports/96tr022.pdf

Note: Cleanroom had excellent results at low cost but disappeared for some reason. I saw someone recently combine Python with Cleanroom with good results. Cleanroom's compositional style means something like Haskell + QuickCheck could be great combo. If anyone tries it, let me know about the results.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: