|
|
|
|
|
by transpute
2995 days ago
|
|
An effort was started by Mudge to use static analysis and fuzzing to assess a range of software, https://34c3.cyber-itl.org & https://theintercept.com/2016/07/29/a-famed-hacker-is-gradin... "... first-of-its-kind method for testing and scoring the security of software — a method inspired partly by Underwriters Laboratories, that century-old entity responsible for the familiar circled UL seal that tells you your toaster and hair dryer have been tested for safety and won’t burst into flames. Called the Cyber Independent Testing Lab, the Zatkos’ operation won’t tell you if your software is literally incendiary, but it will give you a way to comparison-shop browsers, applications, and antivirus products according to how hardened they are against attack. It may also push software makers to improve their code to avoid a low score and remain competitive." |
|
Turing-complete systems are arbitrarily flexible as a matter of principle.
If the firmware can be altered; if any addressable memory can be changed, and a system relies on an internet connection for maintenance and support, it is an unreliable system.