Archive 31. December 2005

Researchers tend to exaggerate

In any case, if the quote in the article about the Research Center for Computer Security at the University of Passau is correctly reproduced:

For this, the Passau scientists have developed test methods that are supposed to detect security vulnerabilities. "The system works very precisely and does not produce false alarms," said Professor Gregor Snelting. "Our analysis method is more complex than standard testing methods, but we guarantee that no security hole will escape us."

Yes, of course. Guaranteed to find all security holes. Logical. Halting problem with programs? Doesn't matter. Software still runs on classic processors, and thus has a completely unsecured layer? Doesn't matter. Of course, we find all security holes.

Nonsense. Such ridiculous claims only disqualify the person who makes them - let's hope that it was just a journalist who heard what he wanted to hear. Or that it was just a dumb assistant who was asked ...

Re: Web application design: the REST of the story - a very interesting discussion of two currently dominant architectural styles for web applications: REST and Continuations.

Whinnying Bureaucratic Horses

Send official mail to Shopblogger - the Social Court of Bremen thinks you are not allowed to have websites with "Social Court of Bremen" in the title. There is more information at LawBlog.

One thing is clear - as long as civil servants at courts can waste time with such nonsense, they cannot expect anyone to take their "we are overloaded" seriously.