This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.
Index Nav: | [Date Index] [Subject Index] [Author Index] [Thread Index] | |
---|---|---|
Message Nav: | [Date Prev] [Date Next] | [Thread Prev] [Thread Next] |
Other format: | [Raw text] |
David A. Wheeler wrote:
The general consensus of people who have *studied* how to develop secure software
Long ago, when I looked into the matter by examining the first few instances of strlcpy in OpenSSH (this was soon after they rewrote it to use strlcpy), the use of strlcpy did not fix any bugs and may have introduced one due to silent truncation. This convinced me that strlcpy was not a good way to go for its intended application area. And I'll bet my admittedly-brief study examined more empirical evidence than the cavalcade of experts you cited.
The argument is not strlcpy versus nothing. It's strlcpy versus reasonable alternatives that take the same or less work. These days the alternatives are better, so why refight this old battle?
Index Nav: | [Date Index] [Subject Index] [Author Index] [Thread Index] | |
---|---|---|
Message Nav: | [Date Prev] [Date Next] | [Thread Prev] [Thread Next] |