Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A whitelist might not even work. In practice whitelists end up with everything in the world on them. It might not be that hard to find a whitelisted program that would let you do the thing in the article just by passing it the right arguments. Certainly anything with a buffer overflow in it would work and there are probably a hundred other ways to do it too.


Yep, one place where I used to work, the owning company's policy had "Linux" on its whitelist, but not "Wireshark". Even though the company was developing software which communicated over the network in various protocols.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: