Thursday, 11 December 2014

Bruce Schnier on ODF & Security

Way back in 2005 Bruce Schnier did a post on ODF and security, comparing it to closed binary formats.

https://www.schneier.com/blog/archives/2005/12/opendocument_fo.html

The comments are still relevant, for example, features vs safety balance.

Sunday, 23 November 2014

Submitted to KickStarter

Finally submitted the proposal to Kickstart for review.

The preview is here, with updated video, text, Q&A and logo.

https://www.kickstarter.com/projects/849734365/942335070?token=49dbb743

The video is on youtube too:


Friday, 21 November 2014

Kickstarter

I've not had much luck exploring the various official funding sources for cyber security - which is puzzling given how much priority is given to cyber.

So I'm going to try social crowd funding through kickstarter.




Have a look at the preview proposal - I'd appreciate you submitting feedback. The words need to be refined and a video produced - should be fun!

Maybe the wisdom of crowds is greater than official bureaucracy?

Sunday, 2 November 2014

Problem, Strategy, Profile Document Online

The document which describes the problem, solution strategy, and secure profile will be developed in full view online at:


Link will always be visible in the Links panel on the top right of this blog.

Feel free to provide ideas, corrections, suggestions to @secureodf or secureodf at gmail dot com.

Saturday, 1 November 2014

Security Research Map

In my search to raise visibility and seek the right funding I've added a profile to the EU's Security Research Map:



Sunday, 26 October 2014

Functional Implementation of Validators

Should document validators be written in imperative or functional languages?

They could be done in both, of course, but there are benefits to implementing them in a disciplined functioal language.

Functional languages force you to break down the problem and describe it declaratively. Ths is good discipline because it means your understanding of the problem has to be precise with clear input/output behaviours.

Furthemore, each sub-problem is addressed by smaller functions, each of which must always behave in predictable ways, with guarantees that there will be no interference from the state of other parts of the program - there are no global variables or the state of other objects which can affect the function at all - that's the guarantee of functional programming.

It seems to me that functional programming discipline is ideal for reducing risks in security enforcing software.

I think I'll try clojure to prototype a validator.