OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Code Complexity vs. Security

From: Gunnar Peterson (gunnararctecgroup.net)
Date: Fri Jul 23 2004 - 16:25:20 CDT


Dan Geer's Blackhat Windows keynote talk last January charted lines of code
against vulnerabilities over time. LOC is not complexity per se, but it is an
indicator.

Quoting Mark Curphey <markcurphey.com>:

> Has anyone seen any good studies that analytically compare the security
> quality of code to code complexity ?