[e-lang] An object-capability subset of Python

Karp, Alan H alan.karp at hp.com
Tue Sep 16 10:12:48 CDT 2008


Toby Murray wrote:
>
> Surely it's not the responsibility of general language developers to
> ensure the concerns of the "security sideshow" (to quote Linus
> Torvalds)
> are given priority. Rather it should be our responsibility to influence
> the design process of languages if we want to ensure that future
> revisions will meet our needs (e.g. allow secure ocap subsetting, etc.)
>
We are in violent agreement.  However, if security knowledgeable people don't know what the proposals are before they are adopted, there will be less chance to have that influence.  I'm proposing that people on this list who know of pending language changes post a summary here, so that others can comment.  Then it's up to us to prove the value of our position.  We may find the language designers indifferent between two versions of a feature, one security enhancing and one security antagonistic.

________________________
Alan Karp
Principal Scientist
Virus Safe Computing Initiative
Hewlett-Packard Laboratories
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp




More information about the e-lang mailing list