{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:43:29Z","timestamp":1750308209592,"version":"3.41.0"},"reference-count":0,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2004,7,1]],"date-time":"2004-07-01T00:00:00Z","timestamp":1088640000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2004,7]]},"abstract":"<jats:p>Many developers see buffer overflows as the biggest security threat to software and believe that there is a simple two-step process to secure software: switch from C or C++ to Java, then start using SSL (Secure Sockets Layer) to protect data communications. It turns out that this na\u00efve tactic isn\u2019t sufficient. In this article, we explore why software security is harder than people expect, focusing on the example of SSL.<\/jats:p>","DOI":"10.1145\/1016998.1017004","type":"journal-article","created":{"date-parts":[[2005,1,26]],"date-time":"2005-01-26T16:33:14Z","timestamp":1106757194000},"page":"60-65","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Security is Harder than You Think"],"prefix":"10.1145","volume":"2","author":[{"given":"John","family":"Viega","sequence":"first","affiliation":[{"name":"Secure Software"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matt","family":"Messier","sequence":"additional","affiliation":[{"name":"Secure Software"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2004,7]]},"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1016998.1017004","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1016998.1017004","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:01Z","timestamp":1750264261000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1016998.1017004"}},"subtitle":["It\u2019s not just about the buffer overflow."],"short-title":[],"issued":{"date-parts":[[2004,7]]},"references-count":0,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2004,7]]}},"alternative-id":["10.1145\/1016998.1017004"],"URL":"https:\/\/doi.org\/10.1145\/1016998.1017004","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"type":"print","value":"1542-7730"},{"type":"electronic","value":"1542-7749"}],"subject":[],"published":{"date-parts":[[2004,7]]},"assertion":[{"value":"2004-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}