Archive for the 'Software Security' Category
« Mark Curphey - SecurityBuddha.com
home page
June 12, 2008
RV is one of my core framework developers. His blog on MSDN is http://blogs.msdn.com/codejunkie/default.aspx. He will be contributing to our team blog when we open it in a few weeks. In the meantime check out his personal blog for workflow, web services, Team Foundation Server and other great .NET coding stuff.
Updated: Curphey …..”reminds me [...]
Categories: CISG, Microsoft, Software Development, Software Security, Working at Microsoft
Comments: Be the first to comment
June 12, 2008
Alex Hutton posted this follow up on my first post about checklists. He is of course spot on. Checklists in my humble opinion can provide a State of Nature, but can’t provide a State of Knowledge or a State of Wisdom (nice phrases). They certainly don’t do computation or analysis but what they do is [...]
Categories: Cool Business, Frameworks, Information Security Economics, Microsoft, Security Platforms, Software Security
Comments: Be the first to comment
June 10, 2008
Counting What Really Counts
Adapted from an article by Harry Robinson, Six Sigma test productivity program manager at Microsoft and sent to me by Daisy Huss on the ACE Team
The original article was published in Interface in December 2001.
Scene one. You are picnicking by a river. You notice someone in distress in the water. You [...]
Categories: Software Security
Comments: 1 Comment
June 8, 2008
My cool security friend JD has done it again (in BETA).
http://www.codeplex.com/WCFSecurityGuide
These things are the definitive guides to the topic. Masterpieces!
Download the Improving Web Services Security Guide(BETA)
Categories: Information Security Economics, Microsoft, Software Security, Web Security, Working at Microsoft
Comments: 1 Comment
February 12, 2008
I just love this pragmatically argued “Back of the Envelope” theory by Pete Lindstrom.
Categories: Information Security Economics, Software Security
Comments: Be the first to comment
January 25, 2008
Virtual labs, Videos and more
http://www.microsoft.com/click/hellosecureworld/default.mspx
Categories: ACE Team, Microsoft, Software Development, Software Security, Web Security, Working at Microsoft
Comments: 2 Comments
January 19, 2008
Something makes me smile, something makes me cringe. I am not sure which way is which; either way you have to admire the way Kleiner Perkins builds companies. Is the future of security start-ups all about the bling? (Apparently Perkins now lives near me in East Sussex BTW!)
The New Face of Cybercrime: Video Here.
Categories: Information Security Economics, Security Industry, Software Development, Software Security
Comments: Be the first to comment
January 17, 2008
My colleague and legendary Hummus eater Alik Levin (that’s my plate at lunchtime today but rumours are that he once ate two) has written an excellent post about how to use the Guidance Explorer to generate a checklist while performing security code reviews.
His first post on his personal blog is here and a more comprehensive [...]
Categories: ACE Team, Information Security Economics, Microsoft, Security Blogs, Software Development, Software Security, Threat Modeling, Web Security
Comments: 2 Comments
January 10, 2008
When a customer development team was recently asked to use the AntiXSS library, validate input and encode output for their web interface they replied (and I quote) “we do not use cross site scripting”.
If any customer ever asks the single most effective thing to affect a positive change on their software security security program I [...]
Categories: Security Industry, Software Development, Software Security, Threat Modeling, Web Security
Comments: 16 Comments
January 9, 2008
New article from John Steer on my team
Security Policies in the Application Development Process
Categories: ACE Team, Microsoft, Software Development, Software Security, Threat Modeling, Web Security
Comments: Be the first to comment
Recent Comments