Yuk-Fai Chan and I wrote a blog posting on domain-specific versus domain-agnostic threats. I'd appreciate hearing any feedback you may have:
http://labs.securitycompass.com/index.php/2011/01/21/domain-driven-security/ Cross-posted to the OpenSAMM blog: https://www.opensamm.org/2011/01/ Thanks, -- Rohit Sethi Security Compass http://www.securitycompass.com twitter: rksethi _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates _______________________________________________