Re: [SC-L] Grass roots secure coding efforts

2004-08-23 Thread Kenneth R. van Wyk
Hans Westphal wrote: Other suggestions: Subscribe to Security lists: [EMAIL PROTECTED], [EMAIL PROTECTED] Self Education through books ... and Webcast's ... Thanks Hans -- good suggestions. I think, though, that what most of my students have wanted more than "just" information sources are sugge

RE: [SC-L] Grass roots secure coding efforts

2004-08-23 Thread Hans Westphal
Other suggestions: Subscribe to Security lists: [EMAIL PROTECTED], [EMAIL PROTECTED] Self Education through books Secure Coding: Principles and Practices http://www.amazon.com/exec/obidos/tg/detail/-/0596002424/103-7129116-7330242?v=glance Writing Secure Code 2nd edition http://www.amazon.com

[SC-L] Grass roots secure coding efforts

2004-08-23 Thread Kenneth R. van Wyk
Greetings all, One of the things that I hear most from software developers when I deliver secure coding tutorials and such is that they're likely to be unable to do things like detailed threat modeling, risk analyses, etc. The reason most often cited is that they're under tight deadlines and t