Re: [SC-L] IBM Acquires Ounce Labs, Inc.

2009-07-29 Thread John Steven
All, The question of "Is my answer going to be high-enough resolution to support manual review?" or "...to support a developer fixing the problem?" comes down to "it depends". And, as we all know, I simply can't resist an "it depends" kind of subtlety. Yes, Jim, if you're doing a pure JavaSE

Re: [SC-L] Integrated Dynamic and Static Scanning

2009-07-29 Thread McGovern, James F (HTSC, IT)
Sometimes integration is a good and bad thing. I hope that my Ounce enhancement request for integration with HP Quality Center and Archer GRC doesn't get deprioritized over rebranding efforts. Likewise, this also has the potential of causing many more IBM employees than current to pay attention to

[SC-L] Source or Binary

2009-07-29 Thread Brad Andrews
This is something where I have to watch my own mind. Figuring out a binary in C++ is very difficult. The Java is not really a binary, at least not in the "runs by itself" meaning. (Everything is (a) binary in reality, including the file holding this email.) Realizing that java "binarie

[SC-L] Software protection

2009-07-29 Thread Gary McGraw
hi sc-l, Christian Collberg (an important pioneer in software protection) just published a great book called "Surreptitious Software". It's just plain good. http://www.amazon.com/Surreptitious-Software-Watermarking-Tamperproofing-Addison-Wesley/dp/0321549252 I blogged about the book on Justice

Re: [SC-L] Source or Binary

2009-07-29 Thread Kenneth Van Wyk
On Jul 29, 2009, at 4:17 PM, Brad Andrews wrote: Realizing that java "binaries" hold a lot more is a mental shift that probably must be actively kept in mind. Those with only Java experience may think it is obvious, but how many developers did not start with Java and have not purged this co