Re: [SC-L] web apps are homogenous?

2010-02-26 Thread Chris Wysopal
A large part of the cost of fixing a bug, especially late in the dev cycle after testing is complete, is the cost of regression testing. The cost of regression testing of a patch for commercial software is much higher than the cost of a custom web application. Think of an Oracle bug that span

Re: [SC-L] web apps are homogenous?

2010-02-26 Thread Benjamin Tomhave
Jon, I think you're getting out of the scope of the costing exercise. The research and estimates around "time to fix" are based on the cost associated with developing the patch, not with deploying it. One could argue that the cost of fixing bugs - particularly major ones - is much higher for web a