[SC-L] Root Canal Treatment vs Source Code Review

2008-06-30 Thread Jonathan Leffler
han submit their source code to anyone for external review. [...] There's a simple reason for that reluctance - most people are painfully aware that their software won't stand the scrutiny that an external review would entail. -- Jonathan Leffler ([EMAIL PROTECTED]) STSM, Informix

Re: [SC-L] Cat out of the bag?

2008-10-30 Thread Jonathan Leffler
m.pdf (I also get the digest - I apologize if this has been beaten to death on the non-digest list.) -- Jonathan Leffler ([EMAIL PROTECTED]) STSM, Informix Database Engineering, IBM Information Management 4400 N First St, San Jose, CA 95134-1257 Tel: +1 408-956-2436 Tieline: 475-2436 &

Re: [SC-L] Recent technical reports from the CERT Secure Coding Initiative

2010-08-23 Thread Jonathan Leffler
time-constraint and a constraint is explained, because otherwise it merely sounds self-contradictory (or a bad choice of terminology). -- Jonathan Leffler (jleff...@us.ibm.com) STSM, Informix Database Engineering, IBM Information Management 4400 N First St, San Jose, CA 95134-1257 Tel: +1 408-956-2

Re: [SC-L] Blog post series on security for agile product owners / managers

2011-05-02 Thread Jonathan Leffler
og.html I found that URL did not work (404). Use one of: http://www.sdelements.com/blog http://www.sdelements.com/blog/agile-security-requirements -- Jonathan Leffler (jleff...@us.ibm.com) STSM, Informix Database Engineering, IBM Information Management 4400 N First St, San Jose, CA 95134-1257

[SC-L] Re: Software Security (the book)

2006-02-03 Thread Jonathan Leffler
to see that it was only officially released today. I only started to read it last night, but it looked good so far. Geer's intro is indeed interesting. It will end up on the shelf next to BSS and ES once read. -- Jonathan Leffler ([EMAIL PROTECTED]) STSM, Informix Database Engineerin

[SC-L] Retrying exceptions - was 'Coding with errors in mind'

2006-09-01 Thread Jonathan Leffler
ryable exception left - and IIRC the code review decided they were better off without it. How much are retryable exceptions really used, in Ruby or anywhere else that supports them? -- Jonathan Leffler ([EMAIL PROTECTED]) STSM, Informix Database Engineering, IBM Information Management Division