Re: [SC-L] State Department break-in last summer

2007-04-19 Thread Nick FitzGerald
be indicative of overall improvements in MS code standards due to SDLC (are newer versions of Office distilled through SDLC?) and compiler "security" improvements, but it might also be indicative of the "attackers" (or, at least those they buy their ex

Re: [SC-L] Yoran on the state of software security

2004-04-22 Thread Nick FitzGerald
trics. In fact, I'm sure they don't care for it at all and would prefer, like their private sector counterparts, to not have to do anything of the sort. The reason they "care enough" to make such measurements is simply because they are required to do so. I would just love to see how the high and mighty, reputedly IT security loving, US private sector stacked up against the same metrics... Regards, Nick FitzGerald

RE: [SC-L] Bugs and flaws

2006-02-03 Thread Nick FitzGerald
could not anticipate, at some point along the Win3x to W2K3 development timeline earlier than 28 Dec 2005, that this WMF design "feature" would cause trouble, one has to ask if MS should be allowed to make software for general consumption... Regards, Nick FitzGerald __

Re: [SC-L] Bugs and flaws

2006-02-03 Thread Nick FitzGerald
aïve use of zero- based counters controlling a loop... 8-) ) The design "For each fund that the user owns, do X" clearly (well, to me -- am I odd in this?) says that NOTHING be done if the number of funds is zero, hence the second result is an implemention error. Regards, Nick F