Re: [SC-L] Sad state of affairs

2013-09-20 Thread Prasad Shenoy
Well, one of the objectives of employing secure coding practices is just that - to raise the cost and complexity of exploiting bugs. Cheers, Prasad > On Sep 20, 2013, at 7:47 PM, "Bobby G. Miller" wrote: > > I was just listening to a podcast interviewing a security executive from a > promine

Re: [SC-L] informIT: attack categories

2009-08-26 Thread Prasad Shenoy
Gary, Great article and since you used attacks and categories in the same :) sentence I am tempted to ask if you looked at WASC Threat Classification project? On Tuesday, August 25, 2009, Steven M. Christey wrote: > > Gary, > > You said in the article: > >>The next category of attacks to expect a

Re: [SC-L] IBM Acquires Ounce Labs, Inc.

2009-07-28 Thread Prasad Shenoy
Wow indeed. Does that makes IBM the only vendor to offer both Static and Dynamic software security testing/analysis capabilities? Thanks & Regards, Prasad N. Shenoy On Tue, Jul 28, 2009 at 10:19 AM, Kenneth Van Wyk wrote: > Wow, big acquisition news in the static code analysis space announced tod

Re: [SC-L] Security Architecture Cheat Sheet - Lenny Zeltser

2009-06-20 Thread Prasad Shenoy
> anyone wishes to collaborate on this guide. > > - Jim > > > ----- Original Message - From: "Prasad Shenoy" > To: > Sent: Friday, June 19, 2009 10:18 AM > Subject: [SC-L] Security Architecture Cheat Sheet - Lenny Zeltser > > >> Lenny Zeltser

[SC-L] Security Architecture Cheat Sheet - Lenny Zeltser

2009-06-19 Thread Prasad Shenoy
, Prasad Shenoy ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by

Re: [SC-L] Announcing LAMN: Legion Against Meaningless certificatioNs

2009-03-22 Thread Prasad Shenoy
Great idea but why would you say CISSP is meaningless or MCSE is meaningless? Certifications are like technology. They have a place where they fit. CISSP became so popular and prolific because of the vast field of coverage (10 domains) that a certified practitioner had to study, understand, relate