Andrew S. Townley wrote:

[snip]

> Until everyone considers security at every step of delivering software,
> security will remain an issue, and the only way it won't be hard anymore
> is the same way riding a bicycle isn't hard after you've been doing it
> for a few years.  I don't think we're there yet, and that's why I made
> the comment I did earlier.
>

+1


Security is notoriously application/service/platform specific and
doesn't respond well to the framework/standardization approach so often
applied.

Note that many services have their own internal authorization models
(custom permissions etc) which can also be difficult to implement
appropriately.

Sure a framework can get you a certain minimum level of security but, if
you need serious security, this won't cut it.  You'll need go through
the entire stack, hardware up and that requires some smart people with
big knowledge.

Cheers,

Dan.





SPONSORED LINKS
Computer software Computer aided design software Computer job
Soa Service-oriented architecture


YAHOO! GROUPS LINKS




Reply via email to