On Nov 30, 2007 1:59 PM, Steven M. Christey <[EMAIL PROTECTED]> wrote:
> > i still think all these ideas are wrong and the model is simple: don't
> > employ people who write and generate insecure code. it's just part of
> > programming. you wouldn't hire a doctor to be a gardener. don't hire
> > an idiot to program your apps.
>
> How does a manager who hasn't written code in the last 10 years (if ever)
> know how to distinguish the idiots from the experts?  Secure programming
> certification and education is, at best, in its infancy.

Felix Linder said it best in his recent presentation, "Security and
Attack Surface of Modern Applications".  Commercial software doubles
in size every 18 months.  How are we going to train developers and
security professionals fast enough to keep up with that pace?

Cheers,
Andre
(I swear this is the last one for now, sorry for splitting this into
so many messages)
_______________________________________________
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
_______________________________________________

Reply via email to