[SC-L] Flame provides an opportunity

2012-05-31 Thread Gary McGraw
hi sc-l,

Whenever a computer security disaster story breaks (pretty much the only kind 
of coverage cyber security can expect in the major press) we have an 
opportunity (while people are paying attention) to talk about how to avoid 
future disasters.  If we're lucky, we can leverage the NASCAR effect 
http://www.darkreading.com/security/application-security/208803559/if-you-build-it-they-ll-crash-it.html
 to discuss software security.

In my view, the only way we can get in front of modern malware is by building 
security in.  I wrote about that for SearchSecurity in May: Eliminating badware 
addresses malware problem 
http://searchsecurity.techtarget.com/opinion/Gary-McGraw-Eliminating-badware-addresses-malware-problem
 (May 2012).

Some of the Flame dustup in the press this week riffed on that idea and even 
mentioned the BSIMM (in the WSJ CIO Journal):
http://blogs.wsj.com/cio/2012/05/29/cios-should-see-flame-as-a-call-to-arms/?KEYWORDS=hickins

Also check out a related radio segment from Marketplace (aired on NPR):
http://www.marketplace.org/topics/tech/flame-malware-burns-through-cyberspace

It actually works to use the NASCAR effect to get our message out!

gem

company www.cigital.com
podcast www.cigital.com/silverbullet
blog www.cigital.com/justiceleague
book www.swsec.com

___
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
___


[SC-L] Silver Bullet 74: Bruce Schneier

2012-05-31 Thread Gary McGraw
hi sc-l,

There are exactly two security gurus we have covered twice in Silver Bullet: 
Ross Anderson (who holds the all time record for hits) and Bruce Schneier.  
Both are very interesting thinkers and thought leaders in computer security.

Episode 74 is the second Silver Bullet conversation with Bruce.  We talked 
mostly about his new book Liars and Outliers, but the conversation ranged 
widely from economics to mixology.  I think you'll enjoy it:

http://www.cigital.com/silver-bullet/show-074/

As always, your feedback is welcome and encouraged.   Please pass this episode 
on to your friends and colleagues.

gem

company www.cigital.com
blog www.cigital.com/justiceleague
book www.swsec.com

___
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
___