Re: [SC-L] Microsoft SDL report card

2011-05-03 Thread Ben Laurie
On 18 April 2011 18:46, Andy Steingruebl stein...@gmail.com wrote: On Fri, Apr 15, 2011 at 7:33 AM, Ben Laurie b...@google.com wrote: Which is why I am interested in and devoting most of my time now to capability systems. Ben, Is your work focused on the technical bits of this, or the

Re: [SC-L] Microsoft SDL report card

2011-04-05 Thread Ben Laurie
On 4 April 2011 16:45, Gary McGraw g...@cigital.com wrote: In my opinion, the most interesting thing about stuxnet was the payload. So what was the huge stride made since Code Red wrt Stuxnet? See: How to p0wn a Control System with Stuxnet

Re: [SC-L] Microsoft SDL report card

2011-04-05 Thread Gary McGraw
hi ben, Strides (with an s). Take a quick look at the Microsoft report card at the beginning of this thread http://www.microsoft.com/downloads/en/details.aspx?FamilyID=918179a7-61c9- 487a-a2e2-8da73fb9eade. Then see if that sparks more specific questions. Does Microsoft make bug/flaw free

Re: [SC-L] Microsoft SDL report card

2011-04-04 Thread Gary McGraw
In my opinion, the most interesting thing about stuxnet was the payload. See: How to p0wn a Control System with Stuxnet http://www.informit.com/articles/article.aspx?p=1636983 (September 23, 2010) You might also listen to Langner on Silver Bullet (the longest episode ever, but a good one):