Re: [SC-L] Integrated Dynamic and Static Scanning

2009-08-07 Thread Ben Livshits
, -Ben -Original Message- From: sc-l-boun...@securecoding.org [mailto:sc-l-boun...@securecoding.org] On Behalf Of Jeremiah Grossman Sent: Thursday, August 06, 2009 4:30 PM To: sc-l@securecoding.org; websecur...@webappsec.org Subject: Re: [SC-L] Integrated Dynamic and Static Scanning Hey all

Re: [SC-L] Integrated Dynamic and Static Scanning

2009-07-30 Thread Brad Andrews
While I completely agree with this statement, it is a much tougher sell to management that is seeking to keep the company making money (or perhaps even alive). I believe that having (and using) an imperfect tool is better than nothing, so I would at least push for that. Getting things

Re: [SC-L] Integrated Dynamic and Static Scanning

2009-07-30 Thread Brad Andrews
That is certainly true. I was just commenting on the issue of systems that work together tightly. None do now (as far as I know), but this should potentially allow that to happen. I did here a few moans when this news came out, since IBM is not known for inexpensiveness from what I