RE: [SC-L] Missing the point?

2004-04-21 Thread Michael A. Davis
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 While you are exactly right that developers write bad code, we shouldn't leave the developers out in the cold and just say You are the problem. Learn to write better code. If there are code auditing and Ah, my original email wasn't verbose

Re: [SC-L] Missing the point?

2004-04-20 Thread Dave Aronson
On Tue April 20 2004 12:34, Michael A. Davis wrote: It is not the source code that is the problem -- it is the developer. The proof of the developer's grokking of secure coding, is in the code. -- Dave Aronson, Senior Software Engineer, Secure Software Inc. Email me at: work (D0T) 2004

RE: [SC-L] Missing the point?

2004-04-20 Thread Alun Jones
[EMAIL PROTECTED] wrote: Michael A. Davis wrote: Isn't she missing the point? It is not the source code that is the problem -- it is the developer. Well ofcause you can improve the quality of your code by educating your developers, but you cannot avoid doing code review. Developers are