Re: [SC-L] Secure Development World ?

2008-03-14 Thread Gadi Evron
On Fri, 14 Mar 2008, Steven M. Christey wrote: > > Gadi, > > All indications are that it was cancelled. Would have been nice if they'd > informed the speakers. Too bad, too - it was looking like it would be a > great conference. They didn't inform me I am speaking, a Google alert did. They infor

[SC-L] Silver Bullet turns 2: Mary Ann Davidson

2008-03-14 Thread Gary McGraw
hi sc-l, We just posted the 24th episode of the Silver Bullet Security Podcast. This time I speak with Mary Ann Davidson. Our conversation was almost exclusively focused on software security. What makes Mary Ann's position so interesting is that she is one of the only major CISOs whose role

Re: [SC-L] Secure Development World ?

2008-03-14 Thread Steven M. Christey
Gadi, All indications are that it was cancelled. Would have been nice if they'd informed the speakers. Too bad, too - it was looking like it would be a great conference. - Steve On Fri, 14 Mar 2008, Gadi Evron wrote: > I am trying to understand if this conference is cancelled or not? >

Re: [SC-L] quick question - SXSW

2008-03-14 Thread Arian J. Evans
I'm not sure if the post made the list, but I outlined what I believe is a huge difference between government and beltway contractors, and the private sector. DoD (and most gov/gov-contractor corps) fall squarely into the "assurance" camps. Private sector is heavily into "mitigation" and "respons

Re: [SC-L] quick question - SXSW

2008-03-14 Thread Gary McGraw
hi sc-l, As many of you know, I have been doing this stuff for over a decade now. In terms of developer awareness and uptake, we have made great strides in the last three years. I taught my first training class on software security at Goldman in 2001. Since then, we've trained well over 8000

[SC-L] Software Security Bibliography

2008-03-14 Thread Gary McGraw
Hi sc-l, I have been having some out of band threads with a couple of people about what to read in software security. I posted this once before to the list, but it's worth doing again... In my book "Software Security" there is an extensive annotated bibliography published as Chapter 13. The

Re: [SC-L] quick question - SXSW

2008-03-14 Thread John Steven
All, I just got back from SD West where I spoke twice in the security track. My third year working this show I was shocked to find larger audiences, avid participation, and (what excited me the most) very clueful development types. Awareness will continue to be a big part of "getting the word o

Re: [SC-L] Software security definition(s)

2008-03-14 Thread Mike Lyman
Arian J. Evans wrote: > What is "secure" software? > It is one quality of an application that can be measured > by the emergent behaviors of the software while trying to > meet and enforce its use-case in a given run-time environment. > Fairly new to the list so if I cover things discussed befo

Re: [SC-L] quick question - SXSW

2008-03-14 Thread Mike Lyman
Arian J. Evans wrote: > Overall security is not a feature or a function that you can monetarize. > It's not even cool or sexy. It's an emergent behavior that is only > observed when it is making your software harder to use. > Maybe it is just the US Department of Defense environment where I am

Re: [SC-L] Secure Development World ?

2008-03-14 Thread Robert A. Martin
Yes it is cancelled. At 1:13 AM -0500 3/14/08, Gadi Evron wrote: >I am trying to understand if this conference is cancelled or not? >___ >Secure Coding mailing list (SC-L) SC-L@securecoding.org >List information, subscriptions, etc - http://krvw.com/mai

[SC-L] Secure Development World ?

2008-03-14 Thread Gadi Evron
I am trying to understand if this conference is cancelled or not? ___ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.