<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1426281128647295476.post8676130365949880968..comments</id><updated>2008-11-30T09:37:32.154-05:00</updated><category term='flash'/><category term='moodle'/><category term='productivity'/><category term='daily life'/><category term='testing'/><category term='gt project'/><category term='football'/><category term='silverlight'/><category term='web'/><category term='security'/><category term='google'/><title type='text'>Comments on radi::blog: The effects of the SDL</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://radi.r-n-d.org/feeds/8676130365949880968/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default'/><link rel='alternate' type='text/html' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html'/><author><name>radi v</name><uri>https://profiles.google.com/118284900687766448702</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh3.googleusercontent.com/-j7QY0fZbRvA/AAAAAAAAAAI/AAAAAAAAFlE/24XbATuGUJA/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1426281128647295476.post-6797224552647702182</id><published>2008-11-30T09:37:00.000-05:00</published><updated>2008-11-30T09:37:00.000-05:00</updated><title type='text'>for a change :-)</title><content type='html'>for a change :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/6797224552647702182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/6797224552647702182'/><link rel='alternate' type='text/html' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html?showComment=1228055820000#c6797224552647702182' title=''/><author><name>Puff, the magic dragon</name><uri>http://lixtetrax.wordpress.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html' ref='tag:blogger.com,1999:blog-1426281128647295476.post-8676130365949880968' source='http://www.blogger.com/feeds/1426281128647295476/posts/default/8676130365949880968' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1516460910'/></entry><entry><id>tag:blogger.com,1999:blog-1426281128647295476.post-287174965877982353</id><published>2008-11-30T06:25:00.000-05:00</published><updated>2008-11-30T06:25:00.000-05:00</updated><title type='text'>agreed. :)</title><content type='html'>agreed. :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/287174965877982353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/287174965877982353'/><link rel='alternate' type='text/html' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html?showComment=1228044300000#c287174965877982353' title=''/><author><name>radi</name><uri>http://www.blogger.com/profile/11459795773754260693</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html' ref='tag:blogger.com,1999:blog-1426281128647295476.post-8676130365949880968' source='http://www.blogger.com/feeds/1426281128647295476/posts/default/8676130365949880968' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-975346751'/></entry><entry><id>tag:blogger.com,1999:blog-1426281128647295476.post-4803875402392386813</id><published>2008-11-30T05:31:00.000-05:00</published><updated>2008-11-30T05:31:00.000-05:00</updated><title type='text'>Hi and thanks for the quick reply.&lt;br&gt;&lt;br&gt;My comme...</title><content type='html'>Hi and thanks for the quick reply.&lt;BR/&gt;&lt;BR/&gt;My comment aimed to convey this message: While the SDL works, I would take statistics with a grain of salt.&lt;BR/&gt;&lt;BR/&gt;The lack of reported vulnerabilities (submitted to vendor, disclosed in mailing lists, captured in the wild/honeypots, you name it) does not guarantee the non-existance of vulnerabilities. &lt;BR/&gt;&lt;BR/&gt;So, yeah, SDL drops the implementation bug/ design flaw count dramatically and gives some useful guidelines to developers (and MS-wise, there were some great results demonstrated) but unfortunately, it is not a cure all :(</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/4803875402392386813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/4803875402392386813'/><link rel='alternate' type='text/html' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html?showComment=1228041060000#c4803875402392386813' title=''/><author><name>Puff, the magic dragon</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html' ref='tag:blogger.com,1999:blog-1426281128647295476.post-8676130365949880968' source='http://www.blogger.com/feeds/1426281128647295476/posts/default/8676130365949880968' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-139843199'/></entry><entry><id>tag:blogger.com,1999:blog-1426281128647295476.post-3369934214893429387</id><published>2008-11-30T03:50:00.000-05:00</published><updated>2008-11-30T03:50:00.000-05:00</updated><title type='text'>I agree with your statement that the number of rep...</title><content type='html'>I agree with your statement that the number of reported vulnerabilities is lower than the number of actual discovered vulnerabilities. However, I think there are two reasons why the fact of the 3 reported vulnerabilities is still impressive:&lt;BR/&gt;1. If a vulnerability is not reported (i.e. disclosed by a 3rd party), it could mean that the SQL team has done a good job during the Verification Phase of the SDL.&lt;BR/&gt;2. If someone on the dark side has found an exploitable vulnerability and has not reported it yet, why haven't we seen a new massive worm spreading around (much like Slammer in 2003)?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/3369934214893429387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/3369934214893429387'/><link rel='alternate' type='text/html' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html?showComment=1228035000000#c3369934214893429387' title=''/><author><name>radi</name><uri>http://www.blogger.com/profile/11459795773754260693</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html' ref='tag:blogger.com,1999:blog-1426281128647295476.post-8676130365949880968' source='http://www.blogger.com/feeds/1426281128647295476/posts/default/8676130365949880968' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-975346751'/></entry><entry><id>tag:blogger.com,1999:blog-1426281128647295476.post-3795905319722129385</id><published>2008-11-29T18:23:00.000-05:00</published><updated>2008-11-29T18:23:00.000-05:00</updated><title type='text'>"reported" is the magic word. While the SDL is sol...</title><content type='html'>"reported" is the magic word. While the SDL is solid (at the very least is a formalized process designed to boost security, forcing them managers to take security seriously for a change), the number of reported vulnerabilities, especially critical ones, is lower than the actual, discovered vulnerabilities.&lt;BR/&gt;&lt;BR/&gt;Having said that, SDL is a good thing :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/3795905319722129385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1426281128647295476/8676130365949880968/comments/default/3795905319722129385'/><link rel='alternate' type='text/html' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html?showComment=1228000980000#c3795905319722129385' title=''/><author><name>Puff, the magic dragon</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://radi.r-n-d.org/2008/11/effects-of-sdl.html' ref='tag:blogger.com,1999:blog-1426281128647295476.post-8676130365949880968' source='http://www.blogger.com/feeds/1426281128647295476/posts/default/8676130365949880968' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1785357061'/></entry></feed>
