Mar 13, 2010
To validate or not to validate... that is the question!
So here comes my question, in order to validate input properly, isn't it better to have the validation to be performed by the code that will act on it as opposed to having the validation at the trust boundary of the overall app? Example: Component1 uses Component2 for backend logic. If Component1 only passes the data straight through to Component2, my belief is that Component1 should leave the input validation to Component2. Thoughts?
Mar 4, 2010
SDL courses in the public
- Basics of Secure Design Development Test
- Introduction to the Microsoft Security Development Lifecycle (SDL)
- Introduction to Threat Modeling
- Privacy in Software Development
I would encourage everyone with a bit of spare time to take a look at these courses.
Sep 7, 2009
The 7 plagues of testing
1. The Plague of Aimlessness
2. The Plague of Repetitiveness
3. The Plague of Amnesia
4. The Plague of Boredom
5. The Plague of Homelessness
6. The Plague of Blindness
7. The Plague of Entropy
There are also some additional plagues that were suggested by various readers (myself included):
- The Plague of Metrics
- The Plague of Semantics/Assumptions
- The Plague of Infinity/Endlessness/Exhaustion
- The Plague of Miscommunication/Language
- The Plague of Rigidness/Complacency
Out of the suggested bunch, I really like Roussi's notion that complacency can be the result of a product's success.
Aug 3, 2009
Recycling security test cases
A while ago James Whittaker talked about building repositories with reusable test cases. The whole discussion is available at the MSDN blogs. I definitely recommend reading it. As applications often have common flaws, it is beneficial to have such a repository. Tweaking the test cases to the application under test is definitely a "must-do". However, once those tweaks are done for the particular software under test, the job gets much easier.
Reflecting at the security industry, it's hard to not notice the need for James's idea to be adopted. In fact, a typical problem report from a security vendor will include the following bits:
- What is the problem?
- How can the problem be reproduced?
- How can the problem be fixed?
Dec 12, 2007
New Version of Guidance Explorer is Out
Dec 6, 2007
Dual Monitor vs Productivity
The original comic strip can be found on PHD Comics.
Oct 18, 2007
Threat modeling in the business world
Aug 28, 2007
Virtualization and the business aspects behind it
From a technical perspective and project execution virtualization is great. It provides the mechanism for shorter turnarounds on project setup, deployment, and removal. This allows project managers to incorporate more slack time into a project's schedule, which in the end results into more time spent on the actual project and more value for the customer. As a step further, the open source community has released a set of pre-built virtual machines that are available to the general public. At the other hand, virtualization at the engineering level provides easy ways to re-configure an environment (including hardware), restore a system to a given state, or simply back-up or clone a system. The ability to do so helps engineers spend less time on maintenance and focus more on the actual problems that are faced throughout the project, which is an incentive for better quality of work. But is virtualization really all that great?
Most commercial software products and services today are distributed under a license in the form of a product key or as a subscription. Both business models are fairly simple. While subscription forces end customers to renew their access to the product or service via a short term license, the product key scenario usually asks end customers for a one time product activation that enables unlimited use of the product. How does virtualization applies to both models?
Among all of its nice uses, virtualization provides a mechanism for backing up or copying virtual machines. Unfortunately for software vendors, replicating virtual machines also replicates any installed software. As such, it is possible to use a single activated copy to suit the needs of multiple users simultaneously. In this scenario the impact of virtualization on the subscription based model is fairly limited. Businesses that have adopted such model should still see a constant stream of revenues with an occasional increase at the time of subscription renewals. This, however, doesn't seem to be the fate of single activation licensing.
Apr 8, 2007
Self development
Here are the articles:
Don't Focus on the Rocks
How To Be an Effective Leader