Secure Coding mailing list archives

Change of position


From: "Gary McGraw" <gem () cigital com>
Date: Thu, 01 Apr 2004 17:33:29 +0100

Hi all,

I have done lots of soul searching lately and have come to the
conclusion that trying to make software secure is not worth the effort.
I think instead we should concentrate more effort on protection
technologies such as advanced stateful firewalls, intrusion detection
mechanisms, host-based behavior control, and above all policy.  We
simply can't make software work effectively in a cost effective manner.

I hope all of you will agree.  

My plan is to create a new mailing list (hope Ken lets this one by)
called nsbsc-l [network-security-beats-secure-coding-list].  Look for
more information about that from me soon.

gem

Gary McGraw, Ph.D.
CTO, Cigital
http://www.cigital.com

----------------------------------------------------------------------------
This electronic message transmission contains information that may be
confidential or privileged.  The information contained herein is intended
solely for the recipient and use by any other party is not authorized.  If
you are not the intended recipient (or otherwise authorized to receive this
message by the intended recipient), any disclosure, copying, distribution or
use of the contents of the information is prohibited.  If you have received
this electronic message transmission in error, please contact the sender by
reply email and delete all copies of this message.  Cigital, Inc. accepts no
responsibility for any loss or damage resulting directly or indirectly from
the use of this email or its contents.
Thank You.
----------------------------------------------------------------------------






Current thread: