Secure Coding mailing list archives
Re: Is developer education a lost cause?
From: George Capehart <gwc () acm org>
Date: Sat, 24 Jan 2004 04:18:13 +0000
On Thursday 22 January 2004 11:35 pm, Chris Wysopal wrote:
He argues that secure coding is impractical. I have submitted a rebuttal. I think layering defenses to isolate buggy vulnerable software and continuously patching is impractical.
I couldn't agree more. It is no harder to do it "right" than it is to do it "wrong." It is a matter of discipline and technique. It is one of the first lessons of discipline in any endeavor, whether it be sport, manufacturing or software development. There is a vast literature and experience base from the quality/QA/TQM/Six Sigma universes to support that. That's road apples! Do it right the first time! The idea of purposely deciding to accept continual patching to me has neither an appealing ROI nor TCO. I do think defense-in-depth and layering defenses is a good idea in general, though . . . FWIW. /g
Current thread:
- Is developer education a lost cause? Kenneth R. van Wyk (Jan 22)
- RE: Is developer education a lost cause? Jason Wilcox (Jan 22)
- Re: Is developer education a lost cause? Joe Teff (Jan 22)
- RE: Is developer education a lost cause? Michael S Hines (Jan 23)
- Re: Is developer education a lost cause? Pascal Meunier (Jan 23)
- Re: Is developer education a lost cause? Chris Wysopal (Jan 23)
- Re: Is developer education a lost cause? George Capehart (Jan 23)
- <Possible follow-ups>
- RE: Is developer education a lost cause? Robert Shields (Jan 23)
- Re: Is developer education a lost cause? Richard Moore (Jan 23)
- RE: Is developer education a lost cause? Giri, Sandeep (Jan 23)
- RE: Is developer education a lost cause? Robert Shields (Jan 23)
- Re: Is developer education a lost cause? Gary McGraw (Jan 23)
- RE: Is developer education a lost cause? Jeremy Epstein (Jan 30)
- Re: Is developer education a lost cause? der Mouse (Jan 31)
- RE: Is developer education a lost cause? Jeremy Epstein (Feb 02)
- Re: Is developer education a lost cause? jeff . williams (Feb 02)
- RE: Is developer education a lost cause? Brad Arkin (Feb 04)