Archive for March, 2005

Benefit of doubt

Eric Lipert:
Well, sure, it’s _easy_ to look at black hole projects after they died a flaming death and say that hey, that was an awful black hole project.
What’s _hard_ is identifying which are going to be the flaming-death black hole products and which are actually going to be the successful “fundamental change” products.

Rephrasing the ‘poor security’ question

People are complaining about bad security and are coming up with various recipes for fixing the situation ranging from using new widgets to setting and enforcing policies to educating developers to my favourite ‘comprehensive approach’. Unfortunately, the suggestions, although helpful in theory, have a zero chance practice, for the simple reason that they ignore realities […]

Ivory tower escape, anyone?

An excellent article with tips on how to escape the ivory tower, which we sometimes finding ourselves in as security professionals. Shame I almost haven’t got through the new annoying Information Security Magazine registration pages…

Next »