I'm also looking forward to another Microsoft security book called Hunting Security Bugs. Michael Howard has another security book through Osborne called Designing Security Software arriving in February. Good work Michael -- push that publication date far enough away for me to catch up on my other reading.
On a related note, does anyone recall learning about this?
I saw it at the Microsoft Security Development Center. Microsoft India hosted a Security Shootout last March. Varun Sharma won. It's interesting to see such a promotion, and I wonder if the US will host something similar.
In the future, I recommend changing the logo. Vulnerabilities in code are not "security threats" -- they are vulnerabilities. I think Microsoft is so hung with up their definition of threat modeling that they think problems in their code are threats, not vulnerabilities. (Cue comments that "vulnerabilities are threats," which I will promptly ignore.)
Tidak ada komentar:
Posting Komentar