[SC-L] Insecure Software Costs US $180B per Year - Application and Perimeter Security News Analysis - Dark Reading

Steven M. Christey coley at linus.mitre.org
Fri Nov 30 15:59:12 EST 2007


On Fri, 30 Nov 2007, silky wrote:

> i still think all these ideas are wrong and the model is simple: don't
> employ people who write and generate insecure code. it's just part of
> programming. you wouldn't hire a doctor to be a gardener. don't hire
> an idiot to program your apps.

How does a manager who hasn't written code in the last 10 years (if ever)
know how to distinguish the idiots from the experts?  Secure programming
certification and education is, at best, in its infancy.

- Steve


More information about the SC-L mailing list