Search the web
Sign In
New User? Sign Up
cinci-art
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 1736 - 1765 of 2647   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
1736
Hello, I would think that LISP, MUMPS, Smalltalk, CLIPS are all examples of "generic" domain languages. I know some ERD freaks that would say SQL done...
inmanjon@...
inmanjon
Offline Send Email
Apr 2, 2007
1:48 pm
1737
Yes, I see language maintenance as a key point that we will be addressing in the next decade. When we look at the linguists and their specific expertise we...
Edward Sumerfield
esumerfd
Offline Send Email
Apr 2, 2007
7:21 pm
1738
I'd like to document some rakefiles with RDoc, but the task/file/rule rake-DSL doesn't seem to be RDoc-compatible. No big suprise, but... Does anyone know...
Dave A
tfhma
Offline Send Email
Apr 3, 2007
1:20 pm
1739
Topic: Software Security Lecture at NKU Gary McGraw, CTO of Cigital, Inc., a software security and quality consulting firm providing services to some of the...
Mark W. Windholtz
WindMark
Offline Send Email
Apr 3, 2007
1:26 pm
1740
... The reason the directions mention this is that the first floor of the BEP building consists of two disconnected halves. If you enter from the side of the...
James Walden
james.walden
Offline Send Email
Apr 3, 2007
6:06 pm
1741
REMINDER: This is an excellent course. Hope you can join us. See details below. Regards, Joe ... ...
Joseph Little
jhlittle1
Offline Send Email
Apr 4, 2007
1:32 am
1742
We don't often have meetings to bash XP, but last night's Gary McGraw gave a great talk on Software security and delivered a few jabs at our beloved Agile...
Mark W. Windholtz
WindMark
Offline Send Email
Apr 4, 2007
1:19 pm
1743
my humble .02 I didn't make it to the talk last night unfortunately, but I came across something somewhat related at a client that kind of threw me for a loop...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
1:56 pm
1744
I would think that refactoring redundant code out of the method in question would reduce the "Attack Surface Area." Thank you, Mark McFadden M Squared Web...
Mark McFadden
m2web
Online Now Send Email
Apr 4, 2007
2:42 pm
1745
The rationale I think is that then that method would have to be some what visible for the code to utilize it so it becomes another entry point to potentially...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
2:55 pm
1746
Methods or classes that have all ecompassing functionality and aren't DRY are hard to read and figure out what they are actually doing and that makes them hard...
Paul Spencer
pdspencer75
Offline Send Email
Apr 4, 2007
3:04 pm
1747
I agree. I just thought it was interesting that it was used as an excuse to not re-factor the code. I only meant it as an interesting anecdote(i thought so...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
3:18 pm
1748
I think you're right. It's more of an excuse than logical reason. Any issue (security or otherwise) could be solved with a well thought out design. I wasn't...
Paul Spencer
pdspencer75
Offline Send Email
Apr 4, 2007
3:34 pm
1749
Well, to be fair to Thomas' client, we haven't see the code in question, nor rigorously tested the security impact of refactoring vs. not in that particular...
Charles L Flatt
charles_flatt
Offline Send Email
Apr 4, 2007
3:43 pm
1750
Hmmm... It's an interesting problem... On one hand you want to manage development issues (TDD, refactoring, etc.) and on the other security issues (attack ...
David Anderson
tfhma
Offline Send Email
Apr 4, 2007
3:44 pm
1751
... LOL. "If you don't let me re-factor/use TDD, I will be unhappy and then I will hack your code..." Something I just thought of is the excuse I was given is...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
4:14 pm
1752
I suspect you're right. You might look for articles pointing to how DRY improves security through maintainability. You might also try a real world metaphor....
Charles L Flatt
charles_flatt
Offline Send Email
Apr 4, 2007
4:22 pm
1753
Thomas, I agree with Paul in that you raised a good point and understood that you were not advocating your client's viewpoint. There is an interesting paper...
Mark McFadden
m2web
Online Now Send Email
Apr 4, 2007
4:32 pm
1754
Hey thanks for this. I just briefly looked at it just now, I'll delve deeper into it later. I think the idea of "misuse stories" is a great idea. And something...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
4:43 pm
1755
Excellent, exactly the kind of article that will help. In my opinion, you'll still need to frame Agile solutions in terms the client is familiar with. "I...
Charles L Flatt
charles_flatt
Offline Send Email
Apr 4, 2007
4:55 pm
1756
At the meeting after the meeting last night, Jim Weirich asked about a Mac tool to help visualize where disk consumption is occurring. I wrote about this on...
Doug Alcorn
lathinet
Offline Send Email
Apr 4, 2007
5:07 pm
1757
Well, I certainly do appreciate all the feedback. There's no question that there are lot's of battles to choose from at this organization. I chose to go the...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
5:35 pm
1758
... I presume these are the PCI data security standards. https://www.pcisecuritystandards.org/ ... Dynamic loading is a vulnerability, as it gives attackers...
James Walden
james.walden
Offline Send Email
Apr 4, 2007
5:43 pm
1759
I discovered this paper, "Toward Agile Security Assurance," which sounds interesting, but I haven't had a chance to read it yet. ...
James Walden
james.walden
Offline Send Email
Apr 4, 2007
5:51 pm
1760
I would like to explore this metaphor further... Wouldn't I just fix the locking mechanism (a bug) in the lock (code) and replace the 6 defective locks (via a...
Allen Theobald
allen_theobald2
Offline Send Email
Apr 4, 2007
6:17 pm
1761
... Again thanks for the help. I may have extrapolated this from the conversation(and maybe incorrectly). If I'm moving code in in such a way that it could be...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
6:27 pm
1762
Looks like I missed out on a good discussion. With regards to the buggy software, I was thinking in terms of refactoring. So even though buggy software may...
Paul Spencer
pdspencer75
Offline Send Email
Apr 4, 2007
7:11 pm
1763
You'd have to fix the defective mechanism in all six locks. That is, you'd have to fix the bug in six different places (via search and replace). This was...
Charles L Flatt
charles_flatt
Offline Send Email
Apr 4, 2007
7:17 pm
1764
That would be an excellent guide on how to approach security. Maybe we should all move to Norway to work with these guys! To be successful in terms of...
Paul Spencer
pdspencer75
Offline Send Email
Apr 4, 2007
7:23 pm
1765
... Maybe a central authority and a watchdog process announcing access.[logging] I recall reading about TJMAXX getting hacked recently and it was the biggest ...
Thomas G. Willis
chudmofo
Offline Send Email
Apr 4, 2007
7:43 pm
Messages 1736 - 1765 of 2647   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help