<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: We’ve Reached the Application Security Tipping Point</title>
	<atom:link href="http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: smith</title>
		<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/comment-page-1/#comment-3441</link>
		<dc:creator>smith</dc:creator>
		<pubDate>Thu, 29 Apr 2010 10:18:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=447#comment-3441</guid>
		<description>Wow!
Great Post!
Thanks a lot for sharing such a nice article.Application security encompasses measures taken throughout the application&#039;s life-cycle to prevent exceptions in the security policy of an application or the underlying system (vulnerabilities) through flaws in the design, development, deployment, upgrade, or maintenance of the application.

For more information check this link: http://www.eccouncil.org/certification/ec-council_certified_security_officer.aspx</description>
		<content:encoded><![CDATA[<p>Wow!<br />
Great Post!<br />
Thanks a lot for sharing such a nice article.Application security encompasses measures taken throughout the application&#8217;s life-cycle to prevent exceptions in the security policy of an application or the underlying system (vulnerabilities) through flaws in the design, development, deployment, upgrade, or maintenance of the application.</p>
<p>For more information check this link: <a href="http://www.eccouncil.org/certification/ec-council_certified_security_officer.aspx" rel="nofollow">http://www.eccouncil.org/certification/ec-council_certified_security_officer.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Common Applications Are Now The Weakest Link &#124; securosis.com</title>
		<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/comment-page-1/#comment-2355</link>
		<dc:creator>Common Applications Are Now The Weakest Link &#124; securosis.com</dc:creator>
		<pubDate>Tue, 18 Nov 2008 00:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=447#comment-2355</guid>
		<description>[...] Two articles this week reminded me of something I&#8217;ve been meaning to talk about. First, Chris Wysopal talks bout how we&#8217;ve reached an application security tipping point. How the OS vendors are doing such a (relatively) good job at hardening the operating system that [...]</description>
		<content:encoded><![CDATA[<p>[...] Two articles this week reminded me of something I&#8217;ve been meaning to talk about. First, Chris Wysopal talks bout how we&#8217;ve reached an application security tipping point. How the OS vendors are doing such a (relatively) good job at hardening the operating system that [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefings - November 10th</title>
		<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/comment-page-1/#comment-2334</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefings - November 10th</dc:creator>
		<pubDate>Mon, 10 Nov 2008 14:22:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=447#comment-2334</guid>
		<description>[...] We&#8217;ve Reached the Application Security Tipping Point - Veracode [...]</description>
		<content:encoded><![CDATA[<p>[...] We&#8217;ve Reached the Application Security Tipping Point &#8211; Veracode [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Daily Incite - 11/06/08 - No sharing (and it&#8217;s a problem) [Security Incite Rants] &#124; Small Business System</title>
		<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/comment-page-1/#comment-2329</link>
		<dc:creator>The Daily Incite - 11/06/08 - No sharing (and it&#8217;s a problem) [Security Incite Rants] &#124; Small Business System</dc:creator>
		<pubDate>Sat, 08 Nov 2008 04:04:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=447#comment-2329</guid>
		<description>[...] eloquently discusses something that we probably already knew, but didn&#8217;t want to say. Everything is a target, which means everyone has to worry about little things like application secur... Of course, this is great news for Chris at his day job, though because everything is at risk [...]</description>
		<content:encoded><![CDATA[<p>[...] eloquently discusses something that we probably already knew, but didn&#8217;t want to say. Everything is a target, which means everyone has to worry about little things like application secur&#8230; Of course, this is great news for Chris at his day job, though because everything is at risk [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Christey</title>
		<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/comment-page-1/#comment-2324</link>
		<dc:creator>Steve Christey</dc:creator>
		<pubDate>Wed, 05 Nov 2008 17:42:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=447#comment-2324</guid>
		<description>While we have not done a similar analysis in CVE, I believe that ISS&#039; statistics are valid based on what we are seeing.

Further, for the OS software vendors, the types of vulnerabilities are often unusual (e.g. use-after-free, missing initialization) or very difficult to find and exploit.</description>
		<content:encoded><![CDATA[<p>While we have not done a similar analysis in CVE, I believe that ISS&#8217; statistics are valid based on what we are seeing.</p>
<p>Further, for the OS software vendors, the types of vulnerabilities are often unusual (e.g. use-after-free, missing initialization) or very difficult to find and exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Williams</title>
		<link>http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/comment-page-1/#comment-2323</link>
		<dc:creator>Jeff Williams</dc:creator>
		<pubDate>Wed, 05 Nov 2008 11:58:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=447#comment-2323</guid>
		<description>Some more thoughts on the fact that we&#039;ve reached a tipping point from the OWASP AppSec Conference in NYC last month - http://video.google.com/googleplayer.swf?docId=-228977859802026041</description>
		<content:encoded><![CDATA[<p>Some more thoughts on the fact that we&#8217;ve reached a tipping point from the OWASP AppSec Conference in NYC last month &#8211; <a href="http://video.google.com/googleplayer.swf?docId=-228977859802026041" rel="nofollow">http://video.google.com/googleplayer.swf?docId=-228977859802026041</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

