<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: White Box Better Than Black Box</title>
	<atom:link href="http://www.veracode.com/blog/2009/10/white-box-better-than-black-box/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2009/10/white-box-better-than-black-box/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Thu, 09 Feb 2012 11:59:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Juan Gama</title>
		<link>http://www.veracode.com/blog/2009/10/white-box-better-than-black-box/comment-page-1/#comment-3139</link>
		<dc:creator>Juan Gama</dc:creator>
		<pubDate>Mon, 16 Nov 2009 19:12:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=964#comment-3139</guid>
		<description>You are right about the coverage, WhiteBox has a better results over BlackBox, but the problem that I&#039;ve been seeing is the cost, maybe is better to have a WhiteBox test but it is also more expensive, maybe this is the main retractor when companies do not want a internal security team and instead of it they go to external companies to perform a security test.

Besides BlackBox tests are way cooler than WhiteBox tests :P</description>
		<content:encoded><![CDATA[<p>You are right about the coverage, WhiteBox has a better results over BlackBox, but the problem that I&#8217;ve been seeing is the cost, maybe is better to have a WhiteBox test but it is also more expensive, maybe this is the main retractor when companies do not want a internal security team and instead of it they go to external companies to perform a security test.</p>
<p>Besides BlackBox tests are way cooler than WhiteBox tests :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M-unition &#187; Blog Archive &#187; WASC Web Application Security Statistics Published</title>
		<link>http://www.veracode.com/blog/2009/10/white-box-better-than-black-box/comment-page-1/#comment-3118</link>
		<dc:creator>M-unition &#187; Blog Archive &#187; WASC Web Application Security Statistics Published</dc:creator>
		<pubDate>Mon, 02 Nov 2009 14:31:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=964#comment-3118</guid>
		<description>[...] to Veracode&#8217;s Blog for pointing me to the Web Application Security Consortium (WASC) Web Application Security [...]</description>
		<content:encoded><![CDATA[<p>[...] to Veracode&#8217;s Blog for pointing me to the Web Application Security Consortium (WASC) Web Application Security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 気になった記事(20091023) [ほほほのほ]</title>
		<link>http://www.veracode.com/blog/2009/10/white-box-better-than-black-box/comment-page-1/#comment-3109</link>
		<dc:creator>気になった記事(20091023) [ほほほのほ]</dc:creator>
		<pubDate>Fri, 23 Oct 2009 03:58:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=964#comment-3109</guid>
		<description>[...] White box better than black box [...]</description>
		<content:encoded><![CDATA[<p>[...] White box better than black box [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Hull</title>
		<link>http://www.veracode.com/blog/2009/10/white-box-better-than-black-box/comment-page-1/#comment-3104</link>
		<dc:creator>Dave Hull</dc:creator>
		<pubDate>Wed, 21 Oct 2009 17:28:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=964#comment-3104</guid>
		<description>I read through the WASS data yesterday and found it matched nicely with my experience. I&#039;ve been working in app sec for a few years now, using the full gamut of threat modeling, static code analysis and manual testing. I see white box testing progressing along Stu Feldman&#039;s maturity model: 

1. You have a good idea.
2. You can make it work.
3. You convince a gullible friend to try it.
4. People stop asking why you&#039;re doing it.
5. People start asking others why they aren&#039;t doing it.

In the not too distant future, the companies that aren&#039;t doing white box testing will be the outliers.

Black box testing has too many unknowns and they are mostly unknown unknowns (thank you Rumsfeld).</description>
		<content:encoded><![CDATA[<p>I read through the WASS data yesterday and found it matched nicely with my experience. I&#8217;ve been working in app sec for a few years now, using the full gamut of threat modeling, static code analysis and manual testing. I see white box testing progressing along Stu Feldman&#8217;s maturity model: </p>
<p>1. You have a good idea.<br />
2. You can make it work.<br />
3. You convince a gullible friend to try it.<br />
4. People stop asking why you&#8217;re doing it.<br />
5. People start asking others why they aren&#8217;t doing it.</p>
<p>In the not too distant future, the companies that aren&#8217;t doing white box testing will be the outliers.</p>
<p>Black box testing has too many unknowns and they are mostly unknown unknowns (thank you Rumsfeld).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

