<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Musings on Custer&#8217;s Last Stand</title>
	<atom:link href="http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Blog Lists of the Best Security Blogs (Worth a Read/Bookmarks)</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-15681</link>
		<dc:creator>Blog Lists of the Best Security Blogs (Worth a Read/Bookmarks)</dc:creator>
		<pubDate>Thu, 08 Mar 2012 15:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-15681</guid>
		<description>[...] Veracode Blog http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Veracode Blog http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Veracode Blog &#187; Welcome to the NEW Veracode Blog!</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-13440</link>
		<dc:creator>Veracode Blog &#187; Welcome to the NEW Veracode Blog!</dc:creator>
		<pubDate>Wed, 21 Dec 2011 01:57:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-13440</guid>
		<description>[...] And we’ll never shy away from controversy as Chris Wysopal demonstrated in his response to the Oracle CSO blog attacking Veracode and Chris Eng’s recent post about the dysfunction that often exists between developers and the [...]</description>
		<content:encoded><![CDATA[<p>[...] And we’ll never shy away from controversy as Chris Wysopal demonstrated in his response to the Oracle CSO blog attacking Veracode and Chris Eng’s recent post about the dysfunction that often exists between developers and the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: So-so SASO &#8230; So What? &#124; BlogInfoSec.com</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9970</link>
		<dc:creator>So-so SASO &#8230; So What? &#124; BlogInfoSec.com</dc:creator>
		<pubDate>Mon, 26 Sep 2011 10:01:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9970</guid>
		<description>[...] I was pointed to Veracode’s Chris Wysopal’s response “Musings on Custer’s Last Stand” at http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/  by an email from Tom Brennan of OWASP. The result was that I thought I should begin again and [...]</description>
		<content:encoded><![CDATA[<p>[...] I was pointed to Veracode’s Chris Wysopal’s response “Musings on Custer’s Last Stand” at <a href="http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/ " rel="nofollow">http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/ </a> by an email from Tom Brennan of OWASP. The result was that I thought I should begin again and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9922</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Fri, 16 Sep 2011 15:32:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9922</guid>
		<description>It&#039;s odd how Guys like Andre Gironda can defend Oracle avoiding any comments about facts as:
- Their laughable “Unbreakable” marketing campaign was famously debunked by security expert David Litchfield
- They’ve also earned a reputation for glacial response times and sloppy patches.

He is right we may leave Oracle alone, completely alone...Avoiding to buy crappy  Software.</description>
		<content:encoded><![CDATA[<p>It&#8217;s odd how Guys like Andre Gironda can defend Oracle avoiding any comments about facts as:<br />
- Their laughable “Unbreakable” marketing campaign was famously debunked by security expert David Litchfield<br />
- They’ve also earned a reputation for glacial response times and sloppy patches.</p>
<p>He is right we may leave Oracle alone, completely alone&#8230;Avoiding to buy crappy  Software.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Podcast, Episode 253 &#187; 信息安全播客</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9746</link>
		<dc:creator>Network Security Podcast, Episode 253 &#187; 信息安全播客</dc:creator>
		<pubDate>Wed, 07 Sep 2011 13:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9746</guid>
		<description>[...] Pissing match between Oracle and Veracode. [...]</description>
		<content:encoded><![CDATA[<p>[...] Pissing match between Oracle and Veracode. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Wysopal</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9745</link>
		<dc:creator>Chris Wysopal</dc:creator>
		<pubDate>Wed, 07 Sep 2011 13:28:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9745</guid>
		<description>While 3rd party testing is important for people consuming software, SDLC based testing is important for people building software.  Testing after the software is built certainly does not replace security processes during the SDLC.  It is merely verification that those processes took place.  The majority of Veracode customers are using our service during the SDLC to build secure software. Some do 3rd party testing in addition but not all.

We believe enterprise application security programs cannot stop at the code you write but must include testing of the components and libraries you use to build your internal software and must include testing of software packages you purchase.

Advocating for 3rd party testing does not mean we don&#039;t believe the best place for software security testing isn&#039;t the SDLC.  We also don&#039;t believe automated testing is all that should be done during the SDLC to produce secure software.  We think training is incredibly important and offer dozens of eLearning courses. We also think application security experts should be part of any SDLC so we have dozens of partners that can perform threat modeling, design reviews, secure architecture, and manual security testing for our customers in concert with our automation.

Automated testing is part of the application security solution.  It is our focus but since day one as a company over 5 years ago we have never said automated testing was a complete application security solution.  It will always be people process and technology.</description>
		<content:encoded><![CDATA[<p>While 3rd party testing is important for people consuming software, SDLC based testing is important for people building software.  Testing after the software is built certainly does not replace security processes during the SDLC.  It is merely verification that those processes took place.  The majority of Veracode customers are using our service during the SDLC to build secure software. Some do 3rd party testing in addition but not all.</p>
<p>We believe enterprise application security programs cannot stop at the code you write but must include testing of the components and libraries you use to build your internal software and must include testing of software packages you purchase.</p>
<p>Advocating for 3rd party testing does not mean we don&#8217;t believe the best place for software security testing isn&#8217;t the SDLC.  We also don&#8217;t believe automated testing is all that should be done during the SDLC to produce secure software.  We think training is incredibly important and offer dozens of eLearning courses. We also think application security experts should be part of any SDLC so we have dozens of partners that can perform threat modeling, design reviews, secure architecture, and manual security testing for our customers in concert with our automation.</p>
<p>Automated testing is part of the application security solution.  It is our focus but since day one as a company over 5 years ago we have never said automated testing was a complete application security solution.  It will always be people process and technology.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Network Security Podcast, Episode 253</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9731</link>
		<dc:creator>Network Security Blog &#187; Network Security Podcast, Episode 253</dc:creator>
		<pubDate>Tue, 06 Sep 2011 23:57:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9731</guid>
		<description>[...] Pissing match between Oracle and Veracode. [...]</description>
		<content:encoded><![CDATA[<p>[...] Pissing match between Oracle and Veracode. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Podcast &#187; Blog Archive &#187; Network Security Podcast, Episode 253</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9730</link>
		<dc:creator>Network Security Podcast &#187; Blog Archive &#187; Network Security Podcast, Episode 253</dc:creator>
		<pubDate>Tue, 06 Sep 2011 23:56:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9730</guid>
		<description>[...] Pissing match between Oracle and Veracode. [...]</description>
		<content:encoded><![CDATA[<p>[...] Pissing match between Oracle and Veracode. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hannibal Lecter</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9652</link>
		<dc:creator>Hannibal Lecter</dc:creator>
		<pubDate>Sat, 03 Sep 2011 04:46:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9652</guid>
		<description>&quot;Though not unusual for CSO&#039;s in the Fortune 500 at large, Davidson&#039;s lack of formal training in technology stands out among CSO&#039;s for major technology companies; her peers include former software developer John Stewart, CSO of Cisco Systems, computer forensics expert Howard Schmidt, former CSO of Microsoft, and famed cryptographer Whitfield Diffie, CSO of Sun Microsystems.&quot;</description>
		<content:encoded><![CDATA[<p>&#8220;Though not unusual for CSO&#8217;s in the Fortune 500 at large, Davidson&#8217;s lack of formal training in technology stands out among CSO&#8217;s for major technology companies; her peers include former software developer John Stewart, CSO of Cisco Systems, computer forensics expert Howard Schmidt, former CSO of Microsoft, and famed cryptographer Whitfield Diffie, CSO of Sun Microsystems.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry Suto</title>
		<link>http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/comment-page-1/#comment-9601</link>
		<dc:creator>Larry Suto</dc:creator>
		<pubDate>Thu, 01 Sep 2011 04:56:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1999#comment-9601</guid>
		<description>I think it is important to have the option of an ecosystem where you can outsource scanning and static analysis because it can provide valuable information that leads to the discovery of security problems.

The problem is that software security requires predictions to be be made on state transitions in some very complex execution contexts. The simple state tracing automata that we have today is woefully inadequate just ask any one who has done manual code review for any length of time.

I think Veracode provides a valuable service but since static analysis still has a long way to go it is just not enough for providing a reasonable sense of assurance on any software system of significant complexity.</description>
		<content:encoded><![CDATA[<p>I think it is important to have the option of an ecosystem where you can outsource scanning and static analysis because it can provide valuable information that leads to the discovery of security problems.</p>
<p>The problem is that software security requires predictions to be be made on state transitions in some very complex execution contexts. The simple state tracing automata that we have today is woefully inadequate just ask any one who has done manual code review for any length of time.</p>
<p>I think Veracode provides a valuable service but since static analysis still has a long way to go it is just not enough for providing a reasonable sense of assurance on any software system of significant complexity.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

