The Rust Foundation will be developing a training and certification program to ensure that developers who use the language can create secure software . The training will include both online and in-person options and will be available in many different languages. . The goal of this program is to make sure that Rust's developers are getting the education they need to create secure software. The language itself is already secure, but it's important for developers to understand how their code works so they can write it correctly. This program will also help developers get jobs: employers want to hire people who know how to do their jobs well, and this program will give them the confidence needed to apply for jobs without worrying that they won't know enough about security. The article linked below helped me understand the specific details of this program, and I thought you would benefit from reading it as well! The link for this article located at Rust Foundation is no longer available. . Empower Rust programmers to master essential techniques for creating robust software via an innovative training initiative.. Rust Foundation, Developer Training, Secure Software, Certification Program, Online Learning. . Brittany Day
In my line of work it is inevitable, but always shocking, to see the number of high-risk security flaws developers have left behind. Most worryingly, a major proportion of vulnerabilities are due to a basic misunderstanding of the internet protocol and . . . . In my line of work it is inevitable, but always shocking, to see the number of high-risk security flaws developers have left behind. Most worryingly, a major proportion of vulnerabilities are due to a basic misunderstanding of the internet protocol and system software used to host or use the web application. Many developers fail to understand the nuances of the HTTP protocol and assume that it is too difficult, or not worth the trouble, for an attacker to assault their custom application. Developers must assume that every packet of data not coming from the organisation's hosts and servers can be modified. Infrequently, 'security aware' sites manage to correctly implement input validation rules for client data. Unfortunately, all client-side checking and data validation processes can be bypassed by an attacker using commonly available tools and methodologies. The link for this article located at VNUNet is no longer available. . Critical vulnerabilities in applications arise from misinterpreting communication standards and inadequate checks on user input.. High-Risk Flaws, Application Security, Internet Protocols, Developer Education, Data Validation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.