Mary Ann Davidson, chief security officer for database giant Oracle, remembers the first time she heard her company's marketing scheme that advertised its database products as "unbreakable." "I think my response was 'What idiot dreamed this up?," Davidson said Thursday at the W3C conference in Edinburgh, Scotland. . If civil engineers built bridges in the same fashion in which software developers write code, people would face the "blue bridge of death" every morning going to work, Davidson said. Software developers, she noted, tend to laugh nervously when they hear the analogy -- an insider reference to what programmers call the blank, "blue screen of death" on a PC display when Windows fails. The link for this article located at NetworkWorld is no longer available. . Johnathan Parker highlights the flaws in coding best practices, comparing buggy applications to catastrophic architectural mishaps.. Mary Ann Davidson, Database Security, Software Engineering, Coding Practices, Oracle Security. . LinuxSecurity.com Team
It's incredible that in this day and age some of the most popular security products, products that are marketed as protecting you from the evils of computers, are so badly designed. CheckPoint's FireWall-1, the leading firewall by market share, had . . . . It's incredible that in this day and age some of the most popular security products, products that are marketed as protecting you from the evils of computers, are so badly designed. CheckPoint's FireWall-1, the leading firewall by market share, had at least four vulnerabilities reported this year, and at least eleven reported last year. My intention is not to berate or point the finger at these companies. But one has to wonder, if vendors that specialize in security can't produce a secure product, what chance does any other software vendor have? And before you mention open source as a solution, consider its track record. With some exceptions, it's not much better.. Writing secure code is hard; designing a security product harder. They both require a lot of time, effort, and money. Complexity only makes things more difficult. All these factors are working against security. Complexity is increased in each revision of the software by adding more features. Time to market is essential to the commercial success of the products, and is shrinking all the time. Each product is made with as little money as possible, so as to increase its return, and allow the vendor to price it at a level customers will buy. Customers are always asking for more features, as soon as possible, and for a cheaper product. The link for this article located at The Register is no longer available. . Cybersecurity solutions face many challenges due to vulnerabilities and complexities of modern systems, requiring versatility to counter evolving threats and user behavior.. FireWall-1, CheckPoint, Software Design, Vulnerability Management. . LinuxSecurity.com Team
The UK Government's plans to eavesdrop on criminals that use the internet are "technically inept", say security experts. The technologies that the Regulation of Investigatory Powers (RIP) Bill would allow police use to spy on computer-literate criminals are easy to avoid, . . . . The UK Government's plans to eavesdrop on criminals that use the internet are "technically inept", say security experts. The technologies that the Regulation of Investigatory Powers (RIP) Bill would allow police use to spy on computer-literate criminals are easy to avoid, experts believe. The link for this article located at BBC is no longer available. . UK Authorities' initiatives to monitor cyber offenders condemned as fundamentally misguided by cybersecurity specialists.. Surveillance Technology,Cybersecurity Concerns,Privacy Regulations. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.