<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Microsoft Security Development Lifecycle (SDL) and Software Security Today</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today/RSS"></atom:link>
	<image>
		<url>http://ecn.channel9.msdn.com/o9/previewImages/100/501491_100x75.jpg</url>
		<title>Channel 9 - Microsoft Security Development Lifecycle (SDL) and Software Security Today</title>
		<link></link>
	</image>
	<description>
The Microsoft Security Development Lifecycle (SDL) team recently released two new security tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer,&amp;nbsp;to help you write more secure code.
 Jeremy Dallman, Michael Howard, and Ivan Medvedev created these tools so we decided to pay them a visit to chat about what these tools do and why they matter. Of course, it&#39;s been
way too long since&amp;nbsp;Michael Howard has preached to us from his security soapbox so we just
had to get him&amp;nbsp;talking about the general state of software security today and where it&#39;s going!
For the Microsoft SDL team, SDL is as much a lifestyle as it is a software&amp;nbsp;development&amp;nbsp;lifecycle. Developers, thrive securely so that others may securely thrive. Oh yeah, brothers and sisters. I&#39;m sensing the need for a security soapbox show
 on 9. We need more preaching. There&#39;s still far too many&amp;nbsp;developers writing insecure code.&amp;nbsp;&amp;quot;Reverend&amp;quot; Howard, are you game, sir?Get&amp;nbsp;BinScope and MiniFuzz&amp;nbsp;on&amp;nbsp;SDL Tool Repository. Please use them!!! 
&amp;nbsp; 
Stay updated on the SDL at: 
http://www.microsoft.com/sdl 
http://blogs.msdn.com/sdl 
</description>
	<link></link>
	<language>en</language>
	<pubDate>Sat, 25 May 2013 00:31:54 GMT</pubDate>
	<lastBuildDate>Sat, 25 May 2013 00:31:54 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Microsoft Security Development Lifecycle (SDL) and Software Security Today</title>
		<description>
			<![CDATA[
<p>Cool - I spoke to Michael after his security session at TechEd last year, and he was talking about getting the time to write a fuzzer himself for 2010, and here it is! MiniFuzz <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /></p>
<p>posted by EdGillett</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today#c633931889410000000</link>
		<pubDate>Sat, 07 Nov 2009 11:09:01 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today#c633931889410000000</guid>
		<dc:creator>EdGillett</dc:creator>
	</item>
	<item>
		<title>Re: Microsoft Security Development Lifecycle (SDL) and Software Security Today</title>
		<description>
			<![CDATA[
<p>This&nbsp;Michael Howard guy's emphasis on security as a core academic subject to be studies in universities WORLD-wide is 100% true and crucial for the current day, but I'd say it's a bit easier to get it in Universities than having a hero do the dirty-work.
 &nbsp;These days universities rarely care of the future research which might actually solve the problems, and instead focus ALL funding on workforce education &amp; training instead of the R&amp;D which I only wish I could experience now. &nbsp;All I get are C#, Java, Algorithms,
 Data-flow etc..... <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-6.gif' alt='Sad' /> So its basically your job to tell the universities you require the skills so they will provide. &nbsp;It's not justified to me but it would work since they are led astray by the &quot;economical&quot; requirements you want them to train their students
 for career success as placeholder positions. &nbsp;</p>
<p>I'd be interested to hear otherwise from other peoples comments and academic experiences, they would be lucky to have such formal training instead of my self-guided learning&nbsp;curriculum&nbsp;of interests.</p>
<p>&nbsp;</p>
<p>Concerning the possible Lectures on C9, I'm already a functional programmer, so I skim the Functional programming videos lightly. &nbsp;I would on the other hand really appreciate and enjoy a security &quot;experts&quot; take on what to watch out for like common pitfalls
 and caveats with code vulnerabilities as a little series going over core secure data structures or constructs that I don't really need to worry about coming from the Haskell world that would apply to my current learning of C# (with Dev10 Beta2 of course) in
 my university classes right now.</p>
<p>&nbsp;</p>
<p>On a side note, my first test run of MiniFuzz showed no crashes in the log of my Assignment#4 for university, so far so good <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif' alt='Wink' />&nbsp;</p>
<p>posted by HeavensRevenge</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today#c633931905300000000</link>
		<pubDate>Sat, 07 Nov 2009 11:35:30 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today#c633931905300000000</guid>
		<dc:creator>HeavensRevenge</dc:creator>
	</item>
	<item>
		<title>Re: Microsoft Security Development Lifecycle (SDL) and Software Security Today</title>
		<description>
			<![CDATA[Is there a version of BinScope that works on Windows XP and with Visual Studio 2010?<br />When I tried it, it died with an unhandled exception on System.MissingMethodException in BinScope [3188]<br />&nbsp;<p>posted by Kelly</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today#c634281350690000000</link>
		<pubDate>Thu, 16 Dec 2010 22:24:29 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Charles/Michael-Howard-Ivan-Medvedev-and-Jeremy-Dallman-Software-Security-Today#c634281350690000000</guid>
		<dc:creator>Kelly</dc:creator>
	</item>
</channel>
</rss>