Microsoft Security Development Lifecycle (SDL) and Software Security Today
- Posted: Nov 06, 2009 at 1:49 PM
- 45,899 Views
- 3 Comments
Download
How do I download the videos?
- To download, right click the file type you would like and pick “Save target as…” or “Save link as…”
Why should I download videos from Channel9?
- It's an easy way to save the videos you like locally.
- You can save the videos in order to watch them offline.
- If all you want is to hear the audio, you can download the MP3!
Which version should I choose?
- If you want to view the video on your PC, Xbox or Media Center, download the High Quality WMV file (this is the highest quality version we have available).
- If you'd like a lower bitrate version, to reduce the download time or cost, then choose the Medium Quality WMV file.
- If you have a Zune, WP7, iPhone, iPad, or iPod device, choose the low or medium MP4 file.
- If you just want to hear the audio of the video, choose the MP3 file.
Right click “Save as…”
- High Quality WMV (PC, Xbox, MCE)
- MP3 (Audio only)
- MP4 (iPod, Zune HD)
- Mid Quality WMV (Lo-band, Mobile)
The Microsoft Security Development Lifecycle (SDL) team recently released two new security tools, BinScope Binary Analyzer and MiniFuzz File Fuzzer, to help you write more secure code.
Jeremy Dallman, Michael Howard, and Ivan Medvedev created these tools so we decided to pay them a visit to chat about what these tools do and why they matter. Of course, it's been
way too long since Michael Howard has preached to us from his security soapbox so we just
had to get him talking about the general state of software security today and where it's going!
For the Microsoft SDL team, SDL is as much a lifestyle as it is a software development lifecycle. Developers, thrive securely so that others may securely thrive. Oh yeah, brothers and sisters. I'm sensing the need for a security soapbox show
on 9. We need more preaching. There's still far too many developers writing insecure code. "Reverend" Howard, are you game, sir?
Get BinScope and MiniFuzz on SDL Tool Repository. Please use them!!!
Stay updated on the SDL at:
Comments Closed
Comments have been closed since this content was published more than 30 days ago, but if you'd like to continue the conversation,
please create a new thread in our Forums,
or
Contact Us and let us know.
Follow the Discussion
Cool - I spoke to Michael after his security session at TechEd last year, and he was talking about getting the time to write a fuzzer himself for 2010, and here it is! MiniFuzz
This Michael Howard guy's emphasis on security as a core academic subject to be studies in universities WORLD-wide is 100% true and crucial for the current day, but I'd say it's a bit easier to get it in Universities than having a hero do the dirty-work. These days universities rarely care of the future research which might actually solve the problems, and instead focus ALL funding on workforce education & training instead of the R&D which I only wish I could experience now. All I get are C#, Java, Algorithms, Data-flow etc.....
So its basically your job to tell the universities you require the skills so they will provide. It's not justified to me but it would work since they are led astray by the "economical" requirements you want them to train their students
for career success as placeholder positions.
I'd be interested to hear otherwise from other peoples comments and academic experiences, they would be lucky to have such formal training instead of my self-guided learning curriculum of interests.
Concerning the possible Lectures on C9, I'm already a functional programmer, so I skim the Functional programming videos lightly. I would on the other hand really appreciate and enjoy a security "experts" take on what to watch out for like common pitfalls and caveats with code vulnerabilities as a little series going over core secure data structures or constructs that I don't really need to worry about coming from the Haskell world that would apply to my current learning of C# (with Dev10 Beta2 of course) in my university classes right now.
On a side note, my first test run of MiniFuzz showed no crashes in the log of my Assignment#4 for university, so far so good
Is there a version of BinScope that works on Windows XP and with Visual Studio 2010?
When I tried it, it died with an unhandled exception on System.MissingMethodException in BinScope [3188]
Remove this comment
Remove this thread
close