Microsoft Security Development Lifecycle (SDL) and Software Security Today

Play Microsoft Security Development Lifecycle (SDL) and Software Security Today

The Discussion

  • User profile image

    Cool - I spoke to Michael after his security session at TechEd last year, and he was talking about getting the time to write a fuzzer himself for 2010, and here it is! MiniFuzz Smiley

  • User profile image

    This Michael Howard guy's emphasis on security as a core academic subject to be studies in universities WORLD-wide is 100% true and crucial for the current day, but I'd say it's a bit easier to get it in Universities than having a hero do the dirty-work.  These days universities rarely care of the future research which might actually solve the problems, and instead focus ALL funding on workforce education & training instead of the R&D which I only wish I could experience now.  All I get are C#, Java, Algorithms, Data-flow etc..... Sad So its basically your job to tell the universities you require the skills so they will provide.  It's not justified to me but it would work since they are led astray by the "economical" requirements you want them to train their students for career success as placeholder positions.  

    I'd be interested to hear otherwise from other peoples comments and academic experiences, they would be lucky to have such formal training instead of my self-guided learning curriculum of interests.


    Concerning the possible Lectures on C9, I'm already a functional programmer, so I skim the Functional programming videos lightly.  I would on the other hand really appreciate and enjoy a security "experts" take on what to watch out for like common pitfalls and caveats with code vulnerabilities as a little series going over core secure data structures or constructs that I don't really need to worry about coming from the Haskell world that would apply to my current learning of C# (with Dev10 Beta2 of course) in my university classes right now.


    On a side note, my first test run of MiniFuzz showed no crashes in the log of my Assignment#4 for university, so far so good Wink 

  • User profile image

    Is there a version of BinScope that works on Windows XP and with Visual Studio 2010?
    When I tried it, it died with an unhandled exception on System.MissingMethodException in BinScope [3188]

Add Your 2 Cents