<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Secure Coding</title>
    <link>http://seclists.org/#securecoding</link>
    <atom:link href="http://seclists.org/rss/securecoding.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>The Secure Coding list (SC-L) is an open forum for the discussion on developing secure applications. It is moderated by the authors of &lt;a href=&quot;http://www.amazon.com/dp/0596002424?tag=secbks-20&quot;&gt;Secure Coding: Principles and Practices&lt;/a&gt;.</description>
    <pubDate>Wed, 23 May 2012 07:00:05 GMT</pubDate>
    <lastBuildDate>Wed, 23 May 2012 07:00:05 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Call for Papers: The 7th International Conference for Internet Technology and Secured Transactions (ICITST-2012)</title>
    <link>http://seclists.org/securecoding/2012/q2/23</link>
    <description>&lt;p&gt;Posted by Call for papers on May 22&lt;/p&gt;Call for Papers: The 7th International Conference for Internet &lt;br&gt;
Technology and Secured Transactions (ICITST-2012)&lt;br&gt;
&lt;br&gt;
Apologies for cross-postings.&lt;br&gt;
&lt;br&gt;
Kindly email this call for papers to your colleagues,&lt;br&gt;
faculty members and postgraduate students.&lt;br&gt;
&lt;br&gt;
CALL FOR PAPERS&lt;br&gt;
&lt;br&gt;
*********************************************************&lt;br&gt;
Papers: The 7th International Conference for Internet Technology and &lt;br&gt;
Secured Transactions (ICITST-2012)&lt;br&gt;
Technical Co-Sponsored by...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 06:52:12 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/23</guid>
  </item>


  <item>
    <title>MetriSec 2012 submission date is May 30th</title>
    <link>http://seclists.org/securecoding/2012/q2/22</link>
    <description>&lt;p&gt;Posted by James Walden on May 14&lt;/p&gt;MetriSec 2012&lt;br&gt;
8th International Workshop on&lt;br&gt;
SECURITY MEASUREMENTS AND METRICS&lt;br&gt;
&lt;br&gt;
Affiliated with the International Symposium on&lt;br&gt;
Empirical Software Engineering and Measurement (ESEM)&lt;br&gt;
&lt;br&gt;
September 21, 2012&lt;br&gt;
Lund, Sweden&lt;br&gt;
&lt;br&gt;
WORKSHOP OVERVIEW&lt;br&gt;
&lt;br&gt;
Quantitative assessment is a major stumbling block for software and&lt;br&gt;
system security. Although some security metrics exist, they are rarely&lt;br&gt;
adequate. The engineering importance of metrics is intuitive: you&lt;br&gt;
cannot...&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 17:16:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/22</guid>
  </item>
  <item>
    <title>Re: Re (badware vs. &quot;goodware&quot;): SearchSecurity: Badware versus	malware</title>
    <link>http://seclists.org/securecoding/2012/q2/21</link>
    <description>&lt;p&gt;Posted by Goertzel, Karen [USA] on May 14&lt;/p&gt;Agent software is all well and good. &lt;br&gt;
&lt;br&gt;
But if you secretly implant the agents, and design them to be undetectable, and do not inform the intended user of the &lt;br&gt;
system that they are there, they are spyware - and at best, unethical. And, by my definition at least, unethical = bad. &lt;br&gt;
&lt;br&gt;
===&lt;br&gt;
Karen Mercedes Goertzel, CISSP&lt;br&gt;
Lead Associate&lt;br&gt;
Booz Allen Hamilton&lt;br&gt;
703.698.7454&lt;br&gt;
goertzel_karen () bah com&lt;br&gt;
&lt;br&gt;
&amp;quot;I love deadlines. I like the whooshing sound they...&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 17:01:12 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/21</guid>
  </item>


  <item>
    <title>Containing bad code</title>
    <link>http://seclists.org/securecoding/2012/q2/20</link>
    <description>&lt;p&gt;Posted by Ben Laurie on May 13&lt;/p&gt;Given the recent discussion, I thought the list might be interested in:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.links.org/?p=1242&quot;&gt;http://www.links.org/?p=1242&lt;/a&gt;. I&amp;apos;m currently working on transparently&lt;br&gt;
wrapping libtiff (that is, wrapping it such that the calling application is&lt;br&gt;
unaware it is wrapped).&lt;br&gt;
&lt;br&gt;
Using Capsicum For Sandboxing &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.links.org/?p=1242&quot;&gt;http://www.links.org/?p=1242&lt;/a&gt;&amp;gt;&lt;br&gt;
&lt;br&gt;
FreeBSD 9.0 &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.freebsd.org/releases/9.0R/announce.html&quot;&gt;http://www.freebsd.org/releases/9.0R/announce.html&lt;/a&gt;&amp;gt;, released&lt;br&gt;
in January 2012, has experimental&lt;br&gt;
Capsicum&amp;lt;...&lt;br&gt;</description>
    <pubDate>Sun, 13 May 2012 15:07:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/20</guid>
  </item>
  <item>
    <title>Re: SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/19</link>
    <description>&lt;p&gt;Posted by Tom Brennan on May 13&lt;/p&gt;OWASP Has started month awareness proble/solution see updated: &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.owasp.com&quot;&gt;http://www.owasp.com&lt;/a&gt;  &lt;br&gt;
&lt;br&gt;
Point you ask......  As a united community we raise visibility for the problem that results in a ecosystem - lets make &lt;br&gt;
noise about it together, monthly and globally from the builder / breaker &amp;amp;  defender perspectives  &lt;br&gt;</description>
    <pubDate>Sun, 13 May 2012 14:21:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/19</guid>
  </item>


  <item>
    <title>Re: SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/18</link>
    <description>&lt;p&gt;Posted by Ben Laurie on May 12&lt;/p&gt;Well, it certainly does _suggest_ it: &amp;quot;All of the things that we do to&lt;br&gt;
improve software security are aimed explicitly at the badware&lt;br&gt;
problem.&amp;quot;&lt;br&gt;
&lt;br&gt;
It doesn&amp;apos;t say it, though, I agree.&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 16:48:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/18</guid>
  </item>
  <item>
    <title>Re: SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/17</link>
    <description>&lt;p&gt;Posted by Gary McGraw on May 12&lt;/p&gt;The article does not suggest otherwise.&lt;br&gt;
&lt;br&gt;
gem&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 16:37:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/17</guid>
  </item>


  <item>
    <title>Re: SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/16</link>
    <description>&lt;p&gt;Posted by Ben Laurie on May 11&lt;/p&gt;Fixing badware universally would plug one hole - and it&amp;apos;s certainly a&lt;br&gt;
hole worth plugging. But it won&amp;apos;t eliminate malware - it seems it is&lt;br&gt;
not hard to persuade users to install it for you, for example.&lt;br&gt;</description>
    <pubDate>Fri, 11 May 2012 18:35:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/16</guid>
  </item>
  <item>
    <title>MoST 2012 (SPW) registration</title>
    <link>http://seclists.org/securecoding/2012/q2/15</link>
    <description>&lt;p&gt;Posted by Larry Koved on May 11&lt;/p&gt;On behalf of the workshop co-chairs and program chair, we would like to &lt;br&gt;
invite you participate in the Mobile Security Technologies (MoST) &lt;br&gt;
Workshop.&lt;br&gt;
&lt;br&gt;
The workshop will be held at the The Westin St. Francis Hotel, San &lt;br&gt;
Francisco.&lt;br&gt;
&lt;br&gt;
Workshop registration site: &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.regonline.com/Register/Checkin.aspx?EventID=1072068&quot;&gt;http://www.regonline.com/Register/Checkin.aspx?EventID=1072068&lt;/a&gt; &lt;br&gt;
&lt;br&gt;
MoST is part of the Security and Privacy Workshops (SPW)&lt;br&gt;
event (&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.ieee-security.org/TC/SPW2012/&quot;&gt;http://www.ieee-security.org/TC/SPW2012/&lt;/a&gt;),&lt;br&gt;
co-located with...&lt;br&gt;</description>
    <pubDate>Fri, 11 May 2012 14:34:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/15</guid>
  </item>
  <item>
    <title>Re: SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/14</link>
    <description>&lt;p&gt;Posted by Goertzel, Karen [USA] on May 11&lt;/p&gt;In other words, flaws and defects caused through developer error, ignorance, negligence etc. can be exploited to cause &lt;br&gt;
harm. So even if one could prevent actual intentional malicious inclusions in software, one hasn&amp;apos;t eliminated the &lt;br&gt;
problem of exploitable flawed logic.&lt;br&gt;
&lt;br&gt;
The megachallenge, of course, is looking for what one doesn&amp;apos;t actually know is there. Which is why software security &lt;br&gt;
testing is so hard.&lt;br&gt;
&lt;br&gt;
===&lt;br&gt;
Karen Mercedes Goertzel,...&lt;br&gt;</description>
    <pubDate>Fri, 11 May 2012 14:22:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/14</guid>
  </item>


  <item>
    <title>Re: SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/13</link>
    <description>&lt;p&gt;Posted by Peter G. Neumann on May 10&lt;/p&gt;The differences are marginal.&lt;br&gt;
&lt;br&gt;
My book has a pervasive theme:&lt;br&gt;
  Many things that could happen accidentally could be triggered &lt;br&gt;
intentionally.&lt;br&gt;
  Many things that happen intentionally could be triggered accidentally.&lt;br&gt;
&lt;br&gt;
Trying to reduce one without the other may be foolhardy in most realistic&lt;br&gt;
threat models.&lt;br&gt;</description>
    <pubDate>Thu, 10 May 2012 15:30:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/13</guid>
  </item>
  <item>
    <title>Breakpoint 2012 Call For Papers</title>
    <link>http://seclists.org/securecoding/2012/q2/12</link>
    <description>&lt;p&gt;Posted by cfp on May 10&lt;/p&gt;                 . ______________________________________&lt;br&gt;
                 ._\\.         Breakpoint 2012           (___.&lt;br&gt;
                 :          Intercontinental Rialto          :&lt;br&gt;
                 :           Melbourne,  Australia           :&lt;br&gt;
                 :             October 17th-18th             :&lt;br&gt;
                 :__                                    . ___:&lt;br&gt;
                    )____________________________________\\...&lt;br&gt;</description>
    <pubDate>Thu, 10 May 2012 15:15:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/12</guid>
  </item>


  <item>
    <title>SearchSecurity: Badware versus malware</title>
    <link>http://seclists.org/securecoding/2012/q2/11</link>
    <description>&lt;p&gt;Posted by Gary McGraw on May 08&lt;/p&gt;hi sc-l,&lt;br&gt;
&lt;br&gt;
What’s worse, bad software or malicious software?  In fact, what’s the difference?&lt;br&gt;
&lt;br&gt;
My second column for SearchSecurity is all about that.  Read it today.  And pass it on.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://searchsecurity.techtarget.com/opinion/Gary-McGraw-Eliminating-badware-addresses-malware-problem&quot;&gt;http://searchsecurity.techtarget.com/opinion/Gary-McGraw-Eliminating-badware-addresses-malware-problem&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Bottom line: Talking about malware may be more fun and entertaining than talking about endless security bugs, but if &lt;br&gt;
we’re going to combat malware we have to...&lt;br&gt;</description>
    <pubDate>Tue, 08 May 2012 12:48:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/11</guid>
  </item>
  <item>
    <title>c0c0n 2012 CFP - Extended Deadline: May 15, 2012</title>
    <link>http://seclists.org/securecoding/2012/q2/10</link>
    <description>&lt;p&gt;Posted by c0c0n International Information Security Conference on May 08&lt;/p&gt;c0c0n 2012 CFP - Extended Deadline: May 15, 2012&lt;br&gt;
&lt;br&gt;
Thanks to everyone for all the paper submissions. The CFP Review Committee&lt;br&gt;
will be evaluating the same for selection. Based on the requests received,&lt;br&gt;
we are extending the CFP deadline to May 15, 2012 in the hope of receiving&lt;br&gt;
few more paper submissions.&lt;br&gt;
&lt;br&gt;
####################################################&lt;br&gt;
c0c0n 2012 - Call For Papers and Call For Workshops...&lt;br&gt;</description>
    <pubDate>Tue, 08 May 2012 12:33:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/10</guid>
  </item>


  <item>
    <title>Silver Bullet 73: Robert Vamosi</title>
    <link>http://seclists.org/securecoding/2012/q2/9</link>
    <description>&lt;p&gt;Posted by Gary McGraw on May 04&lt;/p&gt;hi sc-l,&lt;br&gt;
&lt;br&gt;
This morning we released episode 73 of Silver Bullet.  The new show is an interview with Robert Vamosi.  Robert is a &lt;br&gt;
well-known security reporter, having worked for a bunch of esteemed publications including Forbes, c!net, and &lt;br&gt;
threatpost.  Robert also wrote a book called &amp;quot;When Gadgets Betray Us&amp;quot; which many of you will find interesting.  Have a &lt;br&gt;
listen:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cigital.com/silver-bullet/show-073/&quot;&gt;http://www.cigital.com/silver-bullet/show-073/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
As always, thanks to...&lt;br&gt;</description>
    <pubDate>Fri, 04 May 2012 17:28:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/securecoding/2012/q2/9</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

