Secure Coding mailing list archives

[Owasp-dotnet] Re: Is there any Security problem in Ajax technology?


From: gwc at acm.org (George Capehart)
Date: Thu, 16 Mar 2006 19:17:36 -0500

Gadi Evron wrote:

In other words, it's just Javascript. Do your coding securely. I don't
like the big buzz. This is nothing new.

Hola Gadi!

*grin*  I absolutely agree.  It is absolutely not new . . .

The challenge is in helping people to understand what a security
boundary is.

<rant>
The problem is:  We /*still*/ have _this_ problem . . .  :}  It's been my
experience over the years that very, very, very few system architects
understand the concept and design systems appropriately.  Having said that,
I'm not shaking my finger at them.  If it were important to $MANAGEMENT that
the system design be aware of it and respect it, it would be so.  After all,
in the end, this is all about risk management.  /*That*/ is management's job.
</rant>

Apologies, but I have to get it off my chest every now and then . . .  ;>

I wish I had a good Yoda quote right now, but all I can come up with is
Terry Goodkind, which I feel very ashamed of.

NP.  Thanks for turning me onto a new author!  :)

Cheers,

/g



Current thread: