nyankoframe: (Default)
nyankoframe ([personal profile] nyankoframe) wrote2004-02-16 08:45 am
Entry tags:

Code auditing from the OSS/black-box perspectives

Dana Epp writes an article on this subject, in which he points out that the touted advantage of OSS - "Anyone can audit the code" isn't always true. It depends on whether code audits are done in the first place, who is auditing the code, and what level of auditing skills they have.

He also mentions that Microsoft is investing in security training - both for its own developers and for those that program for its platforms. They will be conducting a series of security webcasts this week.

Even if you don't develop for Windows (or have no intention of doing so), it might still be worth taking a look at. I know that I'll be doing so.

Post a comment in response:

This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting