Show 008 - An Interview with Brian Chess

In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software. Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector. Gary and Brian discuss what commercial developers and academics have to learn from each other, what it’s like to work for a Kleiner-Perkins startup (KP is the VC firm behind familiar names like Google, Amazon, and Sun), and how mystifying it is that some developers are OK with XSS vulnerabilities in their web applications.
- Fortify Software
- extra - Fortify’s software security blog
- Matt Bishop’s Computer Security: Art and Science (mentioned again!)
- Kleiner Perkins Caufield & Byers
- DIMACS Workshop on Software Security with Brian Kernighan
- Brian as a wee lad




February 5th, 2007 at 8:31 pm
Seems like Mr Chess is very proud that there aren’t any Indian programmers at Fortify. Wonder if he knows that many Indian programmers were born and raised in the US.
February 7th, 2007 at 6:25 pm
Interesting comment.
I think that xenophobia around software development is misguided and silly. This is particularly striking in the US government where foreign companies are severly restricted from developing certain kinds of code while at the very same time many foreign nationals write code every day for US companies in silicon valley.
Code is code. Trust but verify and do not discriminate based on nation of origin.
gem
May 18th, 2007 at 7:08 am
Vic. Thank you for making me listen to this entire podcast. I had to with your “Mr. Chess is very proud that there aren’t any Indian programmers at Fortify” comment. Glad to see the P.C. Police are on their toes at http://www.cigital.com/silverbullet.
1) DrC is without a doubt one of the nicest, most open mined, and politically correct people I’ve ever known.
2) As with software security, context is everything. The context of Brian’s “Indian” comment has nothing to do with Asian Indians or the ethnicity of any of the programmers at Fortify. It’s the old, one “Chief” many “Indians”… ala “Too many Chiefs, not enough Indians”. Just part of the lexicon here in the US.
g…