<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.11" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Show 025 - An Interview with Jon Swartz</title>
	<link>http://www.cigital.com/silverbullet/show-025/</link>
	<description>In-depth conversations with leading security gurus, hosted by Gary McGraw, sponsored by IEEE Security &#038; Privacy Magazine.</description>
	<pubDate>Fri, 16 May 2008 13:25:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.11</generator>

	<item>
		<title>by: gem</title>
		<link>http://www.cigital.com/silverbullet/show-025/#comment-27230</link>
		<pubDate>Thu, 01 May 2008 15:22:04 +0000</pubDate>
		<guid>http://www.cigital.com/silverbullet/show-025/#comment-27230</guid>
					<description>Hi Stephen,

I would have to agree with you about hype and security.  I also agree that big vendors make stuff up if it helps them sell product.  One of the reasons I wanted to interview Jon was to find out what he thought about hype, wide public coverage, and security engineering.  What I like about Jon is his realistic attitude and his reporter's skepticism.  

Fact is, the part of computer security that the general public find exciting is the hacking/exploit part.  You can even see this in the sales numbers of my books where the bad guy books outsell the good guy books almost 4:1.  I call this the NASCAR effect.

I agree with you that asking software vendors to show you some evidence that their software is secure can be very helpful.  We've been involved in situations like that a number of times at cigital (where the poor software vendor was scrambling toward software security and needed our help).

BTW, the next victim on Silver Bullet will be Adam Shostack...so we should get a bit more technical!

gem</description>
		<content:encoded><![CDATA[<p>Hi Stephen,</p>
<p>I would have to agree with you about hype and security.  I also agree that big vendors make stuff up if it helps them sell product.  One of the reasons I wanted to interview Jon was to find out what he thought about hype, wide public coverage, and security engineering.  What I like about Jon is his realistic attitude and his reporter&#8217;s skepticism.  </p>
<p>Fact is, the part of computer security that the general public find exciting is the hacking/exploit part.  You can even see this in the sales numbers of my books where the bad guy books outsell the good guy books almost 4:1.  I call this the NASCAR effect.</p>
<p>I agree with you that asking software vendors to show you some evidence that their software is secure can be very helpful.  We&#8217;ve been involved in situations like that a number of times at cigital (where the poor software vendor was scrambling toward software security and needed our help).</p>
<p>BTW, the next victim on Silver Bullet will be Adam Shostack&#8230;so we should get a bit more technical!</p>
<p>gem
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stephen Craig Evans</title>
		<link>http://www.cigital.com/silverbullet/show-025/#comment-27228</link>
		<pubDate>Thu, 01 May 2008 15:07:00 +0000</pubDate>
		<guid>http://www.cigital.com/silverbullet/show-025/#comment-27228</guid>
					<description>Hi Gary,

The interview was interesting (but not nearly as technical and as in depth that I am now expecting :-) but I have a couple of issues in general - not with Mr. Swartz but with his content:

1. Trying to put the onus of software security on developers is so completely asinine (and Jon did not say that - he reported that others had said that). We have to get real. Most developers will never know software security; 70% don't give a damn; 20% of those that want to know will never get funding by their company to learn it; the other 10% will learn by self-motivation and by buying a lot of books :-)

Instead, why don't we preach that when somebody buys or leases software from a company that they ask one simple question: (1) Can you give me a document that tells me the security that you've put in your software?

In Asia Pacific (excluding Australia &#38; Japan), that question would knock out 98% of the companies immediately.

2. Again, completely unrelated to Mr. Swartz himself, but the value and dollar amount placed on breaches PER PERSON PER BREACH. It reminds me too much when I was younger and I would read the value of a marijuana bust, knowing that the cops included the weight of the buds, the stems, the roots, the soil, etc. at the inflated street price per gram. I don't see that correlation. Adam Shostack in a recent Shmoocon event ("Security Breaches are Good for You") tried to address this also - nobody know the actual amount, and my guess is that it is totally overinflated.

To take a page from RSnake and his proposed (and declined) talk at RSA, the heads of the BSVs (Big Security Vendors) are the biggest snake-oil salesman that I've ever seen. Who in their right mind would believe them? Of course, they are now peddling DLP - they've pumped hundreds of millions of dollars into it. I'm having a difficult time distinguishing these BSV CEOs from drug pushers.

Cheers.</description>
		<content:encoded><![CDATA[<p>Hi Gary,</p>
<p>The interview was interesting (but not nearly as technical and as in depth that I am now expecting <img src='http://www.cigital.com/silverbullet/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  but I have a couple of issues in general - not with Mr. Swartz but with his content:</p>
<p>1. Trying to put the onus of software security on developers is so completely asinine (and Jon did not say that - he reported that others had said that). We have to get real. Most developers will never know software security; 70% don&#8217;t give a damn; 20% of those that want to know will never get funding by their company to learn it; the other 10% will learn by self-motivation and by buying a lot of books <img src='http://www.cigital.com/silverbullet/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Instead, why don&#8217;t we preach that when somebody buys or leases software from a company that they ask one simple question: (1) Can you give me a document that tells me the security that you&#8217;ve put in your software?</p>
<p>In Asia Pacific (excluding Australia &amp; Japan), that question would knock out 98% of the companies immediately.</p>
<p>2. Again, completely unrelated to Mr. Swartz himself, but the value and dollar amount placed on breaches PER PERSON PER BREACH. It reminds me too much when I was younger and I would read the value of a marijuana bust, knowing that the cops included the weight of the buds, the stems, the roots, the soil, etc. at the inflated street price per gram. I don&#8217;t see that correlation. Adam Shostack in a recent Shmoocon event (&#8221;Security Breaches are Good for You&#8221;) tried to address this also - nobody know the actual amount, and my guess is that it is totally overinflated.</p>
<p>To take a page from RSnake and his proposed (and declined) talk at RSA, the heads of the BSVs (Big Security Vendors) are the biggest snake-oil salesman that I&#8217;ve ever seen. Who in their right mind would believe them? Of course, they are now peddling DLP - they&#8217;ve pumped hundreds of millions of dollars into it. I&#8217;m having a difficult time distinguishing these BSV CEOs from drug pushers.</p>
<p>Cheers.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Justice League &#187; Blog Archive &#187; Unsafe at any bitrate? [Cigital]</title>
		<link>http://www.cigital.com/silverbullet/show-025/#comment-26460</link>
		<pubDate>Wed, 23 Apr 2008 15:18:15 +0000</pubDate>
		<guid>http://www.cigital.com/silverbullet/show-025/#comment-26460</guid>
					<description>[...] [This a guest post by Cigital&#8217;s Troy Jones, written in reference to episode 25 of The Silver Bullet Security Podcast, an interview with Jon Swartz.] [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] [This a guest post by Cigital&#8217;s Troy Jones, written in reference to episode 25 of The Silver Bullet Security Podcast, an interview with Jon Swartz.] [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: gem</title>
		<link>http://www.cigital.com/silverbullet/show-025/#comment-25248</link>
		<pubDate>Fri, 18 Apr 2008 21:10:50 +0000</pubDate>
		<guid>http://www.cigital.com/silverbullet/show-025/#comment-25248</guid>
					<description>Hi listeners,

Sorry about the sound quality on this episode.  We used a new laptop that apparently has a really awful sound card.  Too late to fix that problem, but rest assured that it won't happen again!

Regardless of sound quality, this episode is a good one I think.

gem</description>
		<content:encoded><![CDATA[<p>Hi listeners,</p>
<p>Sorry about the sound quality on this episode.  We used a new laptop that apparently has a really awful sound card.  Too late to fix that problem, but rest assured that it won&#8217;t happen again!</p>
<p>Regardless of sound quality, this episode is a good one I think.</p>
<p>gem
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
