<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Show 030 &#8211; An Interview with Ken van Wyk</title>
	<atom:link href="http://www.cigital.com/silverbullet/show-030/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/silverbullet/show-030/</link>
	<description>In-depth conversations with leading security gurus, hosted by Gary McGraw, sponsored by IEEE Security &#38; Privacy Magazine.</description>
	<lastBuildDate>Thu, 28 Jan 2010 16:25:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: gem</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33821</link>
		<dc:creator>gem</dc:creator>
		<pubDate>Thu, 02 Oct 2008 19:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33821</guid>
		<description>Hi Stephen,

SANS is also taking a swipe at certifying developers.  I am skeptical of these approaches.  I wrote about this back in a darkreading column you can find here, entitled &quot;Certifiable&quot;:

http://www.darkreading.com/document.asp?doc_id=123606

When I get some time I will take a look at the CSSLP more closely.

gem</description>
		<content:encoded><![CDATA[<p>Hi Stephen,</p>
<p>SANS is also taking a swipe at certifying developers.  I am skeptical of these approaches.  I wrote about this back in a darkreading column you can find here, entitled &#8220;Certifiable&#8221;:</p>
<p><a href="http://www.darkreading.com/document.asp?doc_id=123606" rel="nofollow">http://www.darkreading.com/document.asp?doc_id=123606</a></p>
<p>When I get some time I will take a look at the CSSLP more closely.</p>
<p>gem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Evans</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33816</link>
		<dc:creator>Stephen Evans</dc:creator>
		<pubDate>Thu, 02 Oct 2008 17:25:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33816</guid>
		<description>Hi Gary,

Addressing your response at #2...

Since ISC2 has just announced their new certification, Certified Secure Software Lifecycle Professional (CSSLP), and have been seeking out collaboration informally with OWASP, I think this is a particularly relevant topic. As my #1 software security guy, I want to hear from you what you think about it.

Sounds like an article to me :-)

Cheers,
Stephen</description>
		<content:encoded><![CDATA[<p>Hi Gary,</p>
<p>Addressing your response at #2&#8230;</p>
<p>Since ISC2 has just announced their new certification, Certified Secure Software Lifecycle Professional (CSSLP), and have been seeking out collaboration informally with OWASP, I think this is a particularly relevant topic. As my #1 software security guy, I want to hear from you what you think about it.</p>
<p>Sounds like an article to me <img src='http://www.cigital.com/silverbullet/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Cheers,<br />
Stephen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Evans</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33796</link>
		<dc:creator>Stephen Evans</dc:creator>
		<pubDate>Thu, 02 Oct 2008 06:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33796</guid>
		<description>Thanks, Ken, for that response; looks like I mistakenly judged based on too small a sample. And I promise that I&#039;ll have fewer beers inside of me when I post again :-)

Stephen</description>
		<content:encoded><![CDATA[<p>Thanks, Ken, for that response; looks like I mistakenly judged based on too small a sample. And I promise that I&#8217;ll have fewer beers inside of me when I post again <img src='http://www.cigital.com/silverbullet/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Stephen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gem</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33777</link>
		<dc:creator>gem</dc:creator>
		<pubDate>Wed, 01 Oct 2008 19:13:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33777</guid>
		<description>Thanks Ken.  I, for one, really enjoy sc-l.  To me it feels like home for software security.  For those of you who have not subscribed, see the link up there under the podcast in the links section.

gem</description>
		<content:encoded><![CDATA[<p>Thanks Ken.  I, for one, really enjoy sc-l.  To me it feels like home for software security.  For those of you who have not subscribed, see the link up there under the podcast in the links section.</p>
<p>gem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KRvW</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33770</link>
		<dc:creator>KRvW</dc:creator>
		<pubDate>Wed, 01 Oct 2008 12:52:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33770</guid>
		<description>Hi Stephen (and Gary),

Thanks for the kind words all.

As for the SC-L comment, I&#039;m more than surprised you would feel that way. Most often, I&#039;m accused of not being heavy-handed enough on the list, and giving people far too much leeway in straying from topic.

It&#039;s true, I have stopped a couple of threads that strayed (IMHO) too far, but in every case, I did so by saying something like &quot;let&#039;s please let this thread die.&quot;  Even that was in no way an edict, and I always try to give people plenty of freedom to say what they please -- so long as it stays within the published charter.  (The primary rule there is civility; I will mercilessly crush flame wars and gladly be reprimanded for that.)

So, I&#039;d certainly invite you and anyone else who may feel as you do to &quot;come back&quot; and feel free to post.  If you feel you&#039;ve been wronged, then bring it to my attention. I am always open minded and willing to hear your case.  On that you have my personal guarantee.

Cheers,

Ken van Wyk</description>
		<content:encoded><![CDATA[<p>Hi Stephen (and Gary),</p>
<p>Thanks for the kind words all.</p>
<p>As for the SC-L comment, I&#8217;m more than surprised you would feel that way. Most often, I&#8217;m accused of not being heavy-handed enough on the list, and giving people far too much leeway in straying from topic.</p>
<p>It&#8217;s true, I have stopped a couple of threads that strayed (IMHO) too far, but in every case, I did so by saying something like &#8220;let&#8217;s please let this thread die.&#8221;  Even that was in no way an edict, and I always try to give people plenty of freedom to say what they please &#8212; so long as it stays within the published charter.  (The primary rule there is civility; I will mercilessly crush flame wars and gladly be reprimanded for that.)</p>
<p>So, I&#8217;d certainly invite you and anyone else who may feel as you do to &#8220;come back&#8221; and feel free to post.  If you feel you&#8217;ve been wronged, then bring it to my attention. I am always open minded and willing to hear your case.  On that you have my personal guarantee.</p>
<p>Cheers,</p>
<p>Ken van Wyk</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gem</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33762</link>
		<dc:creator>gem</dc:creator>
		<pubDate>Tue, 30 Sep 2008 17:01:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33762</guid>
		<description>Hi Stephen,

Thanks.  It&#039;s always enjoyable to chat with people as knowledgeable as Ken.  I told him about your posting, so hopefully he can address the sc-l thing here.

There is a brief mention of the overfocus on Web apps in mh informIT article below.  Perhaps I should write about that as a complete topic!

http://www.informit.com/articles/article.aspx?p=1237978

You can also find some discussion about that in &quot;Software Security&quot; http://www.swsec.com on pages 20-23.

For the record, we must focus some attention on securing Web apps...just not ALL of our attention.

gem</description>
		<content:encoded><![CDATA[<p>Hi Stephen,</p>
<p>Thanks.  It&#8217;s always enjoyable to chat with people as knowledgeable as Ken.  I told him about your posting, so hopefully he can address the sc-l thing here.</p>
<p>There is a brief mention of the overfocus on Web apps in mh informIT article below.  Perhaps I should write about that as a complete topic!</p>
<p><a href="http://www.informit.com/articles/article.aspx?p=1237978" rel="nofollow">http://www.informit.com/articles/article.aspx?p=1237978</a></p>
<p>You can also find some discussion about that in &#8220;Software Security&#8221; <a href="http://www.swsec.com" rel="nofollow">http://www.swsec.com</a> on pages 20-23.</p>
<p>For the record, we must focus some attention on securing Web apps&#8230;just not ALL of our attention.</p>
<p>gem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Evans</title>
		<link>http://www.cigital.com/silverbullet/show-030/comment-page-1/#comment-33756</link>
		<dc:creator>Stephen Evans</dc:creator>
		<pubDate>Tue, 30 Sep 2008 05:09:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/#comment-33756</guid>
		<description>Hi Gary,

Another home run; great questions and answers, plus a dose of software security history is always a bonus. Great insight from him about monitoring at the application level.

A couple of comments:
- Ken said his SC-L list was stagnant. I subscribed to it not long ago and found he was too heavy-handed as a moderator (certainly he is not unique!!!), jumping in too quickly to declare a thread off-topic. So I stopped posting and reverted to lurking.

- Is there an article where you have expounded on your misgivings about focusing too much on Web application security? On one recent podcast you touched on it (after you went to Europe and spoke at an OWASP Conference) and you asked Mr. van Wyk a question about it (at 17m44s), so I know it&#039;s bugging you a bit :-) As he stated, and from my previous work on both thick client &amp; web apps, session management is the main area absent from the former... I am genuinely interested in learning what your opinion and thoughts are on this. 

Stephen</description>
		<content:encoded><![CDATA[<p>Hi Gary,</p>
<p>Another home run; great questions and answers, plus a dose of software security history is always a bonus. Great insight from him about monitoring at the application level.</p>
<p>A couple of comments:<br />
- Ken said his SC-L list was stagnant. I subscribed to it not long ago and found he was too heavy-handed as a moderator (certainly he is not unique!!!), jumping in too quickly to declare a thread off-topic. So I stopped posting and reverted to lurking.</p>
<p>- Is there an article where you have expounded on your misgivings about focusing too much on Web application security? On one recent podcast you touched on it (after you went to Europe and spoke at an OWASP Conference) and you asked Mr. van Wyk a question about it (at 17m44s), so I know it&#8217;s bugging you a bit <img src='http://www.cigital.com/silverbullet/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  As he stated, and from my previous work on both thick client &amp; web apps, session management is the main area absent from the former&#8230; I am genuinely interested in learning what your opinion and thoughts are on this. </p>
<p>Stephen</p>
]]></content:encoded>
	</item>
</channel>
</rss>
