Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


October 21, 2007

Bugged by Bugs!

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

My beef this week is software bugs. Specifically, security related software bugs. I am constantly amazed at how little attention some software companies give to security in their code. Recently, I witnessed one such company implementing their product for large customer. It rapidly became evident that this company had never put their code through any kind of security review. A security scan immediately showed the most basic sophomoric mistakes and flaws in their code. Now it would be one thing if this were shareware being given away on the Internet. But this was supposedly enterprise level software! So much for Homeland Security! You can have all the policies and firewalls in the world but go and put a shoddy insecure program running on your network and you can jeopardize the whole thing.

When are software companies going to start really giving a @#$ about security? I guess when the customer (and that means me and you and you) start demanding it. This means documented security evaluations by an objective third party, audits, SAS-70 reports and other assurances before the contract or purchase order is signed. Do your due diligence, people! Or you may be buying unexpected remediation costs, delays, and of course a security risk inside your network.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.





Search Fearless Security
 
Fearless Security
SEPTEMBER 2008
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30     
or

 Recently in Fearless Security
Defcon Buzzword Bingo

Last Comment
I looked at the defcon website and noticed all the contest and events along the top of the main page...
(3 Comments)
A Black Hat Glass Half Full

Last Comment
So, which is the one of their best security conference?...
(1 Comments)
BlackHat and the DNS Non-Event
Make a Comment
Gotcha CAPTCHA!
Make a Comment
Time for Data Backup to Enter the 21st Century
Make a Comment

More blogs about technology,
software, and Windows.

ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Interested in Email Encryption?
Read about the advantages of identity-based encryption in this free report.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing