Secure Coding mailing list archives

Economics of Software Vulnerabilities


From: coley at linus.mitre.org (Steven M. Christey)
Date: Wed, 21 Mar 2007 17:47:19 -0400 (EDT)


On Wed, 21 Mar 2007, mudge wrote:

Sorry, but I couldn't help but be reminded of an old L0pht topic that
we brought up in January of 1999. Having just re-read it I found it
still relatively poignant: Cyberspace Underwriters Laboratories[1].

I was thinking about this, too, I should have remembered it in earlier
comments.  The fact that such a thing has NOT come to fruition seems to be
symptomatic of the industry, although there have been some partnerships
between commercial and non-commercial entities (e.g. Fortify and the Java
Open Review).

- Steve


Current thread: