<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Thoughts on awareness of security vulnerabilities &amp; full disclosure</title>
	<atom:link href="http://damieng.com/blog/2007/12/20/thoughts-on-awareness-of-security-vulnerabilities-full-disclosure/feed" rel="self" type="application/rss+xml" />
	<link>http://damieng.com/blog/2007/12/20/thoughts-on-awareness-of-security-vulnerabilities-full-disclosure?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=thoughts-on-awareness-of-security-vulnerabilities-full-disclosure</link>
	<description>A .NET developer in silicon valley</description>
	<lastBuildDate>Sun, 25 Dec 2011 15:10:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: steve</title>
		<link>http://damieng.com/blog/2007/12/20/thoughts-on-awareness-of-security-vulnerabilities-full-disclosure#comment-5673</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Thu, 20 Dec 2007 11:29:59 +0000</pubDate>
		<guid isPermaLink="false">http://damieng.com/blog/2007/12/20/thoughts-on-awareness-of-security-vulnerabilities-full-disclosure#comment-5673</guid>
		<description>To be honest I find it quite incredible that this is still an item for debate - it&#039;s been a known issue for so long after all. But there are so many &#039;green&#039; developers out there making apps, and so many of them gravitate towards &#039;quick &amp; dirty&#039; techs like PHP and ASP without knowing what the hell they&#039;re doing, I guess it&#039;s no surprise. Security issues like this should be covered as standard in university courses really, it&#039;s so fundamental to modern development; even just having an awareness of it rather than a deep knowledge would help I&#039;m sure. 

It all adds fuel to the argument that the more experienced library / platform developers, particularly those aimed at entry-level people (which .Net is always pitching at, IMO, with all its wizards and create-me-an-app-now helpers) should assume that a significant number of developers using their tech will be totally clueless, and thus default to protecting them from themselves. Smart developers will always figure out how to do what they need to so any extra default behaviour won&#039;t bother them if they need to avoid it, but dumb developers will happily use whatever crappy code snippets and insecure libraries are available with impunity and create a whole new generation of problems.</description>
		<content:encoded><![CDATA[<p>To be honest I find it quite incredible that this is still an item for debate &#8211; it&#8217;s been a known issue for so long after all. But there are so many &#8216;green&#8217; developers out there making apps, and so many of them gravitate towards &#8216;quick &amp; dirty&#8217; techs like PHP and ASP without knowing what the hell they&#8217;re doing, I guess it&#8217;s no surprise. Security issues like this should be covered as standard in university courses really, it&#8217;s so fundamental to modern development; even just having an awareness of it rather than a deep knowledge would help I&#8217;m sure. </p>
<p>It all adds fuel to the argument that the more experienced library / platform developers, particularly those aimed at entry-level people (which .Net is always pitching at, IMO, with all its wizards and create-me-an-app-now helpers) should assume that a significant number of developers using their tech will be totally clueless, and thus default to protecting them from themselves. Smart developers will always figure out how to do what they need to so any extra default behaviour won&#8217;t bother them if they need to avoid it, but dumb developers will happily use whatever crappy code snippets and insecure libraries are available with impunity and create a whole new generation of problems.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

