3 ms·
I'm a bit disappointed that something called the "state of software security" seems to exclusively focus on scan results. That's the cool, flashy, automatable
by mac-chaffee 5y ago
I'm a bit disappointed that something called the "state of software security" seems to exclusively focus on scan results.
That's the cool, flashy, automatable part of security. But IMO the boring, manual parts (operational security, security training, etc.) are too often ignored.
- Kalium 5y agoOn the one hand, I'm also somewhat disappointed. On the other hand, Veracode's central product is a scanner. I cannot even begin to imagine how to consistently evaluate the boring, manual, operational parts of a security program in the context of open source libraries. How does one assess the security training and operations of a library developed and maintained by three people?
- belter 5y agoAgree. Security is a process. I mean its good on what it decided to focus on :-)