A place of Bile & other Humours.
BlogRoll
Bloglines Blogroll feed currently *broken*
Subscribe to
Posts [Atom]bloglines
Security is orthogonal to functionality. Security has nothing to with what the product does, or how well it does it, or how good the user interface is.
You can't give a product to a thousand random people, have them beta test it for a month and really learn anything about the security. They can tell you if it works and how functional it is, but they can't tell you if it's broken or not.
Generally, to test security, at least in the real world, you just put the product out there and experienced security professionals, either working for industry, or in academia, or working on their own (commonly known as hackers), find flaws and alert the New York Times and you get your feedback that way. Not terribly useful. But it's where we've ended up.B. Schneier, "Security in the Real World: How to Evaluate Security Technology," Computer Security Journal, v 15, n 4, 1999, pp. 1-14.
0 Comments:
Post a Comment
Back to Jonathan's Liverstone