Discount Book Store - Rbookshop.comOnline Book StoreBusiness BooksComputer BooksEngineering BooksMathematics BooksScience BooksView All Categoriesnavmap
arrow Search for books at ARC Spider:
arrow Search for books at Powells:
arrow
Buy a Book from Amazon.com
bar
How to buy? - A step-by-step guide

Book Categories


19 Deadly Sins of Software Security (Security One-off)

Buy 19 Deadly Sins of Software Security (Security One-off) here, one of many Active Server Pages books offered for sale at discount prices here at Rbookshop.com.  We greatly appreciate your patronage at Rbookshop and look forward to offering you great products and prices now and in the future.
You Are Here:  Home > Computer Books > Active Server Pages > Item 160

View Previous Product in our Active Server Pages Store      View Next Product in our Active Server Pages Store

Click here to buy 19 Deadly Sins of Software Security (Security One-off) by  Michael Howard, David LeBlanc, and John Viega. 19 Deadly Sins of Software Security (Security One-off)
by Michael Howard, David LeBlanc, and John Viega
Sales Rank: 121590
4.5 out of 5 stars
$27.71
At Amazon
on 8-31-2008.
Buy 19 Deadly Sins of Software Security (Security One-off) now! Get Info on 19 Deadly Sins of Software Security (Security One-off)
Features
  • Cover Type: Paperback with 304 pages
  • Published by: McGraw-Hill Osborne Media
  • Edition: 1st Edition July 26, 2005
  • Written in: English
  • ISBN 10 Number: 0072260858
  • ISBN 13 Number: 978-0072260854
  • Book Dimensions: 9.1 x 7.3 x 0.8 inches
  • Weighs: 1.1 pounds


Reader Reviews
I read six books on software security recently, namely "Writing Secure Code, 2nd Ed" by Michael Howard and David LeBlanc; "19 Deadly Sins of Software Security" by Michael Howard, David LeBlanc, and John Viega; "Software Security" by Gary McGraw; "The Security Development Lifecycle" by Michael Howard and Steve Lipner; "High-Assurance Design" by Cliff Berg; and "Security Patterns" by Markus Schumacher, et al. Each book takes a different approach to the software security problem, although the first two focus on coding bugs and flaws; the second two examine development processes; and the last two discuss practices or patterns for improved design and implementation. My favorite of the six is Gary McGraw's, thanks to his clear thinking and logical analysis. The other five are still noteworthy books. All six will contribute to the production of more security software. The main reason to read 19DS is to quickly become acquainted with various security problems facing software developers. At less than 300 pages, it's not a thick tome like WSC2E. 19DS also is not afraid to mix bugs (coding errors, like buffer overflow conditions) with flaws (design problems, like "failing to protect network traffic.") This sort of lax categorization bothers me (and Gary McGraw, as noted in his book "Software Security"), but it shouldn't interfere with the quality content of 19DS. Probably the most interesting aspect (to me) of 19DS was sin 10, which discussed problems with Secure Sockets Layer (SSL). The chapter didn't describe algorithmic or protocol problems. Instead, it explained how programmers make poor assumptions about the features provided by their language of choice with respect to SSL. For example, many SSL libraries do not properly validate certificates. Without this functionality, the authors argue that SSL is almost worthless. While I don't necessarily agree with this statement, I really like reading this sort of criticism. I'd like to note that p 134 berates Python's ssl() but ignores pyOpenSSL, which probably provides the features the authors would want. Other "sins" take slightly different looks at security issues. Sin 17, for example, explains the importance of key exchange AND authentication. These are the sorts of problems I imagine are only discovered by examining multiple real-world implementations, and I value the authors sharing their experiences. I subtracted one star because the quality of the "sins" isn't even. Some don't adequately explain the problem at hand (e.g., integer overflows). If the authors assume the reader knows the problem well enough to not introduce it properly, then why discuss it at all? Overall, however, 19DS is a great book to get to your developers. It's short enough that they might actually read it, and the content is presented in a convincing enough manner to perhaps influence their coding choices. Comment | | (Report this)


Back To Top

View Previous Product in our Active Server Pages Store      View Next Product in our Active Server Pages Store

19 Deadly Sins of Software Security (Security One-off)
List Price: $41.99
Available from Amazon
Price: $27.71
Updated on 8-31-2008.
Buy 19 Deadly Sins of Software Security (Security One-off) now! Get Info on 19 Deadly Sins of Software Security (Security One-off)




NOTICE: All prices, availability, and specifications
are subject to verification by their respective retailers.




We offer 19 Deadly Sins of Software Security (Security One-off) and other related Active Server Pages Books here at Rbookshop.com. To view more books about Active Server Pages please use the previous and next buttons near the top of this page.




Alternative Med Books | Art Books | Business Books | Comic Books | Computer Books | Cook Books | Engineering Books | History Books | Hobby Books | Law Books | Mathematics Books | Medical Books | Popular Authors | Rare Books | Religion Books | Romance Books | Science Books | Science Fiction Books | Sports Books | Travel Books | Unusual Subjects Books
Discount Book Store
Rbookshop

Copyright © 2008, dvddispatcher.com

121154 Computer Books Online and Available as of 8-31-2008.