Profile picture
mreavey @mreavey
, 7 tweets, 2 min read Read on Twitter
I thought I’d know all the stuff in this talk and just went to see @Lipner. But nope...Dr Lipner is still dropping new knowledge. #bhusa @SAFECode
If you’re not big enough to “do everything” this talk is for you. My key points:

1. Have a vuln response process, use it to learn, and fix more than just what’s reported.
2. Devs are accountable for writing secure code—don’t “test it in.”
3. Do RCAs
4. Track SDL in the mainstream bug tracking workflow you track other bugs in.
5. Have a bug bar — exploitability matters.
6. Secure your 3rd party code. If you ship it, it’s your problem.
7. Do the “free” stuff—use secure libraries, set secure compiler flags, ban unsafe api’s, etc.
8. Inform and motivate your developer population. (Context is powerful)
9. Then you can train—the more targeted to your environment the better.
10. Build security into design—or it’ll be expensive or maybe impossible to fix quickly. Threat Modeling is your friend.
11. Don’t roll your own security features if security isn’t your core biz.
The platform can be your friend.
12. Minimize your attack surface.
And after all that — *now* you can start worrying about code level vulns proactively. But so much goodness to be had before this. And even here, lots of free tools exist to help.

So the good Dr just shared at least dozen ways that SDL, indeed, doesn’t have to break the bank.
Oh—and as a final point: A bug bounty is a *great* compliment to / component of SDL and sec response. But not a replacement. Buying your way out of insecurity bug-by-bug will probably break the bank.
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to mreavey
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member and get exclusive features!

Premium member ($3.00/month or $30.00/year)

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!