Tuesday, January 24, 2006

Apples & Bounties?

I'm sure this will be all over the blogosphere, but there's a guy who stuck his neck out on the line (and put his money where his mouth is) to try to get Windows XP to dual boot on his newly purchased MacBook laptop. You know, Apple's new Intel-based laptop.

He basically told his boss to buy him one, and not to worry because it would run all his Company's windows stuff fine. HEHEHE. So basically, he offered a bounty of $100 to anyone who could make it happen.

Needless to say, he's also accepting donations for the bounty fund, since $100 isn't likely to motivate many hackers, but the fund's up to around $3,300 as of this writing. I've donated $25 bucks, and thought you readers might be interested in contributing to the cause.

I know, I know - I work at Dell, and I'm contributing to this? It's one of my dark secrets - I'm a Mac wannabe, I guess. I like the design of Macs and have been an Apple fan since I first started programming on the Apple ]['s WAAAY back in the day.

So, donate to the cause! It'll help buy some crazy hacker caffeine-loaded water, which they'll probably need if they're going to finish the project by the March deadline.

Monday, December 05, 2005

Great new book - "Writing Secure Code" by David C. LeBlanc and Michael Howard

"Writing Secure Code" by David C. LeBlanc and Michael Howard.
I just got my copy of "Writing Secure Code" by David C. LeBlanc and Michael Howard. 

So far, I'm only at the chapter on Threat Modelling, but it has proven to be quite an enlightning read.

I heard about it in a course I took in training called, aptly enough, Developing Secure Software. 


It's a required course for all developers and testers at Dell which is where I am currently employed. It was presented in a lab format by a representative from St. Edwards University's Professional Education Center

The thing that really pulled me into the class was that it covered development of web apps, C/S database apps, and code in both C# and Java.
They walked us through both the apps in question, the techniques used to compromise said apps, and even the code / technical solutions to the vulnerabilities. Definitely the coolest training I've been able to attend to date here.

If you write and/or test code, even in non-Microsoft environments, you should check out this book. I got my copy on amazon for $7.95, so it's not even a particularly expensive learning tool. Don't you just LOVE a good sale ;) ?

There's a Kindle Edition, and a Paperback available.  Links to purchase them from Amazon included for your convenience.