|
Security in QA is more than just exploits |
|
|
|
|
Written by Paco Hope
|
|
Wednesday, 04 February 2009 14:47 |
|
I read a blog entry about "re-aligning training expectations for QA." It has some useful points that both developers and so-called "security people" need to hear. I disagree with some implicit biases, however, and I think we need to get past some stereotypes that sneak out in the article.
Bias #1, obviously, is the focus on the web. Despite its omnipresence, there is more non-web software than web software in the world, and non-web software does more important stuff than all the web software combined. The role of security in software testing is vital, and the presence or absence of web technologies does not change that. Despite writing my recent book on Web Security Testing, I know my place in the universe. Quality assurance and software testing are disciplines far older than the web, and their mission is so much bigger than finding vulnerabilities. |
|
Last Updated on Wednesday, 04 February 2009 14:48 |
|
Read more...
|