Posted Thursday 29th May 2008 15:03 GMT
Security testing?
"Using test-driven development is excellent for security. By defining a suite of security test cases before development starts, the team is much more likely to include the right controls and use them properly."
Great concept in theory, but really hard to implement in practice: how to develop "negative" tests needed in security? Can you really test that your code is not exploitable?
Of course, you can implement obvious tests, like "if you enter a wrong username/password the access is denied" or even some elementary tests against XSS and SQL Injection, but how to test crypto-strength, session management, denial of service, race conditions, just to name a few?
Opinion
David McLeman
My 25 years of comical IT buzzwords
Tim Worstall
Time to take a sniff at the coffee, perhaps
Chris Mellor
Will they have to drag him back like last time?
Popular Stories
Features
Playing the SLA long game
More than just middlemen...
Applications must work for the cloud to float
How a Unix killer crawled from the dot-com bust