Robert Hurlbut's Blog

Thoughts on .NET, Security, Architecture, Agility, and Databases.

Syndication

.Company / Other Sites / Other Blogs

.NET Links

.NET Local Boston Events

.NET User Groups in New England

Blogs - .NET

Blogs - Agile

Blogs - Architecture

Blogs - CLR

Blogs - Security

Blogs - SQL Server

Blogs - System.Transactions

Enterprise Services (COM+) Resources

Indigo Resources

Microsoft Security Resources

Presentation resources

Recommended Books

Rotor Resources

Security Resources

MAD Security Code Camp recap

I got in from the Washington, DC area yesterday afternoon after a very successful Mid-Atlantic (MAD) Security Code Camp conference held on Saturday, October 29, at the Microsoft offices in Reston, VA. I don't know what the total count was (my guess between 100 and 150 people), but it was great to see so many interested in writing secure applications. I took my older boys (15 and 13) with me to try to catch some of the sights. We didn't see as much as I had hoped in the short time, but I was glad they could see me presenting/teaching again as the last time was about 6-7 years ago.

I thought my talks went well, and there lots of queat questions. I enjoyed catching up with former Boston-area friends like Aaron Weiker, as well as several others I know in the area: G. Andrew DuthieScott Allen, Darrell Norton (it was great to finally meet after all this time!), and Sahil Malik. Speaking of Andrew, he and his dedicated staff of track chairs and volunteers put on an excellent conference -- things just worked, even when there were problems, everyone reacted quickly and efficiently.

The Code Camp site has my earlier slides here, but I have also posted the latest versions on my site as well.

Update: Here is a review of Saturday (and one of my talks) by Rob Garrett. One session I regretted missing (as it was the same time as mine) was Randy Hayes' session on running and developing as non-administrator, something I have also been doing for quite some time. According to Rob's review, it looks like there is one more convert!

Published Monday, October 31, 2005 12:23 PM by RHurlbut
Filed under: , , ,

Comments

# Threat Tree Patterns?@ Monday, October 31, 2005 2:07 PM

Thanks very much for the great talk. Threat modeling is something I'm evangelizing as much as possible - but with very little success as many of my ISVs just don't have the resources (they don't have the resources to properly test either!)
You mentioned in your talk that the PAG folks or someone had posted some starter threat tree patterns - which would be really great as a starting point for some of my companies.
Would you happen to have a link?

Thanks very much

# re: MAD Security Code Camp recap@ Monday, October 31, 2005 2:17 PM

Thanks for the comment, Andrew. It was great meeting another reader of my blog.

I looked in a couple of places, but rather than give links yet, let me do some follow-up work first to verify and get back to you.

# re: MAD Security Code Camp recap@ Monday, November 07, 2005 8:56 AM

Great to finally meet you Robert. Hope everything continues to go well!

by Darrell

# Security Development Lifecycle book and Threat Tree Patterns@ Friday, June 16, 2006 10:52 AM

I bought Michael Howard's and Steve Lipner's book The Security Development Lifecycle here at TechEd 2006...