<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Security training for embedded developers?</title>
	<link>http://ask.metafilter.com/113776/Security-training-for-embedded-developers/</link>
	<description>Comments on Ask MetaFilter post Security training for embedded developers?</description>
	<pubDate>Mon, 09 Feb 2009 11:34:35 -0800</pubDate>
	<lastBuildDate>Mon, 09 Feb 2009 11:34:35 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Security training for embedded developers?</title>
		<link>http://ask.metafilter.com/113776/Security-training-for-embedded-developers</link>	
		<description>What&apos;s a good security course for embedded developers? &lt;br /&gt;&lt;br /&gt; The folks at the top say we need &quot;security training&quot;. The server guys are taking a course in SQL injection, ASP.NET stuff, etc. I&apos;d rather get my embedded guys something more, well, embedded-specific. I&apos;m thinking a refresher on basics of cryptography, network security, specific protocols, etc. and maybe some &quot;code practices greatest hits&quot;. A short two-day course is the target. Does anyone have a recommendation for either online/onsite training that might fit the bill?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2009:site.113776</guid>
		<pubDate>Mon, 09 Feb 2009 11:04:35 -0800</pubDate>
		<dc:creator>RobotVoodooPower</dc:creator>
		
			<category>embedded</category>
		
			<category>security</category>
		
			<category>training</category>
		
			<category>resolved</category>
		
	</item> <item>
		<title>By: pdxpatzer</title>
		<link>http://ask.metafilter.com/113776/Security-training-for-embedded-developers#1634166</link>	
		<description>Read &lt;em&gt;&lt;a href=&quot;http://www.amazon.com/exec/obidos/ASIN/0470068523/metafilter-20/ref=nosim/&quot;&gt;Security Engineering: A Guide to Building Dependable Distributed Systems&lt;/a&gt;&lt;/em&gt;, 2nd Edition.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.113776-1634166</guid>
		<pubDate>Mon, 09 Feb 2009 11:34:35 -0800</pubDate>
		<dc:creator>pdxpatzer</dc:creator>
	</item><item>
		<title>By: doteatop</title>
		<link>http://ask.metafilter.com/113776/Security-training-for-embedded-developers#1634171</link>	
		<description>What platforms do they develop for? Frequently with embedded software on phones or PDAs, for example, the manufacturer will offer platform-specific security training.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.113776-1634171</guid>
		<pubDate>Mon, 09 Feb 2009 11:36:21 -0800</pubDate>
		<dc:creator>doteatop</dc:creator>
	</item><item>
		<title>By: RobotVoodooPower</title>
		<link>http://ask.metafilter.com/113776/Security-training-for-embedded-developers#1634191</link>	
		<description>doteatop, we develop against Windows CE and Linux. I&apos;d like to remain platform-agnostic if possible, because my main goal is not to teach specific API behaviors but to satisfy the PHBs at my company while at the same time getting the developers excited about learning something new.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.113776-1634191</guid>
		<pubDate>Mon, 09 Feb 2009 12:01:14 -0800</pubDate>
		<dc:creator>RobotVoodooPower</dc:creator>
	</item><item>
		<title>By: doteatop</title>
		<link>http://ask.metafilter.com/113776/Security-training-for-embedded-developers#1634509</link>	
		<description>I can strongly recommend &lt;a href=&quot;http://www.fortify.com/&quot;&gt;Fortify&apos;s&lt;/a&gt; training, and &lt;a href=&quot;http://www.cigital.com/&quot;&gt;Cigital&lt;/a&gt; is highly spoken of as well.&lt;br&gt;
&lt;br&gt;
Your developers might also appreciate putting into place some form of automation to check for memory management bugs, etc, during the build. If you have flexibility in your spending, maybe you can check out some affordable static analysis tools or fuzzer suites, and look for training more specific to those. I personally love build automation and this would get me really excited (management never or rarely expresses interest in these kinds of solutions).&lt;br&gt;
&lt;br&gt;
For books, in addition to the above I can recommend:&lt;br&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.amazon.com/exec/obidos/ASIN/0321356705/metafilter-20/ref=nosim/&quot;&gt;http://www.amazon.com/Software-Security-Building-Addison-Wesley/dp/0321356705&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.amazon.com/exec/obidos/ASIN/0321356705/metafilter-20/ref=nosim/&quot;&gt;http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778M&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2009:site.113776-1634509</guid>
		<pubDate>Mon, 09 Feb 2009 14:51:20 -0800</pubDate>
		<dc:creator>doteatop</dc:creator>
	</item>
	</channel>
</rss>
