A while ago a journalist asked me about “secure development lifecycles to code software.” This is what I sent back: First, you don’t code secure systems, you design them. All the important stuff takes place at a level of abstraction above that of coding. Once you have a design you have internalized both your problem [...]
