Re: Security SIG: Roundtable discussion: Building secure web applications

From: John Ingham <jeingham_at_berkeley.edu>
Date: Sat Jan 28 2006 - 02:45:45 PST

Spanked by the best!

As far as this evolution went I guess I am one who needed a little more
notice. I blow off many SIG meetings that I would like to go to but for my
work load. I this case I truly felt a need to be there but for an
obligation I planned just a few weeks ago. I was not happy.

As far as web application security goes spending three years with Mr. Ives
as our resident security wonk I have reasonable level of confidence my
bases are covered. Having said that, hearing other perspectives in a round
table environment would have been a good thing indeed.

Any one posting notes on the discussion? That would be helpful.

John

  At 01:47 PM 1/26/2006, you wrote:
>John Ingham wrote:
>>For such an important topic, I my opinion, a weeks notice is not really
>>enough notice either.
>>It is a great idea just poorly promulgated that is all.
>
>I have to respectfully disagree. It takes a lot of work to coordinate
>these types of meetings, especially roundtables with lots of busy
>people. While in an ideal world, I would aim for somewhat longer
>notice--with reminders, since it's easy to forget if notice is given too
>far in advance and you don't immediately enter it on your calagenda--I
>would certainly not call this "poorly promulgated." In fact, with all of
>the crossposting and reminders, I felt pretty "beaten over the head"
>regarding this meeting. (That's not a bad thing, mind you.)
>
>michael
>
>>At 09:28 AM 1/26/2006, you wrote:
>>>John- this was also announced in an email last Friday to both the
>>>micronet and ucb_security mailing lists. The topic and speakers were
>>>confirmed late last week.
>>>
>>>Chris
>>>
>>>At 09:16 PM 1/26/2006 -0800, you wrote:
>>>
>>>>I am just hearing of this today, with over thirty web applications up
>>>>and running I am indeed interested.
>>>>
>>>>In the future please promulgate more widely and earlier.Two days notice
>>>>is just not enough time.
>>>>
>>>>I hope that you do it again and that you include campus folks with DB
>>>>security savvy as well.
>>>>
>>>>
>>>>At 03:34 PM 1/24/2006, you wrote:
>>>>>The following new items have been published on UC Berkeley iNews: Top
>>>>>stories:
>>>>>
>>>>>Security SIG: Roundtable discussion: Building secure web applications
>>>>>http://securitysig.berkeley.edu/calendar.html
>>>>>Representatives from a number of campus departments will discuss
>>>>>challenges and approaches to building secure web applications. This
>>>>>meeting is organized and moderated by Campus Information Systems
>>>>>Security Officer Craig Lant. Confirmed panelists include Michael
>>>>>Leefers of IST-CCS, Rob McNicholas of EECS, Ryan Means of Boalt Hall
>>>>>School of Law, Kate Riley of IST-ASD, and Mohammed Shamma of Haas
>>>>>School of Business. Thursday, January 26, 10:45 am to 12:15 pm, 150
>>>>>University Hall.
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>================================================================
>>>>>UC Berkeley iNews (http://inews.berkeley.edu:7077/) is a service of
>>>>>IST Public Information (avante@berkeley.edu). To unsubscribe, send
>>>>>email to majordomo@listlink.berkeley.edu with the following line in
>>>>>the body of the message:
>>>>>
>>>>>unsubscribe istnewslist [your-complete-email-address]
>>>>
>>>>-----------------------------------------------------------------------
>>>>The following was automatically added to this message by the list server:
>>>>
>>>>Webnet information is available at http://webnet.berkeley.edu. Email
>>>>sent to this list is archived at http://ls.berkeley.edu/mail/webnet/ .
>>>>This archive is open to the general public and browsable by search
>>>>engine spiders, email-address harvesting robots, your bosses, etc.
>>>
>>>================================================
>>>Chris Ashley, Information Technology Policy Analyst
>>>Information Systems & Technology, UC Berkeley
>>>(510-) 643-2318 http://itpolicy.berkeley.edu
>>
>>------------------------------------------------------------------------
>>The following was automatically added to this message by the list server:
>>For information about Micronet, including subscribing to
>>or unsubscribing from its mailing list and finding out
>>about upcoming meetings, please visit the Micronet Web site:
>><http://micronet.berkeley.edu/>.
>
>
>------------------------------------------------------------------------
>The following was automatically added to this message by the list server:
>
>For information about Micronet, including subscribing to
>or unsubscribing from its mailing list and finding out
>about upcoming meetings, please visit the Micronet Web site:
><http://micronet.berkeley.edu/>.

-----------------------------------------------------------------------
The following was automatically added to this message by the list server:

Webnet information is available at http://webnet.berkeley.edu. Email sent to this list is archived at http://ls.berkeley.edu/mail/webnet/ . This archive is open to the general public and browsable by search engine spiders, email-address harvesting robots, your bosses, etc.
Received on Fri Jan 27 14:49:10 2006

This archive was generated by hypermail 2.1.8 : Fri Jan 27 2006 - 14:49:10 PST