Archive for March, 2012

Reference – Security Bug Assessment Model – STRIDE

Saturday, March 24th, 2012

Before the current focus on security at Microsoft, all security bugs at Microsoft were rated using the DREAD model. (See prior post). Now, Microsoft rates each security bug using the STRIDE model. STRIDE is an acronym that stands for:

  • Spoofing
  • Tampering
  • Repudiation
  • Information Discovery
  • Denial of Service (DoS)
  • Elevation of Privilege (EoP)

 

Video Notes – Robert Johnson interviewed at Velocity 2010

Monday, March 19th, 2012

Robert Johnson interviewed at Velocity 2010
Robert Johnson, Director of Engineering, Facebook
2010 O’REILLY Velocity – Web Performance and Operations Conference
June 22 – 24, 2010
7 min, 4 sec
http://www.youtube.com/watch?v=wXTCPnuDGbg

My Notes:

  • User expectations of mobile in terms of optimization
    • Very little data to answer scientifically
    • Long term need desktop and mobile site performance to come together
  • Need to collect the data before setting benchmarks
  • Acceleration and Business Benefits Research
    • Huge payback for performance improvement
  • Initial thing that a company should do
    • Set benchmarch and understand how user sees the site
    • Keep alives on
    • Compression on
  • Workshop
    • Analyzed Velocity home page
    • Made worse than reality and brought it to current then improved

 

 

Reference – Security Bug Assessment Model – DREAD

Saturday, March 10th, 2012

Before the current focus on security at Microsoft, all security bugs at Microsoft were rated using the DREAD model. DREAD is an acronym stands for:

  • Damage Potential
  • Reproducibility
  • Exploitability
  • Affected Users
  • Discoverability

When a bug was filed, the bug would be rated from 1-10 in each of these areas.

 

February 2012 mensming Twitter Posts

Monday, March 5th, 2012

Follow mensming on Twitter

Posted to testingpodcast.com – Sofware Testing Podcast Episode 18 – http://bit.ly/xqWB4T
28 Feb

Posted to testingpodcast.com – TWiST #84 – Getting Hired, Part III – bit.ly/zWZ9LH
27 Feb

Posted to testingpodcast.com – Software Testing Podcast Episode 17 – bit.ly/yu8d5n
26 Feb

Every Bart Simpson Chalkboard Quote To Date | Geekologie – bit.ly/wHr8RX
24 Feb

INFOGRAPHIC: Why People Hate Their Jobs read.bi/whWbx3
23 Feb

Posted to testingpodcast.com – TWiST #83 – Getting Hired, Part II – bit.ly/x23AYC
22 Feb

Finished reading Eat That Frog!: 21 Great Ways to Stop Procrastinating and Get More Done in Less Time by Brian Tracy – amzn.to/AjCgOi
22 Feb

Internet Explorer Performance Lab – bit.ly/wuad9s
21 Feb

Five Leadership Mistakes Of The Galactic Empire – Forbes onforb.es/w24Rhi
20 Feb

RT @Conenza – Our debut blog post is an edgy one by @John_Schroeter ’7 Reasons for Rethinking Your Facebook Strategy’ bit.ly/yNZcBD
17 Feb

7 Deadly Sins of Automated Software Testing – Adrian Smith bit.ly/yW4wXG
16 Feb

The Staggering Cost Of A Bad Hire [Infographic] – aol.it/AnKzGG
15 Feb

Top ten reasons managers become a**holes – Scott Berkun bit.ly/yEX7Fv
14 Feb

Finished reading _SEO Made Simple_ by Michael H. Fleischner – amzn.to/z1fi0O
13 Feb

Post to testingpodcast.com – Mng Quality within Bdgt and Sched Constraints: Successful and Unsuccessful Techniques – bit.ly/znZtYn
11 Feb

Posted to testingpodcast.com – Twist #82 – Getting Hired, Part I – bit.ly/wo5GtU
10 Feb

Great site for discussing code with others remotely – nopaste.info
10 Feb

My favorite – avoid back scratch recommendations – How To Pimp Your LinkedIn Profile rww.to/wMpecn
9 Feb

Matt Stiles // The Daily Viz ยท FACEBOOK: Who uses it and what are they doing? bit.ly/yzwwvQ
8 Feb

Posted to testingpodcast.com – Software Test Podcast Episode 16 – bit.ly/xE8nL3
7 Feb

Finished reading _Mindfire: Big Ideas for Curious Minds_ by Scott Berkun – amzn.to/zjCBC1
7 Feb

Posted to testingpodcast.com – Software Testing Podcasts Episode 15 Part 2 – bit.ly/zYodpa
6 Feb

Just posted to testingpodcast.com – TWiST #81 – Virtualization, Part II – bit.ly/wBOTEK
6 Feb

Posted to testingpodcast.com – TWiST #80 – Virtualization, Part I – bit.ly/yaYCbV
5 Feb

My company – Conenza – is looking for a senior recruiter. Learn more about this position at talentservices.conenza.net/s/4I
4 Feb

Added to testingpodcast.com – Podcasts from softwaretestpodcast.com – bit.ly/y4LgTy
3 Feb

RT @microsoftalumni – In case you missed our 20 seconds of fame, watch the KIRO-TV video where MSA founder speaks about recent job cuts. kirotv.com/news/business/
2 Feb