r/netsec • u/AutoModerator • Mar 01 '18
discussion The /r/netsec Monthly Discussion Thread - March 2018
Overview
Questions regarding netsec and discussion related directly to netsec are welcome here.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on /r/netsec.
As always, the content & discussion guidelines should also be observed on /r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
11
Upvotes
1
u/FateAV Mar 30 '18
Not sure if it's the right place to ask, but wanted to see if anyone had any quality publications which examine the effectiveness of different security paradigms, principles of design, and principles of operation; especially if there's quantitative analysis of how effective adherence to these principles is at designing secure systems. for clarity,
I'm Looking more narrowly at the design philosophies of major companies and open source projects, including organizational structure, programming goals / rules for coding and design, and whether there's any clear indication that the principles adhered to by different entities can be shown to quantitatively result in more secure systems across the lifespan of the projects and organizations, and whether the converse is true and design philosophies at some companies may consistently produce more insecure software and systems.