Security needs to become a way of life in application development, Microsoft's Michael Howard says. In this Q&A he explains how you need to use tools and educate people to make sure your applications aren't weak links.
Do you have a sense of where developers are in their original natural state in terms of security?
Michael Howard: There are two major buckets on the whole. On the whole, developers in the industry need a bit of help. The actual level of security expertise in the marketplace is abysmally low. I was talking with some academics recently about this -- we were hiring really bright people out of school, and basically they don't know how to build secure software. And it's really scary. With that said, we recognise that's why we have the SDL [Security Development Lifecycle] process. It is really an education. We have to fill that gap.