Welcome to the reborn developerWorks Security zone! Over the coming weeks,
you will witness how we are bulking up this area with regular installments
of our "Make your software behave" column, fresh feature articles,
reader-participation polls, Ask the Expert sessions, tutorials, white
papers, and a variety of additional content and feedback mechanisms
designed to inform and build the developer community.
In the Internet and e-commerce era more than ever, developers are creating
software that has mission-critical ramifications for security. Wherever
your code runs (desktop computer, handheld device, or server), it almost
certainly will reside in a network- or Internet-enabled environment. This
means your applications will likely be accepting data from unknown sources
that can compromise your software, data security, and your company's or
your clients' business operations and even financial bottom line.
Furthermore, in today's global economy, you may be dealing with unknown
customers in far-flung geographical regions where the environment is not
only uncertain, but unsafe, since individuals may attempt to gain
unauthorized access, collect confidential data, or otherwise compromise the
integrity of your software. Now is also the time to consider wireless
networks, mobile code, distributed software, and component-based software,
where security becomes not only more critical, but more challenging than
ever as well.
To help you compete and succeed in our network-enabled world,
developerWorks offers in its Security zone the information, techniques,
tutorials, and tools you need to grasp the risks, and techniques, so that
you can develop secure software.
Until late last year, developerWorks relied on the IBM Security site for
its Security zone content. This included some good material, but it lacked
the breadth and focus that developers need from a comprehensive security
site. With our new, dedicated Security zone, we're moving fast to increase
and improve the resources that developers seek.
We cover a wide range of security issues, technologies, and products that
extends beyond IBM's technologies, products, and services to all of the
developer industry. Yet rather than produce a catch-basin for general
security information, our attention is on the material that developers can
leverage in order to build more secure software.
This renewed developer-specific focus distinguishes developerWorks from
other Web sites and publications dedicated to security, and effectively
addresses a great void. Instead of attempting to cover all security-related
news and information, the Security zone (like all developerWorks zones)
presents what developers care about most. Not end-user virus scanners, not
administrator tips, but concrete guidance from security authorities
designed to help you build safe code from the ground up.
Anchoring our updated Security zone is the weekly column, "Make your
software behave," co-authored by noted security expert Gary McGraw and
senior researcher John Viega. We also stock the zone with feature
articles by experts who describe how to develop secure business
applications for e-commerce and how open source affects your code's security.
Like all developerWorks zones, we sift all the news services to provide you
with a daily news feed, too. Everything you find here is intended to help
you develop software that will withstand the toughest threats to security.
This is only the beginning. Much more is in the works: forums, tools,
example code, tips, tutorials, and other content focused on key software
security issues, such as the following:
- Avoid the common programming error that leads to 80% of all security breaches
- Take advantage of a programming language's built-in features for security
- Use secure services libraries and APIs -- including crypto libraries
- Identify and employ good algorithms
- Assess the risks of mobile code (including Java applets and JavaScript)
- Write secure mobile agents in Java, Tcl, Python, and Ruby
- Run untrusted code safely
These are just some of the items developerWorks plans to publish in the
coming months, based on input from security experts we've consulted, as
well as feedback we continue to gather from the developer community. We
welcome your input! You can help us identify and prioritize the most
pressing issues facing security-conscious developers like you. If you have
wisdom to share, we'll work with you to get your idea or article published. Please take a moment to send us your wish lists, tips, and suggestions via the developerWorks idea form, accessible on the Security zone home page.
As ever, we look forward to helping you make your software more secure.
Steve Deyo
developerWorks Security zone editor
deyo@us.ibm.com
March 1, 2000