
OWASP Statement on the Security of the Internet 2014
<i>Not making a statement can be a statement in i…
January 31, 201414m 14s
Audio is streamed directly from the publisher (feeds.soundcloud.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.
Show Notes
<i>Not making a statement can be a statement in its own right." -- Tobias Gondrom</i>
Earlier this week, <a href="https://www.owasp.org/index.php/OWASP_Statement_on_the_Security_of_the_Internet_2014">OWASP released a statement</a> after an internal debate regarding recent allegations that RSA had weakened its encryption while receiving $10 million dollars from the NSA. There was heated discussion about whether or not to publish a statement. Would it be perceived as political? What is OWASP's responsibility when it comes to defending the trustworthiness of software?
I spoke with Tobias Gondrom and Eoin Keary about that debate. Their premise is that this is not a political statement, but a clarification to keep OWASP focused on its original mission.