Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-28 Thread Rohit Sethi
Hi Jacob, just as an FYI I messaged you last week about this off list - my email was from my first name @securitycompass.com. Just wanted to make sure you got it Thanks, Rohit On Feb 24, 6:55 am, Jacob Kaplan-Moss wrote: > Hi Rohit -- > > I had a skim of the document, too, and my feelings are p

Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-24 Thread Jacob Kaplan-Moss
Hi Rohit -- I had a skim of the document, too, and my feelings are pretty close to Russ's, so I won't bother with any specific feedback -- he basically speaks for me, too. To build off Russ, though, I have a bit of a meta meta-suggestion about OWASP in general. One huge problem I have as a softwa

Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-22 Thread Rohit Sethi
Gabriel, great idea! This is a problem with OWASP in general, but definitely we can do better on this doc. I think we'll first focus on putting our words in action with help in contributing some of the features into Django first, and then revisit the doc. Mainly I'd like to assess what pieces of it

Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-21 Thread Gabriel Hurley
I've got one bit of feedback to offer on the document (which I did bookmark for future reference): Monolithic documents present a huge problem for finding, using and retaining information. A very useful and interesting extension of this type of project would be to work with people who have experi

Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-21 Thread Rohit Sethi
Russell, awesome feedback. Thanks for being candid. We are on the same page that the manifesto is really not all that important in and of itself: The document piece is really only designed to give frameworks a platform to say "hey, these are what we support" so that web app developers building secu

Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-21 Thread Russell Keith-Magee
On Mon, Feb 21, 2011 at 11:21 PM, Rohit Sethi wrote: > Django devs, I wanted to thank you for a truly awesome framework. > Programming with Python, and web app dev in Django, is truly a > pleasure. Our company, Security Compass, uses Django quite > substantially internally. > > We put together a d

Re: Your thoughts on the Secure Web Application Framework Manifesto

2011-02-21 Thread Rohit Sethi
One more point - if any of you have questions for somebody who leaves and breathes web application security every day, please feel free to fire them off to me: rohit at securitycompass.com On Feb 21, 10:21 am, Rohit Sethi wrote: > Django devs, I wanted to thank you for a truly awesome framework

Your thoughts on the Secure Web Application Framework Manifesto

2011-02-21 Thread Rohit Sethi
Django devs, I wanted to thank you for a truly awesome framework. Programming with Python, and web app dev in Django, is truly a pleasure. Our company, Security Compass, uses Django quite substantially internally. We put together a document called the Secure Web Application Framework Manifesto for