Testing in the Real World

In January 2002, Bill Gates sent mail to all employees at Microsoft announcing the Microsoft Trustworthy Computing initiative. Companywide security training was conducted shortly thereafter. The Visual Basic .NET team—including the test, development, user-education (documentation), program-management, and localization teams, along with the rest of the Visual Studio .NET and .NET Framework teams, set several weeks aside to conduct an extensive threat analysis, design, and code review. As presented in this chapter, the Visual Basic .NET test team in conjunction with the development team first assessed all possible inroads for attack by creating a blueprint of Visual Basic .NET and then creating a list of scenarios that ...

Get Security for Microsoft® Visual Basic® .NET now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.