
Eric Sink is the founder of SourceGear, a software vendor in central Illinois. In 2003, SourceGear released Vault, a version control tool designed to be a replacement for SourceSafe. Nine years later, Vault continues to be a successful product in its niche. More recently, Eric has been focused on a next-generation project. Veracity is a Distributed Version Control System (like Git and Mercurial). It is open source (Apache License) and cross-platform (Windows, Mac, Linux). In 2011, Eric published a free book called Version Control by Example. VCBE is available online and free printed copies are available from SourceGear (until we run out).
Carl and Richard talk to Rob Labbe about the Security Development Lifecycle (SDL). After a quick detour down the SOPA discussion, Rob fills the boys in on how the SDL maps neatly to a regular development lifecycle, just including security every step of the way. Rob also introduces the tools of the SDL, providing support for every step of the development lifecycle, from requirements to design to implementation and verification.

Rob Labbé is a Senior Security Program Manager in Microsoft IT’s Information Security and Risk Management team. Rob has over 8 years’ experience working with internal and external application development teams, helping them develop high quality, secure line of business applications. He has extensive experience helping teams design and develop good application development processes and practices based upon Microsoft’s Security Development Lifecycle (SDL). Rob is currently working in the Infrastructure Security Services team, bringing a touch of developer sanity to the insane world of infrastructure security.
Links from the Show