Páginas

28 março 2009

Maré de Agilidade

Bem, pra quem não sabe, estou na Bahia, Salvadô... convidado para o evento Maré de Agilidade


Vim para falar sobre o conceito de Integração contínua.

O pessoal da organização do evento disponibilizou um blog com as informações. Confira! (Slides da minha apresentacao neste blog)

http://maredeagilidade.blogspot.com

até mais!

20 fevereiro 2009

Somos professionais de software?

Uncle Bob, sempre pragmático (e porque nao dizer, radical), se apresentou no JAOO com a seguinte palestra: Craftsmanship and Ethics.

O cara levanta uma bandeira muito interessante: não somos profissionais... somos apenas trabalhadores... e isso se deve pela falta de disciplina que NAO temos aos construir código. E ele faz muito bem o seu papel: evangelização (com uma inclinação meio maluca).


Veja o vídeo:Craftsmanship and Ethics

E então, ainda tocando os tambores?

19 fevereiro 2009

Capital de Risco para projeto Open Source

Dica super interessante!
Que tal criar um business plan de um projeto curto e opensource, e concorrer a uma grana?
Bem, essa é a ideia de Mark Cuban, que promete criar um modelo de investimento para projetos opensource.

Sua ideia consistem em receber projetos promissores (postados publicamente em seu blog) que esperam ter retorno rápido e consistente. Caso o cara goste, ele vai botar uma grana... e talvez encontrar mais participantes para o projeto.

Leia mais em: The Mark Cuban Stimulus Plan

Regras



1. It can be an existing business or a start up.
2. It can not be a business that generates any revenue from advertising. Why ? Because I want this to be a business where you sell something and get paid for it. Thats the only way to get and stay profitable in such a short period of time.
3. It MUST BE CASH FLOW BREAK EVEN within 60 daysÂ
4. It must be profitable within 90 days.
5. Funding will be on a monthly basis. If you dont make your numbers, the funding stops
6. You must demonstrate as part of your plan that you sell your product or service for more than what it costs you to produce, fully encumbered
7. Everyone must work. The organization is completely flat. There are no employees reporting to managers. There is the founder/owners and everyone else
8. You must post your business plan here, or you can post it on slideshare.com , scribd.com or google docs, all completely public for anyone to see and/or download
9. I make no promises that if your business is profitable, that I will invest more money. Once you get the initial funding you are on your own
10. I will make no promises that I will be available to offer help. If I want to , I will. If not, I wont.
11. If you do get money, it goes into a bank that I specify, and I have the ability to watch the funds flow and the opportunity to require that I cosign any outflows.
12. In your business plan , make sure to specify how much equity I will receive or how I will get a return on my money.
13. No mult-level marketing programs (added 2/10/09 1pm)


Alguma idéia?

[]s
Victor

10 fevereiro 2009

Succession na InfoqBrazil

Saudações...

Não sei ao certo se as pessoas que leêm este blog(ou liam - estou muito vagal ultimamente), leêm também o infoq Brazil...

O site gringo começou com uma discussão muito bacana sobre o último assunto de Kent Beck (veja a notícia em inglês).

Bem, repliquei a notícia no site brasileiro, e convido a todos para se juntarem à discussão:Veja a notícia

13 janeiro 2009

TOP 25 Most Dangerous Programming Errors

Saudações a todos!

Voltando de férias esta semana me deparei com um documento MUITO importante para a comunidade de software mundial, resultado do encontro de inúmeras empresas de segurança e autores conhecidos da área em Washington/DC, esta semana.

O encontro visou chegar a um consenso sobre quais seriam os principais erros cometidos no desenvolvimento de software e que possuem o maior impacto na segurança das aplicações web. Bem... a discussão não foi tão intensa, e foi relativamente fácil chegar ao número acima: Os Top 25 (sql injection, code injection, xss e muitos mais).

Bob Martin é o portavoz do documento, e apresenta sua versão sobre a criação. Segue uma pequena parte do texto de introdução:

(January 12, 2009) Today in Washington, DC, experts from more than 30 US and international cyber security organizations jointly released the consensus list of the 25 most dangerous programming errors that lead to security bugs and that enable cyber espionage and cyber crime. Shockingly, most of these errors are not well understood by programmers; their avoidance is not widely taught by computer science programs; and their presence is frequently not tested by organizations developing software for sale.

Leia o Documento Completo


De forma bem humorada, o catálago apresenta a descrição dos erros e como utilizar patterns para mitigar tais riscos. Confira em: http://cwe.mitre.org/top25/


Para constar, os envolvidos:

Robert C. Seacord, CERT
Pascal Meunier, CERIAS, Purdue University
Matt Bishop, University of California, Davis
Kenneth van Wyk, KRvW Associates
Masato Terada, Information-Technology Promotion Agency (IPA), (Japan)
Sean Barnum, Cigital, Inc.
Mahesh Saptarshi and Cassio Goldschmidt, Symantec Corporation
Adam Hahn, MITRE
Jeff Williams, Aspect Security
Carsten Eiram, Secunia
Josh Drake, iDefense Labs at VeriSign, Inc.
Chuck Willis, MANDIANT
Michael Howard, Microsoft
Bruce Lowenthal, Oracle Corporation
Mark J. Cox, Red Hat Inc.
Jacob West, Fortify Software
Djenana Campara, Hatha Systems
James Walden, Northern Kentucky University
Frank Kim, ThinkSec
Chris Eng and Chris Wysopal, Veracode, Inc.
Ryan Barnett, Breach Security
Antonio Fontes, New Access SA, (Switzerland)
Mark Fioravanti II, Missing Link Security Inc.
Ketan Vyas, Tata Consultancy Services (TCS)
Lindsey Cheng, Ian Peters and Tom Burgess, Secured Sciences Group, LLC
Hardik Parekh and Matthew Coles, RSA - Security Division of EMC Corporation
Mouse
Ivan Ristic
Apple Product Security
Software Assurance Forum for Excellence in Code (SAFECode)
Core Security Technologies Inc.
Depository Trust & Clearing Corporation (DTCC)
The working group at the first OWASP ESAPI Summit
National Security Agency (NSA) Information Assurance Division
Department of Homeland Security (DHS) National Cyber Security Division