<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Envelope: Vulnerability Growth Rates</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=189" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=189</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=189&#038;cpage=1#comment-268</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 07 May 2008 12:49:51 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=189#comment-268</guid>
		<description><![CDATA[@Ilja -

I agree that estimation can be challenging. I also think it is worthwhile to add more precision to lines of reasoning (even if they are not yet accurate). In the absence of doing confidence interval work, I opted for something I thought was conservative. Judging from your thoughts on this, I got what I wanted.

Regarding your points about programmers - don&#039;t forget there are a lot of other things programmers do that don&#039;t involve coding. We are shooting for the final product over an extended time. So, if a programmer really only codes 4 hours a day and rewrites 25% of his/her code, those numbers can be affected significantly.

I think we can all get better at this if we keep trying (not necessarily for this specific case, but for estimation in security in general). I know the first time you do it, it seems difficult, so I appreciate you not just saying &quot;its impossible&quot; and actually taking a stab at it.

Thanks.
]]></description>
		<content:encoded><![CDATA[<p>@Ilja -</p>
<p>I agree that estimation can be challenging. I also think it is worthwhile to add more precision to lines of reasoning (even if they are not yet accurate). In the absence of doing confidence interval work, I opted for something I thought was conservative. Judging from your thoughts on this, I got what I wanted.</p>
<p>Regarding your points about programmers &#8211; don&#8217;t forget there are a lot of other things programmers do that don&#8217;t involve coding. We are shooting for the final product over an extended time. So, if a programmer really only codes 4 hours a day and rewrites 25% of his/her code, those numbers can be affected significantly.</p>
<p>I think we can all get better at this if we keep trying (not necessarily for this specific case, but for estimation in security in general). I know the first time you do it, it seems difficult, so I appreciate you not just saying &#8220;its impossible&#8221; and actually taking a stab at it.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ilja</title>
		<link>http://spiresecurity.com/?p=189&#038;cpage=1#comment-267</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Wed, 07 May 2008 11:46:52 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=189#comment-267</guid>
		<description><![CDATA[Hey Pete,
I don&#039;t think I have better numbers, I really don&#039;t know the numbers. And I think getting some of these numbers even in the same ballpark as the actual numbers would probably be hard. I guess it&#039;s just a gut feeling. but 2 million programmers in the world ? if I&#039;d have to make A guess, India alone could probably account for those 2 million. Then again, I could be way off. The same with those 1 bug in 10000 lines of code. It just doesnt sound right to me, I&#039;d be more inclined to say 1 to 1000 (and I&#039;m not alone here) but again, I could be way off. An average dev doing 25 lines of code a day ? I hope that number is really bogus. it has to be. that means on an average 8 hour workday they&#039;d write 3 lines of code an hour ? I would go for atleast 100 a day, but again, I could be way off. My point is that we&#039;re both probably way off and the outcome (using either your or my gueeses) is probably not realistic at all.
]]></description>
		<content:encoded><![CDATA[<p>Hey Pete,<br />
I don&#8217;t think I have better numbers, I really don&#8217;t know the numbers. And I think getting some of these numbers even in the same ballpark as the actual numbers would probably be hard. I guess it&#8217;s just a gut feeling. but 2 million programmers in the world ? if I&#8217;d have to make A guess, India alone could probably account for those 2 million. Then again, I could be way off. The same with those 1 bug in 10000 lines of code. It just doesnt sound right to me, I&#8217;d be more inclined to say 1 to 1000 (and I&#8217;m not alone here) but again, I could be way off. An average dev doing 25 lines of code a day ? I hope that number is really bogus. it has to be. that means on an average 8 hour workday they&#8217;d write 3 lines of code an hour ? I would go for atleast 100 a day, but again, I could be way off. My point is that we&#8217;re both probably way off and the outcome (using either your or my gueeses) is probably not realistic at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=189&#038;cpage=1#comment-266</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 07 May 2008 03:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=189#comment-266</guid>
		<description><![CDATA[@Ilja -

I hope you mean they are very conservative. In any case, I would love to know what numbers you think are more reasonable.
]]></description>
		<content:encoded><![CDATA[<p>@Ilja -</p>
<p>I hope you mean they are very conservative. In any case, I would love to know what numbers you think are more reasonable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ilja</title>
		<link>http://spiresecurity.com/?p=189&#038;cpage=1#comment-265</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Wed, 07 May 2008 01:34:55 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=189#comment-265</guid>
		<description><![CDATA[dude, that must have been some good shit you were smoking when you typed that. 25loc a day ? 2 million programmers in the world ? 1 bug on ever 10kloc (so with those stats you&#039;re saying the average dev makes 1 bug per year ??) those number just have to be bogus. they dont even sound remotely realistic.
]]></description>
		<content:encoded><![CDATA[<p>dude, that must have been some good shit you were smoking when you typed that. 25loc a day ? 2 million programmers in the world ? 1 bug on ever 10kloc (so with those stats you&#8217;re saying the average dev makes 1 bug per year ??) those number just have to be bogus. they dont even sound remotely realistic.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
