Ingres gives Fortify security study a good fisking

Since Fortify released its security study, unleashing the FUD flood, I have been waiting for someone to give it a good fisking.

Today we have a winner. Meet Emma McGrattan, senior vice president of engineering for Ingres, an open source database outfit.

Her main points:

1. There are other security toolkits other than Fortify. Just because you don’t use their system doesn’t mean you don’t care.

2. When reading vendor-sponsored studies consider the source. Always a wise move.

More Here