Syndicated Blog

[su_panel border="1px solid #ddd" radius="3" text_align="center"]
Security Retentive
[/su_panel]

What is old will be new again

|
 There has been a lot of focus the week on so on session-token theft and IP restrictions to help mitigate stolen session tokens. I see that as a useful belt+suspenders approach right ...

What is old will be new again

|
 There has been a lot of focus the week on so on session-token theft and IP restrictions to help mitigate stolen session tokens. I see that as a useful belt+suspenders approach right ...

Whose credentials are they? Mine, or yours?

|
I've been spending a bunch of time lately thinking about usernames and passwords, and other types of credentials, and concept of "ownership". When you get a credit card, on the back it ...

Whose credentials are they? Mine, or yours?

|
I've been spending a bunch of time lately thinking about usernames and passwords, and other types of credentials, and concept of "ownership".When you get a credit card, on the back it typically ...

Why do people expect so much more from mobile platforms?

|
Reading Veracode's recent post: Mobile Security – Android vs. iOS, which is an infographic comparing Android and iOS security, I'm left with a few questions, some of which I posted as a ...

Why do people expect so much more from mobile platforms?

|
Reading Veracode's recent post: Mobile Security – Android vs. iOS, which is an infographic comparing Android and iOS security, I'm left with a few questions, some of which I posted as a ...

Malware prevalence != Infection rates

|
There have been a number of presentations of late that have tried to document howend-users get infected with malware.Both Google's malware report and a recent report from CSIS purport to tell us ...

Malware prevalence != Infection rates

|
There have been a number of presentations of late that have tried to document howend-users get infected with malware.Both Google's malware report and a recent report from CSIS purport to tell us ...

No Browser is an Island

|
Jeremiah wrote today about web browsers and opt-in security. I think he gets it mostly right (and hey, he pointed at a paper I co-authored so I'm biased) but I think it ...

Poll Time – What One Problem in Web Security Do You Want to Fix?

|
It is poll time. Doing a little planning and trying to figure out what people view as the biggest architectural weaknesses on the web security wise. I'm mainly focused on things within ...