Archive for Defense

Protecting the global Internet routing infrastructure

Arbor Networks has a blog post up today about Using RPKI to Construct Validated IRR Data.  Resource PKI (RPKI) is an extension to X.509 to allow for IP address (prefix) and AS identifiers (autonomous system numbers — the organization-based assigned number used by the Border Gateway Protocol to get you or your ISP “online”).
My first […]

CERT on Securing your web browser

‘Lo and behold, CERT has an excellent document on Securing your web browser!  They cover IE, Firefox, and Safari — three secure references for the three most popular browsers.
The documentation and links provided are great.  I was actually surprised that they covered quite a bit of important topics and that the recommendations they gave are […]

Security and safe browsing for Firefox

You installed Firefox. How do you make it more secure for daily use? How do the Mozilla developers ensure that they are doing all the right things? How do you safely browse the Internet?
These are not easy questions to answer, and some of the answers will be system/OS-dependent.
Security functionality in Windows […]

Security in the SDLC is not just code review

Let’s take some time here to discuss what “secure code review” is and what it is not.  I see a lot more people talking about code review.  Many people have only the view of the PCI DSS compliance standard, which almost pits code review against the web application firewall.
David Rice quoted a Gartner study on […]

Firefox 3 first impressions

I’ve downloaded and used the Firefox 3 beta browser software for the past few months and wanted to give a report on the latest of what works and what doesn’t.  Note that I had to install Nightly Tester Tools to get many of these to work.  I am also now using the Classic Compact theme, […]