Archive for Tech
Web application security scanners have not matured much. I guess patent wars and company-buyouts have caused a lot of stagnation over the past year. However, I think the problems may run deeper than just controversy and industry drama.
AppScan DE and DevInspect as exceptions — largely the web application security scanner industry is filled […]
Posted by dre on January 21st, 2008 in Tech, Security.
Comments: 0 | RSS
An audit framework for evaluating structured security program frameworks
How many readers implemented a new security plan for 2006 or 2007? How many had clients that implemented a new security program? Which frameworks were involved?
Possible frameworks (Criteria)
No structured security program, or one based around a single vendor or regulation
Mike Rothman’s Pragmatic CSO (P-CSO)
Gunnar Peterson’s […]
Posted by dre on December 10th, 2007 in Work, Hacking, Politics, Tech, Intelligence, Security, Defense.
Comments: 0 | RSS
Pen-testing is an art, not a science
Penetration-testing is the art of finding vulnerabilities in software. But what kind of an “art” is it? Is there any science to it? Is pen-testing the “only” way or the “best” way to find vulnerabilities in software?
When I took my first fine arts class, we learned […]
Posted by dre on December 2nd, 2007 in Hacking, Tech, Security, Defense.
Comments: 11 | RSS
In my earlier article on Using Google Analytics to Subvert Privacy, I demonstrated how dangerous free tools could be to match privacy information to web clicks.
But now that Google has updated their Analytics service to support internal search queries, you can now link user privacy information to search data, as well. Now everyone can […]
Posted by dre on October 17th, 2007 in People, Conferences, Privacy, Tech, Security, News.
Comments: 2 | RSS
Recently, we’ve heard a lot of talk about P2P apps and data leakage concerning various members of Congress. It started with this article over at NetworkWorld, followed up by the guys at nCircle, directing criticism towards Congree from Techdirt, comments from LonerVamp, and lately a rambling from Alan Shimel on how NAC will solve the […]
Posted by Marcin on July 29th, 2007 in Politics, Tech, Security, News.
Comments: 3 | RSS