How I hope history has reshaped this year's RSA Conference one year after one of the most significant breaches in the past decade
Continue reading "RSA Conference, One Year Later"
The hacker mindset can't be taught -- it must be developed and refined over time
Continue reading "Can You Train A Great Penetration Tester?"
A new FCC-backed initiative will gather real ISP data on infected bot machines, but will it make a dent on the botnet scourge?
Continue reading "Bots: Stand Up And Be Counted"
Heading to San Francisco for RSA, BSides and AGC? Make sure you know how to navigate the vendor gauntlet
Continue reading "Don't Be Fooled By Buzzwords, Flash, And Empty Promises"
Many businesses fool themselves about their compliance problems
Continue reading "Five Dangerous Compliance Assumptions"
Data and databases keep growing, but there's a security tradeoff
Continue reading "Can You Delete A Database?"
Shockingly the responsible disclosure debate rears its head once again, and amazingly enough some vendors still don't get it. Guess we'll never learn
Continue reading "Disclosure Clouded By Obscurity"
Full disclosure risks premium sale price
Continue reading "Nortel Networks: Wolf In The Henhouse, Guard Dog Fast Asleep"
Security requirements for the financial-services industry differ from other industries
Continue reading "The Financial Industry's Effect On Database Security "
Compliance is not a tool for dodging work or dismissing business needs
Continue reading "Being A Security Bully Does Not Make You Compliant"
Preconfigured Linux environments provide powerful tools to aid in pen testing, mobile security testing, malware analysis, and forensics
Continue reading "Linux Live Environments: Cool Tools Even For Windows Folks"
Emergence of machine to machine (M2M) devices make it easier for thieves and hackers -- and more dangerous for victims
Continue reading "Been Caught Stealin'"
Forging a stronger tie between the sign-on process and the actual known user who owns that particular account
Continue reading "On Determining Online Identities"
What the Symantec source-code leak really means
Continue reading "Between Source Code And Cyanide"
RSA key weakness
Continue reading "RSA Weakness and e-Commerce Authentication"
Cryptographic methods at any point in time will become weak at some point due to the advances made in computing
Continue reading "How Can We Gracefully Update Crypto?"
Your product's user interface may not be as appealing as you might think -- and it might just be jeopardizing its adoption
Continue reading "I'm Sorry I Called Your Baby Ugly ... But It Is"
Small and midsize businesses often let the cost of compliance obscure important benefits
Continue reading "Compliance And 'The Little Guys'"
Three key takeaways from a recent webcast about database security in the NoSQL database movement
Continue reading "A Response To NoSQL Security Concerns"
Passive network analysis can reveal OS, service, and even vulnerabilities -- just by sniffing the network
Continue reading "Passive Network Fingerprinting; p0f Gets Fresh Rewrite"
Why haven't user interfaces for security products taken advantage of human movement technologies?
Continue reading "Where's My 'Minority Report' Dashboard?"