SEARCH RESULTS
 
Showing 1-10 of 137 records
 
Expand article

DMCA Does Not Apply to U.S. Government

2008-08-08 11:32:17 by schneier in Schneier on Security
 
...apply It appears that Congress took a "do as we say, not as we need to do" approach to strengthening digital copyrights
 
 
 
 
 
Expand article

Fuzz Testing at Microsoft and the Triage Process

2007-09-20 18:52:00 by sdl in The Security Development Lifecycle
 
...apply be based on type? Use interesting patterns? Over how many bits/bytes Will we apply malformations with or without restriction? Are we going to be deterministic or random or both? How many times in a single iteration do we apply any given malformation Stage 3: Delivery of fuzzed data to the application under test Determining the best...
 
 
 
 
 
Expand article

Another Wisconsin mailing exposes Social Security numbers

The Article has images
2008-01-15 13:32:24 by Evan Francen in The Breach Blog
...apply You itemized your deductions AND received a 2006 Wisconsin income tax refund. The forms at risk were sent to the following communities with a postmark of January 2, 2008: Freedom, Kaukauna, Keshena, Kimberly, Krakow, Lakewood, Lena, Little Chute, Little Suamico, and Marinette Only the social security number of the primary taxpayer were...
 
 
 
 
 
Expand article

SDL and Filtering

2008-03-13 15:00:00 by sdl in The Security Development Lifecycle
 
...apply to that criteria and the result is a clearer starting point for what you need to do to begin adopting the SDL for your project. This applicability filtering also allows product groups to more easily divide up the responsibility for ramping up on the SDL instead of overloading a single person in their group with figuring out what needs...
 
 
 
 
 
Expand article

Oh No! Security Metrics!

2008-04-18 12:43:00 by sdl in The Security Development Lifecycle
 
...apply to their products once in deployment. It costs them time and money to deploy security updates. The primary metric that matters to customers is the number of security updates they need to apply. And the only way to reduce the number of updates is to systematically reduce the number and severity of vulnerabilities in the code in the first...
 
 
 
 
 
Expand article

Security Matters: How to Create the Perfect Fake Identity

2008-09-04 04:00:00 by Bruce Schneier in Wired Security
 
...apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them There are some complications, of course. Maybe...
 
 
 
 
 
Expand article

Identity Farming

2008-09-09 05:42:18 by schneier in Schneier on Security
 
...apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them There are some complications, of course. Maybe...
 
 
 
 
 
Expand article

Covert channel vulnerabilities in anonymity systems

2007-12-10 10:39:42 by Steven J. Murdoch in Light Blue Touchpaper
 
...apply previous research on covert channels (unintended means to communicate in violation of a security policy) to analyse several anonymity systems in an innovative way One application for anonymity systems is to prevent collusion in competitions. I show how covert channels may be exploited to violate these protections and construct defences...
 
 
 
 
 
Expand article

The Big Announcement

2008-03-13 00:03:25 by Bill in Grumpy Security Guy
 
...apply a default deny policy, while a great idea in theory, is pretty hard in the real world . There is just way to much movement in most applications to pin it down. Even if the app does not change frequently, WAF admins are very hesitant to even come close to blocking legitimate traffic.What really sold me though is when I saw it in action...
 
 
 
 
 
Expand article

Privacy Policies Best Practices

2008-03-28 08:19:18 by Jen Albornoz Mulligan in Security & Risk Management
 
...apply to? Or more importantly which ones does it not apply to The policy needs to be comprehensible to the everyday person. Far too many privacy policies have been written by corporate lawyers using terms that most regular people will not understand. Think of your mother or your brother or your child, could they read and understand it? If you...