SEARCH RESULTS
 
Showing 1-10 of 36 records
 
Expand article

We're so big and other marketing games

2008-06-27 10:41:01 by HASH0x8b0794c in StillSecure, After All These Years
 
...repeat a story enough times, whether it is true or not, eventually people believe it . The bigger the lie, the more times you repeat it, the more people will believe it. But that should not stop others from pointing out the facts and doing their best to call out those who just cross the line with marketing claims that are not true Here is...
 
 
 
 
 
Expand article

Myth vs. reality: Wireless SSIDs

2007-10-16 07:08:58 by Steve Riley in Steve Riley on Security
 
...repeat, not -- a password. A wireless network has an SSID to distinguish it from other wireless networks in the vicinity. The SSID was never designed to be hidden , and therefore won't provide your network with any kind of protection if you try to hide it. It's a violation of the 802.11 specification to keep your SSID hidden; the 802.11i...
 
 
 
 
 
Expand article

Protect your data: everything else is just plumbing

The Article has images
2007-07-02 20:46:32 by Steve Riley in Steve Riley on Security
...repeat: they want your data. Theyll steal it and sell it to your competitors, theyll damage it and put you out of business. The network and your computers exist only as a means to get to your data. So we, as defenders of information assets, must change our tactics to react toand possibly get in front ofthe tactics of the bad guys. Weve got to...
 
 
 
 
 
Expand article

The STRIDE per Element Chart

2007-10-29 23:06:46 by sdl in The Security Development Lifecycle
 
...repeat it. They were looking for classes of things that would cause us to ship an update. If we wouldnt update for it, it doesnt exist in the chart. Thats not to say it doesnt exist. If theres an elevation of privilege against an external entity, well, by definition, we cant fix it. Its external. So is there value in calling out that risk in...
 
 
 
 
 
Expand article

Fuzz Testing at Microsoft and the Triage Process

2007-09-20 18:52:00 by sdl in The Security Development Lifecycle
 
...repeat How we do file fuzzing There are a number of approaches taken by product teams to meet the SDL file fuzzing requirements. They often include the use of generation and mutation-based fuzzers as well as a combination of multiple internal and externally available fuzzing tools and/or frameworks When fuzzing file parsers, we monitor for...
 
 
 
 
 
Expand article

Lookit What Network Solutions Registered

2008-01-14 22:17:56 by Editor in Cheap Hack
 
Categories: Domain Name Market Body: One of the more amusing discussions of the Network Solutions front-running scandal is the comment thread to this blog post on domaintools.com . Users have started a contest to see what offensive and denigrating domain names they can trick NetSol into registering by searching for them. Consider these...
 
 
 
 
 
Expand article

Orthogonal Blogging at the SOA Horse Races

2008-01-20 06:30:30 by Tim Bass in The Complex Event Processing Blog
 
...repeat. I have never been interested in selling softare. I am interested in real business solutions Candidly speaking again, many software companies tend to live in La La Land They create go-to-market strategies based on jargon, buzzwords and three letter acronyms that have very little to do with understanding their customers business...
 
 
 
 
 
Expand article

Stolen Bolton Hospitals Laptop affects cancer patients

The Article has images
2008-02-04 10:47:22 by Evan Francen in The Breach Blog
...repeat our apologies that such an event happened and reassure people that the hospital is taking this very seriously We fully understand the anxiety the theft of data can cause and we have stepped up security of premises, as well as investing around 200,000 in additional IT security Evan] The amount of money could equate to how serious...
 
 
 
 
 
Expand article

More trustworthy election systems via SDL?

2008-02-04 23:34:00 by sdl in The Security Development Lifecycle
 
...repeat that again. (See Adams Threat Modeling series and Daves Security Education v. Security Training posts respectively for more info Is the SDL enough to ensure trustworthy voting systems When I offered this blog post for the review of my colleagues, it generated some very interesting discussion. Some of my colleagues were worried that I...
 
 
 
 
 
Expand article

The National Cyber Exercise