Archive for August, 2007

Sex Bars, Bluetooth and Privacy

August 31, 2007

Westminster Council in London are sending a message via Bluetooth to anyone who walks within 30 meters of known clip bars in Soho reported the Daily Mail newspaper in the UK. Will we start seeing Bluetooth messages when we walk into shops telling us that the same goods can be bought cheaper next door? I [...]

The Psychology of Information Security - Part 0

August 31, 2007

After my The Security Genome - Understanding How People Find Security Bugs post I picked up a book I have been wanting to read for ages. Stumbling on Happiness by Daniel Gilbert is a psychology analysis about what makes people happy. I predict (pun for anyone who has already read the book) that  it will spawn a series of [...]

Analogy of Risk Management

August 30, 2007

“Risk Management is like the navigator in a rally car; Business is the driver.”

Hoff’s comment made me chuckle. “..these navigators never stop and ask for directions”.

Software Security Assurance - State of the Art Report

August 30, 2007

3o0 + pages of comentary and opinions on everything software security.
http://iac.dtic.mil/iatac/download/security.pdf
Thanks to Rudy for sending this over.

The Security Genome - Understanding How People Find Security Bugs

August 29, 2007

I think I may buy shares in Wired. I seem to plug it every month when I read articles of interest that spark my imagination. After reading the Web War One article I was engrossed by the Halo 3 story. Just yesterday I had a conversation with someone about the sophistication of games versus the [...]

WW1 (Web War One) - eStonia Attacked!

August 29, 2007

Like many of my blog readers I suspect that the recent story about Estonia being shut of the grid passed with a fleeting interest. Over the years I think I have been jaded by sensationalist journalism about cyber jihads and the Internets impending doom from cybervillans. 
I just picked up a copy of Wired at the airport [...]

Straights Words from Gartner about PCI

August 23, 2007

……. there are some important areas where we part company with the council. One of the most important is that the council sanctions the use of an assessor that is also trying to sell you security services. This is completely at odds with established best practices in audit and compliance.
Well, the card companies may not learned [...]

SilverLight

August 22, 2007

If you ever doubted SilverLight would be able to deliver superb web UI’s here is proof: Tafiti.

Note: It’s shame the relevance of the search results are so poor because this would have me move from Google in an instance.
Check out this SilverLight video from Mix07. Blows me away. When will security tools look this [...]

The Art of Scoping Application Security Reviews (Part 1) - The Business

August 22, 2007

A development manager friend in Europe sent me the following email:
…I know you aren’t in the business anymore (?) but how the f&^% do you scope a web application security review? I have asked six firms to provide proposals and after countless wasted hours repeating the same things they are literally 1000’s of percentage points apart in [...]

How Software is Built

August 20, 2007

 How Software is Built is a really interesting site with some really interesting perspectives and ideas.