Archive for September, 2007

OWASP Helsinki - Tuesday October 2nd

September 27, 2007

If you promise not to mention the name Kimi Raikkonen you are welcome to the OWASP Helsinki chapter meeting next Tuesday where I will be speaking about lots of things software security.
Hope to see you there!

How To Be Spy in London

September 26, 2007

From today’s Telegraph
Secret documents released by the National Archives in 2005 include a guide written by a Russian spy in the 1930s, explaining to his colleagues how to avoid trouble while living in London. (To find it, go to the News menu, choose “New document releases”, then click “Releases in 2005″ and “Highlights” from March.)
His [...]

London Security Supper Club

September 26, 2007

A few UK based “security friends” (mainly work in banks) and I have decided to get together once a month and have dinner, drinks and inevitably chat about security (probably followed by more drinks) somewhere in central London (City/West End). We are aiming for the first Thursday night of each month and a different [...]

Managed Security Firm Covers Up Security Deficiencies?

September 25, 2007

From the Washington Post Unisys are in the dog house.
The FBI is investigating a major information technology firm with a $1.7 billion Department of Homeland Security contract after it allegedly failed to detect cyber break-ins traced to a Chinese-language Web site and then tried to cover up its deficiencies, according to congressional investigators.

I wonder what [...]

SecurityLinkUp is now an OWASP Project

September 25, 2007

SecurityLinkUp.com is now an OWASP project. The original code is being thrown away. Brian Bertacini and Sebastien Deleersnyder are project managers and developing a set of requirements now.

The Ticking Time Bomb - PCI Application Security

September 25, 2007

A while back I wrote a blog post called Lets call a Fig a Fig about the limitations of web application firewalls and the sheer ludicrousness of a security standard offering an alternative of choosing a code review or a web application firewall.
This morning I was reading an excellent post by Chris Eng about [...]

Marc Andreessen on Platforms

September 24, 2007

Marc’s post here is well worth a read.
Level 1 is what I call an “Access API”.
Level 2 is what I call a “Plug-In API”.
Level 3 is what I call a “Runtime Environment”.
The Oxygen Security Platform is actually likely to be a combination of all three!

Why Do We Have Kids?

September 19, 2007

So we can take them to the Grand Prix of course! Jack and I went to the Belgian GP at Spa Francorchamp this weekend. It was superb!

If you do go to a GP check out the Kangaroo TV’s. They give you the live F1 TV feed plus current race stats wherever you are on [...]

MC Borg

September 18, 2007

Helpful as always, a little something for my readers so they don’t need to waste their own precious time.

A big thanks to Melanie Smith, graphics whiz!

Security Data Visualization Book

September 18, 2007

Just picked up from O’Reilly, a new book called Security Data Visualization. It looks to be very network security centric but I will check it out and post a review here.