Archive for the 'OWASP' Category

Team Foundation Server (TFS) and the Open Web Application Security Project (OWASP) Top Ten

November 21, 2008

Nice article over on MSDN here.

Beautiful Security

October 24, 2008

I am currently writing a chapter for a new O’Reilly book called Beautiful Security. You can pre-order it on Amazon now. There is a whole series of them following up from Beautiful Code including Beautiful Architecture from their Theory In Practice Series. This series has some of my favourite books including Scott Berkuns Making Things [...]

OWASP CISO Panel

October 20, 2008

I didn’t go to OWASP NYC (put off by the vulnerability circus to be brutally honest) but I just watched the CISO panel and it’s just fantastic to see a panel of CISO’s discussing really important application security topics.
Jim Routh

‘…..view application security as a supply chain management problem’. Very wise!

‘Static analysis tools are most effective [...]

Microsoft Joins OWASP

October 12, 2008

If you navigate over to the OWASP members page you will see a new logo

It’s an interesting full circle for me having started OWASP back in 2001 and now having had a hand in one of the biggest technology companies in the world (my current employer) joining. Someone sent me a mail on Friday [...]

Are You a Builder or a Breaker

September 10, 2008

I am reading Brain Rules; great book! In the opening chapter there is a wonderful quotation from an interview with Frank Lloyd-Wright that resonates with how I feel about the application security industry.
“When I walk into St. Patrick’s cathedral here in New York City, I am enveloped with a feeling of reverence”, said Mike Wallace. [...]

Social Networking, Crowd Sourcing and Security

June 10, 2008

I thought I posted this a while back so my apologies. At the OWASP Conference I spoke about social networking and how it may be applied to security domain in the future.  I used the slide below.
 

 
In a related but unconnected event, that Friday someone of the team sent out a simple spreadsheet [...]

Checklists Are Not For Dummies, Dummy!

May 24, 2008

At the OWASP Conference in Belgium this week I had a slide about checklists.

This is the story behind the slide. My boss at Microsoft has a friend who is a pilot. He did his pre-take-off checklist and was cleared to taxi onto the runway by air traffic control. He consulted his checklist one [...]

Presenting Security Ideas or Driving Agendas?

May 24, 2008

I opened the OWASP Europe Conference this week with a slide (below) about vendor neutrality.

In essence I urged attendees to consider the motivations of those presenting various ideas at the conference; including myself of course. During the conference it was pointed out that the moderator of a panel “The PCI 6.6 Dogfight – [...]

What Do Online Communities and Global Politics Have in Common?

April 13, 2008

I got back from Redmond yesterday. I am getting old so couldn’t sleep well last night; luckily for me the BBC shows Our World during the night and I caught Danger – Democracy at Work. As usual it was a superb bit of journalism this time questioning Americas dogma to spread their own blend of [...]

Techdays 2008, L’Innovation Avance Avec Nous

February 1, 2008

Comprendre les problèmes courants de sécurité des applications Web, utiliser les ressources du projet OWASP (WEB303)animé par Mark Curphey , Sébastien Gioria
Audience : Architectes Décideur technologique Développeur Enseignants et chercheurs Informaticiens Niveau : Confirmé (300)
Le lundi 11 février 2008, 11:00 – 12:00.
Cette session a pour but de sensibiliser les développeurs aux vulnérabilités et aux [...]