Archive for the 'Web Security' Category

Azure - The Microsoft Cloud Arrives!

October 27, 2008

Azure Platform Home Page
Windows Azure - The Cloud Services Operating System
.NET Services - Access Control, Services Bus and Workflow
SQL Services - Database Services
Live Services - LiveID, LiveEarth, Contacts
Digest that for a while (yes it really is that big), chuck in some LiveMesh and you’ll realize that Microsoft is now not the company you may think [...]

Live Labs WebSandbox

October 27, 2008

I think sandboxes will become more and more important as we continue to mash-up the web and move towards hosting applications and data in the cloud. It’s great to see LiveLabs announcing interesting work in the area at PDC.
I guess it will be eclipsed by Azure….

Security Runtime Engine

October 24, 2008

Today we posted some preview details about a .NET security runtime engine we have been working on that overloads encoding methods in the .NET framework. It’s pretty cool, running at near native speed!
http://blogs.msdn.com/cisg

Consumer Application Security or Enterprise Application Security ?

October 21, 2008

When Linus Torvalds wrote about the security circus he echoed a lot of the sentiment I have felt for a while; when it comes to software security, people care about the wrong things for the wrong reasons. The sensationalism that follows the release of security bugs is of course understandable. The popular press want to [...]

OWASP CISO Panel

October 20, 2008

I didn’t go to OWASP NYC (put off by the vulnerability circus to be brutally honest) but I just watched the CISO panel and it’s just fantastic to see a panel of CISO’s discussing really important application security topics.
Jim Routh

‘…..view application security as a supply chain management problem’. Very wise!

‘Static analysis tools are most effective [...]

Gazza on the Software Security Market

September 12, 2008

Really good article by my pal Gazza (here).
Some highlight’s include;
All told, the software security market for tools and services in 2007 was worth somewhere between $275-300 million.

One of the most important developments in the software security market can be seen in the tools space which, combined, almost doubled to $150-180 million.

…..static analysis tools for [...]

Are You a Builder or a Breaker

September 10, 2008

I am reading Brain Rules; great book! In the opening chapter there is a wonderful quotation from an interview with Frank Lloyd-Wright that resonates with how I feel about the application security industry.
“When I walk into St. Patrick’s cathedral here in New York City, I am enveloped with a feeling of reverence”, said Mike Wallace. [...]

CISG Team Blog

August 25, 2008

The CISG Team Blog is now operational. We are initially blogging about things we are doing with Anti-XSS (and related technologies) but plan to expand to cover our bigger projects over the coming months.
You can expect a wide range of posts from program management, user experience and code level developer commentary.
http://blogs.msdn.com/cisg/

A Great Article on Open Source HTTP Load Testing

August 24, 2008

Using free software for HTTP load testing
T(c(r))rusty old Curl. Whatever happened to Elza?

Visible Web Site Flaws

July 26, 2008

An interesting read picked up from the brilliant Usable Security blog.
Analyzing Websites for User-Visible Security Design Flaws