I “grew up” surrounded by web application security – from a time when Achilles was the only useful proxy and everything was done by hand, to the current state of affairs, where automated tools and proxies are used on a regular basis. OWASP and WASC have been formed, and web application security is taken seriously. However, there are still many web applications that existed before this explosion in security awareness, and they’re still out “in the wild”. Unlike the thick client area where the majority of “major” applications are controlled by larger development firms (Windows, Oracle, etc) with security departments, web applications are written by everyone and their brother Joe. There are some large development houses writing web apps, but[…]
Category: rants
Blizzard offers a One Time Password device for it’s European customers but not the North American or Asia Pacific customers? Blizzard is using a One Time Password device (it appears to be event based) to allow for strong authentication to it’s EU servers. There’s no indication on what manufacturer they’re using, or if it’s OATH compliant, but it is still a “real” two factor authentication, as users will need to have their device with them to log into the account management web pages or to the game servers. It’s optional, and available for 6 euros to EU customers. There are three things that makes this interesting: 1) real two factor authentication is available in a game before it’s available in[…]
One of the most annoying website you find when searching for a solution to a problem on Google is http://www.experts-exchange.com some how someone already asked the same exact question you have. But unfortunately when you go to the page you get something like “Experts Comments are for Premium Members Only” Example you know they have the answer, but is it worth paying? Well they are using an absurd security by obscurity method to ensure you will pay for their services. See any regular Internet user that sees the “For Premium Members Only” sign will immediately hit the back button frustrated and continue on googling. But if you had a bit of curiosity you may find yourself with the answer you[…]
I just closed on a new home last week. One of the first things I had to do was change out all the locks. Mainly because I didn’t have keys to any of the deadbolts nor the utility room on the back of the house, which stores the furnace, hot water heater, all that good stuff. So I went to my local hardware store. At first I was very tempted to get something like this Kwikset SmartScan but I decided at $100 a pop I could hold off. After looking through the selection one thing became very apparent to me. Because I was going to need 3 complete sets (knobs / deadbolts), I wanted them to share the same keys.[…]
Maybe it’s just me, maybe I’ve just been busy with work, and not taking the time to scour over all the many news blogs, maybe there’s something there, and I’m just not picking up on it. But it seems lately, at least over the past couple weeks, it’s been pretty slow in the InfoSec news departments all around the net. Some could even look at this as a good thing, as no news about bugs, exploits, vulnerabilities, and viruses, could be interpreted as good, meaning we’ve been doing our jobs and all is safe in the world. I generally try to stay on top of everything, mostly for personal interest, but also for the self education process that usually comes[…]
With my honeymoon coming up, I’ve been thinking a lot about how I’m dreading going through security at the airport. We’re flying from Washington Dulles to Tokyo, Narita, someplace I’ve never been before. But in my (admittedly limited) travels around the world, I’ve noticed a major difference in security procedures in various airports and countries. Most are not near as onerous as those practiced by the TSA. In Paris’ Charles De Gaulle (CDG), security consists of putting your bag through a metal detector, walking through and going on your way. No taking off your shoes, no limit on liquids, etc. It’s only when you get to the “american bound” gates that you have to go through additional security that checks[…]