Monthly Archives: August 2007

PKI Enhancements in Windows

Windows has included strong, platform-wide support for public key infrastructure (PKI) since the release of Windows 2000. That release included the first native certificate-authority capability, introduced auto-enrollment, and provided support for smart-card authentication. In Windows XP and Windows Server 2003, … Continue reading

Share
Posted in Cryptography, Operating Systems and Application Security | Leave a comment

A Gateway for Hackers

Last week Congress gave US President Bush new wiretapping powers. Read  Susan Landau – A Gateway for Hackers – washingtonpost.com. It says: Grant the NSA what it wants, and within 10 years the United States will be vulnerable to attacks from … Continue reading

Share
Posted in Review, Security | Leave a comment

“Unlock” your iPhone!?

Seems interesting if it is true – Tutorial: “Unlock” your iPhone with SuperSim – Hackint0sh.

Share
Posted in Hardware Security, Mobile / Cellular / Bluetooth | 1 Comment

WordPress 2.2.2 and 2.0.11

On August 5, 2007 WordPress team announced two security-related releases available for both users of our main 2.2 branch and the legacy 2.0 branch. See: WordPress › Blog » WordPress 2.2.2 and 2.0.11. I’ve upgraded my blog today to 2.2.2 and … Continue reading

Share
Posted in Internet Security, Operating Systems and Application Security, Software Security | 6 Comments

Encryption: Security Considerations for Portable Media Devices

IEEE Security and Privacy, issue July/August 2007 (Vol. 5, No. 4), has interesting article Encryption: Security Considerations for Portable Media Devices (subscription required). Abstract With the proliferation of removable media devices, such as iPods and USB drives, large amounts of an … Continue reading

Share
Posted in Cryptography, Hardware Security, Tools and Utilities | 1 Comment

Estimating Software Vulnerabilities

IEEE Security and Privacy, issue July/August 2007 (Vol. 5, No. 4), has interesting article Estimating Software Vulnerabilities (subscription required). Abstract Any given piece of software has some number of publicly disclosed vulnerabilities at any moment, leaving the system exposed to potential attack. The … Continue reading

Share
Posted in Books, Magazines and Journals, Software Security | Leave a comment

Security Developer Center: Threat Modeling

Microsoft Application Threat Modeling is a critical security activity, enabling effective application risk management during the SDLC and beyond. Application Threat Modeling is enforced as part of the Security Development Lifecycle for IT (SDL-IT) at Microsoft. Boeing develops their line … Continue reading

Share
Posted in Operating Systems and Application Security, Secure Programming, Threats, Vulnerabilities, Attacks | Leave a comment