• 11 Aug 2010

    Great information security quote (don’t believe the hype)

    There's a Japanese proverb that fits nicely into infosec:"If you believe everything you read, perhaps it's better not to read."Be it F.U.D., vendor hype, or "experts" who claim the sky is falling with every new exploit they uncover - you ultimately need to focus on doing what's best in your environment under your terms....

    Continue Reading...
  • 11 Aug 2010

    Avoid the temptation to go nowhere

    The cancellation of Tony Robbins show after just two episodes underscores how many people aren't interested in learning more about getting ahead in life. Instead, mindless drivel is the "norm" of today.If you want to make things happen, dare to be different....

    Continue Reading...
  • 09 Aug 2010

    How you can get developers on board with security starting today

    Some people - including a brilliant colleague of mine - think security is not the job of software developers. In the grand scheme of things I think such an approach is shortsighted and bad for business. It's kind of like an auto assembly line worker not being responsible for the quality of his work or citizens not being responsible for their own healthcare (oh wait!) or why the bottom 50% ...

    Continue Reading...
  • 09 Aug 2010

    A bit of inspiration

    I'm back from my last break of the summer and thought I'd share this quote I came across for a bit of inspiration:"A successful life is one that is lived through understanding and pursuing one's own path, not chasing after the dreams of others." -- Chin-Ning ChuThis reminds me of another great quote which says "If you don't have goals for yourself you're doomed forever to achieve the goals of ...

    Continue Reading...
  • 29 Jul 2010

    Neat demo of XSS on Facebook

    Here's an informative video and accompanying article by the folks at Acunetix showing the exploitation of XSS on Facebook. It demonstrates how XSS can not only be made into a serious flaw but also how it's carried out in the background without the user ever knowing about it....

    Continue Reading...
  • 21 Jul 2010

    Good Web application security resource

    In typical monster corporation style, Hewlett-Packard's Web site is painfully difficult to browse around, much less find what you're looking for when it comes to, well, pretty much anything. There is an exception however that benefits all of us in information security. It's HP's Application Security Center Resource Library. It's chock full of goodies from HP (and former SPI Dynamics) engineers, developers, and Web security evangelists.In addition to more recent ...

    Continue Reading...
  • 20 Jul 2010

    Sometimes it’s the little things that’ll get you

    If you're like me you've likely experienced in your daily life how something seemingly innocuous or too simple can create a big problem. Here's a new piece I wrote where I talk about this issue with regards to Web security:Web security oversights: Don’t overlook the “small” stuffWith information security there's usually no need to sweat the small stuff....just don't overlook it altogether!...

    Continue Reading...
  • 19 Jul 2010

    Lessons learned & reminded of this past week

    After taking this past week off to be with my family during my mother's passing I'm back to work this week. I wanted to thank each and every one of you who reached out and sent cards and kind words to me during this tough time. It really meant a lot.There's one thing I learned this past week. It's that no matter how much you think you're prepared, how much ...

    Continue Reading...
  • 12 Jul 2010

    A joyous announcement

    Early this morning my mother, Linda Parks Beaver, left this earth and joined the angels. Her fight with cancer is over. Her pain is over. Her suffering is over. She's now resting in peace. God bless her soul.Many heartfelt thanks to the support and kind words so many of you have given me this year. And thanks so much to my clients and business colleagues who've been so understanding and ...

    Continue Reading...
  • 09 Jul 2010

    The reactive nature of policies that people ignore

    I got stuck in a traffic jam while passing through the famous and lovely town of Kennesaw, GA yesterday because of this unattentive truck driver trying to cross a raised railroad crossing:I wonder what part of the No Trucks sign he didn't understand. There's another sign out of the frame that warns truckers of a $1,000 fine if they cross there. Ouch!This situation can be compared to the disconnected and ...

    Continue Reading...