Another look at 3fun’s mistakes, and three lessons we can take back to our mobile AppDev teams.
See the original article here: https://ift.tt/2JHdCyg
Watch more videos on my YouTube channel.
Another look at 3fun’s mistakes, and three lessons we can take back to our mobile AppDev teams.
See the original article here: https://ift.tt/2JHdCyg
Watch more videos on my YouTube channel.
Credential theft from dating websites can lead to credential reuse, social engineering, or extortion. Take the press on 3Fun, which exposed business and governmental leaders. So what can these third-party websites do to protect their users and our organizations?
Watch more videos on my YouTube channel.
When designing security tool UIs, it is crucial we design for people on their worst day. People stressed, hurried, and distracted. Bad example: hotel same-unit washer dryers. Good example: airports.
Watch more videos on my YouTube channel.
Bee2FireDetection was covered on Marketplace Morning Report on 7/29/2019. They do provide technology to forecast, detect, and predict massive fires. Let’s look at their approach to see what gaps exist in today’s security incident response techniques.
Watch more videos on my YouTube channel.
Using Zoom as an example, let’s talk about the challenges of vulnerability management and patch management when one product is bundled with another.
Watch more videos on my YouTube channel.
Two months after BlueKeep, the Windows RDP vulnerability, there are still some 800,000 affected computers on the Internet. That’s according to BitSight’s analysis in July. So how do we handle 0-days and unpatched vulnerabilities?
Watch more videos on my YouTube channel.
DevOps is measured by increasing velocity, by change. Security is measured by reducing risk, by stability. Perhaps we need to embed naysayers within stand-ups, pointing out abuse cases for new functionality in use cases. As an example, the “add a line” feature of the Samsung.com website that led to a Sprint breach.
Watch more videos on my YouTube channel.
It was announced this week that the Zoom meeting software had two 0-day vulnerabilities (CVE-2019–13449, CVE-2019–13450). Putting the hype aside, there are three security lessons that apply to most all software.
Watch more videos on my YouTube channel.
Using Ansible and Hashicorp as an example, a discussion on how to get the initial secret to automation tools which use password vaults.
Watch more videos on my YouTube channel.
Software has eaten the world. Buggy software. Exploitable software. Fireworks provide a timely anecdote on the importance of protecting software.
Watch more videos on my YouTube channel.