Interesting article on .NET code Security
Safety in Windows: Manage Access to Windows Objects with ACLs and the .NET Framework -- MSDN Magazine, November 2004
Interesting article on the code security features in .NET 2..
Safety in Windows: Manage Access to Windows Objects with ACLs and the .NET Framework -- MSDN Magazine, November 2004
Interesting article on the code security features in .NET 2..
there've been a couple of sites pointing in the direction of what looks like an interesting security publiscation Security Journal
Theere's a very interesting post over at Dana Epp's ramblings at the Sanctuary : B.C Privacy Commissioner says the USA Patriot Act violates privacy laws
I think one very interesting thing which this action may stir up, is given the apparent dichotomy between US privacy laws and the EU Data Protection Directive, why hasn't more action been taken by the various european data protection commissioners to ensure that data relating to EU citizens is properly handled when in the US. Right now the guidelines (at least what I've seen of them) seem fairly vague and not really in keeping with the level of rigour that the rest of the act's provisions have...
Over at the Microsoft Security Guidance Center, there's an interesting looking list of Microsoft security documents for free download (unfortunately to get the PDF's you need to register and give some information that seems pretty unrelated to the documents like your address)
Found a cople of links which give lots of useful information on windows processes like the detail of what each does. links here and here .
Of course you should always be cautious about assuming that just 'cause a process has a given name that it will do what is contained in lists like this, as it isn't too hard to create a binary with any given name, however useful info. all the same.
Here's an interesting questionnaire published by the world bank as an assessment methodology for organisational security.
I've not had a chance to go all the way through it in detail, but it looks like it's got some interesting ideas in it. However one thing that I'm not too keen on in it so far is the section structure. they seem to have sections at very different levels of detail. For example one section for authentication/access control, quite a large area to cover and then one specifically for active content control for Internet access, which is a very specific area to cover!
An interesting blog entry on Locking Down The Obvious: USB
I think it's a point well made. Essentially companies need to look at USB ports in the same way they look at CD-ROM's and floppy drives. If CD's and floppies are locked down then USB ports should be as well... although it is more challenging technologically as USB ports have wider range of functionality than CD-Drives, which makes it more likely that they will need to be enabled.
It also looks like software products are coming into the market to manage this kind of functionality where required. For example Reflex disknet pro looks like an interesting way of controlling access to removable media, including USB keys....
I found an interesting product called GroundWork.
However what was more interesting to me was the advert's they're using to attract customer, which are actively promoting the products open source background
"no proprietary hassles" and "open source flexibility" are 2 of the phrases from the ads.
I'd be interested to know how that approach works out for them, 'cause it's fairly opposed to what a lot of the research firms seem to say about open source, which is that big business finds the open source nature of the software a turn off...
The Great Debates: Pass Phrases vs. Passwords. Part 1 of 3: Security Management - October 2004
Another interesting article on passwords v passphrases
Password vs. Passphrase redux
Interesting article covering passwords and passphrases. I must say that personally I'm not too fond of trying to remember passphrases (I tend to forget how I punctuated them when I originally set them)...
One of the more interesting ways I've heard of for setting passwords was a friend of mine who uses the second letter each word of song lyrics which he's written himself ;op