Entering the “Cloud Security” Fray
I’ve not spent a lot of time thinking about this, but here’s how the CloudSec variables move in my mind. The current state of Security…
I’ve not spent a lot of time thinking about this, but here’s how the CloudSec variables move in my mind. The current state of Security…
On the desk next to me sits full, legal copies of the following Microsoft software: Windows Server 2008 Windows Small Business Server 2008 Microsoft SQL…
I’ve been struggling with a problem for a while now. The problem is how to properly display on my site everything online that I create…
Everyone knows the future of technology lies with the individual. One of the ways this will come about is through something I’ve been thinking about…
For anyone interested in Information Security certifications, the GIAC GSE one to keep on your mental radar. It’s a SANS certification (GIAC), but the trick…
The greatest achievement is selflessness. The greatest worth is self-mastery. The greatest quality is seeking to serve others. The greatest precept is continual awareness. The…
On March 25, 2025, NIST released the initial public draft of NIST SP 800-228, “Guidelines for API Protection for Cloud-Native Systems.” The document provides a…
Image from weber.edu As I sit here at my allergist waiting on the all-clear after my shots, I’m thinking about something that’s been bothering me…
Tom Ryder | 10 April 2025 at 14:33 UTC When we wrapped up our biggest-ever webinar, The Future of AppSec: PortSwigger’s Vision, the conversation was…
Earlier today @mubix (Twitter) asked: Here’s my response: SQL Injection is like a telephone operator who has to phonetically relay verbal speech between two people…
This might be obvious to those most familiar with CSRF and Clickjacking, but for those just getting a handle on it, here’s a short explanation…
It’s not that their logical arguments are slightly more emotional than democratic logical arguments; they’re actually purposely avoiding logic altogether. Emotion is simply far more…