2007.02.07 Daily Security Reading
by Rodney Campbell on Feb.07, 2007, under Security
Pointers to some interesting tools designed to harden your Apache/PHP environment.
Information security is the process of protecting data from accidental or intentional misuse by persons inside or outside of an organization, including employees, consultants, and yes, the much-feared hacker. A security breach can involve anything from a website defacement to a computer virus, to an employee who inadvertently discloses his password, to a former employee who sabotages a customer database, to corporate spies who find out how many widgets your top customer bought last month.
A Brief Exaplnation of Diffie-Hellman Key Exchange
A cryptographic key exchange method developed by Whitfield Diffie and Martin Hellman in 1976. Also known as the "Diffie-Hellman-Merkle" method and "exponential key agreement," it enables parties at both ends to derive a shared, secret key without ever sending it to each other.
Security is both a feeling and a reality. And they’re not the same.
Kevin Mitnick says his story is the Catch Me if You Can of cyberspace.
Security zone shortcomings – why browsers and websites encourage phishing
For those of you unaware or unfamiliar with browser security zones, the short story is that web sites can be classified into ‘zones’. There’s typically a zone for web sites you explicitly trust (such as your bank), a zone for local/intranet web sites (typical in a work environment), and then an Internet zone for everything else.
Study Finds Web Antifraud Measure Ineffective [pdf]
Internet security experts have long known that simple passwords do not fully defend online bank accounts from determined fraud artists. Now a study suggests that a popular secondary security measure provides little additional protection.