November 05, 2008
By Dan Cornell This week I'm in Portugal at the OWASP EU Summit '08. Just after I arrived on Monday I had the opportunity to talk about AJAX security and sprajax to a group of students at the 1 day OWASP event at the University of Algarve. The slide deck was a shortened version of the...
Denim Group, Ltd.
[ Feed -
Focus -
Exclude ]
by
dancornell
at 7:31 AM
May 22, 2008
By Erhan K. The CAPTCHA (a convoluted acronym for "Completely Automated Turing Test To Tell Computers and Humans Apart") has become quite popular in the earlier part of the decade, coinciding with the rise of email spam and script dictionary attacks. The CAPTCHA's original purpose was to a...
Denim Group, Ltd.
[ Feed -
Focus -
Exclude ]
at 2:05 AM
May 01, 2008
By Dan Cornell There has been a rising concern as of late about potential security issues related to backdoor functionality included in processors. This is predominantly a concern about state actors compromising products that are then exported to other nations. Bruce Schneier posted earl...
Denim Group, Ltd.
[ Feed -
Focus -
Exclude ]
at 11:24 AM
April 21, 2008
By Dan Cornell UTSA's Center for Infrastructure Assurance and Security (CIAS) put on the National Collegiate Cyber Defense Competition this weekend and I had the distinct honor of being a White Team member on Sunday. Other Denim Group folks who were also on the White Team at various times duri...
Denim Group, Ltd.
[ Feed -
Focus -
Exclude ]
at 12:01 PM
April 04, 2008
If you are a merchant that processes credit cards, then you are probably already well aware of PCI (Payment Card Industry), but you may not be sure how Web application security fits into the picture. You may also have heard that starting in June 2008, section 6.6 of the rules for PCI compliance will...
IT Professionals
[ Feed -
Focus -
Exclude ]
at 1:40 PM
March 21, 2008
By Dan Cornell Reading through the news I noticed that Barack Obama's passport records were improperly accessed by three contract workers for the State Department. What I thought was interesting was an excerpt toward the end of the article: The officials said that when a prominent person's pas...
Denim Group, Ltd.
[ Feed -
Focus -
Exclude ]
at 7:28 AM
December 19, 2007
By Dan Cornell There has been some hubbub as of late about some ominous involvement of NSA with NIST standards on random number generation - specifically that NSA pushed the DUAL_EC_DRBG algorithm even though it performs relatively slowly and may potentially contain a backdoor. Bruce Schneier says: ...
Denim Group, Ltd.
[ Feed -
Focus -
Exclude ]
at 7:17 AM




