|
|
| (61 intermediate revisions by 5 users not shown) |
| Line 1: |
Line 1: |
| − | ; '''Aug 30 - [http://www.informationweek.com/hardware/showArticle.jhtml?articleID=192500179&subSection=Servers Web apps less secure...wait no, more secure]'''
| + | <IfLanguage Is="en"> |
| − | : "Web applications tend to be written less tightly than other applications," says Alan Paller, director at the SANS Institute...But because the desktop model really isn't any better, and is in some ways worse, "Security will drive people to centralized applications." (There's a peek into Google's security process in this article - verdict: Distributed!)
| + | This news feed is moderated by OWASP and will feature high-quality posts focused on application security that advance the field, provide useful insight, or are useful educational resources. |
| | + | </IfLanguage> |
| | + | <IfLanguage Is="es"> |
| | + | Estas noticias son moderadas por OWASP y mostrarán publicaciónes de alta calidad enfocadas en seguridad de aplicaciones de avanzada, proveen razonamiento profundo o son recursos educativos útiles. |
| | + | </IfLanguage> |
| | | | |
| − | ; '''Aug 29 - [http://www.fcw.com/article95783-08-24-06-Web Personal data exposed on student loan Web site]'''
| + | <owaspfeed/> |
| − | : The U.S. Department of Education has disabled its Direct Loan Servicing System, the online payment feature of its Federal Student Aid site, because of a software glitch that exposed the personal data of 21,000 students who borrowed money from the department, said Education Department spokeswoman Jane Glickman.
| |
| − | | |
| − | ; '''Aug 28 - [http://www.sdtimes.com/article/special-20060815-01.html Secure coding initiatives - Verdict: Don't start with tools]'''
| |
| − | : Tools give a warped perspective on software security. They overemphasize stuff they're good at finding, and completely miss critical flaws. Get your people and process aligned on secure coding, and then it will be easy to see which tools really help you.
| |
| − | | |
| − | ; '''Aug 22 - [http://www.wired.com/news/politics/privacy/1,71622-0.html The privacy debacle hall of shame]'''
| |
| − | : "[The AOL screwup] may have been one of the dumbest privacy debacles of all time, but it certainly wasn't the first. Here are ten other privacy snafus that made the world an unsafer place."
| |
| − | | |
| − | ; '''Aug 22 - [http://www.infoworld.com/article/06/08/16/HNyahoosecurityplug_1.html Yahoo touches application security's third rail - encoding]'''
| |
| − | : "The problem was Yahoo Mail's handling of attachments. By creating an HTML attachment with different encoding schemes, one could have bypassed Yahoo Mail's security filter and executed malicious JavaScript code"
| |
| − | | |
| − | ; [[Application Security News|Older news...]]
| |
This news feed is moderated by OWASP and will feature high-quality posts focused on application security that advance the field, provide useful insight, or are useful educational resources.