Security News


Q&A: A look at static binary analysis and better app security

ADT's Programmers Report occasionally looks at security issues from the point of view of source code analysis and better coding practices. We recently met with Chris Wysopal, vice president of R&D for @stake Inc., and thought he had a different take on this issue. What follows are excerpts from an e-mail interview.

The Security Cycle

A recent security vulnerability suggests that maybe the once a month Microsoft patch cycle wasn't such a good idea after all.

Briefing: Fortify Software

Fortify Software offers a high-end static analysis tool set dedicated to checking security issues.

All That JAAS

JAAS is based on the Pluggable Authentication Modules model and provides authentication and authorization services. Check out its many security benefits for Java applications.

At TechEd: Longhorn can wait: Security patch for XP is priority

Microsoft is urging developers working on or maintaining applications running on Windows XP to get up to speed on Service Pack 2 (SP2), currently a Release Candidate 1 (RC1).

WS-I Security Spec set for public comment

The Web Services Interoperability (WS-I) Organization has released the working-group draft of its Basic Security Profile for public comment.

The danger of the magpie developer

There are lots of ways to think about good software. Is the balance seriously off in recent years?

Security steps for developers

Don't leave application security for tomorrow.

Gartner says budget for Sasser, other worms raising costs

Malicious exploitations of Windows vulnerabilities have become such a common occurrence that Gartner is advising its Windows-using customers to plan for them in their budgets.

Authors provide black-hat insights into security

Since 1996, security guru Dr. Gary McGraw has been admonishing software developers to consider threats and vulnerabilities early in the development cycle. For attackers, it's all about getting to exploitable code, McGraw believes, which ultimately puts the security onus on programmers.

Review: CAS/Tester

CAS/Tester is an innovative product for the .NET developer that shows how your code will react under a variety of security limitations.

HP extends 'Adaptive Enterprise' with TruLogica buy

Hewlett-Packard (HP) Co. last week signed a definitive agreement to buy TruLogica, a Dallas-based provider of identity management software. HP plans to integrate the privately owned company's ID management technology into its OpenView Select Access software to form "a complete federated identity management offering."

The shifting sands of Windows

Windows XP Service Pack 2 is coming. Are you ready to rewrite your applications...again?

Sanctum and Mercury integrate security, QA tools

Web application security software vendor Sanctum Inc., Santa Clara, Calif., has announced a partnership with Sunnyvale, Calif.-based Mercury Interactive Corp. to integrate security testing tools into the QA environment.

Of Money, Information, and Bugs

Microsoft is offering a bounty for writers of malicious code. Maybe they should take some of that money and spend it internally.

IBM reaches security 'checkpoint'; champions SOA

Announcement of new support for Web services security across IBM's WebSphere infrastructure and Tivoli identity management middleware.

Pervasive tightens data security

New versions of three products address data availability, accountability and integrity without having to write additional code.

BEA launches third phase of security plan

Launch of BEA WebLogic Enterprise Security (WLES) first new product resulting from February acquisition of CrossLogix.

CEO complacency blamed for bug incursion

Analysis of the recent wave of virus attacks.

Managing for Security

For many reasons, enterprise application security is an inefficient and expensive model. Obviously there''s no such thing as a completely secure application, but enterprises must target an acceptable level of risk.