Security Journal on Ulitzer
How many times have you seen an employee wave on by a customer when the
“security device enclosed” in some item – be it DVD, CD, or clothing
– sets off the alarm at the doors? Just a few weeks ago I heard one young
lady explain the alarm away with “it must have be the CD I bought at the
last place I was at…” This apparently satisfied the young man at the
doors who nodded and turned back to whatever he’d been doing.
All the data the security guy needed to make a determination was there; he
had all the context necessary in which to analyze the situation and make a
determination based upon that information. But he ignored it all. He failed
to leverage all the tools at his disposal and potentially allowed dollars to
walk out the door. In doing so... (more)
Google’s desire to speed up the web via a new protocol is laudable, but the
SPDY protocol would require massive changes across networks to support
ArsTechnica had an interesting article on one of Google’s latest projects,
a new web protocol designed to replace HTTP called SPDY.
SPDY uses a single SSL-encrypted session between a browser and a client, and
then compresses all the request/resp... (more)
One of the biggest threats to data integrity is the introduction of malicious
content via SQLi (SQL Injection) attacks. Traditional database access methods
don’t provide a lot in the way of validating requests and like HTML the
vagaries of SQL allow for myriad ways in which a statement can be constructed
– and thus exploited.
These vagaries, of course, are one factor in the reason why SQL... (more)
Cloud Computing on Ulitzer
With just a few clicks you, too, can create a cloud computing environment.
But if you’re like a lot of organizations, you may not know what to do with
it after that.
The latest version of Ubuntu Server (9.10) includes the Ubuntu Enterprise
Cloud (UEC), which is actually powered by Eucalyptus. The ability to deploy a
“cloud” on any server running Ubuntu is reall... (more)
Cloud computing is, at its core, about using resources in the most
operational and financially efficient manner possible. It’s about spreading
resources around and sharing them to achieve greater scalability with fewer
investments in hardware and software. But what if you aren’t moving to
cloud? Or virtualization? Or perhaps you are, but the benefits won’t be
really seen until you actual... (more)