Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Cupertino Code Signing, The Next Generation (Maybe It'll Work)

June 14, 2018 by Marc Handelman in Code Review, Code, Code Signing, Useless Security

via Josh Pitts (a staff engineer at OKTA), and writing on the company blog, comes a well crafted explanatory piece on what he has discovered in the third-party-code-signing Apple Inc. (NasdaqGS: AAPL) debacle. So much for the highly touted (by Apple, that is) gatekeeping within Mac OSX (now known as macOS). Enjoy!

June 14, 2018 /Marc Handelman /Source
Code Review, Code, Code Signing, Useless Security

via the inimitable and funny Daniel Stori at turnoff.us

Daniel Stori's 'Commitland'

April 13, 2018 by Marc Handelman in Code, Code Review, Code Commit, Source Code Control
April 13, 2018 /Marc Handelman
Code, Code Review, Code Commit, Source Code Control

NDC Security, Patricia Aas' 'Secure Programming Practices in C++' →

February 16, 2018 by Marc Handelman in Conferences, Code, Code Review, Education, Information Security, NDC Security, Secure Coding
February 16, 2018 /Marc Handelman
Conferences, Code, Code Review, Education, Information Security, NDC Security, Secure Coding

Fast Times At Grammarly High... →

February 07, 2018 by Marc Handelman in All is Information, Code Review, Code, Data Leakage, Information Security, OpenSAMM, SAMM

Tavis Ormandy (a member of Google’s Project Zero organization) has found, reported and the offending Grammarly code fixed by Grammarly (reportedly by Tavis) in record time). A small bit of advice for Grammarly, and others: Have your code thoroughly examined by systems adhereing to the OpenSAMM or SAMM model. It may save your hocks someday... Today's Must Read over at Graham Clueley's blog. Thanks Graham and Trey!

February 07, 2018 /Marc Handelman
All is Information, Code Review, Code, Data Leakage, Information Security, OpenSAMM, SAMM

Daniel Stori, 'The Last Resort' →

February 02, 2018 by Marc Handelman in Sarcasm, Satire, Code Review, Code, Security Humor

via the eponymous Daniel Stori at turnoff.us!

February 02, 2018 /Marc Handelman
Sarcasm, Satire, Code Review, Code, Security Humor

Infosec Reactions' 'The Docker Security Model' →

August 05, 2017 by Marc Handelman in Code, Cloud Security, Code Review, Docker Security?, Information Security, Cyber Cyber Cyber Cyber

Via the excoratingly humorous mind of aloria. Enjoy,

August 05, 2017 /Marc Handelman
Code, Cloud Security, Code Review, Docker Security?, Information Security, Cyber Cyber Cyber Cyber

BSides London 2017, Nick Smith's 'The State of Crypto APIs' →

July 30, 2017 by Marc Handelman in BSides, Conferences, Information Security, Code, Code Review, API
July 30, 2017 /Marc Handelman
BSides, Conferences, Information Security, Code, Code Review, API

Laugh It Up, Sport

Flush The Cruft

July 05, 2017 by Marc Handelman in Blatant Stupidity, Cruft, Code Review, Code, Information Security

Along with the latest downsizing, maybe, just maybe, they will clean the security cruft in their Cloud bits as well...

July 05, 2017 /Marc Handelman
Blatant Stupidity, Cruft, Code Review, Code, Information Security

Cartoon by Rudy Lacovara at Angry .Net Developer

Code Failure, Again →

June 29, 2017 by Marc Handelman in Incompetence, Code, Code Review, Blatant Stupidity, Application Security, Information Security

Meanwhile, in incompetent application security testing news, comes this astonishing example of blatant coding stupidity - Microsoft Corporation's (NasdaqGS: MSFT) crack team of questionable-capability-developers (have these people heard of fuzzers?) unleashed a deeply flawed Windows Defender product on millions of customers.

As luck would have it (if you believe in that sort of thing), the product was just patched months after the faulty codebase was wrapped-up-all-pretty-like. The flaw was discovered by security researcher Tavis Ormandy of Google Project Zero fame; his report (and closure of same) on 2017/06/23 is today's proof - at the very least - there are Security Researchers Doing The Right Thing.

June 29, 2017 /Marc Handelman
Incompetence, Code, Code Review, Blatant Stupidity, Application Security, Information Security

BSides Nashville 2017, Ryan Goltry's 'Springtime for Code Reviews' →

May 17, 2017 by Marc Handelman in All is Information, BSides, Bugs, Code, Information Security, Code Review
May 17, 2017 /Marc Handelman
All is Information, BSides, Bugs, Code, Information Security, Code Review