Kahomono - Still Lucky After All These Years

Random musings on whatever catches my attention that day

David F

We Are Secure Website Developers

We website developers put up with a lot from those security folks.  We're constantly hearing them nag us to do boring things like scrub inputs to prevent SQL injection flaws.  Enforce up-to-date encryption standards.  Quit putting auth tokens into URLs.  All of these things would…

Continue reading...
David F

Biometrics Are NOT Passwords, Dammit!

Today in Stupid Extensions of Biometric Authentication: this item from Sophos. Brainprints will apparently be the new fingerprints. Here is what the press (and from the looks of it, half the security industry) seems unable or unwilling to get: you cannot change your biometrics. You…

Continue reading...