May 8th, 2008
Source: InformationWeek
- Vendors do not need to be ahead of the hackers; they only need to be ahead of the buyer
- Antivirus certifications do not require or test for Trojans
- There is no perimeter
- Risk assessment threatens vendors
- There’s more to risk than weak software
- Compliance threatens security
- Vendor blind spots allowed for the “Storm” botnet
- Security has grown well past the “do it yourself” stage
Tags: Risk
Posted in Computer (電腦), Security | No Comments »
May 8th, 2008
If you’re a good hacker, everyone knows your name
If you’re a great hacker, no one knows who you are
Source: Hackers Wisdom
Posted in Computer (電腦), Security | No Comments »
May 8th, 2008
Source: Five basic mistakes of security policy
1. Not having a policy
2. Not updating the policy
3. Not tracking compliance with the policy
4. Having a “tech only” policy
5. Having a large, unwieldy policy
Posted in Computer (電腦), Security | No Comments »
May 7th, 2008
Security is a process, not a product
by Bruce Schneier
Posted in Well-known saying (名言名句) | No Comments »
May 7th, 2008
One small step for man, one giant leap for hackers.
Hahahaha
Posted in Well-known saying (名言名句) | 1 Comment »
May 1st, 2008
聽說這句是「Google」面試考題,出現情況是在伺服器(server)當掉時,出現的畫面。
Read the rest of this entry »
Tags: Donut, Google
Posted in Funny, Recreation (休閒生活) | No Comments »
April 25th, 2008
Source
簡單說 Availability 看的是 Time Lost ( Uptime / Total time );而 Reliability 是看時間內 failures 的次數。
Tags: Availability, Reliability
Posted in Computer (電腦), Others Computer | No Comments »
April 22nd, 2008
RSA 是目前全球最大的資安會議。 RSA 是由三位密碼學大師的名字於 1977年所設計的(Ron Rivest, Adi Shamir, and Leonard Adleman),也是當今很出名的演算法名稱。
在今年(2008),RSA其中一人,在會議上指出三大重點:
- 優秀密碼學設計至今仍然牢不可破
- 但 Web security 卻很糟
- 根本不能相信 software 的安全性
其他的議程有對 Web/software security 很糟的議題有所回應,說明為何在此兩個領域很難做到。因此,今年的小小結論將會是 Data-Centric Security(以資料為主的資安),也就是加密重要資料(如客戶資料)。如此即使被突破而偷走資料,也不至於在短時間內被破解。
Tags: RSA
Posted in Computer (電腦) | No Comments »
April 22nd, 2008
1996 - XSS
1998 - SQL injection
其它的忘了,有資料再補。
Tags: SQL Injection, XSS
Posted in Computer (電腦) | No Comments »
April 22nd, 2008
Tags: PCI
Posted in Computer (電腦), Security | No Comments »