The Case for Supply Chain Integrity

A couple of recent incidents are shedding some light on the complexity of ensuring software code integrity throughout the supply chain.

Continue Reading

A Touch of Reality

After my Aliens v. Code Breaking blog, I came across something by Tom St. Denis (a fellow Canadian who published TomLib and wrote...

Continue Reading

Is tokenization important in a Chip & PIN world?

One of the questions I get asked frequently is how tokenization works in countries that use EMV, commonly known as ‘Chip & PIN’. The dialogue usually...

Continue Reading

Speaking of Security Podcast #179

Click to Download/Listen

Colleges and universities in the US are now the latest target for phishing attacks. This week's Speaking of Security podcast discusses this new trend.

Continue Reading

Are you smarter than a PC?

A lot of hacking is playing with other people, you know, getting them to do strange things.
-Steve Wozniak

The unexamined life is not worth living
-Socrates, Sec 38.

My girlfriend Kathleen (who incidentally wants to start a food review blog with me since we've eaten at some amazing places recently)...

Continue Reading

The CVV Loophole of Credit Card Fraud is Closed for Business

One of the things I like to do when interviewing job candidates is to ask them questions about the world of fraud. I don’t expect them to prove that they’re certified fraudsters when they come in, but it can flesh out many paradigms that the candidates may already have. For example...

Continue Reading

Aliens v. Code Breaking

Last week, Andrea Pellegrini, Valeria Bertacco and Todd Austin published "Fault Based Attack of RSA Authentication" (I'll call it FBARA here for ease of reference) as I was boarding a plane to return from...

Continue Reading

Videos from RSA Conference 2010

Topics: RSA Conference

See what people are saying about this year's RSA Conference.

Continue Reading

RSA FraudAction Research Lab

Blog


Eric Baize: Secure Infrastructure Blog

Blog


Sam Curry

Blog


Todd Graham: Deconstructing Governance, Risk and Compliance

Blog


Dr. Ari Juels

Blog


Shannon Kellogg

Blog


Mischel Kwon

Blog


Uri Rivner

Blog


Paul Stamp: Token Security Guy

Blog

Securing Virtualization Bloggers

Securing Virtualization Blog

Speaking of Security:
Date: