August 3, 2011 iSEC Talks at BlackHat 2011 Posted
Blog Right now two iSEC Partners teams are taking the stage at Blackhat USA 2011. The slides are available here:
Aaron Grattafiori;
Alex Stamos;
BJ Orvis;
Paul Youn;
Tom Daniels Keep up with industry trends and the latest breaking news and learn from some of the leading professionals in the information security industry.
August 3, 2011
Blog Right now two iSEC Partners teams are taking the stage at Blackhat USA 2011. The slides are available here:
Aaron Grattafiori;
Alex Stamos;
BJ Orvis;
Paul Youn;
Tom Daniels
April 29, 2011
Blog
The amount of personal data stored online is growing every day. But what if a user needs to do something with that data? Perhaps a user wants to use a photo stored with one web service at another web service that creates prints. Downloading the photo and then uploading it to another site may be too much friction for a user. Many web services are implementing the OAuth protocol to solve the problem.
The OAuth protocol describes a way for a web server to establish a relationship with client services (consumers). Consumers can then ask users for authorization to access their information maintained by the web server. The user authenticates directly to the web server and never reveals their actual credentials to the consumer.
Although the OAuth protocol provides a great authorization framework, a lot of specifics are left to the implementer. In an effort to create a safer user-experience, I have written a paper that provides recommendations for the web server and consumer that can be used to protect user data and reduce the amount of trust required between parties so that more relationships can be safely formed. Even if you can’t implement all of the recommendations, this paper will help you understand your risks.
April 25, 2011 Here are the slides for the talk Don Bailey gave last Friday at SOURCE Boston, “Tinker, Tailor, Soldier, A-GPS: How Cost Turns Security Devices Into Weapons.”
April 22, 2011 Here are the slides for the talk David Thiel gave yesterday at SOURCE Boston, “Secure Development on iOS: Advice for developers and penetration testers.”
April 20, 2011
Blog We have just posted Dan Guido’s slides from his SOURCE Boston talk, “The Exploit Intelligence Project”.
Dan Guido;
Presentation;
SOURCE