Webmaniacs: Dean Saxe on Security
Yesterday, Foundstone security consultant Dean Saxe gave a great talk on web application security. Dean covered well-known security vulnerabilities like SQL injection and XSS attacks, and he covered less well-known issues like man-in-the-middle SSL certificate attacks that could expose users to hacks on a seemingly secure site.
Software developers need to know about these issues so they can learn to build applications with a focus on security. Business users need to know about these issues so they can understand potential threats to their businesses.
Security is a set of trade-offs based on risk level and risk tolerance, and everyone concerned should understand the risks in their applications.

There are no comments for this entry.
[Add Comment]