Security Content on InfoQ
Latest featured content about Security

- Topics
- Authentication,
- Identity Management,
- Security,
- Mobile Security
In this IEEE roundtable discussion hosted by guest editors Richard Chow, Markus Jakobsson, and Jesus Molina, the panelists discuss current authentication approaches, how to authenticate users on mobile devices and the future direction of authentication.
News about Security
- Topics
- Cloud Security,
- Microsoft,
- Cloud Computing,
- Security,
- Companies
Microsoft has registered security assessments for Office 365, Windows Azure and Dynamics CRM for public consumption on the cloud security alliance's security registry, STAR. Microsoft is the first major service provider to register their assessments at a time when security concerns in the public cloud space continue to grow.
- Topics
- HTML5,
- Rich Internet Apps,
- HTML,
- Web Development,
- HTTP,
- Markup Languages,
- Languages,
- W3C,
- Programming,
- Specifications,
- WebSocket,
- Security
Lori Macvittie recently raised concerns about WebSockets vulnerabilities to viruses and malware due to the removal of HTTP headers and MIME types. Given other reported security issues with the protocol and implementations, is it time to step back and consider what a world based on WebSockets should look like?
- Topics
- Agile,
- Security
Agile teams are known to produce reliable and high quality code quickly. However, it is also a fact that pressure to deliver quickly might result in short cut reviews, curtailed testing and lack of attention to secure code. Is secure development as good as wishful thinking with Agile?
Articles about Security

- Topics
- CERT,
- Secure Coding,
- Security,
- Book Review
"The CERT Oracle Secure Coding Standard for Java" book covers the rules for secure coding using Java programming language and its libraries with the goal to help Java developers eliminate insecure coding practices that can lead to vulnerable code. InfoQ spoke with book authors about how the security rules discussed in the book compare to other security coding frameworks.

- Topics
- SOA,
- Cloud Adoption,
- Cloud Security,
- Architecture,
- Enterprise Architecture,
- Security,
- Cloud Computing,
- SOA Adoption
In this IEEE article, authors Stephen Yau and Ho An talk about application development using service-oriented architecture and cloud computing technologies. They also discuss application development challenges like security in a multi-tenant environment, quality-of-service monitoring, and mobile computing.

- Topics
- Cloud Security,
- Security,
- Cloud Computing,
- Web Applications
Not all data is sensitive and hence an equal and balanced investment in securing all data categories is not justified. This article presents an architecture that leverages cloud-computing, cloud-storage and enterprise key-management Infrastructure(EKMI) to lower costs while complying to data-security regulations.
Presentations about Security

- Topics
- Intel,
- QCon London 2012,
- SOA Platforms,
- Cloud Security,
- Companies,
- QCon,
- Performance Tuning,
- Concurrency,
- SOA,
- Cloud Computing,
- Security,
- Conferences,
- Performance & Scalability,
- Memory,
- Programming,
- Architecture,
- Enterprise Architecture,
- Hardware
Martin Thompson and Michael Barker explain how Intel x86_64 processors and their memory model work along with low-level techniques that help creating lock-free software.

- Topics
- OAuth,
- OpenID,
- GOTO 2011,
- Authorization,
- HTTP,
- Identity Management,
- REST,
- W3C,
- GOTO Conference,
- Security,
- Enterprise Architecture,
- Conferences,
- Architecture,
- Specifications,
- Enterprise,
- Internet
Paul Downey talks on the current status of identity management on the web covering cross-site challenges, REST, HTTPS, Open ID, all in the context of enterprise architecture.
Interviews about Security

- Topics
- HTML 5,
- HTML5,
- HTML,
- Javascript,
- Rich Internet Apps,
- Web Development,
- Dynamic Languages,
- Markup Languages,
- QCon San Francisco 2010,
- Web 2.0,
- Languages,
- QCon,
- EcmaScript 5,
- Enterprise Architecture,
- Programming,
- Architecture,
- Security,
- Conferences,
- Caja
As web applications have evolved away from the old client-server model, so have the security threads. In this interview Tyler Close talks about common security challenges and how these are affected by the new HTML5 APIs and Ecmascript 5.

- Topics
- HTML 5,
- HTML5,
- Javascript,
- HTML,
- Rich Internet Apps,
- Dynamic Languages,
- Web Development,
- Markup Languages,
- QCon San Francisco 2010,
- Languages,
- QCon,
- Architecture,
- CORBA,
- Security,
- Programming,
- EcmaScript 5,
- Conferences,
- Scheme,
- Caja,
- Distributed Programming
Mark S. Miller talks about the security considerations of JavaScript and how they are dealt with in ECMAScript 5 and the Caja project. He also mentions issues that have to do with HTML5 and compares the security characteristics of other languages like Java and Scheme.
Books about Security

- Topics
- Java,
- Languages,
- Identity Management,
- Programming,
- Security,
- Enterprise
The authors of this book share their experience and lessons learned while building an enterprise-wide Identity and Access Management system using an architectural approach called LIMA.