InfoQ

InfoQ

Topic/Tag specific view

Security Content on InfoQ


Latest featured content about Security

The Future of Authentication

Topics
Authentication,
Identity Management,
Security,
Mobile Security

In this IEEE roundtable discussion hosted by guest editors Richard Chow, Markus Jakobsson, and Jesus Molina, the panelists discuss current authentication approaches, how to authenticate users on mobile devices and the future direction of authentication.

News about Security

Future of Cloud Security Assessments: Microsoft Leads with Public Registrations on CSA

Topics
Cloud Security,
Microsoft,
Cloud Computing,
Security,
Companies

Microsoft has registered security assessments for Office 365, Windows Azure and Dynamics CRM for public consumption on the cloud security alliance's security registry, STAR. Microsoft is the first major service provider to register their assessments at a time when security concerns in the public cloud space continue to grow.

Security vulnerabilities with HTML5 (WebSockets)?

Topics
HTML5,
Rich Internet Apps,
HTML,
Web Development,
HTTP,
Markup Languages,
Languages,
W3C,
Programming,
Specifications,
WebSocket,
Security

Lori Macvittie recently raised concerns about WebSockets vulnerabilities to viruses and malware due to the removal of HTTP headers and MIME types. Given other reported security issues with the protocol and implementations, is it time to step back and consider what a world based on WebSockets should look like?

Secure Code Development: A Casualty With Agile?

Topics
Agile,
Security

Agile teams are known to produce reliable and high quality code quickly. However, it is also a fact that pressure to deliver quickly might result in short cut reviews, curtailed testing and lack of attention to secure code. Is secure development as good as wishful thinking with Agile?

Articles about Security

Interview and Book Review: The CERT Oracle Secure Coding Standard for Java

Topics
CERT,
Secure Coding,
Security,
Book Review

"The CERT Oracle Secure Coding Standard for Java" book covers the rules for secure coding using Java programming language and its libraries with the goal to help Java developers eliminate insecure coding practices that can lead to vulnerable code. InfoQ spoke with book authors about how the security rules discussed in the book compare to other security coding frameworks.

Software Engineering Meets Services and Cloud Computing

Topics
SOA,
Cloud Adoption,
Cloud Security,
Architecture,
Enterprise Architecture,
Security,
Cloud Computing,
SOA Adoption

In this IEEE article, authors Stephen Yau and Ho An talk about application development using service-oriented architecture and cloud computing technologies. They also discuss application development challenges like security in a multi-tenant environment, quality-of-service monitoring, and mobile computing.

Regulatory Compliant Cloud Computing: Rethinking web application architectures for the cloud

Topics
Cloud Security,
Security,
Cloud Computing,
Web Applications

Not all data is sensitive and hence an equal and balanced investment in securing all data categories is not justified. This article presents an architecture that leverages cloud-computing, cloud-storage and enterprise key-management Infrastructure(EKMI) to lower costs while complying to data-security regulations.

Presentations about Security

Lock-free Algorithms

Topics
Intel,
QCon London 2012,
SOA Platforms,
Cloud Security,
Companies,
QCon,
Performance Tuning,
Concurrency,
SOA,
Cloud Computing,
Security,
Conferences,
Performance & Scalability,
Memory,
Programming,
Architecture,
Enterprise Architecture,
Hardware

Martin Thompson and Michael Barker explain how Intel x86_64 processors and their memory model work along with low-level techniques that help creating lock-free software.

Who are You? Who am I? Who is Anybody?

Topics
OAuth,
OpenID,
GOTO 2011,
Authorization,
HTTP,
Identity Management,
REST,
W3C,
GOTO Conference,
Security,
Enterprise Architecture,
Conferences,
Architecture,
Specifications,
Enterprise,
Internet

Paul Downey talks on the current status of identity management on the web covering cross-site challenges, REST, HTTPS, Open ID, all in the context of enterprise architecture.

Interviews about Security

Future of Web Application Security, with Tyler Close

Topics
HTML 5,
HTML5,
HTML,
Javascript,
Rich Internet Apps,
Web Development,
Dynamic Languages,
Markup Languages,
QCon San Francisco 2010,
Web 2.0,
Languages,
QCon,
EcmaScript 5,
Enterprise Architecture,
Programming,
Architecture,
Security,
Conferences,
Caja

As web applications have evolved away from the old client-server model, so have the security threads. In this interview Tyler Close talks about common security challenges and how these are affected by the new HTML5 APIs and Ecmascript 5.

ECMAScript 5, Caja and Retrofitting Security, with Mark S. Miller

Topics
HTML 5,
HTML5,
Javascript,
HTML,
Rich Internet Apps,
Dynamic Languages,
Web Development,
Markup Languages,
QCon San Francisco 2010,
Languages,
QCon,
Architecture,
CORBA,
Security,
Programming,
EcmaScript 5,
Conferences,
Scheme,
Caja,
Distributed Programming

Mark S. Miller talks about the security considerations of JavaScript and how they are dealt with in ECMAScript 5 and the Caja project. He also mentions issues that have to do with HTML5 and compares the security characteristics of other languages like Java and Scheme.

Books about Security

Identity Management on a Shoestring

Topics
Java,
Languages,
Identity Management,
Programming,
Security,
Enterprise

The authors of this book share their experience and lessons learned while building an enterprise-wide Identity and Access Management system using an architectural approach called LIMA.