Knowledge.

Backblog > Policy

By Mark Stanislav

Another Certificate Authority (CA) Blunder; No Hack Required

The Certificate Authority (CA) system that currently handles how we publicly interact 'securely' with web sites, mail servers, and other services around the world can't catch a break. In the latest black-eye, an Entrust bulletin speaks about how a... Read more

November 4, 2011 Browsers, Compliance, Cryptography, Industry, Policy
By Mark Stanislav

Mitigating the Risks of Poor Web Programming

If you weren't paying attention during the early Summer months this year, you may have missed the overwhelming rate at which web sites were being publicly compromised and mocked. Often, these sites were prone to compromise due to SQL injection and... Read more

October 18, 2011 Application Security, Industry, Policy
By Mark Stanislav

Two-Factor Authentication for MediaWiki with Duo Security

Two-factor authentication can be the difference between a major compromise and just a fleeting annoyance for a company. While there have always been a few multifactor authentication options on the market, they rarely have gone to the lengths that... Read more

October 4, 2011 Application Security, Compliance, Policy, Two-Factor Authentication
By Steve Fuller

Skype Security Risks for the Enterprise, Part 1

Recently, I have had a number of questions from clients about the use of Skype in the Enterprise and the security risks that it presents.  While Skype is not new, I believe this represents exactly the type of question that IT security will be... Read more

August 2, 2010 IM, P2P, Policy, Skype, VOIP