Tag Archives: security

Why Use the Principle of Least Privilege?

This editorial was originally published on April 12, 2011. It is being re-run as Steve is away on vacation. SQL Injection is not the fault of the SQL Server. Brian Kelley pointed that out, and reminded me that SQL Injection isn’t … Continue reading

Posted in Editorial | Tagged | Comments Off on Why Use the Principle of Least Privilege?

Correct Old Mistakes

I ran across this piece on the VTech hack that recently occurred. It’s almost a classic example of what not to do in data storage. You can read the piece, and also look at Troy Hunt’s analysis, but clearly we can … Continue reading

Posted in Editorial | Tagged , | Comments Off on Correct Old Mistakes

The $90,000 Laptop

A hospital got the opportunity to pay $90k for a lost laptop. There’s no excuse for this. If you have a Windows laptop, enable bitlocker today. If you have OSX, setup FileVault. If you’re on Linux, choose dm_crypt or something else. Go ahead, get that … Continue reading

Posted in Editorial | Tagged , | Comments Off on The $90,000 Laptop

Security Decisions

How many of you have written code that results in a security issue or data breach? It’s possible many of you have, but are unaware of the issues. I’m sure a few of you have been hacked, have had to … Continue reading

Posted in Editorial | Tagged , | Comments Off on Security Decisions