A site devoted to discussing techniques that promote quality and ethical practices in software development.

Sunday, January 24, 2010

Web Security article & tutorial

This is an excellent article on web security providing an excellent tutorial on this topic. This is worth considering:
The problem with Web security is that, as important as it is, it is also very complex.... Fact is, you are part of the problem and don’t know what you did to cause it.

Thursday, January 21, 2010

Cooking your own EllipseCOM

During a conversation with a reader on my blog post, it has come to my attention that I have missed a key piece of information with respect to MIMSX.

In order for one to build one's own aggregation server, apart from following the recipe you also need to use a version of MIMSX that is at least of version 2.2.4.2 or later. Earlier version contains an internal setting bug making it an invalid candidate to aggregate.

Unfortunately, one cannot tell from a COM component's registered attributes or type library if it is supporting aggregation. You need to build the aggregation server to see if you can successfully create the aggregated component and wired up the query interface mechanism.

Also during instantiation, you must create an instance of the aggregation server and then query the interface of IMimsxServer; you do not create an instance of MIMSX.

Tuesday, January 19, 2010

My view on the effectiveness of antivirus software is vindicated

I have always formed the opinion that antivirus is a very ineffective and blunt device in protecting one from being attacked. This is not to say that I am flirting carelessly with danger on the Internet. What I am saying is that there are far better and efficient way to protect oneself than to rely on antivirus software.

Recent attack on Google in China invoked a number of comments and postmortem analysis and one of them has vindicated my view,
nCircle's Storms believes that one "lesson from this breach is that antivirus software really is dead. For quite a while it's been the least effective tool in the IT enterprise security toolset because it's only effective against known malware. It only takes one piece of customized malware to infiltrate your network."

In my e-mails with Kurtz he wasn't as bold about declaring the death of antivirus tools, but he did suggest a new approach as well. "There are technologies like whitelisting--McAfee Application Control, that would have prevented successful exploitation of this zero day and many others--without signatures. Companies really need to start augmenting their blacklisting with whitelisting protection technologies."
Antivirus is often like looking in the rear vision mirror. It is totally useless until its database has been updated.

Fujitsu has slate tablets before even Apple considering it

Fujitsu has released several slate tablets many years before Apple even has considered it. They just did not put an 'i' in front of the slate and did not impose all sorts of constrains on the owner.

Monday, January 18, 2010

App Store?

Many in the blog-space and media seem to have Apple's App Store undue recognition as something new and innovative. What a load of myopic view!

Handango has been selling software for PDA and Smartphone way before iPhone was even on a drawing board.

Thursday, January 14, 2010

How do you secure your .Net Application?

Here is a very comprehensive set of guidelines to show how to secure your .Net application after it has been developed.

Guidelines to develope secure ADO.Net application

This is a very comprehensive set of guidelines in making your ADO.Net secure.
Writing a secure ADO.NET application involves more than avoiding common coding pitfalls such as not validating user input. An application that accesses data has many potential points of failure that an attacker can exploit to retrieve, manipulate, or destroy sensitive data. It is therefore important to understand all aspects of security, from the process of threat modeling during the design phase of your application, to its eventual deployment and ongoing maintenance.

Blog Archive