<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cybersecurity on Rietta Cybersecurity</title>
    <link>https://rietta.com/categories/cybersecurity/</link>
    <description>Recent content in Cybersecurity on Rietta Cybersecurity</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>1999-2026 Rietta Inc. All Rights Reserved.</copyright>
    <atom:link href="https://rietta.com/categories/cybersecurity/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Government Rails Site Hit Hours After CVE Patch</title>
      <link>https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/</link>
      <pubDate>Fri, 04 Sep 2026 12:55:00 -0400</pubDate>
      <guid>https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/</guid>
      <description>After hours on Wednesday, July 29, 2026, Rietta executed our emergency hotfix procedure across our entire client base for sites impacted by a severe remote code execution vulnerability in ActiveStorage, a component of Ruby on Rails 8 and newer. We worked off the initial GitHub Security Advisory, published the same day the patch shipped. Ethiack, one of the research teams that discovered the flaw, dubbed it KindaRails2Shell (CVE-2026-66066) in their initial disclosure post that same day, July 29th, with a full technical deep-dive following the next day on July 30th.</description>
    </item>
    <item>
      <title>Generate OpenSSL Elliptic Curve Key Pair from the Command Line</title>
      <link>https://rietta.com/blog/openssl-generating-ec-key-from-command/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-generating-ec-key-from-command/</guid>
      <description>&lt;p&gt;Back in 2012, I wrote &lt;a href=&#34;https://rietta.com/blog/openssl-generating-rsa-key-from-command/&#34;&gt;Generate OpenSSL RSA Key Pair from the Command Line&lt;/a&gt;, which has gone on to become the single most-visited post on this entire blog. Fourteen years is a long run for a command-line tutorial, and RSA hasn&amp;rsquo;t gone anywhere. But if you&amp;rsquo;re generating a new key pair in 2026, I&amp;rsquo;d point you toward elliptic curve cryptography (ECC) instead of a bigger RSA key.&lt;/p&gt;</description>
    </item>
    <item>
      <title>22 Years on Firefox, and Today I&#39;m Finally All In</title>
      <link>https://rietta.com/blog/firefox-in-2026/</link>
      <pubDate>Sat, 15 Aug 2026 21:35:00 -0400</pubDate>
      <guid>https://rietta.com/blog/firefox-in-2026/</guid>
      <description>I have now committed to being all in with Firefox as my primary browser in 2026, after splitting time for the last ten years between Google Chrome as my work browser and Firefox as my testing and personal daily driver. What kept me split that long wasn&amp;rsquo;t any loyalty to Chrome, it was dread of the reorganization: two decades of bookmarks I never wanted to touch. What finally forced the issue was Google killing the ad blocker I depended on for security, combined with a passkey future closing in fast enough that staying split between two ecosystems stopped being an option.</description>
    </item>
    <item>
      <title>Threat Modeling for ADA/WCAG Compliance</title>
      <link>https://rietta.com/blog/threat-modeling-ada-wcag-compliance/</link>
      <pubDate>Tue, 28 Jul 2026 14:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/threat-modeling-ada-wcag-compliance/</guid>
      <description>Why Accessibility Belongs in Your Threat Model Most organizations treat digital accessibility as a content problem: someone finds a missing alt tag, fixes it, and moves on. I think that&amp;rsquo;s the wrong frame entirely. Digital accessibility is an organizational risk and governance gap, and once you see it that way, the right tool for the job isn&amp;rsquo;t a content checklist. It&amp;rsquo;s the same discipline we already use for application security: threat modeling and continuous technical monitoring.</description>
    </item>
    <item>
      <title>The Five Pillars of Information Security (And Why We Audit Accessibility)</title>
      <link>https://rietta.com/blog/five-pillars-infosec-ada-accessibility/</link>
      <pubDate>Sat, 25 Jul 2026 15:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/five-pillars-infosec-ada-accessibility/</guid>
      <description>Rietta is a cybersecurity firm. So why have the last three posts on this blog been about missing document titles, undefined languages, and metadata fields in government PDFs? My reasoning comes down to this: accessibility failures are security failures, specifically, they&amp;rsquo;re availability failures, and detecting them at scale is exactly the discipline our industry already practices.&#xA;To explain why, it helps to back up and lay out the actual model we use to reason about security in the first place.</description>
    </item>
    <item>
      <title>The Imminent Funding Lapse of the CVE Database: A Cybersecurity Crisis</title>
      <link>https://rietta.com/blog/cve-program-funding-lapse-national-security/</link>
      <pubDate>Wed, 16 Apr 2025 12:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/cve-program-funding-lapse-national-security/</guid>
      <description>News started breaking yesterday of an imminent funding lapse for the United States government-funded Common Vulnerabilities and Exposures database maintained for the last 25 years under contract with MITRE Corporation. The reporting yesterday included Funding Expires for Key Cyber Vulnerability Database (krebsonsecurity.com) and this lapse has been confirmed by multiple sources CVE program faces swift end after DHS fails to renew contract, leaving security flaw tracking in limbo (csoonline.com) and CVE Program Funding Expires—What It Means And What To Do Next (forbes.</description>
    </item>
    <item>
      <title>Understanding Signal Messaging App Security: Is Encryption Enough?</title>
      <link>https://rietta.com/blog/signal-app-security-is-encryption-enough/</link>
      <pubDate>Fri, 04 Apr 2025 08:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/signal-app-security-is-encryption-enough/</guid>
      <description>In the last few weeks, it has been widely reported that members of the United States&amp;rsquo; National Security Team engaged in certain discussions that reportedly may have contained classified information and included a third party member of the press in the group. This has been publicly disputed by government officials.&#xA;I have avoided engaging in online discussion on this topic until the full details come out. Also as a cybersecurity professional I did not have anything particular to add to the narrative in real time.</description>
    </item>
    <item>
      <title>UUID as a secure API token for API RESTful endpoints? (Video)</title>
      <link>https://rietta.com/blog/uuid-api-security-token-video/</link>
      <pubDate>Tue, 14 May 2024 22:36:00 -0500</pubDate>
      <guid>https://rietta.com/blog/uuid-api-security-token-video/</guid>
      <description>In this video excert, I discussed the the role of the UUID as an API token and how to improve the security of an application when using them.&#xA;Specifically, the RFC 4122, Section 6 Security Considerations, cautions developers to &amp;ldquo;not assume that UUIDs are hard to guess; they should not be used as security capabilities (identifiers whose mere possession grants access), for example. A predictable random number source will exacerbate the situation.</description>
    </item>
    <item>
      <title>An Honest Conversation About Cyber Security (Video)</title>
      <link>https://rietta.com/blog/conversation-about-cyber-security/</link>
      <pubDate>Tue, 28 Nov 2023 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/conversation-about-cyber-security/</guid>
      <description>I recently sat down with Jeremy Duvall of 7Factor Software to discuss Cyber Security and application developers. We talk about the ins and outs of modern cyber security practices, weaknesses, how the development environment has changed and stayed the same over twenty years, and what small companies can do to impact improve security!</description>
    </item>
    <item>
      <title>Prioritizing cybersecurity (Pluralsight)</title>
      <link>https://rietta.com/blog/prioritizing-cybersecurity/</link>
      <pubDate>Wed, 27 Sep 2023 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/prioritizing-cybersecurity/</guid>
      <description>Vikas Rewani and I collaborated on an article about Prioritizing Cybersecurity for the Pluralsight blog last year.&#xA;I want to highlight here one of the topics that was discussed in the article, the importance of breaking down silos:&#xA;The structure and siloing of a large enterprise organization can thwart security efforts. For instance, security often lives under the IT umbrella, while software development is part of R&amp;amp;D.&#xA;Further, organizations may utilize a combination of technical resources—in-house, outsourced, onshore and offshore—all reporting to different people, who have varying business goals.</description>
    </item>
    <item>
      <title>You Can be the Victim of a Cybersecurity Attack: Do Your Part. #BeCyberSmart.</title>
      <link>https://rietta.com/blog/you-can-be-the-victim-cybersecurity-awareness-month/</link>
      <pubDate>Fri, 01 Oct 2021 11:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/you-can-be-the-victim-cybersecurity-awareness-month/</guid>
      <description>This week is the &amp;ldquo;Be Cyber Smart&amp;rdquo; week of Cybersecurity Awareness Month.&#xA;The first thing you need to realize is that you can be a victim of a cyber security attack. It&amp;rsquo;s human nature to assume that an incident cannot happen to you, that you are not a big enough target, that the bad guys are going to go after someone else. When you run Internet connected software this thinking is the path to disaster.</description>
    </item>
    <item>
      <title>Paying Ransomware is Harmful: Invest in proactive defense instead.</title>
      <link>https://rietta.com/blog/paying-ransom-harmful-millions-for-defense/</link>
      <pubDate>Wed, 07 Jul 2021 11:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/paying-ransom-harmful-millions-for-defense/</guid>
      <description>The headline of the day is Ransomware Hackers Demand $70 Million In Bitcoin, Claim Massive U.S. Attack As Biden Investigates Possible Russian Involvement (forbes.com). This is only the latest in a string of increasing attacks both in number of victims and the size of ransom demands. It shows the weakness in the software and services supply chain used for IT management and more. The lessons will come to light as more details emerge.</description>
    </item>
    <item>
      <title>Top 5 Cyber Security Self-Defense Tips for Businesses with Custom Applications</title>
      <link>https://rietta.com/blog/top-5-cyber-security-self-defense-tips/</link>
      <pubDate>Wed, 30 Jun 2021 12:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/top-5-cyber-security-self-defense-tips/</guid>
      <description>Working in cybersecurity tends to create a &amp;ldquo;worst-case-scenario&amp;rdquo; mindset. Which means I&amp;rsquo;m really fun at parties. After people find out what I do for a living, a typical reaction would be to discuss some recent security breach in the news followed by a question about how (or why) does this keep happening. This question is often followed by a question of how to respond to ransomware, but that is a topic for another blog post.</description>
    </item>
    <item>
      <title>Cross-site Scripting Injection Attacks Using SVG Images</title>
      <link>https://rietta.com/blog/svg-xss-injection-attacks/</link>
      <pubDate>Tue, 25 May 2021 11:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/svg-xss-injection-attacks/</guid>
      <description>Cross-site scripting attacks, like all injection attacks, are a perennial favorite of attackers worldwide. These attacks focus on injecting malicious JavaScript that targets users of the website instead of the server itself. The most common way of performing a cross-site scripting attack is to leverage a user input field that is seen by others, such as a comment on a video that does not properly sanitize input.&#xA;The simplest way to create a cross-site scripting payload is to embed hostile JavaScript between two script tags.</description>
    </item>
    <item>
      <title>Lava lamps providing randomness for security!</title>
      <link>https://rietta.com/blog/lava-lamps-for-security/</link>
      <pubDate>Tue, 11 May 2021 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/lava-lamps-for-security/</guid>
      <description>Clients and new co-workers often ask me about my lava lamp that I keep in my home office in view of the web cam. Besides being cool, I do this intentionally to celebrate the lava lamp&amp;rsquo;s role in keeping the Internet secure!&#xA;According to Wikipedia, &amp;ldquo;Lavarand was a hardware random number generator designed by Silicon Graphics that worked by taking pictures of the patterns made by the floating material in lava lamps, extracting random data from the pictures, and using the result to seed a pseudorandom number generator&amp;rdquo; (Lavarand).</description>
    </item>
    <item>
      <title>Testing: Your Future Self Will Thank You</title>
      <link>https://rietta.com/blog/testing-your-future-self-will-thank-you/</link>
      <pubDate>Tue, 27 Apr 2021 11:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/testing-your-future-self-will-thank-you/</guid>
      <description>Testing isn’t always a glamorous endeavor. It’s akin to confirming someone else’s scientific results: needed, and not noteworthy. But I would argue that in fact, testing can be as important as the code we write.&#xA;Testing serves as a great way to get a good view of the overall health of your application. It is not the magic solution to any issue, but is instead a tool used to find and fix weak code.</description>
    </item>
    <item>
      <title>Practical APPSEC starts with people first, processes second, and technology last</title>
      <link>https://rietta.com/blog/practical-security-people-first/</link>
      <pubDate>Thu, 04 Feb 2021 11:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/practical-security-people-first/</guid>
      <description>Application Security (APPSEC) is the subset of Information Security that is focused on hardening software to protect humans, be it customers, partners, and the public at large. The software itself must be designed to be more secure because security cannot effectively be bolted on at the end of the development process. It&amp;rsquo;s an old time idea, but security is about people, processes, and technology in that order. Let&amp;rsquo;s look at how a web application goes astray by people&amp;rsquo;s knowledge, incentives, and the working of the development process.</description>
    </item>
    <item>
      <title>The convergence of Ruby on Rails and #AppSec Podcast Appearance</title>
      <link>https://rietta.com/blog/ruby-on-rails-and-appsec/</link>
      <pubDate>Wed, 07 Oct 2020 08:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/ruby-on-rails-and-appsec/</guid>
      <description>I recently appeared as a guest on the Application Security Podcast with Chris Romeo to talk about the convergence of Ruby on Rails and #AppSec.&#xA;The discussion covered a range of topics including secure coding with Ruby on Rails, RoR vs other languages and culture, the importance of CI/CD, and more.&#xA;Check it out!</description>
    </item>
    <item>
      <title>When Georgia was on the Brink of Outlawing Critical Computer Security Research, the Governor&#39;s Office Met with Me, and Vetoed it!</title>
      <link>https://rietta.com/blog/georgia-cyber-security-veto/</link>
      <pubDate>Sat, 25 Apr 2020 17:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/georgia-cyber-security-veto/</guid>
      <description>Two years ago today, on April 25, 2018, I shared on Facebook that&#xA;at my request, the [Georgia] Governor&amp;rsquo;s office met with me and 8 others from the information security industry that included security professionals, executives, board members and a venture capitalist. We were joined by an elected Republican and Democrat member of the General Assembly. They didn&amp;rsquo;t have to take the meeting and I was very grateful for the opportunity to speak through the issues with SB 315 with them.</description>
    </item>
    <item>
      <title>Dependency Security and Hacking Rails with Jason Swett (Podcast)</title>
      <link>https://rietta.com/blog/dependency-security-and-hacking-rails-with-jason/</link>
      <pubDate>Tue, 21 Apr 2020 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/dependency-security-and-hacking-rails-with-jason/</guid>
      <description>I recently appeared in Episode 41 of The Rails with Jason Podcast for a wide-ranging discussion about Ruby on Rails security, the security value of keeping gems updated, the security risk of infrequent deployment, state-sponsored hacking, and practical tips on how to protect your organization.&#xA;Give it a listen to better understand some common ways that production projects go south in their security practices and why solid test coverage, regular reviews of your dependencies, and frequent deploys help make you much more secure.</description>
    </item>
    <item>
      <title>Snowfroc 2020 - Application Security and Development</title>
      <link>https://rietta.com/blog/snowfroc-2020-appsec-takeaways/</link>
      <pubDate>Wed, 01 Apr 2020 06:00:00 -0600</pubDate>
      <guid>https://rietta.com/blog/snowfroc-2020-appsec-takeaways/</guid>
      <description>I recently attended the Snowfroc conference that took place in Denver early this month. There were a number of talks about creating secure software in the context of a security team working with a development team from the outside, including one by our founder, Frank Rietta. I&amp;rsquo;ll be doing my best to condense the ideas from many of these talks into a single source. My sources are the following talks: Patch Production Now by Frank Rietta, Why Appsec is Hard for Devs by Scott Gerlach, and Climbing AppSec Mountains by Adam Schaal.</description>
    </item>
    <item>
      <title>Dependency Management and Security</title>
      <link>https://rietta.com/blog/dependency-management-and-security/</link>
      <pubDate>Thu, 06 Feb 2020 10:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/dependency-management-and-security/</guid>
      <description>Security in web development touches all avenues of the field from requests, session hijacking, SQL injections and many more mentioned on the Open Web Application Security Project (OWASP). Many buffers now exist between developers and situations where malicious users can capitalize on dependency management oversights. Hackers are resourceful in their exploits of known (and sometimes unknown) vulnerabilities.&#xA;As one of our developers Rob mentions on his blog post, &amp;ldquo;A Newer Dev&amp;rsquo;s Perspective on Learning OWASP&amp;rdquo;,</description>
    </item>
    <item>
      <title>A Newer Dev&#39;s Perspective on Learning OWASP</title>
      <link>https://rietta.com/blog/new-dev-owasp-perspective/</link>
      <pubDate>Tue, 21 Jan 2020 11:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/new-dev-owasp-perspective/</guid>
      <description>After developing a firm understanding of OOP, TDD, and Rails, I found myself conflicted about all the directions I could go with my learning. I&amp;rsquo;ve always understood security was important, but didn&amp;rsquo;t venture very far beyond general best practices. As a developer, especially one who works with databases and servers, this is a naive and potentially dangerous perspective. The commercial (and sometimes hobby) code we write often affects real human lives and livelihoods, so considering potential exploitation of our work is essential.</description>
    </item>
    <item>
      <title>AppSec as a Requirement in the Development Process</title>
      <link>https://rietta.com/blog/appsec-dev-process-requirement/</link>
      <pubDate>Mon, 13 Jan 2020 09:30:00 -0500</pubDate>
      <guid>https://rietta.com/blog/appsec-dev-process-requirement/</guid>
      <description>We&amp;rsquo;re now well underway for the year 2020. People from time-to-time will make predictions about what is to come and when we look back, one has to laugh at how wrong they were. If you had asked me in 2005 if I thought we would be dealing with SQL injection 15 years later in 2020, I would have told you no, it will surely be solved by then. At the time I was still a student at Georgia Tech and wrote on this blog about SQL injection and presented a paper on application layer detection at the ACM South Eastern Conference.</description>
    </item>
    <item>
      <title>Xfinity is Man-in-the-Middle (MITM) Attacking my Internet</title>
      <link>https://rietta.com/blog/comcast-insecure-injection/</link>
      <pubDate>Tue, 29 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/comcast-insecure-injection/</guid>
      <description>I recently moved to Fort Collins, CO. With this move also meant new internet&amp;hellip; Unfortunately, Xfinity (Comcast) is the only ISP available in the area until early next year, so I purchased service through Xfinity. I had heard horror stories from co-workers about Comcast, but after working at a company that makes billing and networking software and hardware for Wireless Internet Service Providers, I was skeptical; everyone seems to hate their ISP.</description>
    </item>
    <item>
      <title>Patch Production Faster with Security-oriented Agile Development Practices</title>
      <link>https://rietta.com/blog/patch-production-faster-with-agile-development/</link>
      <pubDate>Mon, 28 Oct 2019 11:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/patch-production-faster-with-agile-development/</guid>
      <description>Overview All computer security depends on software application security. Some believe that Agile-inspired development methodologies should not be used to implement a Secure Software Development Lifecycle (SSDLC). There are many reasons for this, including experience with poor Agile method implementations which resulted in: software teams who ship very insecure code, teams composed of members with limited security knowledge writing only happy path user stories and tests, and a preference for a top-down approach to security requirements.</description>
    </item>
    <item>
      <title>Ruby Gems Supply Chain Vulnerability</title>
      <link>https://rietta.com/blog/rubygems-supply-chain-vulnerability/</link>
      <pubDate>Fri, 06 Sep 2019 11:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/rubygems-supply-chain-vulnerability/</guid>
      <description>&lt;p&gt;Every Ruby on Rails application depends on Ruby Gems, the third party open source libraries that make development possible. A brand new Ruby on Rails 6 application, with default options, depends upon 75 Gems before the developer makes any customizations to the app! These Gems are produced by volunteer open source maintainers, many of whom are not paid anything to work on open source, and distributed for free via &lt;a href=&#34;https://rubygems.org/&#34;&gt;rubygems.org&lt;/a&gt;. This is a fantastic resource that makes it possible to create so many good Ruby-based applications with minimum effort re-inventing the wheel. However, how is a developer to know the Gems he or she has in a project are in fact safe.&lt;/p&gt;&#xA;&lt;p&gt;There have been malicious backdoors distributed in multiple Gems this year. These supply chain attacks have been detected and remediated by the RubyGems community, but it will happen again. Let&amp;rsquo;s look at the patterns common among the malicious Gems and the how you can go about protecting your own application.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Case for 2FA, Post Rest-client Gem CVE</title>
      <link>https://rietta.com/blog/rest-client-cve/</link>
      <pubDate>Thu, 22 Aug 2019 10:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/rest-client-cve/</guid>
      <description>Most CVEs occur as a result of a oversight in the architecture or mishandling of how libraries may interact with your application. In some cases like what had occurred with the Rest-client gem version 1.6.13, a package maintainer account on https://rubygems.org was hijacked and used to push malicious code that would compromise sensitive credentials for payment manager accounts, database access, repository access, and others that can cause irreparable damages. The hijacker conducted a series of releases - 1.</description>
    </item>
    <item>
      <title>Account Protection Policies to Cover Business Assets</title>
      <link>https://rietta.com/blog/account-protection-policies/</link>
      <pubDate>Thu, 30 May 2019 10:15:00 -0400</pubDate>
      <guid>https://rietta.com/blog/account-protection-policies/</guid>
      <description>&lt;p&gt;The compromise of a staff user account credentials is a critical step in the kill chain of many data breaches. This compromise may be accomplished in many ways, including a staff user falling victim to a:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;em&gt;credential stuffing attack&lt;/em&gt; when email and passwords in outside breaches are used to authenticate with work systems (because people reuse the same passwords frequently)&lt;/li&gt;&#xA;&lt;li&gt;&lt;em&gt;targeted spear-phishing campaign&lt;/em&gt; to intercept valid credentials via a spoofed login form&lt;/li&gt;&#xA;&lt;li&gt;&lt;em&gt;business e-mail compromise&lt;/em&gt; via a convincingly forged e-mail supposedly from a supervisor or the CEO&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;There are a few levels of staff credentials to address, those with access to:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;legitimate business e-mail&lt;/li&gt;&#xA;&lt;li&gt;the administrative portal/customer service via a web interface&lt;/li&gt;&#xA;&lt;li&gt;development resources and testing environments&lt;/li&gt;&#xA;&lt;li&gt;production resources like cloud providers and the domain name configuration&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Traditional information security practice calls for the separation of duties between developers and those with production access. However, often only the most sophisticated, established organizations have the dedicated resources to do that. For everyone else, the developers usually have access to all these resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Restrict Who Can Push to Matching Branches on Github</title>
      <link>https://rietta.com/blog/git-branch-protection/</link>
      <pubDate>Thu, 09 May 2019 11:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/git-branch-protection/</guid>
      <description>&lt;p&gt;An anonymous attacker has been compromising Git repositories and demanding ransom. This attacker stole the contents and used a &lt;code&gt;force push&lt;/code&gt; to wipe the remote repository causing many to lose access to their critical source code assets. Use critical security tools available within the Git ecosystem to protect your company from this threat with:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Deploy Keys&lt;/li&gt;&#xA;&lt;li&gt;Mandatory Two Factor Authentication&lt;/li&gt;&#xA;&lt;li&gt;Protected Branches and Pull Requests&lt;/li&gt;&#xA;&lt;li&gt;Backups of your Git Repositories&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Are you accidentally storing private data in plain text?</title>
      <link>https://rietta.com/blog/plaintext-sensitive-data-in-unfiltered-logs/</link>
      <pubDate>Mon, 29 Apr 2019 16:15:00 -0400</pubDate>
      <guid>https://rietta.com/blog/plaintext-sensitive-data-in-unfiltered-logs/</guid>
      <description>&lt;p&gt;Debug logs that chronicle data about errors and other exceptions on a web application are a vital tool for any web company. It enables engineering teams to troubleshoot problems - sometimes even before a customer reports an issue to support - and thus provide excellent service to customers. But the danger of over-logging is real. When sensitive data is logged, it becomes vulnerable to misuse and abuse. In this article, I&amp;rsquo;ll show you how to prudently minimize the data collected in logs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Interview on Drifting Ruby</title>
      <link>https://rietta.com/blog/new-interview-on-drifting-ruby/</link>
      <pubDate>Thu, 18 Apr 2019 03:15:00 -0400</pubDate>
      <guid>https://rietta.com/blog/new-interview-on-drifting-ruby/</guid>
      <description>&lt;p&gt;Recently, our very own Frank Rietta (yes that Rietta) had a chance to sit down (virtually of course) with Dave Kimura (&lt;a href=&#34;https://twitter.com/kobaltz/&#34;&gt;@kobaltz on Twitter&lt;/a&gt;) of the Drifting Ruby screencast. For those who don&amp;rsquo;t know, Drifting Ruby is an educational site, blog, and screencast with all things Ruby. Drifting Ruby offers premium training with example-based content to up your dev game to the next level.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Applying Agile and Security in Software Development Public Appearance at KSU</title>
      <link>https://rietta.com/blog/applying-agile-and-security-in-software-development-public-appearance-at-ksu/</link>
      <pubDate>Fri, 08 Feb 2019 13:49:59 -0500</pubDate>
      <guid>https://rietta.com/blog/applying-agile-and-security-in-software-development-public-appearance-at-ksu/</guid>
      <description>Update 3/21/2019, the video of this presentation is now available on the Rietta Inc. YouTube Channel, Applying Agile and Security in Software Development.&#xA;I am going to be speaking on Applying Agile and Security in Software Development at the IS General Speaker Series #3 at Kennesaw State University on Wednesday, February 27th, from 7:00pm-9:00pm at the Burruss Building Room BB109.&#xA;There will also be a talk by Philip Andreae on Payment Card Security.</description>
    </item>
    <item>
      <title>Security Quick-Wins: Use DNS CAA records to avoid fraudulent certificates</title>
      <link>https://rietta.com/blog/security-quick-wins-use-dns-caa-records-to-avoid-fraudulent-certificates/</link>
      <pubDate>Tue, 24 Jul 2018 11:30:00 -0500</pubDate>
      <guid>https://rietta.com/blog/security-quick-wins-use-dns-caa-records-to-avoid-fraudulent-certificates/</guid>
      <description>&lt;p&gt;It&amp;rsquo;s ordinarily possible for a &lt;abbr title=&#34;Certificate Authority&#34;&gt;CA&lt;/abbr&gt; to&#xA;sign a certificate for your domain without properly validating it. We&#xA;essentially have to trust them to take security seriously and to not make&#xA;mistakes in their process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Migrate Away from SSL/Early TLS for PCI Compliance</title>
      <link>https://rietta.com/blog/migrate-away-from-ssl-early-tls-for-pci-compliance/</link>
      <pubDate>Sat, 30 Jun 2018 19:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/migrate-away-from-ssl-early-tls-for-pci-compliance/</guid>
      <description>&lt;p&gt;Systems that handle payment information, particularly e-commerce systems, are&#xA;regulated by PCI DSS. Changes to the PCI compliance requirements have&#xA;reclassified the use of outdated and insecure versions of TLS (and its&#xA;predecessor, SSL) as non-compliant. This has some significant impact across the&#xA;software industry as the changes went into enforcement today, June 30, 2018. The&#xA;key takeaways for us as web application developers are that we must ensure that&#xA;our deployed systems are using modern and secure TLS configurations, and that we&#xA;should now do so at the expense of supporting legacy web browsers that are&#xA;non-compliant, namely old versions of Internet Explorer and Windows.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lay off the marketing plugins. Equifax hit with fake Flash update.</title>
      <link>https://rietta.com/blog/lay-off-the-marketing-plugins-equifax-hit-with-fake-flash-update/</link>
      <pubDate>Thu, 12 Oct 2017 17:03:25 -0400</pubDate>
      <guid>https://rietta.com/blog/lay-off-the-marketing-plugins-equifax-hit-with-fake-flash-update/</guid>
      <description>The Equifax website borked again, this time to redirect to fake Flash update (arstechnica.com). This is the latest episode in the sad saga of insecurity at the embattled Atlanta-based credit reporting giant. Atlanta is known for a healthy information security ecosystem and the Georgia Institute of Technology and Kennesaw State University both have cybersecurity programs at the undergraduate and graduate level. If Equifax cared to hire security minded people to work in key areas they could.</description>
    </item>
    <item>
      <title>Automated Patching Will be New Reality</title>
      <link>https://rietta.com/blog/automated-patching-will-be-new-reality/</link>
      <pubDate>Wed, 11 Oct 2017 10:20:41 -0400</pubDate>
      <guid>https://rietta.com/blog/automated-patching-will-be-new-reality/</guid>
      <description>&lt;p&gt;Patch management is hard when the software being patched is supported by a major corporation with a long support window. It&amp;rsquo;s even harder when integrating numerous open source projects of various maturity. One lesson from the Equifax data breach is that failure to update your deployed application for months after the upstream project is updated can lead to dire consequences.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Automate Security Scans with Continuous Integration</title>
      <link>https://rietta.com/blog/automate-security-scans-with-continuous-integration/</link>
      <pubDate>Tue, 03 Oct 2017 00:00:00 -0500</pubDate>
      <guid>https://rietta.com/blog/automate-security-scans-with-continuous-integration/</guid>
      <description>&lt;p&gt;There are many tools out there that help you get a quick idea of possible security issues in your code and dependencies, but how often do you run them? If you&amp;rsquo;re running a Rails app and have never run &lt;a href=&#34;https://github.com/presidentbeef/brakeman&#34;&gt;brakeman&lt;/a&gt; or &lt;a href=&#34;https://github.com/rubysec/bundler-audit&#34;&gt;bundler-audit&lt;/a&gt;, I strongly urge you to run these tools immediately. Brakeman finds common insecure coding patterns that might be exploitable in the correct context and bundler-audit checks for known vulnerabilities within your installed gem dependencies.&lt;/p&gt;&#xA;&lt;p&gt;The premise of this blog post isn&amp;rsquo;t to teach you to run these tools, but rather to teach you how to implement these tools into your Continuous Integration service. If you&amp;rsquo;re curious of how to run these tools outside of the test suite, both tool&amp;rsquo;s READMEs are informative.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Equifax Missed Defense in Depth, Allowing a Massive Data Breach</title>
      <link>https://rietta.com/blog/equifax-defense-in-depth/</link>
      <pubDate>Mon, 18 Sep 2017 00:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/equifax-defense-in-depth/</guid>
      <description>&lt;p&gt;Equifax has confirmed that the main vector that lead to the data breach was a remote code execution vulnerability in Apache Struts that had been known for months [&lt;a href=&#34;https://rietta.com/blog/equifax-defense-in-depth/#equifax-announcement&#34;&gt;1&lt;/a&gt;]. Equifax had not yet patched it within the production environment. This is not just a lesson in the importance of patch management but one of defense in depth. The weakness in Equifax&amp;rsquo;s design was set in motion years before when they failed to design with the assumption that the front-end web server would be compromised.&lt;/p&gt;&#xA;&lt;p&gt;The attacker was able to obtain the massive trove of private data because the web application was the only gatekeeper. Once the remote code execution vulnerability was exploited, the attacker was able to access data unfettered by additional access controls.  Equifax chose to use a typical web application architecture without defense in depth.&lt;/p&gt;&#xA;&lt;p&gt;Defense in depth has to start as part of the development process. All developers should be aware of the OWASP Top 10 (&lt;a href=&#34;https://rietta.com/blog/equifax-defense-in-depth/#owasp-top10&#34;&gt;#3&lt;/a&gt;) and their work should be audited against the OWASP Advanced Security Verification Standard (ASVS) [&lt;a href=&#34;https://rietta.com/blog/equifax-defense-in-depth/#owasp-asvs&#34;&gt;#3&lt;/a&gt;] for the level appropriate for the risk faced by an organization in the event of a security breach.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Engine Yard&#39;s 17 Rails Security Tips</title>
      <link>https://rietta.com/blog/engine-yards-17-rails-security-tips/</link>
      <pubDate>Tue, 05 Sep 2017 00:01:03 -0400</pubDate>
      <guid>https://rietta.com/blog/engine-yards-17-rails-security-tips/</guid>
      <description>Christoper Rigor has posted a good set of Ruby on Rails Security 17-Item Checklist on Engine Yard&amp;rsquo;s blog. Check it out.&#xA;He did a good job hitting the important ones without being overly verbose.&#xA;If you&amp;rsquo;re looking for a standard to follow, check out the OWASP ASVS.</description>
    </item>
    <item>
      <title>Troubling ISP Privacy Repeal: The Data Will be Breached</title>
      <link>https://rietta.com/blog/isp-privacy-repeal/</link>
      <pubDate>Thu, 18 May 2017 11:59:59 -0400</pubDate>
      <guid>https://rietta.com/blog/isp-privacy-repeal/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://rietta.com/images/posts/2017/05/troubling-isp-privacy-repeal.jpg&#34; alt=&#34;The U.S. Congress &amp;amp; The President&amp;rsquo;s Troubling Repeal of Internet Privacy Protections - Photo Credit: &amp;amp;copy; 2013 Frank Rietta. &#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Your Internet Service Provider has direct access to the type of information on you and your family that the National Security Agency uses for spying.&lt;/p&gt;&#xA;&lt;p&gt;Your ISP knows when you are at home and when you are not, when your kids are doing their homework. They know or can know what you&amp;rsquo;re watching on Netflix (&lt;a href=&#34;#reed-kranch&#34;&gt;even when its encrypted&lt;/a&gt;) and YouTube. If any member of your household ever views pornographic content, your ISP knows how much and at what times such content is accessed. They can infer through traffic analysis how many people are living at your home and even know how many iPhone and Android devices that you have. And even though they cannot see into your encrypted search queries on Google, your ISP knows every medical website that you visited to research a condition that you think you have or are looking into a drug that your doctor has prescribed to you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breach Prevention for Developers Talk at Kennesaw State University</title>
      <link>https://rietta.com/blog/breach-prevention-for-developers-at-kennesaw-state-university/</link>
      <pubDate>Tue, 28 Feb 2017 07:56:03 -0500</pubDate>
      <guid>https://rietta.com/blog/breach-prevention-for-developers-at-kennesaw-state-university/</guid>
      <description>&lt;p&gt;Earlier this month I had the honor of speaking with information security students&#xA;at Kennesaw State University in Georgia thanks to &lt;a href=&#34;http://coles.kennesaw.edu/faculty/mattord-herbert.php&#34;&gt;Dr. Herbert Mattord&lt;/a&gt;. It is a very diverse class with both traditional students&#xA;and more mature students who are switching careers. Most of the students had little or no&#xA;professional software development experience so I view these talks as extra critical because&#xA;&lt;acronym title=&#34;Information Security, also known as Cybersecurity&#34;&gt;infosec&lt;/acronym&gt; professionals play an important role in this by working with developers and thus need to know&#xA;something about how software is made.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Intro to App Sec Podcast Interview</title>
      <link>https://rietta.com/blog/intro-to-app-sec-podcast-interview/</link>
      <pubDate>Wed, 22 Feb 2017 19:17:08 -0500</pubDate>
      <guid>https://rietta.com/blog/intro-to-app-sec-podcast-interview/</guid>
      <description>&lt;p&gt;It&amp;rsquo;s been a few months and I wish I had shared the link with you sooner. Back on August 29, 2016,&#xA;I was the guest of &lt;a href=&#34;https://advancedpersistentsecurity.net/podcast/intro-to-app-sec-with-frank-rietta/&#34;&gt;Joe Gray&amp;rsquo;s Advanced Persistent Security Podcast&amp;rsquo;s Intro To App Sec Episode&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;We talked about application security and the news. Give it a listen!&lt;/p&gt;</description>
    </item>
    <item>
      <title>The MongoDB hack and the importance of secure defaults</title>
      <link>https://rietta.com/blog/the-mongodb-hack-and-the-importance-of-secure-defaults/</link>
      <pubDate>Thu, 12 Jan 2017 14:24:11 -0500</pubDate>
      <guid>https://rietta.com/blog/the-mongodb-hack-and-the-importance-of-secure-defaults/</guid>
      <description>Tim Kadlec has written a fantastic blog post that you should read right away at https://snyk.io/blog/mongodb-hack-and-secure-defaults.&#xA;It starts with: &amp;ldquo;If you have a MongoDB installation, now would be the time to verify that it is secure. Since just before Christmas, over 28,000 public MongoDB installs have been hacked. The attackers are holding the hacked data ransom, demanding companies pay using Bitcoins to get their data back. From the looks of it, at least 20 companies have given in and paid the ransom so far.</description>
    </item>
    <item>
      <title>28th Anniversary of the Morris Internet Worm</title>
      <link>https://rietta.com/blog/28th-anniversary-of-the-morris-internet-worm/</link>
      <pubDate>Wed, 02 Nov 2016 12:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/28th-anniversary-of-the-morris-internet-worm/</guid>
      <description>Today marks the 28th anniversary of the Morris Worm, which devastated large portions of the nascent Internet on November 2, 1988. Even though it was unleashed nearly three decades ago, it was more advanced than the Mirai worm that compromised hundreds of thousands of IoT devices in recent weeks.&#xA;The Morris Worm source code on a floppy disk was on display at the Computer History Museum in Mountain View, Calif. Photo licensed under Creative Commons from Intel Free Press, &amp;copy; 2013.</description>
    </item>
    <item>
      <title>Bad Password Practices are Responsible For Most Data Breaches. You Can do Better.</title>
      <link>https://rietta.com/blog/bad-password-practices-are-responsible-for-most-data-breaches-you-can-do-better/</link>
      <pubDate>Tue, 10 May 2016 11:07:58 -0400</pubDate>
      <guid>https://rietta.com/blog/bad-password-practices-are-responsible-for-most-data-breaches-you-can-do-better/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://www.verizonenterprise.com/verizon-insights-lab/dbir/&#34;&gt;2016 Verizon DBIR report&lt;/a&gt; is out and is available for download. Among the findings is the prevalence of data breaches that are attributable to stolen authorization credentials.&lt;/p&gt;&#xA;&lt;p&gt;According to the report &amp;ldquo;63% of confirmed data breaches involved weak, default or stolen passwords&amp;rdquo; (page 20). This is an increase from 2015, when the stat was that 51% of web application breaches were attributable to stolen credentials. If anything is clear, it&amp;rsquo;s that the lowly credential theft is a clear and present danger in information security. It is responsible for more incidents than all the other exotic, technically interesting attacks combined.&lt;/p&gt;</description>
    </item>
    <item>
      <title>It is not just one iPhone, the FBI wants a future where it is impractical to deploy strong encryption without key escrow</title>
      <link>https://rietta.com/blog/its-not-just-one-iphone/</link>
      <pubDate>Wed, 16 Mar 2016 09:01:11 -0400</pubDate>
      <guid>https://rietta.com/blog/its-not-just-one-iphone/</guid>
      <description>&lt;p&gt;Crypto War II, the first crypto war having taken place in the 90s with the clipper chip, is in full swing with hostilities started back up a few years ago when FBI Director James Comey and others started lobbying congress and giving public speeches about how being unable to unlock some devices and communications makes it hard to do their job. It has been an unrelenting full public relations assault on practical strong encryption.&lt;/p&gt;&#xA;&lt;p&gt;Ultimately FBI Director James Comey wants a future where it is illegal or impractical to deploy strong encryption &lt;em&gt;without key escrow&lt;/em&gt;, which is a key backup system that the great consensus of cryptographers and computer scientists assert is insecure at scale. As a statesman he never comes out and says this directly, but it is the only conceivable outcome to what he is demanding of tech companies before congress and the actions that the FBI has taken in court.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What is the difference between bcrypt and SHA256?</title>
      <link>https://rietta.com/blog/bcrypt-not-sha-for-passwords/</link>
      <pubDate>Fri, 05 Feb 2016 10:23:27 -0500</pubDate>
      <guid>https://rietta.com/blog/bcrypt-not-sha-for-passwords/</guid>
      <description>&lt;p&gt;TL;DR; SHA1, SHA256, and SHA512 are all &lt;em&gt;fast hashes&lt;/em&gt; and are bad for passwords. SCRYPT and BCRYPT are both a &lt;em&gt;slow hash&lt;/em&gt; and are good for passwords. Always use slow hashes, never fast hashes.&lt;/p&gt;&#xA;&lt;p&gt;SANS&amp;rsquo; &lt;a href=&#34;https://software-security.sans.org/resources/swat&#34;&gt;Securing Web Application Technologies&#xA;[SWAT] Checklist&lt;/a&gt; is offering a bit of bad security advice for the everyday web application developer, under the heading &amp;ldquo;Store User Passwords Using A Strong, Iterative, Salted Hash&amp;rdquo;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;User passwords must be stored using secure hashing techniques with a strong algorithm like SHA-256. Simply hashing the password a single time does not sufficiently protect the password. Use iterative hashing with a random salt to make the hash strong.&lt;/p&gt;&#xA;&lt;/blockquote&gt;</description>
    </item>
    <item>
      <title>Ruby Application Security Talk Featured in Ruby Weekly Issue # 268</title>
      <link>https://rietta.com/blog/appsec-talk-featured-in-ruby-weekly/</link>
      <pubDate>Thu, 15 Oct 2015 12:40:53 -0400</pubDate>
      <guid>https://rietta.com/blog/appsec-talk-featured-in-ruby-weekly/</guid>
      <description>A link to my talk on &amp;ldquo;Defending Against Data Breaches, as a Practicing Ruby Developer&amp;rdquo; at Rocky Mountain Ruby 2015 was featured in Issue # 268 of Ruby Weekly! Thanks Peter Cooper!&#xA;I&amp;rsquo;m super glad to see the word getting out that security has to be part of the development process. Oh by the way, I learned at the ISSA International conference this week that Microsoft has a version of their Secure Development Lifecycle tailored for Agile development.</description>
    </item>
    <item>
      <title>What is Application Security?</title>
      <link>https://rietta.com/blog/what-is-application-security/</link>
      <pubDate>Mon, 28 Sep 2015 19:25:45 -0400</pubDate>
      <guid>https://rietta.com/blog/what-is-application-security/</guid>
      <description>&lt;p&gt;I&amp;rsquo;m back from Boulder, Colorado, having presented on application security to the Ruby developers at the &lt;a href=&#34;http://rockymtnruby.com/&#34;&gt;Rocky Mountain Ruby Conference&lt;/a&gt;! It was a fantastic group and security is one of those topics that are just not talked about enough within the developer community.&lt;/p&gt;&#xA;&lt;p&gt;I started off with a definition of application security:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Application Security is the subset of Information Security focused on protecting data and privacy from abuse by adversaries who have access to the software system as a whole. Its purpose is to make software resilient to attack, especially when network defenses alone are insufficient.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;Then proceeded to talk about the importance of writing User Stories with security constraints and Abuser Stories, which are user stories from the point of view of a malicious adversary. It&amp;rsquo;s all about clearly communicating among developers and the non-technical stakeholders about the threats so that these considerations can inform development decisions.&lt;/p&gt;&#xA;&lt;p&gt;The Q&amp;amp;A was robust with more questions than there was time to get to them all. I was able to give out two &lt;a href=&#34;https://www.yubico.com/products/yubikey-hardware/fido-u2f-security-key/&#34;&gt;blue Yubikey Fido U2F keys&lt;/a&gt; thanks to Yubico.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Uniqueness Validation Race Condition in Ruby on Rails applications</title>
      <link>https://rietta.com/blog/validates-uniqueness-race-condition-in-ruby-on-rails/</link>
      <pubDate>Mon, 04 May 2015 12:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/validates-uniqueness-race-condition-in-ruby-on-rails/</guid>
      <description>&lt;p&gt;Are you a practicing Ruby on Rails developer? It doesn&amp;rsquo;t matter if you are called a junior developer, senior developer, or the janitor. It is surprisingly easy for &lt;em&gt;race conditions&lt;/em&gt; to slip into your code and out into production. Some of these can lead to annoying duplicate e-mails in your database or they could lead to serious security issues that impact your company&amp;rsquo;s bottom line.&lt;/p&gt;&#xA;&lt;p&gt;As you read on, I&amp;rsquo;m going to teach you a bit about race conditions, also called hazards in some engineering circles, and give you a practical example of how one can slip into a Rails application if you were to choose to enforce validation constraints only within an application&amp;rsquo;s models with a &lt;code&gt;validates :field_name, uniqueness: true&lt;/code&gt; rather than through database constraints.&lt;/p&gt;&#xA;&lt;p&gt;Before we begin, I do want to remind you about one thing. Preventing race conditions is not just something that can be added to Ruby on Rails because the methods for automatically detecting race conditions is an &lt;acronym title=&#34;A problem is NP-hard if an algorithm for solving it can be translated into one for solving any nondeterministic polynomial time problem.&#34;&gt;NP-hard&lt;/acronym&gt; problem in computer science. That&amp;rsquo;s why it&amp;rsquo;s so important that you understand something about spotting situations where they may occur so that you stand a better chance at leaving them out of your next deploy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Video! Understanding &amp;amp; Defending Against Data Breaches</title>
      <link>https://rietta.com/blog/new-video-understanding-and-defending-against-data-breaches/</link>
      <pubDate>Thu, 19 Feb 2015 23:22:58 -0500</pubDate>
      <guid>https://rietta.com/blog/new-video-understanding-and-defending-against-data-breaches/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://rietta.com/images/posts/2015/02/nashrb_understanding_data_breaches.jpg&#34; alt=&#34;Nash.rb Understanding &amp;amp;amp; Defending Against Data Breaches starts with a proper understanding of Professional Ethics&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;A few weeks ago, I spoke with &lt;a href=&#34;http://www.meetup.com/nashrb/&#34;&gt;the Ruby users&amp;rsquo; group in Nashville, TN&lt;/a&gt;, about the importance of understanding the root cause of data breach security incidents and countermeasures that developers can put in place to help prevent them. It&amp;rsquo;s up on YouTube for your enjoyment at &lt;a href=&#34;https://www.youtube.com/watch?v=dj196NhPyWs&amp;amp;list=PLqZY2tk6rSRl8tS4zmgxijjw35lRe-Ptk&amp;amp;index=2&#34;&gt;Understanding &amp;amp; Defending Against Data Breaches, as a Practicing Software Developer - Nash.rb&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Two new videos! How a Ruby on Rails developer can help prevent a Data Breach</title>
      <link>https://rietta.com/blog/two-new-videos-how-a-ruby-on-rails-developer-can-help-prevent-a-data-breach/</link>
      <pubDate>Fri, 09 Jan 2015 11:12:44 -0500</pubDate>
      <guid>https://rietta.com/blog/two-new-videos-how-a-ruby-on-rails-developer-can-help-prevent-a-data-breach/</guid>
      <description>&lt;p&gt;Two new videos of the data breach talk and class that I lead in August and December are now up on YouTube! I hope that it helps you level up on your security knowledge because good software security needs to be a moral stance.&lt;/p&gt;&#xA;&lt;h2 id=&#34;next-public-talk&#34;&gt;Next public talk&lt;/h2&gt;&#xA;&lt;p&gt;I am scheduled to give a presentation to this topic for the &lt;a href=&#34;http://www.meetup.com/nashrb/events/217795882/&#34;&gt;Nash.rb Users&amp;rsquo; Group on Thursday, February 5, 2015&lt;/a&gt; at the &lt;a href=&#34;https://twitter.com/emmaemail&#34;&gt;Emma office&lt;/a&gt; in Nashville, TN. If you are in town and can make it out, I would love to meet you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How To Protect Against the POODLE SSLv3 Vulnerability</title>
      <link>https://rietta.com/blog/how-to-protect-against-the-poodle-sslv3-vulnerability/</link>
      <pubDate>Thu, 16 Oct 2014 09:21:22 -0400</pubDate>
      <guid>https://rietta.com/blog/how-to-protect-against-the-poodle-sslv3-vulnerability/</guid>
      <description>&lt;p&gt;The &lt;acronym title=&#34;Padding Oracle On Downgraded Legacy&#xA;Encryption&#34;&gt;POODLE&lt;/acronym&gt; SSL vulnerability marks the third major security flaw discovered this year that impacts the security of millions of websites.&lt;/p&gt;&#xA;&lt;p&gt;The attack works by forcing the connection to downgrade from the newer TLS protocol to the 18 year old SSL 3 protocol, which is obsolete and insecure, and then utilizing a weakness to calculate small strings of data from the encrypted communication, such as session cookies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Commercial Information Security Classification System</title>
      <link>https://rietta.com/blog/commercial-information-classifications/</link>
      <pubDate>Mon, 13 Oct 2014 18:09:13 -0600</pubDate>
      <guid>https://rietta.com/blog/commercial-information-classifications/</guid>
      <description>&lt;div class=&#34;video-container&#34;&gt;&#xA;  &lt;iframe src=&#34;https://player.vimeo.com/video/127224137&#34; width=&#34;500&#34; height=&#34;281&#34; frameborder=&#34;0&#34; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;When you read books on security, at some point the importance of classified information systems is covered. These typically look at &lt;a href=&#34;https://en.wikipedia.org/wiki/Mandatory_access_control&#34;&gt;Mandatory Access Control&lt;/a&gt; in the context of military classifications, such as top secret, secret, for official use only, and sensitive but unclassified. While the existence of commercial classification systems in use outside of a government context may be mentioned, it&amp;rsquo;s not as common to see a commercial information classification system presented.&lt;/p&gt;&#xA;&lt;p&gt;In this article, I shall present to you a commercial information classification system that you can use to help plan your web application&amp;rsquo;s security standards based upon &lt;a href=&#34;https://en.wikipedia.org/wiki/Information_sensitivity&#34;&gt;information sensitivity&lt;/a&gt; considerations. It is the system that I have developed for use with my own clients and have presented on publicly as part of my series on &lt;a href=&#34;https://speakerdeck.com/rietta/rails-developer-can-help-prevent-a-data-breach-atlrug-1&#34;&gt;how a Ruby developer can help prevent a data breach&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Government vs Security - Schneier explains</title>
      <link>https://rietta.com/blog/government-vs-security-schneier-explains/</link>
      <pubDate>Tue, 07 Oct 2014 14:33:58 -0500</pubDate>
      <guid>https://rietta.com/blog/government-vs-security-schneier-explains/</guid>
      <description>We&amp;rsquo;ve been hearing a lot recently about law enforcement officials upset over the so-called &amp;ldquo;going dark&amp;rdquo; problem, with Apple and Google implementing stronger encryption solutions for their mobile platforms. These government organizations are arguing that by making encryption easy to use and unbreakable, Apple and Google will help criminals escape from justice by impeding investigative work.&#xA;&amp;ldquo;You can&amp;rsquo;t build a backdoor that only the good guys can walk through.&amp;rdquo;&#xA;As security-focused developers, we discuss these issues quite often at Rietta.</description>
    </item>
    <item>
      <title>Raspberry Pi crypto key management project!</title>
      <link>https://rietta.com/blog/raspberry-pi-crypto-project/</link>
      <pubDate>Thu, 02 Oct 2014 21:20:16 -0400</pubDate>
      <guid>https://rietta.com/blog/raspberry-pi-crypto-project/</guid>
      <description>&lt;p&gt;A few months ago I bought a &lt;a href=&#34;http://www.raspberrypi.org/&#34;&gt;Raspberry Pi B&lt;/a&gt; to experiment with, but sadly my day job as a Ruby developer keep me busy enough that it just sat on the shelf unused until this last weekend. For those not yet in the know, the Raspberry Pi is an excellent little complete computer system on a small circuit board that uses very low power and looks like this:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://rietta.com/images/posts/2014/10/raspberry_pi_b_first_boot.jpg&#34; alt=&#34;My Raspberry Pi booting for the First Time!&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Free, Universal SSL with Cloudflare</title>
      <link>https://rietta.com/blog/universal-ssl-with-cloudflare/</link>
      <pubDate>Mon, 29 Sep 2014 09:11:52 -0400</pubDate>
      <guid>https://rietta.com/blog/universal-ssl-with-cloudflare/</guid>
      <description>&lt;p&gt;Cloudflare, the web application security forward proxy and transparent CDN service, has &lt;a href=&#34;https://blog.cloudflare.com/introducing-universal-ssl/&#34;&gt;announced on their blog universal SSL even on their free accounts&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This is a very welcome development for the public interest on the internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Software security is a moral duty</title>
      <link>https://rietta.com/blog/software-security-is-a-moral-duty/</link>
      <pubDate>Sun, 21 Sep 2014 08:57:57 -0400</pubDate>
      <guid>https://rietta.com/blog/software-security-is-a-moral-duty/</guid>
      <description>&lt;p&gt;All too often robust security is put off because the cost of prevention is felt upfront and the cost of breach is to realized at an uncertain future time and mostly by third parties. In the name of saving money, organizations continue to run out of date operating systems, reject appropriate strong encryption systems, fail to deploy sufficient network security, and refuse to employ and empower appropriate security staffs. In the end, security is seen as an expense to be minimized as part of a risk management program. But there is another way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New OpenPGP Key, 0xC004BAE3 (2014)</title>
      <link>https://rietta.com/blog/new-openpgp-key/</link>
      <pubDate>Sun, 27 Jul 2014 17:51:23 -0400</pubDate>
      <guid>https://rietta.com/blog/new-openpgp-key/</guid>
      <description>&lt;p&gt;After 11 years, I have chosen to transition my OpenPGP/GnuPG cryptographic key pair from a 1024-bit DSA to a 4096-bit RSA key. The new key is ID 0xC004BAE3. Please review the fingerprints and update your OpenPGP keychain accordingly.&lt;/p&gt;&#xA;&lt;p&gt;The following is my digitally signed transition statement, notice that it is signed with both my new and old key pairs. My old key is un-compromised and will remain valid for a period of time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction to OpenPGP: Decrypt this Message</title>
      <link>https://rietta.com/blog/the-openpgp-encrypted-message-exercise/</link>
      <pubDate>Mon, 07 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/the-openpgp-encrypted-message-exercise/</guid>
      <description>If you have been following the news in light of the revelations of the NSA domestic surveillance program, which is probably unconstitutional in the United States but in practice is being permitted by the courts, then you should know something about the encrypt everything movement and Google&amp;rsquo;s End-to-End project, which is to add OpenPGP to the Chrome web browser. If this is new to you, this fun challenge will help you get started with what you need to decrypt a message with GnuPG!</description>
    </item>
    <item>
      <title>Retake the Net for Privacy!</title>
      <link>https://rietta.com/blog/retake-the-net-for-privacy/</link>
      <pubDate>Thu, 05 Jun 2014 15:18:56 -0400</pubDate>
      <guid>https://rietta.com/blog/retake-the-net-for-privacy/</guid>
      <description>Rietta (@riettainc on Twitter) will educate customers on the use of strong headers, TLS w/ PFS, and other countermeasures as part of our continuing security initiatives program.&#xA;Will you also help join us in the world-wide cause to retake the net?&#xA;Check out the petition yourself at Reset the Net and choose for yourself today what you can personally do to make the web secure from illegitimate prying eyes.</description>
    </item>
    <item>
      <title>What a Ruby developer can do to help prevent a Data Breach - 2014</title>
      <link>https://rietta.com/blog/what-a-ruby-developer-can-do-to-help-prevent-a-data-breach-2014/</link>
      <pubDate>Thu, 05 Jun 2014 10:18:14 -0400</pubDate>
      <guid>https://rietta.com/blog/what-a-ruby-developer-can-do-to-help-prevent-a-data-breach-2014/</guid>
      <description>I was invited by Tech Talent South to give a guest lecture to their Spring 2014 class of students learning to become Ruby on Rails developers. These students are all adults looking to make a change in their career and are really bright and motivated individuals looking to better themselves with learning to code. In my view this is perfect because being a developer is the most trusted job position one can possibly hold in most organizations.</description>
    </item>
    <item>
      <title>Humana data breach in Atlanta for an unencrypted USB disk</title>
      <link>https://rietta.com/blog/humana-data-breach-in-atlanta-for-an-unencrypted-usb-disk/</link>
      <pubDate>Fri, 30 May 2014 08:24:10 -0400</pubDate>
      <guid>https://rietta.com/blog/humana-data-breach-in-atlanta-for-an-unencrypted-usb-disk/</guid>
      <description>Just this week, Security Professionals Magazine is reporting a data breach of three thousand unencrypted medical records, names, and social security numbers. For want of choosing &amp;ldquo;Encrypt this Drive&amp;rdquo;, Humana and one of it&amp;rsquo;s associates have put thousands of customers at risk of economic harm.&#xA;According to the report an encrypted laptop and an unencrypted USB drive containing the data were stolen from a Humana associate&amp;rsquo;s vehicle. This is classic laptop theft and why anyone with sensitive information in their care should treat their laptop bag like it is handcuffed to their body.</description>
    </item>
    <item>
      <title>ModSecurity and Fail2Ban as an Intrusion Prevention System</title>
      <link>https://rietta.com/blog/mod-security-and-fail2ban-as-an-intrusion-prevention-system/</link>
      <pubDate>Tue, 27 May 2014 12:24:07 -0400</pubDate>
      <guid>https://rietta.com/blog/mod-security-and-fail2ban-as-an-intrusion-prevention-system/</guid>
      <description>ModSecurity and fail2ban can be used as an open source intrusion prevention system.&#xA;The setup is pretty straight forward: Configure ModSecurity to detect some attacks against your system Configure fail2ban to read the ModSecurity audit log file Configure ModSecurity Install a commercial ruleset or open source ruleset, such as the OWASP ModSecurity Core Rule Set, for your ModSecurity web application firewall.&#xA;One of the neat tricks in the OWASP ruleset is that if your application raises an exception or certain content appears to leak out then it triggers a 403 Unauthorized HTTP response rather than returning the content to a potential attacker.</description>
    </item>
    <item>
      <title>Defense in Depth</title>
      <link>https://rietta.com/blog/defense-in-depth/</link>
      <pubDate>Thu, 22 May 2014 12:19:02 -0400</pubDate>
      <guid>https://rietta.com/blog/defense-in-depth/</guid>
      <description>I had no fewer than three separate conversations yesterday about the importance of Defense in Depth in the context of building out a comprehensive plan to secure a web application and its environment. In light of that, I wanted to share with you the basic concept and point out some places to read about this big idea in security.&#xA;Photo: A combination door lock is one possible countermeasure in a layered security approach, but there is so much more to defense in depth.</description>
    </item>
    <item>
      <title>YubiKey Authentication Devices</title>
      <link>https://rietta.com/blog/yubikey-authentication-devices/</link>
      <pubDate>Thu, 15 May 2014 11:42:57 -0400</pubDate>
      <guid>https://rietta.com/blog/yubikey-authentication-devices/</guid>
      <description>&lt;p&gt;Brandon Dees (&lt;a href=&#34;https://twitter.com/brandondees&#34;&gt;@brandondees&lt;/a&gt;) and I are both really big security geeks when it comes to technology. We are both really into bringing &lt;a href=&#34;https://en.wikipedia.org/wiki/Multi-factor_authentication&#34;&gt;multi-factor authentication&lt;/a&gt;&#xA;as standard equipment to the applications that we build. With something you have, and something you know, instances like &lt;a href=&#34;http://open.bufferapp.com/buffer-has-been-hacked-here-is-whats-going-on/&#34;&gt;the Buffer app breach&lt;/a&gt; can be mitigated in many circumstances.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenSSL Vulnerability, Patch 1.0.1 Immediately</title>
      <link>https://rietta.com/blog/openssl-emergency/</link>
      <pubDate>Mon, 07 Apr 2014 23:50:50 -0400</pubDate>
      <guid>https://rietta.com/blog/openssl-emergency/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Major Vulnerability, Action Required.&lt;/strong&gt;  A major vulnerability for OpenSSL 1.0.1 was announced today, April 7, 2014.  &lt;a href=&#34;http://heartbleed.com/&#34;&gt;The Heartbleed Bug&lt;/a&gt;, &lt;a href=&#34;https://www.openssl.org/news/secadv_20140407.txt&#34;&gt;CVE-2014-0160&lt;/a&gt;, is a major vulnerability that may lead to &lt;strong&gt;secret key disclosure&lt;/strong&gt;.  A discussion of this vulnerability can be found on the &lt;a href=&#34;https://news.ycombinator.com/item?id=7548991&#34;&gt;Hacker News thread on the Heartbleed vulnerability&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Anti-virus for Mac for PCI Compliance</title>
      <link>https://rietta.com/blog/anti-virus-for-mac-for-pci-compliance/</link>
      <pubDate>Thu, 23 Jan 2014 10:12:00 +0000</pubDate>
      <guid>https://rietta.com/blog/anti-virus-for-mac-for-pci-compliance/</guid>
      <description>When a contract requires anti-virus on all computers, even the Mac OS X systems, which do you choose? Macs are not Commonly Affected, in the traditional sense One nice thing about working in a heavily Mac OS X environment, which most Ruby on Rails development companies are is that there just are not the number and variety of viruses on the platform as there are in the Windows environment.&#xA;This is not to say that a Mac user does not face many security threats - they do face threats, nor that they cannot be hacked - they most certainly can be hacked.</description>
    </item>
    <item>
      <title>Joppar&#39;s &#39;Tips on Securing Your Mobile App&#39; Infographic Quoted Me!</title>
      <link>https://rietta.com/blog/tips-on-securing-your-mobile-app/</link>
      <pubDate>Mon, 06 Jan 2014 11:26:00 +0000</pubDate>
      <guid>https://rietta.com/blog/tips-on-securing-your-mobile-app/</guid>
      <description>Good morning! I write this on the very cold Monday morning that is January 6, 2014. Today, our friends over at Joppar, a mobile apps startup in Silicon Valley, have released a very good cheat sheet for app developers who want to care about the security of their application. In other words, anyone who does not want their own &amp;lsquo;Snapchat Breach Exposes Weak Security&amp;rsquo; article from the New York Times.</description>
    </item>
    <item>
      <title>Secure Passwords &amp; Passphrases</title>
      <link>https://rietta.com/blog/secure-passwords/</link>
      <pubDate>Mon, 25 Nov 2013 17:40:00 +0000</pubDate>
      <guid>https://rietta.com/blog/secure-passwords/</guid>
      <description>Sometimes when someone sees me type my long password to log into my laptop, I get asked about why I use such a long password. I always sigh a little. Deep down inside, I reflect on how there is not a concise, easy, actionable answer that will help that person practice better password security. My laptop password is better than most, but even it would be potentially susceptible to long, sustained offline attacks.</description>
    </item>
    <item>
      <title>Really Bad Passwords (with Unsalted Hashes)</title>
      <link>https://rietta.com/blog/really-bad-passwords-with-unsalted-hashes/</link>
      <pubDate>Fri, 08 Jun 2012 18:30:00 +0000</pubDate>
      <guid>https://rietta.com/blog/really-bad-passwords-with-unsalted-hashes/</guid>
      <description>The June, 2012, LinkedIn password breach reminds us all the need to protect our user&amp;rsquo;s passwords.&#xA;The following table includes a series of really, really bad passwords. These are passwords that are trivially cracked using an automated tool, such as John the Ripper, or have been found through public password hacks as being in use by real people. This is a simple rainbow table because it lists the precomputed unsalted SHA1 and MD5 hashes.</description>
    </item>
    <item>
      <title>Building Secure Web Applications (Info Graphic)</title>
      <link>https://rietta.com/blog/building-secure-web-applications-info/</link>
      <pubDate>Tue, 05 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/building-secure-web-applications-info/</guid>
      <description>VeraCode just released this great info graphic on what it takes to build a secure web application.&#xA;However, you can simplify this process to two steps:&#xA;Use Ruby on Rails Hire Rietta I personally earned an M.S. in Information Security from Georgia Tech and started Rietta Inc. to build secure web applications for clients. This is our passion. It&amp;rsquo;s what we do. We even will audit the work done by your current / previous Rails development team.</description>
    </item>
    <item>
      <title>What is Protected Personally Identifiable Information? Do I really have to hash users&#39; passwords?</title>
      <link>https://rietta.com/blog/what-is-protected-personally/</link>
      <pubDate>Thu, 05 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/what-is-protected-personally/</guid>
      <description>This post is part of Rietta&amp;rsquo;s ongoing coverage of encryption. Browse the Encryption tag for the rest of the series.&#xA;The Short Answer The legal answer depends on which Federal, State, and local laws apply to your company. And I am not a lawyer. However, for companies whose nexus is in Georgia, where my company is located, the Georgia General Assembly has given some guidance in the data breach law.</description>
    </item>
    <item>
      <title>Generate OpenSSL RSA Key Pair from the Command Line</title>
      <link>https://rietta.com/blog/openssl-generating-rsa-key-from-command/</link>
      <pubDate>Fri, 27 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-generating-rsa-key-from-command/</guid>
      <description>&lt;p&gt;While &lt;a href=&#34;https://rietta.com/blog/openssl-encrypt-file-with-password-from/&#34;&gt;Encrypting a File with a Password from the Command Line using OpenSSL&lt;/a&gt;&#xA;is very useful in its own right, the &lt;em&gt;real power&lt;/em&gt; of the OpenSSL library is its&#xA;ability to support public key cryptography: encrypting or validating data in&#xA;an unattended manner, where the password protecting the private key is never&#xA;needed by the process doing the encrypting or validating.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenSSL: Encrypt a File with a Password from the Command Line</title>
      <link>https://rietta.com/blog/openssl-encrypt-file-with-password-from/</link>
      <pubDate>Mon, 09 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/openssl-encrypt-file-with-password-from/</guid>
      <description>Do you know how to use OpenSSL to protect sensitive information in storage instead of just in transit across the network? In fact, your can use the OpenSSL command line too to encrypt a file on your Mac OS X, Linux, or FreeBSD based computer. Support for the library are included by default in PHP and Ruby. So there is no reason not to use it to add additional security to your web applications.</description>
    </item>
    <item>
      <title>Web Application Security &amp; Performance</title>
      <link>https://rietta.com/blog/web-application-security-and-performance/</link>
      <pubDate>Tue, 22 Sep 2009 17:07:00 -0500</pubDate>
      <guid>https://rietta.com/blog/web-application-security-and-performance/</guid>
      <description>As a business owner or manager, you need to be aware of the main legal liability and technical challenges that face any critical website or application. Your business will be better positioned to succeed if you understand how to answer these five key questions:&#xA;Is your business making one or more of the top five web application mistakes that generate business risk? How can performance and security assessments help increase your ROI?</description>
    </item>
    <item>
      <title>Tired of Contact Form Spam?</title>
      <link>https://rietta.com/blog/tired-of-contact-form-spam/</link>
      <pubDate>Fri, 25 Jan 2008 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/tired-of-contact-form-spam/</guid>
      <description>Many of my customers have been receiving an increasing amount of spam through their website contact forms. The spammers fill in fake names, email addresses, phone numbers, and a junk message with lots of links. To counter these spammers, one must make the web-form difficult for a spambot to fill out and yet keep it usable for valued human guests. CAPTCHAS are used in a lot of places online, but randomized field names are preferable because no strain is put on a human guest.</description>
    </item>
    <item>
      <title>Georgia Tech to Compete in Network Security Contest</title>
      <link>https://rietta.com/blog/georgia-tech-to-compete-in-network/</link>
      <pubDate>Thu, 07 Dec 2006 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/georgia-tech-to-compete-in-network/</guid>
      <description>Students from the Georgia Institute of Technology competed in the 2006 UCSB International Capture The Flag contest. The Tech team was called int80 and consisted of about forty graduate students and some undergraduates.&#xA;The Georgia Tech team, int80, came in 5th place. The winner of the contest was the TU Vienna team, We_0wn_Y0u. The results can be seen at http://www.cs.ucsb.edu/~vigna/CTF/final_results.html. The final video is at http://www.cs.ucsb.edu/~vigna/CTF/iCTF_UCSB_2006.mov.</description>
    </item>
    <item>
      <title>Saying no to PayPal Phishing Attacks</title>
      <link>https://rietta.com/blog/saying-no-to-paypal-phishing-attacks/</link>
      <pubDate>Tue, 09 Aug 2005 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/saying-no-to-paypal-phishing-attacks/</guid>
      <description>Users on my mail server, well at least the ones with domains subscribed to the filtering service, no longer receive PayPal spoofs unaltered! The trick to catching this vermin is both simple and accurate.&#xA;An e-mail is certainly a phishing attack when all three of the following conditions are met:&#xA;The From address claims to be paypal.com The Received header, which indicates the address of the computer from which the e-mail was actually received, is not paypal.</description>
    </item>
  </channel>
</rss>
