Cybersecurity Category

Rietta's cybersecurity posts cover phishing defense, secure passwords and passphrases, and practical web application security and performance guidance.

10/01/2021

You Can be the Victim of a Cybersecurity Attack: Do Your Part. #BeCyberSmart.

Be cyber smart by recognizing that you can be the victim of a cyber security incident and that you have to keep your Internet connected custom software securely configured and patched up-to-date at all times. Do Your Part. #BeCyberSmart.

Read More »

07/07/2021

Paying Ransomware is Harmful: Invest in proactive defense instead.

Paying the pirates has never been a good idea. The long history shows that paying the ransom only increases the financial incentives for more ransoms. Here is how you can use Threat Actor / Capability modeling and practically free counter measures to protect yourself.

Read More »

06/30/2021

Top 5 Cyber Security Self-Defense Tips for Businesses with Custom Applications

Since there is no Internet coast guard coming to your aid, here are the top five tips for your company to be better prepared for your own self-defense against cyber attack.

Read More »

05/25/2021

Cross-site Scripting Injection Attacks Using SVG Images

Cross-Site Scripting attacks can come from a variety of vectors, this article is an explanation of an unusual vector where javascript is embedded within a scalable vector graphics image.

Read More »

05/11/2021

Lava lamps providing randomness for security!

Lava Lamps as a security tool is an old idea, once covered by a patent. This is why I proudly display a Lava Lamp in my office within my web cam shot.

Read More »

04/27/2021

Testing: Your Future Self Will Thank You

Testing, while not always glorious, is a vital part of a good code base. Tests and code should go hand in hand.

Read More »

02/04/2021

Practical APPSEC starts with people first, processes second, and technology last

Technology purchases cannot solve application security. Improving security is a matter of people, processes, and technology. Here's how to invest developer education and processes first.

Read More »

10/07/2020

The convergence of Ruby on Rails and #AppSec Podcast Appearance

Frank Rietta guest on the Application Security Podcast with Chris Romeo

Read More »

04/25/2020

When Georgia was on the Brink of Outlawing Critical Computer Security Research, the Governor's Office Met with Me, and Vetoed it!

On April 25, 2018, nine information security professionals met with the Georgia Governor's office to discuss why the proposed criminal hacking law passed by both houses of the General Assembly was extremely problematic to Georgia's booming Information Security industry and risked putting the public at greater risk. Governor Deal vetoed the law a few weeks later.

Read More »

04/21/2020

Dependency Security and Hacking Rails with Jason Swett (Podcast)

Podcast interview about Ruby on Rails dependencies, security, state-sponsored hacking, and practical tips on how to protect your organization.

Read More »