Cybersecurity Category

Rietta's cybersecurity posts cover phishing defense, secure passwords and passphrases, and practical web application security and performance guidance.

04/29/2019

Are you accidentally storing private data in plain text?

Learn how to prudently minimize the collection of passwords, authentication tokens, and customer private data in your debug logs to protect your company from legal liability.

Read More »

04/18/2019

New Interview on Drifting Ruby

Frank Rietta joins Dave Kimura on Drifting Ruby Episode #183 to discuss Rails app security, securing Linux servers, staff access risk, and OWASP Top 10.

Read More »

02/08/2019

Applying Agile and Security in Software Development Public Appearance at KSU

Frank will be presenting Applying Agile and Security in Software Development at the IS General Speaker Series #3 on 2/28/2018 at KSU in Marietta.

Read More »

07/24/2018

Security Quick-Wins: Use DNS CAA records to avoid fraudulent certificates

Prevent certificate fraud and boost your TLS security in 5 minutes using this simple standardized DNS entry.

Read More »

06/30/2018

Migrate Away from SSL/Early TLS for PCI Compliance

PCI compliance 3.1 and 3.2 no longer allow for SSL/Early TLS. Upgrade now to ensure your company remains compliant with the changes that start June 30, 2018.

Read More »

10/12/2017

Lay off the marketing plugins. Equifax hit with fake Flash update.

Equifax caught distributing malware. Be careful what you allow to be included in your website to avoid these sorts of hacks.

Read More »

10/11/2017

Automated Patching Will be New Reality

How fast can you update your production web application after an update is released? The answer better be within minutes. Automated testing and deployment is the only way.

Read More »

10/03/2017

Automate Security Scans with Continuous Integration

Learn how to automatically run bundle-audit and brakeman in your CI suite with an example for TravisCI.

Read More »

09/18/2017

Equifax Missed Defense in Depth, Allowing a Massive Data Breach

More than bad patch management, the weakness was Equifax's failure to design with the assumption that the front-end web server would be compromised.

Read More »

09/05/2017

Engine Yard's 17 Rails Security Tips

Read More »