In the news
Column: Opinion: Making apps safe is hard
2010-08-12 -at-09:23
In
this month’s Computerworld
column,
Ken delves into the
difficulties faced
by companies that run app stores. It turns out
that vetting apps for security criteria is a
really tough problem to solve, and one that’s not
likely to happen to any great degree on any of the
popular app stores today.
Column: Opinion: Maybe users aren't so funny after all
2010-03-16 -at-17:41
This
month in Computerworld,
Ken continues to delve into examples of how the
security community has failed the everyday
computer user. Click here to
read more on user base misconceptions regarding
e-mail and Web site safety.
Column: Opinion: Alice's adventures in cyberland
2010-02-18 -at-18:59
In
Ken’s February Computer world
column,
he uses a personal experience to point out how
computer security has failed the everyday
consumer. Click here to
read how this experience further supports his
argument for an app store for all users.
Column: IT's 5 big security mistakes
2010-01-18 -at-16:13
Happy
New Year! Ever resolve not to repeat mistakes? In
January's Computerworld
column,
Ken discusses IT's 5 big security
mistakes that
industry never seems to learn from.
Column: An app store for all?
2010-01-18 -at-15:54
Are
you an app store fanatic? Click here for
Ken's December Computerworld
column,
where he provides his opinion on the app store
model for desktop computers.
Column: Opinion: Can the SSL vulnerability hurt you?
2009-11-13 -at-15:22
Ken's column in November's issue of Computerworld is now
available. This month Ken offers his opinion on
whether the latest SSL vulnerability can hurt
you. Click here to read his
column.
Column: Why application-layer defenses belong in the applications
2009-10-12 -at-12:56
In this month's Computerworld, Ken's column
discusses why application-layer defenses belong
in the applications. Click here to read his column.
Column: No more excuses for SQL injection
2009-09-03 -at-11:34
Ken has a new monthly column, in Computerworld. Last month’s column discussed
vulnerability disclosure, and this month he takes on SQL
Injection attacks and how easy they are to
prevent.
OWASP podcast features KRvW
2009-02-27 -at-10:50
Ken was recently featured in an OWASP Podcast as part of
their ongoing series of podcasts. Click here for a link to the
podcast notes.
OWASP: Helping web developers write secure code
2009-02-03 -at-11:01
In Ken’s February column, OWASP: Helping Web Developers
Develop Securely, he talks about some of the
great work being done at OWASP to help software
developers figure out how to write secure web
applications.
CWE/SANS TOP 25 Most Dangerous Programming Errors
2009-01-12 -at-16:29
MITRE’s CWE and the SANS Institute together announced
today a list of the 25 most dangerous programming
problems. The full story can be found here:
SANS Institute - CWE/SANS TOP 25 Most Dangerous Programming Errors
Ken helped out early on with the effort by reviewing and commenting on early drafts. It’s a useful effort that should help us better understand the major underlying problems in our code today. The list should be a must-read for all software developers.
SANS Institute - CWE/SANS TOP 25 Most Dangerous Programming Errors
Ken helped out early on with the effort by reviewing and commenting on early drafts. It’s a useful effort that should help us better understand the major underlying problems in our code today. The list should be a must-read for all software developers.
Hack forced Twitter into "full security review"
2009-01-08 -at-09:16
Ken is quoted in Sharon Gaudin’s latest Computerworld
article,
Hack forces Twitter into 'full security review'.
Column: Security nightmare in the mobile app gold rush?
2009-01-07 -at-13:49
This month, Ken takes a look at some of the dangers
facing mobile application developers in the iPhone
(and other) application gold rush. His column,
Security Nightmare in the iPhone App Gold Rush is
now up.
Column: Safe online shopping
2008-12-03 -at-11:05
In this month’s column, “Safe Online Shopping: a Tech
Expert’s Tips,” Ken provides some pointers
that end users can take to be secure and
confident in their holiday shopping.
Column: The problem with penetration testing.
2008-11-16 -at-11:21
In his November column, Ken discusses a major problem
that happens far too often in penetration testing:
failing to adapt to the language of the audience. If
we really want to have penetration testing--or
security testing of any kind--affect real change, we
need to write to the audience of the software
developer, not (just) the IT Security manager. The
column can be found here on datamation.
October column
2008-10-07 -at-12:58
Ken’s October column has hit the
web.
This month’s topic was about understanding how users will make use of security features in products, and using that knowledge to make the products better.
This month’s topic was about understanding how users will make use of security features in products, and using that knowledge to make the products better.
Interviewed on Silver Bullet Podcast
2008-10-01 -at-09:51
Ken was recently a guest on Gary McGraw’s Silver Bullet podcast. The
podcast is available for listening or
download here.
The topic was on software security, covering many aspects of what is happening in the field today.
The topic was on software security, covering many aspects of what is happening in the field today.