Software Integrity Blog

Author Archive

Taylor Armerding

tarmerding

Taylor Armerding is an award-winning journalist who left the declining field of mainstream newspapers in 2011 to write in the explosively expanding field of information security. He has previously written for CSO Online and the Sophos blog Naked Security. When he’s not writing he hikes, bikes, golfs, and plays bluegrass music. Follow him on Twitter @tarmerding2.


Posts by Taylor Armerding:

 

Click2Gov breaches show the power of zero-days

Patching issues fast is a step toward software security. But as the Click2Gov breaches show, zero-day vulnerabilities resist even the most persistent patchers.

Continue Reading...

Posted in Data Breach, General | Comments Off on Click2Gov breaches show the power of zero-days

 

Can we please drive passwords into extinction now?

Passwords are antiquated and insecure. It’s time to eliminate them altogether. Experts from FIDO explain how to enable authentication without passwords.

Continue Reading...

Posted in General | Comments Off on Can we please drive passwords into extinction now?

 

It’s past time to pay much more attention to API security

Organizations manage 363 APIs, on average. But vulnerable APIs can expose your data to anyone who knows how to ask for it. API security starts with the basics.

Continue Reading...

Posted in Web Application Security | Comments Off on It’s past time to pay much more attention to API security

 

SEC getting more aggressive on financial cyber lapses

SEC security measures, or cyber enforcement actions, are powerful incentives for financial institutions to protect investments and data from theft and fraud.

Continue Reading...

Posted in Financial Services Security, Security Standards and Compliance | Comments Off on SEC getting more aggressive on financial cyber lapses

 

Chenxi Wang polishes her 2019 crystal ball

Dr. Chenxi Wang, founder of Rain Capital, shares some of her 2019 cyber security predictions about the cloud, GDPR, blockchain, DevSecOps, privacy, and ICS.

Continue Reading...

Posted in General | Comments Off on Chenxi Wang polishes her 2019 crystal ball

 

President’s ‘cybersecurity moonshot’: Transformational or pie in the sky?

Making the internet safe and secure in 10 years isn’t going to be easy, if it’s even possible. And that’s why NSTAC’s new proposal is a cyber security moonshot.

Continue Reading...

Posted in General | Comments Off on President’s ‘cybersecurity moonshot’: Transformational or pie in the sky?

 

Hard questions raised when a software ‘glitch’ takes down an airliner

The parts and systems on an airplane don’t have to fail in a big way to have big consequences. A flaw in airline software could be a matter of life or death.

Continue Reading...

Posted in General | Comments Off on Hard questions raised when a software ‘glitch’ takes down an airliner

 

Air gaps in ICS going, going … and so is security

As smart shipping and other network-connected industrial control systems (ICS) grow, the air gap loses value as a barrier against cyber attacks. What’s next?

Continue Reading...

Posted in General | Comments Off on Air gaps in ICS going, going … and so is security

 

Both consumers and retailers need to up their cyber security to make holidays happy

We’ve got some Black Friday advice for retailers and shoppers who want to keep everyone’s data safe and secure, for a truly happy holiday season.

Continue Reading...

Posted in General | Comments Off on Both consumers and retailers need to up their cyber security to make holidays happy

 

Don’t expect jailed CEOs, but Wyden at least puts consumer privacy on the table

The Consumer Data Protection Act (as outlined in the CDPA draft circulated in early November by Sen. Ron Wyden) might not send CEOs to jail, but it will certainly help protect Americans’ data.

Continue Reading...

Posted in General, Security Standards and Compliance | Comments Off on Don’t expect jailed CEOs, but Wyden at least puts consumer privacy on the table