[SC-L] AJAX: Is your application secure enough?

2006-04-05 Thread Kenneth R. van Wyk
Another interesting paper passing through slashdot today is AJAX: Is your application secure enough? You can find it at http://www.darknet.org.uk/2006/04/ajax-is-your-application-secure-enough/ Looks to me like an interesting read, fwiw. Much as I like the interactiveness that AJAX brings to

Re: [SC-L] Re: [Owasp-dotnet] RE: 4 Questions: Latest IE vulnerability, Firefox vs IE security, User vs Admin risk profile, and browsers coded in 100% Managed Verifiable code

2006-04-05 Thread Crispin Cowan
Pascal Meunier wrote: AppArmor sounds like an excellent alternative to creating a VMWare image for every application you want to run but distrust, although I can think of cases where a VMWare image would be safer. For example, the installer/uninstaller may have vulnerabilities, may be dirty

[SC-L] Some different ways to authenticate people

2006-04-05 Thread Glenn Everhart
Some authentication ideas I have come up with may bear mention given all the attention problems of authenticating folks remotely have been getting. Let us suppose to introduce the ideas that we have some token we give folks such that it displays a number sequence (that may vary with time or