Today I read in a forum someone asking about the best way to write an organization’s security policy; should it be a long and complete document or a simpler one with just a couple of pages? I was answering the question when I realized I could post here some of the approaches I have been [...]
I always like to read people trying to look again to more basic issues on security. This approach permits us to find more elegant solutions and is the way to the revolutionary ideas, those that we look at later and think “oh, but it was so obvious!”. I’m always discussing with my clients about why [...]
Since the WMF vulnerability in January 2006 the client applications seemed to become the next target for malware and malicious attackers. I wrote about the evolution of threats and related vulnerabilities at that time. So, it’s not very surprising to see here and here that people are worried about vulnerabilities in software other than the [...]