Security Archives
By Justin
Posted on Jul 10, 2008
Comments (0)
Obfuscation, aside from being a tongue-twister to pronounce, is an important topic within the realm of .NET development. While some folks around the inter-webs might have you believing that obfuscation is a useless, needless or worse - a complete joke and waste of your time - they couldn't be any further from the truth.
Continue reading ".NET Obfuscation - A Waste of Time? Or Not?" »
By Jason Sherrill
Posted on Feb 21, 2008
Comments (0)
Today I signed into one of my AT&T accounts and was presented with their risk-based authentication (RBA) setup page. The challenge question choices they presented reminded me how important it is to follow a few simple rules when choosing challenge questions for your users to choose.
Continue reading "Best Practices for Choosing Challenge Questions for Bank and Credit Union Web Sites" »
By Jason Sherrill
Posted on Jan 4, 2008
Comments (0)
Last week I got a new computer (IBM ThinkPad T60p), which means I retired my old ThinkPad T41. Today is the first time that I've tried to logon to my Chase online account to pay my credit card bill, which is due today. I've never had a problem logging on, but today the Chase online banking site has recognized that my computer fingerprint has changed. The hair-pulling experience I'm in the middle of right now has reminded me that it's a fine line we as software developers walk between creating tough-to-crack security while continuing to make sure our software is user friendly.
Continue reading "Tough Security vs. Good Usability on Chase Bank Website" »
By Jason Sherrill
Posted on Sep 21, 2007
Comments (0)
PGP (www.pgp.com) is one of the most common methods of protecting financial data that customers submit through bank and credit union websites. PGP provides excellent data encryption, but many users leave sensitive PGP-encrypted data vulnerable without even knowing they’re doing so.
Continue reading "Encrypted Email -- Bank and Credit Union Employees Unknowingly Put Banking Data at Risk" »
By Jason Sherrill
Posted on Aug 2, 2007
Comments (0)
The second most common question that managers at banks, credit unions and other financial institutions have asked me over the past year is, "What is the best way to secure our online forms, such as loan applications and contact us forms?" Here are a few simple guidelines your development team should follow when creating your online applications.
Continue reading "Seven Tips Every Bank and Credit Union Manager Should Know About Securing Online Forms" »
By Jason Sherrill
Posted on Jun 6, 2007
Comments (0)
Mildew Stain Away is a fantastic mildew stain remover that also prevents mildew from returning. I used to buy it at Damman Hardware, but they've gone out of business. Last night, I discovered that Amazon Products, the manufacturer, sells the product directly on their website. But due to a major mistake on their website, I'm willing to bet that they're not selling nearly as much as they could.
Continue reading "optional checkout security = no sale" »
By Jason Sherrill
Posted on Sep 19, 2006
Comments (1)
One of our clients recently moved to a new office. They tried to transfer their LDMI telephone and DSL service to the new building, but LDMI missed several deadlines so our client switched to AT&T. Today, our client called seeking advice on troubleshooting some network problems after the AT&T DSL installer left. After 20 minutes of pinging, ipconfig'ing, switching SMTP server settings and numerous other troubleshooting steps, I determined that their internal LAN subnet had changed. "Hmmm," I thought.
Continue reading "Beware of the SBC DSL Installer" »