August 2024
- Beyond the Facade: Evaluating Long-Term Impacts of Enterprise Software Architectures
Many enterprise products these days have a core architecture that consists of placing a proxy in front of an existing service. While the facade architecture makes sense in some cases, it's usually a temporary measure…
- When Words Mislead: Cybersecurity’s Terminology Problem
At Black Hat this year, I did my usual walk around the vendor floor. I talked to lots of companies about their products. One thing that stood out to me is vendors either by accident or on purpose are redefining terms in…
- The True Essence of Secure by Design
When we discuss "secure by design," we often focus on capabilities, features, and defaults—such as logging and monitoring, default-deny, regular updates, authentication, and minimizing by default privileges—rather than…
- CA Misissuance: A Tale of Two Incident Responses
Certificate Authorities on the web are tasked with validating that the websites we visit are truly associated with the domains that serve the content that makes up that website. As a result, we gain confidence that we…