credit Experian CreditExpert ID Theft Protection - Security Review Update : 10/05/2013 - 4PM: The community forum has returned - with site-wide SSL enabled. Appropriate cookies are httponly & secure and protocol support, key transmission and cipher strength all pass with flying colours. Superb. It's still not immediately clear to the user that the username/password required for the forum differ to those of the main site - which could lead to confusion, but there's arguably no security risk there. The register/login form actions however, should be explicitl
acl MyDish.co.uk Security - Missing a vital ingredient? Update as of 15/03/13: I have received a number of emails asking for further comments on the situation @ MyDish. I firmly believe that every effort is being made to rectify the issues I've identified - and the insinuation that Carol or the team at MyDish have ignored the problem is entirely without merit. Beyond that, I'm not prepared to discuss the matter any further at this stage. If there are any updates, I will update this post accordingly. MyDish.co.uk is the brainchild of Carol Sav
Bugcrowd - is crowd-sourced security testing a good idea? "We use the power of the crowd to find and eliminate security vulnerabilities" Bugcrowd offers managed "bug bounty" programs for businesses... but is crowd-sourced security testing actually a good idea? First, let's take a look at the registration screen. "A steady stream of new targets to hone your skills" Put another way... " don't focus on one target, try as many as possible while you learn the trade" Security testing is a serious business. It requires absolute focus by a team of
Information Commissioners Office - Security Review "The Information Commissioner’s office (ICO) is the UK’s independent public authority set up to uphold information rights. We do this by promoting good practice, ruling on complaints, providing information to individuals and organisations and taking appropriate action when the law is broken." "We are responsible for data protection in England, Scotland, Wales and Northern Ireland; we also have some international duties." With responsibilities like that, you'd expect the ICO to be the pinnac
SaNmsung Galaxy S3 Power Case - Don't waste your money. I've recently upgraded from my old, trusty Nexus One (thanks Google) to a Samsung Galaxy S3. Within a few hours after it's first full charge, it was obvious the standard 2100mAh battery (although very good), just couldn't cope with my demanding usage and a bigger battery was needed. The fact you're reading this means you're probably in the same boat. So, on Sunday the 18th and after 10/15 minutes searching the web... I found this. http://www.ebay.co.uk/itm/290795113864?ssPageName=STRK:M
companies house Companies House Security Review - Part 2 Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go. Directory traversal still possible... hint encode/escape or strip, don't add slashes! Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs. At least progress is being made... can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure! At this point, I'm not sure wh
companies house Corporate Identity Theft - Perhaps the biggest risk is where you least expect it... Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go. Directory traversal still possible... hint encode/escape or strip, don't add slashes! Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs. At least progress is being made... can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure! At this point, I'm not sure w
localadverts4u.co.uk localadverts4u.co.uk - Amazing SEO offer or just spam? SEO spam is rife at the moment; not a day goes by without at least one arriving in my inbox. Most are deleted just as soon as they arrive, but one from localadverts4u.co.uk stood out for 2 reasons. 1. The email is particularly bad. 2. The name rang a bell - I had an email from a client just days earlier asking me to block them. The email makes for interesting reading... (click to enlarge) ... but is there any substance to it? Who are they? Apparently run by "David Gange" an
Santander: Input validation & output encoding, what's that? In order to handle data safely, a developer must understand exactly what data they're dealing with and the context within which it's used. Web/App developers (good ones at least) treat all data, regardless of its source, as potentially dangerous. As such, they have to validate (and where necessary, encode) everything you type in to their apps. If we ask for a phone number, we expect you to enter a number. If we ask for an email address, we expect the format to conform to that of an email a
santander Santander aren't secure - Should we bank online? "Your financial protection is our priority and we take this very seriously" "Our service actively protects both your identity and your finances." "We take every step possible to keep your finances and personal details safe." Confident statements; so you'd be forgiven for having equal confidence in their abilities to protect your information. In November 2011, I contacted Santander to alert them to several security concerns which needed to be addressed. Take the "online security" page for e
first post Rambling Rant - Open at last! Bye Blogger - The grass is greener at WordPress! Having spent many hours setting up Blogger, editing templates, adding features... I hit the "Domain Switching" bug which Google have been struggling with over the last few weeks. Not one to wait... I decided to move to WordPress and a new domain :) So... what next? My head's buzzing with comments on a variety of topics; from the government's ridiculous obsession with "super fast broadband" to "pre-installed viruses on new PCs"... so the n