News (42)

Microsoft to embed Live services in Windows

Microsoft's Live-branded online services don't end at the Web browser. They extend deep into Windows. Read more »

Web 2.0 potential unmet?

Despite the explosion of new Web services, a number of hurdles stand in the way of consumer- and business-oriented social-networking applications, experts at the Web 2.0 Summit said Tuesday in the US. Read more »

Microsoft tries to stop Vista piracy monster

Microsoft has issued an update to Windows Vista that's intended to stop a piracy monster. Read more »

Liberty Alliance launches new standards

The launch of ID-WSF 2.0 extends support to SAML 2.0, and should allow easier communication between secure Web services based upon other open standards. Read more »

Zope launch next-generation application server

The open-source organisation has released the first version of Zope X3, which has been completely rewritten to improve the architecture. Read more »

Oracle plugs 101 security flaws

As part of its quarterly patch cycle, Oracle released fixes on Tuesday for 101 security vulnerabilities across its products. Read more »

Oracle patches 11i security flaws

Oracle has issued an upgrade to its E-Business Suite 11i diagnostics module containing a number of the security fixes, according to applications security firm Integrigy. Read more »

Cisco patches security-monitoring system

Networking giant Cisco Systems has fixed several flaws in a security monitoring product meant to protect networks against attacks. Read more »

Oracle plugs 65 security holes

As part of its quarterly patch cycle, Oracle on Tuesday in the US released fixes for 65 security vulnerabilities that affect many of its products. Read more »

Google adds OAuth to gadget mashups

Google has adopted the OAuth web-authentication standard, an open standard for controlling privacy, for its gadget platform. Read more »

Features (99)

How to build secure ASP.NET applications

ASP.NET provides several ways to protect your Web-based app from attack. Here's an overview of authentication, authorisation, and role-based security. Read more »

Integrate Passport into ASP.NET apps

If you are looking for a secure means to transfer sensitive information in an ASP.NET application, try integrating Microsoft's Passport service. Read more »

Master simple forms authentication in .NET

Using forms authentication, you can quickly build a simple, secure Web app. This walk-through shows you how to apply the strategy in your apps. Read more »

Designing secure intranet applications

During the design phase, engineering and security teams must work together to ensure intranet applications meet the established security standards. Read more »

Why AOL wants developers to put passion over profit

Edwin Aoki, technology fellow at AOL, speaks about the impact web applications have had in the enterprise and what trends are emerging. Read more »

Keeping the door open...and shut

A Web server opens up your business to the outside world, so how do you keep out those parts of the world you don't like? Read more »

Kerberos vulnerability hits Linux/UNIX versions

The Kerberos Administration daemon (kadmind), which is used in connection with Kerberos authentication, contains a buffer overflow vulnerability in many implementations, mostly affecting Linux/UNIX. Read more »

Cookieless data persistence is possible

Cookies are a common way to store retrievable user information, such as authentication data. But what if you need a non-cookie solution? Read more »

Authenticate clients and e-transactions with SSL certificate authority

Secure Sockets Layer technology ensures that transactions are encrypted and safe from outside influences. Get the basics of setting up SSL Certificates of Authentication. Read more »

Web application security frameworks (WASF), Part 1: Introduction

Often you will want parts of your Web application to be exclusive to certain users. This access distinction requires the use of Web application security frameworks. This first article in the series introduces you to the three most often used methods. Read more »

Video (2)

RSA 2008: Microsoft outlines Internet security strategy

At the RSA 2008 conference in San Francisco, Microsoft Research and Strategy Officer Craig Mundie describes a new plan for Internet security that includes the creation of a trusted stack. Each element can be authenticated, from the operating system to applications, people, and data. Read more »

Charney: Customers the biggest hole in Microsoft's security

Microsoft customers need to better authenticate applications they install on their PCs, so the next challenge for Microsoft is to figure out how to provide that information, according to Scott Charney, the VP of Microsoft's Trustworthy Computing Group. Read more »

Log in


Sign up | Forgot your password?

What's on?