News (10)

Debian and Ubuntu OpenSSL generates useless crypto keys

For almost two years the OpenSSL library used by Linux distribution Debian has been generating useless cryptographic keys — although Debian has issued a patch, experts warn that systems may still be exposed. Read more »

IE7 gives green light to trusted websites

Microsoft has quietly flipped the switch on a new feature in Internet Explorer 7 meant to combat phishing scams. Read more »

Browsers to get sturdier padlocks

The yellow security padlock in Web browsers, weakened by lax standards and loose supervision, will get reinforced next year with tougher requirements and browser updates. Read more »

Kaminsky details DNS flaw

Security researcher Dan Kaminsky has offered more details about a fundamental flaw in the Domain Name System and the extent of the vulnerability. Read more »

PHP, Python, Samba get security tick of approval

Perl, PHP, Python and Samba have been commended for improving security in a report analysing over 250 open-source projects. Read more »

Adobe releases beta of Flash for Linux

Adobe Systems has released a beta of a Flash Player 9 for Linux and said that it is working on 64-bit editions of Flash. Read more »

Microsoft outlines IE7 security plans

Microsoft is tightening up the way its Internet Explorer browser handles HTTPS for version 7, which is used to secure online transactions, in an attempt to give people more protection online. Read more »

Expert: Hold developers liable for flaws

Software developers should be held personally accountable for the security of the code they write, said Howard Schmidt, a former White House cybersecurity adviser. Read more »

Exposing software flaws -- no easy job

Security researcher Christopher Soghoian reflects on the hard work that comes after finding a vulnerability. Read more »

Crypto researchers abuzz over flaws

Encryption circles are buzzing this week with news that mathematical functions embedded in common security applications might have previously unknown weaknesses. Read more »

Features (24)

Learn to use the openssl command-line program

OpenSSL can be used to create, request, sign, and revoke certificates and can also be used to perform other cryptographic operations such as creating hashes for files, testing SSL connections, and more. Read more »

Hack proof your Web services

Web services promise to revolutionise your company's development practices by connecting your company seamlessly with customers and other companies worldwide. With this promise, however, come new threats from hackers and information thieves. Here are some tips for securing your Web Services. Read more »

Authenticate clients and e-transactions with SSL certificate authority

Secure Sockets Layer technology ensures that transactions are encrypted and safe from outside influences. Get the basics of setting up SSL Certificates of Authentication. Read more »

Use SSL to secure your Apache-based e-commerce transactions

Secure Sockets Layer technology ensures that transactions are encrypted and safe from outside influences. Get the basics of setting up SSL on Apache in this overview. Read more »

Use mod_ssl to configure Apache keys and certificates

The SSL is vital to the secure operation of many Web site transactions . This article will show you how to tweak the Apache mod_ssl module for your web site. Read more »

Gain SSL functionality in JDK 1.3

If you want to add SSL to your Java 1.3 applications, you'll need to work with some external packages to support it. Here's a look at the setup, along with the server-side code. Read more »

How to build a scalable VPN solution

Implementing a virtual private network (VPN) that you won't have to "rip and re-do" as your company expands takes some planning. This article takes a look at two important aspects of VPN planning: protocol scalability and software vs. appliance solutions. Read more »

.NET demystifies encryption

.NET makes cryptography a little simpler by putting everything into one SDK. Find out how to encrypt and decrypt a text file with the System.Security.Cryptography namespace. Read more »

Tools for securing your XML documents

The W3C offers two specifications for securing your XML documents, XML Signature and XML Encryption. Find out which tools can help create secure XML documents that adhere to these standards. Read more »

50 significant moments from internet history

We take you through 50 defining moments of the internet. Read more »

Log in


Sign up | Forgot your password?

  • Staff Crying, mooning and leaving

    In this week's roundup we see that continuous whining can get results, Linux users get 64-bit Flash and Moonlight previews, the latest in the Yahoo/Microsoft relationship and Senator Conroy ducks and weave in Senate Question Time. Read more »

    -- posted by Staff

  • Brendon Chase Sun eye Web developers with Netbeans 6.5

    Despite the recent employment axe hitting Sun the company has pushed out a new release of its Netbeans open source IDE with an eye to appeal more to Web developers. Read more »

    -- posted by Brendon Chase

  • Renai LeMay BarCamp buzz: Let the hacking continue

    Attending last weekend's BarCamp in Sydney, it was hard to escape the conclusion that a certain "dot-com bust" flavour had seeped into the kool aid previously being drunk by Australia's web 2.0 and early stage start-up sector. Read more »

    -- posted by Renai LeMay

What's on?