News (42)

Mozilla: Hackers control bug disclosure

Software makers are at the mercy of bug hunters when it comes to flaw disclosure, Mozilla's security chief said on Saturday. Read more »

Microsoft to fix three 'critical' security holes

Patch Tuesday this week will include fixes for six security bugs, three of which are rated 'critical'. Read more »

Mozilla puts bounty on bugs

A string of high-profile flaws in browser software prompted the Mozilla Foundation to announce on Monday that it would offer US$500 for every serious bug found by security researchers. Read more »

Study: Few bugs in MySQL database

A source-code analysis of the MySQL database, a popular open-source program at the heart of many Web sites, revealed few bugs compared with the number found in commercial code, testing company Coverity said Friday. Read more »

No security silver bullet for Vista: Microsoft

Despite extensive security auditing and development of Vista, the new operating system will not be free of bugs, Microsoft general manager of product security, George Stathakopoulos, concedes. Read more »

Hackers claim zero-day flaw in Firefox

The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon in the US. Read more »

No compensation for 'responsible disclosure': Microsoft

Paying independent security researchers a bounty for responsibly disclosing vulnerabilities is not the best way to protect users, according to Microsoft. Read more »

Black Hat with a Vista twist

Black Hat is not just about breaking and entering this year as Windows Vista and IE7 come under the spotlight. Read more »

Interview with Alan Cox

One of the head programmers behind Linux, Alan Cox talks exclusively to Builder Australia about the uptake of Linux, Microsoft's plans to share its source code and his Linux predictions. Read more »

Security guru wants access to bug databases

Security expert Ross Anderson has called for empirical research to be conducted into whether open source or closed source software is more secure, and into the impact that development practices such as extreme programming (XP) have on code quality. Read more »

Features (8)

Smart planning reduces Web services security risks

Web services have great potential, but security concerns are preventing many organisations from taking advantage of the technology. Here are several suggested policies that CIOs can follow to develop a solid Web services plan. Read more »

Bug hunters, software firms in uneasy alliance

Although many software makers promote responsible disclosure, it isn't universally backed by the security community. Critics say it could make security companies lazy in patching. Full disclosure of flaws is better is preferred. Read more »

New security flaw in Outlook, IE

A Danish security researcher has warned that a recently discovered software flaw could leave user's systems open to malicious code carried on Web pages or in e-mails. Read more »

Develop secure software at the application level

Protect your application from input overflow and underflow attacks, and from other common tactics with these development techniques. Read more »

The Kiwi behind Firefox

Ben Goodger is the lead engineer for the Firefox browser. He talks about Firefox's history, and how he sees it competing with Longhorn. Read more »

Open source's lessons from userspace

Where is the Open Source Usability Experts Group? When you've got your database specialist, your glue logic guy and your OS expert together, where's the person who knows how real non-technical people react to software design? Read more »

Strengthen your app defences

These tips will help you secure your network against attacks that exploit application vulnerabilities. Read more »

A tour of the PHP.INI configuration file, part 1

The php.ini configuration file lets you alter many aspects of PHP's behaviour, including setting file paths and directories, changing session and database parameters, and activating extensions. Read more »

Log in


Sign up | Forgot your password?

What's on?