Skip to main content

Posts

Featured

Don't be so offensive

Recognition is growing that cybersecurity presents a systemic - and potentially existential - threat to companies, governments, and even modern civilisation itself. Yet, even today, many policy choices are producing a paradoxical outcome: in seeking digital advantage, we may be systematically increasing our own exposure to digital catastrophe.  Nicole Perlroth's  This Is How They Tell Me the World Ends: The Cyberweapons Arms Race   documents the rise of the global market for software exploits and zero-day vulnerabilities — previously unknown flaws that can be used to compromise systems before vendors can patch them. One uncomfortable conclusion emerges: governments purchasing vulnerabilities and exploits played a significant role in professionalizing and expanding that market. By offering high prices and legal protection for exploit acquisition, intelligence agencies helped shift researcher incentives away from disclosure and remediation and toward secrecy and weapon...

Latest Posts

The soothsayer

AdTech

Token lockdown?

Holding OIDC's narrative up to the light

OAuth is DAC. What do you do for MAC?

tl;dr: OAuth 2.0

Externalising the Security Token Service and Identity Provider

Problems with Basic Authentication for REST services

Bearer tokens are susceptible to theft and what you can do about it

In the (back)end, JWT is all that matters