XSS Twitter in minutes; Why you shouldn't store important data with 37signals
brian.mastenbrook.net
XSS Twitter in minutes; Why you shouldn't store important data with 37signals
1–10 of 61 posts
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#2Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#3Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#4You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#5You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#6For all the horrible, terrible, awful things about Internet Explorer (namingly: standards support and UI) ... they are innovating heavily in security: http://www.microsoft.com/windows/internet-explorer/features/...
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#7You found a security exploit, feel special. Finding an exploit isn't a voucher to rant against the people responsible for it. The bottom line is that nobody can be 100% sure that their data is secure after they've put it in the hands of a third party.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#8For all the horrible, terrible, awful things about Internet Explorer (namingly: standards support and UI) ... they are innovating heavily in security: http://www.microsoft.com/windows/internet-explorer/features/...
Microsoft is actually decent at security now. The AV they released for free was actually on par with a few commercial products out there (all AV at the moment is pretty bad though, if you're curious). The really difficulty with Microsoft and security is countering their reputation for bad security that they earned over the past several years.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#9Earlier quoted context omitted.
Microsoft is actually decent at security now. The AV they released for free was actually on par with a few commercial products out there (all AV at the moment is pretty bad though, if you're curious). The really difficulty with Microsoft and security is countering their reputation for bad security that they earned over the past several years.
That's because Microsoft is good at anything that they throw resources at. Unfortunately, we haven't thrown enough resources at determining what to throw resources at.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#10I guess every web app should have a page dedicated to security similar to privacy policy and terms of service.
What are the essential information should go there? Special email dedicated to report security issues? PGP key to encrypt emails? and What else?