Live data from Hacker News

Recommended Security Reading

dfir.org

31–40 of 51 posts

Re: Recommended Security Reading

#31
Really a better list is by tom his own self: http://www.amazon.com/lm/R2EN4JTQOCHNBA/ref=cm_lm_pthnk_view...

My recommendations would add:

http://www.amazon.com/The-Codebreakers-Comprehensive-Communi... by David Kahn. Many stories of the whole history of secret communications, with lessons in op-sec, not changing the codes frequently enough, they can't possibly break this.

The John LaCarre http://en.wikipedia.org/wiki/John_le_Carr%C3%A9 books. Do you remember the point where someone says to Smiley "There is no reason to think that they tapped the phone" to which Smiley replies "There is Every reason".

A must read, I tell my students in my Security Awareness training classes is The Cuckoo's Egg http://www.amazon.com/The-Cuckoos-Egg-Tracking-Espionage/dp/.... Examples like default service accounts on Dec Vax with username Field and password Service. Note when this is written and are our habits really any better with junk hung on the internet? Concepts pioneered in his book, as effective as they are, are not practiced. Note the alarms going off, ignored, at a large retailer last thanksgiving. Or another retailer recently, "Wait, what, we are being attacked? I didn't feel anything".

Most vulnerable is the thinking "Well, they can't get our X because ". I have a matrix of attacker motives and what they are after. There motives and targetsyou haven't thought of.

Re: Recommended Security Reading

#32
post #25
post #14

Avoid _Applied Cryptography_. You probably won't get too much value from _Introduction to Modern Cryptography_, either. The only cryptography book I can recommend is _Cryptography Engineering_ (nee _Practical Cryptography_, which is virtually identical). You would be surprised how few professional security people know anything about cryptography. It certainly isn't a qualifier. I generally have a hard time with any b…

Hey Tom, I have now heard from several people about applied crypto being outdated and replaced with crypto engineering. I have since ordered the engineering book and based on initial reading will likely replace applied with crypto engineering once I am done (I only post books I have fully read). I am not sure about the criticism of intro to modern crypto and design patterns though. I learned alot from both of them in…

I have a lot more to say about A.C.:

http://sockpuppet.org/blog/2013/07/22/applied-practical-cryp...

I really think people should avoid that book.

Re: Recommended Security Reading

#33
post #32
post #25

Earlier quoted context omitted.

Hey Tom, I have now heard from several people about applied crypto being outdated and replaced with crypto engineering. I have since ordered the engineering book and based on initial reading will likely replace applied with crypto engineering once I am done (I only post books I have fully read). I am not sure about the criticism of intro to modern crypto and design patterns though. I learned alot from both of them in…

I have a lot more to say about A.C.: http://sockpuppet.org/blog/2013/07/22/applied-practical-cryp... I really think people should avoid that book.

Thanks, you have definitely convinced me to remove it now.

Re: Recommended Security Reading

#34
post #30

Earlier quoted context omitted.

"Of the original GoF patterns, which specific ones make it easier to discuss SQL injection?" That doesn't seem to be the claim made in the parent comment. I read it as a far weaker, "In much the same way that security researchers label antipatterns that enable attacks and that makes it easier to talk about security, the GOF label patterns that make it easier to talk about design." I don't know that the parent comment…

From an security professional's point of view, the idea is to find flaws in software, developers thinking, or corporate culture that make vulnerabilities for attack. GoF doesn't really help with any of the above. What GoF helps with is shoring up weak languages that don't have the proper stuff to begin with. It talks about abstractions and how to build them. What is useful from a security professional's point of view…

Did you just want to voice your opinion and find my comment relevant enough to serve as a place to hang it, or did you mean that as a response to what I wrote? I don't think I substantively disagree, although I think Norvig's claim is often read (not sure if intended) slightly stronger than is merited. I would also note that the list does not seem to be restricted to "security professionals", but to all those interested in learning about the topics in the list I quoted above. I broadly agree with the thesis that Design Patterns doesn't fit that mold particularly well.

(In general, I find it a recurring problem on HN - and to some degree similar fora - that I am not sure what conversational role a poster intended their comment to serve; I wonder if there is a good way to address that...)

Re: Recommended Security Reading

#35
The Hacker Crackdown by Bruce Sterling (cyberpunk author) is awesome. It's the story of Captain Crunch and the rest of the phone phreaks in the late 80s and early 90s, and some of the earliest prosecutions of hacking by the U.S. federal government. Apparently they still throw a 2600 magazine party at defcon....

http://www.mit.edu/hacker/hacker.html

Re: Recommended Security Reading

#37
post #30

Earlier quoted context omitted.

From an security professional's point of view, the idea is to find flaws in software, developers thinking, or corporate culture that make vulnerabilities for attack. GoF doesn't really help with any of the above. What GoF helps with is shoring up weak languages that don't have the proper stuff to begin with. It talks about abstractions and how to build them. What is useful from a security professional's point of view…

Did you just want to voice your opinion and find my comment relevant enough to serve as a place to hang it, or did you mean that as a response to what I wrote? I don't think I substantively disagree, although I think Norvig's claim is often read (not sure if intended) slightly stronger than is merited. I would also note that the list does not seem to be restricted to "security professionals", but to all those interes…

It happens to all of us. There's value in all the comments on these threads; we shouldn't take any of them personally.

Re: Recommended Security Reading

#38
post #31

Really a better list is by tom his own self: http://www.amazon.com/lm/R2EN4JTQOCHNBA/ref=cm_lm_pthnk_view... My recommendations would add: http://www.amazon.com/The-Codebreakers-Comprehensive-Communi... by David Kahn. Many stories of the whole history of secret communications, with lessons in op-sec, not changing the codes frequently enough, they can't possibly break this. The John LaCarre http://en.wikipedia.org/wik…

I got Codebreakers over 15 years ago, and I still haven't finished it. That thing is incredibly dense.

I don't know if this is a recommendation, an anti-recommendation, or an excuse.

Re: Recommended Security Reading

#39
post #31

Really a better list is by tom his own self: http://www.amazon.com/lm/R2EN4JTQOCHNBA/ref=cm_lm_pthnk_view... My recommendations would add: http://www.amazon.com/The-Codebreakers-Comprehensive-Communi... by David Kahn. Many stories of the whole history of secret communications, with lessons in op-sec, not changing the codes frequently enough, they can't possibly break this. The John LaCarre http://en.wikipedia.org/wik…

I got Codebreakers over 15 years ago, and I still haven't finished it. That thing is incredibly dense. I don't know if this is a recommendation, an anti-recommendation, or an excuse.

At the very least, it's a challenge to all the habitual readers on HN.
Post reply on HN