BACK to Blog

Security links [6.2.2010]

(My 10+ years worth of security bookmarks, actually. New links added frequently, hardly never cleaned. Lots of outdated and broken links).


News & portals
Magazines & Newsletters
Terms
Papers, presentations

Online books

Discussions, Mailing lists
Known Bugs, Warnings
Advisories
Guidelines
Standards
Laws

Awareness

Risk Management

Security Management
Psychology
Identity, Authentication and Access Management
Disaster Recovery, Business Continuity
Organizations

Conferences

Surveys, stats
Software security
Intrusion Detection Systems

Penetration testing
Public Key Infrastructure
LDAP, Directories
Virtual Private Networks
Firewalls

Crypto

Biometrics
Unix
Windows
Mobile & Wireless 

Ethics
Privacy
Incidents, exploits, hacks, vulnerabilities 
Hackers, crackers, script-kiddies
Infowar, Hactivism
"Traditional Security"

People
Fun
Blogs & Podcasts


   What's new (most recent first)

    1. Profiling The Defenders
    2. Simplified Implementation of the Microsoft SDL
    3. Active Man-In-The-Middle Attacks
    4. Security Metrics Catalog
    5. KATAKRI: Kansallinen Turvallisuusauditointikriteeristö (finnish)
    6. ITIL v3 and Information Security
    7. Ponemon 2009 Annual Study: Cost of a Data Breach
    8. BSI standard 100-4 on Business Continuity Management
    9. Blog: PCI Guru
    10. Verified by Visa and MasterCard SecureCode: or, How Not to Design Authentication
    11. Deloitte: Cyber Crime: a clear and present danger
    12. SDL Quick Security References
    13. The psychology of scams: Provoking and committing errors of judgement
    14. SSLLabs - How Well Do You Know SSL
    15. Secure Web Application Framework Manifesto
    16. ATM Crime: Overview of the European situation and golden rules on how to avoid it
    17. So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users
    18. Bruce Schneier (fun) facts
    19. OISSG: pen Information Systems Security Group
    20. Understanding scam victims: seven principles for systems security
    21. Foreign Influence on Software Risks and Recourse
    22. Enhancing the Development Life Cycle to Produce Secure Software
    23. Toward an Organization for Software System Security Principles and Guidelines
    24. Information Assurance (IA) Newsletter
    25. Security Acts Magazine
    26. ENISA:Cloud Computing Risk Assessment
    27. Ross Anderson Psychology and Security Resource Page
    28. Observations on Balancing Discipline and Agility
    29. Spider for credit card and other confidential data
    30. InfoSec Island

News & Portals

Magazines & Newsletters

Terms, FAQs

Papers, presentations

Online books, guides

Discussions, Mailing-lists

Known Bugs, Warnings

Advisories

Guidelines

Standards and "standards"

    Common Criteria / ISO 15408

    BS7799 / ISO17799 / ISO 27000

PCI

Laws, directives, etc.

    General

    Finnish Laws

    EC

Awareness

Risk Management

    Methods  & tools

Security Management

Psychology

Identity, Authentication and Access Management

Disaster Recovery, Business Continuity

Organizations

    CERT

Conferences, seminars

 
Surveys, stats

Software security

    Databases

    Design 

    Programming

    Examples, known problems

  Testing

    Tools -free

    Tool - commercial

    Web Services, XML security

    Intrusion Detection Systems

    General

    Articles, papers, presentations

    Commercial tools

    Free tools

    Trojans, vulnerabilities, port numbers

    Analysis

    Snort

    Snort-based commercial products

     Incident handling & forensics

Penetration testing

    General    

    Commercial tools

    Free tools   

Public Key Infrastructure

    General

    Articles, papers, presentations

    Finnish Electronic Identity (fineid)

    Tools

LDAP, Directories

    General

    Articles & presentations

    Free tools

Virtual Private Networks

Firewalls

Crypto

    General

    IPSEC

    SSL/TLS

    Email

    Cryptanalysis

Biometrics

Unix

Windows

Mobile & Wireless

Ethics

Privacy

    Spam  

    Phishing

    Are you being monitored?

Incidents, exploits, hacks, vulnerabilities

Hackers, crackers, script-kiddies,...

Infowar, Hactivism, Network Centric Warfare

Traditional Security

People

Fun

    Videos, hack-tv, clips

    Blogs & Podcasts

Podcasts