IT Security Weekly Newsletter
IT Security Weekly Newsletter

Top new questions this week:

Does password-protecting a server's BIOS help in securing sensitive data?

I'm running a server of which I protected the BIOS with a password. One doesn't have to enter this password before booting, but before entering the BIOS setup. I just did this from routine. However, …

passwords webserver server bios  
asked by Camil Staps 16 votes
answered by Iszi 7 votes

Can robots.txt for your face be made effective?

As Google Glass slowly starts shipping, I've recently came across an article on stopthecyborgs.org that mirrors my anxieties that Google Glass currently does not feature a robots.txt for my face. It …

privacy google  
asked by naxa 10 votes
answered by Tom Leek 19 votes

"Please Enter Nth Character" without HSM

This question has been asked a few times, but always in the format "How does examplewebsite.com implement their 'please enter xth yth and zth characters of your password' function?" And the …

encryption passwords hash hsm  
asked by lynks 9 votes
answered by Tom Leek 8 votes

How can I circumvent the lack of Java updates?

Just imagine you have a bunch of computers which need Java for some important software and you can't just switch to another vendor because all are using Java in this field of technology. If you start …

malware java updates  
asked by vlad 7 votes
answered by Eric G 4 votes

What are the risk implications of not verifying referer header on login form?

Imagine a generic web application with a login form to access the application. Regardless of how the actual authentication is performed, what are the implications of not checking the referer header to …

csrf validation risk referer  
asked by SteveS 7 votes
answered by Tom Leek 6 votes

Truly deniable encryption

What tools can be used to make truly deniable encryption? Suppose, authorities can use any force to make you open your passwords. Truecrypt can have only one hidden container, which means that …

encryption truecrypt  
asked by doom123 6 votes
answered by lynks 6 votes

how secure is passwordcard.org?

How secure is passwordcard.org? Assuming user follows recommended precautions: Don't read along with your finger, or the smudge will tell a thief where your password is. Keep your PasswordCard on …

password-management  
asked by anon 6 votes
answered by Rell3oT 4 votes

Greatest hits from previous weeks:

Can someone steal money from my bank account if they know my IBAN and personal details?

To deposit money into your account, some websites require that you provide them with a lot of details about your bank account: name, complete address and IBAN which includes your account number and …

authentication access-control legal  
asked by Gess 12 votes
answered by M'vy 12 votes

How secure is TeamViewer for simple remote support?

I'm deploying a web-based ERP system for a customer, such that both the server and the client machines will be inside the customer's intranet. I was advised in another question not to use TeamViewer …

network remote-desktop  
asked by mgibsonbr 11 votes
answered by Rory McCune 11 votes

Can you answer these?

In the Clark Wilson models, why can't the TPs be executed in parallel?

I am studying the Clark-Wilson model, I can't exactly understand why the TPs must be executed in serial, is there a way to execute them in parallel? What would happen if I did execute them in …

integrity  
asked by AscaL 3 votes

Webapp2 security

I am coding a REST web application that runs on Google App Engine, it authenticates API requests to privileged data using sessions by cookies provided by webapp2_extras.auth and …

web-application session-management  
asked by Cris Stringfellow 4 votes

Two-way authentication with google authentication app

Can someone guide me on what I've done wrong with implementing Google authentication app? Here is what I've tried without success: 1# Create secret key $chars = …

authentication php  
asked by Manish Trivedi 1 vote
Subscribe to more Stack Exchange newsletters


Unsubscribe from this newsletter or change your email preferences by visiting your subscriptions page on stackexchange.com.

Questions? Comments? Let us know on our feedback site. If you no longer want to receive mail from Stack Exchange, unsubscribe from all stackexchange.com emails.

Stack Exchange, Inc. 110 William St, 28th Floor, NY NY 10038 <3