Articles: TechRepublic IT Security Column
The following are articles Chad Perrin has written for the TechRepublic IT Security column, listed by title in roughly chronological order. You may notice some variance in article titles between this list and the articles at TechRepublic. Chad has little or no control over editorial changes made after the article has been submitted there.
- Five Steps To Becoming The Local Security Guru
- Check Out The Results Of CNET's Security Vendor Survey
- Myth: I'm Not Really At Risk
- Reduce Permissions To Increase DNS Security
- Unix/Linux Rootkits 101
- Rootkits 201
- There's More To Security Than Counting Vulnerabilities
- Security Specialists' Salaries Are Up . . . So What?
- The Three Elements Of Access Control
- 10 (+1) Reasons To Treat Network Security Like Home Security
- Implement Integrity Auditing With Basic Utilities
- Use Rsync For Filesystem Integrity Auditing
- Rootkit Redux: Sony Doesn't Learn From History
- Why There's No Such Thing As A Trusted Brand
- Use Mtree For Filesystem Integrity Auditing
- The Truth About Viruses
- Top 10 News Items, September 15: What's Interesting In IT Security This Week
- Work With End Users -- Not Against Them -- To Improve Security
- Use The Fire.Rb Library To Write Port Knocking Scripts In Ruby
- Privacy Is Security
- Happy Birthday, OpenSSH
- Linux Phishing Botnet Statistics Can Be Deceptive
- Why There's No Such Thing As A Zero-Day Vulnerability
- Network Monitoring For Fun And Profit
- Protect Your Computer And Your Data With A UPS
- 10 Security Tips For All General-Purpose OSes
- A Little More About Passwords
- Automating Shutdown When Your OS Doesn't Support Your UPS
- Protect SSH From Brute Force Password-Cracking Attacks
- 10 Services To Turn Off In MS Windows XP
- Why Encryption That Doesn't Trust The User Isn't Trustworthy
- Radiohead Knows More Than Microsoft About Security
- 10 Wi-Fi Security Tips
- The Politics Of Phishing
- Teach A Man To Fish
- What My Grandmother Taught Me About IT Security
- If You Want Something Done Right . . .
- Follow A University Course In Cryptography For Free
- Use MD5 Hashes To Verify Software Downloads
- Bolted-On Security Features Aren't Secure
- Use The Blowfish Cipher To Improve Password Security
- The Value Of Accidental Security Through Obscurity
- Security TV: "Tiger Teams" Showing This Christmas
- PGP Corps "The 12 Threats Of Christmas"
- The Best Security Article Of 2007 (Isn't About Security)
- SPAM And SPIT: What Are The Dangers?
- Deleting Files Isn't Always Enough
- Retrospective: 10 Security Blunders
- Interface Design Is Security Design
- Using Pf And ALTQ For QoS Management
- The Truth About Email Spam
- How To Spoof A MAC Address
- How To Avoid Being A Phishing Webserver Admin
- Security Is An Ecosystem, Not A Product
- Five Must-Have Security Resources
- Using OpenPGP On Unix/Linux Systems With GnuPG
- How Private Is Your Web-Based Service?
- Use OpenSSH As A Secure Web Proxy
- Basic Email Security Tips
- 10 Tips For Effective Use Of OpenPGP With GnuPG
- Using GnuPG With Mutt To Sign Or Encrypt Email
- Use PuTTY As An SSH Client On MS Windows
- Use PuTTY As A Secure Proxy On MS Windows
- Ensure Basic Web Security With This Checklist
- What Is Cross-Site Scripting?
- The Big Brother Awards
- Using GnuPG Encryption Tools With Gpg4win
- The Importance Of Being Encrypted
- Security 101, Remedial Edition: Obscurity Is Not Security
- DRM And Unintended Consequences
- Meet Me At Penguicon
- Use Getmail To Get Email Simply And Securely
- Use SSMTP To Send Email Simply And Securely
- List Open Ports And Listening Services
- Close Unneeded Ports On Unix/Linux Systems
- Fighting Fire With Fire
- Fighting Fire With Water
- Five Security Tips From MediaWiki's Lead Developer
- There Is No Perimeter, Kinda
- Has Security Grown Beyond DIY?
- The "Insecure Memory" FAQ
- Detect And Replace Vulnerable SSH Keys On Debian
- Not Invented Here Has No Place In Open Source Development
- Making Encryption Popular
- Is PhoneFactor Really Better Security?
- Security Alarmism Helps The Bad Guys Win
- Why You Can't Get Management On Board
- How Should We Handle Security Notifications?
- What Do You Do If Management Won't Get On Board?
- Is Linux The Most Secure OS?
- Vulnerability Counting Revisited: A Hypothetical Example
- How FreeBSD Makes Vulnerability Auditing Easy: Portaudit
- Knowing The Superficial Side Of Security Is Important, Too
- The CIA Triad
- Google Opens Up RatProxy
- 5 Easy Ways To Compromise Your Own Security
- The Reason I Talk About Security
- Five Good Security Reads
- Who Is Really To Blame For The San Fran Network Lockout?
- Bignum Arithmetic And Premature Optimization
- Use Tcpdump For Traffic Analysis
- How Does Bad Password Policy Like This Even Happen?
- The Meaning Of "Good Enough"
- Perfect Vs. Good Enough
- Keyczar: Another Open Source Security Tool From Google
- 10 Common Security Mistakes That Should Never Be Made
- 10 Security Challenges Facing Closed Source Software
- How Do You Interview Security Experts?
- Use Complete Session Encryption With Gmail
- Functional Programming Techniques Can Improve Software Security
- Perspectives: Better Than CAs?
- What Are The Security Implications For Google Chrome?
- The Trouble With Test Versions
- Can You Mitigate Risk By Replacing Sensitive Resources?
- Prioritize Security Concerns With A Simple Risk Assessment
- Email Security Advice For Politicians
- The So-Called Group Called Anonymous
- Is Suggesting Improved Security The Same As Blaming The Victim?
- Choose The Right Licensing Model For Security Software
- What To Do About RFID Chips In Your Wallet
- How Closed Policies Hurt Security Development
- TSA Communication May Get Your Bag Searched
- 12 Security Suites Tested And 12 Security Suites Fail
- 5 Characteristics Of Security Policy I Can Trust
- Wim Van Eck's Legacy
- MS Windows 7 Pre-Beta Gets A Security Patch 13 Days Early
- 10 Security Tips For Microsoft Windows XP
- Security, Complexity, And The GUI Environment
- More Email Security Tips
- Microsoft Finally Catches The Eight Year Bug
- No Such Thing As Effective License Enforcement
- The Safest Way To Sanitize Input: Avoid Having To Do It At All
- 5 Tips To Improve Physical Access Security
- Use Cryptographic Hashes For Validation
- 5 Things Microsoft Should Do To Secure Windows 7
- Use Cryptographic Hashes With Ruby
- Will Google's Native Client Project Change The Game?
- Practical Paranoia: Trust, But Verify
- Distributed Security Cracking
- Understanding Layered Security And Defense In Depth
- 5 Precautions To Take For The Holiday Break
- Internal Defenses Are Part Of Layered Security Strategy
- The Smallest Threat To Open Source In 2009
- REAL ID In A Nutshell
- 25 Most Dangerous Programming Errors
- Managers And Technologists Live In Different Worlds
- How Should You Handle Software Updates?
- Options For OpenPGP
- Don't Try To Control What You Don't Understand
- Filesystem Fragmentation: Security Threat
- Is This What They Call A Feature?
- 10 Important Categories Of Employment Transition Security
- 10 Tips For Personal Security When You Leave An Employer
- A Practical Example Of Why HTML Email Is A Bad Idea
- Lenovo Provides An Excellent Example Of How Not To Handle User Data
- Email Needs Safe Rendering
- 5 Tips For Choosing A Registrar For Sites You Care About
- 5 Interesting Security Links For February 2009
- More About What My Grandmother Taught Me
- Advice For Reading About Security
- Recession: A Chance To Deploy Open Source Security Solutions
- How Likely Is Your Software To Survive The Recession?
- Never Use Buzzwords To Justify Decisions Without Understanding Them
- Security 101, Remedial Edition: Use Strong Passwords
- 10 Tips For Secure Computer Disposal
- Airport Behavior Detection And Security Theater
- Sometimes, No Encryption Is Better
- 10 Questions To Ask Yourself Before Collecting Security Data
- How Secure Is Your Bank Card?
- Hacker Vs. Cracker
- Principles Vs. Magic
- Why Do People Write Viruses?
- There Is No Legal Solution To Malware
- Mydoom.FUD: A Lesson In Fear, Uncertainty, And Doubt
- 5 IT Security Pet Peeves
- The Real Solution To Malware
- Why REAL ID Is Not Secure ID
- 5 Ideas For Secure Invoicing
- Linux And Windows Compromised At Boot
- The Case For National Security
- China Chooses FreeBSD As Basis For Secure OS
- The Cyber Czar: Hope Or Fear?
- Microsoft May Be Firefox's Worst Vulnerability
- Pentagon Has Bold Plan For Digital Warfare
- The Broken Windows Fallacy
- Stainless Steel Wallet Review
- Six Principles Of Practical Ciphers
- Public Officials And Private Lives
- The Basics Of Secure Admin Privilege Use With Unix
- Stay Out Of Bozeman
- Understanding Risk, Threat, And Vulnerability
- Protect Webserver Directories From Unwanted Browsing
- How Anti-Sec Is Anti-Sec?
- Why Are Crime Rates Dropping?
- Open Source Crimebusting
- How To Deal With Adobe Flash And Reader Vulnerability
- Redundant Rules, Rushed Votes, And Bad Policy
- ZF05 Gives Us One More Reason To Use Unique Passwords
- Use The Firefox Password Manager
- Use RFC 2606 Example Domains For Example Emails
- Unmask Your Passwords
- The Microsoft OWC Two-Year Vulnerability Patch
- Interview Coding Tests Should Measure More
- The Pirate Bay Is Back With A Vengeance
- Provide More Than A Feeling Of Security
- Guns Can Keep Computers In Your Luggage Safe
- Paranoid Cookie Management
- Help Reddit Crack The Treasure Master Password
- Fine-Grained Cookie Management In Firefox
- The Bobby Tables Guide To SQL Injection
- The Chinese Domain Scam
- The Key Exchange Puzzle
- Create Great Employees
- Solving The Key Exchange Problem
- Never Get Complacent About Security, Even In Fiction
- Is Firefox + Perspectives The Most Secure Browser For TLS/SSL Encryption?
- Perspectives Provides Out Of Band Verification For SSH
- Microsoft Makes Firefox Vulnerable; Mozilla Responds
- Never Use Dynamic Variables
- The TLS/SSL Certifying Authority System Is A Scam
- Use The SSH Filesystem For Secure Network Filesystem Access
- Use SCP For Quick, Secure File Transfers
- Update Your FreeBSD Software With Care
- How To Use Antivirus Software With MS Windows
- Understand Basic Unix File Permissions
- Managing Default Unix File Permissions With Adduser And Umask
- Five Security News Items For Late 2009
- Five Guidelines For Secure Customer Communication
- Use Google Wave Carefully During The Testing Period
- Basics Of Stack-Smashing Attacks And Defenses Against Them
- Should We Be Afraid Of Google Public DNS?
- Understand The Setuid And Setgid Permissions
- FreeBSD File Flags Enhance Unix Filesystem Security
- Principles Of Basic Filesystem Integrity Auditing
- Google: Being Evil
- Major Security Myths Of 2009
- Why Security Gets No Love
- Use The Find Utility To Scan For Writable Directories
- China Cracks Google Security; Google Defies Chinese Censors
- How China Exposed Google's Hypocrisy
- The Reverse Quine: Making Web Services Transparent
- Are TSA Policies A Bad Joke?
- The Enduring Cipher
- The Use And The Misuse Of The XOR Stream Cipher
- The Danger Of Complexity: SLOC
- Cryptography's Running Gag: ROT13
- American Express Password Policy Takes The Cake
- Coloring Outside The Lines
- Get The Security Buzz About Google Buzz
- Fight Back Against Bad Password Policy
- What Defaults Should Random Password Generators Use?
- Avoid Ambiguity When Referring To Account Names
- Five Features Of A Good Password Manager
- A User Name Is Not A Password
- Microsoft Warns: Don't Press F1
- The Microsoft Internet Driving License
- Use QuickProxy For A Simple Proxy Switch In Firefox
- Simplicity Is Security
- Organizations And Conflicts Of Interest
- Present Security Advice As Convenience Advice
- Google News Follow-Up
- Are Self-Signed Certificates Safer?
- The Future Of Security
- Five Characteristics Of Secure Online Services
- Mitigating The Privilege Escalation Threat
- Mitigating The Social Engineering Threat
- Does The Chrome OS LiveCD Threaten Your Installed OS?
- 10 Security Books For The Future
- A Simple Email Filter: Getlessmail
- The Classic Man-In-The-Middle Attack, In Fantasy TV
- Secure Mercurial And BitBucket Quickstart
- The NTIA Wants Cell Phone Jamming Solutions
- Google Book Search And Our Privacy
- Microsoft Windows Activation Work-Around
- Corporate Ethics Versus Security Ethics
- Google Offers Encrypted Sessions For Web Search
- What Are The Prospects For Smartphone Security Threats?
- Why You Really Should Care About Privacy
- Will Google's Move Spur Others To Drop Microsoft?
- Responsible Disclosure And Its Irresponsible Advocates
- HTTPS Everywhere Makes SSL/TLS Easier
- Stainless Steel Wallet Review: One Year Later
- Use Chroot To Restrict Services
- Use Rssh To Limit User Access
- Understanding The Market For Buggy Software
- Have You Heard The One About The 21st Century Russian Spy Ring?
- Security Hyenas And The Abuse Of The Word "Terrorist"
- Welcome To The Future: Cloud-Based WPA Cracking Is Here
- Knowledgeable Humans Are Still The Best Spam Filters
- Jailbreaking Smartphones Is Finally Legal, For Now
- Point Release Vs. Rolling Release
- Use Pwsafe As A Keyboard Shortcut Driven X Tool
- Bypass A $200 Biometric Lock With A Paperclip
- Hackers And Crackers: A Lesson In Etymology And Clear Communication
- Smartphone Jailbreaking, And What Vendors Are Doing About It
- U.S. Military Compromised By Removable Media Malware: Five Ways To Avoid The Same Fate
- How To Disable Vulnerability Checking For FreeBSD Ports
- Are Multiple Overwrites Really Necessary For Secure Deletion?
- Quantum Hacking Cracks Quantum Crypto
- Are Microkernels The Future Of Secure OS Design?
- Security Vs. Popularity
- Security Consciousness, And Its Opposite
- Should Intel Decide What Software We Can Run?
- Should BCC Be The Default Email Address Field?
- Turn Off Modeline Support In Vim
- Five Security Lessons To Learn From The Twitter Worm
- Lock Your Screen While Away From The Computer
- How To Escape SSH Sessions Without Ending Them
- Security Tools Should Be Designed For Security
- Recover FreeBSD Root Access When You Forgot The Password
- Unix Vs. Microsoft Windows: How System Designs Reflect Security Philosophy
- No Autorun Can Help Protect Microsoft Windows From Malware
- Why You Should Never Trust Facebook
- If Facebook Will Not Protect Your Privacy, Maybe Someone Else Will
- The Many Eyes That Matter For Security Are The Friendly Eyes
- Create A Simple, Simulated Network With The Honeyd Tool
- Are Bad Guys Using Honeypots To Catch Security Researchers?
- Don't Be Fooled By The Argument Against Unique Passwords
- New Developments In OpenPGP Encryption Tools
- Shadow DNS In The Works: Do We Need A Second Internet?
- Use Firewall Software Like PF To Protect Your Desktop Systems
- The Meaning Of Cryptographic Trust
- What Can The OpenBSD IPsec Backdoor Allegations Teach Us?
- Vim Offers Strong File Encryption With Blowfish
- How One-Time Passwords Fit In With Multifactor Authentication
- Key Open Source Security Benefits
- Design Simplicity Is An Important Element Of Open Source Security
- Set Up A Secure File Transfer Account With Rssh
- Use Sysctl Security Settings To Lock Down A FreeBSD System
- The Difference Between Secrecy And Privacy As Security Concepts
- Imagination Is More Important Than Knowledge
- The Book Of PF Is The Canonical Reference For The PF Firewall
- Filtering PF Firewall Logs
- Why Not Use OpenPGP For Web Authentication?
- Captured Images Of Your Physical Keys Can Be Used To Make Copies
- Protect Yourself From Closed Source SSH
- The Security Limitations Of Solid-State Drives
- Rulings In PS3 Jailbreaking Suit Should Worry You
- Electronic Voting Can Be Better Than Paper
- How To Use WinSCP With Public Key Authentication
- How To Use Password Safe On Microsoft Windows 7
- PuTTY Toolset Offers More Than Just An SSH Terminal
- IP Is For Intellectual Property (And Invading Privacy)
- Encrypt Calls On Your Android Device With RedPhone
- SSL/TLS Encryption And The Vacant Lot Scam: Too Big To Fail
- The Privacy Covenant Is An Illusion
- Maybe Your Random CAPTCHA String Generator Should Be Less Random
- There May Be A Better Way To Weed Out Spammers Than CAPTCHA
- Facebook Is Not The Real Privacy Threat
- How To Get People To Use Strong Passwords
- IPhone Tracking Only Part Of Apple's Security And Privacy Shortcomings
- What To Do About The PlayStation Network Breach
- Like Passwords For Chocolate, Coming Soon To A Security Theater Near You
- Sony's Scapegoat For The PSN Compromise Fights Back
- From A To Z: Whistleblowing Versus Social Networking
- Is The IP Address The New SSN?
- DRM Is Counterproductive
- Why Strict Copyright Enforcement Is Becoming Obsolete
- 10 Highlights Of The FBI IT Security Record
- How Your Emails Can Become Public Record: The Enron Dataset
- Has The Mozilla Foundation Lost Its Collective Mind?
- How Do You Protect Yourself From Hacktivist Groups?
- Cryptographer And Computer Scientist Robert Morris Dies At 78
- Stainless Steel Wallet Review: Two Years Later