Sami Laine

What’s The Best Security Key to Buy?

There are dozens of security keys, authenticator apps, and password managers available. Which one should you use?
Sami Laine

SMS Two-Factor Authentication – Worse Than Just a Good Password?

If a website offers SMS-based authentication, should you enroll? Maybe not! In some cases, it’s worse than not having a second factor at all!
Marc Rogers

Mobile Phone-Based COVID-19 Contact Tracing

Using technology as a reliable method of tracking carriers of COVID-19 is a great idea, but it is extremely hard to do without creating huge privacy challenges. What Is Contact Tracing and Why Is It Important? Contact tracing is a way of identifying all the people that an infected person has interacted with. By identifying these interactions, it is possible to reach out to them and ensure that they are properly quarantined. Doing this is incredibly important if you want to stop the spread of an...

Vickie Li

Attacking SSO With Subdomain Takeovers

A brief look at how subdomain takeovers can give attackers a meaningful way to compromise single sign-on solutions.
Sami Laine

Factors & Dongles & Tokens, Oh My - Strong Auth Terminology in 7 minutes

MFA, 2FA, SMS, TOTP, U2F, FIDO2,... SMH, OMG. Strong authentication terminology explained.
Sami Laine

WebAuthn Is Great and It Sucks

WebAuthn and FIDO2 promise a great future. Let's see if we can have it today.
Vickie Li

Attacking Evil Regex: Understanding Regular Expression Denial of Service Attacks (ReDoS)

A quick look at how Regular Expression Denial of Service Attacks work and what you need to be aware of.
Vickie Li

A Quick Introduction to Regular Expressions for Security Professionals

A short introduction to regex. We'll explain how to use it and why it's so helpful for security analysis.
Marc Rogers

How the COVID-19 Pandemic Has Dramatically Changed the Cybersecurity Landscape

Over the past two decades working in the security space, I’ve observed that there’s always an uptick in attackers looking to exploit the chaos during disasters or periods of civil unrest or political instability. As people panic or try to act with more urgency, they become more vulnerable. Caution, one of our strongest defenses, is the first thing to go out of the window. As our sense of urgency grows, we become more willing to take shortcuts and the opportunity to fool us grows exponentially....

Christopher Bennett

The Case for Host Security Logs

A look at why host security logs should be at the top of your list when establishing a security program.