Home / ASP.NET Weblogs

Browse by Tags

Related Posts

  • Bad password requirements

    This morning I signed up with a major credit card company website.  Much to my surprise I was greeted with this requirement while choosing a password: Your Password should contain 6 to 8 characters . at least one letter and one number (not case sensitive), contain no spaces or special characters...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 01-24-2008, 12:00 AM
    Filed under: Software Development, Security, General Software Development
  • Symmetric Salting - remember that salt goes with more than just hash

    If you understand hashing and salting then skip the next paragraph. Stored passwords for logins should be hashed and salted.  Hashing is a one way mechanism to produce a practically unique value based on the given input.  This is useful since we can store the hash (and validate the password...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 11-15-2007, 12:00 AM
    Filed under: Software Development, Security, General Software Development
  • Shipping Software ... Secret Server 3.1 Sneak Peek

    Shipping software is one of the most exciting times for a development team but this new release is easily the most anticipated version of Secret Server to date by our customers. Secret Server 3.1 will feature the two most requested features from customers who visited our booth at TechEd in June 2007...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 07-29-2007, 12:00 AM
    Filed under: TechEd, Software Development, Security, ISV, General Software Development
  • Google launches Google Apps Premier Edition

    As rumored yesterday , Google made a major announcement : a subscription package of premium, hosted business applications. (Man, Arrington's sources are scary good). The service combines GMail, Google Calendar, Google Talk and Google Docs & Spreadsheets for $50 per user annually. I still insist that...
    Posted to Loosely Coupled has moved (Weblog) by Tim Marman on 02-22-2007, 12:00 AM
    Filed under: Security, Technology, Microsoft, Software Development, Web 2.0, Google, Business, Enterprise
  • An Introduction to OpenID

    OpenID, which describes itself as "an open, decentralized, free framework for user-centric digital identity", has been gaining momentum and getting press in the Identity 2.0 space. The fundamental idea of OpenID is that a URI is necessarily unique and thus a good way to identify users. If you say you...
    Posted to Loosely Coupled has moved (Weblog) by Tim Marman on 02-15-2007, 12:00 AM
    Filed under: .NET, Security, Technology, Software Development, Video
  • Intro to Cryptography Course

    A University of Washington course in Cryptography is available online , including videos of all the lectures ( via Bruce Schneier ). I've listened to the first lecture and it seems like a great introduction if you're interested in the subject. Interestingly, he cautions about Schneier's "popular-but...
    Posted to Loosely Coupled has moved (Weblog) by Tim Marman on 09-01-2006, 12:00 AM
    Filed under: Security, Tablet PC, Technology, Software Development, Video
  • Secret Server 1.1 makes the Daily Grind

    Mike Gunderloy, one of our early adopters, has added our Secret Server 1.1 release to the Daily Grind today! This is a huge compliment from a guru in tools, development and the developer community. Thanks Mike! If you don't know about the Daily Grind , read all about it here . Jonathan Cogley is the...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 03-28-2006, 12:00 AM
    Filed under: Software Development, Security, ISV
  • Feeling your users pain (and release notes for Secret Server 1.1)

    It is a wonderful feeling to ship software - it has been a long hard slog to get this round of features complete. Especially while juggling our developers across various projects and client work. This is also a welcome release as we get to use all the new features in our own company Secret Server instance...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 03-27-2006, 12:00 AM
    Filed under: Software Development, Security, ISV
  • Secret Server 1.1 is out ... go and get it!

    I haven't blogged in a few weeks but I have a few good reasons. Client projects with tight deadlines, the final push for our second big release of Thycotic Secret Server and also holding back on the irresistable urge to talk about features that aren't released yet (not much of a marketing person, huh...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 03-27-2006, 12:00 AM
    Filed under: Software Development, Security
  • Keep the numbers meaningful in Security Reviews

    I just came across this post (older) by Robert Hurlbut titled "DREAD is dead" and it reminded me of our experiences with these same ratings today. We are in the middle of a Security Review for a client and have been working through our threat model to assess the risk associated with each item. DREAD...
    Posted to Jonathan Cogley's Blog (Weblog) by thycotic on 12-13-2005, 12:00 AM
    Filed under: Software Development, Security
Page 1 of 2 (12 items) 1 2 Next >