<?xml version="1.0" encoding="utf-8"?>
			
<rss version="2.0" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:cc="http://web.resource.org/cc/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">

<channel>
	<title>Clerkendweller : Web Security, Usability and Design</title>
	<link>http://www.clerkendweller.com</link>
	<description>A blog about security issues for web site designers, developers and owners.</description>
	<atom:link href="http://www.clerkendweller.com/atom.php" type="application/rss+xml" />
	<language>en-gb</language>
	<pubDate>Sat, 25 May 2013 18:10:58 +0100</pubDate>
	<lastBuildDate>Tue, 21 May 2013 19:59:00 +0100</lastBuildDate>
	<item>
		<title>OWASP EU Tour 2013 in London on June 3rd</title>
		<link>http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd</link>
		<description>
		
		
		As part of the OWASP EU Tour 2013, there will be a special event in London next month, along the lines of the recent ones in Cambridge and Leicester.



The one day conference is being held in central London on Monday 3rd of June 2013 at the Lion... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd&apos; style=&apos;display:none;&apos;&gt;OWASP EU Tour 2013 in London on June 3rd&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd&apos; style=&apos;display:none;&apos;&gt;OWASP EU Tour 2013 in London on June 3rd&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>mobile</category>
		<category>vulnerabilities</category>
		<category>data protection</category>
		<category>threats</category>
		<category>SDLC</category>
		<category>PCIDSS</category>
		<category>trust</category>
		<category>risks</category>
		<category>code</category>
		<category>maturity</category>
		<pubDate>Tue, 21 May 2013 19:59:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd</guid>
		
	</item>

	<item>
		<title>Cornucopia Ecommerce Website Edition v1.00</title>
		<link>http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100</link>
		<description>
		
		
		Cornucopia Ecommerce Website Edition v1.00 was uploaded to the OWASP website in February and has now been upgraded to a full OWASP project.



Today, I have completed the new OWASP Cornucopia Project pages which include:


	Description and obj... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100&apos; style=&apos;display:none;&apos;&gt;Cornucopia Ecommerce Website Edition v1.00&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100&apos; style=&apos;display:none;&apos;&gt;Cornucopia Ecommerce Website Edition v1.00&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>PCIDSS</category>
		<category>preventative</category>
		<category>technical</category>
		<category>threats</category>
		<category>SDLC</category>
		<category>development</category>
		<category>specification</category>
		<category>requirements</category>
		<category>risks</category>
		<category>design</category>
		<category>testing</category>
		<pubDate>Sat, 18 May 2013 19:30:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100</guid>
		
	</item>

	<item>
		<title>Internet and Mobile Literacy, Usage &amp; Opinions</title>
		<link>http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions</link>
		<description>
		
		
		OFCOM, the UK communications sector&apos;s regulator and competition authority, has announced a report on adults&apos; use of media and attitudes.

More than half of internet users say they use the same passwords for most websites

The Adults&apos; Media Use an... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions&apos; style=&apos;display:none;&apos;&gt;Internet and Mobile Literacy, Usage &amp; Opinions&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions&apos; style=&apos;display:none;&apos;&gt;Internet and Mobile Literacy, Usage &amp; Opinions&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>metrics</category>
		<category>data protection</category>
		<category>threats</category>
		<category>operation</category>
		<category>legislation</category>
		<category>risks</category>
		<pubDate>Fri, 17 May 2013 08:34:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions</guid>
		
	</item>

	<item>
		<title>IP Address Sharing and Individual Identification</title>
		<link>http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification</link>
		<description>
		
		
		BT has announced a trial of its Carrier-Grade Network Address Translation (CGNAT) where Internet Protocol (IP) addresses will be shared between subscribers.

organisations [will] generally have to treat IP addresses as personal data

Concerns hav... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification&apos; style=&apos;display:none;&apos;&gt;IP Address Sharing and Individual Identification&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification&apos; style=&apos;display:none;&apos;&gt;IP Address Sharing and Individual Identification&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>data protection</category>
		<category>identity</category>
		<category>IP addresses</category>
		<category>legislation</category>
		<pubDate>Fri, 10 May 2013 09:48:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification</guid>
		
	</item>

	<item>
		<title>Consultation on Cyber Security Standard</title>
		<link>http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard</link>
		<description>
		
		
		The UK Cabinet Office has announced a consultation into the proposed cyber risk management standard for organisations as part of its cyber security strategy announced in November 2011.



The proposed guidance and accompanying call for views and ... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard&apos; style=&apos;display:none;&apos;&gt;Consultation on Cyber Security Standard&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard&apos; style=&apos;display:none;&apos;&gt;Consultation on Cyber Security Standard&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>legislation</category>
		<pubDate>Tue, 07 May 2013 19:39:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard</guid>
		
	</item>

	<item>
		<title>OWASP European Tour Kick-Off in Cambridge</title>
		<link>http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge</link>
		<description>
		
		
		Following the success of similar events in Latin America, a rolling tour of events with OWASP speakers will be occurring in European Countries, beginning with Cambridge this month.



This first event of the tour has been organised in conjunction... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge&apos; style=&apos;display:none;&apos;&gt;OWASP European Tour Kick-Off in Cambridge&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge&apos; style=&apos;display:none;&apos;&gt;OWASP European Tour Kick-Off in Cambridge&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>operation</category>
		<category>maturity</category>
		<category>specification</category>
		<category>technical</category>
		<category>SDLC</category>
		<category>PCIDSS</category>
		<category>information assurance</category>
		<category>risks</category>
		<category>disposal</category>
		<category>design</category>
		<category>testing</category>
		<category>development</category>
		<pubDate>Sat, 04 May 2013 07:36:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge</guid>
		
	</item>

	<item>
		<title>2013 Information Security Breaches</title>
		<link>http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches</link>
		<description>
		
		
		Last week the UK&apos;s Department for Business Innovation &amp;amp; Skills published the 2013 Information Security Breaches Survey, created in conjunction with PwC.



The report presents the results of the survey and breaks the findings down for larger ... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches&apos; style=&apos;display:none;&apos;&gt;2013 Information Security Breaches&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches&apos; style=&apos;display:none;&apos;&gt;2013 Information Security Breaches&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>maturity</category>
		<category>incidents</category>
		<category>threats</category>
		<category>operation</category>
		<category>technical</category>
		<category>corrective</category>
		<category>legislation</category>
		<pubDate>Tue, 30 Apr 2013 20:53:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches</guid>
		
	</item>

	<item>
		<title>Reflections on Security B-Sides London 2013</title>
		<link>http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013</link>
		<description>
		
		
		I have just had time to catch up on my attendance and participation at Security B-Sides London 2013.



This community-led event was held at the town hall of the Royal Borough of Kensington and Chelsea on Wednesday 24th April, and was supported b... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013&apos; style=&apos;display:none;&apos;&gt;Reflections on Security B-Sides London 2013&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013&apos; style=&apos;display:none;&apos;&gt;Reflections on Security B-Sides London 2013&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>design</category>
		<category>SDLC</category>
		<category>threats</category>
		<category>operation</category>
		<category>development</category>
		<category>testing</category>
		<category>preventative</category>
		<pubDate>Sun, 28 Apr 2013 23:39:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013</guid>
		
	</item>

	<item>
		<title>Data Disclosure Incidents in 2013</title>
		<link>http://www.clerkendweller.com/2013/4/23/Data-Disclosure-Incidents-in-2013</link>
		<description>
		
		
		The Verizon 2013 Data Breach Investigations Report has been published drawing on data from 19 organisations including the European CyberCrime Center.


Payment cards have been a lock as the most oft-stolen data type since this study began, and 201... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/23/Data-Disclosure-Incidents-in-2013&apos; style=&apos;display:none;&apos;&gt;Data Disclosure Incidents in 2013&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/23/Data-Disclosure-Incidents-in-2013&apos; style=&apos;display:none;&apos;&gt;Data Disclosure Incidents in 2013&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>incidents</category>
		<category>threats</category>
		<category>operation</category>
		<category>technical</category>
		<category>risks</category>
		<category>leakage</category>
		<pubDate>Tue, 23 Apr 2013 06:46:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/23/Data-Disclosure-Incidents-in-2013</guid>
		
	</item>

	<item>
		<title>AppSensor at Security B-Sides London</title>
		<link>http://www.clerkendweller.com/2013/4/19/AppSensor-at-Security-BSides-London</link>
		<description>
		
		
		Next week Dinis Cruz and I will be running an AppSensor workshop at Security B-Sides London 2013.



We will be demonstrating and helping attendees of the workshop specify, define and implement application-specific attack detection and real-time ... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/19/AppSensor-at-Security-BSides-London&apos; style=&apos;display:none;&apos;&gt;AppSensor at Security B-Sides London&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/19/AppSensor-at-Security-BSides-London&apos; style=&apos;display:none;&apos;&gt;AppSensor at Security B-Sides London&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>incidents</category>
		<category>logging</category>
		<category>specification</category>
		<category>technical</category>
		<category>threats</category>
		<category>development</category>
		<category>monitoring</category>
		<category>risks</category>
		<category>design</category>
		<category>defense</category>
		<pubDate>Fri, 19 Apr 2013 08:41:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/19/AppSensor-at-Security-BSides-London</guid>
		
	</item>

	<item>
		<title>Retail Payments Now and Soon</title>
		<link>http://www.clerkendweller.com/2013/4/16/Retail-Payments-Now-and-Soon</link>
		<description>
		
		
		Light Blue Touchpaper is one of my regular places to read robustly researched and argued views around information security and privacy.



This week, the second part of a series on current issues in payments was published:


   Current Issues ... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/16/Retail-Payments-Now-and-Soon&apos; style=&apos;display:none;&apos;&gt;Retail Payments Now and Soon&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/16/Retail-Payments-Now-and-Soon&apos; style=&apos;display:none;&apos;&gt;Retail Payments Now and Soon&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>PADSS</category>
		<category>PCIDSS</category>
		<category>business logic</category>
		<pubDate>Tue, 16 Apr 2013 07:24:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/16/Retail-Payments-Now-and-Soon</guid>
		
	</item>

	<item>
		<title>State of Software Security Report Volume 5</title>
		<link>http://www.clerkendweller.com/2013/4/12/State-of-Software-Security-Report-Volume-5</link>
		<description>
		
		
		The fifth semi-annual &quot;State of Software Security Report - The Intractable Problem of Insecure Software&quot; has been issued by Veracode (see my previous comments on volumes 1, 2, 3 and 4).



In Volume 5, there is extended analysis of the vulnerabil... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/12/State-of-Software-Security-Report-Volume-5&apos; style=&apos;display:none;&apos;&gt;State of Software Security Report Volume 5&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/12/State-of-Software-Security-Report-Volume-5&apos; style=&apos;display:none;&apos;&gt;State of Software Security Report Volume 5&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>vulnerabilities</category>
		<category>technical</category>
		<category>testing</category>
		<pubDate>Fri, 12 Apr 2013 13:55:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/12/State-of-Software-Security-Report-Volume-5</guid>
		
	</item>

	<item>
		<title>Upcoming OWASP Conferences</title>
		<link>http://www.clerkendweller.com/2013/4/9/Upcoming-OWASP-Conferences</link>
		<description>
		
		
		Three regional OWASP application security conferences are planned for later this year.



OWASP runs the most comprehensive application security conferences with a very high standard of training courses, speakers and delegates to network with. Th... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/9/Upcoming-OWASP-Conferences&apos; style=&apos;display:none;&apos;&gt;Upcoming OWASP Conferences&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/9/Upcoming-OWASP-Conferences&apos; style=&apos;display:none;&apos;&gt;Upcoming OWASP Conferences&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>operation</category>
		<category>vulnerabilities</category>
		<category>specification</category>
		<category>maturity</category>
		<category>threats</category>
		<category>SDLC</category>
		<category>development</category>
		<category>information assurance</category>
		<category>risks</category>
		<category>disposal</category>
		<category>design</category>
		<category>testing</category>
		<pubDate>Tue, 09 Apr 2013 08:23:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/9/Upcoming-OWASP-Conferences</guid>
		
	</item>

	<item>
		<title>Fair Data?</title>
		<link>http://www.clerkendweller.com/2013/4/5/Fair-Data</link>
		<description>
		
		
		At the end of January, the Market Research Society (MRS) launched an initiative called Fair Data.



Existing MRS Company Partners (who are already subject to the MRS Code of Conduct), and others who apply and pass an assessment by the MRS of the... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/5/Fair-Data&apos; style=&apos;display:none;&apos;&gt;Fair Data?&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/5/Fair-Data&apos; style=&apos;display:none;&apos;&gt;Fair Data?&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>reputation</category>
		<category>privacy</category>
		<category>data protection</category>
		<category>policies</category>
		<category>legislation</category>
		<pubDate>Fri, 05 Apr 2013 18:32:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/5/Fair-Data</guid>
		
	</item>

	<item>
		<title>WAF Testing</title>
		<link>http://www.clerkendweller.com/2013/4/2/WAF-Testing</link>
		<description>
		
		
		Selecting and deploying a web application firewall (WAF) needs to be undertaken using robust due diligence procurement/acquisition processes.

Try before you buy

A recent report (discussion) compares three different WAFs &amp;mdash; two cloud-based ... 

&lt;a href=&apos;http://www.clerkendweller.com/2013/4/2/WAF-Testing&apos; style=&apos;display:none;&apos;&gt;WAF Testing&lt;/a&gt;
		
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/2/WAF-Testing&apos; style=&apos;display:none;&apos;&gt;WAF Testing&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>XSS</category>
		<category>technical</category>
		<category>operation</category>
		<category>injection</category>
		<category>SQL</category>
		<category>firewalls</category>
		<category>preventative</category>
		<pubDate>Tue, 02 Apr 2013 12:26:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/2/WAF-Testing</guid>
		
	</item>

</channel></rss>