<?xml version="1.0" encoding="utf-8"?>
			
<rss version="2.0" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:cc="http://web.resource.org/cc/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">

<channel>
	<title>Clerkendweller : Web Security, Usability and Design</title>
	<link>http://www.clerkendweller.com</link>
	<description>A blog about security issues for web site designers, developers and owners.</description>
	<language>en-gb</language>
	<pubDate>Fri, 03 Sep 2010 03:32:23 +0100</pubDate>
	<lastBuildDate>Tue, 31 Aug 2010 08:37:00 +0100</lastBuildDate>
	<item>
		<title>HTTP Strict Transport Security</title>
		<link>http://www.clerkendweller.com/2010/8/31/HTTP-Strict-Transport-Security</link>
		<description>
		
		
		It&apos;s good to see different groups working together to improve security.  This week another browser manufacturer announced future support for an initiative relating to Transport Layer Security  (TLS, the successor to SSL).



HTTP Strict Transport... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/31/HTTP-Strict-Transport-Security&apos; style=&apos;display:none;&apos;&gt;HTTP Strict Transport Security&lt;/a&gt;
		
		
		</description>
				
		
		<category>SSL</category>
		<category>technical</category>
		<pubDate>Tue, 31 Aug 2010 08:37:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/31/HTTP-Strict-Transport-Security</guid>
		
	</item>

	<item>
		<title>Automated Attack Responses by Web Applications</title>
		<link>http://www.clerkendweller.com/2010/8/27/Automated-Attack-Responses-by-Web-Applications</link>
		<description>
		
		
		I have been exploring further the possible response actions an application might make once it has detected a suspected or actual attack, as a contribution to the OWASP AppSensor project.  There is now a draft document describing response actions, dis... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/27/Automated-Attack-Responses-by-Web-Applications&apos; style=&apos;display:none;&apos;&gt;Automated Attack Responses by Web Applications&lt;/a&gt;
		
		
		</description>
				
		
		<category>vulnerabilities</category>
		<category>ids</category>
		<category>incidents</category>
		<category>threats</category>
		<category>operation</category>
		<category>detective</category>
		<category>corrective</category>
		<category>preventative</category>
		<pubDate>Fri, 27 Aug 2010 08:52:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/27/Automated-Attack-Responses-by-Web-Applications</guid>
		
	</item>

	<item>
		<title>E-Commerce Due Diligence</title>
		<link>http://www.clerkendweller.com/2010/8/24/ECommerce-Due-Diligence</link>
		<description>
		
		
		Investment decisions for loans, mergers &amp;amp; acquisitions in primarily online businesses need just as much care as investing in more conventional businesses.



This month I contributed to the Autumn 2010 newsletter of DeVere &amp;amp; Co, risk mana... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/24/ECommerce-Due-Diligence&apos; style=&apos;display:none;&apos;&gt;E-Commerce Due Diligence&lt;/a&gt;
		
		
		</description>
				
		
		<category>information assurance</category>
		<category>due diligence</category>
		<category>guidelines</category>
		<pubDate>Tue, 24 Aug 2010 08:27:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/24/ECommerce-Due-Diligence</guid>
		
	</item>

	<item>
		<title>Avoiding Popular Passwords</title>
		<link>http://www.clerkendweller.com/2010/8/20/Avoiding-Popular-Passwords</link>
		<description>
		
		
		A few weeks ago I mentioned two new research papers about the use of passwords on website. Another new paper from Microsoft Research and Harvard University discusses how to avoid, and protect web sites from, users selecting popular passwords.



... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/20/Avoiding-Popular-Passwords&apos; style=&apos;display:none;&apos;&gt;Avoiding Popular Passwords&lt;/a&gt;
		
		
		</description>
				
		
		<category>administrative</category>
		<category>authentication</category>
		<category>policies</category>
		<category>identity</category>
		<category>technical</category>
		<pubDate>Fri, 20 Aug 2010 07:00:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/20/Avoiding-Popular-Passwords</guid>
		
	</item>

	<item>
		<title>Software Licensing</title>
		<link>http://www.clerkendweller.com/2010/8/19/Software-Licensing</link>
		<description>
		
		
		Software licensing may not be high on your agenda once a web site is operational.  But software licences are an important part of ensuring your web site does not infringe any laws, regulations and contracts.

From 15:30 hrs today, train services fr... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/19/Software-Licensing&apos; style=&apos;display:none;&apos;&gt;Software Licensing&lt;/a&gt;
		
		
		</description>
				
		
		<category>administrative</category>
		<category>operation</category>
		<category>preventative</category>
		<pubDate>Thu, 19 Aug 2010 20:08:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/19/Software-Licensing</guid>
		
	</item>

	<item>
		<title>Application Security Logging</title>
		<link>http://www.clerkendweller.com/2010/8/17/Application-Security-Logging</link>
		<description>
		
		
		I have been meaning to write again about web application security logging, but luckily read a paper last week which provides excellent guidance.



How to Do Application Logging Right is the best guidance I have come across to date.  Co-written b... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/17/Application-Security-Logging&apos; style=&apos;display:none;&apos;&gt;Application Security Logging&lt;/a&gt;
		
		
		</description>
				
		
		<category>detective</category>
		<category>incidents</category>
		<category>logging</category>
		<category>guidelines</category>
		<category>preventative</category>
		<pubDate>Tue, 17 Aug 2010 11:22:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/17/Application-Security-Logging</guid>
		
	</item>

	<item>
		<title>PCI DSS and PA-DSS Standards Changes</title>
		<link>http://www.clerkendweller.com/2010/8/13/PCI-DSS-and-PADSS-Standards-Changes</link>
		<description>
		
		
		PCI DSS and PA-DSS standards changes have been pre-announced by the Payment Card Industry Security Standards Council (PCI SCC).



Yesterday&apos;s announcement, which also includes notice of changes to PIN Transaction Security (PTS) requirements, pro... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/13/PCI-DSS-and-PADSS-Standards-Changes&apos; style=&apos;display:none;&apos;&gt;PCI DSS and PA-DSS Standards Changes&lt;/a&gt;
		
		
		</description>
				
		
		<category>policies</category>
		<category>corrective</category>
		<category>technical</category>
		<category>administrative</category>
		<category>preventative</category>
		<category>PADSS</category>
		<category>PCIDSS</category>
		<category>physical</category>
		<category>detective</category>
		<pubDate>Fri, 13 Aug 2010 08:36:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/13/PCI-DSS-and-PADSS-Standards-Changes</guid>
		
	</item>

	<item>
		<title>Phishing and Pharming Protection - Theory and Reality</title>
		<link>http://www.clerkendweller.com/2010/8/10/Phishing-and-Pharming-Protection-Theory-and-Reality</link>
		<description>
		
		
		The UK Centre for the Protection of National Infrastructure (CPNI) have published new guidance on understanding and managing the risks from phishing and pharming.



Whilst most readers of this blog won&apos;t work on projects considered part of the n... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/10/Phishing-and-Pharming-Protection-Theory-and-Reality&apos; style=&apos;display:none;&apos;&gt;Phishing and Pharming Protection - Theory and Reality&lt;/a&gt;
		
		
		</description>
				
		
		<category>technical</category>
		<category>standards</category>
		<category>vulnerabilities</category>
		<category>risks</category>
		<category>policies</category>
		<category>threats</category>
		<category>operation</category>
		<category>procedures</category>
		<category>guidelines</category>
		<category>preventative</category>
		<category>detective</category>
		<category>corrective</category>
		<category>administrative</category>
		<pubDate>Tue, 10 Aug 2010 08:45:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/10/Phishing-and-Pharming-Protection-Theory-and-Reality</guid>
		
	</item>

	<item>
		<title>WCAG 2.0 Coming to More Commercial Websites Soon</title>
		<link>http://www.clerkendweller.com/2010/8/9/WCAG-20-Coming-to-More-Commercial-Websites-Soon</link>
		<description>
		
		
		Early last year I mentioned the security implications of the Web Content Accessibility Guidelines 2.0 and the scope for accessibility testing.  I also spoke about whether an accessible web application be secure at the OWASP AppSec EU09 conference.
... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/9/WCAG-20-Coming-to-More-Commercial-Websites-Soon&apos; style=&apos;display:none;&apos;&gt;WCAG 2.0 Coming to More Commercial Websites Soon&lt;/a&gt;
		
		
		</description>
				
		
		<category>accessibility</category>
		<category>policies</category>
		<category>standards</category>
		<category>technical</category>
		<pubDate>Mon, 09 Aug 2010 18:31:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/9/WCAG-20-Coming-to-More-Commercial-Websites-Soon</guid>
		
	</item>

	<item>
		<title>E-Consumer Protection Consultation</title>
		<link>http://www.clerkendweller.com/2010/8/6/EConsumer-Protection-Consultation</link>
		<description>
		
		
		The UK&apos;s Office of Fair Trading (OFT) promotes and protects consumers&apos; interests by ensuring markets work well, and that businesses act fairly and competitively.  The government has asked the OFT to develop a longer term national strategy for consume... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/6/EConsumer-Protection-Consultation&apos; style=&apos;display:none;&apos;&gt;E-Consumer Protection Consultation&lt;/a&gt;
		
		
		</description>
				
		
		<category>detective</category>
		<category>privacy</category>
		<category>corrective</category>
		<category>data protection</category>
		<category>incidents</category>
		<category>preventative</category>
		<category>legislation</category>
		<category>risks</category>
		<pubDate>Fri, 06 Aug 2010 09:02:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/6/EConsumer-Protection-Consultation</guid>
		
	</item>

	<item>
		<title>Real World Enterprise Application Security Programmes</title>
		<link>http://www.clerkendweller.com/2010/8/3/Real-World-Enterprise-Application-Security-Programmes</link>
		<description>
		
		
		This year I have mentioned web application security programmes, how software vulnerability testing recommended risk-based, application security programmes and generalised results from a survey about web application security programs.



But what ... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/8/3/Real-World-Enterprise-Application-Security-Programmes&apos; style=&apos;display:none;&apos;&gt;Real World Enterprise Application Security Programmes&lt;/a&gt;
		
		
		</description>
				
		
		<category>testing</category>
		<category>corrective</category>
		<category>standards</category>
		<category>vulnerabilities</category>
		<category>specification</category>
		<category>policies</category>
		<category>threats</category>
		<category>SDLC</category>
		<category>development</category>
		<category>procedures</category>
		<category>risks</category>
		<category>validation</category>
		<category>preventative</category>
		<category>guidelines</category>
		<category>detective</category>
		<pubDate>Tue, 03 Aug 2010 09:00:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/8/3/Real-World-Enterprise-Application-Security-Programmes</guid>
		
	</item>

	<item>
		<title>Economics of Website Users&apos; Passwords</title>
		<link>http://www.clerkendweller.com/2010/7/30/Economics-of-Website-Users-Passwords</link>
		<description>
		
		
		Two great papers on web site password security were published this month. We are swamped with passwords and every daily activity is increasingly linked with an online version, which requires users to register to obtain some additional benefits.  Ever... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/7/30/Economics-of-Website-Users-Passwords&apos; style=&apos;display:none;&apos;&gt;Economics of Website Users&apos; Passwords&lt;/a&gt;
		
		
		</description>
				
		
		<category>authentication</category>
		<category>policies</category>
		<category>operation</category>
		<category>identity</category>
		<category>technical</category>
		<category>business logic</category>
		<pubDate>Fri, 30 Jul 2010 08:45:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/7/30/Economics-of-Website-Users-Passwords</guid>
		
	</item>

	<item>
		<title>When is a Vulnerability not a Vulnerability?</title>
		<link>http://www.clerkendweller.com/2010/7/27/When-is-a-Vulnerability-not-a-Vulnerability</link>
		<description>
		
		
		Until this week, I had thought this question would be answered by checking the vulnerability could be exploited and by determining whether there was any technical or business impact.

But I have just finished reading the Summer 2010 edition of Info... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/7/27/When-is-a-Vulnerability-not-a-Vulnerability&apos; style=&apos;display:none;&apos;&gt;When is a Vulnerability not a Vulnerability?&lt;/a&gt;
		
		
		</description>
				
		
		<category>vulnerabilities</category>
		<category>information assurance</category>
		<category>SDLC</category>
		<category>threats</category>
		<category>ids</category>
		<category>risks</category>
		<pubDate>Tue, 27 Jul 2010 09:29:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/7/27/When-is-a-Vulnerability-not-a-Vulnerability</guid>
		
	</item>

	<item>
		<title>Pay Attention to Encoding!</title>
		<link>http://www.clerkendweller.com/2010/7/26/Pay-Attention-to-Encoding</link>
		<description>
		
		
		My company recently received a leaflet from  (HMRC) with an invitation to attend one of their EmployerTalk seminars about payroll and tax including pay as you earn (PAYE).  On the way from my hand to the recycling bin, something caught my eye:


... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/7/26/Pay-Attention-to-Encoding&apos; style=&apos;display:none;&apos;&gt;Pay Attention to Encoding!&lt;/a&gt;
		
		
		</description>
				
		
		<category>encoding</category>
		<category>standards</category>
		<category>specification</category>
		<pubDate>Mon, 26 Jul 2010 14:44:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/7/26/Pay-Attention-to-Encoding</guid>
		
	</item>

	<item>
		<title>Mobile Web Application Best Practices (Draft)</title>
		<link>http://www.clerkendweller.com/2010/7/23/Mobile-Web-Application-Best-Practices-Draft</link>
		<description>
		
		
		Mobile Web Application Best Practices has been published as a last call working draft by the W3C Mobile Web Best Practices Working Group.



Mobile Web Application Best Practices is intended to to aid the development of rich and dynamic mobile we... 

&lt;a href=&apos;http://www.clerkendweller.com/2010/7/23/Mobile-Web-Application-Best-Practices-Draft&apos; style=&apos;display:none;&apos;&gt;Mobile Web Application Best Practices (Draft)&lt;/a&gt;
		
		
		</description>
				
		
		<category>guidelines</category>
		<category>specification</category>
		<pubDate>Fri, 23 Jul 2010 08:39:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2010/7/23/Mobile-Web-Application-Best-Practices-Draft</guid>
		
	</item>

</channel></rss>