Dangers of a Cashless Society
IntroductionWhat Does Cashless Mean?Countries Embracing Going CashlessWhy Cashless Advocates Dislike Cash
Read article: Dangers of a Cashless SocietyNotes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.
IntroductionWhat Does Cashless Mean?Countries Embracing Going CashlessWhy Cashless Advocates Dislike Cash
Read article: Dangers of a Cashless SocietyA starting point for application security.
Read article: Application Security Best Practices“Defense in Depth” is the idea that no single security control is trusted to stop an attack. Instead, you stack multiple, independent layers so that if one fails, others still stand in the way.
Read article: Defense In DepthZero Trust Architecture (ZT or ZTA) is a security model / framework based on one simple idea: Never trust, always verify. From NIST, we have, the “… ZT approach is primarily focused on data and service protection but can and should be expanded to include all enterprise assets (devices,…
Read article: Zero Trust ArchitectureIn certain US industries, usually legacy businesses with low margins and heavily regulated, it is still quite common to use source IP address as an authentication mechanism on the public internet. Now, never mind that in the age of cloud computing and SaaS applications, it is rare for cloud…
Read article: Don’t Use Source IP Addresses As The Primary Authentication MechanismThe word “rule” is overused; so, I went with “precept” — a rule or principle that defines how one should think or act.
Read article: Core Security Precept: Principle of Least PrivilegeA long time ago, I was doing integration architecture work in the land of Enterprise Service Buses (ESBs) and API Gateways. Think IBM WebSphere DataPower and Apigee — I like to remember Apigee the way it was before it was integrated into GCP. After we had designed and built the ESB, we moved on to…
Read article: A Vendor DMZ PatternSometime around 2012, I published a similar list (up to the point of APIs). I recently put the same list in another post. I thought having this as its own post would be useful, or, at least, amusing.
Read article: Begotten & Forgotten Distributed Service TechnologiesIn a previous post, we made a point of “Non-Prod Environments Must Have The Same Security Protections As Production”. In this post, we’re going to go one step further and say that your internal and external endpoints, generally, should have the same security capabilities baked into their security…
Read article: Internal Endpoints Must Have The Same Security Capabilities As External EndpointsI have the ability to be a profound jackass. So, most feedback that’s been included in yearly reviews is probably fair. But, fifteen, plus, years ago, I did get one annual review that had one negative remark on it that bothered me then and still does to this day.
Read article: The Yearly Review Feedback That I Could Never AcceptLooking for something specific? Browse all 124 topics.