Speaking at FIRST in Kyoto, Japan

In addition to the 2009 public speaking engagements listed previously, Ken will also be speaking at this year’s FIRST conference in Kyoto, Japan. The conference runs from 28 June through 3 July. Details are available at the FIRST website.

Ken will be presenting a session on “The essential role of CSIRT in secure software development” in which he’ll highlight things that incident responders can and ought to be doing to assist in an organization’s software development efforts.

CWE/SANS TOP 25 Most Dangerous Programming Errors

MITRE’s CWE and the SANS Institute together announced today a list of the 25 most dangerous programming problems. The full story can be found here:

SANS Institute - CWE/SANS TOP 25 Most Dangerous Programming Errors

Ken helped out early on with the effort by reviewing and commenting on early drafts. It’s a useful effort that should help us better understand the major underlying problems in our code today. The list should be a must-read for all software developers.

Hack forced Twitter into "full security review"

Ken is quoted in Sharon Gaudin’s latest Computerworld article, Hack forces Twitter into 'full security review'.

Column: Security nightmare in the mobile app gold rush?

This month, Ken takes a look at some of the dangers facing mobile application developers in the iPhone (and other) application gold rush. His column, Security Nightmare in the iPhone App Gold Rush is now up.