Get short, timely messages from Michael Coates.

Twitter is a rich source of instantly updated information. It's easy to stay updated on an incredibly wide variety of topics. Join today and follow @_mwc.

Get updates via SMS by texting follow _mwc to 40404 in the United States
Codes for other countries

Two-way (sending and receiving) short codes:
Country Code For customers of
Australia
  • 0198089488 Telstra
Canada
  • 21212 (any)
United Kingdom
  • 86444 Vodafone, Orange, 3, O2
Indonesia
  • 89887 AXIS, 3, Telkomsel
Ireland
  • 51210 O2
India
  • 53000 Bharti Airtel, Videocon
Jordan
  • 90903 Zain
New Zealand
  • 8987 Vodafone, Telecom NZ
United States
  • 40404 (any)

_mwc

  1. Http Strict Transport Security - an enhancement you should definitely use on your website - bit.ly/LoUKM8 #security #appsec
  2. @a0viedo Link to more reading? I'd be interested to see comparison of dictionary attack against pass phrase vs password.
  3. Why are people advocating password complexity instead of password phrases. Phrases are easier for users, more entropy #passwords
  4. Check Your Firefox Plug-Ins in 5 Minutes - bit.ly/JVeo7M #security #firefox
  5. #mozcamp latam security folk - if you want more security knowledge OWASP is holding the #LatamTour2012 on May 26 bit.ly/K9mDtB
  6. #mozcamp slides online for Mozilla Security Talk with latam community slidesha.re/J9eT87
  7. @sandeepsabnani @owasp Welcome! Glad to have you helping out. Feel free to ping me with any questions.
  8. @rjmackay @ushahidi I'd recommend using either Mozilla's CSRF for django bit.ly/JiXFKM or OWASP CSRF guard bit.ly/JiXD5D
  9. @rjmackay @ushahidi Generally yes, but if there are header forging vulns this solution no longer works (like this one - bit.ly/JiXteh
  10. @hillbrad Agreed. Pentest should push changes in lifecycle for early detection & good pentests may find new types of issues in new techs
  11. @hillbrad Goal is to catch security vulns/weaknesses earlier, well before pen test - anything found in pentest is chance to refine S SDLC
  12. @hillbrad Yes, pen test is part of the secure sdlc, but imo it's purpose is a last effort to find breakdowns in the process.
  13. OWASP on linkedin - Show your support on the general group linkd.in/JI8rs1 or network with other members here linkd.in/JI8u73
  14. Finding a flaw in a penetration test means you also have a flaw in your secure development lifecycle #rootcause #security
  15. Did you know: When you clear all your firefox cookies you also clear flash cookies (been that way for a year) bit.ly/KZhbYj #privacy
  16. @kenneth_aa @psiinon But, to answer your question - here's the list of Mozilla Security ppl on twitter - mzl.la/IRTbGZ
  17. @kenneth_aa @psiinon I'm hoping you typo'ed that question? "Sec" team, right?