DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports
Events Video Library
Refcards
Trend Reports

Events

View Events Video Library

The Latest Security Topics

article thumbnail
Internet of Doom: The Security Vulnerabilities of Connected Devices
Security in the Internet of Things is a fairly common concern these days - you know, Heartbleed, toasters, that kind of thing - but you may not even have considered the greatest threat to your connected devices: classic 1990s first person shooters. That's the scenario presented in this recent experiment from Context Information Security. By taking advantage of a web interface that require no user authentication, the Context team managed to get Doom up and running on a Canon Pixma printer. Obviously Doom is not the point in itself, so much as an illustration of the vulnerability, but it definitely gets the idea across. According to Michael Jordon at Context, the vulnerability was fairly serious: At first glance the functionality seems to be relatively benign, you could print out hundreds of test pages and use up all the ink and paper, so what? The issue is with the firmware update process. While you can trigger a firmware update you can also change the web proxy settings and the DNS server. If you can change these then you can redirect where the printer goes to check for a new firmware. So what protection does Canon use to prevent a malicious person from providing a malicious firmware? In a nutshell - nothing... Jordon's post goes into detail on how the encryption was broken. Canon was contacted and informed of the problem, and responded that it would be fixed, but Jordon warns that it's not a unique scenario. While this particular technique is not currently a common concern, it demonstrates the reality of security concerns when it comes to IoT devices. Once everything is connected, how many devices will be vulnerable? How confident can we be that the creators of these devices will be cognizant of these issues? As a potential catch-all solution, Context offers a strange bit of advice: Context recommends that you do not put your wireless printers on the Internet, or any other ‘Internet of Things’ device. So, there you go - one way to be sure. The Internet of Things can't help but be secure if you get rid of that whole "Internet" part.
May 22, 2023
by Alec Noller
· 8,199 Views · 1 Like
article thumbnail
How to Handle Secrets in Kubernetes
One crucial aspect of ensuring a secure Kubernetes infrastructure is the effective management of secrets, such as API keys, passwords, and tokens.
May 21, 2023
by Keshav Malik
· 2,653 Views · 2 Likes
article thumbnail
The Role of Open Source in Cloud Security: A Case Study With Terrascan by Tenable
Open-source software and cloud-native infrastructure are inextricably linked and can play a key role in helping to manage security.
May 18, 2023
by Christina DePinto
· 3,826 Views · 2 Likes
article thumbnail
Change Control Doesn’t Work: When Regulated DevOps Goes Wrong
In this article, I explore a use case and dive deeper into the question, "Is change management the best way to manage IT risk?"
May 18, 2023
by Mike Long
· 5,657 Views · 1 Like
article thumbnail
How To Check IP Addresses for Known Threats and Tor Exit Node Servers in Java
This article discusses the importance of detecting threatening IP addresses in various forms and provides two API solutions to help detect those threats.
May 18, 2023
by Brian O'Neill DZone Core CORE
· 4,959 Views · 3 Likes
article thumbnail
What Is Istio Service Mesh?
Istio makes it easier to scale workloads in Kubernetes across multicloud environments. Learn how Istio can help different IT teams and understand its architecture and benefits.
May 18, 2023
by Md Azmal
· 6,611 Views · 7 Likes
article thumbnail
Build a Cloud Tagging Strategy in 5 Steps
Improve resource management, cost control, and governance.
May 18, 2023
by Leon Kuperman
· 2,318 Views · 1 Like
article thumbnail
How To Conduct a Secure Code Review
Secure code reviews are crucial for building applications that protect users, developers, and data. Here's everything you need to know to conduct one.
May 18, 2023
by Zac Amos
· 3,133 Views · 1 Like
article thumbnail
How To Design Reliable IIoT Architecture
Refining your IIoT design is a key part of building strong cybersecurity resilience in the network architecture. Here's how to add security to every layer.
May 18, 2023
by Emily Newton
· 4,378 Views · 2 Likes
article thumbnail
Why Using Generative AI for OKRs Is Generally a Bad Idea
You may want to think twice before jumping on the AI hype train for your OKRs. Security concerns and algorithmic bias can cause your OKRs to cause more harm than good.
May 17, 2023
by James Bohrman
· 2,173 Views · 1 Like
article thumbnail
The EVM Compatibility Chronicles — Part I
The initial article of this four-part series addresses the fundamentals of EVM and the advantages of creating EVM compatibility for blockchain endeavors.
May 17, 2023
by Shahmeer Khan
· 2,199 Views · 2 Likes
article thumbnail
How the Wrong Content Type Introduced a Vulnerability in Odoo
In this article, Sonar's R&D team will provide an overview of content types and how a minor error resulted in a Cross-Site Scripting vulnerability in Odoo.
May 17, 2023
by Thomas Chauchefoin
· 1,974 Views · 1 Like
article thumbnail
Insider Threats and Software Development: What You Should Know
Preventing insider threats completely is not always possible, but organizations can minimize the risk and ensure operational resilience if a threat does occur.
May 17, 2023
by Anastasios Arampatzis
· 2,933 Views · 1 Like
article thumbnail
Safeguarding Your Data Under GDPR Regulations
Learn how to protect personal data and comply with GDPR regulations. Discover the seven essential measures and understand individual rights.
May 17, 2023
by Muhammad Sannan Ali Bhatti
· 3,852 Views · 2 Likes
article thumbnail
Getting a Public SSL Certificate Free of Cost for a Lifetime
This article will explain the steps to install a Public SSL certificate and how we can generate a wildcard certificate for our domain free of cost for a lifetime.
May 17, 2023
by sagar pawar
· 2,772 Views · 1 Like
article thumbnail
Cyphercon 6: Staying Up Late for Cybersecurity
Nearly 1500 cybersecurity professionals gathered in Milwaukee for Cyphercon 6. Read the highlights from the largest hacker event in Wisconsin.
May 17, 2023
by Dwayne McDaniel
· 3,332 Views · 1 Like
article thumbnail
How Virtualization Helps Security
Virtualization allows you to create servers, storage devices, and networks all in virtual space — here's why that's beneficial for cybersecurity.
May 16, 2023
by Zac Amos
· 3,589 Views · 1 Like
article thumbnail
Global Supply Chain With Kafka and IoT
Transforming global supply chain with data streaming and IoT for end-to-end visibility and decision-making in real-time at BMW, Bosch, and Walmart.
May 12, 2023
by Kai Wähner DZone Core CORE
· 6,618 Views · 2 Likes
article thumbnail
How To Implement Istio Ambient Mesh in GKE or AKS
Ambient mode is the future of Istio service mesh. This article presents a step-by-step tutorial on how to implement it in GKE or AKS.
May 12, 2023
by Ravi Verma
· 7,743 Views · 7 Likes
article thumbnail
System Testing and Best Practices
These best practices will ensure that the testing of your system is effective and efficient, leading to a successful project outcome.
May 12, 2023
by Rambabu Inaganti
· 9,923 Views · 2 Likes
  • Previous
  • ...
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • ...
  • Next
  • RSS
  • X
  • Facebook

ABOUT US

  • About DZone
  • Support and feedback
  • Community research

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Core Program
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 3343 Perimeter Hill Drive
  • Suite 215
  • Nashville, TN 37211
  • [email protected]

Let's be friends:

  • RSS
  • X
  • Facebook
×