Coverity and Armorize link code quality, security analyses

Posted by Paul Krill | Posted in Application Development, Application Security, Developer World, News, Security Central | Posted on 13-07-2010

Code quality and security analyses are being united through the integration of products from Coverity and Armorize Technologies, the companies are announcing on Tuesday.

The integration will link Coverity Static Analysis, for code analysis, with Armorize CodeSecure, for security analysis. Integrations will be featured in upgrades of the two products planned for the end of this calendar year.

Apple pulls a ‘BP’ in responding to App Store hack

Posted by InfoWorld Tech Watch | Posted in Apple, Apple App Store, Application Development, Application Security, Applications, Developer World, Hacking, News, Security Central | Posted on 07-07-2010

Apple pulls a 'BP' in responding to App Store hack

Apple has responded to press inquiries about the hacking of iTunes user accounts and fraudulent purchases made through its App Store, but the company has yet to come clean about the extent of the incident or the pressing questions it raises about the securi

iTunes hack spotlights shady ‘app farms’

Posted by InfoWorld Tech Watch | Posted in Apple App Store, Application Security, Applications, Developer World, Hacking, News, Security Central, iTunes | Posted on 06-07-2010

iTunes hack spotlights shady 'app farms'

The security of Apple’s iTunes App Store is in question this week, as reports surfaced over the weekend about large-scale compromises of customer accounts and efforts to game the company’s Application ecosystem for illicit profit.

AT&T’s iPad security fumble is just the tip of the iceberg

Posted by InfoWorld Tech Watch | Posted in AT&T, Application Testing, Developer World, Hacking, Mobilize, News, Security Central | Posted on 11-06-2010

AT&T's iPad security fumble is just the tip of iceberg

The iPad is everybody’s “it” device: new, bright, sexy, and — as with everything Apple produces — oh so stylish and fun to use. It’s a transformative item worthy of all the press it has garnered.

Facebook’s security solution: Make devs have accounts

Posted by InfoWorld Tech Watch | Posted in Application Security, Developer World, Facebook, News, Security Central, Web services development | Posted on 03-06-2010

Facebook sets low bar for developers

After scoffing at the idea of tightening its application ecosystem, Facebook is now taking the tiniest of baby steps in that very direction.

Adobe upgrades, renames DRM software for Flash

Posted by Paul Krill | Posted in Adobe Flash, Authentication and authorization, Developer World, Development Tools, Java, News, Security Central | Posted on 11-05-2010

Adobe will ship today its renamed digital rights management software for the Flash platform. Previously known Flash Media Rights Management Server, the new incarnation is called Flash Access 2.0. The company already had announced intentions to shorten the name and will roll out the upgrade at New York’s Streaming Media East conference.

IBM looks to pair security technologies for software development

Posted by Paul Krill | Posted in Application Development, Developer World, News, Security, Security Central | Posted on 08-03-2010

Honing in on the need for more security in application development, IBM Rational is planning an enterprise-level  product that features two separately acquired technologies for security testing and code scanning.

Bug-free software? Dream on

Posted by Neil McAllister | Posted in Application Security, Code analysis, Code testing, Developer World, News, Security Central, Tech Support | Posted on 04-03-2010

Not every software company has to deal with bugs as critical as the ones believed to have contributed to accidents involving Toyota cars, but one thing is becoming increasingly clear: Every software company ships products with hidden security defects. There are virtually no exceptions.

The Web’s greatest security threats revealed

Posted by admin | Posted in Developer World, Hacking, News, Security Central, Vulnerability assessment/management, Web applications, internet | Posted on 22-02-2010

Where are the greatest Web-related security threats today? Analysis of Web Hacking Incidents Database (WHID) reveals that in 2009 social networks were at the greatest risk, malware and defacement remained the most common outcome of Web attacks, and SQL injection was the most common attack vector. Here’s a deeper dive on the findings and what you can do about them.

Google fixes Buzz bug

Posted by admin | Posted in Applications, Developer World, Google, Hacking, News, Security Central, social networking | Posted on 17-02-2010

Google has fixed a Web flaw that gave hackers a way to take control of Google Buzz accounts. The flaw was patched late Tuesday, just hours after being disclosed on a Web-hacking blog run by Robert Hansen, CEO of SecTheory.

Hold vendors liable for buggy software, security experts say

Posted by admin | Posted in Application Development, Application Security, Developer World, News, Security Central | Posted on 16-02-2010

A loose consortium of security experts from more than 30 organizations today called on enterprises to exert more pressure on their software vendors to ensure that they use secure code development practices.

Chrome 4 apes IE8 by adding clickjacking, XSS defenses

Posted by admin | Posted in Applications, Browsers, Developer World, Google Chrome, News, Security, Security Central | Posted on 28-01-2010

Google yesterday announced it has added several new security features to its Chrome browser, including two that were first popularized by rival Microsoft in Internet Explorer 8 (IE8) last year.

InfoWorld’s 2010 Technology of the Year Awards

Posted by Doug Dineley | Posted in Application virtualization, Applications, Blogs and wikis, Collaboration, Data Explosion, Data Management, Data center automation, Database Management Systems, Desktop Virtualization, Developer World, Development Environments, Development Frameworks, Development Platforms, Development Tools, Endpoint security, Green IT, Hardware, Infoworld, Infrastructure Services, Mobile Platforms, Mobilize, Network virtualization, Networking, News, Power Management, Processors, SAN, Security Central, Server Virtualization, Server hardware, Storage, Storage Management, Storage virtualization, Systems Management, Video and Web conferencing, Virtualization, Web Services, Windows, cloud computing, social networking | Posted on 06-01-2010

If you caught “InfoWorld’s top 10 emerging enterprise technologies” in November, you had a running start on our 2010 Technology of the Year Awards. MapReduce, desktop virtualization, I/O virtualization, NoSQL databases, cross-platform mobile application development, and application whitelisting topped our list of high-impact technologies, and not surprisingly, all are represented in our list of top products as well.

InfoWorld’s 2010 Technology of the Year Award winners

Posted by Doug Dineley | Posted in Application virtualization, Applications, Blade Servers, Blogs and wikis, Collaboration, Data Explosion, Data Management, Database Management Systems, Desktop Virtualization, Developer World, Development Environments, Development Frameworks, Development Platforms, Endpoint security, Green IT, Hardware, Infoworld, Infrastructure Services, Mobile Platforms, Mobilize, Networking, News, Power Management, Processors, SAN, Security Central, Server Virtualization, Server hardware, Smartphones, Storage, Systems Management, Video and Web conferencing, Virtualization, Web Services, Windows, cloud computing | Posted on 06-01-2010

The top underreported tech stories of 2009

Posted by Galen Gruman | Posted in Applications, Civil Lawsuits, Developer World, Hardware, Intellectual Property, Languages and standards, Mobile communication protocols, Mobilize, Networking, News, Open Source, Processors, Security Central, Tech industry analysis, Telecom, WAN (wide area networking), cloud computing, underreported stories | Posted on 28-12-2009

Think your wireless service is crummy? Just wait until next year when the spectrum drought really hits home. And maybe you’ve been telling your users that installing a graphics card in an office PC is a waste of money. If that’s the case, you’re missing a chance to make them a lot more productive (as long as the games stay at home). You’ve known about CMOS for years. But do you know that an emerging technology called PCMOS, which uses non-Boolean logic, is on the verge of slashing power consumption in ASICs?

Adobe Flash’s security woes: How to protect yourself

Posted by Galen Gruman | Posted in Adobe Flash, Adobe Systems, Application Security, Developer World, Hackers, Malware, News, Security Central, Web services development | Posted on 14-12-2009

Adobe’s Flash Player software is on 99 percent of Internet-connected desktops, offering up multimedia and video capabilities on a multitude of popular Web sites such as YouTube. But the Adobe Flash platform has been beset by a rash of security problems that give intruders potential access to computers running the software.

Five security lessons learned from Office 2010

Posted by Neil McAllister | Posted in Application Security, Desktop productivity, Developer World, Development methodologies, Microsoft Office, News, Security Central, Vulnerability assessment/management | Posted on 03-12-2009

I continue to be impressed with the changes coming in Office 2010 (currently in beta). Previously, I explained how Microsoft drew on real-world usage data to craft the beta suite’s updated UI. Security is another priority for the upcoming release, and while the improvements there aren’t as readily apparent, for developers they’re equally noteworthy.

NSA role in Windows 7 development raises privacy concerns

Posted by admin | Posted in Developer World, Government use of IT, News, Privacy, Security Central, Windows, Windows 7 | Posted on 19-11-2009

The National Security Agency (NSA) worked with Microsoft on the development of Windows 7, an agency official acknowledged this week during testimony before Congress.

2009′s top 10 emerging enterprise technologies

Posted by Doug Dineley | Posted in Data Explosion, Data Management, Database Management Systems, Desktop Virtualization, Developer World, Development Frameworks, Drives and arrays, Endpoint security, Green IT, Hardware, Infoworld, Mobile Platforms, Mobilize, Networking, News, Power Management, Processors, Security Central, Server Virtualization, Storage, Storage virtualization, Virtualization, cloud computing | Posted on 16-11-2009

Microsoft releases security guidelines for Agile development

Posted by admin | Posted in Agile Development, Data Security, Developer World, Development Tools, Development methodologies, News, Security Central | Posted on 09-11-2009

Microsoft will release on Tuesday guidelines for developers building online applications and for those utilizing the Agile code-development process.

The Agile guidelines apply principles from Microsoft’s Security Development Lifecycle (SDL) to Agile, an umbrella term for a development model frequently used for Web-based applications released under short deadlines, called “sprints.”