cyber security Permissions vs authority A discussion of the differences between "having permissions" and "having authority".
eVitabu Why we chose OAuth for eVitabu User authentication is an important consideration when designing any system. Here's how we decided to use OAuth for eVitabu.
conference Towards a safe and secure smart world (conference) A summary of my key take aways from January's conference.
cyber security Learning from cyber attacks Cyber attacks are a regular occurrence, and it's important that we learn from them.
cyber security Reusing paper - good for the environment, risky for privacy It's important to review the paper you re-use to avoid leaking confidential information.
cyber security Delegated trust vs Web of Trust The difference between the web of trust and delegating your trust to a third party.
cyber security Password cracking and how it can help your organisation Password cracking can be an invaluable tool when it comes to checking your organisation's password hygiene.
home automation Thoughts on home automation / smart homes - security (part2) Considering privacy and security with the IoT and smart homes.
cyber security What is a Next Generation firewall? A look at Next Generation firewalls and the extra services they often provide.
cyber security Kent Cyber Security Forum 2019 A short write up following the Kent Cyber Security Forum 2019.
ethics A question of ethics: disclosing security vulnerabilities When you've found a vulnerability, bug or data leak how do you report it? This post looks at the considerations for disclosure.
ethics A question of ethics: filtering and censoring the Internet What's the difference between filtering and censorship? This is a fine line and something I discuss following years of managing web and email filters.
ethics A question of ethics: illegal discoveries during a penetration test Sometimes evidence of crime can be found during penetration tests, so what do you do? I'll discuss the various dilemmas professionals face following some Twitter research.
ethics A question of ethics: investigating users Thoughts on being fair and considerate when investigating others.
ethics A question of ethics: deleting emails from user mailboxes A discussion about the ethics of deleting emails from someone else's mailbox.
System administration Logging: getting the right balance Logging: what's too much? Is there too little? How long should I keep them? This post discusses factors to consider when configuring logging.
development Avoiding direct object reference problems Discussing some of the ways to prevent insecure direct object reference issues.
cyber security Be wary of attackers bearing old emails Analysis of some obfuscated VBScript that a malicious email wanted us to download.
cyber security The threat of security knowledge gaps (conference slides) Slides from my recent conference talk on the threat of security knowledge gaps.
cyber security My journey (so far) to a cyber security career How I got into cybersecurity - the story so far.
cyber security Moving from Keepass to Lastpass Having recently moved from Keepass to LastPass, I discuss my experience so far.
System administration A plea to software developers, vendors and support companies A plea to software vendors so we can all work better together.
cyber security What penetration tests have shown me Having worked with a few cyber security firms over the years, let's take a look at some of the findings.
forensics Show and tell: digital forensics and giving evidence After performing some forensics for the ICO I was called to give evidence in court. Here I discuss some basics of forensics before talking about my experience in court.