On.Security

Developing secure software is a challenge. Writing really secure software is a real challenge.
Here are the articles which touch different security aspects of software, from “what cipher suites are not to be used with TLS”, to certain more or less novel things under ‘Security Research’ subcategory

Advocating “Obscurity Pockets” as a Complement to Security. Part I. Definition and Benefits.

January 31, 2017 by “No Bugs” Bunny

He was preaching Security-by-Obscurity

Quote:

In a hypothetical world where attackers would need to create a unique attack script for each system attacked – such an economy would be a non-starter.

Another Quote:

If all the people would be the same - pandemics such as Black Death would easily take the whole humankind down; it is diversity among humans which allowed us to survive.

Filed under: On.SecurityResearch

Tagged With: crazy stuffCrypto
Read more

Direct Payment Processing. Recovery from ‘Unknown’ Transaction Status. PCI DSS.

January 3, 2017 by “No Bugs” Bunny

PCI DSS Audit

Quote:

With the Direct Processing, customer should trust us (the merchant) with their details

Another Quote:

On the other hand, most of PCI DSS requirements make perfect sense regardless of formal compliance

Filed under: On.SecurityBest PracticesBook: D&D of MOGs1st beta of Vol. IV-VI

Read more

Payment Processing. Credit Cards. Chargebacks and Collateral Damage

December 20, 2016 by “No Bugs” Bunny

Zero Chargeback Guarantee

Quote:

Chargeback monster will come from under the bed and will eat all your hard-earned money!

Another Quote:

it is trivial to develop a system with guaranteed zero chargeback rate – to achieve this, it is sufficient to decline each and every transaction at pre-filter stage

Filed under: On.SecurityFraud PreventionBook: D&D of MOGs1st beta of Vol. VII-IX

Read more

War on Clones, Part II. Identifying Mobile and Browsers. Social and Payment-Based Identification. Putting it all together.

July 18, 2016 by “No Bugs” Bunny

Login

Quote:

as much as iOS is a device identification nightmare, Android is a device identification paradise.

Another Quote:

Everybody makes occasional mistakes, cheaters/abusers included."your DB"

Filed under: On.SecurityFraud PreventionOn.ProgrammingTips and Tricks

Tagged With: multiplayerClient
Read more