Mark Eldridge

Security, software engineering, and technology.

Posts Emails About

Government Identification: BankID and the Australia Card

Blog post, 21 November 2018
One of the less fun aspects of moving countries is that you're a walking edge-case for many IT systems. Being an expat also means becoming intimately familiar with all of the differences in how government services verify the identity of their users.
Read More

Supermicro, hardware trojans, and BMC security

Blog post, 8 October 2018
We need to take two things much more seriously: the security of our supply-chain, and the security of our baseboard management controllers.
Read More

Facebook and the trade-off of centralised authentication

Blog post, 3 October 2018
Having 50 million accounts breached is bad enough, but the bigger issue is that a huge number of third-party services use Facebook to authenticate their users.
Read More

Security gatekeeping in a DevOps world

Blog post, 10 September 2018
In a modern DevOps environment, development teams manage the security of their own systems. In an environment where deployments happen several times a day, this model scales far better than the historical practice of security acting as a gatekeeper to production.
Read More

Security is always a trade-off

Blog post, 23 August 2018
Everything we do in the security industry is a trade-off between convenience and security. The important thing is to be honest about the compromises you are making, and why they are necessary.
Read More

Web Authentication, BankID, and the death of passwords

Blog post, 3 June 2018
In my last email I mentioned Alex Stamos' Twitter takedown of the 'Digi-ID' authentication solution. Buried in the exchange was a mention by Stamos of the Web Authentication standard, which is something you'll be hearing a lot more about in coming months.
Read More
 
Page 1 of 2
Next