Jeff Nathan’s blog
Senior Security Engineer, Arbor Networks
eff Nathan is a Senior Security Engineer within Arbor Networks' Arbor Security Engineering & Response Team (ASERT). In this capacity, he is responsible for analyzing burgeoning Internet security threats, reverse engineering malicious code, software development, developing security mechanisms that are then distributed to Arbor's Peakflow platforms via the Active Threat Feed (ATF) service and innovating new security technology. Prior to joining Arbor Networks, Nathan served as a Senior Software Engineer for Sygate Technologies Inc., where he developed intrusion detection technologies. Before Sygate, Nathan worked in various capacities at McKesson Corp., @stake Inc. and Hiverworld, Inc. During the past seven years, Nathan has also been a core member of the Snort project, an elected member of the Honeynet Project, lead developer of the Nemesis Project, and an occasional contributor to a number of open-source software projects.
Entries in the archive
August 9, 2006
It’s Our Party & We’ll Cry If We Want To…
legal / policy / secure coding / Software Development
Have you ever taken a moment to realize that the primary reason the information security industry even exists is because a noted lack of pedantic people both in the RFC world of the 1980s and the software engineering world up until the mid 1990s? Yes, there was actually a time where people did not consider the unexpected consequence of an unbounded strcpy(). Way back, when these people were focuse...
Read this day in the archive
July 18, 2006
A Double Dose of eBay Fraud
other / Security / social engineering / spam
Back in November 2005, Bruce Schneier wrote about a Western Union-related fraud. This week, I was exposed to some of the techniques used by eBay sub-geniuses and their use of Western Union. I deal primarily in buying and selling rare and hard-to-find comics on eBay, which doesn’t see much fraud activity, and as a result...
Read this day in the archive
July 13, 2006
The Scent of Hardware EULAs Backfiring
hardware / legal / malware / reverse engineering / Security
In our shrill world of paranoia where vendors clench their general counsel’s arm tight enough to powder walnuts, it’s not surprising that End User Licensing Agreements (EULAs) continue to grow in absurdity. With the continued prevalence of free OS’, hardware vendors are undoubtedly under increased pressure to either disclose sufficient information for drivers to be...
Read this day in the archive
June 8, 2006
Advisory Ambiguity
Security / vulnerabilities
In the course of notifying the public, some vendors’ vulnerability advisories have been less informative than others. Whereas a significant number of vendors have come to realize the value of some form of disclosure over time, others continually fail to provide actionable information. This entry is not a discussion of the merits and failings of...
Read this day in the archive
Back to the author index · Open the day-by-day archive