Software Security Blog

A Guide to OWASP’s Secure Coding Practices Checklist
In 2022, 33% of newly discovered vulnerabilities were flagged as critical or high. Explore OWASP’s secure coding practice checklist and learn how to leverage its power to boost your threat protection and reduce attack risks Digitalization is both a blessing and a curse for organizations.…
Blogging About Everything Software Security – Threats, Updates, Best Practices, Tips, & More
Software touches the everyday lives of billions of people around the world. They rely on us (the software industry) to deliver dependable, safe applications for them to use. This blog is dedicated to working together to do our part to make the (software) world a better place…one piece of software at a time!
-
Learn how, when, why, and which PKI digital certificate can help keep your data, customers, and overall business secure in the online world Digitalization has transformed our world and lives dramatically. In the last few years, we’ve seen a significant shift to online communications and transactions: However, the internet wasn’t designed with security in mind.…
-
Hashing algorithms are used all over the internet. Learn what hashing algorithms are, explore their applications, and how to identify what the best hashing algorithm is for your specific needs When talking about hashing algorithms, usually people immediately think about password security. However, hashing algorithms can do much more than that — from data validation…
-
Downloading a single computer virus can spell disaster for your business and result in the theft of customers’ sensitive data. We’ll break down everything you need to know to safely download software, apps, and files from the web How many times did you download a new app, your favorite song or, a free computer program…
-
Is it possible to tell whether a download is safe? In some cases, yes, it is possible. Here’s how to check if a download is safe When you download something from the web, there are chances of accidentally downloading a virus that could harm your computer. More than 5.6 billion malware attacks were carried out…
-
Hashing functions play a vital role in digital security — hashing functions do everything from providing tamper resistance for email communications to securing your software supply chain Just look back at your day so far and try to think how many times you have accessed a website, received an online message, or sent an email.…
-
While it’s possible to generate and use a self signed code signing certificate, this is a practice you should avoid doing for uses outside your organization’s internal testing environment Technically speaking, it’s possible to use self signed code signing certificates. However, doing so in public-facing applications means that the certificate won’t work for its intended…
-
We’ll break down how to sign your EXE files to make them more trustworthy for users As a software developer, you likely know the lifecycle of developing software and are well acquainted with the challenges that come with them. This includes everything from errors and quality checks to the essential phases virtually all software should…
-
Verizon’s 2021 Data Breach Investigation Report data shows that malicious software is involved in more than 70% of system intrusions (including computer hacks). Windows Defender SmartScreen is one of the tools that helps to protect your device against these software-based threats — let’s explore what it is and how it works to protect your PC When…
-
Many malicious programs come from unknown or unverified publishers. But why is software from an unknown publisher dangerous? And why should you only download software from trusted publishers? When you buy or download software, you likely assume that it’s safe. But when an unknown publisher warning pops up on your screen, you quickly realize that’s…
-
AV-TEST says they register more than 450,000 new malware programs and potentially unwanted applications (PUAs) every day. Digitally signing executable files helps you protect your application’s integrity and establish trust According to 2020 data from Statista, one of the most common ways people receive malware is through executable files. So, it’s reasonable to ask questions like:…
-
GoDaddy Has Made the Decision to Stop Issuing & Renewing Code Signing Certificates from June 1, 2021, Onwards GoDaddy Inc., an American company headquartered in Scottsdale, Arizona, and incorporated in Delaware, is one of the biggest publicly traded Internet registrars and web hosting companies. In addition to hosting solutions and domain registration, GoDaddy is also…
-
Microsoft Authenticode Signature Verification – A Cryptographic Procedure Microsoft Authenticode Signature is one type of digital signature format used to determine the origin and integrity of software binaries, like code signing certificates. Microsoft Authenticode is based upon Public-key Cryptography Standards (PKCS) #7 signed data along with X.509 certificates for binding an Authenticode signed binary to the identity of…
-
Here’s How Code Signing Ecosystem Helps Windows Determining Which Software to Trust Have you ever come across an “Unknown Publisher” popup message when you tried installing software? For instance, when you’re installing a piece of software and your Windows computer shows a popup like this stating the software publisher is unknown: How does your operating…
-
List of Software Security Vulnerabilities and Weaknesses If you want to protect your customers and your brand, it’s important to identify and prevent software security vulnerabilities before shipping software. In order to do so, you first need to be aware of the different types of security weaknesses and ways to avoid them. This article aims at…
-
Quick Guide to Generate a CSR Through Java KeyStore for a Java Code Signing Certificate A Java code signing certificate is important to avoid annoying warning messages like “Unknown Publisher” or “Application Blocked by Java Security” and to protect your brand reputation. Java Code Signing Certificates from trusted CAs (like Sectigo) allow developers to sign…