February 2011 Blog Posts

Microsoft’s Web Tracking Protection specs submitted to W3C

In case you were wondering where I got the format for the CDN Tracking Whitelist for IE9 it’s part of the Web Tracking Protection specification that’s was accepted by the W3C yesterday. In addition to the TPL format there’s also a DNT header and document.navigator.doNotTrack DOM property proposed which browser can send when a user selects a don’t track me option somewhere. Of course it’s then up to advertisers and trackers to actually act on that. Technorati Tags: IE9,Tracking Protection List

posted @ Friday, February 25, 2011 11:12 AM | Feedback (0)

Beginning ASP.NET Security is now available as a DRM-free PDF ebook

My book, and some others (but who wants those? *grin*) are now available as DRM-free PDFs, at 35% off the print price. For now you’ll need to enter FROST as a coupon code to get the lower price, but apparently the Wrox site will be updated soon to have the lower prices … Technorati Tags: EBook,PDF,Wrox

posted @ Friday, February 25, 2011 9:25 AM | Feedback (1)

Bye CardSpace

Bye bye. Mike Jones shares his thoughts on something he put a lot of work into. I’m sad to see it go; and I would dearly have loved to have seen a UProve enabled version. Oh well.

posted @ Tuesday, February 15, 2011 1:31 PM | Feedback (0)

IE9‘s tracking protection and content distribution networks

IE9 has had tracking protection since early betas. The built in tracking protection detection searches for scripts and images which are embedded on multiple web sites. Whilst this is a good indicator of transparent gifs and advertising scripts which may drop tracking cookies it also catches content delivery networks which host useful scripts like jquery. It has always been possible to switch from automatic blocking to manual blocking and edit the detected list to white list such domains or scripts but the Release Candidate of IE9 now allows publication of Tracking Protection Lists. So, I’ve created a TPL...

posted @ Tuesday, February 15, 2011 1:00 PM | Feedback (0)

NDC Bound

So after a year of not having any speaking to do I dropped myself in it and agreed to appear at NDC2011 in Norway, on my 41st birthday no less. I’ll be presenting an updated version of “Don’t get stung – an introduction to the OWASP Top Ten” and “A developers guide to encryption” which I never got to finish at DDD8 due to all those interruptions (*mutter*). Jon Skeet will also be there, so I’m going to have to ensure I spell encryption correctly this time, just in case he decides to swing by. Now, where can I...

posted @ Wednesday, February 09, 2011 8:29 AM | Feedback (0)