This New Vulnerability: Dowd’s Inhuman Flash Exploit
matasano.com
matasano.com
But what may interest you, if you're a dev, is TAOSSA, Mark Dowd, John McDonald and Justin Schuh's awesome Addison-Wesley book on reviewing source code for security problems:
If you code, and there's just one book you're going to put on your shelf to fill the "security" slot, fuck Applied Cryptography (which is going to cause security problems in your code). This book is about as large, and, in stark contrast to Schneier, flipping to any page of it is probably going to improve the security of your product.
In the very best case with your company, people like Mark Dowd --- or at least people who've memorized his book --- are what you're up against the moment someone decides your security needs to be reviewed (to take credit card numbers, manage personal information, or get deployed at a Fortune 500 client).
Highest possible recommendation.
I haven't checked out TAOSSA, but I have to admit I've got a pretty dog-eared copy of Applied Cryptography here on my desk. In my defense, I only have it for light reading over lunch, I wouldn't dare implement anything from it by hand ;)
I can't tell whether the gp means it'll cause problems because the protocols are hard to implement or wrong.
http://www.matasano.com/log/487/rsa-signature-forgery-explai...
I recommend it with reservations. It's an extremely valuable book, especially if you're a security evaluator looking for crypto vulnerabilities. As an implementation guide, it misses glaring faults that real software constantly introduces.
There simply is no by-the-numbers guide to implementing crypto in an application, and doing it wrong is worse than not doing it at all.