Books
Computers Electronics Home & Garden Jewelry Movies Music Toys
Search for: in
Developing Trust: Online Privacy and Security
by Apress
Developing Trust: Online Privacy and Security - Click to Enlarge
Avg. Rating: 4.75 of 5 stars (based on 4 reviews)
$1.32 to $39.95 from 2 stores
Suitable for the IP manager or developer seeking to improve Web privacy and security, Developing Trust: Onl… Read more
Information Below:  Store Prices  |  Customer Reviews


Compare Store Prices
View: All  |  Used
Sort By
Store Name
Sort By
Store Rating
Sort By
Price
Sort By
Shipping
 
Description
 
Buy
Bunches of Books
Store Info
Be the first to write a review
Used
See site Developing Trust: Online Privacy and Security See it at at
Bunches of Books
* Prices and availability are subject to change without notice. Please check the merchant store for details.
List Your Products -

Product Description
Developing Trust: Online Privacy and Security
Description
Suitable for the IP manager or developer seeking to improve Web privacy and security, Developing Trust: Online Privacy and Security provides an intriguing, though at times somewhat theoretical, guide to the issues surrounding privacy today.

Interestingly, this book straddles an expert-eye, theoretical overview of what privacy is and a more practical view of how it is often undermined on the Internet today. Early sections cover basic terms and concepts of privacy at a fairly high level. Mixing in sometimes erudite commentary (and an occasional rant), the author's expert-level view does a good job of explaining what privacy is and the larger principles used to protect it. From anonymity to "verinymity" (where sites know who you are), Curtin makes a good case that anonymity is often eventually undermined on today's Web sites. A good section early in the book outlines how a potential attacker might attack a hypothetical Web site for security holes. (We never see the attack carried out, perhaps because it would be irresponsible to do so, but this material establishes Curtin's expertise for the reader.)

Though the early sections largely avoid specific standards and real Internet software, the book soon delves into the nuts and bolts of the Web, for example HTTP, HTML, URLs, and cookies, with an eye to privacy. For most readers, the most fascinating sections of this text will be the author's five case studies on real privacy problems with some of today's leading Web sites and vendors (including Netscape and DoubleClick). He shows how certain features--like cookies--can undermine privacy (or even the ability to "opt out" successfully). A follow-up chapter cements the argument that if Web sites collect "anonymous" browsing behavior, it is all too easy to connect users' real identities to their supposedly anonymous profiles later on, putting privacy in jeopardy. Finally, the author makes a good argument that protecting privacy is good business sense.

The book concludes with more practical advice on implementing good security practices, including an excellent discussion of firewalls, DMZs, including their limitations, and a checklist for beefing up security in your organization. The text closes with a final case study of a hypothetical Web site (which serves up content from third parties) that arguably "does it right" regarding privacy, based on the author's earlier discussion.

While the mix of theoretical and practical here will not suit everyone, there's little doubt that the author's in-depth understanding of the issues surrounding privacy today can help your organization do better with privacy and security. While this title will not help you configure Internet Information Server, for instance, it will help you plan high-level strategies for improved security, as well as show you why protecting user and organizational privacy makes good business sense. --Richard Dragan


Book Description

Although the harrowing number of Internet-based attacks in recent years has elevated the importance of maintaining secure electronic networks, many developers continue to employ passive security administration strategies, addressing issues by using patches in a non-systematic fashion. This counterproductive strategy can be largely attributed to a lack of knowledge regarding the general concepts required to effectively prevent the attack and potential compromise of networked systems.

Developing Trust: Online Privacy and Security is an indispensable resource for system administrators and application developers, providing a means to understand, create, and maintain secure Internet systems. Curtin's instructional approach facilitates a comprehensive understanding of online security by separating the core material into three sections:

  • Understanding Security and Privacy introduces attack models, general privacy theory and policy, online privacy concepts, and provides a synopsis of the mechanics of threats to privacy.
  • Prevention delves into secure design principles and deployment environments, closing with several case studies of major security problems uncovered by the author himself.
  • The Cure investigates the mechanics of identifying and repairing flawed security design techniques before they are incorporated into the final product. Discussion regarding the failure of "Opt-Out" systems to protect privacy is also included in this section.

Author Articles

Read Apress' interview with Matt Curtin.


Download Description

Although the harrowing number of Internet-based attacks in recent years has elevated the importance of maintaining secure electronic networks, many developers continue to employ passive security administration strategies, addressing issues by using patches in a non-systematic fashion. This counterproductive strategy can be largely attributed to a lack of knowledge regarding the general concepts required to effectively prevent the attack and potential compromise of networked systems.

Developing Trust: Online Privacy and Security is an indispensable resource for system administrators and application developers, providing a means to understand, create, and maintain secure Internet systems. Curtin's instructional approach facilitates a comprehensive understanding of online security by separating the core material into three sections:

  • Understanding Security and Privacy introduces attack models, general privacy theory and policy, online privacy concepts, and provides a synopsis of the mechanics of threats to privacy.
  • Prevention delves into secure design principles and deployment environments, closing with several case studies of major security problems uncovered by the author himself.
  • The Cure investigates the mechanics of identifying and repairing flawed security design techniques before they are incorporated into the final product. Discussion regarding the failure of "Opt-Out" systems to protect privacy is also included in this section.

Customer Reviews
2 out of 2 people found the following review helpful:
4 of 5 stars  case studies are good expositions
Wednesday, March 23, 2005
Written in 2002 and with scarcely two years passing, Curtin's message is more timely this year. He warned of the perils of malware and of cracker attacks on corporate databases. Especially by social engineering.

He presents several case studies of insecure privacy applications. He analyzed the commercially deployed systems of Alexa, DoubleClick and others. Showing how cookies and server side bugs could lead to users being tracked. In some cases, as they perused many different websites that reported their activities to a central site. Other books have talked about how cookies could be misused in this way. But Curtin's analysis goes beyond a typical generic treatment and can be more instructive to you.

The malware of 2002 that he warned of has increased in sophistication and danger. No sign of abatement, so keeping the book's ideas in mind is a good idea.

3 out of 3 people found the following review helpful:
5 of 5 stars  Making a dry subject palatable
Thursday, July 11, 2002
Security and privacy are not "sexy" subjects and I was ready for a dry dissertation but this book was anything but.

Although the subject matter is serious and is treated seriously, Curtin has a light and deft touch that make the book a pleasure to read.

And while this book's target audience is programmers responsible for dealing with the issues of Privacy and Security, I would recommend this book to a much wider audience. Every top manager of a company that has a web site should read this book so they can understand how Online Privacy and Security could affect them and so they can ask the questions that someone needs to be asking the folks who are running and developing websites.

I would also recommend the internet savvy who are curious about these two buzzwords because this book will provide them a much better understanding of the stories that have and will appear in the news related to privacy and security. The real world examples are ones that we all can relate to.


7 out of 7 people found the following review helpful:
5 of 5 stars  Really Good book about privacy
Tuesday, May 21, 2002
Privacy means radically different things to different people as it is an abstract and often elusive term that is often difficult to effectively define.

In a nutshell, privacy is the ability of an individual or organization to decide whether, when, and to whom personal or organizational information is released.

While defining privacy is difficult, ensuring on-line privacy is even more challenging. Those required to ensure that their corporate systems and web sites are secure against prying hackers will find Developing Trust: Online Privacy and Security to be an important resource.

Curtain writes in an entertaining and easy to read style; especially when he introduces topics such as attack models, privacy concepts, and threats.

The book suggests prevention mechanisms and includes a few real-world case studies. If you have anything to do with electronic privacy, Developing Trust: Online Privacy and Security is a great book to read.


18 out of 18 people found the following review helpful:
5 of 5 stars  Definitive work
Sunday, May 12, 2002
This book examines the social, legal and technical issues surrounding online privacy. Not only is the consumer side of privacy examined, but the business side from a marketing point of view is also discussed to present a balanced view of the key issues from both sides of the equation.

Mr. Curtin is an expert in privacy and security issues, as well as cryptography and security technology. The approach he takes in the book is to explain both the theory and concepts of privacy in social and legal contexts, and to examine the threats and exposures.

From there he leads you through the design of a solution that starts with principles, then a thorough examination of the underlying online technologies and how they work for and against you. An obvious example of one technical element that works for and against is the 'cookie' which can provide a major convenience (it remembers you and your preferences) and an invasion of your privacy (it remembers you and your preferences - and can also 'stalk' you in a manner of speaking). How to best balance the strengths and weaknesses of not only the technology, but the business imperatives driving commercial uses of the internet are addressed.

My personal vuiew is that this book blends the best of Bruce Schneier's Secrets and Lies and Richard Hunter's World Without Secrets. Schneier's book covered the full range of security issues, social and technical. Hunter's book is more focused on social aspects of privacy. What sets this book apart from those two are the focus on privacy and the multiple contexts in which the book addresses it: social, legal and technical. If the author keeps this book up to date it is destined to become a classic. The challenge is to remain abrest of emerging legal issues and technical breakthroughs - both of which are inevitable.


See all customer reviews...
Home  |  About Priceflo  |  Tell a Friend  |  List Your Products  |  Merchant Login  |  Site Map  |  Help

© 2008, Priceflo, Inc. All rights reserved. Privacy Policy  |  Terms of Service