Information Security/Java "This book is mandatory reading for every user and developer of Webware." -Peter G. Neumann, Moderator of the Risks Forum, from his review of the first edition Securing Java Java security is more important now than ever before. As Java matures and moves into the enterprise, security takes a more prominent role. But as Java evolves, its security issues and architectures get more complicated. Written by the world's leading experts on mobile code security, this updated and expanded edition of the groundbreaking guide to Java security includes lessons for Web users, developers, system administrators, and business decision-makers alike. This book navigates the uncharted waters of mobile code security and arms the reader with the knowledge required for securing Java. It provides in-depth coverage of: * The base Java security sandbox, made up of the Verifier, Class Loaders, and the Security Manager * Code signing, stack inspection, and the new Java 2 security architecture * The pros and cons of language-based enforcement models and trust models * All known Java security holes and the attack applets that exploit them * Techniques commonly used in malicious applets * Twelve rules for developing more secure Java code, with explicit examples * Hard questions to ask third-party Java security tools vendors * Analysis of competing systems for mobile code, including ActiveX and JavaScript * Card Java security, smart card risks, and their impact on e-commerce security On the companion Web site www.securingjava.com you'll find: * The Java Security Hotlist: Over 100 categorized and annotated Java security-related Web links * An e-mail list to keep subscribers abreast of breaking Java security news * A complete electronic edition of this book
This book is very informative, describes Java security model and its evolution in detail, in fact, in too much a detail to suit the advanced developers. It does not cover in detail how to write your own ClassLoader/SecurityManager and other security related components, so I would not recommend it to somebody wanting to rewrite the whole security model for an enterprise grade application, but this book surely covers a wide range of security basics which I find would be useful for anyone interested in security, not only for java developers. This books gives a detailed listing of kinds of security threats Java has faced since its inception and how they were plugged and while doing that it gives a good perspective how a system can be compromised or prevented from being so.
A well written book.
Published by Thriftbooks.com User , 25 years ago
It is one of those few books, which captivates the reader to complete the book once he/she begins to read. Most of the contents can be understood by inexperienced Java programmers as well. It gives good leads to references in the area. It can be an eye opener to many people who donot understand the security and its importance.
Excellent conceptual overview
Published by Thriftbooks.com User , 25 years ago
IMHO, this book is an excellent conceptual overview which also goes into some practcial areas, such as signing applet with JDK1.1 and 1.2, IE & Netscape, SignTool, javakey, keytool, JARs and CABs, etc. Has pointers to many relevant resources on the net.But doesn't go into very details (only 315 pp.) and doesn't have any source code.
Excellent book on Java Security
Published by Thriftbooks.com User , 25 years ago
It covers all aspects of Java security from known bugs to the sandbox to the Java Card API and everything in between. The authors are well known security analysts and give you the straight dope on Java security (good and bad).The book is incredibly well researched and extremely accurate. On top of that the writing is excellent and won't put you to sleep as many security tomes will.This book is useful for anyone from novice users to managers to Java Programmers who are concerned about security. Anyone who is involved with or concerned about Java security should buy this book as it will provide them with the information that they need.
ThriftBooks sells millions of used books at the lowest everyday prices. We personally assess every book's quality and offer rare, out-of-print treasures. We deliver the joy of reading in recyclable packaging with free standard shipping on US orders over $15. ThriftBooks.com. Read more. Spend less.