Beautiful Security and over 360,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
 
Express Checkout with PayPhrase
What's this? | Create PayPhrase
Sorry!
More Buying Choices
50 used & new from $18.22

Have one to sell? Sell yours here
 
   
Beautiful Security
 
 
Start reading Beautiful Security on your Kindle in under a minute.

Don’t have a Kindle? Get your Kindle here.
 
  

Beautiful Security (Paperback)

~ Andy Oram (Editor), (Editor)
5.0 out of 5 stars  See all reviews (8 customer reviews)

List Price: $39.99
Price: $34.61 & this item ships for FREE with Super Saver Shipping. Details
You Save: $5.38 (13%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Wednesday, November 11? Choose One-Day Shipping at checkout. Details
35 new from $19.23 15 used from $18.22

Formats

Amazon Price New from Used from
  Kindle Edition $17.59 -- --
  Paperback $34.61 $19.23 $18.22
Like this book? Find similar titles from O'Reilly and Partners in our O'Reilly Bookstore.

Best Value

Buy Beautiful Security and get Beautiful Teams: Inspiring and Cautionary Tales from Veteran Team Leaders at an additional 5% off Amazon.com's everyday low price.

Beautiful Security + Beautiful Teams: Inspiring and Cautionary Tales from Veteran Team Leaders
Buy Together Today: $67.97

Show availability and shipping details


Customers Who Bought This Item Also Bought

The Myths of Security: What the Computer Security Industry Doesn't Want You to Know

The Myths of Security: What the Computer Security Industry Doesn't Want You to Know

by John Viega
4.4 out of 5 stars (26)  $19.80
Beautiful Data: The Stories Behind Elegant Data Solutions

Beautiful Data: The Stories Behind Elegant Data Solutions

by Toby Segaran
4.2 out of 5 stars (8)  $38.82
Beautiful Architecture: Leading Thinkers Reveal the Hidden Beauty in Software Design

Beautiful Architecture: Leading Thinkers Reveal the Hidden Beauty in Software Design

by Diomidis Spinellis
3.0 out of 5 stars (4)  $39.95
Hacking: The Next Generation (Animal Guide)

Hacking: The Next Generation (Animal Guide)

by Nitesh Dhanjani
5.0 out of 5 stars (4)  $26.39
Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly))

Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly))

by George Reese
4.2 out of 5 stars (21)  $19.79
Explore similar items

Editorial Reviews

Product Description

In this thought-provoking anthology, today's security experts describe bold and extraordinary methods used to secure computer systems in the face of ever-increasing threats. Beautiful Security features a collection of essays and insightful analyses by leaders such as Ben Edelman, Grant Geyer, John McManus, and a dozen others who have found unusual solutions for writing secure code, designing secure applications, addressing modern challenges such as wireless security and Internet vulnerabilities, and much more. Among the book's wide-ranging topics, you'll learn how new and more aggressive security measures work--and where they will lead us. Topics include:
  • Rewiring the expectations and assumptions of organizations regarding security
  • Security as a design requirement
  • Evolution and new projects in Web of Trust
  • Legal sanctions to enforce security precautions
  • An encryption/hash system for protecting user data
  • The criminal economy for stolen information
  • Detecting attacks through context

Go beyond the headlines, hype, and hearsay. With Beautiful Security, you'll delve into the techniques, technology, ethics, and laws at the center of the biggest revolution in the history of network security. It's a useful and far-reaching discussion you can't afford to miss.



About the Author

Andy Oram is an editor at O'Reilly Media, a highly respected book publisher and technology information provider. An employee of the company since 1992, Andy currently specializes in free software and open source technologies. His work for O'Reilly includes the first books ever published commercially in the United States on Linux, and the 2001 title Peer-to-Peer. His modest programming and system administration skills are mostly self-taught.

John is CTO of the SaaS Business Unit at McAfee, his second stint at McAfee. Previously, he was their Chief Security Architect, after which he founded and served as CEO of Stonewall Software, which focused on making anti-virus technology faster, better and cheaper. John was also the founder of Secure Software (now part of Fortify).

John is author of many security books, including Building Secure Software (Addison-Wesley), Network Security with OpenSSL (O'Reilly), and the forthcoming Myths of Security (O'Reilly). He is responsible for numerous software security tools and is the original author of Mailman, the GNU mailing list manager. He has done extensive standards work in the IEEE and IETF and co-invented GCM, a cryptographic algorithm that NIST has standardized. John is also an active advisor to several security companies, including Fortify and Bit9. He holds a MS and BA from the University of Virginia.

Product Details

  • Paperback: 281 pages
  • Publisher: O'Reilly Media (May 6, 2009)
  • Language: English
  • ISBN-10: 0596527489
  • ISBN-13: 978-0596527488
  • Product Dimensions: 9.1 x 7 x 0.8 inches
  • Shipping Weight: 1.2 pounds (View shipping rates and policies)
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (8 customer reviews)
  • Amazon.com Sales Rank: #40,606 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #12 in  Books > Computers & Internet > Business & Culture > History
    #15 in  Books > Computers & Internet > Web Development > Security & Encryption > Encryption
    #16 in  Books > Computers & Internet > Certification Central > Exams > Security+

More About the Authors

Discover books, learn about writers, read author blogs, and more.

Inside This Book (learn more)
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

 

Customer Reviews

8 Reviews
5 star:
 (8)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
5.0 out of 5 stars (8 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
8 of 8 people found the following review helpful:
5.0 out of 5 stars Security: Bureaucratic drudgery or exciting career?, June 28, 2009
By Allen Stenger (Alamogordo, NM USA) - See all my reviews
(REAL NAME)   
This collection of essays is a very clearly written introduction to a number of current topics and techniques in computer security. It is not a how-to book, but it includes several case studies and gives you a good idea of what is happening in the field. For the most part the book does not assume prior knowledge in the field, although occasionally a bit of hacker or security jargon is used without being defined.

For me the most interesting chapters were the one with case studies. In this book you will learn how to steal people's credit card numbers at airports (run a cut-rate WiFi access point), how to scan for malicious websites without getting infected (harder than it looks, and a constant battle of measures and countermeasures), and the true history of Pretty Good Privacy, as told by its inventor, Phil Zimmermann (not as lurid as the versions you have probably heard, but still full of twists and turns). You'll learn the going rates for stolen personal and financial information (not that much, so if you're going to steal it, you need to steal a lot) and how to run your own cyber money-laundering network (which seems to be where most of the money and the risk is). Microsoft plays a prominent role in the book, sometimes as hero, sometimes as chump.

The layout and production of the book are very good, and it has a good index (a glossary would have been nice, too). I have a couple of minor gripes: the book is set in itty-bitty type (I measured it at 8 points on 12 point line spacing); and although the book has two editors, the preface is written in the first person singular (apparently by Oram, but this is not stated).

The book's title, "Beautiful Security", was probably modeled on Oram's previous collection Beautiful Code: Leading Programmers Explain How They Think (Theory in Practice (O'Reilly)), but it doesn't really fit the content of this book. Some of the essays mention beauty in the body or the title, but this is usually a token appearance, or is explained as meaning that security should be built in rather than tacked on. The preface states that the purpose of the book is to convince the reader that security is not bureaucratic drudgery but is an exciting career, and I think the book is successful at this.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
5 of 6 people found the following review helpful:
5.0 out of 5 stars An eye-opening book that will challenge you, July 6, 2009
Books that collect chapters from numerous expert authors often fail to do more than be a collection of disjointed ideas. Simply combining expert essays does not always make for an interesting, cohesive read. Beautiful Security: Leading Security Experts Explain How They Think is an exception to that and is definitely worth a read. The books 16 chapters provide an interesting overview to the current and future states of security, risk and privacy. Each chapter is written by an established expert in the field and each author brings their own unique insights and approach to information security.

A premise of the book is that most people don't give security much attention until their personal or business systems are attacked or breached. The book notes that criminals often succeed by exercising enormous creativity when devising their attacks. They think outside of the box which the security people built to keep them out. Those who create defenses around digital assets must similarly use creativity when designing an information security solution.

Unfortunately, far too few organizations spend enough time thinking creatively about security. More often than not, it is simply about deploying a firewall and hoping the understaffed security team can deal with the rest of the risks.

The 16 essays, arranged in no particular theme are meant to show how fascinating information security can be. This is in defense to how security is often perceived, as an endless series of dialogue boxes and warnings, or some other block to keep a user from the web site or device they want to access. Each of the 16 essays is well-written, organized and well-argued. The following 4 chapter are particularly noteworthy.

Chapter 3 is titled Beautiful Security Metrics and details how security metrics can be effectively used, rather than simply being a vehicle for creating random statistics for management. Security metrics are a critical prerequisite for turning IT security into a science, instead of an art. With that, author Elizabeth Nichols notes that the security profession needs to change in ways that emulate the medical professional when it comes to metrics. She notes specifically that security must develop a system of vital signs and generally accepted metrics in the same way in which physicians work. The chapter also provides excellent insights on how to use metrics and how metrics, in addition to high-level questions that can be used to determine how effective security is within an organization.

Chapter 6 deals with online-advertising and the myriad problems in keeping it honest. Author Benjamin Edelman observed a problem with the online supply chain world, as opposed to brick and mortar (BAM) world, in that BAM companies have long-established procurement departments with robust internal controls, and carefully trained staff who evaluate prospective vendors to confirm legitimacy. In the online world, predominantly around Google AdSense, most advertisers and advertising networks lack any comparable rigor for evaluating their vendors. That has created a significant avenue for online advertising fraud, of which the on-line advertising is a victim to.

Edelman writes that he has uncovered hundreds of online advertising scams defrauding hundreds of thousands of users, in addition to the merchants themselves. The chapter details many of the deceptive advertisements that he has found, and shows how often web ads that tout something for free, is most often far from it.

Chapter 7 is about the PGP and the evolution of the PGP web of trust scheme. The chapter is written by PGP creator Phil Zimmerman, and current PGP CTO Jon Callas. It has been a long while since Zimmerman has written anything authoritative about PGP, so the chapter is a welcome one. Zimmerman and Callas note that while a lot has been written about PGP, much of it though containing substantial inaccuracies. The chapter provides invaluable insights into PGP and the history and use of cryptography. It also gives a thorough overview of the original PGP web of trust model, and recent enhancements bring PGP's web of trust up to date.

Chapter 9 is one of the standout chapters in the book. Mark Curphrey writes about the need to get people, processes and technology to work together so that the humans involved in information security can make better decisions. In the chapter, Curphrey deals with topical issues such as cloud computing, social networks, security economics and more. Curphrey notes that when he starts giving a presentation, he does it with the following quotation from Upton Sinclair -- "it's difficult to get a man to understand something when his salary depends on him not understanding it". He uses the quote to challenge listeners (and readers in this case) to question the reason why they are being presented the specific ideas, which serves as a reminder of common, subtle biases for thoughts and ideas presented as fact.

In its 250 pages, Beautiful Security is both a fascinating an enjoyable read. There are numerous security books that weight a few pounds a use reams of paper, that don't have a fraction of the real content that Beautiful Security has. With other chapters from industry luminaries such as Jim Routh, Randy Sabett, Anton Chuvakin and others, Beautiful Security is a required read.

For those that have an interest in information security or those that are frustrated by it, Beautiful Security is an eye-opening book that will challenge you, and change the way you think about information security. It is a good book for those whose who think information security is simply about deploying hardware, and an even better book for those who truly get information security.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
2 of 2 people found the following review helpful:
5.0 out of 5 stars Beautiful Security is Timely, Important and Readable, July 6, 2009
Beautiful Security is full of pertinent information for all of us. The book is well written, covers topics we need to know about, is very readable. Start with the first entry by Mudge: his perspective is accurate and revealing and of course he writes well so enjoy the new insights you gain by reading this book. Highly recommended.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars A solid set of case histories and examples of how to build better security measures
BEAUTIFUL SECURITY: LEADING SECURITY EXPERTS EXPLAIN HOW THEY THINK provides a collection of essays on digital security and comes from experts who explain how social networking... Read more
Published 2 months ago by Midwest Book Review

5.0 out of 5 stars Well-written with broad coverage of a critical topic
Like O'Reilly's Beautiful Teams, this book's a series of essays by industry experts, this time focused on security. Read more
Published 3 months ago by James Holmes

5.0 out of 5 stars A Resilient Text
Beautiful Security goes well beyond the confines of traditional security books that dive into technical minutia and bore you to tears. Read more
Published 3 months ago by Wesley M. Talbert

5.0 out of 5 stars Awesome: fun to read AND thought provoking
"Beautiful Security" from O'Reilly, which I just finished reading, is truly an awesome book.

Now, I will probably have a high opinion of my own chapter ("Beautiful... Read more
Published 5 months ago by Dr Anton Chuvakin

5.0 out of 5 stars Security is more than hacking
As I say on the back cover:

This collection of thoughtful essays catapults the reader well beyond deceptively shiny security FUD (the drum major of the bug parade)... Read more
Published 5 months ago by Gary McGraw

Only search this product's reviews



Customer Discussions

This product's forum
See all discussions...  
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
   


Listmania!


So You'd Like to...


Create a guide

Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.