<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>SoftwareSecurity on Snake Eyes Software</title><link>https://www.snakeeyessoftware.com/tags/softwaresecurity/</link><description>Recent content in SoftwareSecurity on Snake Eyes Software</description><generator>Hugo -- 0.164.0</generator><language>en-us</language><lastBuildDate>Wed, 10 Dec 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://www.snakeeyessoftware.com/tags/softwaresecurity/index.xml" rel="self" type="application/rss+xml"/><item><title>Supply Chain Vulnerabilities: The NPM Dependency Security Crisis</title><link>https://www.snakeeyessoftware.com/blog/supply-chain-vulnerabilities-npm-dependency-security/</link><pubDate>Wed, 10 Dec 2025 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/supply-chain-vulnerabilities-npm-dependency-security/</guid><description>Explore NPM supply chain vulnerabilities including the React RCE exploit and Shai-Hulud worm. Learn dependency management best practices and AI-powered security solutions.</description></item><item><title>Lean Software Teams Building Digital Landfills</title><link>https://www.snakeeyessoftware.com/blog/lean-software-teams-building-digital-landfills/</link><pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/lean-software-teams-building-digital-landfills/</guid><description>Software teams spend millions building features with minimal value while security vulnerabilities rise. The article critiques misapplication of Lean Manufacturing principles in software development.</description></item><item><title>The Impossible Security Goal Your Team Should Set Anyway</title><link>https://www.snakeeyessoftware.com/blog/the-impossible-security-goal-your-team-should-set-anyway/</link><pubDate>Tue, 07 Jan 2025 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/the-impossible-security-goal-your-team-should-set-anyway/</guid><description>A guide proposing that teams adopt an ambitious security goal of remediating all vulnerabilities within 60 days, emphasizing systems and habits over traditional goal-setting approaches.</description></item><item><title>KPI Chaos to Cash Flow: Rethinking Security Metrics for Real Success</title><link>https://www.snakeeyessoftware.com/blog/kpi-chaos-to-cash-flow-rethinking-security-metrics-for-real-success/</link><pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/kpi-chaos-to-cash-flow-rethinking-security-metrics-for-real-success/</guid><description>An examination of how application security key performance indicators can either sabotage or support successful software development programs.</description></item><item><title>Subscribed to Risk? Unpacking the Security Implications of Subscription-Based Software</title><link>https://www.snakeeyessoftware.com/blog/subscribed-to-risk-unpacking-the-security-implications-of-subscription-based-software/</link><pubDate>Mon, 06 May 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/subscribed-to-risk-unpacking-the-security-implications-of-subscription-based-software/</guid><description>An examination of how subscription-based software models have transformed development and deployment, while introducing new security and privacy challenges for both consumers and product teams.</description></item><item><title>Bulletproof Your UI: Crafting Secure and User-Friendly Interfaces</title><link>https://www.snakeeyessoftware.com/blog/bulletproof-your-ui-crafting-secure-and-user-friendly-interfaces/</link><pubDate>Wed, 27 Mar 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/bulletproof-your-ui-crafting-secure-and-user-friendly-interfaces/</guid><description>Software security begins with user interaction. This article explores how UI design, data validation, and error handling work together to create secure applications while maintaining usability.</description></item><item><title>Security as an Enabler: The Case for a Hands-On Approach</title><link>https://www.snakeeyessoftware.com/blog/security-as-an-enabler-the-case-for-a-hands-on-approach/</link><pubDate>Thu, 21 Mar 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/security-as-an-enabler-the-case-for-a-hands-on-approach/</guid><description>Examines whether security functions as a gatekeeper or enabler across different authentication approaches: building custom solutions, purchasing commercial platforms like Okta, or blending open-source tools like Keycloak.</description></item><item><title>Tools, Gates, and Debates: Navigating the Quirks of Software Security</title><link>https://www.snakeeyessoftware.com/blog/tools-gates-and-debates-navigating-the-quirks-of-software-security/</link><pubDate>Wed, 13 Mar 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/tools-gates-and-debates-navigating-the-quirks-of-software-security/</guid><description>A security expert with 20+ years of experience critiques mainstream software security advice, discussing how security functions as guidance rather than a gatekeeper, the limitations of attribute-based vulnerability prioritization, and why tool diversity strengthens security practices.</description></item><item><title>Secure by Design: Exploring Technology Choices</title><link>https://www.snakeeyessoftware.com/blog/secure-by-design-exploring-technology-choices/</link><pubDate>Wed, 28 Feb 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/secure-by-design-exploring-technology-choices/</guid><description>Examination of consistent versus varied technology stacks in microservices, with focus on security implications for the MyOwnTutorial application.</description></item><item><title>Building Blocks: Architectural Principles Driving Higher Value Software</title><link>https://www.snakeeyessoftware.com/blog/building-blocks-architectural-principles-driving-higher-value-software/</link><pubDate>Wed, 21 Feb 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/building-blocks-architectural-principles-driving-higher-value-software/</guid><description>Examination of design principles including Domain-Driven Design, Hexagonal Architecture, Event-Driven Programming, CQRS, Micro-service Architecture, API-First Development, and Privacy-First approaches for building secure, cost-effective software.</description></item><item><title>Designing for the Future of Education: A Tutorial on Building Secure Applications</title><link>https://www.snakeeyessoftware.com/blog/designing-for-the-future-of-education-a-tutorial-on-building-secure-applications/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/designing-for-the-future-of-education-a-tutorial-on-building-secure-applications/</guid><description>A tutorial exploring secure application design for educational software, balancing legal requirements with business and practical security needs.</description></item><item><title>The Secure Software Habit</title><link>https://www.snakeeyessoftware.com/blog/the-secure-software-habit/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/the-secure-software-habit/</guid><description>Guide to building secure software through intentional practices across building, testing, and deployment phases.</description></item><item><title>Hiding Data in Plain Sight</title><link>https://www.snakeeyessoftware.com/blog/hiding-data-in-plain-sight/</link><pubDate>Wed, 10 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/hiding-data-in-plain-sight/</guid><description>Overview of four data protection methods: encryption, hashing, encoding, and compression, with applications in educational software security.</description></item><item><title>None Shall Pass</title><link>https://www.snakeeyessoftware.com/blog/none-shall-pass/</link><pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/none-shall-pass/</guid><description>Explores access control strategies for protecting data privacy in software systems, using Monty Python references to illustrate security concepts.</description></item><item><title>The Honor Code of Data: Privacy-First Design</title><link>https://www.snakeeyessoftware.com/blog/the-honor-code-of-data-privacy-first-design/</link><pubDate>Wed, 27 Dec 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/the-honor-code-of-data-privacy-first-design/</guid><description>An examination of privacy-first design principles in software, covering data protection, confidentiality, access controls, and secure system architecture.</description></item><item><title>It All Starts With Design</title><link>https://www.snakeeyessoftware.com/blog/it-all-starts-with-design/</link><pubDate>Wed, 20 Dec 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/it-all-starts-with-design/</guid><description>An exploration of software design principles, drawing parallels with woodworking and emphasizing the importance of design throughout the development lifecycle.</description></item><item><title>Software Security Is Software Quality</title><link>https://www.snakeeyessoftware.com/blog/software-security-is-software-quality/</link><pubDate>Wed, 13 Dec 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/software-security-is-software-quality/</guid><description>An exploration of how software security parallels craftsmanship quality, using woodworking analogies to explain why security testing is essential for consumer-facing software products.</description></item><item><title>Security Posture Basics</title><link>https://www.snakeeyessoftware.com/blog/security-posture-basics/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/security-posture-basics/</guid><description>An overview of security posture fundamentals, covering weaknesses, vulnerabilities, threats, and risk management strategies.</description></item><item><title>Availability</title><link>https://www.snakeeyessoftware.com/blog/availability/</link><pubDate>Wed, 04 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/availability/</guid><description>The third pillar of information security focuses on ensuring data accessibility according to established expectations through network, server, and application-level controls.</description></item><item><title>Integrity: What You See Is What You Get</title><link>https://www.snakeeyessoftware.com/blog/integrity-what-you-see-is-what-you-get/</link><pubDate>Wed, 27 Sep 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/integrity-what-you-see-is-what-you-get/</guid><description>Explores data integrity as a fundamental software security principle, examining how to ensure data accuracy and completeness through confidentiality controls, error handling, and digital signatures.</description></item><item><title>Confidentiality</title><link>https://www.snakeeyessoftware.com/blog/confidentiality/</link><pubDate>Wed, 20 Sep 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/confidentiality/</guid><description>An exploration of confidentiality as a key pillar of system trust, covering data management, user authentication, access control principles, and data protection methods.</description></item><item><title>What is Software Security?</title><link>https://www.snakeeyessoftware.com/blog/what-is-software-security/</link><pubDate>Mon, 03 Apr 2023 00:00:00 +0000</pubDate><guid>https://www.snakeeyessoftware.com/blog/what-is-software-security/</guid><description>An introduction to software security covering confidentiality, integrity, and availability of applications, plus post-deployment responsibilities.</description></item></channel></rss>