About the Author

Chris Shiflett

Chris Shiflett is an author and speaker who leads the web application security practice at OmniTI.


All Posts for 2008

OpenID with myVidoop

I like OpenID. I've been an avid user (and consumer) of OpenID for well over a year now, but I've only recently found time to explore Vidoop, whose self-described mission is one username, no password. I keep meaning to write a more general post about ...

CSS Naked Day

If you're wondering what happened to the design, it's gone! I'm participating in CSS Naked Day again to celebrate web standards and good design. True beauty is more than skin deep, and I'm proud of my blog's design. (Thanks again, Jon and Jon!) As a re...

URLs Can Be Beautiful

We launched a new web site for OmniTI on Monday, complete with a new identity designed by Jon Tan. As with most projects of this nature, this was all done in our spare time, but we're proud of the results and hope it represents who we are and what we...

Kiwi Foo Camp

My sunburned feet have healed, so that means it's time to recap my trip to New Zealand for the second annual Kiwi Foo Camp. My trip started in Auckland Friday morning, where I met David Slack (a fellow Foo), who was kind enough to give me a ride to ...

CIO Magazine Trolls for Publicity

All publicity is good publicity, right? I'm not so sure. Last week, CIO Magazine published an article on the advantages and disadvantages of the PHP programming language that can only be described as a blunder. With a target audience of C-level techni...

Security and User Experience

A post entitled SmugMug's Private Pics Are Public caught my eye yesterday. The news doesn't sound too surprising, since these types of security problems aren't at all uncommon, but Don (SmugMug's CEO) is a friend of mine, and I know he takes security v...

2007 Highlights

Posting highlights of the previous year has become a blogging cliché, but this is my 5th consecutive year doing so, and it's a tradition I hope to keep. It gives me a nice record of the previous year as well as a chance to make my plans for the upcomi...

Upcoming Talks

php|tek

21 - 23 May 2008

At Sheraton Gateway Suites Chicago O'Hare, Chicago, Illinois.

DC PHP Conference

02 - 04 Jun 2008

At Cafritz Conference Center, Washington, District of Columbia.

O'Reilly Open Source Convention

21 - 25 Jul 2008

At Oregon Convention Center, Portland, Oregon.

ZendCon

15 - 18 Sep 2008

In Santa Clara, California.

PHP Appalachia

11 - 14 Oct 2008

At Big Bear Lodge, Gatlinburg, Tennessee.

New Comments

hossein wrote:

Hi! May you give me an example how to use mcrypt_encrypt() in order to save passwrod in databa...

Posted in OpenID with myVidoop
Chris Shiflett wrote:

Hi John, I agree with you. I think the optimal solution for this site is for me to let people ...

Posted in OpenID with myVidoop
John Layman wrote:

I had one more thought after I attempted to post a comment. If a user decides to change which Ope...

Posted in OpenID with myVidoop
John Layman wrote:

Thanks for the tip. This should come in handy for all those passwords I never remember. By the...

Posted in OpenID with myVidoop
Richard Edwards wrote:

*relying

Posted in Security Corner: Session Hijacking

Browse Comments