Reading
I read, review, recommend, and write books on digital security. A few years ago I created several Amazon.com Listmania Lists showing my favorite books, in three categories:
Want Me to Review Your Book?
I used to read and review dozens of books per year (17 in 2000, 42 in 2001, 24 in 2002, 33 in 2003, 33 in 2004, 26 in 2005, 52 in 2006, 25 in 2007, 20 in 2008, 15 in 2009). Now I almost exclusively focus on books which fill gaps in my knowledge. My Amazon.com Wish List shows books I'm keeping an eye on.
If you're an author or publisher, and you'd like me to review a book proposal or published work, email 'taosecurity at gmail dot com'.
Reading List
I plan to read the following titles.
- July 2010
- August 2010
- IT Security Metrics
- Methods and Metrics for Security Risk Management (pub Jul 10)
- Network Flow Analysis
- Surviving Cyber War (pub Jul 10)
- Cyber War (pub Apr 10)
- Practical Lock Picking (pub Jul 10)
- September 2010
- Least Privilege Security for Windows 7, Vista, and XP (pub Aug 10)
- Hacking Exposed: Wireless, 2nd Ed
- Professional Assembly Language
- Introduction to Assembly Language Programming, 2nd Ed
- October 2010
- Beginning C, 4th Ed
- C in a Nutshell
- Windows via C/C++, 5th Ed (pub Dec 07)
- Ivor Horton's Beginning Visual C++ 2010 (pub Apr 10)
- Computer Incident and Product Vulnerability Handling (pub Oct 10)
- November 2010
- Windows System Programming 4th Ed (pub Mar 10)
- Windows Internals, 5th Ed (pub Jun 09)
- Buffer Overflow Attacks
- Shellcoder's Handbook, 2nd Ed
- Writing Security Tools and Exploits
- A Guide to Kernel Exploitation (pub Sep 10)
- December 2010
- Reversing: Secrets of Reverse Engineering
- The IDA Pro Book
- The Art of Debugging with GDB
- Advanced Windows Debugging
- Hacking: The Art of Exploitation, 2nd Ed
- Gray-Hat Hacking, 2nd Ed
- January 2011
- Malware Analyst's Cookbook and DVD (pub Nov 10)
- Fuzzing
- The Art of Software Security Testing
- The Art of Software Security Assessment
- Hunting Security Bugs
- Secure Programming with Static Analysis
- Surreptitious Software
- February 2011
- Ninja Hacking (pub Oct 10)
- Managed Code Rootkits (pub Oct 10)
- Hacking Exposed: Web Applications, 3rd Ed (pub Nov 10)
- Web Application Obfuscation (pub Nov 10)
- Social Penetration (pub Dec 10)
- Client-Side Attacks and Defense (pub Dec 10)
- March 2011
- UNIX Network Programming, 3rd Ed
- FreeBSD Device Drivers (pub Dec 10)
- Securing the Smart Grid (pub Oct 10)
- Securing Data Centers with Catalyst Switches (pub Oct 10)
- Corporate Insecurity (pub Dec 10)
- Digital Forensics with Open Source Tools (pub Mar 11)
- April 2011
- December 2011
- Hacking Exposed: Virtualization and Cloud Computing (pub Dec 11)
The Economist
Beyond digital security works, I read the best international news weekly on the planet -- the Economist. I've been a subscriber since 3 May 1997, when I wrote a check for $54.50 and committed to "take part in a severe contest between intelligence, which presses forward, and an unworthy, timid ignorance obstructing our progress." Given the Economist has been doing this since September 1843, they have a minor head start.
