Here's a new piece I wrote called The Top Web Vulnerability We Face. It's something I suspect will be around for a long, long time. I'm curious if you agree?
Friday, 26 March 2010
Tuesday, 23 March 2010
Users *have* to start locking their screens when working remotely
Posted on 12:16 by Unknown
To continue on with the message in this previous post about users locking their screens while away from their computers I'm amazed at how naive people are with their computer usage in public places.
I see it practically every time I'm at a coffee shop - someone leaves his/her laptop sitting at the table while he/she goes out to take a phone call, use the restroom, smoke a cigarette, talk with an employee across the store and provides someone with ill-intent enough time to snatch the computer away or, in some cases, sit there and monkey around with the computer.
All it takes is about 60 seconds for someone to hop onto an unsecured computer, access sensitive files stored locally or via the corporate VPN and then delete them or email them out.
Combine this vulnerability with unencrypted hard drives and Microsoft's new always-on mobile intranet connection called DirectAccess and you've got yourself a big problem on your hands.
I see it practically every time I'm at a coffee shop - someone leaves his/her laptop sitting at the table while he/she goes out to take a phone call, use the restroom, smoke a cigarette, talk with an employee across the store and provides someone with ill-intent enough time to snatch the computer away or, in some cases, sit there and monkey around with the computer.
All it takes is about 60 seconds for someone to hop onto an unsecured computer, access sensitive files stored locally or via the corporate VPN and then delete them or email them out.
Combine this vulnerability with unencrypted hard drives and Microsoft's new always-on mobile intranet connection called DirectAccess and you've got yourself a big problem on your hands.
Check out my new Web application security ebook
Posted on 10:14 by Unknown
Hot off the press...OK, hot off the computer - I've written an ebook on Web application security threats published by SearchSoftwareQuality.com - a great application development/QA site that's part of the TechTarget family.
Download it and learn more about:
- New Web application security challenges
- Assessing your Web application security
- Beating common Web security attacks
- Hacking your own applications
- Web application security best practices
Great quote on business and career success
Posted on 07:59 by Unknown
Harold Geneen once said "In business, words are words, explanations are explanations, promises are promises, but only performance is reality."
Reminds me just how cheap talk can be when the marketing machine gets its way - especially with "cloud computing". Look more at the actions of businesses and people and less at the words. There you'll find what they're made of.
Reminds me just how cheap talk can be when the marketing machine gets its way - especially with "cloud computing". Look more at the actions of businesses and people and less at the words. There you'll find what they're made of.
Posted in careers, cloud computing, customer no service, marketing hype, security leadership, success
|
No comments
Monday, 22 March 2010
Our power of choice has been stripped
Posted on 08:14 by Unknown
No need for us to think any more. Here's a great excerpt from a WSJ piece that underscores the issue:
"In our world of infinite wants but finite resources, there are only two ways to allocate any good or service: either through prices and the choices of millions of individuals, or through central government planning and political discretion."
You hear me say a lot that those in control of information security have a choice in the matter...and, as Dr. Phil McGraw says, you choose the behavior you choose the consequences. So be it.
But we individuals in our own personal lives here in America are losing our ability to choose. It's our new reality with Obamacare and, I suspect, many many other things to come. The politicians know better than the people...and it's all our fault.
I'm going to miss the days when we were in control of ourselves...when we were free.
You probably think I'm crazy. I really don't believe I am...I just see what has happened since the beginning and understand what all of this government control will lead us to. The decisions made this weekend will change our country deeply forever. Everyone will understand sooner or later.
"In our world of infinite wants but finite resources, there are only two ways to allocate any good or service: either through prices and the choices of millions of individuals, or through central government planning and political discretion."
You hear me say a lot that those in control of information security have a choice in the matter...and, as Dr. Phil McGraw says, you choose the behavior you choose the consequences. So be it.
But we individuals in our own personal lives here in America are losing our ability to choose. It's our new reality with Obamacare and, I suspect, many many other things to come. The politicians know better than the people...and it's all our fault.
I'm going to miss the days when we were in control of ourselves...when we were free.
You probably think I'm crazy. I really don't believe I am...I just see what has happened since the beginning and understand what all of this government control will lead us to. The decisions made this weekend will change our country deeply forever. Everyone will understand sooner or later.
Are you destroying your backup media the right way?
Posted on 07:39 by Unknown
Here's a recent podcast I recorded on backup media data destruction...better be sure you're doing it the right way:
Ensuring proper data deletion or destruction of backup media
Ensuring proper data deletion or destruction of backup media
Posted in backups, compliance, data destruction, Kevin's security content, storage security
|
No comments
A sincere "Thanks!"
Posted on 04:30 by Unknown
Frederic Bastiat once said "When plunder becomes a way of life for a group of men living together in society, they create for themselves in the course of time a legal system that authorizes it and a moral code that justifies it."
In the same spirit, I want to send out a sincere and heartfelt Thanks! to all my fellow Americans who voted for "Hope" and "Change" putting a Marxist-loving community organizer into power that has led to the passing of this healthcare "reform"monstrosity.
Specifically,
- I want to thank all the people who cannot think long term.
- I want to thank all the people who do not take responsibility for their own choices and actions.
- I want to thank all the people who vote for a living.
- I want to thank all the people who use the police power of government to mooch off of others who actually work for a living.
- I want to thank all the people who believe that government can solve all their problems.
- I want to thank all the people whose selfish dependence on government takes top priority above all.
- I want to thank all the people for supporting politicians who want to force their ideals upon us for the sole reason of gaining control of us and maintaining their own political power.
- I want to thank all the people for supporting politicians who could only pass a bill by manipulating and cheating a well-defined set of rules and procedures.
- I want to thank all the people who believe that Socialism and Communism are "other people's problems" - things that America could never evolve into.
- I want to think all the people who voted for George W. Bush and all the other spineless Republicans who have played a big part in where we're at today.
- I want to thank all the people whose desire for "Hope" and "Change" have helped diminish the opportunities this country had to offer my kids and my future grandkids and, instead, created a scenario for everyone to work harder with less payoff.
I'm just furious at what we've let this country become. The wars that have been fought...the lives that have been lost...the toil our Founding Fathers endured....All of that to end up like this.
Shame on us.
Subscribe to:
Posts (Atom)
