Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 26 March 2010

What's the biggest Web vulnerability?

Posted on 05:02 by Unknown
Here's a new piece I wrote called The Top Web Vulnerability We Face. It's something I suspect will be around for a long, long time. I'm curious if you agree?
Read More
Posted in stupid security, web application security, web server security | No comments

Tuesday, 23 March 2010

Users *have* to start locking their screens when working remotely

Posted on 12:16 by Unknown
To continue on with the message in this previous post about users locking their screens while away from their computers I'm amazed at how naive people are with their computer usage in public places.

I see it practically every time I'm at a coffee shop - someone leaves his/her laptop sitting at the table while he/she goes out to take a phone call, use the restroom, smoke a cigarette, talk with an employee across the store and provides someone with ill-intent enough time to snatch the computer away or, in some cases, sit there and monkey around with the computer.

All it takes is about 60 seconds for someone to hop onto an unsecured computer, access sensitive files stored locally or via the corporate VPN and then delete them or email them out.

Combine this vulnerability with unencrypted hard drives and Microsoft's new always-on mobile intranet connection called DirectAccess and you've got yourself a big problem on your hands.
Read More
Posted in locking screens, mobile security, stupid security, user awareness, Windows 7, windows security | No comments

Check out my new Web application security ebook

Posted on 10:14 by Unknown
Hot off the press...OK, hot off the computer - I've written an ebook on Web application security threats published by SearchSoftwareQuality.com - a great application development/QA site that's part of the TechTarget family.















Download it and learn more about:

  • New Web application security challenges
  • Assessing your Web application security
  • Beating common Web security attacks
  • Hacking your own applications
  • Web application security best practices
It's free - just sign up for it at Bitpipe.com.
Read More
Posted in Kevin's books, web application security, whitepapers | No comments

Great quote on business and career success

Posted on 07:59 by Unknown
Harold Geneen once said "In business, words are words, explanations are explanations, promises are promises, but only performance is reality."

Reminds me just how cheap talk can be when the marketing machine gets its way - especially with "cloud computing". Look more at the actions of businesses and people and less at the words. There you'll find what they're made of.
Read More
Posted in careers, cloud computing, customer no service, marketing hype, security leadership, success | No comments

Monday, 22 March 2010

Our power of choice has been stripped

Posted on 08:14 by Unknown
No need for us to think any more. Here's a great excerpt from a WSJ piece that underscores the issue:

"In our world of infinite wants but finite resources, there are only two ways to allocate any good or service: either through prices and the choices of millions of individuals, or through central government planning and political discretion."

You hear me say a lot that those in control of information security have a choice in the matter...and, as Dr. Phil McGraw says, you choose the behavior you choose the consequences. So be it.

But we individuals in our own personal lives here in America are losing our ability to choose. It's our new reality with Obamacare and, I suspect, many many other things to come. The politicians know better than the people...and it's all our fault.

I'm going to miss the days when we were in control of ourselves...when we were free.

You probably think I'm crazy. I really don't believe I am...I just see what has happened since the beginning and understand what all of this government control will lead us to. The decisions made this weekend will change our country deeply forever. Everyone will understand sooner or later.
Read More
Posted in government regulations, politics, scary stuff, stupid security | No comments

Are you destroying your backup media the right way?

Posted on 07:39 by Unknown
Here's a recent podcast I recorded on backup media data destruction...better be sure you're doing it the right way:

Ensuring proper data deletion or destruction of backup media
Read More
Posted in backups, compliance, data destruction, Kevin's security content, storage security | No comments

A sincere "Thanks!"

Posted on 04:30 by Unknown

Frederic Bastiat once said "When plunder becomes a way of life for a group of men living together in society, they create for themselves in the course of time a legal system that authorizes it and a moral code that justifies it."

In the same spirit, I want to send out a sincere and heartfelt Thanks! to all my fellow Americans who voted for "Hope" and "Change" putting a Marxist-loving community organizer into power that has led to the passing of this healthcare "reform"monstrosity.

Specifically,

  • I want to thank all the people who cannot think long term.
  • I want to thank all the people who do not take responsibility for their own choices and actions.
  • I want to thank all the people who vote for a living.
  • I want to thank all the people who use the police power of government to mooch off of others who actually work for a living.
  • I want to thank all the people who believe that government can solve all their problems.
  • I want to thank all the people whose selfish dependence on government takes top priority above all.
  • I want to thank all the people for supporting politicians who want to force their ideals upon us for the sole reason of gaining control of us and maintaining their own political power.
  • I want to thank all the people for supporting politicians who could only pass a bill by manipulating and cheating a well-defined set of rules and procedures.
  • I want to thank all the people who believe that Socialism and Communism are "other people's problems" - things that America could never evolve into.
  • I want to think all the people who voted for George W. Bush and all the other spineless Republicans who have played a big part in where we're at today.
And finally,
  • I want to thank all the people whose desire for "Hope" and "Change" have helped diminish the opportunities this country had to offer my kids and my future grandkids and, instead, created a scenario for everyone to work harder with less payoff.

I'm just furious at what we've let this country become. The wars that have been fought...the lives that have been lost...the toil our Founding Fathers endured....All of that to end up like this.

Shame on us.


Read More
Posted in government regulations, politics, scary stuff, stupid security | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile