Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 19 April 2011

Learning is a choice

Posted on 13:24 by Unknown
"If your intent is to learn, you almost always do learn." - Richard Carlson

Like when we see what we want to see, we learn what we want to learn. This is important for our careers in IT and infosec but also provides a great way for us to become better people.
Read More
Posted in careers, great quotes, information security quotes, personal responsibility, security leadership, thinking long term | No comments

Coffee shop laptop thefts in Atlanta a good reminder

Posted on 04:23 by Unknown
Here's a good reason why you need to remind your employees of the risks of using laptops in coffee shops and other public places. Once the thief has it, it's all over...unless of course a brave (stupid?) coffee shop employee comes to your rescue.

A good rule of thumb is if you're setting up shop for a while then use a laptop lock to secure the system to the table. Most importantly, never, ever leave laptops unattended. I know, it does look a little goofy carrying your laptop into the john but, as in other aspects of life, substance (common sense) trumps style.
Read More
Posted in laptop encryption, laptop security, mobile security, scary stuff, stupid security, telecommuting | No comments

Monday, 18 April 2011

From each according to his ability to each according to his need

Posted on 06:42 by Unknown
I thought this Marxist/Obama philosophy was very fitting for our symbolic day today here in the U.S. The general belief that the government should decide what the people need is what's driving our country...and the world. And we wonder why we can't get out of this economic mess! The reality is that the economy cannot be taxed into prosperity but that's what the politicians want to make us believe...especially if they can play on the emotions of the non-achievers - the other 50% of income earners who pay no taxes.

Speaking of this divide, here's a good read on how if the Feds seized all of the income of the top 1% of income earners they couldn't even run the federal government for a year! How can a $980 billion tax base possibly fund a $4 trillion government budget? It can't but no one talks about that. Instead the media and its myrmidon followers just want more taxes...As with government schools, just throw more money at the problem, that'll fix it.

Folks, we don't have a taxation problem, we have a spending problem. But as Obama and the other political elite want us to believe, government is the answer to everything.

On a related note, as Art Laffer wrote today in the WSJ, there's a 30% cost markup on every dollar paid in taxes. In fact, according to his piece: "Tax compliance employs more workers than Wal-Mart, UPS, McDonald's, IBM and Citigroup combined." Amazing...Just like the data breach problem, I know without a doubt that taxation and government growth is MUCH worse - impacting so many lives in a negative way - than most people it perceive it to be.

People largely want personal security over freedom. As with many information security issues people don't want to take personal responsibility for their choices and their actions. Sadly, it's the way of the world - apparently human nature...If you fall into the achiever class you've just got to figure out how to work your way through it. As for me, I can't wait to get the next two months over with so I can stop funding the government with what I earn and start keeping my own money for my own family.
Read More
Posted in data breaches, government regulations, personal responsibility, scary stuff | No comments

Friday, 15 April 2011

Be wary of the well-certified IT pro

Posted on 09:21 by Unknown
You may have read that Gartner projects IT spending to increase in 2011. It's great news that may lead to hiring new staff or at least new consultants for your IT and information security projects....Just proceed with caution and don't fall for the "I'm certified therefore I'm all you need" persona that's rampant in our industry.

There are a lot of people out there looking for work - many of which have added one, two, perhaps five or more IT/security certifications such as CCNA and CISSP to their names over the past year. But you have to be forewarned: just because someone has passed a certification testing regimen doesn't mean he or she is going to be 1) a disciplined worker, 2) a good communicator, 3) have goals, or 4) possess that sticktuitiveness required to succeed in IT.

Certification only goes so far. In fact, I've often found that the more certifications one has the harder he or she is "trying" to prove something to mask other deficiencies (likely the very things you're in need of). Ironically, some of the sharpest and most productive people in IT and infosec have no certifications at all.

It's a harsh reality but it is what it is. Buyer beware.
Read More
Posted in careers, certifications, personal responsibility, running a business, scary stuff | No comments

Tuesday, 12 April 2011

Have no fear and be free

Posted on 10:37 by Unknown
"The whole secret of existence is to have no fear. Never fear what will become of you, depend on no one. Only the moment you reject all help are you freed." -Buddha

This is great for personal power, personal responsibility and, of course, information security - just be careful with that "reject all help" bit. ;)
Read More
Posted in careers, great quotes, information security quotes, personal responsibility, thinking long term | No comments

Friday, 1 April 2011

Web security tidbits on developers, leadership, weak passwords & more

Posted on 18:23 by Unknown
Here are a few pieces I've written recently on Web application security you may be interested in...things that affect each and every one of us working in IT and infosec:

I wouldn’t want to be a developer these days

Don’t overlook the importance of authenticated testing

You can’t change what you tolerate


Testing for weak passwords: a common oversight without a great solution

How often should you test your web applications?

Notable changes in the PCI DSS 2.0 affecting Web application security

Enjoy!

Also, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more.
Read More
Posted in automated scanner oversights, compliance, Kevin's security content, passwords, pci dss, security leadership, software development, vulnerability assessments, web application security | No comments

Time management + getting over your job title in IT

Posted on 18:12 by Unknown
Here are some IT career bits I wrote for TechTarget's SearchWinIT.com that you may be interested in:

Time management strategies for the IT pro


Your title is worthless; your value is priceless

This is the best time ever to focus on these things.

Enjoy!

Also, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more.
Read More
Posted in careers, goal setting, Kevin's security content, personal responsibility, security leadership, thinking long term, time management | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile