Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 27 April 2011

Novell, Utah and the Libertarian Party

Posted on 12:36 by Unknown
Some new news out today was about Novell completing its sale to Attachmate. Wow, the end of an era...

Novell really does have a special place in my heart - NetWare was the first network operating system I learned, way back in the version 2.15c days. Anyone remember those? Then I moved on to v2.2, 3.12, 4.0 and then 4.1. I obtained my first IT certification - the CNE - that was all about NetWare. I even wrote/sold my own patch management application for NetWare before patch management was cool.

Another great thing about Novell was their BrainShare conference. I see that they've moved it from March to October; glad I got my skiing in when I did! Going to BrainShare every year I not only got to know NetWare like the back of my hand but I also discovered the beauty of Utah - in particular its microbreweries and its snow skiing. Absolutely lovely.

To my final point, I was having lunch with a close friend recently who shared my Novell bigotry back in the day and shares my love for limited government right now. We were talking politics and about how the Tea Party mindset consists of regular guys like him and me who are fed up with Republican and Democrat politicians alike so keenly focused on government expansion and intrusion into our lives. I told him the Tea Party mantra used to be called the Libertarian Party. The Tea Party, like Microsoft, rose out of nowhere and grabbed all the attention. I told my friend how sad it is that the Libertarian Party, like Novell, has consistently failed to market itself as a viable option and, thus, we are where we are today. Just damn.

Novell, Libertarian Party or whatever - lots of excellent products and great ideas are/were out there for the taking. Logic sales but who's buying...?
Read More
Posted in government intrusion, marketing hype, Novell, politics, scary stuff, stupid security, thinking long term | No comments

Tuesday, 26 April 2011

What's this "firewall" you speak of??

Posted on 11:56 by Unknown
It seems that #firewalls are making a comeback. Of course, I felt compelled to throw in my two cents worth so here are some new pieces I wrote for the fine folks at SearchNetworking.com on firewalls and firewall management:

Firewall change management and automation can curb human error

Do Web application firewalls complicate enterprise security strategy?

Planning a virtualization firewall strategy

Enjoy!

As always, be sure to check out www.principlelogic.com/resources.html for links to all of my information security books, articles, whitepapers, podcasts, webcasts and more.
Read More
Posted in application firewalls, compliance, firewalls, Kevin's security content, network security, pci dss | No comments

Monday, 25 April 2011

The positive side of infosec

Posted on 05:17 by Unknown
"Have you ever, even once, stopped to marvel at just how often things go right? It's amazing." -Richard Carlson

With all of the smack talk and negative approaches so many of us (myself included) take regarding IT and information security, this'll make you realize that it's not all bad. I we could all benefit from stopping to smell the roses and seeing the bright side of our field every now and then.
Read More
Posted in great quotes, information security quotes, security leadership, thinking long term | No comments

Sunday, 24 April 2011

Tidbits on enterprise mobile security

Posted on 17:06 by Unknown
Here are some recent pieces I wrote for SearchEnterpriseDesktop.com on the subject of mobile security that you may be interested in:

Securing the new desktop: enterprise mobile devices

Security tools that can boost Windows Mobile and Windows Phone 7 security


Whole disk encryption gotchas to look out for


Enjoy!

As always, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, whitepapers, podcasts, webcasts and more.
Read More
Posted in desktop management, drive encryption, Kevin's security content, laptop encryption, mobile security, smartphone security, Windows Mobile | No comments

Thursday, 21 April 2011

Amazon's cloud outage - does it change your perception of the cloud?

Posted on 14:12 by Unknown
Everyone (okay, many; especially the vendor marketing types) keeps swearing by the "cloud"...and then Amazon's EC2 goes down today. How does that affect how you view the cloud?

I've been a skeptic and I'm still a skeptic...beware the cloud bandwagon.
Read More
Posted in cloud computing, disaster recovery, incident response, stupid security, thinking long term | No comments

Wednesday, 20 April 2011

Holy Cow: Police seizing info from phones during traffic stops

Posted on 08:11 by Unknown
Here's some big time scary stuff personally and something that'll no doubt lead to big time security problems for the enterprise. Michigan State Police are copying data off of smartphones during minor traffic stops using the Cellebrite Universal Forensics Extraction Device. Images, address books, files, whatever...it's now fair game for the police (Gestapo?) in Michigan to take whatever whenever.

Is this government out of control or what!?

I know we've all but forgotten about the Constitution in this country but if this happens to me, I guarantee you they'd get nothing - I mean nothing - without probable cause and a warrant.

Yet another reason to force users to put passwords on their smartphones....Oh, and a control that wipes the phone after X number of failed password attempts.

Wow, crazy stuff...what's going to be next?
Read More
Posted in government intrusion, government regulations, scary stuff, smartphone security, stupid security | No comments

Legalese in email footers is useless

Posted on 05:23 by Unknown
Ever get annoyed by those email footers telling you what you can or cannot do with the email you just received? Yeah, me too. Here's an interesting bit from Consumer Reports that talks about how those legal disclaimers in email footers may be legally useless.

It's funny, every time I see them (they're in about 60-70% of the non-spam emails I recieve) I think it's yet another representation of the American way to disclaim any personal responsibility. If anything goes awry when sending an email, it's someone else's fault.

Furthermore, as Consumer Reports mentions at the end of the article, the run-on sentences end up using more ink and paper when emails are printed...wonder what the "global warming" crowd thinks of that? Now there's an opportunity for the the anti-capitalism movement that I might consider buying in to.

Anyway, however you see this issue, be sure to speak with your legal counsel first before making any rash decisions (like reconfiguring Exchange to drop these email footers once and for all). ;-)
Read More
Posted in compliance, global warming, legal, personal responsibility, stupid security | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile