Tech Support For Dummies

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 31 January 2011

The Egyptian uprising tie-in with the U.S. Internet kill switch

Posted on 07:12 by Unknown
The people rioting in Egypt against their oppressive government and the subsequent blocking of the Internet is an interesting issue that has a global reach. Foreign policy aside, have you stopped to think about the ramifications of the cybersecurity "kill switch" bills that our measly politicians are trying to force upon us?

As I wrote previously, the proposed Rockefeller-Snowe Cybersecurity Act of 2009 (Senate Bill 773) and Lieberman-Collins-Carper Protecting Cyberspace as a National Asset Act of 2010 (Senate Bill 3480) provide undeterred powers to the government to effectively shutdown our economy as we know it. Would the president use this power during a cyberattack? Presumably. Would the president use it during an uprising like what's going on in Egypt? It wouldn't surprise me.

But, you say, all of this is happening in Egypt...this is America - we'd never reach that point! That's a shortsighted and dangerous mindset. Just look at all the nonsense the Social Democrat Party have shoved on us the in the past two years alone...evidence enough to rational people that anything's possible with a runaway government. Our government "leaders" don't want to be questioned, they don't want to explain their actions and they certainly don't like it when people speak out against them. [The whole free speech thing cracks me up when you think about what the old-school liberals of the 1960s demanded, but that's another story.]

As Senator Susan Collins recently said "unlike in Egypt, where the government was using its powers to quell dissent by shutting down the internet, it would not." Oh, okay, we understand and believe you Senator Collins. The government has never put legislation in place for one purpose and ended up abusing it for other means down the road. We're good. Here are some more details on this recent news:
As Egypt goes offline US gets internet 'kill switch' bill ready (the graph showing Internet traffic to and from Egypt last week is really interesting)

...according to Wired Magazine, it looks like the Lieberman-Collins-Carper cybersecurity bill is set to be reintroduced into a Senate committee any day now.

So, it's scary to many what the Egyptian government did/is doing to it's people and the U.S. is now wanting to put the same draconian powers in place? But you know it'll be different here...like Socialism. It's failed elsewhere for centuries, but big, strong America can make it work for the greater good of the people.

Folks: good, bad or ugly, our politicians are going to get their way. Way too many voters are concerned about what's happening on Facebook, NCAA basketball and American Idol for us to be able to truly hold these people's feet to the fire.

What can you do...? Interesting times indeed.
Read More
Posted in compliance, government intrusion, government regulations, personal responsibility, scary stuff, stupid security, thinking long term | No comments

It's hard being human

Posted on 05:38 by Unknown
Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and leadership. He said:

"Character is the ability to carry out a good resolution long after the excitement of the moment has passed."

When I saw this I was reminded of how pumped you can get when attending a show like RSA or CSI or how neat certain vendor marketing spiels sound. Another is when an information security consultant or internal auditor produces a report that kindles the fire inside so you resolve that you're going to make things right this time around...but then the newness and the excitement wear off. We get busy and fall back into our old ways and like I wrote about we lose sight of what's important. The cycle continues.
Read More
Posted in careers, great quotes, information security quotes, security leadership, security management, stupid security | No comments

Friday, 28 January 2011

Take patch management out of IT's hands completely?

Posted on 05:37 by Unknown
Here's a piece by CNET's Stephen Shankland on continuously updating software and patch management. Not sure where things will end up (we're already halfway there with this technology) but it's something that certainly couldn't hurt security.
Read More
Posted in patch management, patching, security management | No comments

Monday, 24 January 2011

Web application security testing: how much is enough?

Posted on 17:24 by Unknown
How often should you test your Web sites and apps for #security flaws? Well, it depends of course! Here's a new bit I wrote where I delve into the different variables and things you need to be thinking about:

How often should you test your web applications?

Enjoy.
Read More
Posted in ethical hacking, Kevin's security content, penetration testing, security policies, web application security | No comments

My book Hacking For Dummies is now in 3 languages

Posted on 03:30 by Unknown
I was just told by my acquisitions editor at Wiley that my book Hacking For Dummies is being made available as an Italian language publication.



English, Estonian (I know, who would've thought!?) and now Italian...cool.
Read More
Posted in ethical hacking, Kevin's books, Kevin's security content, recommended books | No comments

Sunday, 23 January 2011

Cybersecurity schmybersecurity

Posted on 11:10 by Unknown
Here are a couple of #cybersecurity pieces I authored for TechTarget's SearchCompliance.com regarding the proposed Rockefeller-Snowe Cybersecurity Act of 2009 (Senate Bill 773) and Lieberman-Collins-Carper Protecting Cyberspace as a National Asset Act of 2010 (Senate Bill 3480):

Why the Cybersecurity Act is better for government than business

Is the latest cybersecurity bill an Internet takeover by the fed?

You know how I am about government growth and its intrusion into the free market. By and large that's what both of these pieces of legislation represent. As with so many other federal government regulations I strongly believe that it'd serve to cause more problems than it fixes.

But who am I to question...the politicians know best, right?
Read More
Posted in compliance, government intrusion, government regulations, Kevin's security content, scary stuff, security leadership, stupid security | No comments

Thursday, 20 January 2011

Skill to do comes of doing

Posted on 02:16 by Unknown
Ralph Waldo Emerson once made this statement which completely and totally applies to what you do in your job and how you develop your career over the long haul:
"Skill to do comes of doing."

As with surgeons, home builders, mechanics, race car drivers and so on...we learn most by doing.

I know a lot of people are going back to school and focusing on getting their degrees and certifications right now. There's certainly value in doing so. Just never ever forget that formal training and education are only a relatively small part of the overall package that you bring to the table. So get out there and get your hands dirty because there's no replacing good old-fashioned hands-on experience!

If you're interested in hearing a lot more of my take on certifications, degrees, and experience and the best way to approach each of them to enhance your career, check out this Security On Wheels audio program I put together. Here's a snippet you can download and listen to.
Read More
Posted in audio programs, careers, certifications, great quotes, information security quotes | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Reaver Pro: a simple tool for cracking WPA on a LOT of wireless networks
    If wireless security testing is on your radar, you need to get Reaver Pro . As I outlined in this Hacking For Dummies, 4th edition chapter ,...
  • Low information users and the challenges they create
    Thanks to the political elite and the dumb masses they inspire, you've probably heard the term low information voter …In a nutshell, thi...
  • "Top Blogs" list & some home security considerations
    I think I may have found the first sign that my blog is growing and gaining some traction. I've made it to the Top 20 Home Security Blog...
  • Wooo...HIPAA audits are coming & the irony of KPMG's involvement
    I've always believed that compliance is a threat to business [hence why I help businesses take the pain out of compliance by addressing ...
  • Windows 8.1 changes/enhancements, BitLocker's improvements, and related Windows mobile/security tips
    In addition to my independent information security assessments through my consultancy Principle Logic , I've been writing a ton...includ...
  • What you need to know about security vulnerability assessments (that no one is willing to share)
    I'd love it if you'd join me over at SearchSecurity.com next week where I'll be talking about the rest of the story regarding ...
  • Sprechen Sie Deutsch? Hacking For Dummies now in German!
    Check out the latest foreign-language edition of my book Hacking For Dummies: Hacking For Dummies is now in 6 languages: English, Estonian, ...
  • It's hard being human
    Cavett Robert once said something about character that resonates within information security - especially regarding ongoing management and l...
  • Experiencing problems with authenticated web vulnerability scans? Try NTOSpider.
    You're performing authenticated web vulnerability scans , right? If you're not, you're missing out...big time. When performing a...
  • The compliance crutch mentality rides on
    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for complianc...

Categories

  • active directory
  • application firewalls
  • APTs
  • aslr
  • atm security
  • audio programs
  • audit logging
  • automated scanner oversights
  • back to basics
  • backups
  • big brother
  • bitlocker
  • budget
  • business case for security
  • business continuity
  • BYOD
  • car hacking
  • careers
  • certifications
  • change management
  • checklist audits
  • cissp
  • clear wireless
  • cloud computing
  • communication
  • compliance
  • computer glitch
  • conferences
  • consulting
  • content filtering
  • cool products
  • cool sites
  • cross-site request forgery
  • cross-site scripting
  • csrf
  • customer no service
  • cybersecurity bill
  • data at rest
  • data breach laws
  • data breaches
  • data centers
  • data destruction
  • data leakage
  • data protection
  • data retention
  • database security
  • degrees
  • desktop management
  • disaster recovery
  • disk imaging
  • disposal
  • dns
  • document security
  • domino
  • DoS attacks
  • drive encryption
  • e-discovery
  • ediscovery
  • employee monitoring
  • encrypting data in transit
  • encryption
  • end point security
  • ethical hacking
  • exchange
  • experience
  • expert witness
  • exploits
  • facebook
  • FERPA
  • file integrity monitoring
  • firewalls
  • forensics
  • full disk encryption
  • global warming
  • goal setting
  • good blogs
  • government intrusion
  • government regulations
  • great quotes
  • hacking
  • hardware
  • hipaa
  • hitech
  • hitech act
  • home security
  • humor
  • identity access management
  • identity theft
  • IIS
  • incident response
  • information classification
  • information security quotes
  • intel
  • intellectual property
  • internal threat
  • java
  • Kevin's books
  • Kevin's interviews
  • Kevin's keynotes
  • kevin's panels
  • kevin's quotes
  • Kevin's security content
  • Kevin's seminars
  • Kevin's videos
  • laptop encryption
  • laptop security
  • legal
  • Linux
  • locking screens
  • low-hanging fruit
  • malware
  • marketing hype
  • message from Kevin
  • messaging security
  • metasploit
  • metrics
  • mobile apps
  • mobile security
  • motivation
  • multi-factor authentication
  • network analysis
  • network complexities
  • network protocols
  • network security
  • networking essentials
  • Novell
  • office
  • online backup
  • online safety
  • open source security
  • owasp
  • p2p
  • passwords
  • patch management
  • patching
  • pci 6.6
  • pci dss
  • PCNAA
  • penetration testing
  • people problems
  • personal responsibility
  • phishing
  • physical security
  • pii
  • podcasts
  • policy enforcement
  • politics
  • presentations
  • privacy
  • quality assurance
  • recommended books
  • recommended magazines
  • recycling
  • remote access security
  • ridiculous password requirements
  • risk analysis
  • risk management
  • rogue insiders
  • ROI
  • RSA 2012
  • running a business
  • saas
  • salary
  • scary stuff
  • sccm
  • sdlc
  • security assessments
  • security audits
  • security awareness
  • security committees
  • security leadership
  • security management
  • security operations
  • security policies
  • security policy
  • security scans
  • security standards
  • security statistics
  • security technologies
  • security testing tools
  • security tools
  • selling security
  • sharepoint
  • small business
  • smartphone security
  • SMBs
  • social media
  • software development
  • source code
  • source code analysis
  • special offer
  • SQL injection
  • sql server
  • ssl
  • storage security
  • student information systems
  • stupid security
  • success
  • telecommuting
  • testimonials
  • thinking long term
  • third-party applications
  • threat modeling
  • time management
  • training
  • twitter
  • uncool products
  • unstructured information
  • unstructured infromation
  • user awareness
  • vendors
  • virtual machine security
  • visibility
  • voip
  • vulnerability assessments
  • web 2.0
  • web application security
  • web browser security
  • web server security
  • webcasts
  • WebInspect
  • whitelisting
  • whitepapers
  • Windows
  • Windows 7
  • windows 8
  • windows 8.1
  • Windows Mobile
  • windows security
  • Windows Vista
  • wireless
  • wireless security
  • zero tolerance

Blog Archive

  • ▼  2013 (35)
    • ▼  November (3)
      • Reaver Pro: a simple tool for cracking WPA on a LO...
      • Low information users and the challenges they create
      • My latest security content (lots of stuff on appli...
    • ►  October (3)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (1)
    • ►  May (4)
    • ►  April (4)
    • ►  March (4)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (77)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (3)
    • ►  July (4)
    • ►  June (5)
    • ►  May (9)
    • ►  April (5)
    • ►  March (10)
    • ►  February (14)
    • ►  January (16)
  • ►  2011 (163)
    • ►  December (15)
    • ►  November (11)
    • ►  October (9)
    • ►  September (16)
    • ►  August (13)
    • ►  July (8)
    • ►  June (13)
    • ►  May (18)
    • ►  April (16)
    • ►  March (13)
    • ►  February (13)
    • ►  January (18)
  • ►  2010 (170)
    • ►  December (10)
    • ►  November (14)
    • ►  October (7)
    • ►  September (27)
    • ►  August (20)
    • ►  July (8)
    • ►  June (15)
    • ►  May (4)
    • ►  April (23)
    • ►  March (21)
    • ►  February (11)
    • ►  January (10)
  • ►  2009 (55)
    • ►  December (5)
    • ►  November (10)
    • ►  October (21)
    • ►  September (19)
Powered by Blogger.

About Me

Unknown
View my complete profile