Let a Hundred Flowers Blossom
December 3rd, 2009 admin

I know many of us work in large, diverse organizations. The larger or more complex the organization, the more difficult it is to enforce uniform security countermeasures. The larger the population to be “secure,” the more likely exceptions will bloom. Any standard tends to devolve to the least common denominator. There are some exceptions, such as FDCC , but I do not know how…
Related Posts
The post One Exploit Should Not Ruin Your Day by Dino Dai Zovi made me think: Finally, the larger problem is that it only took one exploit to compromise these organizations. One exploit should never ruin you day. [sic] No, that is wrong. The larger problem is not that it “only took one exploit to compromise these organizations.” I...
I know some of you pay attention to what Gartner says, or more probably, your management does. I found this new report How to Build a Computer Security Incident Response Team by Jeffrey Wheatman, Rob McMillan, and Andrew Walls helpful if you need external validation from a source your management is likely to recognize. You need a Gartner account...
I just got my hands on a new promo item our Marketing department came out with, which looks quite interesting: It’s Mikado, an old European stick game. Basically, the idea is to carefully pick up sticks without moving the pile, in order to gain points; player with the most points wins. OK, so the game is rather cute, but it is supposed to...
A few people sent me a link to Dan Geer’s article Advanced Persistent Threat . Dan is one of my Three Wise Men, along with Ross Anderson and Gene Spafford. I’ll reproduce a few excerpts and respond. Let us define the term for the purpose of this article as follows: A targeted effort to obtain or change information by means that are...
Amazon.com just published my three star review of Virtualization and Forensics by Dianne Barrett and Gregory Kipper. From the review : “Virtualization and Forensics” (VAF) offers “a digital forensic investigator’s guide to virtual environments” as its subtitle. Eric Cole’s introduction says “How do we...
Today the Ponemon Institute announced results of a survey they conducted titled Growing Risk of Advanced Threats: Study of IT Practitioners in the United States . Unfortunately, this survey looks like it is mainly the blind asking the blind to describe a threat neither really understands. For example, the survey states: While the definition of...
Matti Vanhanen, the Prime Minister of Finland, was recently in Kuala Lumpur, Malaysia for a two day visit. During his time here, we were absolutely honored that he made time in his busy schedule to pay us a visit at F-Secure Kuala Lumpur. F-Secure Tower: We first had lunch, followed by a short tour to the Security Lab and the Development department....
Amazon.com just posted my four star review of At Large by David H. Freedman and Charles C. Mann. From the review : “At Large” is a “hacking” book published during the mid-1990s, but it doesn’t address the characters usually considered to be the “stars” of that era. Rather, At Large tells the tale of a...
An imam with the city Department of Correction was busted trying to smuggle razors and a pair of scissors into the Tombs on Wednesday morning, sources said. Zul-Qarnain Shahid, 58, had his briefcase scanned at about 9 a.m. after reporting to work at the Manhattan Detention Complex, sources said. “He put his briefcase through the X-ray machine,”...
Q: What is this all about? A: It’s about a site called jailbreakme.com that enables you to Jailbreak your iPhones and iPads just by visiting the site. Q: So what’s the problem? A: The problem is that the site uses a zero-day vulnerability to execute code on the device. Q: How does the vulnerability work? A: Actually, it’s two vulnerabilities....
Related Tweets from Twitter
|
mp_mccabe (Michael McCabe) : RT @MHComputing: Review of IT #Security Metrics: A Practical Framework for Measuring Security & Protecting #Data http://ow.ly/2zaUU.. Updated : 2010-09-03T21:27:16Z | Reply | View Tweet |
|
ddpbsd (dan) : #FF @xme @gattaca @hevnsnt @indi303 @jack_daniel @lizborden @taosecurity all smart and entertaining... Updated : 2010-09-03T21:05:24Z | Reply | View Tweet |
|
4v4t4r (4v4t4r) : #InfoSec #FF 5 @exploitdb @PenTesterScript @crackinglandia @kfs @CoreSecurity @taosecurity @thomas_wilhelm @ethicalhacker @_Laz3r_.. Updated : 2010-09-03T20:04:05Z | Reply | View Tweet |
|
aircrackng (Thomas d'Otreppe) : RT @joswr1ght: TaoSecurity: Review of Hacking Exposed: Wireless, 2nd Ed Posted http://t.co/aicbN1F via @taosecurity (Awesome!).. Updated : 2010-09-03T19:44:59Z | Reply | View Tweet |
|
karlarss (Karla Rosas) : RT @barucomx: RT @taosecurity: 10 easy ways to fail a Ph.D. http://bit.ly/aQOHCr I like the focus on research, (cont) http://tl.gd/3feb98.. Updated : 2010-09-03T18:13:22Z | Reply | View Tweet |
Related News from Digg
Leave a comment
| Trackback
























