Let a Hundred Flowers Blossom

December 3rd, 2009 admin

I know many of us work in large, diverse organizations. The larger or more complex the organization, the more difficult it is to enforce uniform security countermeasures. The larger the population to be “secure,” the more likely exceptions will bloom. Any standard tends to devolve to the least common denominator. There are some exceptions, such as FDCC , but I do not know how…


Originally posted on TAOSecurity

 
  Related Posts
Look Beyond the Exploit
Look Beyond the Exploit
The post One Exploit Should Not Ruin Your Day by Dino Dai Zovi made me think: Finally, the larger problem is that it only took one exploit to compromise these organizations. One exploit should never ruin you day. [sic] No, that is wrong. The larger problem is not that it “only took one exploit to compromise these organizations.” I... 
Gartner on CSIRTs
Gartner on CSIRTs
I know some of you pay attention to what Gartner says, or more probably, your management does. I found this new report How to Build a Computer Security Incident Response Team by Jeffrey Wheatman, Rob McMillan, and Andrew Walls helpful if you need external validation from a source your management is likely to recognize. You need a Gartner account... 
IT Security as Easy as Mikado…
IT Security as Easy as Mikado…
I just got my hands on a new promo item our Marketing department came out with, which looks quite interesting: It’s Mikado, an old European stick game. Basically, the idea is to carefully pick up sticks without moving the pile, in order to gain points; player with the most points wins. OK, so the game is rather cute, but it is supposed to... 
Response to Dan Geer Article on APT
Response to Dan Geer Article on APT
A few people sent me a link to Dan Geer’s article Advanced Persistent Threat . Dan is one of my Three Wise Men, along with Ross Anderson and Gene Spafford. I’ll reproduce a few excerpts and respond. Let us define the term for the purpose of this article as follows: A targeted effort to obtain or change information by means that are... 
Review of Virtualization and Forensics Posted
Review of Virtualization and Forensics Posted
Amazon.com just published my three star review of Virtualization and Forensics by Dianne Barrett and Gregory Kipper. From the review : “Virtualization and Forensics” (VAF) offers “a digital forensic investigator’s guide to virtual environments” as its subtitle. Eric Cole’s introduction says “How do we... 
Ponemon Institute Misses the Mark
Ponemon Institute Misses the Mark
Today the Ponemon Institute announced results of a survey they conducted titled Growing Risk of Advanced Threats: Study of IT Practitioners in the United States . Unfortunately, this survey looks like it is mainly the blind asking the blind to describe a threat neither really understands. For example, the survey states: While the definition of... 
Thank you, Mr. Prime Minister
Thank you, Mr. Prime Minister
Matti Vanhanen, the Prime Minister of Finland, was recently in Kuala Lumpur, Malaysia for a two day visit. During his time here, we were absolutely honored that he made time in his busy schedule to pay us a visit at F-Secure Kuala Lumpur. F-Secure Tower: We first had lunch, followed by a short tour to the Security Lab and the Development department.... 
Review of At Large Posted
Review of At Large Posted
Amazon.com just posted my four star review of At Large by David H. Freedman and Charles C. Mann. From the review : “At Large” is a “hacking” book published during the mid-1990s, but it doesn’t address the characters usually considered to be the “stars” of that era. Rather, At Large tells the tale of a... 
Imam Arrested Trying To Smuggle Razors and Scissors Into Jail
An imam with the city Department of Correction was busted trying to smuggle razors and a pair of scissors into the Tombs on Wednesday morning, sources said. Zul-Qarnain Shahid, 58, had his briefcase scanned at about 9 a.m. after reporting to work at the Manhattan Detention Complex, sources said. “He put his briefcase through the X-ray machine,”... 
Questions and Answers on the jailbreakme vulnerability
Q: What is this all about? A: It’s about a site called jailbreakme.com that enables you to Jailbreak your iPhones and iPads just by visiting the site. Q: So what’s the problem? A: The problem is that the site uses a zero-day vulnerability to execute code on the device. Q: How does the vulnerability work? A: Actually, it’s two vulnerabilities.... 
  Related Tweets from Twitter
mp_mccabe (Michael McCabe)  : RT @MHComputing: Review of IT #Security Metrics: A Practical Framework for Measuring Security & Protecting #Data http://ow.ly/2zaUU..
Updated : 2010-09-03T21:27:16Z   |  Reply  |  View Tweet
ddpbsd (dan)  : #FF @xme @gattaca @hevnsnt @indi303 @jack_daniel @lizborden @taosecurity all smart and entertaining...
Updated : 2010-09-03T21:05:24Z   |  Reply  |  View Tweet
4v4t4r (4v4t4r)  : #InfoSec #FF 5 @exploitdb @PenTesterScript @crackinglandia @kfs @CoreSecurity @taosecurity @thomas_wilhelm @ethicalhacker @_Laz3r_..
Updated : 2010-09-03T20:04:05Z   |  Reply  |  View Tweet
aircrackng (Thomas d'Otreppe)  : RT @joswr1ght: TaoSecurity: Review of Hacking Exposed: Wireless, 2nd Ed Posted http://t.co/aicbN1F via @taosecurity (Awesome!)..
Updated : 2010-09-03T19:44:59Z   |  Reply  |  View Tweet
karlarss (Karla Rosas)  : RT @barucomx: RT @taosecurity: 10 easy ways to fail a Ph.D. http://bit.ly/aQOHCr I like the focus on research, (cont) http://tl.gd/3feb98..
Updated : 2010-09-03T18:13:22Z   |  Reply  |  View Tweet
  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP