Android fingerprint security not so secure
Since the introduction of Apple’s Touch ID, I’ve warned readers and clients about the complacency possible with fingerprint recognition on smartphones. At Black Hat USA next month, two different...
View ArticleThey have the tools, just not the will…
As the number of government records stolen increases, we continue asking why so much data was stolen over the past year without detection. The answer seems to lie in an article by Michael Cooney. It...
View ArticleAnother Encryption Perspective
Hacking Team solutions aren’t the only ways government has to access encrypted information. Most large government agencies have their own tools that perform the same tasks: capturing encrypted data...
View ArticleIs Encryption a Right?
With governments beginning to make noise again about weakening encryption, several security professionals have come out against any moves to do this. But does government have the right to take away...
View ArticleShadow IT: Treat the cause, not the symptom
I just posted an article at Toolbox.com about the business risks associated with shadow IT. Many organizations see shadow IT as a disease to be cured. However, as I write in my post, shadow IT is a...
View ArticlePatchwork Security Regulations: Politics as usual
In an article for SearchSecurity, Mike Chapple writes about the potential for states to begin passing their own information security laws. I agree with him that a patchwork of local and state laws...
View ArticleWi-Fi Sense Creates New User-dependent Security Issue
For those who haven’t seen it yet, Windows 10 includes a feature, WiFi Sense, that allows a user’s friends to share WiFi access with others. For example, Bob might allow Alice to access his access...
View ArticleCryptoWall continues to spread
CryptoWall, an instance of ransomware, is a growing threat. Attackers use it to hold an organization’s resources hostage until they get something of value. This costs Americans millions… and it’s...
View ArticleIs email safer than a password?
According to a Register article, Small change to Medium takes large axe to passwords, Medium is providing an option to use email to login instead of passwords. I registered at Medium to check it out...
View ArticleCybercrime’s 5 Most Wanted
The FBI has a most wanted list for cybercriminals. Meet the enemy…Filed under: Uncategorized
View ArticleAndroid malware not yet a real problem, but…
Malware targeting Android devices is growing, likely hitting 2 million instances by the end of 2015 according to the Verizon 2015 Data Breach Investigations Report. And while the number of devices...
View ArticleUnderwriters Lab (UL) ahead for security solutions
Peiter Zatko had left Google to respond to a request by the Whitehouse that he develop a cyber UL, a concept described in a paper published in 1999 by Tan from the L0pht. The paper reads in part “Just...
View ArticleCisco and OpenDNS: Nothing changes for current users
As a user of OpenDNS for several years, I’ve been very satisfied with the protection provided to my systems. Cisco obviously sees the value of OpenDNS, since they have decided to acquire the company....
View ArticleLaptop encryption under attack
In a recent post by Bruce Schneier, he quotes a paper and Wired article in which researchers claim to be able to capture decryption keys. The capture uses a device, buildable for about $300, that can...
View ArticleManage Stale Accounts
It’s always a good idea to scan Active Directory accounts for unused or anomalous user accounts. The SANS Internet Storm Center provides one way with PowerShell. Stale account management is an...
View ArticleAnother government “Oops!”
The OPM breach is just one more instance of a government bureaucrat standing in way of risk mitigation. Congress is getting this one right by asking for the resignations of those responsible....
View ArticleAre we becoming numb to breaches?
Norm Laudermilch writes in an interesting article that people might be anesthetized to news reports about data breaches. Bad situation. See Anesthetized by Data Breaches.Filed under: Uncategorized
View ArticleAdobe Flash? Who really needs it…?
Brian Krebs turned off Flash for a month to see what would happen. Turns out, not much. Flash isn’t all that important for most people to experience an enjoyable, productive Web experience. See...
View ArticleMIT Report Troubling
In a recent report (MIT Report: U.S. Manufacturing Hits a Wall When It’s Time to Scale), Curt Woodward writes that a group of MIT researchers discovered an almost impassable chasm when looking for...
View ArticleThe death of text CAPTCHA? I hope so…
In a Yahoo article posted yesterday (Internet advertisers kill text-based CAPTCHA – Yahoo! News), Mike Wehner writes about possible changes to text CAPTCHA hell. Yes, I said hell. I am nearing my...
View Article