Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Safe Plug
This is a fun piece of simple technology to save power and increase safety of electrical outlets.It uses small little slip on RFID tags on the plugs themselves and are plugged in to the “safe plug” outlets. Plugs cannot work otherwise and can potentially be remotely monitored or even controlled. These could be used to save energy, monitor individual and specific devices, prevent fires, etc. Think of all the meetinghouses that could be rescued from power siphoning and potential fire hazards. The gentleman who invented this was a featured speaker on TED.
Malware Primer
Lifehacker has a pretty good description of the different flavors of malware (viruses, trojan horses, spyware, scareware, and worms), although they leave out phishing attacks and probably a bunch of others you security folks could point us to.
AT&T iOops
Up to 114,000 iPad users (including Michael Bloomberg and Diane Sawyer) unwittingly exposed their email addresses to the public through a security gaffe. Apple products have never been recognized as the CISO's products of choice, but this one looks to be primarily AT&T's goof. Read about it here.
AT&T responds.
AT&T responds.
Data Extortion
Recently somebody hacked into a web site operated by the State of Virginia, deleted the records of over 8 million people and left a note on the homepage, demanding $10M to restore the data.
We're talking about 0's and 1's here.
It's not the first time hackers have used data for extortion. Typically they threaten to release potentially damaging data, whereas this time it's closer to kidnapping where they're offering to return the data for a price.
This event underscores the importance of regular backups and disaster recovery. Granted, the brutes should never have had the opportunity to get into the web site in the first place, but a secure perimeter won't solve the problem if it's an inside job. Appropriate seperation of duties and regular testing of data (and system) restoration is critical for peace of mind when it comes to making sure your data is safely guarded.
Luckily, the state of Virginia apparently had appropriate backup and restoration precedures in place.
Do you?
We're talking about 0's and 1's here.
It's not the first time hackers have used data for extortion. Typically they threaten to release potentially damaging data, whereas this time it's closer to kidnapping where they're offering to return the data for a price.
This event underscores the importance of regular backups and disaster recovery. Granted, the brutes should never have had the opportunity to get into the web site in the first place, but a secure perimeter won't solve the problem if it's an inside job. Appropriate seperation of duties and regular testing of data (and system) restoration is critical for peace of mind when it comes to making sure your data is safely guarded.
Luckily, the state of Virginia apparently had appropriate backup and restoration precedures in place.
Do you?
Risk Magic
Last week at the Research Board, I had the pleasure of sitting down to talk with Peter Tippett, a security guru who bucks common risk management wisdom and has made an enemy of many security folks who find his focus on being "practical" naive. He was both delightfully insightful and hilarious.
He offered many tidbits of wisdom.
For example, he talked about endpoint protection. Security best practices dictate that laptops, particularly ones carried by executives or other folks who might be carrying sensitive data, be encrypted with heavy duty encryption stuff. Tippett argues that this practice is silly.
In order for something bad to happen, ALL of the following must be true:
What is the likelihood that even the first three of these things might happen, let alone the last two?
A good security professional will know the potential attacks and best defenses. An excellent security professional will temper the desire to "continually batten down the hatches" by considering the probability of successful attacks and planning accordingly.
Peter was refreshing and fun.
He offered many tidbits of wisdom.
For example, he talked about endpoint protection. Security best practices dictate that laptops, particularly ones carried by executives or other folks who might be carrying sensitive data, be encrypted with heavy duty encryption stuff. Tippett argues that this practice is silly.
In order for something bad to happen, ALL of the following must be true:
- The individual must lose (by negligence or through theft) a laptop
- The laptop must have information on it that could actually be used in some harmful way
- The person who acquires the laptop (through whatever means) must desire to get data off of the laptop and not just sell the laptop for drug money, which is probably much more often the case.
- The bad guy must have the ability to get through the basic security protection on the laptop
- The bad guy then must have the ability to use that information in some hurtful way
What is the likelihood that even the first three of these things might happen, let alone the last two?
A good security professional will know the potential attacks and best defenses. An excellent security professional will temper the desire to "continually batten down the hatches" by considering the probability of successful attacks and planning accordingly.
Peter was refreshing and fun.
Subscribe to:
Posts (Atom)