Category

Archive for the 'Rants' Category

Piracy as a Crimeware Defense

( Rants )

So, just a quick thought on this one. What if we, as security folks, made a serious endeavor to reduce the earning capability of those who create crimeware, spyware and other malware? What if we did to them exactly what the gaming companies and MPAA have been saying is killing their business? What if every [...]

Twitter Annoys Me #marketing #security

( Rants )

I just deleted 172 twitter users who I was following but for varied reasons, were not following me back. Here is the irony: 90% of them followed me first. I have initiated “the follow” with only a handful of people. Most of the people on my follow list happened because they followed me first and [...]

Microsoft IIS 6.0 WebDav Vulnerability – Urgent

We recently received a report of a vulnerability we thought everyone should be aware of. The vulnerability is in the Microsoft IIS 6.0 implementation of the WebDAV protocol. According to Wikipedia, “Web-based Distributed Authoring and Versioning, or WebDAV, is a set of extensions to the Hypertext Transfer Protocol (HTTP) that allows users to edit and [...]

So, You Wanna Be in InfoSec?

One of the most common questions I get asked is “How can I become an information security professional?”. These days, it seems that a ton more people want to be in the “business” of information security. I get the question so often, I thought I would write this post as a quick and easy way [...]

The Economics of Insecurity

Wanna be bad at information security? Can you afford it? Various sources, metrics and industry studies put a variety of numbers to data loss, but the general range is around $200-$250 per compromised customer/client/credit card, etc. How many pieces of identity data does you company protect? How many clients do you have? How many employees [...]

Major Breach at Heartland Payment Systems

You’ve heard this story before. A major credit card company has experienced a massive breach. Tons and tons of data was stolen during the incident. They think they have it under control and are working with law enforcement. You should check your statements. Blah, blah, blah… Once again, though, in this case, the company was [...]

Win7, Linux and the Future of the Desktop OS

First of all, I think one of the major reasons that Windows 7 will not “kill Linux on the Desktop” is cost. Quite honestly, unless they are going to make Windows 7 free, it might be popular enough to stall the spread of Linux on desktops in the developed world, but the rest of the [...]

Giving for the Holidays

Now is the time when many folks open their hearts and their wallets to help others. At MSI, I am proud to say that we do this all year. This year alone we have worked on gathering and donating old cell phones for the Central Ohio Choices program, made donations to the One Laptop Per [...]

Hackers Hate HoneyPoint

We have been getting so much great feedback and positive response to our HoneyPoint products that Mary Rose, our marketing person, crafted this logo and is putting together a small campaign based on the idea. We are continuing to work on new capabilities and uses for HoneyPoint. We have several new tricks up our sleeve [...]

RE: SANS Are We Doomed?

This kind of stuff is, in my opinion, exactly why management and consumers grow sick of hearing about information security and cyber-risk in general. For years now, security folks have been shouting to high heaven about the end of the world, cyber-terrorism, the cyber-jihad and all of the other creative phrasings for increased levels of [...]