As a consultant, one of the biggest security problems I see is perception: The threats companies think they face are often vastly different than the threats that pose the greatest risk. For example, they hire me to deploy state-of-the-art public key infrastructure (PKI) or an enterprise-wide intrusion detection system when really what they need is […]
As a consultant, one the security biggest problems I see is perception: The threats companies think they face are often vastly different than the threats that pose the greatest risk. For example, they hire me to deploy state-of-the-art public key infrastructure (PKI) or an enterprise-wide intrusion detection system when really what they need is better […]
A jump box is a secure computer that all admins first connect to before launching any administrative task or use as an origination point to connect to other servers or untrusted environments. Over the last few years, with malicious hackers and malware infesting nearly every enterprise network at will, security admins have been looking for […]
For the past two years, I’ve been busy helping Public Key Infrastructure (PKI) customers prepare for and move to SHA-2, the set of cryptographic hash functions that have succeeded SHA-1. Last year, moving to SHA-2 ahead of the global deadline was a nice-to-do preparatory step. This year, now that the migration deadline has passed, it’s required.Many digital-certificate-consuming […]
At last count, more than 200,000 victims in 150 countries have been hit with the weaponized WannaCry ransomware worm. In the United Kingdom, the National Health Service was hit hard by the worm, potentially threatening patients’ lives.Haven’t we had enough? It’s time to stop pretending that lukewarm, poorly executed security measures are really doing something […]
I’m no world-class hacker/penetration tester, but I’ve been able to break into any organization I’ve been (legally) hired to do so in an hour or less, except for one place that took me three hours. That was on my second engagement with the customer after it had implemented many of the protections I had recommended […]
As a traveling consultant, I visit lots of businesses during the year and examine their security plans. For decades, I’ve secretly scoffed at what they’ve tried to do because it was often too little, too late—and misdirected.But these days, I run into more and more companies that get it right rather than wrong, with ideas […]
Today’s increasingly miniaturized world is giving rise to all sorts of hardware devices that can hack almost any computer, device, or network. Plug in an item the size of a USB stick and all your hard-won protections could be defeated. If you haven’t been paying attention to this field of attack, what you learn might […]
As a traveling enterprise security consultant, I get to see security teams at their best and their worst. Under stress, some teams work like a well-oiled machines, while others devolve into inefficient, finger-pointing bureaucracies.Every great computer security team has a synergistic collection of skilled professionals who work well together to meet common goals. The team […]
If you’ve been paying attention lately, you’ve likely noticed that more of your everyday websites are going HTTPS by default: Twitter, Facebook, LinkedIn, and even your favorite search engine.This is a good development. For years, critics have derided default, widespread HTTPS encryption and authentication as unnecessary and performance-wasting. But now that we’ve seen most of […]
“If you’re being watched, you change your behavior, and that means you have less freedom. I don’t think you can have freedom without privacy.” —Kevin Mitnick, quoted in my new book, “Hacking the Hacker.”The United States has a long history of protecting at least some individual privacy rights with respect to common carriers. Much of […]
Readers often ask me how I feel about the latest free, public certificate authorities (CAs). I always tell them the same thing: It’s difficult for a free CA to actually provide any security assurance. There is no free lunch.I was reminded of this maxim when I read a recent article from HashedOut revealing that the […]
It’s a rough number, but I’d wager that 99 percent of computer security risk in most organizations can be attributed to two root causes: social engineering and unpatched software. I’m not talking about pure numbers of success exploits, but overall impact. Many CISOs and threat intelligence analysts have told me that 100 percent of the […]
Wikileaks’ CIA dump is the biggest secret cache released so far. It’s embarrassing to the CIA. It undermines our intelligence efforts. And it didn’t need to happen. The sad fact is that the world’s computers are not configured securely enough to match the confidentiality of the data they are protecting. As a society we allow […]
You’ll never reduce your security risk if you can’t identify and mitigate the root causes of those vulnerabilities. It isn’t enough to have a list of malware programs that your antimalware has detected. You need to to determine how viruses and hackers have penetrated your environment in the past. In the vast majority of organizations, […]
We live in a global society. While your country’s economy may be stagnating or barely growing, someone else’s economy is probably booming. It’s no wonder your company is reaching across international borders to establish new business ties and revenue sources. That’s all well and good. But you should also know that I’ve consulted for a […]
One of the biggest problems with security defenses is the lack of concrete data to measure the effectiveness of mitigations against threats. In almost any other industry, the dearth of data would be embarrassing. As I’ve noted before, every organization needs to develop a data-driven security defense. Such a defense uses a company’s own threat intelligence to […]
For most of my professional life, the term “bot” has been associated with badness. As a computer security professional, whenever I saw bots involved, they were usually committing malicious acts and harnessing hundreds or thousands of otherwise innocent devices and computers to engage in harmful deeds.But that will change as good bots become more common, […]
If you’re worried about fake news, you ain’t seen nothing yet. Soon we may not be able to tell the difference between a fake video and a real one, even forensically. What we are seeing today is the tip of the iceberg. Fake news has already altered the world forever. It’s always been a huge […]
When attackers look for vulnerabilities, they target popular software. Why bother chasing flaws in applications that few people use? That’s why one of my best friends runs a third-party application instead of Adobe Acrobat Reader to open and read PDF documents. Another friend runs the Maxthon browser to stay out of the way of exploits […]
Contrary to popular belief, ransomware has been around for decades. The first malware program to lock up people’s files and ask for a ransom was the PC Cyborg Trojan in 1989. It was created by Harvard-trained evolutionary biologist Dr. Joseph Popp, who was working on several AIDS-related projects at the time. Dr. Popp sent a […]
One of the toughest parts of being a computer security pro is trying to figure out what to hang your career on every two to five years. Which new buzzwords will stick to become a new paradigms, and which will disappear into the ether? Keeping up with the latest and greatest enterprise tech is part […]
I recently had the pleasure of interviewing Dr. Leonard Adleman — the “A” in the very popular public cryptographic algorithm RSA — as part of the Association for Computing Machinery’s 50th anniversary celebration of the Turing Award. In 2002, Adleman himself won the Turing Award, often referred to at the Nobel Prize of the computing […]
Only a handful of industry associations accomplish what they set out to do. In the security realm, I’ve always been a huge fan of the Trusted Computing Group. It’s one of the few vendor organizations that truly makes computers more secure in a holistic manner. The Fast Identity Online (FIDO) Alliance is another group with lots […]
Last week I speculated that the current horrible state of internet security may well be as good as we’re ever going to get. I focused on the technical and historical reasons why I believe that to be true. Today, I’ll tell you why I’m convinced that, even if we were able to solve the technical […]
One billion-plus accounts stolen in one online heist. The U.S. presidential election messed with by another country. Corporate secrets stolen and released on the internet on a regular basis. More and more data held hostage by ransomware. Stock markets routinely manipulated by hackers. Denial-of-service attacks whacking websites all over the place. Will computer security ever […]
As a traveling computer security consultant for over 20 years, I’ve had the chance to visit a lot of different operations and see what works and doesn’t work. I’m always looking for common denominators for successes and failures, and I share these lessons as I learn them. But I realize I’ve unconsciously absorbed one home […]
We live in a world where internet crime is rampant. Cyber criminals steal hundreds of millions of dollars each year with near impunity. For every 1 that gets caught, 10,000 go free — maybe more. For every 1 successfully prosecuted in a court of law, 100 get off scot-free or with a warning. Why is […]
I received the following “domain abuse notice” for one of my inactive registered domains last week: Those of us who have dealt with falsely blacklisted domains in the past have seen notices like this before. It’s usually from an antispam vendor or service letting you know that your domain has been used in a spam […]
The long-awaited SHA-1 deprecation deadline of Jan. 1, 2017, is almost here. At that point, we’ll all be expected to use SHA-2 instead. So the question is: What is your browser going to do when it encounters a SHA-1 signed digital certificate? We’ll delve into the answers in a minute. But first, let’s review what […]
It’s no secret that conservatives, who will soon control all three branches of the U.S. government with the election of President Trump, are more liable to give more power and deference to law enforcement. Perhaps the strongest influence is the likely appointment of one to three conservative Supreme Court justices. What does that mean for […]
Back in January, I wrote one of my most popular posts ever: “Why you don’t need an RFID-blocking wallet.” As the title suggests, I argued that it’s a waste of money to buy a wallet with special shielding to protect your chipped credit card from RFID scanners wielded by street criminals seeking to snatch your […]
People who are upset that Hillary Clinton’s personal email server may have been hacked are missing the big picture. Nearly everything that is worth hacking and connected to the internet is already hacked — and that which is not can be hacked at will. I don’t want to get into the morass of whether Clinton’s […]
Last Friday’s massive DDoS attack against Dyn.com and its DNS services slowed down or knocked out internet connectivity for millions of users for much of the day. Unfortunately, these sorts of attacks cannot be easily mitigated. We have to live with them for now.Huge DDoS attacks that take down entire sites can be accomplished for a […]
For many years I worked for Foundstone teaching hacking classes and doing penetration testing. It was the most enjoyable job I ever had.As part of that job, I traveled the world, including China, and got to determine firsthand which country had the best hackers. Although I didn’t travel to Russia during that time, lots of […]
Honeypots provide the best way I know of to detect attackers or unauthorized snoopers inside or outside your organization. For decades I’ve wondered why honeypots weren’t taking off, but they finally seem to be reaching critical mass. I help a growing number of companies implement their first serious honeypots — and the number of vendors […]
Most companies don’t do what they need to do to reduce security risks. How do I know? Because I’ve consulted for hundreds of them. They don’t patch their most attacked programs in a timely manner, and they do a poor job of teaching their users how to avoid social engineering attacks — the two commonsense […]
It didn’t take 500 million hacked Yahoo accounts to make me hate, hate, hate password reset questions (otherwise known as knowledge-based authentication or KBA). It didn’t help when I heard that password reset questions and answers — which are often identical, required, and reused on other websites — were compromised in that massive hack, too. […]
No fewer than 70 percent of internet-connected Seagate NAS hard drives have been compromised by a single malware program. That’s a pretty startling figure. Security vendor Sophos says the bitcoin-mining malware Miner-C is the culprit.I’m surprised this story hasn’t garnered more attention. Perhaps it’s because we’re talking only 7,000 hard drives possibly in total, or […]
I talk a lot about the security problems and weaknesses of the internet, as well as the devices connected to it. It’s all true, and we badly need improvements. Yet the irony is that security in our online world is actually better than in our physical world. Think of how many people are scammed by […]
People have trouble prioritizing risk. For example, you often hear about the threat of voter fraud, when all evidence suggests that the risks of such fraud are inconsequential. In truth, hacked voting machines are much more likely to affect an election’s outcome. Why would an election fraudster try to herd a flock of criminal participants to […]
If you’ve ever hacked for a living — wearing a white hat, I hope — you probably can’t stand the unrealistic light most shows and movies shine on hacking and hackers. On the big and small screens, supergenius hackers enjoy instantaneous success and always manage to stay one step ahead of the law. Typically they’re […]
When you’ve been writing about security for as long as I have, you develop a following. I’m grateful to my readers — without them, my editor would need to find another security writer. But I can’t help but notice that among those who consume my content is a small but tenacious group of people who […]
In the spirit of the Olympics, it’s time to celebrate our hard-won computer security defense advancements. Given the endless stream of news about embarrassing hacks and data breaches, I can see why you might be skeptical. The fact is tens of millions of computers are currently exploited, nearly every company is owned, and those that […]
I spend a lot of time working on enterprise Public Key Infrastructure (PKI), especially in light of the coming SHA-1 deprecation deadlines. It’s nearly all I do these days. One question my customers ask all the time is how to provision certificates on non-Windows devices and computers. Microsoft does an excellent job of automating the […]
I recently finished reading “Hedy’s Folly” by the scholar Richard Rhodes. In it he discusses the “most beautiful woman in the world,” 1930s and ‘40s superstar Hedy Lamarr. With her composer friend George Antheil, she invented frequency hopping. Frequency hopping (or spread spectrum) is a technology that underlies the communication transport and security of almost […]
Some days when I’m wasting time on the internet, it seems like I can’t visit three websites in a row without hitting a fake “you’re infected” scam or bogus browser extension ad. Most of the time these malicious offerings launch on otherwise legitimate websites — or secretly direct your browser to illegitimate websites. For almost […]
Today, almost all hacking is done by professional criminals. In many countries, illegal hacking accounts for more crime, dollar-wise, than noncomputer crime. The United Kingdom recently joined that club. Why is this important? First, if you find malware on your system, there’s a good chance it’s trying to steal your money. Second, no one is […]
Most people’s computers get exploited in only a handful of ways. Among the most popular methods is tricking people into downloading and running Trojans. Often, unsuspecting users get socially engineered into running a malicious file or app by following a link in email or visiting a website. It can be tough to spot the fake […]
I travel all over the world for my job, and for my hobbies. Although there are still plenty of places I haven’t been, I’ve visited enough foreign countries that I don’t deny it when someone calls me a world traveler. Over the years, I’ve experienced my fair share of foreign spying. I know what it’s […]
There’s an old security mantra that says “always change the defaults!” Although this seems like a good general rule, in fact it’s true only for certain kinds of settings. Changing the defaults in other cases will just end up biting you in the end with little increased security to show for it. A few months […]
One of my most popular posts of all time is about sticking it to Craigslist scammers. And no wonder: I get one or two emails a week from people who have been scammed or almost scammed on Craiglist. The victims are always upset and want my help getting the scammer arrested, which is nearly impossible. My […]
I’ve always thought that improved computer security controls would “fix” the internet and stop persistent criminality — turns out it might be big data analytics instead. I’ve long written that only a large-scale improvement of the internet’s authentication mechanisms (that is, pervasive identity) could significantly reduce crime. If everyone on the internet had a default, […]
Recently, Microsoft published a new password policy recommendation paper containing advice that flies in the face of conventional wisdom on the subject. Some of the contrarian viewpoints include: Eliminate long password requirements Eliminate complexity requirements Do away with password life expirations Along with this unconventional advice comes a bunch of useful suggestions: Ban common passwords […]
There’s a widely held view that our world is full of uber hackers who are too brilliant to stop. Thus, we should fear zero-day attacks because they’re our biggest problem. Nothing could be further from the truth. Most hackers follow the path created by a very few smart ones — and zero days make up […]
Nearly everything we do in computer security is meant to protect data. After all, we don’t deploy antimalware software, tighten security configurations, or implement firewalls to protect users, per se. Job No. 1 is to protect the organization’s data — including employee and (especially) customer data. But guess what? People need to work with that […]
Data is king — for attackers as well as defenders. Malicious hackers have long collected and used data in a systematic manner. For example, they investigate all the public-facing servers of a particular target company, as well as document their IP addresses, services, software versions, and back-end relationships. They collect as much publicly accessible information […]
Some users’ accounts are more attractive to malicious hackers than others. Computer security experts have long focused on local administrators/root — and recently even more on all-powerful network administrators such as members of the domain admin and enterprise admin groups. Those same experts warn about protecting even slightly elevated accounts, like those of network configuration […]
Are you ready for the coming SHA-1 deprecation deadline? I suspect most companies aren’t. They don’t know about the issue — and the pending January 1, 2017 deadline. Others are probably aware that there is something called “SHA-1 deprecation” and have gotten some browser certificate errors, but don’t fully appreciate the need to be substantially […]
As I read about the Kuwaiti government’s plan to test and log the DNA of everyone in that country, I was reminded of what a bad idea such schemes are. It’s great for law enforcement, I guess, but it’s terrible for personal privacy and overall security. What do I mean that it’s bad for security? […]
Nothing on the Internet is perfectly anonymous. Despite what many people may tell you, the complexities of hardware and software systems make true anonymity almost impossible, particularly when the right people decide to expend the effort to find you. That said, there are reasonable (and even unreasonable) steps you can take to remain anonymous to […]
If you’re under the age of 65, chances are you’ll live long enough to see most cars become autonomous, self-driving, shared transportation pods. You’ll see home delivery by drone become the norm. You’ll become host to the myriad of computers you and your clothing will contain. All reality will become augmented reality. You’ll be able […]
Digital certificates and malware go together like peanut butter and petroleum jelly — they can be sandwiched together easily, but the result is not exactly tasty or good for you. As you may know, digital certificates are used to cryptographically sign executable code and documents. If the digital certificate used for signing the content was […]
I love honeypots. I’ve even written a book about them. Any time you set up a fake system that nothing and no one should try to connect to, you cull invaluable information that any security defender will find useful. I’m still surprised that honeypots aren’t part of every organization’s security strategy. My guess is that’s […]
Over the years I’ve hired or helped hire hundreds of computer security folks. Although job interviews tend to last an hour, I can usually tell in a few minutes if I’m talking to the right person for the job. If I think I have the right person, I will lead them into saying the right […]
Almost every day I hear from customers or friends who are worried about security threats reported in the media. Increasingly, I find myself saying: “That’s handled by default in Windows 10.” Windows 10 contains many new security features. Last year, InfoWorld’s Fahmida Rashid provided a great overview in her article, “Why Windows 10 is the […]
Security isn’t black and white. It isn’t a choice between full security and no security — it’s a continuum with a lot of gray in between. Full security, even if achievable, would “secure” things beyond the realm of reasonable usability. But even then hackers would find a way in. Usable security comes down to a single […]
Imagine your friend’s house is broken into over and over. Each time the intruder gains entry by smashing a window. In response, your friend notices that his door locks aren’t Bluetooth-enabled or biometric, so he buys intelligent door locks for his house. He is surprised, over and over, that no matter how much he upgrades […]
Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install patches. They want to do the right thing. But patching can be difficult for a multitude of reasons, and those roadblocks explain why patching is performed so poorly in most organizations. Let’s walk […]
Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for Christmas!” they say. My lack of response should be telling, but they don’t seem to pick up on it. They’ve seen the TV ads about malicious hackers who can “stand […]
As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal debit card was frozen and would have to be unlocked. I knew I should’ve let my bank and credit card companies know I was traveling, but […]
I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing algorithm — and SHA-1 is the signature type used by almost everyone. But SHA-1 has significant cryptographic weaknesses, which is why the crypto world has recommended for years that digital […]
You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people will care about a year later. For me, it’s hard enough to digest what happened in the past and make sense of it, but this was a landmark year. Here […]
Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]
In an election year, particularly one in which we’re all bracing for a downturn, the 1992 Clinton campaign’s famous catchphrase “It’s the economy, stupid!” can’t help but come to mind. Apply that same commonsense thinking to computer security and you get: “It’s the data, stupid!” We suffer from a dearth of data and quality analytics […]
Protecting elevated authentication credentials is one of the best defense-in-depth strategies any company can deploy. In today’s pass-the-hash, pass-the-Kerberos-token, steal-any-credentials world, preventing credentials from falling into the wrong hands can be the entire battle. Identity is security. If an identity and its authentication credentials get into the wrong hands, often enough, it’s game over. For […]
Imagine your friend’s house is broken into over and over. Each time the intruder gains entry by smashing a window. In response, your friend notices that his door locks aren’t Bluetooth-enabled or biometric, so he buys intelligent door locks for his house. He is surprised, over and over, that no matter how much he upgrades […]
Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install patches. They want to do the right thing. But patching can be difficult for a multitude of reasons, and those roadblocks explain why patching is performed so poorly in most organizations. Let’s walk […]
Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for Christmas!” they say. My lack of response should be telling, but they don’t seem to pick up on it. They’ve seen the TV ads about malicious hackers who can “stand […]
As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal debit card was frozen and would have to be unlocked. I knew I should’ve let my bank and credit card companies know I was traveling, but […]
I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing algorithm — and SHA-1 is the signature type used by almost everyone. But SHA-1 has significant cryptographic weaknesses, which is why the crypto world has recommended for years that digital […]
You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people will care about a year later. For me, it’s hard enough to digest what happened in the past and make sense of it, but this was a landmark year. Here […]
Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]
The most fun I’ve had as a security guy was getting paid to penetration-test companies and websites. It’s like getting paid to be a gamer. You earn a fat paycheck to hang out with friends and hack away without fear of being arrested. Most large companies today have multiple teams of professional pen testers, often […]
It’s easier than you think to keep your computer malware and hacker free. Believe it or not, most of today’s computers are pretty safe and secure, whether you’re using Microsoft Windows, Apple OS X, Linux, BSD, or Google’s Chrome OS. Mobile devices are equally as safe, as long as you’re downloading apps from an authorized […]
Whether or not you were born in a big city, you quickly learn the rules of walking in congested public areas, full of people who want your money. You learn what areas and which people to avoid. You learn to walk like you know where you’re going and to ignore strangers trying to get your […]
I often get in arguments with computer security experts who declare such-and-such computer defense is worthless because it isn’t perfect. No topic exemplifies these types of debates better than the value of user education. On one side, you have people who believe that user education is a crucial part of any computer security defense. The […]
Last Wednesday, the world’s largest stock exchange went down for half a day, the world’s fifth-largest airline grounded its planes for a few hours, and The Wall Street Journal’s home page went missing, all within a few hours of each other. No wonder speculation was rife that a large-scale cyber attack was under way. But […]
Reading about the widespread bribery and corruption of public officials supposedly hired to catch Columbian drug lord Pablo Escobar reminds me of the current state of computer crime. In both instances you have criminal interests making hundreds of millions of dollars while the very entities that could easily bring them down only watch or, even […]
I’m a huge PKI (public key infrastructure) fan. I love the beauty of the mathematics and cryptography. I love its myriad uses and scenarios. I’ve been installing PKIs for private and public companies for over two decades. That’s always been a big part of my job, and lately, it seems like that’s all I’ve been […]
Only in the computer security world would I get taken to task for saying the defenses you apply should be directly related to the threats you face. That’s exactly what happened after I posted “The No. 1 problem with computer security” last week. Several readers wrote to tell me how stupid I was for not […]
I’ve been in the computer security field for nearly three decades. During that time, I’ve watched it go from bad to worse to ugly. Today, the average computer security defense is so bad, we had to invent a new paradigm a few years ago called “assume breach.” This phrase admits that our security controls are […]
Be scared! The Russians are attacking us. If it’s not the Russians, it’s the Chinese — or maybe the North Koreans. Yes, foreign governments are attacking us. But we’re also attacking them. It’s spycraft as usual. The U.S. government and the media’s continued warnings about who is hacking us reminds me of a womanizing cheat […]
A big paradigm shift is under way in the malware world. Less malware is being used in the biggest, most sophisticated attacks. Instead, malicious intruders are using the legitimate tools built into various operating systems to do their dirty work. Legitimate tools, including remote management tools and scripting engines, are far harder to detect than […]
It seems like ancient history now, but in the early decades of the Internet we had huge problem: Our email servers were too friendly. In a nutshell, most email servers allowed anyone to connect to them and send email to anyone else. You didn’t have to be a user of that email server, though sometimes […]
Persistent hackers have a common means of taking over company networks: They compromise one or more enterprise users using social engineering. Either they’ve already compromised a website the user visits or they send a phishing email, which asks for enterprise credentials. If the user visits a compromised website, usually a malicious script will probe the […]
I’m still in shock over the Ashley Madison hack, which exposed more than 37 million users. No, my name and email address are not on the list. No, I’m not morally outraged over the number of people who were either lying to a significant other or hoping to have a liaison with someone lying to […]
This post marks my 10th year writing for InfoWorld magazine. I became a regular writer for InfoWorld by being, shall we say, persistent — I wasn’t a big fan of InfoWorld’s security coverage at the time and suggested I could do better. Eventually, InfoWorld’s editors agreed, and I’ve been posting here ever since. Frequent readers of […]
APTs (advanced persistent threats) are tough to detect and stop. Typically, APT attackers break in, survey all the servers on the network, and take what they’ve come for long before they get noticed … if ever. If only there was a way to prevent that stolen data from being used when it left your network. […]
Behavioral psychiatrists say that virtually all people lie. Most are little white lies to protect the feelings of others. Some lies are acts of commission — a deliberate statement of untruth — whereas others are lies of omission. In the latter case, someone tells an absolutely true fact, but leaves out a very important related […]
