Menu

Tag Archives: advice

Why identity is the new security

Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]

Attention, 'red team' hackers: Stay on target

The most fun I’ve had as a security guy was getting paid to penetration-test companies and websites. It’s like getting paid to be a gamer. You earn a fat paycheck to hang out with friends and hack away without fear of being arrested. Most large companies today have multiple teams of professional pen testers, often […]

4 do's and don'ts for safer holiday computing

It’s easier than you think to keep your computer malware and hacker free. Believe it or not, most of today’s computers are pretty safe and secure, whether you’re using Microsoft Windows, Apple OS X, Linux, BSD, or Google’s Chrome OS. Mobile devices are equally as safe, as long as you’re downloading apps from an authorized […]

To catch a thief: Cyber sleuth edition

My wife and I recently returned from one of the best vacations of my life, bareboating around the British Virgin Islands with another couple, when I found we were victims of credit card fraud taking place on the other side of the country. It was a lousy way to end a vacation. Worse, I had […]

7 keys to better risk assessment

I’ve said it before: The No. 1 problem with computer security is poor root-cause analysis, where security pros fail to identify and track the ways an environment was exploited, be it malware or human attack. Common root causes include social engineering, password guessing/cracking, unpatched software, misconfiguration, denial of service, and physical attacks. [ Also on […]

Math to the rescue! Try this novel hacking defense

I came to love math later in life. In junior high, I hated it so bad I had to take pre-algebra three times and my parents celebrated if I got a D. But I fell in love with it in my first year of college and I consider the A+ I got in my three-hour […]

The sorry state of certificate revocation

As much as I love public key infrastructure (PKI) and the mathematical security it can provide, it’s usually horribly implemented in the real world. If done right, like the inventors intended, it would be darn near perfect. It’s mostly broken because admins don’t deploy it right, software doesn’t enforce what needs to be enforced, and […]

Encryption is under siege. Move to SHA-2 now!

It’s been a raucous few months in crypto circles. In a staid, mathematical world long accustomed to incremental changes, new developments are coming as fast as Chrome browser updates. I’m not sure what’s behind the breaks, but crypto cracking suddenly seems to have accelerated. Here’s a quick roundup of what’s been going down — and […]

Freedom or security? Most users have chosen

The writing is on the wall. The future of computers is less application choice — in exchange for a safer overall computing experience. I’m not talking about a draconian security lockdown. I’m referring to the app stores that have emerged not only for mobile but also for desktop operating systems. OS vendors and their stores […]

The most important security question to ask users

Most organizations don’t do enough to educate users about computer security. The main purpose of user education programs is to decrease human-factor risk substantially. If they don’t accomplish that, the whole exercise is a waste of resources. Such programs, if they exist at all, consist of a sort of security orientation program for new employees, […]

Why patching is still a problem — and how to fix it
Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install [...]
Why you don't need an RFID-blocking wallet
Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for [...]
Train your users to beat phone scams
As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal [...]
A better way to move past insecure SHA-1 certs
I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing [...]
How computer security changed in 2015
You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people [...]