• 16 Sep 2009

    My latest security content

    Here's my latest information security content. Hope you enjoy!Big IT Lessons Small Businesses Can Learn (an IncTechnlogy.com piece I contributed to)How often should I change the passwords for my bank and other important online accounts? (a Women's Health magazine piece I contributed to)Web 2.0 application security troubleshooting, testing tutorialHIPAA-covered entities, business associates confront HITECH Act rulesTen sure-fire ways to derail your career in IT What you should know about cloud ...

    Continue Reading...
  • 19 Aug 2009

    No soup for you….20 years!

    Here's a bit on the recent indictment of a Florida man known as the soupnazi (man, I miss Seinfeld) and two Russians for the data breaches of Heartland, Hannaford, and many others. Facing 20 years and a $250,000+ fine and he still has other cases pending!The funny thing is that he's a former informant to the U.S. Secret Service!Lesson to be learned: test your systems for security vulnerabilities before the ...

    Continue Reading...
  • 05 Aug 2009

    Why you need to read privacy policies

    In case you haven't heard, apparently our Imperial Federal Government was at it again with their recent draconian privacy policy on the Cash for Clunkers web site. Here's a snippet of the policy:"Any or all uses of this system, any or all uses of this system and all files on this system may be intercepted, monitored, recorded, copied, audited, inspected, and disclosed to authorized CARS, DOT, and law enforcement personnel ...

    Continue Reading...
  • 30 Jul 2009

    GAO reports federal infosec failures – seriously?!

    So the people in our own Imperial Federal Government has failed yet another security test!? You know, the same people who force us (at gunpoint if necessary) to become secure and stay secure.Some highlights:Twenty of the 24 agencies had inadequate information security controls that were considered a material weakness or a significant deficiency.A 200% increase in security incidents over the past three years...It's a "major management challenge"...even with an unlimited ...

    Continue Reading...
  • 27 Jul 2009

    Imagine if your security plan looked like this

    Imagine if you tried to force an Obamacare-eqivalent information security plan on management (see chart below). How would they respond. They'd probably tell you to go pound sand.And now anyone against such a big goverment idea can't speak out about it. I wonder how much longer I'll get to do my rants in a forum such as this. Wow, where's our freedom going? Is anyone listening...? This isn't about healthcare. ...

    Continue Reading...
  • 23 Jul 2009

    “Change” sells but who’s buying?

    So in the past year we've gone from:"global warming" to "climate change" (esp. with the ridiculous cap and trade bill that's going to further hurt our economy)Islamic terrorism to "man-caused disaster" ...and the latest in the Obamacare scam we heard about last night:healthcare reform to "health insurance reform"Boy are our so-called leaders sneaky! It's amazing how these politicians change their wording up ever so slightly to make their schemes sound ...

    Continue Reading...
  • 20 Jul 2009

    Imagine signing off on something you haven’t read

    Jeff Jacoby with the Boston Globe made an excellent point in his article regarding the Read The Bills Act (the law we need to prevent our own lawmakers from carelessly passing laws they haven't read nor understand).Jeff said: "Senators and representatives who vote on bills they haven't read and don't understand betray their constituents' trust. It is no excuse to say that Congress would get much less done if every ...

    Continue Reading...
  • 03 Jun 2009

    Secret list of nuclear sites released “by accident”

    Apparently our Imperial Federal Government can't even follow its own rules for information privacy and security. It was just announced that a secret list of nuclear sites was released "by accident".First of all, "accidents" are like "computer glitches" - there's almost always human error behind them. Do you see the irony here? How is heavily-regulated private industry to be expected to lock everything down when the very entity writing OUR ...

    Continue Reading...
  • 21 May 2009

    My CNN TV appearance – yet another mobile drive debacle

    CNN's Mike Ahlers and Elaine Quijano put together an intriguiging segment about a lost hard drive from the National Archives for The Situation Room with Wolf Blitzer television show I appeared on last night. The hyperlink goes to the actual article...the video hasn't been posted yet and they're telling me it may not be. I hope you had the chance to see it live last night. If it gets posted ...

    Continue Reading...
  • 20 May 2009

    I’m going to be on CNN at 5pm ET today

    I received a call from the producer of the CNN show The Situation Room With Wolf Blitzer today and ended up doing a TV interview. It's about the National Archive story that just came out regarding and external hard drive that recently went missing.Wonder if it was encrypted like I've ranted about here and elsewhere in the past? Probably not.It's going to be on in the 5pm ET hour on ...

    Continue Reading...