• 28 Jun 2010

    Secure your home Wi-Fi or forever hold your peace

    Google has provided us with yet another reason to keep our home wireless networks secure. Speaking of that, in case you're wondering where things stand, here's a great tool for finding out just how vulnerable your wireless network utilizing WEP and WPA-PSK can be.Our society's continued privacy invasion never ceases to amaze me. And we, by and large (especially with Google), just blow it off and move on....

    Continue Reading...
  • 15 Jun 2010

    Oil rigs now, Internet later?

    Obama shuts down oil rigs - $330 million in lost wages per month. What's going to happen when he shuts down the Internet?Who gave this guy such power!?...elections have consequences....

    Continue Reading...
  • 14 Jun 2010

    Survival of the weakest?

    I just heard Neal Boortz discussing this Wall Street Journal piece about how people with the least amount of economic knowledge are making all the rules in America right now. Very interesting insight.Totally reminds me of management and other non-technical people making all the rules for information security and privacy.Something's backwards here folks. Why is it the tail wags the dog in so many critical situations such as these affecting ...

    Continue Reading...
  • 10 Jun 2010

    iPad “breach” – another sensationalistic Web flaw

    NewsFactor has a nice piece on the recent AT&T iPad "breach" that tells the story of how a code on AT&T's site was cracked exposing email addresses of iPad users. So, some criminals gleaned some email addresses from a telecom provider...In the grand scheme of things: big deal.I agree with Sophos' Paul Ducklin - I think this is being overblown...just like the sensationalism brought forth by my recent bit on ...

    Continue Reading...
  • 07 Jun 2010

    Oil and infosec, a marriage made in heaven?

    Here's a funny - and ironic - pic a friend of mine just forwarded me.Need I say more?Also, I have on my desk the March 8, 2010 edition of InformationWeek (great mag by the way) that has BP as its cover story. A call out quote says:"Two years ago, BP CEO Tony Hayward laid some very tough love on his 500 top managers. Despite revenue of about $300 billion, the ...

    Continue Reading...
  • 28 May 2010

    Where I’ve been + 2 important reading assignments

    Wow, I can't believe it's the end of May....the year's nearly halfway through and I feel like I should still be back in February! After experiencing some family health crises and deaths combined with the busiest year I've ever had with my business (not complaining there!), I've let my blog suffer. I never like to not post for so long but I work to stay true to what I preach ...

    Continue Reading...
  • 21 May 2010

    The compliance crutch mentality rides on

    I believe it was my colleague Kevin Bocek who once said: "Security done right will yield compliance for free. Compliance for compliance sake will always deliver more problems in the end."Why is it so many business leaders keep ignoring this reality?It's funny, I was just thinking about an article I co-authored for CSO Online with Charles Cresson Wood nearly a year ago entitled The Dangers of Over-Reliance on Compliance. Those ...

    Continue Reading...
  • 17 Apr 2010

    Essentials for cracking SQL Server passwords

    Looking to check the resiliency of your Microsoft SQL Server systems? You may very well find that you don't have to look much further than weak/blank passwords to gain full access. I've come across a few vulnerable SQL Server systems via manual analysis. However, I couldn't live without a small set of SQL Server password cracking tools that you should check out as well.Here's a piece I wrote that can ...

    Continue Reading...
  • 15 Apr 2010

    CSRF doesn’t matter?? The sky is falling!

    Here's a great piece where something I wrote put a grown man with a hacker handle's boxers in a bunch. With all due respect to what Robert has contributed to our field, he is missing the point of my 8 sentence statement about cross-site request forgery (CSRF) not being a top priority (formerly published on SearchSoftwareQuality.com). It reminds of me when I wrote about Changes coming to the OWASP Top ...

    Continue Reading...
  • 26 Mar 2010

    Why the rich keep getting richer and the poor keep getting poorer

    Contrary to what Senator Max Baucus (Democrat) recently said about the forthcoming healthcare deform that's being forced upon us:“Too often, much of late, the last couple three years the mal-distribution of income in America is gone up way too much, the wealthy are getting way, way too wealthy, and the middle income class is left behind. Wages have not kept up with increased income of the highest income in America. ...

    Continue Reading...