• 09 Nov 2010

    My (belated) thoughts on Intel’s purchase of McAfee

    I've been so busy working that I've failed to post some timely pieces I wrote over the summer...here's one of them:Intel's McAfee buy marks a turning point for securityI truly believe we cannot even fathom how this acquisition will impact us long term....

    Continue Reading...
  • 09 Nov 2010

    Windows 7 security tools & password weaknesses

    Here are some recent SearchEnterpriseDesktop.com pieces I wrote regarding Windows 7 security...enjoy!Using Windows 7's built-in features to keep your desktops secureWindows 7 doesn’t end the need to monitor passwords...

    Continue Reading...
  • 04 Nov 2010

    Interesting findings from Venafi on encryption management

    Information security vendor Venafi released a survey at the October Gartner show that has some interesting findings related to encryption management:Organizations anticipate a 27% year-over-year certificate and key inventory growth rate85% of organizations manage encryption certificates and private keys manually via spreadsheet and reminder notes 78% of organizations have experienced system downtime due to encryption failures in the past 12 monthsGiven what I see in my information security assessments - ...

    Continue Reading...
  • 04 Nov 2010

    Using GFI LANguard to find open network shares

    Have you see what your users are sharing up on your network? What about your server shares - are they divulging too much PII and intellectual property to any Joe Blow on the network?Outside of mobile security (smartphone weaknesses, lack of laptop encryption, etc.) the problem of unstructured information scattered about the network is a very predictable high priority finding in any given security assessment.The reality is you cannot secure ...

    Continue Reading...
  • 03 Nov 2010

    Let the smoke (and mirrors) clear

    Finally, some hope and change we can believe in!But not so fast...a quick note to all the Republicans out there: you didn't get voted in because people are embracing you...people are just tired of seeing the Democrats' lack of principles and leadership- not to mention their taking money (by force) from the people who earn it and giving it to those who don't deserve it - undermining and effectively destroying ...

    Continue Reading...
  • 02 Nov 2010

    Today is the day

    Today is the day we get a chance to vote for more government or less government.Today is the day those of us in America can begin to stop the bleeding we've been experiencing since January 20, 2009. Technically, for decades.Today is the day we're empowered to remind the career politicians around our country that we the people are in charge. Not them.Today is the day we stop giving up little ...

    Continue Reading...
  • 29 Oct 2010

    The business side of Web security (you can’t afford to ignore)

    Here's a new piece I wrote about the *other* aspects of Web security beyond the bits and bytes...Don't let this stuff catch you off guard.Preventing phishing attacks is not just a technical issue...

    Continue Reading...
  • 27 Oct 2010

    Talk about old school…

    I recently came across a Web site I was creating an account for which stated the following for its login requirements:Your user name & password must consist of letters in all caps 4-7 characters in length.Too funny......

    Continue Reading...
  • 18 Oct 2010

    AppDetectivePro v7 worth checking out

    Have you checked out Application Security's (somewhat) new AppDetectivePro version 7? Have you even heard of AppDetectivePro? If not, it needs to be on your radar. It's a powerful database vulnerability scanner that can perform both unauthenticated penetration tests as well as authenticated audits of SQL Server, Oracle, MySQL, DB2, Notes/Domino and Sybase (wow) systems. A screenshot of a penetration test of an Oracle 11g-based system is shown below:AppDetective is ...

    Continue Reading...
  • 18 Oct 2010

    Is this quote one of the contributing factors to lax infosec?

    Novelist Robert Heinlein once said "In the absence of clearly-defined goals, we become strangely loyal to performing daily trivia until ultimately we become enslaved by it."I suspect this is a large contributing factor to the lack of information security - and subsequent data breaches - in business today.Feel like you need a jump start on goal setting? Check out this piece I wrote on the subject:Eight steps to accomplishing your ...

    Continue Reading...