• 12 Nov 2008

    Excellent resource for hacking goodies

    Check out Adrian Crenshaw's site: www.irongeek.com. It's chock full of good insight on some hard-to-find hacking tricks. Good video demos as well.I had the pleasure of meeting Adrian when I keynoted the Louisville ISSA conference last month. Very nice and knowledgeable guy....

    Continue Reading...
  • 12 Nov 2008

    New way to crack WPA on wireless networks

    Everything in security is just a matter of time, right? Well, a couple of researchers - one of which is the author of the Aircrack-ng tool that I've covered a lot over the years - have found a new way to crack the WPA TKIP key in a just a few minutes without using a dictionary attack (previously the only way to crack it). Reaffirms the arms race we're mired ...

    Continue Reading...
  • 12 Nov 2008

    Think computer security is not a business issue – just ask the FBI

    Here's an interesting tidbit from the Atlanta InfraGard's CounterIntelligence Working Group web site reminding us that information security IS a business problem. Too many executives think this kind of stuff won't happen to them:"The Issue … Does your company have products or technology that someone might want to steal from you? ... If a new competitor suddenly sprang up in the marketplace with exact copies of your products and was ...

    Continue Reading...
  • 12 Nov 2008

    Atlanta-area CISSP training from guys who know their stuff

    If you're looking to take a CISSP prep course, check DSTI's 4-day CISSP bootcamp in Kennesaw, GA December 10-13. You can get more information at digitalsecuritytraining.com. Apparently they're offering a 5% discount is offered for ISSA members. Even though their Web site leaves a little to be desired, I know the guys that run this company and they're top notch.If you're wondering if certification is the best route to take ...

    Continue Reading...
  • 11 Nov 2008

    New book on PCI worth checking out

    Here's a new book fresh off the press written by my friend and colleague Tim Virtue. Very good insight into the world of PCI DSS compliance.I reviewed it for the publisher before it went to print and got my name imprinted forever on the back cover!...

    Continue Reading...
  • 11 Nov 2008

    My latest security content

    Here's an article I wrote for SearchDataBackup.com:Ten ways you can make your data backups more secureHere's one I wrote for Security Technology & Design magazine:Ten Ways to Protect Your Web servers...noticing a trend!?Be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcast interviews, webcasts, screencasts and more....

    Continue Reading...
  • 11 Nov 2008

    Are certifications hurting your salary more than helping?

    Here's a good read on certifications and whether or not they enhance or hinder your earning ability - especially if you focus on vendor-specific certifications such as what Microsoft offers.Mr. Mikols article led me to think about this are more in-depth and I came to this conclusion: I do believe that you can spend too much time focusing on getting certified. In fact, I've seen it personally. The mindset I've ...

    Continue Reading...
  • 07 Nov 2008

    Why your users don’t buy into your policies

    Here's a great quote I just came across that explains why most users aren't motivated to follow security policies."Without a compelling cause, our employees are just putting in time. Their minds might be engaged, but their hearts are not. Meaning precedes motivation." - Lee J. ColanThey're just not in the game...Hence the necessity for strong leadership....

    Continue Reading...
  • 05 Nov 2008

    Election-related security stories

    Although I disagree with Becky's push to vote, vote, vote! (too many uninformed and non-tax paying citizens already vote and shouldn't be able to), here's a good post about some recent election/voting stories involving IT and security....

    Continue Reading...
  • 05 Nov 2008