Check out Adrian Crenshaw's site: www.irongeek.com. It's chock full of good insight on some hard-to-find hacking tricks. Good video demos as well.I had the pleasure of meeting Adrian when I keynoted the Louisville ISSA conference last month. Very nice and knowledgeable guy....
Continue Reading...Everything in security is just a matter of time, right? Well, a couple of researchers - one of which is the author of the Aircrack-ng tool that I've covered a lot over the years - have found a new way to crack the WPA TKIP key in a just a few minutes without using a dictionary attack (previously the only way to crack it). Reaffirms the arms race we're mired ...
Continue Reading...Here's an interesting tidbit from the Atlanta InfraGard's CounterIntelligence Working Group web site reminding us that information security IS a business problem. Too many executives think this kind of stuff won't happen to them:"The Issue … Does your company have products or technology that someone might want to steal from you? ... If a new competitor suddenly sprang up in the marketplace with exact copies of your products and was ...
Continue Reading...If you're looking to take a CISSP prep course, check DSTI's 4-day CISSP bootcamp in Kennesaw, GA December 10-13. You can get more information at digitalsecuritytraining.com. Apparently they're offering a 5% discount is offered for ISSA members. Even though their Web site leaves a little to be desired, I know the guys that run this company and they're top notch.If you're wondering if certification is the best route to take ...
Continue Reading...Here's a new book fresh off the press written by my friend and colleague Tim Virtue. Very good insight into the world of PCI DSS compliance.I reviewed it for the publisher before it went to print and got my name imprinted forever on the back cover!...
Continue Reading...Here's an article I wrote for SearchDataBackup.com:Ten ways you can make your data backups more secureHere's one I wrote for Security Technology & Design magazine:Ten Ways to Protect Your Web servers...noticing a trend!?Be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcast interviews, webcasts, screencasts and more....
Continue Reading...Here's a good read on certifications and whether or not they enhance or hinder your earning ability - especially if you focus on vendor-specific certifications such as what Microsoft offers.Mr. Mikols article led me to think about this are more in-depth and I came to this conclusion: I do believe that you can spend too much time focusing on getting certified. In fact, I've seen it personally. The mindset I've ...
Continue Reading...Here's a great quote I just came across that explains why most users aren't motivated to follow security policies."Without a compelling cause, our employees are just putting in time. Their minds might be engaged, but their hearts are not. Meaning precedes motivation." - Lee J. ColanThey're just not in the game...Hence the necessity for strong leadership....
Continue Reading...Although I disagree with Becky's push to vote, vote, vote! (too many uninformed and non-tax paying citizens already vote and shouldn't be able to), here's a good post about some recent election/voting stories involving IT and security....
Continue Reading...