• 18 Jul 2008

    My security content from this week

    OK, we're back into the swing of things. Here are two information security articles of mine that were published this week:AJAX Security - Is anyone listening?Cross-site Scripting 102 - How it actually worksAnd here's a recent podcast as well:The latest on convergence and network standardsAs always, for my past information security content be sure to check out www.principlelogic.com/resources.html.Enjoy!...

    Continue Reading...
  • 18 Jul 2008

    Crack the darn password!

    Here's an interesting story about a network admin working for the city of San Francisco who's refusing to give up a password. He won't give it up, then why not just crack it? It's probably a shared password anyway quite possibly stored/used somewhere else on his computer. There are TONS of password cracking tools out there by Elcomsoft and others. This could be an easy task.Our government at work......

    Continue Reading...
  • 18 Jul 2008

    Great quote to think about over the weekend

    Remember the Law of Attraction that says we become and achieve what we think about the most? Here's a bit about the one thing - tenacity - that will help you keep driving for what you want in your information security career:"Let me tell you the secret that has led me to my goal. My strength lies solely in my tenacity." - Louis Pasteur...

    Continue Reading...
  • 16 Jul 2008

    Do your users do online banking at work?

    Here's a good reason to not do online banking at work or an untrusted computer. When there's a will there's a way...this is why we'll always have work to do in this field....

    Continue Reading...
  • 16 Jul 2008

    The key to moving up and career success

    Here's a little snippet I thought of when developing my latest audio program - Certifications, Degrees, or Experience - What's Best for Your Security Career?. I thought it'd make for a good blog post.Working in the field of information security, never ever forget that you get paid for what you do and contribute to your employer - not for the letters and acronyms that come after your name in your ...

    Continue Reading...
  • 15 Jul 2008

    Good news and bad news about Webroot

    The good news:I finally gotten so fed up with my previous bloatware anti-virus product (I was a 15+ year loyal customer) that I had to move on to something leaner and meaner. I chose Webroot's Spy Sweeper with Anti-Virus. It has received good ratings over the years from PC Magazine and seems to work pretty well. PLUS, I can actually use my computer now without tons of hang-ups and delays. ...

    Continue Reading...
  • 14 Jul 2008

    Can you imagine a 4-day work week?

    The state of Utah is calling for businesses to adopt a 4-day work week. Not a bad idea. *IF* something like this were put in place, employers would save on operational costs and employees can save on gas. And morale goes up too. A win-win. But can you imagine those controlling and ignorant managers!?....Woooweee. What would THEY DO if their employees were allowed to work from home...Control - it's a ...

    Continue Reading...
  • 12 Jul 2008

    My security content from this week

    ...well, there is none. Two weeks in a row! I have written several articles recently, though, that will be published soon.BTW, sorry for being out of touch recently. Vacation and playing catch-up has set me back a bit!Until later......

    Continue Reading...
  • 08 Jul 2008

    Interesting stats from Information Security Breaches Survey 2008

    First of all, for those of you reading this in the U.S., welcome back from the 4th of July holiday!I just came across some statistics in the U.K.-based Information Security Breaches Survey 2008 that provides some insight and clarity into why we still (and always will) have security breaches:98% of respondents scan for spyware...55% have a documented security policy.97% filter for spam...40% provide security awareness training.Only 6% have suffered a ...

    Continue Reading...
  • 02 Jul 2008

    Funny view of ridicously unsecure Web apps

    My colleague Mike Rothman has a great post at SecurityIncite about Web application security and the "beta" mindset. I couldn't agree more....Just slap a beta tag on everything like Google does and you're off the hook!...

    Continue Reading...