• 18 Mar 2008

    Breaking News! Windows Vista SP1 is here…

    ...and I'm praying that it'll fix my Vista woes! Click here for the download page....

    Continue Reading...
  • 18 Mar 2008

    The book that started it all for me

    I've gotten several inquiries from people lately regarding what book or books they should read to help get them started down the information security career path. Well, believe it or not, here's the one book that really got the ball rolling for me:Yep - I learned the basics of TCP/IP during many a lunch break way back when this book was in its first edition...and I *still* use that stuff.Sure, ...

    Continue Reading...
  • 18 Mar 2008

    Ever wonder how real-time imaging software works?

    I use Acronis TrueImage Echo for my backups. It's a really handy way of performing live backups and I hear from a lot of folks how they love it. If you've ever wondered how the software is actually able to make backups of the live Windows system without having to reboot into a DOS-like interface, here's how it's done. This is from Acronis support engineer Michael Lee - re-printed with ...

    Continue Reading...
  • 17 Mar 2008

    Internet and “global warming” founder to speak at VoiceCon this week

    Al Gore, the founder/creator of both the Internet and "global warming" - I mean "climate change" (the updated term) - is speaking at VoiceCon in Orlando on Wednesday. Going green in the data center. Woohoo. Could they not have found a more compelling/realistic keynote topic - and speaker - for the show? Like how information security causes global warming? :-)Politics under the guise of "doing what's best"...What can you do!?...

    Continue Reading...
  • 14 Mar 2008

    My security content from this week

    Here's a webcast I recorded recently for SearchWindowsSecurity.com:Vulnerability Testing Blunders, Oversights, and Common Mistakes You Must Avoid...and a podcast interview with Mike Rothman:Hacker-Proof Your ApplicationsFor all of my past information security content be sure to check out www.principlelogic.com/resources.html....

    Continue Reading...
  • 12 Mar 2008

    New way of entering online passwords for brokerage houses

    I just heard on the Clark Howard radio show that online brokerage firms are moving towards Web authentication technologies that require you to enter your password with your mouse. This is presumably to help keep the bad guys from gleaning your login credentials using keystroke loggers.I hear about this all the time - especially in the brokerage industry - where the bad guys capture your user name and password (off ...

    Continue Reading...
  • 12 Mar 2008

    Wal-Mart dropping $199 Linux-based PCs

    It looks like Linux on the desktop has taken a hit. Wal-Mart has announced that it's no longer going to sell Everex's Linux-based systems...at least in its brick-and-mortar stores. Based on the stereotypical Wal-Mart demographic, I can't say I'm shocked. Hey - I shop there too when I have to!That said, based on my experience - and continued instability - of Windows Vista running on my HP Compaq 8510p, Wal-Mart ...

    Continue Reading...
  • 12 Mar 2008

    Back in action

    I'm back from my family's ski trip to Salt Lake City...If you've never been there - or tried skiing, or snowmobiling, or snow tubing - I *highly* recommend it. During my down time - I thought of several new ideas for blog posts and even came up with some new content for my Security On Wheels audio programs in the not so distant future.Cheers!...

    Continue Reading...
  • 04 Mar 2008

    Be careful not to expose your information when sharing your desktop with WebEx, etc.

    You've likely used - in some form or fashion - WebEx, GotoMeeting, or similar remote meeting/sharing application, right? Well, if you're ever the presenter of a meeting and end up sharing your desktop out to everyone, be VERY careful. I had stepped away from my desk after a recent online meeting I was participating in had ended. When I returned, I saw that the guy who had shared his desktop ...

    Continue Reading...
  • 03 Mar 2008

    A way to bypass whole disk encryption

    Researchers at Princeton University have found a way around whole disk encryption. Dubbed the "cold-boot attack", apparently there's a way to "freeze" the whole disk encryption passphrase while it's stored in dynamic memory and then extract it using some software they've written. Having learned and applied what can be done with/to a PC at the chip level in my assembly language programming days, this comes as no shocker. Wish it ...

    Continue Reading...