Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
The needs of the Security Profession
CIO magazine published an article on the new required skills for security professionals, including a business acumen (perhaps an MBA) and a basic understanding of psychology. Interesting reading to keep in mind when we begin to build a security curriculum"
Security Breaches and compensation
The University of Georgia had a security breach recently, which was very lightly covered by the media. In response to the breach, you get the standard fare of apologies and news releases (just like we saw in the Ohio University breach last year...but no remuneration for credit report freezes or any other incurred expense by the people whose information was compromised. Why not?
Help! We're under attack!
Posted on CNN and elsewhere, 3 of the 13 'key Internet computers' were were under attack by a massive hack attack. According to the CERT center,
Fortunately, we internet users did not know what was hitting us. Unfortunately, this is becoming more and more likely. Buckle up.
At approximately 0001 GMT on 6 Feb 2007, several root-level DNS servers began receiving a large volume of malformed DNS queries. This initial attack appears to have been a warm-up for a much larger attack that began at 1000 GMT.
DNS servers G (U.S. DOD Network Information Center), L (Internet Corporation for Assigned Names and Numbers), and M (WIDE Project) appear to have been the most severely impacted although none were ever unreachable. The servers were operational and reachable even with the high volume of traffic.
Fortunately, we internet users did not know what was hitting us. Unfortunately, this is becoming more and more likely. Buckle up.
You gotta be kidding me...8 seconds???
How long would it take for a newly internet-attached PC to be attacked by the silent army of hackers around the world? Sadly, the answer according to
this BBC article from 2005 is "eight seconds". Think about it: "1-Mississippi, 2-Mississippi, 3-Mississippi, 4-Mississippi, 5-Mississippi, 6-Mississippi, 7-Mississippi, 8-Mississippi" - and you're hacked. Sobering thought, especially for those who hate anti-virus software packages (and I am one of them).
In some ways, this is an old story - even for the BBC, but the results are still alarming.
this BBC article from 2005 is "eight seconds". Think about it: "1-Mississippi, 2-Mississippi, 3-Mississippi, 4-Mississippi, 5-Mississippi, 6-Mississippi, 7-Mississippi, 8-Mississippi" - and you're hacked. Sobering thought, especially for those who hate anti-virus software packages (and I am one of them).
In some ways, this is an old story - even for the BBC, but the results are still alarming.
Microsoft Office 'Zero-Day' Attack
Slashdot reports that the new version of Microsoft Office is already under attack. No surprise there -- and I am not blaming Microsoft. Why attack Open Office when there are so few users? Why not attack MSFT Office and its legion of well-placed (meaning Corporate) users?
Usable Security
Interesting report on how Bank of America's Sitekey doesn't work as well as it should. This and other reports can be found at this conference which is formed around different aspects of 'usable security'. In some respects, this deals with similar earlier work (ACM membership required - mirror copy here) by Mary Ellen Zurko on User-Centered Security - which she has apparently updated recently.