Thursday, June 20, 2013

Hunter S. Thompson’s Creative, Fearless Job Application Letter


Was the last letter you wrote this creative, honest and dripping with personality?

More:
http://thefuturebuzz.com/2010/10/06/hunters-thompsons-letter/

Sunday, June 16, 2013

Wow. Just. Wow.



Fake internet cafes and key loggers: British intelligence reportedly spied on major world leaders during 2009 G20 summit
http://www.theverge.com/2013/6/16/4436120/british-gchq-world-leader-surveillance-program-2009-g20-summit


Friday, June 7, 2013

China Snatches US Veterans' Data - Security Clan Editor's Blog - Internet Evolution

 China Snatches US Veterans' Data

In one of the nastiest -- not to mention large scale and long-term -- hacking exploits yet to be reported, it appears that the Chinese army has been rummaging through the data of those who have served in the US Armed Forces.

According to testimony given before a House subcommittee, Jerry Davis, the outgoing CSO for the Veteran Affairs Department, broke the astonishing news that at least eight overseas organizations, most of them linked to the Chinese military, have been accessing veterans' data since 2010. Committee Chairman Mike Coffmann (R-Colo.) summarized the position starkly:

The entire veteran database in VA, containing personally identifiable information on roughly 20 million veterans, is not encrypted, and evidence suggests that it has repeatedly been compromised since 2010 by foreign actors, including in China and possibly in Russia.

More:
http://www.internetevolution.com/author.asp?doc_id=264229

Thursday, May 16, 2013

When CIO Reports to CFO, Everyone Loses



VPs of Administration and Finance represent the interests of that business vertical. They are also strongly partial to the systems used by that business vertical. Within a medical university, they cannot be expected to also represent marketing; advancement; communications; business development; client relations; disease control; provost; faculty; student life; or other departments. Think about your enterprise: How can the person overseeing finance be impartial or well-informed across all your departments?

Under many organizations' reporting structures, the CIO is expected to develop relationships with these other business verticals, but since they report to the CFO they are excluded from the cabinet meetings where leaders congregate. Even when CIOs are invited, they are not considered of equal rank -- because they are not. Everyone views the CFO as the final authority for IT decisions, leading to some serious problems.

First, finance drives strategy instead of strategy driving finance. IT is seen as a cost center and there is a perennial pressure to cut costs and reduce expenditures -- often at the detriment of strategy. Setting appropriate salaries for CIOs and people reporting to the CIOs becomes impossible.

Monday, May 13, 2013

DISA issues new guidance for secure, enterprise mobility



The Defense Information Systems Agency (DISA) has approved the Security Technical Implementation Guides (STIG) for Blackberry and Samsung Knox devices, which means that DOD organizations will be able to use those devices in conjunction with a secure enterprise mobility environment.

The release of DISA's Samsung Knox STIG, May 2, provisionally allows the DOD to use the latest technology as soon as it is available commercially. STIGs for the currently available Blackberry 10, Blackberry Playbook, and Blackberry Device Service were also issued. The STIGs allow use of accepted devices as part of approved mobility pilots with actively defended Mobile Device Management (MDM) systems.


More:
http://defensesystems.com/articles/2013/05/09/stig.aspx

Thursday, May 9, 2013

iOS 6 granted FIPS 140-2, approved for U.S. government use


Move over, BlackBerry. iPhones and iPads running iOS 6 are now certified for low-level secure government use.

Apple's iOS 6 mobile operating system is now secure enough for low-level work in the U.S. government after it passed security certification.

The National Institute of Standards and Technology (NIST), which examines and tests mobile devices for security and validation purposes, granted the Apple mobile platform FIPS 140-2 certification (Level 1) last Friday. At this level, devices running the platform can be used in conjunction with the lowest level of security clearance.

It comes just days after the U.S. Department of Defense was reportedly in talks with Apple and Samsung in a bid to approve the two firms' devices for government use. It follows the dropping of an exclusive contract the Dept. of Defense's had with BlackBerry — then named Research in Motion — late last year.

The U.S. government's approval follows seven months after its U.K. counterpart first approved iOS 6-based iPhones and iPads. U.K. government workers are only allowed to use the devices for data deemed "restricted" or below.

More:

Wednesday, May 8, 2013

OK. This is pretty cool. LIVE DDOS dashboard.



Prolexic Tracks More Than 47 Million DDoS Attack Bots Globally.

Now you can too, in PLXpatrol, the free public DDoS attack portal.

Link:
http://www.prolexic.com/plxpatrol/

Tuesday, May 7, 2013

Review: Fitbit Flex Activity Monitor


In well-defined markets, it's rare to see a breakthrough device. And yet here we are. There are a lot of sleep and activity trackers to choose from right now, but none better than the Fitbit Flex. It is the most wearable, best-syncing device in the scrum, with the best app to boot. And it does all this at a great price.
The Flex is very similar to the Fitbit One, but smaller and housed and without a display. And instead of wearing it on your belt, bra or pocket, you slide it in and out of a slim, rubberized wristband. The band is extremely basic, and it lacks the design elements of the Jawbone Up or the display of the Nike+ FuelBand. Other than the LED lights it uses to give you feedback, it is visually flat. In short, it's not obviously some sort of sensor.
What it is, however, is highly wearable. A fitted clasp keeps it locked on your wrist securely. Most of the time, at least — I managed to dislodge it once while getting my squirming two year old out of a car seat. But I found it stayed on better than the Up. Similarly, there are no parts to lose, unlike the Up's end cap that has a tendency to pop off and disappear over time. It's waterproof-ish — while you can't take it diving, you can wear it in the shower. In a huge improvement over the One, you don't have to put it in an armband (it's already in one) at night to track your sleep. That lack of visual flair also means it doesn't look out of place with a suit, or a track suit. It comes in black. You can buy a three-pack of other colors if you want for an extra $30.

More:
www.wired.com/reviews/2013/05/fitbit-flex/

I just ordered the new FitBit Flex. I am excited to try the new features.



You've Started Self-Tracking. Now What?

According to figures published recently by Pew Internet Research, only 46% of people who track some aspect of their health say that it has changed their overall approach to maintaining their health. This is a startlingly low number. If less than half of self-trackers are able to find any actionable benefits, what on earth are the rest self-tracking for?

If you've just started self-tracking, you may well be wondering the same thing–how should you use the data that you collect to make genuine self-improvements? The sheer quantity of data can be overwhelming. If you're one of those who are slightly perplexed about how to really get the best out of the quantified self (QS), here are five tips.

The Rest:
http://lifehacker.com/youve-started-self-tracking-now-what-493562901

Monday, May 6, 2013

Did he just say Ideating? I D ate ing? Really? I'm not ever gonna use that.


Adobe announces first hardware, the Project Mighty smart stylus and Napoleon ruler
http://www.theverge.com/2013/5/6/4305712/adobe-announces-first-hardware-the-project-mighty-smart-stylus

DoD Health Office Loses Control of E-Record Project



After five years and an estimated $1 billion spent trying to build a single integrated electronic health record (iEHR) system with the Department of Veterans Affairs, defense health officials have been taken off the project, sources confirm.

Wielding the hook was Defense Secretary Chuck Hagel who signaled disappointment with his management team to a House panel this month, saying he halted a solicitation for bids from commercial electronic record designers because "I didn't think we knew what the hell we were doing."

A congressional source confirmed that DoD oversight for developing an interoperable electronic health records is now under Frank Kendall, under secretary of defense for acquisition, technology and logistics. The shift was first reported Monday by the news website NextGov.


More:
http://www.military.com/benefits/2013/05/03/mil-update-dod-health-office-loses-control-of-e-record-project.html?comp=7000024213943&rank=3

DARPA looking for a “clean slate” for MANETS -- Defense Systems



Goal is to investigate radical concepts for 20X increase in MANET size

With mobile ad hoc networks (MANET) limited to about 50 nodes before network services become ineffective, the Defense Advanced Research Projects Agency (DARPA) this week issued a Request for Information that calls for research paper abstracts describing bold, new technical approaches to overcoming the MANET scaling problem.

For the past 20 years, researchers have unsuccessfully used Internet-based concepts in attempts to significantly scale MANETs. In its RFI, DARPA wants to explore new technologies unencumbered by Internet protocols that could be the key to enabling large MANETs.


It is actually called a Lie Brary...


Choose your own misadventure at the Bush Presidential Library - The Maddow Blog

Thursday, May 2, 2013

Windows 8: Microsoft's New Coke moment


Summary: The latest operating systems numbers are in, and Windows 8's failure is clearer than ever. Can Microsoft, like Coca-Cola before it, bring victory out of a defeated product launch?

BYOD, or else. Companies will soon require that workers use their own smartphone on the job



Security remains the main BYOD concern, but CIOs seen ready to create strategies that keep companies safe

Bring-your-own-device strategies are the single most radical change to the economics and culture of client computing in a decade, according to a new study by Gartner.

One radical change BYOD is expected to spawn: By 2017, half of all employers will require workers to supply their own devices for work purposes. Also, Gartner says, enterprises that offer only corporately-owned smartphones or stipends to buy your own will soon become the exception to the rule.

As enterprise BYOD programs proliferate, 38% of companies expect to stop providing devices to workers by 2016 and let them use their own, according to a global survey of CIOs by Gartner, Inc.'s Executive Programs.

More:
http://www.computerworld.com/s/article/9238832/BYOD_or_else._Companies_will_soon_require_that_workers_use_their_own_smartphone_on_the_job

True to form, the Bush Library continues the lies of the Bush administration



Choose your own misadventure at the Bush Presidential Library

Below is 8 minutes of video showing the creepily manipulative game play for the Iraq invasion portion of the Decision Points Theater exhibit at the George W. Bush Presidential Library and Museum that Rachel shared tonight and talked about with Col. Lawrence Wilkerson. Actually it's not exactly the same as what Rachel showed. In this one the audience decides against going to war. Ultimately that doesn't really matter, the final soliloquy from the former president is the same.

Video preview photo

Service Accounts Can Be Secure Yet Have Non-Expiring Passwords

 Deny logon locally is a Group Policy Object (GPO) setting that should be used for all service accounts because it shuts down one avenue of exploitation—an interactive logon (e.g., a logon using Ctrl+Alt+Del) to a system with that account. Most security teams frown on allowing accounts with non-expiring passwords to exist, but it's often near impossible to do without having some. One of the biggest concerns people have is the account could be used anywhere on the network, leading to abuse of it. To satisfy security teams and auditors, I came up with a simple way to comply with this security practice but still have service accounts with passwords that don't expire.

More:
http://m.windowsitpro.com/security/service-accounts-can-be-secure-yet-have-non-expiring-passwords