Thursday, April 16, 2015
First time at RSA Conference? How to have the most fun. #RSAC
Wednesday, April 8, 2015
Tuesday, February 24, 2015
VA Secretary Robert McDonald apologizes for misstating military record - The Washington Post
Wood quoted retired Army Col. Gary Bloomberg, a former Special Forces commander, calling McDonald's claim "a boneheaded statement." But Bloomberg said he and other former special ops officers did not consider it as egregious as some other misrepresentations.
"No one got really crazy about the whole thing, compared to some of what we've seen," he told the Huffington Post. "It's a lot different from guys running around faking their special forces credentials. … I can see [other former special forces soldiers] going, 'Hey, check out this boneheaded remark,' but I don't see the gravitas that I would with a guy wearing medals he didn't earn.'"
Monday, February 23, 2015
What Good is Tor in 2014?
It's probable, especially in the wake of the recent NSA revelations, that government agencies such as the NSA and CSIS sniff traffic on many exit nodes.
More:
http://resources.infosecinstitute.com/good-tor-2014/
Friday, February 20, 2015
Replacements - The Ledge Lyrics
Wow. Strong and sad. I think I knew that kid.
I'm glad I was able to get tickets today.
See you guys in DC in May.
http://www.metrolyrics.com/the-ledge-lyrics-replacements.html
Thursday, February 12, 2015
Jeb Bush just revealed the social security numbers of a bunch of former constituents
In a ham-handed effort at transparency, the likely 2016 Republican presidential candidate Jeb Bush just released a trove of emailsfrom his time as Florida's governor—but the emails included confidential messages, personal information and even social security numbers from thousands of people. What was he thinking?
The un-redacted email dump was first identified by the Verge, which found emails that, among other things, discussed the firings of public employees. In some emails, petitioners sent their social security numbers to Bush, who was famously responsive to email inquiries from his constituents.
Friday, January 30, 2015
I was quoted in an FCW article on mobile device security.
Striking a balance with mobile device security
Agencies face a delicate balancing act when it comes to providing mobile security.
On the one hand, IT departments seek to extend endpoint security to a growing population of mobile devices. It's easy to see why: Smartphones can go missing along with agency data, and mobile devices in general can introduce malware to enterprise networks. On the other hand, employees want the ease of use of consumer technology, and agency managers covet the potential productivity boost.
More:
http://fcw.com/articles/2014/12/08/striking-a-balance-with-mobile-device-security.aspx
Thursday, January 29, 2015
Saturday, January 24, 2015
Best Alternatives to Tor: 12 Programs to Use Since NSA, Hackers Compromised Tor Project
More:
http://www.idigitaltimes.com/best-alternatives-tor-12-programs-use-nsa-hackers-compromised-tor-project-376976
Thursday, January 15, 2015
New CISSP Domains
CISSP Domains, Effective April 15, 2015
- Security and Risk Management (Security, Risk, Compliance, Law, Regulations, Business Continuity)
- Asset Security (Protecting Security of Assets)
- Security Engineering (Engineering and Management of Security)
- Communications and Network Security (Designing and Protecting Network Security)
- Identity and Access Management (Controlling Access and Managing Identity)
- Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)
- Security Operations (Foundational Concepts, Investigations, Incident Management, Disaster Recovery)
- Software Development Security (Understanding, Applying, and Enforcing Software Security)
Saturday, December 6, 2014
Crews maintaining 450 ICBMs had just one wrench with which to attach nuclear warheads
Staff at bases in North Dakota, Wyoming and Montana had to send the toolkit to each other via FedEx, the review found. Mr Hagel said that problem had now been rectified.
Inspectors reportedly ignored the fact that ageing blast doors at nuclear silos would no longer seal shut.
On staffing, the reviews found that a culture of micromanagement and extreme exam-testing distracted from major problems with equipment and nuclear readiness.
Thursday, December 4, 2014
Sony Kept Thousands of Passwords in a Folder Named "Password"
Friday, November 28, 2014
Cheap Black Friday Android tablets: Security threats found
More:
http://bgr.com/2014/11/26/cheap-black-friday-android-tablets/
Tuesday, November 11, 2014
New Attack Method Can Hit 95% Of iOS Devices
More:
http://www.darkreading.com/new-attack-method-can-hit-95--of-ios-devices/d/d-id/1317359
Saturday, October 25, 2014
IAF asks personnel not to use Xiaomi phones
"F-secure, a leading security solution company, recently carried out a test of Xiaomi Redmi 1s, the company's budget smartphone, and found that the phone was forwarding carrier name, phone number, IMEI (the device identifier) plus numbers from address book and text messages back to Beijing," says an advisory issued by the IAF to its personnel.
The IAF note, issued some weeks back, has been prepared by the intelligence unit based on the inputs from Indian Computer Emergency Response Team (CERT-In), according to IAF sources.
More:
http://m.timesofindia.com/india/IAF-asks-personnel-not-to-use-Xiaomi-phones/articleshow/44926994.cms
Thursday, October 23, 2014
New Fitbit activity tracker release, price, specs, new features
Here we look at what to expect from the next Fitbit tracker, when it will be available, and what it will cost. We're basing our report on the latest rumours and leaks, historical data, rival trackers, and recent Fitbit trademark applications for a Fitbit Surge, Fitbit Charge and PurePulse. In what may be no coincidence, just weeks after the razzmatazz unveiling of the Apple Watch, first Gizmodo then The Verge suddenly get leaked information each on one of the new trackers.
![]()
New Fitbit Charge and Charge HR trackers: new features – Force replacement and heart-rate monitor
Thursday, October 16, 2014
This POODLE bites: exploiting the SSL 3.0 fallback
Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore our recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.
Tuesday, October 14, 2014
Truly scary SSL 3.0 vuln to be revealed soon: sources
Gird your loins, sysadmins: The Register has learned that news of yet another major security vulnerability - this time in SSL 3.0 - is probably imminent.
Maintainers have kept quiet about the vulnerability in the lead-up to a patch release expected in in the late European evening, or not far from high noon Pacific Time.
Details of the problem are under wraps due to the severity of the vulnerability.
To that end it is unknown what platforms were impacted, but as SSL is very widely used any flaw will require plenty of urgent attention ... and probably be unwelcome news to a tech community already reeling from the recent Shellshock vulnerability in Bash and the Heartbleed flaw.
The SSL flaw won't be the only thing keeping security bods and system administrators busy. A dangerous worm has been discovered exploiting a zero-day flaw (CVE 2014-4114) in all versions of Microsoft Windows and Server 2008 and 2012.
From:
Saturday, October 11, 2014
DEFCON Router Hacking Contest Reveals 15 Major Vulnerabilities
According to the rules of the contest, an entry wasn't considered valid unless the contestant also showed proof of disclosure to the manufacturer. Here's a full list of routers in which 0-days were reported in Track 0, along with our current understanding of the fix in progress:
- ASUS AC66U; reported, but no response from the manufacturer.
- Netgear WNDR4700; reported, but no response from the manufacturer.
- D-LINK 865L; reported, and manufacturer confirms it is working on a fix, currently in beta.
- Belkin N900; reported, and manufacturer acknowledgedbut was unclear on providing a fix.
- TRENDnet TEW-812DRU; reported, and manufacturer claims all reported 0-days are fixed.
- Actiontec Q1000; reported, and manufacturer acknowledged the report.
For details please see the full contest results.
Tuesday, October 7, 2014
OMB gives DHS new powers to scan some civilian agency networks for cyber threats
OMB added this new requirement for DHS to scan civilian agency networks in the aftermath of the Heartbleed vulnerability. During that time, DHS had to get permission from agencies to scan their networks, which delayed its mitigation strategy by a few days.
DHS made it clear in May during a House hearing that it needed Congress to give it more authorities to scan agency networks.
Andy Ozment, the assistant secretary of the Office of Cybersecurity and Communications in DHS, told Federal News Radio in an interview before OMB issued the FISMA guidance that when DHS doesn't have the explicit authorities that it needs and Congress wants them to have, it makes everything harder.