Category: Main Digg

  • Why you should protect your wireless network with WPA.

    A gang (from BBC’s The Real Hustle) using easily available software break into a WEP protected wireless network and find out what a surfer has been up to as well as having access to his computer and his internet connection.

    read more | digg story

  • Welcome to the world of botnets

    “Eric Sites stares at the screen of a “dirty box,” a Windows machine infected with the self-replicating Wootbot network worm. Within seconds, there is a significant spike in CPU usage as the infected computer starts scanning the network, looking for vulnerable hosts. Basically, this machine is now owned by a criminal.”

    read more | digg story

  • Why Bush’s Wire Tapping is Defeated by VoIP Networks

    Bush claims he needs NSA wire tapping to break up terrorist networks but terrorists are not using the phone network Bush is tapping. They … all are using private voice over IP internet phones (VoIP) that can’t be tapped. This video explains how it works. And, how you can set up your own.

    read more | digg story

  • MySpace Adult Content Viewer, More Evil MySpace Adware

    This particular attack displays a pop-up window when you visit certain MySpace pages, usually featuring single, attractive twenty-somethings with page titles like “I Want to be loved” or “I am looking for my soul mate”. The message reads “This profile contains adult content, Click Here to Install MySpace Adult Content Viewer”.

    read more | digg story

  • Integral Computer Security (a.k.a Integral Hacking)

    My message to Brad the Integral Designer at Brad Lauster dot com:
    I have been thinking of implementing Ken’s 4 quadrant approach to my profession, Information Security, as well.  I still need to fill out my understanding of the AQAL method, but so far I imagine seeing applying what Ken calls “quadrivia” to the concept of a security network.  So I guess I’d have to consider the network as a holon (whole part among other wholes) defined by the four quadrants (perspectives that define the network).  What is incredible is that it forces me to think in terms of a network only as people see it: individual users, the organization who owns the network (from the inside and outside), and the world (lower-right?). Its almost like puting it in my hand and observing it from every angle for weakness’ (but I’m seeing it as if I am a four dimensional being because I can see the INSIDE as well).

    Like I said, this requires that I have more knowledge of AQAL.

  • Study: 1 In 3 Workers Write Down Passwords

    One in three people write down computer passwords, undermining their security, and companies should look to more advanced methods, including biometrics, to ensure their systems are safe, a new study shows.

    Security bad ass Bruce Schneier actually recommends writing passwords down and putting them in your wallet –> http://www.schneier.com/blog/archives/2005/06/write_down_your.html

    read more | digg story

  • There is no such thing as Security

    I’ve noticed that there are two types of security people: anal “type A personalities” who live every moment by the rules, and those that realize that there is no real security.  Please understand that these two mindset don’t seem to have anything to do with talent.  I’ve met talented people with both mindset.  A talented security professional is mindful, aware, and always pays attention to detail.  The very best seem almost psychic in their ability to spot wrong doing, security breaches and even malicious intent.

    Type A security people seem to thrive on “catching bad guys”.  Its like they are kids playing cops & robbers.  These people thrive on structure, order and regulations.  In information security they know how important it is to have lots of centralized control and a stardard configuration for all systems.  In the Meyers-Brigg’s personality test, these people are ESTJ’s (Extraverted Sensing Thinking Judging).  The thought of any getting away with breaking the law (ANY LAW) is unacceptable.  These guys make great Directors of Security, CSO’s and other policy creators as long as they don’t micromanage their people.  Their employees will either love them as a great mentor or hate them with every fiber of their being.

    Those who realize that there is no such thing as security are hackers.  They are many times INFP’s (Introverted iNtuitive Feeling Perceptive).  Unlike the ESTJ’s they don’t care about structure and rules because the realize that rules are only suggestion to keep an acceptable level or order.  For them the most important rules are in a persons heart.  ESTJs will usually see these people as lazy and don’t really care but these people are just trying to find an easier way to do things.  If they don’t enforce certain rules or cut corners, it because the sincerely believe that the rule or enforcement (in that particular situation) is not needed.  Employees will usually love INFP’s unless they happen to be ESTJ’s.

    I am a bit biased because I am in the second camp, INFP.  I don’t believe there is a such thing as “security”.  No one is ever completely safe.  All a malicious intending person needs is the element of surprise, time, and pressure an they can get away with anything they want.  Further, anyone at anytime can have malicious intent: employees, kids, bosses, friends, family not just random strangers.

    Security is just an illusion.  The one good thing security does is ensure you are faster than the slowest person, organization, network or whatever on the block.  Those with malicious intent will typically go for the easiest target. 

    Since many crime happen from people that the victims know all we can really do is not worry about it.  Life is too short to waste too much time fretting about every possible thing that can happen to you.     

    I guess that is what Ben Franklin meant when he said:

    “Those Who Sacrifice Liberty For Security Deserve Neither”  

    If you worry so much about security that you can’t enjoy the fruits of your labor, then what is the point of the living and if you can’t enjoy living whats the point of protecting ANYTHING. – elamb

  • Microsoft Now Decides to Accept Outside Security for Vista

    Microsoft did an about-face yesterday, agreeing to make it easier for customers of its forthcoming Vista operating system to use outside security vendors, such as those who make popular antivirus and anti-spyware programs.
    Until now, Microsoft had planned to block those companies from installing their products in the deepest levels of the new OS.

    read more | digg story

  • Stop Viruses for Free!

    I have three subjects today, and each of them is a winner in its way. The interesting fact about them is that all three start with the first letter of the alphabet, their names being Avira PersonalEdition Classic, AVG Free Edition and Avast! Home Edition.

    read more | digg story

  • NVIDIA Binary Graphics Driver Exploit

    A recent security advisory announced today by Rapid7 explains, “the NVIDIA Binary Graphics Driver for Linux is vulnerable to a buffer overflow that allows an attacker to run arbitrary code as root. This bug can be exploited both locally or remotely.”

    read more | digg story