Archive for the 'Security' Category

Oh No! Is SSH Not Secure Enough?

Sunday, May 28th, 2006

A lot of people use Secure Shell (SSH) as the remote administration tool of choice. In this day of Internet worms and zero-day vulnerabilities, it is important to get every bit of security one can possibly get their hands on. One of the most important security systems administration tools is SSH. Recently, an Informit Article […]

Why should Telcos should and should not be concerned with security?

Friday, May 26th, 2006

The telecommunications sector has been bombarded with customer complaints on security lately. There is this issue about Smart Wifi and other Cable DSL services being insecure in the last mine. Now, there is this Inq7 article that describes another spin on the story of Telco security.
“A lot of telecommunications companies don’t take responsibility when it […]

Our Vulnerable Internet 2

Tuesday, May 23rd, 2006

Developing nations remain especially vulnerable to a cyber assault because they haven’t built up defenses for their computer, banking and utility systems, said Yean Yoke Heng, deputy director general of the Kuala Lumpur-based Southeast Asian Regional Center for Counterterrorism.

Our Vulnerable Internet

Saturday, May 20th, 2006

In this Washington Post article, it is reported that Blue Security has surrendered to the spammers. However, what scares me is the collateral damage in this battle against spam:
According to information obtained by Security Fix, the reason is that the attackers were hellbent on taking down Blue Security’s site again, but had trouble because the […]

SOX-compliance too costly?

Sunday, May 14th, 2006

NetworkWorld ran an article entitled “Execs tell regulators than Sarbanes-Oxley costs exceed benefits“. The article has this quote:
“The Sarbanes-Oxley Act was a critical step in addressing an unprecedented string of corporate scandals that were rooted in very serious governance, accounting and audit failures,” said SEC Chairman Christopher Cox in his opening remarks. Section 404 has […]

Out Catching Some Phishers!

Saturday, May 13th, 2006

After reading the PinoyTechBlog articles entitled Phishing: are local banks doing enough? and Phishers targeting local bank clients, I checked my SPAM folder and noticed a good number of Metrobank Phishing emails inside it. Even until today, I just got a new one. So, I decided to do a bit of Internet forensics.
I loaded […]

Information Security Absurdity

Thursday, May 11th, 2006

There is this article entitled the “Security Absurdity: The Complete, Unquestionable, And Total Failure of Information Security“. I read it in Slashdot with some really scathing commentary. It contains a really bleak description of the current state of Information Security.
It is time to admit what many security professional already know: We as security professional […]

Growing Diamonds for Better Information Security

Sunday, May 7th, 2006

There is this NetworkWorld article about an Australian research project that uses a technology to grow Diamonds to create more information secure fiber optic transmissions.
The technology, based on quantum cryptography, uses a diamond to produce a single photon of light to stop information being intercepted, according to Dr Shane Huntington, University of Melbourne scientist and […]

US Net Neutrality Bill

Saturday, May 6th, 2006

A NetworkWorld Article on a proposed Internet neutrality bill is currently being pushed in the US congress.
After failing last week to add a provision to a telecommunications reform bill, four Democrats in the U.S. House of Representatives Tuesday introduced a free-standing bill aimed at preventing broadband carriers from discriminating against competing Web content or […]

SANS Top 20 Internet Security Vulnerabilities

Tuesday, May 2nd, 2006

NetworkWorld has the article describing the SANS Institute releasing an update to its Top 20 Internet Security Vulnerabilities. This report is typically updated every season and this is the 2006 Spring Update for the Top 20. Here are the new findings:

Rapid growth in critical vulnerabilities being discovered in Mac OS/X including a zero-day vulnerability. This […]