Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Jan 23, 2009

Downadup aka...

... Conficker.


It's the name of the latest and greatest evil to daunt Windows computers. Just ask the British DOD, Hospitals, a couple Million people what they think about it and you're likely to be smashed in the face.

Living in a German country and thus speaking the language does permit me to draw a smile every time I read another news about the Conficker.

he's sneaky - link
he's nasty - link
he's everywhere - link
he's skilled - link


n.-

Oct 31, 2008

I was listening to PaulDotCom.com's podcast n.127 and there was a very quotable note:

"Many say that security is a 3 legged stool: Secure, usable, cheap - pick two"

Kinda got me thinking.

n.-


Sep 1, 2008

give me please, 10 minutes of Mikko Hyppönen...



"Mikko Hyppönen discusses the various motives of Crimeware in a follow up to Re:solution."


n.-

Aug 30, 2008

Can you make it easier to understand please?


It's the question nobody really asks when I try to explain Security concepts & best practices.

Analogies
are still the best way to achieve good results.
Don't worry, I don;t think you're stupid! It's just not easy to understand a new subject like IT Security. It's complex, technical, political, sensitive...

Heck, as professionals, we all had to get those concepts in our own head until we just snapped our fingers as we achieved enlightenment!

Sometimes, some people are able to put take real life situations and transpose them for easy understanding.

Here's a very good example - City buses are like desktops.


n.-

Jul 23, 2008

another techy post


The Pwnie Awards nominees are set. My personal favorite being Windows Vista for proving that security does not sell in the the Pwnie for Most Epic FAIL category:
  • The good thing about the Vista debacle is that no other vendor will care to do such a security push, which means that we'll be able to easily own any piece of software for the foreseeable future.

Other than that, the Bloglines Beta news aggregator has been on my RSS reader benchmark ever since Valerie told me about it - great interface, good for reading fast through the news.


n.-

Jul 20, 2008

I never thought a smartphone could be all a "connected" person would need

picture obtained from a gizmodo article

I've been living with a Smartphone ever since I joined Microsoft. On a personal and professional level, it's a fab device, small, charges quickly, great autonomy, best Contact Search I ever experienced...

As a professional, such a device should be able to hold all I need to do my work. It just stinks to use its super small keypad and screen. And this is where a laptop-looking smartphone terminal comes into play - the Redfly.
"... with a large screen and full keyboard with no OS, no CPU, and no storage that lets you use your smartphone like a laptop. REDFLY links to your smartphone via a USB cable or wireless Bluetooth connection... "

After reading a Dark Reading story about how this solution could simplify network security management with mobile devices, I reckon its value in its worst-case scenario - the now soooooo popular lost laptops:
  • once a mobile device gets lost, the device data encryption will keep data safe and ultimately, wipe out features based on repeated wrong passwords or remote command from a server, will keep data definitely clear of malevolent hands. Laptops have similar features too, but how much easier are these features to implement and manage?

499$USD is a high price... (more expensive than the ASUS eee PC 900) but its features balance this negative side: 8hrs autonomy, weighing 1kg, small as it is, allows to recharge the smartphone...

I loved the concept. Wishing to lower the amount of tech hardware needed to perform what I need/want to, this would one way to accomplish it without relying on pure low-tech brain memory and paper sheets to burn after every information write-down.

By the way, how can anyone lose a laptop? I know I have a bad memory, but I never even managed to lose my umbrella ever since I bought it 5 years ago. I do love my Terra cotta Knirps umbrella! Could love be the reason for this prowess? "Love thy laptop and ye shall not lose it"


n.-

Jul 19, 2008

those nasty spammers


The screencap is from a really cool video from the dutch IT Security bureau - www.waarschuwingsdienst.nl.

F-Secure mixed its reporting data with Google Earth. The results? A world map with the reported SPAM (and malware) originators... and let me tell you, it looks reaaalllyyy coooollll!!!
The article - link.

The video:


Besides that, there are some online reports that look more like movie scripts than malware gang reports:


As always, be aware

n.-

Jun 9, 2008

IT-Sec updates...

There has been so much going on, on the IT Security front.

F-Secure shows in a rather simple way how an Adobe Acrobat Reader vulnerability can be used - link
... and they even show how to create such malicious PDFs (considering you got the tools) - link
(links obtained from RHensing's post - here)

Microsoft warned about an Apple Safari for Windows issue - link
... but then a researcher wrote that the issue is just the tip of the iceberg and an IE/Windows vulnerability can be used to propel the issue even further - link

Adobe, according to RHensing, is just increasing its attack surface, almost "just for the fun of adding cool features" by allowing Javascript, and in the future, Flash data to be embedded into PDFs... just great... - link

Kaspersky calls for help to beat a new RansomWare's encryption key, it's REALLY nasty when a virus just encrypts YOUR data, making it unreachable/unreadable and asks for a ransom to decrypt it back - link1 - link2

Some genral simple concepts:
- Adobe Acrobat (Secunia link) as well as Adobe Flash (Secunia link) player from a security point of view, are widely known as swiss cheese ie. have lots of security vulnerabilities, they're always in the (secuurity) news aren't they?
- F-Secure and Kaspersky are top-notch AV vendors (no wonder that several banks propose their customers a discount for products of these two vendors)


n.-

PS: This post's picture was taken from Stuart King's blog post on Computerweekly - link
PPS: I am still... working on trackbacks... my apologies to the affected people

May 28, 2008

"we already knew that..." said the experts

I was just updating my little list of AV and IT-Security sites I should keep an eye on and stumbled on the Sunbelt BLOG post and this fun list:
  • spywarequarantine.com
  • xpprotectionsoftware.com
  • xpdownloadcenter.com
  • antivirus2008pro.info
What is this? Just port of a bigger list of rogue anti-malware sites where you can download the software for free.

Boys and girls, don't trust everything nor everyone...


n.-

PS: you probably shouldn't trust me either.