Securosis Blog

Class Action Against Express Scripts Dismissed

Adrian Lane · December 4, 2009

Jaikumar Vijayam has posted an article at ComputerWorld regarding the Express Scripts Data Breach class action suit. This is the case where, in 2008, Express Scripts received a letter demanding money from the company under the threat of exposing records of millions of patients. The letter included personal information on people covered by Express Scripts, including birth dates, Social Security numbers and prescription information. Many of the insured were seeking damages, and the judge has…

Friday Summary- December 4, 2009

Rich · December 3, 2009

I had one of those weird moments today where I found an unrelated part of my life unexpectedly influenced by my martial arts background.

Clientless SSL VPN Redux

David J. Meier · December 1, 2009

Let’s try this again. Obviously I didn’t do a very good job of defining what ‘clientless’ means, creating some confusion. In part, this is because there’s a lot of documentation that confuses ‘thin client’ with ‘clientless’. Cisco actually has a good set of definitions, but in case you don’t want to click through I’ll just reiterate them (with a little added detail):

I’ve been working with the Cloud Security Alliance on the next revision of their official Security Guidance document, and we decided to include a short note on risk in the beginning, to help add some context. Although we are deep in the editorial process, I realized this is the sort of thing I should put out for some public comment, as it’s at the beginning of the document and will help frame how it’s read.

Let the games begin.

It seems that Radiant Systems, a point of sale terminal company, and Computer World, the company that sold and maintained the Radiant system, are in a bit of a pickle. Seven restaurants are suing them for producing insecure systems that led to security breaches, which led to fines for the breached companies, chargebacks, card replacement costs, and investigative costs. These are real costs, people, none of that silly “lost business and reputation” garbage.

Sign Up To Drop Comment Moderation

Rich · December 1, 2009

We hate that we have to moderate comments, but the spammers are relentless and there’s no way we’ll let those jerks ruin our site.

Top Questions Regarding Guardium Acquisition

Adrian Lane · December 1, 2009

I spent about 8 hours on the phone yesterday discussing the Guardium acquisition with press, analysts, security vendors, and former associates in the Database Activity Monitoring space. The breadth of questions was surprising, even from people who work with these products – enough that I thought we should do a quick recap for those who have questions. First, for those of you looking for a really quick overview of Database Activity Monitoring, I just completed an introductory series for Dark…

Christmas Wish

Adrian Lane · November 30, 2009

When there is good news in holiday retail, we usually hear. In this economic climate, it’s headline news. When there is bad news, we don’t hear much. The news from PayPal, according to PC Magazine’s article on Record Breaking Black Friday, was that total transactions were way up – in some cases by 20%. What they are not disclosing is the total dollar volume. In fact, most of the quotes I saw from individual retailers are along the lines of “We did well”, but we don’t know how low their…

Like many of you, for a long time I really couldn’t see the use of those URL shortener service thingies. Sure, when I was designing sites I tried to avoid long, ugly URLs, but I never saw slapping some random characters after a common base URL as being any more useful. I considered my awareness of the existence of these obscure services as an aberration induced by my geek genes, rather than validation of their existence or popularity.

Serious Flaw in Clientless SSL VPNs

David J. Meier · November 30, 2009

Good job! You paid tens of thousands of dollars for that shiny new name-brand VPN, and then decided to deploy its web VPN functionality because, well, it was just easier than deploying software clients.