Securosis Blog

Friday Summary- January 23, 2009

Rich · January 24, 2009

Warning- today’s introduction includes my political views.

History

Whatever your political persuasion, there’s no denying the magnitude of this week. While we are far from eliminating racism and bias in this country, or the world at large, we passed an incredibly significant milestone in civil rights. My (pregnant) wife and I were sitting on the couch, watching a replay of President Obama’s speech, when she turned to me and said, “you know, our child will never know a world where we didn’t have…

How Much Security Will You Tolerate?

Adrian Lane · January 24, 2009

I have found a unique way to keep anyone from using my iMac. While family & friends love the display, they do not use my machine. Many are awed that they can run Windows in parallel to the Mac OS, and the sleek appearance and minimal footprint has created many believers- but after a few seconds they step away from the keyboard. Why? Because they cannot browse the Internet. My copy of Firefox has NoScript, Flashblock, cookie acknowledgement, and a couple of other security related ad-ons. But…

You’ve probably noticed that we’ve been a little quieter than usual here on the blog. After blasting out our series on Building a Web Application Security Program, we haven’t been putting up much original content.

Brian Krebs of the Washington Post dropped me a line this morning on a new article he posted. Heartland Payment Systems, a credit card processor, announced today, January 20th, that up to 100 Million credit cards may have been disclosed in what is likely the largest data breach in history. From Brian’s article:

Friday Summary - Jan 16, 2009

Adrian Lane · January 16, 2009

It has been a very trying week, between all our current projects- both Rich and I have had untimely home repair work, Rich is recovering from the flu, and we are both scrambling to get work done before deadlines. We have been focused on a series for security spending justification, which we will be mostly posting in blog entries. This is one of the tougher projects I have ever worked on, especially when your goal is to provide pragmatic advice that does not require dusting off calculus. While I…

It’s just Martin and myself on the podcast this week. Originally Martin sent out a bunch of stories and we figured, knowing our verbosity, that we would only get through about 3. But totally against our normal natures we managed to roll through them with nary a non-sequitur.

Oracle January 2009 CPU

Adrian Lane · January 14, 2009

Just finished a review of the Oracle January 2009 Critical Patch Update/advisory (CPU).

There are two issues that you need to pay attention to with this release: If you are using Oracle Secure Backup or Weblogix Server plugins, you will want to download and patch ASAP. Here is why:

Phil Collins is the Mel Torme of my generation

Adrian Lane · January 13, 2009

This post is deeply off topic, has nothing to do with security, and everything to do with my personal realizations about music.

While not on the scale of Amex or BusinessWeek, I just find this one amusing.

Paris Hilton’s official website was hacked and is serving up a trojan (the malware kind, not what you’d expect from her*). From Network World:

Friday Summary - January 9, 2009

Adrian Lane · January 9, 2009

Here it is, our first Friday Summary of 2009. While it’s Adrian’s week to put the summary together, we thought it would be better if I handled the intro since I was at Macworld looking at cool stuff all week while he was manning the fort and cleaning my gutters (if he ever reads his employment contract, I’m totally screwed).