Securosis Blog

Yes, it’s one of those weeks, with two webcasts and a conference (SANS Pen Testing and Application Security in Vegas).

This Tuesday I’ll be giving a webcast for RSA on encryption and key management. It’s heavy on the data center side; focusing on SAN/NAS/Tape, Databases, and Applications. Not much discussion of mobile or email, but a bit of file and folder (server based).

Kevin Poulson over at Wired reports that a new National Journal report claims that Chinese hackers may have been responsible for a recent power outage in Florida and the big 2003 northeast blackout.

When To Layer Encryption

Rich · May 28, 2008

Sorry for the general lack of updates the past few days, but I managed to get sick while down in Mexico for a friend’s wedding. No, not that kind of sick, just some flu I picked up from one of the many children running around. Aside from setting me back at work, it makes me a bit sad since my copy of Wii Fit showed up while we were gone and I’ve been too out of it to start my Nintendo-inspired workout regimen. Yeah, I’m just that geeky.

This week we had a special guest on the podcast, Adrian Lane from IPLocks and the Information Centric Security blog. We spend some time talking about the latest security news, then dive deep for a bit into information-centric security, one of our favorite topics.

It appears people are recovering data off old iPhones. Whoops- looks like you can pull data out of memory using forensics tools, just like any other platform. While your Mac includes the ability to overwrite old data when formatting your hard drive to prevent recovery (very cool that this is included in a consumer operating system), there is no equivalent mechanism to clear off that “ancient” original iPhone when you trade up to the 3G version next month.

Tomorrow I’ll be giving a free webcast through SANS on Understanding and Selecting a Database Activity Monitoring Solution. Here’s the description:

One of the most under-appreciated aspects of DLP solutions is content discovery- scanning stored data to identify sensitive content, classify information, and (in some cases) even protect the data. Major DLP tools have long evolved past just scanning network traffic for credit card and Social Security Numbers.

The Two Laws Of Rootkits

Rich · May 19, 2008

I loved Mike Rothman’s title to his take on the Cisco IOS rootkit (original article here).

What about “everything is vulnerable” didn’t sink in?

Don’t Drop That Landline

Rich · May 15, 2008

Engadget is reporting some stats that households are increasingly dropping their landline phone service for mobiles only. For safety reasons, I highly recommend against this.