I’m out in Boston for the SOURCE conference where Hoff and I just presented on Disruptive Innovation and the Future of Security. It went well, but we’re only giving ourselves a 6 out of 10. We tried to stuff in too much content and didn’t focus as much as we should. We’ve already mapped out the next version and I wish we were giving it before June (our next scheduled show).
I was reading an article by Rsnake this morning on the problems of using a username as a primary key, and it reminded me of something I’ve been meaning to write about for a while.
I’m pretty excited about speaking at the Source conference in Boston next week, despite the expected 6 hours of agony while flying with this damn shoulder.
I thought it was a slow news week, but once we got recording there was a heck of a lot to talk about this week. Martin and I spend a little time on two hardware-based attacks- a bit of a redux on the cold boot encryption attack, and discussion of the firewire Direct Memory Access attack. Seems like your RAM is taking a beating these days. We update the WikiLeaks coverage and Martin spends a little time on PCI.
In my last post on the DLP side of information-centric security, Adrian rightfully dropped a comment criticizing my narrow view. Since this is something he’s been talking about himself, I feel I owe a little clarification. I only meant that post to reflect how a portion of information-centric security technology will evolve; the truth is it’s much broader than that.
Remember that cold boot encryption attack we talked about last week? Looks like someone went out and released a public tool that replicates part of the functionality of the Princeton tool. I thought it would take a little longer; guess I was wrong. Does this change my advice? Not really- your best bet is still to maintain physical control of your laptop, and the odds are still pretty low you’ll have to deal with this in the real world. But keep asking your vendors how you need to configure your…
Over the past couple of weeks Mike Rothman has been posting his Security Incites, a series of predictions for 2008. Prediction number 9 was titled, “Get the Jumper Cables for DLP”, and I, of course, have to disagree with at least some of it.
This week, our question is courtesy of Allen:
… As a long time Mac user and an inspiring security professional (i am in the process of completing my CISSP certification), I found this article on Macworld’s web site to be very fascinating. If you could please comment on this on your web site and/or on your podcast would be very grateful.
It seems that every time I write the next part of this multipart series I find myself apologizing for taking too long between posts. I swear I have a good excuse this time- with the whole doctor sticking cameras into my shoulder, shaving out bits, cutting tendons and tying them to new places, putting in plastic anchors, and sewing torn parts of muscles together thing. I’m 11 days into my recovery and while the days are fine, despite learning not to use my arm for the next three months, the…
Today, Mark Curphey posted about Tenets of Effective BPM. He lays out five high level principles for doing business process management. This is really great stuff. It’s so good, in fact, that I’m going to quote a huge chunk of his post here: