Securosis Blog

The Five Laws Of Data Masking

Rich · January 24, 2008

Tomorrow I’ll be giving a webcast over at ZDNet (sponsored by Oracle) on the Top 5 Database Security Resolutions for 2008. The resolutions have changed a bit since I first posted about them over here, and I decided to swap in data masking for the last one. I almost pulled it back out after I found out my sponsor (Oracle) just released a data masking product (I try to avoid being too promotional in my webinars), but it’s something I’ve been talking about for a while and it’s too important to…

Over on BoingBoing, Cory Doctorow is doing his best to raise awareness of data breaches in a post entitled, “Database leaks are as immortal and toxic as nuclear spills – let’s start acting like it”.

Supervisory Control and Data Acquisition systems are the technology connection between control systems and the switches, pumps, and motors that run our automated physical world. SCADA is the basis of everything from power plants to train systems. It’s also one heck of a security risk.

Remember the good old days when vulnerabilities would just affect one platform? Back when there was NO WAY my Commodore 64 could be infected by your TRS-80?

Security professionals seem to have a strained relationship with Apple these days. Any trip to a security conference shows that more and more security professionals are using Macs on a regular basis. A not-insignificant percentage of the high-end industry types I know shows they all use Macs and iPhones; at home if not at work, often against corporate policy.

Just a quick note-

Yesterday, Apple released a QuickTime patch to cover a couple of vulnerabilities, but this does not patch the new RTSP flaw revealed last week.

Macworld Keynote Impressions

Rich · January 15, 2008

Just finished up attending the Steve Jobs keynote for the first time. From a security perspective, as expected there wasn’t anything worth noting. Being a product-launch event we really weren’t planning on seeing any discussion of security, and the other updates don’t seem to have many obvious security ramifications.

From the Breach Blog:

Victims: “wealthy investors” Number Affected: 200 Types of Data: Financial details Breach Description: A box containing sensitive paperwork related to 200 wealthy investors was found on the side of the road near Reading in Berkshire (UK). The box was in transit from a Prudential building in Reading to a secure storage facility in Essex when it apparently fell out of the DHL courier van. Among the 200 wealthy investors that were affected were three UK national lottery…

This morning, database security company Sentrigo released some results from in informal survey they performed at a series of Oracle User Group meetings.

Marathon Down, Macworld Up

Rich · January 13, 2008

Okay, it was only a half-marathon, but considering I hurt my knee and wasn’t able to train for a month I feel pretty darn good about finishing. In my head that is; legs aren’t quite as pleased.