I don’t cover industry issues here, but this is just too good to pass up.
Sanjay Kumar, former CEO of CA, is sentenced to 12 years and $8M in fines.
Now there’s something I need to admit here. Hopefully it won’t scare you courageous readers away. You see, as much as I (and fortunately, my employer) consider myself a security expert it wasn’t exactly my major. Nope, wasn’t computer science either. History, you ask? With a bit of molecular biology? Yep, you got it.
I’m linking to Jim at DCS Security- he has the best SCADA background in the blog community and hopefully he’ll dig into this particular hack a little more:
The first flaw isn’t all that interesting (affecting older PowerBooks, and only under certain conditions) but methinks November will be pretty darn interesting:
One of the great things about the Internet is that it allows isolated assholes to connect and communicate like never before. Thus Rothman and I, mere professional acquaintances and friendly faces at a few industry events, can engage in deeper dialog, dragging any of our loyal readers down with us. (Mike and I are the assholes, not you guys. Except maybe for Will). I like it when smart guys like Mike push me, it makes for better analysis.
Evilsquirrel Enterprises Announces North American Expansion
Leaders in world domination to expand geographic services.
Undisclosed HQ, USA, Oct. 31, 2006 – Evilsquirrel Enterprises, the leading provider of world domination services, announced today that they are leveraging their best-in-class international infrastructure to expand into the North American market. As the preeminent world domination specialists, enterprises now have a truly global provider offering unmatched services and support.…
There’s been a lot of hubbub the past couple of days over Christopher Soghoian posting a tool to let anyone print their own boarding pass. While I’m all for publicizing security silliness, I personally try and avoid things that might invite 2 a.m. non-social visits from the FBI.
Good security will almost always make you compliant (or pretty darn close, not counting all the documentation). Compliance alone will pretty much never make you secure.
The blogoshpere is kind of funny sometimes as we all run around referencing each other constantly, so you’ll have to excuse the “my sister’s best friend’s 2nd cousin twice removed’s boyfriends bookie” path for this post. (Actually, I really dig all our cross referencing, I think it creates a cool community of experts).
Jim over at DCS Security (a great new blog) just finished his last in a series of good posts on security layers.