Securosis Blog

Shipping Decent Breach Notification

Mike Rothman · August 25, 2014

Many folks have strong opinions about the right way to perform breach notification. More to the point, many folks think they know what not to do. But that’s okay – the great thing about opinions is that everyone gets their own. Recently the UPS Store, a franchised chain of shipping stores, reported a breach.

Friday Summary: STEM

Rich · August 21, 2014

A few days after returning from DEF CON my family experienced an inevitable life-changing event you cannot really prepare for.

Incite 8/20/2014: Better get a Bucket

Mike Rothman · August 20, 2014

So I am finally home for a few weeks, coinciding with the kids starting school. As usual I grab my messenger bag first thing in the am and head out on my nomadic journey. With about 10 local Starbucks with Google WiFi, I am typically in one of those. I get faster Internet at Starbucks than I do at home (57mbps down FTW). It does make me a little more predictable, so that’s a bit alarming. But I’ll trade 50mb downloads for the anemic DSL speeds of AT&T WiFi every day of the week.

APT hits the ER

Mike Rothman · August 19, 2014

Everyone wants to be special. When I’m chatting with a company that doesn’t fit the typical profile for a state-sponsored attacker target, sometimes they seem disappointed. I certainly don’t mean to hurt their self-esteem, but the reality is that most businesses just don’t have anything of interest to a nation state.

CISO’s Head Asplode

Mike Rothman · August 18, 2014

Just in case you felt it was only you as the CISO who had an overwhelming amount of stuff to do, it’s not. This mind map on the Security Advisor Alliance site should bring that message home.

After our little Black Hat and DEF CON induced hiatus, the boys are back to talk about the latest vendor suing Gartner. Yes, there is a Gartner Tax. No, it isn’t what you think. No, there is no pay for play. Yes, there are better ways to handle this. Yes, end users love Magic Quadrants no matter how much you trash talk them. And yeah, somehow we know a bit about how all this works from all sides.

21st Century Shakedown

Mike Rothman · August 15, 2014

Over the past year or so we have done a bunch of research into denial of service attacks, at both the application and network levels. Tactics are one thing, but we usually start with adversary analysis. You know: who wants to pop your environment and steal your stuff. Or maybe just knock you down so you can’t get up.

Friday Summary: August 15, 2014

Adrian Lane · August 14, 2014

Oddly enough my big takeaway from the Black Hat security conference was not about security – it was about innovation. It seems many of the disruptive trends we have been talking about are finally taking hold, finding mainstream acceptance and recognition. We have been talking about cloud computing for a long time – Rich has been teaching cloud security for four years now – but people seem to be really ‘getting’ it. It takes time for the mainstream to fully embrace new technologies, and only…

It’s not a problem until someone dies…

Mike Rothman · August 14, 2014

One of the noteworthy activities coming out of BlackHat/DEF CON was the open letter to the auto industry from I am the Cavalry espousing 5 principles for making the computers in cars safer – before someone gets hurt. As our pal Josh Corman says in a CSO article on the initiative:

Incite 8/13/2014: Butterflies

Mike Rothman · August 13, 2014

A couple weeks ago we went to see the kids at camp on visiting day. They have so much fun, learn new skills, and grow as individuals at camp – despite being away from the watchful eyes of their parental units. Go figure – let your kids spread their wings, and they do. One of the new skills both XX2 and the Boy tried out was waterskiing. So during visiting day they get to show off for the folks.