Securosis Blog

Incite 5/21/2014: Recitals

Mike Rothman · May 21, 2014

As we get into late May it is getting to be summer in the ATL. The kids finish up school this week, the pools open, and my standard work attire consists of shorts, a T-shirt, and flip flops. The Boss is frantically getting the kids ready for camp, and we have a few family trips planned before they leave.

We apologize for the quality of this week’s show… but Rich is on the road and can’t seem to understand the word ‘bandwidth’. Assuming you are willing to put up with us, watch us amuse ourselves over FBI wanted posters with Chinese army members on them. Then we debate the sometimes-sorry state of 95% of the 863 security cons in the world.

When Security Services Attack

Mike Rothman · May 20, 2014

In the unintended consequences file, it’s awesome when big honking devices to stop attacks get owned and blast other sites. Yup, the folks at Incapsula found a huge DDoS that was leveraging equipment from two (not one, but two!) DDoS protection services.

CEO on Line 2

Mike Rothman · May 19, 2014

It has been a couple weeks since Target’s CEO was fired. Maybe not officially fired, but for all intents and purposes that’s what happened. The data breach was the most visible reason, though as George Hulme points out that was really a red herring.

Friday Summary: May 16, 2014

Adrian Lane · May 16, 2014

It’s odd, given the large number of security conferences I attend, how few sessions I get to see. I am always meeting with clients around events, but I rarely get to see the sessions. Secure360 is an exception, and that’s one of the reasons I like to go. I figured I’d share some of better ones – at least sessions where I not only learned something but got to laugh along the way:

Incite 5/14/2014: Solo Exploration

Mike Rothman · May 14, 2014

Is it possible to like interacting with people, yet need time alone? To really enjoy working in a team, yet cherish a night of solitude? I have always defined myself as an introvert. It provided a convenient excuse when I just didn’t want to deal with people. Though I do need my solo time to recharge, that’s for sure. But I also need to be social. Not all the time and not for extended periods of time, but a life of solitude doesn’t really appeal to me either. It’s an interesting contrast.

A lot is going on in security land, so Rich, Mike, and Adrian return with another 3 for 5 episode. Three stories, five minutes each, all the sarcastic bite in a convenient package.

Summary: Thin Air

Rich · May 9, 2014

Rich here. A quick mention: I will run a security session at Camp DevOps in Boulder on May 20th. I am looking forward to learning some things myself.

Incite 5/7/2014: Accomplishments

Mike Rothman · May 7, 2014

Yesterday I was in Winnipeg. By choice! I was invited to speak at the Western Canada Information Security Conference, and there isn’t much I like better than giving talks in Canada. Folks are nice. They appreciate when you come up to their towns to talk. They don’t say much during the pitch, but they come up after the session or in the coffee line and make it clear that they were listening. Just like in the Northeast. OK, not so much.

Anti-virus is basically dead, at least according to the biggest anti-virus vendor. The good news is that signature-based AV has actually been dead for a long time; even the big players have been broadening their capabilities to assess, prevent, detect, and investigate advanced malware on endpoints and servers. There has been a tremendous amount of activity and innovation in protecting endpoint and servers, driven by necessity: