Pages

Friday, May 29, 2015

Third Party Vendors Are Your Weakest Links

We've all seen the issues, many of them disastrous, that companies have with third party vendors and it's something that the security community still needs to take seriously. If the Target breach wasn't engouh to wake you up regarding the control of your third party accounts, I don't know what is. You need to have policy in place that limits these accounts and the ability to monitor them as well as possible. In these two article I speak about ways to ensure network security when working with third party vendors.

Here are the two links:

Article 1 of 2
Article 2 of 2

Thursday, May 28, 2015

Infosec Pulp Fiction

Whoever made this meme deserves a slow golf clap. Well done, sir.


Wired Magazine on the Silk Road saga

Just finished reading the two part series from Wired Magazine on the Silk Road saga. Gotta say that this was a fine piece of work by Wired. It was an interesting read knowing a few people that were involved on both sides of this case. If you haven't already picked up the past two months of Wired Magazine (April and May) that review the case, I'd highly recommended it. Good read.

Here's the link to the first part (April).

Wednesday, May 27, 2015

Why Two Factor Authentication Is Important

We've seen so many hacks today that focus on stealing user credentials and using them to pivot or escalate in a network. In this article I explain where two factor authentication should be used and alternate methods of technology that are available to implement this protection. Two factor isn't just for big business, either. It's for personal use too.

http://blog.algosec.com/2015/05/two-factor-authentication-why-when-and-how.html

Monday, May 11, 2015

Thinking about purchasing a MDM solution?

In this article I write about six questions you need to ask yourself before purchasing an MDM solution. If you're considering MDM, already in a PoC, or have a system already installed, it might be helpful to determine if your MDM meets up to these six criteria. Let me know what you think and if there are other areas you think should be added to the list of recommendations.

http://searchsecurity.techtarget.com/feature/Six-questions-to-ask-before-buying-enterprise-MDM-products


Wednesday, November 19, 2014

The War Against Personal Privacy

With the recent revelation of FBI director, James Comey, attacking tech companies for allowing complete encryption on their mobile devices, we as citizens should be concerned with our liberty and freedom; not just our privacy. When a government official thinks we as a people should lower our security and privacy standards because it makes his job easier to catch criminals, we should all be on our guard. If this is the case, I might as well leave my home unlocked, because if I was to get robbed it would make it easier for law enforcement to enter my home and catch the thieves. This of course is ridiculous and there are ulterior motives involved that include snooping on American citizens. With recent allegations and court hearings being brought up against our government due to citizen snooping, it came as a surprise that Director James Comey would come out so boldly with these remarks. This to me shows that our government doesn't care about our privacy and are still barreling down the path of complete control, with limited oversight.

Privacy is liberty and when it’s slowly siphoned away from our individual rights, so is our liberty and freedom. This is something that’s been happening for decades, with the FISA courts, PATRIOT Act, NSA warrant-less surveillance, etc. and with each legislative power grab by the government, either under the guise of security, the fight against global terrorism, the protection of our children, we end up handing over more of our God given right that our founding fathers fought so hard to establish. James Madison understood these issues when he proposed the Bill of Rights into the constitution; he understood that an individual has rights that a government shouldn't be infracting upon and that by pillaging these rights away from citizens will weaken not only our individual freedoms, but our collective rights as Americans.     

Why does the government want us under such high surveillance? It might come as a surprise to some, but just because you’re a government doesn't automatically make you trustworthy. There have been multiple occasions in history where regimes have controlled their inhabitants by the ever seeing eye of surveillance. We must learn from these mistakes in history now, so that we don’t repeat them again for our generation and generations to come. Even if a government was doing something honorable with mass surveillance doesn't mean that over time it won’t change its ideologies for something more nefarious. Once power has been given, once control has been handed over, it becomes orders of magnitude harder to withdrawn and rein that authority back to what it once was. Governments are aware of this and are consistently using fear and uncertainty during times of crisis to influence the actions of lawmakers and citizens to snatch more power. The best trick a Government can play during a crisis is making its citizens believe that it was their idea to include mass surveillance.

Why, then, is Director James Comey terrified of encryption? This isn't a new thing either. The Government has had a long fear of encryption, not really a fear of cryptography, but a fear of not knowing is more of what they’re concerned with. This goes back to the early nineties when the Government threatened Phillip Zimmerman, an amateur encryption enthusiast, with potential prison time after creating PGP. Not only was he being threatened, but he was being charged for being an “arms dealer”. Is this what the Government see’s encryption as? A weapon?! Encryption isn't a weapon, it’s a shield and we as citizens have a right to protect ourselves from mass surveillance. It’s not a war against crime; it’s a war against personal privacy.