You don’t have to wait to deploy DNSSEC

Business Continuity, Cybercrime, DNS Security, Risk Management, Security, data theft Comments Off

A look at DNS security with a high-level examination of DNSSEC, why DNSSEC is still not globally deployed, and some things you can do to improve DNS transaction integrity until it is.

read more from this topic.....


No such thing as effective license enforcement

Security Comments Off

License security is not the same as software security. In fact, sometimes they are at odds with one another.

read more from this topic.....


Simple hardware approaches to secure laptops

Encryption, Risk Management, Security Comments Off

Users are increasingly buying laptops and netbooks, attracted by their portability and low prices. The inevitable result is more employees bringing personal laptops into the office, where they are used to access and store corporate data. Here are some ways to mitigate the risks of data breaches.

read more from this topic.....


DNS resource record integrity is still a big, big problem

Cybercrime, DNS Security, Internet, Risk Management, Security Comments Off

The need to secure DNS has never been greater. Attacks against DNS cache integrity, including entire zone references, are an easy way for criminals to redirect your unsuspecting users to malicious sites. Current controls are still lacking.

read more from this topic.....


Microsoft finally catches the eight year bug

News, Security, patching, vulnerability Comments Off

Microsoft released a patch this week for a critical vulnerability. The catch: this vulnerability has been known since 2000, and it’s a bug in a service active on almost every MS Windows system in the world. How safe do you feel?

read more from this topic.....


How do new private browsing capabilities affect forensics?

Computer Forensics, Privacy, Security Comments Off

Chrome has it. IE8 and Firefox 3.1 have it. So what does it mean to forensics investigators? I’m talking about private browsing–the ability to visit sites, conduct research, or participate in illegal/unethical activities without leaving tell-tale signs behind.

read more from this topic.....


More email security tips

Internet, Security Comments Off

Email security is about a lot more than just using a good password on your POP or IMAP server. Perhaps the most important part of email security is ensuring you don’t shoot yourself in the foot.

read more from this topic.....


Prevent your employees from “going rogue”

Business Continuity, Cybercrime, Intrusion Detection, Risk Management, Security, Security Awareness Training, Threats, data theft Comments Off

There is often a personal crisis trigger that causes an already borderline employee to cross the border. Would intervention prevent information compromise or system loss? Can an employee be helped in a way which prevents an incident?

read more from this topic.....


Security News Roundup: Security researchers to demonstrate WPA packet injection

Security, Threats, patching, vulnerability Comments Off

This week’s security events include news that there will be just two updates for Microsoft’s Patch Tuesday this month, of the appearance of an exploit for Adobe Reader spotted in- the-wild, Adobe releasing an update to resolve a ColdFusion vulnerability, and news that security researchers will demonstrate WPA packet injection for the first time.

read more from this topic.....


Security, complexity, and the GUI environment

Security Comments Off

As our computing environments grow more sophisticated, security suffers. It may be time to simplify, starting with the GUI environment.

read more from this topic.....

« Previous Entries