Saturday | 5 July, 2008
ARN

Security: Opinions

Opinions
  • +

    EU struggles with diversifying technology 24 June, 2008 15:41:51

    Heterogeneous provide their own headaches for security professionals.
    In the immortal words of the Young Ones "[A] social conscience is like a garden shed. If you try to eat it, it will stick in your throat!". At least that is the lesson that the EU seems to be learning [1] in its efforts to promote greater competition in the technology industry as it tries to implement the use of alternate (to Microsoft) office software and operating systems that adhere to open standards.
  • +

    Chinese financial systems begin hardening 23 June, 2008 13:43:39

    China's financial regulators are taking steps to shore up financial systems.
    China's financial markets have paralleled the rapid growth and development of the country and for a time were regarded as something of a 'Wild West' environment, where the risks were significant but the rewards were immense. Rapid growth in cities like Shanghai and the handover of Hong Kong and Macau have provided ample opportunities for investment and the development of a form of capitalist communism has created an environment where the potential rewards seemed to justify the risk.
  • +

    When weak web security can expose medical records 16 June, 2008 10:46:17

    What happens when a networked system to view and manage medical records has critical weaknesses.
    With recent reporting showing the ineffectiveness of breach disclosure laws on the rate and scope of data losses, what sort of teeth will HIPAA and similar laws have when electronic health records are compromised in similar numbers and scope.
  • +

    Is data loss compensation unfair? 13 June, 2008 15:39:36

    Jericho has spoken out against the poor standard of compensation to consumers affected by businesses losing their data.
    A well known Information Security researcher who is best known for his recent work in collating and archiving reports of the often-inextricably linked forerunner to identity theft, data loss, has recently spoken out against the seemingly poor standard of compensation generally offered by the affected companies to their consumers.
  • +

    A resurgent Denial of Service threat emerges 11 June, 2008 19:12:24

    Something new might be emerging from the underground.
    A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack.
  • +

    Silence of top security voices a cause for concern 27 May, 2008 14:35:36

    Two of the top Web Security researchers have admitted that as their businesses grow, they will be reporting and sharing less.
    Remaining platform and technology agnostic in Information Security is a progressively more difficult task as people and companies develop the skills and abilities to form professional fee-based relationships with the vendors that they previously reported about.
  • +

    How not to solve the Disclosure Dilemma 27 May, 2008 16:18:41

    When ignored by your company, publicly disclosing security weaknesses can get you fired.
    Following TJX's major loss of credit card data last year, the company implemented a series of internal changes that were meant to make it more difficult for theft to take place again in the future. The only problem was that the implementation was not exactly ideal and at least one TJX employee identified this and made an effort to report the situation internally. When faced with no response from the company, he chose to release the information publicly.
  • +

    When selling snake oil catches up with you 26 May, 2008 09:05:05

    InfoSec experts, law suits regard Identity theft protection services as nothing more than a sham.
    Recent reporting from AP and The Charleston Gazette demonstrates that selling snake oil will eventually catch up with you. LifeLock, an identity theft protection company based in Arizona, is facing a class-action lawsuit alleging that their services are 'inept' at preventing identity theft from taking place.
  • +

    Notes from AusCERT 2008 26 May, 2008 11:34:08

    The interesting discussions from the Australian security conference
    I've had the pleasure of speaking and attending this year's AusCERT 2008 security conference held in Gold Coast, Australia. If you've never been to Australia, you're missing some of the best that life has to offer, and I feel the same way about the conference. Although a bit smaller than most US security conferences, it's intentionally kept small (around 1,000 participants) and makes up in quality speaker presentations and vendor participation what it lacks in headcount. One of the great attributes of the typical Aussie is their aversion to marketing hype, along with their ability to "cut the fat off a chicken" (as my grandmother used to say) and pull out the salient points. If a vendor tries to push marketing fluff about their product too much, they are likely to get verbally assailed rugby-style. Here are some of my favorite notes and quotes from selected speakers:
  • +

    This Site is Safe from Hackers. Is it really? 19 May, 2008 15:50:28

    Information Security Experts are voicing their opinions about the significant drawbacks and outright misleading marketing associated with tools like ScanAlert and SiteAdvisor.
    Antivirus and antimalware developers have been in the spotlight for the last month or so and have been the focus of malware developers for much longer over the plan to run the Race to Zero contest at this year's DefCon in Las Vegas. Now, it might be the turn of companies that produce and promote 'This Site is Safe from Hackers'-style certification and coverage for their clients to share the spotlight.
  • +

    How to avoid the Debian SSH key attacks 16 May, 2008 08:35:57

    It only took two days, but viable, simple attacks against the weak Debian SSH key generation flaw have surfaced
    If you are running a Debian-based Linux system and haven't already caught up with the announcement [1] that there was a major flaw with the generation of SSH, OpenVPN, DNSSEC, SSL/TLS session keys and X.509 certificate key material, you might want to update your system to address the problem.
Additional Resources
ARN Library
Videos
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN News
Play
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
Delivered Monday, ARN Security is the only channel-specific weekly security service dedicated to the Australian IT channel.
RSS Feeds
Polls

A recent Yankee Group survey in the US found that eight out of 10 companies are running Macs. Do you have any in your business?

Yes
No
View Results
Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Australian water treatment company uses four GFI products to protect its network

OSMOFLO, an Australian company, implemented a suite of four GFI products to protect its network from viruses and spam, to monitor and control internet usage and to save time and money on faxing.

Sponsored Links