Please wait while the page is being loaded Skip this advertisement >
Saturday | 22 November, 2008
ARN

Security: Opinions

Opinions
  • +

    A resurgent Denial of Service threat emerges 11 June, 2008 19:12:24

    Something new might be emerging from the underground.
    A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack.
  • +

    Silence of top security voices a cause for concern 27 May, 2008 14:35:36

    Two of the top Web Security researchers have admitted that as their businesses grow, they will be reporting and sharing less.
    Remaining platform and technology agnostic in Information Security is a progressively more difficult task as people and companies develop the skills and abilities to form professional fee-based relationships with the vendors that they previously reported about.
  • +

    How not to solve the Disclosure Dilemma 27 May, 2008 16:18:41

    When ignored by your company, publicly disclosing security weaknesses can get you fired.
    Following TJX's major loss of credit card data last year, the company implemented a series of internal changes that were meant to make it more difficult for theft to take place again in the future. The only problem was that the implementation was not exactly ideal and at least one TJX employee identified this and made an effort to report the situation internally. When faced with no response from the company, he chose to release the information publicly.
  • +

    When selling snake oil catches up with you 26 May, 2008 09:05:05

    InfoSec experts, law suits regard Identity theft protection services as nothing more than a sham.
    Recent reporting from AP and The Charleston Gazette demonstrates that selling snake oil will eventually catch up with you. LifeLock, an identity theft protection company based in Arizona, is facing a class-action lawsuit alleging that their services are 'inept' at preventing identity theft from taking place.
  • +

    Notes from AusCERT 2008 26 May, 2008 11:34:08

    The interesting discussions from the Australian security conference
    I've had the pleasure of speaking and attending this year's AusCERT 2008 security conference held in Gold Coast, Australia. If you've never been to Australia, you're missing some of the best that life has to offer, and I feel the same way about the conference. Although a bit smaller than most US security conferences, it's intentionally kept small (around 1,000 participants) and makes up in quality speaker presentations and vendor participation what it lacks in headcount. One of the great attributes of the typical Aussie is their aversion to marketing hype, along with their ability to "cut the fat off a chicken" (as my grandmother used to say) and pull out the salient points. If a vendor tries to push marketing fluff about their product too much, they are likely to get verbally assailed rugby-style. Here are some of my favorite notes and quotes from selected speakers:
  • +

    This Site is Safe from Hackers. Is it really? 19 May, 2008 15:50:28

    Information Security Experts are voicing their opinions about the significant drawbacks and outright misleading marketing associated with tools like ScanAlert and SiteAdvisor.
    Antivirus and antimalware developers have been in the spotlight for the last month or so and have been the focus of malware developers for much longer over the plan to run the Race to Zero contest at this year's DefCon in Las Vegas. Now, it might be the turn of companies that produce and promote 'This Site is Safe from Hackers'-style certification and coverage for their clients to share the spotlight.
  • +

    How to avoid the Debian SSH key attacks 16 May, 2008 08:35:57

    It only took two days, but viable, simple attacks against the weak Debian SSH key generation flaw have surfaced
    If you are running a Debian-based Linux system and haven't already caught up with the announcement [1] that there was a major flaw with the generation of SSH, OpenVPN, DNSSEC, SSL/TLS session keys and X.509 certificate key material, you might want to update your system to address the problem.
  • +

    System hardening effective weapon against unknown security threats 12 May, 2008 15:11:04

    System hardening the InfoSec specialist's greatest weapon.
    Many Information Security practices have outcomes that are difficult to quantify. How do you prove that your measure is effective at preventing whatever malicious activity is out there from being effective against your system?
  • +

    Recovering PDF redaction 09 May, 2008 10:08:57

    PDF redaction exposed by security researcher.
    Unintentional exposure of sensitive data through Word files is a has caused problems for companies in the past, especially when people forget that Track Changes can easily allow document recipients to view information that has been deleted or sanitised for release.
  • +

    The cost of convenience 07 May, 2008 12:24:37

    Moving online makes life easier but is increasingly fraught with danger
    I had to go to the bank recently for the first time in months and, although it was the day before a public holiday, I was still amazed to see how many people were queuing up to talk to a teller. It felt like I'd stepped into a time warp.
  • +

    7 dirty secrets of the security industry 02 May, 2008 09:21:59

    Insider tells Interop attendees what to look out for.
    Corporate IT executives need to beware the seven dirty secrets of the security industry that can undermine the safety of business networks, a security expert told attendees at Interop Las Vegas.
Additional Resources
ARN Library
Videos
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN News
Play
Channel Watch
Play
Newsletter Subscription
Sign up for our ARN newsletters!
RSS Feeds
Polls

Is Acer justified in raising its prices by 25%?

Yes
No
View Results
Market Place
 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Bankstown Council streamlines their IT with Microsoft® Windows Server® 2008

Deciding it was time for more streamlined operations, Bankstown Council teamed up with OSS Infotech, a Microsoft Gold Certified Partner. The solution included Microsoft Windows Server, Microsoft SQL Server® and Microsoft Exchange®.

Sponsored Links