if you overlook the threat represented by a 25 foot long missile because it has the word "viagra" painted on it then you might be a security idiot...
(inspiration)
Friday, June 19, 2009
Thursday, June 18, 2009
security fail redux

from epiclosers
yeah, so in case you didn't realize it, securing a car is a lot different from securing a bicycle. it's really important that your security strategy matches the asset you're trying to secure.
Wednesday, June 17, 2009
if nude pictures of your wife...
if nude pictures of your wife get leaked on the internet because you left your UNLOCKED iphone at mcdonalds, then you might be a security idiot...
(inspiration)
(inspiration)
Tuesday, June 16, 2009
risk management fail
from failblog
i don't think these guys are managing their risks very well, but for some reason i really wouldn't want to go over there and tell them that.
Monday, June 15, 2009
if you think a wireless protocol...
if you think a wireless protocol that can be cracked in seconds is good enough to protect credit card transactions then you might be a security idiot...
(inspiration)
(inspiration)
Sunday, June 14, 2009
security fail

from failblog
sort of like closing the barn door after the horses have escaped - locking this door has absolutely no benefit.
Tuesday, May 12, 2009
the security guy and the frog
a couple of years ago my boss came up to me and started spinning a tale... he told me to imagine i was walking along when all of a sudden i encounter this frog, but instead of just an ordinary frog this is a special frog because it talks... apparently the frog says that it wasn't always a frog and that if i kiss it it will be come a beautiful woman (not to mention other tempting suggestions)... so when my boss finishes this tale he asks me "would you kiss the frog?"... my answer?
the wording of the story makes it pretty clear that it's underlining the differences in values between the geeky engineer and a normal person (the engineer values a talking frog over a beautiful woman) but as i explained to my boss, my answer, my choice had nothing to do with those sorts of evaluations...
the reality is that it's not really a choice between a beautiful woman and a talking frog - if both were present at the same time then that would be the choice (and i would certainly choose the woman over the frog) - but in reality the choice is whether or not to believe the frog when it makes those promises... to me, kissing a frog for the promise of a beautiful woman is like giving up my passwords for a candy bar, it's a strategically bad move, and there are any number of ways it could backfire... the reality is that my answer (and the answer of any security guy worth his salt) comes from one place and one place only -
(*in fact, i don't trust much at all, and that's probably what gives me an edge over the average person with respect to security)
NOat this point he proceeds to tell me (and the others in the room) this humourous tale of the engineer and the frog, the punchline of which (with his telling of it at least) has the engineer saying "women are alright, but a talking frog is really cool!"... he got quite a chuckle out of my apparently being so similar to this stereotypical engineer in the story, and has brought it up in passing a number of times since then...
the wording of the story makes it pretty clear that it's underlining the differences in values between the geeky engineer and a normal person (the engineer values a talking frog over a beautiful woman) but as i explained to my boss, my answer, my choice had nothing to do with those sorts of evaluations...
the reality is that it's not really a choice between a beautiful woman and a talking frog - if both were present at the same time then that would be the choice (and i would certainly choose the woman over the frog) - but in reality the choice is whether or not to believe the frog when it makes those promises... to me, kissing a frog for the promise of a beautiful woman is like giving up my passwords for a candy bar, it's a strategically bad move, and there are any number of ways it could backfire... the reality is that my answer (and the answer of any security guy worth his salt) comes from one place and one place only -
i don't trust the frog*...
(*in fact, i don't trust much at all, and that's probably what gives me an edge over the average person with respect to security)
Wednesday, March 25, 2009
if you donate mp3 players
if you donate mp3 players full of military documents to thrift stores for the benefit of the less fortunate then you might be a security idiot...
(inspiration)
(inspiration)
Saturday, January 10, 2009
Facebook Privacy: Beyond The Blacklist 2 - Sandboxes
in the previous 2 articles on this topic (Facebook Privacy: The Limited Profile Blacklist and Facebook Privacy: Beyond The Blacklist - Whitelists) i discussed both selectively blocking access to certain things and selectively allowing access to certain things respectively... both of which have their place but both of which require a certain amount of trust in the person you're adding to your friend list...
if you participate in any of the social gaming on facebook then you know that the current game design du jour focuses heavily on rewarding the user for adding their facebook friends to the game... since it can be hard to find people amongst your real life friends who want to play the same games you do the easiest strategy for advancing in these games is to add strangers from within the game to your facebook friends list...
the social gaming is just an example, by the way, there are any number of reasons why you may be faced with need to add people you don't know well enough to call friend to your friend list and this can present a problem... how can you know the person is safe to add to your profile if you don't know the person yet? on the other hand, how can you get to know the person if you don't make a connection with them using the friend list?
it's a catch-22 situation but it turns out there is a solution which may or (as in my case) may not be obvious - make a second profile with nothing personal in it and connect to that person through this new non-personal profile... this non-personal profile is essentially a sandbox - bad things can happen with it and it doesn't matter because there is nothing sensitive, nothing of value in it... i don't just mean that you left out your real date of birth or your cell phone number or any of that stuff, it's also separate from your actual friends so if something bad does happen you won't be exposing them to any risk...
facebook may not like the idea of their users having 2 profiles a piece but they'll have to get over it because a sandbox profile fills a very important need - it gives users a tool with which they can build relationships from the very beginning, before knowing whether or not a person is trustworthy enough to add to their real profile, and without making the person jump through any hoops like getting to know each other via some alternate channel before adding them (i've done that, it's no fun being the difficult one)...
as i alluded to before, this was not an obvious strategy to me - which is a surprising considering i go on and on about the blacklist/whitelist/sandbox triad for malware protection - but it took a pair of ladies (laura ly and tammy vickery) to clue me in to this one... i suppose it shouldn't really be surprising, though... all things considered i actually would expect the fairer sex to have more experience protecting themselves from people online...
related posts:
Facebook Privacy: The Limited Profile Blacklist
Facebook Privacy: Beyond The Blacklist - Whitelists
if you participate in any of the social gaming on facebook then you know that the current game design du jour focuses heavily on rewarding the user for adding their facebook friends to the game... since it can be hard to find people amongst your real life friends who want to play the same games you do the easiest strategy for advancing in these games is to add strangers from within the game to your facebook friends list...
the social gaming is just an example, by the way, there are any number of reasons why you may be faced with need to add people you don't know well enough to call friend to your friend list and this can present a problem... how can you know the person is safe to add to your profile if you don't know the person yet? on the other hand, how can you get to know the person if you don't make a connection with them using the friend list?
it's a catch-22 situation but it turns out there is a solution which may or (as in my case) may not be obvious - make a second profile with nothing personal in it and connect to that person through this new non-personal profile... this non-personal profile is essentially a sandbox - bad things can happen with it and it doesn't matter because there is nothing sensitive, nothing of value in it... i don't just mean that you left out your real date of birth or your cell phone number or any of that stuff, it's also separate from your actual friends so if something bad does happen you won't be exposing them to any risk...
facebook may not like the idea of their users having 2 profiles a piece but they'll have to get over it because a sandbox profile fills a very important need - it gives users a tool with which they can build relationships from the very beginning, before knowing whether or not a person is trustworthy enough to add to their real profile, and without making the person jump through any hoops like getting to know each other via some alternate channel before adding them (i've done that, it's no fun being the difficult one)...
as i alluded to before, this was not an obvious strategy to me - which is a surprising considering i go on and on about the blacklist/whitelist/sandbox triad for malware protection - but it took a pair of ladies (laura ly and tammy vickery) to clue me in to this one... i suppose it shouldn't really be surprising, though... all things considered i actually would expect the fairer sex to have more experience protecting themselves from people online...
related posts:
Facebook Privacy: The Limited Profile Blacklist
Facebook Privacy: Beyond The Blacklist - Whitelists
Subscribe to:
Posts (Atom)