Friday, October 7, 2011

cyber protection rackets

from the knight life (thanks to anton chuvakin for tweeting it)

this is, no doubt, how some people view the security industry. it's not how i would characterize things, but it is in a similar vein.

(in)security glass

from there i fixed it

there's got to be a better way to secure that door than to (apparently) break the security glass windows so you can put a chain around the frames. maybe pulling that extension cord inside would allow you to actually lock the door properly instead of trying to use a bike security mechanism on a door.

it's bad enough we people try to use it on a car, but a door?

Thursday, October 6, 2011

protecting and serving

this seems to correspond to a line of merchandise on zazzle by liberty maniacs

with the nonsense that's been going on recently at the occupy wallstreet protest, as well as a few other instances in recent memory (toronto's G20 debacle stands out in my mind) it's hard not to question whether the motto "to serve and protect" has any meaning anymore.

which is not to say that i think we should get rid of police, but we seem to be witnessing one of the downsides to delegating our protection to a body of authority - abuse of power.

stopbadware stories

story telling is a memetic medium for the exchange of knowledge. not only are we prone to telling our own stories upon hearing other peoples (so we copy the story telling aspect), we also tend to copy the successful strategies those stories convey.

now i've told a security tale or two in my time, but the folks at stopbadware have created an entire site around the idea. if you're curious about how other people cope with security incidents or if perhaps you have a tale of your own to tell, go ahead a check it out.

Wednesday, October 5, 2011

infect evolve repeat

this silly little web game about viruses has been one of my favourite time killers for years now. go figure.

one of the ideas that gets bandied around in security circles is the notion that defenders need to think more like attackers. the argument being that defenders would be more successful if they could better anticipate how attackers act, what they target, and thus where our weak points really are.

i'd like to turn that on it's head and i think this game serves as a pretty good demonstration. i think we should examine the ways in which attackers need to think like defenders. they want their attacks to succeed so they need to do various things to defend their efforts. things like making their attack tools and techniques more immune to counter attack (immunity is one of the characteristics in the game that you can power up), or increasing the fault tolerance of their attack platform by adding redundancy (the game allows you to increase the reproduction rate of your virus so that your virus can become many viruses), or even reduce the window of exposure during which an attack is at it's most vulnerable (the latency characteristic in the game refers to how long your virus stays trapped within a cell where you can't move it out of the way when something dangerous comes near). these are the sorts of things one needs to think about in order to create or select effective countermeasures.

can you spot any more parallels between how attackers and defenders operate?

only you can stop spam on the internet

only you can stop spam on the internet
obviously a take off on smokey the bear and his "only you can stop forrest fires" message, but really it's just as true as the original.

if nobody bought merchandise from companies who engage in spamming then the spammers wouldn't get any money - and they're certainly not going to send those annoying messages for free.

do your part and spread the message. a failure by one of us has an impact on all of us.

Tuesday, October 4, 2011

malware papercraft

found on boing boing

this was apparently something put out by symantec, believe it or not. it's certainly a different approach to the topic of security awareness, but there's a tiny little gotcha - the link is broken. let this be a lesson to security vendors: don't move your shit around. leave it in one place so that people can continue to find it and benefit from it for a long time.

(it's not that surprising to me that a symantec link would go dead, though. the organization is so big that they easily run afoul of the 'left hand not knowing what the right hand is doing' phenomenon.)

anti-phishing phil


i originally heard about this through the stop badware blog but since then their link has gone dead and the project has been commercialized by wombat security. frankly, i think games are a really good way of teaching security concepts. they engage people in ways that other media simply can't.

Monday, October 3, 2011

cracking is easy

HACKING IS EASY! from Airwave Ranger on Vimeo.

found on boing boing quite some time ago if i could go in and rewrite the video to make it's terminology use better reflect what it's actually talking about, i would. you'll have to settle for blog title.

scareware localization fail

from here (original image found on the f-secure blog)

you'd think the people who made this would realize that the majority of the text is in english and at least one of the buttons (not sure about OK) appears to be in russian. oops. hopefully ridiculous errors like that helped people avoid getting infested.