Tuesday, August 30, 2011

if you think less crypto..

if you think less cryptography will result in more security, you might be a security idiot.

(inspiration)

yo dawg, we herd u like spying...

from here (original tweet here)

who contracts with a company from a foreign land to perform their spy-craft for them? would the US hire a russian or chinese company to build their spy tools? i don't think so.

Monday, August 29, 2011

if you think a man-sized candy bar...

if you think a man-sized candy bar advertising prop looks like a suspicious package that needs to be reported to authorities then you might be a security idiot.

(inspiration - hat tip to paul ferguson)

IDS vs IPS

from dan glass' G+ post

not a bad representation of the relative effectiveness of intrusion detection systems and intrusion prevention systems at protecting your stuff.

although, when you get into details like why there's a difference between them, it actually doesn't have anything to do with the size of the dog or the size of the fight in the dog (or anything similar or analogous). if an intrusion detection system could say unequivocally that the thing it's detecting should be stopped then it's really not that hard to stop it - it's coming up with the accurate classification of badness in the first place that's hard.

Friday, August 26, 2011

reinforcing the security = inconvenience stereotype

Dilbert.com from dilbert.com

i see no reason why security HAS to be inherently inconvenient, but i know it often turns out to be that way.

i don't always try out new software

from here

this is just something i thought up during one of those rare moments when i was actually trying out a new piece of software, and that really is how i do it.

Thursday, August 25, 2011

green eggs and DRM

from virtual shackles

aside from having a soft spot in my heart for dr. seuss, i think this displays a couple of important points about DRM. not only how it's an anti-consumer technology that works against the users' interests, but also how people often don't care if they're given a compelling enough reward for abandoning their interests. sort of like people giving up their passwords for a candy bar.

if you ruin people's lives..

if you ruin people's lives and tear apart families over a problematic self-serve checkout then you might be a security idiot.

(inspiration, if you can call this story inspirational)

Wednesday, August 24, 2011

perspective

from sinfest

in actuality this is the first part in a 6 part story arc that delves into the topic of sensitive info and the need to keep it confidential (part 1, part 2, part 3, part 4, part 5, part 6). strangely enough it has kind of a happy ending, not unlike the revelation that hbgary wound up benefiting from the attack by anonymous. go figure, i guess there are bigger things in this world than just security.

problem phone support scammers?

from memebase after dark (where they use the naughty words)

i'm sure eventually the scammers who call you up and trick you into giving them remote access of your machine (they're like the manual version of scareware) will figure out a script for exploiting mac users too, but as far as i know right now they assume you've got a pc. i suppose you could always lie to them and tell them you have webtv.