Posts

Showing posts with the label security

Microsoft's Ten Immutable Laws Of Security [GENERAL SECURITY STUDY]

A few years ago when I was working at Microsoft they released a paper titled Ten Immutable Laws Of Security. It looks as if they have made some updates to this as it is now titled Ten Immutable Laws Of Security (Version 2.0) Whether you are a security specialist, a systems administrator or simply an end user of computer systems I believe this is a great read. I have often referred back to it when dealing with customers that desperately needed assistance in developing their own security standards in their own environments. I have also suggested a review of this for folks that are studying for their Security+ and / or CISSP exams as well as it allows for a good base of understanding.

The differences between Symmetric and Asymmetric Encryption [SECURITY+ CERTIFICATION]

One of the ways to remember something you’re always forgetting to to write it down. It’s one of the reasons I like blogging. I was so caught up in the middle of something I was doing today that when asked what should have been a simple question on the differences between symmetric and asymmetric encryption my mind locked up. So again, repetition is the best way to memorization. Symmetric Encryption Symmetric encryption uses a secret key which can be any set of characters. When that key is applied to the text of a message to change the content in a particular way. This might be as simple as shifting each letter by a number of places in the alphabet. As long as both sender and recipient know the secret key, they can encrypt and decrypt all messages that use this key. So if A=01 and B=02 and so on to Z=26 then 1001191514 becomes JASON.  Obviously this is a very simple example and it would be somewhat easy to figure out. The problem with secret keys of any strength is t...

Software security revenue to hit $16.5 billion in 2010 [GENERAL TECHNOLOGY NEWS]

According to a recent story published the IT PRO Enterprise and Business IT News website by Tom Brewster, Ruggero Contu who is a principal research analyst at Gartner, indicated that the software security market will emerge from the recession in decent shape, growing by 11.3 per cent in 2010, as businesses put more emphasis on protecting their IT. The article went on further to say that market revenue is predicted to exceed $16.5 million this year, compared to $14.8 billion in 2009, when growth slowed to seven percent due to the overall state of the global economy. Despite Gartner's claims that companies are to invest more heavily in security, a recent survey from the Ponemon Institute showed IT pros were concerned about the level of their protection capabilities . More than two thirds of IT workers polled said their firms did not have resources to deal with serious threats. The full article can be found online at - Software security revenue to hit $16.5 billion in 2010 . ...

That Facebook 'Dislike' button isn't real, unfortunately [GENERAL TECHNOLOGY NEWS]

Image
August 17, 2010 — by Dan Tynan Originally posted on ITWORLD – AN OPEN EXCHANGE Like many people of an inherently cynical nature, the fact Facebook only allows you to express your "Like" on various topics, posts, and advertisements irks me. I know I'm not alone, and so do Facebook scammers, which is why the latest viral "Dislike button" scam has spread so quickly. Facebook Security has issued an official warning about the bogus Dislike button scam. (Of course, this was after Sophos Security researcher Graham Cluley blogged about it and major media outlets like CNN picked it up. You get the feeling the Facebook Security guys spend most of their time riding around the building on Segways and playing with their tasers?) [ See also: Facebook bug coughs up user names and photos to anyone who asks ] The scam starts with a fake status update from someone you know who's been infected (like "Get the official DISLIKE button NOW!") followed by a ...

NAP Time With Windows Server 2008 [70-680 Direct Access and VPN Connections]

Emma Nelson recently posted an article over on the Windows Server HQ website regarding Network Access Protection. I would recommend review the article in it’s entirety. As part of the Windows 7, Configuring Exam (70-680) you’re going to need to have a good understanding of now NAP works and how it affects users that are connecting via Direct Access or via traditional VPN connections. NAP can also be used on the LAN as well. Windows Server 2008 uses NAP to restrict network access based on a system by system basis by performing a health assessment check on each computer that connects to the corporate network. If the client system meets the health benchmark by passing the health assessment check it is granted access the network. If the computer is in noncompliance, NAP is generally configured to block those systems from accessing the network until they can be made compliant with the health policy. For the most part there is a set of criteria that is set through the Windows Secu...

Brad's TechTips - Social Networking and Security Risks [GENERAL NEWS]

A MUST READ for anyone that uses Facebook, Twitter and / or LinkedIn. These sites are without a doubt very popular and very useful when used with care and thoughtfulness with respect to computer system security and data / information confidentiality. The popularity of social networking sites has increased at astonishing levels. There is no arguing the usefulness of sites such as Facebook , Twitter and LinkedIn .  They can be used for professional networking and job searches, as a means to increase sales revenue, as a tool to keep the public informed of safety and other issues or as a way to reconnect with friends from way-back-when. However, as with any new tool or application, it is always important to keep a close watch on its security implications.  Each of these tools comes with its own set of security concerns which can put your information systems and/or personal data at risk. This white paper will look at some of these risks and identify possible solutions to hel...