Would You Fire This Person?

December 29th, 2011

In this case study, I present you with a problem employee. You are hereby invited to help his frazzled boss either a) deal with this employee or b) show the guy the nearest exit. I solicited input from a bunch of IT bosses and management experts regarding how they’d respond, and at the end I reveal the true fate of this real-life IT worker. Check out the story at Input-Output.

In God We Trust, but Security Vendors Need to Sign the Papers

December 26th, 2011

If Anonymous, LulzSec et al. can pwn security vendors, who can protect us? Here’s help on how to rate security vendors on the sitting-duck scale.

In this two-part look at how to vet security vendors, my first article—In God We Trust, but Security Vendors Need to Sign the Papers—focuses on assessing a vendor. This is done at arm’s length by simple online research as well as by holding security vendors accountable for not living up to various agreed-upon levels of service, similar to what’s being done increasingly by the industries Veracode notes.

The second article, In God We Trust, but It’s Nice to Do a Physical Walk-Through on Security Vendors, features input from Infosec professionals on what to watch for if you can conduct an on-site visit to a security vendor.

Google-funded study finds Firefox least secure browser, Chrome the best

December 14th, 2011

A new study has tossed the big browsers into the security mosh pit and decreed that Google’s Chrome comes in first, ahead of Internet Explorer and Firefox. But when it comes to the top three, is security more about your browser being up to date and properly configured than its brand? The full story is here. 

Four Romanians charged with multimillion-dollar hack of Subway, others

December 14th, 2011

The US Department of Justice has indicted and arrested four Romanians for credit card fraud perpetrated against Subway restaurants and other retailers concluding a three year investigation. Looks like default/easily cracked passwords enabled another needless theft. Here’s the full story.

XXX porn web domain names now up for grabs

December 14th, 2011

Pornography domain names ending in .xxx are now up for general sale, with 100,000 having already been snatched up in a previous, restricted sale. All registered .xxx sites will be scanned for malware daily, but don’t trust that to replace up-to-date anti-virus software. Here’s the story