-->

Sunday, March 30, 2014

Outdated Software and Your Privacy and Safety

By now everyone has heard of Malaysian Air Flight 370, the plane that disappeared somewhere over the Indian Ocean. Early reports were speculative that the aircrafts systems may have been hacked, causing it to become unresponsive and even be remote controlled from somewhere else. There were even claims of proof of concept ideas that this has already been demonstrated using models and Android phones. Is it possible? Yes, it might be.

Wednesday, March 19, 2014

The Importance of Independent Auditing

There are some simple concepts that we encounter regularly within information security - conflict of interest, least privilege, and separation of duties to name a few. These simple concepts are what make independent auditing such an important concept. The concept of independent auditing is a requirement in order to get an honest, and true-to-life review. An accurate audit is important because it could identify weaknesses and/or flaws in processes. These weaknesses and/or flaws could lead to public embarrassment if not handled properly before becoming exploited, loss of trust, or even legal implications in some cases.

Monday, March 10, 2014

Security Awareness Programs

These days just about every organization has a security awareness program, and yet people are still the weakest link. Why? How could this be? People are generally good natured. They want to help. This simple characteristic is what makes social engineering such an excellent tactic even today. The tactics are simple. Ask someone a series of questions, start out simple, and progress into other more revealing questions. Another tactic of social engineering is to make regular contact. By doing this you develop a persona and become someone likable to the target. Each time you call not only are you developing a persona, but you are also slowly collecting useful information that you can use for research in between contact. All the while the person being targeted has no idea. Those that are really good at this tactic essentially hack the mind. They can lead a conversation directly into the direction that they want it to go.

Thursday, February 20, 2014

Evolution of a Security Engineer

Everyone has a story.  For me it started in 2003.  I had been recalled to Active Duty from the Naval Reserve as a Unix Administrator.  I knew nothing of IT or Unix back then, but I did hold the qualities that employers look for - fast learner, on time, driven, etc. 

The short version of my story follows. My orders were up and I would have been going back to working four jobs - bagging groceries, naval reserve weekends, band gigs, and college.  The Air Force Technical Sergeant that I worked for knew I was worthy of much more.  He had a cigarette with another guy on one of my last days.  This man was looking for entry level IT Security people to become intrusion analysts.  I met with him and he asked me what I knew about TCP/IP.  I told him I could spell it, and he told me to go to Barnes and Noble, buy two books about TCP/IP so he knew I was sincere about the position, and I would be hired.  I did obviously.  I put myself on twelve hour nights purposely for the first year and a half so I could read, use the lab, and catch up to the required skillset and the rest is history.  It was pretty much a lucky break, and along the way I've been extremely lucky to have worked with some great mentors and people that have helped me grow quickly, coupled with jobs that make for an outstanding resume, and of course...a little hard work. I've had the luxury of growing up in security, and as such have worked the gamut over the past 11 years.  But enough about me.  What about everyone else? 
I would venture to say that most security administrators are prior server admins.  Most have probably come through the traditional IT ranks - helpdesk to client support, client support to server support, small environments to large enterprises.  Why?  Because our field is still young.  Most are converts from networking, server administration, or were administrators of security tools. 

Either way you came up, we all have new hurdles to overcome!