Archive for July, 2007

Security Causality

July 30, 2007

I was asked by a friend “in gest” to give a “Security Buddha like” quote for him to use at a presentation. Here it is.
In Buddhism causality is generally accepted as a natural law. If there are certain types of negative events that you don’t desire then the best method to ensure they don’t [...]

FaceBook, Hairy Bikers and Learning Lessons from the Anti-Virus Industry

July 28, 2007

I can’t help predicting futility when I see stories about companies blocking FaceBook. For a long time the anti-virus industry has been forced to find better ways to detect and protect from “variations on a theme” yet inside sources who implement web filtering at some big banks tell me filter rules in products are updated and [...]

Whole Security Solutions

July 27, 2007

“Friends and family” yawn when I harp on about the need for whole solutions. Take Data Leakage Protection as an example. Some technology companies would have you believe that network devices or digital rights management alone is the solution. The truth of course is that information security is a complex topic that requires skillful people to think [...]

Virtual ATM Network Hacked - Inside Job

July 26, 2007

1.2 million Lindens (271 Lindens = 1 USD so about $12,000 USD) was stolen through the virtual ATM network in SecondLife.
It appears that a past employee of Hope Capital, who assisted in fixing previous bugs in our ATM, had decided to try and use their inside knowledge of our ATM communication channel to their advantage,” said Vandeverre [...]

Can Privacy be a Premium Service?

July 26, 2007

Om Malik suggests for a $1 a month people would pay the search engines to remove their digital search footprint in his blog post here.
If not today, but soon enough, we might be willing to pay to protect the privacy, and erase the digital footprints we are leaving behind…………….turn privacy into an opportunity for making [...]

More Thoughts About Platforms

July 25, 2007

A few weeks back I posted the Security Next.o platform and thought I quoted Marc Andreesons great definition. Seems I didn’t so here it is.
By definition a “platform” is a system that can be reprogrammed and therefore customized by outside developers and users and so it can be adapted to countless needs and niches that the [...]

Drunken Blackout

July 25, 2007

I wonder if this story about a drunken employee taking out 40 racks in a datacenter was ever considered part of a threat scenario?
I see the convergence marketing stories converting this from “urban myth / valleywag rumor” to “”irrefutable proof” within days.
Trivia: I used to work in the building behind this datacenter.
 

Definition of "Demo"

July 13, 2007

Customer: “I want a demo…well I really want to try before I buy”
Sales Guy: “You want me to wash you and you don’t want me to get you wet.”
Customer: “Exactly”
Deal done! Made me laugh.

Information Security Metrics Dashboard Example - People Productivity

July 12, 2007

I am in London with my friend Andreas Fuchsberger. He jokingly showed me his information security personal productivity metric dashboard for the last year hanging on his door!
 

A Great Site for Budding Entrepreneurs

July 12, 2007

Kaufman eVenturing is a simple superb web site for any budding entrepreneur. It has all sorts of wonderful content from articles about valuations of pre-revenue companies to sample term sheets and advice on a wide variety of topics. Thoroughly recommended.