Security, networking & systems

Welcome! 

My new blog has been launched today. This is intended to be a compilation of musings and thoughts with a rough focus on security and privacy. The idea is to provide analysis, commentary and geekspeak translations of news, events, and happenings in the security and technology arenas.

Feel free to comment and reply, the idea is to dialog.

You can read new posts on this blog via the RSS feed.

-J-

Musings - Geek speak elucidations

Day 3 iPad 2 review: an Android geek's perspective

2012-01-06 14:55
  Day 3 It's the interface; it just preforms so smoothly with absolutely no hesitation, and all of the little animations  that are built in are really impressive. I never had any complaints about the Xoom, but the iPad just screams. Apparently there's no way to access my Gmail contacts from my iPad… although there are iPhone apps to sync them to the local contacts I was force to pay for my first app… IMHO one of Apple's significant contributions to society: training people to pay for every little thing Brightness - actually works on "auto". The Xoom auto setting is far too dim for my tastes 3G - well, it sure ain't the 4G on the Xoom… but to be honest it's not that bad
>>

Day 2 iPad 2 review: an Android geek's perspective

2012-01-05 09:41
  Day 2 I really miss the Amazon free app of the day… Android only Widgets and notifications… I've gotten very used to being able to see new emails, the weather, etc. at a glance and get a preview when new emails come in. If there's a anything that brings me back to the Xoom, it will be this functionality… Seriously? No electronics store in the mall has an power/data cable over 4 ft long? Oh, but there's a power cable adaptor to the USB power brick that's 6 ft long... Any particular reason app icons can't be arranged as I see fit? Any particular reason I can’t put Apple apps into folders? Really?! Power: excellent, much longer life than my Xoom… I actually didn’t charge it last night and it's still at 72%. The Xoom never lasted longer than a day, and often warned of low power if I stayed up late Smartcover: probably the best designed accessory I've...
>>

Day 1 iPad 2 review: an Android geek's perspective

2012-01-04 10:37
  As an admitted Android fan who purchased a Motorola Xoom Android tablet the day it was released, and I was surprised by receiving a new iPad 2 for the holidays. Being what I consider to be a fair individual, I’m giving it a try and will compare and contrast… Day 1, first impressions: The iPad seems a little lighter than the Xoom, although I don’t have a case for it yet Very impressed by the responsiveness, slick! Despite the instructions from Verizon; thankfully I wasn’t forced to install iTunes on my PC Onscreen keyboard seems to register the jab of my fat fingers a bit better App store: I’d really like to keep browsing for other apps after I choose one to install. I could care less about the download progress Password hell: Why do I need to retype my password every time I open the App store Onscreen keyboard need a numbers row so I can...
>>

Scareware - Not a just a fashion statement anymore

2010-04-05 16:01
Scareware is the latest type of malware (MALicious softWARE) labeled by the media, not my poor sense of style. These are nasty little messages try to frighten you into browsing infected websites, installing infected software, and even giving up your credit card numbers. We have discussed this type of malware before, but since we are seeing an upswing in it recently, we thought we'd touch on it again. As our computers become more resilient to traditional methods of infection, we have seen an increasing number of bugs that bypass a computer's security by fooling you into allowing them in. This type of infection is spreading through social networking website apps, paid advertisements on legitimate websites, or even bogus search engine entries that take you to infected sites. This Scareware is actually comprised of elements from a few types of malware. Infection stage 1: Social...
>>

Security Breach: the human factor

2010-02-15 13:51
A few weeks ago, it was reported that one of our local school districts was the victim of a security breach. This breach resulted in wire transfers totaling almost $3 million from their bank accounts to various foreign banks; reportedly 20% of the school's annual budget. While the school district has recovered most of the funds, and is working with the FBI and the State Police to recover the rest, this incident brings home the pressing need for Information Security in today's environment. (http://www.timesunion.com/AspStories/story.asp?storyID=885104#ixzz0bwm3keRx) How this happened has not been disclosed, although the above article speculates on two likely scenarios. One is through "phishing". This involves an email message or website that tries to fool the reader into entering protected information such as user names/passwords or account numbers. These can be very sophisticated,...
>>

Defensive Depths

2010-02-01 13:17
With the new year, it's time to get back to basics and review some key concepts in the security field. One term we often bandy about is "defense in depth" as a means to secure your information and it has nothing to do with deep sea warfare. The term is taken from military parlance and can be traced back to ancient times as a way to increase the survival of whatever it is you're protecting. By placing your king, or gold, or big rock, or sensitive information within multiple layers of defense, you can significantly increase the difficulty of others getting to it. Think of a medieval castle: for a marauding dragon to get at your king he must go through the town walls, then swim across the moat, and then get through the castle walls. Once inside the castle, there is the main keep or central tower to get into and climb. At each layer, defensive countermeasures can be taken to repel...
>>

Budgeting for Disaster

2009-12-01 11:49
As the year winds to a close, thoughts are turning to the coming holidays: turkey, pies, snow shoveling, and perhaps a new budget. So how exactly does one plan for the unexpected, or budget for disasters? By definition disasters are very bad: bad enough that we should be insured against them. Assuming that we are insured against most disasters, we're going to downgrade this discussion to mere emergencies. Specifically, we'll be focusing on those nasty little incidents that fall into that gray area between "AHHHH!!" and "doh!". This might be a network server going down, a critical file being corrupted, a virus getting loose in the network, a lost backup tape with patient records, or even a court ordered e-discovery request. The common threads between all of these incidents are 1) they are unexpected, 2) they involve the technologies we use to run our organizations, and 3) they have the...
>>

Virtual security in a real world

2009-11-20 09:23
Virtualization has become a force to be reckoned with for organizations of all sizes and shapes. The flexibility and consolidation options available in virtualized environments give this technology an unusual distinction: it appeals to both the engineers and the accountants. But as with any new technology, virtualization does bring new security considerations. Virtualization allows a "host computer" to run multiple "virtual computers" as applications, with all of them sharing the same physical server hardware. Different vendors have different terms and implement this in different ways, but basically they all run computer operating systems as applications. This has many benefits; allowing better hardware to be employed (as it is shared by numerous servers) and the infrastructure to be reconfigured at will. Need more memory for your web server? Change the settings on the virtual host...
>>

Avoiding the Storm Clouds

2009-10-06 10:58
As cloud computing becomes more commonplace and vital to our operations, it's imperative to keep in mind the security implications of running your business from “the cloud". Moving expensive and hard to maintain programs to the cloud can be an attractive  alternative to large one time investments in hardware and software. However, we need to be very aware of how this move affects our information's security. Specifically, we will be focusing on our information's availability in the cloud. With business critical applications and services hosted in the cloud, internet access, which smaller organizations have traditionally seen as just "useful", is suddenly elevated to "vital". With your application in the cloud, slow internet means low productivity. “Cloud computing” offers programs and applications as services that are accessible from any internet connection instead of running...
>>

Lock up your servers!

2009-08-25 15:44
One aspect often overlooked when securing our information is physical security. The goal of physical security is to control who can walk up to the information and touch it. The idea is to prevent unwanted information disclosure, loss, or corruption, the same as when securing the information across the network or from the internet. The difference is that physical security deals with the “real world". For most of us, this doesn't mean training your Chihuahua as an attack dog or outfitting your employees with dark shades, cheap suits and sleeve microphones; it simply means using some common sense. Before we can take measures to physically secure our information, we need to know what type of information needs to be protected. There is no need to post armed guards around your product catalog after it's been published: it's meant to be seen by others. Before it's published could be a...
>>
1 | 2 | 3 > >>

Rants - Tech savvey explications

IE 0 Day Exploit

2008-12-12 19:27
Microsoft reported a new "zero-day exploit" that affects most versions of the Internet Explorer browser. A zero-day exploit is a security vulnerability that is being exploited before the software vendor or public know that the issue exists. This particular exploit attacks flaws within Internet...
>>

Spoofed NDR issues

2008-04-14 13:05
We've seen a rash of NDR (non-Delivery Response) floods happening to our clients. In all cases, it appears that the spam being NDRed is spoofed, but we are receiving reports from these users that they are being black listed on spam filters. Is anyone else seeing this problem? Thanks, -J-
>>

Search site

© 2008 All rights reserved. Jason Appel

Free hosted e-commerce