Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Where Has All Our Data Gone?
0
comments
Trent Slabaugh
-
When there is a massive breach in security protecting personal data often times we hear about it for a week but then it's promptly forgotten. It's as if our brains can only retain the data for so long and then it's formatted.
Unless you are one of the thousands of people who's data was stolen, hacked, lost, etc.
A recent article in the Columbus Dispatch covered a loss of data at Chase when four laptops "disappeared" from a "secure" room. I don't understand why companies feel the need to store confidential personal information on mobile devices. With the state of computer networks, the data should reside on a server and the laptops configured to access the data but never store it. When it was discovered the laptops were missing, all Chase would have been out was the cost of the laptops.
In addition there is the problem of companies saving information on clients, customers, and employees that is not relevant and shouldn't be saved. TJX, the parent company of T.J. Maxx recently had data stolen. TJX believes their credit and debit ca rd transactions from January 2003 to June 2004 were compromised.
To make matters worse, this data was used recently to create dummy credit cards and then they purchased Wal-Mart and Sam's Club gift cards.
According to a report by the University of Washington, when analyzing the past 25 years, three out of five reported incidents of data breaches point to organizational malfeasance of some variety, including missing or stolen hardware, insider abuse or theft, administrative error, or accidentally exposing data online.
Businesses and Corporations need to get a handle on how they handle information. If they don't they may find that customers won't use them for fear of where all their data is going.
Here Endeth the Lesson

Read more
Unless you are one of the thousands of people who's data was stolen, hacked, lost, etc.
A recent article in the Columbus Dispatch covered a loss of data at Chase when four laptops "disappeared" from a "secure" room. I don't understand why companies feel the need to store confidential personal information on mobile devices. With the state of computer networks, the data should reside on a server and the laptops configured to access the data but never store it. When it was discovered the laptops were missing, all Chase would have been out was the cost of the laptops.
In addition there is the problem of companies saving information on clients, customers, and employees that is not relevant and shouldn't be saved. TJX, the parent company of T.J. Maxx recently had data stolen. TJX believes their credit and debit ca rd transactions from January 2003 to June 2004 were compromised.
To make matters worse, this data was used recently to create dummy credit cards and then they purchased Wal-Mart and Sam's Club gift cards.
According to a report by the University of Washington, when analyzing the past 25 years, three out of five reported incidents of data breaches point to organizational malfeasance of some variety, including missing or stolen hardware, insider abuse or theft, administrative error, or accidentally exposing data online.
Businesses and Corporations need to get a handle on how they handle information. If they don't they may find that customers won't use them for fear of where all their data is going.
Here Endeth the Lesson

Windows Vista Woes
According to Ollie Whitehouse, a security researcher for Symantec, a feature that is supposed to protect a normal user from running harmful software may act as a Trojan for malware and viruses.
Now from this and previous posts you'd probably think I'm anti-Vista. I'm not against the new OS, I'm against bad software. All operating systems go through a period where all the bugs and kinks are worked out, Vista is no different.
What concerns me most though is that this is the second security vulnerability reported within the past few weeks. In addition I looked at an advert in the newspaper for BestBuy and CompUSA. All the systems they are advertising come with Vista pre-loaded. Now it may be possible to get a non Vista system at these stores, I haven't checked into that yet. However the general population doesn't know that the brand new computer they just bought may not be able to run the software that they want it to, as well as put their sensitive data at risk.
I guess if you need a new computer & you don't want the security risks of Vista, you'll have to pony up some more money and buy a full version of XP. Hopefully you'd be able to find someone to wipe the hard drive and install XP.
As technical savvy as I am, I wouldn't want to tackle that job.
Read more about the newest Vista bug

Here Endeth the Lesson

Read more
Now from this and previous posts you'd probably think I'm anti-Vista. I'm not against the new OS, I'm against bad software. All operating systems go through a period where all the bugs and kinks are worked out, Vista is no different.
What concerns me most though is that this is the second security vulnerability reported within the past few weeks. In addition I looked at an advert in the newspaper for BestBuy and CompUSA. All the systems they are advertising come with Vista pre-loaded. Now it may be possible to get a non Vista system at these stores, I haven't checked into that yet. However the general population doesn't know that the brand new computer they just bought may not be able to run the software that they want it to, as well as put their sensitive data at risk.
I guess if you need a new computer & you don't want the security risks of Vista, you'll have to pony up some more money and buy a full version of XP. Hopefully you'd be able to find someone to wipe the hard drive and install XP.
As technical savvy as I am, I wouldn't want to tackle that job.
Read more about the newest Vista bug
Here Endeth the Lesson

Vista Vulnerability
Now I may have missed something but I was under the impression one of the selling points of Windows Vista, Microsoft's newest incarnation of its operating system, was it's security suite.
A privilege escalation bug was discovered by eEye Digital Security. The bug, similar to a buffer overflow problem allows users to elevate their privileges from normal user to whatever virus wrecking havoc level of user that they want.
The security flaw was found on January 9th, and reported to Microsoft on the 19th. Vista was released for retail at the end of January. Of course even if Microsoft admitted their was a security flaw, it was probably too late to change it in the copies that were shipped out.
A spokesman for Microsoft said that they are investigating the vulnerability.
Here Endeth the Lesson

Read more
A privilege escalation bug was discovered by eEye Digital Security. The bug, similar to a buffer overflow problem allows users to elevate their privileges from normal user to whatever virus wrecking havoc level of user that they want.
The security flaw was found on January 9th, and reported to Microsoft on the 19th. Vista was released for retail at the end of January. Of course even if Microsoft admitted their was a security flaw, it was probably too late to change it in the copies that were shipped out.
A spokesman for Microsoft said that they are investigating the vulnerability.
Here Endeth the Lesson

Vista Security

I had to laugh at the new Mac commercial.
If you haven't seen it yet, check it out.
You need QuickTime installed to watch this ad.
Here Endeth the Lesson

Silica - Be afraid...be very afraid!
Silica is a portable hacking device created by Immunity Inc., that can search for and join 802.11 (Wi-Fi) access points, scan other connections for open ports, and automatically launch code execution exploits from CANVAS, the company's flagship point-and-click attack tool that features hundreds of exploits, an automated exploitation system, and an exploit development framework.
Silica is designed to be used by penetration testers looking for security holes in a network. Justine Aitel, CEO of Immunity, demonstrated the device at the 2007 RSA Security Conference with alarming success.
Aitel said Immunity is careful to do due diligence when selling its products, which can fall into the wrong hands and end up being used for illegal purposes. "We don't sell to anonymous users. We make a fair effort to vet buyers and know where the money is coming from and who we're shipping to," she explained.
She said Immunity is taking orders for the $3,600 device, mostly from law enforcement agencies looking to do covert hacking on sensitive networks.
Future upgrades will include support for Bluetooth wireless connections, and GPS technology to pinpoint precise geographic locations of access points.
Click Here for more on Silica
Click Here for more on Immunity, Inc.
Here Endeth the Lesson

Read more
Silica is designed to be used by penetration testers looking for security holes in a network. Justine Aitel, CEO of Immunity, demonstrated the device at the 2007 RSA Security Conference with alarming success.
Aitel said Immunity is careful to do due diligence when selling its products, which can fall into the wrong hands and end up being used for illegal purposes. "We don't sell to anonymous users. We make a fair effort to vet buyers and know where the money is coming from and who we're shipping to," she explained.
She said Immunity is taking orders for the $3,600 device, mostly from law enforcement agencies looking to do covert hacking on sensitive networks.
Future upgrades will include support for Bluetooth wireless connections, and GPS technology to pinpoint precise geographic locations of access points.
Click Here for more on Silica
Click Here for more on Immunity, Inc.
Here Endeth the Lesson

Popular Posts
-
According to a company statement provided by Apple spokesman Derick Mains, "Although iTunes 7.0.2 may work with Windows Vista on many t...
-
The Recording Industry Associate of America (RIAA) may becoming more open to the idea of digital music rights. "It's a model worth ...
Category List
Technology
(16)
Security
(5)
Music
(4)
Windows
(4)
Apple
(3)
Miscellaneous
(3)
Politics
(3)
Graphic Design
(1)
Society
(1)
Powered by Blogger.
