Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, 17 September 2013

Your E-ZPasses are Not Just Read At Tollbooths

In Forbes:  Are privacy conditions implied to just occur at locations where we expect a device to read our location?   This is probably disclosed somewhere deep in the signed agreement with E-ZPass tollbooth charging system.   A Hacker determines the truth.

Wednesday, 11 September 2013

Limits of Fingerprint Security

The reported inclusion of fingerprint authentication in new iPhones means we will see this approach being used commonly.  It is very convenient, but has its limitations.  Bruce Schneier, security expert provides details about the issues with its use.   Most importantly: " ... Biometric systems are seductive, but the reality isn't that simple. They have complicated security properties. For example, they are not keys. Your fingerprint isn't a secret; you leave it everywhere you touch. ... " 

Sunday, 25 August 2013

Pentagon as Silicon Value Incubator

In the NYT:  Work by DARPA like the Darpanet and related activities have been happening for a long time.  Part of my graduate education was funded by DOD scholarships.  " ...  For years, the Pentagon has knocked on Silicon Valley’s door in search of programmers to work on its spying technologies. But these days, it’s the Pentagon that is being scouted for expertise. Entrepreneurs and venture capitalists are finding it valuable to have an insider’s perspective on the national security apparatus when trying to find or prevent computer vulnerabilities or mine large troves of data. ... " 

Friday, 23 August 2013

Face Recognition Security Pins

I recently reported on the current state of face recognition.  The most obvious use of all,  why not use it as a pin for security?    Too easily mimicked from images?   An example in Finland.  From a system called Uniqul.  We experimented with iris scanning systems.

Sunday, 18 August 2013

The Threat of Medical Device Hacking

In Bloomberg:   A very scary possibility.  Though the article suggests that sufficient precautions are being taken for now.  But the potential exists as new hacks emerge and technologies evolve.   Note the comment about varying rates of innovation ... a key here.  " ... Considering the varying rates of technical innovation among hackers, medical companies, and regulators, it’s likely that the health-care industry will always be at least a half-step behind. Meanwhile, as medical devices continue to utilize wireless technology, the manufacturers will continue to face the tension of straddling two worlds, says Chester Wisniewski of Sophos, a security firm. “There are very few security people in the medical device industry, and there are very few medical people in the security industry,” he says. ... " ...'

Saturday, 10 August 2013

A Curious Tale of a Loss of E-Mail Privacy

In Forbes:  An interview with Silent Circle co-founder Phil Zimmermann.   Had not heard of the company.   The company deleted its secure email service this past Friday.  Are there other options for encrypted email that can prevent external entities, like the government, from demanding and getting  their disclosure?  From their site:  " ... we have reconsidered this position. We've been thinking about this for some time, whether it was a good idea at all. Yesterday, another secure email provider, Lavabit, shut down their system less they "be complicit in crimes against the American people." We see the writing on the wall, and we have decided that it is best for us to shut down Silent Mail. We have not received subpoenas, warrants, security letters, or anything else by any government, and this is why we are acting now. ... " 

Thursday, 8 August 2013

Security Risks and BYOD

Cursory look at the implications for security of Bring Your Own Device (BYOD) implementations.  We were early experimenters with the BYOD concept, and security was an immediate concern.

Wednesday, 7 August 2013

Advances in Tagging

In GigaOM:  Tagging is a long time interest. Costs and power requirements have always been an issue.  This also relates to an internet of things, where simply finding a physical thing can be a first step  Note also the use of crowd sourcing.

" ... Ever since Bluetooth Low Energy chips emerged, a growing number of object tagging and tracking services have sprouted up to take advantage of the technology’s potential as a proximity-based sensor. Innova Technology is one of those companies, but starting this week it’s offering a twist to its new Protag Elite devices.

In addition to using Bluetooth LE as a kind of radar to keep track of your valuables, Protag now has new crowd collaboration features into its apps so strangers can help you find your stuff if it gets lost. On Wednesday Innova plans to kick off an Indiegogo campaign to raise $100,000 for the new credit-card-sized Elite tag, which will eventually incorporate these new features. The first 1,000 backers can get its rechargeable device for $29.... " 

Monday, 29 July 2013

Necessity of Encryption

In CIO Insight: A good overview of the reasons for using encryption with personal data.  The legal risks involved and current status of state laws in this area.

Mobile Devices and Cybercrime

And more In Knowledge@Wharton on Mobile devices and crime.  Here in much more detail about the implications of mobile to cybercrime.   Your phone may be your weakest link. " ... Not only do such devices become points of access for cybercriminals, but they also may be more easily breached than personal computers since many consumers do not secure their smartphones or tablets with antivirus software or take simple precautions such as enabling password protection. ... " 

Wednesday, 17 July 2013

Virtual Sandbox

Brought to my attention for a project that will require more than the usual amount of malicious software security.  A virtual sandbox called Sandboxie that prevents software being run within it from altering any other parts of the system outside the sandbox.  Exploring this and alternatives.
Somewhat, but not very technical.   A CW article that explains its use.

Monday, 8 July 2013

More Smartphone Metadata Gathering

Another claim for a vendor gathering metadata from Smartphones, here from Motorola.   Metadata, or 'data about data', has been trivialized as a source of personal information, but when combined with other sources of data it can be very insightful and potentially invasive.

Tuesday, 25 June 2013

Cyber Security from Recorded Future

Have presented Recorded Future a number of times as a forward looking unstructured analysis method.  Now they announced something new, using their unique methods to do Cyber Security Monitoring.  Worth examining.  Much in the news today.  They write and I am currently reading:

"Today, we're excited to introduce our Cyber Security Monitoring application.

Together with our existing analyst tools, this new capability enables security teams to uniquely leverage the web in support of threat intelligence and cyber situational awareness.

The web is an immensely rich resource for signals of cyber threats, but its lack of structured information is a challenge for maintaining a real-time view of the cyber landscape.

Our breakthrough web intelligence platform aggregates, organizes, and effectively surfaces indicators of threats and attacks reported in open web sources. This information is now available in the Recorded Future Cyber Security Monitoring application.

If you believe your company needs better protection against cyber threats then make sure you grab a copy of our *new* white paper.

It explains our Cyber Security Monitoring application in more detail and it doesn't cost anything. Go here to get started: http://go.recordedfuture.com/cyber-security-insights-from-web-intelligence/