Monday, October 19, 2009

microsoft and yahoo together forever?

Microsoft really wants to one up google http://blogs.zdnet.com/microsoft/?p=4288&tag=content;col1

Monday, October 12, 2009

Sunday, October 4, 2009

Windows 7 get ready to exploit!!!

With every release of a new O/S comes new exploits but to see something like this so eary is rare. Maybe Microsoft will have a patch soon? lol probably not!

Monday, September 28, 2009

User IDs, Terminate immediately!

after reading another article on how an insider that was terminated i wonder when companies will start to get it together. How can you realistically terminate someone and then not delete their user name from the system. In this story just that happened, it all could have been avoided if they just would have followed industry best practice.

http://www.inc.com/magazine/20090401/technology-when-it-workers-attack.html

Monday, September 7, 2009

Securing the cloud

I was reading an article on cloud computing specifically web O/S and was wondering what everyone thought about the security threats to the cloud. What approches will change when we start using the cloud? http://blogs.zdnet.com/Hinchcliffe/?p=771 .

Monday, August 31, 2009

ddos becoming more and more common

This is just one of many articles you see today on this subject. It seems to me that this is becoming more and more common to see rivals attacking each other using a ddos. From rival video game companies in china ( See ddos attacks in China ) to the shutting down of facebook and twitter a few weeks back due to some blog about russia. The key concept here is how do corporations protect themselves. I belive the only way to protect yourself from this is having a good security team on thier toes with a good IDS running and properly configured. This is something that will take entirely too much money for any small business to invest in. Any one else have any ideas on how to protect from DDOS?

Monday, August 24, 2009

Number one threat! the dreaded insider job!

After reading an article on searchsecurity.com http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1365888,00.html I have renewed concern for any company large or small to put an emphasis on combating threats from the inside. We need to go one step further from just disabling user accounts of a terminated employees. Management must take an active roll in being involved with their employees. By having a close relationship managers can spot problems and assess if the person may become a security threat. I think there may be a deficiency in integrating the IT security department and HR so they are both on the same page. A recurring topic came up in this article TRAINING AND POLICY I think we will see both of these words come up frequently.