Posts Tagged ‘Infosec’

I’ve written on here before about major bugs in the PGP platform for whole disk encryption.  Fairly recently it was discovered that there exists a bug with the latest version of PGP Desktop (specifically, whole disk encryption), with machines that are running the new Intel Sandy Bridge architecture with certain hard drives.  On the new [...]

Back to basics

Posted: 3rd March 2011 by John in Personal
Tags: ,

There’s a bad habit that I think pervades infosec right now: Focusing on the technology without understanding and nailing the basics. For instance – having IDS and IPS systems on all segments of your network is good… but doesn’t help you if you’re not monitoring and doing correlation on the resulting output (and following up [...]

Infosec: Pick your battles. Choose wisely.

Posted: 22nd November 2010 by John in Personal
Tags: , ,

Something I see quite often working in security is a mentality of “we must implement control X, regardless of the consequences”. This is a dangerous mentality to have, and is more likely to cause more problems than it will ever (if it ever) solves. This is dangerous for a few reasons, but most notable is [...]

Making Vulnerability Management Easier: HoneyApps

Posted: 14th September 2010 by John in Personal
Tags: , ,

Every now and then in my line of work I come across a tool / service that I find to be interesting or just plain useful.  These are tools that either allow me to do some really cool things or have the potential to save me a ton of time, or both. A few weeks [...]

Knowing is half the battle

Posted: 9th September 2009 by John in Personal
Tags: , ,

Information security is a tricky topic when it comes to business.   On one hand, businesses want to be secure to prevent themselves from generating negative headlines or having to tell their customers that they failed to protect their data.   On the other hand, they don’t want to spend a lot of money on [...]