Posts

World of Warcraft: Does the Internet have controllable Borders?

Image
World of Warcraft is an online game played by millions of players around the globe since Blizzard launched it in 2004. All you need is a computer, internet connection and a subscription, you play in a fantasy virtual world long with hundreds of other players at the same. This game is fun and highly social, but very addictive with typical players logging hundreds of hours play over a span of years. Players regard their online accounts and characters as very 'precious' due to the number of hours building character skills and abilities, and time acquiring in-game items. Last week ( 22nd Aug 2012 ) Iranian players started to complain on a Blizzard forum that they couldn't access the World of Warcraft servers, unless they went through a proxy server outside of their country.  After many more complaints from Iranian players and several days had past, Blizzard explained they had to take action to block all Iranian World of Warcraft players to due the US's economic ...

RSA Conference Europe 2012 Keynote Line-up

Image
The Premier League Champions of Information Security Conferences, RSA Conference Europe 2012  is just less than two months away. The keynote line-up has been confirmed and it is looking finger licking good with an Advanced Persistent Threat (APT) flavour to it. Jimmy Donal Wales,  Founder of Wikipedia Art. Coviello (RSA) Intelligence-Driven Security: The New Model Francis deSouza  (Symantec)  The Art of Cyber War: Know Thy Enemy, Know Thyself Adrienne Hall (Microsoft) Risks and Rewards in Cloud Adoption Herbert 'Hugh' Thompson  Securing the Human: Our Industry’s Greatest Challenge Philippe Courtot  (Qualys) Big Data : Big Threat or Big Opportunity for Security? Bruce Schneier  (BT) Trust, Security, and Society Joshua Corman   "Are We Getting Better?" Why We Don't Know. What We Can Do About It. Misha Glenny   The Struggle for Control of the Internet I always recommend information security professionals, whether new to the profes...

Security is a Contraceptive, but Ribbed!

Image
During a recent conference presentation, I heard a speaker proclaim 'IT Security is a Contraceptive, it does nothing to improve performance', much to the amusement of the audience. I completely disagree with that statement and regard it as  an uninformed  viewpoint by those who generally do IT and IT Security poorly, as in my experience I have seen how good IT security practises can have many positive effects on business performance.  Consider one of the holy information security trinity (CIA Triad), "availability", which is all about "business availability", and tied to business performance.  When comes to availability security measures is very much part of the performance equation, the threat of  malware  and denial of service attacks should be assessed along with the threat of power outages and hardware failure. For example business critical web services which has not been built with a capacity to withstand denial of service attacks can ...

The Hotel with Assumed Security

Image
It is fair to say most people will automatically place a certain amount of trust in hotel they never have visited before, especially those hotels with a decent star rating. Sure you might read a few reviews on the internet about the quality of the services and standard of the facilities at the hotel, but you would have the hotel complete a self costumed questionnaire before you booked. The type of security a hotel has is rarely considered by guests, instead most would blindly trust the hotel provides adequate enough security which protects their possessions, and themselves. Yet making assumptions that someone else's values will be the same as yours is a dangerous thought of complacency. Think about how a hotel's physical security measures up to your home security, and now consider the additional threats staying at a hotel has compared to your home. This week I checked into a Best Western Hotel in the North East of England. The receptionist duly handed me a room key and I wen...

Olympic Games Security has lessons for Airport Security

Image
The London 2012 Olympics Games were a tremendous success, I know I thoroughly enjoyed the games, and as a Brit I was extremely impressed, moved and inspired by the performances of Team GB, and how well the games were organised. Not being jingoistic, but what a Fantastic Olympics Games I was fortunate enough to attend a few London 2012 events, I can report from the spectator's point of view, the security checks were pretty much on par with what you would expect from passing through airport security, except the staff asking you to remove belts and place loose change into clear plastic bags before being walked through metal detectors and being searched, were way, way more friendlier and civil. Thorough Security with Tiny Queues & Friendly Service Such was the organisation and capacity of the security check points, I witness no queues, this despite tens of thousands of fans passing through at a similar time.  Definitely les...

Cyber-warfare rumbles on with Gauss

Hot on the heals of Stuxnet, Duqu and Flame comes another highly sophisticated "nation state" sponsored malware dubbed "Gauss".  Analysts at Kaspersky Labs de-engineering Gauss are saying it shares many elements of the same source code of the Stuxnet Worm and Flame, therefore have concluded it could only have been made by the same people, and given this new malware's specific purpose, underlines the link to another state sponsored cyber attack within the middle east. I posted who was behind Flame in  flame-culprit-fingered , no doubt it's the same folk behind Gauss. At present Gauss is specifically targeting financial users in Lebanon, stealing web browser history, browser passwords and host system configuration details. However the main purpose of Gauss appears to be that it steals account credentials from specific Lebanese online banks, and from PayPal and CitiBank, probably to monitor and collect details from financial transactions rather t...

94.5% of Business Overlook Third Party Data Security

Image
egress , specialists in data security and have their very own email and data encryption software, surveyed businesses about data security and have provided the following snapshot of their survey results to share on this blog. You need to Love yourself before you can Love Others This survey echoes the same old information security issues, businesses do not fully grasp and value the confidential information to which they process and store. This leads to a lack of expertise, capability and will to protect such data adequately within the business. It is not surprising then to learn such business are blindly trusting third parties to which they share their most important data, to protect their data sufficiently. They say you need to love yourself before you can love others, same applies to information security and assuring third parties protect business data properly.