Posts

The problem of Securing the New iPad 3 within Business

Image
Apple announced the latest edition of their fantastic iPad today, not only is this device irresistible for consumers, but it has become irresistible for business.  This presents a new challenge for information security professionals, as the iPad has been bred for consumerization not for business usage, yet the business application capability of tablets are undeniable. Within main stream businesses up and down the land a change is afoot, it is no longer about giving the odd few magpie like senior executes the latest shinny new toys, as there is an unquenchable thirst for Apple’s latest tablet gadget emanating across entire businesses. This is not a time to have heads buried in the sand and wishing for risk aspects of business usage of tablets to go away, the tablet is coming to a business near you. In a few years from now they will be as common place on office desks as laptops, and will be smugly grasped by the majority of attendees within meeting rooms. But let us not forget, a ...

SmartPhone App Security Advice

Image
Smartphones really are a fraudster’s paradise, there are so many opportunities for fraudsters to monetise from them. From Rogue Malicious Apps sending premium rate text messages costing up to £6 a text, to stealing the personal information and passwords held on them. And there are even further fraud opportunities with smarphones being increasingly used for making Payments and with Online Banking. These factors together with a general smartphone user security naivety, are a major incentive for the bad guys to target these little handheld cash cows. So it is no surprise cyber attacks targeting smartphones are rapidly increasing in the UK, "800% increase in cyber attacks on smartphones" (Nov 11)  http://www.mirror.co.uk/news/top-stories/2011/11/07/800-increase-in-cyber-attacks-on-smartphones-115875-23543307/ .    In this post we will look at how to go about protecting against one of the most commonly successful attacks a...

Why PCI DSS is good for Information Security

Image
There is a growing consensus within the Information Security Community that the Payment Security Industry Data Security Standard (PCI DSS), is actually proving to be detriment to the general information security across the business. One point regularly made is the Payment Card Industry standard is responsible for diverting precious funding and resource away from the overall business information security strategy, where the breach risks can be much greater for the overall business.  That well maybe the case in larger enterprises which rightly regard best practice information security as a business priority, but consider the medium to small businesses, this is the land where information security ignorance is bliss. Within such SMEs  PCI can be a real InfoSec wake up call, as in merely attempting to comply with the many PCI DSS requirements, it can provide benefits across the business, where before the business were previously completely unaware of the risks...

Securely Wiping your Personal Data from the iPhone

Image
It seems like every year Apple release a better 'must have' version of the amazing iPhone, sparking a rush to upgrade by the masses. Ensuring all your precious personal information is securely removed from your old iPhone is an essential step to take before trading in or selling your old iPhone on eBay. Like any smartphone, the iPhone hoards all types of sensitive information about you, not just your embarrassing ABBA playlist and dodgy drunken pictures from the weekend, but all your Emails including access to future mails, username and passwords for websites and social media, and even sensitive financial information such as bank account and credit card details are often stored. So unless you are putting your iPhone through an industrial crusher, you really need to ensure you erase all the data from it before passing it on, this post explains how. This data erasing advice and method also applies to the iPad and iPod Touch If your old iPhone is a 3GS or an above model, then se...

Internet Troll Stomping

Image
I was featured in The Sun newspaper today in relation to Internet Trolls.  Trolling or a Troll is net slang for an individual who intentionally posts inflammatory, insulting or threatening remarks online. Pretty much anywhere where people can feedback comments on the Internet, such as on Forums, Facebook pages, Twitter, YouTube, Newspaper comments, is often subject to abusive comments. People can say the most extreme things when they think they are protected with the shroud of anonymity, words they’d never dream of saying to anyone face to face. However there are increasingly individuals that post abusive comments which go well beyond the boundaries of decency and taste, these are the individuals which are really regarded as the trolls under the definition. Recently a troll was convicted for abusing tribute websites of deceased girls, bringing the whole trolling issue into the public arena - http://www.bbc.co.uk/news/uk-england-14907590 You're not as anonymous as you might thi...

Evolution of UK Home Banking Security - In progress?

I was featured in an article by MSN Money titled "Online Banking Security gets more Complex" http://money.uk.msn.com/news/crime/articles.aspx?cp-documentid=159017310 Nothing ground breaking, but it would appear UK banking consumers are starting to feel the pain of increased online banking security trade-offs, due to UK banks trying to save money by cutting previously acceptable losses from online account fraud. "One person, one bank: three devices But despite the evidence that new measures are more than just inconvenient, many banks are pressing ahead. Lloyds, Barclays, Cooperative Bank, RBS and Nationwide Building Society all require customers to use a card reader when amendments are made to standing orders, direct debits or when setting up payments. "This is called two-factor authentication," said independent bank security expert Dave Whitelegg. How two-factor authentication works The idea is that no fraudster can access your account, however muc...

How to comply with the EU Cookie Law in the UK

Image
There is still much confusion and to be completely frank, some plain old nonsense being sprouted about the so called EU Cookie Law. So I thought it is high time to explain what it is all about, and specifically what UK businesses should be doing about complying with it. I am not a lawyer or an EU Law expert, therefore you should regard this blog entry as guidance and personal opinion. Having said that, it has not escaped my attention, there are some in the legal profession that are jumping on the EU Cookie Directive bandwagon in order to make a quick buck, and even providing very questionable technical advice to UK businesses. If you are already in the know with this issue, you may just want to skip to the bottom paragraph, where I provide my advice – “ How to comply with EU Cookie Law and avoid Fines.” What is the EU Cookie Directive and its requirements? All member countries (states) of the European Union are obligated to adopt EU Directives. One such EU Directive, known a...