I had prior posting on the recent HackMiami conference here in the South Florida area.
They have gotten some media attention for their conference, in particular for one of their panel discussions on the growing "cryptocurrencies" such as Bitcoin and the like. You can read the article HERE at Financial Tech Spotlight. I had attended this panel, and thought it was pretty good.
Friday, May 31, 2013
Thursday, May 30, 2013
Disney's new MagicBands
In a recent article at All Things D, its noted that Disney is rolling out a new item called MagicBands, that serve as replacements for park tickets (including FastPass), even room keys. They work wirelessly, so are similar to various RF access cards. They can also be tied to credit cards, so guests can use their MagicBands to pay for stuff.
It's good that the article did bring up potential security risks, especially with the credit cards. Ok, the bands don't have the credit card info on them, and the guest must use a PIN code to fully utilize that, so you do have 2-factor authentication for that part. But you do have to wonder if the bands can be cloned. This would allow someone to get into hotel rooms or use them to get into the parks, etc.
Here is a Disney Blog posting on it.
It's good that the article did bring up potential security risks, especially with the credit cards. Ok, the bands don't have the credit card info on them, and the guest must use a PIN code to fully utilize that, so you do have 2-factor authentication for that part. But you do have to wonder if the bands can be cloned. This would allow someone to get into hotel rooms or use them to get into the parks, etc.
Here is a Disney Blog posting on it.
Review: The Phoenix Project
In a previous posting, I mentioned a new book out, The Phoenix Project. Surprisingly, this is a novel that is "about IT, DevOps, and Helping your Business Win." I had heard about it from a couple of IT Security colleagues, and had to check it out.
As I noted in my previous posting, the idea of process improvement in IT is one I've had an interest in over the years. Up till now, nothing I had seen used had really done the job well. This book is intended as an introduction to a new way of thinking about IT, called DevOps (a combination of Development and Operations, two groups in IT that are often at odds).
As I noted in my previous posting, the idea of process improvement in IT is one I've had an interest in over the years. Up till now, nothing I had seen used had really done the job well. This book is intended as an introduction to a new way of thinking about IT, called DevOps (a combination of Development and Operations, two groups in IT that are often at odds).
Wednesday, May 29, 2013
SANS' Securing the "Internet of Things" Summit
I recently learned that the SANS Institute, a leading IT Security training and certification organization, has a Call for Papers (CFP) for an upcoming one day workshop on securing the "Internet of Things".
The event is the Securing the Internet of Things Summit, being held on October 21st in San Fransisco.
The page has full info on the event, including the CFP.
The event sounds pretty good. I'd love to be there, but most likely won't be able to. I do hope that the papers presented will be available to others. (say a conference report or the like).
The event is the Securing the Internet of Things Summit, being held on October 21st in San Fransisco.
The page has full info on the event, including the CFP.
The event sounds pretty good. I'd love to be there, but most likely won't be able to. I do hope that the papers presented will be available to others. (say a conference report or the like).
Failure of Bouncer
In a previous posting, I mentioned Bouncer, Google's service within the Google Play Store that is supposed to keep out malware. This is important, because the Play Store does not vet new apps to the level that Apple's App Store does, meaning that Google Play becomes one of the biggest vectors for malware to get into Android phones.
Well, per a recent article at ArsTechnica, someone figured out how to get around this. I discovered this thru an article at TechRepublic.
Apparently how they did it was upload an app to Google that was ok, which was checked by Bouncer. Then they uploaded a new version of that app, this one with the malware. Now, I have to wonder why Bouncer didn't re-check it. Wouldn't that malware app be different (different size, atleast a new update date), and thus Bouncer would re-examine it? Seems its not setup that way. Certainly a new upload, if its not a new size, should trigger a recheck.
Apparently some 9 million user got it. Upsy.
Check out the article at TechRepublic. I thought it had some pretty good points, similar to what I've been saying, on the need for better security stance when it comes to Android. A big part is that we need to get more people to install AV software (ok, they are really anti-malware, but still) on their phones. Stop giving people the impression these devices are totally secure, and take practical security in mind.
Well, per a recent article at ArsTechnica, someone figured out how to get around this. I discovered this thru an article at TechRepublic.
Apparently how they did it was upload an app to Google that was ok, which was checked by Bouncer. Then they uploaded a new version of that app, this one with the malware. Now, I have to wonder why Bouncer didn't re-check it. Wouldn't that malware app be different (different size, atleast a new update date), and thus Bouncer would re-examine it? Seems its not setup that way. Certainly a new upload, if its not a new size, should trigger a recheck.
Apparently some 9 million user got it. Upsy.
Check out the article at TechRepublic. I thought it had some pretty good points, similar to what I've been saying, on the need for better security stance when it comes to Android. A big part is that we need to get more people to install AV software (ok, they are really anti-malware, but still) on their phones. Stop giving people the impression these devices are totally secure, and take practical security in mind.
Sunday, May 26, 2013
DevOps- a preliminary look
This is a posting I've been working a bit on for sometime. I decided to at least get this out, as its a topic I will probably be visiting more in the future.
As a long time IT professional, I've had to deal with process and procedures. These are needed to manage the systems we are responsible for and deliver the services we should be. Even as security professionals, we need to understand that our job is to secure these systems to help ensure that the delivery of them is not interrupted. And often times this means doing so in a consistent matter, which happens when we follow procedures.
As a long time IT professional, I've had to deal with process and procedures. These are needed to manage the systems we are responsible for and deliver the services we should be. Even as security professionals, we need to understand that our job is to secure these systems to help ensure that the delivery of them is not interrupted. And often times this means doing so in a consistent matter, which happens when we follow procedures.
Labels:
CMM,
CMM-I,
Cobit,
DevOps,
ITIL,
Maturity Models,
Phoenix Project,
procedure,
process
Review: Android Security
I recently picked up a new book on Android security. Looks to be the only (so far) book on the topic, so they have kind of set the bar for subsequent works. The book is Android Security: Attacks and Defenses by Anmol Misra and Abhishek Dubey (CRC Press, ISBN 978-1-4398-9659-4). They have an accompanying website and blog, www.androidinsecurity.com where there is also resources from the book. (but there's not much traffic on the blog, hope this changes.)
Having read over it, I have to give it an overall grade of B+. (or if you prefer, 4 out of 5 stars).
Having read over it, I have to give it an overall grade of B+. (or if you prefer, 4 out of 5 stars).
Subscribe to:
Posts (Atom)
