Showing posts with label practices. Show all posts
Showing posts with label practices. Show all posts

Tuesday, September 9, 2014

(SuperValu) Wrote Me A Letter

   I'm hearing the Joe Cocker version of Box Tops song! (though I always picture John Belushi doing this!)

   I don't want my summer to end, but October is coming soon and, in the US, October is National Cyber Security Month.  This will be the first post of a series on Identity Theft that will carry us into October.

   First of all, the term Identity Theft is a misnomer.  According to Findlaw:
 Theft is often defined as the unauthorized taking of property from another with the intent to permanently deprive them of it. Within this definition lie two key elements:
1) a taking of someone else's property; and
2) the requisite intent to deprive the victim of the property permanently.
The taking element in a theft typically requires seizing possession of property that belongs to another, and may also involve removing or attempting to remove the property. However, it is the element of intent where most of the complex legal challenges typically arise in theft-related cases.
   But, with Identity Theft, your identity is not actually stolen, because you still have use of it.  A more accurate term is Identity Fraud.  Someone is using your identity, without permission, to execute fraudulent transactions or commit other crimes.  And, in many cases it's just aspects of identifying or financial information that is being used fraudulently, like your credit card.

Tuesday, May 13, 2014

The Best (First Good) Password Policy Ever!



In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   But, maybe one of the key issues is that password policies are universally so bad that consumers can't do the right thing because they can't figure out what that is!  We've been living with that old dogma of.... say it with me...
  • 8 characters;
  • upper/lower case;
  • numbers;
  • special characters.
   That's been around since the 60's.  Perhaps it worked in a world when people had only one password, when systems weren't all networked together, and attacking systems wasn't the lucrative business it is now.

Tuesday, September 3, 2013

Putting the Face in Facebook

   As can happen in a month whose name contains an "a", "e" or "u" :-), Facebook has once again made
changes to its privacy policy and practices.  And, as always we all have two choices: accept the changes (and adjust our settings and practices appropriately), or; leave Facebook.

   Of course most people won't leave Facebook, and if anything they will add more users than those that leave.

   As I look through the changes (see Facebook's notice here with links to the details), I think there are three things to know...

Tuesday, May 14, 2013

One Size Does Not Fit All

   The annual Secure360 conference kicked off yesterday in St. Paul with pre-conference sessions. 
Secure360 is the major upper Midwest security conference and has become a US national event, now in its 11th year (I think!).

   I'll be pretty busy at this year's conference.  I've actually spoken at every Secure360, but this year I did a half-day seminar yesterday on BYOD, and tomorrow I've got back-to-back talks - one on the Insider Threat I call "The Accidental Insider" (blog post), and one on authentication "3 Factors of Fail" (blog series starts here).  Slides for all are on my slideshare site.

   I've got a wide variety of topics to cover!

   And that's what is so cool, and critical, about conferences.