Fun Reading on Security - 6

Instead of my usual "blogging frenzy" machine gun blast of short posts, I will just combine them into my new blog series "Fun Reading on Security." Here is an issue #6, dated August 7th, 2008.

  1. DNS + Karma = Boom! Enuf said. Also, hear Pete Linstrom squeal.
  2. Fun essay on "blocking" and risk. Is it our job to stop'em from using Facebook?
  3. MS Exploitability Index. Smart ... or misguidedly focused on "vulnerability release" (and not creation)
  4. Chip-n-PIN, a PCI killer? I don't think so!
  5. Mike R revisits "good enough security" - read it, then review your IR plans (...for you will be 0wned)
  6. Very fun RSA survey here; data leakage beats malware again, people still not report incidents (to whom???)
  7. More and more and more people point at idiocies of academic security research... Read the whole w00t 08 thread here. Weep. Laugh.
  8. Neosploit has a bad quarter... breaks support "contracts" ... shuts down? Ah, the economy :-)
  9. Awesome stuff from  Richard Bejtlich: CAER.
  10. "The Network Firewall is a Consensual Hallucination" :-)
  11. More GRC-ball-kicking: here, here ("IT-GRC "vendors" are not IT-GRC vendors") - both are pretty insightful for GRC-lovers and GRC-haters)
  12. More SIEM-ball-kicking: here ("underwhelming","ridiculous", "missing the point"), here ("dead ...unless","cripple")
  13. Fun DLP portal launches.
  14. Final word (?) on TerryChilds-gate here. "When management starts controlling the actions of admins, things start to fall apart." Huh? When management loses control of the business, it dies. Folks, IT vs IT security gap IS real. I never quite believed it, but this taught me a lesson. Some common security sense for a change (also here).


