Archives

Secure Messaging Gateway: An Ironport Review

Over the weekend, I did a lot of reading on a company in the mail gateway business called Ironport. I mean a lot of reading. This was another consolidation (see Why behemoths buy startups & March 08’s Information Security Magazine’s Schneier/Ranum Face Off), with Cisco snatching up the market leader.

I read about capabilities, product offerings, market penetrations, strategic positioning, competitors and magic quadrants. All of this was at the urging of a friend of mine at Cisco, and how this product would drive profits for the company for the next several quarters.

I did a similar [...]

Want to hack ANYONE's computer? Just follow Microsoft's lead!

Original Post on 13-Sep-07 7:37pm:

In an interesting move today, it is reported that Microsoft is silently updating Windows XP and Vista. I emphasize silently. Remember Sony’s rootkit debacle? There are no reports of problems, but when my machine mysteriously decided on its own that it was time to reboot in the middle of a presentation, it made me look bad, and question my IT staff. We don’t have auto update turned off, but several of our customers do because of patching and regulatory restrictions. And this patch occurs even in the instances where customers turned off Windows [...]

Want not be hacked? Security Vendors – why less is more!

Original Post on 10-Jul-06 5:30pm
The IT industry loves advanced technology, even to the point of gadgetry. Some immature technologies are adopted simply for the gee whiz factor. Others have a specific niche application, and are money well spent. The IT staff spends time and effort integrating the new application into the enterprise architecture, and then rolls out the first release. Security in the past relied on these new, hot technologies; they were stand-alone, and the architects selected the best [...]

Hacking "Linked-In": Working around the social part of social networking

Original Post on 14-Jun-06 4:50pm
I use “Linked-In” for a social networking, and online contact management tool. It’s quite convenient, nearly a true peer-to-peer instantiation of a friend of a friend tool (at least in the free version) and pretty indicative of most of these sites. In order to connect with someone, you either must have their email address and send them an invitation, or ask someone you’re already connected with for an introduction, all brokered by Linked-In. I say nearly a true peer-to-peer social networking tool, as there are a couple of ways to bypass their system. Take a [...]

Are you at risk? Bogus Entries on Networking Sites & it's impact on personal branding

Original Post on 12-Jun-06 9:24pm
The Information Assurance (IA) industry is quite small; the same major players are known throughout everyone’s circles. Gene Spafford is the GodFather. His legendary research into the security arena influenced most (read all) computer science/engineering students since before my time, and his contributions through Purdue’s CERIAS department still push IA research. Martin Roesch designed the Snort Intrusion Detection System, considered by most as the only open source IDS deployable in a true operational environment. [...]