Tuesday, January 27, 2009

Data breaches and PCI

Lot of people have blogged about PCI (here, here and here) and the latest Heartland breach. While many of them argue the effectiveness of PCI compliance, I think it is too early to make a judgment on that. One way to measure the effectiveness would be to compare the breaches reported by PCI compliant and non-PCI compliant companies over the course of 6 to 12 months and of course this is assuming that the PCI complaint companies went through rigorous external audit requirements.

Branden brings up an excellent point in his blog that many of the companies may not be PCI compliant at the time of the breach.  " PCI Assessments are point-in-time and many companies struggle with keeping it going every day."

Many of the online PCI scanning vendors are set to automatically scan for vulnerabilities on a daily basis, so it would be good to know if these companies are compliant on a daily basis rather than once a quarter or once a year.

Sunday, January 25, 2009

Top 3 Books

Richard over at TaoSecurity lists the top 7 books he read in 2008. While I read many books in 2008, I am going to list the top 3 books, these were not necessarily published in 2008



3. File System Forensic Analysis by Brian Carrier

2. Nmap Network Scanning by Fyodor

1. Security Metrics: Replacing Fear, Uncertainty, and Doubt by Andrew Jaquith

Data breaches


Identity theft Resource Center tracks the data breaches reported by various organizations, recently they published their year end summary. They report that the number of data breaches increased by 47% over the last year. The full report is here.

Of course, there is a huge increase in theft and while lot of this could be attributed to increase in organized theft, I strongly believe that majority of these breach disclosures are necessitated by various regulations.

Speaking of data breaches, here is a chilling account of credit card theft and the underground economy. At the end it may seem like a movie plot but it is a true image of what's happening out there. 


Predictions

While I did quite good on the 2008 predictions, I stopped believing in them because Information Security has become so unpredictable with more and more new attacks and threats surfacing on a daily basis. My only prediction is going to be that I am going to be blogging more often.

Monday, March 10, 2008

Attacks on disk encryption keys - Tool in the wild

Last month I wrote about some new attacks on disk encryption, researchers at Princeton did not release any tool at that time but now people at mcgrewsecurity has released such a tool.

Thursday, February 21, 2008

Attacks on disk encryption keys

As forensic practitioners whenever we deal with disk encryption, we have always known that the only theoretical way to retrieve the key was to somehow access the memory where the key is kept. Researchers from Princeton demonstrates that disk encryption can be defeated by "relatively simple methods", more details are here

Sunday, February 10, 2008

Data leak

Saw this Infoworld article through Rebecca Herold’s blog , “IT managers who object to employees using unauthorized software at work have another tool to worry about: Google Apps Team Edition, which requires no IT participation to implement”

As corporate Information Security professionals, does this really worry you? If you say yes, here is a list of applications to add to this,

Pownce “Pownce is a way to send stuff to your friends. What kind of stuff? You can send just about anything: music, photos, messages, links, events, and more.”

Qipit “Qipit turns camera phones and digital cameras into mobile copy centers so people can turn photographs or written and printed materials into scan-quality digital documents they can share and store on the go.”

Meebo “Meebo is a website for instant messaging from absolutely anywhere. Whether you’re at home, on campus, at work, or traveling foreign lands, hop over to meebo.com on any computer to access all of your buddies (on AIM, Yahoo!, MSN, Google Talk, ICQ and Jabber) and chat with them, no downloads or installs required”

Willselfdestruct “You can create a secure anonymous email message to a friend or colleague by entering their e-mail address and the message to see.”

The site goes on to say that “No messages or e-mail addresses are stored after the message has been viewed. We also do not log your IP address or any information about you, your message, or the recipient. Once sent, all data disappears forever.”

DocSyncer “DocSyncer automatically finds and syncs your document files to Google Docs and your DocSyncer account. DocSyncer monitors your documents for changes and syncs the updated files as well.”

YouSendIt “Our innovative service enables users to send, receive and track files, on-demand.”

These examples make a great case for deploying DLP and other monitoring solutions but understand that many of them offer ways to bypass monitoring by allowing the users to encrypt and password protect the channels and data.


Thursday, February 7, 2008

iPhone Denial of Service Vulnerability

Securityfocus reports a new iPhone Denial of Service Vulnerability. This exploit causes a kernel panic, crashing the device.

Speaking of vulnerabilities Apple (QuickTime), Adobe (Reader) and Firefox all announced patches for application flaws.

How do we check for patches like these automatically? Check my earlier post on Secunia PSI

Tuesday, February 5, 2008

Yahoo Jukebox zero day


McAfee Avert Labs reports a Zero day Yahoo application vulnerability, a temporary workaround has been given if your anti virus does not recognize this.

Monday, January 28, 2008

Metasploit releases Version 3.1

This new version features a graphical user interface and full featured Windows interface. This also incorporates many other useful modules, the one I am particularly interested in testing is the Lorcon 802.11 packet fuzzing module.