The Security Eunoia

Blogging about Security Auditing, IdM & Access Mgmt, Web App Security etc

IBM’s answer to the Endpoint Security problem

Remember the post about how big security vendors are moving down the food chain to consolidate their hold on the security market? Well IBM through its partnership with (a much smaller) BigFix has released a desktop security solution that is positioned to enhance endpoint security and “reduce cost”.

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Telegraph CIO thanks folks at Hackersblog

I’m not sure what the real intentions are but doesn’t it sound a bit odd that the Telegraph media group CIO will thank the guys at Hackersblog for exposing their SQL injection vulnerabilities?

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Will your security vendor go bankrupt?

What would you do if your security vendor went bankrupt? It is said that the security industry is recession proof but the reality is that companies are cutting costs and that means less spending on security solutions too.

In response to this changing market dynamic the big boys (IBM, Cisco, EMC etc) are repositioning their products to be attractive to smaller budgets.

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Companies can learn from the Tylenol-Cyanide case

In 1982 Johnson & Johnson the company making Tylenol had to contend with a major financial and image problem when contaminated Tylenol capsules caused the deaths of 7 people. Investigators discovered that someone had filled Tylenol capsules with solid cyanide compound and replaced the original Tylenol bottles with poisoned ones in some supermarkets and drug stores.
What did the company do and what lessons do we learn from it?

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Spotify hacked! - My account compromised

Oh great! Its now my account that has been compromised .. ouch! Interestingly this is the first time any service provider has sent me any such notification. This may be in part because I live in Europe where data breach notification is still being debated therefore many providers may remain silent until exposed.

This is a mail I received from Spotify this evening

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

UK Prime Minister’s medical records breached

The UK Prime Minister’s medical records have been breached in a series of high profile ‘data violations’ involving UK politicians and others, the Sunday mail reports. Last week UK cabinet minister Jack Straw’s hotmail account was pwned by criminals trying to hoodwink the minister’s ‘friends’ into sending them money.

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Virtual Firewall to gain momentum

I read about a startup (Altor Networks) that has developed a virtual firewall for VMware hypevisor. It is basically a virtual appliance that you plug into your virtual environment to act as a firewall between your virtual switches and virtual machines. It also wraps firewall policies for each VM so that even when migrated, the VMs will still be protected.

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Clueless tech support

* Customer: “The ethernet card you supplied doesn’t work under Linux.”
* Tech Support: “Have you installed the DOS drivers?”
* Customer: “I’m using Linux, so the DOS drivers won’t work.”
* Tech Support: “Why not?”

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Green doesn’t have to be expensive

Citrix this week made its XenServer Enterprise hypervisor free allowing small businesses to virtualize for free - virtually. Way to go if you are on a shoestring budget.

Features packed into the 64-bit XenServer Enterprise edition include an enterprise management software called XenCenter, VM live migration technology, resource sharing and the enterprise storage management.

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit

Card readers for online banking - Some risks

Researchers from the University of Cambridge have published a paper which discusses problems with the introduction of new hand held card readers optimized for online banking in the UK. Here is a part of the abstract:

Continue reading…

Share, its free!
  • Digg
  • del.icio.us
  • Google Bookmarks
  • Technorati
  • Slashdot
  • Reddit