Recently a number of mass media articles have started discussing a JP Morgan "hack" and alluded to 4 other companies that were also hacked. This story has the potential to be really interesting if more details emerge.
Thursday, August 28, 2014
Friday, July 11, 2014
I don't know
Fair warning, this post is going to be very "professional developmenty".
I've watched this scenario play out a number of times already in my relatively short career. A manager asks a question of an employee, and the response is, "I don't know." Followed by an awkward silence while the manager waits for more.
I've watched this scenario play out a number of times already in my relatively short career. A manager asks a question of an employee, and the response is, "I don't know." Followed by an awkward silence while the manager waits for more.
Tuesday, May 27, 2014
Humility in Cyber Security
I'm about to (attempt to) wax eloquent about the philosophy of cyber security, so this post will probably get real existential (and perhaps not terribly applicable). Credit to John Strand for bringing up some of these talks during a recent conference.
A common adage on the elementary school playground is, "There's always someone out there bigger, stronger, and faster than you."
A common adage on the elementary school playground is, "There's always someone out there bigger, stronger, and faster than you."
Tuesday, May 20, 2014
Blackshade: What does it mean for you
A new cyber security story has hit the news this week: Blackshade. The FBI put out a notification about it, so it's likely to get some play in the media. But what is Blackshade and what does it mean for you?
Tuesday, May 13, 2014
How long will our hearts bleed?
Here's an interesting tidbit: Google shows you a lot of information about your posts and the traffic to them.
This is especially interesting because of this article. I first posted it a couple days after Heartbleed came to light when there was lots of attention and activity. But now, weeks later it's still getting a decent amount of traffic. And it certainly isn't the only article about scanning for Heartbleed with nmap (one of my favorites), so we can assume that those other posts are getting as much or more traffic.
This is especially interesting because of this article. I first posted it a couple days after Heartbleed came to light when there was lots of attention and activity. But now, weeks later it's still getting a decent amount of traffic. And it certainly isn't the only article about scanning for Heartbleed with nmap (one of my favorites), so we can assume that those other posts are getting as much or more traffic.
Friday, May 9, 2014
Heartbleed: Scanning Uncommon SSL Ports
Alright, I lied in a previous post. Definitely not done riding the Heartbleed bandwagon.
While we were scanning for Heartbleed at my company, it mostly helped us find systems that were vulnerable when the vendor or system owner claimed it was clean (That's a fun conversation to have with a system engineer).
While we were scanning for Heartbleed at my company, it mostly helped us find systems that were vulnerable when the vendor or system owner claimed it was clean (That's a fun conversation to have with a system engineer).
Subscribe to:
Posts (Atom)