Posts

(ComputerSecurity) Conference Collecting

Image
We wanted to quickly announce the availability of http://cc.thinkst.com ( a resource in need of it's own domain & a better name .) CC is a simple application that aims to give us a single point where one can search and browse infosec conference talks and materials*. Quick Overview One of the cool things about having all of this data in a central db is that we are just as easily able to search by topic ( http://cc.thinkst.com/searchMore/foo/ ) as we are by speaker ( http://cc.thinkst.com/searchMore/halvar/ ) Finding a speaker we are interested in, allows us to see all the talks (we know about) he has given ( http://cc.thinkst.com/speaker/Flake/Halvar/ ) And also allows us to get a good overview of his public research timeline ( http://cc.thinkst.com/speaker/Flake/Halvar/timeline/ ) One of the "funner" things is the ability to see who the speaker has previously (publicly) collaborated with ( http://cc.thinkst.com/speaker/Flake/Halvar/links ) This allows you to go from ...

Interview with the Infosec Institute

Image
The folks over at the Infosec Network have recently started doing interviews with security researchers. They have interviewed some real rock stars so far ([ Charlie Miller ], [ HD Moore ], [ Joanna Rutkowska ], [ David Litchfield ], [ Matthieu Suiche ], [ Dan Kaminsky ], and [ Jeremiah Grossman ] ) so i was pretty flattered when they asked me.. My interview is up [ here ] complete with dodgy photo and embarrassingly bad answers..

Nothing (really) new under the Sun - Verizon Breach Report..

Image
The Verizon RISK Team has once again released their annual Data Breach Investigations Report. [ Grab it Here ] Once more, the report makes for interesting reading and this year the discussion point is bound to be the marked decline noted in compromised records (From 361 million in 2008, to 144 million in 2009, to 4 million in 2010). We will kick off a ThinkstScapes adhoc update to customers analyzing the report, but thought one of the interesting points to note was the similarity between 2010 and 2011 recommendations. A quick point for point comparison shows that the 2011 recommendations are an almost perfect superset of the 2010 recommendations. The prognosis then? more of the same + a little bit more?

What Anonymous taught us about Cyber War

Image
I wrote a piece on Cyber War, and what the recent HBGary breach teaches us about the current landscape. While I still feel bad for anyone who has their mail spool exposed to the world, the HBGary mails give us an interesting insight into a part of the world seldom seen by all. Check it out [ here ]

Our Upcoming Security Apocalypse!

Image
(This Post was written for ITWeb for the Upcoming ITWeb Security Conference) A security guy talking about impending doom. How rare! Except I'm not talking about the next Botnet, virus or nuclear reactor destroying worm, I'm talking about the crisis of confidence that’s heading our way, and the fact that we seem completely oblivious to its arrival. We (in the field) have been building a house of cards, and some day really soon it's going to come down around us. 10 years ago, the Infosec industry was in its infancy and we complained bitterly about the lack of management buy-in while we struggled to justify our existence in the corporate hierarchy. In the mid 90's we started getting taken seriously. Firewalls and security policies became a part of the corporate lexicon and security teams grew in size. For a while it seemed like the game had equalized, our efforts matched the threats of the day, but the threats of the day were pranksters and kids. We cried "Mission Ac...

Eurotrash Security Podcast

Image
The guys over at the Eurotrash Information Security Podcast had me on last week. We discussed HBGary, Thinkst, ZaCon and a bunch of other stuff.. It was pretty enjoyable (although i tried listening to myself and think its a lucky thing i dont do this too often). You can grab it [ here ]

A freshly etched MacBook Pro (Aka - Welcome Jameel!)

Image
A quick note to Welcome Jameel Haffejee ( email ) to Thinkst. Some of you might remember him as "the guy who did the Power Shell talk at Zacon2" .. (The talk was cool, but (in truth) I remember him as the guy that sponsored the coffee!) Jameel has signed up as a Developer and future world-denter, so you should be reading more of him here soon.. Hello World!