Posts

ThinkstScapes on Risky.Biz

We spent a bit of time on Patrick Grays excellent Risky.Biz this week, to talk about our ThinkstScapes service. We have been running ThinkstScapes for about 4 years now, and (so far) have never had a cancellation yet. (We take this to mean that people generally like it!) As part of the show, we gave away a free issue of the 2nd Quarter Research Roundup Issue for 2014. If you are not a subscriber, you can grab your [ free copy here ]* * Also: Why aren't you a subscriber? mail us at info@thinkst.com to make it happen .

(Waaay overdue) 2013 - the year in review..

Image
At the end of last year we did BlackHats 2013 year in review. It was a webcast (which means you are spared seeing our faces, but not from hearing our voices or seeing our slides ). Although its probably slightly dated, we think theres some value in it for those who didn't dial in. You can grab a copy of the slides in PDF here , and can watch the video below: ( talk starts at 2m07s ) Ps. We know it's dreadfully late to post the content, and have no good excuse for it. A friend asked for a copy & we realised we never put it up here.. (we promise to to do better!)

What the Snowden leaks mean for South Africa

Our ITWeb Security Summit keynote this year covered the Snowden Leaks from a South African point of view. Our talk was based on ideas we articulated in an op-ed piece for Al Jazeera last year, titled: " Silicon Valley, spy agencies and software sovereignty " ITWeb has already uploaded the video (Go ITWeb!) - Below you can grab a version of the video, with the slides added as an overlay (if nothing else, it makes the nasal voice more bearable)

"When we win, it is with small things, and the victory itself makes us small"

Image
The video from the 44CON talk ( A talk about (infosec) talks ) we gave in September has been posted to YouTube. You can grab the slides [ here ] | You can watch the video online [ here ]

Phish your company, before someone else does!

Image
Today we are happy to release to the public: http://phish5.com Simply, Phish5 is Phishing as a service. It allows a fairly unsophisticated user to phish users in her organization, quickly, easily and from the comfort of her own browser. Why would we do this ? In the past year, a host of high profile news organizations were phished, and then publicly spanked. The attack that compromised the AP's twitter account [ Verge ] even led to a visible dip on the Dow. If you talk to security folks, they will quickly dismiss Phishing attacks with a trite: "Educate your users" Unfortunately, in any reasonably sized organization, this is not a trivial task & learning requires constant reinforcement. Phish5 exists to help with this. A super short registration process, and users can enter a list of victims, create phishing mails, create phishing pages and track results. The whole process should take less than 5 minutes! Phish5 means that you can track peoples behaviour changing over ...

Introducing Consli, easy scheduling and feedback for conference organisers and attendees

The number of security conferences shows no signs of slowing down, feeding an ever-growing appetite for talks, presentations and content . If you're anything like us, both attending and speaking at conferences is part and parcel of your job, even if it's one event per year. In the absence of publication channels available in other disciplines such as good quality journals, security researchers have the option of blog posts, ezines such as Phrack, mailing lists or conferences. Many choose to go to conferences. It's a source of regular wonder that computing/IT conferences are still so heavily paper-based. Your conference pack is typically a sheaf of papers that includes, at a minimum, a schedule and a set of feedback forms. They lead to a few headaches for both attendees and organisers. Larger events have schedules where multiple talks happen in parallel. Planning my conference day involves circling talks I want to see, changing my mind, scratching out talks, circling others....

ThinkstScapes 2013-AH1: On the China report

The Mandiant APT1 report that was released a week ago has been causing some consternation, which makes it a ripe topic for our ThinkstScapes service . This morning, we issued an ad-hoc update to our customers containing our views of the APT1 report. In short, the data is interesting, but does not conclusively point to Unit 61938. There are too many open questions to justify the finger pointing. Take, for example, the markers released for the APT1 group. The report does not contain sufficient data to replicate the grouping of attackers bearing those markers into a single cohesive unit. By Mandiant's own admission the presence of a single marker is insufficient to tag an attacker as APT1, but thresholds are not provided for the number of markers required. In the end, it appears as if the classification boils down to an analyst's opinion, metrics are absent the public report. The entire report is founded on the notion that APT1 exists and is definable; should this not be the case...