|
Archive for January, 2008
Thursday, January 31st, 2008
For an almost daily fix of forehead slapping disbelief, head on over to the Breach Blog. We believe that this blog will be a busy one throughout 2008: “Unfortunately, this past year was a record year for data breaches, according to a couple of groups. (Although, I’m not sure that statement is completely true. It seems more to have been a record year for reporting breaches, due to a number of new factors. Incident reporting has always provided only a partial view of actual events.)”.

This steady stream of sensitive data flowing into other hands continues to raise questions around “Server in the sky” efforts by government intelligence agencies.
Posted in Security breach | No Comments »
Thursday, January 31st, 2008
Broadband users around the world often don’t think much about uninterrupted access to online resources, relying on the massive web of cables across the globe. But today, Egyptian, Indian and other users of the internet suffered major interruptions to their online activity, because an underwater Mediterranean internet cable was severed (audio link). Reasons for the interruption may go unidentified for another week. Update: Renesys blogged about the countries initially impacted, the isp’s and carriers in the region, a set of five effected countries and their isps before and after the event, and a report on how Iran was not taken off the grid altogether. It’s a fascinating series for those interested in the physical connections of the internet and their relevance to entire regions of the globe.
So how might this event effect decisions and issues around computer security? There isn’t a whole lot that behavioral based client side software can do about a severed submarine cable. But when this sort of contained client side solution that is not dependent on constant updates is compared against “herd mentality” and update-driven technologies, the security technology that is effective against malicious activity, independent of online database access and updates, has an advantage during regional interruptions like this one. Activity in the region continues on, including malicious activity. Phone home solutions are dead in the water, and self contained solutions continue protecting their client.
Posted in Uncategorized | No Comments »
Tuesday, January 29th, 2008
The Storm continues to fall, and while their Valentine’s Day message started early in January 2008, we see users continuing to fall for the sweet message of love. Tonight, we observed this site serving up malicious love from Flint, Michigan. The usual set of encoded javascript exploits accompany this lacy heart and “withlove.exe” executable. Do not visit this malicious web site, a slight variation on a Storm site we blogged on earlier this month:

Posted in Exploit, Storm | No Comments »
|
|
|
|