Thursday, 6 November 2008

Telecommuting

I've been working from home a lot more since my replacement hip operation a year ago. It started as a necessity, but I found it very productive and stuck with it. Now I've got to the point where I miss my colleagues and the general office banter, so am adjusting my routine to include more days in the office (it's only 15 minutes away, so not much of an effort). Thinking about this, I remembered a wonderful sequence of Dilbert cartoons.

However, as more and more organisations give employees the flexibility to work at home, I can't help wondering about the impact on security ... unencrypted (or WEP-encrypted) home wireless networks ... kids playing with company laptops ... unencrypted hard drives ... no clear desk policies ... poor physical security ... and an increasing trend for staff to use their home computers to connect to company VPNs. Scary stuff.

Perhaps we ought to consider expanding ethical hacking and audit to include home networks and PCs?

Tuesday, 28 October 2008

Team Cymru

An old chum e-mailed me about a very interesting service that Team Cymru has just launched. Here's what he had to say:

This email is to announce a new look-up service that Team Cymru is launching today. The Malware Hash Registry (MHR) service allows you to query our database of many millions of unique malware samples for a computed MD5 or SHA-1 hash of a file. If it is malware and we know about it, we return the last time we've seen it along with an approximate anti-virus detection percentage.

There is no cost for non-commercial use of this tool. Access is publicly available to anyone.

Upon submission of a malware hash, the output of the command will return a date the sample was first seen as well as the detection rate we've seen using up to 30 AV packages. The detection rate is based on the first time we scanned the sample.

Queries, including reasonable bulk queries, may be made using the command line only.

The MHR compliments an anti-virus (AV) strategy by helping to identify unknown or suspicious files that we have already identified as malicious. This enables you to take action earlier than you would otherwise be able to.

Full details including command syntax and procedures can be found at: https://www.team-cymru.org/Services/MHR/

This is one of several new (free) data sets and services we are currently providing to the community; if you haven't visited our (recently revamped) site recently please do so for details of the extensive work we do for the security community as well as further advice, data and tips to help you make your networks more secure:

We very much look forward to working with you all on this new project and we sincerely hope that as many of you as possible will be able to actively participate in the use of this unique and very exciting new service.

Warm regards,
Team Cymru.

Wednesday, 17 September 2008

Cloud computing

Data Security Podcast recently asked me to comment on the security issues in cloud computing - the result is here if you're interested. Nothing revolutionary of course, just best practice and my usual hatred of passwords :-)

Sunday, 24 August 2008

Geek humour

Last week I spent a very enjoyable three days passing along some penetration testing skills to a room full of nice people. Amongst them was a gentleman named Dan from Texas. Dan was good company and a knowledgeable penetration tester - he also recommended xkcd to me and I strongly suggest it to you - it's inspired.

Saturday, 2 August 2008

Le SPAM?

I've recently spent a good deal of time getting my head around French IT terms (including impenetrable phrases such as matrise d'ouvrage) in order to translate some IT security awareness material into English. A few days after I finished the first piece of work, imagine my surprise when I started receiving French SPAM. And, no, it's no more interesting than the English/US version IMHO!

A little head scratching and I realised that my pride had caused me to announce that I was translating French awareness material into English in my "what are you doing at the moment" thingy in Facebook. As far as I can see this is the only place on the web where my translation skills were on display. So - are the spammers monitoring all our Facebook accounts to refine their targets, or am I being paranoid again?

~{:-D