Sunday, 15 March 2009

Excellent podcasts

I was recently introduced to podcasts by finux on Hacker Public Radio

finux is a very talented guy who I met during a trip to the University of Abertay in Dundee. His podcasts are well worth a listen. You can also find him on his Linux Society blog

Wednesday, 11 March 2009

Fame at last

OK - it had to happen, someone finally posted a video interview of me to YouTube. It's all about blended attacks and was recorded at the Combating Cybercrime in Betting & Gaming conference in January this year. I'm quite pleased with the interview, but I hate to imagine what the YouTube viewers are going to say! :-)

Tuesday, 20 January 2009

Gary McKinnon

As someone who works to combat cybercrime and cyberterrorism you may be surprised that I am very much against the extradition of Gary McKinnon. However, I am also someone with intimate knowledge of Asperger's syndrome in two members of my immediate family. As a result, I had the privilege of meeting and discussing Asperger's with the UK's foremost authority, Dr. Simon Baron-Cohen during a diagnosis some years ago. Dr. Baron-Cohen has lucidly explained the condition and the potential impact of incarceration on Gary here. I have no doubt that if he believes Gary has Asperger's then that will be the case.

The IT industry not only contains more than its fair share of people with Asperger's, it also benefits significantly from their intelligence and intense focus. If you work in IT you probably know several people with this condition, although you (and they) may not realise it. We need to try to understand them, to celebrate their positive contributions and to make allowances for some of their apparently obsessive behaviours. You may even be interested to test your own Autism-Spectrum Quotient or to support the National Autistic Society.

Wednesday, 10 December 2008

Identifying compromised credit cards

I just received news of a new Team Cymru no-cost service for worldwide Financial Institutions.

Their BIN ('Bank Identification Number') feed comprises a near real time list of accounts and credit cards that have been identified as being compromised. This data comes from Team Cymru's unique insight into the Underground Economy.

Representatives of Financial Institutions can email outreach@cymru.com with details of their BIN/IIN numbers. Team Cymru will provide access to a secure web portal where Financial
Institutions can obtain a regularly updated list of their own compromised accounts. Details of the compromised accounts of other Financial Institutions will not be available.

for further details of this new service.

Team Cymru provide no cost data sets and services to the community. Take a look at their site for details of the extensive work they do for the security community as well as further advice, data and tips to help you make your networks more secure: http://www.team-cymru.org/Services

Thursday, 6 November 2008

Telecommuting

I've been working from home a lot more since my replacement hip operation a year ago. It started as a necessity, but I found it very productive and stuck with it. Now I've got to the point where I miss my colleagues and the general office banter, so am adjusting my routine to include more days in the office (it's only 15 minutes away, so not much of an effort). Thinking about this, I remembered a wonderful sequence of Dilbert cartoons.

However, as more and more organisations give employees the flexibility to work at home, I can't help wondering about the impact on security ... unencrypted (or WEP-encrypted) home wireless networks ... kids playing with company laptops ... unencrypted hard drives ... no clear desk policies ... poor physical security ... and an increasing trend for staff to use their home computers to connect to company VPNs. Scary stuff.

Perhaps we ought to consider expanding ethical hacking and audit to include home networks and PCs?