[ View menu ]

Monthly Archive December, 2008

Some good predictions for 2009

Sorry if you were expecting something big. Usually the best next year’s predictions are the dullest ones. Until now I found these from Andreas Antonopoulos the best. But what do I mean by best?
Best as those with the biggest chances of being right. According to the Black Swan theory (funny, I remember Antonopoulos and Dan Kaminsky [...]

New Kids on the Block Cipher

Seriously, their research is awesome…but the picture…OMG!

War and Information Security

Andrew Hay has posted a very nice piece on how war strategies evolved and how that compares to information security. He finishes it with this very nice line:
“I believe that all security professionals should be students of military history and tactics. Seeing what failed for great generals will show us how to adapt to, and [...]

Phishing now installing malware…NEW?

I was LOL when reading about this “new stuff” from Network World today. They are saying that last August phishers started to change from trying to get information from victims to tricking them into installing malicious software? LAST AUGUST? Hey, that is happening in Brazil for years by now.
In Brazil the banks were suffering with [...]

Why people stick to IE…or why should they change?

It’s interesting to see some reactions afters the IE 0-day thing that happened last week.  There is one that always appear on these situations, the old question “why people don’t change from IE?”.
First, I believe this question should be answered in two parts, home users and corporate, with the final answer being the result of [...]

2009 predictions

Everybody is doing that, so I’ll try some too. But I won’t try any bold move here, like Paul Asadoorian did
I’ll mention four main things:

Apple threats: the number of people using Macs is growing very fast. It is starting to become something attractive for botnet herders, specially because almost all Mac users don’t [...]

Keep alive

As all the bloggers sometimes do, I’ll also post a simple “keep alive” here just to show that this is not a abandoned blog
It is holiday season, with guests at home, more things to do at work and too few interesting things to comment out there. So, please don’t unsubscribe, I’m keeping some [...]

Can good programmers be part of a SDLC?

I’ve just read this small article from Paul Graham, called “The other half of ’Artists Ship’”. The key point of the text is this:
“For good programmers, one of the best things about working for a startup is that there are few checks on releases. In true startups, there are no external checks at all. If you [...]

AV on Mac

Of course you will need that, as even Apple is sayingnow. I can say that the need for anti-malware is one of the “growing pains” for end user Operating Systems. Soon they will start to suffer from backward compatibility issues, “too dumb” users, bad written applications and other problems that WIndows had to deal with [...]

VP has taken the red pill

My friend VP has just discovered that everything is broken.
He is talking about his last work on pentesting web applications. I had the same feelings about basic network infrastructure, like privileged credentials, file shares, the xyz-illion unidentified devices plugged to the network.
The interesting part of this job is not realizing that everything is broken. He [...]