Bejtlich OWASP Podcast Posted

March 10th, 2010

My appearance on OWASP Podcast 61 is available.

The .mp3 is 36 MB. Thanks to Jim Manico for inviting me to participate.

We recorded the podcast in late January. Jim asked me the following questions:

  1. Would you care to tell us how did you get into IT and what lead you into a career in information security? What keeps you busy these days?
  2. What’s the difference between focusing on threats vs focusing on vulnerabilities?
  3. What is your problem with the “protect the data” mindset?
  4. What do you mean by “building visibility in”?
  5. What is your take on the Aurora/Google hack?
  6. You just tweeted that “Network Security Monitoring ideology is the proper mechanism to combat APT/APA”. Do you think network IPS/IDS/WAF can help defend insecure web applications? What are the limits of Network Security Monitoring?
  7. How important a role do you think secure coding and secure software development life-cycle play in defending the enterprise?
  8. Have HIPAA, PCI, SOX and other regulations helped reduce risk in the average enterprise?
  9. Is seems pretty clear that attackers have a clear advantage. Why is that? How can we turn the tide?
  10. Any thoughts on OWASP? Are we helping the cause?
  11. Where are we going to be as an industry in 10 years?
  12. You blogged that “The trustworthiness of a digital asset is limited by the owner’s capability to detect incidents compromising the integrity of that asset.” Given that we don’t have any high integrity database, identities or application servers – how do you detect a breach of integrity when there is no verifiable integrity in the system in the first place?

Behind the scenes, crafting the US no-fly list – The Associated Press

March 10th, 2010

Seattle Post Intelligencer
Behind the scenes, crafting the US no-fly list
The Associated Press
It ends when a person is forbidden to board an airplane — a decision that's in the hands of about six experts from the Transportation Security
AP Source: No-Fly List Doubled Since NW PlotChristian Broadcasting Network

all 301 news articles »

Security law in full force Thursday – Thai News Agency MCOT

March 10th, 2010

Bangkok Post
Security law in full force Thursday
Thai News Agency MCOT
BANGKOK, March 10 (TNA) – The Thai government on Wednesday tightened security at key government offices and public transportation hubs before enforcing the
Thai security force put on alert over bomb attack warningXinhua
Security tightened on 30 to 40 areas prone for bomb attacksThe Nation
Thai cabinet resolves to impose act for mass rally securityPeople’s Daily Online
Bangkok Post -The Nation -Bangkok Post
all 30 news articles »

Thailand’s upcoming mass rally sees no winner – Xinhua

March 10th, 2010

Malaysia Star
Thailand's upcoming mass rally sees no winner
Xinhua
By Xinhua writer Shi Xianzhen BANGKOK, March 10 (Xinhua) — With just three days before the planned major anti-government rally in Bangkok, security has
Thai protesters say security law won't deter themMalaysia Star
Thailand invokes security lawCCTV
Tourists told to avoid weekend protests in Bangkokmsnbc.com
Bangkok Post -Sydney Morning Herald -UPI.com
all 85 news articles »

The Limits of Identity Cards

March 10th, 2010

Good legal paper on the limits of identity cards: Stephen Mason and Nick Bohm, “Identity and its Verification,” in Computer Law & Security Review, Volume 26, Number 1, Jan 2010. Those faced with the problem of how to verify a person’s identity would be well advised to ask themselves the question, ‘Identity with what?’ An enquirer equipped with the answer…

Chinese man Haisong Jiang charged after Newark Airport kissing chaos – Daily Mail

March 10th, 2010

Sydney Morning Herald

Amsterdam Announces Tightening of Airport Security – CompareCarrentals.com

March 10th, 2010
Amsterdam Announces Tightening of Airport Security
CompareCarrentals.com
It now appears that security has been tightened at Amsterdam's Schiphol Airport. This tightening up of security comes after a team of investigative
Reporter Breaches Amsterdam Airport's SecurityNew York Times
Amsterdam airport tightens security at duty freeThe Associated Press
Amsterdam airport tightens security after stingPress Trust of India
Wired News -MoodieReport -WLOS
all 238 news articles »

Tight security on Tibet anniversary – Aljazeera.net

March 10th, 2010

The Guardian
Tight security on Tibet anniversary
Aljazeera.net
China has stepped up security in Tibet as the Himalayan region marks the sensitive anniversaries of the failed uprising against Chinese rule in 1959 and
Tibet security tight for anniversary: residentsSin Chew Jit Poh
Heavy security around Chinese embassyTimes of India
Security tight in Tibet on uprising anniversaryeTaiwan News
Sify -eTaiwan News
all 646 news articles »

US hid waterboarding of 9/11 accused, says former MI5 chief – Telegraph.co.uk

March 10th, 2010

BBC News
US hid waterboarding of 9/11 accused, says former MI5 chief
Telegraph.co.uk
Baroness Manningham-Buller said she only discovered that Khalid Sheikh Mohammed had been waterboarded 183 times
Ex-MI5 head: US concealed tortureThe Press Association
Ex-MI5 chief says US 'concealed suspect mistreatment'BBC News
Ex-MI5 head: US hid torture tactics from UKIndependent
Financial Times -Reuters -New York Times
all 230 news articles »

Thai security force put on alert over bomb attack warning – Xinhua

March 10th, 2010

Bangkok Post
Thai security force put on alert over bomb attack warning
Xinhua
BANGKOK, March 10 (Xinhua) — Security forces have been put on alert after it is reported that some 30 to 40 areas in capital Bangkok might be targeted for
Thai cabinet resolves to impose act for mass rally securityPeople’s Daily Online
Security tightened on 30 to 40 areas prone for bomb attacksThe Nation
Govt ready to handle red-shirt protestersBangkok Post
Thai News Agency MCOT -Business Times (subscription) -Bernama
all 30 news articles »

Review: Astaro Security Gateway 7.5

March 10th, 2010

A hardware appliance that provides many different security features rolled into one appliance.

The Network Security Podcast, Episode 188

March 10th, 2010

Can you hear that? That’s the sound of air escaping as we all finally recover from the RSA conference. Rich and Martin are back, and Zach… never left (but did celebrate a birthday last week). We do a quick recap of RSA and then dig into the security news… much of which had nothing to do with the conference. Weird.

Network Security Podcast, Episode 188, March 9, 2010
Time:  32:01

Show Notes:


[Slashdot]
[Digg]
[Reddit]
[del.icio.us]
[Facebook]
[Technorati]
[Google]
[StumbleUpon]

Opera users baffled by vulnerability warnings

March 10th, 2010

Security vendors sending out misleading information, claims Secunia.

McAfee warns of scareware plague

March 10th, 2010

Fake anti-virus scams extracting millions from unwary users.

Patch Tuesday sees new fixes and warnings

March 10th, 2010

Company gives details on IE attack along with Office fixes.

Man whose kiss caused airport security scare pleads guilty – CNN

March 10th, 2010

The Age

Vodafone ships handset riddled with malware

March 10th, 2010

Spanish customer buys HTC Magic preloaded with Mariposa botnet client.

Serious flaw discovered in Apache

March 10th, 2010

IT admins warned to upgrade immediately.

News: Change in Focus

March 10th, 2010

Change in Focus

LifeLock to pay $12 mln to settle charges over ads – Reuters

March 9th, 2010
LifeLock to pay $12 mln to settle charges over ads
Reuters
Todd Davis, LifeLock's chief executive, has been known for putting his Social Security number in ads to show confidence in his service.
LifeLock settles with FTC for $12 millionCNNMoney.com
LifeLock To Pay $12M For False Security ClaimsWSMV Nashville
Lifelock fraud alert firm to pay $12M in ad suitThe Associated Press
Seattle Post Intelligencer (blog) -Chicago Tribune (blog) -Hilton Head Island Packet
all 359 news articles »