Archive for December, 2009

Scotland will not boycott Commonwealth Games over security fears – Scottish Daily Record

Thursday, December 31st, 2009

Telegraph.co.uk

Flurry of proposals targets air security – USA Today

Thursday, December 31st, 2009

Daily Mail
Flurry of proposals targets air security
USA Today
19 — on air security. Topics to be covered will include security screening and watch lists. "This is a pretty serious security problem," Dorgan said,
Editorial: The system failed | Philadelphia Inquirer | 12/31/2009Philadelphia Inquirer
Lawmakers vow to probe security failuresFederal Times
Obama acknowledges mistakes made in Detroit incidentLos Angeles Times
Foreign Policy
all 100 news articles »

US air passengers willing to trade privacy for security as feds ramp up use of … – Los Angeles Times

Thursday, December 31st, 2009

Washington Post
US air passengers willing to trade privacy for security as feds ramp up use of
Los Angeles Times
By AP SAN FRANCISCO (AP) — As homeland security officials rush to bring more full body scanners to US airports, passengers where the devices are already in
Nigeria to Use Full-Body Scanners to Improve Security at its AirportsVoice of America
Detroit flight plot may prove boon for security firmsAFP
FG upgrades airports' security systemThe Punch
Reuters -CCTV -Canada.com
all 2,022 news articles »

MBE for Aberafan shopping centre security manager – BBC News

Thursday, December 31st, 2009

BBC News
MBE for Aberafan shopping centre security manager
BBC News
A security manager who helped tackle shoplifting and anti-social behaviour in a town centre is to become an MBE. Chris Morgan, 36, from Neath,

and more »

Travel: USA’s new rules are unworkable admits TSA – ChiefOfficers.Net

Thursday, December 31st, 2009

Telegraph.co.uk
Travel: USA's new rules are unworkable admits TSA
ChiefOfficers.Net
The USA's Transportation Security Administration or TSA has said that the new rules – at least insofar as they relate to what happens on an aircraft – are
Nigerian Airports to Increase Security After AttackBloomberg
Mexico airport boosts security after US air incidentXinhua
Airports to boost security after scareDaily Mail – Charleston
TIME -WXXA -New York Times
all 2,963 news articles »

DHS Threatens Blogger Who Posted TSA Screening Directive – Wired News

Thursday, December 31st, 2009

Wired News
DHS Threatens Blogger Who Posted TSA Screening Directive
Wired News
Two bloggers received home visits from Transportation Security Administration agents Tuesday after they published a new TSA directive that revises screening
TSA Subpoenas Bloggers, Demands Names of SourcesNew York Times
TSA targets travel bloggers over leaked security memoUSA Today
Exclusive: TSA Seizes Hard Drive from Travel BloggerHuffington Post (blog)
Plain Dealer -NewsHour -Reporters Committee for Freedom of the Press
all 305 news articles »

Phishing attacks soar in December

Thursday, December 31st, 2009

Phishers represent over half of all web-based threats.

Microsoft denies IIS flaw claims

Thursday, December 31st, 2009

Security response team says there is no vulnerability in IIS 6.0.

Two Cheers for Airport Security – Wall Street Journal

Thursday, December 31st, 2009

The Guardian
Two Cheers for Airport Security
Wall Street Journal
Al Qaeda can still count on the sizeable damage we will inflict on ourselves through an airport security apparatus that specializes in expensive political
RICHARD LITTLEJOHN: Stable door security panic hands victory to the bad guys . . .Daily Mail
Mary Dejevsky: Britain's student visa system is a security breach in itselfIndependent

all 391 news articles »

He Simply Strolled Through a Security System Hole – Wall Street Journal

Thursday, December 31st, 2009

Telegraph.co.uk

Turf war seen at root of security lapse – Financial Times

Thursday, December 31st, 2009

Ha’aretz
Turf war seen at root of security lapse
Financial Times
The intelligence failure has already generated finger-pointing among agencies responsible for US security. The CIA, which jealously guards its primacy in
The clues piled up, but why did US security fail to act over terrorist?Independent
Security services had month's warning about airline bomb plotIreland Online
Attempted terror attack on Flight 253Detroit Free Press
BBC News -Telegraph.co.uk -Jerusalem Post
all 5,258 news articles »

Mexico airport boosts security after US air incident – Xinhua

Thursday, December 31st, 2009

Globe and Mail
Mexico airport boosts security after US air incident
Xinhua
30 (Xinhua) — Mexico City International Airport has boosted security in the wake of the Dec. 25 incident on a Northwest Airlines flight bound for US city
Nigerian Airports to Increase Security After AttackBloomberg
TSA targets travel bloggers over leaked security memoUSA Today
TSA Subpoenas Bloggers, Demands Names of SourcesNew York Times
TIME -Plain Dealer -NewsHour
all 2,534 news articles »

Cary Clack: Terrorist attack serves as reminder – San Antonio Express

Thursday, December 31st, 2009

CBC.ca
Cary Clack: Terrorist attack serves as reminder
San Antonio Express
In the eight years since the attacks of 9-11 we have dutifully and patiently endured the increased security measures at airports. We arrive early, stand in
Point-Counterpoint: Full-Body Scans at Airport SecurityNew York Magazine
New Focus For Airport Screening: Strange BehaviorNPR
Failed bombing sees air security tighten in the UK but not hereGuernsey Press and Star
Washington Post -FOXNews -Telegraph.co.uk
all 8,792 news articles »

Scotland has ‘no plans’ to withdraw from Delhi Games over security fears – Scotsman

Thursday, December 31st, 2009

The Guardian

FG upgrades airports’ security system – The Punch

Wednesday, December 30th, 2009

CBC.ca

Every Software Vendor Must Read and Heed

Wednesday, December 30th, 2009

Matt Olney and I spoke about the role of a Product Security Incident Response Team (PSIRT) at my SANS Incident Detection Summit this month. I asked if he would share his thoughts on how software vendors should handle vulnerability discovery in their software products.

I am really pleased to report that Matt wrote a thorough, public blog post titled Matt’s Guide to Vendor Response. Every software vendor must read and heed this post. “Software vendor” includes any company that sells a product that runs software, whether it is a PC, mobile device, or a hardware platform executing firmware. Hmm, that includes just about everyone these days, except the little old ladies selling fabric at the hobby store.

Seriously, let’s make 2010 the year of the PSIRT — the year companies make dealing with vulnerabilities in their software an operational priority. I’m not talking about “building security in” — that’s been going on for a while. Until I can visit a variation of company.com/psirt, I’m not satisfied. For that matter, I’d like to see company.com/cirt as well, so outsiders can contact a company that might be inadvertently causing trouble for Internet users. (And yes, if you’re wondering, we’re working on both at my company!)

Law and order prevails: Lebanon wraps up a year of relative security – Daily Star – Lebanon

Wednesday, December 30th, 2009
Law and order prevails: Lebanon wraps up a year of relative security
Daily Star – Lebanon
Democratic elections, conducted free from the shadow of foreign tutelage for the first time in more than three decades, did not bring the security flare-ups

and more »

2009’s “Most-Hacked Software” Named

Wednesday, December 30th, 2009

It’s that time of year again: the time at which all sorts of organizations put together lists naming the best and worst things they’ve seen over the past 12 months. Below, you’ll find out what Forbes and iDefense determined to be very much in the “worst” category, as they got together to name “The Year’s Most-Hacked Software.”

2009's 'Most-Hacked Software' Named
2009’s “Most-Hacked Software” Named

The big non-award goes to Adobe Reader. A whopping 45 bugs were found in it, which obviously isn’t great, averaging out to about one per week. Microsoft’s Internet Explorer came in second place with a better – but still not good – 30 bugs.

Next up is what may be a more surprising pick in the form of Mozilla Firefox. It was plagued by 102 bugs. Just don’t try to perform an apples-to-apples comparison with other contenders, since the open source nature of Firefox means that all of its issues are discussed in public.

Then we go back to Adobe with Adobe Flash. Apple Quicktime followed. Microsoft Office was next, and finally, Windows wrapped up the list.

Perhaps this naming and shaming will encourage companies to do a better job of making their products safe. If not, at least it acts to provide security vendors and individuals with a little more information.

Amsterdam airport to beef up security – ABC Online

Wednesday, December 30th, 2009

The Guardian
Amsterdam airport to beef up security
ABC Online
Amsterdam's Schiphol Airport will begin using full-body scanners within three weeks to scan people travelling to the
Nigerian Airports to Increase Security After AttackBloomberg
Airport Security Cos Rise Again As Dutch To Use Body ScannersWall Street Journal
Failed attack highlights airport screening proceduresWashington Post
Spiegel Online -CTV.ca -Times Online
all 1,558 news articles »

Two of England’s big track hopes admit they have their own security fears over … – Daily Mail

Wednesday, December 30th, 2009

Sydney Morning Herald
Two of England's big track hopes admit they have their own security fears over
Daily Mail
By Sportsmail Reporter Two of England's medal-winning Commonwealth Games athletes have expressed their fears about the possible threats to their security at
England calm Delhi Commonwealth Games security fearsBBC Sport
Commonwealth Games England will not make final Delhi decision until SeptemberTelegraph.co.uk
Security fears for GamesNEWS.com.au
AFP -Wall Street Journal -Daily News & Analysis
all 522 news articles »