I hate being advertised to. I can’t watch cable TV (which I already pay for), listen to the radio (even subscription satellite radio has ads now), goof off on the internet, play a video game, drive in my car, read a magazine, buy groceries, or check my e-mail/snail mail/answering machine without being bombarded by coupons, billboards, commercials, in-game ads, Google AdWords, spam, telemarketing, and third class junk mail. The sad fact is, advertising is everywhere. Opinions and research vary widely on the question of how many advertisements Americans see during a typical day, with estimates ranging from a few hundred to a few thousand. (via Google Answers) So, it’s no surprise that the advertisement industry is always trying to come[…]

Jeff over at Coding Horror lashed out at the MENSA web site today, after discovering that their web site uses a presumably weak password storage mechanism that stores passwords in a recoverable format. The main point is that because the passwords can be retrieved by the application and sent back to the users, then they must be stored in a way that would allow an attacker to obtain a list of all (or some) of the passwords in the system. One primary reason that this is seen as a bad thing is that many users use the same password for all of their various accounts, and therefore if the password is compromised in one place, it’s compromised everywhere. Apparently, according[…]

Another lost laptop story, this time from the UK. The details of the theft aren’t too unique – laptops with sensitive patient data were stolen from a hospital and a doctor’s house, and while the files were supposed to be encrypted, they weren’t. This story, much like every other data leak story, brings up the same arguments for why it isn’t a big deal: “The data, which also cannot be accessed without passwords, contained patients’ names, postcodes, hospital numbers and dates of birth.” (Emphasis added) Passwords are ridiculously weak forms of security, and, if the files aren’t encrypted, chances are the statement that access is impossible without a password is most likely just flat-out wrong “However they insisted there was[…]

From DarkReading.com: With all the talk about hackers launching attacks from legitimate Websites, you’d think that the major security vendors’ sites, at least, would be vulnerability-free. Not so, according to a report issued yesterday by a security watchdog site. The site, XSSed, states that it has verified some 30 cross-site scripting vulnerabilities spread across the Websites of three of the industry’s best-known security vendors: McAfee, Symantec, and VeriSign. The vulnerabilities could make it possible for attackers to launch phishing campaigns from these sites or even distribute malware to the companies’ customers, according to XSSed. Cross-site scripting vulnerabilities aren’t a new type of threat, and they aren’t particularly difficult to defend against. It seems a little crazy that the companies that[…]

There’s an old saying that the great thing about standards is that there are so many to choose from. This is clearly evident in the Health Care IT arena. The standards landscape is getting a little crowded, despite the fact that the push to actually integrate and support these standards seems to take a back seat to refining and creating more and more of them. Right now, I’m dealing with several of these standards at once – SAFE, XAdES and CDISC ODM to be specific. And, this is just a tiny fraction of the health care IT standards collection – there are more than 200 entries on the so-called “short list” of standards that apply to electronic records in the[…]

According to Network World, the federal government is stepping up its commitment to data security by adding full disk encryption software to 800,000 laptops. This is pretty encouraging, but there are still a lot of laptops and portable devices left to go. The software products, which are being purchased through the Data at Rest program, is only costing the government about $10 per license. This is good news for everyone as taxpayers, and it’s also encouraging in that budgetary concerns are unlikely to prevent agencies from continuing to secure more and more devices against data loss from theft or misplacement. It’s always nice to read about companies or government agencies being proactive about security. While this may be an overdue[…]