I recently came across a paper by Atul Prakash Analyzing Websites for User-Visible Security Design Flaws which discusses some findings in a recent survey of 214 financial institutions conducted in 2006. The origin of the study came about when Prakash notices many of the below listed flaws in his own financial institutions websites. The top design flaws that Prakash and his team were looking for were: Placing secure login boxes on insecure pages: A full 47 percent of banks were guilty of this. A hacker could reroute data entered in the boxes or create a spoof copy of the page to harvest information. In a wireless situation, it’s possible to conduct this man-in-the-middle attack without changing the bank URL for[…]
Category: general
The web becomes a more threatening place each and every day. This is especially evident due to the uptick in legitimate websites being compromised to push malware. ScanLife reported increase of over 400 percent last month. So, what is going to help alleviate these threats? I’m pushing for more secure code. Microsoft issued a security advisory last week that offered companies free tools to help scan for SQL injection vulnerabilities. Another area that’s helping to secure code is the new PCI Data Security Standard section 6.6 guidelines that just went into effect. Under the new rules, merchants need to implement a web application firewall and/or conduct a complete code review by a 3rd party. It is vital that secure code[…]
RFIDs can switch off equipment used in hospitals. Researchers tested several types of devices used to save lives in close proximity to RFIDs and found that the devices, in a number of instances, interfered with the equipment’s functioning. A total of 123 tests, three on each machine, were carried out, and 34 produced an “incident” in which the RFID appeared to have an effect – 24 of which were deemed either “significant” or “hazardous”. The use of RFIDs in hospitals has begun to grow. The devices are being used for tasks such as patient identification, inventory management, and allowing only relevant hospital staff to view a patient’s medical records. Hospitals will need to consider the new findings as they continue[…]
According to this article instances of malware infections have been increasing over the past few years. In fact, nowadays malware typically makes up the majority of all new software applications developed for Windows-based PCs. As a result, it is becoming more and more difficult for security products and vendors to detect them all. The typical way they do this is by blacklisting these programs. As soon as malware shows up on your computer, they can (usually) be detected. Since malware is becoming harder to blacklist, one suggestion is to keep a whitelist— a list of all programs that should be trusted. This differs from a blacklist, which lists programs that should not be trusted. This suggestion was implied by both[…]
At the recent InfoSec conference in London, Secure Computing conducted a survey of IT managers. Their findings are interesting: Over 80 per cent of respondents said that data leaks by insiders, whether deliberate or accidental, is at the top of their list of security woes. Only 17 per cent cited external threats posed by cyber-criminals, such as spammers and hackers, as more dangerous. This shows that insider threats are considered more of an issue than external threats. IT managers have to worry about all of the threats to their systems and data, and to that end, they analyze each threat and assign a risk level to it. Obviously, this group of managers consider internal threats a higher risk than external[…]
Throughout our lives we are taught, beginning from when we are children, to never say never. A good philosophy since nothing in the universe is absolute, just a matter of probabilities. The reverse – never say always – is equally as true, since again, nothing is absolute.
As security professionals, we’re told to do completely the opposite. We’re encouraged to say ‘never’ and ‘always’ with the knowledge that sometimes those 2 words just don’t apply.