So far, nothing has happened today with Conficker except that it’s phoned home to get new instructions, which it has done before. I’ve been unable to find any reports of disaster, or even misuse of network resources anywhere I’ve looked. Has Conficker done anything to you or your organization (other than be an annoyance)? I’d like to hear reports in the comments. For me, my home network is all Unix systems, and no Windows, so nothing to report there. No one in our office picked it up, but some colleagues of mine (not security people) were infected and merely removed the infection and went on with their lives.

Recently I’ve been receiving a lot of email in Russian. I don’t know why, does anyone? If it is spam, it’s not very effective, because I can’t read it. Would be nice if my email provider gave me a way to auto-spam all email that was in a language I didn’t have a hope of reading. I’ve received another interesting pair of emails on the same tactic. These are standard trojan/phishing attacks, but the tactic of the email is new: Bank of America Warning: Automatic Installation failed for Bank of America certificate component. The only thing you can do at the moment is to install the 4.12.2009 version from our website. That is the same application with the new publisher[…]

C-SPAN recently aired a discussion with Eugene “Spaf” Spafford, a computer science professor at Purdue University (also know for his work in analyzing the Morris Worm of 1988). The interview touches on many aspects of the computer industry, specifically with regards to security and privacy, and offers some interesting perspectives on a lot of the issues we deal with today. The question-and-answer session is very informative and should be generally easy to follow for people unfamiliar with computer security. Topics discussed include everything from the capability of the Internet’s infrastructure to withstand a localized attack, to the controversial “pay-per email” theory of reducing spam. One specific item of interest mentioned by Professor Spafford was the idea of endpoint security. When[…]

The other day, Peter wrote about an unreasonable investment in cryptography and information security. Walt and I both chimed in with our thoughts, but take for a moment the investment criminals make. Ignoring this fact is often the reason government officials, the media, and overprotective parents take extreme security measures that are really just theater. As we’ve mentioned many times before, a determined attacker can always get to your data. Then again, you could also get a free iPhone by beating up some kid who has one, but you won’t. The investment is unreasonable with huge risks (not to mention a small reward). An organized crime syndicate could probably get their hands on a few though by paying people to[…]

I’ve been playing with Windows 7 Beta since its official release. As most have expected, it really is much like the current Vista. But I’ve noticed enough tweaks to be inspired. It can really be looked at as like the jump from Win98 to Win98 2nd Ed. It definitely improves over Vista, and so far, every way is better (at least to me). There are quite a few GUI and UI changes, but I’m not going to get into those. What I’ve focused on so far is tracking down any and all security related items that seemed to irk me in Vista. One of the first things I checked out was UAC. They changed it slightly but mostly just to[…]

I’m sure if you’ve been paying attention to any of the tech/geek news blogs you’ve seen the attention given to the “COMPROMISING ELECTROMAGNETIC EMANATIONS OF WIRED KEYBOARDS” article. So you already know the buzz, and are probably all running out to build Faraday cages around your offices or workstations. But there really isn’t anything terribly new or ground breaking here. It’s simply a further spin on an old trick. Anyone who can remember back might recall a little something about “TEMPEST“. It’s the codename given to compromising emanations (CE). This research dates all the way back to 1985 when the security risks of emanations from computer monitors was analyzed. By no means do I want to take away from the[…]