Today the Internet knows what you’re doing, who your friends are, and how much money you make. The Internet knows when you were born, your favorite books, and turn-ons.

The Internet knows these things because we tell it – and it makes it easy to do so. The problem is, once we tell it something it never forgets. The Facebook account deletion debacle is a microcosm of the problem.

Recently I had a customer ask me When would you recommend an EV Certificate over a standard SSL certificate? My response was simple: only when the business determines that having the green address bar outweighs the additional cost. The green address bar is looking to replace the gold lock in the bottom right as the standard for secure web sites. The below picture is Microsoft’s demonstration for EV SSL graphical interface: There is no difference between a $15 GoDaddy Standard SSL certificate and a $1500 Verisign Secure Site Pro with EV certificate, at least thinking about cryptographic strength and browser acceptance. Should there be? Yes, the EV certificate does a stronger check against the issuer and the subject, and gives[…]

Um, botnets have been an existing problem for sometime now. According the FBI press release, here’s what you can do to protect yourself. Make sure your anti-virus software is up to date, install a firewall, use complicated passwords and be careful opening e-mail attachments and advertisers’ links on Web sites, the bureau advised. Sentences like that are exactly the reason the public is confused. Use complicated passwords for what? Protections need to be built into the system.

Some in the pharma industry have begun to outsource the testing phase of drug research to 3rd party companies. With an approaching U.S. presidential election in which health care will be a major issue, the drug makers are clearly in the political cross-hairs. What this may mean for security, in the short term, are budget cuts. Cutting security shows up in the bottom line immediately – but eventually ends up costing more in the long term.

Just rereading this article over at SecurityFocus and wondering… An American computer security consultant on Friday admitted to using massive botnets to illegally install software on at least 250,000 machines and steal the online banking identities of Windows users by eavesdropping on them while they made financial transactions. Out of those 250K machines, how many are not home user machines? I’m guessing a larger number than anyone expects. Having worked my inlaws through a few malware infestations personally, I can tell you that the stuff is insidious. Virus scanners can’t detect it, or are disabled by it. Out of 4 spyware scanners I tried, only a combination of a few of them were able to find and remove it. Are[…]

Our friends over at worse than failure have posted a pretty funny article about implementing “bank-level security”. The idea behind Two-Factor authentication isn’t too complicated. Simply (1) verify that a user knows something, and (2) verify that he physically has something. This could be done with a (1) name and password, and (2) one of those key fob things or even a print-out of one-time use codes. Banks, however, weren’t too happy with the requirement of implementing such “costly” changes and instead chose to invent the Wish-It-Was Two-Factor authentication. In this method of authentication, they (1) verify that a user knows something, and (1, again) verify that a user knows something else. Two-factor security does not mean you know your[…]