via /.—A “certified ethical hacker” has written an article on how best to protect your own identity. Nothing tremendously new here (tips given include shred your papers, don’t carry your social security card in your wallet, get frequent credit reports)… but it’s good to have all this information in one place. The biggest thing I tell people is don’t be afraid to ask questions. If someone asks you for personal information, either online, on the phone, or in person, the fact that they are asking for it will provide them an aura of authority. Don’t let that stop you from asking them all the questions you need to in order to keep your identity safe. I never provide any information[…]

I know this has nothing to do with “information security” but… From CNN, Air travel in chaos after plot to bomb airliners exposed. I think Bruce Schneier said it best in today’s post on his blog: A collection of 11 prison shivs confiscated over 20 years ago in New Jersey. Think about these, and the adverse conditions they were made under, the next time you see someone’s pocket knife being taken away from them at airport security. We can’t keep weapons out of prisons; we can’t possibly expect to keep them out of airports. Preventing against liquids on planes, like taking away fingernail clippers, is just one more step in a direction which doesn’t provide us any more security…

What’s the difference between the following strings: ldap://myserver.mycompany.com/ ldap://myserver.mycompany.com LDAP://myserver.mycompany.com/ LDAP://myserver.mycompany.com Give up? Several hours of debugging, that’s what. In the .NET world, the System.DirectoryServices namespace contains classes named DirectoryEntry and DirectorySearcher. To search an LDAP directory, you created a DirectoryEntry based on the server address and DN to specify the root of your search, and then create a DirectorySearcher, passing in the DirectoryEntry to the constructor. This can be used to search any ldap directory. So, you would think that you could pass in any valid LDAP URL into the DirectoryEntry class, right? Wrong. Microsoft’s implementation of the DirectoryServices namespace is build upon ADSI. So, the URL you’re passing in isn’t a typical URL at all. It’s based on[…]

You can read over at F-Secure the story of Netscape.com from a few days ago. Not withstanding the fact that the new Netscape.com is a blatant rip-off of Digg, it was kind of funny to see the fact that a company with as strong a perceived brand as Netscape making the rookie mistake of not preventing XSS from being stopped in user comments. Just a few days earlier, Myspace was attacked by the Flash worm, which spread thanks to XSS and a vulnerability in the ubiquitous Macromedia/Adobe Flash Player. To all you web developers: wake up! XSS is a serious threat. The combination of the Web 2.0 style sites—where everyone is creating content—and the threats of phishing and/or destructive viruses[…]

Data, laptops, etc. make headlines when they get stolen. Not good news for the companies that get heisted. Of course companies, governments and the like don’t want bad publicity. They hide or make excuses – implementing damage control as fast as possible. Boy, do they sure feel good about themselves when that missing laptop with your social security number on it is found. Take this article for example. A laptop computer containing personal information on more than half a million New York state workers has been found after it disappeared May 9 from the offices of a third-party data management company. Excuse me, when did you say the laptop went missing? May 9th did you say? The point is that[…]

Came across this article via digg. A sad story is told how the “Director of Data Security And Compliance” was fired from his job due to incompetence after a break-in and theft left the company with hundreds of thousands in replacement and labor costs. The fired person’s story is that he tried to convince his management to implement all kinds of security controls that would have prevented this, but they chose not to due to cost. Whether or not the story is true, a few lessons can probably be learned from it. If your job is to ensure your company is secure, and you’re recommending something that is absolutely required, don’t take “no” for an answer. Your job could end[…]