Wednesday, October 12, 2005

Moves to professionalise Infosec

Was at the ISC2 Secure London conference yesterday. Interesting day, and lots of interesting info. Check out which is a site supported by Intellect, the trade body for the UK hi-tech industry. It is currently hosting the working group info for the move to professionalising the information security industry.

Another interesting URL mentioned was which could be of use to your average user.

Interesting stats - from Gartner originally

75% of attacks are at application level
70% of vulnerabilities as at application level


Reducing the number of application vulnerabilities by 50% should lead to a 75% reduction in costs!


Non photo realistic Quake

How cool is that?

Security from the start

Dana Epp discusses building security into code and applications. This seems absolutely obvious but you would be astonished at how many organisations do not have secure coding guidelines or even best practices. This should help any application developers.

Thursday, October 06, 2005

The end for simple vulnerability scanning?

Nessus is dropping the GPL

Could change the way a lot of security consulting firms run the basic section of a security assessment, as nessus - even though it has its issues around false positives - has always been a staple part of the toolkit.

Tuesday, September 13, 2005


free online dating
free online dating
free online dating
free online dating
Friday, June 03, 2005

Thursday, March 17, 2005

A Plan For Scams

Gerv has some good ideas here. Okay, so they have all been discussed before, but they all make sense in the right environment, and together can significantly improve security.

Thursday, March 03, 2005

Sunday, February 27, 2005

Thursday, February 10, 2005

The joy of SOx

Financial Cryptography has another interesting article on Sarbanes-Oxley. The funny thing is the number of companies I have seen who aren't listed on the US Stock Exchange who want to go through something comparable to or exceeding Section 404 requirements. Just in case.

Friday, February 04, 2005

Integrated WIFI Laptop Hack

This is pretty cool. Okay, these days all laptops are likely to have wireless capability anyway, but for those that don't, here's Nermal's Integrated WIFI Laptop Hack

Thursday, January 20, 2005


As this Hack In The Box article shows, there is good information out there for those who do not wish to be caught out by forensic analysis of their computers.

Makes relying on forensics that bit trickier...

Monday, January 17, 2005

How to make windows more like Linux

12 steps to becoming more l33t. I think it's supposed to be pro MS, but some of it definitely looks the opposite to me.

Sunday, January 16, 2005

This article over on Bruce Schneier's blog is interesting, but what is more interesting is the comment and debate fuelled by this. Remarkably similar to the whole open/closed debate in IT Security but for the physical security world.

Sunday, January 09, 2005

Thursday, January 06, 2005

Wired News: India's Odd Couple: Cops and Tech

Mobile users need for power

The New York Times has an article: Power Users, Ready for a Refill which points out something I hadn't really thought about - the need for power when mobile. For me, even if I use my mobile all day, a charge lasts a day - more than a week on standby, my laptop lasts 5 hours (if I'm just working on documents etc) and my main mobile mp3 device is in the car so I hadn't come across this issue. But it seems people with high current devices are desperate for a charge:-)

Sunday, January 02, 2005

