Securosis Blog

$50K buys how much FDE?

Mike Rothman · January 10, 2013

Feds step up HIPAA enforcement with hospice settlement

The Hospice of North Idaho (HONI) in Hayden will pay $50,000 to avoid more costly penalties if it would have been found in violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

Friday Summary: January 11, 2013

Adrian Lane · January 10, 2013

Tina Slankas presented at the Phoenix ISSA chapter this week on use of patterns for building security programs – slides can be downloaded here (PDF). The thrust of her idea was to use patterns – think design patterns if you like – for putting together control frameworks to define security efforts. Tina stated she was using the definition of ‘pattern’ in a very broad way, but the essence was reusable constructs for managing different aspects of enterprise security. For example: how identity…

Integration vs. Segregation

Mike Rothman · January 10, 2013

But, he said, segregation of EHR data simply is not feasible or practical for integrated health systems such as Wellstar, …

Java Sucks. Again.

Rich · January 10, 2013

Zero-day in the wild, in a popular exploit kit.

From Brian Krebs:

The hackers who maintain Blackhole and Nuclear Pack – competing crimeware products that are made to be stitched into hacked sites and use browser flaws to foist malware — say they’ve added a brand new exploit that attacks a previously unknown and currently unpatched security hole in Java.

Most Consumers Don't Need Mac AV

Rich · January 10, 2013

I can’t believe I forgot to post here when I put the article up on TidBITS, but here you go:

DDoS: Distributed, but not evenly

Rich · January 9, 2013

It shouldn’t come as any surprise, but big financials are still suffering a wave of DDoS attacks.

DDoS is like an accidental amputation – there is no question whether it’s a problem. The trick is to know ahead of time if you are on the list, and the best thing to do is keep an eye on your peers. Not everyone needs to invest proactively in DDoS protection, but you sure as heck need a plan and a vendor contact just in case. Especially if you are big, handle money, work with (or piss off)…

Incite 1/9/2013: Never Lost

Mike Rothman · January 9, 2013

I was in the car the other day with one of the kids, and they asked me if I ever get lost. I have a pretty good sense of direction and have been able to read maps as long as I remember. I was probably compensating for my Mom’s poor sense of direction and my general anxiety at a young age about feeling lost. But it’s different today. With the advent of ever-present GPS and decent navigation, I can say it has been a long while since I have really been lost. I get misdirected sometimes, but that…

Detection vs. Protection and the Game of Words

Mike Rothman · January 8, 2013

Any time you go after an entrenched technology, there will be pushback. So it’s not surprising that some folks believe that imperva’s anti-virus study is garbage.

ENISA BYOD FTW

Rich · January 7, 2013

ENISA released a solid BYOD/Consumeriation of IT guide.

At first I was turned off by phrases in the executive summary like:

Prove It to Use It

Rich · January 7, 2013

“Last year, one billion dollars was stolen in the U.S. by Romanian hackers,” says American ambassador in Bucharest, Mark Gitenstein.