Hurt back yesterday
Too much pain to write much now
Haiku easier
And don’t forget to sign up for our Black Hat cloud security training in December!
On to the Summary:
Webcasts, Podcasts, Outside Writing, and Conferences
- Mike’s Dark Reading article on Shiny and New.
- Rich’s Touch ID and Secure Enclave article was picked up by Daring Fireball, AllThingsD, and who knows where else.
- Dave Lewis at CSO: Stuffing The Social Media Genie Back In
Favorite Securosis Posts
- Adrian Lane: Investigating Touch ID and the Secure Enclave. Really good analysis from Rich on the security implementation of Touch ID on the iPhone 5s. But I’m not buying the ‘article’ angle – he just wanted a cool new toy!
- Mike Rothman: Cybercrime at the Speed of Light. Everything can (and will) be gamed. Everything.
- Gal Shpantzer: API Gateways. Especially because it made @beaker jealous.
- Rich: Keep Calm and Bust out the Tinfoil Hat. Mike is supposed to be an engineer, not a history major. But this is exactly what I have been thinking. Plus, every other country is doing the same thing to the best of their ability.
Other Securosis Posts
- Continuous Security Monitoring [New Paper].
- Data brokers and background checks are a massive security vulnerability.
- Walled Garden Fail.
- Incite 9/25/2013: Road Trip.
- Firewall Management Essentials: Quick Wins.
- A Quick Response on the Great Touch ID Spoof.
Favorite Outside Posts
- Adrian Lane: Meet the machines that steal your phone’s data. Interesting to see professional eavesdropping devices for mainstream law enforcement. Nothing state of the art, but it allows Officer Barbrady to jack a cell tower. Still, before Snowden nobody cared about this stuff.
- Mike Rothman: Apple’s Fingerprint ID May Mean You Can’t “Take the Fifth”. We’re entering (yet) another new age, when the legal system is nowhere near keeping pace with technological innovation. Interesting thoughts from Marcia Hoffman about the legal question of whether you can be compelled to unlock your phone (with presumably damning evidence on there) because biometrics are not protected under the 5th Amendment, while passwords would be.
- Rich: A TED talk by master pickpocket Apollo Robbins. This is more entertainment than learning (as are most TED talks), but damn. You may think you understand the limits of your perception, but you don’t. The last line is the real kicker.
- Dave Lewis: London schoolboy secretly arrested over ‘world’s biggest cyber attack’
- Gal Shpantzer: Yahoo recycled email accounts may contain emails destined to old account owner. No matter how they try to talk this up, or what they do to recover, this is a mess.
Research Reports and Presentations
- Continuous Security Monitoring.
- API Gateways: Where Security Enables Innovation.
- Identity and Access Management for Cloud Services.
- Dealing with Database Denial of Service.
- The 2014 Endpoint Security Buyer’s Guide.
- The CISO’s Guide to Advanced Attackers.
- Defending Cloud Data with Infrastructure Encryption.
- Network-based Malware Detection 2.0: Assessing Scale, Accuracy and Deployment.
- Quick Wins with Website Protection Services.
- Email-based Threat Intelligence: To Catch a Phish.
Top News and Posts
- Chaos Computer Club breaks Apple Touch ID.
- A Survey of the State of Secure Application Development Processes. Just downloaded a copy. Review forthcoming.
- TouchID defeated: what does it mean?
- New CA law will let minors digitally erase their past.
- ‘Mr Big’ of UK cyber-crime among gang of eight arrested over £1.3million Barclays computer hijack plot in carbon copy of Santander scam
Blog Comment of the Week
This week’s best comment goes to Gunnar, in response to Cybercrime at the Speed of Light.
HFT is about trading, not investing. Traders buy and sell every second of every day.
Investors have multi year time horizons. That’s how ordinary should approach it, long term, buy and hold investment not as traders.
These events which continue to happen on a more regular basis and show no signs of stopping, are worrisome, for traders. They can bankrupt themselves with their own algorithms, as one of the biggest Knight Capital did last year
Comments