Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

RSAC 2017, Planning for Chaos →

March 08, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security
March 08, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security

Kicking the Certificate Habit →

March 07, 2017 by Marc Handelman in All is Information, Simplicity, Web Security, WebTrust, Trust, TOFU, Information Security, Authentication, Must Read

Dr. Jaap-Henk Hoepman's security posts (via his blog), detailing his provocative yet fundamentally sound thoughts on the subject of terminating the utilization of certificates is today's absolute MustRead.

The basic idea - A few days ago I explained the idea including a mechanism to detect phishing attacks. This makes the protocol more complex, and creates confusion. So let’s try again, explaining the basic idea first. Whenever a browser sets up a new TLS connection with a domain, the web server serving that domain respond with its public key (instead of a certificate, as is currently the case) in the initial TLS handshake. (This is more precise than saying that the web server sends its public key in the header of every page it sends.)... Read more at Dr. Hoepman' blog

March 07, 2017 /Marc Handelman
All is Information, Simplicity, Web Security, WebTrust, Trust, TOFU, Information Security, Authentication, Must Read

RSAC 2017, Unlucky Number Seven →

March 07, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, RSA Conference
March 07, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, RSA Conference

RSAC 2017, Cryptographer's Panel →

March 06, 2017 by Marc Handelman in All is Information, Conferences, Cryptography, Education, Information Security, RSA Conference
March 06, 2017 /Marc Handelman
All is Information, Conferences, Cryptography, Education, Information Security, RSA Conference

RSAC 2017, Bruce Schneier's Regulating the Internet of Things →

March 05, 2017 by Marc Handelman in All is Information, Conferences, Information Security, Education
March 05, 2017 /Marc Handelman
All is Information, Conferences, Information Security, Education

An Interview with Howard Schmidt →

March 04, 2017 by Marc Handelman in All is Information, Education, Information Security

Professor Barbara Endicott-Popovsky, Ph.D., interviews Howard Schmidt. This video originally aired via the International Conference on Cloud Security Management at The Information School of the University of Washington, in October 2013. The principles, patterns and anti-patterns discussed in the video remain evident today.

March 04, 2017 /Marc Handelman
All is Information, Education, Information Security

RSA 2017, How Google Protects Its Corporate Security Perimeter without Firewalls →

March 04, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, RSA Conference
March 04, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, RSA Conference

Shmoocon 2017, Mark Kuhr - Disinformation Campaigns vs. Attribution Claims →

March 03, 2017 by Marc Handelman in All is Information, Conferences, Information Warfare, Information Security, Disinformation, Repudiation, Attribution
March 03, 2017 /Marc Handelman
All is Information, Conferences, Information Warfare, Information Security, Disinformation, Repudiation, Attribution

Shmoocon 2017, Nicolas Kseib and Simon Modi - I Have a Graph Database. Now What? →

March 02, 2017 by Marc Handelman in All is Information, Conferences, Education
March 02, 2017 /Marc Handelman
All is Information, Conferences, Education

Basic Encryption, In Small(ish) Words →

March 01, 2017 by Marc Handelman in All is Information, Encryption, Confidentiality, Integrity, Information Security

Ed Felten, Ph.D., has written a superb encryption primer - specifically targeting the politicians and policy wonks amongst us - in it's utility of small words. We really like those small words... H/T

March 01, 2017 /Marc Handelman
All is Information, Encryption, Confidentiality, Integrity, Information Security

Shmoocon 2017, Whitney Merrill and Aaron Alva - Goodnight Moon & the House of Horrors →

March 01, 2017 by Marc Handelman in All is Information, Conferences, Education
March 01, 2017 /Marc Handelman
All is Information, Conferences, Education

'He Is (As A Matter Of Course) Correct'

February 28, 2017 by Marc Handelman in All is Information, USNSA, US Armed Forces, Information Security, Information Warfare, Cyberthis Cyberthat, Cyber Cyber

Michael Rogers ADM USN, Director of the National Security Agency and Commander of the United States Cyber Command sums up 'cyber' quite nicely, indeed:

"Cyber is an operational domain in which we do a variety of missions and functions, many of which are very traditional,” Adm. Rogers said. “We do reconnaissance, we do fires, we do maneuvers. The same things I was used to as a surface [warfare] officer … I’m constantly going back to that.”

"Don’t make this thing so specialized, so unique, so different that it just gets pushed to the side. That will sub-optimize our ability to execute cyber operations, and quite frankly it will minimize or at least negatively impact, in my view, the operational outcomes, which is the whole reason we’re doing this in the first place.”

February 28, 2017 /Marc Handelman
All is Information, USNSA, US Armed Forces, Information Security, Information Warfare, Cyberthis Cyberthat, Cyber Cyber

Shmoocon 2017, Allison Miller, Melissa Clarke and Margaret Schedel - háček: Computing a Hacker Experience →

February 28, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security
February 28, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security

Goatse of Cloudbleed →

February 27, 2017 by Marc Handelman in All is Information, Web Security, Information Security, Data Security, Data Leakage, Must Read

via the eponymous Phoneboy, comes his take on the latest security foible of a major backend provider (in this case Cloudflare), entitled 'Cloudflares with a Chance of Goatse', Mr. Welch-Abernathy explains it all, in imitiable form. Today's MustRead.

February 27, 2017 /Marc Handelman
All is Information, Web Security, Information Security, Data Security, Data Leakage, Must Read

Shmoocon 2017, Kenny McElroy's Implantable Logic Analyzers Unlocking Doors →

February 27, 2017 by Marc Handelman in All is Information, Conferences
February 27, 2017 /Marc Handelman
All is Information, Conferences

Mozilla Firefox Certificate Cache Coughs Up Credentials →

February 24, 2017 by Marc Handelman in All is Information, Cruft, Data Leakage, Poor Coding Practices, Application Security, Web Security

Meanwhile, in cruft news...

A Tale of Cruftery

First discovered by security researcher Alexander Klink, and discussed on his shift or die blog, the leakage documentation he has amassed is a tour de force in correct handling of the discovery. Mozilla's response has been a tad lackadaisical and (disappointlingly) still in telemetry data gathering mode as of this post.

The Workaround

Superb work by Alexander; nonetheless, he does suggest regular cleansing your browser user profile (if you are so unlucky as to be using the browser under scrutiny, yet most likely, a good idea on any browser). There are many tools available that deal with the cache cleaning task (both scripted and manual, GUI-based and not, both in-built and otherwise). Enjoy the cruft. H/T

February 24, 2017 /Marc Handelman
All is Information, Cruft, Data Leakage, Poor Coding Practices, Application Security, Web Security

Shmoocon 2017, Falcon Darkstar and Sergey Bratus - LangSec for Penetration Testing: How and Why →

February 24, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, Penetration Testing
February 24, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, Penetration Testing

Shmoocon 2017, Sebastian Verschoor's (In-)secure messaging with SCIMP and OMEMO →

February 23, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, Messaging Security
February 23, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, Messaging Security

Wisdom, Ignorance of the Crowds

February 22, 2017 by Marc Handelman in IARPA, Intelligence, All is Information, National Security, Must Read

IARPA's doing it, the Neuromongers did it, why not You? Well crafted report on the methodology behind applying the power behind the ignorance and widom of the crowd... Known as the Crowdsourcing Evidence, Argumentation, Thinking and Evaluation (CREATE), IARPA's new program ostensibly may enhance intelligence anlayst's capability levels by leveraging the behavior of crowdsourced resources. Today's Must Read.

February 22, 2017 /Marc Handelman
IARPA, Intelligence, All is Information, National Security, Must Read

Shmoocon 2017, Travis Goodspeed's Quick & Dirty ARM Emulation →

February 22, 2017 by Marc Handelman in All is Information, Conferences, Cybersecurity, Education, Hardware Security, Emulators
February 22, 2017 /Marc Handelman
All is Information, Conferences, Cybersecurity, Education, Hardware Security, Emulators
  • Newer
  • Older