Archive for August, 2009

InfoSec Compendium: August 29th

Saturday, August 29th, 2009

Good morning one and all. Hope your Saturday is going well and you are enjoying freinds and family.

Here is today’s InfoSec highlights.

1 – Helpful HIPAA websites when you have to report a violation.

2 – Top 10 Windows Malware.

3 – Facebook to modify Privacy Practices in Canada.

4 – Credit Union warns against fake CD-ROMs.

5 – Some Truth about AV software.

InfoSec Compendium: August 27th

Thursday, August 27th, 2009

Good afternoon everyone. Sorry for the delay between posts but real world issues overwhelmed my time.

Now on to today’s InfoSec highlights.

1 – CISCO WLAN Vulnerability

2 – Wireless WPA encryption cracked in under a minute

3 – Can you trust Free AV Software

4 – Apple’s Snow Leopard includes Anti-virus Software

5 – Analysis of PCI effectiveness

InfoSec Compendium: August 19th

Wednesday, August 19th, 2009

Good morning everyone sorry I have not posted in the past few days, but real life has been calling. Today will be a short list of interesting InfoSec posts and blogs. Have a great day!

1 – The Goal of Security

2 – 10 Digits that will change privacy as we know it

3 – 8 Dirty Secrets of IT Security Industry

NFCU Site Unsecure

Friday, August 14th, 2009

I have been a memeber of NFCU since I joined the US Navy 20 plus years ago. And I hate to say that I have used their site on a daily basis and never once noticed the issue with the home page being unsecure. While the login information is sent secure once you have clicked on the submit button, the page itself is not. Therefore as Scott Jarkoff states this site is ripe for a phising scam.

When I visted the site today after reading the article I noticed a new “Security” link under the logon area. Clicking the link brings up a pop up window which goes about stating the Home Page is not secured by HTTPS but that the information entered is transmitted securely. Security FAIL!

A user can access a secure NFCU logon site by leaving the logon information blank and clicking the submit button, which drops you on to the expected HTTPS secure log on.

Read the whole post as well as a demand from RSA, which oversees NFCU security.

NFCU Site Unsecure

InfoSec Compendium: August 13th

Thursday, August 13th, 2009

Good evening everyone! Hope your week is coming to a successful close.

Here are some InfoSec posts that I found interesting.

1 – Word Press Password bug

2 – Browser Vulnerability

3 – Hacking a Voting Machine for around 100k

4 – eBay Password Vulnerability prompts change

5 – Navy CIO says cybersecurity is an urgent national issue

And of course the big interview with the CEO of Heartland discussing their security breach.

6 – Heartland CEO answers questions (blames others) about their Security Breach