Showing posts with label infosec. Show all posts
Showing posts with label infosec. Show all posts

1/28/2016 NSA’s top hacking boss explains how to protect your network from his attack squads


True words have not been spoken at the Usenix enigma conference it seems that the Nsa's top hacking boss is explaining how they exploit your networks and he is giving free advices... I doubt it, I've seen a lot of  systems over the time and wherever I've been, security invariably sucks even in the places where they really know it does suck. So, it's not a non sequitir to state that they'd probably be more secure with someone else handling the data at rest part of the equation or data in transit within the cloud provider.

Data in transit and data at rest still on premises will remain key determiners of exactly how the overall security posture rates up or rates down. A proper provider will help the business to lock down the in transit data as well. Then only the on premises setup will be the only part that sucks.Security is a process and the number of people that actually can read and apply proper processes is vanishingly small if it's possible, to advance your systems security and understand it just do it, and the first step is to encrypt everything, and trying to mitigate adding more layers of security.

I respect all people working in US goverment but as you know according to the recent statistics of some resources [Check spiegel.de] say that USA is the largest invading privacy , because they don't respect the American rights over national security , also we know that MI6 and other intel agencies are reading alien code searching for explotaible bugs. This is a game where the number one player is USA , and that talk given by Roy Joice is strange because he is part of that exploiters team.
Digg it StumbleUpon del.icio.us

11/28/2015 Linux Kernel, Security or Myth?



Recently I was reading an interesting interview who Craig Timberg made to Torvalds. Clearly the principal argument in the interview is the increase of known vulnerabilities in the linux Kernel and obviously the mindset of the lead developer of Linux, who is arguing that security is another concern more.

Even more broadly, the battle over Linux security is a fight over the future of the online world. At a time when leading computer scientists are debating whether the Internet is so broken that it needs to be replaced, the network is expanding faster than ever, layering flaw upon flaw in an ever-expanding web of insecurity. Perhaps the best hope for fixing this, some experts argue, lies in changing the operating system that — more than any other — controls these machines.


Kernel Security is pretty important right now and if you don't believe in that check the statistics in android's phone usage, also you can take a quick Look at a few recent kernel security holes that has been discovered Buffer Overflows, initialization failures and the list goes on. The point is that been Torvalds the king of geeks he is obviously going to be the king of the bad guys if they don't review properly commits and new patches, security is above usability or I think so, that's why Security of Linux even as it became a bigger is more important, but seriously Torvalds just said that People in security is just too paranoid.I remember when  long time ago Linux in its early days was widely considered a safer choice than Windows or other commercial operating systems, but now it has been disappear slowly. I have to say that not all problems did not involve the kernel itself, but they're there, and it's becoming a popular target for hackers building “botnets,” and the companies that sell them surveillance tools like Finfisher.

Could be The Kernel Security taking as a relevant topic ?

Digg it StumbleUpon del.icio.us


When companies publish their internal security strategy, to show how secure they are

Digg it StumbleUpon del.icio.us