Browse by Tags

Is the “Managed Desktop” the ultimate solution?
When I talk about the big trends, one of them is about the call of the younger generation for more flexibility. Flexibility in this context is about where you work, when you work and how you organize yourself. If you take this as a given, you have to Read More...
Security – One of the Key Reasons to Migrate to Windows Vista (part 2)
In my last post , I briefly touched on different features of Windows Vista, which I think are important with regards to the view on Windows XP vs. Windows Vista. Let’s take a different approach now: I recently was on a panel in Eastern Europe where I Read More...
“Stacked against hacks” in World Finance
I recently had the pleasure to be part of an article in World Finance called Stacked against hacks Visit the virtual version here and go to page 60 and 61 Roger Read More...
Posted 20 October 08 09:44 by rhalbh | 2 Comments   
Filed under ,
Challenging the 10 Immutable Laws of Security
You probably know them: The 10 Immutable Laws of Security , we published I think around 2000 and they were often cited. They are: Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore Law #2: If a bad Read More...
Posted 10 October 08 07:49 by rhalbh | 0 Comments   
Filed under ,
SAFECode released „Fundamental Practices for Secure Software Development”
SAFECode just released a new paper called Fundamental Practices for Secure Software Development . This is a collaboration of different people from different companies (SAP, EMC, Symantec, Juniper, Nokia and Microsoft). As you probably know, SAFECode is Read More...
Some Thoughts on UAC
I blogged several times already on UAC as this has been (and partly still is) a very disputed security feature in Windows Vista (which I still support!). I just found today a not really new blog post on UAC, which I think is worth reading. It is from Read More...
Information Accountability
I just read a pretty interesting paper; you should have a look at. The interesting thing is – from my point of view – the paper is close to your End to End Trust paper we published in March. What I want to say with that is, that it seems that several Read More...
Posted 24 September 08 08:05 by rhalbh | 0 Comments   
Filed under ,
Renting a Botnet on eBay
It is getting better over time: Now you can rent a Botnet on eBay to increase your hitrate on YouTube (By the way: Free shipping is included): http://cgi.ebay.com/Guaranteed-100-000-views-for-your-YouTube-video_W0QQitemZ220279609299QQcmdZViewItem?hash=item220279609299&_trkparms=72%3A1163|39%3A1|66%3A2|65%3A12|240%3A1318&_trksid=p3286.c0.m14 Read More...
Announcing the Exploitability Index
At Blackhat we announced an important change to our Security Bulletins becoming effective during the October release. One of the requests we often heard talking to our customers is, that they would like to get better information on how hard it is to exploit Read More...
8 Dirty Secrets Of The Security Industry
I just read this article called 8 Dirty Secrets Of The Security Industry , which seems pretty nasty. Let's briefly have a look at them: Vendors do not need to be ahead of the hackers; they only need to be ahead of the buyer : Wow, this is a bad statement Read More...
Posted 03 May 08 10:17 by rhalbh | 1 Comments   
Filed under , ,
“The Security Business has no Future” (Quote by IBM)
This is actually an interesting statement. If you had ever to deal with the press you know how these headlines are composed. It might be that the person actually made the sentence in this way – the question is whether he meant it so absolute. Nevertheless, Read More...
Posted 14 April 08 08:52 by rhalbh | 1 Comments   
Filed under ,
Common Criteria and answering the “real” questions
It seems that I am not yet gone J . Eric Bidstrup, a colleague of mine, wrote a great blog post about Common Criteria, where it does a pretty good job and where it fails. Basically he claims – and I could not agree more – that the customer "only" wants Read More...
Consumer Trust in e-Business
If the light of the latest outreach we did around scam ( Lottery Scam – The voice of the victim ), Research firm Ipsos was retained to conduct research with consumers in Germany, Italy, Denmark, UK and The Netherlands. About 3'500 users were contacted Read More...
Lottery Scam – The voice of the victim
We all know that there are scammers telling you that you won in the lottery. A lot of security people think that the victims are naïve and dumb. We just started to run a story on lottery scam and part of it was an interview with a victim. The victim – Read More...
HP confirms vulnerabilities on 82 Laptop models.
Remember this post OEMs: Join in to "Secure by Default" ? I wrote it in June… Now, HP just confirmed a vulnerability in their software delivered on 82 laptop models on all the different Windows versions: HP Quick Launch Buttons Critical Security Update Read More...
More Posts Next page »

Search

This Blog

Syndication

Page view tracker