The Macrosite for News, Analysis and Opinion about the Future of the Internet

Paul Henry, Security Forensics Specialist

Internet Evolution's instant message board - join the crowd...
You must login to participate in this chat.

Thanks everyone.  Great session and I hope you all got something out of it.

Thinkernetter

Many thanks Paul Henry!

Thinkernetter

Anyone else thinks whitelisting is sort of like a social media connection?  Unless both parties agree, there's no contact made?

Thinkernetter

@smk - One could spend all day coming up with answers.

High School you graduated from - cheeseburger :)

Rank: Cave Painter

Thank you phenry. Great interview.

Rank: Cave Painter

@Phenrycissp -- exactly.  Question:  "When were you married?" Answer:  (I don't actually use this but it's for an example) "A sandbox full of waffles".

Thinkernetter

Thanks for attending ...

Rank: Cave Painter

Well - I need to get back to work, great chatting with everyone today !

Rank: Cave Painter

smkinoshita - I use uniques answers for each account and not biographical data

Rank: Cave Painter

@Phenrycissp -- I don't actually use logical answers for my secret questions.

Thinkernetter

smkinoshita - many security pro's I know get the passwords right but still share the information on the secret questions across multiple accounts. If I can get your answers from your facebook page I will just change your password...

Rank: Cave Painter

Passwords.  Whole other topic.  They are almost as done as AV, aren't they?

Thinkernetter

Yes AV vendors are diversifying... they all have a whitelisting product on the shelf but don't want to lose the traditional AV update revenue so seem to be dragging their feet on its use

 

Rank: Cave Painter

Not only is a single signon kinda scary but it messes up a lot of personal security in my opinion.  I have several kinds of passwords -- some for low-importance items that won't hurt me, to mid-level stuff that won't hurt me but is important, to high-stuff that I want to make sure is secure.

Thinkernetter

smkinoshita - agreed

Rank: Cave Painter

personally single signon spooks me.... we can't get it right with passwords ... and we are going to put everything under a single password - scary

 

Rank: Cave Painter

I keep hoping that at some point basic Internet security and safety will be a mandatory class in public school -- from dealing with trolls and cyberbulling to the understanding of long-term consequences of social media and sharing as well as the techniques used by cyber-scum.

Thinkernetter

@Paul H: What about password reform and the issue of single sign on? Any ideas of how the future may look?

Thinkernetter

Notable that major AV vendors seem to be diversifying.

Thinkernetter

Mary - yes whitelisting vendors in my view are ready for prime-time

Rank: Cave Painter

interesting info thank you

Rank: Cyborg

I think there's a psychological barrier.  People are so emotionally and physically close to their smartphones, they can't believe they're "owned" by someone else.  One reason they take so little care with pins.

Thinkernetter

@Paul H: So if whitelisting is the way to go, do you foresee any technology like that on a kind of grand scale?

Thinkernetter

Mary - yes I would say mobile app situation is critical and needs to be addressed sooner then later

Rank: Cave Painter

SecTech - yes a dashboard has become a necessity today

Rank: Cave Painter

@Paul H: Would you say the mobile app situation is critical?

Thinkernetter

@smkinoshita: I was surprised too. Sometimes exceptions are allowed.

Thinkernetter

Mary - tons of stats out their just google around a bit and you will find them

 

Rank: Cave Painter

@smk: Came as kind of a surprise.

Thinkernetter

@Paul Henry: Do you have any statistics to share on the overall vulnerability of mobile software?

Thinkernetter

Paul - I don't know that I would go as far as to say Social Media can take out our infrastructure ... we have other issues that have a higher capability in that regard ;-)

Rank: Cave Painter

@Kim Davis -- Chrome's not on the list?

Thinkernetter

We use white list here, as I discovered when I tried to download Chrome!

Thinkernetter

@phenrycissp:  Is it better to attempt to be proactive or just stick to being reactive?  You mention looking at logs, but log mining is a very tedious process especially if you don't know exactly what you're looking for.  How do you feel about dashboards for monitoring network activity?

Thinkernetter

Victor - yes the malware comes from a "driveby malware website" but it still has to execute on your PC and that is whre white listing comes in to play - I don't care haow it is delivered if I am using whitelisting...

 

Rank: Cave Painter

@Paul: do you think social media secuiryt threats have the potential to become the gateway to jeopardize the security of the entire web infrastructure?

Researcher

On white listing in the simplest of terms... only allows validated code that is explicetly permitted to run to ever execute on a given machine... it goes a long way at mitigating malware... a new day zero exploit hits your machine and your running traditional AV and your toast..... if your running a whitelisting solution it is stopped in its tracks..

 

 

Rank: Cave Painter

The problem is way to many reactive products call them selves pro active...

 

Rank: Cave Painter

Paul, thanks so much.  We could easily have spoken for an hour on those topics.

Thinkernetter

Great interview Kim!

Rank: Cave Painter

Whatever happened to being proactive with security rather than reactive?

Thinkernetter

How does white listing solve the problem of malware?
I thought most malware came in through exploitable code in the web sites?

Rank: Cave Painter

I've never even been tempted to scan a QR Code even though I have the scanner

Thinkernetter

I've seen a QR Rick-Roll, too.  Not to a video, but the QR scan did the lyrics.

Thinkernetter

Sheesh, that should pretty obvious with QR codes.  Well, one would THINK at least. 

Thinkernetter

@Mary: they will just add those extra costs to d fees

Researcher

Ten years too late!

Thinkernetter

Wow. Antivirus isn't working.

Thinkernetter

But you'd think that all service providers would see an opportunity to make $ from security add-on.

Thinkernetter

carriers are like ISPs, they don't really seem to have a vested interest in keeping the tubes clean

Thinkernetter

My ISPs offers antivirus and firewall as a separately priced service.

Thinkernetter

Oh that's scary.  Carriers should really know better.

Thinkernetter

Well, carriers often sell security as a separate service.

Thinkernetter

@paul: how do you assess the security readiness of the various social media outlets like facebook, twitter and others? Are they making the investment that is needed in this area?

Researcher

I recall that SSL certificates were noted as vulnerable in a couple of events last year.

Thinkernetter

Interesting that vendors aren't responsible for updates, but carriers are.

Thinkernetter

Ping!  Totally agree regarding education.

Thinkernetter

@Paul: can social media security threats posed a significant threat to the security of the enitre web?

Researcher

I find whitelisting a bit annoying, but reassuring.

Thinkernetter

Also hello to Awilliams!

Thinkernetter

@Paul Henry:  Why is it that entrprise never tells employees the hazzards of using their personal devices for business use?

Thinkernetter

I've seen some interesting discussion of virtualizing a seperate work OS on a smartphone. 2 devices in 1

Thinkernetter

@Paul Henry: Are companies not wiping the phones of ex-employee?

Thinkernetter

I don't think using personal devices for business is will EVER be a good idea.

Thinkernetter

@Paul Henry: How would you characterize the state of mobile security? Is it an emergency?

Thinkernetter

RFID chip in your farhead.... NOT

Rank: Cyborg

For instance, the person who proclaims that they will be on vacation and therefore not home--a tip for robbers.

Thinkernetter

What would we use instead of the social security number?

Thinkernetter

@Mary: what is a total date of birth? Are u siggesting people should put in fake numbers?

Researcher

@Paul Whyte: Not sure that social sites are as save for all kinds of interactions with friends/family.

Thinkernetter

@WilNix, I am too. I share very sparingly.

Thinkernetter

I always tell folk not to use their total date of birth on their social profiles.

Thinkernetter

@Mary: Trust in what sense? We trust them to provide a platform to interract with friends and families

Researcher

@Mary I'm quite skeptical of social media.

Rank: Cyborg

@Paul Henry: How prevalent are security breaches from social media? Any statistics?

Thinkernetter

Does everyone here trust social media?

Thinkernetter

And welcome to Paul Henry as well! Thank you for joining us.

Thinkernetter

Hello Mary and Kim

Researcher

@Awilliam: Ya and I hope yours too

Researcher

Hello everyone!

Thinkernetter

2012 is shaping up to be a great year

 

Rank: Cave Painter

Okay, we're all set.

Thinkernetter

Hi Paul, I hope your new year is starting off well!

Thinkernetter

Hello Awilliams and Phenrycissp

Researcher

Afternoon everyone.....

 

Rank: Cave Painter

Raaadiioooooo

Thinkernetter

Time for another security talk

Researcher

hope to learn something new :)

Rank: Cyborg
IBM information resources
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   4 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE