An Information Security Place

Commentary on the State of Information Security
  • About
RSS

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 6 other subscribers

Blog Post Calendar

May 2012
M T W T F S S
« Feb    
 123456
78910111213
14151617181920
21222324252627
28293031  
May03

An Information Security Place Podcast – Episode 35

by Michael Farnum on May 3rd, 2010 at 9:00 am
Posted In: Podcasts, Security

 

Episode 35 is here. The format is different today. Instead of you listening to Dan, Jim, and me yap about news and pontificate about security topics, you are going to hear a talk I gave at the Texas Technology Summit in early April 2010. The talk title and synopsis are below, along with a link to the slide deck.

Title: Breaking Down the Enterprise Security Assessment

Synopsis: Many enterprise security assessments look at too few attack vectors or do not dig far enough into the attack vectors once a vulnerability has been discovered. Come join a discussion on the breakdown of a security assessment, explore the essential attack vectors, and debate the depth to which the assessment should go.

Link to MP3

Link to slides

└ Tags: assessment, enterpirse, Security
Comments Off
Apr16

An Information Security Place Podcast – Episode 34

by Michael Farnum on April 16th, 2010 at 7:43 am
Posted In: Podcasts

 

We are really sorry for the long delay, but all three of our schedules have been packed for the last 2 months. But I’m sure you don’t want to hear any excuses, so without further hesitation… Here’s Episode 34.

Show Notes:

Kudos to Tommy Perniciaro for article at SC Magazine – Link Here

InfoSec News Update –

  • Physical Security on Mac sucks – Link Here
  • What Drives Corporate Security Spending? – Link Here
  • Crazy Patch Week – Link 1 / Link 2
  • Federal Court Uphold Border Searches for Laptops – Link Here
  • Are Bank Breaches Still Trending High in 2010 -Link Here
  • So Easy, Even a Celebretard Can Do It! – Link Here
  • Perceptions Of Security Vary Widely Between IT Management, Security Staff – Link Here
  • Slow Death of XSS Vulns – Link Here

Discussion Topic #1 – Integration of Web Vuln Scanners with IPS/WAFs

Discussion Topic #2 - Update your End user Awareness Training and stop blaming your users!

Link 1 / Link 2 / Link 3

Music Notes:

  • Intro / Outro – Digital Breaks – “Therapy”
  • Segway 1 – The Mannish Boys – “Too Tired”
  • Segway 2 – Slide Show Baby – “Long, Long Road”
  • Segway 3 – Megaphone – “Making Sense”

Link to MP3

Comments Off
Mar12

An Information Security Place Podcast – Episode 33

by Michael Farnum on March 12th, 2010 at 4:34 pm
Posted In: Security

 

Yes, the logo is weird this time.  If you can’t tell what it is, maybe this will help.  For the first time ever (and probably the only time since I don’t get to Atlanta much), An Information Security Place Podcast has joined forces with the  Southern Fried Security Podcast to create a joint episode.  Can you see it now??  Yes, that is the logo for An Information Security Place Podcast placed over Colonel Sander’s face (he is the patron saint for the SFS podcast).  Yea,  I thought it was actually kinda freaky, too.  but what else do I have to do with my time??

So we joined forces for a couple of reasons:

  1. Because I was in Atlanta to speak about security assessments at the local NAISG chapter.
  2. I begged Martin to let me post it up as episode 33 over here since Dan, Jim and I haven’t had a chance to record yet, and this makes it all better!

So we stayed in the same room where the event was held and got irradiated by a myriad of computer and sound equipment while recording the podcast.  I had to wear someone’s headset, and now I have some kind of weird rash and some minor swelling around my ears.  And to make it even more fun, Mike Rothman sat across from us the whole time and heckled us.  What a night.

Actually, I had an awesome time.  Very good times with very good friends.  Thanks to the whole Atlanta NAISG crew and the SFS podcast crew (Andy Willingham, Martin Fisher, and Steve Ragan) for inviting me in with typical southern hospitality (even though Steve is a Yankee).

As to show notes, I am lazy.  I am only going to have one note (below) because it is the one news item that I brought along and the ONLY one that Andy didn’t include in his notes (in fairness, I never sent him the link).  Here’s a link to the SFS podcast site with the rest of the notes.   (Hey, Andy did the hard work – why duplicate efforts??)

  • Caleb Sima says that developers shouldn’t learn anything about security – Link here

Link to MP3

Comments Off
Feb23

iTunes picked up the wrong episode

by Michael Farnum on February 23rd, 2010 at 5:28 pm
Posted In: Security

Just realized that iTunes picked up Episode 31 instead of episode 32 on the latest post. I had to delete the enclosure in WordPress and then recreate it. Not sure what happened. If you subscribe to the podcast via iTunes, you may need to delete Episode 32 and then update. Sorry about that!

Vet

Comments Off
Feb18

An Information Security Place Podcast – Episode 32

by Michael Farnum on February 18th, 2010 at 8:24 am
Posted In: Podcasts, Security

 

OK, holy crap.  We expected this episode to be pretty short since Jim was not around to add his golden commentary, but we got to yappin’ and churned out almost an hour of content (I use that term loosely).  So enjoy the show!

Show Notes:

InfoSec News Update –

  • Iran Shutters Google’s Gmail Service, offering own email for citizens – Link here
  • Security Scoreboard – Link here
  • Brian Kreb’s has blog post used by scammers - Link here and Sophos article link here
  • The Death of Product Reviews (Mike Rothman at Securosis) - Link here
  • TSA agent arrested for molestation - Link here
We won’t get intot he details here because this guy is sick, but I had to point out this line from the TSA blog about the issue:
“TSA holds the highest standards for our workforce and this individual’s actions do not reflect on the more than 50,000 men and women who work every day to keep the traveling public safe.”
  • Hacker threat forces DoH to close appraisal site (Political Activist?) - Link here
Discussion Topic – Smaller, more intimate security conferences (Security B-Sides, Schmoocon, etc)

  • Intro/Outro – Digital Breaks – “Therapy”
  • Segway 1 – Guitar Slingers – “Johnny Dangerously”
  • Segway 2 – Matthew Ebel – “Trees”

Link to MP3

└ Tags: agent, arrested, Brian Krebs, Chuvakin, dictatorship, Gmail, Google, Iran, Malware, Schmoocon, Scorecard, Security B-Sides, security conference, Sophos, trojan, TSA, Zeus
Comments Off
  • Page 5 of 139
  • « First
  • «
  • 3
  • 4
  • 5
  • 6
  • 7
  • »
  • Last »

That’s me

©0-2012 An Information Security Place | Powered by WordPress with Easel | Subscribe: RSS | Back to Top ↑