QoTW #53 How can I punish a hacker?
Elmo asked: I am a small business owner. My website was recently hacked, although no damage was done; non-sensitive data was stolen and some backdoor shells were uploaded. Since then, I have deleted...
View ArticleQoTW #52 Which factors should I consider for devices that accept handwritten...
Indrek asked this question on digital signature devices, such as the ones delivery drivers get you to sign for your packages. While he identified EU directive 1993/93/EC as appearing to regulate, he...
View ArticleIs our entire password strategy flawed?
paj28 posed a question that really fits better here as a blog post: Security Stack Exchange gets a lot of questions about password strength, password best practices, attacks on passwords, and there’s...
View ArticleCommunicating Security Risks to Senior Management – 3 years on
Back in July 2011 I wrote this brief blog post on the eternal problem of how to bridge the divide between security professionals and senior management. Thought I’d revisit it nearly 3 years on and...
View ArticleQoTW #50: Does password protecting the BIOS help in securing sensitive data
Camil Staps asked this question back in April 2013, as although it is generally accepted that using a BIOS password is good practice, he couldn’t see what protection this would provide, given, in his...
View ArticleQoTW #49: How can someone go off-web, and anonymise themselves after a life...
Everything we do these days is online, whether through our own social media, purchases from online stores, tracking by google, Amazon etc., and the concept of gaining some sort of freedom is getting...
View ArticleQoTW #48: Difference between Privilege and Permission
Ali Ahmad asked, “What is the difference is between Privilege and Permission?“ In many cases they seem to be used interchangeably, but in an IT environment knowing the meanings can have an impact on...
View ArticleQoTW #47: Lessons learned and misconceptions regarding encryption and cryptology
This one is a slightly different Question of the Week. Makerofthings7 asked a list-type question, which generally doesn’t fit on the Stack Exchange network, however this question generated a lot of...
View ArticleQoTW #46: CTRL+ALT+DEL Login – Rationale behind it?
CountZero asked this interesting question: Why is CTRL+ALT+DEL required at login on Windows systems? His perspective was that it adds an extra step before login, so is bad from a usability perspective,...
View ArticleQoTW #45: Is my developer’s home-brew password security right or wrong, and why?
An incredibly popular question, viewed 17000 times in its first 3 weeks, this question has even led to a new Sec.SE meta meme. In fact, our top meta meme explains why – the First Rule of Crypto is...
View ArticlePresentations: Starting your security career – where can you go?
I gave a talk on career planning in Information Security at Abertay University on the 16th of January 2013. Securi-Tay is an annual security conference organised by students at Abertay and is a very...
View ArticleQoTW #44: How to block or detect user setting up their own personal wifi AP...
Nominated by Terry Chia, this question by User15580 should be of interest to anyone managing the security of network s. The show the variety of aspects security covers in this sort of scenario: Daniel...
View ArticleQoTW #42: Would publishing a network diagram make the network less secure?
I chose this week’s Question of the Week, saber tabatabaee yazdi‘s “Would publishing a network diagram make the network less secure?” because this is a point which seems to be often misunderstood....
View ArticleSecuri-Tay 2 Conference
Spent January 16th up in Dundee, at the University of Abertay, at Securi-Tay 2. It was a very well run conference – it was organised by students on the Ethical Hacking and Countermeasures course, but...
View ArticleQoTW #41: Why do we lock our computers?
Iszi chose this week’s question of the week, Tom Marthenal‘s “Why do we lock our computers?” - as Tom puts it: It’s common knowledge that if somebody has physical access to your machine they can do...
View ArticleQoTW #40: What’s the impact of disclosing the front-face of a credit or debit...
“ What is the impact of disclosing the front face of a credit card?” and “How does Amazon bill me without the CVC/CVV/CVV2?” are two questions which worry a lot of people, especially those who are...
View ArticleQoTW #39: Why would a virus writer bother to check to see if a machine is...
Terry Chia proposed Swaroop’s question from 2 October 2012: Why would a virus writer bother to check to see if a machine is infected before infecting it? Swaroop was wondering if this would be an...
View Article