Forgot your password?

typodupeerror

Comment: Re:No (Score 1) 671

by Flendon (#39257527) Attached to: Ask Slashdot: Using Company Laptop For Personal Use

Given that mode of thinking, I would assume you would check the image of returning employees laptop hard drive for malicious changes installed by professionals.

That is the funniest thing I've read in a long time. Thanks for the laugh.

Even if you trust your employee completely, the laptop has been in the hands of customs and other unknown people while in the world. It can't be assumed safe until re-imaged. Finding any attackers code would be a bonus of the 'standard' harddrive swap by IT on return.

Very true here. However, most IT departments have more important things to worry about, like making sure the new security patch isn't going to interfere with the CEO's favorite gambling website. Looking for malicious code isn't going to be on any priority lists when a wipe will "solve the problem".

And no it wouldn't be that bad. Employee has only had laptop for a few days. Tech pulls old drive, installs standard image replacement, checks for nonstandard flash, updates crypto, puts back on shelf. Tech installs old drive in USB enclosure, enters crypto key, scans then copies data folders to employees user folder, then runs paranoia process on OS and drive. If nothing found drive re-imaged and put back on shelf.

To the employee it looks like he turned in his machine and his data showed up in his folder 30 minutes later. To the tech it looks like he has a job doing paranoid shit, until one day he finds the next Stuxnet.

An anti-virus scan will only catch malware that is widespread and has been in the wild for several days. Look how old Stuxnet was before it was detected by A/V. Their are other custom jobs that have gone years without detection as well. The 'paranoia process' would require a forensic examination. A decent forensic triage takes at least 4 hours on a smallish drive. A full examination can take days just to determine if something unusual is present. Than you have to take apart that unusual piece of software just to find out you are chasing down the wrong rabbit hole. This is the kind of work it takes to find the next Stuxnet.

Unless you are in the security industry then some VP is going to look at a poorly done risk assessment, look at the pricetag as overhead, and slash the budget, thinking "that won't happen here" and put down on his next review how many millions he just saved the company. Even in the security industry this isn't done nearly as often as it should.

Comment: Re:No (Score 1) 671

by Flendon (#39257365) Attached to: Ask Slashdot: Using Company Laptop For Personal Use
Their are several well known adages in the IT security field. The most important one is that the usability of a system is inversely proportional to the security of the system. The corollary to this is, the only secure system is the one locked in a safe with no power or internet connection. I've worked cases of documents being stolen from computers which had never been connected to the internet and had all the security bells and whistles. If the computer is required to be capable of running software (kind of important for most users) security holes will be found. No exceptions. The biggest threat I've seen to network security is admins who are overconfident in the security of their network.

Comment: Re:Alternatives (Score 1) 208

by Flendon (#26959421) Attached to: SSLStrip Now In the Wild
For those who don't like to verify there connection themselves can just use Firefox 3.0. If the site really is secure the background of the favicon changes to blue or green depending on how trusted the certificate is. So when the background of the padlock doesn't change color you will know it is fake.

Viking Mars Mission Might Have Missed Life 136

Posted by Hemos
from the head-turned-the-wrong-way dept.
Johan Louwers writes "The Viking mars mission in 1976 might have missed signs of life due to not completely working analysis equipment. GC-MS on the Viking 1976 Mars missions did not detect organic molecules on the Martian surface, even those expected from meteorite bombardment. This result suggested that the Martian regolith might hold a potent oxidant that converts all organic molecules to carbon dioxide rapidly relative to the rate at which they arrive. This conclusion is influencing the design of Mars missions. We reexamine this conclusion in light of what is known about the oxidation of organic compounds generally and the nature of organics likely to come to Mars via meteorite."

Google Launches PayPal Rival 449

Posted by timothy
from the lookit-all-them-teeny-payments-vern dept.

Google Checkout Launched

Roy van Rijn informs us that Google's new online payment system is now online. "Under the name Checkout, the venture offers an incorporated manner to search, advertise and pay. If you buy something on Checkout, 2% and $0.20 go to Google. Paypal, the biggest competitor uses 1,9% and $0,30. Analysts compare Google/Paypal to for example Visa/Mastercard living peacefully together, while others predict the end of Paypal." W3K adds "You can use your Google account to store an unlimited number of credit cards and addresses. The service allows you to track all your orders and shipping in one place," and adds a link to a quick video tour.
Microsoft

Journal: Bill Gates watches pirated videos

Journal by Flendon

If you read way down to the bottom of a Wall Street Journal interview with Bill Gates that ran yesterday, you'll discover that the Microsoft executive admitted to watching pirated movies on the Internet. The confession came as he was talking about content he had viewed on YouTube. Here's part of the exchange:

WSJ: You watch physics lectures and Harlem Globetrotters [on YouTube]?

User Journal

Journal: The Birthday meme

Journal by Flendon

helicobacter has started a new meme. The steps are simple. Go to Wikipedia and in the search box type in your day and month of birth. Leave off the year. Hit search. Post in your journal 3 events, 2 births, and 1 death that are of particular interest to you.

User Journal

Journal: Ponies everywhere!

Journal by Flendon

So I've never felt the need to post a journal here until now. Here I am surfing the "lesbians, lesbians, and more lesbians" thread on myspace (its funny to laugh at the pathetic guys trying to turn these girls straight)and I decide to check some NSFW JEs that I have been putting off reading for a while. Pink?! Did my brain go wacky from reading to much male bashing? After a few refreshes I see the OMG Ponies and realize what day it is.

To be is to be related. -- C.J. Keyser.

Working...