Securosis Blog

My Home Office Security Defense System

Rich · September 17, 2007

It sweeps across a defined field of fire and launches its (un)deadly projectile at anything that invades it’s defined perimeter (3 feet).

Send Your Friends and Family To

Rich · September 17, 2007

Big Bad Mike Rothman over at Security Incite just announced a new program he’s launching next months for consumers. Mike told me about this a while ago, and I think it’s a great idea.

TD Ameritrade- Perhaps It Was Malware?

Rich · September 17, 2007

TD Ameritrade issued a press release Friday with another nugget of information in it.

TD AMERITRADE Holding Corporation (NASDAQ:AMTD) has discovered and eliminated unauthorized code from its systems that allowed access to an internal database. The discovery was made as the result of an internal investigation of stock-related SPAM.

Looks like we’ve had another data breach. TD Ameritrade is now notifying 6.3 million customers. If we use my ridiculously low estimate of $2 per notification, they just erased $12.6M from the books. I can think of a lot of good security technologies (and people) that cost less.

There’s been a bit of debate lately between the quantitative and qualitative camps of the risk management world. The good news is that both camps recognize the need for an organized way to approach risk, rather than the “wave your hands and prognosticate” approach that’s been so popular over the years.

Article Published On TidBITS

Rich · September 13, 2007

Just a quick note that I just published an article over at TidBITS called The Ghost in My FileVault. It’s a tale of terror from a recent trip to Asia. Here’s an excerpt:

My title, but must-read content at Daring Fireball.

Remember, the media companies are trying to condition you into paying more for every piece of content you use. More money for every device, every viewing, every time you make a mix tape with those perfect songs to bring back your lost love. Heck, the RIAA is actively petitioning to pay artists less (if at all) for ringtones and other uses of the artists’ content, so it’s not like your favorite drug-deprived musician is missing out on getting a…

The Pink Taco Claims Another Victim

Rich · September 13, 2007

Richard Stiennon was in town last night, so I took him out for everyone’s favorite local Mexican food. No, it’s not obscene, it’s a normal place with an amusing name.

Welcome to part 2 of our series on helping you better understand Data Loss Prevention solutions. In Part 1 I gave an overview of DLP, and based on follow-up questions it’s clear that one of the most confusing aspects of DLP is content awareness.

Article on the latest CSI/FBI study.

The study does not use a consistent loss model, thus the loss numbers over time are meaningless. I’m all for numbers, but we need an accurate model that won’t just reflect who wants more money this year for more tools/people. Just estimating a lump sum for losses is a load of crap.