RSS

Archive for March, 2011

Apple iPad

Monday, March 28th, 2011

I was talking to a friend today, and he brought to my attention the iPad 2… again, Apple has made an entry into a market not as the “first”, nor as the fastest, most feature laden nor cheapest… but they’re still causing quite a stir and taking the marketplace by storm.

but what does this mean for an enterprise? How does the iPad adapt to a large business environment? Or even more importantly, how do apple adapt to a business environment? Especially when we consider that Apple have recently left corporate customers high and dry by withdrawing their server hardware offerings!

I’ll put together something soon… but would love to hear your thoughts and or ideas in the meantime! Drop me a line, comment here, take your pic ;)

M.

RSA Pwned

Friday, March 18th, 2011

So RSA have been breached…

I spent the far too long listening to RSA saying “sorry, we’ve been hacked. Something got stolen, but we won’t tell you what. It does affect the security of the system, but there still are passwords, right? Oh yeah, and if you want EMC consulting can come in and mitigate our screw up”…

Oh wait, I’m not being very professional, am I?

http://www.theregister.co.uk/2011/03/18/rsa_breach_leaks_securid_data/

The reason I’m so annoyed is that they went through the whole set of “enforce password policies, monitor accounts, update patches, password complexity, social networks” stuff (security daycare anyone?). Oh, and the best was that a compromise of the RSA SecureID isn’t enough to directly cause a breach…

The whole point of 2-factor authentication is that there are 2-factors! If one gets breached, the other comes into play. No sh*t sherlock! That’s why we spend a fortune getting that second factor instead of just using username and password! What you’re saying is that we are back to username and password in a worst case scenario; so in essence, they’ve said nothing more than “oops, something went wrong”.

We need some facts on what got stolen – without that, we cannot judge the risk for the estates we are handling and cannot decide what to do to mitigate the additional associated risks. Oh, and we need this information yesterday.

While I agree that full disclosure isn’t always the best solution, especially not immediately, as an RSA customer, we need to be kept informed instead of being told “my bad, sorry”. Some useful information is needed, at the moment, this is akin to shouting “Boo!” and running away.

There’s no point in being told in 2 weeks that the RBN or a Chinese hacking group had a way to bypass the SecureID side of things for the last month.

Rant over…
M.

Tweeter button Facebook button Technorati button Reddit button Myspace button Linkedin button Webonews button Delicious button Digg button Flickr button Stumbleupon button Newsvine button
5 visitors online now
0 guests, 5 bots, 0 members
Max visitors today: 5 at 01:58 am GMT
This month: 9 at 02-09-2012 11:58 pm GMT
This year: 26 at 01-04-2012 05:45 pm GMT
All time: 28 at 07-23-2010 05:59 am BST