How is it possible that a Dept of Defense IT service provider continues to send announcements (maintenance windows, outages, etc.) to a HUGE list of clients and simply adds all of the client email addresses to the To: line?
Seriously?
If I were evil I would farm that list for potential victims and also for an easy information set to use in a social engineering attack on the service provider.
Come on folks!
This is basic Operational Security stuff!
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Wednesday, December 19, 2012
Tuesday, November 3, 2009
Lost It? You gotta come clean. FAST!
From a CIO.com article on the cost of a lost laptop
FTA: "According to Ponemon Institute, the average cost of a lost or stolen laptop PC is more than $49,000. Most of this cost is due to the exposure of sensitive data." That is bad, but not entirely unexpected. The hardware/software is 1-2% of that cost. The rest is the 'clean-up'.
but the Important Point is this:
"The study reports that if a company becomes aware of the loss the same day it happens, the average cost is only $8,950. If it takes more than a week to discover the loss, the cost jumps to an average of $115,849."
That is a serious chunk of change. Almost 13 times as much in just one week...
FTA: "According to Ponemon Institute, the average cost of a lost or stolen laptop PC is more than $49,000. Most of this cost is due to the exposure of sensitive data." That is bad, but not entirely unexpected. The hardware/software is 1-2% of that cost. The rest is the 'clean-up'.
but the Important Point is this:
"The study reports that if a company becomes aware of the loss the same day it happens, the average cost is only $8,950. If it takes more than a week to discover the loss, the cost jumps to an average of $115,849."
That is a serious chunk of change. Almost 13 times as much in just one week...
Wednesday, May 9, 2007
I've stopped caring about your data...
Seriously.
If you have a wireless network at home or work and don't secure it, I no longer care about your data losses. Really.
Pictures of your kids? Nope.
Your checkbook data? Not even.
Your tax information? Nah.
I've talked until I'm blue in the face and still companies, agencies and regular people just ignore the security of their wireless networks. I've told everyone I know, I've spoken at conferences, I've written guides and papers for agencies and still wireless is a total nightmare. And really, I've had enough.
Now, I'm really a nobody in the world of wireless security evangelism. Compared to others, I've talked to a tiny group of folks. My impact has only been on my colleagues and family, direct clients, and the few folks who attended one of a couple conference presentations. But the word is out there, and almost everyone has heard about the 'dangers'. I mean really, it's on mainstream nightly newscasts all the time.
And it still gets ignored. If your wireless network is open, you can only blame yourself
So, no more.
You carelessly open your network to the outside world? -- Your problem.
You lose your data? -- I don't care.
Have someone use you network for crimes? -- Sucks for you.
Your identity stolen and your credit destroyed? -- Tough nuts.
Your client data exposed to scammers and criminals? -- You should pay.
Later, why I still care about your insecure wireless network.
--Sheffus
If you have a wireless network at home or work and don't secure it, I no longer care about your data losses. Really.
Pictures of your kids? Nope.
Your checkbook data? Not even.
Your tax information? Nah.
I've talked until I'm blue in the face and still companies, agencies and regular people just ignore the security of their wireless networks. I've told everyone I know, I've spoken at conferences, I've written guides and papers for agencies and still wireless is a total nightmare. And really, I've had enough.
Now, I'm really a nobody in the world of wireless security evangelism. Compared to others, I've talked to a tiny group of folks. My impact has only been on my colleagues and family, direct clients, and the few folks who attended one of a couple conference presentations. But the word is out there, and almost everyone has heard about the 'dangers'. I mean really, it's on mainstream nightly newscasts all the time.
And it still gets ignored. If your wireless network is open, you can only blame yourself
So, no more.
You carelessly open your network to the outside world? -- Your problem.
You lose your data? -- I don't care.
Have someone use you network for crimes? -- Sucks for you.
Your identity stolen and your credit destroyed? -- Tough nuts.
Your client data exposed to scammers and criminals? -- You should pay.
Later, why I still care about your insecure wireless network.
--Sheffus
Subscribe to:
Posts (Atom)