Reading local Blogger’s recent rants….

Posted on February 25th, 2009 by Drazen Drazic

Have a look and support the local guys as well.

Jarrod’s been talking about PCI compliant processor breaches at: /dev/null – ramblings of an infosec professional.
Patrick Gray continues on with his Information Security podcasts. Up to Risky Business 96 now here at Risky Business.
Donal’s Ockham’s Razor talking: 10 Laws of Networking.
Christian’s un-excogitate.org on: New 2FA on the Block.
Jordan’s Security Technology Science: Outsourcing and Controls.
Matthew blogging on the train on the way to work at: Infamous Agenda.

Hey, if I am missing anyone on this list here, please let me know.

Posted in news | 3 Comments »

Random vuln testing security vendor websites…..

Posted on February 24th, 2009 by Drazen Drazic

Interesting to once again hear little about any potential prosecutions against those people performing supposed illegal activity. What sort of message does that send out to others? Oh….it’s okay?

Previous post: Unauthorised access to company websites/information/systems….

In cases like this, it does not seem like searching for a needle in a haystack in regards to the identification of individuals….but I could be wrong. Jurisdiction issues? Less of an issue if the perpetrator is known (assuming “friendly” country involved)? Appetite for chasing it up on anyone’s part?

Posted in Bad Stuff, Research, Vulnerability Management, WTF, Web Application Security, cyber crime | 2 Comments »

Cloud Computing – kill it NOW!!!

Posted on February 22nd, 2009 by Drazen Drazic

This terminology, acronym or whatever you want to call it, is nothing more than a vendor marketing tactic from the 90’s. It is BS and deserves no more from me now. It’s been done here in this post:
Cloud Computing is for Wankers

Our “industry” should be killing it (again) :-) – with clients and within ourselves. It is taking us backwards! Arghh!!!

Posted in Bad Stuff, Dumb Security, UFOs, WTF | 9 Comments »

Internet Blackout N.Z

Posted on February 17th, 2009 by Drazen Drazic

Typical Oz press not bothering to keep up with what is happening in New Zealand. I’m sitting here typing away on “what could be” here in Australia, and NZ is about to hit some of this head-on shortly. In brief from Internet Blackout N.Z:

“Section 92 of the Copyright Amendment Act assumes Guilt Upon Accusation and forces the termination of internet connections and websites without evidence, without a fair trial, and without punishment for any false accusations of copyright infringement. We should speak out against injustices like Guilt Upon Accusation being done in the name of artists and protecting creativity.”

Read the rest here. Join the N.Z Internet Blackout protest to show your support.

Posted in Bad Stuff, Dumb Security, Internet Filtering, WTF | 4 Comments »

Fionnbharr talking iPhone security…..

Posted on February 17th, 2009 by Drazen Drazic

Risky Business has podcast a section of Securus Global’s Fionnbharr Davies’ Enterprise Security talk from Ruxcon 2008 on Risky Business #96.

Posted in Bad Stuff, Vulnerability Management | No Comments »

Mandatory Internet Filtering Project – Dead or Dying?

Posted on February 16th, 2009 by Drazen Drazic

Just a few days after a few small ISPs were reported as on the bandwagon with the Government’s Internet Filtering project, unsubstantiated rumour (from a mate – not a bad source :) ), is that the Government may be looking at pulling out of this “gracefully”.

One can only hope this is the case at present, but if it’s not for now, lets at least hope that at the time [it is decided to be ditched], the people involved don’t drag this out more than need be, in any form, as a last ditch and desperate attempt to save some face.

Previous posts on Internet Filtering in Australia.

Posted in Bad Stuff, Dumb Security, Internet Filtering, WTF | 4 Comments »

ISPs should be supporting iiNet…..not just lip service!

Posted on February 14th, 2009 by Drazen Drazic

iiNet is targeted as the fall guy for this BS “piracy” lawsuit. (My opinion).

Previous thoughts here. Every other ISP in Australia I put it to you would be taking the same stance as iiNet, so why is iiNet at present not being supported by the other ISPs?! By support, I mean something of substance….money, meaningful help and numbers….not just lip service in the press!

Read on:
Read the rest of this entry »

Posted in Uncategorized | 2 Comments »

iPrimus supports Internet Filtering in Australia?!

Posted on February 14th, 2009 by Drazen Drazic

Our old mate Darren Pauli from Computerworld pulled off a beautie last week with this article: Content filter pilots debunk critics.

Unless I have missed something recently, the iPrimus CEO has gone on record as supporting Internet Filtering! This goes against the position of every other ISP we have read about to date, (unless I have missed something and please do correct me if I am wrong here).

Now I could sit here and go over old ground (previous posts), but reading the article, it just comes across as if this guy has just heard about this and thought, “hey, sounds okay to me!”.

Is it just me thinking that?

Read on:
Read the rest of this entry »

Posted in Bad Stuff, Dumb Security, Internet Filtering, WTF | 1 Comment »

Latest on the iiNet “Piracy” Lawsuit

Posted on February 12th, 2009 by Drazen Drazic

This is going to be interesting. Update from MIS; iiNet has two-pronged defence in piracy lawsuit.

Previous post putting a few questions out there:
http://beastorbuddha.com/2008/11/21/supporting-iinet-the-test-case/

I stand by these questions/predictions. The potential outcomes of this case could be quite scary.

One wonders if somehow the “Internet Filtering” government initiative could end up being linked to the outcomes of this court case. (Or even before and during). Or am I again thinking weird conspiracy things?

Posted in Bad Stuff, Internet Filtering, cyber crime | 13 Comments »

Beast Hot Jobs – What’s doing?

Posted on February 12th, 2009 by Drazen Drazic

Beast Hot Jobs is now free posting all IT security and related roles. If you have open positions you would like to advertise, send them here.
(Accepting all Australian, New Zealand and International Roles).

Posted in Uncategorized | No Comments »

Journalism, Free Marketing and Opinions…..

Posted on February 10th, 2009 by Drazen Drazic

Guess which one of the following talking about another scary “survey” I enjoyed reading the most:

Cybercrime losses top $US1 trillion – From News.com.au
Australian IT (same as the last one)
SC Magazine
Sydney Morning Herald

……same old regurgitated vendor marketing in all…….Okay, it’s the next one I liked most! More of this please:

Pick a pocket or two – MIS Financial Review

Posted in Bad Stuff, Dumb Security, WTF, cyber crime | 6 Comments »

“System” view security vs. “Application” view security

Posted on February 5th, 2009 by Drazen Drazic

One key failing that limits an organisations ability to develop an enterprise/holistic view of their overall security position is assessing security solely on an application by application basis. Links, dependencies, information flows (relationships) between applications in a “system” (applications working and linked to each other) are rarely assessed (from our experience). A “system-level” perspective on security is vital in providing an organisation with a more thorough assessment of potential risks (direct and indirect) in a specific application and the corporate environment as a whole. Read on….

Read the rest of this entry »

Posted in Applications, Bad Stuff, Risk Management, Vulnerability Management, Web Application Security, cyber crime, governance | 9 Comments »

Regulation is Bad! Let the market solely dictate things!….What a load of BS!

Posted on February 1st, 2009 by Drazen Drazic

I talked in a previous post about PCI DSS vs. regulatory requirements in some countries, (in some industries). Thought I would expand a bit more on the topic of “regulation”.

In many posts here, I’ve talked about the benefits of regulation (done right) being a big driver for better IT security practices. I was interviewed by Computerworld on this topic about 6 years ago and a representative from the Attorney-General’s Department disagreed with me, and suggested that “new standards” they were going to develop, (that showed businesses how to do things better), were sufficient, and no regulation was required. Gees, even then, we had plenty of “good practice” standards – we didn’t need more of them! (side note: none did come out from the AGD anyway that I am aware of). We need(ed) someone to say, you MUST be doing this. You have an obligation to your business, your employees, your shareholders, your business partners, the business community and society in general!

I still believe that, and I disagree with arguments that the “market” should drive this. WTF does “the market” actually mean? When has “the market” done anything of substance to improve IT security practices in the last 15 years? We’re not going forwards, so how is “the market” going to now dictate and improve this? Magic? Open to your comments as usual. Read on. I’ve added a section from a talk I had with with David Rice about regulation. I liked his thoughts on this:

Read the rest of this entry »

Posted in PCI, PCI DSS, Risk Management, cyber crime, governance | 1 Comment »

It’s never to late to give up the bad stuff……

Posted on February 1st, 2009 by Drazen Drazic

In a rare event as most Sydney-siders would acknowledge, I met a top cabbie last night. Thick Italian accent (been here 50 years :) )…we had a great chat on my drive home. All his kids had finished Uni and were in top jobs and life is good. Topic turned to vices (as they do) and things that are not good for the health – women at the top of his list (in a nice way)…He drank a little (sometimes), which he acknowledged was not healthy, but smoking; “no good mate, don’t smoke…..my father drank and smoked and the smoking killed him”.

“Gees mate, sorry to hear that. How old was your father when he died?”

Cabbie: “95!…….. I reckon he would have have lived to 130!”

ROFL….who knows, he probably could have! Lessons there.

Thanks St. George cabs cabbie. The world needs more people like you. :)

Posted in Too cool | No Comments »

Osama destroys Google!

Posted on February 1st, 2009 by Drazen Drazic

Not much more to add at this stage but the Giant has been taken down. :)

Remember this:
http://beastorbuddha.com/2008/06/04/cyber-terrorism-i-love-this-quote-from-geekonomics/

Now you know I am just kidding right?!

Posted in Bad Stuff, Dumb Security, WTF, cyber crime | 7 Comments »