Tuesday, March 09, 2010

...and another one from ASIS


ASIS is definitely not a small organization in the global security landscape. As a member, I receive lots of useful information through my membership, and I'm studying for their CPP certification. And now they want to conduct a small survey. Right.

Tuesday, March 02, 2010

A non-secure survey from ISACA...

 




I'm disappointed. As a member of ISACA, I do expect them to be a role model for their members, in terms of security. "Do as we say, not as we do" a colleague once told me, before leaving the organisation we both worked for once upon a time. For years I have told family, friends, colleagues and others to follow some simple pieces of advice for securing their online activity. One advice is to always ensure that a website uses https (ssl) before you log in or answer questions that might do damage to you or others in any way. I expect ISACA to do the same thing.

Friday, February 26, 2010

Sikkerhet i spørreundersøkelser


25. Oktober 2007 hadde jeg et innlegg i Aftenposten med tittelen "Er anonyme undersøkelser anonyme?". Dagen etter ga de meg støtte til mine synspunkter på lederplass. Takk til dem for det. Trygve Hegnar kom også på banen med en kommentar, men jeg er fortsatt usikker på om han forstår konsekvensene av det han uttalte der.

Nå er det kanskje på tide å avsløre at mitt innlegg i stor grad var basert på en kundeundersøkelse jeg mottok fra Bergens Tidende, men som også ble benyttet av Aftenposten i sin tid. Interessant da med en leder fra Aftenposten som "slaktet" det opplegget deres eget morselskap benyttet mot sine kunder. Jaja. Om ikke annet så bekrefter det et prinsipielt viktig skille mellom den redaksjonelle og den salgs/markedsmessige siden hos Aftenposten, og det er vel positivt? :-)

Det er på høy tid å gi en liten oppfølger til det innlegget.

Monday, February 22, 2010

Never trust password meters

On February 20th, Mikko Hypponen of F-Secure tweeted this message (click for full size):
 

He linked directly to this jpg file, while the graphic belongs to this article at CXO Europe. I usually find his tweets to be very interesting, as well as blog posts from the F-Secure team as well, so don't get me wrong here. Being a little obsessed with passwords after researching them for approximately 9 years, I had to take a look at this article. (Most articles on password strength and passwords in general are full of assumptions, a blend of information from various resources, and a bit of personal opinion from the author at the time of writing. At least that is what I think of them.)

The CXO article had tested a bunch of passwords against the password strength meter of Google Mail, which you can find when creating a new account (or changing your existing one). The graphic from CXO summarizes the strength of the passwords. Looking at that for <5 seconds was enough for me, i had to release this blog post which I've been thinking about for quite some time.

Friday, February 19, 2010

Contributing to the official Elcomsoft blog

Just a quick note to inform you that i am now a contributor to the official blog from Elcomsoft:



My very first posting there is entitled "Why you should crack your passwords". Questions and comments are always welcome!

Thursday, February 18, 2010

The one-frame explanation on how to defeat biometrics

Well, seems like at least one person thought my "cartoons" were kind of funny... hm. Well, here's one more, in order to simplify some seemingly advanced technologies. Click the image for full size.

Questions on board liability insurance

Board members in Norway, including the chairman, has the opportunity to purchase board liability insurance (also referred to as Directors & Officers Liability Insurance). This link provides simple background information (in English) on the purpose of such an insurance from a Norwegian insurance provider.

According to the Norwegian Companies Act §17-1,  board members (members of the corporate assembly, CEO, shareholders) will be held liable for the losses they intentionally or negligently cause during the execution of their duties. Every individual board member who is made responsible - eventually in solidarity with one or several others, and not the board as a collective organ. Board members can get insurance against the liability they expose themselves to in their function as members of the board. 

This is a topic I find interesting in relation to maintaining adequate security for any business. What risk does such an insurance represent to the business itself and its employees?

Wednesday, February 17, 2010

Spørsmål om styreansvarsforsikring

(for English readers: this post is about board liability assurance, and will also be available in English)

Styremedlemmer i Norge, inkludert styreformann, har mulighet til å inngå styreansvarsforsikring, noen steder bare referert som styreforsikring. Bakgrunn og formål er enkelt oppsummert hos HSH StyreNorge:

"Etter aksjelovens § 17-1 blir styremedlemmer (medlemmer av bedriftsforsamlingen, daglig leder, aksjeeiere) erstatningsansvarlige for tap de forsettlig eller uaktsomt volder under utførelsen av sin oppgave. Det er det enkelte styremedlem som blir ansvarlig – eventuelt solidarisk med en aller flere andre, og ikke styret som kollektivt organ.Styremedlemmer kan langt på vei forsikre seg mot det ansvaret de eksponerer seg for i sin funksjon som medlemmer i styret."

Dette er et tema jeg finner interessant i forhold til å ivareta tilstrekkelig sikkerhet for enhver virksomhet. Hva innebærer egentlig en slik forsikring av risiko for virksomheten og dens ansatte?

Tuesday, February 16, 2010

Risks when using social networking services

This article is partially based on some text I've written earlier about the risks of using social networking services such as Facebook, Linkedin, Twitter etc. Before you continue to read, remember that this is written from a business perspective where secrets exists, both from competitive as well as from regulatory requirements. In other words, this is your employer speaking.

I decided to put this out as a blog entry here, as I've gotten into several discussions lately on security, or the lack of it, in such services. I'm registered on a wide range of such social networking services myself, using some of them more frequently than others. My mission here is not to scare away anyone from using them, but to encourage a safe introduction and usage of such services to any organization or enterprise. You have to do it correct the first time around, second chances are very rare in this world.

Monday, February 15, 2010

Kudos (and complaint) to Wacom!

I received my Bamboo Fun small pen & touch today. I like it, but enough with the marketing talk.

As I always try to do, i wanted to register my new device, download the newest drivers etc. Visiting bamboo.wacom.com, i followed directions and was asked to create an account for myself. Struggling hard with the absence of https and other issues, i decided to register the product anyway. Probably not the very worst information to loose control of anyway.