On Monday April 4, I did a presentation at the Scandinavian ISACA conference, held in Oslo, Norway. The title was "Board Member Security" (Link to Slideshare), and were part of the governance track. I will get back to the contents of the presentation later, first of all I would like to introduce the people behind the presentation.
Wednesday, April 13, 2011
Saturday, April 09, 2011
Passwords^11 - REGISTER NOW!
![]() |
| Twitter hashtag: #passwords11 |
We are getting ready. You can now register for participation at Passwords^11, a 2-day conference on passwords & PINs. Free for all, at the University in Bergen (Norway), on June 7-8. Limited seats available. Quite possibly the very first-ever conference *only* about passwords & PIN codes! :-)
Saturday, April 02, 2011
Sikkerhetsansvaret
Jeg er litt overrasket over at Janne Hagen i FFI på siste FFI-FORUM skal ha påpekt at vi har "...et fragmentert statlig ansvar for IT-sikkerhet" (NSM bloggpost, 1 April 2011. Tviler på det er noen aprilspøk). Jeg regner med hun da uttaler seg om den reelle etterlevelsen av sikkerhet i det offentlige, plasseringen av ansvar bør det da ikke være noen tvil om? Styrelederen heter Harald, adm.dir heter Jens, og generalforsamlingen heter Stortinget. De har ansvaret for sikkerheten.
Friday, April 01, 2011
The end of passwords
After more than 9 years of research on passwords, there is no doubt anymore: we should get rid of them. No, not by implementing any so-called alternatives such as biometrics or 2-factor token authentication. Be smart, use a blank password on your account. It's much easier, we can downsize customer support with at least 50%, it's completely free and every CFO will be ecstatic. Who would ever think that you would be so stupid to not use any passwords at all? Based on this, I will discontinue my research into passwords, as it is neither fun, interesting or useful anymore.
Sunday, March 20, 2011
Security Gone South
I've been on vacation with my wife and our daughter for one week at Gran Canaria (Spain). The picture on the left here shows parts of the hotel we stayed at. The tour operator as well as the hotel name shall remain anonymous in this blog post, as I don't think my observations are unique for this hotel only.
Being on vacation doesn't mean leaving my interest in security & safety at home, hence this blog post.
Being on vacation doesn't mean leaving my interest in security & safety at home, hence this blog post.
Tuesday, March 08, 2011
Call for Papers: Passwords^11
"Passwords^10 is probably the best security conference I have ever attended"
- Note on evaluation form after Passwords^10, Dec 8-9, 2010
After a fantastic conference with 38 participants (!) in December last year, we have received many many requests from participants as well as others world-wide to do another conference on passwords only. So with the same close-to-zero budget as last year, I am happy to announce our Passwords^11 : Call for Papers!
Monday, March 07, 2011
Tell me your password...
And I'll tell you who you are, where you work, and what kind of work you do. Not that you would ever lie about your password of course. :-)
I saw an online article on March 4 at Computerworld Norway, entitled "Bryter seg inn i norske bedrifter" (Google translated to English). At a recent security seminar held by Norwegian ISF, a previous colleague of mine held an interesting presentation. Read the 2-page article at Computerworld first, notice some of the statements from Christian Jacobsen (now at Secode).
I saw an online article on March 4 at Computerworld Norway, entitled "Bryter seg inn i norske bedrifter" (Google translated to English). At a recent security seminar held by Norwegian ISF, a previous colleague of mine held an interesting presentation. Read the 2-page article at Computerworld first, notice some of the statements from Christian Jacobsen (now at Secode).
Thursday, March 03, 2011
Pwnd. Again.
Thursday, February 24, 2011
Oppdater din PC del 1 (Java)
Ovenstående bilde er tatt fra nettbanken min, men det kunne selvfølgelig vært tatt fra en rekke andre steder også. Det er nok av sikkerhetsfolk og andre som skriver og sier dette - du kan simpelthen ikke ha unngått å lese det. Men hva betyr det i praksis? Jeg skal lage noen enkle guider med skjermbilder for å forklare hva du bjør gjøre, og jeg begynner med oppdatering av Java Runtime Environment.
Tuesday, February 22, 2011
Far Out Dude!
This is a blog post specifically for Davey Winder (@happygeek), after I read your article "The password cracking software enigma". I came across the article through @WeldPond, who retweeted a message from @L0phtCrackLLC saying "so why is exposing weak passwords and weak hashing bad again?"
Subscribe to:
Posts (Atom)



