Hacking + business savvy
Hackers and technical wizards that like to break things usually have their own l33t speek. But unfortunately, this does not translate very well in business. It's like speaking in two different languages, hacker talk and business spiel. You could argue it's more than two as you could be dealing with management, general IT and helpdesk. All of whom speak a different language. Anyways, in security consultancy, you do have to talk to the client and explain things in an easy understandable way, essentially in their language. This is well discussed in this securityfocus column. So it's like someone told me, "l33t speak evolved" and "pwntry with a touch of class".
Disclosure
Hackers and pen-testers naturally like to show off what exactly they can do by releasing vulnerabilities and attacks. This securityfocus column discusses how some MIT students were gagged by the MBTA from demonstrating their research at defcon despite discussions with them. Unfortunately, it is usual to shoot the messenger! There has been many a time, when a vulnerability has been found and the vendor contacted but very little happens for months. Hence some vulnerabilities can be released months even years after it was originally found. Should the vulnerability be released despite the contact with the vendor? Arguably they should be. If a customer has this issue, they should be aware of this and would like a solution. Ultimately it's the responsibility of the vendor. But unfortunately, it's usually the man-in-the-middle, the messenger, the security tester that gets the heat!
Showing posts with label Disclosure. Show all posts
Showing posts with label Disclosure. Show all posts
Tuesday, 31 March 2009
Sunday, 1 July 2007
Careful what you say...
I remember an old work colleague telling me, "Look I'm going to tell you something really important about work but I'll tell you later". The reason I found out later was that you never know who was on board that train from London. And you know he is right. When you are in public, you represent a number of things, yourself, your family, your religion, your country and your workplace. You have to be careful what you say. Admittedly, you are not likely to be famous and no-one is likely to care. But people will overhear and remember things like anger, swearing and anything illicit. I remember from a kid's story that the 'corn has ears' and can pass messages when the wind blows through the cornfields.
I am a firm believer in keeping a low profile and not drawing too much attention to oneself. You will always leak information about yourself but you can certainly control the amount you give. The little information you give, the less information people have to use against you and chances of such things of id theft happening become slimmer.
Similarly that's why I am not keen on social networks, I mean all the data going into the databases. For example check out: mobuzz on facebook and does what happens in the facebook stay in the facebook
Now I do have a myspace and a facebook but I am trying to leak as little information as possible. The only correct thing you should need is an email address. But again in a public arena, with data bound to be logged, you do still have be careful what you announce. Hmmm is everything we say logged? I mean I was a bit mortified to release all my gtalk discussions was logged within gmail. I mean all your most intimate conversations are logged if someone broke into this feature then that would cause all kinds of brown stuff to hit the fans. Can we trust yahoo or hotmail in the same vein?
Referring to the mobuzz video once more, amazon and ebay appear to store information about you and that's become more apparent with the fact that you cannot close your accounts with them....
So in summary, be careful what you reveal about yourself...
BE CAREFUL WHAT YOU SAY!!!
I am a firm believer in keeping a low profile and not drawing too much attention to oneself. You will always leak information about yourself but you can certainly control the amount you give. The little information you give, the less information people have to use against you and chances of such things of id theft happening become slimmer.
Similarly that's why I am not keen on social networks, I mean all the data going into the databases. For example check out: mobuzz on facebook and does what happens in the facebook stay in the facebook
Now I do have a myspace and a facebook but I am trying to leak as little information as possible. The only correct thing you should need is an email address. But again in a public arena, with data bound to be logged, you do still have be careful what you announce. Hmmm is everything we say logged? I mean I was a bit mortified to release all my gtalk discussions was logged within gmail. I mean all your most intimate conversations are logged if someone broke into this feature then that would cause all kinds of brown stuff to hit the fans. Can we trust yahoo or hotmail in the same vein?
Referring to the mobuzz video once more, amazon and ebay appear to store information about you and that's become more apparent with the fact that you cannot close your accounts with them....
So in summary, be careful what you reveal about yourself...
BE CAREFUL WHAT YOU SAY!!!
Subscribe to:
Posts (Atom)