Tuesday, November 18, 2008

I Have Returned

It's been a long time, I shouldn't have left you
Without a strong post to "think" to...

I know. That line is awkward. I just wanted everyone to know that I have returned to the blogging scene. Lots has been happening to me professionally that has caused me to be "distracted" from posting to say the least. Nevertheless, I have decided to get back into the action. After all, posting is therapeutic. I have tons of security topics to tackle. Stay tuned!

Wednesday, August 6, 2008

Friday, August 1, 2008

A Little Satire

It's Friday and I don't want to begin the weekend with a bunch of doom and gloom which seems to be my M.O. lately. Here is this David Banner video that delivers some good, old-fashioned sarcasm.

Tuesday, June 24, 2008

Bundled Facial Recognition Software on New Laptops

Did you know that some new laptops are shipped bundled with facial recognition software? I haven't done all of the research on this topic yet, but I did come across an interesting video that is making this point. Check it out.

Tuesday, June 17, 2008

I Have Been Slipping!

No new post for such a long time. Sorry about that. I have been busy with work, training and all of the activities involved with trying to save the world. ;o)

I did take a week long class on Intrusion Detection. Interesting topic and lots to learn. First step, become competent in Snort. This may take longer than I would like to admit.

Wednesday, May 7, 2008

Unleash the Cracken aka DARPA




A Presidential Directive and Congressional nod have been given to DARPA to go to work on a National Cybersecurity Initiative. Details are classified, of course. DARPA's general orders are to:

• Conduct unbiased, quantitative and qualitative assessment of information assurance and survivability tools in a representative network environment.
• Replicate complex, large-scale, heterogeneous networks and users in current and future Department of Defense (DoD) weapon systems and operations.
• Enable multiple, independent, simultaneous experiments on the same infrastructure.
• Enable realistic testing of Internet/Global-Information-Grid (GIG) scale research.
• Develop and deploy revolutionary cyber testing capabilities.
• Enable the use of the scientific method for rigorous cyber testing.

Question. Why?
Stay tuned...

Wednesday, April 23, 2008

I Think That My Internet is Tapped



April 23, 2008 11:48 AM PDT
FBI wants widespread monitoring of 'illegal' Internet activity
Posted by Anne Broache | 2 comments WASHINGTON--The FBI on Wednesday called for new legislation that would allow federal police to monitor the Internet for "illegal activity."

The proposal from FBI Director Robert Mueller, which came during a House of Representatives Judiciary Committee hearing, appears to go beyond a current plan to monitor traffic on federal-government networks. Mueller seemed to suggest that the bureau should have a broad "omnibus" authority to conduct monitoring and surveillance of private-sector networks as well.

The surveillance should include all Internet traffic, Mueller said, "whether it be .mil, .gov, .com--whatever you're talking about."

In response to questions from Rep. Darrell Issa, a California Republican, Mueller said his proposed legislation "balances on one hand the privacy rights of people receiving information with...the necessity of having some omnibus search capability, utilizing filters that would identify illegal activity as it goes through, and allow us the ability to catch it at a choke point."

Issa suggested he would support such legislation.

If Mueller's omnibus-monitoring proposal became law, it could implicate the Fourth Amendment's guarantee of freedom from unreasonable searches and seizures. In general, courts have ruled that police need search warrants to obtain the content of communication, and the federal Wiretap Act created "super warrant" wiretap orders that require additional steps and judicial oversight.

In addition, it's unclear whether "illegal activity" would be limited to responding to denial-of-service attacks and botnets, or would also include detecting other illegal activities, such as online gambling, the distribution of "obscene" images of adults engaged in sexual acts, or selling drugs without a license.


To be fair, Wednesday's discussion of the plan was geared toward cybercrime and the Bush administration's classified "cyberinitiative," which includes a shadowy program known as Einstein.

Some politicians have already raised concerns that even Einstein, which is described as dealing only with government networks and not private ones, could infringe upon the privacy rights of American citizens. It's already in place at 15 federal agencies, but Homeland Security has said it's still preparing the necessary privacy impact assessments for a proposed $293 million governmentwide Einstein expansion.

Issa, for his part, referred on Wednesday to malicious attacks being undertaken by foreign and domestic hackers who want to "take control of computers" and harvest the national-security secrets and private information of government agencies, private companies, and individual Americans.

"What authorities do you need in order to monitor, looking for those illegal activities, and then act on those both defensively and, either yourself or certainly other agencies, offensively in order to shut down a crime in process?" Issa asked.

In response, Mueller said he would be happy to have his legislative staff work with members of Issa's committee on creating a bill for a broader-reaching surveillance system.

Issa suggested that perhaps the FBI already has the power to seek voluntary private-sector partners that would like to be "defended" by its agents, provided that they give the FBI their consent. Mueller, however, wasn't so sure, saying, "that's going to require some thought."

CNET News.com's Declan McCullagh contributed to this report.