Archive for August, 2009

Don’t take knives through airport security, buy them afterwards

Just another reason to abolish the TSA….

http://blog.fortify.com/blog/2009/08/29/A-knife-with-my-name-on-it-at-the-airport

Be leary of Blogger.com (lack of) privacy

Somehow I missed this story, but it seems an anonymous blogger using blogger.com (owned by Google) posted pictures of a wannabe model and posted derogatory comments about her such as “psychotic,” “skank,” and “ho.”  The model  got an attorney and filed a lawsuit at which time the blogger immediately took down the site.  The New York state supreme court ruled that Blogger.com must reveal the identity of the blog owner.  Google complied with the request and the blog owner’s identify was revealed at which time the model dropped the lawsuit.

It really stinks that Google chose not to fight the request to hand over the blogger’s identity.  Just another thing to keep in mind…

PASS ID = REAL ID

Don’t be fooled…it looks like the US Senate is again trying to pass a bill which would impose folks to have a smart ID.  This was originally noted by the EFF.  People are given the ID after showing documents identifying themselves.  These documents are then stored electronically by the government and linked to the issued ID.  Does the government really think it can protect this data?

This idea was initially billed as REAL ID and was loudly objected.  They’ve renamed the program PASS ID and are trying again under the guise of “national security” — just like everything else post 9/11 which has been limiting our freedoms.

Read more here: http://www.techdirt.com/articles/20090821/0232295951.shtml

Data on the cloud

Just saw this TechTarget article regarding seizure notification or lack thereof for data on the cloud or SaaS.  This is just one more thing to consider when moving applications and or sensitive data to a cloud environment.  It’s still a hot topic whethere you’re provided with better security or not when following the SaaS model.  If you don’t have an information security team and it’s not a focus in your organization SaaS could very well be a good alternative. 

Make sure you assess any cloud providers security and make sure they will allow you to at least penetration test your applications.