Sunday, March 21, 2010

Bookmark and Share

Archive for the ‘Walt Disney’ Category

InfoSec World 2010


If you’re heading down to Orlando in April for InfoSec World, please consider checking out the demo session on auditing wireless networks that I’m doing with Lisa Phifer.

Using Free Tools to Assess and Audit Your Wi-Fi Network
Lisa A. Phifer, President, Core Competence, Inc.
Diana Kelley, Partner, SecurityCurve

Date: Monday, 19 April 2010
Time: 10:30am – 12pm

• Business justification for a Wi-Fi vulnerability assessment (VA)
• The Wi-Fi VA lifecycle: plan, scan, validate, remediate
• How to build your own Wi-Fi VA toolkit without spending a bundle
• Using free tools to pinpoint Wi-Fi network vulnerabilities (live demo)
• Applying lessons learned to improve your network’s security posture

Bookmark and Share

Disney? Or something else…

So there’s an interesting article over at InformIT that tongue-in-cheek links social engineering to Walt Disney. It’s an interesting article, and I highly recommend reading it if you haven’t seen it already. The point of the article is about social engineering – what it is, why it’s a risk, and why it works.

The point the article makes is that community brings about a willingness to help between folks in that community, which can in turn put an organization at risk because of social engineering. In other words, Disney instill lessons into people that create a susceptibility later in life to social engineering. An interesting line of thought and one that I’ve always been fascinated about. The reason I’m so interested is that it seems like we just can’t fix the social engineering problem – and whenever there’s a problem we can’t fix, I always find the dynamics of why we can’t fix it very interesting.

In this case, I don’t entirely agree with the Disney argument. I think it goes back before that. Instead, I’m going with the Cialdini argument that states that humans exist only because of the “rule of reciprocity” – meaning, that we are hardwired to trust, accept, and help each other. It’s built into us to allow us to survive – for example, if you help me till the field today, I’ll share my harvest with you tomorrow. Reciprocity. It’s the currency that allows us humans to specialize, develop unique skills that have value to the community, and move beyond small nomadic groups.

So even without Disney and other childhood lessons of similar stripe, I think we’d still have an ingrained reaction to help each other – and in this case, that means social engineering opportunities.

Now, I’m not claiming to have any answers here. I just think it’s useful to point out that the traditional wisdom of ‘tell your employees to just say no’ is flawed. Anyway, an interesting line of thought for a friday…

Bookmark and Share
“Our promise to our customers is that the intelligence, analysis, and research we provide lives up to the highest standard of integrity.”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (2)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (2)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives