Friday, March 28, 2008

Laptop theft exposes patients' medical data

Laptop theft exposes patients' medical data (C|Net News)

The computer was stolen in February ... but officials did not notify the patients of the theft until Thursday, saying they didn't want to spread unnecessary alarm, according to The Washington Post.
Pure infosec brilliance.

Targeted Malware Used in Hannaford Credit Card Heist

Targeted Malware Used in Hannaford Credit Card Heist (eWeek)

Saturday, March 15, 2008

CanSecWest hacking contest here. OS X Leopard vs. Vista vs. Linux. Entertaining, but hope no one actually thinks the results will be conclusive. You certainly wouldn't make risk based decisions on the results... would you?
Anymore, with true 0-days becoming more and more commonplace, even though your risk may be lowered a bit by using an OS that seems to have fewer vulnerabilities discovered per year, it's still not worth comparing until the reliability factor goes way, way up. Until that number reaches one remotely exploitable vulnerability every 5 or 10 years (like OpenBSD, say?), you still need to "worry" and stack up your defense in depth security controls.

We're still at a point in OS software reliability where it's like comparing a 70's Italian roadster to a 70's British roadster. One may drive an extra day or two longer before breaking down but who cares? They both spend more time in the shop than on the road.