Big Blog

Arts & Culture
Biological Science
Blog Watch
Computer Games
Computer Security
Cricket
Data Privacy
Developer
Domain Names
E-commerce
Gadgets
General Science
Handhelds
IP & Patents
Java
Linux
MP3
Nanotech
Online Auctions
Online Legal Issues
Open Source
Personal Finance
Photography
Quirky
Robotics
Search Engines
Space Science
Top Internet
Top Stories
Top Tech
Video Games
Web Developer
Webmaster Tips
XML & Metadata
{Home}



security: search

What Examples of Security Theater Have You Encountered?

swillden writes "Everyone who pays any attention at all to security, both computer security and 'meatspace' security, has heard the phrase Security Theater. For years I've paid close attention to security setups that I come in contact with, and tried to evaluate their real effectiveness vs their theatrical aspects. In the process I've found many examples of pure theater, but even more cases where the security was really a cover for another motive." swillden would like to know what you've encountered along these lines; read on for the rest of his question below.

Alternative Technology Adds McAfee Security

ENGLEWOOD, Colo. -- Alternative Technology, Inc., an Arrow Electronics, Inc. company and leading specialty distributor of thin-client/server-based computing, edge infrastructure, virtualization, and security solutions, continues to expand its security solutions by announcing it will distribute the full line of McAfee security software, appliances and managed security services for small to medium businesses and enterprises. Those offerings include: system/endpoint security, network security, data protection, and risk and compliance management.

Book Review: Little Black Book of Computer Security - 2nd Ed

If you go to a Borders or Barnes and Noble and check out the computer book section, you will most likely find an entire wall (or two) filled with various information security titles. There are 1000 page tomes dedicated to single topics like cryptography, or VoIP security, or how to secure some version of Microsoft's Windows operating system, and it is important to understand the information and concepts contained in those books. What Joel Dubin delivers in The Little Black Book of Computer Security - 2nd edition, is a compact, concise checklist in outline form that helps remind you of all of the key points you need to remember when implementing information security. The book is compact and portable. Not only can administrators use it to act as a reminder when developing information security policies and practices, but information security

More Patent Battles Making Your Computer Less Secure

Last year, we pointed to some patent battles among security software companies, noting how the end result would undoubtedly be less secure computers. As these security firms argued over who thought up an idea "first" and who owed who what amounts of money, you can rest assured that those exploiting the security holes couldn't care any less about who came up with what exploit first. In the constant battle between security firms and malicious hackers, distracting the security firms and having resources devoted to arguing over patents (and paying each other royalties) seems designed to just make it that much easier for malicious hackers to stay that much further ahead, while making it more and more difficult for any security firm to actually provide anything close to comprehensive security.

Computer Security

Computer Security is a branch of technology known as information security as applied to computers. Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction. The objective of computer security varies and can include protection of information from theft or corruption, or the preservation of availability, as defined in the security policy.

Oracle Label Security for Privacy and Compliance

Oracle Label Security helps organizations address security and compliance requirements using sensitivity labels such as confidential and sensitive. Sensitivity labels can be assigned to users in the form of label authorizations and associated with operations and objects inside the database using data labels. Label authorizations provide tremendous flexibility in making access control decisions and enforcing separation of duty. Oracle Label Security can be used to address numerous operational issues related to security, compliance and privacy. Used with Oracle Database Vault, Oracle Label Security label authorizations are factors that control access to applications, databases and data. Label authorizations can be used in conjunction with virtual private database to mask out PII data.

Oracle Label Security for Privacy and Compliance

Oracle Label Security helps organizations address security and compliance requirements using sensitivity labels such as confidential and sensitive. Sensitivity labels can be assigned to users in the form of label authorizations and associated with operations and objects inside the database using data labels. Label authorizations provide tremendous flexibility in making access control decisions and enforcing separation of duty. Oracle Label Security can be used to address numerous operational issues related to security, compliance and privacy. Used with Oracle Database Vault, Oracle Label Security label authorizations are factors that control access to applications, databases and data. Label authorizations can be used in conjunction with virtual private database to mask out PII data.

Oracle Label Security for Privacy and Compliance

Oracle Label Security helps organizations address security and compliance requirements using sensitivity labels such as confidential and sensitive. Sensitivity labels can be assigned to users in the form of label authorizations and associated with operations and objects inside the database using data labels. Label authorizations provide tremendous flexibility in making access control decisions and enforcing separation of duty. Oracle Label Security can be used to address numerous operational issues related to security, compliance and privacy. Used with Oracle Database Vault, Oracle Label Security label authorizations are factors that control access to applications, databases and data. Label authorizations can be used in conjunction with virtual private database to mask out PII data.

[RHSA-2008:0537-01] Important: openoffice.org security update

Red Hat Security Advisory Synopsis: Â Â Â Â Â Important: openoffice.org security update Advisory ID: Â Â Â RHSA-2008:0537-01 Product: Â Â Â Â Â Red Hat Enterprise Linux Advisory URL: Â Â Â https://rhn.redhat.com/errata/RHSA-2008-0537.html Issue date: Â Â Â Â 2008-06-12 CVE Names: Â Â Â Â CVE-2008-2152 ===================================================================== 1. Summary: Updated openoffice.org packages to correct a security issue are now available for Red Hat Enterprise Linux 4 and Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ppc, x86_64 Red Hat Enterprise Linux Desktop versi

[RHSA-2008:0538-01] Important: openoffice.org security update

Red Hat Security Advisory Synopsis: Â Â Â Â Â Important: openoffice.org security update Advisory ID: Â Â Â RHSA-2008:0538-01 Product: Â Â Â Â Â Red Hat Enterprise Linux Advisory URL: Â Â Â https://rhn.redhat.com/errata/RHSA-2008-0538.html Issue date: Â Â Â Â 2008-06-12 CVE Names: Â Â Â Â CVE-2008-2152 CVE-2008-2366 ===================================================================== 1. Summary: Updated openoffice.org packages to correct two security issues are now available for Red Hat Enterprise Linux 3 and 4. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat En

[RHSA-2008:0267-01] Critical: java-1.6.0-ibm security update

Red Hat Security Advisory Synopsis: Critical: java-1.6.0-ibm security update Advisory ID: RHSA-2008:0267-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2008-0267.html Issue date: 2008-05-19 CVE Names: CVE-2008-1187 CVE-2008-1188 CVE-2008-1189 CVE-2008-1190 CVE-2008-1191 CVE-2008-1192 CVE-2008-1193 CVE-2008-1194 CVE-2008-1195 CVE-2008-1196 ===================================================================== 1. Summary: Updated java-1.6.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 5 Supplementary. This update has been rated as having critical security impact by the Red Hat Security Response Team.

More customers are shopping for security software online

A recent report from The NPD Group revealed some interesting statistics about consumers' perceptions and awareness of security software products. Among the findings: the majority of security software purchases occur on the Internet, free security software downloads are competing directly with paid security software, and the biggest perceived household security threat is viruses.

McAfee, Inc. Delivers Stronger Security and Simplified Compliance ... - CNNMoney.com (press release)

SANTA CLARA, Calif., July 14 /PRNewswire-FirstCall/ -- McAfee, Inc. (NYSE: MFE) announced enhancements to McAfee(R) Total Protection (ToPS) for Endpoint, McAfee’s flagship endpoint security solution. This release provides new and updated compliance and security functions, including powerful policy auditing, flexible network access control, rogue system detection, enhanced Web security and improved anti-malware technology. The integration of management capabilities between endpoint security and compliance management enables customers to reduce costs, improve visibility and comply with industry & security policy across their entire infrastructure.

McAfee, Inc. Delivers Stronger Security and Simplified Compliance in a Single Solution

SANTA CLARA, Calif., July 14 /PRNewswire-FirstCall/ -- McAfee, Inc. (NYSE: MFE) announced enhancements to McAfee(R) Total Protection (ToPS) for Endpoint, McAfee's flagship endpoint security solution. This release provides new and updated compliance and security functions, including powerful policy auditing, flexible network access control, rogue system detection, enhanced Web security and improved anti-malware technology. The integration of management capabilities between endpoint security and compliance management enables customers to reduce costs, improve visibility and comply with industry & security policy across their entire infrastructure.

Mozilla Foundation developing a model for a security metric

The Mozilla Foundation plans to develop a better model for gauging the security of its Firefox web browser. In contrast to Microsoft, the number of officially provided security updates is not to be the sole parameter used. According to the method in which Microsoft measures security, an absence of patches would equate to a high degree of security. The Microsoft approach is further illustrated by its claim that Vista is still more secure than other operating systems. In contrast to this approach, the Mozilla Foundation wants its evaluation to include a variety of factors involved in the development process and the techniques and tools used in it. The sequence of the process from the time a security vulnerability is reported until a patch is distributed is also to be analysed.

Security Hole in Citibank ATMs Underscores Larger Security Flaws in Banking Networks According to TraceSecurity

PRNewswire/ -- TraceSecurity, a leading provider of SaaS security compliance and risk management solutions, disclosed today that the case of Citibank customers whose funds were hacked via the connection between ATMs and third parties processing their PIN codes, are just the tip of the iceberg when it comes to the overall security and compliance of the networks that process ATM transactions. Over the past five years, TraceSecurity personnel have uncovered thousands of un-patched ATM processing servers while performing routine security compliance inspections. TraceSecurity is responsible for performing annual audits and inspections for firms in the financial services space to ensure they are complying with industry and government regulations that help protect consumers' sensitive data as well as the funds in their accounts.

Security Hole in Citibank ATMs Underscores Larger Security Flaws in Banking Networks According to TraceSecurity

PRNewswire/ -- TraceSecurity, a leading provider of SaaS security compliance and risk management solutions, disclosed today that the case of Citibank customers whose funds were hacked via the connection between ATMs and third parties processing their PIN codes, are just the tip of the iceberg when it comes to the overall security and compliance of the networks that process ATM transactions. Over the past five years, TraceSecurity personnel have uncovered thousands of un-patched ATM processing servers while performing routine security compliance inspections. TraceSecurity is responsible for performing annual audits and inspections for firms in the financial services space to ensure they are complying with industry and government regulations that help protect consumers' sensitive data as well as the funds in their accounts.

Security Hole in Citibank ATMs Underscores Larger Security Flaws in Banking Networks According to TraceSecurity

BATON ROUGE, La., July 2 /PRNewswire/ -- TraceSecurity, a leading provider of SaaS security compliance and risk management solutions, disclosed today that the case of Citibank customers whose funds were hacked via the connection between ATMs and third parties processing their PIN codes, are just the tip of the iceberg when it comes to the overall security and compliance of the networks that process ATM transactions. Over the past five years, TraceSecurity personnel have uncovered thousands of un-patched ATM processing servers while performing routine security compliance inspections. TraceSecurity is responsible for performing annual audits and inspections for firms in the financial services space to ensure they are complying with industry and government regulations that help protect consumers' sensitive data as well as the funds in their

Security Hole in Citibank ATMs Underscores Larger Security Flaws in Banking Networks According to TraceSecurity

BATON ROUGE, La., July 2 /PRNewswire/ -- TraceSecurity, a leading provider of SaaS security compliance and risk management solutions, disclosed today that the case of Citibank customers whose funds were hacked via the connection between ATMs and third parties processing their PIN codes, are just the tip of the iceberg when it comes to the overall security and compliance of the networks that process ATM transactions. Over the past five years, TraceSecurity personnel have uncovered thousands of un-patched ATM processing servers while performing routine security compliance inspections. TraceSecurity is responsible for performing annual audits and inspections for firms in the financial services space to ensure they are complying with industry and government regulations that help protect consumers' sensitive data as well as the funds in their

CompTIA Says Small Business Committee Task Force on Cyber Security Will Help Small U.S. Businesses Maintain Proper Info Security Practices

Maintaining the integrity and security of data is important for businesses, large to small. Today, leading Members of both the House and Senate Small Business Committees introduced the Small Business Information Security Act of 2008, S. 3102 and H.R. 6206. This legislation will go a long way toward addressing the technology security challenges of U.S. small businesses -- America

Hackers 'seeding' legitimate websites

End of the line for standalone security vendors? Security expert: BT should be prosecuted over its use of Phorm IT consulting group buys out Tumbleweed Microsoft to patch seven vulnerabilities -- three critical Proof-of-concept revealed for Safari for Windows bug Spear-phishing campaigns on the rise Trojan holds victim's files for ransom Senator Conroy launches National E-security Awareness Week Government launches alert service to kick off E-security Week Second tier vendors to challenge McAfee, Symantec on endpoint security Threat forecast predicts more Storm, spam, phish Trend Micro to boycott security tests Boffins tackle random scanning worms Researchers map out web badlands

What Is Application Security?

Application Security is the strategy and actions to prevent security breaches of applications and systems. Because the vast majority of applications are known to have bugs, security issues such as design, development, implementation, and/or deployment flaws, application security is a necessary component of any company's technology strategy.


Search News:


Copyright © 2001-2008 Jonathan Hedley