Facebook privacy news blowsup, but should it?

News on the latest privacy capabilities have been going around a lot lately. I posted a vid of an overview, as well as a 10 things you need to know article(i think). There has been a lot of talk, and I actually like the new capabilities. I made good use of the previous settings, mostly for pictures.

One thing that came up in all this hoopla, is that Facebook’s default setting or recommended setting is to share with everyone. This will then imply that it is internet accessible. If you dont want that but havent changed the setting, then Facebook will remove it from their servers or you can delete your account. Is your information really gone though?

Some people are even flaming FB for the sharing with everyone or the fact that once it is internet accessible and indexed or spidered or archived by search engines, there is no way it is taken off the internet. This is common knowledge though. Everything you type into your browser should be considered exposed. We can take exception to banking or legitimate -commerce, because they are held accountable by law to protect your information. However Facebook or your blog or google archiving your FB wall or blog or FB possible passing your info via apps or you passing your info via malware spread through FB mail should be considered exposed and out there for everyone to see.

Even with privacy settings hardened I would not post private information on FB. Who are they anyway? Just a company trying to make money, be popular and be successful. Do I know them, to actually store my private information on their servers. If I even store private information on my own computer, that I physically have, I make sure I encrypt it. So why am i going to post private information on FB or blogspot or anywhere else? I am not.

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in Security | Tagged , | Comments Off

Interesting Forensics Story

http://ezinearticles.com/?The-Case-of-the-Teacher-and-the-Teen-Tricksterand160;&id=3208559

A teacher gets spied on via her computer complains, takes her PC to forensics, who finds trojan.

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in Desktop Security | Comments Off

Site Modifications

So I changed the theme, I added some add-ons, most significant one being the twitter feed on the side bar. I retweet a lot of interesting news that I find on twitter.

Let me explain my use of twitter. I follow all the well known security professionals and to be able to see their point of view on subjects as well as get the latest news and information that is going around. Twitter provides good information when following the correct people. I will often retweet interesting articles that people post and they will in turn appear on the website.

I encourage you to follow me if you are interested in information security.

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News | Tagged , , | Comments Off

Follow my Google Reader shared news

Check out this link for access to my RSS shared news.


http://www.google.com/reader/shared/09423364391415399129

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News, Security | Tagged , , | Comments Off

COFEE from Microsoft

Interesting. Computer Online Forensic Evidence Extractor.

http://www.microsoft.com/industry/government/solutions/cofee/default.aspx

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News | Tagged , | Comments Off

smb2 vulnerability

Hello. BSOD + restart is what happens.

See Laurent’s blog post:

http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html

So I had a windows 2008 server, ran the PoC posted by Laurent and BSOD ocurred then a reboot.

ISS Proventia Server Sensor has a signature as well as other HIPS technologies to prevent this. That is for further testing.

Nessus has an uncredentialed plugin to detect this vulnerability as well:

http://www.nessus.org/plugins/index.php?view=single&id=40887

See the MS site for workarounds.

Hopefully they come up with a patch soon.

http://www.microsoft.com/technet/security/advisory/975497.mspx

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in Hacks | Tagged , | Comments Off

Its been a while…

So today Microsoft came out with 2 patches for a critical and important vulnerabilities. Its a good idea to subscribe to the Patch Management mail list:

http://www.patchmanagement.org/

Doing some work today made me refer to the command line kung fu website. I needed a linux command to sort largest files so I could free up some space:

http://blog.commandlinekungfu.com/2009/02/episode-4-listing-files-and-their-sizes.html

Blackhat / Defcon going on this week. Ill try to keep in tune and provide anything that comes up.

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News | Tagged , , | Comments Off

CoreSecurity BlackHat Party

This was an interesting post by McGrew Security:

http://www.mcgrewsecurity.com/2009/06/23/core-security-you-just-might-not-be-cool-enough-for-their-party/

I have checked out their product and it is pretty good. It is always interesting to get this type of information from the community.

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News | Tagged , , | Comments Off

National Cybersecurity: Obama

Im late on this but this was an interesting speach on Cybersecurity.

It is good to see words like hacker, vulnerability and conficker come out of the President of the United States as the site integrates with youtube to bring this video online:

http://www.whitehouse.gov/video/President-Obama-on-Cybersecurity/

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News | Tagged , | Comments Off

Get L0phtCrack

http://www.l0phtcrack.com/

They are back with L0phtcrack 6. I downloaded this and tested it out on my system, cracked a test account I created. I am very interested in using this with Unix passwords and a certain password dictionary that happens to be 99mb in size. ;)

Share and Enjoy:
  • Digg
  • Facebook
  • Google Bookmarks
  • RSS
  • Slashdot
  • Twitter
Posted in News | Tagged | Comments Off