Misunderstanding Cybercrime

Thats a big fingerprint

Information Security used to be easy. I would spend the day emailing friends, wait until my manager hassled me for the 17th time about responding to a users query, make a couple of recommendations attaching a copy of the security policy then go back to emailing pictures which explained why there was only one female [...]

Most Annoying Consultants

Thats all your stinkin policy is good for

Infosec would have a better reputation if all consultants were perfect like me. When speaking to a project manager, we should have completed our research. Scoured the internet, finding out what a particular application does and how many security vulnerabilities are out there. The list goes on, but suffice to say a good consultant always [...]

Most over-hyped security

I don't care if you're an old woman. You're taking your shoes off or I will tazer your wrinkly ass

Whether you call it security theatre or just a sales pitch that sets expectations too high. We’ve had lots of products and processes that have claimed to increase security only to contain enough hot air to propel one of Richard Bransons baloons across the world.
Here’s the cynical breakdown of security that was too hyped up.
Airport [...]

Michael Jackson on Infosec

Wacko Jacko the IT Security Experto

 
After being declared having the best infosec song ever with “Smooth Criminal”, Michael Jackson took some time out of his busy schedule to speak exclusively with the cynic.

Moonwalking its way right onto this site, the full unedited text of how it went down:

IC: Hi Michael, thanks for taking the time out to speak with me [...]

Is Your Firewall A Fire Hazard?

With the economy taking quite a bashing  and the housing market looking pretty miserable the question might be: Where is the silver lining? And I think I may have found it for those poor souls who have just seen their plans of moving to a new house dashed – you don’t have to tidy up! [...]

7 ways Infosec can prepare you for Swine Flu

Pandemic flu, virus outbreaks, the end of the world. These are things that a cynic laughs in the face of… but an infosec cynic only raises an eyebrow.
If working in Infosec, which is an industry built on the solid foundations of PC viruses, has taught me anything. Its how to survive a pandemic. I look [...]

5 reasons to love infosec

Infosec sometimes unfairly gets a lot of bad press for being a barrier to business goals and objectives. How infosec professionals don’t understand business needs and drivers. How pouring money into security is about as good as burning it.
But infosec has improved the quality of working and the lives of workers the world over. The [...]

When the Cynic went to Infosec

Day 1 and I was determined to be at infosec nice and early, wanting to cram all the information I could in the one day that I was attending. However, things didn’t start off too well.The trains on the Picadilly line were suspended and took me around 2 hours getting to Earls Court.
Other than the [...]

Cracking Cryptography

How to bypass encryption

I think the cartoon sums it all up! Wikipedia even explains it here.

Repenting of your seven deadly sins

SIN! SIN! Most people know sin. Whether you are religious or not, sin is a really useful concept that involves a wrong attitude toward your higher power and results in alienation from it. All major faiths, Islam, Christianity, Judaism have the concept. Even if you are not a believer, you have probably seen movies such [...]

8 films that needed more infosec

Many times its difficult to illustrate the benefits of following good information security advice. Company’s tend to keep quiet about their failings so there are few case study’s available to analyse.

But not to fear, the cynic has improvised and analysed 8 movies whose entire outcomes could have been changed had some simple infosec guidelines been [...]

The Cynics guide to information security consultancy

So you want to be an infosec consultant? If you’re like most guys, its better you consider a career in risk management or audit. Or maybe you’ve already got some variation of “security” in your job title but are stuck in a rut. Results are coming slowly and career progression is almost non-existent. What you [...]

Not so good security

fail owned pwned pictures

For the easter weekend, a few reminders of how security doesn’t work… or does it?

Prevent terminated employees from accessing sensitive data

Redundancies and corporate re-organisations are an unfortunate reality in today’s economic climate. Too often, businesses leave themselves vulnerable to a data breach or serious security incident during the redundancy cycle by not immediately revoking the network and application access points of terminated employees.
With Companies like RBS announcing massive job cuts, the threats that these companies [...]

The Cynical Roundup: The year so far Q1-2009

Obama allowed to keep his blackberry
President 2.0 fought against the Whitehouse’s security policy of no personal emails by lying on the floor of the oval office and crying for 15 minutes until his demands were met.
 
Neither George W Bush not Bill Clinton used e-mail during their presidencies. When asked to comment on blackberry users, George [...]

Crashing Cars and Firewall Management

With all the doom and gloom of the past few months and billions of whatever currency you like being poured into the economy I have to report on a ray of hope. I think my son may have hit on the solution completely inadvertently. He’s not a renowned economist, just an honest, hard working car [...]

Infosec 2009

Speak to anyone born before 1975 and they’ll harp on about ‘the good old days’ and how the younger generation of today have everything too easy.
Naturally, being born after 1975, I disagree with the viewpoint. Take education for example. In the olden days you packed kids off to whichever boarding school was furthest from where [...]

Quizzing the recruiter – an interview with Ruth Jacobs

Barclay Simpson (www.barclaysimpson.com) is the leading company in corporate governance recruitment in the UK, and was established in 1989. Ruth Jacobs is an Information Security Recruitment Consultant with Barclay Simpson.
Like most security professionals, my contact with recruitment consultants is limited to times when I am looking for a new job, so I decided to reverse [...]

Ross Anderson does it again

In what is becoming an attention-grabbing ‘look at me’ trend, Ross Anderson, the much-famed Professor of Security Engineering at Cambridge University has added to his ongoing list of entertaining gripes and accusations, the good Professor has stated that the dedicated cheque and plastic fraud crime unit is funded by banks!
Apparently having banks part fund an [...]

Aunties Botnets

The British Broadcasting Corporation (BBC) is the world’s largest broadcaster. Having a budget of more than £4 billion, its no wonder there’s little they can’t do in persuit of the greater good.
So, unsurprisingly the BBC would cover the rise in cybercrime. However, as part of their investigation and subsequent program “click” the BBC purchased a [...]