Sunday, May 2, 2010

Windows 7 Security

This is a great guide to read if you are trying to understand Windows 7 Security.  It does not go too far into the weeds (or details) that will confuse someone with a security background.  If you want an easy to read overview of some of the new security features that are available in Windows 7, this is the place to start.

-Ultimate guide to Windows 7 security

Use AppLocker, BitLocker to Go and other Microsoft security tools
By Roger A. Grimes, InfoWorld, 21 April 10

Windows 7 has been warmly received and swiftly adopted by businesses, with the result that many IT admins are now struggling with the platform's new security features. In addition to changes to User Account Control, BitLocker, and other features inherited from Windows Vista, Windows 7 introduces a slew of security capabilities that businesses will want to take advantage of.

Windows 7 improves on Vista with a friendlier UAC mechanism, the ability to encrypt removable media and hard drive volumes, broader support for strong cryptographic ciphers, hassle-free secure remote access, and sophisticated protection against Trojan malware in the form of AppLocker, to name just a few.

In this guide, I'll run through these and other significant security enhancements in Windows 7, and provide my recommendations for configuring and using them. I'll pay especially close attention to the new AppLocker application control feature, which may be a Windows shop's most practical and affordable way to combat socially engineered Trojan malware.

More.......

Monday, April 5, 2010

ID Theft Protection Services

I was researching a topic that was possibly related to fraud the other day.  It was closer to the grey line of consumer fraud, but I refuse to draw any conclusions based solely on my opinion.  Life has a way of teaching you that even if something grates on your nerves, there are always two sides to every story or even two, three, four sides, depending on who you are speaking to at that time. 

What I ran into was some news about ID Theft Protection Services.   I do not think that you will find anyone who will tell you that ID Theft is not a serious crime or that the documented cases have sky-rocketed in the past three years.  When you look at this from a Risk Management point of view,  you want to look at some options that will help mitigate this threat.  One option that is available is ID Theft Protection Services.

When choosing an ID Theft Protection Service or Insurance, you have to read the fine print to see if it will be a benefit you.  You have to watch out for consumer fraud and conduct research on the company.  Personally, I would never accept an offer by way of phone marketing because there is an increased chance that you are being scammed.  The person on the other end of the phone might not be who you think they are and if they really want your business they can provide a phone number that can be validated (searched for on the Internet).  That way, you can call them back when you are ready to conduct business with them.

Lifelock claimed that it covered all types of ID Theft and basically it didn’t. 

-This is a link to the FTC Case Information with a phone number to contact them for more information.

INFORMATION ON LIFELOCK SETTLEMENT

Here are some more newsworthy angles to the LifeLock controversy and the ID Theft Protection industry.

-Lifelock CEO Todd Davis Does Damage Control
By Dave Nielsen, March 16, 2010


If you hadn't heard, identity theft company LifeLock agreed to pay $12 million dollars to settle charges from the Federal Trade Commission and 35 states. The FTC felt that LifeLock ads were deceptive and overstated the protection provided by the service.


Personally, I think the charges are valid and I had to chuckle a bit when I read this email from CEO Todd Davis sent out to his partners. Mr. Davis certainly has his public relations firm working overtime to write something like this.

More....

and-

-Identity Theft Protection Industry: Divided we Stand, for Better or for Worse
By Denise Richardson, March 17, 2010, updated March 22, 2010


When have you ever seen one bank tear apart another?  Never.  Why?  Because they unify as part of the same industry and work together, for good or ill.  Think about it: the same could be said about any industry--the insurance, credit and debt collection industries to name a few. They band together in a sort of code of honor where one never knocks the other.  They go about their business promoting their own products and services.  It boggles my mind why the identity theft industry does things differently.  Why is it so divided?


Last week's press conference by the FTC and 35 Attorneys General launched a media frenzy that left some of us shaking our heads and others scurrying about to see how best they can twist the news of this recent settlement with LifeLock into their own personal pot of gold.


More...

I have only found one ID Theft Protection Service that offers a Recovery service that covers all types of ID Theft (financial, criminal, social security, medical, etc) and Family Fraud.  They are honest in claiming, “While we provide a comprehensive approach to help prevent the occurrence of Identity Theft for our members, no identity protection service can prevent identity theft from happening.”  They do not even collect your SSN unless you need the Recovery service.  Zander Insurance Group (FAQ) Also, check out the link to how they compare to other ID Theft Protection Services.

Wednesday, March 10, 2010

MSRC - Security Advisory 981374 Released

Does not affect IE8 or Windows 7.

Security Advisory 981374 Released

Microsoft Security Response Center(MSRC) Blog, March 09, 2010

Hi everyone,

Today we released Security Advisory 981374 addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is not affected by this issue. Customers using Internet Explorer 6 or 7 should upgrade to Internet Explorer 8 immediately to benefit from the improved security features and defense in depth protections. Additionally, Internet Explorer 5.01 on Windows 2000 is not affected.

At this time, we are aware of targeted attacks seeking to exploit this vulnerability against Internet Explorer 6. Internet Explorer Protected Mode in Internet Explorer 7 running on Windows Vista helps to mitigate the impact of this issue. Additionally, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. This mode sets the security level for the Internet zone to High. This is a mitigating factor for Web sites that you have not added to the Internet Explorer Trusted sites zone. Please review the Security Advisory for additional workarounds which include modifying the Access Control List (ACL) on iepeers.dll (the affected component), setting the Internet and local Intranet security zones to "high", configuring Internet Explorer to prompt before running Active Scripting, and enabling Data Execution Prevention (DEP) where possible which makes it difficult to successfully exploit the vulnerability.

More.......

-Microsoft Security Advisory (981374)

Vulnerability in Internet Explorer Could Allow Remote Code Execution

Published: March 09, 2010

Link

Sunday, March 7, 2010

The Economics of Spam & Botnets

To state that it has been a while since my last blog post would be an understatement.  I will quote a true unnamed mentor of mine and just say, “Life Happens.”   My work changed and brought me into the world of Project Management.  This subject almost interests me as much as Information Security.  I want to highlight this TechRepublic article because it describes the most recent top 10 spam botnets.  The economic reasons for spam and why the spammers use botnets became somewhat clearer to me.    

The top 10 spam botnets: New and improved

 by Michael Kassner, February 25th, 2010

While doing research for this project, I came across a blog series (first, second, third post) that forced me to rethink. Ranking spam botnets is not as simple as I thought. The blog author, Terry Zink, pointed out that there are several measurement philosophies:

  • The number of bot members
  • The number of bytes sent
  • The number of messages sent

In the grand scheme of things, it may not seem important. But techies like details. Counting the number of bot members or bytes sent is straightforward enough. You would assume that the number of messages would be, too.

Well, it’s not. Botnets are smart enough to create a spam message but address it to a lot of different recipients. That adds another factor when counting messages.

Confused? So am I. To make some sense out of it all, I juggled the different attributes (totally unscientifically, of course) and came up with the following list of the best of the breed.

More here……

Friday, July 17, 2009