Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Category Archives: Cybercrime

Medical Identity Theft: Your Money or Your Life

– What could be worse than ID theft of your financial identity? After all, you could lose thousands of dollars, spend days on the phone with financial institutions, credit bureaus, and merchants. Your interest rates could climb on your credit card debt due to the practice of “universal default”…

Protecting the Critical Infrastructure: Beware of Crimeware

– I first became involved with U.S. critical infrastructure protection in the late 1990s when I joined others in the Banking and Finance Sector to form the FS-ISAC (Financial Services Information Sharing and Analysis Center). This is how it happened. In the 1998 timeframe, John Lauria, a colleague…

Bad Behavior - Thoughts on the Malicious Insider

– Following every high-profile insider security breach, there is usually a slew of vendors who will triumphantly point out that, had they installed their product, the victim company would have avoided the whole painful problem. The adverse publicity, the implementation of new Draconian controls,…

Should the US Military Create a DDOS Botnet?

– Absolutely. The military should have both defensive and offensive capabilities in electronic warfare, just as in traditional warfare. DDOS capabilities to knock attackers off-line should certainly be a priority. If one believes that it should be policy to “walk softly and carry a big…

Slashdot Post On Security Ethics Demonstrates Professional Naiveness

– Over at Slashdot, an anonymous reader was quoted as follows (in entirety): “I am a senior security xxx in a Fortune 300 company and I am very frustrated at what I see. I see our customers turn a blind eye to blatant security issues, in the name of the application or business requirements. I…