Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Executive Women's Forum - Information Security, Risk Management and Privacy

Tag Archives: Phishing

Save The Whales

– By now we all familiar with Phishing, which is the attempt to extract valuable information from an unsuspecting user via some form of social engineering which is usually done via E-Mail but can also be done via telephone (called Vishing.) In the case of an individual, the target is usually…

Attack Vectors Through the Pragmatic Use of Steganography

– The BBC reports that Fujitsu has discovered pragmatic uses for steganography. Unfortunately, by redirecting the mobile phone’s browser automatically, this could lead to using these images as attack vectors. Here are some quotes from the BBC report: “The key is to take the yellow hue…

SecList.org and GoDaddy.com

– Wired reports that godaddy.com shut down seclists.org because Fydor’s site hosted a file that contained myspace user names and passwords that were phished. There are many comments regarding the fact that godaddy.com’s behavior was inexcusable. While mentioned on Wired, it is not…

Security Awareness - Not Education - is the Answer

– Security awareness and security education are two different things. In my mind, awareness is a “lighter” version of education. To be educated means one has a deep understanding of something and acts upon that understanding. Awareness, or to be made aware of something, means that one…

Reducing Online Fraud: A Banking Case

– A bank in Australia is using its back-end to reduce online fraud: The new transaction monitoring system, supplied by the EMC-owned RSA Security, scans online activity in real time to track fraud indicators and generate a “risk score” for each transaction. Customers are then…