Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Tag Archives: RSA

The FFIEC and Password-Generating Tokens

– In June 2011, the FFIEC (Federal Financial Institutions Examination Council) issued a “Supplement to Authentication in an Internet Banking Environment,” available at http://www.ffiec.gov/pdf/Auth-ITS-Final%206-22-11%20(FFIEC%20Formated).pdf The FFIEC comprises five financial regulatory…

Take Heed of Lockheed’s Plight (Update as of 6/7/2011)

– Note:  Due to breaking news concerning the Lockheed breach, this article—originally published on Monday, June 6—has been updated. Update: According to an article in the June 4, 2011 New York Times by Christopher Drew with the title “Stolen Data Is Tracked to Hacking at Lockheed,”…

Take Heed of Lockheed’s Plight

– I recall, about a decade ago, Dan Geer presenting to members of the FS-ISAC (Financial Services Information Sharing and Analysis Center) and warning that as security measures strengthened so we put more valuable assets under their protection. Then, if there is a breach of that particular mode of…

The Economics of Safety and Security

– One of the most horrifying comments through the entire Japanese mega-catastrophe was that by CNBC anchor Larry Kudlow, as reported in a March 20, 2011 New York Times article by Jeff Sommer with the title: “A Crisis That Markets Can’t Grasp – As Japan’s Disaster Evolves, Wall Street Keeps…

Nastiness at NASDAQ

– Did you catch the article in the February 5, 2010 Wall Street Journal about hacker intrusions at NASDAQ? It is by Devlin Barrett and has the title “Hackers Penetrate Nasdaq Computers.” It is believed that the initial penetration of NASDAQ’s networks and systems dates back to 2010. And it…