-
Recent Comments
- Bouch on Who’s In Charge Here? The Problem of Information Security Governance
- SecurityExec on Who’s In Charge Here? The Problem of Information Security Governance
- dustin on Patent No. 7,124,197: ARP Poisoning Hack!
- Rob on Agility and Risk Compensation: Exploring the Connection
- Navin on Why Information Security Professionals Should Learn Texas Hold ‘em Poker
Tags
agility algorithms application security assessment awareness Awareness / Education awareness instruction awareness training bloginfosec Annoucements Books on InfoSec breach incidents Budgeting for Security business continunity CIA triad CISO CISO savvy CISO skills COBIT Coding Securely / SDLC compliance Conferences / Events / Meetups contingency plans counterfeit counterfeit equipment data breaches data breach notification laws data classification digital signature disaster recovery education Encryption end-point security equipment Exploit Code / Malware facebook fake FBI featured FFIEC Forensics / Incidents FUD FUD Theater GLBA governance government Gramm-Leach-Bliley hackers hash HIPAA honeynet honeypot identity management identity theft IDM incident Industry Commentary Information security Interviews ISACA Jobs in Information Security Johnny Long KPMG law leadership Legal & Regulatory Issues malicious insider malware metrics nation states network News Commentary No Tech Hacking OWASP Patching PCI Penetration Testing perimeter Phishing Policies and Procedures Privacy Privacy Rights Clearinghouse Reverse Engineering risk Risk Analysis risk management ROI ROSI SB 1386 Security security awareness Security Breaches self-awareness Social Engineering soft skills Solutions / Workarounds SPAM spotlight successful behaviors Tools training Uncategorized Virtual Trust Viruses / Worms vulnerability assessment Vulnerability Commentary Vulnerability Disclosure Wireless Wireless Client Wireless Discussion Wireless Security Wireless Vulnerability Discussion
Tag Archives: Social Engineering
No Tech Hacking
April 4, 2008 – 6:00 am
–
I recently had the privilege of bring a special contributor, along with a few other brilliant security folks, of Johnny Long’s latest book: No Tech Hacking. All of us in the security profession are familiar with the concepts, and have used them from time to time without realizing it. So what…
Our End Users: The Weakest Link
March 12, 2008 – 6:00 am
–
Hackers and professional criminals are like most people; they want to accomplish their goal in the easiest way possible. As we have become better at implementing technical controls, such as hardening servers, more aggressive patching, and deployment of a vast array of security devices /…
ID Thieves: Now Getting Married Under Your Name!
August 27, 2007 – 6:00 am
–
The NY Post reports:
Thirty-five couples who were denied marriage licenses in New York City have appealed those denials in the past 10 months on the basis that they were victims of ID theft. The prevailing theory is that thieves used the stolen names to get married for the purposes of green cards…
Businessweek: Business Entities Victims of Identity Theft Too
July 24, 2007 – 6:00 am
–
Businessweek reports that businesses may become victims of identity theft too. The scam is called a “business bust-out”:
A criminal rents space in the same building as your company. Then he applies for corporate credit cards using your firm’s name. The application passes a…
Woman Captures Her Own Identity Thief
June 18, 2007 – 7:03 am
–
Interesting story:
Lodrick’s heart was pounding. Despite the expensive coat, the Prada bag, the glitter-frame Gucci glasses, there was something not right about the impostor she would later learn was named Maria Nelson.
“She had bad teeth and looked like she hadn’t…
Loading ...


