Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, May 6, 2011

CompTIA Security Minus

Today I took and passed the CompTIA Security+ 2008 exam. I don’t see a lot of value in these certifications, but it was a requirement for work, and my employer paid for the exam, so that was all fine.

Anyway, this post is about the security practices of CompTIA, the organization that thinks it’s competent to judge my knowledge of security practices.

Wednesday, March 9, 2011

Security non-story of the day

Via BusinessInsider, Verifone Trashes Square, Saying It Has "A Serious Security Flaw":

Today is a wake-up call to consumers and the payments industry. Last year, a start-up named Square introduced a credit card reader for smartphones with the goal of making it very easy for anyone to accept credit cards through a mobile device. Seems like a great idea, but there is a serious security flaw that Square has overlooked that places consumers in dire risk.

In less than an hour, any reasonably skilled programmer can write an application that will "skim" – or steal – a consumer's financial and personal information right off the card utilizing an easily obtained Square card reader.

So what? Anybody you hand your card to could be putting it through a skimmer. It doesn’t matter if it’s a Square user, the 7-11 clerk, or the waiter at your favorite restaurant. There’s no Square-specific risk here. The only story is that Verifone is scared to death of the competition.

Thursday, March 3, 2011

How to raise a generation of assholes

Via BoingBoing:

An "A" student at a Virginia middle school was given a one-day suspension for holding open a door for a known adult who had her hands full. This violated the school security policy, which holds that the doors may only be opened centrally after visitors are vetted by a CCTV camera.

Thursday, November 18, 2010

On keeping people from dying

Over the past several years, the TSA has steadily increased the scrutiny that airline passengers face. There was the liquids thing, the ziploc thing, the shoes thing, the laptop thing, and now the backscatter/scrotum-mashing thing. The purported objective of all these things is to prevent terrorists from blowing up planes, which would result in passengers dying. Which would be bad.

However, as the burden of air travel increases, would-be passengers are likely to shift some of their air travel to other forms of transportation, such as driving. Megan McArdle and Stephen Bainbridge have already announced their intention to do so.

I drive about 15,000 miles a year. If I, and everyone like me, decided just once every 13 years that we'd rather drive 500 miles and back, instead of flying, we'd be driving 0.5% more than we do now. About 45,000 people die each year in the United States in motor vehicle accidents. Americans driving 0.5% more will kill about 200 more people each year in the US. That's as many deaths as a Boeing 757-200 being blown out of the sky every year. And 12,000 more people will be injured.

Flying is, by far, the safest means of transportation for covering a given distance. Making flying less attractive, relative to driving, has deadly consequences.

Is the TSA really trying to keep people from dying, or just push the blame outside their agency?


Update: Shortly after I wrote this post, Nate Silver covered the topic in both greater depth and breadth. (The nerve!) Here’s a particularly interesting excerpt:

Other passengers may substitute car travel for air travel. But this too has its consequences, since car travel is much more dangerous than air travel over all. According to the Cornell study, roughly 130 inconvenienced travelers died every three months as a result of additional traffic fatalities brought on by substituting ground transit for air transit. That’s the equivalent of four fully-loaded Boeing 737s crashing each year.

It’s nice to see that my back-of-the-blog estimates are in line with reality. Thanks, Sterl!

Here’s a related Fermi problem: How many people are aboard airline flights over the United States right now?

Saturday, November 13, 2010

And you thought Stuxnet was bad

Roger C. Davidson walked into a computer services shop on Main Street in Mount Kisco, N.Y., seeking help with his virus-plagued computer.

The owner of the shop, Vickram Bedi, 36, confirmed that there was a virus on Mr. Davidson’s computer, a virus Mr. Bedi said was so troublesome that it had also damaged the shop’s computers, officials said.

This led, of course, to $6 million dollars in fees being paid to the computer shop, and a tale of intrigue involving the CIA and Opus Dei.