Data Security Podcast Episode 67, Aug 24 2009

30 minutes every week on data security, privacy, and the law…..(plus or minus five)

On this week’s program:

* The security lessons from Heartland data breach – what the newscasters didn’t tell you. Details on our Tales from The Dark Web segment.

* What if you discovered a web security flaw and their customer service staff ignored your alerts? An exciting announcement about a project to address this problem.

* Our take on this week’s news.

–> Stream This Week’s Show with our Built-In Flash Player:

–> Scroll down to see links and show notes for this week’s show

–> Stream, subscribe or download Episode 67 – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.

–>Tune into the show directly on iTunes, you can also subscribe to the program on iTunes.

–> A simple way to listen to the show from with stricter firewalls: Listen from Odeo. This site works better if you are behind a more restrictive enterprise firewall.

Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:

  • Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: http://www.testdrivevipre.com .
  • GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. GET YOUR FREE BASIC WEB APP SCAN, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: Podcast.
  • SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by Secure Computing MagazineData Clone Labs is the premier SonicWall Medallion Partner for all your security needs.
  • DeviceLock; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.

Show Notes for Episode 67 of the Data Security Podcast

* EXCLUSIVE: Ira talks with Russ McRee of HolisticInfoSec.org about major security issues. This conversation  project, ReportSecurityFlaws.com .

* Tales From The Dark Web: What the other newscasters didn’t talk about with the news of an indictment of the Heartland / TJMaxx / 7-11 attacker, Albert Gonzales.

*From the News:  Web app attacks lead to possible breach of Law Enforcement data

*From the News:  SQL Injection Dymisytified – A look at the attack and how to protect your applications from it

* From the News:  Report by the Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack

* From the News:  Cyber-Ambulance Chasing (Can’t we think of another way to accomplish this?)

Unspam Technologies filed a “John Doe” lawsuit in federal court against cybercriminals who have been targeting banks. The unfortunate bank customers are now caught between the devil and the deep blue sea. Unspam’s suit seeks confidential account information from the financial institutions, as part of its strategy to track down the hackers.

Here’s the money quote from the coverage in the New York Times:  Even though Unspam’s lawyer “concedes he is unlikely ever to discover the names of the hackers… he hopes to get the details of the thefts, the names of victims and other information from the banks that can be used to improve security and possibly identify the hackers.”

We’re not sure we like this strategy. Who’s next? Shall we force insurance companies to cough up individual medical records in order to prosecute hospital ID theft?

Read the story by Saul Hansell in the New York Times.

* Wrap: Vanishing eMail

Leave a comment