Brian

Archive

Can’t trust those strength meters to give you a strong password

So a study by Concordia has shown that the password strength meters we sometimes rely on to measure how good our passwords are, aren’t really that good themselves. The same password gave varied results about...

So this is why you need larger monitors (humor)

I ran across this today and thought it was yet another reason for strong passwords, but also so true and very funny. So with that, I will leave you with the comic. The real reason...

FREAK Vulnerability Report

On March 3, 2014 researchers announced an SSL/TLS vulnerability billed the FREAK Attack. This attack is a result of a long ago US Government policy requiring “weak” encryption for export outside of the US. The...

Why do we need a universal authenticator?

So I ran across this article and it was just "wow" about how some people manage their passwords. Now I've seen the stickies under the keyboard (or worse, on the monitor), and I even remember...

Are We Getting Closer to Universal Authenticators?

So I’ve talked a lot about how you can use 2FA within your organization, and how it could have solved some big issues in terms of hacks and other breaches in the last few months,...

Goodbye Spock, you will be missed

So on a personal note, I had to mention the death of Leonard Nimoy yesterday (nice obit here). I remember watching Star Trek in syndication on PBS on Saturday nights (3 straight shows and no...

Location becomes a factor in 2FA

As I’ve said before, there are many things that could be used as a factor for authentication, and I think this may be the first commercial use on a large scale. This is potentially a...

Sometimes 2FA is hidden, but it’s still there

Now this isn’t something new, but I thought that the description of what some banks do to secure your login is a good one. We aren’t all banks, and we don’t all have the resources...

Remember: Compliance does not equal security

I was thinking about the push for compliance that we always hear about: “I need to be compliant to XYZ for reason ABC”, where you can fill in things like PCI, so you won’t be...

Healthcare Breach of 70M Records

Late on Wednesday, it was confirmed that Anthem, the second largest health insurer in the U.S., was breached (ransacked is the word used to describe the attack and severity of the access). While it isn’t...