47 karma · joined February 8, 2011
I usually use sentances with 4 or so words, that is odd enough to remember. I combine that with keepass safe for sites i only log into on my computers and synch it using dropbox. I also have access to it on my iphone and ipad. The combination of these techniques enable me to log into most sites without a password manager and all of them on the fly.
If the restaurant would have treated the customers like all the other guests and maybe let them order the more expensive bottle of wine while explaining that it's actually not included (with a smile!) those two guys would have walked out happy and would probably have returned.
Groupon and the other coupon sites is a marketing expense, so treat it like one. You don't put up ads in the magazine with a discount and then scare away the customers when they show up! I don't defend the coupon sites, they seem to take a whole lot of the money for a small benefit. However, if you go into the deal, you might as well make the best of it. They will use the groupon no matter if you're nice or not.
Until twitter sorts out this themselves, there is a need for something like a browser add-on that hides the following from hashtag searches: new accounts, Retweets, Accounts with less than 10 followers, Accounts that often tweet trending topics, Tweets with more than one trending hashtag
Even more interesting, would be a survey within a bigger geographical spread. Is there differences within Europe? What about the rest of the world? Are the opinions similar world wide? I would also appreciate a more detailed view into the selection of the group that answered.
The most interesting thing about the article is that it is spun very heavily in the direction of piracy... The actual answers about piracy for private use, is that less than 20% accept piracy, slightly over 30% not accepting it. The rest have answered that they are sceptical to piracy for personal use.
Accept is 7-10 on a scale from 1-10, sceptical is 2-6 and don't accept is 1 on the same scale. All from the linked report in Danish.
As a security specialist myself, I always do my very best to follow best practices, not only to protect myself, but to show others that I am willing to follow my own advice. I have met security people doing presentations that need to elevate to admin, and they are logged in as admin already. Sometimes even with UAC turned off. This completelly shatters my confidence in them. I am always logged in as normal user and have long (20+) passwords, and make sure people see that I have long passwords. I don't hold others to the same standard, but I know people. If they see that I use 20+ characters, they will not think that the 10 that I want them to use is that bad.
This is the way the security landscape should work. We should all set ourselves to much higher standards than the advice we give others. We should always follow up on it. We KNOW lazyness will cause breaches, so therefore we should never be lazy when it comes to security. For a security company - and especially the president - to have such low security lowers the confidence for the whole industry.
Yes, security is asymmetric. That is why companies must always follow at least the recommended best practices. If they are followed, the target might be too hard to break into and a hacker might go someplace else where it's easier to break in. Targeted attackers might still get it, but we should all make sure they have to work DAMN hard to succeed! If we start thinking that the attackars will succeed anyway, we might as well drop all defences. Display the admin passwords at the bottom of the "About us"-pages.
Bottom line, HBgary fucked up good. They showed the world that they give advice that they don't follow. They deserve the burn and anybody thinking about hiring them should think again. Even if they change the problems that allowed this breach, the basic problem is that they obviously don't understand security. If they did, none of this would have happened.
</end rant>