Tampilkan postingan dengan label computer security. Tampilkan semua postingan
Tampilkan postingan dengan label computer security. Tampilkan semua postingan

Senin, 18 April 2011

Why the importance of computer partnership-InformationWeek

The underlying connection was closed: A connection that was expected to be kept alive was closed by the server. For years, the federal government has launched one policy initiative after another to protect critical IT infrastructure in coordination with the private sector. There's been progress, but the threats--computer breaches from foreign parties, fast-spreading worms, and hidden malware--have outpaced the advances, leaving computer systems and networks across industries more vulnerable than ever.

What can businesses and Uncle Sam to, together, it reverse this dangerous trend? There must be three areas of immediate focus. First, the public and private sectors need to share more information--more parties must be included and new platforms used. Second, they must pay more attention to defending against attacks that threaten critical IT infrastructure and even damage physical facilities. Third, their collaboration must be ratcheted up to the next level-the-real-time identification and response as threats occur and, more to the point, "moving security practices from a reactionary posture to one that's proactive and preemptive," says Rich Baich, leader of Deloitte's Cyber Threat Intelligence Group.


In other words, the growing number of cybersecurity "partnerships" being established between the federal government and the business community are more than a one-way street. The feds may be driving the effort through initiatives such as Homeland Security's 2009 National Infrastructure Protection Plan, developed in response to a presidential directive, but companies stand that benefit from the more resilient cyber defenses that result from such collaboration.


The feds have defined 18 infrastructure areas considered essential national interests. They include the agriculture, banking, chemical and defense industries, as well as government facilities. The goal is to protect the computer systems and networks that serve those vital sectors from increasingly winning threats, including those running the hostile actors such as terrorist organizations and rogue nations.



Even the Department of Defense is looking to work with the private sector. When Deputy Secretary of Defense William Lynn recently outlined the DOD's plans for bolstering its cyber defenses, he called for increased cooperation with industry. "With the threats we face, working together is not only a national imperative to, it's one of the great technical challenges of our time," he said in February at the RSA Conference in San Francisco.


Over the past two years, the DOD has developed "active defenses" that use sensors, software, and signatures to protect its military networks. Next, Lynn said, the agency will make its cyber capabilities available to the private sector "to help protect the networks that support government operations and critical infrastructure," such as the power grids, telecommunications networks, and defense will systems.


Several organizations have laid the groundwork for increased collaboration on cybersecurity. Since 2003, the U.S. Computer Emergency Readiness Team (US-CERT) has been providing updates on threats that industrial control systems and other computing infrastructure. The 42,000 members of InfraGard, and partnership between the FBI and the private sector that dates back to 1996, are devoted to it, creating the "actionable intelligence" for infrastructure protection.


Much of the activity revolves around information sharing in key industries. For example, the National Council of Information Sharing and Analysis Centers supports threat response for companies in financial services, healthcare, public transportation, and a handful of other industries.


Information sharing is important, but it's not enough. Scott Charney calls, VP of trustworthy computing with Microsoft, calls the information "and the tool, not an objective."


Industry-specific initiatives are evolving into something more substantial. The Financial Services Sector Coordinating Council, whose members include Bank of America, Citigroup, Morgan Stanley, and Visa, coordinates the protection of the IT and other infrastructure operated banks, insurance companies, and other financial institutions. The council does that work in collaboration with the departments of Homeland Security and Treasury, and in December it took things a step further via a memorandum of understanding with the National Institute of Standards and Technology, Commerce Department, and Homeland Security that paves the way for financial firms and government agencies to work together on the development of cybersecurity technologies and test beds.

Minggu, 17 April 2011

Security against identity theft-the Times Herald-Record

"Nothing in our garbage, if it is shredded," says Robert Unger, CPA and Certified Fraud Examiner Judelson, Giordano on ampersand Siegel in Ashtabula. DOMINICK FIORILLE/TimesStephen Sacco Herald-Record, the FBI says that identity theft is the fastest growing crime in the United States over time, tax – if it is, And the personal information floating around the Internet and in the mailboxes of citizens – is ruthless to prime attempted theft your personal data.Good news: E-submission by the State, the IRS, or New York is safe – in fact, many experts on the security of your computer is recommended. There are also some bad news: you should be very careful, with everything else, including leaving personal information in your mailbox. E-file. Experts argue that electronically is safe, and probably your refund sooner. If not (e) the file, the envelope directly to the post office, not the location in the mailbox. Keep your tax returns on safe safe. Shred documents that you will not have to keep. Do not use e-mail for sensitive information. Be aware of phishing. The IRS's e-mail. If you receive a call that from the IRS, the IRS to verify by calling 800-829-1040. Source: myID. comGreg Miller, owner of CMIT solutions of Goshen, which provides computer support and security for small and medium-sized enterprises, is warning people about a "phishing scams", or in the practice of sending e-mailin order to filch the personal data. These e-mails look very professional and masquerade as legitimate communications from existing companies, or even the IRS. But following the links in the e-takes you to the website of the lousy thugs trying to trick you to give up its information.So, all verified and never give out your password information or social security number, Miller said. Miller also warns that any personal work on an unsecured Wi-Fi network. In other words, don't try to file to your local coffee shop with free Wi-Fi. But even a home network may be vulnerable, how to use WEP encryption — which is 10 years old technology – instead of the more credible the WPA encryption.If nothing, Miller suggests, consultation with an expert on computer. Many people to wireless routers with the encryption in a credible, he said, but I don't know how to turn it on. "It is not hard to turn on (encryption), but it's not intuitive," said Miller. Rob Unger, CPA and Certified Fraud Examiner Judelson, Giordano on ampersand Siegel in Middletown, said keeping information safe has become a major concern for the people who prepare taxes. "Nothing gets in our garbage when it is shredded, '' he said.Unger encourages people never use email for things such as social security numbers, "shred" confidential documents, and let sit in your mailbox.Patrick Turner, a small pond advice in Wallkill, which also provides computer support and security for small and medium business, agrees with Unger. He said that the main rule should be never include any personal information in e-mail. "Email was simply not designed with regard to safety," he said. Turner also suggest updating all viruses and anti-spyware software.But (e) the application is another matter. Most experts advise people electronically. "(E) programs are solid in terms of encryption practices," said Brad Maione, a spokesman for the New York State Department of Taxation, The practice is also lit up. From 11. March of the 3.9 million New Yorkers their state tax returns filed electronically, in comparison with 690,000 New Yorkers, who on paper, said Maione.ssacco@th-record.com
Reader response we reserve the right at any time delete all content from this community, including, without limitation. Please check our Community rules for more information. We ask that you report content that you believe in good faith violates the above rules, click the flag next to the offending comments. New comments are received, only two weeks from the date of publication.

Sabtu, 16 April 2011

China populating the holes in the ' Great Firewall '-The Independent

It seems that China is moving aggressively to plug holes in its "Great Firewall" censorship system, the frustration for businesses and Web users, foreign Internet companies and analysts.


E-mail service Google Gmail is heavily damaged, as well as several popular online services providing encryption software, which depends on many companies and individuals for site security and bypass firewall.


Analysts said that the problems were followed by a call for tender, the weekly "walks" protests in China, inspired by the political uprising in the Middle East and North Africa and an indication that the Government intends to nipping dissent in the bud.


"Tested the new options to determine whether there are technical means to solve with the possibility of organized opposition," said Russell Leigh Moses, a political analyst at Beijing-based, AFP.


China is still expanding the system of control and censorship of the Internet has been dubbed the "Great Firewall of China", aimed at the wick information or comment, that the Government considers a threat to his authority.


Gmail users complained about the access difficulties in recent weeks, which led some to switch to other services, such as Hotmail and Yahoo!, and Google shows his finger on the Chinese Government.


"There is no technical problem on our side-we checked extensively."It's a Government deadlock on the issue is carefully designed with Gmail, "he said in a statement Monday to AFP by Google.


Providers of virtual private networks (VPN)-encrypted tunnels through the Internet to facilitate secure communications and allow users to circumvent the censors also accuse Government-from the point of sometimes colourful.


"Yes ... The Klingon Empire scored a couple of (z) full of hits on the USS Enterprise, "Bill Bullock, Executive Director of the popular VPN provider, WiTopia, said based on China-in the last email, images from the American television show," star trek ".


At least three other VPN providers found that reports of distortion in China recently.


A spokesman for the 12VPN AFP that providers were, to avoid new entries from China and the period of instability. "


"How can we know that it is part of the Chinese response to the invitation to" walk "as a form of protest," he said.


Appeal on a mysterious online demonstrations in dozens of cities around China, every Sunday created a high security at places designated by the protest. Still no apparent protests have been reported.


China faces growing public discontent over official corruption, inflation and growing income disparities-similar to a combination of factors which contribute to Arab riots.


The Beijing Government as the Middle East mess with unease, in large part, blocking or mention of the Chinese Internet.


The impact of the disruption they are looking for Online users to access blocked sites such as the long time Facebook or Twitter and company.


"It's one more attack, which makes it difficult to get complicated in China," said Ben Cavender, Associate Director of market research group based at Shanghai, China.


He said that the company already faces a tough business environment in China, including foreign complaints to the regulatory environment, which discriminates against them.


"And when they have problems of access to information, it is one more important issue to address."


The Chinese Government has repeatedly said that he has the right to the police station of the Internet. The Ministry oversees Internet issues immediately did not respond to a request for comment on the latest violation.


Some observers said foreign companies are particularly affected, as they rely on access to foreign sites for business.


But Chinese netizens expressed dismay, especially also over Gmail, which is popular with users for white-collar and educated.


"This kind of intermittent interference on the Internet-where users have the patience-seriously affects the rate of use (for Gmail)."It's really despicable method, "said one of the online rules of conduct on the popular Web portal Sina.com.

Jumat, 15 April 2011

As threats grow, so demand for the safety of the data-The Tennessean

The underlying connection was closed: A connection that was expected to be kept alive was closed by the server.

PHILADELPHIA Aaron Weaver works in the basement of his Pittsburgh Allegheny Co., Pa, home, making the Internet a little safer.

His skills as an information security specialist are in such demand that his employer, Pearson Education, years of him work from home after he told the education-publishing firm he wouldn't relocate it to Colorado when it recruited him.

With increasingly frequent reports of big companies such as Google, DuPont, GE, and Johnson and Johnson being targeted would be hackers, the "infosec" career field is growing "as fast as the online computing is expanding," said Weaver, 33.

As new technologies spread, sat in the security threats, said David Foote, CEO and co-founder of Foote Partners LLC in Vero Beach, Fla., which conducts independent research on information technology jobs.

"It's the blessing and curse of technology," he said, adding, "It's a slam dunk that work in security."

In 2007, spending on security as a percentage of operational IT spending by businesses was 7.2 percent, Foote said. The 2010, it had increased it to 13.5 percent.

Weaver, the married father of three, graduated from Bob Jones University in 2000 with a degree in graphic design, but he was later drawn that computer science.

"To be quite honest, there wasn't that much money in graphic design," said Weaver, who was born in Quakertown, PA., and grew up in Kenya.

As a security specialist for Pearson Education, and global publisher of print and online educational materials, the Weaver works, assure the security of Web applications related to online teaching and protect user data, such as student grades and teacher-student interactions.

He also ensures that the company complies with a wide array of privacy laws and regulations.

Weaver can rattle off numerous examples of where security needs to catch up to the galloping pace of new technologies.

Think about your smartphone and all those nifty mobile apps you trust with your personal data.

Think about "cloud computing" and how it has shifted much of what you once did on your physical computer's online services, such as photo storage.

Think about the regulations that govern information security that differ from the state's state and nation's nation. "Global companies need experts on all regions and what you can and can't do, '' Weaver said.

Information security is not limited to computers, networks and databases. Security needs are emerging with technological advances in the cars that will soon transmit status reports via email, or smart meters that communicate information about household electric usage, said Ed Schlesinger, head of electrical and computer engineering at Carnegie Mellon University in Pittsburgh.

"There's security, even in the recycling and disposal process," he said, referring to personal data left on devices that are discarded.

Just last week, New Jersey's state comptroller reported much warmer than a third of state computers ready to be sold at public auction still contained Social Security numbers, health records, and child-abuse documents.


View the original article here

Recent events, the challenges of data security concerns-Sioux Falls Argus leader

It is the time of the year in the field of data protection.


CRIS Freiwald for a lot of calls lately from the companies, the suspension of the trade and information security.


The main reason for concern is the series of disasters triggered by an earthquake in Japan, or military battles in countries such as Libya. The threat is local and seasonal, and although predictable, still catches some companies not ready.


"Phone calls we are, therefore, the rivers are rising. I get calls every day, "said Freiwald, which sells business continuity services. "It's a flood, that gets people in this part of the country."


Freiwald is Vice President and General Manager of the northern region CoSentry, Omaha-based company which operates data center in Sioux Falls; Kansas City, Missouri; and two in the area of Omaha.


CoSentry services range from providing backup workstations-complete with telephones and computer-security services for the company's computer data. Some companies rent space for storing the computers back up important data. Clients are, however, increasingly, advancing cloud computing option lease capacity computers CoSentry.


Sioux Falls Center occupies part of the former gate of the building in the North-East Sioux Falls. It shares the building with the warehouse Lewis drug.


CoSentry, promotes as the second largest data center in South Dakota. It routes the lowest super Center-profile for automatic data processing in northwestern Sioux Falls.


The difference between CoSentry and ADP is that CoSentry provides services that help other companies to protect data and commercial activities. The recently expanded ADP Center protects data related to payroll services, which ADP provides to clients on a national basis.


CoSentry launched Sioux Falls in 2005 with the client a single anchor: CNA guarantee. Now has 71 clients. Most of them rent of premises for the common location of the computer.


Data Center is also home. Secure leases the Office space at Cajana, which provides services in the field of technology to institutions such as universities.


Qwest recently for its high capacity, fiber optic networks to combine all four CoSentry data centers in the region. That was the problem for the local and national commercial appeal, said Freiwald.


Midcontinent communications providers, regional, and SDN also have data systems, tied to the Center.


Part of the Centre is being adjusted on the basis of the Colorado financial services business will be run on the device. The company will occupy 42 CoSentry currently stocks from 106 computer chassis, each of which represents the seven feet high.


How to use technology to extend to trade, the growing number of undertakings, which are sensitive to human attack, as well as a national disaster.


Many of the recent challenges to CoSentry originate from flooding feared areas in Minnesota and North Dakota. Freiwald expects a similar rush of flood-related phone calls again next year.


Many companies undertook to prepare even more this year, after last year's flooding problems, said Freiwald. "But they weren't."


Business behaviour is obviously not otherwise than human nature. Procrastination often prevails.

Aruba Networks ® architecture step will speed up the access network of the Enterprise ...-Business Wire (press release)

SUNNYVALE, Calif.--(BUSINESS WIRE)--The rapid onslaught of Wi-Fi-enabled mobile devices presents a number of new challenges to IT departments seeking to speed service delivery, significantly lower network-related costs and mitigate risk. Businesses' access networks are critical to meeting these challenges. The recent and exponential growth of enterprise mobility has fundamentally changed requirements for how these networks are built and operated.



“The granular visibility that Aruba's mobile access network services, based on its MOVE architecture, give us into users, devices and applications, speeds troubleshooting and enables us to improve service quality for every user across the network.”


"The 'centers of gravity' for computing and network architectures have largely mirrored each other through the history of IT," said Mark Fabbi, vice president and distinguished analyst at Gartner Research. "However, the trends of server and data center consolidation, hosted virtual desktops (HVDs) and cloud computing have altered the requirements for network services and how the LAN could be architected. IT organizations can easily overspend on highly engineered, expensive, traditional approaches to campus LAN architectures."


To help companies meet new challenges resulting from these shifts, and to facilitate the evolution from Ethernet port-centric to mobility-centric access networks, Aruba Networks®, Inc. (NASDAQ:ARUN) today unveiled its Mobile Virtual Enterprise (MOVE) architecture. Aruba MOVE provides context-aware networking for the post-PC era. Aruba Mobility Network Services are delivered centrally from the data center across thin mobility access “on-ramps.” With Aruba MOVE, IT organizations have a purpose-built but flexible solution for enabling mobility, and a clear path to shift expensive investments away from legacy wired access networks.


NEW! Industry’s First Mobile Device Access Control (MDAC) Solution for Apple® iOS Devices


Providing easy, secure network access to facilitate the “Bring Your Own Device” (BYOD) phenomenon is one of today’s most significant IT pain points. Aruba addresses this with the introduction of Mobile Device Access Control (MDAC). This solution is designed for zero-touch, secure provisioning of Apple® iOS mobile devices. Recently acquired Aruba Amigopod enables self-registration of mobile devices, automated certificate installation on iOS devices and automated authorization of users. Scalable up to 10,000 concurrent sessions, Amigopod also enables seamless Integration of corporate branding for captive portals, and is fully interoperable with multi-vendor networks.


NEW! ArubaOS 6.1 Mobility Services: Enabling Context-Aware Capabilities across Wireless and Wired Networks


At the heart of Aruba's MOVE architecture, ArubaOS Mobility Services enable the development, deployment and enforcement of a single set of network services that manage security, policy and network performance for every user and device on the network, regardless of access type. ArubaOS Mobility Services are centrally deployed, with private or public cloud-based management. This mobility- and user-centric approach enables a necessary shift away from more than 20 years of Ethernet port-centric network architectures to reduce costs and enable workforce mobility.


Mobile Device Fingerprinting, another key innovation announced today, enables the network to identify and monitor Apple iOS and other mobile device platforms. This capability, combined with Aruba Amigopod and Aruba Airwave Network Management, enable the Aruba MDAC solution.


"Since the beginning of the year, we've consistently had two to three times the number of wirelessly-connected devices on the network as we have staff," said Lee Cullivan, manager of data, voice and security networks at Boston Medical Center. "The new device fingerprinting capabilities and the general level of visibility and control that the Aruba MOVE architecture gives me into users, application traffic and even device types helps us ensure that our mobile network is truly enterprise-grade. Aruba gives us the tools we need to ensure that the network not only works, but that it gives our physicians, patients, visitors and staff the best possible experience."


“A mobility-centric approach delivers better security and easier user administration across wireless, wired, remote office and outdoor networks," said Philippe Hanset, network architect at the University of Tennessee. "The granular visibility that Aruba's mobile access network services, based on its MOVE architecture, give us into users, devices and applications, speeds troubleshooting and enables us to improve service quality for every user across the network."


"Working with Aruba gives Accuvant the confidence that we will have the right solution for our customers' mobility problems, whether they are network-, device- or application-based," said Dan Wilson, co-founder and vice president of Accuvant, an Aruba sales partner. "Advanced features like device fingerprinting and application fingerprinting, combined with the new guest access enhancements are truly helping my customers manage the onslaught of mobile devices on their business networks."


The Next Step: Rightsizing for Mobility


With companies already leveraging 802.11n to reduce the number of Ethernet ports provisioned on their LANs from four ports per person to two- or even one-port-per-person, Aruba’s MOVE architecture enables further cost reduction through "Network Rightsizing for Mobility." Rightsizing for Mobility with Aruba’s MOVE architecture reduces the total cost of ownership (TCO) for the access network by up to 70 percent when compared to legacy port-based network architectures.


"Until recently, we built networks based on the assumption that we'd need four Ethernet ports per person - one each for voice and data, with redundancy," said Mike Redeker, CTO for ATB Financial, a leading financial institution headquartered in Edmonton, Alberta. "The Aruba MOVE architecture lets us rightsize our network for mobility, not only greatly reducing the number of physical ports and cables we deploy, but also giving us the ability to better support our increasingly mobile workforce. Taking a mobility-first approach to access network development has decreased both capex and opex, reduced help desk calls and enabled people to work wherever they need to on whatever device they choose.”


NEW! Ubiquitous, Affordable Network “On-ramps”


For more detail on new Aruba access points and additional products announced today, please see the companion press release here: www.arubanetworks.com/news-releases/aruba-networks-announces-the-mobility-centric-enterprise-access-network/


"In a world where users are always on the move and utilizing more than one device, the need for IT to enable context-aware mobility, which identifies the user, device, application and location is critical," said Dominic Orr, president and CEO of Aruba. "The Aruba MOVE architecture represents a real opportunity for businesses to not only rightsize their networks, but to rightsize their operations. Securely enabling users to work when and where they like results in increased productivity for both IT and users, as well as the opportunity for significant cost reduction."


For additional information on Aruba MOVE: www.arubanetworks.com/the-lan-is-dead


(Hilarious!) Videos – Mobility challenges and Aruba MOVE:


About Aruba Networks, Inc.


Aruba is a global leader in distributed enterprise networks. Its award-winning portfolio of campus, branch/teleworker, and mobile solutions simplify operations and secure access to all corporate applications and services - regardless of the user's device, location, or network. This dramatically improves productivity and lowers capital and operational costs.


Listed on the NASDAQ and Russell 2000® Index, Aruba is based in Sunnyvale, California, and has operations throughout the Americas, Europe, Middle East, and Asia Pacific regions. To learn more, visit Aruba at http://www.arubanetworks.com. For real-time news updates follow Aruba on Twitter and Facebook.


© 2011 Aruba Networks, Inc. Aruba Networks’ trademarks include ®, Aruba Networks®, Aruba Wireless Networks®, the registered Aruba the Mobile Edge Company logo, Aruba Mobility Management System®, Mobile Edge Architecture®, People Move. Networks Must Follow®, RFProtect®, Green Island®. All rights reserved. All other trademarks are the property of their respective owners. Specifications are subject to change without notice.


Forward-Looking Statements


This press release contains forward-looking statements, including statements related to expected benefits and availability of our products, expected performance of our products, anticipated demand for new products and features offered by us, future market and customer demand conditions and position of our products in the market. These forward-looking statements involve risks and uncertainties, as well as assumptions which, if they do not fully materialize or prove incorrect, could cause Aruba's results to differ materially from those expressed or implied by such forward-looking statements. The risks and uncertainties that could cause our results to differ materially from those expressed or implied by such forward-looking statements include our ability to react to trends and challenges in our business and the markets in which we operate; the adoption rate of our products; shortages or price fluctuations in our supply chain; our ability to compete in our industry; fluctuations in demand, sales cycles and prices for our products and services; and our ability to successfully market and transition customers to next generation products; as well as those risks and uncertainties included under the captions "Risk Factors" and "Management's Discussion and Analysis of Financial Condition and Results of Operations," in Aruba's report on Form 10-Q for the fiscal second quarter ended January, 31, 2011, which was filed with the SEC on March 11, 2011, and is available on Aruba's investor relations Web site at www.arubanetworks.com and on the SEC Web site at www.sec.gov. All forward-looking statements in this press release are based on information available to us as of the date hereof, and we assume no obligation to update these forward-looking statements.

Kamis, 14 April 2011

MIT and the University of Wales, train cyber technicians-ComputerworldUK

University of Wales may become one of the Great Britain in particular, computer education and training centre after the recent Conference produced a lot of work with the prestigious MIT geospatial data centers in the us.


What will emerge from cooperation in concrete terms, it is still unclear, but the Declaration after the Summit this week in Cardiff this week spoke of an agreement, "working together to create solutions for cyber security leadership and training, an agreement that will be Wales, led by developments in this area."


WikiLeaks-fearless nevymenovaly or irresponsible nuisances? Updates with latest developments. Read more:


"The Conference came to the conclusion that the multidisciplinary team it is necessary to solve the problems of cyber security and that the United Kingdom and the United States will have to produce thousands of experts in this field, in the next few years," said Professor John Williams, Director of the MIT geospatial data centre.


As well as University and MIT in institutions such as Harvard University, the University of Oxford, the University of Memphis, Boston University and the University of Central Florida.


Currently in Great Britain, becomes the cyber security training in FF. scattered way University courses throughout the country, or through the computer science engineers, who professionally later change in the direction of their career.


Stenografu as some outside expertise and the experience gained from the preparation of which the UK is still lacking, even if there is a lack of trained personnel in the US, as it stands.

Selasa, 12 April 2011

Ottawa urged to fight with the grid hackers-Vancouver Sun

Computer hackers are infiltrating the distribution in Canada, say insiders, industry, who want the Federal Government to act.


"Of course we know from our customers that have been infiltrated their systems. It already for some time, "said Doug Westlund, President of N-dimension solutions, company, Richmond Hill, Ontario, computer security, which works with national instruments.


"You don't even know who they are, but are close to home."


Westlund, whose company is part of a research project sponsored by the United States Department of energy to protect the emerging digital "smart grid" against cyber attacks, compared to the penetration and exploration of the American intelligence system incidents in 2009.


You also allegedly embedded software cyberspies in tools for computer, which would disrupt future services. Officials speculate, Russia or China was responsible.


Westlund said that Canadian intrusion think that was the transition to the systems and their controls to embed malicious codes.


Francis Bradley, a Canadian Electric Association, said that "sometimes, we see potential attacks" against portions of the grid.


"Intrusion detection Systems on the company to pick up some of the people effectively ping servers. We haven't seen the loss of energy to customers as a result of the cyber-attack. "


Security jitters about North American power system interconnected deepens as the industry evolves from largely isolated systems electromechanical world into the grid, built around the interoperable, wireless digital technology. The objective is to optimize the production, transmission and distribution.


The most disturbing change includes tens of millions of wireless "smart meters" installed in homes and businesses for faster and more effective two-way communication with the local Utility, which subsequently combine operators of transmission and generators.


"There will be greater and greater potential for cyber attack, because there are potentially multiple vectors of attack," said Bradley. "It is real. I see that the types of resources that companies are putting into it and they even devoting a number of resources that are on IT security on an ongoing basis, if it is not real. Their answer is proportional to the threat and the response is significant. "


But understanding the shrill claims that smart grid is dangerously insecure.


Capture of critical infrastructure is going on in tandem with the militarization of all on the Web-and Governments are responding.


The US said its digital infrastructure a strategic asset and computer security a priority of national security. Britain has computer security a matter of the highest in its national security strategy.


Canada last fall revealed the national cyber security strategy, which is similar to the more political than the framework action plan, with which many for a measly $ 90 million in the five years of funding.


Bradley, who in the past criticized the Federal inaction, but now it seems that her Government confirmed.


"For the first time in many years, at least on IT security, I'm very positive steps the Federal Government, it seen." He refused to elaborate.


The news came out this week that security chiefs in Britain have signed up, Prime Minister David Cameron's press company responsible for the critical national infrastructure, including the National Grid, the Government agency electronic spy watch for hackers on their systems.


Unlike water or gas electricity cannot be stored in large quantities; must be generated and then immediately use. It is in the world of extreme just-in-time commodities.


This means, for the production and the transfer operation must be monitored and controlled by doling out millions of wireless devices across the continent to the Internet, potentially all the time, still exposing system able to hackers and other cyber attacks.


It is the arrival of smart meters, which potentially opens up a huge new front "ways of attack" that could allow sophisticated intruders access to the system-for anything from attacks denial-of-service and identity theft, stealth attacks on power stations.


Most models of smart meters now have at least basic security functions, although the instrument-sponsored tests in the us are still successfully hacked into some.


"The general consensus among colleagues and most of us in the security business, the technology of intelligent meter out of security technologies," said Mark Weatherford, Chief Security Officer for Washingtonbased North American Electric Reliability Corporation. NERC enforces reliability standards for North America, a huge and interconnected bulk power system of generators, transmission lines and control systems.


Although the smart meters are next to the distribution grid, Weatherford fears could manipulate to distort the balance of the generation and transmission.


For example, the hacker can exploit some of the common errors in metres, serves the city could potentially turn off 100 000 or more meters, or "flip" the power on and off, causing the electrical load back through the system, tripping breakers "ripples", throwing power plants offline and, where appropriate, frying equipment.

Minggu, 10 April 2011

Experts: Vehicle systems can be hacked-UPI.com

SAN DIEGO, March 16 (UPI)--computer systems in modern cars are susceptible to hacked, allowing criminals to gain control of them remotely, American security researchers say.


A team of security experts from the University of California, San Diego and the University of Washington has identified a number of vulnerabilities through which hackers can gain access to the computer system of the vehicle remotely, NewScientist.com reported Tuesday.


In one test was attacked by a cell phone hardware installed in luxury cars, allowing the team to inject malicious code into the electronic management of the car.


In theory the hackers would then sell the car thief, giving them their position and the unlock is remotely.


The team also managed to take control of the car using malicious applications on Smartphones with Bluetooth system in the car.


Another weakness identified was a stereo system, as the scientists were able to show that the software embedded in the MP3 file to install the firmware into the car, allowing similar abuse.


Previous research has revealed how an automobile computer systems could also be accessed via the on-board diagnostics port, the access point usually used by dealers and repair businesses to download data on the health of the vehicle.

Sabtu, 09 April 2011

Twitter settles with FTC over celebrity pisálků-register account

Twitter has been settled with the US Federal Trade Commission (FTC) over a complaint that it failed to maintain the privacy of the users quite well, the lack of the two successful attacks against micro blogs network in 2009.


The settlement means that Twitter will be obliged to establish more stringent information security policy-which is independently audited on Twitter at the expense of, every two years. Micro blogs Web site have also agreed to guarantee that mislead consumers about the "extent to which protects the security, privacy and the confidentiality of private information.


Breach of the agreement, concluded last Friday, the State of Twitter until 16 thousand dollars apiece.


The agreement draws a line under the FTC'S complaint over the brace violations from January to May 2009 that hackers gain administrative control of Twitter. The hackers were able to send messages under a false name, as well as snoop in the privacy settings of the users, the most prominent.


The hackers were able to take a prominent Twitter accounts – including those that manage Barack Obama and Britney Spears--and cheering as the result of safety deficiencies in Twitter back in January 2009. A simple password that the attack was used to penetrate into the Twitter channels, before falsely trip Fox News pundit Bill O'Reilly as gay and protichudnou special admission from the spear, her vagina that four feet wide "with razor sharp teeth".


Second, a separate hack at the end of April enabled the hackers to spy on the account settings of Twitterati. Breach of the hamster found that Ashton Kutcher and pop star Lily Allen Rose blocked a celebrity gossip indicates Perez Hilton, for example. Barack Obama blocked 96 Twitter users at the time, according to the screenshots on the French blog hack. ®

He warns of the Adobe Flash Player is a zero day attack-ZDNet (blog)

Daniel Kennedy leads initiatives in the policy and operational security management, directs strategy for risk assessment and certification and is Director of business continuity planning and restoration on the Praetorian security group, LLC.


Before the Praetorian security group, Daniel was a global information security D.B. Zwirn co., where he directed the company's information security program. He was specifically responsible for the development, implementation and maintenance of information security policies of the company. He could also security metrics, security awareness and training programme, security incident response, security, audit and development of the company security technology strategy. In this role, the company worked closely with the CIO, COO, head of compliance, head of the legal, the head of the infrastructure, client services and overseas IT managers.


Before the D.B. Zwirn, Daniel was Vice President and program manager for security applications on Pershing LLC, a division of the Bank of New York. Daniel responsibilities included management of enterprise application security program, the coordination of the application security assessment and penetration testing, application security training, documentation, general principles of safe coding and development of application security firm SDLC LINK SERVICE SETUP. He was the main connection for application security issues between the development of applications and teams, such as information about the Security Office, Internal Audit, risk, IRM (Management) and business teams. He served in several committees, including the company's security infrastructure working, security architecture and leased and the Presidency of the Council concerning the application of security companies, interdisciplinary group, consisting of application developers, and information security subject matter experts.


His previous position at Pershing include the development of management and systems engineering positions in the construction of Web applications to facilitate online merchant. He also was employed by Donaldson, Lufkin and Jenrette Inc. analyst role for technology in the area of finance.


Daniel has the title of the masters of Science in information systems from the Stevens Institute of Technology, masters of Science in information assurance from Norwich University and Bachelors of science in information management and technology, Syracuse University. Is certified as a CEH (Certified Ethical Hacker), EC Council, CISSP and has license to NASD Series 7.

Jumat, 08 April 2011

Ensure the security of the information in the interconnected world-VOVNews vn.

Ensure the security of information in the interconnected world, it will be the main topic 6 Security World Conference and Expo (Security World 2011), which is scheduled to take place in Hanoi in April 5-6.

The event is jointly organised by the Department of General Logistics and technology under the Ministry of public security of Viet Nam, the computer Emergency Response (VNCERT) and the International Data Group in Vietnam (IDG Viet Nam).


It is expected that the safety of the world 2011, the most prestigious national forum for the information security industry. It will be an excellent environment for networking and experience sharing of the latest technology and security trends from the experts and leading organizations around the world. Allows managers and senior staff work directly with the safety information in Vietnamese businesses access the latest security devices and solutions that are appropriate for the business strategy of companies.


The Conference will focus on the introduction of highly effective security solution at a reasonable price for the optimization of the investment security organisations and businesses.


The exhibition will also include a parade, the latest software products, equipment and solutions, including against viruses, spyware, spam, information storage and management; Cyber security management, Web application security, identity and access management and objective safety oversight from leading local and international information security solutions company. The Expo will be a good opportunity for the security firms to extend their relationship with local and international partners.


Gaps in the field of information security and cyber still exist despite the rapid development of information technology in recent years, and 2010 was considered a "heated" year of cyber security with the occurrence and spread of new viruses, and professional and sophisticated hackers.


In Vietnam, many enterprises are faced with the Foundation and the dissemination of many new variants of viruses, and the number of cyber attacks is steep.


According to the latest news from ASEAN, IDC estimated that the prospects for security of the information will be promising in 2011. Growth market security software is helping to increase the threat of data loss and attacks, and an increase in the need for the management of safety in society and with the individual user. The report also emphasises that the management of risks to the security market is expected to grow at the highest rate of 13% in 2011. While risk management and information security market, it is estimated that an increase of 10.5% in comparison with that in 2010, identity and access management market increased by 12.5% in the same period.

Vormetric data security provides encryption, access control and ...-key management Security Park

Nexidia is a leading provider of audio search and speech analytics solutions. From inception, Nexidia OnDemand hosted platform has expanded significantly and now handles more than 150,000 hours of audio per day for a large contact centres and entities.


Nexidia selected the Vormetric Data Security provides encryption, access, and key management to meet the requirements of regulatory compliance for PCI DSS, and other credentials, which governed its OnDemand hosted solution.


Nexidia speech analytics pioneer supply through a model that will be hosted, Software as a Service (SaaS). Nexidia OnDemand platform, contact centre provides access to the full set of functions in its intelligence Enterprise product suite (ESI), including automatic topic discovery, detailed call reporting and categorization, and agent performance management. Nexidia selected Vormetric to ensure the safety of the data for this large volume of audio files and to assist, in accordance with the requirements for the safety of customers.


Our hosted solutions continuously reads and writes a large audio files, and we are obliged to meet stringent service level agreement, said Ethan Zweigel, vice President of safety for Nexidia. The Vormetric solution integrates smoothly with our existing systems, working in the background data and the security of our customers remain transparent to end users. Vormetric with performance has had no discernable impact on our response times.


After a comprehensive evaluation of competing products, encryption, Nexidia selected Vormetric data security to protect the millions of files, access to Nexidia ESI on high performance servers. Nexidia selected for their ability to Vormetric centralize and simplify key management, policy, virtually no impact on the performance of applications and be extremely low maintenance.


Vormetric gained a reputation as a transparently protects the intensive environment of transactions like Nexidia OnDemand, without any discernible impact on the performance, said Richard Gorman, President and CEO Vormetric. Vormetric with pleasure to work with software as a service providers, such as to protect their data customers Nexidia on the source, helping them to comply with the numerous regulatory mandates, which controls many of the industry today.

Kamis, 07 April 2011

Fujitsu showcasing PalmEntry physical checks access solutions and Vantage Data ...-Business Wire (press release)

04 April 2011 7: 30 AM eastern daylight time

FOOTHILL RANCH, Calif. and LAS VEGAS--(BUSINESS WIRE)--The International Security Conference Exposition (ISC West) – Fujitsu Frontech North America Inc. (FFNA) "," a leading provider of computer business solutions, including advanced technology, biometric security products and solutions, digital media, will demonstrate its PalmEntry ™ physical access control solutions in booth # 4045 at the 2011 International Security Conference Exposition (ISC West). The biggest event in the us for the physical security, ISC West will be held 6-8 April 2011 at the Sands Expo and Convention Center, Las Vegas, Nevada.



"The day the Earth smart data center revolution"


Interested in meeting with Christer Bergman and Brian Yoshii on ISC West should contact Erin Sun at (949) 855 5543 or erin.sun@us.fujitsu.com.


About Fujitsu Frontech North America Inc.


Fujitsu Frontech North America Inc. offers a wide range of products, including solutions for the retail trade, networking and switching solutions, digital media solutions, RFID tags and biometric solutions bill dispensers-sales, service and engineering support throughout the United States. Fujitsu Frontech North America Inc., headquartered with operations and product development in 25902 Towne Centre Drive, Foothill Ranch, CA 92610.. For more information about Fujitsu products and services call us at 800-626-4686 or visit www.fujitsufrontechna.com.


About Fujitsu Frontech Limited


As part of the Fujitsu Group, Fujitsu Frontech Limited binds people together through the development, manufacture and sale of application technology, such as ATMs, the operation of the branch, POS and totalizator terminals and public display facilities. Fujitsu Frontech also offers associated software, system integration and outsourcing as part of their overall solution. The company supports the security sector supply of products incorporating the latest Fujitsu palm vein authentication technology and is actively involved in the development of key technologies in various fields, with the current focus on color electronic paper and RFID systems. For more information, visit: www.frontech.fujitsu.com/en/.


Copyright Fujitsu Frontech North America 2011, Inc. all rights reserved. Fujitsu and the Fujitsu logo are registered trademarks. All other trademarks are the property of their respective owners. The commands in this document are based on normal operating conditions and are not intended to create any implied warranty of merchantability or fitness for a particular purpose. Fujitsu Frontech North America Inc. reserves the right to change at any time, without warning for these commands, our services, products, and their warranty and performance specifications.

HID Global Unveils US Federal Identity compliance initiative for physical ...-Business Wire (press release)

05 April 2011 09: 07 AM eastern daylight time demonstrates how the Agency can reduce the cost and complexity of the FIPS 201 compliance using the modular approach and industry on key offers from a single supplier

LAS VEGAS--(BUSINESS WIRE)--HID Global, leading edge solutions for the provision of secure identity, today announced that it will be demonstrated in a planned family of simple, cost-effective, complete solution for the FIPS 201 compliance at ISC West 2011 first. The company's Federal Identity compliance initiative will facilitate the upgrade of the existing federal agency physical access control system (PACS) to support the recently authorised Government identity validation standards.



"HID the unique position to serve this important market, the need for Government"


Initiative of the Federal compliance with HID Global combines the strengths of the company's solutions for access control and technology migration, enhanced cryptographic security of its next generation reader platform and extensive identity portfolio insurance, acquired from ActivIdentity, recently purchased HID global society. Customers will be able to deploy the HID Global readers are seamlessly integrated with the ActivIdentity ActivEntry upgrade modules and FIPS 201 fully comply, without having to replace their physical access control head end server, or hardware control panel door.


According to a memorandum of February 2011, issued by the US Department of Homeland Security (DHS) and the Office of management and budget (OMB), the existing physical and logical access control systems, you must upgrade to a personal identification verification (PIV) credentials in accordance with the instructions of the National Institute of standards and technology (NIST)before federal agencies can use technology developments and to update the financial means to carry out other activities. HID Global's Federal Identity compliance initiative will speed and simplify the implementation, offer migration path from legacy PIV credentials and provide access to the modular hardware, which facilitates the Agency to respond to regulatory changes, change the security level in selected areas, such as the požadovánoa take advantage of the ongoing progress in access control technology.


"HID the unique position to serve this need, the Government of critical market," said Brad Jarvis, Vice President, strategic product initiatives with HID Global. "Our federal initiative against the conformity of the identity gives the Agency the confidence that they can achieve compliance quickly, efficiently and with the support of all of the necessary audit, on the basis of incremental, continuous financing, protecting investment in existing infrastructure. We are extending our generation platform with modular reader hardware, which allow agencies, very flexibly address compliance with the requirements at all levels of the access permissions area of BEERS. "


HID Global for the next generation of readers using the EAL5 + safe element (SE) hardware tamper-proof protection keys and cryptographic operations, and standard open under the supervision of device Protocol (OSDP) seamless and secure, bi-directional communication link with the company ActivEntry hardware modules. This creates a fully certified, turnkey solutions and for the modernisation of the existing physical access control infrastructure so that it can verify the credentials across the full range of PIV assurance levels defined by the Federal Government's Special Publication 800-116 (SP800-116). Last ActivEntry 2.4 offers also adds a new service application programming interface (API) integrates the ability to write PACS directly to services for authentication.


HID global plans to extend its offer solutions to all levels of permissions SP800-116 access, including the area of regulated, restricted, and exclusion. If you want to show the ability of the HID Global offers deployment during the first two phases of the initiative on compliance with its Federal Identity, the company featuring his upcoming generation of access management platform, the iCLASS readers, in the following examples in ISC West 2011:

Of regulated access to transactions: This solution shows how HID Global next generation access management platform supports card authentication key (ZAG) certificate access, and provides access to the controlled area for the requirements of SP800-116. Contact and biometric transactions: This solution enables the BEERS certificate validation approach, which provides access to the regulated, restricted, and the exclusion of the requirements of SP800-116.

HID Global will offer their Federal Identity compliance initiative, a group of products through its network of proven, physical access control channel partners. The initiative is backed by the company's genuine HID value offered, which stresses the highest level of quality and delivery performance of global products. HID Global also plans to extend the program beyond the FIPS 201 to support Public Key Infrastructure (PKI)-on-the-door compliance and also BEER and BEER-I-C (PIV-compatible) cards issued without the requirements of the federal bodies.


About HID Global

HID Global is the trusted source for secure identity solutions for the millions of customers around the world. Recognized for high-quality, innovative designs and direction of the industry, HID Global is the supplier of choice for OEMs, system integrators and application developers serving different markets. These markets include the physical and logical access control of concentration, including strong authentication and credential management; Printing cards and personalization; highly secure social security number; and the identification of technologies used by the animal industry and ID and logistics applications. The main brands of the company belongs to HID ®, ActivIdentity ™, FARGO ® and LaserCard ®. In Irvine, California, HID Global has more than 2100 employees worldwide and operates international offices that support more than 100 countries. HID Global is an ASSA ABLOY Group brand. For more information, visit www.hidglobal.com.

HID ® and the logo of the HID iCLASS, FARGO and HID connect are trademarks or registered trademarks of HID Global in the u.s. and other countries. All other trademarks, service marks and names of the products or services are trademarks or registered trademarks of their respective owners.

Rabu, 06 April 2011

EMC Division against hackers hacked-abc27

SAN FRANCISCO (AP)-the largest manufacturer in the world of computers, data storage, said Thursday that its Security Division has been hacked and that aliens vulnerable to widely used technology for the prevention of the computer break-in.


Infringement is embarrassed, EMC Corp., also Prime Minister, security vendor and potentially threatens highly sensitive computer systems.


The Incident is a rare public acknowledgement of the security company that was hacked its internal technology against hackers. It's particularly disturbing, because the company sold technology Security Division of EMC, RSA, plays an important role in the sure unauthorized persons are not allowed to log on to the heavily guarded networks.


The scope of the attack was not known immediately, but the potential impact could be widespread. RSA's customers include military governments, banks and health care facilities and health insurance outfits. EMC, Hopkinton, Massachusetts is founded, in itself is an RSA customer.


EMC said in a filing with the Securities and Exchange Commission, RSA has been the victim of what is known as "Advanced persistent threat," jargon into sophisticated computer attack. The term is often associated with corporate espionage, national attacks or high cybercriminal gangs.


EMC offer clues about the origin of the suspected attack. He says he recently discovered a "highly sophisticated" attack in the course of its networks and discovered analyticky that confidential information about RSA SecurID products. The technology supports the ubiquitous original RSA keys "hardware" and the other products this important computer networks with an additional layer of protection.


Products more difficult for someone to break into your computer and in the event that your password is stolen, for example. RSA, work equipment in conformity with the back-end software, generates additional password, which should know only the holder of the device. But if a criminal can figure out how they are generated by the additional password, the system is at risk.


RSA is one of the best-known names for this type of technology ", two-factor authentication".


RSA refused to comment on the type, or how much information was stolen.


Richard Stiennon, security analyst at IT-harvest, he said that the "great consequences" of the criminals were able to silently connect critical systems using information stolen.


"Never would have been a sign that you have violated," he said.


In his submission to the SEC, RSA said it "believes that the information extracted is not successfully a direct attack on one of our customers, RSA SecurID." However, he warned that "this information serve to reduce the effectiveness of the existing implementations of two-factor authentication as part of a wider attack."


"We have no evidence that the safety of the customer relating to other products like RSA influence," said the Executive President of the society, Art Coviello. "We also believe that no other EMC products was influenced by this attack. It is important to note that we don't believe that a customer or employee is personally identifiable information has been compromised as a result of this incident. "


The company said it provides "immediate remediation steps" for customers. It didn't say what it is. It outlined the safety tips that offer clues about how their customers could focus with information stolen from the RSA, for example, to carefully monitor the use of social networking sites, people with access to networks, the critical and the need to educate employees on dangers of clicking on links or attachments in suspicious emails.


EMC said it expected that the breach to have a meaningful impact on its financial results.


Its shares slipped 8 cents to $ 25.58 in extended trading on Thursday. They ended the regular session of 25 cents to $ 25.56.


Copyright 2011 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

Target e-mail addresses-stolen, Minneapolis Star Tribune

Target Corp. has joined the list of dealers and bankers, whose e-mail addresses were stolen by hackers over the weekend.


The seller sent messages to customers Monday afternoon and evening, warning of a security breach on the Epsilon marketing company in Irving, Texas, it works with some of the greatest names of the people in the banking and retail.


Best Buy Co., Inc. and U.S. Bancorp were also among the victims of the attack.


"The objective of data protection takes very seriously and will continue to ensure that all appropriate measures to protect personal data," he said in a statement Tuesday, the target.


Analysts say that the customer lists could allow hackers to craft a credible, but false e-mails, known as "phishing" attacks, "the aim of defrauding consumers or taking control of their computer.


"Now the criminals know more about you, and you can focus better," said Avivah Litan, a computer security analyst research firm Gartner. She ranked the breach of security such as the level of disaster 7.5 to 8, on a scale where 10 is the worst, "because of" what could turn into a.


Infringement, one of the largest in history, it reveals the risk of outsourcing customer communication outside the company-long interest in experts, privacy. Experts predict, it could lead to major changes in the way of storing and sharing personal information.


The stolen emails to customers of large banks, including capital one Financial Corp., Ameriprise Financial Inc., Barclays Bank, US Bancorp, Citigroup Inc. and J.P. Morgan Chase and co., and customers of the large retailers such as Best Buy, target, Walgreen Co., and Kroger Co.


Also stolen were the e-mail addresses of students through the College Board, a not for profit organisation that runs, saturation and customers of the Walt Disney Travel Co., a subsidiary of Disney destinations.


The first threat for the consumers is likely to be flooded with unwanted spam messages. Also could be a bum to give away passwords and user names, which provide access to bank accounts, allows hackers to know more about their personal life.


The direct theft of bank accounts unlikely because in most cases, a hacker did not have enough information to perform transactions. But consumers would be tricked into visiting phony Web sites that download malicious software to PC consumers. Can record key or in some cases, to take on a computer without the knowledge of consumers.


Consumers cannot prevent an authentic-looking but fake e-mails in your Inbox, but deleting emails that ask for personal information or provide a link on a Web page, can protect. "Be more skeptical than to believe," he warned, Jason Miller, Manager of the safety of the data and information and computer security company Shavlik Technologies New Brighton.


The company, such as Epsilon store a large amount of personal information from some of the largest companies in the world, which is a very attractive target for hackers. When their security systems are breached, the influence is growing, because the data of the client exceeds the number of companies and sectors, privacy experts say. Hackers can then combine this information together to create a more complete profile of the man.


"These companies represent a large, concentrated instead of attack," said George Peabody, Director of emerging technologies in the Mercator Advisory Group in Maynard, mass.


Often, hackers wait years before using the stolen information, knowing that people will not be retained in breach of the initial data, said Paul Stephens, Director of the defense and protection of the Privacy Rights Clearinghouse on privacy in San Diego. "There is a real tendency to forget these things, but the information that is stolen is there forever."


However, the breach of the data so easily taken care of Epsilon, experts predict. Millions of people have already received an e-mail warning from banks and retailers, though avoid replies to e-mails that request personal information.


Best buy to promote its affected customers "be very careful" when opening links or attachments in e-mails from unknown senders, while J.P. Morgan recommended that customers use their e-mail address as a login ID and password for access to the information of the bank account. Bank of Minneapolis to suspend all marketing and e-mail programs through Epsilon for an unlimited period, said a spokesman for the US Bancorp.


Epsilon, a subsidiary of Alliance Data Systems Corp., of Plano, Texas, describes itself as "the world's largest permission e-mail marketing service provider." The company sends e-mails 40 billion a year and boasts 2 200 clients.


Epsilon refused to publish all the names of the companies affected by the breach of security or the number of people with disabilities. Spokesman also refused to discuss the causes of the disturbance.


Of the violation is so large that it could have a lasting impact on consumer confidence in the e-mail notification. Chris Douglas, head of the project in the Park in spring, in Stillwater, said, e-mail notification of security breaches has received from the three companies: US Bancorp, Ameriprise, and Best Buy.


Douglas said he had already shifted their membership in the Best Buy Reward Zone loyalty program, because they believe that the company violated a promise not to share your personal information. "I know it's the proverbial barn door closing, after he goes on a horse," he said. "But it seems that one of the few things within my control."


Richard Trident, Executive Director of Bank technologies, consultancy firms in San Carlos, predicts that the breach will reduce the response rate for e-mail solicitations by 30 to 50% in the next year. "We just turned into marketing the highway in a dirt road with holes," said Crone. "It will slow down your e-mail marketing efforts significantly."

Is your smartphone are security risk? -JoongAng daily

Most computer users wouldn't t dream of from their desktop or laptop open attacks, viruses and malware.

Guess what? Your smartphone at risk as well as cyberattacks. No, just that, but you never had to leave the computer in the cab or in the bar, but it can happen with a smartphone. And then the alien could all highly personal information, continue past your mobile device.


As the wonders of mobile computing start sinking in with consumers so they are anxious. And in Korea, it is almost non-existent security awareness for mobile devices. But the risks are real.


Example: reports emerged yesterday that the older version of Cocoa, and it's one of the most downloaded applications in Korea, is exposed to major cyberattacks. Cocoa is the Mobile Messenger service through which people can send and receive messages to a mobile and Wi-Fi.


WINS Technet, a local area network information security company, said the 1.3.4 version of Cocoa speech for Smartphone that is running on the operating system Google with Android, it was found the security vulnerability that allows hackers to intercept messages, if used Wi-Fi.


IF it is shown to be true, I don t, I ll use [Cocoa] from now on, said Joyce Shin, Cocoa 28letý aficionado, who works in the electronic industry. Shin says, that its report may contain personal data, and even intimate information. I think people tend to be more open and Frank said, because the application is working on their own handset.


Technet with advice on Win last week, cocoa allegedly fired for this version of the application that uses the 1 percent of users, cocoa 10 million.


We advise our users always upgrade to the latest version, which not only includes new features, but also the necessary measures for safety, said an official of the Cocoa.


Cocoa phenomenon highlights the greater threat: Smartphones are increasingly becoming targets for hackers around the world.


According to Symantec, California-based maker of software for computer security, known in the mobile operating systems increased from 115 in 2009 to 163 in 2010.


Experts argue that there are many ways how hackers can attack on the mobile phone, the most popular is to download the application. In the second week of March, Android market, app store for Android phones, hit around 60 malicious applications.


So what are you doing with your smartphone if you want to stay safe? Experts advise people to ensure that all of their applications are the latest version, which may have fix for security lapses in previous versions.


It may have to be done manually from Smartphones don t automatically update the application as a normal computer.


Also advise, download your security software and made using an unsecured wireless network.


Most harmful codes that we found in Smartphones are designed to collect personal information, such as lists of contacts, text messages and other things, said Lee Seong-geun, an analyst at Ahn lab, a computer security company Korea with 1. We advise people to download antivirus software for smartphones.


AhnLab V3 Mobile recently released 2.0, an antivirus program with different security features, such as passwords for important files, limitations of the wireless network connection, as well as for data backup.


And AhnLab is not alone. Companies are rushing to develop a security infrastructure for the Smartphone. Ssomon, Korean tech firm, recently published by the mobile device Management, an application that allows users to delete sensitive files and documents stored on a Smartphone from a remote location, if the device is not lost. SoftSecurity also made similar applications.


Although further development is necessary, security of the information in the mobile arena starts much more attention these days. According to a report by the Agency for Internet Security Korea Korea with information security industry broke the mark of 1 trillion won last year for the first time.


While the largest proportion was taken up by the network security products (accounting for 324.6 billion won), wireless and mobile security products accounted for 26.2 billion won, 80 percent jump from the year 2009.


The wireless and mobile business isn t big, but we expect a sharp rise in the near future, said an official of KISA.


Kim Hyung-eun [hkim@joongang.co.kr]

Security of data demand, well-Philadelphia Inquirer

Aaron Weaver works in the basement of his Pittsburgh households to the Internet for something safer.


In its capacity as a specialist information security are in such demand that his employer, Pearson Education, let him work from home, after the company said that he would move the education publishing in Colorado, when it hired him.


The increasingly frequent reports of big companies such as Google, DuPont, GE, and Johnson and Johnson of hackers field career "infosec" grow "as fast as the online calculation," said Weaver, 33.


How new technologies, security threats, said David Foote, CEO and co-founder of Foote partners, l.l.c., in Vero Beach, Florida, which carries out independent research on information technology (IT) jobs.


"It's a blessing and a curse," he said, adding: "It is nothing to work in safety."


In 2007, the expenditure on security as a percentage of operating company to 7.2 percent was, said Foote. By 2010, increased by 13.5 per cent.


Weaver, a married father of three, he graduated from Bob Jones University in the year 2000 in the field of graphic design, but later was computer science.


"Frankly, it wasn't so much money in graphic design," said Weaver, who was born in Quakertown, but grew up in Kenya.


As a specialist security Pearson Education, a global publisher of print and online educational materials, Weaver is working to ensure the security of Web applications related to online teaching and for the protection of user data, for example, the results of the study and a student-teacher interaction.


He shall also ensure that the company is in compliance with a wide range of privacy laws and regulations.


Weaver may seek from the numerous examples of security needs to catch up with the high pace of new technology.


Think your smartphone and all those nifty mobile application, trust, your personal information.


Think about "cloud computing" and how it is moved, many of what were you doing in the online services, computer, physical such as saving the photos.


Think about the regulations governing the security of the information which differ from State to State and nation to nation. "Global companies need experts in all regions and what can and cannot do," said Weaver, "".


Information security is not only computers, networks and databases.


Security needs with technological advances in the cars, which will soon be transmitting status reports by e-mail, or smart meters that communicate information about household electricity use, said Ed Schlesinger, head of the electrical and computer engineering at Carnegie Mellon University in Pittsburgh.


"And in the process of recycling and disposal, is security," he said, referring to the personal data left on the devices, which are discarded.


Just last week, the controller of the State of New Jersey announced a major problem-almost a third State of computers that are ready for sale by public auction still contains social security numbers, health records and documents of the abuse of children.


Corporate executives on bad publicity, the company suffer, their data, in particular, their customers, they are attacked or stolen.


"It may take over the company, the whole tag," Foote said.


Even firms whose expertise is Internet security is not immune. Consider the example of HBGary federal, which was an attack hacker activist group Anonymous rocked last month.


When the Washington firm Executive, Aaron Barr, has threatened to reveal the identity of the anonymous members, the group struck.


Hackers broke into a network of California company and stole tens of thousands of e-mails, which were published on-line. After the embarrassment of Barr announced his resignation.


Even greater story is how WikiLeaks disconnected visitors confidential American military and diplomatic documents into the public domain, showing that information security is more important than ever before.


Dice.com, the national work listing pages for information technology professionals, has more than 1300. the security of information places listed-an increase of 54 percent from this time last year, said Tom Silver, Senior Vice President for the cube.

Selasa, 05 April 2011

NCP engineering selected as finalist in three categories for the network ...-SYS-CON Media (press release)

NCP engineering selected as finalist in three categories for the network products Guide Awards 2011

NCP Engineering Inc. today announced that network products Guide named the company a finalist in three categories for the annual 2011 hot companies and awards the best products in the publication. NCP Secure Enterprise solution was selected as a finalist in the category of best security Software. In addition, the company's successful implementation of your business solution for the American Hospice was honored in the category of best layout and NCP's blog, VPN Haus, has been recognized in the category of best's blog.


Key facts:

Network Products Guide hot company and awards the best product to honor the achievements and awards in every aspect in the IT industry. This year's winners will be announced at the annual lunch on 10. May 2011 in Las Vegas, during the week of Interop. The NCP Secure Enterprise solution, which consists of the NCP Secure Enterprise client, NCP Secure Enterprise Server and NCP Secure Enterprise Management System, is designed specifically for companies with large, comprehensive remote access environments. Centrally managed software solution provides workers with a single point for administration of remote access system of the company, including IPSec/SSL VPN, firewall, Certificate Management, provisioning and practical functions of the NAC. Flexible software solution for remote access management is simple, integration into any third-party hardware or software is already on the spot, while maintaining the strong and the creation of a set of rules. As the only administrator is able to easily configure and manage profiles for remote users from one central station. American Hospice requires VPN solution, which would have allowed 180 home health aides directly and securely access the corporate network via their mobile devices at the same time in the field. NCP Secure Enterprise solution provided by the customer with a single, comprehensive, universally compatible-and-replace strategy without rip. NCP's solution protects patient data, the employees of the American Hospice – both on the road and on the devices themselves. The Foundation also provides the Department with a single point of Administration for the entire network, a VPN, as well as practical network features for access control and management. VPN Haus is the hub for conversation on all things related to network security. The Blog provides readers with Q: as in a network of appropriate and timely security issues with experts. Readers can learn how to overcome common problems relating to issues such as the mobile health compliance, secure remote access to the network, PCI compliance, inter alia. Readers can stay in touch with VPN Haus via e-mail subscriptions to RSS, Twitter and YouTube.

Resources:


Tags


NCP engineering, network products Guide hot company and best product awards, NCP Secure Enterprise solution, remote access, VPN, IPsec, SSL, American Hospice, VPN Haus


About NCP engineering, Inc.


Since its founding in 1986, the NCP engineering delivers innovative software that enables enterprises to rethink their secure remote access and to overcome the complexity of the construction, management and maintenance of the network access for employees.


NCP is an excellent product line includes a range of remote access IPSec/SSL VPN endpoint firewall, and network access control (NAC) functionality. The company's products support enterprise needs comprehensive remote users who want to take advantage of the latest terminal equipment to increase employee productivity, reduce network administration, and to adapt the policy changes on-the-fly. Each solution is interoperable with existing software, or hardware.


Headquartered in San Francisco Bay Area, the company serves over 30,000-plus customers for worldwide in its medical, financial, educational, and government markets, as well as many companies in the Fortune 500. NCP has created a network of national and regional technology, channel and OEM partners to serve their customers. For more information, see www.ncp-e.com.


About network products Guide Awards


As head of research in the areas of technology and advisory publications industry network products Guide plays a vital role in keeping decision makers and end-users informed of the possibility, which may make in all areas of information technology. You'll discover a wealth of information and tools in this guide including the best products and services, plans, industry directions, technology advancements and independent product evaluations that facilitate in making the most pertinent technology impact on business and personal goals. The Guide follows conscientious research methodologies developed and enhanced by specialists in the field. If you want to learn more, visit www.networkproductsguide.com


About Business Wire
Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of content Business Wire is expressly prohibited without the prior written consent of Business Wire. Business Wire is not responsible for any errors or delays in content, or for any actions in reliance thereon. Subscribe to our Rss feeds: Get your SYS-CON News Live! To publish my article! Please send it to editorial (at) sys-con.com!
Advertise on this site! Contact for advertising (at) sys-con.com! 201 802-3021