Sign in or Join FriendFeed
FriendFeed is the easiest way to share online. Learn more »
As Moran put it, “recruiting long-haired geeks is not easy for law enforcement.” http://www.fastcompany.com/1814963...
Naming and shaming doesn't catch criminals http://www.zdnet.com.au/naming-...
Facebook criticised for 'hurting' cybercrime investigation http://www.telegraph.co.uk/technol...
"Being compliant is totally different from being secure. " David Jacoby at #sas2012
PPI prices vary depending on the risk level of the malware involved. FakeAV is among the riskiest (aka more profitable) / #sas2012
PPI (Pay Per Install) affiliate networks pay up to $400 per 1000 installs. #sas2012
RT @assolini: +1 RT @_timarmstrong: Me too! "@trompi: finally I learned how to pronounce Team Cymru! #sas2012"
The application layer is usually the most vulnerable to attack. Resource exhaustion is the goal. @levigundert at #sas2012
500K open DNS resolvers are available on the internet at any given time, can be and are used in DoS attacks / @levigundert at #sas2012
DoSaaS = Denial of Service as a Service / @levigundert at #sas2012 :)
Fabio @Assolini is presenting malware designed to intercept credit cards at POS level / #sas2012
APT - a once useful term, it is now limited in value due to too many competing definitions. Microsoft avoids using it. #sas2012
Posion Ivy - most popular tool with targeted attackers - was coded by an 18 year old Swedish kid / @k_sec at #sas2012
APT emails are almost written like native speakers are behind them. THis was not the case a few years ago. / @k_sec at #sas2012
In most of the APT cases it's not about a 0day, but about a publicly available RAT / @k_sec at #sas2012
Even people who are interested in security don't always upgrade / @k_sec at #sas2012
"2011 has been incredible busy for APT (...) and attribution is a problem" / @k_sec at #sas2012
RT @spgedwards: Want to crack a TrueCrypt volume? If if doesn't fall in week #1 it's won. <- Greg Hoglund, on accessing botnet C&C servers. #sas2012
HBGary's Greg Hoglund talks about detecting APT by detecting lateral movement / #sas2012
#Facebook makes almost $5/year/user in ad revenue. Would you pay $5/year to use #FB without ads and with enforced privacy settings? #sas2012
Enjoying @csoghoian's narrative path on evil defaults: from serving pizza in schools, to IE toolbars, to privacy and security / #sas2012
RT @craiu: Judging by the first day, #sas2012 is easily the best security conference I've attended in the past 3-4 years.
RT @threatpost: #Tpost: Cyber Cops Wrestle With Legal Hurdles Public Perception - #SAS2012 - http://threatpost.com/en_us...
Faith in webmasters' security rewarded-kinda http://itknowledgeexchange.tec... - good summary of my talk at #SAS2012 by @Mike_Mimoso
RT @spgedwards: Want to learn exploit-writing? Start with a PLC. "Does not require ninja coders." #sas2012
"We noticed guards in prison central control rooms checking their personal Gmail accounts" / @TiffanyRad at #sas2012
"The belief that PLCs are not vulnerable because they're not connected to the internet is not true" / @TiffanyRad at #sas2012
"At the time PLC were developed 40 years ago, cyber threats were not taken into consideration" #sas2012
"Security through obscurity not longer works with SCADA" / @TiffanyRad at #sas2012
"The state of the industrial control system security is laughable" - @0psys at #sas2012
Other ways to read this feed:Feed readerFacebook