Tuesday, January 22, 2013

(Belated) InfoSec Predictions for 2013

Now that we are more than halfway through January I feel obligated to make my predictions for what will happen in 2013. Are you ready to have your mind blown?

MORE OF THE SAME!

I know, it is not a pearl of wisdom but with 2013 already bringing us a vulnerability in IE 6, 7 & 8 plus... [wait for it] yet another scary bad Java vuln, the year is off to a helluva start.

And let us not leave out our favorite whipping boy(s)/girl(s) at Adobe - Reader and Flash remain among the best ways to pop a box with our pals at Oracle and their Java write once debug everywhere platform.

So there you have it from the security equivalent of the armchair quarterback.
As they used to say on Hill Street Blues, let's be careful out there.

Peace,
Doug

Sunday, January 20, 2013

Welcome to 2013!

Wow, my blog is so very neglected. With Twitter fitting my attention span better, it isn't likely to see many new posts this year either. And I think I am OK with that.

Happy belated new year to all who stumble on this lonely blog. I pray 2013 will be a better year for you and yours. My new year's resolution is to be grateful and appreciate at least one person and/or thing every day. There's a lot of good to be happy about in this life if we open our eyes and make an effort to be aware of it.

Sincerely,
Doug

DefCon 20 (My 1st pilgrimmage)

The summer of 2012 was an eventful one for me - several camping trips with my better half the kids and of course the dog. Two new babies in the family tree - congrats to my brother and sister! Add to all of that my 1st visit to the mother of all InfoSec cons - DefCon XX.

I was very excited when the planets aligned and I received work and home management approval to attend. I've been wanting to go for as long as I can remember, so this was a bucket list-worthy item in my book.

DefCon did not disappoint. Met many new people from across the US and around the world: Brazil, Germany, Romania, and more. I even made a new friend from Canada of all places (hi Carlo!) from working on the scavenger hunt with some friends from Grand Rapids.

I went to a handful of talks each day and wandered around taking in all the other happenings - the contests, gaming areas, the DefCon private cellular network van... The standout talks for me were General Keith Alexander, Mark Weatherford from DHS, Wesley McGrew, and Cutaway - the ones related to critical infrastructure protection, vulnerability research on SCADA HMIs & how breakable many current 'smart' meters are.

I hope to return next year if possible and perhaps take in both Black Hat + DefCon.