John Pescatore

A member of the Gartner Blog Network

Archives for March, 2011


Twelve Word Tuesday: Whatever Happened to Oracle and “Unbreakable”?

by John Pescatore  |  March 29, 2011  |  Submit a Comment

MySQL.com hacked by SQL injection is like cash injection compromising an ATM. MySQL website falls victim to SQL injection attack

Submit a Comment »

Category: Uncategorized     Tags:

SSL: Panacea, Plague or Eyewash?

by John Pescatore  |  March 25, 2011  |  Submit a Comment

Back in early 2007, after the CA Browser Forum introduced Extended Validation Certificates, Vic Wheatman, Avivah Litan, Greg Young and I wrote a Gartner Research Note “Extended Validation SSL Certificates: A Big Step Forward, but More Progress Is Needed.” In that note we said: The success of phishing attacks has generated demand to make SSL [...]

Submit a Comment »

Category: Uncategorized     Tags:

Sorry, The Computer Is Down and The Advanced Persistent Threat Stole Your Data – But Your Business Is Important to Us!

by John Pescatore  |  March 22, 2011  |  1 Comment

Don’t berate, or sue me Your identity was stolen by an APT

1 Comment »

Category: Uncategorized     Tags:

Twelve Word Tuesday: Adobe Flash is to 2010 as Microsoft IIS Was to 2001

by John Pescatore  |  March 15, 2011  |  1 Comment

When automobile tires or software are > 50% patches, time to replace. Yet more attacks in the wild exploiting yet more Adobe Flash vulnerabilities.

1 Comment »

Category: Uncategorized     Tags:

Should We Look Gift Cookies In The Mouth?

by John Pescatore  |  March 14, 2011  |  Submit a Comment

In about two months, the European e-Privacy Directive on Web cookies will take effect, essentially requiring explicit consent from European users before any form of tracking is done via cookies. The upside of this is, of course, an increase in privacy for web surfers. Opponents, however, are claiming major negative impacts: Without persistent cookies, your [...]

Submit a Comment »

Category: Uncategorized     Tags:

Consumerization Is To IT Security as Matches Were to Fire Safety

by John Pescatore  |  March 9, 2011  |  3 Comments

I spoke on the executive track at the NSA/DISA Information Assurance Symposium in Nashville yesterday. My talk was on how consumerization and mobility are changing how IT security has to be delivered. I decided to base the talk on this analogy: Back in the early cave people days, there was no fire. Then lightning caused [...]

3 Comments »

Category: Uncategorized     Tags:

Windows Malware and Gambling Industry Have the Same 20 Year CAGR

by John Pescatore  |  March 2, 2011  |  1 Comment

Great piece in Network World on the history of Windows malware.  Many trying to hype up “polymorphic” malware and malware using encryption today, but that was done long ago, too.  Plus, there has been an important constant over those two decades – people acting like people.  He ends the piece like this: But the most [...]

1 Comment »

Category: Uncategorized     Tags:

Twelve Word Tuesday: Will We See Six More Weeks of HIPAA Enforcement?

by John Pescatore  |  March 1, 2011  |  Submit a Comment

After 15 years of HIPAA passivity, HHS emerges levying $5.3M in fines. http://www.networkworld.com/news/2011/022511-hipaa-privacy-actions-seen-as.html?source=nww_rss

Submit a Comment »

Category: Uncategorized     Tags: