-
Recent Posts
Recent Comments
Archives
- August 2025
- January 2025
- December 2024
- November 2023
- August 2023
- September 2022
- June 2022
- April 2022
- January 2022
- October 2021
- September 2021
- August 2021
- July 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- June 2018
- May 2018
- January 2016
- October 2015
- February 2013
- January 2013
- April 2011
- October 2010
- September 2010
- August 2010
- February 2010
- January 2010
- October 2009
- September 2009
- April 2009
- March 2009
- November 2008
- September 2008
- August 2008
- June 2008
- April 2008
- March 2008
- February 2008
- January 2008
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
Categories
Meta
Author Archives: dutcherstiles
Everyday Privacy & Security Part 2: Fear Factor Authentication, or I Won’t Forget You Baby, Even Though I Should
If you are like me, or, if in fact, you are me, your online financial transacting experience has gone all Security 2.0 by the factor of WOW! Over the weekend, I had an unpleasant experience. The clerk at our local … Continue reading
SSNS ON THE LOOSE! (Legacy Edition)
I’m trying to understand the newsworthiness of the latest episode of “SSNS On The L0OzE. OMG!!1!!” Some dude in the mail room puts a bunch of computer tapes in the wrong slot, according to the AP report in the Houston … Continue reading
Posted in Uncategorized
Tagged breach notification, disclosure laws, internal auditing, physical security, sb1386, security
Leave a comment
Throwing Scorpion Out With the Frog Water
Declan McCullagh says that the federal government is unlikely to implement the National Research Council’s privacy recommendations, in particular, a privacy commissioner, because it isn’t in the federal government’s scorpion-like nature. Ars Technica also has coverage. (And why must it … Continue reading
Waffle are Just Pancakes with Little Squares On ‘Em
I’ve been working on something, but I don’t know if it will make by race time in Shanghai. In the meantime, the most important part of internal auditing is “production value.” And we know what that means.
Posted in Uncategorized
Tagged internal auditing, risk assessment, tapeheads, waffles
Leave a comment
Impacted Molars
Brighter Teeth From Educational Security Incidents via Pogo comes this terrifying story of privacy laden scratch paper from the land of the gigantic stone Texan. Apparently Sam Houston State U. uses a student ID number that is not their SSN. … Continue reading
Posted in Uncategorized
Leave a comment
Go Ask Alec Baldwin
SSL apostate Ian G. refers to an article on estimation of loss due to a privacy breach.I think we are measuring the wrong thing, and operating on these assumptions is dangerous. From the article, a Forrester analyst says: “After calculating … Continue reading
Posted in Uncategorized
Tagged disclosure laws, identity theft, privacy, sb1386, security
Leave a comment
The Red, Yellow and Green Legos of Judgment
I’m out here in Coyote and Roadrunner land, knee deep in internal auditing. I co-presented yesterday on privacy, as a co-author of an Institute of Internal Auditing publication.It’s been a interesting couple of days, driven in part by the isolation … Continue reading
Apocalypse Pooh
It’s a grim world around us. A mass murder turns into a cynical ploy to promote and condemn any issue you care to name, or exploit the grief for naked profit. How can I deal, in the short term, except … Continue reading
Sweet Fancy Moses
Lots of odd stuff (mostly from Pogo & Fergie): Why Justice Went Blind The courthouse security folks in El Paso County can see you nekkid.“The new machine will not replace the metal detectors already in use at the judicial complex. … Continue reading
Posted in Uncategorized
Leave a comment
In defense of controls
Alex is pretty down on ISO 17799. I think the reasons are that he sees organizations substituting ISO 17799 for risk management FAIR style. Instead of calculating a realistic, customized risk profile, an organization pulls ISO 17799 (or COBIT, though … Continue reading
Posted in Uncategorized
3 Comments