The Ad-Tech Industry Must Finally Admit That Their Product (Ads) is Dangerous

How would you react if I told you that computer security experts are six times more likely to run just an ad blocking software on their PCs, over just anti-malware? Would you be surprised? That was the result from a Twitter poll I conducted last year, in which more than 1,000 self-identified computer security experts shared that they are more concerned about ads than malware. While social media polls are admittedly unscientific, I’d argue these numbers are actually pretty close to reality, which means that roughly three-out-of-four computer security experts largely view ad-blocking as a more indispensable part of protection than anti-virus software by far. Let that sink in for a moment.Malvertising, or malicious ads, are hurting people – a lot of people. Anyone who is familiar with the malware problem will tell you that. As just one example of many, last year ads appeared on the New York Times, BBC, AOL, NFL and other popular websites in a malicious campaign attempting to install “ransomware” on visitors’ computers. To put things into context, the chances are better that the average internet user...
Read more

InfoSec warranties and guarantees

This is a living list of InfoSec companies who offer warranties and guarantees on their various products and services. If you know of others that should be on the list, please comment. CymmetriaKnowBe4AsTech Consulting (press release), Vigilance / Qualys (terms)WaratekSentinelOneTrusonaWhiteHat SecuritySymantec & Norton (money-back)McAfee (money-back)Trustwave HIPAA Secure NewForcepointAviraProofpointDigiCert ComodoArmorVerizon (100% uptime SLA), including DDoS Hack Yourself First: Jeremiah Grossman
Read more

InfoSec Start-up Advising and Product Recommendations

As a long-time InfoSec veteran and entrepreneur, I’m often asked by company founders to join their advisory board and lend a hand. Sometimes the founders need someone with experience they can trust to bounce ideas off of, provide guidance on how to scale their business, point out the many pitfalls to avoid, make key introductions, and so on. I’ve been in this advisor role for many years, as well as mentoring more than fifty young businesses over the last five years alone through a startup incubator. Making this contribution has been highly rewarding, both personally and professionally. It leverages the many successes and mistakes I’ve made in my career to help others. Advising and mentoring is something I plan to continue doing for the foreseeable future. The only downside is that due to time constraints, I have to be extremely selective. When I come across a hot new start-up, I fully research the company, try out the product, research their target market, meet the management team, speak with a handful of customers, and if I have something useful to offer, only then do I feel comfortable enough to get involved. Oh, another requirement is that none should be competitive with...
Read more

What keeps me in the security industry

It’s common for long-time information experts like myself to be asked what keeps us in the security industry. Some say it’s a good stable job that nicely pays the bills. Others find the work interesting and enjoy the constant intellectual challenge. Some the like the people, the community, the culture, and exchange of ideas. Of course for many, it be some combination of all these things. For myself, while each of the above plays a part, I must admit those haven’t been my core reasons to stay on for a long time now.Like I’ve said many times in the past, the Internet is single greatest invention we’re likely to witness in our lifetime. The Internet is a place that now connects over 2 billion people. The Internet is how we communicate and keep up with friends and family. It’s where we shop. It’s how we learn about ourselves and the world. It’s where bank and pay bills. It’s what entertains us and how we get from place to place. It’s how we better ourselves. Entire economies are now dependent on the Internet. If you think about it, we’re often more open and honest about our most intimate secrets with...
Read more

I’m joining the fight against malware and ransomware with SentinelOne

Today is a big day for me. I’m contributing to a company called SentinelOne, but I really don’t think of it as a job. I’ve accepted an opportunity to work side by side with other brilliant and highly motivated people where we’re all helping to solve important and challenging InfoSec problems. In this case, malware and ransomware. You see, more than anything, I want to make a positive impact on InfoSec. As I’ve said many times, we who work InfoSec are responsible for protecting the greatest invention we’ll see if our lifetime — the Web, the Internet, and the billions of people using it every day. That’s our mission, our calling. As such, I’ve always kept a evolving list of our industries biggest challenges, which I include in most of my slide decks.Intersection of security guarantees and cyber-insuranceExplosion of RansomwareVulnerability remediationIndustry skill shortageMeasuring the impact of SDLC security controlsThe only problem on the list I haven’t gotten the chance to work on is ransomware, an incredibly effective and fast-growing form of malware that’s taking over. I’ve long railed hard about the crap antivirus products on the market and the...
Read more

Life is Better without Username Reuse (email aliases FTW!)

Facebook, LinkedIn, Amazon, PayPal, Yahoo, Google. We keep accounts with many of these websites. They and many others use email addresses as the first half of the classic username and password combo. They do this because email addresses are unique and double as a reasonably secure communication channel with the user. And of course we often sign-up for things online to receive information by entering our email address. All this email address sharing, while technically nothing being wrong with it, unfortunately causes several highly annoying problems. These problems can be solved, or at least made far easier to deal with, by leveraging email address aliases. An email alias is where you create one or more email addresses that all send to the same account, vaguely similar to desktop folder shortcuts.With email address sharing / username reuse, by far the biggest problem we run into is spam. And the more we share and reuse our email addresses across systems, the bigger the spam problem becomes. Sometimes websites sell our email addresses. Other times they share them with third-partie business partners, and from time to time they get leaked in a data breach. Whatever the case, once an email address is...
Read more

Millions experience serious computer security problems and have no one to call for help

A couple times a week, people I may or may not know reach out to me for help because they’re experiencing some kind of computer security catastrophe. Sometimes the situation is serious, other times not. They might be dealing with an online bank account takeover, online scam, data breach, malware infection, identity theft, and the list goes on and on from there. Whatever the circumstance, a great many people often find themselves thrust into the deep end of this technology driven world, without the know-how to solve the problem on their own, and no one to call for help. These experiences are especially painful for the elderly and small-business owners, whose livelihood are disrupted, and the stress takes a toll on them. Personally, I hate it when good people get taken advantage of.In the most recent case, I was introduced to the founder of a TV and movie production company through a mutual friend. They explained that someone is messing with their website and actively using their company name to scam their business contacts. They said ‘hacked,’ but that could mean anything these days. The situation was causing them real brand damage, and with over a dozen show titles...
Read more

7 Tips to Get the Absolute Best Price from Security Vendors

Security budgets are always extremely tight, so it’s smart to get the absolute best price possible from your security vendors. Never ever pay full price, or even take the first quote vendors give you. That price just sets the stage and it’s best to think of it as the ‘dummy price,’ so don’t pay it! I’ve spent nearly two decades sitting at the price negotiation table in the security industry and seen all manner of techniques customers use successfully to win discounts, and more people should use them. Customers, even small ones, can exercise a ton of leverage over their security vendors if they only knew how. And, more often than not, vendors themselves don’t really mind. It signals that a deal is likely to be made and to a vendor, that’s what’s most important.While it’s common for large companies to have negotiations handled by a separate department, typically called ‘Procurement,’ many leave the responsibility to whomever is actually making the purchase. In either case, security practitioners can personally say, do, and offer things the procurement department can’t to help obtain the best possible price. Remember, security product margins can range anywhere from 40-60% or even higher. I’ve seen...
Read more

From 300 lbs to 200 lbs

Did you know that one point in my life I was just over 300 pounds? Most don’t, but I was. Then after considerable effort, I got to the 250 pounds range and remained for several years. At the time of this writing, I’m about 210 pounds. My goal is to stabilize at around 200 pounds with a body fat of ~10%. If all goes as planned, maybe in 6 months or so I’ll be about where I want to be. At 6’2”, it’s a pretty solid physique. Upon witnessing my physical transformation, many friends and family ask how I’m doing this. “What’s your secret?” Spoiler: I don’t have one. Before going any further, let me clearly state that I’m NOT a personal trainer. I’m NOT a nutritionist. And I’m certainly NOT trying to sell anything. This post simply answers the question people ask by listing out my nutrition and exercise regiment. Additionally, while everything I’ve done has undoubtedly improved my overall health, the goal is primarily focused towards improving my performance in combat sports, such as particularly Brazilian Jiu-Jitsu and Mixed Martial Arts. Competing...
Read more

My last days at WhiteHat and setting sights on the future

I’ve said it many times; the Web is probably the greatest invention we’ll see in our lifetime. The Web touches the lives of everyone we know, every family member, every child, every friend, and everyone we meet. The Web connects over two billion people and fuels entire economies. It’s a place where we learn, communicate, and share our closest kept secrets. Something as important as the Web must be protected and I’ve always felt it was a privilege to do so. For the last 15 years, as founder of WhiteHat Security, I’ve done exactly that every single day. WhiteHat has not just changed my life, it has been my life — wholly inseparable. Bittersweet as it is, the end of March will be my last day. Right now, I’d like to take a moment to reflect. While it’s impossible to measure, I sometimes think about how many hacks didn’t happen — how many people and companies were not hacked — as a result of the work we did at WhiteHat. People have often shared how much we’ve helped them and how important our work is. It’s an amazing feeling knowing that what you do matters. Everyone should be so fortunate....
Read more