Syndicated Blog

Boaz Gelbord
A practicing CISO’s perspective on managing information security in large enterprises.

Comodo, RSA, and Security Priorities

More details are coming in on the Comodo digital certificate hack by an Iranian hacker. The young man apparently exploited the use of plaintext usernames and passwords in a generally vulnerable certificate ...

Security Scoreboard – Join the Conversation

| | Security Scoreboard
This week Security Scoreboard made an exciting announcement - the company received angel funding and Dominique Levin has joined as full-time CEO.Now that we have an expanded team and some cash (both ...

iPad and the Illusion of Privacy

It's been a bad week for Apple. First the wifi choked at Steve Job's iPhone 4 demo at WWDC. And now Gawker has reported that AT&T inadvertently leaked the email addresses of ...

Napera selling security at the Google Apps Marketplace

Napera networks announced yesterday the availability of what appears to be the first systems management application in the Google Apps Marketplace.Google Apps Marketplace was launched in March of this year and is ...

Flash Security Under the Microscope

| | adobe, flash, Vulnerabilities
On the heels of Apple's very public tussle with Adobe over Flash support on the iPad, Adobe announced a "critical vulnerability" in Flash on Friday.Vulnerability announcements happen all the time. For better ...

Google Secure Search and Security Overkill

| | google, Network Security
Google announced on Friday the availability of a beta version of its secure search.Secure search? Well, kind of. Google, of course, still retains all your search data. But users will now have ...

Facebook and Security Minimalism

Facebook can't seem to catch a break. Just this Wednesday an XSRF bug was announced that gave access to birthdates users had designated as private.Not that Facebook users care. I would bet ...

Application Security Underfunded

Imperva and WhiteHat just came out with a report on security spending and resource allocation (registration required). This report is a must-read for anyone who is in charge of security budgets.The basic ...

Security Scoreboard is Live!

I am very excited to announce the launch this week of Security Scoreboard - an online resource for researching and reviewing information security vendors. Security Scoreboard features over 600 vendors and aims ...

Mass Security Regulation Gets Tech Priorities Wrong

| | Massachusetts, regulation
The final version of a sweeping new data security regulation in Massachusetts was published last week. Some parts look pretty good. But some parts look like they are straight out of 1999.Let's ...