Boaz Gelbord
A practicing CISO’s perspective on managing information security in large enterprises.
Comodo, RSA, and Security Priorities
More details are coming in on the Comodo digital certificate hack by an Iranian hacker. The young man apparently exploited the use of plaintext usernames and passwords in a generally vulnerable certificate ...
Security Scoreboard – Join the Conversation
This week Security Scoreboard made an exciting announcement - the company received angel funding and Dominique Levin has joined as full-time CEO.Now that we have an expanded team and some cash (both ...
iPad and the Illusion of Privacy
It's been a bad week for Apple. First the wifi choked at Steve Job's iPhone 4 demo at WWDC. And now Gawker has reported that AT&T inadvertently leaked the email addresses of ...
Napera selling security at the Google Apps Marketplace
Napera networks announced yesterday the availability of what appears to be the first systems management application in the Google Apps Marketplace.Google Apps Marketplace was launched in March of this year and is ...
Flash Security Under the Microscope
On the heels of Apple's very public tussle with Adobe over Flash support on the iPad, Adobe announced a "critical vulnerability" in Flash on Friday.Vulnerability announcements happen all the time. For better ...
Google Secure Search and Security Overkill
Google announced on Friday the availability of a beta version of its secure search.Secure search? Well, kind of. Google, of course, still retains all your search data. But users will now have ...
Facebook and Security Minimalism
Facebook can't seem to catch a break. Just this Wednesday an XSRF bug was announced that gave access to birthdates users had designated as private.Not that Facebook users care. I would bet ...
Application Security Underfunded
Imperva and WhiteHat just came out with a report on security spending and resource allocation (registration required). This report is a must-read for anyone who is in charge of security budgets.The basic ...
Security Scoreboard is Live!
I am very excited to announce the launch this week of Security Scoreboard - an online resource for researching and reviewing information security vendors. Security Scoreboard features over 600 vendors and aims ...
Mass Security Regulation Gets Tech Priorities Wrong
The final version of a sweeping new data security regulation in Massachusetts was published last week. Some parts look pretty good. But some parts look like they are straight out of 1999.Let's ...