The Week That Was – 2013-03-19

We have some good ones this week.

Andrew Hay and Ray Umerley have some interesting points about brining up the next generation of information security professionals.  [2], [9]  As a profession we tend to focus on the technical aspect of the problem and encourage folks to specialize in one particular area of the profession.  We tend not to value the human aspect of our job as much as the technical.  This also leads us to see the information security profession as a function independent of business operations.  There are certainly some exceptions to this statement, but generally speaking, it tends to be true.  These two authors suggest we need to expand our awareness as information security professionals to understand our role in the business, develop the skills and knowledge needed to be a successful business unit, and teach the next generation of security professionals to do the same.  I tend to agree.

Next up we have trojanized Adobe Photoshop plugins.  [18]  This isn’t what you think.  Dove, the skin and hair care company, has a corporate social vision.  Here is what they have to say on their web site:

Dove® is committed to building positive self-esteem and inspiring all women and girls to reach their full potential—but we need your help.

As a part of achieving this mission they distributed Adobe Photoshop plugins purporting to add a healthy glow to photographic subjects.  In fact, this plugin undoes all the photo retouching work and editor does to enhance the appearance of the subject.  Then it informs the editor that he or she is contributing to the distorted view of the ideal female body shape.  Nothing like a little corporate sponsored hacktivism.

And, this one is really interesting.  Genesco, Inc. is suing Visa.  [5], [6]  Genesco feels the  noncompliance penalties Visa levied against it are unfair and scam-like.  I’ve always felt like the PCI compliance routine felt a little suspect myself and figured it would be a matter of time before it wound up in court.  Well, I guess we’ll get to see how this falls out.  I’m glad to see someone challenging the PCI Council on their enforcement practices.

Security pundit Brian Krebs got SWAT-ed.  [17]  I didn’t even know what SWATing was until I read this article.  Nothing like looking down the barrel of a loaded gun to liven up your day.  Fortunately, Mr. Krebs was OK and no one was harmed.

Finally, it looks like hacker angst is an intercultural phenomenon.  [3], [11]  The Chinese hacker your are just as disillusioned as their American counterparts.

That’s all for this week.


