SolarWinds hack: what just happened?

Solarigate, Sunbusrt, UNC2452 or whatever they call it, how even fireEye, SolarWinds, Crowdstrike and many other involved are able to sell and survive after this disaster, and how security community is able to trust them again? it is interesting that how these top security companies with lots of managed service and bunch of products in… Continue reading SolarWinds hack: what just happened?

human firewall

no doubt that users are the main problem in the whole concept of cyber defense, as we call it weakest link. Now, Awareness and Training as security community typically has been doing is neither effective nor actually deliverable. Imagine we would want to continue law enforcement and public awareness by means of “Most Wanted” posted… Continue reading human firewall

say The Word and you will be Secure:”wishes don’t wash dishes”

“Talk doesn’t cook rice.” Ancient Chinese Proverb There is a saying in Persian…you won’t taste sweetness in your mouth just by say Sweet, Sweet, Sweet…but it looks like industry believe we can be Secure just by saying Secure, Security, Sec… just by putting a Sec in front or end of a product, service, name, process,… Continue reading say The Word and you will be Secure:”wishes don’t wash dishes”

is Security inconvenient?

we presume Security is always equal inconvenient, either form consumer point of view, or developer. as a consumer you have to remember passwords and configure stuff, and as a developer to need to make sure you put controls around authentication process and how passwords are being used. I agree that is inconvenient but are we… Continue reading is Security inconvenient?

Attacks are not advanced, we are naive!

cyber attacks that you hear about them in news these days are not advanced at all, this is security community acting so naive and blind, knowingly and unknowingly which then implies into thinking that attacks are sophisticated. in mature industries like agriculture, professionals study their enemies and for centuries they have been able to defeat… Continue reading Attacks are not advanced, we are naive!

Software is the root cause of all insecurities

Software is the core of any computerized system and it is the most effective way of introducing insecurities to cyberspace with all its entities. eliminate fancy tools like synthesizer if you want your child be a musician. root cause of all security vulnerabilities (mainly) resides with the software, the foundation of all computer systems, where… Continue reading Software is the root cause of all insecurities

Security and Quality

Security is a matter of usability and one of elements of quality of a system. ain’t it literally a matter of “safety”? how come Quality does care about a defect related to safety of a user in physical world but not the virtual world? security bug is named differently: security vulnerability, but ain’t just a… Continue reading Security and Quality

Cyber Security: The Essential Role of Internet Service Provider

It has been logically proven to me that some elements of cyber security of any internet user is solely on shoulder of ISP but that has been the last thing we ever cared perhaps because we tend to complicate simple things! ISP is supposed to be the only owner, or main layer to internet user… Continue reading Cyber Security: The Essential Role of Internet Service Provider

Regulating Dark Web!

I came across an article the other day on Legal Considerations when Gathering Online Cyber Threat Intelligence and Purchasing Data from Illicit Sources!  A publication from justice.gov with interesting insight but opened an old wound for me! Trying to regulate an environment which is naturally unregulated sounds not reasonable. it is like saying you can… Continue reading Regulating Dark Web!

Fix Cybersecurity Issues vs Making Money Out of Them!

Have we really been fixing cyber-security issues and challenges, or we just want to make money out of “lack of awareness”? The simplest analogy I can think of is cigarette and generally tabaco industry. If we really believed that those are against society and individual health, how much is cost of cancer and other complications… Continue reading Fix Cybersecurity Issues vs Making Money Out of Them!