Credit Card breach at Mandarin Oriental

[caption id="" align=“alignnone” width=“2500”] Image by Sean MacEntee used under Creative Commons License [/caption] We have seen claims that the luxury hotel chain has suffered a credit card breach (some outlets are now confirming it). The last confirmation I received was that the chain is working with its banking partners to investigate the claims. We don't know yet if the breach impact some or all of its global properties. Unnamed sources say the breach goes back to just before christmas 2014.

Continue reading →


The internet's bad security is YOUR fault

[caption id="" align=“alignnone” width=“2500”] Image by Nick Carter used under Creative Commons License [/caption] As a security expert, my biggest security risk (in the corporate world) is people. I can buy the best technology and write the most efficient processes but if people get sloppy, everything falls apart. Security and convenience (simplicity) are on opposing ends of the spectrum. Ultimate security means no convenience and ultimate convenience means no security. Did I mentioned that only through good security can you get good privacy?

Continue reading →


Attacked by the Internet of Things

[caption id="" align=“alignnone” width=“2500”] Image by JD Hancock used under Creative Commons License [/caption] In the last 30 days, I participated to 2 CIO conferences (Montreal and San Francisco) and interestingly heard similar questions from executives about the security risks and dangers of Internet of things devices. Are they really that dangerous? When I talk about Software as a Service, most readers think of the Google computer cloud, Amazon Web Services or Microsoft's Azure cloud platform. What never gets mentioned is the new breed of Attack as a Service providers.

Continue reading →


China bans Apple, McAfee, Cisco, Citrix and more for state purchase

[caption id="" align=“alignnone” width=“2500”] Image by Gidzy used under Creative Commons License [/caption] Reuters is reporting (link) that the Chinese government has removed several prominent US tech companies from its authorized vendor list meaning government (state) departments or entities are no longer authorized to purchase them. This change isn't surprising considering all of the Snowden leaks about NSA spying. Reuters does mention that some of its unnamed sources said this change is being done to encourage organizations to buy locally rather than for security concerns.

Continue reading →


2015 will be the year of targeted stealthy malware

[caption id="" align=“alignnone” width=“2500”] Image by spencer used under Creative Commons License [/caption] 2014 was the year of the hack. The year of the spectacular hack. You know this because these major incidents were reported in your run of the mill 6PM news show (not just the tech press). As we start a fresh new year, what can we expect? This isn't your father's malware Virus' and malware started out (in the early days of computing) as a way to show hacking was possible but didn't harm anything.

Continue reading →


How to browse LinkedIn profiles anonymously

[caption id="" align=“alignnone” width=“2500”] Image by Pierre (Rennes) used under Creative Commons License [/caption] LinkedIn is a critical business tool for many professionals. It can be incredibly useful for research, communication, strategy building and corporate intelligence. Social Network privacy is a difficult concept for most users to understand. Social Networks are built on their ability to track you and then use that information to generate money. Facebook does this by leveraging your network to generate custom sticky newsfeeds. LinkedIn uses this information to entice users to "

Continue reading →


Did iCloud just get hacked?

[caption id="" align=“alignnone” width=“2500”] Image by Johan Viirok used under Creative Commons License [/caption] Ordinarily, a bad actor would have to steal some of your information before breaking into your 2-factor protected iCloud account. They would need your AppleID, your password and a 2-factor authentication code (or a digital token stolen from an authenticated device like a laptop or desktop). Now everyone's favorite russian purveyor of fine cracking software, Elcomsoft (link), has a tool called Phone Breaker. This new software requires the aforementioned information but then creates a permanent authentication token which means they won't have to re-authenticate until you change your password.

Continue reading →


Canada's Anti Spam Law (CASL) and what it means and CASL 2.0

Over the last month, I received several emails asking me about CASL (the Canadian Anti Spam Law) which went into effect July 1 2014. The purpose of CASL is to protect consumers from unsolicited email messages. “Nothing in this article should be construed as legal advice. Always check with a qualified legal professional.” What is CASL There are well written white papers by lawyers that provide the legal perspective on CASL and how it impacts business'. If that applies to you, you should go find and read some of those.

Continue reading →


Is someone stealing your credit card data?

[caption id="" align=“alignnone” width=“2500”] Image by Saiko Weiss used under Creative Commons License [/caption] As you spend on CyberMonday and beyond, what happens when a retailer swipes your credit card? Brian Krebs, a trusted security researcher, provides his colorful insight about the subject. The 2 line summary is that there are multiple failures in the chain that could lead to your financial data being compromised 

Continue reading →


Whatsapp to become more secure than Apple Messages

[caption id="" align=“alignnone” width=“628”] Image by downloadsource.fr used under Creative Commons License [/caption] I'm an advocate of personal privacy through encryption. I love the Threema instant messenger (Link) but none of my contacts used it. This is the problem with secure instant messenger apps, your friends aren't there so it becomes useless. Now Whatsapp is including the encryption functionality of TextSecure from Open Whisper Systems in their Android client and this will make Whatsapp the most secure instant messenger (beating even Apple's a Messages/iMessage).

Continue reading →