Security Excuse Bing

A couple of people pointed me to this yesterday, and I thought it was a brilliant idea:

http://www.crypto.com/bingo/pr

Sort of like the old "manager speak bingo". Very appropriate.

Published 11 August 2007 09:06 AM by jesper

Comments

# Chris Quirke said on 12 August, 2007 02:14 AM

"But it was from someone I know!"

"We can't have a virus, we use NORTON"

"I don't know what it was, we always just wipe and rebuild"

# Alun Jones said on 14 August, 2007 11:12 AM

I've heard that last - "I don't know what it was, we always just wipe and rebuild" - a number of times, and sometimes the perpetrator of the remark points to Jesper's article on "Help: I Got Hacked. Now What Do I Do?" as justification.

The answer, of course, is that this article tells you how to clean the system (by flattening and repaving) - but if you do this, and you clean the system back to the state it was in before it got infected, all you've done is restored the system back to the state that allowed it to get infected.

You'll get infected again, for sure, that way (with the updated version of the same attack - and maybe the updated version is harder to detect).

That's why you can't get away with reading and parroting security articles, no matter how good they might be. You actually have to think about their implications, or your reading is useless.

Leave a Comment

(required) 
(required) 
(optional)
(required)