Archive

Archive for April, 2007

Skypekiller sounds ridiculous

April 30th, 2007 4 comments


There have been a lot of discussions and even debate on whether or not enterprises should permit Skype. The focus point here is its security issues. I list out ten security concerns to Skype before. However, it’s indeed of value. It can help lower the voice communication cost and very convenient. There are more and more value-added service on it. Anyway, nobody can oversee the existence of hundreds of millions subscribers of Skype. It means business opportunity to many startups and technical geeks. They are proud of their hacking and breaking-into of Skype. Read more…

Categories: P2P, Security, Telecom Tags: , , ,

Use Skype as a home security system ?

April 29th, 2007 1 comment

Solomon’s blog shared an very interesting idea: to use Skype as a home security system. When you work at office or go out for travel, you can connect back to watch what’s happening at your home. So cool !

1. Open two new accounts.
* 2. On account 1 add new user two as your ONLY contact
* 3. Re-log in as account 1 and set as follows:
Go to tools–>options–>advanced–>(tick) automatically answer Incoming calls–>
Then go to Tools–>options–>Video–>(tick) start video automatically and Only People in My contacts–>save.
Leave this account online
* 4)Log in as account 2 from another PC.

But I am wondering if there is not some security here, the world will share your home view with you, as long as they find that account. So please do remember to configure youself as the only person can talk with this account.

Categories: -English-, P2P, Security Tags: , ,

Details in security operations – Beijing CCClub Conference

April 29th, 2007 No comments


April 18 2007, CCClub, an organization of China security professionals, like CISSP,CISA and etc. had a conference in Beijing. This organization is chartered to build a friendly, fair community for discussion and knowledge sharing. Check out the agenda of this conference. Dr.Wang Jie introduced the latest events and trends of information security in USA. He shared some impressive “Botnet yer pay” and related industry chain: vulnerability discovery – exploit development – botnet operation – spaming or attack service. Dr.Wang is trying to introduce more Made in China security products into USA market.

In my session, I shared my experience that security managers should pay more attention to details of operation execution and policy implemention. No doubt, it’s always a virtue of security managers to “think high”. In one old post, I summarized 5 key memory points for a security manager: plan, communicate, leverage consultancy, resolve Top 3 questions always, develop toolkits. That’s written when I was the principal consultant of CA. However, after newly 8 month experience of security operations, I think we must pay much attention to details of execution. Even you have a very good vision and plan, you will encounter a lot of trouble during the execution if you don’t prepare details well. Read more…

Categories: -English-, Security Tags: ,