After 28 years, SSLv2 is still not gone from the internet… but we’re getting there, (Thu, Jun 1st)

Although the SSL/TLS suite of protocols has been instrumental in making secure communication over computer networks into the (relatively) straightforward affair it is today, the beginnings of these protocols were far from ideal.

Continue reading After 28 years, SSLv2 is still not gone from the internet… but we’re getting there, (Thu, Jun 1st)→

Posted in Uncategorized

Your Business Data and Machine Learning at Risk: Attacks Against Apache NiFi, (Tue, May 30th)

Apache NiFi describes itself as &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x9c;an easy-to-use, powerful, and reliable system to process and distribute data.&#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x9d; &#;x26;#;x5b;1&#;x26;#;x5d; In simple terms, NiFi implements a web-based interface to define how data is moved from a source to a destination. Users may define various &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x9c;processors&#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x9d; to manipulate data along the way. This is often needed when processing business data or preparing data for machine learning. A dataset used for machine learning may arrive in one format (let&#;x26;#;39;s say JSON), but to conveniently use it for training, it must be converted to JSON or inserted into a database. The features are not just attractive to machine learning, but many business processes require similar functionality.

Continue reading Your Business Data and Machine Learning at Risk: Attacks Against Apache NiFi, (Tue, May 30th)→

Posted in Uncategorized

We Can no Longer Ignore the Cost of Cybersecurity, (Sun, May 28th)

I read recently that disregarding cyber risks is a way of inviting trouble and unnecessary attention to any organization. Cyber threats is nothing new, everyone is a target taking many forms whether it is by some form of scanning or targeted phishing. For example, Sophos describes the naughty nine which are all some form of services that can be purchased for a price (i.e. access, malware, phishing, crypting, etc). “Just as information technology companies have shifted to &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x9c;as-a-service&#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x9d; offerings, so has the cybercrime ecosystem.” &#;x26;#;x5b;1&#;x26;#;x5d; This is no surprise that ransomware is still the one thing that affect the most organizations and, in the end, cost the most if you have no choices but to pay the ransom. In the case of the Hospital for Sick Children in Toronto, lockbit , “&#;x26;#;x5b;…&#;x26;#;x5d; issued a brief apology and offered SickKids a free decryptor to unlock its data.” &#;x26;#;x5b;2&#;x26;#;x5d; but this is far from always being the case. In the end, they did not use the decryptor but that isn&#;x26;#;39;t always the case.

Continue reading We Can no Longer Ignore the Cost of Cybersecurity, (Sun, May 28th)→

Posted in Uncategorized