State Department scores an F on 2FA security

Senators have discovered that the State Department is breaking the law by not using multi-factor authentication in its emails. Continue reading State Department scores an F on 2FA security

A Zero Trust Manifesto

A Google search for “zero trust” returns ~ 195Million results.  Pretty sure some are not necessarily related to access management and cyber security, but a few probably are.  Zero Trust was a term coined by analyst group Forrester… Continue reading A Zero Trust Manifesto

Listening Watch sounds out security idea with websites that listen

Listening Watch, a project based on earlier work by researchers Prakash Shrestha and Nitesh Saxena, uses the power of sound to log you into your favourite websites. Continue reading Listening Watch sounds out security idea with websites that listen

NSA hasn’t closed security windows Snowden climbed through

One of three problems found in an audit: two-person access controls haven’t been properly implemented at data centers and equipment rooms. Continue reading NSA hasn’t closed security windows Snowden climbed through

Google hasn’t suffered an employee phishing compromise in over a year

Phishing attackers have failed to compromise a single employee account at Google since the company mandated authentication using U2F hardware tokens in early 2017. That’s the remarkable claim made to security writer Brian Krebs. Continue reading Google hasn’t suffered an employee phishing compromise in over a year