Some days ago my old friend Pete Herzog from ISECOM
posted a blog entry titled “Hackers May Be Giants with Sharp Teeth”
here
which – along with some quite insightful reflections on the way kids perceive
“bad people” – contains his usual rant on (the uselessness of) risk
assessment.
Given that this debate (whether taking a risk-based infosec approach is a wise
thing or not) is a constant element of our – Pete’s and mine – long lasting
relationship I somehow feel enticed to respond 😉
Building
News from Old Friends, Edition 2010/06/09
This is the first post of a – potential – series of rants on ubiquitous pieces
of crap (security-wise), bothering pretty much every ISO I know.
I’m talking about “common desktop applications” and today’s topic is going to be
the beloved Adobe Flash Player. Some of you who had the opportunity (or
imposition 😉 to listen to one my talks covering “modern enterprise security
space” (e.g.
this one)
might remember me saying sth like “If a fairy godmother turned up and asked me
for three things to get rid of in order to enhance overall corporate information
security in a sustainable way, my answers would be…” and then giving Adobe Flash
as the first mention. (before you ask: amongst the other candidates are Apple
Quicktime, Windows GDI and “Javascript in Acrobat Reader”).