The security password is 'constant vigilance'

July 14, 2011|By Jeff Gelles, Inquirer Columnist
Image 1 of 2
  • Charles Henderson, director of application security services for SpiderLabs, awaits the day when passwords are a thing of the past. Until then, his advice: Avoid reusing the same password.
  • Charles Henderson, director of application security services for SpiderLabs, awaits the day when passwords are a thing of the past. Until then, his advice: Avoid reusing the same password.
  • Hameed Mohammed likens today's breaches to the relatively high level of air and auto accidents that occurred in the 1950s. (RICH HAND )

Charles Henderson has seen the dark side of the Internet - he works there, you might say, as director of application security services for SpiderLabs, the "advanced security team" at Trustwave, a leading data-security firm.

But ask Henderson about the latest risks facing companies and consumers, and he soon starts talking about a seemingly lighter subject: a pregnant woman who works at a Fortune 500 company.

Henderson will only call her "Sarah." He can't use her actual name because of client confidentiality. But he says he saw virtually the identical story play out half a dozen times last year as SpiderLabs investigated about 220 corporate security breaches and consulted with thousands of other security clients.

Story continues below.

As anyone would be, Sarah was thrilled to be expecting, and shared her excitement on a social-networking site. Henderson won't name names there, either, but you can go ahead and guess.

That was pretty much all the attacker needed. He soon sent out a message labeled "Sarah's baby pictures," and many of her friends and coworkers enthusiastically downloaded his malicious code. That made them victims of a scam known as "spear-phishing," a targeted version of the more familiar phishing scam in which the bait is a broad-based e-mail telling recipients that something has gone wrong with one of their accounts.

Just like the old Tom and Jerry cartoons, the cat-and-mouse game of hacker vs. IT professional never ends but continually changes scenes, though with anything but humorous stakes. That's why Henderson and other security experts drew an avid crowd of about 75 potential victims to a "Data Security Summit" on Wednesday at Penn State's Great Valley campus.

The all-day session was sponsored by INetU Inc., an Allentown Web-hosting company that also runs server farms in Chicago and Amsterdam. Other speakers included Microsoft's Hameed Mohammed, an expert in cloud-computing security who likens today's frequent data breaches to the relatively high level of air and auto accidents that occurred in the 1950s, when jets and superhighways were likewise in their infancy.

Henderson and Mohammed both aimed their advice at businesses trying to secure their systems and networks. But computer users of any type can benefit from warnings gleaned from their work.

1 | 2 | Next »
|
|
|
|
|