Top Ten Ways to Stir the Cyber Pot
I spent a few minutes just now thinking about the digital security issues that people periodically raise on their blogs, or on Twitter, or at conferences. We constantly argue about some of these topics. I don't think we'll ever resolve any of them.
If you want to start a debate/argument/flamewar in security, pick any of the following.
- "Full disclosure" vs "responsible disclosure" vs whatever else
- Threat intelligence sharing
- Value of security certifications
- Exploit sales
- Advanced-ness, Persistence-ness, Threat-ness, Chinese-ness of APT
- Reality of "cyberwar"
- "Builders vs Breakers"
- "Security is an engineering problem," i.e., "building a new Internet is the answer."
- "Return on security investment"
- Security by mandate or legislation or regulation
Did I miss any subjects people raise to "stir the cyber pot?"
Comments
* Security awareness sucks/rocks.
* Is DDoS hacking or not.
*New vision on protocol modeling (Ex. "ipv6 is no a solution", "ARP, HTTTP,DNS are fexible but no secure protocols").
*Architecture paradigm (Ex. "stack overflow is the oldest and the most effective attack", "new computers are based on the same vulnerable architecture; it doesn't exist new computer architecture models: ip phones,smarthphones, smart tv's").
OS X vs Windows 7?
Digital Forensics Investigation Challenge Nov 29-30
Location : Prince George's Community College, Largo MD
Contact : Michael Burt mburt@pgcc.edu
www.mddfi.org
http://cyberwatchcenter.org/index.php?option=com_jevents&task=icalrepeat.detail&evid=845&Itemid=68&year=2012&month=11&day=29&uid=26c695a3187030e56cf8f4e11743fe2b