Phishing

SCADA Security: Phishing Season is Open

Last week I received am email (shown further down on this page) purporting to be from the US Internal Revenue Service (IRS).

Simpler SCADA Security Beats More User Training

One of the mantras about good SCADA security is that it is primarily dependent on people and processes, not technology.

Thus if you have an ICS security problem, first look for solutions such as user training or better processes rather than  technology solutions.  This sounds good on the surface, but I’m not sure it’s true.

Performing tasks securely just isn’t part of human nature. Doing them the easiest way possible is. Unless the secure way is also the easy way, security will lose 9 times out of 10.

Facebook Wins at the Oscars, Fails at Security

The Oscars are over and the film about Facebook, The Social Network, won three awards. Pretty good – I saw the movie and thought it deserved a few gold statues.

But just as I was getting ready for the Oscar weekend, I received the following email from Facebook:

From: Facebook
Sent: Friday, February 25, 2011 1:17 PM
To: Eric Byres
Subject: Joe Smith posted on your Wall.

Subscribe to RSS - Phishing