Zocalo Technology NewsA short description about your blog
Apr
06
Epsilon Security Breach Victim ListPosted by: david.stycos |Tagged in: Untagged
Epsilon Data Management is a legit email marketing service provider that was hacked back around March 24th. The attacker made off with their database of thousands of email addresses of target customers. That feat is more alarming given that Epsilon has some very big clients, many of whom you would at least heard of, if you are not already doing business with them. As of now, it only appears the email addresses were compromised, not any passwords or other PIV. If true, it may mean if you have an account with one of the companies listed below, the worst that might happen is a little more spam than usual in your inbox. These companies should, however, be sending data breach notifications to their customers just the same. The following companies have had their email lists breached by this attack:
For more information on the breach itself, see this Threatpost article.
Dec
21
FBI Installs Backdoor in OpenBSD Security SoftwarePosted by: david.stycos |Tagged in: Untagged
Recently, the security world was rocked by allegations the FBI had software developers install "back doors" into a suite of software designed to encrypt and secure network communications. An email was posted by Theo de Raadt, one of the founding developers of the OpenBSD operating system, stating that back in 2000-2001, co-workers were approached by the FBI to deliberately implant defects into the IPSEC VPN security software in order to make it easier for the agency to eavesdrop on otherwise secure communications. Read the original posting here. IPSEC VPN is a standard for creating secure encrypted connections, or "tunnels", across the internet between to locations. OpenBSD is an open source unix operating system. Being open source, the IPSEC software is openly, freely available to all to examine and copy. Like other open projects, such as Wikipedia, the work is contributed to it on an ad-hoc basis from many developers, rather than from a structured corporate environment. Open source advocates say this case is a win for open source, since the software is available for all to analyze and modify, and if any such back doors or flaws are discovered, they are seen and dealt with in the open. It can be alleged that since close projects, such as Microsoft Windows, are kept secret, there could also be such vulnerabilities in those products, but the world has no way to confirm this. See this Tech Republic article on this discussion here. It is unclear at this time whether this affects any other implementations of IPSEC on any other operating systems, and the allegations have not yet been proven by examination of the affected code. http://blogs.techrepublic.com.com/security/?p=4857 -- Tech Republic article http://permalink.gmane.org/gmane.os.openbsd.tech/22557 -- original posting
Oct
21
ZDS Gets The Center for Simulation Excellence Off To A Good StartPosted by: david.stycos |Tagged in: Untagged
Zocalo Data Systems has just completed an installation for the Center For Simulation Excellence in Muskegon, MI. The CSE trains doctors, nurses and EMTs how to deal with casualties in a variety of situations. Each of its nine simulation rooms presents students with different situations and environments, such as an ambulance, nursery, ICU or outdoors. The Center uses state-of-the-art simulation mannequins for the patients. These mannequins have very lifelike qualities. They breathe, make vocal sounds, have a heartbeat & pulse, and even a blood pressure. They are capable of producing a variety of symptoms including respiratory and cardiac arrest, pupils that dilate, convulse, and even sweat. The mannequins and the classroom environment are all monitored and controlled by instructors working from a control room. Cameras in each simulation room record the students' reactions, and can be reviewed later in a classroom. Zocalo Data Systems installed the computers, cameras, phones and audio/video systems for the CSE. ZDS also installed an expandable storage system for the recorded simulations, since CSE needed to keep simulations archived in order to support studies in trauma care and medical training. More information about the CSE can be found here. http://mercy-healthpartners.org/services/simlab.shtml See the WZZM News story here. http://www.wzzm13.com/news/story.aspx?storyid=135908&catid=14 The CSE is a joint project between the Muskegon County Health Authority, Mercy Health Partners and the Region 6 Biodefense Network.
Mar
25
Local Security Expert to discuss Cryptographic Applications in Data Security - April 7thPosted by: david.stycos |Tagged in: Untagged
FOR IMMEDIATE RELEASE Contact : David Stycos Local Security Expert to discuss Cryptographic Applications in Data Security David Stycos of Zocalo Data Systems will be speaking to Dornerworks employees on April 7th, 2010 at the Dornerworks building beginning at 12:00 p.m.
He will look at how cryptography is applied to some of the problems of data security. He will show how good cryptography can be implemented poorly, dispelling the myth that just because something is encrypted it's secure. He will also explore how cryptography systems work to protect us, and how our actions often hinder them. David Stycos has been a software developer for over 25 years in many different fields, including developing cryptographic systems for hand-held encryption devices. In 2004 he started Zocalo Data Systems as a vehicle to develop and sell data security products and services of his own design, and to help businesses strengthen their security risk profiles.
Mar
25
Grand Rapids Security Expert to discuss Cryptographic Applications in Data Security - April 16thPosted by: david.stycos |Tagged in: Untagged
FOR IMMEDIATE RELEASE Contact : David Stycos Local Security Expert to discuss Cryptographic Applications in Data Security David Stycos of Zocalo Data Systems will be speaking at the Grand Rapids chapter of the Information Systems Security Association (ISSA) on April 16th, 2010 at the Steelcase HQ beginning at 2:30 p.m. He will look at how cryptography is applied to some of the problems of data security. He will show how good cryptography can be implemented poorly, dispelling the myth that just because something is encrypted it's secure. He will also explore how cryptography systems work to protect us, and how our actions often hinder them. David Stycos has been a software developer for over 25 years in many different fields, including developing cryptographic systems for hand-held encryption devices. In 2004 he started Zocalo Data Systems as a vehicle to develop and sell data security products and services of his own design, and to help businesses strengthen their security risk profiles. Please contact David for further information.
Mar
25
Pwn2Own 2010: iPhone hacked, SMS database hijackedPosted by: david.stycos |Pwn2Own 2010: iPhone hacked, SMS database hijacked : http://ow.ly/1qKiG
Mar
25
Hacker exploits IE8 on Windows 7 to win Pwn2OwnPosted by: david.stycos |Hacker exploits IE8 on Windows 7 to win Pwn2Own : http://ow.ly/1qK1W
Mar
16
Malware-Serving ISP Taken Down, Researchers Say : http://ow.ly/1mXf3Posted by: david.stycos |Malware-Serving ISP Taken Down, Researchers Say : http://ow.ly/1mXf3
Mar
16
Vulnerability in Internet Explorer Could Allow Remote Code ExecutionPosted by: david.stycos |Vulnerability in Internet Explorer Could Allow Remote Code Execution : http://ow.ly/1mXgW
Mar
16
Product Watch: Kaspersky Lab Rolls Out Password ManagerPosted by: david.stycos |Product Watch: Kaspersky Lab Rolls Out Password Manager : http://ow.ly/1mX8R |





