Marc and Jolyn’s Wedding!

Marc and Jolyn’s wedding (the best of the pictures that we took)

20160423_232733962_iOS

There, we fixed it!

There, we fixed it!

And some other random pictures that we took from the wedding :)

20160423_230334920_iOS

20160424_013838590_iOS

20160424_013911441_iOS

20160424_001357860_iOS

20160424_012440498_iOS

20160424_013857600_iOS

20160424_015942946_iOS

20160424_030245963_iOS

20160424_031142779_iOS

Posted in life | Comments Off on Marc and Jolyn’s Wedding!

Pat’s Run 2016

I was part of the work team that did the Pat Tillman run.

Patrick Daniel Tillman was an American football player (Arizona Cardinal) who left his professional career and enlisted in the United States Army in June 2002 in the aftermath of the September 11 attacks.

Pat’s Run raises money for the Pat Tillman Foundation, which invests in military veterans and their spouses through academic scholarships – building a diverse community of leaders committed to service to others.

IMG_0416a

20160423_123548000_iOS

20160423_135336137_iOS

20160423_155624969_iOS

20160423_155800792_iOS

Posted in life | Tagged | Comments Off on Pat’s Run 2016

Project Management Vs. InfoSec

13055465_1387715854575617_1262076811322847094_n

Posted in Security Blog | Tagged | Comments Off on Project Management Vs. InfoSec

Eating 20% Fat Beef or 80% Lean Beef… A Google Android Problem

You know, it’s really how you frame something to make it sound almost appealing. Lots of grocery stores sell beef and it’s labeled as lean, but you know it has a lot of fat content if you were to flip the percentages around.

Google said back in September that there were 1.4 billion active Android devices worldwide at the time. Google also said that 70.8% of all active Android devices are running modern versions of Android that it supports with patches.

That means there are 29.2%… or 409 million unpatchable Android devices.

Not included in this massive number, rooted phones.

Here’s some good news though, even the most high-profile vulnerabilities don’t seem to have been exploited by hackers. Despite the widespread concern around the Stagefright vulnerabilities, which affected nearly 1 billion phones, no successful exploits were ever reported (which doesn’t mean anything evil didn’t actually happen).

Read more on Forbes and on Sophos.

Does this effect your Mobile Device Management strategy?

Posted in Security Blog | Tagged , , , , , , , | Comments Off on Eating 20% Fat Beef or 80% Lean Beef… A Google Android Problem

2016 = 2015 + 10%… In Breaches!

The Identity Theft Resource Center reports that there has been a total of 269 data breaches recorded through April 19, 2016, and that more than 11.27 million records have been exposed since the beginning of the year.

A data breach is defined as an incident in which an individual name plus a Social Security number, driver’s license number, medical record or financial record (credit/debit cards included) is potentially put at risk because of exposure. This exposure can occur either electronically or in paper format.

The 269 data breaches reported so far for 2016 are more than 10% higher than the number reported for the same period last year. A total of more than 169 million records were exposed in 2015.

The data breach report is chock full of good information! Each of the 269 breaches is laid out with a brief summary and a link to the source. Remember, these breaches only happened this year!

Want to read the Data Breach Report? Here –> http://www.idtheftcenter.org/images/breach/DataBreachReports_2016.pdf

Posted in Security Blog | Tagged , , | Comments Off on 2016 = 2015 + 10%… In Breaches!

Did you hear about the FDIC data breach?

Thanks to DLP (data loss prevention) software, the FDIC caught 44,000 customer records getting copied to a USB drive on an employee’s last day of work. She legitimately used the customer records normally as part of her day-to-day and while copying off personal files, she picked a pack of oopsie-daisies, and the folder with customer records went with her.

The FDIC’s security operations team caught on to this, performed an incident response and less than a week later, was able to get the thumb-drive back. They notified Congress as a precautionary measure and had the former employee sign an affidavit that she did not sell the data on the deep & dark web.

The FDIC has now banned all forms of removable media to prevent deliberate and accidental loss of customer data. It’s nice when a story ends on a good note.

Read the whole story on American Banker

Posted in Security Blog | Tagged , , , , , , , , , | Comments Off on Did you hear about the FDIC data breach?

A Warrior-Weekend

Damien and I, with some work friends, did the Warrior Dash today. Here are some pics with James, Tammy, Brian, and Ron.

20160409_151032252_iOS

20160409_152335781_iOS

20160409_152347021_iOS

20160409_154006604_iOS

James is the only enthusiastic one of the bunch. The calm before the storm perhaps? Is it maybe just too early for this?

20160409_175326255_iOS

20160409_175310446_iOS

20160409_175308178_iOS

20160409_175304810_iOS

20160409_175302775_iOS

20160409_175259440_iOS

20160409_175543158_iOS

20160409_175416173_iOS

20160409_175339229_iOS

The mud and the course definitely loosened everybody up!

The mud and the course definitely loosened everybody up!

20160409_175555098_iOS

20160409_182037366_iOS

20160409_181938389_iOS

20160409_181933653_iOS

20160409_185655985_iOS

20160409_185654518_iOS

20160409_185652083_iOS

20160409_185648715_iOS

20160409_185645413_iOS

20160409_185000324_iOS


20160409_181949886_iOS

20160409_185700524_iOS

 

Here are some of the official photos I found of Damien and I.
race_1802_photo_32957049

race_1802_photo_32956984

race_1802_photo_32959865

race_1802_photo_32944249

race_1802_photo_32944245

race_1802_photo_32944190

race_1802_photo_32944197

race_1802_photo_32938709

race_1802_photo_32938696

race_1802_photo_32964450

Posted in life | Comments Off on A Warrior-Weekend

The Law Firm Mossack Fonseca (The Panama Papers)

Panama-based law firm, Mossack Fonseca has services which include incorporating companies in offshore jurisdictions such as the British Virgin Islands. Other services include wealth managementKinda sorta like how HSBC does things

Mossack Fonseca’s data leak reveals the hidden wealth of some of the world’s leaders, politicians, and celebrities. Face it, when you have a ton of money, the world wants and the world’s governments want two things:

  1. To know how was the money made and
  2. How can they get a cut of it.

It’s not known yet how the data was exfiltrated or who leaked it, but 2.6TB was leaked, this infographic is a great visual representation of the size. The gray box is the Panama leak compared to the yellow boxes.

graybox

Some findings include:

  • Twelve national leaders are among 143 politicians, their families and close associates from around the world known to have been using offshore tax havens.
  • A $2bn trail leads all the way to Vladimir Putin. The Russian president’s best friend – a cellist called Sergei Roldugin – is at the centre of a scheme in which money from Russian state banks is hidden offshore. Some of it ends up in a ski resort where in 2013 Putin’s daughter Katerina got married.
  • Among national leaders with offshore wealth are Nawaz Sharif, Pakistan’s prime minister; Ayad Allawi, ex-interim prime minister and former vice-president of Iraq; Petro Poroshenko, president of Ukraine; Alaa Mubarak, son of Egypt’s former president; and the prime minister of Iceland, Sigmundur Davíð Gunnlaugsson (who has stepped down and out because of the leak).
  • In the UK, six members of the House of Lords, three former Conservative MPs and dozens of donors to British political parties have had offshore assets.
  • The families of at least eight current and former members of China’s supreme ruling body, the politburo, have been found to have hidden wealth offshore.
  • Twenty-three individuals who have had sanctions imposed on them for supporting the regimes in North Korea, Zimbabwe, Russia, Iran and Syria have been clients of Mossack Fonseca. Their companies were harboured by the Seychelles, the British Virgin Islands, Panama and other jurisdictions.
  • A key member of Fifa’s powerful ethics committee, which is supposed to be spearheading reform at world football’s scandal-hit governing body, acted as a lawyer for individuals and companies recently charged with bribery and corruption.
  • One leaked memorandum from a partner of Mossack Fonseca said: “Ninety-five per cent of our work coincidentally consists in selling vehicles to avoid taxes.”

Mossack Fonseca says it complies with anti-money-laundering laws and carries out thorough due diligence on all its clients. It says it regrets any misuse of its services and tries actively to prevent it. The firm says it cannot be blamed for failings by intermediaries, who include banks, law firms and accountants.

Posted in Security Blog | Tagged , , , , , | Comments Off on The Law Firm Mossack Fonseca (The Panama Papers)

SuSe, Yes Please

Posted in Security Blog | Tagged , , , | Comments Off on SuSe, Yes Please

Uptime Funk You Up!

Here are the lyrics so you can sing along.

This bit
Uncontrolled
A bad bug,
Make my system fold
This bug, in the kernel
My kernel
My uptime ceases
Freakin’, Spazzin’
My manager’s mad, it ain’t pretty
I need caffeine, a big screen
Gotta fix this server in a jiffy

It’s too hot (hot patch)
Call Torvalds and Kroah-Hartman
It’s too hot (hot patch)
Make a Sys Admin retire man
It’s too hot (hot patch)
Holy cow, am I in a jam
It’s too hot (hot patch)
Tellin’ ya now it ain’t that funny
Server’s down

Live patching hallelujah (whoo)
Live patching hallelujah (whoo)
Live patching hallelujah (whoo)
‘Cause Uptime Funk gon’ give it to ya
‘Cause Uptime Funk gon’ give it to ya
‘Cause Uptime Funk gon’ give it to ya
Saturday night and servers alright
Don’t reboot it just patch (come on)
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Hey, hey, hey, oh

Halt
Don’t reboot, init
Found a fix, grab code from git
Make a build, passed the tests
Julio! Make a patch!
Ride to Provo, Nuremberg, Newbury in the UK
We got Linux, and there’s no doubt
Gonna fix that server in a jiffy

I’m all green (hot patch)
Called a Penguin and Chameleon
I’m all green (hot patch)
Call Torvalds and Kroah-Hartman
It’s too hot (hot patch)
Yo, say my name you know who I am
It’s too hot (hot patch)
I ain’t no simple code monkey
Nuthin’s down

Live patching hallelujah (whoo)
Live patching hallelujah (whoo)
Live patching hallelujah (whoo)
‘Cause Uptime Funk gon’ give it to ya
‘Cause Uptime Funk gon’ give it to ya
‘Cause Uptime Funk gon’ give it to ya
Saturday night and servers alright
Don’t reboot it just patch (come on)
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Hey, hey, hey, oh!

Before we leave
Imma tell y’all a lil something
Uptime Funk you up, Uptime Funk you up
Uptime Funk you up, Uptime Funk you up
I said Uptime Funk you up, Uptime Funk you up
Uptime Funk you up, Uptime Funk you up

Come on, patch
Get on it
If you stable then flaunt it
If you online then own it
Don’t text about it, come show me
Come on, patch

Get on it
If you stable then flaunt it
Well it’s Saturday night and the servers alright
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Don’t reboot it just patch
Hey, hey, hey, oh!

Uptime Funk you up, Uptime Funk you up
(say whaa?!)
Uptime Funk you up, Uptime Funk you up
Uptime Funk you up, Uptime Funk you up
(say whaa?!)
Uptime Funk you up, Uptime Funk you up
Uptime Funk you up, Uptime Funk you up
(say whaa?!)
Uptime Funk you up, Uptime Funk you up
Uptime Funk you up, Uptime Funk you up
(say whaa?!)
Uptime Funk you up

Posted in Security Blog | Tagged , , | Comments Off on Uptime Funk You Up!