Obama to Announce Cybersecurity Plans in State of the Union Preview

WASHINGTON — President Obama will announce new initiatives next week designed to bolster online security and improve access to cyberspace, White House officials said Saturday.

In a series of speeches, Mr. Obama will call for better safeguards against identity theft, improved privacy protection, enhanced cybersecurity for the government and private companies, and increased access to high-speed broadband connections across the country.

A White House official said in a statement to reporters that the president would “lay out a series of legislative proposals and executive actions that will be in his State of the Union that will tackle identity theft and privacy issues, cybersecurity, and access to the Internet.”

The president’s proposals are part of what the White House calls “SOTU Spoilers,” a series of announcements that preview Mr. Obama’s State of the Union address, which he is scheduled to deliver to a joint session of Congress on Jan. 20.

Delayed or Slow SSH Connection on Mac OS X Systems Fix

When conducting a vulnerability security scan of a Mac OS X system and attempting to obtain credentialed information, it maybe required some configuration changes occur. Often the SSH connections on Mac OS X systems has long delays that will fail when the vulnerability scanner tries to log-in. To solve the problem, follow the below recommendations.

Update Client Configuration

sudo vi /etc/ssh_config

Replace this line:

#GSSAPIKeyExchange yes

by:

GSSAPIKeyExchange no

Be aware you must also remove the sharp symbol (#)

Update Server Configuration

sudo vi /etc/sshd_config

Replace this line:

#UseDNS yes

by:

UseDNS no

Again, be aware you must remove the sharp symbol (#).

An additional course of action would be to add the IP addresses you’re going to connect to (or which are going to connect to your mac) in /etc/hosts.

 

 

(ISC)2 Security Congress 2015 Call for Speakers Submit Proposal by March 2nd

(ISC)2 Security Congress 2015 Call for Speakers Submit Proposal by March 2nd
If you are an expert information security professional, share your experience and knowledge at the industry’s premier event by submitting your proposal! Once again colocated with ASIS International 61st Annual Seminar and Exhibits, (ISC)2 Security Congress 2015 is expected to bring together more than 20,000 professionals worldwide from both the traditional and information security disciplines. The goal of (ISC)2 Security Congress is to help you secure tomorrow today with invaluable education, networking and career advancement opportunities to all levels of security professionals.

 

2015 (ISC)2 Security Congress Tracks include:

  • Cloud Security
  • Swiss Army Knife
  • Mobile Devices – Security and Management
  • Governance, Regulation & Compliance
  • Software Assurance & Application Security
  • Malware
  • Threats – Management, Detection, Intelligence & Mitigation
  • Professional Development
  • Forensics
  • Healthcare Security
  • Women in Security
  • Identity/Access Management

In order to be considered, please submit your proposal by March 2, 2015.

Xbox ‘Hacker’ Reveals Why He Attacked Consoles

Sony hack: The most bizarre tech story of 2014

Major theater chains had just announced their refusal to show the film as scheduled on Christmas Day, fearing threats of violence from the computer …
Xbox and PlayStation tackle cyber attacks

To make the most of the Xbox and PlayStation consoles, players have to connect to the internet in order to reach the console manufacturers’ computer …
Security experts skeptical North Korea behind Sony hack, NY Times reports

Some private security researchers are voicing doubts that North Korea was behind the hack of Sony’s computer systems, The New York Times reports.
Backlash against Sony hacking crisis is underway

… behind the huge cyber hack of Sony Pictures, the studio behind the movie. … audits by a third party regarding the security of its computer systems.
Cyber Wars and the Legal Lessons from the Sony Hack

At its core, the story of “what went wrong” at Sony boils down to two inexcusable problems: (1) Sony failed to secure its computer systems, servers, and …
Nudes and North Korea: A Year In “Hacktivism”

The one thing that many people may forget however, which made a major impact on the year, is computer hacking. Between the famed “hacktivist” …

Apple Releases Security Updates for OS X

Original release date: December 23, 2014

Apple has released security updates for OS X Mountain Lion, Mavericks, and Yosemite to address multiple vulnerabilities in the Network Time Protocol daemon. Exploitation of these vulnerabilities may allow a remote attacker to take control of a vulnerable system.

US-CERT encourages users and administrators to review Apple Security Update HT6601 and Vulnerability Note VU#852879 for additional information, and apply the necessary updates.

 

Also…

Apple Inc has pushed out its first-ever automated security update to Macintosh computers to help defend against newly identified bugs that security researchers have warned could enable hackers to gain remote control of machines.

The company pushed out the software on Monday to fix critical security vulnerabilities in a component of its OS X operating system called the network time protocol, or NTP, according to Apple spokesman Bill Evans.NTP is used for synchronizing clocks on computer systems.

The bugs were made public in security bulletins on Friday by the Department of Homeland Security and the Carnegie Mellon University Software Engineering Institute. Carnegie Mellon identified dozens of technology companies, including Apple, whose products might be vulnerable.

Read more here