Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

You Can Quote Me on That

And we did - 12 months of memorable statements, gaffes, and asides from Dark Reading

May 03, 2007 | 09:35 AM

By Terry Sweeney
DarkReading

An embarrassment of riches: That's what we found when we went back to a year's worth of stories on Dark Reading to find the most notable and quotable. It's a little early in our lifespan to be getting nostalgic, but if nothing else, what follows here is a good snapshot of the people, issues, and technology that shape today's security landscape.

Hit us up here or here and let us know your favorite.

So That's Why He Hums "Close to You"
"HD makes security hot. Everyone wants to take him to the prom."
— Dennis Cox, CTO, BreakingPoint, on his colleague HD Moore, in 10 Hot Security Startups

Yes We Can, And Do, Every Time We're in a Merge Lane
"Our problem as technologists is we can't pretend people don't exist. We must build security for people."
— Bruce Schneier, founder and CTO, BT Counterpane, in Schneier: In Touch With Security's Sensitive Side

What Happened to "Honey, Time to Get Up"?
"He [the FBI agent] had a gun to my head and said, 'Don't move,' and yanked my covers off. And there was this guy running past my room with a shotgun like [it was] a drug [bust]. This was extreme, because I was just some computer nerd."
— Marc Maiffret, chief hacking officer and CTO, eEye Digital Security, in From Script Kiddie to CTO

Why Hope Makes a Bad Strategy
"It's like putting a stick in the ground and hoping a guy running at you runs into that instead."
— Jose Nazario, software and security engineer, Arbor Networks, on the relative ineffectiveness of honeypots, in Enterprises Still Not Sweet on Honeypots

No Thanks, Bill
"As long as I'm releasing exploit code, I couldn't work for them, and I'm fine with that. My work is contrary to companies who sell security solutions... I don't want to be gagged by corporate culture."
— HD Moore, director of security research, BreakingPoint Systems, on job offers from Microsoft, in HD Moore Unplugged

This Also Qualifies Them to Work in PR
"People think that black hats target a specific company, but they don't. They see everyone, everywhere, and everything as a resource, IP address, or number, and they will use you to their best advantage. A lot of people think their companies are too small to be targets -- but they are, and so are their neighbors."
— Scott Swenka, security engineer for a Phoenix-based healthcare company, in Five Myths About Black Hats

WWF Meets "The Office"
"He raced toward us and began trying to pry the laptop from my colleague's hands, while cursing and calling us unprintable names. Finally my colleague was overpowered and lost the laptop. I was amazed at how strong this guy suddenly became, since he had to be 15 years older than my partner."
— Steve Stasiukonis, VP and founder, Secure Network Technologies, on a social engineering stunt gone awry, in Let's Wrestle for It

Yeah? Try Juggling a Chainsaw, Anvil, and Lit Torch, Too
"The problem IPS is trying to tackle is extremely hard -- to look at network traffic and understand the intent of it. It's like walking a tightrope between false positives and false negatives in an earthquake. It's moving all the time, and catching all variants of an attack is difficult."
— Thomas Ptacek, researcher, Matasano Security, in IDS/IPS: Too Many Holes?

First, We Kill All the Users
"You can't expect the user to have any input into the security equation -- it just doesn't work. It has to be taken out of the user's hands and built into the browsers, into the ISPs that route the traffic, into the operating system that has to render the pages. When you take it out of the user’s hands, it’s suddenly far more scalable, easier to update, and easier to adapt."
— Hacker Robert Hansen, a.k.a. RSnake, CEO, SecTheory, in Getting Users Fixed

Jaws of Strife
"No shit, it is literally jaw-dropping how stupid AOL has been. Don't forget this is the very data that Google refused to hand over the U.S. [Department of Justice] -- citing reasons of privacy."
— Blogger Ben Metcalfe, concerning AOL's inadvertent publication of live search data from 600,000+ subscribers, in Users Outraged by AOL Gaffe

Finally, Something We Can't Pin on Karl Rove
"For years, vendors treated the 'cyber-punk' as the boogeyman, and they built at least some of their business on the fear that some brilliant teen would launch a virus. Now some of them are painting organized crime as the boogeyman, spreading this notion that the Russian mafia is out to get every business."
— Marc Rogers, professor, Purdue University, in Eight Faces of a Hacker

What About Not Buying Google Stock?
"We thought we were doing everyone a favor. That was the biggest mistake of my life, not handing out an exploit."
— Hacker Jon Ellch, a.k.a. Johnny Cache, on the exploit of the Apple wireless vulnerability he developed with David Maynor, in Johnny Cache: Man in Black (Hat)

Me, I'd Need a Flashlight and a Good Map
"I just don't care... I've published enough working exploits that I can own your damn wireless drive. Anyone with a technical clue can figure out what really happened."
— Hacker Jon Ellch, a.k.a. Johnny Cache, also in Johnny Cache: Man in Black (Hat)

Phishing Rod: Buy It Now!
"There are bad guys targeting our systems every day -- it's an arms race in its most classic form. People see phishing attacks in their email on a regular basis. Some people are fooled by them. Some people learn to ignore them. Some people just get tired of seeing them and decide not to buy online anymore. Companies like eBay are targets. It's not our fault, but it's definitely our problem."
— Meg Whitman, CEO, eBay, in Banks, Retailers Seek to Regain User Trust

— The Staff, Dark Reading

  • Arbor Networks Inc.
  • BT Counterpane
  • BreakingPoint Systems
  • eBay Inc. (Nasdaq: EBAY)
  • eEye Digital Security
  • Matasano Security LLC
  • Microsoft Corp. (Nasdaq: MSFT)
  • Secure Network Technologies Inc.


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)