Learn about Zero Trust Architecture
Impenetrable cybersecurity without sacrificing usability
Gain detailed visibility into all your endpoints activities
Harden applications and hardware environments
Immediate and continuous response to incidents
Close the window of time your data could be exposed
Get your Comodo solutions setup, deployed or optimized
Control access to malicious websites
Defend from any internet based threats
Stop email threats before it enters your inbox
Preserve and protect your sensitive data
Keep your website running fast and malware free
Add encryption to your websites
Automated certificate mgmt. platform
Secure private intranet environments
Digital signature solutions for cloud apps
Encrypt emails for senders and recipients
Stay compliant with PCI DSS
Trusted authentication for IoT devices
Francisco Partners a leading technology-focused private equity fund, has acquired a majority stake in Comodo’s certificate authority business. Newly renamed from Comodo CA Limited to Sectigo Limited. Privacy Policies, Trademarks, Patents and Terms & Conditions are available on Sectigo Limited’s web site.
Meet the people behind the direction for Comodo
Get the latest news about Comodo
People are the key to achievement and prosperity
Stay up to date with our on-demand webinars
Worldwide: Sales, Support and General Inquiries
Schedule a live demonstration of our solutions
Need immediate help? Call 1-888-551-1531
Instantly removes viruses to keep your PC virus free
Experience true mobile security on your mobile apple devices
Secure Internet Browser based on Chrome
Chrome browser internet security extension
Submit a ticket to our support team
Share any product bugs or security flaws
Collaborate with research experts on data sets
Valkyrie Threat Intelligence Plugins
Valkyrie Threat Intelligence APIs
The RSA Conference is one of the biggest events in the world of cybersecurity. I wasn’t there this year, but most of my colleagues were. They weren’t replying to my emails while RSAC 2018 was happening, but I can certainly understand why. A lot of the most important people and companies in information security share very useful information during the event. Thankfully, I got to find out a bit about what happened during the event, thank goodness for the internet. Some of the things I learned were rather surprising!
RSA Conference App Vulnerability
First of all, there was a breach in RSA’s conference app. No, this wasn’t some sort of demonstration. It was a genuine and embarassing mistake on RSA’s part. Imagine if a conference of Cordon Bleu chefs served pre-frozen microwave dinners. Or if a conference on building fire regulations took place in a venue with blocked fire exits. Or if we discovered that the editor of MacWorld used a Windows 10 PC and a Samsung Android device exclusively. (That’s almost certainly not true.) I could go on.
Twitter user svblxyz noticed the huge vulnerability and announced their discovery on the platform.
Through the RSA Conference Mobile App, users could find URLs that allowed easy access to sensitive data. Some of the data included all of the app user’s real names. RSA then confirmed the vulnerability officially.
“Our initial investigation shows that 114 first and last names of RSA Conference Mobile App users were improperly accessed. No other personal information was accessed, and we have every indication that the incident has been contained. We continue to take the matter seriously and monitor the situation.”
First and last names aren’t the most sensitive type of data that a user can have. Everyone who has heard about me on the internet knows mine. Nonetheless, these sorts of mistakes can lead to much more sensitive data being leaked, such as credit card and bank account numbers, usernames and passwords, and government ID numbers. Let’s hope that the RSA’s own app development team has learned from this mistake.
Forget Buzzwords, Think Risk Management
In my job writing about cybersecurity, I get exposed to buzzwords about my area of expertise. I also get exposed to so many general Silicon Valley buzzwords that they disrupt the innovation potential of the metaphorical gig economy of the CPU in my skull, my brain. Netwrix’s Marc Potter warned that buzzwords are a distraction from what we should really be focusing on, risk management. He mentioned these buzzwords in particular:
“What has actually happened is vendors are so intent on matching solutions to buzzwords that the solution is often becoming the problem. What then happens is new companies are then launched to fix the problems that the last set of solutions caused,” said Marc Potter. “There is no silver bullet and vendors are trying to do everything and be everything for everyone. They search for taglines to match solutions to buzzwords.”
I presume a focus on risk management is a return to the basics. Matters like ransomware and insider threats are huge and growing problems. But yeah, maybe focusing security hardening and incident response efforts on each of the very numerous specific cybersecurity threats may be a waste of time.
GDPR is a new set of data security regulations in the European Union which will take effect on May 25th. Most international internet service companies are affected by it, and their European datacenters must comply. Pretty much everyone who uses the internet worldwide is affected by GDPR in some way because we all have data on European servers. It seems to be the biggest thing in corporate cybersecurity, like The Beatles to popular music.
RSAC board member Dmitri Alperovitch discussed the overwhelming challenge of GDPR compliance.
“(GDPR makes companies have to) think long and hard about whether they need to store this data. That is a very, very good thing.”
But apparently, only about 25% of affected companies have prepared for GDPR compliance. Ouch!
RSAC board member Todd Inskeep doesn’t think that organizations are ready for cyber attacks on data in general.
“Companies aren’t fully ready (for future data attacks),” he said. “Our adversaries have been much more focused on information, either using it for propaganda or manipulating information. This country is behind in thinking about it—not just to defend ourselves but also in leveraging it ourselves.” Companies need to think more creatively about how to fend off nefarious actors but also to use intelligence proactively.”
Could thinking more creatively about data security and GDPR compliance involve blockchain somehow? RSAC board member Benjamin Jun thinks so.
“What (blockchain has) showed us that there were ways to let people work together who had no existing reason to trust each other. Through these systems, we could build enough consensus and enough trust to exchange money, to exchange contracts. Most of the stuff we see right now deals with using these technologies in a very transaction oriented way… These are just the beginnings of how things are going to change.”
Silicon Valley Versus State-Sponsored Attacks
Thirty-four of the largest tech companies in the world are concerned about how government-sponsored cyber attacks may be affecting ordinary people. The group includes Facebook, Microsoft, and HP (a company I worked with earlier this year.) They’ve combined their efforts to form the Cybersecurity Tech Accord. Microsoft President Brad Smith, no relation to my boyfriend Jason Smith (hi Jay!), discussed the Accord at RSAC 2018.
“This is a sobering time. When World War II ended, governments of the world pledged a moral responsibility and legal duty to protect civilians in the time of war. Then in May and June of last year, we saw governments attacking civilians in a time of peace. We have a message to the governments of the world – that’s an attack that endangers people’s lives.”
You can read more about the Cybersecurity Tech Accord on their website. The Accord says, “the companies will not help governments launch cyberattacks against innocent citizens and enterprises, and will protect against tampering or exploitation of their products and services through every stage of technology development, design and distribution.”
The world of cybersecurity is evolving at a rapid pace. Between an embarrassing mistake and a lot of passionate keynote speakers, 2018’s RSA Conference was as eventful as ever.
Tags: RSAC 2018,cybersecurity
Reading Time: 4 minutes Increased dependency on computers and access to data makes an organization more vulnerable to cybersecurity threats. With the increase in cyber-criminals and cyber-attacks, many companies today are looking for greater protection of their decentralized computing work environments from their Managed Service Providers (MSPs). As a result, MSPs need to deliver firewall solutions that are designed…
Reading Time: 3 minutes Disruptions are often unforeseen. This could be a catastrophic event like a hurricane, a fire, or an earthquake. Disruptions, however, can also come in other forms such as that of a pandemic. This means that a building doesn’t necessarily have to be demolished or lives have to be lost for an unforeseen event to completely…
Reading Time: 4 minutes There should be no doubt in anyone’s mind that the coronavirus pandemic will reshape our education systems. It has already altered how students around the world learn and share knowledge with their peers in just a matter of months. Those changes can give insight into how education will progress in the long run, for better…
Sign up to our cyber security newsletter
Comodo Cybersecurity would like to keep in touch with you about cybersecurity issues, as well as products and services available. Please sign up to receive occasional communications. As a cybersecurity company, we take your privacy and security very seriously and have strong safeguards in place to protect your information.
See how your organization scores against cybersecurity threats