Category Archives: Security

Comcast replaces Disney with porn

I am hardly a fan of Disney, but this still sounds like a nightmare scenario for parents who do not want (sexual) porn broadcast into their homes:

Children here got more than they bargained for when they tuned in to “Handy Manny” on the Disney Channel this week — hard-core pornography.

Cable giant Comcast is investigating how the porn was broadcast during the popular cartoon, which is about a bilingual handyman, Manny Garcia, and his talking tools.

Talking tools? Ahem…

Could this generate new interest in content monitoring and in-line restrictions? I am sure many of us would like to be able to block content from being broadcast through our home devices. Imagine if you could detect and block spam-like product advertisements before they hit the screen, for example…kind of like firewalls and anti-malware on the consumer router.

Locksmith hired by police to break into jail

Here is an unusual story about a simple control failure:

Police in Germany had to call in a locksmith to break into jail when the lock on a cell broke, trapping a prisoner inside, authorities said Wednesday.

Police in the Bavarian town of Zwiesel near the Czech border locked up the 18-year-old at the police station after he was accused of smashing a car window during May day festivities on Tuesday.

I guess it is fortunate there was no immediate danger to the prisoner. Wonder what kind of lock it was and why/how there was no emergency override options. Was it a design failure?

Why regulate?

The Cutter Consortium has a brief interview with one of their own consultants about risk management. It took me a little effort to get beyond the awkward context, but I found this nugget. It is supposedly based on real data:

I would say that the external drivers of risk management were much stronger than I had expected. In 2002, organizations responding to our survey indicated that neither Y2K nor 9/11 pushed them to take on risk management.

However, in our 2006 survey, it seems pretty clear that the changes in corporate governance requirements like Sarbanes-Oxley as well as changes in the external risk environment have strongly influenced organizations to practice risk management. I would guess that the events of the past four years, as well as future risks like the possibility of a pandemic have been traumatic enough to convince organizations that they need to actively manage their risks.

So it is not the catastrophe itself that becomes a driver to mitigate risks, but regulation created as a result of the catastrophe. That makes a lot of sense, especially when you consider that much of the risk from a lack of regulation does not directly impact the companies themselves but the citizens that live near the meadows and waterways filled with waste or to the shareholders left holding the bag when a CEO/President is a crook…

Panther detection

I like this story because it highlights several problems in detecting elusive and unpredictable events:

Lt. Steve Cleveland from the Vineland police department said the idea of a black panther in the area was so unheard of that when the department first received the report, they thought someone was talking about the Black Panther Party — a political organization.

Prejudice and other externally imposed bias often prevents us from analyzing data clearly.

A conservation officer from the Division of Fish and Wildlife visited the area three times over the weekend and found nothing to indicate a panther was in the area, said Darlene Yuhas, a spokeswoman for the state’s Department of Environmental Protection.

“There was absolutely no evidence to indicate that there was a panther out there,” Yuhas said.

Paraskevas said she was told by the conservation officer that the ground was too dry for the animal to leave paw prints.

No evidence because there was no evidence-gathering mechanism in place, or because there really was no evidence?

Reminds me of all the times I hear people say they have no viruses when they have no virus detection, or they have no incidents when they have no intrusion detection, let alone incident response and investigation, professionals on staff.