I ran across an article on SearchSecurity.com this morning that caught my attention. It's about how rootkits are becoming more popular. What caught my attention is this comment on the teaser page "industry experts at RSA Conference 2007 say rootkits have also emerged as useful tools for legitimate businesses trying to exert control over users." My jaw dropped. After the Sony fiasco and just the fact that rootkits are, by design, hacker tools used to hide bad things you would think that we would have learned something. I know that there are lots of hacker tools out that have legitimate uses in security. I think it's great when we can use hacker tools to make our networks and systems more secure against those very tools. I think it's a good idea to keep a close eye on what the hackers are doing so we can counter them. I don't think that using something designed to hide bad things on our systems is a good idea for any reason. If there is a way to subvert the legitimate rootkit, and there is a way that will be found, then it is a major danger to our systems security and we need to fight against any company that wants to implement their use.
Security's Everyman
Wednesday, February 07, 2007
Legitimate Rootkits?
Posted by
Andy, ITGuy
at
6:29 AM
1 comments
Labels: hackers, information security, rootkits, RSA, searchsecurity.com
Monday, January 08, 2007
Project Updates
I'm on my way back to Atlanta from Va Beach and using the time to write several posts. [Rich C., this is one way to maintain a blog while busy. :)] I made some phone calls on Friday and was able to get confirmation that Cisco will ship my routers tomorrow (Monday). That makes me feel much better. If hoping to get approval to have them sent overnight so we can start configuring them Tuesday and get them installed starting Thursday. That way I can get this part of the project completed and focus on the domain rollout and a lot of the petty things that have to be done.
Early on I was hoping that I'd get everything done early and still make RSA, but that won't happen. Even if I do have everything in place, tested and ready to go the follow-up and post project support will not allow me to leave. Actually that translates into "I couldn't get my CIO to approve me leaving that soon after implementing all these major changes.
Posted by
Andy, ITGuy
at
6:53 AM
Labels: cisco, information security, RSA
