Everything online is hackable. This is true for Equifax’s data and the federal Office of Personal Management’s data, which was hacked in 2015. If information is on a computer connected to the Internet, it is vulnerable. But just because everything is hackable doesn’t mean everything will be hacked. The difference between the two is complex, … Read More “Can Consumers’ Online Data Be Protected?” »
Category: schneiernews
Auto Added by WPeMatico
My next book is still on track for a September 2018 publication. Norton is still the publisher. The title is now Click Here to Kill Everybody: Peril and Promise on a Hyperconnected Planet, which I generally refer to as CH2KE. The table of contents has changed since I last blogged about this, and it now … Read More “New Book Coming in September: “Click Here to Kill Everybody”” »
Last week, I testified before the House Energy and Commerce committee on the Equifax hack. You can watch the video here. And you can read my written testimony below. Testimony and Statement for the Record of Bruce Schneier Fellow and Lecturer, Belfer Center for Science and International Affairs, Harvard Kennedy School Fellow, Berkman Center for … Read More “Me on the Equifax Breach” »
Blog regulars will notice that I haven’t been posting as much lately as I have in the past. There are two reasons. One, it feels harder to find things to write about. So often it’s the same stories over and over. I don’t like repeating myself. Two, I am busy writing a book. The title … Read More “My Blogging” »
I have successfully gotten the fake LinkedIn account in my name deleted. To prevent someone from doing this again, I signed up for LinkedIn. This is my first — and only — post on that account: My Only LinkedIn Post (Yes, Really) Welcome to my LinkedIn page. It looks empty because I’m never here. I … Read More “More on My LinkedIn Account” »
I seem to have a LinkedIn account. This comes as a surprise, since I don’t have a LinkedIn account, and have never logged in to LinkedIn. Does anyone have any contacts into the company? I would like to report this fraudulent account, and possibly get control of it. I’m not on LinkedIn, but the best … Read More “I Seem to Have a LinkedIn Account” »
New paper: “Taking Stock: Estimating Vulnerability Rediscovery,” by Trey Herr, Bruce Schneier, and Christopher Morris: Abstract: How often do multiple, independent, parties discover the same vulnerability? There are ample models of vulnerability discovery, but little academic work on this issue of rediscovery. The immature state of this research and subsequent debate is a problem for … Read More “Measuring Vulnerability Rediscovery” »
Humble Bundle is selling a bunch of cybersecurity books very cheaply. You can get copies of Applied Cryptography, Secrets and Lies, and Cryptography Engineering — and also Ross Anderson’s Security Engineering, Adam Shostack’s Threat Modeling, and many others. This is the cheapest you’ll ever see these books. And they’re all DRM-free. Powered by WPeMatico
Forbes Names Beyond Fear as One of the “13 Books Technology Executives Should Have On Their Shelves”
It’s a good list. Powered by WPeMatico
I’m in Cambridge University, at the tenth Workshop on Security and Human Behavior. SHB is a small invitational gathering of people studying various aspects of the human side of security, organized each year by Ross Anderson, Alessandro Acquisti, and myself. The 50 or so people in the room include psychologists, economists, computer security researchers, sociologists, … Read More “Security and Human Behavior (SHB 2017)” »