Don’t use Password1 as your password

CNN reported yesterday that Password1 is the most common password in business environments. It’s the simplest password that meets common “complexity” requirements. It illustrates the problem with complexity requirements–a password can meet those requirements while still being extremely predictable.

As such, those passwords can be easy to guess, and they cast doubt on the entire idea of complexity.

Read more

Yesterday was Windows 8 day, but I found this e-reader hack more interesting

Yesterday, the consumer preview of Windows 8 hit the streets. I haven’t downloaded it. I’m mildly curious, but have a number of things higher on my priority list. Being a late adopter of Windows versions serves me well more often than not anyway.

I found something else yesterday that I find a lot more interesting: An e-ink Android tablet. Humor me.

Read more

A cloud computing-related Security+ question

Someone tossed a Security+ study question my way this week. This is an example of Security+ trying to be CISSP Lite, but it’s still a valid question–probably for either test, and for SSCP and CISM too.

A small not-for-profit organization needs to invest in a new expensive database. There is no budget for additional servers or personnel. Which of the following solutions would allow it to save money by avoiding hiring additional personnel and minimize the footprint in their current datacenter?

A. Linux
B. Software as a Service (SaaS)
C. Infrastructure as a Service (IaaS)
D. Platform as a Service (PaaS)

Let’s take it one at a time.

Read more

Living with a past-its-prime computer

I’m playing catch-up a bit. This weekend, Lifehacker ran a guide about living with a computer that’s past its prime.

I’ve made a career of that. One of my desktop PCs at work (arguably the more important one) is old enough that I ought to be preparing to send it off to second grade. And for a few years I administered a server farm that was in a similar state. They finally started upgrading the hardware as I was walking out the door. (I might have stayed longer if they’d done that sooner.) And at home, I ran with out-of-date computer equipment for about a decade, just this summer buying something current. Buying something current is very nice, but not always practical.

So of course I’ll comment on a few of Lifehacker’s points.

Read more

Why can’t St. Louis repurpose buildings like Baltimore does?

I had the opportunity to visit Savage Mill, near Baltimore, recently. Savage Mill is an old textile mill dating to the 1820s that fell into disuse in the 1940s. Today, the complex houses a variety of businesses. While the place has vacancies–the economy is still struggling, after all–it’s crowded, and it’s a great reuse.

It makes me wonder why we can’t do the same thing in St. Louis.
Read more

How to study for CISSP

How to study for CISSP

I got the letter this week. The one from (ISC)². If the first word is “congratulations,” it means you passed. But if the first two words are “thank you,” you didn’t. If you want the letter that says “congratulations” in your future, it helps to know how to study for CISSP. Here’s how I studied for mine. Hopefully it will help you. It’s a long road. But it’s doable.

Read more