Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Laptop Losses and Phishing Fruit Salad
Dr. Neal Krawetz, 2007-02-15

Dr. Neal Krawetz takes a look at the numbers behind reports of laptop thefts and phishing attacks, showing inconsistent metrics and the difficulty in using numbers to determine the real level of threat.

Comments Mode:
Laptop Losses and Phishing Fruit Salad 2007-02-16
Anonymous (2 replies)
Instead of trying to figure out the risk, we should work on minimizing it. Let the insurance companies figure out the risk....

[ more ]  [ reply ]
Re: Laptop Losses and Phishing Fruit Salad 2007-02-16
Anonymous
If you can determine that the value of the data + laptop is less than the cost of implementing the control, you won't need to implement the control. That is why you need to determine the risk. It boils down to economics. This procedure applies to all forms of information security. When it comes down...

[ more ]  [ reply ]
Re: Laptop Losses and Phishing Fruit Salad 2007-02-19
Ben
Additionally, as budgets for security controls are limited, one would have to prioritize risks to mitigate the most important threats first and leave less endangered assets for later. Assurance companies can provide extremely valuable data that can be used as input in these risk assessments. Unfortu...

[ more ]  [ reply ]
Laptop Losses and Phishing Fruit Salad 2007-02-16
Anonymous
Nice article, but there were far more than just 2 companies that had laptops stolen or lost in 2006.

Ameriprise, the VA, and Fidelity come to mind off the bat....

[ more ]  [ reply ]
Laptop Losses and Phishing Fruit Salad 2007-02-16
mroonie
There's actually a really good article that covers the issue of laptop theft and protection here:
http://www.essentialsecurity.com/news.htm?id=41

There's also some good links for more information on Wikipedia on it as well:
http://en.wikipedia.org/wiki/Remote_laptop_security...

[ more ]  [ reply ]
Laptop Losses and Phishing Fruit Salad 2007-02-17
Anonymous
According to Postini (http://www.postini.com/stats/index.php), 80% of email today is spam.
At the same time, MessageLabs (http://www.messagelabs.com/Threat_Watch) reports that spam is 52% of all email.

What are they measuring, and why do they have such different stats?...

[ more ]  [ reply ]
Laptop Losses and Phishing Fruit Salad 2007-02-19
Anonymous
Lies, damned lies and statistics....

[ more ]  [ reply ]
APWG Response: Laptop Losses and Phishing Fruit Salad 2007-02-21
APWG (2 replies)
Neal,

Thanks for a good and stimulating article. In the future, it might be helpful for you to ask APWG statisticians about how the numbers are computed before writing an article.

APWG has not revised our methodology for counting. Rather, we have ADDED additional, separately tracked, measure...

[ more ]  [ reply ]
Re: APWG Response: Laptop Losses and Phishing Fruit Salad 2007-02-21
Neal Krawetz (1 replies)
Hi Dave,

It's always good to hear from you.

With regards to your comments:

In your reply, you wrote: "APWG has not revised our methodology for counting."
This seems to be contradicted by the APWG_Phishing_Activity_Report-Oct2004.pdf which begins by saying:
"With this report for October 20...

[ more ]  [ reply ]
Re: Re: APWG Response: Laptop Losses and Phishing Fruit Salad 2007-02-22
APWG
Neal,

Our experience is that people contribute phishing emails to sites and services that take action against them (eg. takedown or law enforcement). This can be seen by the growth of the Anti-Phishing Working Group membership, and by the rapid growth of the PhishTank and PIRT anti-phishing comm...

[ more ]  [ reply ]
Re: APWG Response: Laptop Losses and Phishing Fruit Salad 2007-02-23
mike (1 replies)
i think jevans is missing the point. every admin out there should not have to personally ask him or anyone else what he collects and what he measures. asking every vendor how they come up their numbers sounds like a full time job and i dont have the budget for it...

[ more ]  [ reply ]
Re: Re: APWG Response: Laptop Losses and Phishing Fruit Salad 2007-02-27
APWG
Mike,
Fair enough. We do try to describe the methodology in each of our monthly reports, posted at www.antiphishing.org. We will look to enhance this description in the next report.

Dave
...

[ more ]  [ reply ]
Laptop Losses and Phishing Fruit Salad 2007-07-31
Anonymous
1 in 7 laptops stolen
Police database
https://www.juststolen.net/

PCWORLD article
http://blogs.pcworld.com/tipsandtweaks/archives/003279.html
...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus