Be Prepared

…and ordinarily, there’d be a witty allusion here to Tom Lehrer, who used the same title for one of his songs, but there’s a very serious edge to this post.

The part of the world I live in is mostly spared (touch wood) the sort of dramatic, extreme disaster that I sometimes discuss here in the context of disaster-related scams, blackhat SEO and so forth. Even flooding in the often-rainsoaked UK lacks drama compared to the impact it has in other parts of the world. But it’s depressing to think how much of my security writing in recent years has related to criminal exploitation of the 2004 and other tsunami, earthquakes and so on, and at the beginning of September I’m addressing the topic again at the CFET 2011 conference in the UK.

Many of my friends, acquaintances and readers are rather more used to the risk and reality of earthquakes, tsunami, forest fire, eruptions and so on, not least those who are situated close to the Pacific “Ring of Fire”, which has 75% of the world’s active and dormant volcanoes and experiences 80% of its largest earthquakes, and includes most of the West coasts of North and South America. However, a glance at the links on the Federal Emergency Management Agency’s page at http://www.fema.gov/ demonstrates that the US population as a whole is at enough risk from national disasters to justify the existence of the National Prepared Month Coalition. AVIEN’s US subscribers may well want to think about supporting the initiative (it’s free, it isn’t restricted to USians, and it gives access to some resources you may find especially useful in the US).

The point I really want to get over here, though, is less this particular initiative (though AVIEN does support it as a member, so you may hear more of this from me) than the importance of training for disaster as a mindset that we can all benefit from, even if we don’t live too close for comfort to a major fault line, like my colleagues in San Diego. Disaster is a beast with many faces, and not all disasters are “natural”.

Tip of the hat to Robert Slade for turning my attention to the issue (not for the first time, of course) .

Blackhat SEO and other nuisances

The horrific Russian suicide bombings have, inevitably, generated a load of blackhat SEO (search engine optimization) attacks, not to mention Twitter profile attacks, using topical keywords to lure victims into running malicious code. I’ve blogged on that elsewhere recently – e.g. “Here come (more of) the Ghouls”, at http://www.eset.com/blog/2010/03/30/here-come-more-of-the-ghouls – so I won’t repeat myself here.

However, I hear from that nice Mr. Cluley at Sophos that there’s an awfully good paper available about “Poisoned search results: How hackers have automated search engine poisoning attacks to distribute malware”, by Fraser Howard and Onur Komili.  

It is a good paper, and it will interest a lot of the people who read this blog. And it should interest quite a few people who probably won’t read it. 🙁

