Category Archives: Security

SEC Social Media Risk Alert

The SEC has released a brief on Investment Adviser Use of Social Media

Firms’ use of social media must comply with various provisions of the federal securities laws, including, but not limited to, the antifraud provisions, compliance provisions, and recordkeeping provisions.

The SEC points out several staff observations that should help clarify their concern with the social behavior of registered investment advisors (RIA) or firms.

  1. Unclear procedures reduce the accuracy of compliance program measurement
  2. Sites that allow third-party content need policies on what is permissible
  3. Social media communication often falls under required record retention and accessibility rules

OpenSSL Fixes Six CVE

OpenSSL has announced fixes for the following six security flaws for versions 1.0.0f and 0.9.8s. The first is the notorious “extension of the Vaudenay padding oracle attack on CBC mode encryption”.

  1. DTLS Plaintext Recovery Attack (CVE-2011-4108)
  2. Double-free in Policy Checks (CVE-2011-4109)
  3. Uninitialized SSL 3.0 Padding (CVE-2011-4576)
  4. Malformed RFC 3779 Data Can Cause Assertion Failures (CVE-2011-4577)
  5. SGC Restart DoS Attack (CVE-2011-4619)
  6. Invalid GOST parameters DoS Attack (CVE-2012-0027)

The last CVE has an “original release date of 01/06/2012”, yet the OpenSSL security advisory was released “04 Jan 2012”.

Breaking Human Limits

Radiolab has a humorous hour of interviews about how humans can exceed their own limits by studying them and then breaking through (e.g. hacking the body, mind and knowledge)

On this hour of Radiolab: a journey to the edge of human limits.

How much can you jam into a human brain? How far can you push yourself past feelings of exhaustion? We test physical endurance with a bike race that makes the Tour de France look like child’s play, and mental capacity with a mind-stretching memory competition. And we ask if robots–for better or worse–may be forging beyond the limits of human understanding.