Welcome to the Aconiac Security Group Blog

This blog includes company news, company statements, tutorials, guides and much more. So please add this blog to your RSS reader and let us help you to become better security professionals.
Disclaimer: The views of individual bloggers may not be the views of Aconiac as a whole.

The official Aconiac company blog

NOTE: This news item was originally posted on December 30, 2008

Security threats in 2009

2008 will soon be over and a new and exciting year lies in front of us. 2008 was an interesting year for computer security. We saw, once again, escalating threats towards companies from almost all fronts. Especially the leaks of unencrypted data in England, the automated SQL injection mass-attacks and the attacks on social network services were some of the big public problems in 2008.
But then how will 2009 be? Now, it’s obviously very hard to predict the future in such a dynamic world, however we have made an effort to come up with our ideas for what might be, the 10 biggest security threats in 2009:

  1. Weak economy

    The economic crisis, which right now is devastating many businesses all over the world, will most likely result in companies having to cut down on expenses. In these kinds of expense cuts, typically what gets cut first is the administrative expenses like e.g. computer security and preventive measures. We can therefore expect to see an increase in the amount of security issues in software and systems developed in 2009.

  2. Lack of education

    One of the greatest threats towards security in a company is and will always be education. This has been, in our minds, the biggest issue in 2008 and actually have always been the biggest issue. Users of IT solutions do not understand the security problems in such a way, that they can effectively protect themselves. We will therefore, once again this year, probably see an increase in successful hacker attacks – attacks that largely could be prevented by increased education.

  3. Mobile devices

    Employees are becoming more and more mobile as each day passes. One of the big things that really got a boost in 2008 was mobile broadband. This technology specifically, can lead to employees beginning to do their jobs outside of the company’s secure parameters. A trend that could ultimately lead to catastrophic data leakage, that is if it is not prevented by good policies and encryption.

  4. Outsourcing

    Due to the economic crisis, a lot of companies will probably begin to outsource certain tasks to cheaper labor in other countries. This act however has a lot of serious security implications, since the company now no longer has control of how its data is handled. It is therefore extremely important, that companies make a proper security policy with their outsourcing partner and that this policy is actually followed.

  5. Espionage

    The time when hackers were just small kids in a basement is, by far, over. Today several indications are showing that hacking has, in several cases, been used by e.g. China to attack government institutions in the USA. This type of attack, which for the record can have catastrophic consequences, will likely escalate in 2009, where we will see even more examples of this form of Internet warfare.

  6. Anonymity/Privacy

    While nations all over the world are using more and more censorship and surveillance, many freedom-loving employees will begin to work harder to secure their privacy and the right to free speech. This will probably manifest itself in an increased use of software to break blocking mechanisms and hide information about the user. With this increased usage, it will become much harder for companies to identify malicious users, since it will now not only be the criminals who are attempting to hide from identification.

  7. Apple’s Mac OS X

    While viruses and spyware are everyday fears of Windows users, Apple’s Mac OS X has up until now avoided most problems. They’ve actually avoided it so well, that many Mac users are now, mistakenly, believing Mac OS X can not be infected with malicious software, like e.g. a virus. Apple had a record high sale of Macs in 2008 and as their market share increases, so will the number of attacks on the platform increase. Sooner or later it will therefore become a security risk to have an unprotected Mac OS X on the company network and companies should therefore implement effective security policies for Mac users.

  8. Insecure websites

    A lot of companies and government institutions still have websites with several security issues of varying types. With the increasing economic crisis and the likewise increasing amount of computer criminals, it is very likely many more companies will be attacked from the web this year. Even many more than earlier years.

  9. SMS Scams (SMiShing)

    With the expanded use of SMSs for almost any thinkable communication, criminals will soon begin to notice the possibilities in the use of SMS to scam individuals and companies. Most do not know, that it is extremely easy to fake an SMS so that it seems as if the SMS is from “Mom” or “The Boss”. This makes it easy for criminals to scam people into wiring funds or giving out passwords.

  10. Social networks

    Social networks are not as big of a threat as some security companies would have you believe, however there are several dangers you should take seriously as a company owner. Like e.g. in 2008 there were several attempts at spreading viruses through Facebook and especially MSN Messenger is often a target for computer criminals. All of these attacks can however generally be avoided with simple education of one’s employees. We don’t recommended blocking the access to social networks for your employees, even though we know certain companies do this today.

NOTE: This news item was orignally posted on December 3, 2008

Since our password generator has always been free and is fairly simple software, we have now decided to release the software as open source under the so called 3-clause BSD license.

This means that if you need a password generation feature for your software, you can actually take our code and use it directly in your code without paying us a dime. Just as long as you write publicly that you are using our code.

You can read more about the BSD license on Wikipedia

The code is stored on SourceForge.Net and there is a direct link to the project here on the website

New phone number

NOTE: This news item was originally posted on October 14, 2008

After a longer period of time with irritating problems due to our telephone provider, we have now switched to a more stable solution and do not expect any issues with our phone systems in the future.

Our new phone number is +45 72207279.

NOTE: The news item was originally posted on May 3, 2008

Aconiac Password Generator

Aconiac’s tool for generating random passwords has now been released and is free to download from the product page. We encourage everyone to download the tool and generate some secure passwords for the many user accounts an average user has these days.

Right now, the application is only available for Windows XP/Vista, however we expect to have a release for Linux, BSD and Mac within the next few weeks.

NOTE: This news item was originally posted on April 26, 2008.

michaelnyeMichael Lind Mortensen is Aconiac Security Group’s Business Manager and is responsible for areas such as management, marketing and security

testing. But today, the 26th of April, is Michael’s birthday – therefore, we hereby present: “10 things you didn’t know about Business Manager Michael Lind Mortensen”

Michael…

  1. ..can’t whistle
  2. ..cried at the end of Titanic
  3. ..is getting married to Sara Lind in the summer of 2009
  4. ..voted for Martin on X-Factor
  5. ..loves The Daily Show with Jon Stewart
  6. ..eats Corn Flakes with no milk
  7. ..has a slight shark phobia – or rather all sea creatures with sharp teeth!
  8. ..got kicked in the groin by his Ninjutsu-trainer because he wouldn’t act scared
  9. ..was skiing and ran into a tree – with one leg on each side of the tree!
  10. ..once talked himself out of a ticket by criticising the system

NOTE: This news item was originally posted on April 20, 2008.

IT-Forum memberAconiac Security Group has now become an official member of IT-Forum Midtjylland.

IT-Forum Midtjylland is a knowledge-network for IT-interested companies, organisations, educational institutions and public institutions throughout the Midtjylland region in Denmark.

Through our membership, we hope to achieve an even better service for our customers and also hopefully add something positive to IT-Forum’s future events.

NOTE: This news item was originally posted on February 14, 2008.

Aconiac will be moving to new offices in InnoCamp at Katrinebjerg in Aarhus the 1st of March 2008. InnoCamp is an initiative taken by the Center for Entrepreneurship at Aarhus University. The purpose of the initiative is to form an innovative entrepreneur environment where young companies can grow and draw benefit from each other.

We look forward to being a part of the fast moving development at Katrinebjerg and to servicing our customers from our new offices.

NOTE: This news item was originally posted on February 4, 2008

After lengthy consideration, we have decided to change the company name from Zepcom to Aconiac Security Group. The name change is a result of several things, including domain name availability and a wish for change. We look forward to a bright future with Aconiac Security Group.

Finally, after several weeks of consideration, Aconiacs public blog has been created. Now you can always follow what we’re doing these days including news, announcements, scientific content, tutorials, political content, research results and much more.

Please add the blog to your RSS reader and we’ll be adding content soon.