Fallout from the Epsilon Security Breach
Security Architect, IntraLinks
POSTED ON May 6, 2011

Mushegh HakhinianAs many people know from reading the news over the last month, Epsilon, a permission-based email marketing provider, suffered a major security breach. Their clients’ customer data was exposed as a result of an unauthorized entry into Epsilon’s email system. Their customers include big brand names such as Target, Red Roof Inn, Best Buy, Chase, Marriott and Brookstone.

It’s safe to assume the people that launched this attack on Epsilon are no script kiddies that accidentally hit the jackpot. The recent breaches at Epsilon as well as RSA have proven that there are individuals or groups out there that are willing to commit significant resources to hacking and anticipate a decent return on their investment. The Epsilon breach is essentially part of a criminal business model that simplifies the attackers’ task in crafting e-mails targeted to specific people. Sadly, we can only expect that these so-called spear-phishing attempts will soar.

 
READ

Customizing Two-Factor Authentication to Protect your Information
Security Architect, IntraLinks
POSTED ON August 3, 2010

Mushegh HakhinianLast year, I wrote about the IntraLinks vision for using enhanced two-factor authentication (2FA) to protect data in a SaaS-based environment. What I covered in that blog was used as a basis for designing a customized 2FA (or strong authentication) framework for the IntraLinks platform. The most important feature of the framework is the adaptability it offers to users for their security policy requirements. The idea is that people who own the data are more likely to understand its sensitivity and level of protection required than the people who design systems. On the other hand, system designers have the necessary technical skills to implement robust protection mechanisms. Our framework allows for the optimal ‘separation of duties’ — we implement the best of breed 2FA mechanisms, and our users apply those where and when they think it makes sense.

 
READ

IntraLinks Video Discussions: Structured Team Collaboration, Search, Security and Performance
EVP, Product Development & Operations, IntraLinks
POSTED ON December 2, 2009

Fahim SiddiquiI recently sat down with the folks at VisibleGains and other members of our technology team to talk about our thoughts on structured team collaboration, as well as search and our partner Attivio. Mush Hakhinian also gives an interesting talk about security with two-factor authentication and our partner RSA, while Charlie Weiblen discusses performance enhancement and our partner Akamai.

Please click on the video below to watch.

 
READ