<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecuriTeam Blogs</title>
	<atom:link href="http://blogs.securiteam.com/index.php/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<lastBuildDate>Tue, 14 May 2013 00:44:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>REVIEW: &#8220;Security and Privacy for Microsoft Office 2010 Users&#8221;, Mitch Tulloch</title>
		<link>http://blogs.securiteam.com/index.php/archives/2116</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2116#comments</comments>
		<pubDate>Tue, 14 May 2013 00:44:09 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Book Reviews]]></category>
		<category><![CDATA[Corporate Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[OPSEC]]></category>
		<category><![CDATA[Sec Tools]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2116</guid>
		<description><![CDATA[BKSCPRO2.RVW   20121122 &#8220;Security and Privacy for Microsoft Office 2010 Users&#8221;, Mitch Tulloch, 2012, 0735668833, U$9.99 %A   Mitch Tulloch info@mtit.com www.mtit.com %C   1 Microsoft Way, Redmond, WA   98052-6399 %D   2012 %G   0735668833 %I   Microsoft Press %O   U$9.99 800-MSPRESS fax: 206-936-7329 mspinput@microsoft.com %O  http://www.amazon.com/exec/obidos/ASIN/0735668833/robsladesinterne http://www.amazon.co.uk/exec/obidos/ASIN/0735668833/robsladesinte-21 %O   http://www.amazon.ca/exec/obidos/ASIN/0735668833/robsladesin03-20 %O   Audience n- Tech 1 Writing 1 (see revfaq.htm for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://victoria.tc.ca/int-grps/books/techrev/bkscpro2.rvw" target="_blank">BKSCPRO2.RVW</a>   20121122</p>
<p>&#8220;Security and Privacy for Microsoft Office 2010 Users&#8221;, Mitch Tulloch,<br />
2012, 0735668833, U$9.99<br />
%A   Mitch Tulloch info@mtit.com <a href="http://www.mtit.com" target="_blank">www.mtit.com</a><br />
%C   1 Microsoft Way, Redmond, WA   98052-6399<br />
%D   2012<br />
%G   0735668833<br />
%I   Microsoft Press<br />
%O   U$9.99 800-MSPRESS fax: 206-936-7329 mspinput@microsoft.com<br />
%O  <a href="http://www.amazon.com/exec/obidos/ASIN/0735668833/robsladesinterne" target="_blank">http://www.amazon.com/exec/obidos/ASIN/0735668833/robsladesinterne</a><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0735668833/robsladesinte-21" target="_blank">http://www.amazon.co.uk/exec/obidos/ASIN/0735668833/robsladesinte-21</a><br />
%O   <a href="http://www.amazon.ca/exec/obidos/ASIN/0735668833/robsladesin03-20" target="_blank">http://www.amazon.ca/exec/obidos/ASIN/0735668833/robsladesin03-20</a><br />
%O   Audience n- Tech 1 Writing 1 (see <a href="http://victoria.tc.ca/techrev/revfaq.htm" target="_blank">revfaq.htm</a> for explanation)<br />
%P   100 p.<br />
%T   &#8220;Security and Privacy for Microsoft Office 2010 Users&#8221;</p>
<p>Reducing the complex jargon in the introduction to its simplest terms, this book is intended to allow anyone who uses the Microsoft Office 2010 suite, or the online Office 365, to effectively employ the security functions built into the software.  Chapter one purports to present the &#8220;why&#8221; of security, but does a very poor job of it.  Company policy is presented as a kind of threat to the employee, and this does nothing to ameliorate the all-too-common perception that security is there simply to make life easier for the IT department, while it makes work harder for everyone else.</p>
<p>Chapter two examines the first security function, called &#8220;Protected View.&#8221;  The text addresses issues of whether or not you can trust a document created by someone else, and mentions trusted locations.  (Trusted locations seem simply to be defined as a specified directory on your hard drive, and the text does not discuss whether merely moving an unknown document into this directory will magically render it trustworthy.  Also, the reader is told how to set a trusted location, but not an area for designating untrusted files.)  Supposedly &#8220;Protected View&#8221; will automatically restrict access to, and danger from, documents you receive from unknown sources.  Unfortunately, having used Microsoft Office 2010 for a couple of years, and having received, in that time, hundreds of documents via email and from Web sources, I&#8217;ve never yet seen &#8220;Protected View,&#8221; so I&#8217;m not sure how far I can trust what the author is telling me.  (In addition, Tulloch&#8217;s discussion of viruses had numerous errors: Concept came along five years before Melissa, and some of the functions he attributes to Melissa are, in fact, from the CHRISTMA exec over a decade earlier.)</p>
<p>Preparation of policy is promised in chapter three, but this isn&#8217;t what most managers or security professionals would think of as policy: it is just the provision of a function for change detection or digital signatures.  It also becomes obvious, at this point, that Microsoft Office 2010 and Office 365 can have significantly different operations.  The material is quite confusing with references to a great many programs which are not part of the two (2010 and 365) MS Office suites.</p>
<p>Chapter four notes the possibility of encryption with a password, but the discussion of rights is unclear, and a number of steps are missing.</p>
<p>An appendix lists pointers to a number of references at Microsoft&#8217;s Website.</p>
<p>The utility of this work is compromised by the fact that it provides instructions for functions, but doesn&#8217;t really explain how, and in what situations, the functions can assist and protect the user.  Any employee using Microsoft Office will be able to access the operations, but without understanding the concepts they won&#8217;t be able to take advantage of what protection they offer.</p>
<p>copyright, Robert M. Slade   2012     <a href="http://groups.yahoo.com/group/techbooks/message/901" target="_blank">BKSCPRO2.RVW</a>   20121122</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2116&amp;title=REVIEW%3A%20%E2%80%9CSecurity%20and%20Privacy%20for%20Microsoft%20Office%202010%20Users%E2%80%9D%2C%20Mitch%20Tulloch" id="wpa2a_2"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2116/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake security can hurt you &#8230;</title>
		<link>http://blogs.securiteam.com/index.php/archives/2112</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2112#comments</comments>
		<pubDate>Sun, 12 May 2013 00:45:53 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2112</guid>
		<description><![CDATA[&#8220;Fraudster James McCormick has been jailed for 10 years for selling fake bomb detectors. &#8230; One invoice showed sales of £38m over three years to Iraq, the judge said.&#8221; http://www.bbc.co.uk/news/uk-22380368 Closer to our technical field, we know about the pure fraud of fake AV, of course.  And there are plenty of companies out there selling [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Fraudster James McCormick has been jailed for 10 years for selling fake bomb detectors. &#8230; One invoice showed sales of £38m over three years to Iraq, the judge said.&#8221;</p>
<p><a href="http://www.bbc.co.uk/news/uk-22380368" target="_blank">http://www.bbc.co.uk/news/uk-22380368</a></p>
<p>Closer to our technical field, we know about the pure fraud of fake AV, of course.  And there are plenty of companies out there selling shoddy products.  But there are also the &#8220;consultants&#8221; out there doing desultory work, and spending more time on building a client base than doing any research or analysis.  (I recently ran into a monitoring and surveillance &#8220;expert&#8221; who had no idea about the problems with IP-connected video cameras.)  Some of them even hold CISSP certificates.</p>
<p>This is basically the whole reason behind the certificate: to have a standard that allows people to expect a minimal level of competence.  It&#8217;s not perfect, never will be, and there are other attempts (so far seemingly even less successful) at doing the same thing.  We need to assist the process, where we can, even if we don&#8217;t feel like pushing the ISC2 &#8220;brand.&#8221;</p>
<p>Do what you can to help.  Even if it is just pointing out fixable errors.</p>
<p>(When was the last time you submitted a question to the exam committee?)</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2112&amp;title=Fake%20security%20can%20hurt%20you%20%E2%80%A6" id="wpa2a_4"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2112/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why BC holds the record for &#8220;World&#8217;s Weirdest Politicians&#8221;</title>
		<link>http://blogs.securiteam.com/index.php/archives/2107</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2107#comments</comments>
		<pubDate>Thu, 09 May 2013 16:25:40 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[OT]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2107</guid>
		<description><![CDATA[Whenever political pundits get together, they all start the competition for &#8220;our politicians are more corrupt/venal/just plain weird than yours.&#8221;  Whenever anyone from BC enters the fray, everyone else concedes. Herewith our latest saga. The ruling &#8220;Today&#8217;s BC Liberal Party&#8221; is finding itself polling behind the NDP.  (Do not let the word &#8220;liberal&#8221; in the [...]]]></description>
			<content:encoded><![CDATA[<p>Whenever political pundits get together, they all start the competition for &#8220;our politicians are more corrupt/venal/just plain weird than yours.&#8221;  Whenever anyone from BC enters the fray, everyone else concedes.</p>
<p><a href="http://www.vancouversun.com/technology/Liberals+refuse+remove+YouTube+video+attacking+Adrian+with+video/8355209/story.html" target="_blank">Herewith our latest saga</a>.</p>
<p>The ruling &#8220;Today&#8217;s BC Liberal Party&#8221; is finding itself polling behind the NDP.  (Do not let the word &#8220;liberal&#8221; in the party name fool you.  Whereas pretty much every other liberal party would be centre-left, the BC Liberals are, politically, somewhat to the right of Attila the Hun.)  The liberals are runing attack ads stating that, twelve years ago, the leader of the NDP backdated a memo.</p>
<p>(No, I&#8217;m not making this up.)</p>
<p>The Liberals have just released another version of the same attack ad, this time using a snippet of footage from the recent leaders debate.  Trouble is, the media consortium that ran the debate has copyright on the video of the debate, and all parties agreed that none of the material would be used for political purposes.</p>
<p>The Liberals, called on their use of the video, have refused to take it down.</p>
<p>(How old do you have to be to understand the meaning of &#8220;copyright infringement?&#8221;)</p>
<p>(I am eagerly awaiting the next installment of this story.  I assume the lawyers paid for by Today&#8217;s BC Liberals [or possibly by <a href="http://www.cbc.ca/news/canada/british-columbia/story/2013/05/09/bc-liberals-campaign-meetings.html" target="_blank">public money: that's happened before</a>] will argue the provisions of &#8220;<a href="http://cyberlaw.stanford.edu/blog/2007/03/fairy-use-tale" target="_blank">fair use</a>,&#8221; and claim that the attack ads are commentary, or even educational &#8230;)</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2107&amp;title=Why%20BC%20holds%20the%20record%20for%20%E2%80%9CWorld%E2%80%99s%20Weirdest%20Politicians%E2%80%9D" id="wpa2a_6"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2107/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>REVIEW: &#8220;World War Hack&#8221;, Ethan Bull/Tsubasa Yozora</title>
		<link>http://blogs.securiteam.com/index.php/archives/2104</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2104#comments</comments>
		<pubDate>Fri, 03 May 2013 22:54:24 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Book Reviews]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2104</guid>
		<description><![CDATA[BKWWHACK.RVW   20121009 &#8220;World War Hack&#8221;, Ethan Bull/Tsubasa Yozora, 2012, 978-0-9833670-8-6 %A   Ethan Bull %A   Tsubasa Yozora %C   9400 N. MacArthur Blvd., Suite 124-215, Irving, TX   75063 %D   2012 %E   Gwendolyn Borgen %G   978-0-9833670-8-6 0-9833670-8-6 %I   Viper Entertainment Inc./Viper Comics %O   U$7.95 wyatt@worldwarhack.com www.worldwarhack.com %O  http://www.amazon.com/exec/obidos/ASIN/0983367086/robsladesinterne http://www.amazon.co.uk/exec/obidos/ASIN/0983367086/robsladesinte-21 %O   http://www.amazon.ca/exec/obidos/ASIN/0983367086/robsladesin03-20 %O   Audience n- Tech 1 Writing 1 [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://victoria.tc.ca/int-grps/books/techrev/bkwwhack.rvw" target="_blank">BKWWHACK.RVW</a>   20121009</p>
<p>&#8220;World War Hack&#8221;, Ethan Bull/Tsubasa Yozora, 2012, 978-0-9833670-8-6<br />
%A   Ethan Bull<br />
%A   Tsubasa Yozora<br />
%C   9400 N. MacArthur Blvd., Suite 124-215, Irving, TX   75063<br />
%D   2012<br />
%E   Gwendolyn Borgen<br />
%G   978-0-9833670-8-6 0-9833670-8-6<br />
%I   Viper Entertainment Inc./Viper Comics<br />
%O   U$7.95 wyatt@worldwarhack.com <a href="http://www.worldwarhack.com" target="_blank">www.worldwarhack.com</a><br />
%O  <a href="http://www.amazon.com/exec/obidos/ASIN/0983367086/robsladesinterne" target="_blank">http://www.amazon.com/exec/obidos/ASIN/0983367086/robsladesinterne</a><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0983367086/robsladesinte-21" target="_blank">http://www.amazon.co.uk/exec/obidos/ASIN/0983367086/robsladesinte-21</a><br />
%O   <a href="http://www.amazon.ca/exec/obidos/ASIN/0983367086/robsladesin03-20" target="_blank">http://www.amazon.ca/exec/obidos/ASIN/0983367086/robsladesin03-20</a><br />
%O   Audience n- Tech 1 Writing 1 (see <a href="http://victoria.tc.ca/techrev/revfaq.htm" target="_blank">revfaq.htm</a> for explanation)<br />
%P   72 p.<br />
%T   &#8220;World War Hack&#8221;</p>
<p>Someone (eventually we find out they are backed by the Chinese) has hacked into the United States military and government control systems.  Fortunately, despite being in complete control and untraceable, all they seem to want to do is make one military drone act up.</p>
<p>The US government immediately swings into action, and sponsors a hacking contest, to try and identify suitably talented young geniuses (genii?) to find out what is going on.</p>
<p>It&#8217;s hard to follow what is going on, since the artwork makes it difficult to differentiate between characters.  There are young people with bad haircuts, and there are other people with suits.  Some people are female.  After that, it gets hard to tell who&#8217;s who.  One of the hackers is a government agent, another one has a criminal record but seems to be a son of a suited government agent.</p>
<p>Some of the technical and hacking activity is somewhat realistic, but other aspects are bizarre, and betray a complete lack of understanding of basic technology.  For example, at different times a programming language gets &#8220;hacked&#8221; (in the sense of breaking into it), and at another time a government administrator can&#8217;t tell what computer language has been used to write a specific program.  In the real world of programming and hacking neither of these scenarios makes any sense.  Absent Ken Thompson&#8217;s famous speech nobody &#8220;hacks&#8221; a language, and generally nobody cares what language has been used to write a utility once it is operating.  (By the way, no programmer ever said LISP was a concise language, and there is no way that even a &#8220;skin&#8221; on top of LISP would look like C.)  At another point two devices &#8220;piggyback&#8221; on the same IP address, which simply does not work in networking terms.</p>
<p>There are aspects of this story that are realistic.  One is that, if you are not careful with your systems, someone can penetrate them and mess with you.  If there are any other useful factors in this story, I can&#8217;t think of them offhand.</p>
<p>(As usual, the draft of this review was submitted to the author/publisher for comment prior to publication.  I often get rude email in response, sometimes threats of physical harm, and once even a death threat.  [Yes, really.]  In this case the publisher has threatened unspecified legal action &#8220;to protect the copyright on our work.&#8221;  I would be interested to see the publisher&#8217;s reaction to counsel explaining the &#8220;commentary&#8221; aspect of the concept of &#8220;fair use.&#8221;)</p>
<p>copyright, Robert M. Slade   2012     <a href="http://groups.yahoo.com/group/techbooks/message/900" target="_blank">BKWWHACK.RVW</a>   20121009</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2104&amp;title=REVIEW%3A%20%E2%80%9CWorld%20War%20Hack%E2%80%9D%2C%20Ethan%20Bull%2FTsubasa%20Yozora" id="wpa2a_8"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2104/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password reset questions</title>
		<link>http://blogs.securiteam.com/index.php/archives/2100</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2100#comments</comments>
		<pubDate>Sun, 14 Apr 2013 01:20:30 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Corporate Security]]></category>
		<category><![CDATA[Culture]]></category>
		<category><![CDATA[OPSEC]]></category>
		<category><![CDATA[Sec Tools]]></category>
		<category><![CDATA[Tips & Tricks]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2100</guid>
		<description><![CDATA[Recently therewas some discussion about &#8220;self-service&#8221; password resets.  The standard option, of course, is to have some sort of &#8220;secret question&#8221; that the true account holder should be able to answer.  You know: super-secret stuff like your pet&#8217;s name.  (Yes, Paris Hilton, I&#8217;m talking about you.) The discussion was more detailed, turning to policy and [...]]]></description>
			<content:encoded><![CDATA[<p>Recently therewas some discussion about &#8220;self-service&#8221; password resets.  The standard option, of course, is to have some sort of &#8220;secret question&#8221; that the true account holder should be able to answer.  You know: super-secret stuff like your pet&#8217;s name.  (Yes, Paris Hilton, I&#8217;m talking about you.)</p>
<p>The discussion was more detailed, turning to policy and options, and asked whether you should turn off &#8220;custom&#8221; questions, and stick to a list of prepared questions.</p>
<p>I would <em><strong>definitely</strong></em> allow custom questions.  The standard lists never seem to give me options that I can both a) remember, and b) that wouldn&#8217;t be immediately obvious to anyone who was able to find out some minimal information about me.</p>
<p>If I can make up my own question, I can ask myself what my favourite burial option would be.  The answer, &#8220;encryption,&#8221; is something I will remember to my dying day, and nobody else is ever going to guess.  (Well, those who have read the &#8220;<a href="http://store.elsevier.com/Dictionary-of-Information-Security/Robert-Slade/isbn-9781597491150/" target="_blank">Dictionary of Information Security</a>&#8221; might guess that one, so I guess I won&#8217;t actually use it.)</p>
<p>Go ahead: try and guess what is the only pain reliever that works for me.</p>
<p>What sits under my desk and keeps the computers running in the case of a power failure?</p>
<p>What is Gloria&#8217;s favourite ice cream flavour?</p>
<p>Finish the following sentence: Don&#8217;t treat Rob as your _______ ___.  (This is a two-factor authentication: you also have to fill in the standard response to that statement.)</p>
<p>The thing is, all of these oddball questions have special meaning for Gloria and I, but for very few other people in the world.  They rely on mistakes or quirks that have become &#8220;family phrases.&#8221;  For example, what do you need before bed to get to sleep?  Answer: &#8220;warum melek,&#8221; coming from an elderly lady of our acquaintance from a northern European background.</p>
<p>Yeah, I like &#8220;custom questions&#8221; a lot.</p>
<p>(OK, yes, you do have to do a bit of security awareness training to indicate that &#8220;who is my sweetie poo&#8221; may not be as secret as some people seem to think &#8230;)</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2100&amp;title=Password%20reset%20questions" id="wpa2a_10"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2100/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>&#8220;New&#8221; ideas about distributed computing?</title>
		<link>http://blogs.securiteam.com/index.php/archives/2097</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2097#comments</comments>
		<pubDate>Tue, 26 Mar 2013 18:02:18 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Culture]]></category>
		<category><![CDATA[OT]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2097</guid>
		<description><![CDATA[The CEO of BitTorrent thinks we should think about using distributed computing to deal with upgrade issues over the Internet. It sounds like a good idea.  So good, that you wonder why someone hasn&#8217;t thought of it before.  Well, surprise, surprise (unless you know Slade&#8217;s Law of Computer History), someone has.  How about Shoch and [...]]]></description>
			<content:encoded><![CDATA[<p>The CEO of BitTorrent thinks we should think about <a href="http://gigaom.com/2013/03/25/is-there-a-better-way-to-upgrade-the-internet-bittorrents-ceo-says-there-is/" target="_blank">using distributed computing to deal with upgrade issues over the Internet</a>.</p>
<p>It sounds like a good idea.  So good, that you wonder why someone hasn&#8217;t thought of it before.  Well, surprise, surprise (unless you know <a href="http://blogs.securiteam.com/index.php/archives/1182" target="_blank">Slade&#8217;s Law of Computer History</a>), someone has.  How about Shoch and Hupp, who worked on the idea at Xerox PARC in the late 70s, and <a href="http://dl.acm.org/citation.cfm?id=358453.358455" target="_blank">reported on it in 1980 and 1982</a>?  Or Fred Cohen, who was quite vocal about using &#8220;good&#8221; viruses in the late 80s, and <a href="http://victoria.tc.ca/int-grps/books/techrev/bkitsalv.rvw" target="_blank">mentioned it in one of his earlier popular books</a>?  Or Vesselin Bontchev, who, in the 90s, gave a <a href="http://www.people.frisk-software.com/~bontchev/papers/goodvir.html" target="_blank">detailed outline of what you have to do to make it work</a> &#8230;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2097&amp;title=%E2%80%9CNew%E2%80%9D%20ideas%20about%20distributed%20computing%3F" id="wpa2a_12"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2097/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>S. Korea Cyber Attack Crashes Navigation Devices. Time to fuzz your GPS?</title>
		<link>http://blogs.securiteam.com/index.php/archives/2089</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2089#comments</comments>
		<pubDate>Thu, 21 Mar 2013 05:41:05 +0000</pubDate>
		<dc:creator>Aviram</dc:creator>
				<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Corporate Security]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Fuzzing]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[OPSEC]]></category>
		<category><![CDATA[Sec Tools]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2089</guid>
		<description><![CDATA[South Korea suffered a major cyber attack yesterday. The origin of the attack seems to be China at the moment, but that is far from being definite. I happened to be in one of the (several) cyber security operation centers, by pure coincidence. I had a chance to see events unravel in real time. Several [...]]]></description>
			<content:encoded><![CDATA[<p>South Korea suffered a major cyber attack yesterday. The origin of the attack seems to be China at the moment, but that is far from being definite.</p>
<p>I happened to be in one of the (several) cyber security operation centers, by pure coincidence. I had a chance to see events unravel in real time. Several banks have been hit (including the very large shinhan bank) and a few broadcasting channels.</p>
<p>The damage is hard to assess, since it&#8217;s now in everyone&#8217;s advantage to blame the cyber attack on anything from a system crash to the coffee machine running out of capsules. Budget and political moves will dominate most of the data that will be released in the next few days.<br />
It&#8217;s clear, however, that the damage substantial. I reached out to a few friends in technical positions at various MSPs and most had a sleepless night. They&#8217;ve been hit hard.</p>
<p>The most interesting part of this incident, in my opinion, was a report on car GPS crashing while the attack was taking place. I haven&#8217;t seen a news report about that yet, and I couldn&#8217;t personally verify it (as I mentioned, I was stationary at the time, watching the frantic cyber-security team getting a handle on a difficult situation) but this is making rounds in security forums and a couple of friends confirmed to me that their car navigation system crashed and had to be restarted, at the exact time the attack was taking place.</p>
<p>The most likely explanation is that the broadcasting companies, who send <a href="http://en.wikipedia.org/wiki/TPEG">TPEG</a> data to the GPS devices (almost every car in Korea has a GPS device, almost all get real-time updates via TPEG), had sent malformed data which caused the devices to crash. This data could have been just a result of a domino effect from the networks crashing, or it could have been a very sophisticated proof-of-concept by the attacker to see if they can create a distruption. Traffic in Seoul is bad even on a normal day; without GPS devices it can be a nightmare.</p>
<p>Which brings up an interesting point about fuzzing network devices. TPEG fuzzers have been available for a while now (<a href="http://www.beyondsecurity.com/beSTORM">beSTORM</a> has a TPEG module, and you can easily write your own TPEG fuzzer). The difficult part is getting the GPS device to communicate with the fuzzing generator; this is something the GPS developer can do (but probably won&#8217;t) but it is also possible for a government entity to do the necessary configuration to make that happen, given the proper resources or simply by forcing the vendors to cooperate.</p>
<p>The choice of the attacker to bring down the broadcasting networks might be deliberate: other than knocking TV and radio off the air (an obvious advantage in a pre-attack strike) the broadcasting networks control many devices who rely on their data. Forcing them to send malformed data to crash a variety of devices can have interesting implications. If I was a little more naive, I would predict that this will push governments around the world to focus more on fuzzing to discover these kind of vulnerabilities before they see their adversaries exploit them. But in the world we live in, they will instead throw around the phrase &#8220;APT&#8221; and buy more &#8220;APT detection products&#8221; (an oximoron if I&#8217;ve ever heard one). Thank god for APT, the greatest job saving invention since bloodletting.</p>
<p>An detailed analysis of the attack here:<a href="http://training.nshc.net/KOR/Document/virus/20130321_320CyberTerrorIncidentResponseReportbyRedAlert(EN).pdf"></p>
<p>http://training.nshc.net/KOR/Document/virus/20130321_320CyberTerrorIncidentResponseReportbyRedAlert(EN).pdf</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2089&amp;title=S.%20Korea%20Cyber%20Attack%20Crashes%20Navigation%20Devices.%20Time%20to%20fuzz%20your%20GPS%3F" id="wpa2a_14"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2089/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Users are smarter than we give them credit for</title>
		<link>http://blogs.securiteam.com/index.php/archives/2081</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2081#comments</comments>
		<pubDate>Wed, 27 Feb 2013 04:18:56 +0000</pubDate>
		<dc:creator>dmitryc</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2081</guid>
		<description><![CDATA[So, my boss had asked me last week to read the Mandiant report and see how these Chinese APT1 attacks could be detected on a network both during and after an attack. After reading the report, I was pretty saddened by just how little has been done in the last 20 years in Infosec. The [...]]]></description>
			<content:encoded><![CDATA[<p>So, my boss had asked me last week to read the Mandiant report and see how these Chinese APT1 attacks could be detected on a network both during and after an attack.  After reading the report, I was pretty saddened by just how little has been done in the last 20 years in Infosec.  The tactics and protocols used to steal data are old (decades old) and stale.  My initial reaction was, and is, that user&#8217;s are still not being properly educated AND held responsible for their actions.  We&#8217;re letting the users off too easily!  Corporations are still trying to solve a people problem with software or appliances.  </p>
<p>Take a look at the top 15 Security startups of 2013 (<a href="http://www.businessinsider.com/15-most-important-security-startups-2013-1?op=1">http://www.businessinsider.com/15-most-important-security-startups-2013-1?op=1</a>).  Now, look at how many of these software products ASSUME that the user will do the wrong thing and click on a link or an attachment.  We have sandbox technology so that when the user downloads the malware, software can fix it (remember Pelican SafeTNet from late 90&#8242;s early 2000&#8242;s).  We have software that steers employees away from bad websites (how does this work?  A list of bad sites won&#8217;t work&#8230;downloading the page and running static checks won&#8217;t work&#8230;I dunno&#8230;would be interesting to hear more, but I digress).</p>
<p>Look, if your kids were prone to starting fires while cooking food, is the fix to create a million dollar stove that auto-senses when the heat is too high or when the smell of burnt food is in the air and automatically shuts down?  Or, is the fix to teach your kids the proper way to use the stove?  If I was a Corporate Security officer, I would make user education a top priority.  I would even be willing to bring in a company that specialized in user security education (train the trainer type stuff).  That would be money well spent.  Every new user gets a class in computer security complete with a hands-on lab, test, and an Acceptable Use policy that they sign after completion.   Existing users have to &#8220;re-certify&#8221; every year when they get a performance review.  </p>
<p>Next, hold the user accountable for their actions after completing said training.  In this day and age, a compromised computer inside the network is a license to steal.  Having a computer with Internet access is a serious responsibility.  If you mess up and do what you were trained NOT to do, then you are punished.  Keep messing up and you get your pink slip.  The user&#8217;s aren&#8217;t as stupid as we make them out to be.  If their actions impact their bottom line, they will act accordingly.  If we don&#8217;t hold the user responsible, why do they have any reason to change their behavior?</p>
<p>And, on a related tangent, maybe I&#8217;m just too old school but I don&#8217;t understand why a company would allow their employees (paid to do a Corporate-related job) to surf social media, p2p, job-search sites, dating sites, web-based email, etc. etc.    </p>
<p>smh,</p>
<p>!Dmitry </p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2081&amp;title=The%20Users%20are%20smarter%20than%20we%20give%20them%20credit%20for" id="wpa2a_16"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2081/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Western society is WEIRD [1]</title>
		<link>http://blogs.securiteam.com/index.php/archives/2083</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2083#comments</comments>
		<pubDate>Tue, 26 Feb 2013 02:49:36 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Culture]]></category>
		<category><![CDATA[Insider Threat]]></category>
		<category><![CDATA[OPSEC]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2083</guid>
		<description><![CDATA[(We have the OT indicator to say that something is off topic.  This isn&#8217;t, because ethics and sociology is part of our profession, but it is a fairly narrow area of interest for most.  We don&#8217;t have a subject-line indicator for that  This article, and the associated paper, are extremely interesting in many respects.  The [...]]]></description>
			<content:encoded><![CDATA[<p>(We have the OT indicator to say that something is off topic.  This isn&#8217;t, because ethics and sociology is part of our profession, but it is a fairly narrow area of interest for most.  We don&#8217;t have a subject-line indicator for that  <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>This <a href="http://www.psmag.com/magazines/pacific-standard-cover-story/joe-henrich-weird-ultimatum-game-shaking-up-psychology-economics-53135" target="_blank">article</a>, and the associated <a href="http://www2.psych.ubc.ca/~henrich/pdfs/Weird_People_BBS_final02.pdf" target="_blank">paper</a>, are extremely interesting in many respects.  The challenge to whole fields of social factors (which are vital to proper management of security) has to be addressed.  We are undoubtedly designing systems based on a fundamentally flawed understanding of the one constant factor in our systems: people.</p>
<p>(I suppose that, as long as the only people we interact with are WEIRD [1] westerners, we are OK.  Maybe this is why we are flipping out at the thought of China?)</p>
<p>(I was particularly interested in the effects of culture on actual physical perception, which we have been taught is hard wired.)</p>
<p>[1] &#8211; WEIRD, in the context of the paper, stands for Western, Educated, Industrialized, Rich, and Democratic societies</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2083&amp;title=Western%20society%20is%20WEIRD%20%5B1%5D" id="wpa2a_18"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2083/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Read this book. If you have anything to do with security, read this book.</title>
		<link>http://blogs.securiteam.com/index.php/archives/2076</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2076#comments</comments>
		<pubDate>Mon, 04 Feb 2013 23:28:17 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Ask the Expert]]></category>
		<category><![CDATA[Book Reviews]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Corporate Security]]></category>
		<category><![CDATA[OPSEC]]></category>
		<category><![CDATA[Sec Tools]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2076</guid>
		<description><![CDATA[I have been reviewing security books for over twenty years now.  When I think of how few are really worthwhile that gets depressing. However, Ross Anderson is always worth reading.  And when Ross Anderson first published &#8220;Security Engineering&#8221; I was delighted to be able to tell everyone that it was a worthwhile read.  If you [...]]]></description>
			<content:encoded><![CDATA[<p>I have been reviewing security books for over twenty years now.  When I think of how few are really worthwhile that gets depressing.</p>
<p>However, Ross Anderson is always worth reading.  And when Ross Anderson first published &#8220;Security Engineering&#8221; I was delighted to be able to tell everyone that it was a worthwhile read.  If you are, in any way, interested in, or working in, the field of security, there is something there for you.  Probably an awful lot.</p>
<p>When Ross Anderson made the first edition available online, for free, and then published the second edition, I was delighted to be able to <a href="http://victoria.tc.ca/int-grps/books/techrev/bkseceng.rvw" target="_blank">tell everyone that they should buy the second edition</a>, but, if they didn&#8217;t trust me, they should read the first edition free, and then buy the second edition because it was even better.</p>
<p>Now Ross has made the <a href="http://www.cl.cam.ac.uk/~rja14/book.html" target="_blank">second edition available, online, for free</a>.</p>
<p>Everyone should read it, if they haven&#8217;t already done so.</p>
<p>(I am eagerly awaiting the third edition  <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2076&amp;title=Read%20this%20book.%20If%20you%20have%20anything%20to%20do%20with%20security%2C%20read%20this%20book." id="wpa2a_20"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2076/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>REVIEW: Identity Theft Manual: Practical Tips, Legal Hints, and Other Secrets Revealed, Jack Nuern</title>
		<link>http://blogs.securiteam.com/index.php/archives/2069</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2069#comments</comments>
		<pubDate>Sat, 19 Jan 2013 19:45:14 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Book Reviews]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Tips & Tricks]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2069</guid>
		<description><![CDATA[BKIDTHMA.RVW   20120831 &#8220;Identity Theft Manual: Practical Tips, Legal Hints, and Other Secrets Revealed&#8221;, Jack Nuern, 2012 %A   Jack Nuern http://www.idtheftadvocates.com %C   4901 W. 136 St., Leawood, KS, USA   66224 %D   2012 %G   ASIN: B0088IG92E %I   Roadmap Productions %O   fax 866-594-2771 %O  http://www.amazon.com/exec/obidos/ASIN/B0088IG92E/robsladesinterne http://www.amazon.co.uk/exec/obidos/ASIN/B0088IG92E/robsladesinte-21 %O   http://www.amazon.ca/exec/obidos/ASIN/B0088IG92E/robsladesin03-20 %O   Audience n- Tech 1 Writing 1 (see revfaq.htm for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://victoria.tc.ca/int-grps/books/techrev/bkidthma.rvw" target="_blank">BKIDTHMA.RVW</a>   20120831</p>
<p>&#8220;Identity Theft Manual: Practical Tips, Legal Hints, and Other Secrets Revealed&#8221;, Jack Nuern, 2012<br />
%A   Jack Nuern <a href="http://www.idtheftadvocates.com" target="_blank">http://www.idtheftadvocates.com</a><br />
%C   4901 W. 136 St., Leawood, KS, USA   66224<br />
%D   2012<br />
%G   ASIN: B0088IG92E<br />
%I   Roadmap Productions<br />
%O   fax 866-594-2771<br />
%O  <a href="http://www.amazon.com/exec/obidos/ASIN/B0088IG92E/robsladesinterne" target="_blank">http://www.amazon.com/exec/obidos/ASIN/B0088IG92E/robsladesinterne</a><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/B0088IG92E/robsladesinte-21" target="_blank">http://www.amazon.co.uk/exec/obidos/ASIN/B0088IG92E/robsladesinte-21</a><br />
%O   <a href="http://www.amazon.ca/exec/obidos/ASIN/B0088IG92E/robsladesin03-20" target="_blank">http://www.amazon.ca/exec/obidos/ASIN/B0088IG92E/robsladesin03-20</a><br />
%O   Audience n- Tech 1 Writing 1 (see <a href="http://victoria.tc.ca/techrev/revfaq.htm" target="_blank">revfaq.htm</a> for explanation)<br />
%P   128 p.<br />
%T   &#8220;Identity Theft Manual: Practical Tips, Legal Hints, and Other Secrets Revealed&#8221;</p>
<p>Despite the implications of the title, this is not a primer for performing identity theft, but a guide to preventing and recovering from it.  The information, unfortunately, is fairly pedestrian, and most of it could be obtained from any magazine article on the topic.</p>
<p>Chapter one is a (very) basic introduction to identity theft, with a rather odd emphasis on the use of medical information.  Methods of identity theft are described in chapter two.  Unfortunately, this is where the book starts to show signs of serious disorganization, and some of the material is more sensational than helpful.  Chapter three lists some steps you can take to attempt to prevent identity theft.  The suggestions are the usual standards of not giving out any information to anyone, and the book tacitly admits that protection is not assured.</p>
<p>Chapter four gets to the real intent of the work: actions to take when your identity has been stolen and misused.  There is a great deal of useful content at this point, limited by two factors.  One is that everything discussed is restricted to institutions in the United States.  The other is that there is almost no discussion of what the entities mentioned can do for you or what they can&#8217;t or won&#8217;t.</p>
<p>As one could expect from a book written by a law firm, chapter five addresses the liability that the victim of identity theft faces.  The answer, unsurprisingly, is &#8220;it depends,&#8221; backed up with a few stories.  (Pardon me: &#8220;case studies.&#8221;)</p>
<p>There are some appendices (called, predictably, &#8220;Exhibits&#8221;).  Again, most of these will only be of use to those in the United States, and some, sections of related laws, will be of very little use to most.  There is a victim complaint and affidavit form which would probably be very helpful to most identity theft victims, reminding them of information to be collected and presented to firms and authorities.</p>
<p>The book is not particularly well written, and could certainly use some better structure and organization.  However, within its limits, it can be of use to those who are in the situation, and who frequently have nowhere to turn.  As the book notes, authorities are often unhelpful and take limited interest in identity theft cases.   And, as the book also (frequently) notes, the book is cheaper than hiring a law firm.</p>
<p>copyright, Robert M. Slade   2012     <a href="http://groups.yahoo.com/group/techbooks/message/897" target="_blank">BKIDTHMA.RVW</a>   20120831</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2069&amp;title=REVIEW%3A%20Identity%20Theft%20Manual%3A%20Practical%20Tips%2C%20Legal%20Hints%2C%20and%20Other%20Secrets%20Revealed%2C%20Jack%20Nuern" id="wpa2a_22"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2069/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Memory lane &#8230;</title>
		<link>http://blogs.securiteam.com/index.php/archives/2066</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2066#comments</comments>
		<pubDate>Fri, 18 Jan 2013 00:12:38 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Funny]]></category>
		<category><![CDATA[OT]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2066</guid>
		<description><![CDATA[I ordered a new computer before Christmas, and there have been delays getting it.  Today the shop called and said that the one I ordered (with 4 Gigs of RAM) was still short, but they did have one with 6 Gigs, if I was willing to pay an extra ten bucks.  So I said fine. [...]]]></description>
			<content:encoded><![CDATA[<p>I ordered a new computer before Christmas, and there have been delays getting it.  Today the shop called and said that the one I ordered (with 4 Gigs of RAM) was still short, but they did have one with 6 Gigs, if I was willing to pay an extra ten bucks.  So I said fine.</p>
<p>Got off the phone and told Gloria about it.  She asked &#8220;How many Commodores is that?&#8221; since I still have a Commodore 64 in the &#8220;computer museum&#8221; trunk.</p>
<p>32,000.  Give or take a few for rounding purposes.  For ten bucks, the equivalent memory of 32,000 Commodore 64 computers.</p>
<p>We work in a bizarre field.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2066&amp;title=Memory%20lane%20%E2%80%A6" id="wpa2a_24"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2066/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online forum rule haikus</title>
		<link>http://blogs.securiteam.com/index.php/archives/2061</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2061#comments</comments>
		<pubDate>Sat, 12 Jan 2013 23:59:51 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Culture]]></category>
		<category><![CDATA[Funny]]></category>
		<category><![CDATA[OT]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2061</guid>
		<description><![CDATA[On the CISSPforum we were discussing precepts for getting along and keeping the discussions meaningful.  Somebody started listing rules, so I started casting them as haikus.  That prompted a few more. I wondered if these were only for that group, but then realized most of them were applicable to online discussions of whatever type.  So, [...]]]></description>
			<content:encoded><![CDATA[<p>On the CISSPforum we were discussing precepts for getting along and keeping the discussions meaningful.  Somebody started listing rules, so I started casting them as haikus.  That prompted a few more.</p>
<p>I wondered if these were only for that group, but then realized most of them were applicable to online discussions of whatever type.  So, herewith:</p>
<p>&nbsp;</p>
<p>Create your own space<br />
Meaningful content only<br />
Comes to those who post.</p>
<p>Silence calls silence<br />
Lurkers don&#8217;t disturb quiet<br />
Sleep beckons as well.</p>
<p>The posts are boring?<br />
Raise topic of interest<br />
Thread starter lauded.</p>
<p>Forum like sewer:<br />
What you get out of forum<br />
Depends on input.</p>
<p>Being creative<br />
Is much better than being<br />
Tagged as complainer.</p>
<p>These are your colleagues.<br />
Why are you so much  better<br />
That they must start first?</p>
<p>The forum that is<br />
Is not what must always be.<br />
Build a better world.</p>
<p>Friday is not for<br />
Building new realities.<br />
Your colleagues would sleep.</p>
<p>&nbsp;</p>
<p>Then some other chimed in:</p>
<p><a href="http://greatergreaterwashington.org/post/7971/security-haiku/" target="_blank">I remember trust<br />
It disappeared so quickly<br />
I guess we were fools</a></p>
<p>Pointing to resource<br />
Always appreciated<br />
Who can search the whole?</p>
<p>Putting platitudes<br />
into pleasing haiku<br />
removes sting of truth</p>
<p>Now you&#8217;re getting it.<br />
Format is everything.  (Well,<br />
And maybe context  <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>friday gratitude<br />
is here at last for resting<br />
ignoring infosec</p>
<p>Friday at last! Time for<br />
Bottles of overpriced wine.<br />
Why&#8217;m I still at work???</p>
<p>Request not correct.<br />
Reformat for this thread.<br />
Please resubmit now.</p>
<p>UNSUBSCRPTION post<br />
Jangles cosmic harmonies<br />
Til balance achieved.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2061&amp;title=Online%20forum%20rule%20haikus" id="wpa2a_26"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2061/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Awareness mottoes and one-liners</title>
		<link>http://blogs.securiteam.com/index.php/archives/2054</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2054#comments</comments>
		<pubDate>Fri, 11 Jan 2013 19:39:21 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Corporate Security]]></category>
		<category><![CDATA[Culture]]></category>
		<category><![CDATA[Funny]]></category>
		<category><![CDATA[OPSEC]]></category>
		<category><![CDATA[Tips & Tricks]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2054</guid>
		<description><![CDATA[From various forums, mailing lists, discussions and other sources (many of which exist only in my febrile imagination), herewith a bit of a compilation of mottoes that can be used as part of a security awareness campaign: No-one in Africa wants to GIVE anyone their money or gold. Microsoft/Google/a Russian oil magnate/VW/BMW/etc certainly does not [...]]]></description>
			<content:encoded><![CDATA[<p>From various forums, mailing lists, discussions and other sources (many of which exist only in my febrile imagination), herewith a bit of a compilation of mottoes that can be used as part of a security awareness campaign:</p>
<p>No-one in Africa wants to GIVE anyone their money or gold.</p>
<p>Microsoft/Google/a Russian oil magnate/VW/BMW/etc certainly does not want to GIVE anyone money/a car/etc.</p>
<p>A stunning Russian blonde DOES NOT want to marry you.</p>
<p>If it sounds too good to be true, IT IS.</p>
<p>A web site, Email message, IM or tweet that tells you you need to install security software IS LYING.</p>
<p>Just because it&#8217;s in a Google search result or an &#8220;ad by Google&#8221; does NOT mean it is safe.</p>
<p>If the options seem to be &#8220;Click OK/Run/Install&#8221; or &#8220;turn off the computer&#8221;, TURN OFF THE COMPUTER.</p>
<p>Did your friend really send you that message?</p>
<p>Is your friend really as smart about computer security as you think?<br />
A. No    B. Not at all    C. Well and truly not    D. All the above</p>
<p>You didn&#8217;t win the Irish lottery.</p>
<p>Your bank doesn&#8217;t want you to change your password.</p>
<p>Don&#8217;t be Phish Phood.</p>
<p>Pwnly Phools Phall for Phishing.</p>
<p>Think, THINK every click.</p>
<p>Need extra money?  Want to work from home?  Getting a job from a spammer is NOT A GOOD IDEA!!!</p>
<p>When did you last make a backup?  Do you want to do [period of time] worth of work all over again?</p>
<p>Report the suspicious, not the strange.</p>
<p>If the bank thinks your online account has been hacked, they won&#8217;t warn you by email.</p>
<p>Being sociable doesn’t mean being totally open. Be careful what you disclose via social media.</p>
<p>If someone wants/offers to make something really easy for you, there is a way that can be used against you.</p>
<p>Hide your &#8216;cheese&#8217; (get a router).</p>
<p>A patch a day keeps hackers away (keep your OS and apps up to date).</p>
<p>Always wear a helmet (install a firewall/antivirus package).</p>
<p>The great unknown ain&#8217;t so great (only use software you can trust).</p>
<p>Use sunscreen to prevent burns (lock down your OS and apps).</p>
<p>Make 007 jealous (learn to use additional security tools).</p>
<p>&#8220;Password&#8221; is not a password (use strong passwords).</p>
<p>Keep your skeletons in the closet (protect your personal data).</p>
<p>Don&#8217;t be a dork (be smart when you&#8217;re on-line).</p>
<p>Keep your dukes up (stay informed and vigilant).</p>
<p>Infosec is like a sewer: what you get out of it, depends on what you put into it.</p>
<p>&nbsp;</p>
<p>Some are recently from the <a href="https://twitter.com/search/realtime?q=%23infosecMotherlyAdvice&amp;src=typd" target="_blank">#InfosecMotherlyAdvice</a> tag on Twitter:</p>
<p>Don&#8217;t click &#8230; it&#8217;ll get infected.</p>
<p>Don&#8217;t take cookies from strangers.</p>
<p>Idle systems are a botnet&#8217;s playground.</p>
<p>A backup in hand is worth two in the cloud.</p>
<p>While you&#8217;re connected to my network you&#8217;ll live by my firewall rule.</p>
<p>A backup a day keeps data loss away.</p>
<p>We&#8217;d better get you a bigger firewall &#8211; you&#8217;ll grow into it.</p>
<p>Close the security holes, you&#8217;re letting all our sensitive data out.</p>
<p>If your system gets compromised and crashes, don&#8217;t come emailing to me.</p>
<p>Always encrypt your data. you never know when you&#8217;ll have an accident.</p>
<p>If everybody else clicked on links in emails, would you do that too?</p>
<p>Either you&#8217;re inside the firewall, or outside the firewall! Don&#8217;t leave it open!</p>
<p>Install your patches if you want your security to grow up big and strong.</p>
<p>Don&#8217;t put that in your browser, you don&#8217;t know where it&#8217;s been.</p>
<p>Someday your bluescreen will freeze like that!</p>
<p>It&#8217;s all fun and games until someone loses sensitive data.</p>
<p>Only you can prevent Internet meltdowns.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2054&amp;title=Secure%20Awareness%20mottoes%20and%20one-liners" id="wpa2a_28"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2054/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Official (ISC)2 Guide to the CISSP CBK</title>
		<link>http://blogs.securiteam.com/index.php/archives/2048</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2048#comments</comments>
		<pubDate>Thu, 10 Jan 2013 19:12:42 +0000</pubDate>
		<dc:creator>p1</dc:creator>
				<category><![CDATA[Book Reviews]]></category>
		<category><![CDATA[Commentary]]></category>
		<category><![CDATA[OT]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2048</guid>
		<description><![CDATA[Recently, on the CISSPforum, there was some discussion of the new, third edition of the Official (ISC)2 Guide to the CISSP CBK (which, I note, is pretending to be available as an ebook for only ten bucks).  At the end of one post, one of the correspondents stated that he was &#8220;leaning towards buying the [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, on the CISSPforum, there was some discussion of the new, third edition of the Official (ISC)2 Guide to the CISSP CBK (<a href="http://www.amazon.com/exec/obidos/ASIN/146656976X/robsladesinterne" target="_blank">which, I note, is <em><strong>pretending</strong></em> to be available as an ebook for only ten bucks</a>).  At the end of one post, one of the correspondents stated that he was &#8220;leaning towards buying the new book.&#8221;</p>
<p>First, lemme say that, for those who haven&#8217;t yet got the cert, I do recommend the &#8220;Official Guide&#8221; as my first choice.  (Harris is easier to read, but does contain *lots* of errors, and I tell my seminar candidates that I refuse to answer any question that starts out &#8220;Shon Harris says &#8230;&#8221;   <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>However, on the other hand &#8230; why would anyone who <em><strong>has</strong></em> the cert buy the guide?  Of course, I am speaking from the perspective of someone who <em><strong>does</strong></em> read the source literature (and I am aware that all too many of my colleagues do not).</p>
<p>I also recall at least two seminar attendees who actually <em><strong>did</strong></em> have the cert.  Furthermore, they were consultants, and thus going on their own dime for the course.  The reason given was the same: they charged by the hour, so any time spent upgrading was time they could not charge.  Therefore, regularly attending the seminar was the fastest, and therefore, in their situation cheapest, way to ensure they were current.</p>
<p>So, yes, I can see that some people would want to get the guide as a quick check.  (In that regard, I would tend to recommend ISMH instead of the guide, but &#8230;)  But I still find it kind of odd &#8230;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2048&amp;title=Official%20%28ISC%292%20Guide%20to%20the%20CISSP%20CBK" id="wpa2a_30"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2048/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The death of AV. Yet again.</title>
		<link>http://blogs.securiteam.com/index.php/archives/2037</link>
		<comments>http://blogs.securiteam.com/index.php/archives/2037#comments</comments>
		<pubDate>Tue, 08 Jan 2013 19:31:00 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[free AV]]></category>
		<category><![CDATA[Gunter Ollman]]></category>
		<category><![CDATA[Imperva]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[VirusTotal]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=2037</guid>
		<description><![CDATA[And in other news, Gunter Ollman joins in the debate as to whether Imperva&#8217;s quasi-testing is worth citing (just about) and, with more enthusiasm, whether AV is worth paying for or even still breathing. If you haven&#8217;t come across Ollman&#8217;s writings on the topic before, it won&#8217;t surprise you that the answer is no. If [...]]]></description>
			<content:encoded><![CDATA[<p>And in other news, Gunter Ollman joins in the debate as to whether <a href="http://antimalwaretesting.wordpress.com/2013/01/04/impervavirustotal-timeline/" target="_blank">Imperva&#8217;s quasi-testing</a> is worth citing (just about) and, with more enthusiasm, whether AV is worth paying for or even still breathing. If you haven&#8217;t come across Ollman&#8217;s writings on the topic before, it won&#8217;t surprise you that <a href="http://blog.ioactive.com/2013/01/the-demise-of-desktop-antivirus.html" target="_blank">the answer is no</a>. If you haven&#8217;t, he&#8217;s thoughtfully included several other links to articles where he&#8217;s given us the benefit of his opinions.</p>
<blockquote><p>
If it’s free, never ever bothers me with popups, and I never need to know it’s there, then it’s not worth the effort uninstalling it and I guess it can stay…</p></blockquote>
<p>Ollman notes:</p>
<blockquote><p>In particular there was great annoyance that a security vendor (representing an alternative technology) used VirusTotal coverage as their basis for whether or not new malware could be detected – claiming that initial detection was only 5%.</p></blockquote>
<p>However, he doesn&#8217;t trouble himself to explain why the anti-malware industry (and VirusTotal itself) are so annoyed, or to comment on Imperva&#8217;s squirming following those criticisms. Nor does he risk exposing any methodology of his own to similar criticism, when he claims that:</p>
<blockquote><p>desktop antivirus detection typically hovers at 1-2% &#8230; For newly minted malware that is designed to target corporate victims, the rate is pretty much 0% and can remain that way for hundreds of days after the malware has been released in to the wild.</p></blockquote>
<p>Apparently he knows this from his own experience, so there&#8217;s no need to justify the percentages. And by way of distraction from this sleight of hand, he introduces &#8216;a hunchbacked Igor&#8217; whom he visualizes &#8216;bolting on an iron plate for reinforcement to the Frankenstein corpse of each antivirus product as he tries to keep it alive for just a little bit longer…&#8217; Amusing enough, I suppose, at any rate if you don&#8217;t know how hard those non-stereotypes in real anti-malware labs work at generating proactive detections for malware we haven&#8217;t seen yet and multi-layered protection. But this is about cheap laughs at the expense of an entire industry sector that Ollman regards as reaping profits that should be going to IOActive. Consider this little exchange on Twitter.</p>
<blockquote><p>
@virusbtn<br />
Imperva&#8217;s research on desktop anti-virus has stirred a fierce debate. @gollmann: bit.ly/XE76eS @dharleyatESET: bit.ly/13e1TJW</p>
<p>@gollmann<br />
@virusbtn @dharleyatESET I don&#8217;t know about &#8220;fierce&#8221;. It&#8217;s like prodding roadkill with a stick.</p></blockquote>
<p>What are we, 12 years old? Fortunately, other tweeters seem to be seeing through this juvenilia.</p>
<blockquote><p>@jarnomn<br />
@gollmann @virusbtn @dharleyatESET Again just methaphors and no data. This conversation is like trainwreck in slow motion <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p></blockquote>
<p>The comments to the blog are also notable for taking a more balanced view: Jarno succinctly points to <a href="http://Virustotal.com/about" target="_blank">VirusTotal&#8217;s own view</a> on whether its service is a realistic guide to detection performance, Kurt Wismer puts his finger unerringly on the likely bias of Ollman&#8221;s nebulous methodology, and Jay suggests that Ollman lives in a slightly different (ideal) world (though he puts a little more politely than that). But no doubt the usual crop of AV haters, Microsoft haters, Mac and Linux advocates, scammers, spammers and downright barmpots will turn up sooner or later. </p>
<p>There is, in fact, a rational debate to be held on whether AV &#8211; certainly raw AV with no multi-layering bells and whistles &#8211; <em>should</em> be on the point of extinction. The rate of detection for specialized, targeted malware like Stuxnet is indeed very low, with all-too-well-known instances of low-distribution but high-profile malware lying around undetected for years. (It helps if such malware is aimed at parts of the world where most commercial AV cannot legally reach.) And Gunter Ollman is quite capable of contributing a great deal of expertise and experience to it. But right now, it seems to me that he and Imperva&#8217;s Tal Be&#8217;ery are, for all their glee at the presumed death of anti-virus, a pair of petulantly twittering budgies trying to pass themselves off as vultures.</p>
<p><strong>David Harley<br />
AVIEN/Small Blue-Green World/Mac Virus/Anti-Malware Testing<br />
ESET Senior Research Fellow</strong></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F2037&amp;title=The%20death%20of%20AV.%20Yet%20again." id="wpa2a_32"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/2037/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
