<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: affect]]></title>
    <link>http://securityratty.com/tag/affect</link>
    <description></description>
    <pubDate>Wed, 20 Aug 2008 03:48:56 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[John Zanni Delivers Keynote at the Tier1 Hosting Transformation Summit]]></title>
      <link>http://securityratty.com/article/e6b5db3dba618f48e7fa728ff2173006</link>
      <guid>http://securityratty.com/article/e6b5db3dba618f48e7fa728ff2173006</guid>
      <description><![CDATA[As General Manager of Worldwide Hosting, John Zanni is a key guy for every Managed Service Provider delivering Microsoft based solutions. At this years Hosting Transformation Summit , John gave a...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="spla_image" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/spla-image.png" width="244" align="left" border="0"> As General Manager of Worldwide Hosting, <a href="http://www.microsoft.com/presspass/features/2008/jul08/07-29qazanni.mspx" target="_blank">John Zanni is a key guy for every Managed Service Provider</a> delivering Microsoft based solutions. At this year&#8217;s <a href="http://www.hostingtransformation.com/na/2008/" target="_blank">Hosting Transformation Summit</a>, John <a href="http://www.hostingtransformation.com/na/2008/agenda.php" target="_blank">gave a keynote</a> titled: &#8220;Leadership Perspective: Cloud Computing – is Virtualization Enough?&#8221;</p>
<p>John talked <a href="http://blogs.zdnet.com/BTL/?p=10007" target="_blank">about Microsoft’s mission</a>, his perspectives on key industry trends and market opportunity; he touched on <a href="http://www.betanews.com/article/Will_Microsofts_virtualization_spur_a_lot_more_cloud_computing/1221867502" target="_blank">Cloud Computing and Virtualization</a> and took some Q&amp;A from the audience of <a href="http://technet.microsoft.com/en-us/serviceproviders/default.aspx" target="_blank">Managed Service Provider</a> executives.</p>
<p>One of his first proclamations - Microsoft has really embraced the heterogeneous environment. Really? How in the world is Microsoft going to help convince IT line managers, or mid level managers to believe this statement? I think they have a long way to go to achieve this vision with any credibility in the marketplace.&nbsp; I do know that they are making small strides.</p>
<p>Microsoft has been widely credited with some very good blogs that are self critical and introspective. They have also been quite active in the standards boards within <a href="http://www.dmtf.org/home" target="_blank">DMTF</a> and many others such as <a href="http://www.openwsman.org/" target="_blank">Open WSMAN</a> and CIMON (<a href="http://www.openpegasus.org/" target="_blank">Open Pegasus</a>). Microsoft in February published 30,000 pages detailed technical specifications – protocol documentation for Exchange, since that time they have published another 15,000 pages. They have had over 224,000 downloads since February 21, 2008. Thus they are trying to be more open by making some of these <a href="http://www.microsoft.com/about/legal/intellectualproperty/protocols/default.mspx" target="_blank">secret sauce protocol resources</a> <a href="http://msdn.microsoft.com/openprotocols" target="_blank">directly available on the web</a>.</p>
<p>So for now, I will take a very cautious wait and see approach to this proclamation. Time will tell.</p>
<p><strong>Trends</strong></p>
<ul>
<li>Rapid growth continues
<li>Hosting Competition has a new face
<ul>
<li>Platform gorillas (amazooglesoft)
<li>Ad supported Web 2.0 hosters (Google, Facebook,) </li>
</ul>
<li>Utility Cloud Computing models are expanding to non-traditional hosting companies
<ul>
<li>Wells Fargo vSafe - hard to believe that a big bank would start to offer a SaaS offering
<li>New tools and markets digital ribbon, CohesiveIT </li>
</ul>
</li>
</ul>
<p><a href="http://mshostingsummit08.spaces.live.com/blog/cns!4308FE7290C0AF4!245.entry" target="_blank">IDC Data shows that growth of SaaS ISV’s is the biggest layer of growth</a>. The fastest growing services are complex, custom applications. IDC says this area will be bigger than the hosting area in the next 5 years. John said that <a href="http://blogs.msdn.com/ukisv/archive/2008/09/22/the-route-to-saas-and-beyond-final-seminar-places-remain-2nd-oct-08.aspx" target="_blank">Microsoft is spending a lot of time, money and energy on this right now</a>.</p>
<p>John said:</p>
<blockquote><p>“when Microsoft thinks about the building blocks that make-up the cloud, <a href="http://www.microsoft.com/virtualization/" target="_blank">virtualization is a core piece</a> of the puzzle. However you also need also identity services, Operating system with standard set of libraries to tap into… or remote storage that application developers will tap into.. Developers will consume these set of services, but you will also need a set of tools to manage your physical, virtual and geographically distributed datacenter infrastructure.” (that is where ScienceLogic comes in!!)</p>
</blockquote>
<p>He went on to say,</p>
<blockquote><p>“In some ways, virtualization enables decentralization – allows you to move from data centers, enables fast scaling out, business to move from on premise to the cloud and off again…. Automation is very important – this will help you scale your business – this is core to your future success.”</p>
</blockquote>
<p>He talked about a new breed of knowledge worker: He called them Digital Natives (compared to grey haired guys like me who are left out of this category).</p>
<p>Definition of a Digital natives? A young adult who has grown up with cellphone, web based applications, Facebook account, as their primary mode of communications.</p>
<p>John commented that we are 5 years into a 10 year journey. Only 12% of all servers in the world are virtualized today… in the next 4 years it will double to 25%. This is <a href="http://www.interopnews.com/news/vmware-ceo-maritz-addresses-virtualization-the-cloud-and-cha.html" target="_blank">the time to think through</a> how this business will affect you.</p>
<blockquote><p>‘Virtualization without good management is more dangerous than not using virtualization in the first place.” Thomas Bittman, Analyst Gartner</p>
</blockquote>
<p>Patching and provisioning nightmare – no scalable administration – sprawl chaos.</p>
<p>John posed a question to the audience: How do you partner to provide the ISV support in application development with specific market needs… partner by keeping the <a href="http://tarrysingh.blogspot.com/2008/09/microsofts-coo-on-cloud-computing.html" target="_blank">hosting to SaaS solution</a> providers up and running and provide the quality of service that their customers expect…. Complimentary services of storage and backup is a big win with a huge market-upside over the next 5 years..</p>
<p>John said that <a href="http://blogs.msdn.com/mhpta/archive/2008/04/10/microsoft-hosting-summit-2008.aspx" target="_blank">Microsoft continues</a> to make&nbsp; <a href="http://www.virtualization.info/2008/07/microsoft-bets-on-hosting-providers-to.html" target="_blank">huge investments with Managed Service Providers</a>.</p>
<ul>
<li>Investing in the <a href="http://www.microsoft.com/hosting/" target="_blank">windows hosting platform</a>
<li>Hyper V and SQL2008 GoLive program - getting beta code out to service provides to find as many bugs as early as possible.
<li><a href="http://blogs.msdn.com/stevecla01/archive/2008/09/22/explaining-software-plus-services.aspx" target="_blank">Software + Services (S+S)</a> incubation center program
<li>Partnering for <a href="http://tarrysingh.blogspot.com/2008/09/microsofts-coo-on-cloud-computing.html" target="_blank">cloud platform market offers</a>
<li>Cloud platform guidance and best practices </li>
</ul>
<p>During the Q&amp;A, David Burns from Cincinnati Bell asked the very best question… “when are you going to make it easier for the Service Provider market to <a href="http://www.virtualization.info/2008/09/microsoft-to-allow-3rd-parties-to.html" target="_blank">deal with the Microsoft Service Provider Licensing Agreement (SPLA)</a> quarterly statistics pull and change the SPLA pricing to be more efficient and creative for the new Virtualization and Cloud offerings you have talked about?&#8221;</p>
<p>John’s response: “We hear your frustrations loud and clear and are working on some new ideas for the future version of SPLA.” My interpretation – &#8220;Dear Service Providers don’t expect anything new or easier to deal with in the next 6 months!&#8221;</p>
<p>His closing remarks: &#8220;Cloud is evolving = very early stages, lots of hype, but think of how this evolution will effect your business and how you can plug into it.”</p>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:00:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service provider market">service provider market</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider executives">service provider executives</category>
      <category domain="http://securityratty.com/tag/john">john</category>
      <category domain="http://securityratty.com/tag/john zanni">john zanni</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft based solutions">microsoft based solutions</category>
      <source url="http://blog.sciencelogic.com/john-zanni-delivers-keynote-at-the-tier1-hosting-transformation-summit/09/2008">John Zanni Delivers Keynote at the Tier1 Hosting Transformation Summit</source>
    </item>
    <item>
      <title><![CDATA[Interview with Lenny Heymann, Interop General Manager]]></title>
      <link>http://securityratty.com/article/217ace76b38485c2a4f0f06d60ec758b</link>
      <guid>http://securityratty.com/article/217ace76b38485c2a4f0f06d60ec758b</guid>
      <description><![CDATA[Interop General Manager Lenny Heymann, took some time out of his very busy show schedule to talk with us at Interop New York this year
We chatted about the growth of the show and how much that growth...]]></description>
      <content:encoded><![CDATA[<p>Interop General Manager Lenny Heymann, took some time out of his very busy show schedule to talk with us at Interop New York this year.</p>
<p>We chatted about the growth of the show and how much that growth reflects the industry itself. Since the bust earlier in the decade both Interop Las Vegas and New York shows have grown year over year – not just in attendees and exhibitors but in topics covered in the conference tracks. As any of us who are in the space know, it’s a rapidly changing market and Interop strives not just to cover the latest trends but also to get ahead of them while still making sure that they are relevant.</p>
<p>The show’s mission overall has expanded beyond “just” networking to cover performance and new trends like virtualization, cloud computing and SAAS that all affect network performance. It is a mirror for the demands on the network (and network admins) and the convergence we see going on that make managing the network so complex today.</p>
<p>Responding to <a href="http://blog.sciencelogic.com/futher-comments-about-interop-and-interoperability/05/2008">criticisms about the lack of interoperability at the show</a>, Lenny says, “Our special sauce is interoperability.” And in fact the expanded mission of the show ensures that there are more interoperability issues to deal with and he invites the community to comment and share feedback on this core mission.</p>
<p>Last, we talked about InteropNet. We’ve loved our participation in it this year for a variety of reasons – from the opportunity to work with other cool vendors in an intensive and real-life/real-time environment to the true sense of camaraderie and “getting it done” that everyone shares on the InteropNet team to the wonderful atmosphere of hard work AND hard play that you have to experience to believe.</p>
<p><object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="247" height="159" id="viddler_a2342bd1"><param name="movie" value="http://www.viddler.com/simple/a2342bd1/" /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><embed src="http://www.viddler.com/simple/a2342bd1/" width="247" height="159" type="application/x-shockwave-flash" allowScriptAccess="always" allowFullScreen="true" name="viddler_a2342bd1" ></embed></object></p>
<p>We talked with Lenny about how he measures InteropNet “success” and the answer was illuminating. They’ve got high expectations at Interop; they expect the network to just work, so the focus is actually not on uptime and SLAs – that’s a given. “Nothing less than perfection works here.” (Let me tell you, after my horrible experience with the super slow and inaccessible network at the VMworld conference, that is definitely not always the case. Maybe InteropNet should sell its services…hmmmm&#8230;) Rather, it’s about being able to <a href="http://blog.interop.com/blog/2008/09/18/video-interop_ny-show-report-day-2/">showcase technologies and strategies</a> for <a href="http://blog.interop.com/blog/2008/09/16/interopnysummary/">networking and interoperability</a> – or as we’re interpreting that, basically “walking the walk – which in the end is what InteropNet is all about.</p>
<p><a href="http://www.viddler.com/explore/sciencelogic/videos/4/">See the full video here</a>.</p>
<p><object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="247" height="205" id="viddler_8620897d"><param name="movie" value="http://www.viddler.com/simple/8620897d/" /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><embed src="http://www.viddler.com/simple/8620897d/" width="247" height="205" type="application/x-shockwave-flash" allowScriptAccess="always" allowFullScreen="true" name="viddler_8620897d" ></embed></object></p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 16:47:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/inaccessible network">inaccessible network</category>
      <category domain="http://securityratty.com/tag/lenny">lenny</category>
      <category domain="http://securityratty.com/tag/network admins">network admins</category>
      <category domain="http://securityratty.com/tag/interopnet">interopnet</category>
      <category domain="http://securityratty.com/tag/interopnet team">interopnet team</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/affect network performance">affect network performance</category>
      <source url="http://blog.sciencelogic.com/interview-with-lenny-heymann-interop-general-manager/09/2008">Interview with Lenny Heymann, Interop General Manager</source>
    </item>
    <item>
      <title><![CDATA[Blamestorming]]></title>
      <link>http://securityratty.com/article/95618fa2d7ec7b889e72d37343245d7a</link>
      <guid>http://securityratty.com/article/95618fa2d7ec7b889e72d37343245d7a</guid>
      <description><![CDATA[So, let's recap the sequence of events
The Sun-Sentinel newspaper in Fort Lauderdale accidentally republishes a six-year-old news story about the bankruptcy of UAL. It wasn't on the home page, but...]]></description>
      <content:encoded><![CDATA[<p>So, let's recap the sequence of events:</p>  <ol>   <li>The <em>Sun-Sentinel</em> newspaper in Fort Lauderdale accidentally republishes a six-year-old news story about the bankruptcy of UAL. It wasn't on the home page, but instead buried somewhere inside the web site. </li>    <li>Google's news crawler (an automated thing, remember) finds the story and incorporates it as part of its news feed. </li>    <li>Investors see the story, and immediately react. When UAL's stock <a href="http://money.cnn.com/2008/09/08/news/companies/united_airlines/index.htm" target="_blank">plunged 76% to a low of $3</a>, Nasdaq shut down trading. Eventually trading resumed, and the stock closed at just under $11, losing about 11%. </li>    <li>United blamed Tribune Company (the owner of the <em>Sun-Sentinel</em>) for <a href="http://www.cnbc.com/id/26608126" target="_blank">&quot;irresponsibly&quot; changing the date</a> on the story and <a href="http://media.corporate-ir.net/media_files/irol/83/83680/articles/bankruptcy_statementFINAL2.pdf" target="_blank">demanded a retraction</a>. </li>    <li>Tribune Company blamed Google, claiming they've <a href="http://www.eweek.com/c/a/Search-Engines/Tribune-Blames-Google-for-UAL-Bankruptcy-Story/?kc=rss" target="_blank">had issues</a> with Google's crawler &quot;for months.&quot; </li> </ol>  <p>Who will blame be shifted to next?</p>  <p>Look -- if people haven't realized by now that the Internet pretty much <a href="http://www.archive.org/index.php" target="_blank">lacks a delete function</a>, then (IMNSHO) it becomes the requirement of <em>each and every one of us</em> to pay close attention to what we're reading, to use our own big brains and fine-tuned bullshit detectors to suss out whether something makes sense.</p>  <p>Since this is my blog, I'm going to parcel out blame the way I see it:</p>  <ul>   <li><strong>United: 0%.</strong> If the concept of &quot;negative blame&quot; made any sense, then I'd actually write <strong>&#8722;&#8734;</strong> (that's a negative infinity, in case your character set is different than mine). </li>    <li><strong>Google: 5%.</strong> How can an automated crawler know that a newly-dated story isn't really new? Well, those folks over there at Google are smart. Certainly it shouldn't be that difficult to compare a &quot;new&quot; article against existing ones. Content hashes won't work as a comparison tool, because the date would be included in the hash computation, thus making the hashes different anyway. Full-text comparisons? Sure, it would take a lot of horsepower. Perhaps not every &quot;new&quot; story needs comparison, but at least the crawler could submit to the comparator any stories that ought to be verified (say those with the word &quot;bankruptcy&quot; in them). </li>    <li><strong>Tribune Company: 30%.</strong> Hey guys, <em>you changed the date on the article.</em> Don't go blaming someone else for your screw-up. </li>    <li><strong>Investors: 65%.</strong> If you're using an automated news aggregator (remember, an aggregator is not a <em>source</em> of news) to make major financial decisions -- decisions that affect the livelihoods of thousands (maybe millions) of people -- well, you're a moron. You should know that incorrect information can be just as instantly available as correct information. Verify potentially damaging claims before engaging in reckless behavior. </li> </ul>  <p>What's this got to do with security? I don't know, maybe nothing directly related. But it certainly raises the question -- what if someone intentionally wanted to cause nearly permanent damage to a person or a corporation? Malicious content, disguised as &quot;news,&quot; certainly seems to have become a potentially successful attack vector this week.</p>  <p>Worried about a social engineering attack on a massive scale? I suspect that what happened Monday (8 September) <em>was</em> the largest social engineering attack in history -- although I wouldn't classify it as intentionally malicious. Just you wait until the <a href="http://en.wikipedia.org/wiki/Meme" target="_blank">idea spreads</a>.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3122810" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 02:03:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/news aggregator">news aggregator</category>
      <category domain="http://securityratty.com/tag/news feed">news feed</category>
      <category domain="http://securityratty.com/tag/six-year-old news story">six-year-old news story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/news crawler">news crawler</category>
      <category domain="http://securityratty.com/tag/tribune company">tribune company</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/successful attack vector">successful attack vector</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/11/blamestorming.aspx">Blamestorming</source>
    </item>
    <item>
      <title><![CDATA[Automation Gone Wrong]]></title>
      <link>http://securityratty.com/article/7c236cd455cc9d0b2eb9da846ba03f97</link>
      <guid>http://securityratty.com/article/7c236cd455cc9d0b2eb9da846ba03f97</guid>
      <description><![CDATA[Weve talked about the changing nature of the data center and the critical role that even more automation from virtual machine movement to runbook tools to auto-remediation and more will have in trying...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/swn-2007-united-brand.gif" border="0" alt="swn_2007_united_brand" width="189" height="20" align="left" /> We’ve talked about the changing nature of the data center and the critical role that even more automation – from <a href="http://www.bladewatch.com/2008/09/10/data-centers-need-to-be-made-lite/" target="_blank">virtual machine movement</a> to runbook tools to auto-remediation and more – will have in trying to manage data center operations in real-time. But it’s always a balancing act. How “smart” can automated processes really be? What really should be automated versus requiring some level of human scrutiny and decision-making?</p>
<p>Well here’s a story where the tradeoff for speed and efficiency caused a massive stock dump erroneously.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/sentinel-article-blog.jpg" border="0" alt="Sentinel_article_blog" width="368" height="420" /></p>
<p>Apparently, many traders use <a href="http://blog.wired.com/27bstroke6/2008/09/six-year-old-st.html" target="_blank">automation software that trolls the Web</a> for news stories and then, depending on what it finds, executes stock trades automatically. It was <a href="http://aviationblog.dallasnews.com/archives/2008/09/dow-jones-kicks-them-when-they.html" target="_blank">United Airline’s bad luck that an old article about its 2002 bankruptcy</a>-court filing showed up on Google’s news service and somehow made it to the list of most popular stories. In one of a series of mistakes here, the story had no date on it – which means Google’s algorithm for assessing popularity didn’t have a way to exclude it as an “old” story – OR (because there are conflicting accounts) the South Florida Sun-Sentinel actually put “today’s” date on the page that the story appeared on. This got <a href="http://www.networkworld.com/community/node/32424" target="_blank">picked up by the Income Security Advisors newsletter</a> and sent over to Bloomberg News as a one-line brief. Plus there’s the inevitable conspiracy theory that people manipulated the web traffic for this story to adversely affect UAL. Regardless, on Monday afternoon, the <a href="http://www.editorsweblog.org/multimedia/2008/09/us_united_airlines_stock_plummets_after.php" target="_blank">stock plunged 76%</a> in less than a day.</p>
<p>But the real problem here is the <a href="http://exchanges.nyse.com/archives/2008/09/we_robots.php" target="_blank">growing use of automated programs</a> to trigger stock trades without any human interaction – instead based on news headlines and earnings data. According to the Wall Street Journal, these automated programs were responsible for a very surprising <a href="http://online.wsj.com/article/SB122100794359017593.html?mod=djemMM">25% of NYSE trades</a> in the last week of August.</p>
<p>I’m sure we’ll hear more as the lawyers are now involved trying to figure out who should get the blame.</p>
]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 17:00:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stock">stock</category>
      <category domain="http://securityratty.com/tag/trigger stock trades">trigger stock trades</category>
      <category domain="http://securityratty.com/tag/automation">automation</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/executes stock trades">executes stock trades</category>
      <category domain="http://securityratty.com/tag/web traffic">web traffic</category>
      <category domain="http://securityratty.com/tag/wall street journal">wall street journal</category>
      <category domain="http://securityratty.com/tag/googles news service">googles news service</category>
      <category domain="http://securityratty.com/tag/virtual machine movement">virtual machine movement</category>
      <source url="http://blog.sciencelogic.com/automation-gone-wrong/09/2008">Automation Gone Wrong</source>
    </item>
    <item>
      <title><![CDATA[Update Windows Now More Critical Patches]]></title>
      <link>http://securityratty.com/article/678c5e6e7320a7193bcfa9bd5707d08f</link>
      <guid>http://securityratty.com/article/678c5e6e7320a7193bcfa9bd5707d08f</guid>
      <description><![CDATA[Yesterday was the Patch Tuesday where microsoft released patches for 8 critical security issues
The issues affect Windows Media Player, Windows Media Encoder, and five problems in the Windows Graphic...]]></description>
      <content:encoded><![CDATA[<p>Yesterday was the Patch Tuesday where microsoft released patches for 8 critical security issues.</p>
<p>The issues affect Windows Media Player, Windows Media Encoder, and five problems in the Windows Graphic Device Interface (GDI). Patch today, because the exploits are coming fast on these, according to <a rel="nofollow" target="_blank" href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_patches_for_eight_se.html">other experts. </a></p>
<p>Visit Microsoft for <a rel="nofollow" target="_blank" href="http://update.microsoft.com/">the updates</a>.</p>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 16:58:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/patch tuesday">patch tuesday</category>
      <category domain="http://securityratty.com/tag/windows media encoder">windows media encoder</category>
      <category domain="http://securityratty.com/tag/visit microsoft">visit microsoft</category>
      <category domain="http://securityratty.com/tag/critical security issues">critical security issues</category>
      <category domain="http://securityratty.com/tag/patch">patch</category>
      <category domain="http://securityratty.com/tag/patches">patches</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/388318217/">Update Windows Now More Critical Patches</source>
    </item>
    <item>
      <title><![CDATA[Microsoft patches affect scores of systems]]></title>
      <link>http://securityratty.com/article/51e553d37b9183b9ae938455d0e48425</link>
      <guid>http://securityratty.com/article/51e553d37b9183b9ae938455d0e48425</guid>
      <description><![CDATA[Microsoft Tuesday released four critical patches targeting vulnerabilities mostly in Windows-based server and client operating...]]></description>
      <content:encoded><![CDATA[Microsoft Tuesday released four critical patches targeting vulnerabilities mostly in Windows-based server and client operating systems.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/general;sz=468x60;ord=85379?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/general;sz=468x60;ord=85379?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/microsoft tuesday">microsoft tuesday</category>
      <category domain="http://securityratty.com/tag/critical patches">critical patches</category>
      <category domain="http://securityratty.com/tag/client">client</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <source url="http://www.networkworld.com/news/2008/090908-microsoft-patches-list.html?fsrc=rss-security">Microsoft patches affect scores of systems</source>
    </item>
    <item>
      <title><![CDATA[IT Sec ProfessionalsWill Automated Security Tools Affect Your Job Security?]]></title>
      <link>http://securityratty.com/article/42bece0353bdccce0e60275afee9d3ed</link>
      <guid>http://securityratty.com/article/42bece0353bdccce0e60275afee9d3ed</guid>
      <description><![CDATA[Hackers, security professionals and security tools are becoming both more sophisticated and more automated. With more demand for security experts, people are getting trained and coming in from many...]]></description>
      <content:encoded><![CDATA[<p>Hackers, security professionals and security tools are becoming both more sophisticated and more automated. With more demand for security experts, people are getting trained and coming in from many different backgrounds &#8212; like Patrick Foley over at Blog Info Sec, who said he worked as a longshoreman, journalist, and manager before being trained in tech. He has an interesting article today looking to the future as well &#8212; as security gets bigger, how many of our tools will become automated and will that leave security professionals with less job security?</p>
<blockquote><p>I know that I am always looking for better, cheaper, and faster ways to do what I do now. As regulations like PCI become more prescriptive, as discovery and compliance tools get better, as organizations embed security more seamlessly in the business, and as security itself becomes part of more expansive and, theoretically, more valuable business roles, will security professionals need to reinvent themselves?&#8230;</p>
<p>Very few jobs in any large organization look like they did 20 years ago; some of security’s most traditional work may see big changes ahead. How do we prepare our colleagues and teams for those challenges and turn them into opportunities?</p></blockquote>
<p>Read the whole <a rel="nofollow" target="_blank" href="http://www.bloginfosec.com/2008/09/03/so-why-do-we-need-security-professionals-anyway/">article here</a>.</p>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 06:13:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/job security">job security</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/security tools">security tools</category>
      <category domain="http://securityratty.com/tag/organizations embed security">organizations embed security</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/valuable business roles">valuable business roles</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382565190/">IT Sec ProfessionalsWill Automated Security Tools Affect Your Job Security?</source>
    </item>
    <item>
      <title><![CDATA[Security ROI]]></title>
      <link>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</link>
      <guid>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</guid>
      <description><![CDATA[Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable
It's become a big deal...]]></description>
      <content:encoded><![CDATA[<p>Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable.</p>

<p>It's become a <a href="http://www.csoonline.com/article/print/217727">big</a> <a href="http://www.computerworld.com/securitytopics/security/story/0,10801,83207,00.html?nas=ROI-83207">deal</a> in IT security, too. Many corporate customers are demanding ROI models to demonstrate that a particular security investment pays off. And in response, vendors are providing ROI models that demonstrate how their particular security solution provides the best return on investment.</p>

<p>It's a <a href="http://communities.intel.com/openport/blogs/it/2008/08/25/are-security-roi-figures-meaningless">good</a> <a href="http://communities.intel.com/openport/blogs/it/2007/08/14/the-problem-of-measuring-information-security">idea</a> in <a href="https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/677-BSI.html">theory</a>, <a href="http://taosecurity.blogspot.com/2007/07/are-questions-sound.html">but</a> <a href="http://www.bloginfosec.com/2007/07/13/bejtlich-and-business-will-it-blend/">it's</a> <a href="http://blog.vorant.com/2007/07/my-input-to-roi-spat.html">mostly</a> <a href="http://taosecurity.blogspot.com/2007/07/no-roi-no-problem.html">bunk</a> <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">in</a> <a href="http://taosecurity.blogspot.com/2007/07/security-roi-revisited.html">practice</a>.</p>

<p>Before I get into the details, there's one point I have to make. "ROI" as used in a security context is inaccurate. Security is not an investment that provides a return, like a new factory or a financial instrument. It's an expense that, hopefully, pays for itself in cost savings. Security is about loss prevention, not about earnings. The term just doesn't make sense in this context.</p>

<p>But as anyone who has lived through a company's vicious end-of-year budget-slashing exercises knows, when you're trying to make your numbers, cutting costs is the same as increasing revenues. So while security can't produce ROI, loss prevention most certainly affects a company's bottom line.</p>

<p>And a company should implement only security countermeasures that affect its bottom line positively. It shouldn't spend more on a security problem than the problem is worth. Conversely, it shouldn't ignore problems that are costing it money when there are cheaper mitigation alternatives. A smart company needs to approach security as it would any other business decision: costs versus benefits.</p>

<p>The classic methodology is called annualized loss expectancy (ALE), and it's straightforward. Calculate the cost of a security incident in both tangibles like time and money, and intangibles like reputation and competitive advantage. Multiply that by the chance the incident will occur in a year. That tells you how much you should spend to mitigate the risk. So, for example, if your store has a 10 percent chance of getting robbed and the cost of being robbed is $10,000, then you should spend $1,000 a year on security. Spend more than that, and you're wasting money. Spend less than that, and you're also wasting money.</p>

<p>Of course, that $1,000 has to reduce the chance of being robbed to zero in order to be cost-effective. If a security measure cuts the chance of robbery by 40 percent -- to 6 percent a year -- then you should spend no more than $400 on it. If another security measure reduces it by 80 percent, it's worth $800. And if two security measures both reduce the chance of being robbed by 50 percent and one costs $300 and the other $700, the first one is worth it and the second isn't.</p>

<p>The Data Imperative</p>

<p>The key to making this work is good data; the term of art is "actuarial tail." If you're doing an ALE analysis of a security camera at a convenience store, you need to know the crime rate in the store's neighborhood and maybe have some idea of how much cameras improve the odds of convincing criminals to rob another store instead. You need to know how much a robbery costs: in merchandise, in time and annoyance, in lost sales due to spooked patrons, in employee morale. You need to know how much not having the cameras costs in terms of employee morale; maybe you're having trouble hiring salespeople to work the night shift. With all that data, you can figure out if the cost of the camera is cheaper than the loss of revenue if you close the store at night -- assuming that the closed store won't get robbed as well. And then you can decide whether to install one.</p>

<p>Cybersecurity is considerably harder, because there just isn't enough good data. There aren't good crime rates for cyberspace, and we have a lot less data about how individual security countermeasures -- or specific configurations of countermeasures -- mitigate those risks. We don't even have data on incident costs.</p>

<p>One problem is that the threat moves too quickly. The characteristics of the things we're trying to prevent change so quickly that we can't accumulate data fast enough. By the time we get some data, there's a new threat model for which we don't have enough data. So we can't create ALE models.</p>

<p>But there's another problem, and it's that the math quickly falls apart when it comes to rare and expensive events. Imagine you calculate the cost -- reputational costs, loss of customers, etc. -- of having your company's name in the newspaper after an embarrassing cybersecurity event to be $20 million. Also assume that the odds are 1 in 10,000 of that happening in any one year. ALE says you should spend no more than $2,000 mitigating that risk.</p>

<p>So far, so good. But maybe your CFO thinks an incident would cost only $10 million. You can't argue, since we're just estimating. But he just cut your security budget in half. A vendor trying to sell you a product finds a Web analysis claiming that the odds of this happening are actually 1 in 1,000. Accept this new number, and suddenly a product costing 10 times as much is still a good investment.</p>

<p>It gets worse when you deal with even more rare and expensive events. Imagine you're in charge of terrorism mitigation at a chlorine plant. What's the cost to your company, in money and reputation, of a large and very deadly explosion? $100 million? $1 billion? $10 billion? And the odds: 1 in a hundred thousand, 1 in a million, 1 in 10 million? Depending on how you answer those two questions -- and any answer is really just a guess -- you can justify spending anywhere from $10 to $100,000 annually to mitigate that risk.</p>

<p>Or take another example: airport security. Assume that all the new airport security measures increase the waiting time at airports by -- and I'm making this up -- 30 minutes per passenger. There were 760 million passenger boardings in the United States in 2007. This means that the extra waiting time at airports has cost us a collective 43,000 years of extra waiting time. Assume a 70-year life expectancy, and the increased waiting time has "killed" 620 people per year -- 930 if you calculate the numbers based on 16 hours of awake time per day. So the question is: If we did away with increased airport security, would the result be more people dead from terrorism or fewer?</p>

<p>Caveat Emptor</p>

<p>This kind of thing is why most ROI models you get from security vendors are <a href="http://www.postini.com/services/roi_calculator.html">nonsense</a>. Of course their model demonstrates that their product or service makes financial sense: They've jiggered the numbers so that they do.</p>

<p>This doesn't mean that ALE is useless, but it does mean you should 1) mistrust any analyses that come from people with an agenda and 2) use any results as a general guideline only. So when you get an ROI model from your vendor, take its framework and plug in your own numbers. Don't even show the vendor your improvements; it won't consider any changes that make its product or service less cost-effective to be an "improvement." And use those results as a general guide, along with risk management and compliance analyses, when you're deciding what security products and services to buy.</p>

<p>This essay <a href="http://www.csoonline.com/article/446866/Security_ROI_Fact_or_Fiction_">previously appeared</a> in <i>CSO Magazine</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Ql60WL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Ql60WL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=npHViL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=npHViL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 02:05:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security countermeasures">security countermeasures</category>
      <category domain="http://securityratty.com/tag/countermeasures">countermeasures</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/security incident">security incident</category>
      <category domain="http://securityratty.com/tag/individual security countermeasures">individual security countermeasures</category>
      <category domain="http://securityratty.com/tag/security measure cuts">security measure cuts</category>
      <category domain="http://securityratty.com/tag/security measure reduces">security measure reduces</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/security_roi_1.html">Security ROI</source>
    </item>
    <item>
      <title><![CDATA[Fake Security Software Domains Serving Exploits]]></title>
      <link>http://securityratty.com/article/a2ffa8d411dc417bdb5a774ee6ab5207</link>
      <guid>http://securityratty.com/article/a2ffa8d411dc417bdb5a774ee6ab5207</guid>
      <description><![CDATA[Psychological imagination, &quot;think cybercriminals&quot; mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, I pointed out that

Ironically, the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaDCa0a4yI/AAAAAAAACIU/V4NpXSLdBEA/s1600-h/fake_software_client_side_exploits.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaDCa0a4yI/AAAAAAAACIU/6N2G2L2h2-0/s200-R/fake_software_client_side_exploits.png" /></a>Psychological imagination, "think cybercriminals" mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">I pointed out that</a> :<br />
<br />
"<i>Ironically, the participant in the affiliate program whose original objective was to drive traffic to the fake security software's site, may in fact start receiving so much traffic due to the combination of traffic acquisition tactics, that <a href="http://ddanchev.blogspot.com/2008/02/serving-malware-through-advertising.html">introducing client-side exploits courtesy of a third-party affiliate network</a>, may in fact prove more profitable then the revenue sharing partnership with the rogue security software's vendor at the first place.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SLaJ9G1B_YI/AAAAAAAACIk/WVx1enYkT0E/s1600-h/fake_security_client_side.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SLaJ9G1B_YI/AAAAAAAACIk/XSe4BHhrt2w/s200-R/fake_security_client_side.JPG" /></a>The next day, <a href="http://sunbeltblog.blogspot.com/2008/08/xp-antivirus-2008-now-with-sploits.html">client-side exploits start getting introduced</a> "in between" the fake security software sites :<br />
<br />
"<i>I've blogged before about the problem of Google Adwords pushing Antivirus XP Antivirus 2008. The situation is still ongoing.&nbsp; However, it's taken a turn for the worse, as these XP Antivirus pages are pushing exploits to install malware on the users system. This will also affect the many syndicators of Google Adwords.</i>"<br />
<br />
The domain in question <b>bestantivirus2009.com</b> - (68.180.151.21) is hosting the binary at <b>bestantivirus2009 .com</b>/setup_1096_MTYwM3wzNXww_.exe and has an IFRAME pointing to <b>huytegygle .com</b>/index.php (200.46.83.246).<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaOX5IUu2I/AAAAAAAACIs/UmA8sFcQCIA/s1600-h/antivirus0003.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaOX5IUu2I/AAAAAAAACIs/YL8oDzvUAeY/s200-R/antivirus0003.png" /></a>Here's another example <b>antivirus0003.net</b> with an IFRAME pointing to a different location - <b>124.217.250.85 /~ave/etc/count.php?o=16</b>.<br />
<br />
Despite that these domains are part of the "International Virus Research Lab" fake domains portfolio, it remains to be seen whether others will start multitasking as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yRDO0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yRDO0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mEJFVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mEJFVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=74vKNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=74vKNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FMF6wk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FMF6wk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnoShK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnoShK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5q8hIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5q8hIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GNqd3k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GNqd3k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/377056323" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 02:41:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/client-side exploits courtesy">client-side exploits courtesy</category>
      <category domain="http://securityratty.com/tag/client-side exploits start">client-side exploits start</category>
      <category domain="http://securityratty.com/tag/start">start</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/google adwords">google adwords</category>
      <category domain="http://securityratty.com/tag/fake domains portfolio">fake domains portfolio</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/377056323/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</source>
    </item>
    <item>
      <title><![CDATA[A Security Assessment of the Internet Protocol]]></title>
      <link>http://securityratty.com/article/ebac4e1107d0d958cc5b67c257c5ea71</link>
      <guid>http://securityratty.com/article/ebac4e1107d0d958cc5b67c257c5ea71</guid>
      <description><![CDATA[Interesting : Preface
The TCP/IP protocols were conceived during a time that was quite different from the hostile environment they operate in now. Yet a direct result of their effectiveness and...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cpni.gov.uk/Docs/InternetProtocol.pdf">Interesting</a>:</p>

<blockquote><strong>Preface</strong>

<p>The TCP/IP protocols were conceived during a time that was quite different from the hostile environment they operate in now. Yet a direct result of their effectiveness and widespread early adoption is that much of today's global economy remains dependent upon them.</p>

<p>While many textbooks and articles have created the myth that the Internet Protocols (IP) were designed for warfare environments, the top level goal for the DARPA Internet Program was the sharing of large service machines on the ARPANET. As a result, many protocol specifications focus only on the operational aspects of the protocols they specify and overlook their security implications.</p>

<p>Though Internet technology has evolved, the building blocks are basically the same core protocols adopted by the ARPANET more than two decades ago. During the last twenty years many vulnerabilities have been identified in the TCP/IP stacks of a number of systems. Some were flaws in protocol implementations which affect only a reduced number of systems. Others were flaws in the protocols themselves affecting virtually every existing implementation. Even in the last couple of years researchers were still working on security problems in the core  protocols.</p>

<p>The discovery of vulnerabilities in the TCP/IP protocols led to reports being published by a number of CSIRTs (Computer Security Incident Response Teams) and vendors, which helped to raise awareness about the threats as well as the best mitigations known at the time the reports were published.</p>

<p>Much of the effort of the security community on the Internet protocols did not result in official documents (RFCs) being issued by the IETF (Internet Engineering Task Force) leading to a situation in which "known" security problems have not always been addressed by all vendors. In many cases vendors have implemented quick "fixes" to protocol flaws without a careful analysis of their effectiveness and their impact on interoperability.</p>

<p>As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past.</p>

<p>Producing a secure TCP/IP implementation nowadays is a very difficult task partly because of no single document that can serve as a security roadmap for the protocols.</p>

<p>There is clearly a need for a companion document to the IETF specifications that discusses the security aspects and implications of the protocols, identifies the possible threats, proposes possible counter-measures, and analyses their respective effectiveness.</p>

<p>This document is the result of an assessment of the IETF specifications of the Internet Protocol from a security point of view. Possible threats were identified and, where possible, counter-measures were proposed.  Additionally, many implementation flaws that have led to security vulnerabilities have been referenced in the hope that future implementations will not incur the same problems. This document does not limit itself to performing a security assessment of the relevant IETF specification but also offers an assessment of common implementation strategies.</p>

<p>Whilst not aiming to be the final word on the security of the IP, this document aims to raise awareness about the many security threats based on the IP protocol that have been faced in the past, those that we are currently facing, and those we may still have to deal with in the future. It provides advice for the secure implementation of the IP, and also insights about the security aspects of the IP that may be of help to the Internet operations community.</p>

<p>Feedback from the community is more than encouraged to help this document be as accurate as possible and to keep it updated as new threats are discovered.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=klyypK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=klyypK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xR8bMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xR8bMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:48:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/security assessment">security assessment</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/internet technology">internet technology</category>
      <category domain="http://securityratty.com/tag/internet operations community">internet operations community</category>
      <category domain="http://securityratty.com/tag/protocols">protocols</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/a_security_asse.html">A Security Assessment of the Internet Protocol</source>
    </item>
  </channel>
</rss>
