<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: history]]></title>
    <link>http://securityratty.com/tag/history</link>
    <description></description>
    <pubDate>Thu, 11 Sep 2008 18:32:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The More Things Change, the More They Stay the Same]]></title>
      <link>http://securityratty.com/article/12ab611c9b823e0e31278b582051d7cf</link>
      <guid>http://securityratty.com/article/12ab611c9b823e0e31278b582051d7cf</guid>
      <description><![CDATA[Guess the year: Murderous organizations have increased in size and scope; they are more daring, they are served by the most terrible weapons offered by modern science, and the world is nowadays...]]></description>
      <content:encoded><![CDATA[<p>Guess the year:</p>

<blockquote>Murderous organizations have increased in size and scope; they are more daring, they are served by the most terrible weapons offered by modern science, and the world is nowadays threatened by new forces which, if recklessly unchained, may some day wreck universal destruction. The Orsini bombs were mere children's toys compared with the later developments of infernal machines. Between 1858 and 1898 the dastardly science of destruction had made rapid and alarming strides...</blockquote>

<p>No, that wasn't a typo.  "Between 1858 and 1898...."  This quote is from Major Arthur Griffith, <a href="http://query.nytimes.com/mem/archive-free/pdf?res=9907E7D8153DE633A25757C0A9659C94689ED7CF"><i>Mysteries of Police and Crime</i></a>, London, 1898, II, p. 469.  It's quoted in: Walter Laqueur, <a href="http://www.amazon.com/History-Terrorism-Walter-Laqueur/dp/0765807998/ref=pd_bbs_sr_1?ie=UTF8&s=books&qid=1223482236&sr=8-1"><i>A History of Terrorism</i></a>, New Brunswick/London, Transaction Publishers, 2002.  </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3iuIM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3iuIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YTBGM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YTBGM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 08:30:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/major arthur griffith">major arthur griffith</category>
      <category domain="http://securityratty.com/tag/orsini bombs">orsini bombs</category>
      <category domain="http://securityratty.com/tag/murderous organizations">murderous organizations</category>
      <category domain="http://securityratty.com/tag/infernal machines">infernal machines</category>
      <category domain="http://securityratty.com/tag/transaction publishers">transaction publishers</category>
      <category domain="http://securityratty.com/tag/terrible weapons">terrible weapons</category>
      <category domain="http://securityratty.com/tag/dastardly science">dastardly science</category>
      <category domain="http://securityratty.com/tag/walter laqueur">walter laqueur</category>
      <category domain="http://securityratty.com/tag/modern science">modern science</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_more_things.html">The More Things Change, the More They Stay the Same</source>
    </item>
    <item>
      <title><![CDATA[Identity-Based Encryption and Beyond]]></title>
      <link>http://securityratty.com/article/e5f876b2d5c818e8124d0009fc2f018a</link>
      <guid>http://securityratty.com/article/e5f876b2d5c818e8124d0009fc2f018a</guid>
      <description><![CDATA[In June 2008, the US National Institute for Standards and Technology (NIST) held a workshop entitled, &quot;Applications of Pairing Based Cryptography: Identity-Based Encryption and Beyond,&quot; in...]]></description>
      <content:encoded><![CDATA[In June 2008, the US National Institute for Standards and Technology (NIST) held a workshop entitled, "Applications of Pairing Based Cryptography: Identity-Based Encryption and Beyond," in Gaithersburg, Maryland. In a series of 14 talks and two panel discussions, the presenters at this workshop discussed several aspects of identity-based encryption (IBE) and related pairing-based public-key schemes, including the history of the technology, applications for which it is well suited, and potential future developments. Copies of the presentations are now available on the workshop's Web site (www.nist.gov/ibe/). Close to 100 people from a wide range of security vendors, government agencies and academic institutions attended the event; this installment of Crypto Corner takes a closer look at all the events.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a5d6d2edce9d2f509b4706c97716c5f2" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a5d6d2edce9d2f509b4706c97716c5f2" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/encryption">encryption</category>
      <category domain="http://securityratty.com/tag/potential future developments">potential future developments</category>
      <category domain="http://securityratty.com/tag/workshop">workshop</category>
      <category domain="http://securityratty.com/tag/crypto corner takes">crypto corner takes</category>
      <category domain="http://securityratty.com/tag/academic institutions">academic institutions</category>
      <category domain="http://securityratty.com/tag/public-key schemes">public-key schemes</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/based cryptography">based cryptography</category>
      <source url="http://www.pheedo.com/click.phdo?i=a5d6d2edce9d2f509b4706c97716c5f2">Identity-Based Encryption and Beyond</source>
    </item>
    <item>
      <title><![CDATA[ePolicing - Tomorrow the world?]]></title>
      <link>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</link>
      <guid>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</guid>
      <description><![CDATA[This week has finally seen an announcement that the Police Central e-crime Unit (PCeU) is to be funded by the Home Office. However, the largesse amounts to just 3.5 million of new money spread over...]]></description>
      <content:encoded><![CDATA[<p>This week has finally seen an <a href="http://press.homeoffice.gov.uk/press-releases/new-specialist-ecrime-unit">announcement</a> that the <a href="http://www.met.police.uk/pceu/index.htm">Police Central e-crime Unit</a> (PCeU) is to be funded by the Home Office. However, the largesse amounts to just £3.5 million of new money spread over three years, with the Met putting up a further £3.9 million &#8212; but whether the Met&#8217;s contribution is &#8220;new&#8221; or reflects a move of resources from their existing <a href="http://www.met.police.uk/computercrime/">Computer Crime Unit</a> I could not say.</p>
<p>The announcement is of course Good News &#8212; because once the PCeU is up and running next Spring, it should plug (to the limited extent that £2 million a year can plug) the &#8220;level 2&#8243; eCrime gap that I&#8217;ve <a href="http://www.lightbluetouchpaper.org/2006/02/06/mysterious-and-menacing/">written</a> <a href="http://www.lightbluetouchpaper.org/2006/10/13/mainstreaming-ecrime/">about</a> <a href="http://www.lightbluetouchpaper.org/2007/02/11/soca-we-just-want-your-money/">before</a>. viz: that SOCA tackles &#8220;serious and organised crime&#8221; (level 3), your local police force tackles local villains (level 1), but if criminals operate outside their force&#8217;s area &#8212; and on the Internet this is more likely than not &#8212; yet they don&#8217;t meet SOCA&#8217;s threshold, then who is there to deal with them?</p>
<p>In particular, the PCeU is envisaged to be the unit that deals with the intelligence packages coming from the <a href="http://www.cityoflondon.police.uk/CityPolice/ECD/Fraud/">City of London Fraud Squad&#8217;s</a> new online Fraud Reporting <a href="http://www.kablenet.com/kd.nsf/Frontpage/356DD0A1942F3A998025745F0049092C?OpenDocument">website</a> (once intended to launch in November 2008, now scheduled for Summer 2009).</p>
<p>Of course everyone expects the website to generate more reports of eCrime than could ever be dealt with (even with much more money), so the effectiveness of the PCeU in dealing with eCriminality will depend upon their prioritisation criteria, and how carefully they select the cases they tackle.</p>
<p>Nevertheless, although the news this week shows that the Home Office have finally understood the need to fund more ePolicing, I don&#8217;t think that they are thinking about the problem in a sufficiently global context.</p>
<p>A little history lesson might be in order to explain why.<br />
<span id="more-401"></span></p>
<p>Back in 1930&#8217;s, <a href="http://www.fbi.gov/libref/historic/famcases/clyde/clyde.htm">Bonnie and Clyde</a> and other US bank robbers were using the new-fangled automobile to flee across state lines &#8212; creating jurisdictional problems as a result. The US solution was to make bank robbery (along with auto-theft and other related offences) into federal offences rather keeping them as state-specific infractions. In particular this meant that the FBI could provide federal level policing (tracking down and killing <a href="http://en.wikipedia.org/wiki/John_Dillinger">John Dillinger</a> for example).</p>
<p>We have the same jurisdictional issues dealing with cyberspace, with criminals in one country fleecing consumers in another while using systems hosted in a third. The <a href="http://conventions.coe.int/Treaty/EN/Treaties/Html/185.htm">Convention on Cybercrime</a> addresses part of the problem by trying to ensure international consistency where eLaws are specifically needed (which of course is only the case for small parts of eCriminality, <a href="http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060035_en_1">fraud</a> is fraud whether eEnabled or not). However, there is limited inter-jurisdictional <em>co-ordination</em> for eCrime investigations &#8212; for example <a href="http://www.interpol.int/">Interpol</a> (often <a href="http://en.wikipedia.org/wiki/Interpol#Interpol_in_popular_culture">incorrectly perceived</a> to be international police force)  merely keeps a large database and passes faxes from one place to another.</p>
<p>In practice, most cross-border investigations are done as &#8220;joint operations&#8221; and the jointness is usually very limited &#8212; one force does all the legwork and a liaison officer in the other country deals with local paperwork. There&#8217;s usually a <a href="http://www.phrases.org.uk/meanings/quid-pro-quo.html">quid pro quo</a> element to these joint operations, for budgeting reasons if no other.</p>
<p>What isn&#8217;t happening, or at least only in a handful of very specialised areas, is any international co-operation in setting priorities or selecting cases to pursue. Every country is doing its own thing about eCrime, and there&#8217;s a widespread impression that any criminal who can operate from &#8220;across the state line&#8221; is essentially immune from serious investigation.</p>
<p>We identified this problem last year when we (<a href="http://www.cl.cam.ac.uk/~rja14/">Ross Anderson</a>, <a href="http://www.inf.tu-dresden.de/index.php?node_id=489">Rainer Böhme</a>, <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a>) wrote a report on <a href="http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&#038;_int_mark_20080131.pdf">Security Economics and the Internal Market</a> for <a href="http://www.enisa.europa.eu/">ENISA</a>. It&#8217;s not an easy one to fix whilst politicians (and populaces) are unwilling to see &#8220;foreign&#8221; police officers operating in their country, and the establishment of a truly international &#8220;cyber police force&#8221; seems equally unlikely.</p>
<p>Our policy proposal to tackle the issue harks back to WWII&#8217;s <a href="http://www.archives.gov/research/holocaust/finding-aid/military/rg-331.html">SHAEF</a>, which has morphed into similar arrangements within <a href="http://www.nato.int/shape/about/background2.htm">NATO</a>. In essence liaison officers from multiple forces would sit around a single table, working with a central coordinator, to set policy and decide which investigations to pursue. They would then communicate back to their own countries, who have specifically budgeted to provide appropriate assistance. So it&#8217;s very like &#8220;joint operations&#8221;, but the scheme is multi-laterial, and has a true command and control function in the centre &#8212; who will quickly learn to shy away from politically sensitive topics and make a real impact on eCriminality.</p>
<p>To summarise then, a <a href="http://www.cartoonbank.com/item/34449">welcome</a> to the Home Office for finally finding a small amount of funding for some country-wide ePolicing; but it&#8217;s well past time to be working on world-wide initiatives.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 13:57:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecrime gap">ecrime gap</category>
      <category domain="http://securityratty.com/tag/ecrime">ecrime</category>
      <category domain="http://securityratty.com/tag/provide federal level">provide federal level</category>
      <category domain="http://securityratty.com/tag/ecrime investigations">ecrime investigations</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/level">level</category>
      <category domain="http://securityratty.com/tag/country deals">country deals</category>
      <category domain="http://securityratty.com/tag/deals">deals</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/02/epolicing-tomorrow-the-world/">ePolicing - Tomorrow the world?</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Seven]]></title>
      <link>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</link>
      <guid>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</guid>
      <description><![CDATA[In case you haven't heard - Microsoft and the Washington state are suing a U.S based -- naturally -- &quot;scareware&quot; vendor Branch Software

We won't tolerate the use of alarmist warnings or deceptive...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/V5DqP_zsvuk/s1600-h/lawsuit_got_one.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="161" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/FVk3TrvBJIo/s200-R/lawsuit_got_one.gif" width="200" /></a>In case you haven't heard - <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">Microsoft and the Washington state</a> are suing a U.S based -- naturally -- "scareware" vendor Branch Software :<br />
<br />
"<i>We won't tolerate the use of alarmist warnings or deceptive 'free scans' to  trick consumers into buying software to fix a problem that doesn't even exist,"  Washington <b style="font-weight: normal;">Attorney General Rob McKenna</b> said. <b>"We've repeatedly  proven that Internet companies that prey on consumers' anxieties are within our  reach.</b></i><b>"</b><br />
<br />
Sadly, Branch Software is the tip of the iceberg on the top of the affiliates participating in different affiliation based programs, which similar to <a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">IBSOFTWARE CYPRUS</a> and <a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Interactivebrands</a>, which I've been tracking down for a while, are the aggregators of scareware<b><span style="font-weight: normal;"> that popped up on the radars due to their extensive portfolios. These three companies offering software bundles or plain simple fake software, are somewhere in between the food chain of this ecosystem, with the real vendors paying out the commissions on a per installation basis slowly starting to issue invitation codes that they've distributed only across invite-only forums/sections of particular forums.</span></b><br />
<br />
Behind these brands is everyone that is participating in the franchise and is putting personal efforts into monetizing the high payout rates that the fake security software vendor is paying for successful installation. These high payout rates -- with the financing naturally coming straight from other criminal activities online -- are in fact so high, that I can easily say that the last two quarters we've witnesses the largest increase of such domains ever, and they're only heating up since the typosquatting possibilities are countless and they seem to know that as well.<br />
<br />
It's important to point out that their business model of acquiring traffic is outsourced to all the affiliates that do the blackhat SEO, SQL injections, web sessions hijacking of malware infected hosts in order to monetize, so basically, you have an affiliates network whose actions are directly driving the growth into all these areas. Throwing money into the underground marketplace as a "financial injection", is proving itself as a growth factor, and incentive for innovation on behalf of all the participants.<br />
<br />
Here are some of the most recent fake security software domains, a "deja vu" moment with a known RBN domain from a "previous life" that is also parked at one of the servers, and evidence that typosquatting for fraudulent purposes is still pretty active with a dozen of Norton Antivirus related domains, some of which have already started issuing "fake security notices" by brandjacking the vendor for traffic acquisition purposes.<br />
<br />
<b>Antivirus-Alert .com </b>(203.117.111.47) where<b> pepato .org</b> a domain that was used in the <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">Wired.com and History.com IFRAME injections</a>, which back in March was also hosted at Hostfresh (58.65.238.59).<br />
<br />
<b>softload2008name .com</b> (78.157.143.250)<br />
<b>softload2008nm .com<br />
softload2008n .com<br />
softload2008jq .com</b><br />
<br />
<b>microantivir-2009 .com</b> (91.208.0.223)<br />
<b>scanner.microantivir-2009 .com<br />
microantivir2009 .com<br />
microantivirus-2009 .com<br />
microantivirus2009 .com</b><br />
<br />
<b>ms-scan .com</b> (91.208.0.228)<br />
<b>msscanner .com</b><br />
<b>ms-scanner .com</b><br />
<br />
<b>Personalantispy .com</b> (93.190.139.197)<br />
<b>freepcsecure .com<br />
quickinstallpack .com<br />
quickdownloadpro .com<br />
advancedcleaner .com<br />
performanceoptimizer .com<br />
internetanonymizer .com</b><br />
<br />
<b>ieprogramming .com</b> (92.62.101.83)<br />
<b>uptodatepage .com<br />
fileliveupdate .com<br />
qwertypages .com<br />
sharedupdates .com<br />
ierenewals .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/eJI5I5BgGoQ/s1600-h/norton_alert.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/Rpjz8LY4LEQ/s200-R/norton_alert.png" /></a><b>norton-antivirus-alert .com<br />
norton-anti-virus-2007 .com <br />
norton-antivirus-2007 .com <br />
norton-antivirus2007 .com <br />
nortonantivirus2007 .com <br />
norton-antivirus-2008 .com <br />
nortonantivirus2008 .com <br />
nortonantivirus2008freedownload .com <br />
norton-antivirus-2009 .com <br />
nortonantivirus2009 .com <br />
norton-antivirus-2010 .com <br />
nortonantivirus2010 .com <br />
nortonantivirus360 .com <br />
nortonantivirus8 .com <br />
nortonantivirusa .com <br />
nortonantivirusactivation .com <br />
norton-antivirus-alert .com <br />
nortonantivirusalerts .com <br />
norton--anti-virus .com <br />
norton-anti-virus .com <br />
norton-antivirus .com <br />
nortonanti-virus .com <br />
nortonantivirus.com <br />
nortonantiviruscom .com <br />
nortonantiviruscorporate .com <br />
nortonantiviruscorporateedition .com <br />
nortonantiviruscoupon .com <br />
nortonantivirusdefinition .com <br />
nortonantivirusdefinitions .com <br />
nortonantivirusdirect .com</b><br />
<br />
Fake Antivirus Inc. is not going away as long as the affiliate based model remains active. If the real vendors were greedy enough not to share the revenues with others, they would have been the one popping up on the radar, compared to the situation where it's the affiliate network's participations greed that's increasing their visibility online.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Cybersquatting Symantec's Norton AntiVirus</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">Cybersquatting Security Vendors for Fraudulent Purposes</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake  Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">EstDomains  and Intercage VS Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake  Security Software Domains Serving Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got  Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake  PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy  Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating  Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The  Malicious ISPs You Rarely See in Any Report</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=88nnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=88nnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=F8uQL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=F8uQL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T1xil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T1xil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eAF4l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eAF4l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rdg2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rdg2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nXveL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nXveL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=moMol"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=moMol" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407645950" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 12:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/vendor branch software">vendor branch software</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/software bundles">software bundles</category>
      <category domain="http://securityratty.com/tag/branch software">branch software</category>
      <category domain="http://securityratty.com/tag/norton antivirus">norton antivirus</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407645950/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</source>
    </item>
    <item>
      <title><![CDATA[John McCain: Desperate and Reckless]]></title>
      <link>http://securityratty.com/article/a299c2b37dd8172588b5324124b6f3cd</link>
      <guid>http://securityratty.com/article/a299c2b37dd8172588b5324124b6f3cd</guid>
      <description><![CDATA[Normally I would not blog about political topics here, but this is an extraordinary time in history and extraordinary times call for extraordinary posts from time-to-time
John McCain is, objectively,...]]></description>
      <content:encoded><![CDATA[<p>Normally I would not blog about political topics here, but this is an extraordinary time in history and extraordinary times call for extraordinary posts from time-to-time.</p>
<p>John McCain is, objectively, a bad decision maker, desperate and reckless.   He knows that his party is in trouble and that the Democrats have the advantage; so what does he do?</p>
<p>First, he picks a very conservative, inexperienced female governor from Alaska who, until recently, did not even have a US passport, as his running mate.  This was an obvious act of desperation, thinking that he could pull the Hillary votes in the election.  A heartbeat from the US Presidency at a time when there are two ongoing wars and our country on the verge of economic collapse and he gambles with a &#8220;Hail Mary&#8221; touchdown pass?  This is not the man we need as President.</p>
<p>Then, not even a member of the Banking committee in the Senate, and self-described &#8220;not knowledgeable on economic issues&#8221;, John McCain tries another &#8220;Hail Mary&#8221; pass by rushing off to DC to &#8220;save the world&#8221; and tries to demand Obama suspend his campaign and the debates?    The US is on the brink of economic collapse and McCain puts politics and election desperation above the future of the country?   This is not the man we need as President.</p>
<p>During the same period, Barack Obama has proven to be cool, intelligent, and a good decision maker.   This should be obvious to anyone with the mind to actually think what is good for the country and not about politics.</p>
<p>John McCain is desperate and reckless.   We don&#8217;t need desperate and reckless people leading this country.</p>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 14:54:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mccain">mccain</category>
      <category domain="http://securityratty.com/tag/john mccain">john mccain</category>
      <category domain="http://securityratty.com/tag/reckless">reckless</category>
      <category domain="http://securityratty.com/tag/bad decision maker">bad decision maker</category>
      <category domain="http://securityratty.com/tag/decision maker">decision maker</category>
      <category domain="http://securityratty.com/tag/economic collapse">economic collapse</category>
      <category domain="http://securityratty.com/tag/extraordinary time">extraordinary time</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/election desperation">election desperation</category>
      <source url="http://www.thecepblog.com/2008/09/26/john-mccain-desperate-and-reckless/">John McCain: Desperate and Reckless</source>
    </item>
    <item>
      <title><![CDATA[Video: Solar Sunrise, the Best FBI-Produced Hacker Flick Ever]]></title>
      <link>http://securityratty.com/article/b257db146426c2603b2608bc49f730e1</link>
      <guid>http://securityratty.com/article/b257db146426c2603b2608bc49f730e1</guid>
      <description><![CDATA[With Ehud &quot;The Analyzer&quot; Tenenbaum back in legal hot water, we've dug up the old FBI training video Solar Sunrise: Dawn of a New Threat dramatizing his 1998 hack attacks against the Pentagon. It's not...]]></description>
      <content:encoded><![CDATA[With Ehud "The Analyzer" Tenenbaum back in legal hot water, we've dug up the old FBI training video Solar Sunrise: Dawn of a New Threat dramatizing his 1998 hack attacks against the Pentagon. It's not the most exciting movie in history, but it still beats Die Hard 4.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=36fb816901008a69e5ef3ac51676079b" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=36fb816901008a69e5ef3ac51676079b" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=UhnRL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=UhnRL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Xmhxl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Xmhxl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=8loal"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=8loal" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lMfML"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lMfML" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=oP6bL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oP6bL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=VOP3l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=VOP3l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=USvOl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=USvOl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UJH8L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UJH8L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/401064241" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/401064256" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video solar sunrise">video solar sunrise</category>
      <category domain="http://securityratty.com/tag/beats die hard">beats die hard</category>
      <category domain="http://securityratty.com/tag/legal hot water">legal hot water</category>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/hack attacks">hack attacks</category>
      <category domain="http://securityratty.com/tag/pentagon">pentagon</category>
      <category domain="http://securityratty.com/tag/dawn">dawn</category>
      <category domain="http://securityratty.com/tag/history">history</category>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/401064256/video-solar-sun.html">Video: Solar Sunrise, the Best FBI-Produced Hacker Flick Ever</source>
    </item>
    <item>
      <title><![CDATA[NFL Players and Senseless Violence]]></title>
      <link>http://securityratty.com/article/9ba2dec13c340b4da207249c75e0576b</link>
      <guid>http://securityratty.com/article/9ba2dec13c340b4da207249c75e0576b</guid>
      <description><![CDATA[Scott Brown writes about the dangers that well known NFL players face on a regular basis. For some, it has even led to their untimely deaths

Interestingly, many players seem reluctant to hire...]]></description>
      <content:encoded><![CDATA[<a href="http://www.pittsburghlive.com/x/pittsburghtrib/sports/steelers/s_588150.html">Scott Brown writes </a>about the dangers that well known NFL players face on a regular basis.  For some, it has even led to their untimely deaths. <br /><span id="fullpost"><br />Interestingly, many players seem reluctant to hire professional security agents.  There is a fear that it will make them seem "self important" and may arouse "indignation".  Is it just me or does this strike anybody else as a stupid reason to forego concerns and plans to safeguard one's own personal safety?    <br /></span><br />Does anybody think any less of a country's President because he/she is flanked by highly trained personal protection specialists?  Of course not. Why? Because history has proven to us that there are disturbed individuals in society who would kill a well known person/celebrity just for their 15 minutes of fame.<br /><br />Why then should an NFL player not be entitled to have a security person(s) looking out for them?  I am fairly sure that the family of Sean Taylor wishes that he had employed personal security and that they had confronted those criminals who broke into his house rather than Mr. Taylor.  <br /><br />There is no shame in taking precautions.  Ask any security consultant for their opinion on whether a person is better off saying; "I wished I had..." or saying;  "I am going to, just in case".  <br /><br />Consider of all of the wonderful music John Lennon could have produced these past years had he employed a Personal Protection Agent to watch his back and protect him from the lunatics of this world.  Artists like Lennon and world class athletes need to be protected so that they can continue to entertain us and thrill us with the gifts that they have been given.  They deserve our support, not our indignation.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 18:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/players">players</category>
      <category domain="http://securityratty.com/tag/nfl players">nfl players</category>
      <category domain="http://securityratty.com/tag/world class athletes">world class athletes</category>
      <category domain="http://securityratty.com/tag/taylor">taylor</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/sean taylor wishes">sean taylor wishes</category>
      <category domain="http://securityratty.com/tag/personal protection specialists">personal protection specialists</category>
      <category domain="http://securityratty.com/tag/scott brown writes">scott brown writes</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <source url="http://www.thebulletproofblog.com/2008/09/nfl-players-and-senseless-violence.html">NFL Players and Senseless Violence</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-15 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</link>
      <guid>http://securityratty.com/article/76641371b3a7f5060624cdd792c7e9cb</guid>
      <description><![CDATA[Quest grabs NetPro to strengthen Windows management wares - Network World NetPros lineup includes tools focused on security/compliance, infrastructure administration and identity/access. Those tools...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.networkworld.com/news/2008/091208-quest.html">Quest grabs NetPro to strengthen Windows management wares - Network World</a><br/>
NetPro’s lineup includes tools focused on security/compliance, infrastructure administration and identity/access.

Those tools include auditing, backup/recovery, policy enforcement, event log management, Exchange migration, group policy management, health/performance and user self-service password management</li>
<li><a href="http://searchsecurity.techtarget.com.au/articles/26900-Are-common-logging-and-audit-standards-emerging-">Are common logging and audit standards emerging? :: SearchSecurity.com.au</a></li>
<li><a href="http://news.zdnet.com/2424-9595_22-218408.html">SaaS market will 'collapse' in two years | Tech News on ZDNet</a><br/>
Q: Won&#039;t people avoid the mistakes of &quot;previous&quot; SaaS incarnations, as you mentioned?

A: People are stupid. History has shown it repeats itself, and people make the same mistakes.</li>
<li><a href="http://www.crmoutsiders.com/2008/08/28/lawson-ceo-saas-will-collapse-in-two-years/">CRM Outsiders &raquo; Blog Archive &raquo; Lawson CEO: SaaS Will &ldquo;Collapse&rdquo; In Two Years</a><br/>
I couldn’t disagree more, but than again it was also Harry Debes that predicted that many of today’s Web 2.0, cell phone gadgets would never catch on either. SaaS is certainly here to say. I</li>
<li><a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">Nerd News: Eventlog to Syslog</a></li>
<li><a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">(ISC)2 Blog: Event Correlation</a></li>
<li><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">Speaking of Security... | Blog Entry: Paul Stamp | Correlation is no silver bullet: 1301</a><br/>
So, when deploying SIEM to improve your security operations, remember that correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs. I call it &quot;working out what type of needles you&#039;ll find in your haystack.&quot;</li>
<li><a href="http://blogs.zdnet.com/Gardner/?p=2723">Systems log analytics offers operators performance insights that set stage for IT transformation | Dana Gardner&rsquo;s BriefingsDirect | ZDNet.com</a></li>
<li><a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals | Nemertes Research</a><br/>
When hunting for a needle in a haystack, after all, making the haystack larger is not an obviously productive course; getting a tool that can assist in the hunt - a magnet, or a metal detector - makes more sense!</li>
<li><a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy | Nemertes Research</a><br/>
It&#039;s not all about security, it&#039;s not all about events, it&#039;s not all about compliance. All those things are critically important to IT, of course, but even more fundamental is the task of keeping things running.</li>
<li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">jdm's Blog: How worthwhile is logging?</a><br/>
Logs are like a warm blanket; verbose logging means you can know what&#039;s happening on your systems if you keep up with the logs.  At the same time, logs become a burden very very easily, and they are easy to ignore.</li>
<li><a href="http://blog.gerhards.net/2008/07/what-is-event-and-what-event-log.html">Rainer's Blog: What is an Event? And what an Event Log?</a></li>
<li><a href="http://duckdown.blogspot.com/2008/07/taming-documentum-audit-trail.html">Enterprise Architecture: From Incite comes Insight...: Taming the Documentum Audit Trail</a><br/>
First and foremost, it is a good security principle to separate log data from the system.</li>
<li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">Log management is a pain | Thomas Nicholson</a><br/>
So for an administrator to not care about logs was a shock.</li>
<li><a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">thebaumblog &raquo; Blog Archive &raquo; Life after SIEM. Situational Awareness is next.</a><br/>
Life after SIEM. Situational Awareness is next.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393875149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/event log management">event log management</category>
      <category domain="http://securityratty.com/tag/event log">event log</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/saas market">saas market</category>
      <category domain="http://securityratty.com/tag/saas">saas</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393875149/anton18">Links for 2008-09-15 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Blamestorming]]></title>
      <link>http://securityratty.com/article/95618fa2d7ec7b889e72d37343245d7a</link>
      <guid>http://securityratty.com/article/95618fa2d7ec7b889e72d37343245d7a</guid>
      <description><![CDATA[So, let's recap the sequence of events
The Sun-Sentinel newspaper in Fort Lauderdale accidentally republishes a six-year-old news story about the bankruptcy of UAL. It wasn't on the home page, but...]]></description>
      <content:encoded><![CDATA[<p>So, let's recap the sequence of events:</p>  <ol>   <li>The <em>Sun-Sentinel</em> newspaper in Fort Lauderdale accidentally republishes a six-year-old news story about the bankruptcy of UAL. It wasn't on the home page, but instead buried somewhere inside the web site. </li>    <li>Google's news crawler (an automated thing, remember) finds the story and incorporates it as part of its news feed. </li>    <li>Investors see the story, and immediately react. When UAL's stock <a href="http://money.cnn.com/2008/09/08/news/companies/united_airlines/index.htm" target="_blank">plunged 76% to a low of $3</a>, Nasdaq shut down trading. Eventually trading resumed, and the stock closed at just under $11, losing about 11%. </li>    <li>United blamed Tribune Company (the owner of the <em>Sun-Sentinel</em>) for <a href="http://www.cnbc.com/id/26608126" target="_blank">&quot;irresponsibly&quot; changing the date</a> on the story and <a href="http://media.corporate-ir.net/media_files/irol/83/83680/articles/bankruptcy_statementFINAL2.pdf" target="_blank">demanded a retraction</a>. </li>    <li>Tribune Company blamed Google, claiming they've <a href="http://www.eweek.com/c/a/Search-Engines/Tribune-Blames-Google-for-UAL-Bankruptcy-Story/?kc=rss" target="_blank">had issues</a> with Google's crawler &quot;for months.&quot; </li> </ol>  <p>Who will blame be shifted to next?</p>  <p>Look -- if people haven't realized by now that the Internet pretty much <a href="http://www.archive.org/index.php" target="_blank">lacks a delete function</a>, then (IMNSHO) it becomes the requirement of <em>each and every one of us</em> to pay close attention to what we're reading, to use our own big brains and fine-tuned bullshit detectors to suss out whether something makes sense.</p>  <p>Since this is my blog, I'm going to parcel out blame the way I see it:</p>  <ul>   <li><strong>United: 0%.</strong> If the concept of &quot;negative blame&quot; made any sense, then I'd actually write <strong>&#8722;&#8734;</strong> (that's a negative infinity, in case your character set is different than mine). </li>    <li><strong>Google: 5%.</strong> How can an automated crawler know that a newly-dated story isn't really new? Well, those folks over there at Google are smart. Certainly it shouldn't be that difficult to compare a &quot;new&quot; article against existing ones. Content hashes won't work as a comparison tool, because the date would be included in the hash computation, thus making the hashes different anyway. Full-text comparisons? Sure, it would take a lot of horsepower. Perhaps not every &quot;new&quot; story needs comparison, but at least the crawler could submit to the comparator any stories that ought to be verified (say those with the word &quot;bankruptcy&quot; in them). </li>    <li><strong>Tribune Company: 30%.</strong> Hey guys, <em>you changed the date on the article.</em> Don't go blaming someone else for your screw-up. </li>    <li><strong>Investors: 65%.</strong> If you're using an automated news aggregator (remember, an aggregator is not a <em>source</em> of news) to make major financial decisions -- decisions that affect the livelihoods of thousands (maybe millions) of people -- well, you're a moron. You should know that incorrect information can be just as instantly available as correct information. Verify potentially damaging claims before engaging in reckless behavior. </li> </ul>  <p>What's this got to do with security? I don't know, maybe nothing directly related. But it certainly raises the question -- what if someone intentionally wanted to cause nearly permanent damage to a person or a corporation? Malicious content, disguised as &quot;news,&quot; certainly seems to have become a potentially successful attack vector this week.</p>  <p>Worried about a social engineering attack on a massive scale? I suspect that what happened Monday (8 September) <em>was</em> the largest social engineering attack in history -- although I wouldn't classify it as intentionally malicious. Just you wait until the <a href="http://en.wikipedia.org/wiki/Meme" target="_blank">idea spreads</a>.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3122810" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 02:03:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/news aggregator">news aggregator</category>
      <category domain="http://securityratty.com/tag/news feed">news feed</category>
      <category domain="http://securityratty.com/tag/six-year-old news story">six-year-old news story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/news crawler">news crawler</category>
      <category domain="http://securityratty.com/tag/tribune company">tribune company</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/successful attack vector">successful attack vector</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/11/blamestorming.aspx">Blamestorming</source>
    </item>
    <item>
      <title><![CDATA[New addition to the starting line-up...]]></title>
      <link>http://securityratty.com/article/bba1eed8238898849e065890447b0038</link>
      <guid>http://securityratty.com/article/bba1eed8238898849e065890447b0038</guid>
      <description><![CDATA[Hey all Dave here
Wanted to drop a quick note to introduce the latest member of the SDL team - Katie Moussouris
Many of you may already know Katie from her past work on the MSRC Ecosystem Strategy...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><?xml:namespace prefix = o /><o:p>Hey all – Dave here…</o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Wanted to drop a quick note to introduce the latest member of the SDL team - Katie Moussouris!</o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Many of you may already know Katie from her past work on the <A class="" title="MSRC Ecosystem Strategy Team" href="http://blogs.technet.com/ecostrat/default.aspx" target=_blank mce_href="http://blogs.technet.com/ecostrat/default.aspx">MSRC Ecosystem Strategy Team</A> or her tenure at Symantec and @Stake. </o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Katie has joined the SDL team to help drive crucial elements of our SDL outreach effort; her primary responsibility will be managing our relationships with security consulting and training partners. She’ll additionally be tasked with ongoing analysis of the SDL – with a goal of assisting industry verticals that are looking to apply the SDL in critical computing scenarios.&nbsp; </o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>It goes without saying that she will be a regular contributor on the SDL Blog – but given her expertise, it’s likely she’ll continue to blog on an occasional basis over on Ecostrat...</o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Anyway – here’s Katie in her own words!</o:p></FONT></FONT></P>
<BLOCKQUOTE>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p><EM>Katie Moussouris is a Senior Security Program Manager in the Security Development Lifecycle (SDL) Outreach Team, working to bring Microsoft’s SDL to partners, vendors and customers in order to improve the security of the Internet as a whole. Katie began her nerdy life programming her C64 in grade school, writing her own Zork-like text-based adventure – which was of limited use, since she had no friends and she knew all the puzzles in her own game.&nbsp; Good thing she eventually left her room and found some like-minded people at a local 2600 meeting.</EM></o:p></FONT></FONT></P></BLOCKQUOTE>
<BLOCKQUOTE>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p><EM>Katie’s professional background is application security, having come from Symantec by way of the @stake acquisition. Katie founded the Microsoft Vulnerability Research Program (MSVR), extending the focus of Microsoft’s security vulnerability research to third party software.&nbsp; Katie also founded and ran the Symantec Vulnerability Research Program, the first program of its kind in Symantec's history to allow the publication through Responsible Disclosure of original vulnerability advisories discovered by Symantec researchers. In addition to performing security research, Katie has been an application penetration tester for Fortune 500 companies across numerous industries. She has uncovered serious vulnerabilities during the course of her work before they could be widely exploited by hooligans and criminals for either fun or profit, respectively.<BR></P></BLOCKQUOTE></EM></o:p></FONT></FONT><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8945661" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 18:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/sdl outreach effort">sdl outreach effort</category>
      <category domain="http://securityratty.com/tag/katie">katie</category>
      <category domain="http://securityratty.com/tag/katie moussouris">katie moussouris</category>
      <category domain="http://securityratty.com/tag/microsofts sdl">microsofts sdl</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security research">security research</category>
      <category domain="http://securityratty.com/tag/sdl team">sdl team</category>
      <category domain="http://securityratty.com/tag/security development lifecycle">security development lifecycle</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/11/new-addition-to-the-starting-line-up.aspx">New addition to the starting line-up...</source>
    </item>
  </channel>
</rss>
