<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: institute]]></title>
    <link>http://securityratty.com/tag/institute</link>
    <description></description>
    <pubDate>Wed, 02 Jul 2008 18:30:21 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Network skill level gap is growing, but growth opportunities abound!]]></title>
      <link>http://securityratty.com/article/a4929ca88458feb902376bc7bd38e824</link>
      <guid>http://securityratty.com/article/a4929ca88458feb902376bc7bd38e824</guid>
      <description><![CDATA[A recent IDC report sponsored by the Cisco Learning Institute reveals a huge networking skills gap is emerging in North America, which spells trouble for enterprises. Listen to this: 600,000 IT...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/exam.jpg" border="0" alt="Test Quiz" width="240" height="160" align="left" /> A recent IDC report sponsored by the Cisco Learning Institute reveals <a href="http://www.networkworld.com/newsletters/itlead/2008/080408itlead1.html" target="_blank">a huge networking skills gap</a> is emerging in North America, which spells trouble for enterprises. Listen to this: “600,000 IT workers were needed to install, configure, manage and secure networks in North America in 2007, 14% of the total IT workforce.” However, IDC reports that another 180,000 engineers with wireless as well as traditional network engineering experience will need to be added by 2011 to keep pace with advances in technology that is transforming the role of the network.</p>
<p>The convergence of voice and video traffic are quickly transforming the growing complexity of networks at a torrid pace. IDC estimates that the skills gap in VOIP should grow to 19% by 2011.</p>
<p>This changing profile in the role of the network plays a key role in the skills shortage. Network enabled collaboration tools such as social networking apps and the Webex conferencing/collaboration solutions we use in our business each and every day are demanding a new set of IT skills to deliver business value.</p>
<p>My perspective is two-fold on this issue; the first is what I have seen in the resources we have attempted to hire! We give a very straightforward quick written/oral test to all new technical hires. This requires basic networking knowledge and some Unix commands. On average, (after filters from reputable recruiting firms, some with 5-10 years experience) less than 10% pass muster for the first filter we use in our hiring process. This is a troubling fact, which has cost us considerable time and effort to secure the right resources with competent skills. So I can say from our market assessment in a very strong technological job skills market, core Unix and networking foundation skills are slipping.</p>
<p>The second is that we as an IT Operations Management (ITOM) industry need to keep pushing hard to build better proactive and intuitive solutions to aggregate instrumentation from all Data Center tools, including more work around VOIP, video streaming, and collaboration so that we can ease this transition. If ITOM solutions become more proactive across the typical Cisco infrastructure that is commonly installed in the Data Center, we can free up some additional time for advanced “emerging technologies” training where existing IT workers can enhance their core skills and re-invigorate their careers. We have to do a much better job of getting our existing IT professionals trained on emerging technologies!</p>
<p>While there’s less that ScienceLogic can do around <a href="http://www.cisco.com/web/learning/le3/learning_career_certifications_and_learning_paths_home.html" target="_blank">training</a>, we certainly strive to do our part to enhance a day in the life of the networking engineers who use our solutions to simplify monitoring of increasingly complex networking, <a href="http://www.networkworld.com/news/2008/080608-p-g.html" target="_blank">Wireless, VOIP, and collaboration needs</a>.</p>
]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 17:06:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/foundation skills">foundation skills</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/skills gap">skills gap</category>
      <category domain="http://securityratty.com/tag/skills shortage">skills shortage</category>
      <category domain="http://securityratty.com/tag/intuitive solutions">intuitive solutions</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/traditional network">traditional network</category>
      <category domain="http://securityratty.com/tag/recent idc report">recent idc report</category>
      <source url="http://blog.sciencelogic.com/network-skill-level-gap-is-growing-but-growth-opportunities-abound/08/2008">Network skill level gap is growing, but growth opportunities abound!</source>
    </item>
    <item>
      <title><![CDATA[Red Light Cameras Don't Work]]></title>
      <link>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</link>
      <guid>http://securityratty.com/article/8352bdbeaa301a76267200c64791415d</guid>
      <description><![CDATA[Interesting : the solution to one problem causes another. &quot;The rigorous studies clearly show red-light cameras don't work,&quot; said lead author Barbara Langland-Orban, professor and chair of health...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.ridelust.com/red-light-cameras-just-dont-work/">Interesting</a>: the solution to one problem causes another.</p>

<blockquote>"The rigorous studies clearly show red-light cameras don't work," said lead author Barbara Langland-Orban, professor and chair of health policy and management at the USF College of Public Health. "Instead, they increase crashes and injuries as drivers attempt to abruptly stop at camera intersections."

<p>Comprehensive studies from North Carolina, Virginia, and Ontario have all reported cameras are associated with increases in crashes. The study by the Virginia Transportation Research Council also found that cameras were linked to increased crash costs. The only studies that conclude cameras reduced crashes or injuries contained "major research design flaws," such as incomplete data or inadequate analyses, and were always conducted by researchers with links to the Insurance Institute for Highway Safety. The IIHS, funded by automobile insurance companies, is the leading advocate for red-light cameras since insurance companies can profit from red-light cameras by way of higher premiums due to increased crashes and citations.</blockquote></p>

<p>And, of course, the agenda of the government is to increase revenue due to fines:</p>

<blockquote>A 2001 paper by the Office of the Majority Leader of the U.S. House of Representatives reported that red-light cameras are "a hidden tax levied on motorists." The report came to the same conclusions that all of the other valid studies have, that red-light cameras are associated with increased crashes and that the timings at yellow lights are often set too short to increase tickets for red-light running. That's right, the state actually tampers with the yellow light settings to make them shorter, and more likely to turn red as you're driving through them.

<p>In fact, six U.S. cities have been found guilty of shortening the yellow light cycles below what is allowed by law on intersections equipped with cameras meant to catch red-light runners. Those local governments have completely ignored the safety benefit of increasing the yellow light time and decided to install red-light cameras, shorten the yellow light duration, and collect the profits instead.</p>

<p>The cities in question include Union City, CA, Dallas and Lubbock, TX, Nashville and Chattanooga, TN, and Springfield, MO, according to Motorists.org, which collected information from reports from around the country.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GkyduK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GkyduK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gARYoK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gARYoK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:19:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/red">red</category>
      <category domain="http://securityratty.com/tag/red-light">red-light</category>
      <category domain="http://securityratty.com/tag/red-light runners">red-light runners</category>
      <category domain="http://securityratty.com/tag/install red-light cameras">install red-light cameras</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/red-light cameras">red-light cameras</category>
      <category domain="http://securityratty.com/tag/conclude cameras">conclude cameras</category>
      <category domain="http://securityratty.com/tag/studies">studies</category>
      <category domain="http://securityratty.com/tag/rigorous studies">rigorous studies</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/red_light_camer.html">Red Light Cameras Don't Work</source>
    </item>
    <item>
      <title><![CDATA[NIST revises SP800-60 Volume 1: Go forth and classify]]></title>
      <link>http://securityratty.com/article/49cded7ac0f52666b282669d6a8216be</link>
      <guid>http://securityratty.com/article/49cded7ac0f52666b282669d6a8216be</guid>
      <description><![CDATA[According to GCN , NIST has released a revision to SP800-60 Vol 1 and Volume 2 . The two-volume Special Publication 800-60 Revision 1, Guide for Mapping Types of Information and Information Systems to...]]></description>
      <content:encoded><![CDATA[According to <a href="http://www.gcn.com/online/vol1_no1/46877-1.html" target="_blank">GCN</a>,  NIST has released a revision to <a href="http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf" target="_blank">SP800-60 Vol 1</a> and <a href="http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf" target="_blank">Volume 2</a>. The two-volume Special Publication 800-60 Revision 1, “Guide for Mapping Types of Information and Information Systems to Security Categories,” is a revision of guidelines published in 2004.<br /><span style="font-weight:bold;">Asset and data classification is the keystone to building proper protective schemes. Simply, if you don't know what you have, you can't apply the appropriate levels of value and importance.</span><br />SP 800-60's intro reads:<br />"The identification of information processed on an information system is essential to the proper selection of security controls and ensuring the confidentiality, integrity, and availability of the system and its information. The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60 has been developed to assist Federal government agencies to categorize information and information systems."<br />Give this document a read; while it is geared to a federal agency audience, it is entirely useful for baselining your own classification process.]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 04:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/volume">volume</category>
      <category domain="http://securityratty.com/tag/information system">information system</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information systems">information systems</category>
      <category domain="http://securityratty.com/tag/two-volume special publication">two-volume special publication</category>
      <category domain="http://securityratty.com/tag/special publication">special publication</category>
      <category domain="http://securityratty.com/tag/nist">nist</category>
      <category domain="http://securityratty.com/tag/federal agency audience">federal agency audience</category>
      <category domain="http://securityratty.com/tag/proper protective schemes">proper protective schemes</category>
      <source url="http://holisticinfosec.blogspot.com/2008/08/nist-revises-sp-800-60-volume-1-go.html">NIST revises SP800-60 Volume 1: Go forth and classify</source>
    </item>
    <item>
      <title><![CDATA[Gallery: Images From the 16th Annual DefCon]]></title>
      <link>http://securityratty.com/article/fb7d8c7afe69bef6c3f3ee2131da03a6</link>
      <guid>http://securityratty.com/article/fb7d8c7afe69bef6c3f3ee2131da03a6</guid>
      <description><![CDATA[Photo: Dave Bullock/Wired.com
LAS VEGAS -- Last weekend, more than 9,000 hackers, freaks, feds and geeks gathered for the 16th annual DefCon, the world's largest computer security convention
Wired.com...]]></description>
      <content:encoded><![CDATA[<img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_2_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>LAS VEGAS -- Last weekend, more than 9,000 hackers, freaks, feds and geeks gathered for the 16th annual DefCon, the world's largest computer security convention. </p>

<p>Wired.com brought you <a href="http://blog.wired.com/27bstroke6/defcon/index.html">live coverage</a> of the most newsworthy events at DefCon 16. Here are some photos from the lighter side of the conference.</p>

<p><strong>Left:</strong> South Korean hackers compete in the Capture the Flag competition. The goal is to hack into and keep control of targeted servers.</p>
<img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_3_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Mr. Sinister and Dragon Cracker battle it out in a round of <cite>Guitar Hero</cite> -- one of DefCon's newest competitions.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_1_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Bringing-your-own-booze supply ensures optimal buzz at DefCon. Shortly after this picture was taken, hotel security escorted this backpack-hacker to his room.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_4_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Computer geeks from the National Institute of Standards and Technology set up a network secured with quantum encryption in a conference room at DefCon. The quantum-entangled photons are being used to encrypt a video stream across a line-of-site network.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_5_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>A compact optical bench and an atomic clock (left) are used to secure a network with quantum encryption.   </p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_6_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>In the Lock Pick Pavilion, DefCon attendees Dustin, Jennalynn and Kunfoozball practice their lock-picking skills. </p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_7_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>DefCon founder and organizer Jeff Moss, aka Dark Tangent, at the conference's closing ceremony Sunday.</p>

<img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_9_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>A collection of black badges awaits the winners of the various competitions. These badges give their holders lifetime entry to DefCon.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_11_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>One of DefCon's logos, the smiley-faced skull and crossbones, is welded inside a yellow sphere. The sphere is the primary stage of one of the most difficult competitions at DefCon: <a href="http://blog.wired.com/27bstroke6/2008/08/the-defcon-16-m.html">The Mystery Challenge</a>. </p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_15_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>Unbeknownst to attendees, this laptop is sniffing RFID tags and taking photos of their owners when they pass in front of the detectors. RFID tags are used in everything from building access to some credit cards.</p><img src='http://www.wired.com/images/slideshow/2008/08/gallery_defcon16/defcon_gallery_12_t.jpg'></img>: Photo: Dave Bullock/Wired.com<p>At the closing ceremony, DefCon organizers turn off the lights while the attendees wave their <a href="http://blog.wired.com/27bstroke6/2008/08/exclusive-defco.html">high-tech badges</a> back and forth.</p><br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=68dd26e52adb5b467e7c3e6137cda635"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=68dd26e52adb5b467e7c3e6137cda635"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=68dd26e52adb5b467e7c3e6137cda635" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=5LS6EK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=5LS6EK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=K4FTfk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=K4FTfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IRLAWk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IRLAWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=NFFkrK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=NFFkrK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=oS38eK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oS38eK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qIurlk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qIurlk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TG21wk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TG21wk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=n3oFWK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=n3oFWK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/362249101" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/362249108" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 14:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/16th annual defcon">16th annual defcon</category>
      <category domain="http://securityratty.com/tag/defcon founder">defcon founder</category>
      <category domain="http://securityratty.com/tag/attendees wave">attendees wave</category>
      <category domain="http://securityratty.com/tag/attendees">attendees</category>
      <category domain="http://securityratty.com/tag/defcon organizers">defcon organizers</category>
      <category domain="http://securityratty.com/tag/defcon attendees dustin">defcon attendees dustin</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/dave">dave</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/362249108/gallery_defcon16">Gallery: Images From the 16th Annual DefCon</source>
    </item>
    <item>
      <title><![CDATA[No, FISMA Doesnt Require That, Silly Product Pushers]]></title>
      <link>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</link>
      <guid>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</guid>
      <description><![CDATA[Post #9678291 on why people dont understand what FISMA really is : Secure64 DNSSEC Press Releases
FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security...]]></description>
      <content:encoded><![CDATA[<p>Post #9678291 on <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">why people don&#8217;t understand what FISMA really is</a>:  <a href="http://www.domaininformer.com/news/press/310708DNSSEC.html" target="_blank">Secure64 DNSSEC Press Releases</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security specifications set by the National Institute of Standards and Technology, and it has been reported that the federal government<span id="bwanpa5">’</span>s Office of Management and Budget (OMB) plans to begin enforcing DNSSEC requirements through an auditing process, setting the standard for DNS best practices.&#8221;</em></p>
<p>Yep, if you stamp FISMA on it, people will buy it, maybe in your PR department&#8217;s wettest and wildest dreams.  Guys, it&#8217;s been 6 years, that kind of marketing doesn&#8217;t work nowadays, mostly because we spent ourselves into oblivion buying junkware similar to yours and now we&#8217;re all jaded.</p>
<p>Now don&#8217;t get me wrong, DNSSEC is a good thing, especially this month.  But there is something I need to address:  FISMA requires good security management with a dozen or so key indicators, not a solution down to the technical level.  Allusions to OMB are just FUD, FUD, and more FUD because unless it&#8217;s in a memo to agency heads, it&#8217;s all posturing&#8211;something everybody in this town knows how to do very well.  OMB would rather stay out of mandating DNSSEC and maybe give a &#8220;due date&#8221; once NIST has a final standard.</p>
<p>My one word of wisdom for today:  anybody who tries to sell a product and <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">uses FISMA as the &#8220;compelling event&#8221; has no clue what they&#8217;re talking about</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers&amp;url=http://www.guerilla-ciso.com/archives/440&amp;version=0.7" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/440&amp;t=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2mnw8J"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2mnw8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=HAXdPj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=HAXdPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/351599310" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 10:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma requires">fisma requires</category>
      <category domain="http://securityratty.com/tag/fisma act encourages">fisma act encourages</category>
      <category domain="http://securityratty.com/tag/stamp fisma">stamp fisma</category>
      <category domain="http://securityratty.com/tag/dnssec">dnssec</category>
      <category domain="http://securityratty.com/tag/dnssec requirements">dnssec requirements</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/351599310/440">No, FISMA Doesnt Require That, Silly Product Pushers</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</link>
      <guid>http://securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 13:20:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://www.blueboxpodcast.com/2008/07/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</link>
      <guid>http://securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=fNSqdO"><img src="http://feeds.feedburner.com/~a/BlueBox?i=fNSqdO" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=lbjc2J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lbjc2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=7bk2TJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7bk2TJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=3wwMDJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=3wwMDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=sD0qZJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=sD0qZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Y7dDJj"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Y7dDJj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uKgX6J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uKgX6J" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/336458984" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 12:22:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/336458984/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Unpatched Windows PCs fall to hackers in under 5 minutes, says ISC]]></title>
      <link>http://securityratty.com/article/2feae0d20835474134463191eb0a3176</link>
      <guid>http://securityratty.com/article/2feae0d20835474134463191eb0a3176</guid>
      <description><![CDATA[Hackers can find and compromise an unpatched Windows PC in less than five minutes after it's connected to the Internet, the SANS Institute's Internet Storm Center said...]]></description>
      <content:encoded><![CDATA[Hackers can find and compromise an unpatched Windows PC in less than five minutes after it's connected to the Internet, the SANS Institute's Internet Storm Center said today.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=kQslop"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=kQslop" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/335295158" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet storm center">internet storm center</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/minutes">minutes</category>
      <category domain="http://securityratty.com/tag/sans institute">sans institute</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/compromise">compromise</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/335295158/article.do">Unpatched Windows PCs fall to hackers in under 5 minutes, says ISC</source>
    </item>
    <item>
      <title><![CDATA[Hundreds of Thousands of Laptops Lost at U.S. Airports Annually]]></title>
      <link>http://securityratty.com/article/c9073d10b076742bcd87430314c09618</link>
      <guid>http://securityratty.com/article/c9073d10b076742bcd87430314c09618</guid>
      <description><![CDATA[This is a weird statistic : Some of the largest and medium-sized U.S. airports report close to 637,000 laptops lost each year, according to the Ponemon Institute survey released Monday. Laptops are...]]></description>
      <content:encoded><![CDATA[This is a <a href="http://www.pcworld.com/businesscenter/article/147739/laptops_lost_like_hot_cakes_at_us_airports.html_">weird statistic</a>:

<blockquote>Some of the largest and medium-sized U.S. airports report close to 637,000 laptops lost each year, according to the Ponemon Institute survey released Monday. Laptops are most commonly lost at security checkpoints, according to the survey.

Close to 10,278 laptops are reported lost every week at 36 of the largest U.S. airports, and 65 percent of those laptops are not reclaimed, the survey said. Around 2,000 laptops are recorded lost at the medium-sized airports, and 69 percent are not reclaimed.

Travelers seem to lack confidence that they will recover lost laptops. About 77 percent of people surveyed said they had no hope of recovering a lost laptop at the airport, with 16 percent saying they wouldn't do anything if they lost their laptop during business travel. About 53 percent said that laptops contain confidential company information, with 65 percent taking no steps to protect the information.</blockquote>

I don't know how to generalize that to a total number of lost laptops in the U.S.; let's call it 750,000.  At $1,000 per laptop -- a very conservative estimate -- that's $750 million in lost laptops annually.  Most are lost at security checkpoints, and I'm sure the numbers went up considerably since those checkpoints got more annoying after 9/11.

There aren't a lot of real numbers about the costs of increased airport security.  We pay in time, in anxiety, in inconvenience.  But we also pay in goods.  TSA employees <a href="http://www.cbsnews.com/stories/2004/09/13/eveningnews/main643165.shtml">steal out of suitcases</a>.  And opportunists steal hundreds of millions of dollars of laptops annually.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LSh7nJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LSh7nJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=DT8VQJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=DT8VQJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 04 Jul 2008 04:20:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/recover lost laptops">recover lost laptops</category>
      <category domain="http://securityratty.com/tag/lost laptops">lost laptops</category>
      <category domain="http://securityratty.com/tag/lost">lost</category>
      <category domain="http://securityratty.com/tag/laptops lost">laptops lost</category>
      <category domain="http://securityratty.com/tag/commonly lost">commonly lost</category>
      <category domain="http://securityratty.com/tag/airports">airports</category>
      <category domain="http://securityratty.com/tag/lost laptop">lost laptop</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/hundreds_of_tho.html">Hundreds of Thousands of Laptops Lost at U.S. Airports Annually</source>
    </item>
    <item>
      <title><![CDATA[40% of surfers don't bother with browser security updates]]></title>
      <link>http://securityratty.com/article/2d8e61b1813dbaaaa2a656ba6403be33</link>
      <guid>http://securityratty.com/article/2d8e61b1813dbaaaa2a656ba6403be33</guid>
      <description><![CDATA[A new collaborative study between Google, IBM, and the Swiss Federal Institute of Technology suggests that users are slower to move between product updates than they should beespecially those using...]]></description>
      <content:encoded><![CDATA[A new collaborative study between Google, IBM, and the Swiss Federal Institute of Technology suggests that users are slower to move between product updates than they should be—especially those using Internet Explorer. The researchers believe that browsers could learn from the food industry, of all things.]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 18:30:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/swiss federal institute">swiss federal institute</category>
      <category domain="http://securityratty.com/tag/collaborative study">collaborative study</category>
      <category domain="http://securityratty.com/tag/technology suggests">technology suggests</category>
      <category domain="http://securityratty.com/tag/internet explorer">internet explorer</category>
      <category domain="http://securityratty.com/tag/food industry">food industry</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <source url="http://digg.com/security/40_of_surfers_don_t_bother_with_browser_security_updates">40% of surfers don't bother with browser security updates</source>
    </item>
  </channel>
</rss>
