<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: it-service]]></title>
    <link>http://securityratty.com/tag/it-service</link>
    <description></description>
    <pubDate>Fri, 03 Oct 2008 11:49:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Schwarzenegger again nixes data breach bill]]></title>
      <link>http://securityratty.com/article/b18549d7ba497f2c9b45a58944bc57c5</link>
      <guid>http://securityratty.com/article/b18549d7ba497f2c9b45a58944bc57c5</guid>
      <description><![CDATA[For the second time in 12 months, California Gov. Arnold Schwarzenegger has vetoed legislation that would have set new IT security requirements designed to protect credit and debit card data in retail...]]></description>
      <content:encoded><![CDATA[For the second time in 12 months, California Gov. Arnold Schwarzenegger has vetoed legislation that would have set new IT security requirements designed to protect credit and debit card data in retail systems.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b4feb71108223eaa89889cda3541d3d6:%2Bljl9N2lkICVQyC7YvFTj8%2BulBSs1g0Y1L2LgWtXMhrNtzMSGzWQI6bj6OAeiGhcEJo49ovSwC7v'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2f25bd788cf96f70a15cacfe9ec9e5a6:8ydJYBLJTV2a2qbThHy1OXXO7uSzZRPYG5ScVAXYkRWlrLXXYCtZWBYhprglpTEsNDsz%2Bi7tbZpuUg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:51e28f79df211aa7e11d1aab44e249eb:exI4silRTX6JyhzMbp%2BjJJPq5fb8Ybgoqrt3J1gnbHhvvDghRhgxNrn4Tw89jarbv5Ebp4x3GCME6Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1333fb505caf33a1f6952bf856e36ccd:W1lOI5ZOccLDy3pEtSPXVoIxe%2FBd%2BjeF1E8w8a7fMBbAG9%2FW7WT3Ua%2F0MHdHYxW%2Blm4WffE%2BM%2BffxA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=486715e67b26aa759fe6b7d5bddf9a61" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=486715e67b26aa759fe6b7d5bddf9a61" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/debit card data">debit card data</category>
      <category domain="http://securityratty.com/tag/protect credit">protect credit</category>
      <category domain="http://securityratty.com/tag/arnold schwarzenegger">arnold schwarzenegger</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/california gov">california gov</category>
      <category domain="http://securityratty.com/tag/retail systems">retail systems</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/legislation">legislation</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=486715e67b26aa759fe6b7d5bddf9a61">Schwarzenegger again nixes data breach bill</source>
    </item>
    <item>
      <title><![CDATA[Supremes Mull Whether Bad Databases Make 4 Illegal Searches]]></title>
      <link>http://securityratty.com/article/4f2b2dae87ae3df59b42743bd8f65b1b</link>
      <guid>http://securityratty.com/article/4f2b2dae87ae3df59b42743bd8f65b1b</guid>
      <description><![CDATA[If a false entry in a database leads to a unconstitutional police search that reveals illegal drugs, does the government get to hold it against...]]></description>
      <content:encoded><![CDATA[If a false entry in a database leads to a unconstitutional police search that reveals illegal drugs, does the government get to hold it against you?]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 13:30:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reveals illegal drugs">reveals illegal drugs</category>
      <category domain="http://securityratty.com/tag/database leads">database leads</category>
      <category domain="http://securityratty.com/tag/false entry">false entry</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/hold">hold</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <source url="http://digg.com/security/Supremes_Mull_Whether_Bad_Databases_Make_4_Illegal_Searches">Supremes Mull Whether Bad Databases Make 4 Illegal Searches</source>
    </item>
    <item>
      <title><![CDATA[Proxy Caches are a Challenging Threat to Internet Security]]></title>
      <link>http://securityratty.com/article/39c5fc50305be98bca63ce241a75ebbd</link>
      <guid>http://securityratty.com/article/39c5fc50305be98bca63ce241a75ebbd</guid>
      <description><![CDATA[Proxy caches, combined with poorly written session management code, can easily leads to serious security flaws similar to what we highlighted in A New Security Breach in Google Docs Revealed
Web...]]></description>
      <content:encoded><![CDATA[<div class="entry-body">
<p>Proxy caches, combined with poorly written session management code, can easily leads to serious security flaws similar to what we highlighted in <a href="http://blog.isc2.org/isc2_blog/2008/09/serious-securit.html">A New Security Breach in Google Docs Revealed</a>.</p>
<p>Web developers have no control over proxy caches in the Internet. However, developers do have control of the code they write and their admin teams have configuration control of their web servers. Developers must assume the worst case Internet scenario with aggressive Internet cache management policies that serve cached data for economic and performance reasons.</p>
<p>As a consequence, this fact-of-life on the Internet sometimes results in multiple web clients being sent the same Set-Cookie HTTP headers, for example.  Caching proxy servers should obtain a fresh cookie for the each new client request. Ideally, proxy caches should not cache session management cookies and distribute cached cookies to multiple clients. However, application developers cannot assume that proxy caches are well behaved, especially for applications where security and privacy are required.</p>
<p>Web developers cannot know whether their content is consumed directly or via a proxy cache. Developers also cannot assume that the HTTP responses will be delivered to the intended browser. Moreover, developers cannot be sure that the intended browser even receives the intended content.  For example, a session ID issued to a client gets used while it is valid or until abandoned and expired. If it is served and delivered in response to an unencrypted HTTP GET request, there’s no guarantee it will be consumed by the intended web browser.</p>
<p>Ideally, SSL should be used on all web transactions that require confidentiality and privacy, including our recent <a href="http://blog.isc2.org/isc2_blog/2008/09/serious-securit.html">Google Docs breach</a>.  On the other hand, even SSL is not foolproof. For example, many web developers do not correctly set the &#8220;Encrypted Sessions Only&#8221; cookie property. These incorrectly configured “secure” servers will send HTTPS cookies in the open, unencrypted.</p>
<p>There be dragons &#8230;</p>
</div>
<hr />Note: Reposted from the <a href="http://blog.isc2.org/isc2_blog/2008/09/proxy-caches-ar.html" target="_blank">(ISC)2 blog</a>.</p>
]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 06:41:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/proxy caches">proxy caches</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/web developers">web developers</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/application developers">application developers</category>
      <category domain="http://securityratty.com/tag/security flaws similar">security flaws similar</category>
      <category domain="http://securityratty.com/tag/session management code">session management code</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://www.thecepblog.com/2008/10/05/proxy-caches-are-a-challenging-threat-to-internet-security/">Proxy Caches are a Challenging Threat to Internet Security</source>
    </item>
    <item>
      <title><![CDATA[Supremes Mull Whether Bad Databases Make for Illegal Searches]]></title>
      <link>http://securityratty.com/article/53061d54dc98b3433afafae6b86ce18d</link>
      <guid>http://securityratty.com/article/53061d54dc98b3433afafae6b86ce18d</guid>
      <description><![CDATA[If a false entry in a database leads to an unconstitutional police search that reveals illegal drugs, does the government get to hold it against you? That's the question the Supreme Court will tackle...]]></description>
      <content:encoded><![CDATA[If a false entry in a database leads to an unconstitutional police search that reveals illegal drugs, does the government get to hold it against you? That's the question the Supreme Court will tackle on Tuesday.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=f68be9e833c6a3592072d0d80152071e" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f68be9e833c6a3592072d0d80152071e" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=WKgpM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=WKgpM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=FMomm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=FMomm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=kYqgm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=kYqgm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=r9U8M"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=r9U8M" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=5O9YM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=5O9YM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=KRCFm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=KRCFm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nFTXm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nFTXm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=PT9OM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=PT9OM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/411657927" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/411657957" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 17:26:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reveals illegal drugs">reveals illegal drugs</category>
      <category domain="http://securityratty.com/tag/database leads">database leads</category>
      <category domain="http://securityratty.com/tag/false entry">false entry</category>
      <category domain="http://securityratty.com/tag/supreme court">supreme court</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/tackle">tackle</category>
      <category domain="http://securityratty.com/tag/question">question</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/411657957/supremes-mull-w.html">Supremes Mull Whether Bad Databases Make for Illegal Searches</source>
    </item>
    <item>
      <title><![CDATA[Hacking Your VoIP Box From The Net]]></title>
      <link>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</link>
      <guid>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</guid>
      <description><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read this recent blog from McAfee's Avert Labs and you may wonder. An Avert analyst, reading about vulnerabilities in the...]]></description>
      <content:encoded><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read <a href="http://www.avertlabs.com/research/blog/index.php/2008/09/29/the-lack-of-attention-in-voip-devices/">this recent blog from McAfee's Avert Labs</a> and you may wonder.

An Avert analyst, reading about vulnerabilities in the Cisco IP phone model 7960 then used Google to try to find publicly-accessible 7960 phones. He found "almost 10" (does that mean 9? awkward turn of phrase). 1 of them had the vulnerable firmware version  And the vulnerability was that the phone's web interface reveals a lot of sensitive network information, so the company that holds that phone has a vulnerable network.

What was revealed by the phone? "...the IP addresses of the TFTP server/router/DNS server/DHCP server/Cisco Call Manager, as well as some application links, internal device configuration, and debugging information. If there are any exploitable vulnerabilities in one of these linked servers, attackers could use this information to stage further attacks."

There's always more to test for, and mistakes you in device configuration can have dire consequences.
<p><a href="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/a"><img src="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/sIcbcZ5FSGQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 13:06:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive network information">sensitive network information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/device configuration">device configuration</category>
      <category domain="http://securityratty.com/tag/internal device configuration">internal device configuration</category>
      <category domain="http://securityratty.com/tag/phone model">phone model</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/exploitable vulnerabilities">exploitable vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerable network">vulnerable network</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/sIcbcZ5FSGQ/hacking_your_voip_box_from_the_net.html">Hacking Your VoIP Box From The Net</source>
    </item>
    <item>
      <title><![CDATA[Presentation from SANS 2008 Lunch and Learn in Las Vegas]]></title>
      <link>http://securityratty.com/article/9e013f4069a35954694c89f4bb3e700d</link>
      <guid>http://securityratty.com/article/9e013f4069a35954694c89f4bb3e700d</guid>
      <description><![CDATA[As promised , here is my infamous presentation on &quot;Log management 'Worst Practices'&quot; that I gave at SANS Network Security 2008 yesterday

This presentation can also be considered a sequel to my...]]></description>
      <content:encoded><![CDATA[As <a href="http://chuvakin.blogspot.com/2008/10/my-lunch-presentation-at-sans-network.html">promised</a>, <a href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation">here </a>is my infamous presentation on "Log management 'Worst Practices'" that I gave at SANS Network Security 2008 yesterday.<br /><br />This presentation can also be considered a sequel to my <a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource">"Choosing a Log Management Approach" presentation</a>, which was my previous SANS Lunch and Learn preso.<br /><br />If you are involved / about to be involved with logging, read both (<a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource">first</a>, <a href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation">second</a>)!<br /><br />It is also embedded below:<br /><br /><div style="width: 425px; text-align: left;" id="__ss_635093"><a style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; display: block; text-decoration: underline;" href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation?type=powerpoint" title="Anton's Log Management 'Worst Practices'">Anton's Log Management 'Worst Practices'</a><object style="margin: 0px;" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=sanslmworstpracticesd6oct2008-1223079958645247-8&amp;stripped_title=antons-log-management-worst-practices-presentation"><param name="allowFullScreen" value="true"><param name="allowScriptAccess" value="always"><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=sanslmworstpracticesd6oct2008-1223079958645247-8&amp;stripped_title=antons-log-management-worst-practices-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a style="text-decoration: underline;" href="http://www.slideshare.net/anton_chuvakin/antons-log-management-worst-practices-presentation?type=powerpoint" title="View Anton's Log Management 'Worst Practices' on SlideShare">presentation</a> or <a style="text-decoration: underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration: underline;" href="http://slideshare.net/tag/chuvakin">chuvakin</a> <a style="text-decoration: underline;" href="http://slideshare.net/tag/logging">logging</a>)</div></div><br /><br /><br /><span style="font-weight: bold;">Possibly related material:</span><br /><ul><li>All my presentation on Slideshare.<br /></li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Ch9yM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Ch9yM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=27R3M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=27R3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0cfCM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0cfCM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/411284395" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 07:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log management approach">log management approach</category>
      <category domain="http://securityratty.com/tag/infamous presentation">infamous presentation</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/worst practices">worst practices</category>
      <category domain="http://securityratty.com/tag/previous sans lunch">previous sans lunch</category>
      <category domain="http://securityratty.com/tag/sans network security">sans network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/411284395/presentation-from-sans-2008-lunch-and.html">Presentation from SANS 2008 Lunch and Learn in Las Vegas</source>
    </item>
    <item>
      <title><![CDATA[Is it a virus?]]></title>
      <link>http://securityratty.com/article/752d89dbe22206523218e065c32dde25</link>
      <guid>http://securityratty.com/article/752d89dbe22206523218e065c32dde25</guid>
      <description><![CDATA[I get a lot of e-mail from people who believe their computer is infected by a virus. In most cases, it's not infected at all - evil software designers are still outnumbered by incompetent...]]></description>
      <content:encoded><![CDATA[I get a lot of e-mail from people who believe their computer is infected by a virus. In most cases, it's not infected at all - evil software designers are still outnumbered by incompetent ones.]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/evil software designers">evil software designers</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/incompetent">incompetent</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <source url="http://www.networkworld.com/news/2008/100308-is-it-a.html?fsrc=rss-security">Is it a virus?</source>
    </item>
    <item>
      <title><![CDATA[Google Trends Labs Abused By Cybercriminals To Spread Malware]]></title>
      <link>http://securityratty.com/article/4ea1cd9db70bcac5a0266b22111315ab</link>
      <guid>http://securityratty.com/article/4ea1cd9db70bcac5a0266b22111315ab</guid>
      <description><![CDATA[According to a recent advisory issued by Webroot, cybecriminals are exploiting the search engines by monitoring the peak traffic for popular search queries using Googles Trend Labs and syndicating the...]]></description>
      <content:encoded><![CDATA[According to a recent advisory issued by Webroot, cybecriminals are exploiting the search engines by monitoring the peak traffic for popular search queries using Google’s Trend Labs and syndicating the keywords in order to acquire the traffic and direct it to malware serving blogs primarily hosted at Windows Live’s Spaces.
For the first time, hackers are [...]]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 17:59:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows lives spaces">windows lives spaces</category>
      <category domain="http://securityratty.com/tag/googles trend labs">googles trend labs</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/peak traffic">peak traffic</category>
      <category domain="http://securityratty.com/tag/blogs primarily">blogs primarily</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/recent advisory">recent advisory</category>
      <category domain="http://securityratty.com/tag/engines">engines</category>
      <category domain="http://securityratty.com/tag/direct">direct</category>
      <source url="http://cyberinsecure.com/google-trends-labs-abused-by-cybercriminals-to-spread-malware/">Google Trends Labs Abused By Cybercriminals To Spread Malware</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.3.08]]></title>
      <link>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</link>
      <guid>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</guid>
      <description><![CDATA[Well finally, an upside to the financial crisis more students in computer science. After the dot-com crash, enrollment went down in computer science, almost 50% since 2003. Many students shifted their...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/africa-map.jpg" border="0" alt="africa-map" width="204" height="240" align="left" /> Well finally, an upside to the financial crisis – more students in computer science. After the dot-com crash, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9066659" target="_blank">enrollment went down</a> in computer science, almost 50% since 2003. Many students <a href="http://www.washingtontechnology.com/online/1_1/33584-1.html" target="_blank">shifted their interest from the technology field</a> to banking and finance because they thought they’d make more money. And now the financial crisis could scare them into <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115616&amp;source=rss_news" target="_blank">choosing majors and careers that are “safer alternatives”</a>, like IT. And perhaps the trend is reversing for those already on Wall Street as well. Ben Worthen writes about the influx of resumes Kodiak Venture Partners has been getting: <a href="http://blogs.wsj.com/biztech/?s=wall+street+jobs" target="_blank">from financial-services vets who want to work at tech startups</a>, – not to “strike it rich” this time around, but just to make a living. And it’s not just the tech workers. Seems like the ones that don’t even have any real IT experience are looking too – for jobs as VPs of marketing (harrumph). (<a href="http://www.fas.org/irp/imint/docs/rst/Sect6/africa-map.jpg" target="_blank"><em>img from www.fas.org</em></a>)</p>
<p>I’m sure you already know about the other “network management” – where ISPs and carriers get their hands publicly slapped for limiting bandwidth to high-traffic offenders. But when is this kind of “network management” a good thing? At a panel sponsored by the FCC in DC, reps from carriers and ISPs discussed what steps they’ve been taking <a href="http://www.networkworld.com/news/2008/091808-telcos-pandemic.html?hpg1=bn" target="_blank">to prepare for a pandemic</a> or other major global crisis – that would force workers to stay at home or work from more remote locations to limit exposure.</p>
<p>Are people paying attention to ICANN? They’re saying that IPv4 will be fully <a href="http://blog.icann.org/?p=365" target="_blank">allocated in the next two or three years</a>. Does anyone care? In their bid to make people care, ICANN talks about the state of IPv6 adoption and <a href="http://www.thestandard.com/news/2008/09/30/africa-faster-adopting-ipv6-according-icann">touts Africa as the most rapid adopter</a>.</p>
<p><a href="http://blogs.zdnet.com/service-oriented/?p=1187" target="_blank">SOA soon part of the ‘cloud’</a>? No, please no.</p>
<p>Microsoft – The Silver Lining in Every Cloud. Joe Wilcox over at eWeek’s Microsoft Watch, has been <a href="http://www.microsoft-watch.com/content/corporate/steve_ballmer_sure_has_lots_to_say.html?kc=EWWHNEMNL10022008STR4" target="_blank">following Steve Ballmer</a> around and collecting some nice quotes on how the company is transitioning. “For many years, we had kind of what I would call the all-encompassing mission, vision and scorecard statement: a computer on every desk and in every home. …Well, our footprint and portfolio is broader than that. “ [In every hand and of course, in every cloud…] “So, as a vision statement we talk about creating seamless experiences that combine the magic of software, the power of the Internet across a world of devices.” The magic of software – something I haven’t thought about for a while. And:</p>
<blockquote><p>&#8220;You need a real platform in the cloud. When we wanted to go after the PC, we built an operating system. When we wanted to go after the phone, we built an operating system. When we wanted to go after the enterprise, we built an operating system. We&#8217;ll announce a new operating system, one that runs in the cloud and has a wide variety of capabilities.”</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:55:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/computer science">computer science</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/financial crisis">financial crisis</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/eweeks microsoft">eweeks microsoft</category>
      <source url="http://blog.sciencelogic.com/links-list-10308/10/2008">Links List 10.3.08</source>
    </item>
    <item>
      <title><![CDATA[Just A Thought on Compliance]]></title>
      <link>http://securityratty.com/article/0ae476d5942aec813ca6f6b8f73276d0</link>
      <guid>http://securityratty.com/article/0ae476d5942aec813ca6f6b8f73276d0</guid>
      <description><![CDATA[Do you know the difference between a solution &quot; sold as compliance &quot; and a solution that &quot; helps with compliance? &quot; In other words, are you &quot;a checkmark&quot; in a compliance checkbox OR do you help people...]]></description>
      <content:encoded><![CDATA[Do you know the difference between a solution "<span style="font-weight: bold;"><span style="font-style: italic;">sold </span>as compliance</span>" and a solution that "<span style="font-weight: bold;"><span style="font-style: italic;">helps</span> with compliance?</span>" In other words, are you "a checkmark" in a compliance checkbox OR do you help people with their compliance challenges?<br /><br />Get it?<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wqVgM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wqVgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Iac7M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Iac7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=G872M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=G872M" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/410668995" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 11:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/compliance challenges">compliance challenges</category>
      <category domain="http://securityratty.com/tag/compliance checkbox">compliance checkbox</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/difference">difference</category>
      <category domain="http://securityratty.com/tag/checkmark">checkmark</category>
      <category domain="http://securityratty.com/tag/words">words</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/410668995/just-thought-on-compliance.html">Just A Thought on Compliance</source>
    </item>
  </channel>
</rss>
