<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: off-site]]></title>
    <link>http://securityratty.com/tag/off-site</link>
    <description></description>
    <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[VeriSign, ICANN Square Off Over DNS Root]]></title>
      <link>http://securityratty.com/article/e09951a583d19a46cfd191b37da438b1</link>
      <guid>http://securityratty.com/article/e09951a583d19a46cfd191b37da438b1</guid>
      <description><![CDATA[As the U.S. government starts the process of closing a major net vulnerability, two longtime net infrastructure rivals -- the non-profit ICANN and for-profit VeriSign -- are battling over who will...]]></description>
      <content:encoded><![CDATA[As the U.S. government starts the process of closing a major net vulnerability, two longtime net infrastructure rivals -- the non-profit ICANN and for-profit VeriSign -- are battling over who will compile and verify the net's most important document. Internet experts give the nod to ICANN and bring up VeriSign's greedy past.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=f68ae856dab3bd7dff1ae681ba10e35e"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f68ae856dab3bd7dff1ae681ba10e35e"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=f68ae856dab3bd7dff1ae681ba10e35e" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=dZHQM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=dZHQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gjrUm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gjrUm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=653Nm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=653Nm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jMyZM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jMyZM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=uzQnM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=uzQnM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=H1iem"><img src="http://feeds.wired.com/~f/wired/politics/security?i=H1iem" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=OzxSm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OzxSm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Lzv5M"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Lzv5M" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/417281554" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/417281562" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 17:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/verisign">verisign</category>
      <category domain="http://securityratty.com/tag/major net vulnerability">major net vulnerability</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/non-profit icann">non-profit icann</category>
      <category domain="http://securityratty.com/tag/for-profit verisign">for-profit verisign</category>
      <category domain="http://securityratty.com/tag/internet experts">internet experts</category>
      <category domain="http://securityratty.com/tag/greedy past">greedy past</category>
      <category domain="http://securityratty.com/tag/government starts">government starts</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/417281562/who-should-sign.html">VeriSign, ICANN Square Off Over DNS Root</source>
    </item>
    <item>
      <title><![CDATA[Army Orders Pain Ray Trucks; New Report Shows 'Potential for Death']]></title>
      <link>http://securityratty.com/article/2e2ddc7b1cea25fd38c0ffb45844a005</link>
      <guid>http://securityratty.com/article/2e2ddc7b1cea25fd38c0ffb45844a005</guid>
      <description><![CDATA[After years of testing, the Active Denial System -- the pain ray which drives off rioters with a microwave-like beam -- could finally have its day. The Army is buying five of the truck-mounted systems...]]></description>
      <content:encoded><![CDATA[After years of testing, the Active Denial System -- the pain ray which drives off rioters with a microwave-like beam -- could finally have its day. The Army is buying five of the truck-mounted systems for $25 million. But the energy weapon may face new hurdles, before it's shipped off to the battlefield; a new report details how the supposedly non-lethal blaster could be turned into a flesh-frying killer.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=43556599e0be6ecc67d2075afe0b7f82" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=43556599e0be6ecc67d2075afe0b7f82" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=1qJXM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=1qJXM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=bGPNm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=bGPNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2inMm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2inMm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=XwqSM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=XwqSM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=tN2IM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=tN2IM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=KhEjm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=KhEjm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=9dV0m"><img src="http://feeds.wired.com/~f/wired/politics/security?i=9dV0m" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=A4gWM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=A4gWM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/416909996" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/416910007" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 11:17:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pain ray">pain ray</category>
      <category domain="http://securityratty.com/tag/supposedly non-lethal blaster">supposedly non-lethal blaster</category>
      <category domain="http://securityratty.com/tag/active denial system">active denial system</category>
      <category domain="http://securityratty.com/tag/army">army</category>
      <category domain="http://securityratty.com/tag/microwave-like beam">microwave-like beam</category>
      <category domain="http://securityratty.com/tag/energy weapon">energy weapon</category>
      <category domain="http://securityratty.com/tag/report details">report details</category>
      <category domain="http://securityratty.com/tag/rioters">rioters</category>
      <category domain="http://securityratty.com/tag/killer">killer</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/416910007/army-ordering-p.html">Army Orders Pain Ray Trucks; New Report Shows 'Potential for Death'</source>
    </item>
    <item>
      <title><![CDATA[Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports]]></title>
      <link>http://securityratty.com/article/c45254a44427955d16e606148d540d82</link>
      <guid>http://securityratty.com/article/c45254a44427955d16e606148d540d82</guid>
      <description><![CDATA[New Video: Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports Host based firewalls are fine and dandy, but I'd rather turn off services I don't need...]]></description>
      <content:encoded><![CDATA[New Video:<a href="http://www.irongeek.com/i.php?page=videos/finding-listening-ports-on-your-windows-box-using-netstat-fport-tcpview-icesword-and-current-ports">Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports</a><br/>Host based firewalls are fine and dandy, but I'd rather turn off services I don't need than to just block them. Host based firewalls are sort of a bandage, and while they can be useful for knowing what is connecting out (see egress filtering), it's better just not to have unneeded network services running in the first place. This video can be seen as a supplement to my article "<a href="http://www.irongeek.com/i.php?page=security/ipinfo#5">What can you find out from an IP?</a>"
<p><a href="http://feedads.googleadservices.com/~a/CNXtCJO8CcQDAk9fB9tE4S0hjUw/a"><img src="http://feedads.googleadservices.com/~a/CNXtCJO8CcQDAk9fB9tE4S0hjUw/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/5mRbbSK0tUc" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:41:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/network services">network services</category>
      <category domain="http://securityratty.com/tag/host based firewalls">host based firewalls</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/fport">fport</category>
      <category domain="http://securityratty.com/tag/icesword">icesword</category>
      <category domain="http://securityratty.com/tag/netstat">netstat</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/tcpview">tcpview</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/5mRbbSK0tUc/i.php">Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports</source>
    </item>
    <item>
      <title><![CDATA[Innovators, Imitators and Idiots]]></title>
      <link>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</link>
      <guid>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</guid>
      <description><![CDATA[Charlie Rose interviews Warren Buffett


Charlie Rose
And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage. We just lost sight...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;">Charlie Rose <a href="http://www.cnbc.com/id/26982338/page/2/">interviews</a> Warren Buffett:</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage.&#0160; We just lost sight of risk and leverage of what was appropriate?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.&#0160; Again, because it pays off for a while.&#0160; You know, you can lose leverage, and it&#39;s the only way a smart guy can go broke.&#0160; If you owe money, you can&#39;t pay them out.&#0160; You just pay for everything, you do smart things, you eventually get very rich.&#0160; If you do smart things and use leverage and do one wrong thing along the way, it could wipe you out, because anything times zero is zero.&#0160; But it&#39;s reinforcing when the people around you are doing it successfully, you&#39;re doing it successfully, and it&#39;s a lot like Cinderella at the ball.&#0160; I mean you know at midnight everything is going to turn to pumpkins and mice; right?&#0160; But if the evening goes along, I mean, you know, the guys look better all the time, the music sounds better, it&#39;s more and more fun, you think why the hell should I leave at quarter of 12.&#0160; I&#39;ll leave at two minutes to 12.&#0160; But the trouble is, there are no clocks on the wall.&#0160; And everybody thinks they&#39;re going to leave at two minutes to 12.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating <a href="http://1raindrop.typepad.com/1_raindrop/2007/11/dhandho-infosec.html">risk and uncertainty</a>. As our current financial situation shows, its a hard thing to pull off</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And should wise people have known better?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">People should always know better.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">I mean people -- people don&#39;t get -- they don&#39;t get smarter about things that get as basic as greed and you can&#39;t stand to see your neighbor getting rich.&#0160; You know you&#39;re smarter than he is, and he&#39;s doing these things, you know, and he&#39;s getting rich, and your spouse is getting unhappy with you because you aren&#39;t doing -- pretty soon you start doing it.&#0160; And so you get what I call the natural progression, the three Is.&#0160; The innovators, the imitators, and the idiots.&#0160; And that&#39;s what happens.&#0160; Everybody just kind of goes along.&#0160; And you look kind of silly if you disagree.&#0160; I mean, you know, you could have these crazy Internet valuations in the late 1990s, but they prove themselves out in the market.&#0160; The next day they were selling for more than they were the day before, and people said, you know, you&#39;re crazy if you don&#39;t get in on this.&#0160; So it&#39;s very human.&#0160; Now, with housing it&#39;s something even more dramatic than that, because most people aspire to own their own home.&#0160; And if you really think that houses prices are going to go up next year and the year after, you feel if I don&#39;t buy it this year, I&#39;m going to have to buy it next year.&#0160; That&#39;s not true of an Internet stock.&#0160; But it&#39;s true of a home.&#0160; And when somebody makes it very easy for you to do it by saying you don&#39;t really have to put up my money, you can lie about your income a little, or we&#39;ll give you 100 percent mortgage, you&#39;re going to do it, because everybody that&#39;s done it has been proven right.&#0160; You have what they call social tools, and, you know, you&#39;re going to feel like an idiot if you didn&#39;t do it, because the house cost more.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system.</span></div><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Oh, I think confidence will come back.&#0160; I will tell you this.&#0160; This country is going -- be living better ten years from now than it is now.&#0160; It will be living better in 20 years from now than ten years from now.&#0160; The ingredients that made this country, you know, the miracle of the world -- I mean we had a seven for one improvement in the average American standard of living in the 20th century.&#0160; Now, we had the great depression, we had two world wars, we had the flu epidemic.&#0160; You know, we had oil shock.&#0160; You know, we had all these terrible things happen.&#0160; But something about the American system unleashed more and of a potential to human beings over that hundred years so that we had a seven for one improvement in -- there&#39;s never been any -- I mean, you have centuries where if you&#39;ve got a 1 percent improvement, then it&#39;s something.&#0160; So we&#39;ve got a great system.&#0160; And we&#39;ve got more productive capacity now than we ever have.&#0160; The American worker is more productive than he&#39;s ever been.&#0160; We&#39;ve got more people to do it.&#0160; We&#39;ve got all the ingredients for a sensational future.&#0160; It&#39;s just that right now the athlete&#39;s on the floor.&#0160; But we -- this is a super athlete.</span></p></blockquote><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Again, we want to look at risk events in a broader, long term context. In Buffett&#39;s words its - &quot;be fearful when others are greedy and greedy when others are fearful.&quot; As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* Buffett&#39;s partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive.</span></div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/oeprational risk">oeprational risk</category>
      <category domain="http://securityratty.com/tag/risk events">risk events</category>
      <category domain="http://securityratty.com/tag/risk-reward balance">risk-reward balance</category>
      <category domain="http://securityratty.com/tag/wise people">wise people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/buffett raises">buffett raises</category>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/blind risk acceptance">blind risk acceptance</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/innovators-imitators-and-idiots.html">Innovators, Imitators and Idiots</source>
    </item>
    <item>
      <title><![CDATA[University sets up a campus warning network for free ]]></title>
      <link>http://securityratty.com/article/532f402f74efb59fafb0b176f8e8a342</link>
      <guid>http://securityratty.com/article/532f402f74efb59fafb0b176f8e8a342</guid>
      <description><![CDATA[Elon University needed to come up with a campus-wide emergency notification system that integrated with all the possible warning-delivery systems already installed on campus, and managed to pull it...]]></description>
      <content:encoded><![CDATA[Elon University needed to come up with a campus-wide emergency notification system that integrated with all the possible warning-delivery systems already installed on campus, and managed to pull it off for free.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=44788?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=44788?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/campus">campus</category>
      <category domain="http://securityratty.com/tag/elon university">elon university</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/pull">pull</category>
      <source url="http://www.networkworld.com/news/2008/100708-campus-warning-network.html?fsrc=rss-security">University sets up a campus warning network for free </source>
    </item>
    <item>
      <title><![CDATA[10 steps to loading dock security]]></title>
      <link>http://securityratty.com/article/2217cdb4a4821c442470cf3eda7e733f</link>
      <guid>http://securityratty.com/article/2217cdb4a4821c442470cf3eda7e733f</guid>
      <description><![CDATA[It's the stuff of CSO nightmares. Early on the morning of Sept. 2, while most folks were home sleeping off the hot dogs, thieves used bolt cutters to break into an Alltel Communications warehouse and...]]></description>
      <content:encoded><![CDATA[It's the stuff of CSO nightmares. Early on the morning of Sept. 2, while most folks were home sleeping off the hot dogs, thieves used bolt cutters to break into an Alltel Communications warehouse and four of its loading docks in Fort Smith, Ark. Sources say they escaped with an estimated US$10 million worth of cell phones, not a bad haul for their Labor Day efforts.]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/us10 million worth">us10 million worth</category>
      <category domain="http://securityratty.com/tag/labor day efforts">labor day efforts</category>
      <category domain="http://securityratty.com/tag/alltel communications warehouse">alltel communications warehouse</category>
      <category domain="http://securityratty.com/tag/cso nightmares">cso nightmares</category>
      <category domain="http://securityratty.com/tag/bad haul">bad haul</category>
      <category domain="http://securityratty.com/tag/fort smith">fort smith</category>
      <category domain="http://securityratty.com/tag/hot dogs">hot dogs</category>
      <category domain="http://securityratty.com/tag/cell phones">cell phones</category>
      <category domain="http://securityratty.com/tag/bolt cutters">bolt cutters</category>
      <source url="http://www.networkworld.com/news/2008/100608-10-steps-to-loading-dock.html?fsrc=rss-security">10 steps to loading dock security</source>
    </item>
    <item>
      <title><![CDATA[Mac security focus: Firewalls]]></title>
      <link>http://securityratty.com/article/89cc3f0566653fdb74654f43826d92d5</link>
      <guid>http://securityratty.com/article/89cc3f0566653fdb74654f43826d92d5</guid>
      <description><![CDATA[Firewalls monitor and regulate the data moving on and off your computer or network. They can keep criminals out while allowing legitimate network traffic in. Mac OS X comes with not one but two...]]></description>
      <content:encoded><![CDATA[Firewalls monitor and regulate the data moving on and off your computer or network. They can keep criminals out while allowing legitimate network traffic in. Mac OS X comes with not one but two firewalls of its own. However, those two aren't always enough.]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firewalls">firewalls</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network traffic">network traffic</category>
      <category domain="http://securityratty.com/tag/firewalls monitor">firewalls monitor</category>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://www.networkworld.com/news/2008/100608-mac-security-focus.html?fsrc=rss-security">Mac security focus: Firewalls</source>
    </item>
    <item>
      <title><![CDATA[A Few Fun Bits, While I Am Preparing for My Speech at SANS]]></title>
      <link>http://securityratty.com/article/95afa537556e21e9766eb67ee13152a8</link>
      <guid>http://securityratty.com/article/95afa537556e21e9766eb67ee13152a8</guid>
      <description><![CDATA[A few more things, that qualify as fun reads, with - hopefully just as fun! - comments

Love, love, love this piece :-) Remember the &quot;robotic gun rampage&quot; stories from last year? How does this sound:...]]></description>
      <content:encoded><![CDATA[A few more things, that qualify as fun reads, with - hopefully just as fun! - comments.<br /><ul><li>Love, love, love <a href="http://www.defensetech.org/archives/004449.html">this piece</a> :-) Remember the <a href="http://chuvakin.blogspot.com/search/label/warfare">"robotic gun rampage" stories</a> from last year? How does this sound: "The gun can track 360 degress, but there is <span style="font-weight: bold;">a software-driven safety zone that makes sure rounds don't blow the rotors off.</span> If the Osprey has to maneuver away from the target and the crew chief can't hold the gun on the bad guys manually, the system slaves the gun to the point of the last shot, slewing it as the plane moves." (watch the fun video there too)<br /></li><li>"Security idiot" meme lives on - go <a href="http://duckdown.blogspot.com/2008/09/are-you-it-security-idiot.html">here</a>. BTW, the post is a follow-up to <a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">this </a></li><li><a href="http://www.securitybalance.com/2008/09/which-compliance-pill-to-take/">A fun follow-up</a> to my post on compliance approaches titled <a href="http://chuvakin.blogspot.com/2008/09/is-pci-dss-prescriptive.html">Is PCI DSS "Too Prescriptive"?</a> </li><li>Finally, my fave post: "<a href="http://www.cutawaysecurity.com/blog/archives/342" rel="bookmark" title="Permanent Link: Increase Your Logging">Increase Your Logging</a>." I am sooooo happy that logging evangelism is spreading  far and wide! A quote from<a href="http://www.cutawaysecurity.com/blog/archives/342"> the paper</a>: ”<em>Logs are interesting, logs are fun, logs should be done by EVERYONE…..get to logging!!!</em>” (I promise that specific case was not my quote, even though I do say that very thing all the time!)<br /></li></ul>Enjoy! Time for me to run and do my preso ... about logs of course!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dEUWM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dEUWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Jdl7M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Jdl7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=7k1zM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=7k1zM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/410521073" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 08:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/fun video">fun video</category>
      <category domain="http://securityratty.com/tag/fun follow-up">fun follow-up</category>
      <category domain="http://securityratty.com/tag/follow-up">follow-up</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/robotic gun rampage">robotic gun rampage</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/fun reads">fun reads</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/410521073/few-fun-bits-while-i-am-preparing-for.html">A Few Fun Bits, While I Am Preparing for My Speech at SANS</source>
    </item>
    <item>
      <title><![CDATA[Taleb on the Limitations of Risk Management]]></title>
      <link>http://securityratty.com/article/f91dcedda258c55172e0d795aebda8a8</link>
      <guid>http://securityratty.com/article/f91dcedda258c55172e0d795aebda8a8</guid>
      <description><![CDATA[Nice paragraph on the limitations of risk management in this occasionally interesting interview with Nicholas Taleb: Because then you get a Maginot Line problem. [After World War I, the French erected...]]></description>
      <content:encoded><![CDATA[<p>Nice paragraph on the limitations of risk management in this <a href="http://www.portfolio.com/views/columns/the-world-according-to/2008/08/14/Interview-With-Nassim-Nicholas-Taleb">occasionally interesting interview</a> with Nicholas Taleb:</p>

<blockquote>Because then you get a Maginot Line problem. [After World War I, the French erected concrete fortifications to prevent Germany from invading again -- a response to the previous war, which proved ineffective for the next one.] You know, they make sure they solve that particular problem, the Germans will not invade from here. The thing you have to be aware of most obviously is scenario planning, because typically if you talk about scenarios, you'll overestimate the probability of these scenarios. If you examine them at the expense of those you don't examine, sometimes it has left a lot of people worse off, so scenario planning can be bad. I'll just take my track record. Those who did scenario planning have not fared better than those who did not do scenario planning. A lot of people have done some kind of "make-sense" type measures, and that has made them more vulnerable because they give the illusion of having done your job. This is the problem with risk management. I always come back to a classical question. Don't give a fool the illusion of risk management. Don't ask someone to guess the number of dentists in Manhattan after asking him the last four digits of his Social Security number. The numbers will always be correlated. I actually did some work on risk management, to show how stupid we are when it comes to risk.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XoSTM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XoSTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=iSyHM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=iSyHM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 03:48:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/scenario">scenario</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/people worse">people worse</category>
      <category domain="http://securityratty.com/tag/concrete fortifications">concrete fortifications</category>
      <category domain="http://securityratty.com/tag/maginot line">maginot line</category>
      <category domain="http://securityratty.com/tag/illusion">illusion</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/taleb_in_the_li.html">Taleb on the Limitations of Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Money meltdown, Ozzie's cloud, security worries]]></title>
      <link>http://securityratty.com/article/d4c8a90dbbb22938be850c3f4dd5bf8e</link>
      <guid>http://securityratty.com/article/d4c8a90dbbb22938be850c3f4dd5bf8e</guid>
      <description><![CDATA[At least those of us who are fans of professional baseball have the playoffs to take our minds off the grim news this week (at least that's the case for fans of the teams that are winning). The U.S....]]></description>
      <content:encoded><![CDATA[At least those of us who are fans of professional baseball have the playoffs to take our minds off the grim news this week (at least that's the case for fans of the teams that are winning). The U.S. financial system meltdown smacked world markets and set off a whole lot of worry, which tended to overshadow all the other news.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=73179?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=73179?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial system meltdown">financial system meltdown</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/grim news">grim news</category>
      <category domain="http://securityratty.com/tag/fans">fans</category>
      <category domain="http://securityratty.com/tag/professional baseball">professional baseball</category>
      <category domain="http://securityratty.com/tag/world markets">world markets</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/teams">teams</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.networkworld.com/news/2008/100308-money-meltdown-ozzies-cloud-security.html?fsrc=rss-security">Money meltdown, Ozzie's cloud, security worries</source>
    </item>
  </channel>
</rss>
