<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: self-taught]]></title>
    <link>http://securityratty.com/tag/self-taught</link>
    <description></description>
    <pubDate>Tue, 04 Nov 2008 08:42:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ Here Comes Everybody Review]]></title>
      <link>http://securityratty.com/article/639cf7107fd08bc70488e1f27a8ec2a3</link>
      <guid>http://securityratty.com/article/639cf7107fd08bc70488e1f27a8ec2a3</guid>
      <description><![CDATA[In 1937, Ronald Coase answered one of the most perplexing questions in economics: if markets are so great, why do organizations exist? Why don't people just buy and sell their own services in a market...]]></description>
      <content:encoded><![CDATA[<p>In 1937, Ronald Coase answered one of the most perplexing questions in economics: if markets are so great, why do organizations exist? Why don't people just buy and sell their own services in a market instead? Coase, who won the 1991 Nobel Prize in Economics, answered the question by noting a market's transaction costs: buyers and sellers need to find one another, then reach agreement, and so on. The Coase theorem implies that if these transaction costs are low enough, direct markets of individuals make a whole lot of sense. But if they are too high, it makes more sense to get the job done by an organization that hires people. </p>

<p>Economists have long understood the corollary concept of Coase's ceiling, a point above which organizations collapse under their own weight -- where hiring someone, however competent, means more work for everyone else than the new hire contributes. Software projects often bump their heads against Coase's ceiling: recall Frederick P. Brooks Jr.'s seminal study, <cite>The Mythical Man-Month</cite> (Addison-Wesley, 1975), which showed how adding another person onto a project can slow progress and increase errors. </p>

<p>What's new is something consultant and social technologist Clay Shirky calls &quot;Coase's Floor,&quot; below which we find projects and activities that aren't worth their organizational costs -- things so esoteric, so frivolous, so nonsensical, or just so thoroughly unimportant that no organization, large or small, would ever bother with them. Things that you shake your head at when you see them and think, &quot;That's ridiculous.&quot;</p>

<p>Sounds a lot like the Internet, doesn't it? And that's precisely Shirky's point. His new book, <a href="http://www.amazon.com/exec/obidos/ASIN/1594201536/counterpane/"><cite>Here Comes Everybody: The Power of Organizing Without Organizations</cite></a>, explores a world where organizational costs are close to zero and where ad hoc, loosely connected groups of unpaid amateurs can create an encyclopedia larger than the Britannica and a computer operating system to challenge Microsoft's. </p>

<p>Shirky teaches at New York University's Interactive Telecommunications Program, but this is no academic book. Sacrificing rigor for readability, <cite>Here Comes Everybody</cite> is an entertaining as well as informative romp through some of the Internet's signal moments -- the Howard Dean phenomenon, Belarusian protests organized on LiveJournal, the lost cellphone of a woman named Ivanna, Meetup.com, flash mobs, Twitter, and more -- which Shirky uses to illustrate his points. </p>

<p>The book is filled with bits of insight and common sense, explaining why young people take better advantage of social tools, how the Internet affects social change, and how most Internet discourse falls somewhere between dinnertime conversation and publishing. </p>

<p>Shirky notes that &quot;most user-generated content isn't 'content' at all, in the sense of being created for general consumption, any more than a phone call between you and a sibling is 'family-generated content.' Most of what gets created on any given day is just the ordinary stuff of life -- gossip, little updates, thinking out loud -- but now it's done in the same medium as professionally produced material. Unlike professionally produced material, however, Internet content can be organized after the fact.&quot; </p>

<p>No one coordinates Flickr's 6 million to 8 million users. Yet Flickr had the first photos from the 2005 London Transport bombings, beating the traditional news media. Why? People with cellphone cameras uploaded their photos to Flickr. They coordinated themselves using tools that Flickr provides. This is the sort of impromptu organization the Internet is ideally suited for. Shirky explains how these moments are harbingers of a future that can self-organize without formal hierarchies. </p>

<p>These nonorganizations allow for contributions from a wider group of people. A newspaper has to pay someone to take photos; it can't be bothered to hire someone to stand around London underground stations waiting for a major event. Similarly, Microsoft has to pay a programmer full time, and <cite>Encyclopedia Britannica</cite> has to pay someone to write articles. But Flickr can make use of a person with just one photo to contribute, Linux can harness the work of a programmer with little time, and Wikipedia benefits if someone corrects just a single typo. These aggregations of millions of actions that were previously below the Coasean floor have enormous potential. </p>

<p>But a flash mob is still a mob. In a world where the Coasean floor is at ground level, all sorts of organizations appear, including ones you might not like: violent political organizations, hate groups, Holocaust deniers, and so on. (Shirky's discussion of teen anorexia support groups makes for very disturbing reading.) This has considerable implications for security, both online and off. </p>

<p>We never realized how much our security could be attributed to distance and inconvenience -- how difficult it is to recruit, organize, coordinate, and communicate without formal organizations. That inadvertent measure of security is now gone. Bad guys, from hacker groups to terrorist groups, will use the same ad hoc organizational technologies that the rest of us do. And while there has been some success in closing down individual Web pages, discussion groups, and blogs, these are just stopgap measures. </p>

<p>In the end, a virtual community is still a community, and it needs to be treated as such. And just as the best way to keep a neighborhood safe is for a policeman to walk around it, the best way to keep a virtual community safe is to have a virtual police presence. </p>

<p>Crime isn't the only danger; there is also isolation. If people can segregate themselves in ever-increasingly specialized groups, then they're less likely to be exposed to alternative ideas. We see a mild form of this in the current political trend of rival political parties having their own news sources, their own narratives, and their own facts. Increased radicalization is another danger lurking below the Coasean floor. </p>

<p>There's no going back, though. We've all figured out that the Internet makes freedom of speech a much harder right to take away. As Shirky demonstrates, Web 2.0 is having the same effect on freedom of assembly. The consequences of this won't be fully seen for years. </p>

<p><cite>Here Comes Everybody</cite> covers some of the same ground as Yochai Benkler's <cite>Wealth of Networks</cite>. But when I had to explain to one of my corporate attorneys how the Internet has changed the nature of public discourse, Shirky's book is the one I recommended.</p>

<p>This essay <a href="http://www.spectrum.ieee.org/sep08/6631">previously appeared</a> in <i>IEEE Spectrum</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=wZmPN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=wZmPN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xDcAN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xDcAN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 04:39:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shirky">shirky</category>
      <category domain="http://securityratty.com/tag/shirky notes">shirky notes</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/virtual community safe">virtual community safe</category>
      <category domain="http://securityratty.com/tag/organizations collapse">organizations collapse</category>
      <category domain="http://securityratty.com/tag/internet content">internet content</category>
      <category domain="http://securityratty.com/tag/internet discourse falls">internet discourse falls</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/here_comes_ever.html"> Here Comes Everybody Review</source>
    </item>
    <item>
      <title><![CDATA[RIAA Lawsuits May Be Unconstitutional]]></title>
      <link>http://securityratty.com/article/93a6a6f47d9d5b1467dbe190bc929894</link>
      <guid>http://securityratty.com/article/93a6a6f47d9d5b1467dbe190bc929894</guid>
      <description><![CDATA[Harvard law professor Charles Nesson is arguing , in court, that the Digital Theft Deterrence and Copyright Damages Improvement Act of 1999 is unconstitutional: He makes the argument that the Digital...]]></description>
      <content:encoded><![CDATA[<p>Harvard law professor Charles Nesson is <a href="http://techdirt.com/articles/20081030/0203582685.shtml">arguing</a>, in court, that the Digital Theft Deterrence and Copyright Damages Improvement Act of 1999 is unconstitutional:</p>

<blockquote>He makes the argument that the Digital Theft Deterrence and Copyright Damages Improvement Act of 1999 is very much unconstitutional, in that its hefty fines for copyright infringement (misleadingly called "theft" in the title of the bill) show that the bill is effectively a criminal statute, yet for a civil crime. That's because it really focuses on punitive damages, rather than making private parties whole again. Even worse, it puts the act of enforcing the criminal statute in the hands of a private body (the RIAA) who uses it for profit motive in being able to get hefty fines.

<blockquote>Imagine a statute which, in the name of deterrence, provides for a $750 fine for each mile-per-hour that a driver exceeds the speed limit, with the fine escalating to $150,000 per mile over the limit if the driver knew he or she was speeding. Imagine that the fines are not publicized, and most drivers do not know they exist. Imagine that enforcement of the fines is put in the hands of a private, self-interested police force, that has no political accountability, that can pursue any defendant it chooses at its own whim, that can accept or reject payoffs in exchange for not prosecuting the tickets, and that pockets for itself all payoffs and fines. Imagine that a significant percentage of these fines were never contested, regardless of whether they had merit, because the individuals being fined have limited financial resources and little idea of whether they can prevail in front of an objective judicial body.</blockquote></blockquote>

<p>Another <a href="http://www.usatoday.com/tech/news/2008-11-16-music-downloading_N.htm">news story</a>. </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=5mEhN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=5mEhN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=u1zCN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=u1zCN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 10:33:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/digital theft deterrence">digital theft deterrence</category>
      <category domain="http://securityratty.com/tag/fines">fines</category>
      <category domain="http://securityratty.com/tag/deterrence">deterrence</category>
      <category domain="http://securityratty.com/tag/hefty fines">hefty fines</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <category domain="http://securityratty.com/tag/criminal statute">criminal statute</category>
      <category domain="http://securityratty.com/tag/statute">statute</category>
      <category domain="http://securityratty.com/tag/objective judicial body">objective judicial body</category>
      <category domain="http://securityratty.com/tag/body">body</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/riaa_lawsuits_m.html">RIAA Lawsuits May Be Unconstitutional</source>
    </item>
    <item>
      <title><![CDATA[Its hard enough staying safe online when sober!]]></title>
      <link>http://securityratty.com/article/92af4d1e89f2acbf0aecfc277b6450ac</link>
      <guid>http://securityratty.com/article/92af4d1e89f2acbf0aecfc277b6450ac</guid>
      <description><![CDATA[My fav tip is #4. What a great idea


clipped from mashable.com

5 Ways to Keep Your Drunken Self Away From the Internet


Here are a few methods for keeping your drunken alter-ego away from the...]]></description>
      <content:encoded><![CDATA[<div > My fav tip is #4. What a great idea. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/BF4211D4-E026-4D51-8864-4B31BFA63867/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/579a0378-7900-4583-9e87-622d15c6c849/BF4211D4-E026-4D51-8864-4B31BFA63867/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://mashable.com/2008/11/14/drunken-emails/" href="http://mashable.com/2008/11/14/drunken-emails/" style="font-size: 11px;">mashable.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://mashable.com/2008/11/14/drunken-emails/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;"><A href="http://mashable.com/2008/11/14/drunken-emails/">5 Ways to Keep Your Drunken Self Away From the Internet</A></div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://mashable.com/2008/11/14/drunken-emails/ --><P>Here are a few methods for keeping your drunken alter-ego away from the computer. Hopefully, you’ll have a tougher time getting around these than you did getting around Gmail’s math quiz.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/BF4211D4-E026-4D51-8864-4B31BFA63867/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_181108051834"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=181108051834&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=181108051834&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=181108051834&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_181108051834" /></a></P>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 14:18:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gmails math quiz">gmails math quiz</category>
      <category domain="http://securityratty.com/tag/tougher time">tougher time</category>
      <category domain="http://securityratty.com/tag/fav tip">fav tip</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/mashable">mashable</category>
      <category domain="http://securityratty.com/tag/idea">idea</category>
      <category domain="http://securityratty.com/tag/methods">methods</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/alter-ego">alter-ego</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=659">Its hard enough staying safe online when sober!</source>
    </item>
    <item>
      <title><![CDATA[McColo takedown: Internet vigilantism or online Neighborhood Watch?]]></title>
      <link>http://securityratty.com/article/710ddf8376f7091316d99eaccd6a4494</link>
      <guid>http://securityratty.com/article/710ddf8376f7091316d99eaccd6a4494</guid>
      <description><![CDATA[The shutdown of alleged rogue ISP McColo Corp. by its upstream service providers highlights the ongoing struggle between malware purveyors and self-appointed Internet police in the security...]]></description>
      <content:encoded><![CDATA[The shutdown of alleged rogue ISP McColo Corp. by its upstream service providers highlights the ongoing struggle between malware purveyors and self-appointed Internet police in the security community.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9930687624037dcacdf5e512168bb396:eU%2FsUfqE2NKE4z2jAw96trFg%2BonVgjTBw0P1JAGn7lzgZIandY%2FY2V%2BsGVxkHGD4JFPgvnKUlUhn'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c2bf8f05d849c0c9decaed5aa763ba18:KgUi9qCoxkwtUwRUv6NXUQHPZlY%2Bv5t5BAeK5odEv0gG3HVaYcB6hUReikc6KlHB7nKEri83qN7rMA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fbed7b54fce1a75feb6337fa13c61e50:lrHHyAXP4Kvg80eEbgJ7r7c8o%2BRzil9b5x0syrysRaDgLETsj4MlCVnkM27zUeF%2FoD9Jt607hWl03Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e65bbb5aa012d6f31e3d387bc9197675:NpWpIKA7Of%2Fav7PcARiKLhB0u5id2tk3BOV%2BJK5X%2BFvI3X8MK9BkZO9L8CMtBxbTHtPLAy%2FVKHMNxw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=82d197c3186c13afdccabb65afe2d001" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=82d197c3186c13afdccabb65afe2d001" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet police">internet police</category>
      <category domain="http://securityratty.com/tag/malware purveyors">malware purveyors</category>
      <category domain="http://securityratty.com/tag/security community">security community</category>
      <category domain="http://securityratty.com/tag/struggle">struggle</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=82d197c3186c13afdccabb65afe2d001">McColo takedown: Internet vigilantism or online Neighborhood Watch?</source>
    </item>
    <item>
      <title><![CDATA[The Economics of Spam]]></title>
      <link>http://securityratty.com/article/ce621f4781770ea2968bfaa3678135c2</link>
      <guid>http://securityratty.com/article/ce621f4781770ea2968bfaa3678135c2</guid>
      <description><![CDATA[Excellent paper on the economics of spam. The authors infiltrated the Storm worm and monitored its doings. After 26 days, and almost 350 million e-mail messages, only 28 sales resulted -- a conversion...]]></description>
      <content:encoded><![CDATA[<p>Excellent <a href="http://www.icsi.berkeley.edu/pubs/networking/2008-ccs-spamalytics.pdf">paper</a> on the economics of spam.  The authors infiltrated the Storm worm and monitored its doings.</p>

<blockquote>After 26 days, and almost 350 million e-mail messages, only 28 sales resulted -- a conversion rate of well under 0.00001%. Of these, all but one were for male-enhancement products and the average purchase price was close to $100. Taken together, these conversions would have resulted in revenues of $2,731.88 -- a bit over $100 a day for the measurement period or $140 per day for periods when the campaign was active. However, our study interposed on only a small fraction of the overall Storm network -- we estimate roughly 1.5 percent based on the fraction of worker bots we proxy. Thus, the total daily revenue attributable to Storm's pharmacy campaign is likely closer to $7000 (or $9500 during periods of campaign activity). By the same logic, we estimate that Storm self-propagation campaigns can produce between 3500 and 8500 new bots per day.

<p>Under the assumption that our measurements are representative over time (an admittedly dangerous assumption when dealing with such small samples), we can extrapolate that, were it sent continuously at the same rate, Storm-generated pharmaceutical spam would produce roughly 3.5 million dollars of revenue in a year. This number could be even higher if spam-advertised pharmacies experience repeat business. A bit less than "millions of dollars every day," but certainly a healthy enterprise.</blockquote></p>

<p>Of course, the authors point out that it's dangerous to make these sorts of generalizations:</p>

<blockquote>We would be the first to admit that these results represent a single data point and are not necessarily representative of spam as a whole. Different campaigns, using different tactics and marketing different products will undoubtedly produce different outcomes. Indeed, we caution strongly against researchers using the conversion rates we have measured for these Storm-based campaigns to justify assumptions in any other context.</blockquote>

<p>Spam is all about economics.  When sending junk mail costs a dollar in paper, list rental, and postage, a marketer needs a reasonable conversion rate to make the campaign worthwhile.  When sending junk mail is almost free, a one in ten million conversion rate is acceptable.</p>

<p><a href="http://voices.washingtonpost.com/securityfix/2008/11/study_spam_still_profitable_at.html">News</a> <a href="http://www.theregister.co.uk/2008/11/10/storm_botnet_spam_economics/">articles</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=MWN9N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=MWN9N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=CvOtN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=CvOtN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 03:52:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/campaign activity">campaign activity</category>
      <category domain="http://securityratty.com/tag/storm">storm</category>
      <category domain="http://securityratty.com/tag/conversion">conversion</category>
      <category domain="http://securityratty.com/tag/reasonable conversion">reasonable conversion</category>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/junk mail costs">junk mail costs</category>
      <category domain="http://securityratty.com/tag/produce">produce</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_economics_o.html">The Economics of Spam</source>
    </item>
    <item>
      <title><![CDATA[Steve Hunt on the Physical Security Industry]]></title>
      <link>http://securityratty.com/article/d98515fd4bff98bac60235d37183ac17</link>
      <guid>http://securityratty.com/article/d98515fd4bff98bac60235d37183ac17</guid>
      <description><![CDATA[Security industry consultant Steve Hunt is a self-described rabble rouser. Hunt, a former analyst who once headed up the security research practices at Giga Information Group and Forrester Research,...]]></description>
      <content:encoded><![CDATA[Security industry consultant Steve Hunt is a self-described rabble rouser. Hunt, a former analyst who once headed up the security research practices at Giga Information Group and Forrester Research, now runs Hunt Business Intelligence, an industry advisory firm. His additional background in physical security has made him a central figure in discussion about the interplay of physical and IT security.]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/physical security">physical security</category>
      <category domain="http://securityratty.com/tag/physical">physical</category>
      <category domain="http://securityratty.com/tag/security research practices">security research practices</category>
      <category domain="http://securityratty.com/tag/industry advisory firm">industry advisory firm</category>
      <category domain="http://securityratty.com/tag/hunt">hunt</category>
      <category domain="http://securityratty.com/tag/forrester research">forrester research</category>
      <category domain="http://securityratty.com/tag/giga information">giga information</category>
      <category domain="http://securityratty.com/tag/additional background">additional background</category>
      <source url="http://www.networkworld.com/news/2008/111208-steve-hunt-on-the-physical.html?fsrc=rss-security">Steve Hunt on the Physical Security Industry</source>
    </item>
    <item>
      <title><![CDATA[SDL Announcements at TechEd EMEA]]></title>
      <link>http://securityratty.com/article/44b5ec43858dd346e90b7adfbd141edb</link>
      <guid>http://securityratty.com/article/44b5ec43858dd346e90b7adfbd141edb</guid>
      <description><![CDATA[Hello all, Dave here

I am in Barcelona, Spain with Michael Howard and Adam Shostack at the TechEd EMEA: Developers Conference

In addition to teaching and attending security sessions, we are in...]]></description>
      <content:encoded><![CDATA[<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><FONT face=Calibri>Hello all, Dave here…<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><FONT face=Calibri>I am in Barcelona, Spain with Michael Howard and Adam Shostack at the TechEd EMEA: Developers Conference. <o:p></o:p></FONT></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><FONT face=Calibri>In addition to teaching and attending security sessions, we are in Barcelona to formally announce the launch of the SDL Optimization Model, SDL Pro Network and the Microsoft SDL Threat Modeling Tool Beta!<SPAN style="mso-spacerun: yes">&nbsp;&nbsp; </SPAN>For those of you who are unaware of these initiatives here’s a description of each…<o:p></o:p></FONT></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><FONT face=Calibri><B style="mso-bidi-font-weight: normal"><U><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial">SDL Optimization Model:</SPAN></U></B><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"> The SDL Optimization Model was created to facilitate gradual, consistent and cost-effective implementation of the SDL in development organizations outside of Microsoft. It allows development managers and IT policy-makers to assess the state of the security in development and create a vision and road map for reducing customer risk.<o:p></o:p></SPAN></FONT></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><FONT face=Calibri>Specific objectives of the model include the following:<o:p></o:p></FONT></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l3 level1 lfo1" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Enable organizations outside of Microsoft to create more secure and privacy-enhanced software by successfully</SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"> implementing the SDL <o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l3 level1 lfo1" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Allow organizations to self-assess current software development security practices and create a strategy for gradual improvement <o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l3 level1 lfo1" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Provide SDL Pro Network service providers with a consistent and effective framework for providing S</SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">DL services<o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><FONT face=Calibri><B style="mso-bidi-font-weight: normal"><U><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial">SDL Pro Network:</SPAN></U></B><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"> The SDL Pro Network is a group of security service providers that specialize in application security and have substantial experience and expertise with the methodology and technologies of the Microsoft SDL. SDL Pro Network service providers will guide and support organizations in implementing the SDL into their environments.<o:p></o:p></SPAN></FONT></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><FONT face=Calibri>The primary focus area for all members, both now and in the future, will be to deliver on the program’s commitment to make the SDL available outside Microsoft, specifically focusing on these issues:<o:p></o:p></FONT></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Protecting the customer - Helping customers adopt the SDL or general secure coding practices.<o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Improving the SDL - Leveraging member knowledge to understand how the SDL is used by customers, what needs to be m</SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">odified and what customer needs must be met in the future.<o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><FONT face=Calibri><B style="mso-bidi-font-weight: normal"><U><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial">SDL Threat Modeling Tool Beta:</SPAN></U></B><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"> The Microsoft SDL Threat Modeling Tool Beta allows for structured analysis, proactive mitigation and tracking of potential security and privacy issues in new and existing applications.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Microsoft developed the tool and we use it internally on many of our products. This tool offers a threat modeling methodology that any software architect can lead effectively — in contrast with other processes, which are more expert-dependent. A few quick notes about the features:<o:p></o:p></SPAN></FONT></P>
<P style="TEXT-ALIGN: justify; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt; mso-bidi-font-family: Arial"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l4 level1 lfo3" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Automated guidance and feedback in drawing threat diagrams<o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l4 level1 lfo3" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Guided analysis of threats and mitigations based on the STRIDE taxonomy<o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l4 level1 lfo3" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Integration with bug-and issue-tracking systems like Visual Studio Team Foundation Server<o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-bidi-font-family: Arial; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt" class=MsoNoSpacing><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">To learn more about these, visit the SDL portal, </SPAN><A href="http://www.microsoft.com/sdl"><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #c00000; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">http://www.microsoft.com/sdl</SPAN></A><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #c00000; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">. <o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: justify; MARGIN: 0in 0in 0pt" class=MsoNoSpacing><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #c00000; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt"><FONT face=Calibri>By the way, if you are in Barcelona and want to stop by and chat, the session list is below:<o:p></o:p></FONT></SPAN></P>
<P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt"><FONT face=Calibri>SDL Theater Sessions:<o:p></o:p></FONT></SPAN></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo5" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Getting started with the new SDL Threat Modeling Tool<SPAN style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><o:p></o:p></SPAN></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Adam Shostack, Theater 1, Tuesday, Nov. 11, 15:20 – 15:40<o:p></o:p></SPAN></P>
<P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo5" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">You could do that but it would be wrong – a discussion of pros/cons of threat mitigations<o:p></o:p></SPAN></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">Michael Howard &amp; Adam Shostack, Theater 1, Thursday, Nov. 13, 10:20 – 10:40<o:p></o:p></SPAN></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"><o:p>&nbsp;</o:p></SPAN></P>
<P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal><SPAN style="FONT-SIZE: 10pt"><FONT face=Calibri>General Sessions:<o:p></o:p></FONT></SPAN></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo4" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">DVP308<SPAN style="mso-tab-count: 1">&nbsp; </SPAN>How I Learned to Stop Worrying and Love Threat Modeling<SPAN style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>Nov. 12, 10:45 – 12:00<o:p></o:p></SPAN></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo4" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">DVP309<SPAN style="mso-tab-count: 1">&nbsp; </SPAN>How to Review Your Code and Test for Security Bugs <SPAN style="mso-tab-count: 2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>Nov. 13, 3:15 – 4:30<o:p></o:p></SPAN></P>
<P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo4" class=MsoListParagraph><SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore">·<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 10pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin">DVP312<SPAN style="mso-tab-count: 1">&nbsp; </SPAN>Top Ten Strategies to Security Your Code<SPAN style="mso-tab-count: 3">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>Nov. 14, 10:45 – 12:00<o:p></o:p></SPAN></P>
<P style="MARGIN: 0in 0in 10pt" class=MsoNormal><SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"><o:p><FONT face=Calibri>&nbsp;</FONT></o:p></SPAN></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9058818" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 19:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/sdl pro network">sdl pro network</category>
      <category domain="http://securityratty.com/tag/sdl optimization model">sdl optimization model</category>
      <category domain="http://securityratty.com/tag/sdl threat">sdl threat</category>
      <category domain="http://securityratty.com/tag/sdl portal">sdl portal</category>
      <category domain="http://securityratty.com/tag/microsoft sdl">microsoft sdl</category>
      <category domain="http://securityratty.com/tag/security sessions">security sessions</category>
      <category domain="http://securityratty.com/tag/sessions">sessions</category>
      <category domain="http://securityratty.com/tag/sdl theater sessions">sdl theater sessions</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/11/10/sdl-announcements-at-teched-emea.aspx">SDL Announcements at TechEd EMEA</source>
    </item>
    <item>
      <title><![CDATA[Hardware Drive Encryption Becomes Manageable]]></title>
      <link>http://securityratty.com/article/3f1f395706509cb09fc84984610e562a</link>
      <guid>http://securityratty.com/article/3f1f395706509cb09fc84984610e562a</guid>
      <description><![CDATA[Regulatory compliance requirements and other best security practices are driving enterprises more consistently towards use of hard drive encryption, but it's not always an easy decision., Software...]]></description>
      <content:encoded><![CDATA[Regulatory compliance requirements and other best security practices are driving enterprises more consistently towards use of hard drive encryption, but it's not always an easy decision., Software encryption products can impose a performance burden and key management can be problematic.

<a href="http://www.seagate.com/security">The answer, argues Seagate, is hardware encryption built into the drive.</a> Integration into McAfee's Endpoint Encryption products makes key management more organized and secure, and no CPUs are burdened in the encryption or decryption of the data. Seagate also has announced they are now shipping 320GB and 500GB self-encrypted drives up to 7200RPM. Dell will be shipping notebooks with these drives. The drives come factory pre-loaded with management software.

Early this year headlines were had with the revelation, by researchers at Princeton, of a theoretical attack that could recover software encryption keys even from a notebook that had been shut off. It's actually silly James Bond stuff that real people shouldn't worry about, but it did demonstrate the real point that the keys exist in memory and there are ways they can be gotten. Attacks on the live system that gain control of it, through malware for example, could still gain access to any data to which the compromised user has access. With hardware-encrypted drives, at least the private key is secure and the Princeton attack is prevented.

Notebooks with drives like these in a managed environment really do make it easier to feel secure about notebooks, even if they have sensitive data on them. Combine them with other best practices, like multi-factor authentication, and you've given yourself the best chance to succeed in security. One day we'll use products like this and nothing less will be acceptable.
<p><a href="http://feedads.googleadservices.com/~a/T_UMdFf59j2CuXKDSsm3b87YBMY/a"><img src="http://feedads.googleadservices.com/~a/T_UMdFf59j2CuXKDSsm3b87YBMY/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/SRLtIgpRBwM" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 06:51:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/encryption">encryption</category>
      <category domain="http://securityratty.com/tag/software encryption products">software encryption products</category>
      <category domain="http://securityratty.com/tag/endpoint encryption products">endpoint encryption products</category>
      <category domain="http://securityratty.com/tag/drive">drive</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/hard drive encryption">hard drive encryption</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/key management">key management</category>
      <category domain="http://securityratty.com/tag/sensitive data">sensitive data</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/SRLtIgpRBwM/hardware_drive_encryption_becomes_manageable.html">Hardware Drive Encryption Becomes Manageable</source>
    </item>
    <item>
      <title><![CDATA[Zeus Crimeware Kit Gets a Carding Layout]]></title>
      <link>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</link>
      <guid>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</guid>
      <description><![CDATA[With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s1600-h/zeus_new_layout_22.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s200/zeus_new_layout_22.GIF" /></a>With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a boost. Following the <a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">ongoing modification</a> of open source <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">crimeware kits</a> and the inevitable innovation introduced <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">by third parties</a>, last week a new layout was introduced for Zeus, once again courtesy of a group that's piggybacking on Zeus popularity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>It's particularly interesting to see how a one-man operation evolves into a group of third-party developers starting to claim ownership rights over the modified versions despite that they're basically brandjacking the Zeus brand and building business models on the top of it.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s1600-h/zeus_new_layout_11.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s200/zeus_new_layout_11.GIF" /></a>Open source crimeware and web malware exploitation kits on the other hand undermine the business model of a great number of "<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">malware/spyware for hire</a>" vendors, which surprisingly doesn't stop them from continuing offering their services and products which are often using the de facto crimeware kits as the foundations for their propositions. Are the buyers even aware of this fact? From a buyer's perspective in times when most of the output is sold in bulk form, or access to the botnet rented for a specific period of time, the buyer doesn't care about the cybercrime platform of use, but is looking for transparent ways to justify the investment he's made into renting the service.<br />
<br />
Now that Zeus administrators and their cybercrime clerks in the face of those managing the campaigns knowingly or unknowingly knowing the type of campaigns and the data that they manage, can <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">listen to their favorite music within Zeus</a> and choose different layouts for the command and control interfaces while commiting cybercrime, what's next?<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Convergence</a> and improved monetization.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQb6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQb6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rhj0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rhj0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9MADn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9MADn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Kqtmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Kqtmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cqo2N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cqo2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pkhEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pkhEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i9tYn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i9tYn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/448333234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 02:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/zeus administrators">zeus administrators</category>
      <category domain="http://securityratty.com/tag/zeus popularity">zeus popularity</category>
      <category domain="http://securityratty.com/tag/source crimeware kits">source crimeware kits</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime clerks">cybercrime clerks</category>
      <category domain="http://securityratty.com/tag/source crimeware">source crimeware</category>
      <category domain="http://securityratty.com/tag/zeus brand">zeus brand</category>
      <category domain="http://securityratty.com/tag/cybercrime platform">cybercrime platform</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/448333234/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</source>
    </item>
    <item>
      <title><![CDATA[On Small Companies and PCI Compliance]]></title>
      <link>http://securityratty.com/article/e0e1165c2e26892133c37ebe3e10c017</link>
      <guid>http://securityratty.com/article/e0e1165c2e26892133c37ebe3e10c017</guid>
      <description><![CDATA[Read this post ( &quot;E-Commerce Startups deal with PCI compliance &quot; at &quot;PCI Anwsers&quot; Blog ) and weeeeeeep: &quot;I once was talking with a small business owner who was reading through the Self-Assessment...]]></description>
      <content:encoded><![CDATA[Read <a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">this post</a> (<a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">"E-Commerce Startups deal with PCI compliance</a>" at <a href="http://pcianswers.com">"PCI Anwsers" Blog</a>) and weeeeeeep:  "I once was talking with a small business owner who was reading through the Self-Assessment Questionnaire (SAQ) and stopped at the first question, which basically said, Do you have a properly configured firewall? <span style="font-weight: bold;"> The business owner called into the back room and asked the store manager, “Hey, do we have a firewall?”</span>  <span style="font-weight: bold;">The store manager replied that he thought they had a fire extinguisher which was up to date.  </span>I then watched as the store manger<span style="font-weight: bold;"> checked the “In Place” box</span> on the form stating they had a properly configured firewall in place."<br /><br />Wonna "sell  PCI compliance" to small businesses? One need to get smart in a very special way! :-)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=McEHN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=McEHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=g0W2N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=g0W2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IAe6N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IAe6N" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/442458664" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 08:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/store manager">store manager</category>
      <category domain="http://securityratty.com/tag/business owner">business owner</category>
      <category domain="http://securityratty.com/tag/e-commerce startups deal">e-commerce startups deal</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <category domain="http://securityratty.com/tag/self-assessment questionnaire">self-assessment questionnaire</category>
      <category domain="http://securityratty.com/tag/properly">properly</category>
      <category domain="http://securityratty.com/tag/fire extinguisher">fire extinguisher</category>
      <category domain="http://securityratty.com/tag/store manger">store manger</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/442458664/on-small-companies-and-pci-compliance.html">On Small Companies and PCI Compliance</source>
    </item>
  </channel>
</rss>
