<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: survey]]></title>
    <link>http://securityratty.com/tag/survey</link>
    <description></description>
    <pubDate>Tue, 19 Aug 2008 12:12:41 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Should You Install Messaging Security Software on Your Exchange Server?]]></title>
      <link>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</link>
      <guid>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</guid>
      <description><![CDATA[Source: Sunbelt Software) Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions. Read this white paper to help...]]></description>
      <content:encoded><![CDATA[<b>(Source:  Sunbelt Software)</b> Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions.  Read this white paper to help you understand the latest Exchange security risks and also learn about reasons why an installed security solution may be the best option for you in countering those challenges.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:4c2325713dd32016c18954ac278d0864:NFQXxHFMI5joATi8rb9XqG1wphiNoRddmISCypgry8gEDx2Kenb%2BwST2VWrGNREyFwdH5a2LrernMF3UzVyemXdU3bxFrh23RewQbJvsbuU%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ae8b7af0edbdcbad40287f4417dc000e:fzsuOnQABO%2F8zb5KR73dVE95rbdex%2BnHTgnrI25OHes0WbXZDNfE9nFNPIILxlOYupKK7IkQgzmbRxlSncXrguiZ7MZAsL4%2FH5S1pQG82Pw%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9c187aa78b037950ceedc32de289ca2a:oM6A8Agm%2F3STbmMJgABVmGsiNFyFOaEhlsz8Si9HGzhxFAyAewDxbjLhdwiEQuD0ypx4eY%2BBm21mHRQFzIJF9g8%2FNKkoh0hbbKprpRjTCWY%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:be6d95967a93a89dc81e7f6b60ac6416:ibgVPVeXQV%2FqsmmMgf4t8i5bA1sbwSydZxlubOrocwKd3AketgClxa1YazuQW6MMa1W2lTZwLFa1Y8zrp1bym0dpybbsmX4n87C8piBSqHs%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=27986667fa8fa86c25fb326572f03aad" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=27986667fa8fa86c25fb326572f03aad" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email security solutions">email security solutions</category>
      <category domain="http://securityratty.com/tag/exchange security risks">exchange security risks</category>
      <category domain="http://securityratty.com/tag/white paper">white paper</category>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/security solution">security solution</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/dispel">dispel</category>
      <source url="http://www.pheedo.com/click.phdo?i=27986667fa8fa86c25fb326572f03aad">Should You Install Messaging Security Software on Your Exchange Server?</source>
    </item>
    <item>
      <title><![CDATA[More MMORPG Fakeouts]]></title>
      <link>http://securityratty.com/article/b648d83d66372f23dbf0ea3ee7b7deee</link>
      <guid>http://securityratty.com/article/b648d83d66372f23dbf0ea3ee7b7deee</guid>
      <description><![CDATA[Here's a few more sites presumably created by the maker of the fake Batman Online game

Step up, Dragonball Z



Click to Enlarge

To &quot;download&quot; this Dragonball Z MMORPG, you have to fill out a...]]></description>
      <content:encoded><![CDATA[
        Here's a few more sites presumably created by the maker of the <a href="http://blog.spywareguide.com/2008/09/zango-and-the-batman-online-vi.html">fake Batman Online game</a>. <br /><br />Step up, Dragonball Z:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbz1.html" onclick="window.open('http://blog.spywareguide.com/images/dbz1.html','popup','width=624,height=585,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbz1-thumb-324x303.gif" alt="dbz1.gif" class="mt-image-none" style="" height="303" width="324" /></a></span><br />Click to Enlarge<br /></div><br />To "download" this Dragonball Z MMORPG, you have to fill out a survey:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbz2.html" onclick="window.open('http://blog.spywareguide.com/images/dbz2.html','popup','width=672,height=530,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbz2-thumb-372x293.gif" alt="dbz2.gif" class="mt-image-none" style="" height="293" width="372" /></a></span>
<br />Click to Enlarge<br /></div><br />Once done, you'll be amazed(!) to find you're taken to....shockingly....the <i>official</i> Dragonball Z MMORPG game.<br /><br />The only problem? The website is in Japanese and the game <a href="http://en.wikipedia.org/wiki/Dragon_Ball_Online">hasn't been released yet</a>.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbz3.html" onclick="window.open('http://blog.spywareguide.com/images/dbz3.html','popup','width=815,height=592,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbz3-thumb-315x228.gif" alt="dbz3.gif" class="mt-image-none" style="" height="228" width="315" /></a></span><br />Click to Enlarge<br /></div><br />Forgive me for thinking this isn't the greatest deal I've ever been sold.<br /><br />Now it's Harry Potters turn:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hp1.html" onclick="window.open('http://blog.spywareguide.com/images/hp1.html','popup','width=565,height=580,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hp1-thumb-365x374.jpg" alt="hp1.jpg" class="mt-image-none" style="" height="374" width="365" /></a></span><br />Click to Enlarge<br /></div><br />Like the Batman site, you need to install Zango. Do so, and.....you're taken to the popular <a href="http://www.hogwartslive.com/">Hogwarts Live</a>, which you could have easily found and played yourself without installing Adware. As you probably guessed, the screenshot from the title graphic on the site is <i>not</i> part of the game you'll eventually play.<br /><br />The sites involved are<br /><br />onlinedbzgame.info<br /><br />and<br /><br />harrypottergame.info<br /><br />in case you want to add them to your blocklists.<br />
        
    ]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 12:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mmorpg">mmorpg</category>
      <category domain="http://securityratty.com/tag/mmorpg game">mmorpg game</category>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/official dragonball">official dragonball</category>
      <category domain="http://securityratty.com/tag/dragonball">dragonball</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/popular hogwarts live">popular hogwarts live</category>
      <category domain="http://securityratty.com/tag/batman site">batman site</category>
      <source url="http://blog.spywareguide.com/2008/09/more-mmorpg-fakeouts.html">More MMORPG Fakeouts</source>
    </item>
    <item>
      <title><![CDATA[Survey: VARs concerned about cybersecurity, health care]]></title>
      <link>http://securityratty.com/article/a99ef3c85e4baaa553ed939d414e433e</link>
      <guid>http://securityratty.com/article/a99ef3c85e4baaa553ed939d414e433e</guid>
      <description><![CDATA[Many U.S. businesses fail to take cybersecurity protection seriously and are unwilling to spend money on additional protection, according to a recent survey of value added resellers (VARs) by the...]]></description>
      <content:encoded><![CDATA[Many U.S. businesses fail to take cybersecurity protection seriously and are unwilling to spend money on additional protection, according to a recent survey of value added resellers (VARs) by the Computing Technology Industry Association.]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/technology industry association">technology industry association</category>
      <category domain="http://securityratty.com/tag/cybersecurity protection">cybersecurity protection</category>
      <category domain="http://securityratty.com/tag/recent survey">recent survey</category>
      <category domain="http://securityratty.com/tag/additional protection">additional protection</category>
      <category domain="http://securityratty.com/tag/businesses fail">businesses fail</category>
      <category domain="http://securityratty.com/tag/vars">vars</category>
      <category domain="http://securityratty.com/tag/resellers">resellers</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <source url="http://www.networkworld.com/news/2008/090408-survey-vars-concerned-about-cybersecurity.html?fsrc=rss-security">Survey: VARs concerned about cybersecurity, health care</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.29.08]]></title>
      <link>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</link>
      <guid>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</guid>
      <description><![CDATA[ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents reported that third-quarter IT spending was lower than previously planned while 12...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="240" alt="michaelphelps" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/michaelphelps.jpg" width="174" align="left" border="0" /> ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents <a href="http://www.infoworld.com/article/08/08/27/Grim_outlook_for_US_IT_spending_1.html?source=NLC-DAILY&amp;cgd=2008-08-28" target="_blank">reported that third-quarter IT spending was lower</a> than previously planned &#8211; while 12 percent spent more than planned. Thirty-five percent cited higher energy costs as the top factor for spending slowdown. </p>
<p>Parlez-vous open source? While wide-spread open source usage is still debated in many companies, the French have been advocating for <a href="http://www.infoworld.com/article/08/08/28/35NF-open-source-france-lessons_1.html" target="_blank">all open source all the time in government and education</a>. French President Nicolas Sarkozy set up an economic commission that recommended tax benefits to stimulate more open source development. Lesson learned from France: start &#8216;em early. &#8220;All students in France use open source.&#8221;</p>
<p>Just in time for Labor Day, John Edwards (no, not that one) comes out with an informative guide on &#8220;<a href="http://www.infoworld.com/article/08/08/27/35NF-cloud-providers_1.html" target="_blank">Who provides what in the cloud</a>&#8221;. No doubt, this will be a rapidly expanding list, but what&#8217;s really interesting is the comment on the article. People have very strong opinions on the cloud&#8230;</p>
<p>Research firm Aberdeen Group reports that <a href="http://www.cio.com/article/445863/Network_Management_Tips_for_Managing_Costs?page=1" target="_blank">network costs will increase</a> slightly more than 5 percent over 2007. Contributing factors: &#8220;need for speed&#8221;, shift from standard to mobile PCs (more end points of connectivity), and the ever-expanding network. And of course the hidden costs of multiple tools with multiple management consoles &#8211; if you&#8217;re not smart enough to choose say a comprehensive network management solution that is vendor agnostic&#8230;One tool to monitor them all&#8230;</p>
<p>And just because I miss the Olympics already, here&#8217;s an irreverent take on what it&#8217;s like to lose to Michael Phelps. <a href="http://www.thetechstop.net/?p=1503">http://www.thetechstop.net/?p=1503</a></p>
<p>Enjoy your long Labor Day Weekend!</p>
]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 10:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/source development">source development</category>
      <category domain="http://securityratty.com/tag/thirty percent">thirty percent</category>
      <category domain="http://securityratty.com/tag/labor day">labor day</category>
      <category domain="http://securityratty.com/tag/source usage">source usage</category>
      <category domain="http://securityratty.com/tag/costs">costs</category>
      <category domain="http://securityratty.com/tag/energy costs">energy costs</category>
      <category domain="http://securityratty.com/tag/thirty-five percent cited">thirty-five percent cited</category>
      <source url="http://blog.sciencelogic.com/links-list-82908/08/2008">Links List 8.29.08</source>
    </item>
    <item>
      <title><![CDATA[How do you Manage Virtualization if you cant see Performance?]]></title>
      <link>http://securityratty.com/article/ed2ef4931f690c62b02f28e517c0aa0d</link>
      <guid>http://securityratty.com/article/ed2ef4931f690c62b02f28e517c0aa0d</guid>
      <description><![CDATA[NetIQ, which seemed to drop off the planet not long after being bought by Attachmate , is back with the results of a very interesting virtualization survey . Now, you know that you need to take all...]]></description>
      <content:encoded><![CDATA[<p>NetIQ, which seemed to drop off the planet not long after being <a href="http://www.itjungle.com/tfh/tfh071706-story08.html">bought by Attachmate</a>, is back with the results of a very interesting <a href="http://tarrysingh.blogspot.com/2008/08/netiq-survery-virtualization-initiative.html">virtualization survey</a>. Now, you know that you need to take all surveys with a big grain of salt (e.g., the majority of respondents to this one were less than 10% virtualized), but it&#8217;s still good to take temperatures whenever possible. </p>
<p>The numbers we found interesting: </p>
<p>- only 21% currently deploying virtualization have any kind of systems management solutions for their virtual infrastructure </p>
<p>- about 27% are managing performance/ability of virtual systems with same tools they use for physical servers (Nothing wrong with that as long as they&#8217;re seeing what they need to see but&#8230;)</p>
<p>- 40 percent of those surveyed do not report the performance of their virtualized applications, hardware, <a href="http://virtualization.com/news/2008/08/26/netiq-survey-results-reflect-lack-of-virtualization-management-basics/">operating systems, or their virtual machines in any measureable</a> way (which rather undercuts the whole point)</p>
<p>Get the full results <a href="http://download.netiq.com/Library/Misc/VirtualizationSurveyAnalysis-Aug2008.pdf">here</a>.</p>
]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 21:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/systems management solutions">systems management solutions</category>
      <category domain="http://securityratty.com/tag/virtual systems">virtual systems</category>
      <category domain="http://securityratty.com/tag/virtualization survey">virtualization survey</category>
      <category domain="http://securityratty.com/tag/virtual machines">virtual machines</category>
      <category domain="http://securityratty.com/tag/physical servers">physical servers</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/performance">performance</category>
      <source url="http://blog.sciencelogic.com/how-do-you-manage-virtualization-if-you-cant-see-performance/08/2008">How do you Manage Virtualization if you cant see Performance?</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[Watch Out! Firing IT Workers Can Cost You]]></title>
      <link>http://securityratty.com/article/58e9222ea818b146a5e3f7452193a99b</link>
      <guid>http://securityratty.com/article/58e9222ea818b146a5e3f7452193a99b</guid>
      <description><![CDATA[When IT employees are dismissed, watch out! A new survey by Cyber-Ark Software, a provider of identity management products, reports that theft of sensitive information by disgruntled former insiders...]]></description>
      <content:encoded><![CDATA[When IT employees are dismissed, watch out! A new survey by Cyber-Ark Software, a provider of identity management products, reports that theft of sensitive information by disgruntled former insiders is out of control.]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity management products">identity management products</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/cyber-ark software">cyber-ark software</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/insiders">insiders</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/reports">reports</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <source url="http://www.networkworld.com/news/2008/082808-watch-out-firing-it-workers.html?fsrc=rss-security">Watch Out! Firing IT Workers Can Cost You</source>
    </item>
    <item>
      <title><![CDATA[Four quick tips for choosing an IM security product]]></title>
      <link>http://securityratty.com/article/644c4d858c0af28c530dae2d00363c43</link>
      <guid>http://securityratty.com/article/644c4d858c0af28c530dae2d00363c43</guid>
      <description><![CDATA[Instant messaging (IM) has become an increasingly useful business tool for modern corporations. Data from a Forrester Research survey suggests that 71% of businesses will invest in real-time messaging...]]></description>
      <content:encoded><![CDATA[Instant messaging (IM) has become an increasingly useful business tool for modern corporations. Data from a Forrester Research survey suggests that 71% of businesses will invest in real-time messaging this year.]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/modern corporations">modern corporations</category>
      <category domain="http://securityratty.com/tag/business tool">business tool</category>
      <category domain="http://securityratty.com/tag/real-time">real-time</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/instant">instant</category>
      <category domain="http://securityratty.com/tag/increasingly">increasingly</category>
      <source url="http://www.networkworld.com/news/2008/082608-four-quick-tips-for-choosing.html?fsrc=rss-security">Four quick tips for choosing an IM security product</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.22.08]]></title>
      <link>http://securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</link>
      <guid>http://securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</guid>
      <description><![CDATA[Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning running in the sky with the torch? Oooh, aah. And wait, whats that image on the wall behind him? Looks kinda familiaroops,...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="170" alt="bsod_nest_main2" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/bsod-nest-main2.jpg" width="244" align="left" border="0"> Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning “running” in the sky with the torch? Oooh, aah. And wait, what’s that image on the wall behind him? Looks kinda familiar…oops, it’s an <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/08/geek_week_tk_tk_1.html?source=NLC-NOTES&amp;cgd=2008-08-18" target="_blank">XP blue screen of death</a>….I wonder how much Microsoft paid for advertising during the Olympics?
<p><em>(</em><a href="http://cache.gizmodo.com/assets/images/gizmodo/2008/08/bsod_nest_main2.jpg" target="_blank"><em>Photo Credit: Gizmodo</em></a><em>)</em>
<p>You lose some. You win some: Of course as NBC’s online partner, Microsoft gets a least a cut of the <a href="http://www.paidcontent.org/entry/419-online-ad-spend-tied-to-olympics-expected-to-reach-100-million/" target="_blank">$100 million dollars in online advertising</a> spent around the Olympics. And the millions of <a href="http://www.businessweek.com/technology/content/aug2008/tc20080820_627259.htm?campaign_id=rss_daily" target="_blank">downloads of Silverlight</a> aren’t too shabby either.
<p>The Internet is Falling! Arbor Networks, a security and network management company, partnered with ninety network services and content providers from around the world to publish an extensive <a href="http://www.circleid.com/posts/88181_largest_study_of_ipv6_traffic/" target="_blank">study of IPv6 traffic</a> on the Internet. Craig Labovitiz, Arbor Networks chief scientist, stated that <a href="http://asert.arbornetworks.com/2008/8/the-end-is-near-but-is-ipv6/" target="_blank">only 900 days were left until the end of the Internet</a>, or at least the exhaustion of IPv4 registry allocations. For the past year, the study shows very little IPv6 traffic – something like 1/100<sup>th</sup> of 1% of Internet traffic. Craig credits this to money issues. “The department of commerce estimates it will cost $25 billion for ISPs to upgrade to native IPv6.”
<p>Blogger <a href="http://blog.jamesurquhart.com/2008/08/cloud-computing-bill-of-rights.html" target="_blank">James Urquhart created a bill of rights for cloud computing</a>. The purpose of the bill is to “help guide would-be cloud customers to those clouds best able to guarantee their freedom.” The blogosphere is a great place to get some open debate going, and I applaud James for trying to make something yet so “cloudy” a bit more clear and concrete. But what’s up with the creating a PAC for this?? (Check out the comments.)
<p>Trying to get by on limited resources? Need more money, staff and the freedom to focus on long-term projects? Sound familiar? Then you just might be in <a href="http://blogs.wsj.com/biztech/2008/08/21/life-is-tough-for-midsize-tech-departments/?mod=djemTECH" target="_blank">IT at a midsize company</a>. (or in marketing at a young but rapidly growing IT company <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) Arrow Enterprise Computing Solutions conducted a survey of 200 tech leaders at midsize companies (500 to 3000 employees). The upside: 61% of those surveyed think they’ll be spending more on IT next year – is this bullish thinking about the economy or how much their own business (rev) will be growing?
<p>Bill Snyder calls Dell “<a href="http://weblog.infoworld.com/tech-bottom-line/archives/2008/08/michael_dell_is.html?source=NLC-DAILY&amp;cgd=2008-08-21" target="_blank">Bozo of the Month</a>” for trying to trademark “cloud computing”. Yikes. Maybe not a “bozo” move but certainly inadvisable given how ubiquitous the term is. Here’s <a href="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008" target="_blank">our take</a> on it.</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 16:15:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network management company">network management company</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet traffic">internet traffic</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/nbcs online partner">nbcs online partner</category>
      <category domain="http://securityratty.com/tag/ipv6 traffic">ipv6 traffic</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/blogger james urquhart">blogger james urquhart</category>
      <category domain="http://securityratty.com/tag/ninety network services">ninety network services</category>
      <source url="http://blog.sciencelogic.com/links-list-82208/08/2008">Links List 8.22.08</source>
    </item>
    <item>
      <title><![CDATA[Consumer Reports Responds]]></title>
      <link>http://securityratty.com/article/6c99136056552315f93619486db85f54</link>
      <guid>http://securityratty.com/article/6c99136056552315f93619486db85f54</guid>
      <description><![CDATA[Consumer Reports has sent a response to my recent column Security Software Reviews Done Wrong , which criticized their recent story on computer security and review of security products. This statement...]]></description>
      <content:encoded><![CDATA[Consumer Reports has sent a response to my recent column <A href="http://www.eweek.com/c/a/Security/The-Wrong-Way-To-Review-Security-Software/">Security Software Reviews Done Wrong</A>, which criticized their recent story on computer security and review of security products.

This statement is from Jeff Fox, Technology Editor, Consumer Reports:
<blockquote><i>At Consumer Reports, we have always believed that scientific testing is the best way to evaluate products. We also use a statistically-valid survey methodology to measure consumer experiences. In preparing our September security reports, we employed both methods as we have for many decades. Some additional notes on this column:

<ul>
	<li>The story was not, as you state, "filled with data sourced to eMarketer." That service provided just two pieces of data, namely the current number of Internet- and broadband-using U.S. Households</li>
	<li>Using a separate credit card for online transactions avoids having to cancel your main card should fraud occur.</li>
	<li>We test software against modified versions of actual malware because such threats are what security software will often be called upon to recognize on the job.</li>
</ul>

Finally, a note about your claim that Consumer Reports was invited to respond. Your e-mail to us requesting a comment was time-stamped on the same Saturday evening as your column is labeled as having posted. That left fewer than six hours to respond, on a weekend. It would have been helpful to have had more time.</i></blockquote>

It's true, as I said in the column, that I didn't give them much time to respond. I hope I can make up for that some by putting this response out now and including it in the column itself.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/jvhoWp-SQns" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 12:12:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/consumer reports">consumer reports</category>
      <category domain="http://securityratty.com/tag/column">column</category>
      <category domain="http://securityratty.com/tag/measure consumer experiences">measure consumer experiences</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/online transactions avoids">online transactions avoids</category>
      <category domain="http://securityratty.com/tag/recent story">recent story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/september security reports">september security reports</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/jvhoWp-SQns/consumer_reports_responds.html">Consumer Reports Responds</source>
    </item>
  </channel>
</rss>
