<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tjxs]]></title>
    <link>http://securityratty.com/tag/tjxs</link>
    <description></description>
    <pubDate>Tue, 05 Feb 2008 04:44:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Show 030 - An Interview with Ken van Wyk]]></title>
      <link>http://securityratty.com/article/0b1369b7e3490f60e22d2ae7d871f6c7</link>
      <guid>http://securityratty.com/article/0b1369b7e3490f60e22d2ae7d871f6c7</guid>
      <description><![CDATA[On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates. Ken was the first employee of CERT and has been an active member of...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Ken van Wyk" title="Ken van Wyk" src="http://www.cigital.com/silverbullet/kvanwyk-125.png" style="padding-left: 7px;" /></p>
<p>On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline of computer science doesn&#8217;t learn from failure like mechanical engineering does, how we&#8217;re making steps backwards in computer security, whether focusing on web applications is a good or bad thing for software security, and Ken&#8217;s recommendation for moderately-priced red wines.</p>
<ul>
<li><a href="http://www.vanwyk.org/ken/">Ken&#8217;s personal page</a></li>
<li><a href="http://www.krvw.com/">KRvW Associates</a></li>
<li><a href="http://www.cert.org/">CERT</a></li>
<li><a href="http://www.first.org/">FIRST</a></li>
<li><a href="http://www.securecoding.org/"><em>Secure Coding</em></a></li>
<li><a href="http://oreilly.com/catalog/9780596001308/"><em>Incident Response</em></a></li>
<li><a href="http://www.securecoding.org/list/">SC-L mailing list</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/07/06/from-the-foreword-to-secure-programming-with-static-analysis/">From the foreword to Secure Programming with Static Analysis</a> - blog entry with photo of Tacoma Narrows Bridge</li>
<li><a href="http://finance.google.com/finance?chdnp=1&#038;chdd=1&#038;chds=1&#038;chdv=1&#038;chvs=maximized&#038;chdeh=0&#038;chdet=1222200000000&#038;chddm=166345&#038;q=NYSE:TJX&#038;ntsp=0">TJX&#8217;s stock increase since the January 2007 security breach</a></li>
<li><a href="http://www.buildsecurityin.com/">The Addison-Wesley Software Security Series</a></li>
<li><a href="http://www.google.com/search?hl=en&#038;client=opera&#038;rls=en&#038;hs=fdc&#038;sa=X&#038;oi=spell&#038;resnum=0&#038;ct=result&#038;cd=1&#038;q=barbara+d%27asti&#038;spell=1">Barbara D&#8217;Asti wines</a></li>
</ul>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 17:23:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/van wyk">van wyk</category>
      <category domain="http://securityratty.com/tag/tjxs stock increase">tjxs stock increase</category>
      <category domain="http://securityratty.com/tag/barbara dasti wines">barbara dasti wines</category>
      <category domain="http://securityratty.com/tag/tacoma narrows bridge">tacoma narrows bridge</category>
      <category domain="http://securityratty.com/tag/kens personal page">kens personal page</category>
      <category domain="http://securityratty.com/tag/red wines">red wines</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/gary talks">gary talks</category>
      <source url="http://www.cigital.com/silverbullet/show-030/">Show 030 - An Interview with Ken van Wyk</source>
    </item>
    <item>
      <title><![CDATA[Again On Breaches and Stock Price]]></title>
      <link>http://securityratty.com/article/13371f6c645132032f5b6217ed929cd6</link>
      <guid>http://securityratty.com/article/13371f6c645132032f5b6217ed929cd6</guid>
      <description><![CDATA[Richard &quot;IDS is dead&quot; Stiennon throws a bomb : &quot; First, esoteric matters like IT security really do not matter to the overall performance of a retailer. Customers, employees, stakeholders, apparently...]]></description>
      <content:encoded><![CDATA[<span style="font-style: italic;">Richard "IDS is dead" Stiennon</span> <a href="http://www.cioupdate.com/trends/article.php/11047_3732346_2">throws a bomb</a>: "<span><span style="font-family:Verdana, Arial, Helvetica;font-size:-1;"><span style="font-size: 11pt; font-family: Verdana;">First, esoteric matters like IT security really do not matter to the overall performance of a retailer. Customers, employees, stakeholders, apparently don’t care. Second, no matter what the security industry says, <span style="font-weight: bold;">you should not justify security spending based on potential impact of a data breach on your stock price. </span>That theory is completely disproved by TJX."<br /><br />Enraged? Think he is pushing it too far? Being illogical? Me too :-) I don't think TJX example just goes and "disproves" it; we don't really know how it works with breaches and stock prices (some say 4-8% down, some say none, some say 'major impact', whatever...)<br /><br />He then clarifies: "</span></span></span><span><span style="font-family:Verdana, Arial, Helvetica;font-size:-1;"><span style="font-size: 11pt; font-family: Verdana;">But let me point out that TJX has attributed $200 million in direct costs to this breach. It is easy to surmise this is bigger than just about anyone’s security budget. In TJX’s case some well known security practices and a little security spending would have avoided this whole incident."<br /><br />Overall, <a href="http://www.cioupdate.com/trends/article.php/11047_3732346_2">a fun read</a>. Still, I think breach impact assessment and breach's impact <span style="font-style: italic;">on anything </span>(much less the stock price...) is not really well-defined or understood yet ...<br /></span></span></span><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=QMNRJtF"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=QMNRJtF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=kNdfn1F"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=kNdfn1F" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/249984709" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 11 Mar 2008 21:34:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security practices">security practices</category>
      <category domain="http://securityratty.com/tag/stock price">stock price</category>
      <category domain="http://securityratty.com/tag/data breach">data breach</category>
      <category domain="http://securityratty.com/tag/impact">impact</category>
      <category domain="http://securityratty.com/tag/anyones security budget">anyones security budget</category>
      <category domain="http://securityratty.com/tag/potential impact">potential impact</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/breach impact assessment">breach impact assessment</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/249984709/again-on-breaches-and-stock-price.html">Again On Breaches and Stock Price</source>
    </item>
    <item>
      <title><![CDATA[Nobody Is That Dumb ... Oh, Wait IX]]></title>
      <link>http://securityratty.com/article/4e7c40a54a803f72383def6af4071f99</link>
      <guid>http://securityratty.com/article/4e7c40a54a803f72383def6af4071f99</guid>
      <description><![CDATA[Yes, my &quot;Nobody Is That Dumb ... Oh, Wait&quot; series comes back - with a vengeance! I really should have launched &quot;the dumbest prediction of the year&quot; contest, but I didn't :-) Still, we have a...]]></description>
      <content:encoded><![CDATA[Yes, my "Nobody Is That Dumb ... Oh, Wait" <a href="http://chuvakin.blogspot.com/search/label/stupidity">series </a>comes back - with a vengeance!  I really should have launched "the dumbest prediction of the year" contest, but I didn't :-) Still, we have a wiiiiiiiiiiinner: "<a href="http://www.high-tower.com/blogs/gschultz/ninth-prediction-for-2008/">TJX’s Security Breaches Will Force it to Go out of Business or to Merge with Another Company</a>"  Huh?   Then it gets better: "Furthermore, the negative impact upon TJX’s public image is difficult to assess, but it is not difficult to imagine that it has been large."<br /><br />Ummm, no! I think people <span style="font-style: italic;">rightly </span>don't care and will continue to shop at TJX. In the event of card abuse, one 10 minute call to your CC issuer solves the problem; a new card arrives in a few days. Magic! :-)<br /><br />I bet the opposite will happen: this will prove that you can <span style="font-weight: bold;">operate while 0wned</span> and leaking data like a sieve ...<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Qqo1USE"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Qqo1USE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=vA60tZE"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=vA60tZE" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/229677491" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Feb 2008 04:44:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tjxs security breaches">tjxs security breaches</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/card arrives">card arrives</category>
      <category domain="http://securityratty.com/tag/tjxs public image">tjxs public image</category>
      <category domain="http://securityratty.com/tag/minute call">minute call</category>
      <category domain="http://securityratty.com/tag/negative impact">negative impact</category>
      <category domain="http://securityratty.com/tag/dumb">dumb</category>
      <category domain="http://securityratty.com/tag/issuer solves">issuer solves</category>
      <category domain="http://securityratty.com/tag/wait">wait</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/229677491/nobody-is-that-dumb-oh-wait-ix.html">Nobody Is That Dumb ... Oh, Wait IX</source>
    </item>
  </channel>
</rss>
