<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: way-out]]></title>
    <link>http://securityratty.com/tag/way-out</link>
    <description></description>
    <pubDate>Tue, 25 Nov 2008 11:20:47 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Who do you train and how do you train them?]]></title>
      <link>http://securityratty.com/article/44b3ebd8b5a65afcb390936d3b7d2f0d</link>
      <guid>http://securityratty.com/article/44b3ebd8b5a65afcb390936d3b7d2f0d</guid>
      <description><![CDATA[The Motley Fool's Dave Gardner blogged about Drucker's approach to training

We've tried to manage our Motley Fool business the Drucker way for 15 years, too. Lemme ask you a question. I'm putting you...]]></description>
      <content:encoded><![CDATA[<p>The Motley Fool&#39;s Dave Gardner <a href="http://caps.fool.com/Blogs/ViewPost.aspx?bpid=115905&amp;t=01000000000000052298">blogged</a> about <a href="http://en.wikipedia.org/wiki/Peter_Drucker">Drucker&#39;s</a> approach to training:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: 17px; ">We&#39;ve tried to manage our Motley Fool business the Drucker way for 15 years, too. Lemme ask you a question. I&#39;m putting you in charge of your human resources group, in charge of your corporate culture, and you have two choices of how to spend $100,000 -- your call, here, Drucker or Anti-Drucker -- these are the two ways you can invest:</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: 17px;"><br /></span><span style="font-family: arial; line-height: 17px; ">(a) a program to try to get D- employees up to a C, people who have motivational and/or social problems, toxicly bring down the teams they&#39;re on, and clearly aren&#39;t fit to be hired even by weak competitors in your field, or</span><br /><span style="font-family: arial; line-height: 17px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: 17px; ">(b) a program to invest in your stars -- invest in more training, outside experiences, and leadership opportunities for your best employees</span></p></blockquote><div><span style="font-family: Arial; font-size: 16px; line-height: normal; "><p style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-bottom: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; font-family: Arial, Helvetica, sans-serif; font-size: 0.7em; font: normal normal normal 0.8em/normal arial, sans-serif; margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-right: 2em; line-height: 1.4em; ">In my swamp of <a href="http://arctecgroup.net/training.htm">software security training</a>, I have trained both an organization&#39;s average developers as well as their top people. I think there is validity to both, because security is a system problem, but the approaches you use are slightly different. In the case of getting the general developer population up to speed you usually want to aim for a <a href="http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf">checklist</a> type approach and give the developers something like a cookbook full of recipes they can follow. So you are heavier on the prescription of what to do and less about the why.</p><p style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-bottom: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; font-family: Arial, Helvetica, sans-serif; font-size: 0.7em; font: normal normal normal 0.8em/normal arial, sans-serif; margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-right: 2em; line-height: 1.4em; ">When I am training the top architects, developers, and security people, then I usually aim to give more of a <a href="http://arctecgroup.net/pdf/ArctecSecurityArchitectureBlueprint.pdf">security architecture</a> <a href="http://arctecgroup.net/ISB1009GP.pdf">framework</a>, so they can then apply the framework depending on the specific problem context.</p><p style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-bottom: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; font-family: Arial, Helvetica, sans-serif; font-size: 0.7em; font: normal normal normal 0.8em/normal arial, sans-serif; margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-right: 2em; line-height: 1.4em; "></p></span></div>]]></content:encoded>
      <pubDate>Thu, 04 Dec 2008 10:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/security people">security people</category>
      <category domain="http://securityratty.com/tag/motley fool">motley fool</category>
      <category domain="http://securityratty.com/tag/security architecture framework">security architecture framework</category>
      <category domain="http://securityratty.com/tag/motley fool business">motley fool business</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/top people">top people</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/12/who-do-you-train-and-how-do-you-train-them.html">Who do you train and how do you train them?</source>
    </item>
    <item>
      <title><![CDATA[One More Bit On "Compliance First"]]></title>
      <link>http://securityratty.com/article/11258c988c75c2f65a373a3364eb6202</link>
      <guid>http://securityratty.com/article/11258c988c75c2f65a373a3364eb6202</guid>
      <description><![CDATA[I did say that I am writing a longer blog post on that (&quot;Scary Tales from 'Compliance First' World&quot;), but I just can't resist

Yes!, Yes!! , Yes!!! - everybody smart and security-savvy KNOWS : focus...]]></description>
      <content:encoded><![CDATA[I did say that I am writing a longer blog post on that ("Scary Tales from 'Compliance First' World"), but I just can't resist.<br /><br /><span style="font-weight: bold;">Yes!, </span><span style="font-weight: bold;font-size:130%;" >Yes!!</span><span style="font-weight: bold;">, </span><span style="font-size:180%;"><span style="font-weight: bold;">Yes!!!</span> </span>- everybody smart and security-savvy <span style="font-weight: bold;">KNOWS</span>: focus on security, risk management first AND whatever <span style="font-style: italic;">compliance du jour</span> will come. "Security first" mantra works, it just works.<br /><br /><span style="font-style: italic;">But you know what?</span> I am constantly <span style="font-weight: bold;">SHOCKED </span>since I notice a volume of people who INSIST on "compliance first" AND in silo'ed, regulation by regulation way.   OMFG!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=iHexO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=iHexO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IvXHO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IvXHO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Ly8UO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Ly8UO" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/474064138" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Dec 2008 11:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/security-savvy">security-savvy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/regulation">regulation</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/scary tales">scary tales</category>
      <category domain="http://securityratty.com/tag/insist">insist</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/474064138/one-more-bit-on-compliance-first.html">One More Bit On "Compliance First"</source>
    </item>
    <item>
      <title><![CDATA[It makes good sense to just re-install]]></title>
      <link>http://securityratty.com/article/0600378a6736bed0cab395f17c9d710e</link>
      <guid>http://securityratty.com/article/0600378a6736bed0cab395f17c9d710e</guid>
      <description><![CDATA[This article offers a different approach to fighting malware infections. There is that stigma that users have with a re-install, they are not familiar with how to do it. Many dont even know if they...]]></description>
      <content:encoded><![CDATA[<div > This article offers a different approach to fighting malware infections.<br/>There is that stigma that users have with a re-install, they are not familiar with how to do it. Many dont even know if they have a restore CD that may have come with their puter when they bought it. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/32FCFB9B-7779-4D5D-A72D-4AF74CDEA753/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/76350314-72c8-431c-9bcc-ad3ab017ae8e/32FCFB9B-7779-4D5D-A72D-4AF74CDEA753/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/" href="http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/" style="font-size: 11px;">www.isyougeekedup.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/ --><H2 id="post-446"><A rel="bookmark" href="http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/">The Only Way To Permanently Remove Viruses, Spyware, and Malicious Code</A></H2></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/ --><P>If you ask any experienced and competent IT professional what to do about an infected system, they should only give you one answer: format your hard drive and reinstall your operating system.? Why skip straight to the format/reinstall and disregard the anti-virus and anti-spyware removal tools?</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/32FCFB9B-7779-4D5D-A72D-4AF74CDEA753/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_021208043534"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021208043534&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021208043534&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=021208043534&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_021208043534" /></a></P>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 13:35:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/anti-spyware removal tools">anti-spyware removal tools</category>
      <category domain="http://securityratty.com/tag/permanently remove viruses">permanently remove viruses</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://securityratty.com/tag/skip straight">skip straight</category>
      <category domain="http://securityratty.com/tag/article offers">article offers</category>
      <category domain="http://securityratty.com/tag/hard drive">hard drive</category>
      <category domain="http://securityratty.com/tag/malware infections">malware infections</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=668">It makes good sense to just re-install</source>
    </item>
    <item>
      <title><![CDATA[BlueHat SDL Sessions Wrap-up]]></title>
      <link>http://securityratty.com/article/5bc4bc363bab903a7f7f8a6245e3234d</link>
      <guid>http://securityratty.com/article/5bc4bc363bab903a7f7f8a6245e3234d</guid>
      <description><![CDATA[Hi everyone, Bryan here. The debut BlueHat SDL Sessions are over, and they were a resounding success: 96% of attendees completing evaluation surveys reported that they will be able to apply knowledge...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Hi everyone, Bryan here. The debut </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/09/25/sdl-sessions-at-bluehat.aspx"><FONT face=Calibri size=3>BlueHat SDL Sessions</FONT></A><FONT face=Calibri size=3> are over, and they were a resounding success: 96% of attendees completing evaluation surveys reported that they will be able to apply knowledge that they learned in the SDL sessions to make their products more secure. This is a great score and I’d like to thank all of our speakers and the BlueHat planning team for their hard work. As for the other 4% of attendees, we’ll just have to work that much harder next year to bring them actionable guidance for dealing with new vulnerabilities.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>As promised, we recorded all of the day’s presentations and we’ve published them on </FONT><A href="http://technet.microsoft.com/en-us/security/cc748656.aspx#day2"><FONT face=Calibri color=#0000ff size=3>TechNet</FONT></A><FONT face=Calibri size=3>:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd282968.aspx"><FONT face=Calibri color=#0000ff size=3>Keynote Address</FONT></A><FONT face=Calibri size=3> by Scott Charney, Corporate VP, Microsoft Trustworthy Computing</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd282977.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at EMC and Microsoft</FONT></A><FONT face=Calibri size=3> by Danny Dhillon of EMC and Adam Shostack of the Microsoft SDL team (of course)</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285253.aspx"><FONT face=Calibri color=#0000ff size=3>Mitigations Unplugged</FONT></A><FONT face=Calibri size=3> by Matt Miller, Microsoft Security Science team</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285262.aspx"><FONT face=Calibri color=#0000ff size=3>Concurrency Attacks on Web Applications</FONT></A><FONT face=Calibri size=3> by Scott Stender and Alex Vidergar of iSEC Partners</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285263.aspx"><FONT face=Calibri color=#0000ff size=3>Fuzzed Enough? When it’s OK to Put the Shears Down</FONT></A><FONT face=Calibri size=3> by Jason Shirk, Dave Weinstein and Lars Opstad, Microsoft Security Science team</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285265.aspx"><FONT face=Calibri color=#0000ff size=3>Real World Code Review – Using the Right Tools in the Right Place at the Right Time</FONT></A><FONT face=Calibri size=3> by Vinnie Liu of Stach &amp; Liu</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>In addition to the presentations, we also recorded some short interviews (about 10 minutes long) with each of the speakers. If you’re just looking for a quick summary of a particular talk, these interviews are the place to start:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285269.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at EMC</FONT></A><FONT face=Calibri size=3>, Danny Dhillon</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285454.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at Microsoft</FONT></A><FONT face=Calibri size=3>, Adam Shostack</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285260.aspx"><FONT face=Calibri color=#0000ff size=3>Mitigations Unplugged</FONT></A><FONT face=Calibri size=3>, Matt Miller</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285461.aspx"><FONT face=Calibri color=#0000ff size=3>Concurrency Attacks on Web Applications</FONT></A><FONT face=Calibri size=3>, Scott Stender and Alex Vidergar</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285279.aspx"><FONT face=Calibri color=#0000ff size=3>Fuzzed Enough?</FONT></A><FONT face=Calibri size=3> Jason Shirk and Dave Weinstein</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285463.aspx"><FONT face=Calibri color=#0000ff size=3>Real World Code Review</FONT></A><FONT face=Calibri size=3>, Vinnie Liu</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>I hope at least 96% of online readers will be able to directly apply this material to their products, just like the show attendees. Please post back and let us know, either way. And let us know what you’d like to see for next year. We have big plans to build on our success and make SDL Sessions 2.0 even bigger and better than the first.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9161040" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 14:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl sessions">sdl sessions</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft trustworthy">microsoft trustworthy</category>
      <category domain="http://securityratty.com/tag/microsoft sdl team">microsoft sdl team</category>
      <category domain="http://securityratty.com/tag/vinnie liu">vinnie liu</category>
      <category domain="http://securityratty.com/tag/liu">liu</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <category domain="http://securityratty.com/tag/matt miller">matt miller</category>
      <category domain="http://securityratty.com/tag/jason shirk">jason shirk</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/12/01/bluehat-sdl-sessions-wrap-up.aspx">BlueHat SDL Sessions Wrap-up</source>
    </item>
    <item>
      <title><![CDATA[Vulnerabilities and Office Versions]]></title>
      <link>http://securityratty.com/article/33580f773ea9bcdfab98d5db31b1fd04</link>
      <guid>http://securityratty.com/article/33580f773ea9bcdfab98d5db31b1fd04</guid>
      <description><![CDATA[Most of the ink on Microsoft vulnerability coverage goes to browsers and operating systems, but in a way the best progress vulnerabilities have made has been in Microsoft Office. Some of the great...]]></description>
      <content:encoded><![CDATA[Most of the ink on Microsoft vulnerability coverage goes to browsers and operating systems, but in a way the best progress vulnerabilities have made has been in Microsoft Office. Some of the great attacks of all time (remember LoveLetter?) have been through Office bugs, and I believe most targeted attacks over the last few years have utilized vulnerabilities in Office document parsers.

That's why it's encouraging that Microsoft has done a much better job in making current versions of Office secure, as <a href="http://blogs.msdn.com/david_leblanc/archive/2008/11/17/improvements-in-office-security.aspx">David LeBlanc's recent blog shows</a>. He claims that the company has really stepped up the security testing for Office 2003 SP3 and Office 2007, and that it shows up in the number of reported vulnerabilities. The trend is clear: There are about half as many vulnerabilities as for earlier versions.

There may be a little flaw in the analysis in that LeBlanc studied reports during the period from 9/18/2007 to 11/17/2008. By that time earlier Office versions had been around for a long time and many vulnerabilities had already been reported on them. But even so, it makes the numbers all the more impressive for the new versions; the older ones had already had the low-hanging fruit picked clean and yet they still had CVE numbers in excess of the new ones. It seems there is no low-hanging vulnerability fruit in new versions of Office.

Are you running an old version of Office? Are you running Office 2003 SP2, which <a href="http://blogs.eweek.com/cheap_hack/content/office/office_2003_sp2_approaching_end_of_life.html">reached the end of support life in October</a>? If so, you are exposing yourself to more known threats than you may think.

Office versions are not plug-and-play interchangeable. It's unfortunate that Microsoft saw fit to accompany Office 2007's security enhancements with a radical user interface change. I personally have gotten used to it, but I can see an enterprise being intimidated by the training it would necessitate.

If you feel you're stuck in Office 2003, at the very least it's irresponsible to linger on in an old service pack. Do what you can to move on to SP3.
<p><a href="http://feedads.googleadservices.com/~at/4uM3tOE5mU12QfUHAZpBRMt2y_E/a"><img src="http://feedads.googleadservices.com/~at/4uM3tOE5mU12QfUHAZpBRMt2y_E/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/cnC-qNVdwk4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 04:19:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/office versions">office versions</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <category domain="http://securityratty.com/tag/microsoft office">microsoft office</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <category domain="http://securityratty.com/tag/office secure">office secure</category>
      <category domain="http://securityratty.com/tag/office bugs">office bugs</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/office document parsers">office document parsers</category>
      <category domain="http://securityratty.com/tag/accompany office">accompany office</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/cnC-qNVdwk4/vulnerabilities_and_office_versions.html">Vulnerabilities and Office Versions</source>
    </item>
    <item>
      <title><![CDATA[Tips for staying safe online this Holiday season]]></title>
      <link>http://securityratty.com/article/4601cb0e0df5f980983616dff3fecc59</link>
      <guid>http://securityratty.com/article/4601cb0e0df5f980983616dff3fecc59</guid>
      <description><![CDATA[Great article by Mr Walling. Take the time read the tips and maybe you wont become a statistic this season


clipped from www.marketwatch.com

Walling Datas Top Ten Safety Tips for Online Shopping


...]]></description>
      <content:encoded><![CDATA[<div > Great article by Mr Walling.<br/>Take the time read the tips and maybe you wont become a statistic this season </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/5CC9381E-01B3-4581-A29F-B6C7D9C85A8E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/a9a2ac45-d36e-42ed-8102-6fd92fd5847c/5CC9381E-01B3-4581-A29F-B6C7D9C85A8E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D" href="http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D" style="font-size: 11px;">www.marketwatch.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Walling Data&#8217;s Top Ten Safety Tips for Online Shopping</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D --><DIV class="p"><br />
            &#8220;The Internet is safe if you follow basic, fundamental rules of<br />
      using a computer safely,&#8221; says Luke Walling, Founder and President of Walling<br />
      Data, one of the largest distributors of online security products in<br />
      the country. &#8220;Many people think of their computer much like<br />
      they would an appliance, such as a microwave or stereo that behaves in a<br />
      predictable pre-programmed way. But, in reality computers<br />
      are dynamic devices that evolve dramatically with the installation of<br />
      each new program. It&#8217;s important to remember that viruses<br />
      and spyware are programs as well.&#8221;<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/5CC9381E-01B3-4581-A29F-B6C7D9C85A8E/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_281108043701"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043701&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043701&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043701&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_281108043701" /></a></P>]]></content:encoded>
      <pubDate>Fri, 28 Nov 2008 13:37:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/tips">tips</category>
      <category domain="http://securityratty.com/tag/online security products">online security products</category>
      <category domain="http://securityratty.com/tag/computer safely">computer safely</category>
      <category domain="http://securityratty.com/tag/safety tips">safety tips</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/dynamic devices">dynamic devices</category>
      <category domain="http://securityratty.com/tag/datas top">datas top</category>
      <category domain="http://securityratty.com/tag/safe">safe</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=665">Tips for staying safe online this Holiday season</source>
    </item>
    <item>
      <title><![CDATA[Forensic genomics]]></title>
      <link>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</link>
      <guid>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</guid>
      <description><![CDATA[I recently presented a paper on Forensic genomics: kin privacy, driftnets and other open questions (co-authored with Lucia Bianchi, Pietro Liò and Douwe Korff ) at WPES 2008 , the Workshop for...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cl.cam.ac.uk/~fms27/">I</a> recently presented a paper on <a href="http://www.cl.cam.ac.uk/~fms27/papers/2008-StajanoBiaLioKor-genomics.pdf"><em>Forensic genomics: kin privacy, driftnets and other open questions</em></a> (co-authored with Lucia Bianchi, <a href="http://www.cl.cam.ac.uk/~pl219/">Pietro Liò</a> and <a href="http://www.londonmet.ac.uk/research-units/hrsj/staff/douwe-korff.cfm">Douwe Korff</a>) at <a href="http://dais.cs.uiuc.edu/wpes08/">WPES 2008</a>, the Workshop for Privacy in the Electronic Society of <a href="http://www.sigsac.org/ccs/CCS2008/">ACM CCS</a>, the ACM Computer and Communication Security</a> conference. Pietro and I also gave a <a href="http://talks.cam.ac.uk/talk/index/13300">related talk</a> here at the Computer Laboratory in Cambridge.</p>
<p>While <a href="http://en.wikipedia.org/wiki/Genetics">genetics</a> is concerned with the observation of specific sections of DNA, genomics is about studying the entire <a href="http://en.wikipedia.org/wiki/Genome">genome </a> of an organism, something that has only become practically possible in recent years. In forensic genetics, which is the technology behind the large national DNA databases being built in several countries including notably UK and USA (<a href="http://www.nature.com/embor/journal/v7/n1s/pdf/7400727.pdf">Wallace&#8217;s outstanding article</a> lucidly exposes many significant issues), investigators compare scene-of-crime samples with database samples by checking if they match, but only on a very small number of specific locations in the genome (e.g. 13 locations according to the <a href="http://en.wikipedia.org/wiki/Codis">CODIS</a> rules). In our paper we explore what might change when forensic analysis moves from genetics to genomics over the next few decades. This is a problem that can only be meaningfully approached from a multi-disciplinary viewpoint and indeed our combined backgrounds cover computer security, bioinformatics and law.</p>
<p><img src="http://upload.wikimedia.org/wikipedia/commons/7/7a/Codis_profile.jpg" alt="CODIS markers" /><em><br />
(Image from <a href="http://en.wikipedia.org/wiki/Image:Codis_profile.jpg">Wikimedia commons</a>, in turn from <a href="http://www.cstl.nist.gov/div831/strbase/fbicore.htm">NIST</a>.)</em></p>
<p>Sequencing the first human genome (2003) cost 2.7 billion dollars and took 13 years. The US&#8217;s National Human Genome Research Institute has <a href="http://www.medicalnewstoday.com/articles/118963.php">offered over 20 M$ worth of grants</a> towards the goal of <a href="http://www.genome.gov/27527584">driving the cost of whole-genome sequencing down to a thousand dollars</a>. This will enable <a href="http://en.wikipedia.org/wiki/Personal_genomics">personalized genomic medicine</a> (e.g. predicting genetic risk of contracting specific diseases) but will also open up a number of ethical and privacy-related problems. Eugenetic abortions, genomic pre-screening as precondition for healthcare (or even just dating&#8230;), (mis)use of genomic data for purposes other than that for which it was collected and so forth. In various jurisdictions there exists legislation (such as the recent <a href="http://www.govtrack.us/congress/billtext.xpd?bill=h110-493&amp;show-changes=0&amp;page-command=print">GINA</a> in the US) that attempts to protect citizens from some of the possible abuses; but how strongly is it enforced? And is it enough? In the forensic context, is the DNA analysis procedure as infallible as we are led to believe? There are many subtleties associated with the interpretation of statistical results; when even professional statisticians disagree, how are the poor jurors expected to reach a fair verdict? Another subtle issue is kin privacy: if the scene-of-crime sample, compared with everyone in the database, partially matches Alice, this may be used as a hint to investigate all her relatives, who aren&#8217;t even in the database; indeed, some 1980s murders were recently solved in this way. &#8220;This raises compelling policy questions about the balance between collective security and individual privacy&#8221; [<a href="http://www.sciencemag.org/cgi/content/full/sci;312/5778/1315">Bieber, Brenner, Lazer, 2006</a>]. Should a democracy allow such a &#8220;driftnet&#8221; approach of suspecting and investigating all the innocents in order to catch the guilty?</p>
<p>This is a paper of questions rather than one of solutions. We believe an informed public debate is needed <em>before</em> the expected transition from genetics to genomics takes place. We want to stimulate discussion and therefore we invite you to read the paper, make up your mind and support what you believe are the right answers.</p>
]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 12:58:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/genomics">genomics</category>
      <category domain="http://securityratty.com/tag/forensic genomics">forensic genomics</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/individual privacy">individual privacy</category>
      <category domain="http://securityratty.com/tag/dna">dna</category>
      <category domain="http://securityratty.com/tag/national dna databases">national dna databases</category>
      <category domain="http://securityratty.com/tag/genome">genome</category>
      <category domain="http://securityratty.com/tag/whole-genome">whole-genome</category>
      <category domain="http://securityratty.com/tag/kin privacy">kin privacy</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/27/forensic-genomics/">Forensic genomics</source>
    </item>
    <item>
      <title><![CDATA[New DHS Head Understands Security]]></title>
      <link>http://securityratty.com/article/575cb97ea046ccf013e7674856572469</link>
      <guid>http://securityratty.com/article/575cb97ea046ccf013e7674856572469</guid>
      <description><![CDATA[This quote impresses me: Gov. Janet Napolitano, D-Ariz., is smashing the idea of a border wall, stating it would be too expensive, take too long to construct, and be ineffective once completed
You...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.worldnetdaily.com/news/article.asp?ARTICLE_ID=48017">This quote</a> impresses me:</p>

<blockquote>Gov. Janet Napolitano, D-Ariz., is smashing the idea of a border wall, stating it would be too expensive, take too long to construct, and be ineffective once completed.

<p>"You show me a 50-foot wall and I'll show you a 51-foot ladder at the border. That's the way the border works," Napolitano told the Associated Press.</p>

<p>Instead of a wall, she said funds would be better utilized on beefing up Border Patrol manpower, technology sensors and unmanned aerial vehicles.</blockquote></p>

<p>I am cautiously optimistic.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=bndCN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=bndCN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=yBMYN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=yBMYN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 09:43:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/border">border</category>
      <category domain="http://securityratty.com/tag/border patrol manpower">border patrol manpower</category>
      <category domain="http://securityratty.com/tag/border wall">border wall</category>
      <category domain="http://securityratty.com/tag/wall">wall</category>
      <category domain="http://securityratty.com/tag/50-foot wall">50-foot wall</category>
      <category domain="http://securityratty.com/tag/janet napolitano">janet napolitano</category>
      <category domain="http://securityratty.com/tag/napolitano">napolitano</category>
      <category domain="http://securityratty.com/tag/technology sensors">technology sensors</category>
      <category domain="http://securityratty.com/tag/cautiously optimistic">cautiously optimistic</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/new_dhs_head_un.html">New DHS Head Understands Security</source>
    </item>
    <item>
      <title><![CDATA[A Review of EM7]]></title>
      <link>http://securityratty.com/article/7c2d378fa923b40a0fe3059fab4258a1</link>
      <guid>http://securityratty.com/article/7c2d378fa923b40a0fe3059fab4258a1</guid>
      <description><![CDATA[Were very happy to have had EM7 reviewed by The Tech Stop . We originally met Fr. Robert Ballecer SJ at Interop Las Vegas 2008. Padre (as everyone knows him) was one of the networking team leads at...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;re very happy to have had EM7 reviewed by <a href="http://www.thetechstop.net/?page_id=975" target="_blank">The Tech Stop</a>.  We originally met Fr. Robert Ballecer SJ at Interop Las Vegas 2008.  Padre (as everyone knows him) was one of the networking team leads at Interop and got hands on experience with EM7 in the NOC at the show.  As far as we&#8217;re concerned Interop was the best way to review EM7.  While working with a product in a lab gets you a reasonable idea of how it works, using the product in a high pressure, real world environment like Interop, really shows you what a product can do.  We&#8217;d like to thank Padre for taking the time to do such a complete review of EM7 and look forward to hopefully working with him again during Interop 2009.</p>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 14:39:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/review em7">review em7</category>
      <category domain="http://securityratty.com/tag/real world environment">real world environment</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/complete review">complete review</category>
      <category domain="http://securityratty.com/tag/robert ballecer">robert ballecer</category>
      <category domain="http://securityratty.com/tag/reasonable idea">reasonable idea</category>
      <source url="http://blog.sciencelogic.com/a-review-of-em7/11/2008">A Review of EM7</source>
    </item>
    <item>
      <title><![CDATA[Blurring the Lines Between Managed Service Provider and Cloud Computing]]></title>
      <link>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</link>
      <guid>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</guid>
      <description><![CDATA[VMware made big announcements at their VMworld conference back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the...]]></description>
      <content:encoded><![CDATA[<p>VMware made big announcements at their <a href="http://www.vmworld.com/index.jspa" target="_blank">VMworld conference</a> back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the “cloud” with vCloud services. Like most people, I had a lot of skepticism about what vCloud really meant; was this just more hype trying to take advantage of the cloud computing buzz? Certainly CEO Paul Maritz came from this world and virtualization itself (and especially vMotion) is an enabling technology for cloud computing. But how ready were VMware and its ecosystem of partner vendors to actually fulfill on the promise?</p>
<p>So I was very interested when I heard that <a href="http://opusinteractive.com/" target="_blank">Opus Interactive</a>, a customer of ours, had “joined the VMware vCloud initiative as a <a href="http://www.opusinteractive.com/news_detail.asp?item=40" target="_blank">VMware Service Provider</a>”. I talked to Eric Hulbert, CTO of Opus Interactive, to get some details directly from the source.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0025.jpg" border="0" alt="clip_image002" width="202" height="74" align="left" /></p>
<p>Eric shared our own caution about making “cloud-ready” announcements. There have simply been too many companies talking about cloud solutions that lack any substance – usually based on definitions of cloud computing that are hazy or just too broad. The backlash against the cloud hype is often quite justified. But in Opus’ case, there are real components that if they don’t add up to a “full” cloud computing solution just yet, are well on their way – and enabled by <a href="http://www.vmware.com/partners/vip/service-providers/" target="_blank">VMware’s program for service providers</a> (VSPP).</p>
<p>Opus Interactive is <a href="http://www.viddler.com/explore/sciencelogic/videos/3" target="_blank">serious about virtualization</a>, which is an indispensable tool in their stated goal of creating a high-density micro-data center with the smallest footprint possible. They are 100% wind-powered and have already virtualized much of their data center, reducing the amount of hardware necessary to run the business and driving down costs to produce even more competitive advantage in a crowded marketplace.</p>
<p>VSPP for vCloud provides a rental model of VMware licenses – e.g., for Enterprise ESX or VDI. VMware Service Providers report on their customers’ virtual machines (vm) and pay only for what is actually used. This model lets Opus Interactive quickly spin up a vm to get a new customer up and running in about an hour and stay very cost competitive at the same time; Opus offers their <a href="http://opusinteractive.com/vClustr.asp" target="_blank">vClustr entry-level virtual server</a> for only $99.</p>
<p>Cost-effective, rapidly scalable computing “on-demand” based on shared resources, managed by “expert” third-parties, enabled by virtualization technology and pay-per-use vm licenses. Cloud computing? Instead of thinking about a single definition of cloud computing, perhaps it’s more relevant as the market matures to think about a continuum of cloud computing. And by that definition, Opus Interactive is providing cloud services, enabled by VMware’s VSP program. Next on the schedule, automated provisioning and perhaps in the future, API’s that make it even easier for application developers to test and deploy apps on Opus Interactive’s cloud platform – which, by the way, uses <a href="http://www.sciencelogic.com/products.htm" target="_blank">EM7</a> for its core management solution.</p>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 11:20:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud hype">cloud hype</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/cloud-ready announcements">cloud-ready announcements</category>
      <category domain="http://securityratty.com/tag/cloud solutions">cloud solutions</category>
      <category domain="http://securityratty.com/tag/announcements">announcements</category>
      <category domain="http://securityratty.com/tag/vmware vcloud initiative">vmware vcloud initiative</category>
      <category domain="http://securityratty.com/tag/ready">ready</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <source url="http://blog.sciencelogic.com/blurring-the-lines-between-managed-service-provider-and-cloud-computing/11/2008">Blurring the Lines Between Managed Service Provider and Cloud Computing</source>
    </item>
  </channel>
</rss>
