<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: exam]]></title>
    <link>http://www.securityratty.com/tag/exam</link>
    <description></description>
    <pubDate>Mon, 07 Apr 2008 00:22:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[MSDN Security Issue Articles]]></title>
      <link>http://www.securityratty.com/article/1074b3008b822d4dbf799e92676f81a1</link>
      <guid>http://www.securityratty.com/article/1074b3008b822d4dbf799e92676f81a1</guid>
      <description><![CDATA[Bryan here. The SDL team is well represented in the annual security issue of MSDN magazine we have three articles that might be interesting to you, given that you read the SDL Blog
First up is a code...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Bryan here. The SDL team is well represented in the annual security issue of MSDN magazine – we have three articles that might be interesting to you, given that you read the SDL Blog!</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>First up is a code review quiz, “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/cc982154.aspx"><FONT face=Calibri size=3>Test Your Security IQ</FONT></A><FONT face=Calibri size=3>”. Put your C/C++/C# security skills to the challenge by reviewing ten tricky code snippets that Michael and I devised. As an added incentive, I’ll post public congratulations here in the SDL blog to the first person who reverses the insecure hash found somewhere in the exam (not to give too much of a hint).</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Next up, we have “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/dd153756.aspx"><FONT face=Calibri size=3>Agile SDL: Streamline Security Practices for Agile Development</FONT></A><FONT face=Calibri size=3>”. I’ve been talking about web application security issues in the SDL blog (and in the </FONT><A href="http://msdn.microsoft.com/en-us/magazine/cc794277.aspx"><FONT face=Calibri size=3>September</FONT></A><FONT face=Calibri size=3> issue of MSDN magazine, if you missed it). However, while it’s essential to make sure that web-specific issues are covered in the SDL, it’s equally important to make sure that web development teams – and other Agile development teams – can use the SDL effectively, and the classic, phased SDL approach is not always a good fit for these teams. This MSDN article is the first public look at the new SDL/Agile methodology that we’ve been working on for the last year. This process is currently in beta with some internal Microsoft product teams and online services. We’d love to get some external feedback on it before we release it to the entire company, so please send us your thoughts.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Finally, be sure to check out Michael’s Security Briefs column “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/dd148644.aspx"><FONT face=Calibri size=3>Threat Models Improve Your Security Process</FONT></A><FONT face=Calibri size=3>”. Regular readers of this blog know how important threat modeling is to secure development. This article describes methods of using threat modeling not just to identify security vulnerabilities outright, but how to use it to make other SDL activities such as fuzzing and reducing attack surface more effective.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Three articles are more than enough for one team for one month! But be on the lookout for more articles from the usual SDL suspects in the near future. As always, keep watching this space for details.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9067921" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 20:58:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/sdl">sdl</category>
      <category domain="http://www.securityratty.com/tag/usual sdl suspects">usual sdl suspects</category>
      <category domain="http://www.securityratty.com/tag/sdl approach">sdl approach</category>
      <category domain="http://www.securityratty.com/tag/annual security issue">annual security issue</category>
      <category domain="http://www.securityratty.com/tag/agile sdl">agile sdl</category>
      <category domain="http://www.securityratty.com/tag/sdl activities">sdl activities</category>
      <category domain="http://www.securityratty.com/tag/security process">security process</category>
      <category domain="http://www.securityratty.com/tag/sdl team">sdl team</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/11/13/msdn-security-issue-articles.aspx">MSDN Security Issue Articles</source>
    </item>
    <item>
      <title><![CDATA[(ISC)2s Newest Cash Cow: The CSSLP Certification]]></title>
      <link>http://www.securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</link>
      <guid>http://www.securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</guid>
      <description><![CDATA[Earlier this week, during the OWASP AppSec 2008 Conference , the people behind the ubiquitous CISSP certification announced their latest creation the Certified Software Security Lifecycle Professional...]]></description>
      <content:encoded><![CDATA[<p>Earlier this week, during the <a href="http://www.owasp.org/index.php?title=OWASP_NYC_AppSec_2008_Conference">OWASP AppSec 2008 Conference</a>, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the <a href="http://isc2.org/csslp">Certified Software Security Lifecycle Professional</a> (CSSLP).  In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the <a href="http://blog.isc2.org/isc2_blog/tipton/index.html">Executive Director of (ISC)2</a> outlined this new certification designed to appeal to application security professionals.  To his credit, Mr. Tipton stated very clearly that the CSSLP is not intended to measure one&#8217;s technical skillset.  Unfortunately, it&#8217;s inevitable that employers will treat it as such.</p>
<p>You can read all the details on their website (except for the part about the certification not being a measure of practical skills).  From what I can tell, the CSSLP is just the CISSP with different CBKs, or Common Bodies of Knowledge.  As with the CISSP, they are going for broad knowledge, not depth.  Starting in June 2009, you can get certified by taking a paper exam, likely a multiple choice test similar to the CISSP.  Why June?  Because the test isn&#8217;t even written yet &#8212; I&#8217;ve heard from several sources that they are actively soliciting their existing pool of CISSPs to help write test questions.</p>
<p>Ah, but what if you can&#8217;t wait that long and want to get certified <i>right away</i>?  You&#8217;re in luck. If you act before March 31, 2009, you can get grandfathered in without even having to take the exam!  That&#8217;s right, they call it the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1691">CSSLP Experience Assessment</a>, and here are the requirements:</p>
<div style="float:right; margin-left: 15px"><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money-191x300.jpg" alt="" title="101-hand_with_money" width="191" height="300" class="alignright size-medium wp-image-372 photoborder" /></a></div>
<ul>
<li>Upload a resume showing three years of experience related to software security, or four years if you don&#8217;t have a college degree</li>
<li>Write short essays (500 words maximum) discussing four CBKs of your choice</li>
<li>Get a CISSP to vouch for you</li>
<li>Pay $650</li>
<p>
</ul>
<p>Let&#8217;s examine these requirements one at a time.</p>
<p><b>Three years of experience</b>.  (ISC)2 doesn&#8217;t provide any requirements on depth of experience, other than citing the broadly-defined CBKs.  Considering they are targeting everyone from software developers to security assessors to business analysts (yes, really), chances are they are going to accept any experience that is even tangential to the SDLC or software security.</p>
<p><b>Short essays on four of the CBKs</b>.  I asked the (ISC)2 exhibitors specifically what they are looking for to satisfy this requirement, and they said the essays should be a general discussion of the CBK topic, <i>optionally</i> citing your personal experience in that area if you have any.  This messaging is not quite aligned with the website guidance, which states that the essays should be &#8220;Accomplishment Records&#8221; which are self-reported descriptions of experience.  Either way, with a maximum essay length of 500 words, it&#8217;s pretty obvious that substance is not (ISC)2&#8217;s first priority.  Here&#8217;s one data point for you: I spoke to someone who has already submitted the CSSLP Experience Assessment, and he said it took about an hour to write the essays.</p>
<p><b>Get a CISSP to vouch for you</b>.  Actually this can be any (ISC)2 certified person, not just CISSPs.  Contrary to what you&#8217;d expect, though, the person isn&#8217;t vouching for your skillset so much as they are confirming that the attestations on your resume are accurate.</p>
<p><b>Pay $650</b>.  You knew it was coming.  After all, there is money to be made.  How is it that qualifying for the CSSLP through professional experience should cost $650?  If you&#8217;re taking the written exam, fair enough, (ISC)2 does incur the cost of administering and grading that exam (even though the <a href="http://www.scantron.com/datacollection/scanners.aspx">Scantron machine</a> is probably paid off by now).  But $650 for the submitted-online Experience Assessment?  If we assume that the person reading these essay submissions makes a rather generous $100k per year, then $650 accounts for roughly a day and a half.  Will it really take that long to read a <i>maximum</i> of 2,000 words and pass judgment?  Of course not.  (ISC)2 wants to get as many people as possible to qualify based on &#8220;experience&#8221;, seeding the initial pool of CSSLPs and netting them $650 per head for doing next to nothing.</p>
<p>As <a href="http://www.ljkushner.com/about_mstr.html">Lee Kushner</a> stated during his OWASP AppSec presentation (<i>7 Habits of Highly Effective Career Managers</i>), &#8220;the more people who own a cert, the less relevant it becomes.&#8221;  Irrelevant &#8212; that&#8217;s exactly what the CISSP has become, and it&#8217;s exactly where the CSSLP is headed.  Meanwhile, (ISC)2 will sit back and watch while you and your employers continue to fill their coffers.</p>
<p>In closing, let me acknowledge that this blog entry probably comes across as judgmental.  I accept that.  I&#8217;m not ranting against the idea of certifications, though admittedly <a href="http://www.veracode.com/blog/2008/04/not-a-cissp/">I&#8217;m not a fan of them either</a>.  I am disappointed that (ISC)2, an organization with tremendous influence, could have created something more meaningful but chose not to. Why bother when people will just fork over the cash anyway?</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 11:08:38 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/csslp">csslp</category>
      <category domain="http://www.securityratty.com/tag/csslp experience assessment">csslp experience assessment</category>
      <category domain="http://www.securityratty.com/tag/experience assessment">experience assessment</category>
      <category domain="http://www.securityratty.com/tag/certification">certification</category>
      <category domain="http://www.securityratty.com/tag/experience">experience</category>
      <category domain="http://www.securityratty.com/tag/isc">isc</category>
      <category domain="http://www.securityratty.com/tag/personal experience">personal experience</category>
      <category domain="http://www.securityratty.com/tag/ubiquitous cissp certification">ubiquitous cissp certification</category>
      <category domain="http://www.securityratty.com/tag/cissp">cissp</category>
      <source url="http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/">(ISC)2s Newest Cash Cow: The CSSLP Certification</source>
    </item>
    <item>
      <title><![CDATA[CISA and CISSP Preparation]]></title>
      <link>http://www.securityratty.com/article/4990229406d5e949151cc28d8d8799b9</link>
      <guid>http://www.securityratty.com/article/4990229406d5e949151cc28d8d8799b9</guid>
      <description><![CDATA[Recently I have received a number of questions seeking preparation tips and insights for the CISA and CISSP certifications. I hold both of these certifications, and passed them both on the first...]]></description>
      <content:encoded><![CDATA[<p>Recently I have received a number of questions seeking preparation tips and insights for the CISA and CISSP certifications. I hold both of these certifications, and passed them both on the first attempt using very different preparation approaches. I took the CISA first, and based on a few lessons learned, I radically changed my preparation plan for the CISSP.<br />
<br />
FYI, the official preparation information, qualification requirements, exam requirements, etc. can be found at:</p>
<ul>
<li>Certified Information Systems Auditor (CISA) : <a href="http://www.isaca.org/cisa/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.isaca.org/cisa/');" target="_blank">http://www.isaca.org/cisa/</a></li>
<li>Certified Information Systems Security Professional : <a href="https://www.isc2.org/cissp" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://www.isc2.org/cissp');">https://www.isc2.org/cissp</a></li>
</ul>
<p><strong>Are You Ready ?</strong><br />
A few basic questions to ask yourself to gauge how ready you are:</p>
<ul>
<li>Do I meet the spirit, and not just the letter, of the experience requirements ?</li>
<li>Has there been sufficient diversity in my experience ?</li>
</ul>
<p></p>
<div>Both of these exams cover a very broad spectrum of subjects. It is my personal belief that the experience requirements exist as an aid to whittle test takers down to candidates who have the professional experiences required to be successful, and to discourage people from taking the exams before they are ready. If you truly meet the background requirements, then you should have had some contact with many of the core topic areas for the exam.</div>
<p></p>
<div>If you are looking at the core content of the examination, and do not believe that you really have the breadth of exposure to be able to describe and discuss each domain at a high level, then you may be better served by delaying the exam in favor of working with your management to gain broader professional experience.</div>
<p><strong>Five Step Approach to CISA or CISSP Exam Preparation</strong></p>
<ol>
<li>Perform an initial benchmark and assessment of your readiness</li>
<li>Read a &#8220;survey&#8221; level preparation guide cover to cover</li>
<li>Perform a secondary benchmark, and compare your readiness</li>
<li>Review official, or &#8220;deep dive&#8221;, preparation materials on areas identified as your weaknesses</li>
<li>Re-benchmark, and repeat targeted reviews until ready</li>
</ol>
<p></p>
<div>For the first certification that I prepared for, I did not perform the first three steps outlined above. I went directly to the official source materials and began trying to review them cover to cover. I passed the exam, but I also spent a lot of time &amp; energy reviewing things that I already knew &#8220;well enough&#8221;, and was burned out when reviewing the areas which could have been richer learning opportunities. No matter what your professional background, no one knows-it-all or does-it-all, so there is always  an opportunity to learn new things while you are preparing for the certification exam. The goal of this five step approach is to focus your time where you have the greatest learning opportunities. Hopefully this focuses your time and energy in the most rewarding way.</div>
<p></p>
<div><strong>Performing the Benchmarks</strong></div>
<div>For the Benchmarks, I like to complete a timed half-length or full-length examination.</div>
<p></p>
<div>It is my feeling that a half-length exam is long enough that fatigue, maintaining focus, and pace are all stressed, as they will be on examination day. This of course requires access to a large set of test questions or sample tests, preferably with explanations of incorrect answers. In addition to commercial third-party test preparation tools, there are good (and free) test preparation quizzes available from <a href="http://www.cccure.org/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.cccure.org/');">www.cccure.org</a>.</div>
<p></p>
<div><strong>Survey Materials</strong></div>
<div>I find the &#8220;Exam Cram&#8221; series to be very useful survey literature. I purchase books from this series when I want a high-level and quick handling of an entire subject matter area. As a result, I own survey books from the series in topic areas which I have no intention of pursuing certification for. Obviously the books I recommend for these certifications are:</div>
<p><a href="http://www.amazon.com/gp/product/078973446X?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=078973446X" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/078973446X?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=078973446X');"><img src="http://artofinfosec.com/wp-content/uploads/cissp_exam_cram.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=078973446X" border="0" alt="" width="1" height="1" /> <a href="http://www.amazon.com/gp/product/0789732726?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0789732726" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/0789732726?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0789732726');"><img src="http://artofinfosec.com/wp-content/uploads/cisa_exam_cram.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=0789732726" border="0" alt="" width="1" height="1" /></p>
<div><strong>Deep Dive Materials</strong></div>
<div>There are exam preparation materials available from a variety of sources that fit the bill in this area. What we are looking for are books that contain solid coverage of the areas where benchmarking has shown the most significant need for improvement. In addition to the materials from (ISC)2 and ISACA that I list below, consult your local library - often they will have books that fit the bill. (And, of course, consider arranging a donation of good materials if they do not.)</div>
<p><a href="http://www.amazon.com/gp/product/0849382319?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0849382319" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/0849382319?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=0849382319');"><img src="http://artofinfosec.com/wp-content/uploads/official_cissp.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=0849382319" border="0" alt="" width="1" height="1" /> <a href="http://www.amazon.com/gp/product/1933284935?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1933284935" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.amazon.com/gp/product/1933284935?ie=UTF8&amp;tag=artofinfosecu-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1933284935');"><img src="http://artofinfosec.com/wp-content/uploads/cisa_review_2008.jpg" border="0" alt="" /></a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=artofinfosecu-20&amp;l=as2&amp;o=1&amp;a=1933284935" border="0" alt="" width="1" height="1" /></p>
<div><strong>Final Thoughts</strong></div>
<div>Good luck on your journey toward Information Security or Audit certification. One word of caution: Make sure that you have realistic expectations about what actually being certified will mean. Although I do think being certified helps a person establish credibility more quickly, and is helpful when searching for new employment, often people are underwhelmed by the &#8220;Congratulations, that&#8217;s nice&#8221; from their current employer. If your expectation is that a big raise, bonus, promotion, etc. is hinging on your being certified, then I would strongly encourage you to reality-check that with peers in your organization.</div>
<p></p>
<div>Cheers, Erik</div>
<p></p>
<p><a href="http://artofinfosec.com/60/cisa-and-cissp-preparation/" >CISA and CISSP Preparation</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/351541992" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 09:14:07 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/exam">exam</category>
      <category domain="http://www.securityratty.com/tag/exam requirements">exam requirements</category>
      <category domain="http://www.securityratty.com/tag/cissp exam preparation">cissp exam preparation</category>
      <category domain="http://www.securityratty.com/tag/half-length exam">half-length exam</category>
      <category domain="http://www.securityratty.com/tag/exam cram series">exam cram series</category>
      <category domain="http://www.securityratty.com/tag/certification exam">certification exam</category>
      <category domain="http://www.securityratty.com/tag/exam preparation materials">exam preparation materials</category>
      <category domain="http://www.securityratty.com/tag/preparation materials">preparation materials</category>
      <category domain="http://www.securityratty.com/tag/cissp">cissp</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/351541992/">CISA and CISSP Preparation</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://www.securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</link>
      <guid>http://www.securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 13:20:45 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/voip">voip</category>
      <category domain="http://www.securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://www.securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://www.securityratty.com/tag/voip news">voip news</category>
      <category domain="http://www.securityratty.com/tag/voip security">voip security</category>
      <category domain="http://www.securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://www.securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://www.securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://www.securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://www.blueboxpodcast.com/2008/07/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://www.securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</link>
      <guid>http://www.securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=fNSqdO"><img src="http://feeds.feedburner.com/~a/BlueBox?i=fNSqdO" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=lbjc2J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lbjc2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=7bk2TJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7bk2TJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=3wwMDJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=3wwMDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=sD0qZJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=sD0qZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Y7dDJj"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Y7dDJj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uKgX6J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uKgX6J" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/336458984" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 12:22:35 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/voip">voip</category>
      <category domain="http://www.securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://www.securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://www.securityratty.com/tag/voip news">voip news</category>
      <category domain="http://www.securityratty.com/tag/voip security">voip security</category>
      <category domain="http://www.securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://www.securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://www.securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://www.securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/336458984/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[SDL Training]]></title>
      <link>http://www.securityratty.com/article/36095f95c3adf54cf7cabefc378acfcb</link>
      <guid>http://www.securityratty.com/article/36095f95c3adf54cf7cabefc378acfcb</guid>
      <description><![CDATA[Hi everyone, Shawn Hernan here. Being a security guy is incredibly rewarding because you get to look at virtually any part of a product, from kernel drivers to web services to user education to sales...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Hi everyone, Shawn Hernan here. Being a security guy is incredibly rewarding because you get to look at virtually any part of a product, from kernel drivers to web services to user education to sales and servicing. You have to do that because a failure in one of those areas can endanger the security of our customers. Microsoft’s SDL process reflects that reality. The process is structured so that you really do have to look at each piece before you can sign off. But sometimes when others want to emulate the success of the SDL, they want to skip steps. They try to boil the SDL down into its component parts, like training, or tooling, or security response. Maybe the most common form of that mistake is training, but you see that same thinking applied to code scanning, security response, and just about every phase of the SDL. “<I style="mso-bidi-font-style: normal">Let’s just train everyone, and all our security problems will go away</I>.” If only it were so easy. I’d like to take a few minutes to try to explain why it’s not really that easy from my own experience. </FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>Have you ever sat in a corporate training? Some are good, some are bad, but did you ever say, “man I can’t <I>wait</I> for training today.” What about mandatory training? What about mandatory training in a subject that you really don’t think is your area? What if you had to do it every year, and got harassed if you didn’t do it? What if you were, say, an audio engineer and were dragged into a security class? <?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>I ran the SDL training program at Microsoft for a long time, and developed and taught a big chunk of the training. I spent hundreds of hours in front of thousands of developers, testers, and program managers. <SPAN style="mso-bidi-font-style: italic">I got some really good reviews (and a few bad ones) on the classes I offered. And I tried to do a lot of things to try to make the trainings interesting. I handed out dozens of fresh peaches in an early class on fuzz testing, for example.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The room smelled really nice after that, and there are probably still a few people around Microsoft who think of fuzz testing when they see a peach. </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>But even on my best day, I was under no illusion that the majority of the audience was excited to be there, and I was certain that they weren’t going to go back to their offices and spend weeks applying the lessons from the class, setting aside <I>other </I>things that are causing present and immediate problems in favor of something that is far off into the future. <o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><SPAN style="mso-bidi-font-style: italic"><FONT face=Calibri>You have to work at getting people’s attention – especially as it relates to security and privacy. From time to time, I would see people reading their mail in class, and I would point to them and ask them a question. That did not endear me to the audience as much as the peaches, but embarrassment is always fresh and in season.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></SPAN><SPAN style="FONT-FAMILY: Wingdings; mso-bidi-font-style: italic; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-char-type: symbol; mso-symbol-font-family: Wingdings"><SPAN style="mso-char-type: symbol; mso-symbol-font-family: Wingdings">J</SPAN></SPAN><SPAN style="mso-bidi-font-style: italic"><FONT face=Calibri> <o:p></o:p></FONT></SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>One student wrote of one of my classes, “<I>the basics for secure design - could be replaced by non-anonymous site-wide exam with open material.” </I><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>He was not alone, I assure you. <o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Is that an indication that our training, or any training, is pointless? Hardly, but training alone is not a change agent.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-bidi-font-style: italic"><FONT face=Calibri size=3>Richard Derwent Cooke </FONT></SPAN><A href="http://www.changingminds.org/articles/articles08/you_get_the_results_you_reward.htm"><SPAN style="mso-bidi-font-style: italic"><FONT face=Calibri color=#0000ff size=3>wrote</FONT></SPAN></A><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>,<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><I><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>“It is a first principle of Change Management that people will act in what they perceive as being their best interests.”<o:p></o:p></I></FONT></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>At best, training can provide people with insight into what they need to do to solve a security problem <I>if they believe that solving that security problem is in their best interests. <o:p></o:p></I></FONT></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>To be effective, training needs to happen in an environment:<o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-style: italic; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>Where expectations are clearly set (the SDL sets specific minimum requirements). <o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-style: italic; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>People have appropriate incentives and consequences (security is a great career path at Microsoft, and nobody wants to be the one holding up a ship schedule for failure to meet a security requirement).<o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-style: italic; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>Where tools and resources to accomplish the goals are available (we build a whole variety of tools that map to the SDL requirements).<o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-style: italic; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>Where management models the behavior (recall the original BillG TWC memo). <o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-style: italic; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"><SPAN style="mso-list: Ignore"><FONT size=3>·</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><SPAN style="mso-bidi-font-style: italic"><FONT size=3><FONT face=Calibri>Where the environment reflects and supports the values presented in the training (apparent in everything Microsoft does). <o:p></o:p></FONT></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Don’t make the mistake of thinking that a bunch of training, even really high quality training done periodically, will result in actual behavior change. It won’t. You have to build an environment where people perceive solving security problems as being in their best interests. You have to make security <I style="mso-bidi-font-style: normal">their</I> problem – not in the sense of passing the buck, but in the sense of changing their behavior so they will bring security problems to you.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>To illustrate further, I’ll cite two examples. First, fuzz testing. Fuzz testing has been a success story here at Microsoft. Tools arise spontaneously to solve new fuzzing challenges, written by people who believe the challenges are their challenges. There are people who feel ownership for our fuzzing strategy and on-going research and science, there are specific goals and requirements, we have training (remember the peaches?), and internally developed fuzzers have won prestigious awards within the company, handed out by members of the executive staff, and all of this gets revisited periodically as part of the SDL. </FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>By contrast, I’ll choose a less successful area – defect estimation. On my own volition, I created (based mostly on some excellent material from Microsoft Research) and taught a class called “Defect Estimation and Management” and added it to the SDL curriculum. Microsoft is a great place to work in that regard. It was pretty close to the best-reviewed class I taught. But, we have not yet been able to establish a set of tools to estimate security defect density effectively, and establish a fair set of expectations, incentives, and consequences, or even<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>decide what we should do if we had the data. We discovered some things, though. For example, based on what I observed (which should not be construed as rigorous research), it does not appear as if the density of general defects correlates closely with the density of security defects. <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>And Microsoft Research found higher code coverage in testing correlates with <I style="mso-bidi-font-style: normal">higher </I>bug rates in the field. </FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>And so even though people like the idea of defect estimation, and we’ve got some interesting and surprising data, we’ve not yet been successful in changing people’s behavior. <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>Generally speaking, an individual test manager does not feel that establishing a high quality estimate of their defect density is in his or her best interests, as compared to, say, improving the time in which an established series of tests can be performed . <SPAN style="mso-spacerun: yes">&nbsp;</SPAN><SPAN class=msoIns><INS cite=mailto:Kristen%20Kish dateTime=2008-05-28T10:53><o:p></o:p></INS></SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>We need to build an environment that has the tools, training, rewards and incentives, and expectations and consequences to change people’s behavior. Not that we’re not trying. But training won’t solve it alone, nor would tools, trophies, rants, testing, code review, or some edict from on high. The SDL is as much about changing the culture and influencing the behavior of individual engineers as it is anything else. </FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>I’m convinced that Microsoft’s SDL process works because it addresses the end-to-end problem - from training through servicing, and provides a complete environment where people feel ownership of their part of the security problem and have the resources to solve it. </FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>So the next time you find yourself sitting in some mandatory training, remember the lessons of the SDL (and most of the research on human performance management): training alone won’t cut it. If you want real behavior change, there have to be things outside the lecture room to influence people to change their behavior.</FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8558916" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 29 May 2008 11:22:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/real behavior change">real behavior change</category>
      <category domain="http://www.securityratty.com/tag/behavior">behavior</category>
      <category domain="http://www.securityratty.com/tag/sdl">sdl</category>
      <category domain="http://www.securityratty.com/tag/change peoples behavior">change peoples behavior</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/security guy">security guy</category>
      <category domain="http://www.securityratty.com/tag/security defects">security defects</category>
      <category domain="http://www.securityratty.com/tag/defects">defects</category>
      <category domain="http://www.securityratty.com/tag/security class">security class</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/05/29/sdl-training.aspx">SDL Training</source>
    </item>
    <item>
      <title><![CDATA[Why even having health insurance is not enough anymore]]></title>
      <link>http://www.securityratty.com/article/c4f007a02c60338f0381adcb2dd11c15</link>
      <guid>http://www.securityratty.com/article/c4f007a02c60338f0381adcb2dd11c15</guid>
      <description><![CDATA[Forgive me for going totally off topic (hey its my blog I write what I want) but it is Sunday and not much news on security. I wanted to write about an article I saw in the NY Times today called &quot;...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/INSURE_GRAPH.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 5px 0px; border-left: 0px; border-bottom: 0px" height="260" alt="INSURE_GRAPH" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/INSURE_GRAPH_thumb.jpg" width="247" align="left" border="0"></a> Forgive me for going totally off topic (hey its my blog I write what I want) but it is Sunday and not much news on security.&nbsp; I wanted to write about an article I saw in the NY Times today called "<a href="http://www.nytimes.com/2008/05/04/business/04insure.html?_r=1&amp;partner=rssyahoo&amp;emc=rss&amp;oref=slogin" target="_blank">Even the Insured Feel the Strain of Health Costs</a>". The article details that with the hard economic times even people who have health insurance are being bitten by the ever rising costs of health care.&nbsp; Rising premiums, covering less procedures and care and charging more for prescriptions and medical care combine to put the bite on everyone.&nbsp; From my own experience here are 4 examples of how even with health insurance, medical care costs are taking a bite:</p> <p>1. My wife had minor surgery in September.&nbsp; It was ambulatory surgery where she went in the morning and went home that afternoon/evening.&nbsp; Even though we have full PPO coverage and it was participating doctors, hospital, etc. my out-of-pocket costs after insurance were almost $3000! The surgeon received a whopping $472 from the insurance company for the operation and the hospital billed like 17k!&nbsp; When I called the hospital they said they did not expect to get paid that much, but had to bill it so they could get as much as they could.&nbsp; I than had to negotiate what I would pay out of pocket beyond that. I also had to pay the anesthesia, the prescriptions, etc.</p> <p>2. Here at StillSecure we had to switch providers again this year because United Health Care wanted another 15 to 20% raise in premiums. In fact that is about normal for health insurance, way above the cost of living and inflation.&nbsp; We pay a good chunk of our employees insurance premiums, but even so the 20% or so that we have the employee pick up gets bigger and bigger.&nbsp; Plus the insurance company covers less and less.&nbsp; This squeeze is frankly baffling. How can you pay more and get less.</p> <p>3. I had a dental implant a few months back.&nbsp; Though we pay for dental coverage, our insurance would cover a bridge or cap, but they don't consider implants necessary and would not cover any of it. I had to lay 2k out of pocket. On top of this the panoramic x-ray the oral surgeon took (which again was not covered, another 100 bucks) showed I had an impacted wisdom tooth with a cyst around it.&nbsp; My dental insurance covered the wisdom tooth, but the cyst removal would be considered under my regular insurance and my dentist was not participating. In fact I could not find a participating oral surgeon in the area.&nbsp; So I had to an extra $600 dollars out of pocket and of course my out-of-network deductible was $750, so I ate it again.</p> <p>4. The orthodontist.&nbsp; This one is perhaps the worst of all and really gets my goat.&nbsp; My oldest son went for an orthodontic exam. The doctor told my wife that he would probably need braces when he gets older and that current best practices in orthodontics is to put braces on now in a phase 1 and than if necessary they put other braces on later when more of his adult teeth come in. Putting braces on now would lesson the severity of what he would need later.&nbsp; OK, great lets do it, right?&nbsp; Wrong!&nbsp; Our insurance covers a one time payment of $1200. The dentist said if we use it now, the cost for phase 1 would be $3600.&nbsp; That leaves a balance of $2400 that I have to pay.&nbsp; However, if I do it without insurance he would charge me $2400 and than I could use the $1200 towards the phase 2 braces my son may need which could be up to 10k. So if we went through insurance the cost was $3600 with $2400 out of pocket or no insurance $2400 out of pocket.&nbsp; What is wrong with that picture. Whether I have insurance or not, it still costs me $2400!&nbsp; This is fundamentally what is wrong with our health care system.&nbsp; The dentist is willing to accept $2400.&nbsp; He should take the $1200 from my insurance and I should pay him another $1200.&nbsp; Anything else is ludicrous and in my mind borders on criminal insurance fraud.</p> <p>We need to restore sanity to the whole system. It is not just the 48 million people in this country that don't have insurance, it is also the costs of the people who do have insurance. Don't tell me that giving us greater limits to put in tax deferred health savings plan are the answer either.&nbsp; Fundamentally we need the insurance companies to stop sucking the blood of the premium payers. We need the health industry to bill for what the do and what it is worth, not how to maximize what the insurance company pays and most of all we need to make sure that people can afford and receive decent health care!</p> <p>BTW, if you want to read an excellent blog on this subject, Dr. Stanley Feld, Brad's dad writes a <a href="http://stanleyfeldmdmace.typepad.com/" target="_blank">great blog</a> on it.</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=glbKcq"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=glbKcq" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JXuPNH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JXuPNH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=68kijH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=68kijH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=F5w3nH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=F5w3nH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=N5GpqH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=N5GpqH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=fCI2Xh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=fCI2Xh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=tOX5ch"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=tOX5ch" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/283478411" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 04 May 2008 11:13:07 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/insurance">insurance</category>
      <category domain="http://www.securityratty.com/tag/health insurance">health insurance</category>
      <category domain="http://www.securityratty.com/tag/premiums">premiums</category>
      <category domain="http://www.securityratty.com/tag/employees insurance premiums">employees insurance premiums</category>
      <category domain="http://www.securityratty.com/tag/insurance company pays">insurance company pays</category>
      <category domain="http://www.securityratty.com/tag/regular insurance">regular insurance</category>
      <category domain="http://www.securityratty.com/tag/insurance company">insurance company</category>
      <category domain="http://www.securityratty.com/tag/care">care</category>
      <category domain="http://www.securityratty.com/tag/health care system">health care system</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/283478411/why-even-having.html">Why even having health insurance is not enough anymore</source>
    </item>
    <item>
      <title><![CDATA[Security Catalyst Forums]]></title>
      <link>http://www.securityratty.com/article/20e04e3c2f82c7de0dc5fbcdc4c94f22</link>
      <guid>http://www.securityratty.com/article/20e04e3c2f82c7de0dc5fbcdc4c94f22</guid>
      <description><![CDATA[I've written often about all the ways I have met people. My network has certainly grown in the last year between facebook , linkedin , the numerous blogs that I read and the numerous blogs that they...]]></description>
      <content:encoded><![CDATA[I've written often about all the ways I have met people. My network has certainly grown in the last year between <span class="blsp-spelling-error" id="SPELLING_ERROR_0">facebook</span>, <span class="blsp-spelling-error" id="SPELLING_ERROR_1">linkedin</span>, the numerous blogs that I read and the numerous blogs that they all link to.<br /><br />One place that has certainly been a terrific place to meet smart people interested in Information Security and to harvest some of their ideas are the <a href="http://www.securitycatalyst.org/forums/index.php">Security Catalyst Forums</a>. Registration is free and gets you access to some really amazing people.<br /><br />Each week someone volunteers to sum up the last week's postings and this week is my turn so here goes...<br /><br />Andrew Hay is doing his <span class="blsp-spelling-error" id="SPELLING_ERROR_2">CISSP</span> and has been given a lot of advice by the members. Generally it is agreed that <span class="blsp-spelling-error" id="SPELLING_ERROR_3">cccure</span>.org is a good resource but always ready to jump in and start new Security Catalyst initiatives, Michael wants to put together a resource for those Catalyst Members studying for the <span class="blsp-spelling-error" id="SPELLING_ERROR_4">CISSP</span>.<br /><br />I personally did the official <span class="blsp-spelling-error" id="SPELLING_ERROR_5">CISSP</span> boot camp training course and found it well worth doing. I bought the official <span class="blsp-spelling-error" id="SPELLING_ERROR_6">ISC</span>2 guide but found it to be too wordy and technical. It is a great resource though and I have used it many times since my exam but at 10pm after a days work it is the last thing your eyes want to see.<br /><br />Education seems to be a theme at the moment - <span class="blsp-spelling-error" id="SPELLING_ERROR_7">Didier</span> Stevens write his <span class="blsp-spelling-error" id="SPELLING_ERROR_8">GSSP</span>-C exam and Kevin <span class="blsp-spelling-error" id="SPELLING_ERROR_9">Riggins</span> is debating doing a Masters in Information Protection/Assurance.<br /><br />Information Security is slowly becoming so much more more than just Firewalls and Antivirus and the education needed is becoming vast. I think it has already come to the point where it is impossible to know everything and <span class="blsp-spelling-corrected" id="SPELLING_ERROR_10">practitioners</span> now need to work out what section of Information Security they want to get into.<br /><br />I personally am interested in the management side of <span class="blsp-spelling-error" id="SPELLING_ERROR_11">InfoSec</span> but if I choose that then I will not be able to get deeply into any particular part of <span class="blsp-spelling-error" id="SPELLING_ERROR_12">InfoSec</span> anymore. I have my <span class="blsp-spelling-error" id="SPELLING_ERROR_13">CISSP</span> and would love to get a Masters like the one above but <span class="blsp-spelling-error" id="SPELLING_ERROR_14">GSSP</span>-C would be too restrictive for me but to each his own. Well done <span class="blsp-spelling-error" id="SPELLING_ERROR_15">Didier</span> and good luck Andrew, Kevin and all those that are looking to grow their knowledge.<br /><br />Don Weber raises an interesting question - should businesses be monitoring search queries via their proxy servers. My feeling is that yes, they should. Companies should monitor everything and they have the right (in South Africa at least) to do so. However, (there is always an however with me) context is everything. One has to use the information that one gets from logs as a guide and try to understand exactly why someone browses so much or such strange sites or whatever. I believe that Information Security has to become a central part of the organisation and has to make connections with all departments. All browsing issues must be driven by HR with technical and policy help from <span class="blsp-spelling-error" id="SPELLING_ERROR_16">InfoSec</span>.<br /><br />There were other discussions, jobs posted and conferences listed but I'm not going to go into them all. The last thing I'd like to say is that I asked a question on the Security Catalyst Forums and got some quality replies - all different but all quality that will allow me to do my job that much better.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/279901176" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 02:17:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security catalyst forums">security catalyst forums</category>
      <category domain="http://www.securityratty.com/tag/catalyst">catalyst</category>
      <category domain="http://www.securityratty.com/tag/information security">information security</category>
      <category domain="http://www.securityratty.com/tag/information">information</category>
      <category domain="http://www.securityratty.com/tag/smart people">smart people</category>
      <category domain="http://www.securityratty.com/tag/people">people</category>
      <category domain="http://www.securityratty.com/tag/security catalyst initiatives">security catalyst initiatives</category>
      <category domain="http://www.securityratty.com/tag/numerous blogs">numerous blogs</category>
      <category domain="http://www.securityratty.com/tag/infosec anymore">infosec anymore</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/279901176/security-catalyst-forums.html">Security Catalyst Forums</source>
    </item>
    <item>
      <title><![CDATA[Not a CISSP]]></title>
      <link>http://www.securityratty.com/article/1086ae7fb50978a9789a276c29a70584</link>
      <guid>http://www.securityratty.com/article/1086ae7fb50978a9789a276c29a70584</guid>
      <description><![CDATA[One of my favorite pieces of swag from RSA was this Not a CISSP button that was pinned onto me by none other than Sinan Eren as I was chatting with Justine Aitel at the Immunity booth. Actually, there...]]></description>
      <content:encoded><![CDATA[<p>One of my favorite pieces of swag from RSA was this &#8220;Not a CISSP&#8221; button that was pinned onto me by none other than Sinan Eren as I was chatting with Justine Aitel at the <a href="http://immunityinc.com/">Immunity</a> booth.  Actually, there should have been a prize awarded just for finding the Immunity booth &#8212; they were subletting another vendor&#8217;s space for a few hours at a time, so one minute they&#8217;d be there and the next they were gone.  </p>
<p><a href='http://www.veracode.com/blog/wp-content/uploads/2008/04/picture-2.jpg'><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/04/picture-2-300x225.jpg" alt="Not a CISSP" title="Not a CISSP" width="300" height="225" style="margin-bottom: 20px" /></center></a></p>
<p>I digress.  What inevitably happened once I started walking around with this button proudly displayed was that I would get one of two reactions.  The first group &#8212; mostly current and former co-workers and acquaintances &#8212; understood the humor and got a good chuckle out of it.  The second group would ponder for a bit and then ask, with some confusion, why I&#8217;d intentionally point out the fact that I&#8217;m not a CISSP.  I&#8217;d give a brief answer and get back to talking about Veracode (we booth babes have responsibilities, you know).</p>
<p>So, why indeed?  The long answer is that like many security certifications, it&#8217;s an ineffective measure of a security professional&#8217;s practical abilities.  Employers and customers often assume the guy with the five magic letters on his resume is technically superior to the guy without.  In my experience, it&#8217;s exactly the opposite, particularly in situations where you have to sit down at a keyboard and actually DO something as opposed to talking about it.  Certainly, I&#8217;ve encountered some very notable exceptions to this observation, but we&#8217;re playing by the 80/20 rule here.</p>
<p>There&#8217;s a good reason for this.  The trend in information security is toward specialization.  Security has become such a broad umbrella of varying disciplines that it&#8217;s quite difficult to be a generalist.  A security career is a balance between breadth and depth, and these days, the skilled pen tester, reverse engineer, or vulnerability researcher is more marketable than the guy who knows a little bit about dozens of different disciplines but can&#8217;t apply that knowledge in a practical situation.  The <a href="http://en.wikipedia.org/wiki/Certified_Information_Systems_Security_Professional">CISSP subject matter</a> illustrates this perfectly &#8212; you have cryptographic algorithms, site location principles, network security, and civil law on the same exam.  I won&#8217;t even get into the complaints I&#8217;ve heard about the poorly-worded, overly simplistic exam questions or the ones that simply test one&#8217;s ability to memorize obscure facts.</p>
<p>I&#8217;m not claiming that there&#8217;s no value to holding the CISSP certification.  It can&#8217;t hurt to have some exposure to business continuity planning, for example.  The problem, as I stated in the beginning, is that the CISSP title is often interpreted as an indicator of practical abilities rather than a book-level understanding of security basics.  These misaligned expectations can ultimately lead to bad hiring or staffing decisions.  </p>
<p>Career advice, take it or leave it: If an employer or prospective employer demands that you get your CISSP in order to be hired or to progress in your career, run fast in the opposite direction and find a place where you will be valued for your cumulative experience rather than a piece of paper.  Learn by doing, don&#8217;t &#8220;learn the test,&#8221; so to speak.</p>
<p>And that, in a nutshell, is why I love my &#8220;Not a CISSP&#8221; button.</p>
<p>By the way, here was my other favorite from RSA, thanks to WhiteHat.  This one and &#8220;Samy is my hero&#8221; were the best out of a pretty clever selection&#8230; even though they forgot the semicolon after the single quote.  &lt;grin&gt;</p>
<p><a href='http://www.veracode.com/blog/wp-content/uploads/2008/04/picture-3.jpg'><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/04/picture-3-300x225.jpg" alt="DROP Table SalesPitch" title="DROP Table SalesPitch" width="300" height="225" /></center></a></p>
]]></content:encoded>
      <pubDate>Fri, 18 Apr 2008 10:36:41 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/cissp">cissp</category>
      <category domain="http://www.securityratty.com/tag/cissp certification">cissp certification</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/cissp button">cissp button</category>
      <category domain="http://www.securityratty.com/tag/network security">network security</category>
      <category domain="http://www.securityratty.com/tag/information security">information security</category>
      <category domain="http://www.securityratty.com/tag/security career">security career</category>
      <category domain="http://www.securityratty.com/tag/career">career</category>
      <category domain="http://www.securityratty.com/tag/cissp title">cissp title</category>
      <source url="http://www.veracode.com/blog/?p=86">Not a CISSP</source>
    </item>
    <item>
      <title><![CDATA[My RSA trip is off to a terrible start]]></title>
      <link>http://www.securityratty.com/article/5f1b53bddc48eb6074041ecd9bc6f955</link>
      <guid>http://www.securityratty.com/article/5f1b53bddc48eb6074041ecd9bc6f955</guid>
      <description><![CDATA[It started when I had to change my flight home for the trip this week. The Expedia Corporate folks messed up the pricing and canceling of my first flight because their site was down, so it wound up...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>It started when I had to change my flight home for the trip this week.&nbsp; The Expedia Corporate folks messed up the pricing and canceling of my first flight because their site was down, so it wound up costing 800 dollars more than it should have!&nbsp; But I cannot miss the show, so had to eat it. I got to Ft Lauderdale airport this afternoon to find out my flight out was 45 minutes late.&nbsp; That put my connection in Atlanta in jeopardy.&nbsp; The agent checking me in (who took 45 minutes for the two people in front of me) put a big priority tag on my luggage because I am Platinum Medallion on Delta.&nbsp; As he was doing that, I said to myself that is a kiss of death if I ever saw one.&nbsp; I got to Atlanta to find out my connection was an hour late anyway and everything was fine, if you don't count landing in San Fran at 1am pacific time (4am east coast time) to late.&nbsp; So I got on the plane and we are off to San Fran.&nbsp; On the way there a woman on the plane had some medical problem, so when we landed there were paramedics waiting for the plane.&nbsp; Though the woman appeared alright now, we had to wait for them to come on, exam her and take her off the plane.&nbsp; About 20 minutes later, they let us off the plane.&nbsp; Ok, now it is 1:30 in the morning pacific, 4:30am on my body clock. </p>

<p>I head down to baggage claim. I wait another 30 minutes for all of the luggage to come off the plane and don't you know it, my luggage with the big priority tag they put on it is not on the plane.&nbsp; I stand on another line to make another claim.&nbsp; They tell me that the first flight in tomorrow is due in at 10:58 am, I might have my luggage by noon if I am very lucky.&nbsp; That is great, I am scheduled to be at the Americas Growth Capital Conference at 8:30am.&nbsp; I am sure I will look great in my Levi jeans and denim shirt with sneakers! Not to mention using the cheap toiletries that the hotel gives the dredges who don't have their own deodorant.&nbsp; &nbsp;Also what is the idea with hotels charging $12.95 a night for Internet access.&nbsp; Shame on you San Francisco Hilton!</p>

<p>So far this is one hell of a conference and trip.&nbsp; Can't tell you how happy I am to have come out here already.&nbsp; The good news is that it can only get better, not sure how it can get worse.&nbsp; More tomorrow.</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=kib6X2"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=kib6X2" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1bIzMfG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1bIzMfG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=9UHs3GG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=9UHs3GG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=aelhIcG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=aelhIcG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=KqF6dHG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=KqF6dHG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wF0UMlg"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wF0UMlg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qKcNk5g"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qKcNk5g" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/265543023" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 07 Apr 2008 00:22:02 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/plane">plane</category>
      <category domain="http://www.securityratty.com/tag/flight home">flight home</category>
      <category domain="http://www.securityratty.com/tag/flight">flight</category>
      <category domain="http://www.securityratty.com/tag/san fran">san fran</category>
      <category domain="http://www.securityratty.com/tag/minutes">minutes</category>
      <category domain="http://www.securityratty.com/tag/luggage">luggage</category>
      <category domain="http://www.securityratty.com/tag/1am pacific time">1am pacific time</category>
      <category domain="http://www.securityratty.com/tag/pacific">pacific</category>
      <category domain="http://www.securityratty.com/tag/trip">trip</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/265543023/my-rsa-trip-is.html">My RSA trip is off to a terrible start</source>
    </item>
  </channel>
</rss>
