<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hard]]></title>
    <link>http://www.securityratty.com/tag/hard</link>
    <description></description>
    <pubDate>Fri, 21 Nov 2008 06:50:19 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Darpa's Battlefield Dream: Tell Me a Story]]></title>
      <link>http://www.securityratty.com/article/78eed9672d28924d259dc00a2d52a575</link>
      <guid>http://www.securityratty.com/article/78eed9672d28924d259dc00a2d52a575</guid>
      <description><![CDATA[Drone feeds, informant tips, news reports, captured phone calls -- sometimes, a battlefield commander gets so much information, it's hard to make sense of it all. So Darpa is looking to distill all...]]></description>
      <content:encoded><![CDATA[Drone feeds, informant tips, news reports, captured phone calls -- sometimes, a battlefield commander gets so much information, it's hard to make sense of it all. So Darpa is looking to distill all that data into something "more suitable for human consumption." Namely, a story. One told by a series of intelligent algorithms.<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=9322dd8ba993af446796342abb48cc1d&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=9322dd8ba993af446796342abb48cc1d&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9322dd8ba993af446796342abb48cc1d" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=RlkNO"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=RlkNO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=93Feo"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=93Feo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Ga7vo"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Ga7vo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gugqO"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gugqO" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=pbc1O"><img src="http://feeds.wired.com/~f/wired/politics/security?i=pbc1O" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=2rpPo"><img src="http://feeds.wired.com/~f/wired/politics/security?i=2rpPo" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=GP9Qo"><img src="http://feeds.wired.com/~f/wired/politics/security?i=GP9Qo" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TZzkO"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TZzkO" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/474725093" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/474725097" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Dec 2008 11:16:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/story">story</category>
      <category domain="http://www.securityratty.com/tag/drone feeds">drone feeds</category>
      <category domain="http://www.securityratty.com/tag/informant tips">informant tips</category>
      <category domain="http://www.securityratty.com/tag/intelligent algorithms">intelligent algorithms</category>
      <category domain="http://www.securityratty.com/tag/human consumption">human consumption</category>
      <category domain="http://www.securityratty.com/tag/battlefield commander">battlefield commander</category>
      <category domain="http://www.securityratty.com/tag/news reports">news reports</category>
      <category domain="http://www.securityratty.com/tag/phone calls">phone calls</category>
      <category domain="http://www.securityratty.com/tag/darpa">darpa</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/474725097/blog_dangerroom_darpastories1204">Darpa's Battlefield Dream: Tell Me a Story</source>
    </item>
    <item>
      <title><![CDATA[Darpa's Battlefield Dream: Tell Me a Story]]></title>
      <link>http://www.securityratty.com/article/80e126bf070533cd87c7025968a1f14c</link>
      <guid>http://www.securityratty.com/article/80e126bf070533cd87c7025968a1f14c</guid>
      <description><![CDATA[Drone feeds, informant tips, news reports, captured phone calls -- sometimes, a battlefield commander gets so much information, it's hard to make sense of it all. So Darpa will distill all that data...]]></description>
      <content:encoded><![CDATA[Drone feeds, informant tips, news reports, captured phone calls -- sometimes, a battlefield commander gets so much information, it's hard to make sense of it all. So Darpa will distill all that data into a story -- one told by a series of intelligent algorithms.<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=f387647becba0a448a77167993d76fc3&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f387647becba0a448a77167993d76fc3&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f387647becba0a448a77167993d76fc3" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=etsDO"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=etsDO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=s5Uno"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=s5Uno" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=SNNto"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=SNNto" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=96JfO"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=96JfO" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=nyqBO"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nyqBO" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Qrdno"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Qrdno" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IOodo"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IOodo" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=VAV7O"><img src="http://feeds.wired.com/~f/wired/politics/security?i=VAV7O" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/474872954" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/474875527" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Dec 2008 11:16:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/informant tips">informant tips</category>
      <category domain="http://www.securityratty.com/tag/intelligent algorithms">intelligent algorithms</category>
      <category domain="http://www.securityratty.com/tag/story">story</category>
      <category domain="http://www.securityratty.com/tag/drone feeds">drone feeds</category>
      <category domain="http://www.securityratty.com/tag/news reports">news reports</category>
      <category domain="http://www.securityratty.com/tag/battlefield commander">battlefield commander</category>
      <category domain="http://www.securityratty.com/tag/phone calls">phone calls</category>
      <category domain="http://www.securityratty.com/tag/darpa">darpa</category>
      <category domain="http://www.securityratty.com/tag/distill">distill</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/474875527/darpa-memory-pr.html">Darpa's Battlefield Dream: Tell Me a Story</source>
    </item>
    <item>
      <title><![CDATA[It makes good sense to just re-install]]></title>
      <link>http://www.securityratty.com/article/0600378a6736bed0cab395f17c9d710e</link>
      <guid>http://www.securityratty.com/article/0600378a6736bed0cab395f17c9d710e</guid>
      <description><![CDATA[This article offers a different approach to fighting malware infections. There is that stigma that users have with a re-install, they are not familiar with how to do it. Many dont even know if they...]]></description>
      <content:encoded><![CDATA[<div > This article offers a different approach to fighting malware infections.<br/>There is that stigma that users have with a re-install, they are not familiar with how to do it. Many dont even know if they have a restore CD that may have come with their puter when they bought it. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/32FCFB9B-7779-4D5D-A72D-4AF74CDEA753/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/76350314-72c8-431c-9bcc-ad3ab017ae8e/32FCFB9B-7779-4D5D-A72D-4AF74CDEA753/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/" href="http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/" style="font-size: 11px;">www.isyougeekedup.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/ --><H2 id="post-446"><A rel="bookmark" href="http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/">The Only Way To Permanently Remove Viruses, Spyware, and Malicious Code</A></H2></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.isyougeekedup.com/the-only-way-to-permanently-remove-viruses-spyware-and-malicious-code/ --><P>If you ask any experienced and competent IT professional what to do about an infected system, they should only give you one answer: format your hard drive and reinstall your operating system.? Why skip straight to the format/reinstall and disregard the anti-virus and anti-spyware removal tools?</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/32FCFB9B-7779-4D5D-A72D-4AF74CDEA753/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_021208043534"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021208043534&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021208043534&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=021208043534&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_021208043534" /></a></P>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 13:35:34 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/spyware">spyware</category>
      <category domain="http://www.securityratty.com/tag/anti-spyware removal tools">anti-spyware removal tools</category>
      <category domain="http://www.securityratty.com/tag/permanently remove viruses">permanently remove viruses</category>
      <category domain="http://www.securityratty.com/tag/system">system</category>
      <category domain="http://www.securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://www.securityratty.com/tag/skip straight">skip straight</category>
      <category domain="http://www.securityratty.com/tag/article offers">article offers</category>
      <category domain="http://www.securityratty.com/tag/hard drive">hard drive</category>
      <category domain="http://www.securityratty.com/tag/malware infections">malware infections</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=668">It makes good sense to just re-install</source>
    </item>
    <item>
      <title><![CDATA[User Experience in the Identity Community]]></title>
      <link>http://www.securityratty.com/article/4592f20408c5847cdeebe7d00b843e62</link>
      <guid>http://www.securityratty.com/article/4592f20408c5847cdeebe7d00b843e62</guid>
      <description><![CDATA[Eric Sachs &amp; Ben Laurie, Google Security



One of the major conferences on Internet identity standards is the Internet Identity Workshop (IIW), a semiannual 'un-conference' where the sessions are not...]]></description>
      <content:encoded><![CDATA[<span class="Apple-style-span" style="font-family: Verdana; font-size: 13px; "><div style="margin-top: 0px; margin-bottom: 0px; ">Eric Sachs &amp; Ben Laurie, Google Security<br /></div><div style="margin-top: 0px; margin-bottom: 0px; "><br /></div><div style="margin-top: 0px; margin-bottom: 0px; ">One of the major conferences on Internet identity standards is the <a href="http://iiw.idcommons.net/" id="xwok" title="Internet Identity Workshop" style="color: rgb(85, 26, 139); ">Internet Identity Workshop</a> (IIW), a semiannual 'un-conference' where the sessions are not determined ahead of time. It is attended by a large set of people who work on Internet security and identity standards such as OAuth, OpenID, SAML, InfoCards, etc.  A major theme within the identity community this year has been about improving the user experience and growing the adoption of these technologies.  The OpenID community is making great progress on user experience, with Yahoo, AOL, and Google quickly improving the support they provide (read a <a href="http://blog.plaxo.com/archives/2008/11/yahoo_ups_the_a.html" id="jh0r" title="summary" style="color: rgb(85, 26, 139); ">summary</a> from Joseph Smarr of Plaxo).  Similarly, the InfoCard community has been working on simplifying the user experience of InfoCard technology, including the <a href="http://blogs.msdn.com/card/archive/2008/11/18/the-cardspace-geneva-selection-experience.aspx" id="pyzp" title="updated" style="color: rgb(85, 26, 139); ">updated</a> CardSpace selector from Microsoft.</div><div style="margin-top: 0px; margin-bottom: 0px; "><br /></div><div style="margin-top: 0px; margin-bottom: 0px; ">Another hot topic at IIW centered around <span style="background-color: rgb(255, 255, 255); ">how to improve the user experience when testing alternatives and enhancements to passwords to make them less susceptible to phishing attacks.  Many websites and enterprises have tried these password enhancements/alternatives, but they found that people complained that they were hard to use, or that they weren't portable enough for people who use multiple computers, including web cafes and smart phones.  We have published an <a href="http://sites.google.com/site/oauthgoog/UXFedLogin/strongauth" id="zq0m" title="article" style="color: rgb(85, 26, 139); ">article</a> summarizing some of the community's current ideas for how to deploy these new authentication mechanisms using a multi-layered approach that minimizes additional work required by users.  We have also pulled together a set of <a href="http://sites.google.com/site/oauthgoog/UXFedLogin/strongauthvideos" id="ln7n" title="videos" style="color: rgb(85, 26, 139); ">videos</a> showing how a number of these different approaches work with both web-based and desktop applications.  We hope this information will be helpful to other websites and enterprises who are concerned about phishing.</span></div></span><div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=g2twxZuB"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=9u931A56"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=9u931A56" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/KdUhqcr2y0c" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 03:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/identity community">identity community</category>
      <category domain="http://www.securityratty.com/tag/community">community</category>
      <category domain="http://www.securityratty.com/tag/user experience">user experience</category>
      <category domain="http://www.securityratty.com/tag/infocard community">infocard community</category>
      <category domain="http://www.securityratty.com/tag/identity standards">identity standards</category>
      <category domain="http://www.securityratty.com/tag/internet identity standards">internet identity standards</category>
      <category domain="http://www.securityratty.com/tag/openid community">openid community</category>
      <category domain="http://www.securityratty.com/tag/openid">openid</category>
      <category domain="http://www.securityratty.com/tag/people">people</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/KdUhqcr2y0c/user-experience-in-identity-community.html">User Experience in the Identity Community</source>
    </item>
    <item>
      <title><![CDATA[BlueHat SDL Sessions Wrap-up]]></title>
      <link>http://www.securityratty.com/article/5bc4bc363bab903a7f7f8a6245e3234d</link>
      <guid>http://www.securityratty.com/article/5bc4bc363bab903a7f7f8a6245e3234d</guid>
      <description><![CDATA[Hi everyone, Bryan here. The debut BlueHat SDL Sessions are over, and they were a resounding success: 96% of attendees completing evaluation surveys reported that they will be able to apply knowledge...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Hi everyone, Bryan here. The debut </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/09/25/sdl-sessions-at-bluehat.aspx"><FONT face=Calibri size=3>BlueHat SDL Sessions</FONT></A><FONT face=Calibri size=3> are over, and they were a resounding success: 96% of attendees completing evaluation surveys reported that they will be able to apply knowledge that they learned in the SDL sessions to make their products more secure. This is a great score and I’d like to thank all of our speakers and the BlueHat planning team for their hard work. As for the other 4% of attendees, we’ll just have to work that much harder next year to bring them actionable guidance for dealing with new vulnerabilities.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>As promised, we recorded all of the day’s presentations and we’ve published them on </FONT><A href="http://technet.microsoft.com/en-us/security/cc748656.aspx#day2"><FONT face=Calibri color=#0000ff size=3>TechNet</FONT></A><FONT face=Calibri size=3>:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd282968.aspx"><FONT face=Calibri color=#0000ff size=3>Keynote Address</FONT></A><FONT face=Calibri size=3> by Scott Charney, Corporate VP, Microsoft Trustworthy Computing</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd282977.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at EMC and Microsoft</FONT></A><FONT face=Calibri size=3> by Danny Dhillon of EMC and Adam Shostack of the Microsoft SDL team (of course)</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285253.aspx"><FONT face=Calibri color=#0000ff size=3>Mitigations Unplugged</FONT></A><FONT face=Calibri size=3> by Matt Miller, Microsoft Security Science team</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285262.aspx"><FONT face=Calibri color=#0000ff size=3>Concurrency Attacks on Web Applications</FONT></A><FONT face=Calibri size=3> by Scott Stender and Alex Vidergar of iSEC Partners</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285263.aspx"><FONT face=Calibri color=#0000ff size=3>Fuzzed Enough? When it’s OK to Put the Shears Down</FONT></A><FONT face=Calibri size=3> by Jason Shirk, Dave Weinstein and Lars Opstad, Microsoft Security Science team</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285265.aspx"><FONT face=Calibri color=#0000ff size=3>Real World Code Review – Using the Right Tools in the Right Place at the Right Time</FONT></A><FONT face=Calibri size=3> by Vinnie Liu of Stach &amp; Liu</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>In addition to the presentations, we also recorded some short interviews (about 10 minutes long) with each of the speakers. If you’re just looking for a quick summary of a particular talk, these interviews are the place to start:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285269.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at EMC</FONT></A><FONT face=Calibri size=3>, Danny Dhillon</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285454.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at Microsoft</FONT></A><FONT face=Calibri size=3>, Adam Shostack</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285260.aspx"><FONT face=Calibri color=#0000ff size=3>Mitigations Unplugged</FONT></A><FONT face=Calibri size=3>, Matt Miller</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285461.aspx"><FONT face=Calibri color=#0000ff size=3>Concurrency Attacks on Web Applications</FONT></A><FONT face=Calibri size=3>, Scott Stender and Alex Vidergar</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285279.aspx"><FONT face=Calibri color=#0000ff size=3>Fuzzed Enough?</FONT></A><FONT face=Calibri size=3> Jason Shirk and Dave Weinstein</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285463.aspx"><FONT face=Calibri color=#0000ff size=3>Real World Code Review</FONT></A><FONT face=Calibri size=3>, Vinnie Liu</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>I hope at least 96% of online readers will be able to directly apply this material to their products, just like the show attendees. Please post back and let us know, either way. And let us know what you’d like to see for next year. We have big plans to build on our success and make SDL Sessions 2.0 even bigger and better than the first.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9161040" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 14:51:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/sdl sessions">sdl sessions</category>
      <category domain="http://www.securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://www.securityratty.com/tag/microsoft trustworthy">microsoft trustworthy</category>
      <category domain="http://www.securityratty.com/tag/microsoft sdl team">microsoft sdl team</category>
      <category domain="http://www.securityratty.com/tag/vinnie liu">vinnie liu</category>
      <category domain="http://www.securityratty.com/tag/liu">liu</category>
      <category domain="http://www.securityratty.com/tag/web applications">web applications</category>
      <category domain="http://www.securityratty.com/tag/matt miller">matt miller</category>
      <category domain="http://www.securityratty.com/tag/jason shirk">jason shirk</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/12/01/bluehat-sdl-sessions-wrap-up.aspx">BlueHat SDL Sessions Wrap-up</source>
    </item>
    <item>
      <title><![CDATA[Hard to find AntiVirus Uninstall program links]]></title>
      <link>http://www.securityratty.com/article/d1d7302336a1955cd91310f325dad536</link>
      <guid>http://www.securityratty.com/article/d1d7302336a1955cd91310f325dad536</guid>
      <description><![CDATA[Well done article on where to find those uninstall programs to completely remove certain AntiVirus programs


clipped from whatsonmypc.wordpress.com
Uninstalling and Installing AntiVirus?Software

...]]></description>
      <content:encoded><![CDATA[<div > Well done article on where to find those uninstall programs to completely remove certain AntiVirus programs. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/8D308EC3-1947-4722-9D59-1F6806CBCCE3/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/a04ef5b9-ce72-4f84-9ecf-2e9d29309d52/8D308EC3-1947-4722-9D59-1F6806CBCCE3/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://whatsonmypc.wordpress.com/2008/12/01/uninstalling-and-installing-antivirus-software/" href="http://whatsonmypc.wordpress.com/2008/12/01/uninstalling-and-installing-antivirus-software/" style="font-size: 11px;">whatsonmypc.wordpress.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://whatsonmypc.wordpress.com/2008/12/01/uninstalling-and-installing-antivirus-software/ -->Uninstalling and Installing AntiVirus?Software…</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://whatsonmypc.wordpress.com/2008/12/01/uninstalling-and-installing-antivirus-software/ --><P>The points of this article is to educate you to the fact that there are FREE antivirus software options available and that follow-up research may be required to “completely” uninstall (remove) antivirus software from your system in the event you desire to install another antivirus program.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/8D308EC3-1947-4722-9D59-1F6806CBCCE3/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_011208022535"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=011208022535&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=011208022535&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=011208022535&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_011208022535" /></a></P>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 11:25:35 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://www.securityratty.com/tag/antivirus software">antivirus software</category>
      <category domain="http://www.securityratty.com/tag/software">software</category>
      <category domain="http://www.securityratty.com/tag/antivirus programs">antivirus programs</category>
      <category domain="http://www.securityratty.com/tag/remove">remove</category>
      <category domain="http://www.securityratty.com/tag/antivirus program">antivirus program</category>
      <category domain="http://www.securityratty.com/tag/completely remove">completely remove</category>
      <category domain="http://www.securityratty.com/tag/article">article</category>
      <category domain="http://www.securityratty.com/tag/completely uninstall">completely uninstall</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=666">Hard to find AntiVirus Uninstall program links</source>
    </item>
    <item>
      <title><![CDATA[Its not just about a strong password any more]]></title>
      <link>http://www.securityratty.com/article/a700eb95d1070aedb5ab5ff1520c6ac9</link>
      <guid>http://www.securityratty.com/article/a700eb95d1070aedb5ab5ff1520c6ac9</guid>
      <description><![CDATA[Make sure, as discussed in this great article, that you have a hard to guess login name


clipped from www.pcworld.com

Logins Are Half Your Access


Thieves need the login and password to access your...]]></description>
      <content:encoded><![CDATA[<div > Make sure, as discussed in this great article, that you have a hard to guess login name.<br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/C3ADC4F0-095C-4746-A0AA-F115F73B0989/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e8d56bc8-ccab-4b20-b493-6238be719143/C3ADC4F0-095C-4746-A0AA-F115F73B0989/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.pcworld.com/article/154538/article.html?tk=nl_spxblg" href="http://www.pcworld.com/article/154538/article.html?tk=nl_spxblg" style="font-size: 11px;">www.pcworld.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.pcworld.com/article/154538/article.html?tk=nl_spxblg -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Logins Are Half Your Access</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.pcworld.com/article/154538/article.html?tk=nl_spxblg --><P>Thieves need the login and password to access your accounts, so make the login difficult to guess, too. Avoid a simple, name-based method; add extra numbers, letters, or an ID that&#8217;s entirely different. Ideally, use unique logins (and passwords) for each service to isolate any exposure, should someone breach an account. (At the very least, keep unique logins and passwords for your most sensitive accounts, such as online banking.) While you may have to tell a customer service representative your login on occasion, don&#8217;t share the information without need. And never give anyone a password.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/C3ADC4F0-095C-4746-A0AA-F115F73B0989/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_281108043052"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043052&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043052&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043052&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_281108043052" /></a></P>]]></content:encoded>
      <pubDate>Fri, 28 Nov 2008 13:30:52 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/login difficult">login difficult</category>
      <category domain="http://www.securityratty.com/tag/logins">logins</category>
      <category domain="http://www.securityratty.com/tag/login">login</category>
      <category domain="http://www.securityratty.com/tag/unique logins">unique logins</category>
      <category domain="http://www.securityratty.com/tag/password">password</category>
      <category domain="http://www.securityratty.com/tag/customer service representative">customer service representative</category>
      <category domain="http://www.securityratty.com/tag/service">service</category>
      <category domain="http://www.securityratty.com/tag/accounts">accounts</category>
      <category domain="http://www.securityratty.com/tag/sensitive accounts">sensitive accounts</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=664">Its not just about a strong password any more</source>
    </item>
    <item>
      <title><![CDATA[Victoria's Secret Competition Gets Hacked]]></title>
      <link>http://www.securityratty.com/article/11d22ef9ce9705f72da9b7dcadecd7e4</link>
      <guid>http://www.securityratty.com/article/11d22ef9ce9705f72da9b7dcadecd7e4</guid>
      <description><![CDATA[Colleges aren't assigning enough homework these days
In seriousness, it's hard to prevent ballot stuffing in online...]]></description>
      <content:encoded><![CDATA[<p>Colleges aren't <a href="http://media.www.dailypennsylvanian.com/media/storage/paper882/news/2008/11/21/News/Victoria.Secret.Competition.Gets.Hacked-3556689.shtml">assigning enough homework</a> these days.</p>

<p>In seriousness, it's hard to prevent ballot stuffing in online polls.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=CYprN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=CYprN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ZjPfN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ZjPfN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 05:39:38 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/prevent ballot">prevent ballot</category>
      <category domain="http://www.securityratty.com/tag/online polls">online polls</category>
      <category domain="http://www.securityratty.com/tag/seriousness">seriousness</category>
      <category domain="http://www.securityratty.com/tag/homework">homework</category>
      <category domain="http://www.securityratty.com/tag/colleges">colleges</category>
      <category domain="http://www.securityratty.com/tag/hard">hard</category>
      <category domain="http://www.securityratty.com/tag/days">days</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/victorias_secre.html">Victoria's Secret Competition Gets Hacked</source>
    </item>
    <item>
      <title><![CDATA[Is That a Coffee Table or a Munition?]]></title>
      <link>http://www.securityratty.com/article/bcc3ebc100f5b51c419148587e587e92</link>
      <guid>http://www.securityratty.com/article/bcc3ebc100f5b51c419148587e587e92</guid>
      <description><![CDATA[One of the standard software security prescriptions for the SDLC is to data classification and enforce least privilege. From a security perspective this sounds fantastic, especially on a whiteboard....]]></description>
      <content:encoded><![CDATA[<p>One of the standard software security prescriptions for the SDLC is to data classification and enforce least privilege. From a security perspective this sounds fantastic, especially on a whiteboard. When the rubber meets the real world road, things often turn out slightly different.&#0160;</p><br /><div>It turns out that it is hard to conduct business with excessive granularity.</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e201053619a7a7970b-pi" style="display: inline;"><a href="http://www.economist.com/displaystory.cfm?story_id=11965352"><img alt="D3408BB1" class="at-xid-6a00d83451c75869e201053619a7a7970b " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e201053619a7a7970b-320wi" /></a></a><span style="font-family: &#39;Trebuchet MS&#39;; ">
</span> <br /></div><br /><div>Here is an <a href="http://www.economist.com/displaystory.cfm?story_id=11965352">article</a> from The Economist on the challenges of space technology, commercialization and information sharing. This is widely applicable to corporate information security policies:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-weight: bold; line-height: normal; ">Gravity is not the main obstacle for America’s space business. Government is</span></p><p><span style="font-family: Verdana; line-height: normal; ">IN THE spring of 2006 Robert Bigelow needed to take a stand on a trip to Russia to keep a satellite off the floor. The stand was made of aluminium. It had a circular base and legs. It was, says the entrepreneur and head of Bigelow Aerospace in Nevada, “indistinguishable from a common coffee table”. Nonetheless, the American authorities told Mr Bigelow that this coffee table was part of a satellite assembly and so counted as a munition. During the trip it would have to be guarded by two security officers at all times.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal;"><br /></span><span style="font-family: Verdana; line-height: normal; ">Exporting technology has always presented a dilemma for America. The country leads the world in most technologies and some of these give it a military advantage. If export rules are too lax, foreign powers will be able to put American technology in their systems, or copy it. But if the rules are too tight, then it will stifle the industries that depend upon sales to create the next generation of technology.</span><br /><span style="font-family: Verdana; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">It is a difficult balance to strike and critics charge that America has erred on the side of stifling. They claim that overly strict export controls have so damaged the space industry that America’s national security is now threatened by its dwindling leadership in space technology. The system, they complain, fails to distinguish between militarily sensitive hardware that should be controlled and widely available commercial technologies, such as lithium-ion batteries and solar cells. The zealous application of the export rules is the American space industry’s biggest handicap.</span></p></blockquote><div><span style="font-family: Verdana; font-weight: bold; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal; ">Read the whole thing its fascinating. So what started off as well intentioned asset protection eventually compromised the most important asset of all - strategic advantage.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;">So what&#39;s a better model? I am partial to think about these sorts of problems as free trade agreements. Each integration point should have a set of policies, and enforcement mechanisms that also include compensating transactions.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;">For example, did you know that in the US you can buy companies that trade on other exchanges through ADRs? You buy the ADR of say a French Telco which trades on a European exchange only you buy the ADR on the NYSE or Nasdaq. Then the French Telco issues you a dividend because you are a shareholder, but the French government withholds the dividend for foreign owners. Yet because there is a free trade agreement between the two countries, the US lets you write off the unreceived portion of the dividend on your taxes. (this may or may not be the case in US-France just an example). Anyway, its not a silver bullet but its an interesting strategy.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 09:40:20 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/coffee table">coffee table</category>
      <category domain="http://www.securityratty.com/tag/technology">technology</category>
      <category domain="http://www.securityratty.com/tag/american technology">american technology</category>
      <category domain="http://www.securityratty.com/tag/free trade agreement">free trade agreement</category>
      <category domain="http://www.securityratty.com/tag/trade">trade</category>
      <category domain="http://www.securityratty.com/tag/space technology">space technology</category>
      <category domain="http://www.securityratty.com/tag/french telco issues">french telco issues</category>
      <category domain="http://www.securityratty.com/tag/common coffee table">common coffee table</category>
      <category domain="http://www.securityratty.com/tag/information security policies">information security policies</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/is-that-a-coffee-table-or-a-munition.html">Is That a Coffee Table or a Munition?</source>
    </item>
    <item>
      <title><![CDATA[Confidentiality, Integrity, Availability - Pick Any Two]]></title>
      <link>http://www.securityratty.com/article/c60f46f9f63d51e4a5a9e84ddb44cfe9</link>
      <guid>http://www.securityratty.com/article/c60f46f9f63d51e4a5a9e84ddb44cfe9</guid>
      <description><![CDATA[Under Worm Assault, Military Bans Disks, USB Drives

The Defense Department's geeks are spooked by a rapidly spreading worm crawling across their networks. So they've suspended the use of so-called...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blog.wired.com/defense/2008/11/army-bans-usb-d.html">Under Worm Assault, Military Bans Disks, USB Drives</a></p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The Defense Department&#39;s geeks are spooked by a rapidly spreading worm crawling across their networks. So they&#39;ve suspended the use of so-called thumb drives, CDs, flash media cards, and all other removable data storage devices from their nets, to try to keep the worm from multiplying any further.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="font-size: 14px; line-height: 17px; "><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The ban comes from the commander of U.S. Strategic Command, according to an internal Army e-mail. It applies to both the secret&#0160;</span><a href="http://en.wikipedia.org/wiki/SIPRNET" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: #007ca5; text-decoration: none; outline-style: none; outline-width: initial; outline-color: initial; "><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: #007ca5; text-decoration: none; outline-style: none; outline-width: initial; outline-color: initial; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">SIPR</span></a><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;and unclassified&#0160;</span><a href="http://en.wikipedia.org/wiki/NIPRNET" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: #007ca5; text-decoration: none; outline-style: none; outline-width: initial; outline-color: initial; "><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: #007ca5; text-decoration: none; outline-style: none; outline-width: initial; outline-color: initial; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">NIPR</span></a><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;nets. The suspension, which includes everything from external hard drives to &quot;floppy disks,&quot; is supposed to take effect &quot;immediately.&quot; Similar notices went out to the other military services.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In some organizations, the ban would be only a minor inconvenience. But the military relies heavily on such drives to store information. Bandwidth is often scarce out in the field. Networks are often considered unreliable. Takeaway storage is used constantly as a substitute.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><p><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Its almost like we built out a bunch of systems and then connected them to huge networks without building security into the software or something.</span></div>]]></content:encoded>
      <pubDate>Fri, 21 Nov 2008 06:50:19 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/networks">networks</category>
      <category domain="http://www.securityratty.com/tag/worm assault">worm assault</category>
      <category domain="http://www.securityratty.com/tag/huge networks">huge networks</category>
      <category domain="http://www.securityratty.com/tag/worm">worm</category>
      <category domain="http://www.securityratty.com/tag/flash media cards">flash media cards</category>
      <category domain="http://www.securityratty.com/tag/military bans disks">military bans disks</category>
      <category domain="http://www.securityratty.com/tag/internal army e-mail">internal army e-mail</category>
      <category domain="http://www.securityratty.com/tag/nipr nets">nipr nets</category>
      <category domain="http://www.securityratty.com/tag/military relies heavily">military relies heavily</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/confidentiality-integrity-availability-pick-any-two.html">Confidentiality, Integrity, Availability - Pick Any Two</source>
    </item>
  </channel>
</rss>
