<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>darkweb &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/darkweb/</link>
	<description>Feed of posts on WordPress.com tagged "darkweb"</description>
	<pubDate>Wed, 10 Feb 2010 15:51:59 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Episodes 106 and 107- January 31, 2010 ]]></title>
<link>http://datasecurityblog.wordpress.com/2010/01/31/episodes-106-and-107-january-31-2010/</link>
<pubDate>Sun, 31 Jan 2010 17:01:58 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2010/01/31/episodes-106-and-107-january-31-2010/</guid>
<description><![CDATA[After some experiments with posting our new radio show, we return to our classic podcast sound.   If]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><!--[if gte mso 9]&#62;   72 1024x768  &#60;![endif]--><!--[if gte mso 9]&#62;  Normal 0   false false false          &#60;![endif]--><!--[if gte mso 9]&#62;   &#60;![endif]--><!--[if !mso]&#62;--></p>
<p class="MsoNormal">After some experiments with posting our new radio show, we return to our classic podcast sound.   If you were a fan of the Data Security Podcast, you will recognize the familiar sound in The CyberJungle from now on. Thanks for enduring the experimental phase.  We tried to edit out portions where the radio station played popular music under our voices.  Legally necessary, but we acknowledge that the result was choppy. There are also certain required live radio elements made the podcast versions longer than they needed to be.</p>
<p>If want the full radio show,   radio station KOH can legally post it and they retain <a title="koh on demand page" href="http://www.kkoh.com/sectional.asp?id=36169" target="_blank">full radio versions</a> of The CyberJungle.  And of course, you can  <a title="listen live  on saturdays" href="http://www.thecyberjungle.com/listen.php" target="_blank">listen  live on Saturday mornings</a>.  If you&#8217;re interested in a <a title="where to listen to the podcast" href="http://http://www.thecyberjungle.com/listen.php" target="_blank">shorter show with just the meat and potatoes, get it here on our website</a>.</p>
<p>On with the show notes:</p>
<p class="MsoNormal"><a title="su root rob lee" href="http://www.thecyberjungle.com/listen.php" target="_blank">Episode 106</a> is The CyberJungle’s su root interview for the technically advanced listener. Mandiant’s Rob Lee on the APT – advanced persistent threat.  Attacks used to be short-term and removable.  Now they burrow in for months or years, for the purpose of ongoing theft.  Episode 106 is the 30-minute, unedited version.  The short version of the interview can be heard in <a title="whole show 107" href="http://www.thecyberjungle.com/listen.php" target="_blank">episode 107</a>.  It starts roughly 40 minutes into the show.</p>
<p class="MsoNormal">
<p class="MsoNormal">Mandiant allows you to  <a title="APT report" href="http://www.mandiant.com/products/services/m-trends." target="_blank">download a copy</a> of Rob Lee&#8217;s report here.<span style="color:#6d5444;"> </span></p>
<p class="MsoNormal">
<p class="MsoNormal">In <a title="listen to 107" href="http://www.thecyberjungle.com/listen.php" target="_blank">Episode 107</a> we discuss the week’s top story &#8211; In “Digital Combat, U.S. Finds No Easy Deterrent&#8221;</p>
<p>A conference-room war game featuring sophisticated cyberattacks left top military officials perplexed. <a title="ny times cyberwar piece" href="http://www.nytimes.com/2010/01/26/world/26cyber.html" target="_blank">This article</a> discusses the apparent head-scratching in the Pentagon over how to respond to digital threats to national security. The problem – at least in part – seems that the U.S. government is still using the language of conventional war.  Two things are troubling. First, a gee-whiz quality to this piece suggests that this is the first time the U.S. military is considering these challenges. It’s certainly not, but the portrayal of top military brass as stuck in low gear on this issue is unsettling at best. Second, it muses about an attack on the grid, OR the banking system, OR the emergency communication system.  Doesn’t venture any possibility of a “digital pearl harbor”  featuring these events simultaneously.</p>
<p style="text-align:justify;">We also talked with Peter Eckersly of <a title="electronic frontier foundation" href="http://www.eff.org" target="_blank">EFF</a>. He’s heading up a project that measures your computer’s unique configuration&#8230;. and calculates whether you’re easy to track (even when you shut off cookies and do the other “prudent” things that should prevent tracking, but don’t). EFF is <a title="panopticlick eff" href="http://panopticlick.eff.org" target="_blank">seeking participants in this analysis</a>. You can get a uniqueness rating ad participate in the experiment. And no, they will not use your computer’s fingerprint for any other purpose.</p>
<p>Our conversation with Peter Eckersly starts about 15 minutes into <a title="whole show 107" href="http://www.thecyberjungle.com/listen.php" target="_blank">Episode 107</a>.</p>
<p>Speaking of tracking… the Google Toolbar appears to be spying on you even after you disable it.  No matter what Google says.  Read <a title="edelman on google tool bar" href="http://www.benedelman.org/news/012610-1.html" target="_blank">Ben Edelman’s account</a> of his own exploration of  this matter. Ben says he followed Google’s instructions and found he was still being scrutinized.</p>
<p>More news from the week:</p>
<p>International survey: IT Security managers see disaster looming. The takeaway from this 40-page report, <a title="report on critical infrastructure" href="http://resources.mcafee.com/content/NACIPReport" target="_blank">Critical Infrastructure in the Age of Cyber War</a> :  Top management just doesn’t get it.</p>
<p>70 percent of major companies are considering iPhone adoption.<a title="iphone use doubles" href="http://www.readwriteweb.com/enterprise/2010/01/a-new-era-for-corporate-cultur.php" target="_blank"> A New Era For Corporate Culture: iPhone Use Doubles in the Enterprise</a> Ira would rewrite this headline:  &#8220;Likelihood of secure business communication cut in half.&#8221;</p>
<p>Latest email scams tap into widespread interest in current events.  Like the one that tells colleagues  &#8220;I just wrote an article about the Chinese cyberattack. Hope you like it. Click here. &#8220;  The attached PDF file is the Chinese cyberattack.  See <a title="poisened pdf example" href="http://www.f-secure.com/weblog/archives/00001863.html" target="_blank">this example</a> from and earnest researcher at George  Washington University at F-secure.</p>
<p><a title="more email scams" href="http://darkreading.com/insiderthreat/security/app-security/showArticle.jhtml?articleID=222600285" target="_blank">More email scams</a> – we tried to deliver a package but you weren’t home. Click here for info. The bad guys are using physical addresses to discover email addresses.</p>
<p>Affluent individuals who live &#8216;the good life&#8217; are 43 percent more likely to be victims.  A <a title="affluent more likely victims" href="http://www.darkreading.com/story/showArticle.jhtml?articleID=222600185" target="_blank">survey of ID theft victims</a> who were hit based on activity profiling.</p>
<h2><span style="font-size:12pt;font-weight:normal;"> </span></h2>
<p><span style="font-size:12pt;font-weight:normal;"> </span></p>
<p><span style="font-size:12pt;font-weight:normal;"> </span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Show Notes: The CyberJungle Episodes 103 and 102 Jan 12 2010]]></title>
<link>http://datasecurityblog.wordpress.com/2010/01/16/show-notes-the-cyberjungle-episode-103-and-102-jan-12-2010/</link>
<pubDate>Sun, 17 Jan 2010 06:41:22 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2010/01/16/show-notes-the-cyberjungle-episode-103-and-102-jan-12-2010/</guid>
<description><![CDATA[Two episodes this week: Episode 103 is a podcast version of the live radio program. Episode 102 is o]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:left;"><strong>Two episodes this week: Episode 103 is a podcast version of the live radio program. </strong></p>
<p style="text-align:left;"><strong>Episode 102 is our &#8217;su root&#8217; podcast, in-depth technical interviews for the more advanced listener.<br />
</strong></p>
<p>Overview of <a title="Listen to Episodes 103 + 102" href="http://www.thecyberjungle.com/listen.php" target="_blank">this week&#8217;s program</a>.  More detailed notes and links provided below under &#8220;show notes.&#8221;</p>
<p>*Episode 103 the broadcast- Breaking News:  Do airport checkpoint whole body scanners have logging and auditing to enforce security and privacy policies?  We&#8217;re not sure after talking with a representative of one of the companies that makes the machines.  Seems the TSA may not have included an audit function in its specifications.   And, our guest tells us what happened to the “puffer machine” that would have detected the underwear bomber’s chemical payload on Christmas Day.</p>
<p>We also talked with an attorney from EPIC, the organization that sought and won the TSA specification documents revealing that body scanning machines are indeed capable of retaining and transmitting the naked images of the passengers they scan. This is NOT what TSA told the American public.</p>
<p>*Episode 102 (the su root interiews&#8230; requires above-average technology background). Click fraud is running rampant… ripping off internet advertisers.  A new, more serious attack that not only steals credit for click-through purchases, but hijack’s the end user’s computer.  This is a must-listen for marketing, security, and legal personnel.  Discussion on the live show, with the full interview online.</p>
<p>*Episode 102 (the su root interviews&#8230;requires above-average technology background.) A new user credential – your cell phone calls you for a voice print… and then lets you into your email, bank account, authorizes credit card purchases or VPN remote access.  Great idea?  We have an exclusive audio interview with the co-founder of the company.</p>
<p>–&#62; Listen This Week’s Show through our <a title="The CyberJungle" href="http://thecyberjungle.com" target="_self">Main Site</a></p>
<p><strong>Show Notes for Episode 103 of the CyberJungle</strong></p>
<p>*ZeroDay Flaw in some versions of Microsoft Internet Explorer (MSIE) web browser.  Microsoft&#8217;s TechNet site has posted detailed information about the flaw. If you have not checked your MSIE browser version, do it now. Launch MSIE, find the Help Icon (usually the far right menu/icon, depending on the version of MSIE you are running), and select About Internet Explorer. If you are not running MSIE verson 8, you need to update your browser. Read <a title="TechNet" href="http://blogs.technet.com/srd/archive/2010/01/15/assessing-risk-of-ie-0day-vulnerability.aspx" target="_blank">more here</a>. Update your browser to <a title="MSIE8" href="http://www.microsoft.com/nz/windows/internet-explorer/default.aspx" target="_blank">MSIE 8 here</a>.</p>
<p>* People around the world are searching the web for the latest updates on Haiti earthquake. Members of the Dark Web use major events like this to spread their malicious code. Read more on this attack at the <a title="Websense" href="http://securitylabs.websense.com/content/Alerts/3524.aspx" target="_blank">WebSense Security site</a>. Ira mentioned the <a title="Google Trends" href="http://www.google.com/trends" target="_blank">Google Trends site</a>, a site that tracks hot topics on The Web.</p>
<p>* Samantha had a conversation with Ginger McCall, Esq., with the Electronic Privacy Information Center (EPIC). They talked  about the DHS airport body scanners, and a Freedom of Information lawsuit by EPIC. Read more at <a title="EPIC" href="http://www.stopdigitalstripsearches.org/" target="_blank">this EPIC-sponsored site</a>.</p>
<p>* Samantha and Ira had a conversation Brook Miller, VP with <a title="Smiths Detection" href="http://www.SmithsDetection.com" target="_blank">Smiths Detection</a>, the makers of &#8220;the puffer&#8221; machine, and the whole body scanners.</p>
<p>* Samantha had a conversation with Dr. Kerry Kerry Nemovicher, Ph.D. about &#8220;The Human Firewall&#8221; event by  <a title="InfraGard" href="http://www.infragard.net" target="_blank">InfraGard</a>. This event takes place on Thursday, Jan 21st at Boomtown Casino, in Reno Nevada. This lunch event runs from 11.15am to 1.15pm. $15 donation when you <a title="PayPal InfraGard" href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&#38;hosted_button_id=8616944" target="_blank">reserve your ticket by Monday</a> at 9:00am, $20 at the door.</p>
<p><strong>Show Notes for Episode 102 of The CyberJungle, an &#8217;su root&#8217; program, in-depth technical interviews and analysis</strong></p>
<p>*Ira has a conversation with Dr. Ben Edelman, from the Harvard Business School, about a new type of online advertising &#8220;click fraud&#8221; that takes over customer&#8217;s computers. Read more on <a title="Ben Edleman" href="http://www.benedelman.org/news/011210-1.html" target="_blank">Dr. Edelman&#8217;s site</a>. On the main site you can listen to the full, detailed, and technical conversation. Look for the &#8220;su root&#8221; podcast (Episode 102) on the main site, <a title="The CyberJungle" href="http://www.thecyberjungle.com/" target="_blank">www.TheCyberJungle.com</a>.</p>
<p>* Ira has a conversation with Steven Dispensa, CTO and co-founder of <a title="PhoneFactor" href="http://www.phonefactor.com" target="_blank">PhoneTrust</a>, about voice print authentication. On the main site you can listen to the full, detailed, and technical conversation. Look for the &#8220;su root&#8221; podcast (Episode 102) on the main site, <a title="The CyberJungle" href="http://www.thecyberjungle.com" target="_blank">www.TheCyberJungle.com</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The CyberJungle Episode 101 - Jan 10 2010]]></title>
<link>http://datasecurityblog.wordpress.com/2010/01/10/the-cyberjungle-episode-101-jan-10-2010/</link>
<pubDate>Mon, 11 Jan 2010 05:19:03 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2010/01/10/the-cyberjungle-episode-101-jan-10-2010/</guid>
<description><![CDATA[Security, Your Privacy, and The Law On this week’s program: * Houston DA Tweets the names of people ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:center;"><strong>Security, Your Privacy, and The Law</strong></p>
<p>On this week’s program:</p>
<p>* Houston DA Tweets the names of people arrested for DUI<strong> </strong></p>
<p>* WiFi for passive aggressives</p>
<p>* You won&#8217;t believe the password to launch nuclear war</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player (for higher security, stream through FeedBurner, using the hyperlink below):</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fdataclonelabs.com%2Fsecurity_talkworkshop%2Fthecyberjungle_101.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 101</a> – Use Feedburner to listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall. The shows don’t always display on chronological order on Odeo.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li><a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> Award-winning Sunbelt Network Security Inspector a scalable and effective vulnerability scanner. Windows IT Pro Magazine readers chose SNSI as their Favorite Vulnerability Scanner for two years in a row. <a title="Sunbelt" href="http://www.sunbeltsoftware.com/Business/Sunbelt-Network-Security-Inspector/" target="_blank">Read more</a> here, and contact <a title="Data Clone Labs" href="http://www.dataclonelabs.com/" target="_blank">Data Clone Labs</a> for a test drive.</li>
</ul>
<p><strong>Show Notes for Episode 101 of the CyberJungle</strong></p>
<p>* Conversation: Ira and Samantha interview Houston civil rights attorney Randall Kallinen about the Houston Texas-area DA <a title="Tweeting DUIs" href="http://www.chron.com/disp/story.mpl/metropolitan/6802419.html" target="_blank">Tweeting the names of those arrested for DUI</a>.</p>
<p>*How Google <a title="Google collects info" href="http://royal.pingdom.com/2010/01/08/how-google-collects-data-about-you-and-the-internet/" target="_blank">collects information</a></p>
<p>*Google <a title="Near Me Now" href="http://googlemobile.blogspot.com/2010/01/finding-places-near-me-now-is-easier.html" target="_blank">Near Me Now</a> application</p>
<p>* Digital piracy <a title="ebook piracy" href="http://www.cnn.com/2010/TECH/01/01/ebook.piracy/" target="_blank">hits the book industry</a></p>
<p>* <a title="Airport Security" href="http://www.foxnews.com/scitech/2010/01/08/mind-reading-systems-change-air-security/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%253A+foxnews%252Fscitech+%2528Text+-+SciTech%2529" target="_blank">Mind-reading</a> at the airports</p>
<p>*WiFi for <a title="New use for WiFi" href="http://www.passiveaggressivenotes.com/2009/12/30/wifi-for-passive-aggressives/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+passiveaggressivenotes+%28the+passive-aggressive+notes+blog%29&#38;utm_content=Twitter" target="_blank">passive aggressive</a></p>
<p>*Nuclear launch <a title="Nuclear Passcodes" href="http://www.cdi.org/blair/permissive-action-links.cfm" target="_blank">passcodes</a></p>
<p>*Ransomware – <a title="Ransomware" href="http://www.f-secure.com/weblog/archives/00001850.html" target="_blank">buy back your own files</a>?</p>
<p>*One in ten botnets are <a title="Botnets" href="http://www.securityfocus.com/brief/1055" target="_blank">engaged in the Zues attack</a></p>
<p>*<a title="USB crypto flaw" href="https://www.ironkey.com/usb-flash-drive-flaw-exposed" target="_blank">Ironkey</a> CEO speaks about the USB crypto flaw</p>
<p>*<a title="FTC to FCC" href="http://arstechnica.com/tech-policy/news/2010/01/ftc-reminds-us-that-storing-data-in-the-cloud-has-drawbacks.ars" target="_blank">FTC says</a> FCC needs to consider the dangers of cloud computing</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 88, Jan 04 2010]]></title>
<link>http://datasecurityblog.wordpress.com/2010/01/03/data-security-podcast-episode-88-jan-04-2010/</link>
<pubDate>Mon, 04 Jan 2010 03:43:09 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2010/01/03/data-security-podcast-episode-88-jan-04-2010/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Bad guys buying services to evade anti-virus<strong> </strong></p>
<p>* Special announcement</p>
<p>* Our take on this week’s news</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player (for higher security, stream through FeedBurner, using the hyperlink below):</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fdataclonelabs.com%2Fsecurity_talkworkshop%2Fdatasecpodcast_88.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 88</a> – Use Feedburner to listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall. The shows don’t always display on chronological order on Odeo.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Award-winning Sunbelt Network Security Inspector a scalable and effective vulnerability scanner. Windows IT Pro Magazine readers chose SNSI as their Favorite Vulnerability Scanner for two years in a row. <a title="Sunbelt" href="http://www.sunbeltsoftware.com/Business/Sunbelt-Network-Security-Inspector/" target="_blank">Read more</a> here, and contact <a title="Data Clone Labs" href="http://www.dataclonelabs.com/" target="_blank">Data Clone Labs</a> for a test drive .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 88 of the Data Security Podcast</strong></p>
<p>* Tales From The Dark Web: Bad guys buying services evade anti-virus. Brian Krebs (formerly with The Washington Post) does his usual outstanding work on the topic, from his brand new blog. <a title="Krebs on Security" href="http://www.krebsonsecurity.com/2009/12/virus-scanners-for-virus-authors/" target="_blank">Read more here</a>.</p>
<p>* From Our Take on The News: Body scanning machines;  here&#8217;s a story from the UK that dismisses their effectiveness in cases where a guy stuffs a chemical explosive in his underwear. (But they are very effective at revealing the other junk in your underwear.) <a title="UK Independent" href="http://www.independent.co.uk/news/uk/home-news/are-planned-airport-scanners-just-a-scam-1856175.html" target="_blank">Read more here</a>.</p>
<p>Meanwhile, Logan International in Boston and the Newark Liberty Airport in New Jersey will both get the body imaging machines. (Both were points of origin for the September 11 attacks.) <a title="Star Ledger" href="http://blog.nj.com/ledgerupdates_impact/print.html?entry=/2010/01/newark_liberty_international_a_4.html" target="_blank">Read more here</a> from The Star Ledger. And <a title="Boston Globe" href="http://www.boston.com/business/articles/2009/12/29/tsa_promises_full_body_scanner_for_logan_airport/" target="_blank">read more here</a> from Boston Globe.</p>
<p>* From Our Take on The News: TSA nominee misled Congress about accessing confidential records. <a title="Washington Post" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/12/31/AR2009123102257.html" target="_blank">Read more here</a> from The Washington Post.</p>
<p>* From Our Take on The News:  How embarrassing!  The Chairman of the FCC sends a facebook spam. <a title="NY Times" href="http://bits.blogs.nytimes.com/2009/12/31/whoops-fcc-chairman-spams-facebook-friends/?ref=technology" target="_blank">Read more here</a> from The New York Times blog.</p>
<p>* Special Announcement:  The Data Security Podcast will go LIVE this week as the nation&#8217;s first  call-in talk show on security, privacy and the law. You can listen on a web stream or terrestrial radio every Saturday, starting this Saturday, Jan 9th from 10 a. m. until noon Pacific Time.  Be sure to tune into the web stream of KKOH-780am, here is a link to <a title="KKOH" href="http://www.kkoh.com" target="_blank">their site</a>, click on the&#8217; Listen Live&#8217; link on the upper right hand corner.</p>
<p>We are changing the name of the show to The CyberJungle. We will keep this site active, and we will keep the current iTunes site active for a while, as we transition to the new name and site.   We will  continue to post our interviews with security experts. The material that&#8217;s too technical for the radio will be posted here.</p>
<p>We want to thank all of you for  the support and feedback for the last 18 months. We are grateful that you chose to spend your time with us. Our sponsors have also been very good to us. If you enjoy the show, please try their products, and please let the know you heard about them from us.</p>
<p>A big thanks also to the management of KOH Radio. They &#8220;get it,&#8221; and we salute them for understanding that the time is right for this show.</p>
<div class="wp-caption aligncenter" style="width: 439px"><a href="http://images.radcity.net/6697/3372423.jpg"><img class=" " title="KKOH Call-In for The New Show" src="http://images.radcity.net/6697/3372423.jpg" alt="" width="429" height="84" /></a><p class="wp-caption-text">KOH Call-In for The New Show</p></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 85, Dec 14 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/12/14/data-security-podcast-episode-85-dec-14-2009/</link>
<pubDate>Mon, 14 Dec 2009 19:26:11 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/12/14/data-security-podcast-episode-85-dec-14-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* New surge in attacks targeting bank accounts<strong><br />
</strong></p>
<p>* Data security requires physical security</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fdataclonelabs.com%2Fsecurity_talkworkshop%2Fdatasecpodcast_85.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 85</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall. The shows don&#8217;t always display on chronological order on Odeo.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Award-winning Sunbelt Network Security Inspector a scalable and effective vulnerability scanner. Windows IT Pro Magazine readers chose SNSI as their Favorite Vulnerability Scanner for two years in a row. <a title="Sunbelt" href="http://www.sunbeltsoftware.com/Business/Sunbelt-Network-Security-Inspector/" target="_blank">Read more</a> here, and contact <a title="Data Clone Labs" href="http://www.dataclonelabs.com" target="_blank">Data Clone Labs</a> for a test drive<a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank"></a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 85 of the Data Security Podcast</strong></p>
<p><a href="http://www.amazon.com/OPEN-THIRTY-SECONDS-Cracking-America/dp/0975947923"><img class="alignright" title="Ira Speaks With Marc Weber Tobias" src="http://ecx.images-amazon.com/images/I/41t%2B0zo-duL._SL500_AA240_.jpg" alt="" width="240" height="240" /></a>* Ira talks with Marc Weber Tobias  about lock security. <a title="Marc's Blog" href="http://in.security.org" target="_blank">Read more</a> at the in.security.org blog site.  The book authored by Marc, mentioned in the segment, <a title="Open in Thrity Seconds" href="http://www.amazon.com/OPEN-THIRTY-SECONDS-Cracking-America/dp/0975947923/ref=sr_1_1?ie=UTF8&#38;s=books&#38;qid=1260813551&#38;sr=8-1" target="_blank">Open in Thirty Seconds</a>.</p>
<p>* Tales From The Dark Web:  New surge in bank stealing attacks, via SQL injection.  <a title="SQL Injection" href="http://www.theregister.co.uk/2009/12/10/mass_web_attack/" target="_blank">Read more</a> at The Register.  Part II: Top Cyber Attack Vectors of 2009, as documented by Verizon. <a title="Verizon Report" href="http://www.verizonbusiness.com/resources/security/reports/rp_2009-data-breach-investigations-supplemental-report_en_xg.pdf" target="_blank">Read the report here</a>.</p>
<p>* From Our Take on The News: It’s confirmed Cybercriminals are now hiring hit men just like the real mafia. Read more at <a title="LawFuel" href="http://lawfuel.com/show-release.asp?ID=24289" target="_blank">LawFuel.com</a> <a title="LimeWire" href="http://cbs13.com/local/limewire.child.porn.2.1346842.html" target="_blank"></a>.</p>
<p>* From Our Take on The News:  Bruce Schneier (of <a title="Schneier on Security" href="http://www.schneier.com/blog/" target="_blank">Schneier on Security</a>) says he missed this story… and pointed us to the Top Ten Stories You Missed this year, posted by a publication called “Foreign Policy.  <a title="Passport Security" href="http://www.foreignpolicy.com/articles/2009/11/30/the_top_10_stories_you_missed_in_2009?page=0,6" target="_blank"> Here’s story number 7</a>.  How to get an American passport for a fake person..</p>
<p>* The Wrap:  Holiday attacks target Facebook users, <a title="Facebook Xmas Attacks" href="http://www.pandasecurity.com/usa/homeusers/media/press-releases/viewnews?noticia=9978" target="_blank">read more</a> from PandaLabs .</p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 84, Dec 7 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/12/07/data-security-podcast-episode-84-dec-7-2009/</link>
<pubDate>Mon, 07 Dec 2009 19:23:16 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/12/07/data-security-podcast-episode-84-dec-7-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Is there is a Russian connection to the &#8220;Climategate&#8221; attack?<strong><br />
</strong></p>
<p>* &#8216;Take Back Your Privacy&#8217; &#8212; A new nation-wide effort ramps up</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fdataclonelabs.com%2Fsecurity_talkworkshop%2Fdatasecpodcast_84.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 84</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 84 of the Data Security Podcast</strong></p>
<p>* Samantha has a conversation with Leslie Harris, president and CEO of The Center for Democracy and Technology. They are a D.C. group launching a consumer privacy campaign.  They want to educate consumers, pressure businesses, and push for a new law. <a title="Take Bake Your Privacy" href="http://www.cdt.org/takebackyourprivacy" target="_blank">Read more</a> at the &#8220;Take Back Our Privacy&#8221; area of their site.</p>
<p>* Tales From The Dark Web:  What, if any connection is there between Russian and the &#8220;Climategate&#8221; attack? Read more in the <a title="Climategate" href="http://www.dailymail.co.uk/news/article-1233562/Emails-rocked-climate-change-campaign-leaked-Siberian-closed-city-university-built-KGB.html" target="_blank">The UK Daily Mail story</a>. And, Adobe to release <a title="Adobe Patches" href="http://www.adobe.com/support/security/bulletins/apsb09-19.html" target="_blank">critical security patches</a> tomorrow .</p>
<p>* From Our Take on The News: <a title="Sting" href="http://www.wbtv.com/Global/story.asp?S=11623288" target="_blank"><span style="font-size:small;">SC police academy IT chief nabbed in Web sting</span></a>;  <a title="LimeWire" href="http://cbs13.com/local/limewire.child.porn.2.1346842.html" target="_blank"><span style="font-size:small;">&#8216;Accidental&#8217; Download Sending Man To Prison</span></a>.</p>
<p>* From Our Take on The News:  Department of Defense misses its own deadline for removing social security numbers from military ID cards.  <a title="Stars and Stripes" href="http://www.stripes.com/article.asp?section=104&#38;article=66444" target="_blank">Read about it at Stars and Stripes</a>.</p>
<p>* From Our Take on The News: Sprint received 8 million requests from Law Enforcement for GPS location data.  EFF is on the case, but this story has a fascinating origin… and an almost instantaneous rebuttal from Sprint.  (Which doesn’t deny the 8 million figure, but attempts to give it some context… The company is, of course, a regulated industry stuck in the middle, between the demands of its customers and the demands of congress, law enforcement and FTC… ). <a title="EFF" href="http://www.eff.org/deeplinks/2009/12/surveillance-shocker-sprint-received-8-million-law" target="_blank">Read more at EFF</a>.</p>
<p>* From Our Take on The News: <span style="font-size:small;">The economics of security advice; a very interesting MSFT research paper, and a related SANS posting. Read more at <a title="SANS" href="http://isc.sans.org/diary.html?storyid=7696" target="_blank">The SANS Internet Storm Center</a>.</span></p>
<p><span style="font-size:x-small;">* </span>The Wrap:  Many More Government Records Compromised in 2009 than Year Ago, Report Claims. <a title="Databreaches.net" href="http://www.databreaches.net/?p=8691" target="_blank">Read more at databreaches.net</a> .</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 83, Nov 30 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/29/data-security-podcast-episode-83-nov-29-2009/</link>
<pubDate>Mon, 30 Nov 2009 06:01:04 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/29/data-security-podcast-episode-83-nov-29-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<div>
<div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* New highly damaging attack plays on the very fear of being attacked<strong><br />
</strong></p>
<p>* Stopping insider attacks with the right internal controls</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_83.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 83</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 83 of the Data Security Podcast</strong></p>
<p>* Ira has a conversation with Cheryl Traverse President/ Chief Executive Officer with <a title="Xceedium.com" href="http://www.xceedium.com/en/" target="_blank">Xceedium</a>, a company that provides centralized, secure IT operations management.  Ira and Cheryl talk about the controls that protect against insider threats, and help put organizations in compliance with data security and privacy mandates.</p>
<p>* Tales From The Dark Web:  Bank attacks hides in &#8217;software update&#8217; links. This attack combines the fear of not properly patching with attacks that empty business bank accounts. Hat tip to the story in <a title="Bank attacks hide in software update links" href="http://darkreading.com/security/attacks/showArticle.jhtml?articleID=221901213" target="_blank">Darkreading.com</a> .</p>
<p>* From Out Take on The News: Reuters news story on the <a title="Cyber breaches are a closely kept secret" href="http://www.reuters.com/article/ousivMolt/idUSTRE5AN4YH20091124" target="_blank">under-reporting of cyber attacks</a>.</p>
<div class="wp-caption alignright" style="width: 260px"><img title="What Happens In Vegas...Goes Where??" src="http://cache.vegas.com/attractions/on_the_strip/images/welcomesign.jpg" alt="" width="250" height="188" /><p class="wp-caption-text">What Happens In Vegas...Goes Where??</p></div>
</div>
<p>* From Our Take on The News: Las Vegas Metro Police admits to large databreach of background check data.  Hat tip to excellent work by <a title="Metro Data Breach" href="http://www.lasvegassun.com/news/2009/nov/28/metro-admits-release-data/" target="_blank">The Las Vegas Sun newspaper</a>.</p>
<p>*  From The Wrap: We comment on the news that the <a title="Ikee Worm Writer" href="http://www.sophos.com/blogs/gc/g/2009/11/26/ikee-worm-author-job-iphone-app-firm/" target="_blank">Ikee worm author gets job at iPhone app firm</a>, as posted by Graham Cluley.</p>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 82, Nov 24 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/23/data-security-podcast-episode-82-nov-24-2009/</link>
<pubDate>Tue, 24 Nov 2009 06:31:20 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/23/data-security-podcast-episode-82-nov-24-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* FBI Report: Latest target for the cybercriminal? Law Firms and PR Firms<strong><br />
</strong></p>
<p>* Adobe Speaks: special segment with their senior security officers</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_82.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 82</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 82 of the Data Security Podcast</strong></p>
<p><img class="alignleft" title="Adobe Flash" src="http://www.adobe.com/devnet/images/160x160/logo_flashplayer.jpg" alt="Adobe Flash Logo" width="160" height="160" />* Ira has a conversation with two security officers at Adobe Systems about the allegations made by web security researcher Mike Bailey of unpatchable &#8220;Same Origin Flaws&#8221; in Adobe Flash.  Brad Arkin, Director of Product Security and Privacy, and Peleus Uhley, Senior Security Researcher give their take on Mike Bailey&#8217;s claims. Here are the links mentioned in the segment:</p>
<p style="padding-left:30px;">
<div style="padding-left:30px;">- Adobe Flash Player <a title="Flash White Paper" href="http://www.adobe.com/devnet/flashplayer/articles/flash_player10_security_wp.html" target="_blank">security white paper</a></div>
<p style="padding-left:30px;">- Browser Security Handbook, Part 2—Information on the <a title="Security Handbook" href="http://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy" target="_blank">Same-Origin Policy</a>.</p>
<p style="padding-left:30px;">-  <a title="Adobe Flash article" href="http://www.adobe.com/devnet/flashplayer/articles/secure_swf_apps.html" target="_blank"> Peleus Uhley’s article</a> on creating more secure Flash applications / “Understanding that SWFs are Code”</p>
<p>* Tales From The Dark Web: FBI WARNING: <a title="FBI Warning" href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221900096" target="_blank">U.S. LAW FIRMS AND PUBLIC RELATIONS FIRMS</a>.  That link is a copy of the <a title="FBI Warning" href="http://www.fbi.gov/cyberinvest/escams.htm" target="_blank">FBI posting</a>. The FBI does not contain a permanent link, so it may become hard to find as new stories are posted above this law firm alert.</p>
<p>* From Our Take on The News:  <a title="UMC Records Leak" href="http://www.lasvegassun.com/news/2009/nov/21/fbi-looking-umc-records-leak/" target="_blank">FBI looking at UMC records leak: Agent says ‘multiple federal laws’ might have been violated</a>. Hat tip to the Las Vegas Sun newspaper for the investigative reporting on this story.</p>
<p>* From Our Take on The News:  <a title="Symantec SQL Attack" href="http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/" target="_blank">Symantec exposed passwords, serials numbers;  SQL Injection, full database access</a>, from Romanian security researcher, Unu. Apologies for mis-spelling Unu&#8217;s name on the show.<a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank"><img class="    alignright" title="Microsoft Internet Explorer 6 Icon" src="http://blogs.zdnet.com/security/images/internet_explorer.png" alt="" width="70" height="74" /></a></p>
<p>*  From The Wrap:  Read the SANS Internet Storm Center&#8217;s reports on <a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">IE</a><a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">6 </a><a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">and IE7 web browser 0-Day Flaw</a>, and <a title="SANS" href="http://isc.sans.org/diary.html?storyid=7633" target="_blank">an Update</a>. No patch available (yet?), but Microsoft has some mitigation suggestions, linked through the Update.</p>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 81, Nov 20 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/20/data-security-podcast-episode-81-nov-20-2009/</link>
<pubDate>Fri, 20 Nov 2009 16:20:56 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/20/data-security-podcast-episode-81-nov-20-2009/</guid>
<description><![CDATA[EXCLUSIVE &#8211; For Friday November 20th, we depart from our regular format for those with an adva]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div id="post-1393">
<div>
<div>
<h3>EXCLUSIVE &#8211; For Friday November 20th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. </strong></h3>
<h3><strong>This is part two of two special editions featuring technical conversations with newsmakers on new counter measures to fight web drive-by downloads. Part two features</strong> Louis Hughes, Chairman and CEO of InZero Systems; and Yura Socolov, Director, IT Security of InZero Systems. InZero Systems has created a new hardware sandbox approach to this vexing security issue.</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 82.  Episode 82 is scheduled to post Sunday night /Monday morning, November 23rd, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 81:  InfoSec Conversation with InZero Systems on countering web drive-by downloads with a new hardware sandbox.</p>
<p>–&#62; Stream This Special Episode with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_81.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 81</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 81 of the Data Security Podcast</strong></p>
<p>Ira has an extended, technical conversation with Louis Hughes, Chairman and CEO of InZero Systems; and Yura Socolov, Director, IT security of InZero Systems. <a title="InZero" href="http://www.inzerosystems.com" target="_blank">InZero Systems</a> has an interested approach to fighting web drive-by downloads.</p>
</div>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 80, Nov 19 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/19/data-security-podcast-episode-80-nov-19-2009/</link>
<pubDate>Thu, 19 Nov 2009 14:23:31 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/19/data-security-podcast-episode-80-nov-19-2009/</guid>
<description><![CDATA[For Thursday November 19th, and Friday November 20th, we depart from our regular format for those wi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3>For Thursday November 19th, and Friday November 20th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. </strong></h3>
<h3><strong>These two special editions feature technical conversations with newsmakers on new counter measures to fight web drive-by downloads. Part one (this episode) features</strong> Pedro Bustamante, Senior Security Researcher with PandaSecurity. Part two will post tomorrow, with an EXCLUSIVE interview with the creators of a new hardware sandbox approach to this vexing security issue.</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 82.  Episode 82 is scheduled to post Sunday night /Monday morning, November 23rd, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 80:  InfoSec Conversation with Pedro Bustamante on countering web drive-by downloads.</p>
<p>–&#62; Stream This Special Episode with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_80.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 80</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 80 of the Data Security Podcast</strong></p>
<p>Ira has an extended, technical conversation with Pedro Bustamante, Senior Security Researcher with PandaSecurity.  Ira and Pedro will discuss web drive-by downloads. Here is <a title="Panda" href="http://cloudprotection.pandasecurity.com/" target="_blank">the link that Pedro mentions</a> in the segment.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 79, Nov 16 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/</link>
<pubDate>Mon, 16 Nov 2009 18:02:05 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* The odds of unknowingly logging onto an &#8216;evil twin&#8217; of your online banking site is increasing due to new broadband hazards.<strong><br />
</strong></p>
<p>* A revised Google Book Settlement was submitted to the courts . It doesn’t address privacy at all.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_79.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 79</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 79 of the Data Security Podcast</strong></p>
<p>* Program note about this week&#8217;s Conversation:  Ira will have an extended, technical conversation with Pedro Bustamante, Senior Security Researcher with PandaSecurity.  Ira and Pedro will discuss web drive-by downloads and other security issues in a special interview segment that will appear in a separate posting later this week. You can listen to the segment by streaming on this site, on iTunes, or other RSS feeds you use to listen to the Data Security Podcast.</p>
<p>* Tales From The Dark Web: What if you typed in your bank&#8217;s web address, but unknown to you, you were taken to an evil twin of your bank, controlled by cyber criminals? Well, the odds of that happening is increasing, due to Domain Name System (DNS)  issues in a significant number of broadband modems and routers.  Many other attacks can use these DNS flaws. Hat tip to the <a title="DNS Problems" href="http://www.pcworld.com/businesscenter/article/182168/dns_problem_linked_to_ddos_attacks_gets_worse.html" target="_blank">coverage</a> by Robert McMillan of the IDG News Service.</p>
<p>* From Our Take on The News:  Airport security in Saint Louis hassled one guy for half an hour, because he was carrying $4,700 in a cash box, which he placed on the x-ray conveyor belt and subjected to TSA scrutiny, as is required for all carry-on cargo.  The money was connected with his (legal) job with <a title="Campaign for Liberty" href="http://www.campaignforliberty.com/blog.php?view=14907" target="_blank">Campaign for Liberty</a>. The guy <a title="Steven Bierfeldt" href="http://contrarian.ca/tag/steven-bierfeldt/" target="_blank">recorded the abusive inquisition</a> on his iPhone.  The ACLU sued the TSA.  Now the airport security rules have changed. Read the coverage in <a title="Airport rules changed after Ron Paul aide detained" href="http://www.washingtontimes.com/news/2009/nov/11/rules-changed-after-paul-aide-detained-at-airport/" target="_blank">The Washington Times</a>.</p>
<p>* From Our Take on The News:  A flaw in Adobe Flash has a huge impact on web usage, especially those businesses that use Google Gmail/Google Apps/PHP Discussions, and sites the scores of sites that allow the upload of information to the site.  Mike Bailey, an expert on web application security, has an excellent infosec write up at the <a title="Foreground Security" href="http://www.foregroundsecurity.com/MyBlog/flash-origin-policy-issues.html" target="_blank">Foreground Security blog</a>.  Faster read in <a title="Flash Flaw" href="http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers" target="_blank">Computerworld</a>.</p>
<p>*  From The Wrap:  Revised Google Book Settlement was submitted to the court late Friday night. It doesn’t address privacy at all, even after EFF and other parties submitted a legal brief outlining legitimate fears that Google can track, and is likely to share individual book search information with law enforcement and anyone else who issues a subpoena. Google will retain book-search details, right down to page number and how long you lingered there, for every book you search.  <a title="Google Books" href="http://www.washingtontimes.com/news/2009/nov/11/rules-changed-after-paul-aide-detained-at-airport/" target="_blank">Read this account of the revised settlement</a>.</p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 78, Nov 09 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/</link>
<pubDate>Mon, 09 Nov 2009 05:40:21 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Why are web drive-by downloads proliferating like cockroaches?<strong><br />
</strong></p>
<p>* Sixty Minutes just covered a data security story. We rate the coverage.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_78.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 78</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 78 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks with Georg Hess, CEO and Co-Founder, <a title="Art of Defence" href="http://www.artofdefence.com/en" target="_blank">Art of D<span style="font-size:small;">efence</span></a>, about network scans versus web application scans. <a title="OWASP AppSec DC 2009" href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" target="_blank">OWASP AppSec DC 2009</a> takes place this week,  November 10-13th, in Washington, DC. The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Their mission is to make application security visible,  so that people and organizations can make informed decisions about true application security risks.</p>
<p style="text-align:center;"><a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009"><img class=" aligncenter" title="OWASP Conf 2009 Wash DC" src="http://www.owasp.org/images/9/92/Dc09.png" alt="OWASP Conf 2009 Wash DC" width="468" height="60" /></a></p>
<p>* Tales From The Dark Web:  Our take on the 60 Minutes segment Sabotaging The System:  Could hackers get into the computer systems that run crucial elements of the world&#8217;s infrastructure, such as the power grids, water works or even a nation&#8217;s military arsenal?  Be sure to <a title="60 Minutes" href="http://www.cbsnews.com/video/watch/?id=5578986n&#38;tag=api" target="_blank">watch this video segment</a> with the highest level non-technical boss in your organization. Also, make sure you, and your non-technical boss watch the &#8220;Web Extras&#8221; from this segment.  One of the stunning parts of the segment was the claim that private companies are more vulnerable because the companies only care about profit. Unlike government networks, which are more secure (uh?).  If that was the case, how can that be squared against the portion of the segment that revealed that the Feds lost 12TB of data from the DOD, DOE, DOC and possible NASA, in 2007? Where was the profit motive that stopped good security in those organizations? Security expert Robert Graham explores this, and other issues, in this posting: <a title="Brazil Grid Attacks?" href="http://erratasec.blogspot.com/2009/11/brazil-outage-not-caused-by-hackers.html" target="_blank">Brazil outage NOT caused by hackers</a>.</p>
<p>* From Our Take on The News:  New open-source voting technology – the developer is looking for jurisdictions to try it for free.  <a title="http://www.wired.com/threatlevel/2009/11/scantegrity" href="http://www.wired.com/threatlevel/2009/11/scantegrity" target="_blank">Read the Wired account</a>.</p>
<p>* From Our Take on The News:  A technical overview of the <a title="SSL flaw report" href="http://www.leviathansecurity.com/pdf/Renegotiating_TLS.pdf" target="_blank">newly discovered SSL vulnerabilities</a> and possible mitigation. Ben Laurie has excellent, technical <a title="SSL flaw blogs" href="http://www.links.org/?p=789" target="_blank">blog postings</a> about the SSL protocol flaw.</p>
<p>* From Our Take on The News:  Voters hate traffic surveillance cameras &#8212; proven in three U. S. cities in last week’s elections. (<a title="Washington Post" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/11/04/AR2009110404747.html" target="_blank">As if we still need proof</a>.) Great coverage of <a title="StopBigBrotherMD.org" href="http://www.stopbigbrothermd.org" target="_blank">traffic surveillance and related matters</a> in Maryland. (But the topic is universal).</p>
<p>* From The Wrap:  First iPhone worm found, <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank">details at F-Secure</a>.  A <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/cydia.htm" target="_blank">how-to for changing the SSH default password</a> in your jailbroken iPhone; one uses a computer connected to your iPhone to change the SSH settings.  Note: If you are not using a jailbroken iPhone, you don&#8217;t need to make changes to be protected from this particular attack.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Special Security Geek Edition: Interview with Marsh Ray, Discoverer of SSL Flaw]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/</link>
<pubDate>Fri, 06 Nov 2009 04:41:57 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/</guid>
<description><![CDATA[For Thursday November 5th, we depart from our regular format for those with an advanced understandin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3>For Thursday November 5th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. This episode is a one-topic special edition, </strong>providing coverage of a major man-in-the-middle flaw discovered in the SSL protocol (see, we told you it was for security geeks).</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 78.  Episode 78 is scheduled to post Sunday night /Monday morning, November 8th, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 77:  Conversation with Marsh Ray, discoverer of the new SSL flaw</p>
<p>–&#62; Stream This Special Episode Show with our Built-In Flash Player:<span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_77.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 77</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 77 of the Data Security Podcast</strong></p>
<p>Breaking news with an extended interview with Marsh Ray,  Senior Software Developer and Engineer with multi-factor security company <a title="Phone Factor" href="http://www.Phonefactor.com" target="_blank">PhoneFactor</a>.</p>
<div class="wp-caption alignleft" style="width: 195px"><img title="SSL Lock" src="http://www.deskdrivers.com/images/ssl-lock-icon.jpg" alt="SSL lock engaged, but is the connection secure?" width="185" height="113" /><p class="wp-caption-text">SSL lock engaged, but is the connection secure?</p></div>
<p>Marsh Ray discovered a major security flaw in the SSL protocol.   SSL is the most widely used encryption protocol on the internet.</p>
<p>Marsh Ray keeps a blog at <a title="Extendedsubset Blog" href="http://extendedsubset.com/" target="_blank">extendedsubset.com</a>.  He works for PhoneFactor, where you can read more about this <a title="PhoneFactor/SSL hazard" href="http://www.phonefactor.com/sslgap/" target="_blank">vulnerability in SSL</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 76, Nov 02 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/</link>
<pubDate>Mon, 02 Nov 2009 02:14:38 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Placing an online bet for the World Series? Employees of online betting sites might be selling customer data online. <strong><br />
</strong></p>
<p>* Google Book Search: What data is Google storing about readers of online books?</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_76.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 76</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 76 of the Data Security Podcast</strong></p>
<p>* Conversation:  Samantha talks with Rebecca Jeschke  of the <a title="EFF" href="http://www.eff.org" target="_blank">Electronic Frontier Foundation</a> (EFF). There are lots of privacy objections  to the Google book search settlement… EFF is leading the way on the privacy  objections. <a title="EFF" href="http://www.eff.org/press/archives/2009/09/08" target="_blank">Read about it here.</a> And <a title="EFF Legal Filing" href="http://www.eff.org/files/filenode/authorsguild_v_google/File%20Stamped%20Brf.pdf" target="_blank">here’s the legal document</a> filed by EFF… the  settlement hearing has been indefinitely postponed.</p>
<p>* Tales From The Dark Web:  Are online casinos leaking information about their customers? Hard to say, as we saw the original web posting about this is only available in the Google Cache. Here is <a title="TightPoker" href="http://shar.es/axiGT" target="_blank">a story from TightPoker.com</a> about the original posting. That story lists the original site at AustralianGambling.au, but the URL should be AustralianGambling.com.au .</p>
<p>* From Our Take on The News:  <a title="Metadata Case" href="http://arstechnica.com/tech-policy/news/2009/10/lobbyists-beware-arizona-rules-metadata-is-public-record.ars" target="_blank">Lobbyists beware: judge rules metadata is public record</a>. This story also talks about the Google metadata leak.</p>
<p>* From Our Take on The News: A MUST READ &#8211; Samantha writes at the <a title="Reasonable Reporter" href="http://reasonablereporter.wordpress.com/2009/10/29/social-engineering-high-tech-crimes-require-low-tech-legwork/" target="_blank">ReasonableReporter.com about social engineering</a> and how the technique is used in real life, and in the new movie Law Abiding Citizen:</p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/yFTlG-gxPAA&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/yFTlG-gxPAA&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
<p>* Wrap: Ira talked about the launch of <a title="Digital Forensics Magazine" href="http://tr.im/DQRA" target="_blank">Digital Forensics Magazine</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obama: $3.4B Toward 'Smart' Power Grid - What About Smart Security and Privacy for The Grid?]]></title>
<link>http://datasecurityblog.wordpress.com/2009/10/27/obama-3-4b-toward-smart-power-grid-what-about-smart-security-and-privacy-for-the-grid/</link>
<pubDate>Tue, 27 Oct 2009 13:05:42 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/10/27/obama-3-4b-toward-smart-power-grid-what-about-smart-security-and-privacy-for-the-grid/</guid>
<description><![CDATA[President Obama is annoucing $3.4b in stimulus monies for the &#8220;Smart&#8221; Power Grid today (]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>President Obama is annoucing $3.4b in stimulus monies for the &#8220;Smart&#8221; Power Grid today (see story <a title="Smart Grid" href="http://www.foxnews.com/politics/2009/10/27/obama-putting-b-smart-power-g rid/?test=latestnews" target="_blank">here</a>).</p>
<p>But, here is part of the story that is not getting much, if any, coverage: What are the security and privacy issues in deploying the Smart Grid and Smart Meters?</p>
<p>While I am not an expert on energy, I am knowledgable on the data security and privacy issues on this topic. This is an issue that could literally impact every citizen and business in the US, and impact the very foundation of the economy.</p>
<p>There are advanced technologies that could truly help secure the delivery of power. There are rules that can be put into place to help protect privacy. But, these items do not appear to be on the agenda today, and get little attention in day-to-day coverage.</p>
<p>Early deployments of the Smart Grid and Smart Meters have not made security and privacy a priority, much beyond lip service.</p>
<p>There will be some very negative outcomes for this program if  security and privacy are not truly &#8220;baked in&#8221; at the beginning of this next wave of deployments.</p>
<p>Written By: Ira Victor, GIAC G17799 GCFA GPCI GSEC   ISACA CGEIT</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 75, Oct 25 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/10/25/data-security-podcast-episode-75-oct-25-2009/</link>
<pubDate>Mon, 26 Oct 2009 04:44:05 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/10/25/data-security-podcast-episode-75-oct-25-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Everyone loves retail gift cards&#8230;they are quick and easy for consumers, and for web application &#8220;hackers.&#8221; <strong><br />
</strong></p>
<p>* Some Time Warner cable internet users are vulnerable to serious attacks &#8212; when will Time Warner release a fix?</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_75.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 75</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 75 of the Data Security Podcast</strong></p>
<div class="wp-caption alignright" style="width: 183px"><img class="  " title="Time Warner-supplied SMC cable modems: Open for Exploit?" src="http://www.smc-broadband.com/product_files/8014WN-RESthumb.jpg" alt="Time Warner-supplied SMC cable modem: open for exploit?" width="173" height="92" /><p class="wp-caption-text">Time Warner-supplied SMC cable modems: Open for Exploit?</p></div>
<p>* Conversation:  Ira talks with David Chen of Pip.io with an update on the critical vulnerabilities he discovered in a batch of Time Warner cable modems (made by SMC). TW now acknowledges the flaw, and they have made statements elsewhere that a fix is being deployed.  David Chen tells us that as of this past weekend the vulnerabilities remain.  Both David Chen and The Data Security Podcast have attempted to get an update on a fix. Time Warner cable has not replied to written requests from David Chen, or from this program.  David Chen is blogging with recommendation on how he thinks Time Warner Cable could mitigate these flaws&#8230; see  <a title="David Chen's Blog" href="http://chenosaurus.com/2009/10/26/time-warner-security-hole-still-wide-open/" target="_blank">his latest blog here</a>.<a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"> </a></p>
<p>* Tales From The Dark Web: Retail gift cards are potentially vulnerable to attacks. One that jumps out: web application attacks. <a title="Gift card report" href="http://research.corsaire.com/whitepapers/091021-attacking-magstripe-gift-cards.pdf" target="_blank">Read the entire report by Corsaire</a>.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News: Jurors are using smartphone from the jury box and the deliberation room – <a title="The Christian Science Monitor " href="http://www.csmonitor.com/2009/1021/p02s26-usju.html" target="_blank">potentially putting trial outcomes into jeopardy</a>.</p>
<p>* From Our Take on The News: <a title="Tresury Strategies" href="http://www.treasurystrategies.com/resources/pressReleases/TSIBankWillFail.pdf" target="_blank">Treasury Strategies Sees Possible Bank Failures Due to Fraud Losses</a></p>
<p>* The Kicker: <span style="color:#000000;"><a title="Long Island Teen" href="http://www.newsday.com/long-island/teen-s-video-snags-surprise-locker-thief-suspect-1.1542434" target="_blank">Long Island Teen Uses Hidden Video to Catch a Thief</a><br />
</span></p>
<div id="_mcePaste" style="overflow:hidden;position:absolute;left:-10000px;top:1054px;width:1px;height:1px;"><strong><span style="font-family:Verdana,Arial,Helvetica,sans-serif;color:#330066;font-size:small;">Modern Bank Robbers Could Shutter As Many As 10 Financial Institutions</span></strong></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 74, Oct 18 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/10/19/data-security-podcast-episode-74-oct-18-2009/</link>
<pubDate>Mon, 19 Oct 2009 17:24:53 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/10/19/data-security-podcast-episode-74-oct-18-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Now the bad guys are holding computer files for ransom if you don&#8217;t buy their phony anti-virus software. We have a workaround. <strong><br />
</strong></p>
<p>* Midyear elections are coming up, and the last thing the campaigns seem to think about is data security.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:<br />
<span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_74.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 74</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 74 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks with Gretchen Hellman, VP of Marketing for <a title="Election 2010 data security" href="http://www.vormetric.com/" target="_blank">Vormetric</a> about information security, the security issues with the new GOP web site, and election campaign security.<a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"> </a></p>
<p>* Tales From The Dark Web:  Watch the video by PandaSecurity that demonstrates a damaging new fake anti-virus that denies access to files and applications on victim systems unless a ransom is paid. The link below takes you to a video of the attack, and we have posted the keys to defeat the current variant of lock out.  If you work in IT/InfoSec please write an email to users with a warning, include the keys to unlock the software, and have the end user re-image their hard drive.</p>
<div class="wp-caption aligncenter" style="width: 250px"><a href="http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx"><img title="Rogueware with new Ransomware Technology" src="http://farm3.static.flickr.com/2642/3993133972_af6917dbf6_m.jpg" alt="Rogueware with new Ransomware Technology" width="240" height="69" /></a><p class="wp-caption-text">Rogueware with new Ransomware Technology</p></div>
<p><a href="http://vimeo.com/6949998">Click here to view the Rogueware with new Ransomware Technology™</a> video. The video comes to us from <a href="http://vimeo.com/pandasecurity">Panda Security</a>.  Take note that the malware icon disappears from the computer, and when it does, the attack is in place.  If you have a system that is infected with this attack, Panda has cracked the malware and has provided a list of working keys, which give access to the current variants of the TotalSecurity2009 attack:</p>
<p>WNDS-TGN15-RFF29-AASDJ-ASD65<br />
WNDS-U94KO-LF4G4-1V8S1-2CRFE<br />
WNDS-6W954-FX65B-41VDF-8G4JI<br />
WNDS-G84H6-S854F-79ZA8-W4ERS<br />
WNDS-TTUYJ-7UO54-G561H-J1D6F<br />
WNDS-A1SDF-6AS4D-RF5RE-79G84<br />
WNDS-A1SDF-RY4E8-7U98D-F1GB2<br />
WNDS-5SRTS-AEHUF-YA54S-D6F35<br />
WNDS-P9685-4H41A-DSW3A-2R64T<br />
WNDS-2AE32-1VFC2-B6894-G67YU<br />
WNDS-4TS8R-D6F5D-4JH8T-U4JK5<br />
WNDS-FGS5D-649RG-4S53D-412SF<br />
WNDS-452S3-ER00F-TSE35-S8FSD<br />
WNDS-SERFH-2642S-F04SD-64FG1<br />
WNDS-F40SA-1ER5H-4FG5D-F8412<br />
WNDS-5D1V2-XB0D5-JT1TY-97DS3<br />
WNDS-4BGY2-JY4KO-IT98Y-7HJ43<br />
WNDS-G8FB6-1V87S-DRT1S-63SRG<br />
WNDS-HFVDR-9844O-U54DA-5TBSC<br />
WNDS-89OF7-7324R-5SAD4-TG68U<br />
WNDS-JUYH3-24GHJ-HGKSH-FKLSD</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Danger Will Robinson! Danger! Additional insiders have stepped forward to shed more light into Microsoft&#8217;s troubled acquisition of Danger, its beleaguered Pink Project, and what has become one of <a title="Danger Story on AppleInsider" href="http://www.appleinsider.com/articles/09/10/12/microsofts_sidekick_pink_problems_blamed_on_dogfooding_and_sabotage.html" target="_blank">the most high profile Information Technology disasters</a> in recent memory.  <strong> </strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 73, Oct 11 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/</link>
<pubDate>Mon, 12 Oct 2009 04:57:36 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Major patching in store this week, due in part to flaws revealed this summer in Las Vegas? <strong><br />
</strong></p>
<p>* A fresh look at a Zeus banking attack counter-measure</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_73.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 73</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 73 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira takes a new look at a counter-measure for the latest wave of Zeus banking attacks in his conversation with Steven Dispensa, CTO of <a title="PhoneTrust" href="http://www.phonefactor.com/" target="_blank">PhoneFactor</a>. <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"><br />
</a></p>
<p>* Tales From The Dark Web: It&#8217;s like clockwork&#8230;two months after security events BlackHat and Defcon every summer in Las Vegas, we see a surge in patches for attacks that were highlighted at these events.  Microsoft Security Bulletin Advance <a title="Patch Tuesday" href="http://www.microsoft.com/technet/security/Bulletin/MS09-oct.mspx" target="_blank">Notification for October 13th 2009.</a> Security Advisory for <a title="Adobe Patches" href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank">Adobe Reader and Acrobat</a> for October 13th 2009, including the CVE number.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Danger Will Robinson! Danger!  Update on <a title="Sidekick Data Loss" href="http://forums.t-mobile.com/tmbl/?category.id=Sidekick" target="_blank">Danger&#8217;s Sidekick Massive Data Loss</a>.  Read the <a title="Sidekick Data Loss FAQ" href="http://forums.t-mobile.com/tmbl/board/message?board.id=Sidekick2&#38;thread.id=6095" target="_blank">FAQ</a> for tips on trying to salvage your data.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Computer Network <a title="Denial of Service Denial" href="http://www.sciencedaily.com/releases/2009/09/090930141541.htm" target="_blank">Denial Of Service Denial</a></p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News: Twitter shuts down legit security researcher, Mikko Hypponen.  Reports from <a title="Mikkoh Blog 1" href="http://www.f-secure.com/weblog/archives/00001786.html" target="_blank">his blog here</a>, and <a title="Mikkoh Blog 2" href="http://www.f-secure.com/weblog/archives/00001789.html" target="_blank">an update here</a>.</p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 503px"><a href="http://www.f-secure.com/weblog/archives/00001786.html"><img class="  " title="Twitter Shuts Legit Down Security Researchers Account" src="http://www.f-secure.com/weblog/archives/twitter_suspended4.png" alt="Twitter Shuts Legit Down Security Researchers Account" width="493" height="244" /></a><p class="wp-caption-text">Twitter Shuts Legit Down Security Researcher&#39;s Account</p></div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 72, Oct 04 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/10/04/data-security-podcast-episode-72-oct-04-2009/</link>
<pubDate>Mon, 05 Oct 2009 02:54:12 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/10/04/data-security-podcast-episode-72-oct-04-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Polymorphic malware &#8211; every time it attacks it has a new signature.<strong><br />
</strong></p>
<p>* The balance on your bank account looks find, too bad all your money&#8217;s gone.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_72.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 72</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 72 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks about a dangerous new twist to the banking attacks Yuval Ben-Izhak the CTO of security company Finjan. Here is the link to the <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank">Finjan Report on the new Zeus bank Trojan</a> mentioned in the segment.<a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"><br />
</a></p>
<p>* Tales From The Dark Web: Polymorphic malware &#8211; every time it attacks it has a different signature.  That means you anti-virus won&#8217;t recognize it.  Ira talked about the presentation at ISACA Security and Risk Conference by Stuart Staniford, the Chief Scientist at <a title="FireEye" href="http://www.fireeye.com" target="_blank">FireEye</a>.  Read the related <a title="APWK" href="http://www.antiphishing.org/reports/apwg_report_h1_2009.pdf" target="_blank">Anti-Phishing Working Group paper</a> on the topic.</p>
<p>* From Our Take on The News:  <span style="color:#000000;">From Wired.com &#8211; <a title="Wired.com" href="http://www.wired.com/threatlevel/2009/10/probe-targets-archives-handling-of-data-on-70-million-vets" target="_blank">Probe Targets Archives’ Handling of Data on 70 Million Vets</a></span></p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  <a title="TSA" href="http://www.tsa.gov/what_we_do/layers/secureflight/index.shtm" target="_blank">Secure Flight Program</a> by the TSA. EPIC (The Electronic Privacy Information Center)  follows the surveillance and profiling of airline passengers. Their most recent post on the TSA “Secure Flight” program was in 2007, when the organization recommended that “secure flight should be grounded” due to privacy concerns. The program is now being expanded to require airline passengers to provide their date of birth when they purchase an airline ticket.  See: <span style="font-family:Arial;"><a title="EPIC" href="http://epic.org/privacy/airtravel/secureflight.html" target="_blank">http://epic.org/privacy/airtravel/secureflight.html</a></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BREAKING NEWS - New Twist to Zeus Bank Trojan; Well-Known Penetration Tester at ISACA Conference Calls Revelation "Disastrous"]]></title>
<link>http://datasecurityblog.wordpress.com/2009/09/30/breaking-news-new-twist-to-zeus-bank-trojan-well-known-penetration-tester-at-isaca-conference-calls-revelation-disasterous/</link>
<pubDate>Wed, 30 Sep 2009 08:00:29 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/09/30/breaking-news-new-twist-to-zeus-bank-trojan-well-known-penetration-tester-at-isaca-conference-calls-revelation-disasterous/</guid>
<description><![CDATA[Reporting from the ISACA Security and Risk Management Conference in Las Vegas, we have breaking secu]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Reporting from the <a title="ISACA Las Vegas" href="http://www.isaca.org/Template.cfm?Section=ISRMC1&#38;Template=/ContentManagement/ContentDisplay.cfm&#38;ContentID=45178" target="_blank">ISACA Security and Risk Management Conference</a> in Las Vegas, we have breaking security news this morning.</p>
<p>Organized cyber criminals have added a new damaging element to an already viscous cyber attack. Yuval Ben-Itzhak, CTO of Finjan spoke by phone with the Data Security Podcast about a frightening new twist to the surge of bank account stealing Trojan attacks.</p>
<p>First some background:  This news program, and other media outlets, have been reporting in the last few months about a wave of bank account Trojans that have been stealing money from small and medium sized businesses, and local governments. Theses well organized cyber criminals have been combining web drive-by attacks, with unauthorized electronic funds transfers. The cyber criminals then use innocent money mules to launder the money.  The mules are typically lured into popular “make cash at home” schemes.</p>
<p>A construction company in Maine lost $588,000 from a recent attack, and they are now suing their bank.  It’s important to note that while consumers generally have 60 days to “unwind” an unauthorized electronic funds transfer, businesses accounts are only protected if the bank is alerted within 48 hours of an unauthorized transfer.  On The Data Security Podcast earlier this week, we interviewed the lawyer representing the construction company that suffered the $588,000 loss, see link below.</p>
<p>The Data Security Podcast can now report a dangerous new element to these attacks.  Ben-Izthak tells the Data Security Podcast that Finjin security researchers have seen the cyber criminals actually alter the “account view” online screens that a victim sees. Of course the altered screen views do not show suspicious transactions. This means that a business will probably lose the chance to catch unauthorized transactions within the 48 hour window.</p>
<p>Here’s the process &#8211; The business uses a computer(s) to do online business banking, and uses that same computer  to do web activities, email, and other standard business internet tasks. The attackers use those normal internet activities to plant a version of Zeus banking Trojan onto the business computer systems. These attacks are designed to by-pass most firewalls and many popular anti-virus programs.</p>
<p>The Trojan captures log-in info, challenge question/answers, and account numbers, right from the business computer systems…all the info the criminals need to conduct unauthorized electronic funds transfers.</p>
<p>Here’s the new twist: The attackers are now altering the web screens that display business account information. The bank’s computers are not altered, but rather the business customer’s view of their own accounts, as seen from their own computers.  This is known in security-speak as an integrity attack: when authorized persons are unable to trust the accuracy of their own information</p>
<p>Ira Victor, Co-Host of The Data Security Podcast, is covering the ISACA Las Vegas Conference and had an exclusive sit-down interview with well-known data security researcher and penetration testing expert &#8216;Famous Peter Woods&#8217; (as he is known), about this new attack.  Peter Woods is the COO of <a title="First Base" href="http://Firstbase.co.uk" target="_blank">First Base</a>, a security company in the UK.  Mr. Woods is also  a keynote speaker at the conference.</p>
<p>Peter Woods characterized this new variation of the Zeus bank Trojan &#8220;as a disaster.&#8221;  Mr. Woods recommended that business engage is a serious round of new user awareness training. When we asked Mr. Woods about technical counter-measures the banks could undertake, he questioned the willingness of many banks to invest in counter-measures that would truly be effective against these types of attacks. He thought that many banks would be more likely to add new legal disclosures in an attempt to indemnify themselves from financial loss.</p>
<p>Indeed, some banks are now putting new warnings on their web sites that encourage customers to &#8220;update anti-virus&#8221; and to &#8220;update system-patches.&#8221; Other speakers at the ISACA conference in Las Vegas generally agree that while that those measures are good for stopping certain attacks, they are mostly insufficient to thwart these newer types of attacks.</p>
<p>In <a title="Data Security Podcast 71" href="http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/" target="_blank">Data Security Podcast Episode 71</a>, Samantha Stone has an eye-opening interview with the attorney of the Maine construction company that lost $588,000 in a cyber attack, and is suing their bank. The cause of action? The plaintiff claims the bank breached it fiduciary duty when it failed to protect against the loss of the $588,000.  We suspect that a  variant of  the Zeus banking Trojan attack was used to steal the money.</p>
<p>Be sure to listen to subscribe to our RSS feed and listen Data Security Podcast Episode 72. When that show posts, it will include our interview with Yuval Ben-Yitzhak of Finjan. Here is the link to the <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank">Finjan Report on the new Zeus bank Trojan</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 71, Sep 28 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/</link>
<pubDate>Sun, 27 Sep 2009 23:39:54 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus five) On this week’s p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* $4k per day scamming fake Viagra? That&#8217;s just the tip of the iceberg.<strong><br />
</strong></p>
<p>* Business bank accounts are the targets of attacks, businesses are responding with lawsuits against banks.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_71.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 71</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 71 of the Data Security Podcast</strong></p>
<p>* Conversation: Samantha talks with attorney Dan Mitchell, of Bernstein Shur. His business client was the victim of one of the bank account attacks, resulting in a cash loss of over $500,000. His client is suing the bank. Coverage in <a title="Computerworld" href="http://www.computerworld.com/s/article/9138467/Construction_firm_sues_after_588_000_online_theft?source=rss_security" target="_blank">Computerworld</a>.</p>
<p>* Tales From The Dark Web: Pharma scams earn $4k per day for members of the Dark Wek.  Read that and a LOT more in Dimitry Samosseiko of SophosLabs<a title="Dmitry Samoseiko's Paper" href="http://www.sophos.com/sophos/docs/eng/marketing_material/samosseiko-vb2009-paper.pdf" target="_blank"> paper he presented to the Virus Bulletin Conference</a> in Geneva Switzerland. That event wrapped up last Friday.</p>
<p>* From Our Take on The News:  <a title="Twitter Attacks" href="http://lastwatchdog.com/waves-twitter-attacks-errode-trustworthiness-tweets/" target="_blank">Waves of Twitter attacks erode trustworthiness of Tweets</a>.</p>
<div class="wp-caption aligncenter" style="width: 310px"><a href="http://lastwatchdog.com/waves-twitter-attacks-errode-trustworthiness-tweets/"><img title="How much should you trust Tweets?" src="http://lastwatchdog.com/wp/wp-content/uploads/twitter_spam.gif" alt="How much should you trust Tweets?" width="300" height="225" /></a><p class="wp-caption-text">How much should you trust Tweets?</p></div>
<p>* From Our Take on The News:  How much of your business data should you trust to web mail?</p>
<p>* From Our Take on The News:  <a title="Cameras keep track of all cars..." href="http://seattletimes.nwsource.com/html/localnews/2009873854_medina16m.html" target="_blank">Cameras keep track of all cars entering Medina Washington.</a></p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 70, Sep 21 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/09/20/data-security-podcast-episode-70-sep-21-2009/</link>
<pubDate>Mon, 21 Sep 2009 04:28:48 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/09/20/data-security-podcast-episode-70-sep-21-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus five) On this week’s p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* Full access to anyone&#8217;s Facebook account for $100?</p>
<p>* Update on confidential data case in Maricopa County, AZ</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_70.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 70</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 70 of the Data Security Podcast</strong></p>
<p>* Tales From The Dark Web:  According to a PandaLabs report, for $100, members of the Dark Web will provide you with <a title="Panda Report on Facebook attacks" href="http://pandalabs.pandasecurity.com/archive/Your-Facebook-account-is-worth-_2400_100.aspx" target="_blank">the password on any Facebook user</a>.  What else are they doing with the data?</p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 455px"><a href="http://pandalabs.pandasecurity.com/archive/Your-Facebook-account-is-worth-_2400_100.aspx"><img class=" " title="$100 for a Facebook Users Password?" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/09/18/fb3a.png" alt="$100 for a Facebook Users Password?" width="445" height="257" /></a><p class="wp-caption-text">$100 for a Facebook User&#39;s Password?</p></div>
<p>* From the News:  The SANS Institute releases The Top Cyber Security Risks report.  <a title="SANS" href="http://www.sans.org/top-cyber-security-risks/" target="_blank">It&#8217;s a must read</a> .</p>
<p>* From the News: An Ohio children&#8217;s hospital <a title="Data Breach" href="http://www.pcworld.com/article/id,172185/article.html" target="_blank">experienced a data breach</a> when man tried to spy on ex-girlfriend using malware. Excellent coverage by Robert McMillan of IDG News Service.</p>
<p>*  From the News:   According to a <a title="McAfee Study" href="http://newsroom.mcafee.com/article_display.cfm?article_id=3562" target="_blank">new study</a>: eCommerce Merchants &#8220;&#8230;Can Convert 11% More Digital Window Shoppers by Adding Security Trustmarks&#8221;</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 69, Sep 14 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/09/13/data-security-podcast-episode-69-sep-14-2009/</link>
<pubDate>Sun, 13 Sep 2009 23:50:53 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/09/13/data-security-podcast-episode-69-sep-14-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus five) On this week’s p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* Beware the non-delivery email notice &#8211; it might really be an attack.</p>
<p>* Apple has added an anti-phishing feature to the new iphone but few people have been able to get it to work right.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_69.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 69</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 69 of the Data Security Podcast</strong></p>
<p>*  Ira talks with Michael Sutton, vice president of research at <a title="Zscaler" href="http://www.Zscaler.com" target="_blank">Zscaler</a> about issues with the new Apple iPhone anti-phishing feature in Safari for the iPhone.  Read the details on how to fix this issue in this <a title="LoopInsight" href="http://www.loopinsight.com/2009/09/12/apple-responds-to-iphone-anti-phishing-confusion/" target="_blank">LoopInsight.com</a> posting.</p>
<p>* Tales From The Dark Web: 2000% rise in non-delivery report spam, according to a <a title="NDR Spam" href="http://www.pandasecurity.com/usa/homeusers/media/press-releases/viewnews?noticia=9841" target="_blank">PandaLabs report</a>.</p>
<p>* From the News:  Brian Mastenbrook: <a title="Brian's Posting" href="http://brian.mastenbrook.net/display/36" target="_blank">How I cross-site scripted Twitter in 15 minutes, and why you shouldn&#8217;t store important data on 37signals&#8217; applications</a>. <a title="37 Signals responds" href="http://brian.mastenbrook.net/display/37" target="_blank">Update: Response from 37signals, including a change in their policy</a>. Also, check out <a title="Report Security Flaws" href="http://reportsecurityflaws.com" target="_blank">ReportSecurityFlaws.com</a> .</p>
<p>* Topics From the News:   Tracking employee internet usage;  iPhone man in the middle SSL attack;  Should public officials be banned from using Blackberry PIN-to-PIN, and other text messages during hearings?</p>
<p>Wrap: iPhone 3.1 breaks Exchange Sync for pre-3GS phones from the <a title="iPhone Exchange" href="http://www.dslreports.com/forum/r22999133-iPhone-31-breaks-Exchange-Sync-for-pre3GS-phones~start=20" target="_blank">discussion boards of DSL Reports</a>.</p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 170px"><img class=" " title="iPhone Exchange Headaches?" src="http://cache.gawker.com/assets/images/gizmodo/2009/09/ehangebrok.jpg" alt="iPhone Exchange Fail" width="160" height="240" /><p class="wp-caption-text">iPhone Exchange Headaches?</p></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 68, Sep 01 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/08/30/data-security-podcast-episode-68-sep-01-2009/</link>
<pubDate>Mon, 31 Aug 2009 00:09:34 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/08/30/data-security-podcast-episode-68-sep-01-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus five) On this week’s p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* New attacks against business bank accounts&#8230;. an earth-shaking recommendation from the banking industry.</p>
<p>* Hackers say they are gearing up for winter attacks &#8211; according to a survey of hackers at DefCon 2009.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_68.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 68</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 68 of the Data Security Podcast</strong></p>
<p>*  Ira talks with Michael Hamel, Chief Security Architect, with Tufin Technologies, about the survey of hackers he crafted for DefCon 2009. We cover:  <a title="Tufin" href="http://tufin.com/news_events_press_releases.php?index=2009-08-25" target="_blank">Hackers Take a Break This Summer Before Winter Hacking Spike</a>, and importantly, counter-measures to get prepared.</p>
<p>* Tales From The Dark Web: New attacks against business bank accounts&#8230;. an earth-shaking recommendation from the banking industry.</p>
<p>* From the News:   WPA WiFi encryption can now be cracked in one minute, according to new research.  Terms in the story:</p>
<p style="padding-left:30px;">WPA:  Wi-Fi Protected Access</p>
<p style="padding-left:30px;">WPA -TKIP: WPA with Temporal Key Integrity Protocol for encryption</p>
<p style="padding-left:30px;">WPA-AES:  WPA with Advanced Encryption Standard for encryption</p>
<p style="padding-left:30px;">WPA2:  Second Generation WPA encryption</p>
<p style="padding-left:30px;">WEP:  Wired Equivalent Privacy</p>
<p style="padding-left:30px;"><strong>Take-Away: WPA-TKIP and WEP is bad, um-kay?</strong> <strong>WPA-AES and WPA2 is good, um-kay?</strong></p>
<p>* From the News:  Federal <a title="WaPo Stimulus Story" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/08/20/AR2009082003970.html" target="_blank">Web Site Collects Data on Stimulus</a>. We report: Whose minding the security of the data?</p>
<p>* From the News: <a title="Stealth Laptop Case" href="http://technabob.com/blog/2009/08/26/macbook-pro-newspaper-case/" target="_blank"> Stealth-Laptop Bag</a></p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 370px"><a href="http://technabob.com/blog/2009/08/26/macbook-pro-newspaper-case/"><img class=" " title="Stealth Laptop Case" src="http://technabob.com/blog/wp-content/uploads/2009/08/laptopcaseformacbookproagainstcrime.jpg" alt="Stealth Laptop Case" width="360" height="241" /></a><p class="wp-caption-text">Stealth Laptop Case</p></div>
<p>Wrap Up Story:    <a title="Cyber Security Act" href="http://datasecurityblog.wordpress.com/2009/08/28/cybersecurity-act-is-federal-infosec-license-key-to-net-control/" target="_blank">Is Federal InfoSec License Key To ‘Net Control?</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 67, Aug 24 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/08/24/data-security-podcast-episode-67-aug-24-2009/</link>
<pubDate>Mon, 24 Aug 2009 13:42:58 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/08/24/data-security-podcast-episode-67-aug-24-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus five) On this week’s p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* The security lessons from Heartland data breach – what the newscasters didn&#8217;t tell you. Details on our Tales from The Dark Web segment.</p>
<p>* What if you discovered a web security flaw and their customer service staff ignored your alerts? An exciting announcement about a project to address this problem.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://s3.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_67.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 67</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 67 of the Data Security Podcast</strong></p>
<p>* EXCLUSIVE: Ira talks with Russ McRee of <a title="HolisticInfoSec.org" href="http://HolisticInfoSec.org" target="_blank">HolisticInfoSec.org</a> about major security issues. This conversation  project, <a title="ReportSecurityFlaws.com" href="http://ReportSecurityFlaws.com" target="_blank">ReportSecurityFlaws.com</a> .</p>
<p>* Tales From The Dark Web: What the other newscasters didn&#8217;t talk about with the news of an indictment of the Heartland / TJMaxx / 7-11 attacker, Albert Gonzales.</p>
<p>*From the News:  Web app attacks lead to possible breach of Law Enforcement data</p>
<p>*From the News:  <a title="SQL Injection" href="http://darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=219401046&#38;cid=RSSfeed" target="_blank">SQL Injection Dymisytified – A look at the attack and how to protect your applications from it</a></p>
<p>* From the News:  <a title="EMP Report" href="http://www.empcommission.org/docs/A2473-EMP_Commission-7MB.pdf" target="_blank">Report by  the Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack</a></p>
<p>* From the News:  Cyber-Ambulance Chasing (Can&#8217;t we think of another way to accomplish this?)</p>
<p><a title="Unspam" href="http://www.unspam.com" target="_blank"> Unspam Technologies</a> filed a &#8220;John Doe&#8221; lawsuit in federal court against cybercriminals who have been targeting banks. The unfortunate bank customers are now caught between the devil and the deep blue sea. Unspam&#8217;s suit seeks confidential account information from the financial institutions, as part of its strategy to track down the hackers.</p>
<p>Here&#8217;s the money quote from the coverage in the New York Times:  Even though Unspam&#8217;s lawyer &#8220;concedes he is unlikely ever to discover the names of the hackers&#8230; he hopes to get the details of the thefts, the names of victims and other information from the banks that can be used to improve security and possibly identify the hackers.&#8221;</p>
<p>We&#8217;re not sure we like this strategy. Who&#8217;s next?  Shall we force insurance companies to cough up individual medical records in order to prosecute hospital ID theft?</p>
<p>Read the story by <a title="NYT" href="http://www.nytimes.com/2009/08/20/technology/20hacker.html?_r=1&#38;scp=3&#38;sq=saul%20hansell&#38;st=cse" target="_blank">Saul Hansell in the New York Times</a>.</p>
<p>* Wrap: <a title="Vanishing Email" href="http://www.itp.net/news/565589-self-destructing-emails-now-a-reality" target="_blank">Vanishing eMail</a></p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/vQRXPG8T4Hs&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/vQRXPG8T4Hs&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
