<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>defcon &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/defcon/</link>
	<description>Feed of posts on WordPress.com tagged "defcon"</description>
	<pubDate>Sat, 28 Nov 2009 15:45:43 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[DEFCON tests AA]]></title>
<link>http://mywordlikefire.wordpress.com/2009/11/17/defcon-tests-aa/</link>
<pubDate>Tue, 17 Nov 2009 16:10:00 +0000</pubDate>
<dc:creator>mywordlikefire</dc:creator>
<guid>http://mywordlikefire.wordpress.com/2009/11/17/defcon-tests-aa/</guid>
<description><![CDATA[The saints at DEFCON know Scripture. This makes for an interesting give and take between Bible belie]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>The saints at DEFCON know Scripture. This makes for an interesting give and take between Bible believers and advocates of 12 Step spirituality. <strong>LINK:</strong> <a href="http://defendingcontending.com/2009/11/07/exposing-the-12-step-cult/#comment-15698">http://defendingcontending.com/2009/11/07/exposing-the-12-step-cult/#comment-15698</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 79, Nov 16 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/</link>
<pubDate>Mon, 16 Nov 2009 18:02:05 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* The odds of unknowingly logging onto an &#8216;evil twin&#8217; of your online banking site is increasing due to new broadband hazards.<strong><br />
</strong></p>
<p>* A revised Google Book Settlement was submitted to the courts . It doesn’t address privacy at all.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_79.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 79</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 79 of the Data Security Podcast</strong></p>
<p>* Program note about this week&#8217;s Conversation:  Ira will have an extended, technical conversation with Pedro Bustamante, Senior Security Researcher with PandaSecurity.  Ira and Pedro will discuss web drive-by downloads and other security issues in a special interview segment that will appear in a separate posting later this week. You can listen to the segment by streaming on this site, on iTunes, or other RSS feeds you use to listen to the Data Security Podcast.</p>
<p>* Tales From The Dark Web: What if you typed in your bank&#8217;s web address, but unknown to you, you were taken to an evil twin of your bank, controlled by cyber criminals? Well, the odds of that happening is increasing, due to Domain Name System (DNS)  issues in a significant number of broadband modems and routers.  Many other attacks can use these DNS flaws. Hat tip to the <a title="DNS Problems" href="http://www.pcworld.com/businesscenter/article/182168/dns_problem_linked_to_ddos_attacks_gets_worse.html" target="_blank">coverage</a> by Robert McMillan of the IDG News Service.</p>
<p>* From Our Take on The News:  Airport security in Saint Louis hassled one guy for half an hour, because he was carrying $4,700 in a cash box, which he placed on the x-ray conveyor belt and subjected to TSA scrutiny, as is required for all carry-on cargo.  The money was connected with his (legal) job with <a title="Campaign for Liberty" href="http://www.campaignforliberty.com/blog.php?view=14907" target="_blank">Campaign for Liberty</a>. The guy <a title="Steven Bierfeldt" href="http://contrarian.ca/tag/steven-bierfeldt/" target="_blank">recorded the abusive inquisition</a> on his iPhone.  The ACLU sued the TSA.  Now the airport security rules have changed. Read the coverage in <a title="Airport rules changed after Ron Paul aide detained" href="http://www.washingtontimes.com/news/2009/nov/11/rules-changed-after-paul-aide-detained-at-airport/" target="_blank">The Washington Times</a>.</p>
<p>* From Our Take on The News:  A flaw in Adobe Flash has a huge impact on web usage, especially those businesses that use Google Gmail/Google Apps/PHP Discussions, and sites the scores of sites that allow the upload of information to the site.  Mike Bailey, an expert on web application security, has an excellent infosec write up at the <a title="Foreground Security" href="http://www.foregroundsecurity.com/MyBlog/flash-origin-policy-issues.html" target="_blank">Foreground Security blog</a>.  Faster read in <a title="Flash Flaw" href="http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers" target="_blank">Computerworld</a>.</p>
<p>*  From The Wrap:  Revised Google Book Settlement was submitted to the court late Friday night. It doesn’t address privacy at all, even after EFF and other parties submitted a legal brief outlining legitimate fears that Google can track, and is likely to share individual book search information with law enforcement and anyone else who issues a subpoena. Google will retain book-search details, right down to page number and how long you lingered there, for every book you search.  <a title="Google Books" href="http://www.washingtontimes.com/news/2009/nov/11/rules-changed-after-paul-aide-detained-at-airport/" target="_blank">Read this account of the revised settlement</a>.</p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thank you, DEFCON]]></title>
<link>http://mywordlikefire.wordpress.com/2009/11/13/thank-you-defcon/</link>
<pubDate>Fri, 13 Nov 2009 16:47:21 +0000</pubDate>
<dc:creator>mywordlikefire</dc:creator>
<guid>http://mywordlikefire.wordpress.com/2009/11/13/thank-you-defcon/</guid>
<description><![CDATA[A late thank you to the saints at this faithful discernment blog for their support in this battle. ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A late thank you to the saints at this faithful discernment blog for their support in this battle. <strong>&#8220;Exposing the 12 Step Cult&#8221;</strong> placed the truth about the 12 Steps before many. <strong>LINK:</strong> <a href="http://defendingcontending.com/2009/11/07/exposing-the-12-step-cult/">http://defendingcontending.com/2009/11/07/exposing-the-12-step-cult/</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nom de code : Defcon]]></title>
<link>http://mpj2009.wordpress.com/2009/11/13/nom-de-code-defcon/</link>
<pubDate>Fri, 13 Nov 2009 11:39:57 +0000</pubDate>
<dc:creator>mpj2009</dc:creator>
<guid>http://mpj2009.wordpress.com/2009/11/13/nom-de-code-defcon/</guid>
<description><![CDATA[Las Vegas, centre incarné de tous les plaisirs, rime habituellement avec casinos et mariages à la mi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Las Vegas, centre incarné de tous les plaisirs, rime habituellement avec casinos et mariages à la minute. Pour un hacker, la ville américaine est davantage synonyme de paradis du piratage informatique, et ce, le temps d’un festival, <a href="http://www.defcon.org/index.html" target="_blank">la Defcon</a>. Tous les ans, au cœur de l’été, les hackers du monde entier se donnent rendez-vous pour partager leurs dernières trouvailles en matière de hacking. Conférences sur les dernières techniques de piratage sous Mac, affrontements entre hackers afin de déterminer le pirate le plus rapide dans le crochetage de systèmes de sécurité, concours de robotique sont autant d’activités proposées pour divertir le plus grand monde. Avec succès puisque la convention américaine attire aujourd’hui plus de 8.500 visiteurs.<!--more--></p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/L0C8bqRzK6o&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/L0C8bqRzK6o&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
<p>Mais qui dit piratage, dit infraction à la loi. Aux Etats-Unis, le <a href="http://www.justice.gov/criminal/cybercrime/ccmanual/01ccma.pdf" target="_blank">Computer Fraud and Abuse Act</a> protège les Américains contre le hacking depuis 1986. La loi n’a pas empêché la création de la Defcon par Jeff Moss en 1993.</p>
<p>La convention ne se déroule pas sans heurt pour autant. En témoigne les derniers incidents survenus en 2008. Un <a href="http://www.eff.org/press/archives/2008/08/09" target="_blank">groupe d’étudiants du Massachusetts Institute of Technology</a> (MIT) dévoile durant une conférence comment ne plus payer les transports en commun à Boston grâce au piratage. Devant une telle divulgation d’informations, le réseau de transports de Boston réagit les jours suivants en poursuivant en justice les étudiants concernés. La Defcon est certes un paradis, mais pas sans contrôle.</p>
<p> Cécilia Rowe</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[25 (geeky) Random Facts]]></title>
<link>http://geekgirlnotes.wordpress.com/2009/11/04/25-geeky-random-facts/</link>
<pubDate>Wed, 04 Nov 2009 03:19:59 +0000</pubDate>
<dc:creator>zgirl07</dc:creator>
<guid>http://geekgirlnotes.wordpress.com/2009/11/04/25-geeky-random-facts/</guid>
<description><![CDATA[&nbsp; I started tweeting on Chris Pirillo&#8217;s birthday (@chrispirillo) to help him be a trendin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>&#160;</p>
<ol>
<li>I started tweeting on Chris Pirillo&#8217;s birthday (@chrispirillo) to help him be a trending topic on Twitter, thanks to him I got my first followers. Thanks Chris.</li>
<li>I&#8217;m a PC (and Linux) period.</li>
<li>The one subject I always feared become my favorite: Physics.</li>
<li>My first computer was an Acer Windows 95, I learned to use it before my older brother and I was only in Kinder.</li>
<li>My favorite PC games of all time are: Buzzy the Knowledge Bug: The Jungle and Buzzy the Knowledge Bug: The Farm.</li>
<li>I secretly disliked math with a passion back in high school, now it&#8217;s what I do everyday =)</li>
<li>My Spring Break was spent in a lab writing code, the staff actually told me to go out and enjoy my break.</li>
<li>My secret favorite color is red.</li>
<li>I usually give my phone number in binary.</li>
<li>I strongly dislike Hotmail and love Gmail.</li>
<li>The blue whale of death scares me waaay more than the blue screen of death.</li>
<li>I seem to work better under pressure.</li>
<li>I gave my 8 year old nephew a lecture on Physics only to be called “brain washer” by my family because he says he wants to study Computer Science when he grows up. Not my fault science is fun.</li>
<li>I want to attend DEFCON sooo bad.</li>
<li>Back in the day I wanted to be an Astronomer and math scared me away, funny how things change.</li>
<li>I love science but I don&#8217;t really like Sci-Fi stuff.</li>
<li>My Taskbar HAS to be on the top. If its at the bottom I feel lost.</li>
<li>I have to change my desktop background every 3-4 days or I&#8217;ll go insane.</li>
<li>I&#8217;ve only crossed one thing off my Bucket List and that was: Solve a Rubik&#8217;s Cube.</li>
<li>I take my math notes in many colors, it makes math even more fun!</li>
<li>I would like to be stuck in an elevator.</li>
<li>I&#8217;ve had dreams where I&#8217;m writing code for my projects, AND the code actually worked.</li>
<li>I love jigsaw puzzles, I work on at least one in between quarters.</li>
<li>I learned my multiplication tables in one day, my dad said I wasn&#8217;t going to sleep until I knew all my 1-12&#8217;s. I&#8217;m very glad he did that.</li>
<li>My favorite number is five, 5^2 = 25 therefore this is why this is here.</li>
</ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jay Electronica- Defcon]]></title>
<link>http://backtopluto.wordpress.com/2009/10/25/jay-electronica-defcon/</link>
<pubDate>Sun, 25 Oct 2009 15:34:01 +0000</pubDate>
<dc:creator>BMR</dc:creator>
<guid>http://backtopluto.wordpress.com/2009/10/25/jay-electronica-defcon/</guid>
<description><![CDATA[Jay Electronica &#8211; Download &#8211; Defcon Yep&#8230;..a lot of people think Jay is the next be]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="aligncenter size-full wp-image-1071" title="jay-electronica" src="http://backtopluto.wordpress.com/files/2009/10/jay-electronica.jpg" alt="jay-electronica" width="491" height="316" /></p>
<p>Jay Electronica &#8211; Download &#8211; <a href="http://usershare.net/2DopeBoyz/pq2rckvoadif">Defcon</a></p>
<p>Yep&#8230;..a lot of people think Jay is the next best thing for sure&#8230;He is dope, but I&#8217;ll let you guys be the judge of that.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Johnny Get Your Gun: A Call for Peace]]></title>
<link>http://universalartists.wordpress.com/2009/10/21/johnnygetyourgun/</link>
<pubDate>Wed, 21 Oct 2009 17:09:22 +0000</pubDate>
<dc:creator>universalartists</dc:creator>
<guid>http://universalartists.wordpress.com/2009/10/21/johnnygetyourgun/</guid>
<description><![CDATA[Universal Artists, Int&#39;l. Supports Our Troops PROMOTE PEACE &#8220;I pray for my life every nigh]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div class="mceTemp mceIEcenter">
<div id="attachment_147" class="wp-caption aligncenter" style="width: 168px"><img class="size-full wp-image-147" title="SupportOurTroops" src="http://universalartists.wordpress.com/files/2009/10/supportourtroops1.gif" alt="Universal Artists, Int'l. Supports Our Troops" width="158" height="300" /><p class="wp-caption-text">Universal Artists, Int&#39;l. Supports Our Troops</p></div>
</div>
<div class="mceTemp mceIEcenter">PROMOTE PEACE</div>
<div class="mceTemp mceIEcenter"><em>&#8220;I pray for my life every night, as it&#8217;s another day  in hell, as I&#8217;m walking through the battlefield. Still wanting to come home, but I know that I can&#8217;t, so I just stick with it, because I know in my heart, this is for my country&#8230;&#8221; Johnny Get Your Gun </em></div>
<p>As the United States comes close to the end of yet another year mired down in what appears for all purposes to be a fruitless and senseless pursuit of security and freedom without solid basis or foundation in Iraq, it must ask itself, how much longer to wander aimlessly down this road without without clear end in sight? Swept into a dream state, a nightmare of neither sleep nor rest, it wanders pointlessly throughout a hostile land which hasn&#8217;t changed in culture or resentment since the close of the second world war and the dismantling of the days of naked colonialism.</p>
<p>In America&#8217;s blind pursuit of economic latitude, and longevity of the securement of reasonably priced crude, it has inadvertently fallen pray to a foe it had once believed itself worthy of side stepping the second time around, entrenchment and siege, such as it had experienced on the level of Vietnam. In spite of the U.S.S.R.&#8217;s history of similar suffering and beleaguer in their occupation of the troublesome and perilous nation of Afghanistan, the US continues its drive into the region, threatening to ignite the ire of a people legendary in defiance of any power which fails to recall its opposed mindset in search of its own sovereignty and freedom since the days of the Khyber Pass.</p>
<p>Throughout the sixties and early seventies, Generation X suffered the daily bombardment of images of the Vietnam War broadcast from pitch battle and directly piped into their living room&#8217;s television sets. The throngs of protestors, largely known today collectively as baby boomers, sought freedom from propaganda, secrecy, and war. They proceeded so loudly and defiantly, they unwittingly forced the proverbial powers behind the throne to take notice to the extent they would pay heed to such lessons and censor future generations of Americans.  Perhaps they&#8217;ve reverted to secrecy to stave the threat to national peace given the reality of polar extremes of political,  moral, and ethical thought, but their public reasoning seems veiled and questionable.</p>
<p>Again, as the year draws close to the end, we are left to ponder the question of an end to all of this. Do we truly believe this will draw to a close with any Congressional Act for withdrawal given the seeds we&#8217;ve planted throughout the region? Yes, for all purposes it will appear we&#8217;ve weathered the storm, but have we truly, and at what future cost? What does destiny hold for generations to come in a region notorious for religious, cultural, racial, and political conflict since the beginning of time.</p>
<p>Does the cradle of civilization reside within the borders of Iraq, or is it the bath of chaos, the source of churning conflict, and the slaughter mill of not only our youth but theirs?</p>
<p>In the sad, telling music video, &#8220;Johnny Get Your Gun,&#8221; written, directed, produced, and edited by Joe Stern-McGovern, and performed by A-Dub and Lil&#8217; Chase, the story told is that of a youth of today swept abroad into the conflict in Iraq. The video shows the progression and doomed fate of Johnny as he transitions from fear, insecurity, despair, and then oddly boldness, only to find his end at the conclusion story&#8217;s end. Narrated by his grieving friend (Lil&#8217; Chase), Johnny&#8217;s (A-Dub) sad letters home are read to his worried mother throughout the song&#8217;s chorus. It&#8217;s touching, heartfelt, and inevitable conclusion to a story thousands have come to realize in this tangible world.</p>
<p>Please join us now as Joe Stern-McGovern and Universal Artists, International, accompanied by Shaka Productions, present to you the beautiful and haunting music video, &#8220;Johnny Get Your Gun,&#8221;  a recurring theme which seems to trail America since the days of its inception. </p>
<p>When will we, or anyone else, ever truly be free? How long will this violence continue? Where is end in sight? How many more of our brothers, sisters, mothers, fathers, and friends will continue to bear this senseless grief in a muddied and oft questioned conflict? Support our troops, but who in their right mind could support a concept so miserable as war, by definition a pall on the blighted soul of mankind? </p>
<p><em>&#8220;Disconnected realities without proper analysis or sufficient information, blindly defended through violent means under questionable circumstances, and born on the backs and blood of our children in a distant land&#8230;Farewell Vietnam, hello Iraq, goodbye to our sons&#8230;and with a stroke of the brush, the world was painted red!&#8221;</em></p>
<p>Joe Stern-McGovern    </p>
<p>Support our troops, but think before you blindly support the cause. Ask yourselves, in a world with civilizations as advanced as ours, isn&#8217;t their any other means than war?</p>
<p>For more information, or to view the video, please visit us at <a href="http://www.myspace.com/universalartists">www.myspace.com/universalartists</a> or <a href="http://www.youtube.com/universalartistsintl">www.youtube.com/universalartistsintl</a>.</p>
<p>Coming soon! The debut of the Black Flock Gang: BFG! For more information, please visit them at <a href="http://www.univeralartists.net">www.univeralartists.net</a> under talent or at <a href="http://www.myspace.com/blackflockgang">www.myspace.com/blackflockgang</a>.</p>
<p>For more information regarding booking any of our acts, here or abroad, please write to <a href="mailto:universalartists@myspace.com">universalartists@myspace.com</a> or <a href="mailto:info@universalartists.net">info@universalartists.net</a>.</p>
<div id="attachment_148" class="wp-caption aligncenter" style="width: 110px"><a href="http://www.myspace.com/universalartists"><img class="size-full wp-image-148" title="adub default th_belopose-Editcopy" src="http://universalartists.wordpress.com/files/2009/10/adub-default-th_belopose-editcopy1.jpg" alt="A-Dub &#38; Lil' Chase" width="100" height="77" /></a><p class="wp-caption-text">A-Dub &#38; Lil&#39; Chase</p></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Departure of the Pentagon CISO]]></title>
<link>http://lewisshepherd.wordpress.com/2009/10/13/departure-of-the-pentagon-ciso/</link>
<pubDate>Tue, 13 Oct 2009 22:47:48 +0000</pubDate>
<dc:creator>lewisshepherd</dc:creator>
<guid>http://lewisshepherd.wordpress.com/2009/10/13/departure-of-the-pentagon-ciso/</guid>
<description><![CDATA[I&#8217;ve had the good fortune to work with talented folks in my (short) time in Washington, since ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I&#8217;ve had the good fortune to work with talented folks in my (short) time in Washington, since moving back East in 2002, particularly in the Intelligence Community and Department of Defense.  And one such fellow at DoD has been<a href="http://www.federalnewsradio.com/index.php?nid=35&#38;sid=1769067" target="_blank"> Bob Lentz</a>, the outgoing deputy assistant secretary of Defense for information and identity assurance &#8211; the Chief Information Assurance Officer and equivalent to a private-sector CISO.</p>
<p>I gave an interview this afternoon to Federal News Radio (AM 1500 in the DC area, worldwide at <a href="http://www.FederalNewsRadio.com">www.FederalNewsRadio.com</a>), on Bob&#8217;s tenure, and what will come next for DoD in the wake of his departure. You can <a href="http://www.federalnewsradio.com/index.php?nid=35&#38;sid=1785032" target="_blank">read the news story about the interview here</a>, or listen to the entire 15-minute interview as an mp3:</p>
<p style="padding-left:30px;"><a href="http://media.bonnint.net/wtop/16/1663/166392.mp3">Shepherd interview on Federal News Radio, 10/13/2009</a></p>
<p><!--more-->Not everything has gone perfectly, or even well, for Pentagon infosec during his tenure; we have been fighting several wars, declared and undeclared, real and cyber, during the past few years. It&#8217;s an unbelievably daunting mission, to secure the nation&#8217;s ability to defend herself and our most critical systems amid unrelenting attack.</p>
<p>But Bob has worked closely with the private sector on information security technological advances &#8211; he and I joined several leading Silicon Valley startup CEOs, leading-firm CISOs, and venture-capital entrepreneurs in the <a href="http://www.security-innovation.org/itsef/speakers.htm" target="_blank">Information Technology Security Entrepreneurs Forum</a>, or ITSEF.  He&#8217;s worked closely with DHS and NSA, including in the <a href="http://www.federalnewsradio.com/?sid=1669746&#38;nid=35" target="_blank">establishment of the Pentagon&#8217;s Cyber Command</a>. He has also taken a number of counter-intuitive approaches, ranging from <a href="http://newsblaze.com/story/2009071010110200002.pnw/topstory.html" target="_blank">getting involved with Black Hat and DEFCON</a>, to establishing jointly with the IC the Unified Cross Domain Management Office, or UCDMO. If you have the right credentials, visit the <a href="https://www.intelink.gov/sites/ucdmo" target="_blank">UCDMO SharePoint Collaboration Site (requires Intelink-U Access)</a>, or see their open web site at <a href="http://www.ucdmo.gov/">http://www.ucdmo.gov/</a>.</p>
<p>This week Bob himself published a great &#8220;farewell column&#8221; in Government Computer News, &#8220;<a href="http://gcn.com/articles/2009/10/09/robert-lentz-dod-farewell-column.aspx" target="_blank">5 Key Challenges to DoD&#8217;s Cybersecurity</a>.&#8221; The article includes policy advice for his successor and the Defense Department as a whole &#8211; but it is thoughtful advice that should be read by any CISO.  I&#8217;ll include his bullet-point list from the article: he writes, &#8220;If I had to list five of the biggest challenges that remain, my list would include&#8221;:</p>
<ul>
<li>The need to continuously harden the network, in this era of Web 2.0, cloud services, and increased mobile workforce and growing global requirements.</li>
<li>The whole area of Supply Chain Risk Management. As the threat changes, we need to adjust as well, which includes rolling out technologies that inspect and secure the supply chain.</li>
<li>Raising awareness across DOD and greater national security community on cyber resilience, so that commanders are prepared to operate in a contested cyber domain when communications are degraded or, worse, untrusted. The increased complexity of our technologies, coupled with our even greater dependence on them for mission success, make this an imperative.</li>
<li>The necessity of education, training and workforce manning for critical IT/IA skill sets.</li>
<li>And, again, the need to move to multi-factor and attribute-based identity assurance access for people, devices, data and applications.</li>
</ul>
<p>That third bullet could be read as a provocative statement (which in Washington terms means admitting the truth):<strong><em> Imperfection, in DoD!</em></strong>  Military commanders are going to have to put up with &#8220;untrusted&#8221; communications systems in &#8220;a contested cyber domain.&#8221;  That&#8217;s the harsh reality, and military commanders are on the front lines in facing it. Bob Lentz&#8217;s successor will find his boots challenging to fill.</p>
<p><a href="http://twitter.com/home/?status=new ShepherdsPi post by @lewisshepherd:+http://bit.ly/LC6HT" target="_blank">Share this post on Twitter</a></p>
<p><a href="mailto:?Subject=Interesting%20post%20on%20the%20Shepherds%20Pi%20blog&#38;Body=Thought you might enjoy this, http://lewisshepherd.wordpress.com/2009/10/13/departure-of-the-pentagon-ciso/">Email this post to a friend</a></p>
<p><!-- AddThis Bookmark Button BEGIN --><a title="Bookmark using any bookmark manager!" href="http://www.addthis.com/bookmark.php" target="_blank"><span style="text-decoration:none;"><img src="http://s9.addthis.com/button1-share.gif" border="0" alt="AddThis Social Bookmark Button" width="125" /></span></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 73, Oct 11 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/</link>
<pubDate>Mon, 12 Oct 2009 04:57:36 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Major patching in store this week, due in part to flaws revealed this summer in Las Vegas? <strong><br />
</strong></p>
<p>* A fresh look at a Zeus banking attack counter-measure</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_73.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 73</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 73 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira takes a new look at a counter-measure for the latest wave of Zeus banking attacks in his conversation with Steven Dispensa, CTO of <a title="PhoneTrust" href="http://www.phonefactor.com/" target="_blank">PhoneFactor</a>. <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"><br />
</a></p>
<p>* Tales From The Dark Web: It&#8217;s like clockwork&#8230;two months after security events BlackHat and Defcon every summer in Las Vegas, we see a surge in patches for attacks that were highlighted at these events.  Microsoft Security Bulletin Advance <a title="Patch Tuesday" href="http://www.microsoft.com/technet/security/Bulletin/MS09-oct.mspx" target="_blank">Notification for October 13th 2009.</a> Security Advisory for <a title="Adobe Patches" href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank">Adobe Reader and Acrobat</a> for October 13th 2009, including the CVE number.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Danger Will Robinson! Danger!  Update on <a title="Sidekick Data Loss" href="http://forums.t-mobile.com/tmbl/?category.id=Sidekick" target="_blank">Danger&#8217;s Sidekick Massive Data Loss</a>.  Read the <a title="Sidekick Data Loss FAQ" href="http://forums.t-mobile.com/tmbl/board/message?board.id=Sidekick2&#38;thread.id=6095" target="_blank">FAQ</a> for tips on trying to salvage your data.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Computer Network <a title="Denial of Service Denial" href="http://www.sciencedaily.com/releases/2009/09/090930141541.htm" target="_blank">Denial Of Service Denial</a></p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News: Twitter shuts down legit security researcher, Mikko Hypponen.  Reports from <a title="Mikkoh Blog 1" href="http://www.f-secure.com/weblog/archives/00001786.html" target="_blank">his blog here</a>, and <a title="Mikkoh Blog 2" href="http://www.f-secure.com/weblog/archives/00001789.html" target="_blank">an update here</a>.</p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 503px"><a href="http://www.f-secure.com/weblog/archives/00001786.html"><img class="  " title="Twitter Shuts Legit Down Security Researchers Account" src="http://www.f-secure.com/weblog/archives/twitter_suspended4.png" alt="Twitter Shuts Legit Down Security Researchers Account" width="493" height="244" /></a><p class="wp-caption-text">Twitter Shuts Legit Down Security Researcher&#39;s Account</p></div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[La chiave privata di PayPal? Pubblica!]]></title>
<link>http://armyz.wordpress.com/2009/10/09/la-chiave-privata-di-paypal-pubblica/</link>
<pubDate>Fri, 09 Oct 2009 10:51:00 +0000</pubDate>
<dc:creator>armyz</dc:creator>
<guid>http://armyz.wordpress.com/2009/10/09/la-chiave-privata-di-paypal-pubblica/</guid>
<description><![CDATA[Man in the middle &#8211; fonte OWASP - Dopo alcuni mesi (Moxie Marlinspike e Dan Kaminsky, Defcon e]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div class="mceTemp">
<dl class="wp-caption alignleft"><img title="Man in the middle" src="http://www.owasp.org/images/2/21/Main_the_middle.JPG" alt="Man in the middle - fonte OWASP -" width="279" height="155" /> Man in the middle &#8211; fonte OWASP -</dl>
</div>
<p style="text-align:justify;">Dopo alcuni mesi (<a title="Thoughtcrime.org" href="http://www.thoughtcrime.org/" target="_blank">Moxie Marlinspike</a> e <a title="Wired su Dan Kaminsky" href="http://www.wired.com/threatlevel/2009/07/kaminsky/" target="_blank">Dan Kaminsky</a>, Defcon e Blackhat) si riparla di una vulnerabilità alle implementazioni SSL (API crittografiche) che, di fatto, prestano il fianco ad un attacco di tipo man in the middle nonchè a tecniche di phishing.</p>
<p style="text-align:justify;">Perchè se ne <a title="ZeusNews su Transazioni PayPal a rischio" href="http://www.zeusnews.com/index.php3?ar=stampa&#38;cod=11120" target="_blank">riparla</a> dopo poco più di due mesi? E&#8217; proprio di questi giorni la <a title="Full discolsure: PayPal Certification and private RSA Key" href="http://seclists.org/fulldisclosure/2009/Oct/87" target="_blank">pubblicazione di un certificato (e chiave privata)</a> attribuito a PayPal carpita proprio grazie alla vulnerabilità descritta da <a title="Defeat SSL" href="http://www.blackhat.com/presentations/bh-usa-09/MARLINSPIKE/BHUSA09-Marlinspike-DefeatSSL-SLIDES.pdf" target="_blank">Moxie Marlinspike</a> al <a title="BlackHat USA 09" href="http://www.blackhat.com/html/bh-usa-09/bh-us-09-main.html" target="_blank">BlackHat USA nel luglio di quest&#8217;anno</a> (<a title="Video Defcon 17" href="https://media.defcon.org/dc-17/video/DEFCON%2017%20hacking%20conference%20presentation%20by%20Moxie%20Marlinspike%20-%20More%20Tricks%20for%20Defeating%20SSL%20-%20video%20and%20slides.m4v" target="_blank">vedi video dell&#8217;intervento al defcon 17</a>).</p>
<p style="text-align:justify;"><a title="Shashdot" href="http://it.slashdot.org/story/09/10/06/2118211/Null-Prefix-SSL-Certificate-For-PayPal-Released" target="_blank">Frutto di tecniche di parsing</a> datate e usate nelle librerie crittografiche dei client che implementano e usano lo strato SSL (per cui non solo browser web ma anche client di posta, instant messaging, client irc,VPN SSL, etc) e di tool appositi (sslsniff).</p>
<p style="text-align:justify;">In particolare, questa vulnerabilità sfrutta la struttura del certificato X.509 del certificato e le informazioni in esso contenute usandole a proprio piacimento in quel procedimento di validazione a cascata della fiducia.</p>
<p style="text-align:justify;">La catena di fiducia tra il sito interessato e la Certification Authority (CA) funziona come descritto sotto</p>
<p style="text-align:justify;"><strong>Root CA <span style="color:#ff0000;">-&#62;</span> Intermediate CA <span style="color:#ff0000;">-&#62;</span> Intermediate CA <span style="color:#ff0000;">-&#62;</span> .. <span style="color:#ff0000;">-&#62;</span> Intermediate CA <span style="color:#ff0000;">-&#62;</span> esempio.com</strong></p>
<p style="text-align:justify;">Cosa dovrebbe avvenire:</p>
<ol style="text-align:justify;">
<li>verifica che il nome del nodo foglia è lo stesso del sito a cui ci si sta collegando</li>
<li>verifica che il certificato è valido, non è scaduto, revocato, etc</li>
<li>Controllo della firma (signature)</li>
<li>Se tale firma della CA appartiene alla nostra lista di una Root CA trusted il processo di conclude positivamente altrimenti si ripetono nuovamente gli step dopo aver risalito la catena di un livello.</li>
</ol>
<p style="text-align:justify;">Questo è lo scenario incriminato:</p>
<p style="text-align:justify;"><strong>Root CA <span style="color:#ff0000;">-&#62;</span> Intermediate CA <span style="color:#ff0000;">-&#62;</span> Intermediate CA <span style="color:#ff0000;">-&#62;</span> .. <span style="color:#ff0000;">-&#62;</span>Intermediate CA <span style="color:#ff0000;">-&#62;</span> sitomalevolo.com <span style="color:#ff0000;">-&#62;</span> esempio.com</strong></p>
<p style="text-align:justify;">Purtroppo, questo scenario, nelle condizioni di vulnerabilità indicate nel paper di Marlinspike al Blackhat di Las Vegas, sembra essere del tutto lecito: le firme sono validate, i certificati non sono scaduti/revocati, il procedimento indicato di verifica si conclude con una Root CA trusted &#8220;embedded&#8221; incorporata nel browser.</p>
<p style="text-align:justify;">Questo significa però che abbiamo costruito un certificato <span style="color:#ff0000;">VALIDO</span> per <strong>esempio.com</strong> ma che in nessun modo rappresentiamo in quanto siamo legati a <strong>sitomalevolo.com</strong></p>
<p style="text-align:justify;">Affinchè questo funzioni, viene sfruttata la <a title="Paper SSL Defeat - Marlinspike" href="http://www.blackhat.com/presentations/bh-usa-09/MARLINSPIKE/BHUSA09-Marlinspike-DefeatSSL-PAPER1.pdf" target="_blank">debolezza </a>di una codifica del CN (Common Name) Subject del <a title="PKCS #10: Certification Request Syntax Standard" href="http://www.rsa.com/rsalabs/node.asp?id=2132" target="_blank">PKCS #10</a> in cui il campo (stringa) viene &#8220;chiuso&#8221; da un particolare valore <em>null</em> (<strong></strong>).</p>
<p style="text-align:justify;">Quando viene effettuato il controllo 1), in questo scenario vengono confrontate due stringhe di lunghezza potenzialmente diversa.</p>
<p style="text-align:justify;">Tenendo conto che la stringa si conclude con il carattere <strong></strong>, il parsing considera solamente i primi <em>n</em> caratteri fino al valore <em>null</em> (<strong></strong>).</p>
<p style="text-align:justify;">Quindi se in un certificato X509 è specificato di essere <a href="http://www.esempio.com/0sitomalevolo.com">www.esempio.com<span style="color:#ff0000;"><strong></strong></span>sitomalevolo.com</a> le verifiche vengono effettate sulla precedente stringa (fino al campo <strong></strong>) e l&#8217;indirizzo a cui vogliamo collegarci (<a href="http://www.esempio.com/">www.esempio.com</a>).<br />
A questo punto si hanno tutti gli elementi per effettuare un MITM che generi il certificato apposito e si interponga trasparentemente tra le parti (molte CA rilasciano dei certificati se il richiedente è l&#8217;owner specificato <span style="color:#ff0000;">DOPO</span> il valore <em>null</em>).</p>
<p style="text-align:justify;">Per quanto riguarda Mozilla, i <a title="Security advisor" href="http://www.mozilla.org/security/announce/2009/mfsa2009-42.html" target="_blank">security advisor</a> riportano di avere chiuso la falla a partire dalla versione di firefox 3.5 e 3.0.13 (<a title="Defeat SSL" href="http://www.h-online.com/open/SSL-trick-certificate-published--/news/114361" target="_blank">vedi variante attacco su 3.0.11 vulnerabile</a>), Thunderbird dalla 2.0.0.23, SeaMonkey dalla 1.1.18 e NSS dalla 3.12.3</p>
<p style="text-align:justify;">Al momento sembra che le crypto API di windows siano vulnerabili.</p>
<p style="text-align:justify;">Ci sono ripercussioni e impatti anche nel campo delle <a title="Mobile Security Lab" href="http://www.mseclab.com/" target="_blank">applicazioni <em>mobile</em></a>.</p>
<p style="text-align:justify;">PayPal ha nel frattempo <a title="PayPal sospende l'account di Marlinspike" href="http://www.theregister.co.uk/2009/10/06/paypal_banishes_ssl_hacker/" target="_blank">sospeso l&#8217;account di Moxie Marlinspike</a>.</p>
<p style="text-align:justify;">Raccomandazioni: massima attenzione sulle transazioni in https e scrivere manualmente il link sul browser (possibilmente firefox, aggiornato) e mai fidarsi di link specialmente contenute in messaggi di posta elettronica.</p>
<p style="text-align:justify;">_______<br />
<a title="Il Taccuino" href="http://blog.armandoleotta.com/2009/10/la-chiave-privata-di-paypal-pubblica/" target="_blank">Taccuino</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chilling of Security Researchers (Again) - Let's Fix It!]]></title>
<link>http://t3chlaw.wordpress.com/2009/10/07/chilling-of-security-researchers-again-lets-fix-it/</link>
<pubDate>Wed, 07 Oct 2009 02:17:03 +0000</pubDate>
<dc:creator>t3chlaw</dc:creator>
<guid>http://t3chlaw.wordpress.com/2009/10/07/chilling-of-security-researchers-again-lets-fix-it/</guid>
<description><![CDATA[Today it was reported that security researcher Moxie Marlinspike was &#8220;banished from PayPal]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Today it was reported that security researcher <a href="http://www.thoughtcrime.org/about.html">Moxie Marlinspike</a> was &#8220;banished from PayPal&#8221;.  <a href="http://www.theregister.co.uk/2009/10/06/paypal_banishes_ssl_hacker/">According to The Register</a>, he received an email which seemed to indicate he violated the acceptable use policy.  It further explained that he should remove PayPal logos from his site and submit and affidavit acknowledging that it has been done.</p>
<p>This action comes one day after someone <a href="http://www.theregister.co.uk/2009/10/05/fraudulent_paypay_certificate_published/">posted </a>a null-prefix certificate on the full-disclosure mailing list.  The <a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike">concept of this hack</a> was introduced by Moxie Marlinspike this summer in Las   Vegas during Black Hat and then again at Defcon 17.  I happened to have attended his brief at Black Hat and remember the buzz that resulted from his presentation.  The effect of the disclosure seemingly lost some of the shock factor after Dan Kaminsky <a href="https://media.blackhat.com/bh-usa-09/video/KAMINSKY/BHUSA09-Kaminsky-BlackOpsPKI-VIDEO.mov">gave a presentation</a> where he discussed this same vulnerability.  Mr.  Kaminsky commented that he had reached out to certificate authentication authorities.  So why does this problem still exist and more importantly why is a chilling action being taken against a security researcher, again?</p>
<p>This seemingly retaliatory action against a security researcher is not the first of its kind.  In 2008, three students at the Massachusetts Institute of Technology (MIT) were put under a gag order after it was discovered they were going to give a <a href="http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Anderson">talk at DEFCON 16</a> that would reveal vulnerabilities in Boston&#8217;s transit fare payment system.</p>
<p>Electronic Frontier Foundation (EFF), who defended the MIT students, were able to get a positive result for the three students but the problem of chilling researchers still exists.  EFF&#8217;s <a href="http://www.eff.org/issues/coders">Coder&#8217;s Rights Project</a> was established to defend researchers during these types of situations.  While they do great work, it is not a long-term solution.  We need something more concrete that can scale and be available to all researchers.</p>
<p>I propose creation of a safe harbor system where security researchers can reveal their findings to an objective third party (possibly US-CERT) prior (maybe 30 days) to publishing them to the public and in exchange receive some benefits and legal protections.</p>
<p>Without such a protection mechanism, security researchers will continue to be threatened by potential chilling effects that come with revealing vulnerabilities to the public.  In an age when cyber security is making the nightly news and is widely considered one of our greatest national security problem sets, we have a system that provides an obstacle to security research.</p>
<p>I am looking forward to discussion of this proposal and moving forward with trying to establish protections for security researchers.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hack in the Box Conference]]></title>
<link>http://cmchoatelaw.wordpress.com/2009/10/05/hack-in-the-box-conference/</link>
<pubDate>Mon, 05 Oct 2009 14:29:07 +0000</pubDate>
<dc:creator>C.M. Choate</dc:creator>
<guid>http://cmchoatelaw.wordpress.com/2009/10/05/hack-in-the-box-conference/</guid>
<description><![CDATA[Today marks the beginning of HITBSecConf2009&#8211;the Hack in the Box Security Conference&#8211;bei]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Today marks the beginning of <a href="http://conference.hitb.org/hitbsecconf2009kl/" target="_blank">HITBSecConf2009</a>&#8211;the Hack in the Box Security Conference&#8211;being held in Malaysia.  The topics sound threatening (&#8220;<a href="http://conference.hackinthebox.org/hitbsecconf2009kl/?page_id=400" target="_blank">Clobbering the Cloud</a>,&#8221; &#8220;<a href="http://conference.hackinthebox.org/hitbsecconf2009kl/?page_id=472" target="_blank">Attacking Interoperability</a>,&#8221; &#8220;<a href="http://conference.hackinthebox.org/hitbsecconf2009kl/?page_id=478" target="_blank">Bugs and Kisses: Spying on BlackBerry Users for Fun</a>,&#8221; and &#8220;<a href="http://conference.hackinthebox.org/hitbsecconf2009kl/?page_id=468" target="_blank">Defeating Software Protection with Metasm</a>&#8220;) but the conference is geared toward education and enhancement of security: &#8220;The main aim of our conference is to enable the dissemination, discussion and sharing of deep knowledge network security information.&#8221;  And while a large part of the conference is devoted to attacking interconnected data, whether it is stored in &#8220;<a href="http://cmchoatelaw.wordpress.com/2008/09/03/googleupdateexe-chrome-and-the-cloud/" target="_blank">the Cloud</a>,&#8221; or on seemingly more-secure local servers, there&#8217;s even a &#8220;<a href="http://conference.hackinthebox.org/hitbsecconf2009kl/?page_id=358" target="_blank">lock picking village</a>&#8221; that aims to show that even physical storage of data isn&#8217;t 100% secure.</p>
<p>It&#8217;s not like this is some sort of ultra-secret cabal (though some attendees are no doubt black hat);  the conference has a plethora of big-name sponsors, including IBM, Microsoft, Mozilla, and Google.  And the lessons learned from conferences like Hack in the Box and <a href="http://www.defcon.org/" target="_blank">DefCon</a> do have the tendency to create innovations which lead to greater security.  At the same time, however, it <em>is </em>rather like trying to plug a dam, because once one security hole is fixed, another is discovered.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online Discernmentalist Mafia - Lo-Fi Tribe ]]></title>
<link>http://rzhblog.wordpress.com/2009/10/02/online-discernmentalist-mafia-lo-fi-tribe/</link>
<pubDate>Fri, 02 Oct 2009 01:48:15 +0000</pubDate>
<dc:creator>rzhblog</dc:creator>
<guid>http://rzhblog.wordpress.com/2009/10/02/online-discernmentalist-mafia-lo-fi-tribe/</guid>
<description><![CDATA[The strange things that you find via a BING search &#8230;. maybe I should try BING more and GOOGLE ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://lofitribe.com/online-discernmentalist-mafia/">The strange things that you find via a BING search</a> &#8230;. maybe I should try BING more and GOOGLE less?  I have really enjoyed the latest postings on &#8220;Online Discernmentalist Mafia&#8221;.  I have to read it periodically as reading Online Discernment blogs tend to be so depressing that I need satire to cheer myself back up.  Another thing that cheers me up after getting depressed reading Online Discernment blogs is listening to Mark Driscoll or Tim Keller.  Not to say that listening to John Piper can cheer me back up too but John MacArthur is not always successful in cheering me up after getting depressed by reading too many <a href="http://en.wordpress.com/tag/crn/">Online Discernment blog articles</a>.</p>
<p>What is really depressing is seeing personal opinion passed off as somehow being spiritual discernment; sort of makes me think that I am still a member of the American Restoration Movement.</p>
<p>What really tends to depress me is reading the Biblical Thought blog.  There should be a warning on that blog stating reading this blog for too long of a period may depress you to the point of joining the Lutheran church and declaring Calvinism to be a non-Christian cult.</p>
<blockquote><p><a href="http://lofitribe.com/online-discernmentalist-mafia/">I just discovered another awesome blog.</a> It’s satirically titled <a title="Online Discernment Mafia" href="http://itodyaso.wordpress.com/">The Online Discernmentalist Mafia</a>. It didn’t take long before ODMAFIA made a <a href="http://lofitribe.com/online-discernmentalist-mafia/">regular reader out of me</a>. Great stuff. Just remember, it is satire. It is good satire. In fact, the author(s) have a disclaimer in the sidebar in clear view.</p></blockquote>
<blockquote>
<p style="padding-left:30px;text-align:justify;"><a href="http://itodyaso.wordpress.com/">Before you get all bent out of shape, please realize this is a satire site spoofing the so-called “discernment ministries” who deem themselves more worthy of Grace than the rest of us. So read and have fun! BTW, we are not against “good” discernment ministries that do actual real research and extend grace to others, only the bad ones.</a></p>
</blockquote>
<blockquote><p>Do check it out! Satire is good for the soul. I’m subscribing and I’m going to blogroll the site with a quickness.</p></blockquote>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sygaire &amp; Defcon - Yigitler]]></title>
<link>http://movingscene.wordpress.com/2009/09/25/sygaire-defcon-yigitler/</link>
<pubDate>Fri, 25 Sep 2009 12:42:01 +0000</pubDate>
<dc:creator>movingscene</dc:creator>
<guid>http://movingscene.wordpress.com/2009/09/25/sygaire-defcon-yigitler/</guid>
<description><![CDATA[And again it´s time for some music. After drinking my coffee, eating my Bifi and listening to the st]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>And again it´s time for some music. After drinking my coffee, eating my Bifi and listening to the stream of the great Discodiamant, I found a video of one of the two DJ´s on the web. Defcon together with Sygaire. Nice made of seventies dancing, mixed with strange sci-fi and martial arts scenes.</p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/TMW46END8to&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/TMW46END8to&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[50th "Beyond The Perimeter" Podcast HighLights]]></title>
<link>http://techbuddha.wordpress.com/2009/09/21/50th-beyond-the-perimeter-podcast-highlights/</link>
<pubDate>Mon, 21 Sep 2009 23:10:40 +0000</pubDate>
<dc:creator>amritw</dc:creator>
<guid>http://techbuddha.wordpress.com/2009/09/21/50th-beyond-the-perimeter-podcast-highlights/</guid>
<description><![CDATA[Not too long ago I embarked on a creating a podcast series that would provide more regularity than t]]></description>
<content:encoded><![CDATA[Not too long ago I embarked on a creating a podcast series that would provide more regularity than t]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of the sexual marketplace]]></title>
<link>http://fbardamu.wordpress.com/2009/09/21/the-future-of-the-sexual-marketplace/</link>
<pubDate>Mon, 21 Sep 2009 10:00:17 +0000</pubDate>
<dc:creator>Ferdinand Bardamu</dc:creator>
<guid>http://fbardamu.wordpress.com/2009/09/21/the-future-of-the-sexual-marketplace/</guid>
<description><![CDATA[We all know what&#8217;s happening in the West right now, but what&#8217;s going to happen in the ne]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>We all know what&#8217;s happening in the West right now, but what&#8217;s going to happen in the next decade or so in regard to the sexual marketplace? More importantly, how can a man plan for the changes that are coming? Fear not, my readers, for I am here to bring you in from the freezing cold of ignorance and fear into the fire-lit cabin of knowledge. Here are my prognostications for the coming years, based on current trends.</p>
<p>1) <strong>Increasing prevalence of polyamory, with moves to legalize polygamy.</strong> Not only has the &#8220;mancession&#8221; thrown a LOT of guys <a href="http://business.theatlantic.com/2009/07/its_not_just_a_recession_its_a_mancession.php" target="_self">out of work</a>, but with women making up the <a href="http://www.pbs.org/newshour/extra/features/july-dec02/college.html" target="_self">majority of college undergrads and graduates</a>, the number of men being shut out from the middle class is increasing at a rapid clip. With women genetically hardwired to <a href="http://www.thornwalker.com/ditch/devlin_shalit.htm" target="_self">seek men that are higher in status</a>, the depopulation of dudes from the professional classes is shrinking the number of men they are capable of being attracted to. As a result, the number of men who cut the mustard status-wise will be able to form their own harems. The West&#8217;s hypergamous purgatory is already coming into existence &#8211; for instance, John Edwards (hat tip: <a href="http://roissy.wordpress.com/2009/08/20/john-edwards-is-bringing-big-love-back/" target="_self">Roissy</a>) is openly <a href="http://www.foxnews.com/politics/2009/08/19/report-edwards-mistress-help-raise-love-child/?test=latestnews" target="_self">keeping his mistress in his house</a>:</p>
<blockquote><p>John Edwards will move the mother of his love child into his North Carolina neighborhood so he can help raise their 18-month-old baby, the National Enquirer reported Wednesday.</p>
<p>The Enquirer also reported that Elizabeth Edwards, who is stricken with cancer, was furious when her husband told her of his parenting plans.</p></blockquote>
<p>I fully expect the nattering nabobs of <span style="text-decoration:line-through;">negativism</span> feminism to make a push for legalized polygamy. They&#8217;re already clamoring for polyamory, as shown (hat tip: <a href="http://ozconservative.blogspot.com/2009/09/new-feminist-frontier.html" target="_self">Mark Richardson</a>) in <a href="http://www.feministing.com/archives/017592.html" target="_self">this Feministing post</a>:</p>
<blockquote><p>I&#8217;m currently in a relationship with a man I love dearly, and I have been for nearly 3 years. It&#8217;s going well, he&#8217;s marvelous, we get on great. There&#8217;s just one thing &#8211; this is a polyamorous relationship. He also has another girlfriend, who he&#8217;s been with for a long time. That in itself isn&#8217;t a problem. I knew about her before I entered into the relationship and I&#8217;ve never had a problem with polyamory, it suits me fine, we take suitable precautions in our sex lives and we&#8217;re always open and honest with each other about everything. The problem is in explaining this to my parents. My mother noticed that my boyfriend was listed as in a relationship with the other lady on a social networking site, and has the notion that she must be his ex and he just hasn&#8217;t changed his status. She keeps asking me why he&#8217;s still listed as being with her, I keep changing the subject but I want to be honest with her. I&#8217;m not sure if she&#8217;s ever come across the concept of polyamory and I really don&#8217;t know what her reaction will be at all. I want to convey that this relationship is every bit as committed as a monogamous one and just as loving. How do you go about explaining this kind of thing with no knowledge of the response you&#8217;ll get? What if the response is negative? Please help.</p></blockquote>
<blockquote><p>Answer their questions with patience. I also caution that words like polyamory may not work for the first conversation. Keep it simple. &#8220;Mom, I know you keep asking me about the woman who says she is in a relationship with Jack. They are in a relationship. I&#8217;ve always known about it. Jack and I are serious and committed and we see other people. We are open and honest with each other and this works really well for both of us.&#8221;</p>
<p>If she denigrates the relationship, I would point out ways that he has been great in the past. When he has been at family functions, when he has helped your family, how happy you are together.</p>
<p>And then, and this may be the most difficult part, let it go. It will take time for your mother to understand and accept this (just ask the majority of queer folks who eventually have accepting parents). Keep answering their questions, but also set boundaries. If either of them are rude to your boyfriend or questions his love for you, you can call a stop to that. Your relationship and partner deserves respect.</p>
<p>This is the last and most important part &#8211; prove them wrong by actions. Show them that for all of their preconceived notions of what a &#8220;real&#8221; relationship is, you and your man are happy and love each other. It takes time, but this will be the greatest convincer of all.</p></blockquote>
<p>From Mr. Richardson&#8217;s post:</p>
<blockquote><p>It also hints at the real preferences of the more serious feminists. The sexuality of men and women operates at different levels. At one level, male sexuality is naturally promiscuous and female sexuality is hypergamous (meaning that women have an instinct to be with the most dominant male). If human nature only operated at this level then monogamy would be exceptionally rare.</p></blockquote>
<blockquote><p>I wonder if there are serious feminists who have rejected the traditional family as patriarchal (or as an impediment to female autonomy) and who therefore seek to &#8220;liberate&#8221; female sexuality &#8211; which really means liberating the female instinct to hypergamy.</p>
<p>The family form which corresponds best to hypergamy is, of course, polygamy &#8211; as this gives the most women access to the small number of socially dominant men.</p></blockquote>
<p>When the first high court declares polygamy legal, we can officially pound that last nail into civilization&#8217;s coffin.</p>
<p>2) <strong>The collapse of marriage.</strong> As a general rule, people don&#8217;t get married unless <a href="http://blog.vdare.com/archives/2005/05/08/affordable-family-formation-the-neglected-key-to-gops-future/" target="_self">they can afford to</a>. For example, marriage rates and birthrates <a href="http://www.numbersusa.com/overpopulation/decadegraph.html" target="_self">tumbled</a> during the Great Depression but <a href="http://en.wikipedia.org/wiki/Post-World_War_II_baby_boom" target="_self">exploded</a> after the economy recovered following World War II. Men, already being <a href="http://fbardamu.wordpress.com/2009/07/20/two-revealing-observations-on-marriage/" target="_self">dissuaded</a> <a href="http://dontmarry.wordpress.com/" target="_self">from marriage</a> due to the feminist legal system, will definitely not bite once they&#8217;ve been economically devastated. Expect the rate of marriage to take a HUGE drop. Divorce will also fall, as marriage will be confined almost exclusively to the genteel upper classes.</p>
<p>3) <a href="http://fbardamu.wordpress.com/2009/08/06/george-sodini-and-the-contract-between-the-sexes/" target="_self"><strong>Sex-motivated rage killings</strong></a><strong> </strong><strong>will continue unabated, at the rate of one every other year at the least.</strong> Young women will continued to be <a href="http://fbardamu.wordpress.com/2009/08/25/jasmine-fiore-and-the-feminist-blood-tithe/" target="_self">killed by their sociopathic lovers</a> at the same rate.</p>
<p>4) <strong>The death of nightlife.</strong> It&#8217;s a given, in both mainstream culture and PUA circles, that bars and nightclubs are the primary venues in which men meet women and (hopefully) make sweet reproductive music. The problem is two-fold. One, bar-hopping and clubbing are money-intensive activities. If you&#8217;ve unemployed or have otherwise seen your income collapse, the nightlife budget is the first to go. As Roosh wrote <a href="http://www.rooshv.com/the-economics-of-sex" target="_self">a year ago</a>:</p>
<blockquote><p>I predict that in the next two years meeting girls in the cities hardest hit by the economy will be even more difficult for the average guy. With less disposable income girls are going to stay home more instead of going out. Empty bars and clubs mean guys will be more reliant on meeting girls through friends, family, Myspace, and work. There will be less pump and dumps as guys will want to keep what they managed to get, as they themselves are strapped for cash and meeting girls does cost money. The only guys immune will be those in college, who will graduate to a barren landscape—in more ways than one.</p></blockquote>
<p>Swap &#8220;guys&#8221; with &#8220;girls&#8221; and you have, in a peanutshell, what&#8217;s happening.</p>
<p>The other point pertains to clubs only &#8211; namely, seducing a club girl is nearly impossible if you aren&#8217;t an apex alpha or close to it. The atmosphere of nightclubs, depending on flash and looks, is something most guys can&#8217;t play to. You need to have a certain look, style, and attitude to pull consistently or even occasionally in clubs, and even if they have good game elsewhere, the club is a gigantic stumbling block that most dudes can&#8217;t overcome.</p>
<p>Combine this with the priciness of nightclubs and the recession, and you have a recipe for total market collapse. I predict that the number of nightclubs in cities will fall by half at the least, as the long lines of betas standing in line for an hour and plunking down their dollars for cover charges all so they can dance to shitty music, drink obscenely overpriced liquor, and hit on girls who do not wanted to be fucked by them vanish. Bars will also be hit, but not as severely, as they cost less and appeal to a wider market.</p>
<p>5) <strong>An explosion of interest in day game.</strong> The advantages of day game are so obvious it&#8217;s a surprise no one&#8217;s pounced on it. When you pick up girls during the daytime, you don&#8217;t have to deal with their bitch shields on at full blast, their cockblocking friends (as many girls are alone), gameless idiots hitting on them and giving them unwarranted boosts to their self-esteem, and the general jackassery of nightlife. Not only that, but approaching girls during the day is way cheaper then going to a bar or club. And yet, googling &#8220;day game&#8221; turns up no worthwhile information from seduction community websites &#8211; they are exclusively oriented around nightlife.</p>
<p>Going hand in hand with the coming collapse of the nightlife industry, I predict that guys interested in getting their knobs polished will focus their efforts on swooping girls while the sun is shining. The guru who writes a complete handbook on day game will be laughing all the way to the bank, laughing so hard he&#8217;ll shit himself, as his recalcitrant competitors recede into the darkness of irrelevance.</p>
<p>So knowing all of this, how can you, the humble reader, put yourself in a position of power? I have but one tip: <strong>LEARN GAME.</strong> If you are interested in having a sex life at all, you MUST have game. If you want to get married and possibly make babies, you MUST have game. If you want to do anything aside from have a five-fingered pants party, you MUST have game. Game is more important than getting a promotion at your job, your college education, or ANYTHING else in this regard. As <a href="http://www.singularity2050.com/" target="_self">the Fifth Horseman</a> <a href="http://roissy.wordpress.com/2009/08/05/game-can-save-lives/#comment-117676" target="_self">says here</a>:</p>
<blockquote><p>Moderate competence in Game is easily worth about the same SMV as having a net worth of $2 million. This is a rough estimate. Furthermore, no one can tax your Game, swindle you out of Game, or steal your Game in divorce court (as long as you don’t let this sap your confidence as a human being).</p>
<p>I define moderate competence in Game as the following 5 steps :</p>
<p>***1) Regular, consistent, and somewhat effortless ability to do approaches to women who are 8s or higher. This is the most important point of all, as without approaches, you will not create the opportunities to practice ANY other part of Game. This is also the filter that blocks most novices from ever progressing.</p>
<p>2) Ability to qualify the woman, as well as identify and pass her own tests easily. Be the first to end the phonecall, always be leaving, other time constraints, etc. The ability to use the occasional well-placed neg is valuable too.</p>
<p>3) Ability to run comfort and rapport for the requisite 6-8 hours. Have a lot of interesting stories, games, and other things to run on her.</p>
<p>***4) Ability to bridge from Day 1 to Day 2, and minimize flakes. This is important as flakes are frustrating, demoralizing, and discouraging. A lot of guys are very close to the brass ring, but this derails them in their quest for Game.</p>
<p>5) Ability to run competent seduction Game, after you get her alone. This is where Ross Jeffries NLP can be extremely useful (but not mandatory by any means).</p>
<p>1) and 4) cause the biggest frustration, paralysis, and ‘giving up’, hence the asterisks. But a man who becomes pretty good at these 5 points is ahead of 98% of all men, and is on par with a Beta who has $2 million in net worth (and is ahead of such a Beta if that Beta has no game and is suckered easily by feminine manipulation).</p></blockquote>
<p>The copulation arms race is at DEFCON 2, my friends. Learn game or be wiped out in the ensuing nuclear fires.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Defcon 17, presentaciones de lo que fue la convecion de este año.]]></title>
<link>http://vulnerabilityteam.wordpress.com/2009/09/11/defcon-17-presentaciones-de-lo-que-fue-la-convecion-de-este-ano/</link>
<pubDate>Fri, 11 Sep 2009 10:30:11 +0000</pubDate>
<dc:creator>komz</dc:creator>
<guid>http://vulnerabilityteam.wordpress.com/2009/09/11/defcon-17-presentaciones-de-lo-que-fue-la-convecion-de-este-ano/</guid>
<description><![CDATA[Todo persona que le guste la seguridad informática conoce una de las más viejas convenciones de hack]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:justify;">Todo persona que le guste la seguridad informática conoce una de las más viejas convenciones de hackers de todo el mundo, la <strong>DEFCON</strong>, para todos aquellos que no pudimos asistir, ahora ya es posible descargar las presentaciones y charlas que se presentaron en su edición del año pasado.</p>
<p style="text-align:justify;">Que DEFCON permitan descargar este tipo de información es my buena noticia para los amantes de la seguridad informática, puesto que además de las presentaciones podemos descargar también el código fuente que han utilizado. Sin duda, unos artículos que no pueden faltar en nuestras bibliotecas personales.</p>
<p style="text-align:justify;">Según comentan dentro de poco estarán disponibles también los videos de las charlas, habrá que estar atento, pero mientras tanto para los que no conozcan DEFCON o quieran saber un poco más sobre está convención de hackers podéis ver este <a href="http://www.websecurity.es/documental-defcon-video" target="_blank">Documental sobre DEFCON</a>.</p>
<p style="text-align:justify;">Descargar las presentaciones y el código fuente desde su página <a href="https://www.defcon.org/html/links/dc-archives/dc-17-archive.html" target="_blank">DEFCON 17 Archive.</a></p>
<p><em>fuente: websecurity.es</em></p>
<p><em><a href="http://vulnerabilityteam.wordpress.com/files/2009/09/defcon.jpg"><img class="alignleft size-full wp-image-4890" title="Defcon" src="http://vulnerabilityteam.wordpress.com/files/2009/09/defcon.jpg" alt="Defcon" width="250" height="188" /></a><br />
</em></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DEFCON 17]]></title>
<link>http://omercakir.wordpress.com/2009/08/31/defcon-17/</link>
<pubDate>Mon, 31 Aug 2009 09:04:56 +0000</pubDate>
<dc:creator>Ömer Çakır</dc:creator>
<guid>http://omercakir.wordpress.com/2009/08/31/defcon-17/</guid>
<description><![CDATA[DEFCON 17 Press Page Updated! Head on over to the DEFCON Press Page and check out the news from this]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignleft" title="defcon-17" src="http://defcon.org/images/defcon-17/dc-17-logo.png" alt="" width="170" height="150" /></p>
<div>
<h2>DEFCON 17 Press Page Updated!</h2>
</div>
<p>Head on over to the <a title="DEFCON Press Page" href="http://defcon.org/html/links/dc_press/dc_press.html">DEFCON Press Page</a> and check out the news from this year&#8217;s show!  You can also find the press listed on the <a title="DEFCON 17 Archives" href="http://defcon.org/html/links/dc-archives/dc-17-archive.html">DEFCON 17 Archives Page</a>!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 68, Sep 01 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/08/30/data-security-podcast-episode-68-sep-01-2009/</link>
<pubDate>Mon, 31 Aug 2009 00:09:34 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/08/30/data-security-podcast-episode-68-sep-01-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus five) On this week’s p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* New attacks against business bank accounts&#8230;. an earth-shaking recommendation from the banking industry.</p>
<p>* Hackers say they are gearing up for winter attacks &#8211; according to a survey of hackers at DefCon 2009.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_68.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 68</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 68 of the Data Security Podcast</strong></p>
<p>*  Ira talks with Michael Hamel, Chief Security Architect, with Tufin Technologies, about the survey of hackers he crafted for DefCon 2009. We cover:  <a title="Tufin" href="http://tufin.com/news_events_press_releases.php?index=2009-08-25" target="_blank">Hackers Take a Break This Summer Before Winter Hacking Spike</a>, and importantly, counter-measures to get prepared.</p>
<p>* Tales From The Dark Web: New attacks against business bank accounts&#8230;. an earth-shaking recommendation from the banking industry.</p>
<p>* From the News:   WPA WiFi encryption can now be cracked in one minute, according to new research.  Terms in the story:</p>
<p style="padding-left:30px;">WPA:  Wi-Fi Protected Access</p>
<p style="padding-left:30px;">WPA -TKIP: WPA with Temporal Key Integrity Protocol for encryption</p>
<p style="padding-left:30px;">WPA-AES:  WPA with Advanced Encryption Standard for encryption</p>
<p style="padding-left:30px;">WPA2:  Second Generation WPA encryption</p>
<p style="padding-left:30px;">WEP:  Wired Equivalent Privacy</p>
<p style="padding-left:30px;"><strong>Take-Away: WPA-TKIP and WEP is bad, um-kay?</strong> <strong>WPA-AES and WPA2 is good, um-kay?</strong></p>
<p>* From the News:  Federal <a title="WaPo Stimulus Story" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/08/20/AR2009082003970.html" target="_blank">Web Site Collects Data on Stimulus</a>. We report: Whose minding the security of the data?</p>
<p>* From the News: <a title="Stealth Laptop Case" href="http://technabob.com/blog/2009/08/26/macbook-pro-newspaper-case/" target="_blank"> Stealth-Laptop Bag</a></p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 370px"><a href="http://technabob.com/blog/2009/08/26/macbook-pro-newspaper-case/"><img class=" " title="Stealth Laptop Case" src="http://technabob.com/blog/wp-content/uploads/2009/08/laptopcaseformacbookproagainstcrime.jpg" alt="Stealth Laptop Case" width="360" height="241" /></a><p class="wp-caption-text">Stealth Laptop Case</p></div>
<p>Wrap Up Story:    <a title="Cyber Security Act" href="http://datasecurityblog.wordpress.com/2009/08/28/cybersecurity-act-is-federal-infosec-license-key-to-net-control/" target="_blank">Is Federal InfoSec License Key To ‘Net Control?</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DefCon Removed My Copyrighted Photo From Their Blog]]></title>
<link>http://rzhblog.wordpress.com/2009/08/24/defcon-removed-my-copyrighted-photo-from-their-blog/</link>
<pubDate>Mon, 24 Aug 2009 07:23:51 +0000</pubDate>
<dc:creator>rzhblog</dc:creator>
<guid>http://rzhblog.wordpress.com/2009/08/24/defcon-removed-my-copyrighted-photo-from-their-blog/</guid>
<description><![CDATA[To rzh, Apologies for using what you say is your photo. There was nothing on the photo to show that ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><blockquote><p>To rzh,</p>
<p>Apologies for using what you say is your photo. There was nothing on the photo to show that it was copyrighted, but we have removed it to alleviate any concerns you have. Thanks for bringing this to our attention.</p>
<p>The Desert Pastor</p></blockquote>
<p>I wait for CRN to follow Defcon and remove my copyrighted photo from their website.</p>
<div id="attachment_2388" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-2388" title="Photo Stolen" src="http://rzhblog.wordpress.com/files/2009/08/photo-stolen.jpg" alt="Photo stolen by CRN from my Flickr website." width="500" height="375" /><p class="wp-caption-text">Photo stolen by CRN from my Flickr website.</p></div>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/aH9eKeALWlA&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/aH9eKeALWlA&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My Favorite Geek Music Tracks (Playlist)]]></title>
<link>http://leahshanker.wordpress.com/2009/08/18/my-favorite-geek-music-tracks-playlist/</link>
<pubDate>Tue, 18 Aug 2009 23:46:01 +0000</pubDate>
<dc:creator>Leah Shanker</dc:creator>
<guid>http://leahshanker.wordpress.com/2009/08/18/my-favorite-geek-music-tracks-playlist/</guid>
<description><![CDATA[Music emotionally engineers me to feel whatever it wants every time I listen to it. I really have no]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Music emotionally engineers me to feel whatever it wants every time I listen to it. I really have no control over it, regardless of how intensely I&#8217;m into a project or consciously trying to ignore it. I suspect it comes from being an auditory learner &#8211; there&#8217;s really no way to shut off your ears without earplugs! Anyway, I have a bunch of geek music I&#8217;ve collected over the years and I think it&#8217;s time I share it with the world <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So everything I could find on the Amazon MP3 Store, I&#8217;ve linked to here in the playlist because the truth is: geeks are a very small clique that simply doesn&#8217;t generate as much income for the artists as your normal, run-of-the-mill boring pop culture radio blether. So please, support the artists &#8211; they really need your help!</p>
<h3>Geekster Rap</h3>
<p>Much of the great geek music collection here owes much to the underground Nerdcore subculture. But I&#8217;ve classified the music even further by distinguishing the vulgar, testosterone-infused vulgar Geekster Rap (which is almost a direct parody of classic Gangster Rap) from the rest of the Nerdcore scene.</p>
<h4>
<div id="attachment_343" class="wp-caption alignleft" style="width: 310px"><a href="http://www.monzy.com/index.php?s=phd"><img class="size-medium wp-image-343" title="Monzy" src="http://leahshanker.wordpress.com/files/2009/08/germantv_small.jpg?w=300" alt="Monzy" width="300" height="251" /></a><p class="wp-caption-text">Monzy</p></div>
<p>Monzy: So Much Drama in the PhD [NSFW]</h4>
<p>This was a Stanford grad student&#8217;s masterpiece &#8211; it&#8217;s *FILLED* with algorithms and terminology we&#8217;re all so familiar with from CS core classes. NSFW! <a href="http://graphics.stanford.edu/~monzy/DramainthePhD.mp3">Download mp3 (Free)</a></p>
<h6>My flow is so intense that I will overflow your buffer,<br />
Corrupt your stack pointer makin&#8217; all your data suffer.<br />
I&#8217;ve got saturated edges but your flow is sparser,<br />
Real gangstas sip on Yacc; instead you generate a parser.<br />
While you&#8217;re busy poppin&#8217; stacks I&#8217;ll pop a cap in your skull,<br />
While you smoke your crack pipe I&#8217;m gonna pipe you to  <span style="font-family:Courier New;">/dev/null</span><span style="font-family:Arial,Helvetica,sans-serif;">.<br />
I may not have a label but I rap like a star;<br />
I&#8217;m an </span><span style="font-family:Courier New;">unsigned long int</span><span style="font-family:Arial,Helvetica,sans-serif;"> and you&#8217;re an 8-bit </span><span style="font-family:Courier New;">char</span><span style="font-family:Arial,Helvetica,sans-serif;">.</span></h6>
<h6>Your mom circulates like a public key,<br />
Servicing more requests than HTTP.<br />
She keeps all her ports open like Windows ME,<br />
Oh, there&#8217;s so much drama in the PhD.</h6>
<h6>I run gmake and gcc,<br />
And I ain&#8217;t never called <span style="font-family:Courier New;">malloc</span><span style="font-family:Arial,Helvetica,sans-serif;"> without calling </span><span style="font-family:Courier New;">free</span><span style="font-family:Arial,Helvetica,sans-serif;">.<br />
I&#8217;ll beat your ass until it&#8217;s colored like a red-black tree<br />
&#8216;Cause there&#8217;s so much drama in the PhD.</span></h6>
<h4>(Ode to the DEFCON) Badgez</h4>
<p>DEFCON 15&#8217;s Badgehacking Team Winner, Team Osogato, went all out on their badgehacking submission: they got a friend-of-a-friend (The Brothers Grimm) who was a Nerdcore rapper to create a rap from the poem Joe Grand wrote in the DEFCON schedule booklet that year. It sounds really great too! <a href="http://www.osogato.com/hacks/badgez.mp3">Download mp3 (Free)</a></p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/GniWtk2MER8&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/GniWtk2MER8&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
<h4>
<div id="attachment_359" class="wp-caption alignleft" style="width: 170px"><a href="http://www.amazon.com/gp/product/B001BMQ9ZG?ie=UTF8&#38;tag=leashasblo-20&#38;linkCode=as2&#38;camp=1789&#38;creative=390957&#38;creativeASIN=B001BMQ9ZG"><img class="size-full wp-image-359" title="Secrets From the Future Album" src="http://leahshanker.wordpress.com/files/2009/08/51dya1dduhl-_sl160_.jpg" alt="Secrets From the Future Album" width="160" height="160" /></a><p class="wp-caption-text">Secrets From the Future Album</p></div>
<p>Secrets From the Future</h4>
<p>MC Frontalot is probably my all-time favorite Nerdcore Rapper. He&#8217;s got an exquisite sound and an intuitive sense of (geek) culture in his music. His track, &#8220;Secrets from the Future&#8221; has a god-like quality to it: I think it was even composed at DEFCON? Man I would have killed to see him at DEFCON. Anyway,<a href="http://frontalot.com/index.php/?page=lyrics&#38;lyricid=41"> lyrics are here</a>. And also, <a href="http://frontalot.com/media.php/325/MC_Frontalot_SFTF_%2801%29_Secrets_From_The_Future.mp3">Download the mp3 (Free) </a>from his website. Or, do the right thing and <a href="http://www.amazon.com/gp/product/B001BMQ9ZG?ie=UTF8&#38;tag=leashasblo-20&#38;linkCode=as2&#38;camp=1789&#38;creative=390957&#38;creativeASIN=B001BMQ9ZG">buy the entire album</a>!</p>
<h4>
<div id="attachment_344" class="wp-caption alignleft" style="width: 160px"><a href="http://leahshanker.wordpress.com/files/2009/08/mpaastickersm.gif"><img class="size-full wp-image-344" title="Anti-MPAA Sticker of My Youth" src="http://leahshanker.wordpress.com/files/2009/08/mpaastickersm.gif" alt="Anti-MPAA Sticker of My Youth" width="150" height="38" /></a><p class="wp-caption-text">Anti-MPAA Sticker of My Youth</p></div>
<p>Fuck the MPAA [NSFW]</h4>
<p>Oh yeah, back when I was in 6th grade the cool thing to do was post those bright yellow &#8220;STOP THE MPAA&#8221; bumper stickers all over town. Several of the payphones at school had those bumperstickers plastered all over them (I can neither confirm nor deny placing them there). The Futuristic Sex Robotz took it to a whole new level of cool with this song. Oh and pretty much anything by FSR is obscenely vulgar (but awesomely geeky), so obviously nowhere near safe for work: <a href="http://www.last.fm/music/Futuristic+Sex+Robotz/_/Fuck+The+MPAA">Download mp3 (Free)</a></p>
<h3>Partytron (Electronic)</h3>
<h4>The Geeks Were Right &#38; The Conductor</h4>
<p>The Faint has quickly become one of my favorite artists of all time. They&#8217;ve got this grungy, industrial sound plus kickin&#8217; bass beats: I dub this new genre&#8230; Partytron! &#8220;The Conductor&#8221; is about the conductor of an orchestra, stepping up to the stage and taking control of the music. &#8220;The Geeks Were Right&#8221; is all about the Sci-fi Prediction that we&#8217;ll all become robots someday actually comes true. The Faint gets a HUGE less-than-three from me <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<div id="attachment_340" class="wp-caption aligncenter" style="width: 170px"><a href="http://www.amazon.com/gp/product/B001CN5O8W?ie=UTF8&#38;tag=leashasblo-20&#38;linkCode=as2&#38;camp=1789&#38;creative=390957&#38;creativeASIN=B001CN5O8W"><img class="size-full wp-image-340" title="The Geeks Were Right by The Faint" src="http://leahshanker.wordpress.com/files/2009/08/61bao3kkjsl-_sl160_.jpg" alt="The Geeks Were Right by The Faint" width="160" height="160" /></a><p class="wp-caption-text">The Geeks Were Right</p></div>
<div id="attachment_341" class="wp-caption aligncenter" style="width: 170px"><a href="http://www.amazon.com/gp/product/B000TD6WE6?ie=UTF8&#38;tag=leashasblo-20&#38;linkCode=as2&#38;camp=1789&#38;creative=390957&#38;creativeASIN=B000TD6WE6"><img class="size-full wp-image-341" title="The Conductor (Thin White Duke Remix) by The Faint" src="http://leahshanker.wordpress.com/files/2009/08/612btdn7izl-_sl160_.jpg" alt="The Conductor (Thin White Duke Remix) by The Faint" width="160" height="160" /></a><p class="wp-caption-text">The Conductor (Thin White Duke Remix)</p></div>
<h3>8-bit Remixes</h3>
<p>So, this is probably the most represented genre of the geek music I listen to. Everyone and their mother has probably heard a video game theme remix somewhere along the lines. So I&#8217;ve decided to focus on only the *good* ones, lol.</p>
<h4>
<div id="attachment_356" class="wp-caption alignleft" style="width: 310px"><a href="http://remixartistcollective.com/releases/nintendovssegaep.zip"><img class="size-medium wp-image-356" title="RAC's Nintendo vs. Sega EP" src="http://leahshanker.wordpress.com/files/2009/08/nintendo_vs_sega_ep_500.jpg?w=300" alt="RAC's Nintendo vs. Sega EP" width="300" height="300" /></a><p class="wp-caption-text">RAC&#39;s Nintendo vs. Sega EP</p></div>
<p>RAC&#8217;S Nintendo vs. Sega EP</h4>
<p>I can&#8217;t pick my favorite from this album: EVERYTHING is great. RAC is pretty much the crowned king of video game remixes in my world. Sonic and Mario getting together on the weekends for an 8-bit Party? Oh YEAH! The Remix Artist Collective Agency (RAC) is a group of artists that remix all kinds of popular music: I pretty much read (RAC Remix) next to any song as (Eff-YEAH Remix). <a href="http://remixartistcollective.com/releases/nintendovssegaep.zip">Download zip of entire album (Free)</a></p>
<h4>Anything by EEPROM</h4>
<p style="text-align:right;">EEPROM is pretty much the God of Leah&#8217;s Musical World. Everything he touches turns to gold &#8211; I honestly haven&#8217;t found any song that he&#8217;s created that my mind hasn&#8217;t been blown countless times over.</p>
<p style="text-align:right;">EEPROM Remix of Weezer&#8217;s Say It Ain&#8217;t So: <a href="http://mark.jworks.ca/eeprom/music/siasremix.mp3">mp3 Download (Free)</a></p>
<p style="text-align:right;">The Beatles&#8217;s Lonely People (EEPROM Rigby Remix): <a href="http://www.thesixtyone.com/#/eeprom/song/Lonely+People+(Eleanor+Rigby+Remix+by+EEPROM)/30480/">mp3 Download (80¢)</a></p>
<p style="text-align:right;">EEPROM Remix of the Safety Dance: <a href="http://www.thesixtyone.com/#/eeprom/song/Safety+Dance/58970/">mp3 Download (80¢)</a></p>
<p style="text-align:right;">EEPROM Remix of Human Robotics: <a href="http://www.thesixtyone.com/#/eeprom/song/Human+Robotics/43848/">mp3 Download (80¢)</a></p>
<p style="text-align:right;">EEPROM Remix of OneRepublic&#8217;s Apologize: <a href="http://www.thesixtyone.com/#/eeprom/song/Apologize/32854/">mp3 Download (80¢)</a></p>
<p style="text-align:right;">EEPROM Remix Rick Astley&#8217;s Never Gonna Give You Up (Rick Roll): <a href="http://www.thesixtyone.com/#/eeprom/song/Never+Gonna+Give+You+Up/34708/">mp3 Download</a><a href="http://www.thesixtyone.com/#/eeprom/song/Safety+Dance/58970/"> (80¢)</a></p>
<p style="text-align:right;">
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Defcon, is it over already ?]]></title>
<link>http://c22blog.wordpress.com/2009/08/12/defcon-is-it-over-already/</link>
<pubDate>Wed, 12 Aug 2009 11:50:11 +0000</pubDate>
<dc:creator>ChrisJohnRiley</dc:creator>
<guid>http://c22blog.wordpress.com/2009/08/12/defcon-is-it-over-already/</guid>
<description><![CDATA[Well Defcon has come and gone. For those following my blog (sorry about that), you might have notice]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignleft" style="border:5px;margin:5px;" src="https://pics.defcon.org/data//537/medium/andrus_defcon17_p.jpg" alt="" width="228" height="352" />Well Defcon has come and gone. For those following my blog (sorry about that), you might have noticed a lack of posts covering what I saw at Defcon. This was for several reasons. They&#8217;re  good reasons honest, and none of them are that I was too scared to get on the Defcon network or that I was too hungover (although I won&#8217;t deny I attended a party or 6).</p>
<p>Defcon was, for me, a chance to finally meet a group of people who I&#8217;ve been conversing with online for some time now. I set myself a goal before I left, to meet people and actually communicate with people (not really my primary skillset). Although I did get to attend some talks, I didn&#8217;t feel that blogging about the 2/3 a day I actually saw, was going to be interesting to my readers (yes, both of you).</p>
<p>Although you&#8217;ve probably already got your fill of Defcon recaps by now, Id like to recommend Frank Breedijk&#8217;s blog over at <a title="cupfighter.net" href="http://www.cupfighter.net/" target="_blank">cupfighter.net</a> as he has various writeups on presentations that we attended together or individually. Frank and I were also lucky enough to talk to F1nux from HPR (Hacker Public Radio) about the event. If you want to listen, you can grab a copy at the <a title="HPR Episode 420" href="http://hackerpublicradio.org/eps/hpr0420.mp3">Hacker Public Radio website</a>.</p>
<p>I&#8217;d like to thank the various people I met at Defcon. Especially Frank (@autonessus), Martin (@mckeay), Chris Nickerson (@indi303), Carlos (@carlos_perez), Tom (@agent0&#215;0), Mick (@bettersafetynet), John Strand (@strandjs) and the rest of the #pauldotcom crew.I met so mmany people I couldn&#8217;t start to list them all. So i&#8217;ll just say thanks to everyone, and don&#8217;t be strangers <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Hope to see you all at another event soon <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackit: Ideal conference badge?]]></title>
<link>http://hackaday.com/2009/08/11/hackit-ideal-conference-badge/</link>
<pubDate>Wed, 12 Aug 2009 00:05:38 +0000</pubDate>
<dc:creator>Eliot Phillips</dc:creator>
<guid>http://hackaday.com/2009/08/11/hackit-ideal-conference-badge/</guid>
<description><![CDATA[In 2006, Defcon 14 premiered a unique electronic badge. All it did was blink, but it raised the bar ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignnone size-full wp-image-13258" title="assembly" src="http://hackadaycom.wordpress.com/files/2009/08/assembly.jpg" alt="assembly" width="470" height="260" /></p>
<p>In 2006, Defcon 14 premiered a unique electronic badge. <a title="Grand Idea Studio  » Archive   » DEFCON 14 Badge" href="http://www.grandideastudio.com/portfolio/defcon-14-badge/">All it did was blink</a>, but it raised the bar for what was expected from a hacker conference badge. In 2007, they went from 2 LEDs to <a title="The Defcon Badge  - Hack a Day" href="http://hackaday.com/2007/08/02/the-defcon-badge/">95 in a scrolling marquee</a>. Along with a POV mode, the badge had two capacitive switches to let the user edit the displayed text. Defcon 16&#8217;s badge featured an <a title="Defcon 16: Badge details released  - Hack a Day" href="http://hackaday.com/2008/08/05/defcon-16-badge-details-released/">IR transmitter and receiver</a> for transferring files from an SD card. It worked as a TV-B-Gone and had pads to access a USB bootloader. That was the same year that The Last Hope debuted their <a title="The trackable Last HOPE conference badge  - Hack a Day" href="http://hackaday.com/2008/07/18/the-trackable-last-hope-conference-badge/">RFID tracking badges</a>.</p>
<p>This year the official Defcon badge <a title="Defcon 17: Badge details released  - Hack a Day" href="http://hackaday.com/2009/07/31/defcon-17-badge-details-released/">reacted to sound</a>, but they were no longer the only game in town. Ninja Networks brought their <a title="Ninja Networks Party Badge  - Hack a Day" href="http://hackaday.com/2009/08/10/ninja-networks-party-badge/#comments">10 character party badges with a built in debugger</a>. The Arduino compatible <a title="HackTheBadge 1.0  - Hack a Day" href="http://hackaday.com/2009/08/10/hackthebadge-1-0/">HackTheBadge 1.0</a> also made an appearance. With these new entrants into the field, we wondered what you&#8217;d want to see in your ideal badge. What badge would you want to see at next year&#8217;s Defcon? Leave you comments below and keep in mind that it should be an idea that is easy to cheaply mass produce.</p>
<p><strong>UPDATED:</strong> Forgot to mention the <a href="http://www.radiantmachines.com/2009/07/neighborcon-2-badge/">Neighborcon 2 badge</a> based on the <a href="http://goodfet.sourceforge.net/hardware/goodfet20/">GoodFET20</a>.</p>
<p>[Photo: <a title="2009 Ninja Badge - Black on Flickr - Photo Sharing!" href="http://www.flickr.com/photos/ninja_networks/3808785263/">Ninja Networks</a>]</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DEFCON 17]]></title>
<link>http://dtrammell.wordpress.com/2009/08/11/defcon-17/</link>
<pubDate>Tue, 11 Aug 2009 21:51:49 +0000</pubDate>
<dc:creator>Dustin D. Trammell</dc:creator>
<guid>http://dtrammell.wordpress.com/2009/08/11/defcon-17/</guid>
<description><![CDATA[After staying with some of my local Vegas friends during BlackHat, I went over and checked into the ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>After staying with some of my local Vegas friends during BlackHat, I went over and checked into the Riviera for DEFCON 17 on Thursday afternoon.  After dropping my bags in my room and getting my temporary paper badge because they were <em>already</em> out of the electronic badges, I ran back up to my room for a bit and then headed over to the Microsoft party which I already wrote about in my <a title="BlackHat USA 2009" href="http://dtrammell.wordpress.com/2009/08/07/blackhat-usa-2009/">BlackHat USA 2009 post</a>.  After an extremely long night I crashed in the early morning and slept through most of the first day of DEFCON talks.  I did however catch Richard Thieme&#8217;s talk about UFOlogy, which was one of the talks I really wanted to see.</p>
<p>Shortly after Richard&#8217;s talk and some discussion with friends about what to do for dinner, I started not feeling well so I went back up to my room.  After an hour or two I knew I really was sick because I started getting the fever sweats, cold chills, and headache, so I ordered some room service since I probably needed to eat, called it a night and went to sleep.  I stayed in bed pretty much all day Saturday and only came downstairs once in the afternoon during the conference to speak during the Metasploit track, and then went right back upstairs to my room.  By then I had a horrible cough and chest congestion, but was feeling much better regardless, so I decided to take a walk for a couple hours and let the dry desert air into my lungs for a bit.</p>
<p>I hadn&#8217;t yet walked the length of the Strip this visit, and also hadn&#8217;t eaten a FatBurger, both of which are personal Vegas traditions.   Since I was running out of days in Vegas during which to accomplish these, I decided to walk from the Riviera up on the North end of the Strip all the way down to FatBurger which is near the South end of the strip, get a burger, and then walk back, which took around 2.5 hours and immensely helped my lungs and cough.</p>
<p>By the time I got back to the Riviera, I was feeling well enough to attend some parties, so I went up to the Penthouse for a while to check out the IOActive Freak Show party for a bit.  It was similar to last year&#8217;s party, but had some new attractions so that wasn&#8217;t too bad.  I tried to dance for a bit but my chest cold was severely holding me back since I could only dance for a few minutes before not being able to breathe.  I left that party shortly after Keith went on since I couldn&#8217;t really dance and he started off with tracks that were a little too glitchy for my taste anyhow.  Unfortunately I missed the fire dancer at the IOActive party who had a fire hoop like my friend Angi&#8217;s, but living in Austin surrounded by burners I think I&#8217;m a bit spoiled regarding fire spinning/dancing/performance anyhow.  After leaving the Penthouse I took the Ninja Shuttle over to the Ninja Party and hung out there for a few hours talking to friends and waiting in line at the bar until I decided not to push my recent health luck and went back to my room at the Riviera and went to sleep.</p>
<p>On Sunday I slept a little late still trying to fully recover until I needed to check out of my room.  Unfortunately this meant that I missed Richard Thieme&#8217;s other talk on BioHacking, but I did manage to catch a few more of the talks before I had to head to the airport to catch my plane back to Austin.  You can read my thoughts on the talks that I saw below:</p>
<p><!--more--><strong><img title="More..." src="../wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" /><a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Thieme">Hacking UFOlogy 102: The Implications of UFOs for Life, the Universe, and Everything</a></strong> &#8211;  Richard Thieme</p>
<p>Richard is an exceptional speaker, and I personally love UFO and extraterrestrial lore and pop culture.  It&#8217;s fun to try and sift through all the conspiracy theory, misinformation, pop-culture, and cover up to try and see if there&#8217;s any truth there, and that&#8217;s what Richard&#8217;s talk was essentially about.  It was also a follow-up to the talk he gave the previous year, Hacking UFOlogy 101.  It&#8217;s always a pleasure to hear Richard speak because he&#8217;s very engaging and has very well organized content, even if he does never seem to be able to cover it all.</p>
<p><strong><a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Druid">MSF Telephony</a></strong> &#8211;  I)ruid</p>
<p>Since the Metasploit track was available at both BlackHat <em>and</em> DEFCON, I had the opportunity to give my talk a second time.  I presented a turbo-talk about the new telephony library that I’ve added to Metasploit.  I discussed exploiting systems with Metasploit over dial-up and the new Metasploit Wardialer, both of which use the new telephony library.  It didn&#8217;t go quite as well as it did at BlackHat, however I was rushing to try and get it down to about 10 minutes due to some scheduling conflicts and confusion and the Metasploit track having more content for DEFCON than it did at BlackHat.  I managed to hit the 10 minute mark, and my voice held out even though my throat was dry, scratchy, and I wanted to cough the entire time.</p>
<p><strong><a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Latrope">eXercise in Messaging and Presence Pwnage</a></strong> &#8211;  Ava Latrope</p>
<p>I had briefly looked at Extensible Messaging and Presence Protocol (XMPP) back when I was doing a lot of research in the VoIP security space, and remembered it looking like a huge pile of attack opportunity.  XMPP is basically an interoperability standard borne of Jabber which provides a protocol for managing Instant Messaging sessions and communication, presence applications, and is beginning to merge a bit with some of the VoIP and &#8220;Unified Communications&#8221; systems.  After seeing this talk, I&#8217;m glad to know that I was pretty much correct.  Ava&#8217;s talk was short but did a good job explaining what XMPP is, what it&#8217;s generally used for, some of it&#8217;s attack surface, and then detailed some DoS and amplification attacks that are possible due to the way the protocol is designed.</p>
<p><strong><a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Abraham">Unmasking You</a></strong> &#8211;  Joshua &#8220;Jabra&#8221; Abraham and Robert &#8220;RSnake&#8221;</p>
<p>I only caught the last half of this talk, but basically the Google &#8220;Safe Browsing&#8221; functionality phones home.  A LOT.  Like, way more often than is probably necessary.  How often do they update their site and URL filters anyway?  Anyhow, if you&#8217;re an 31337 h4&#215;0r and you like to hide the source of your traffic when you h4x, but then use the Internet normally when you&#8217;re not, the uniquely identifying information that the Google &#8220;Safe Browsing&#8221; functionality sends to Google when updating it&#8217;s filters every 0.23435151 seconds or so will easily track you across your covert and overt sessions, through Tor, across proxies, you name it.</p>
<p><strong><a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#DaBeave">AAPL- Automated Analog Telephone Logging</a></strong> &#8211;  Da Beave and JFalcon</p>
<p>I had met Da Beave  and JFalcon via the <a href="telnet://bbs.telephreak.org/">Telephreak BBS</a> a year or so ago and had yet to meet either of them in person, so I went and checked out their talk.  They covered the newest iteration of <a title="iWar" href="http://www.softwink.com/iwar/" target="_blank">iWar</a>, spoke a bit about HD&#8217;s <a title="WarVOX" href="http://warvox.org/" target="_blank">WarVOX</a>, and showed some interesting systems they&#8217;ve found over dialup.  Basically it was VoIP-ish wardialing in about 20 minutes, since it was a turbo talk.</p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
