<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MSI :: State of Security</title>
	<atom:link href="http://stateofsecurity.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://stateofsecurity.com</link>
	<description>Insight from the Information Security Experts</description>
	<lastBuildDate>Wed, 16 May 2012 13:43:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Are You Attending the 2012 Central Ohio InfoSec Summit?</title>
		<link>http://stateofsecurity.com/?p=2463&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=are-you-attending-the-2012-central-ohio-infosec-summit</link>
		<comments>http://stateofsecurity.com/?p=2463#comments</comments>
		<pubDate>Wed, 16 May 2012 13:37:03 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Central Ohio InfoSec Summit]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2463</guid>
		<description><![CDATA[<div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=20320310172&amp;xfbml=1"></script><script language="JavaScript">
					FB.Event.subscribe('edge.create', function(response) {
						_gaq.push(['_trackEvent','SocialSharing','Facebook - like button',unescape(String(response).replace(/\+/g, " "))]);
					});
				</script>&#160; We&#8217;re excited to be a part of this year&#8217;s 5th Annual 2012 Central Ohio InfoSec Summit! Each year it keeps getting better and better, and this year is no different. MicroSolved&#8217;s CEO and founder, Brent Huston will be presenting &#8230; <a href="http://stateofsecurity.com/?p=2463">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/ISSALogo.png"><img class="alignleft size-full wp-image-2411" title="ISSALogo" src="http://stateofsecurity.com/wp-content/uploads/2012/04/ISSALogo.png" alt="" width="656" height="145" /></a></p>
<p>&nbsp;</p>
<p>We&#8217;re excited to be a part of this year&#8217;s <strong><a href="http://www.centralohioissa.org/?page_id=936">5th Annual 2012 Central Ohio InfoSec Summit</a></strong>! Each year it keeps getting better and better, and this year is no different.</p>
<p>MicroSolved&#8217;s CEO and founder, Brent Huston will be presenting &#8220;Detection in Depth: Changing the PDR Focus.&#8221; Phil Grimes will also present &#8220;Attacking Mobile Devices&#8221; in the Advanced Technical Track.</p>
<p>There are other great speakers lined up. Included are:</p>
<ul>
<li>Bill Hagestad, author of <em>21st Century Chinese Cyber Warfare</em></li>
<li>Jay Jacobs, a Principal with Verizon&#8217;s RISK Intelligence team, will focus on cyber crime</li>
<li>Curtis Levinson, who has served two sitting Presidents of the United States, two Chairman of the Joint Chiefs of Staff and the Chief Justice of the United States, who will be presenting on a balanced approach for survivability and sustainability in the cyber realm</li>
</ul>
<p>There are more great speakers, plus over thirty vendors who help businesses stay secure. We hope to see you at the event! It promises to be a great time re-connecting with old friends, making new connections, and learning new approaches toward a proactive information security strategy.</p>
<p>See you there!</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&text=Are+You+Attending+the+2012+Central+Ohio+InfoSec+Summit%3F" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2463']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&title=Are+You+Attending+the+2012+Central+Ohio+InfoSec+Summit%3F&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463&name=Are+You+Attending+the+2012+Central+Ohio+InfoSec+Summit%3F&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2463']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2463" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2463</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Hack! 5 Ways to Avoid Being the Victim of a Phishing Attack</title>
		<link>http://stateofsecurity.com/?p=2450&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=twitter-hack-5-ways-to-avoid-being-the-victim-of-a-phishing-attack</link>
		<comments>http://stateofsecurity.com/?p=2450#comments</comments>
		<pubDate>Thu, 10 May 2012 15:20:35 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2450</guid>
		<description><![CDATA[Twitter is downplaying a security breach that exposed tens of thousands of user emails and passwords. The leaked information, comprising 58,978 username and password combinations, appeared Monday on Pastebin. While Twitter said that it&#8217;s investigating the breach, it’s also downplayed &#8230; <a href="http://stateofsecurity.com/?p=2450">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/05/twitter_273x178.jpg"><img class="alignleft size-full wp-image-2453" title="twitter_273x178" src="http://stateofsecurity.com/wp-content/uploads/2012/05/twitter_273x178.jpg" alt="" width="223" height="128" /></a><strong>Twitter is downplaying a security breach that exposed tens of thousands of user emails and passwords.</strong></p>
<p style="padding-left: 60px;"><em>The leaked information, comprising 58,978 username and password combinations, appeared Monday on Pastebin. While Twitter said that it&#8217;s investigating the breach, it’s also downplayed the supposed size and severity of the data dump.</em></p>
<p style="padding-left: 60px;"><em>&#8220;We are currently looking into the situation,&#8221; said spokeswoman Rachel Bremer via email. &#8220;It&#8217;s worth noting that, so far, we&#8217;ve discovered that the list of alleged accounts and passwords found on Pastebin consists of more than 20,000 duplicates, many spam accounts that have already been suspended, and many login credentials that do not appear to be linked (that is, the password and username are not actually associated with each other).&#8221;</em></p>
<p style="padding-left: 60px;"><strong><a href="http://www.informationweek.com/news/security/attacks/240000060" target="_blank">Information Week Security article</a></strong></p>
<p>Whenever you read about such breaches, it is always a good idea to change your password, especially if you&#8217;ve not changed it for some time.</p>
<p>The compromised Twitter accounts could have been the result of phishing attacks. A phishing attack is when an attacker acquires personal information by duping the user into revealing it through manipulating their emotions.</p>
<p>Remember how one of your wiser friends told you it&#8217;s never a good idea to make a big decision while you&#8217;re overly-emotional? The same stands true for avoiding phishing attacks.</p>
<p>Here are some ways to stay safe:</p>
<ol>
<li><strong>Do not give out your financial information ever through an email appeal.</strong> I hope we all know now that you haven&#8217;t won the Nigerian lottery or that some prince or princess is willing to give you part of their inheritance if only you&#8217;ll keep their money in your bank account. Emails of this nature prey upon people who would love to &#8220;win&#8221; money or worse, may lose money in their account unless they give out their account information. Never give out your personal information. Instead, call your bank to verify that they need the information. <strong><a href="http://stateofsecurity.com/?p=1331" target="_blank">You could also have some fun with the hackers like I did.<br /> </a></strong></li>
<li><strong>Don&#8217;t call any phone number or visit a website that is linked in the email.</strong> There&#8217;s a good chance it will connect you directly to the attacker. Look at the URL associated with the link. Does it contain words, letters, or numbers that seem odd? It&#8217;s likely an attempt to masquerade as an organization&#8217;s true website address, so don&#8217;t click it. You can see the URL by hovering over it or highlighting it with your mouse. Again, if you think it may be a legitimate request for information, verify it by contacting your financial institution directly.<br /> </li>
<li><strong>Never fill out forms in an email that asks for personal information.</strong> Most organizations like PayPal notify their customers but do not ask for personal information to be placed into forms. Again, verify, verify, verify.<br /> </li>
<li><strong>Regularly check your online banking accounts.</strong> Don&#8217;t allow months to go by before checking in. By frequently monitoring your account, you&#8217;ll be able to immediately see suspicious activity.<br /> </li>
<li><strong>Patch it!</strong> When that annoying &#8220;Software Updates Available Now&#8221; window pops up, don&#8217;t ignore it. (I&#8217;m talking mainly to myself, now.) Click to install. Patches fix vulnerabilities and many attackers will jump on the opportunity to hit an un-patched machine. If you&#8217;re in doubt about whether your browser system is up-to-date, check by clicking your browser&#8217;s info link or your system&#8217;s and click &#8220;Software Update&#8221; or &#8220;Check for updates.&#8221; (In Firefox, it&#8217;s in the &#8220;Tools&#8221; section.)</li>
</ol>
<p>Finally, you can report phishing attacks to the following organizations:</p>
<ul>
<li>The Federal Trade Commission at spam@uce.gov.</li>
<li>Forward the email to the &#8220;abuse&#8221; email address to the company that is being spoofed (i.e. &#8220;abuse@XYZcompany.com&#8221; or &#8220;spam@XYZcompany.com&#8221;). Make sure to forward the complete email message with the original email header.</li>
<li>Notify the <strong><a href="http://www.fbi.gov/scams-safety/fraud/internet_fraud/internet_fraud" target="_blank">Internet Fraud Complaint Center of the FBI</a></strong> by filing a complaint on their website: <strong><a href="http://www.ic3.gov/default.aspx" target="_blank">http://www.ic3.gov/default.aspx</a></strong> There is an excellent selection of tips on the FBI site to help you avoid fraud, so make sure to check it out.</li>
</ul>
<p>The key to avoid becoming a victim is to stay alert, stay suspicious, and stay on top of changing your passwords.</p>
<p>Stay safe!</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&text=Twitter+Hack%21+5+Ways+to+Avoid+Being+the+Victim+of+a+Phishing+Attack" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2450']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&title=Twitter+Hack%21+5+Ways+to+Avoid+Being+the+Victim+of+a+Phishing+Attack&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450&name=Twitter+Hack%21+5+Ways+to+Avoid+Being+the+Victim+of+a+Phishing+Attack&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2450']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2450" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2450</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Resources for Mobile Application Security</title>
		<link>http://stateofsecurity.com/?p=2445&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=resources-for-mobile-application-security</link>
		<comments>http://stateofsecurity.com/?p=2445#comments</comments>
		<pubDate>Tue, 08 May 2012 18:37:35 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[Mobile Application Security]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[mobile application security]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2445</guid>
		<description><![CDATA[Mobile application security continues to be a hot topic within the information security community. With more and more employees expecting to use their own devices at their workplaces, IT departments are scrambling to develop the right approach for securing their &#8230; <a href="http://stateofsecurity.com/?p=2445">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/05/mobiledevice.jpg"><img class="alignleft size-full wp-image-2447" title="Woman using cellphone" src="http://stateofsecurity.com/wp-content/uploads/2012/05/mobiledevice.jpg" alt="" width="300" height="300" /></a><strong>Mobile application security continues to be a hot topic within the information security community. With more and more employees expecting to use their own devices at their workplaces, IT departments are scrambling to develop the right approach for securing their data.</strong></p>
<p>If you&#8217;re working on developing security policies or seeking ways to secure your mobile applications, you may find some of these resources helpful. Stay safe out there!</p>
<ul>
<li><a href="http://www.amazon.com/Programming-Mobile-Devices-Introduction-Practitioners/dp/0470057386/ref=sr_1_12?ie=UTF8&amp;s=books&amp;qid=1258729420&amp;sr=1-12"><em>Programming Mobile Devices: In Introduction for Practitioners</em></a> by Tommi Mikkonen</li>
<li><a href="http://www.amazon.com/Embedded-Java-Security-Mobile-Devices/dp/1846285909/ref=sr_1_2?ie=UTF8&amp;s=books&amp;qid=1258729560&amp;sr=1-2"><em>Embedded Java Security: Security for Mobile Devices</em></a> by Mourad Debbabi, Mohamed Salah, Chamseddiing Talhi, Sami Zhioua</li>
<li><a href="http://www.amazon.com/Advances-Security-Payment-Methods-Commerce/dp/1591403456/ref=sr_1_14?ie=UTF8&amp;s=books&amp;qid=1258729693&amp;sr=1-14"><em>Advances in Security and Payment Methods for Mobile Commerce</em></a> by Wen-Chen Hu, Chung-wei Lee, Weidong Kou</li>
<li><a href="http://www.amazon.com/Construction-Analysis-Secure-Interoperable-Devices/dp/3540242872/ref=sr_1_15?ie=UTF8&amp;s=books&amp;qid=1258729800&amp;sr=1-15"><em>Construction and Analysis of Safe, Secure, and Interoperable Smart Devices: International Workshop CASSIS 2004</em></a>, by Gilles Barthe (Editor)</li>
<li><a href="http://download.cnet.com/1770-20_4-0.html?query=Anti+virus+for+smartphones&amp;tag=mncol%253Bsort&amp;searchtype=downloads&amp;filterName=&amp;filter=">Anti-Virus Software for Smartphones (CNET)</a></li>
<li><a href="http://www.stanford.edu/group/security/securecomputing/mobile_devices.html">Guidelines for Security Mobile Computing Devices (Stanford University)</a></li>
<li><a href="http://www.cio.com/article/40360/Mobile_Security_Definition_and_Solutions">Mobile Security Definition and Solutions (CIO Magazine)</a></li>
<li><a href="http://www.techrepublic.com/blog/security/five-steps-to-protect-mobile-devices-anywhere-anytime/529">Five Steps to Protect Mobile Devices Anywhere, Anytime (TechRepublic)</a></li>
<li><a href="http://www.edn.com/article/459301-Mobile_device_security_through_virtualization.php">Mobile Device Security Through Virtualization (EDN)</a></li>
<li><a href="http://www.scmagazine.com/mobile-device-protection/article/217434/">Mobile Device Protection (SC Magazine)</a></li>
</ul>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&text=Resources+for+Mobile+Application+Security" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2445']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&title=Resources+for+Mobile+Application+Security&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445&name=Resources+for+Mobile+Application+Security&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2445']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2445" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2445</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Quick Wireless Network Reminders</title>
		<link>http://stateofsecurity.com/?p=2434&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=quick-wireless-network-reminders</link>
		<comments>http://stateofsecurity.com/?p=2434#comments</comments>
		<pubDate>Fri, 04 May 2012 13:35:10 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2434</guid>
		<description><![CDATA[I recently tested a couple of Android network stumblers on a drive around the city and I found that not a lot has changed for consumer wireless networks since I last stumbled. There are still a TON of unprotected networks, &#8230; <a href="http://stateofsecurity.com/?p=2434">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/05/laptopmobile300.jpg"><img class="alignleft size-full wp-image-2438" title="OLYMPUS DIGITAL CAMERA" src="http://stateofsecurity.com/wp-content/uploads/2012/05/laptopmobile300.jpg" alt="" width="300" height="225" /></a><strong>I recently tested a couple of Android network stumblers on a drive around the city and I found that not a lot has changed for consumer wireless networks since I last stumbled. </strong></p>
<p><strong></strong>There are still a TON of unprotected networks, default SSIDs and WEP networks out there. It appears that WPA(x) and WPS have been slower to be adopted than I had expected. I don&#8217;t know if that is consumer apathy, ignorance or just a continued use of legacy hardware before the ease of push button WPS. Either way, it was quickly clear that we still have a long way to go to deprive criminals of consumer-based wireless network access.</p>
<div>The good news is that it appears from this non-comprehensive sample that the businesses in our area ARE taking WiFi security seriously. Most networks easily coordinated with a business were using modern security mechanisms, though we did not perform any penetration testing and can&#8217;t speak to their password policies or detection capabilities. But for the most part, their SSIDs made sense, they used effective crypto and in most cases were even paying attention to channel spread to maximize the reliability of the network. This is good news for most organizations and shows that much of the corporate awareness and focus on WiFi security by vendors seems to be working. It makes the business risk of these easy-to-deploy systems more acceptable.</div>
<div> </div>
<div>I also noted that it was apparent on the consumer side that some folks deploying WiFi networks are paying attention. We saw SSIDs like &#8220;DontHackMe&#8221;, &#8220;DontLeechMeN3rds&#8221;,&#8221;Secured&#8221;, &#8220;StayOut&#8221;., etc. Sadly, we also saw plenty of SSIDs that were people&#8217;s names, addresses, children&#8217;s names and in one case &#8220;PasswordIsPassword1&#8243;. Clearly, some installers or consumers still haven&#8217;t seen the dangers of social engineering that some of these names can bring. So, while we have seen some improvement in SSID selection, there is still work to be done to educate folks that they need to pick non-identifiable information for broadcast.</div>
<div> </div>
<div>That said, how can we better teach consumers about the basics of WiFi security? What additional things could we do as an industry to make their data safer at home?</div>
<div> </div>
<div> </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&text=Quick+Wireless+Network+Reminders" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2434']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&title=Quick+Wireless+Network+Reminders&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434&name=Quick+Wireless+Network+Reminders&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2434']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2434" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2434</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How to Save Your Photos From a BYOD Security Policy</title>
		<link>http://stateofsecurity.com/?p=2430&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-save-your-photos-from-a-byod-security-policy</link>
		<comments>http://stateofsecurity.com/?p=2430#comments</comments>
		<pubDate>Wed, 02 May 2012 16:21:07 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[Mobile Application Security]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2430</guid>
		<description><![CDATA[Many companies have adopted a BYOD policy regarding mobile devices. Realizing that it&#8217;s unrealistic to require employees to leave their iPhones or tablets at home, they&#8217;ve accepted mobile technology; albeit, with a few rules. One of the more common rules &#8230; <a href="http://stateofsecurity.com/?p=2430">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2011/09/cellphonereflection.jpg"><img class="alignleft size-medium wp-image-1810" title="cellphonereflection" src="http://stateofsecurity.com/wp-content/uploads/2011/09/cellphonereflection-300x224.jpg" alt="" width="300" height="224" /></a><span style="font-size: medium;"><strong>Many companies have adopted <a href="http://www.businessnewsdaily.com/1267-bring-your-own-device-benefits.html">a BYOD policy</a> regarding mobile devices. Realizing that it&#8217;s unrealistic to require employees to leave their iPhones or tablets at home, they&#8217;ve accepted mobile technology; albeit, with a few rules.</strong></span></p>
<p>One of the more common rules is to enable the remote wipe and lock feature. This means that if your device was ever stolen or compromised, the IT department can remotely lock the device and then wipe any data from it. And yes, that would include all of your photos as well as other items.</p>
<p><strong><a href="http://www.networkworld.com/news/2012/043012-byod-mimecast-258799.html?source=NWWNLE_nlt_daily_pm_2012-04-30">One CEO recently experienced personal data loss as a result of his own company&#8217;s policy that he himself helped establish.</a></strong> (Ouch!) While on vacation, his five-year old daughter tried to use his smartphone. After several failed attempts of entering the passcode, the corporate-installed remote wipe was triggered and the CEO lost all of the photos he had taken during the first half of their vacation. (Double ouch!)</p>
<p>If you have an iPhone with the latest iOS 5, you can sign up for the free iCloud, which will sync your devices and store everything on Apple&#8217;s servers. But first, you have to enable it. After installing the iCloud feature, tap Settings/iCloud and then choose &#8220;On.&#8221; Click on the &#8220;Back Up Now&#8221; and you&#8217;re good to go. This way, if your device is wiped clean because of a security breach, you&#8217;ll still have your photos. </p>
<p>Again, you&#8217;ll have to remember to do this frequently if you are using your smartphone to take vacation photos. It may be a good idea to back up your data during dinner or before you go to bed.</p>
<p><a href="http://www.usatoday.com/tech/products/story/2012-04-02/android-data-backup/53950154/1">If you have an Android phone</a>, make sure you have a Gmail address in order to take advantage of storing your data in the cloud. Titanium Backup and MyBackup Pro are also two apps that can back up your entire phone and transfer the data to your PC&#8217;s hard drive.</p>
<p>Whatever device you use, make sure you have a back up plan. Know well your company&#8217;s BYOD policy. It will give you peace of mind the next time you&#8217;re taking a bunch of photos at an event that will never happen again.</p>
<p>Stay safe and enjoy the ride!</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&text=How+to+Save+Your+Photos+From+a+BYOD+Security+Policy" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2430']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&title=How+to+Save+Your+Photos+From+a+BYOD+Security+Policy&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430&name=How+to+Save+Your+Photos+From+a+BYOD+Security+Policy&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2430']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2430" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2430</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Discuss Detection in Depth at CMH ISSA Summit</title>
		<link>http://stateofsecurity.com/?p=2421&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=discuss-detection-in-depth-at-cmh-issa-summit</link>
		<comments>http://stateofsecurity.com/?p=2421#comments</comments>
		<pubDate>Mon, 30 Apr 2012 18:59:18 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[ISSA InfoSec Summit]]></category>
		<category><![CDATA[Detection in Depth]]></category>
		<category><![CDATA[InfoSec Summit]]></category>
		<category><![CDATA[ISSA]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2421</guid>
		<description><![CDATA[&#160; &#160; On May 18th, I will be presenting on detection in depth at the CMH ISSA Summit. I look forward to a good discussion of the ideals, organizational needs, and maturity models. Given all of the focus on re-allocating resources &#8230; <a href="http://stateofsecurity.com/?p=2421">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/ISSALogo.png"><img class="alignleft size-full wp-image-2411" title="ISSALogo" src="http://stateofsecurity.com/wp-content/uploads/2012/04/ISSALogo.png" alt="" width="656" height="145" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>On May 18th, I will be presenting on <strong><a href="http://stateofsecurity.com/?p=1946">detection in depth</a> </strong>at the CMH ISSA Summit. I look forward to a good discussion of the ideals, organizational needs, and maturity models. Given all of the focus on re-allocating resources from &#8220;prevention only&#8221; strategies to an equal spread across the core values of prevention, detection and response, this is likely to be a useful discussion to many organizations.</p>
<div>Come ready with good questions. I will also be available throughout the Summit for break-out discussions, one-on-ones, and small team meetings. Please reach out via email, phone or Twitter to schedule a sit down. Otherwise, feel free to approach me in the halls and we can have an ad-hoc discussion if you want to learn more about specific detection in depth approaches.</div>
<div> </div>
<div>I speak on Friday, May 18th at 11:15 am. <strong><a href="http://www.centralohioissa.org/?page_id=936">I hope to see you there!</a></strong></div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&text=Discuss+Detection+in+Depth+at+CMH+ISSA+Summit" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2421']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&title=Discuss+Detection+in+Depth+at+CMH+ISSA+Summit&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421&name=Discuss+Detection+in+Depth+at+CMH+ISSA+Summit&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2421']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2421" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2421</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Follow Up to Out of Band Authentication Post</title>
		<link>http://stateofsecurity.com/?p=2416&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=follow-up-to-out-of-band-authentication-post</link>
		<comments>http://stateofsecurity.com/?p=2416#comments</comments>
		<pubDate>Fri, 27 Apr 2012 10:00:59 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[Credit Unions]]></category>
		<category><![CDATA[Mobile Application Security]]></category>
		<category><![CDATA[Out of Bound Authentication]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2416</guid>
		<description><![CDATA[(This is a commentary follow up to my earlier post, located here.) A couple of folks have commented on Twitter that they have a fear of using SMS for any sort of security operations. There have been discussions about the &#8230; <a href="http://stateofsecurity.com/?p=2416">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/ServerRoom.png"><img class="alignleft size-full wp-image-2390" title="ServerRoom" src="http://stateofsecurity.com/wp-content/uploads/2012/04/ServerRoom.png" alt="" width="300" height="200" /></a>(This is a commentary follow up to my earlier post, located <strong><a href="http://stateofsecurity.com/?p=2388">here</a>.</strong>)</p>
<div>A couple of folks have commented on Twitter that they have a fear of using SMS for any sort of security operations. There have been discussions about the insecurity of SMS and the lack of attention to protecting the cellular network by carriers around the world. I generally disagree with blanket statements, and I would push for organizations considering SMS as a means of authentication to undertake a real risk assessment of the process before they jump in.</div>
<div> </div>
<div>However, if the controls in place in the cell networks meet their appetite for risk, then I think it is a perfectly acceptable business case. It certainly beats in-band simple authentication mechanisms like &#8220;pictures of trust&#8221; and traditional login/password as a security control.</div>
<div> </div>
<div>At least in SMS authentication, the attacker would usually need to have control over or access to more than one device belonging to the user. I think this helps make the risk model more acceptable for my views.</div>
<div> </div>
<div>Other folks discussed how Out of Band Authentication (OOBA) has been done now successfully in many places. I agree with this. We know how to do it. There are a LOT of vendors out there who can successfully integrate, deploy and manage a solution for you. Sadly, though, there are still more than a few who are struggling to get it right or done at all. As with most things in life, it helps to do a little research. Organizations should perform due diligence on their vendors and factor vendor risks into the equation of purchases and project planning. </div>
<div> </div>
<div>Lastly, a few folks commented on the fact that they, too, are running into speed bumps with deployments and logistics. Several folks echoed the sentiments of the original challenges and few offered suggestions beyond simply &#8220;doing more homework&#8221; and looking for &#8220;quickly scalable solutions&#8221;. The good news with this is that you are not alone out there. Other folks are facing AND BEATING challenges. Feel free to reach out to your peers and discuss what is and what isn&#8217;t working for them.</div>
<div> </div>
<div>As per the original post, the more communication and discussion we can have amongst the community about these topics, the better off we all will be. So, discuss, seriously…</div>
<div> </div>
<div>##Special thanks to the vendors that replied with case studies, references or stories about how they have done integration and deployment. There are a lot of good vendors out there with knowledge in this area. Careful review of their capabilities will help you sort them out from the less capable. Communication is key.</div>
<div> </div>
<div>Thanks for reading! </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&text=Follow+Up+to+Out+of+Band+Authentication+Post" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2416']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&title=Follow+Up+to+Out+of+Band+Authentication+Post&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416&name=Follow+Up+to+Out+of+Band+Authentication+Post&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2416']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2416" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2416</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Are You Attending the 2012 ISSA Central Ohio InfoSec Summit?</title>
		<link>http://stateofsecurity.com/?p=2410&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=are-you-attending-the-2012-issa-central-ohio-infosec-summit</link>
		<comments>http://stateofsecurity.com/?p=2410#comments</comments>
		<pubDate>Wed, 25 Apr 2012 17:42:11 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[InfoSec Summit]]></category>
		<category><![CDATA[ISSA]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2410</guid>
		<description><![CDATA[&#160; If you are in the midwest and can make it to Columbus for the ISSA Summit this year, you owe it to yourself to do so. Great speakers, great content, an amazing location and some of the best folks &#8230; <a href="http://stateofsecurity.com/?p=2410">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/ISSALogo.png"><img class="alignleft size-full wp-image-2411" title="ISSALogo" src="http://stateofsecurity.com/wp-content/uploads/2012/04/ISSALogo.png" alt="" width="656" height="145" /></a></p>
<p>&nbsp;</p>
<p>If you are in the midwest and can make it to Columbus for the ISSA Summit this year, you owe it to yourself to do so. Great speakers, great content, an amazing location and some of the best folks from around the world, for two days focused on infosec. It&#8217;s been amazing the past several years. You can find info online about it <strong><a href="http://www.centralohioissa.org/?page_id=936">here</a></strong>. </p>
<div>Some of the things I am looking forward to are getting to hear more from Richard Clarke (I might not always agree with his view, but he is an excellent speaker and a very good man.), and the rest of the speakers. In fact, there is not a speaker on the docket that I don&#8217;t think is amazing. We have developer insights, business folks, techno geeks, hackers, auditors and even a few MSI folks. </div>
<div> </div>
<div><strong>So, if you can come to town and be here May 17th and 18th, do so. If not, you&#8217;ll miss out on what is sure to be an amazing event.</strong></div>
<div> </div>
<div>Special thanks to the Columbus ISSA team for putting the event together. These folks work really hard to pull it off, and the volunteers on the day of the event go above and beyond to make it all happen. Please take a moment at the event and give them a pat on the back. If something would happen to go wrong, or could be done better, drop them a line in email and they will look at improving it next year. Thank them, in person, for all of the things that go right. Seriously, it helps. Even better, volunteer for the Summit and help them and the community out. It&#8217;s a great way to give back for all that the community does for all of us, all year long. </div>
<div> </div>
<div>Thanks for reading and we&#8217;ll see you at the Summit! </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&text=Are+You+Attending+the+2012+ISSA+Central+Ohio+InfoSec+Summit%3F" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2410']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&title=Are+You+Attending+the+2012+ISSA+Central+Ohio+InfoSec+Summit%3F&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410&name=Are+You+Attending+the+2012+ISSA+Central+Ohio+InfoSec+Summit%3F&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2410']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2410" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2410</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>HoneyPoint Internet Threat Monitoring Environment: An Easy Way to Pinpoint Known Attacker IPs</title>
		<link>http://stateofsecurity.com/?p=2401&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=honeypoint-internet-threat-monitoring-environment-an-easy-way-to-pinpoint-known-attacker-ips</link>
		<comments>http://stateofsecurity.com/?p=2401#comments</comments>
		<pubDate>Tue, 24 Apr 2012 15:19:25 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[Free Tool]]></category>
		<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[HoneyPoint]]></category>
		<category><![CDATA[HITME]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2401</guid>
		<description><![CDATA[One of the least understood parts of MicroSolved is how the HoneyPoint Internet Threat Monitoring Environment (#HITME) data is used to better protect our customers. If you don&#8217;t know about the #HITME, it is a set of deployed HoneyPoints that &#8230; <a href="http://stateofsecurity.com/?p=2401">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2011/04/HPWaspLogo2-160x208.png"><img class="alignleft size-full wp-image-1521" title="HPWaspLogo2-160x208" src="http://stateofsecurity.com/wp-content/uploads/2011/04/HPWaspLogo2-160x208.png" alt="" width="160" height="208" /></a><span style="font-size: medium;"><strong>One of the least understood parts of MicroSolved is how the HoneyPoint Internet Threat Monitoring Environment (#HITME) data is used to better protect our customers.</strong></span></p>
<p><strong><a href="https://twitter.com/#!/HoneyPoint">If you don&#8217;t know about the #HITME</a></strong>, it is a set of deployed HoneyPoints that gather real world, real time attacker data from around the Internet. The sensors gather attack sources, frequency, targeting information, vulnerability patterns, exploits, malware and other crucial event data for the technical team at MSI to analyze. You can even follow the real time updates of attacker IPs and target ports on Twitter by following <strong><a href="https://twitter.com/#!/HoneyPoint">@honeypoint</a></strong> or the #HITME hash tag. MSI licenses the data under Creative Commons, non-commercial and FREE as a public service to the security community.</p>
<p>That said, <strong>how does the #HITME help MSI better protect their customers?</strong> First, it allows folks to use the #HITME feed of known attacker IPs in a blacklist to block known scanners at their borders. This prevents the scanning tools and malware probes from ever reaching you to start with.</p>
<p>Next, the data from the #HITME is analyzed daily and the newest, bleeding edge attack signatures get added to the MSI assessment platform. That means that customers with ongoing assessments and vulnerability management services from MSI get continually tested against the most current forms of attack being used on the Internet. The #HITME data also gets updated into the MSI pen-testing and risk assessment methodologies, focusing our testing on real world attack patterns much more than vendors who rely on typical scanning tools and backdated threats from their last &#8220;yearly bootcamp&#8221;.</p>
<p>The #HITME data even flows back to the software vendors through a variety of means. MSI shares new attacks and possible vulnerabilities with the vendors, plus, open source projects targeted by attackers. Often MSI teaches those developers about the vulnerability, the possibilities for mitigation, and how to perform secure coding techniques like proper input validation. The data from the #HITME is used to provide the attack metrics and pattern information that MSI presents in its public speaking, the blog, and other educational efforts. Lastly, but certainly not least, MSI provides an ongoing alerting function for organizations whose machines are compromised. MSI contacts critical infrastructure organizations whose machines turn up in the #HITME data and works with them to mitigate the compromise and manage the threat. These data-centric services are provided, pro- bono, in 99% of all of the cases!</p>
<p><strong>If your organization would be interested in donating an Internet facing system to the #HITME project to further these goals, <a href="http://microsolved.com/?page_id=13">please contact us</a>.</strong> Our hope is that the next time you hear about the #HITME, you&#8217;ll get a smile on your face knowing that the members of our team are working hard day and night to protect MSI customers and the world at large. You can count on us, we&#8217;ve got your back!</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&text=HoneyPoint+Internet+Threat+Monitoring+Environment%3A+An+Easy+Way+to+Pinpoint+Known+Attacker+IPs" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2401']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&title=HoneyPoint+Internet+Threat+Monitoring+Environment%3A+An+Easy+Way+to+Pinpoint+Known+Attacker+IPs&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401&name=HoneyPoint+Internet+Threat+Monitoring+Environment%3A+An+Easy+Way+to+Pinpoint+Known+Attacker+IPs&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2401']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2401" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2401</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Financial Organizations Struggle with Out of Band Authentication</title>
		<link>http://stateofsecurity.com/?p=2388&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=financial-organizations-struggle-with-out-of-band-authentication</link>
		<comments>http://stateofsecurity.com/?p=2388#comments</comments>
		<pubDate>Fri, 20 Apr 2012 16:51:45 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[Credit Unions]]></category>
		<category><![CDATA[Mobile Application Security]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2388</guid>
		<description><![CDATA[Many of our client financial organizations have been working on implementing out of band authentication (OOBA) mechanisms for specific kinds of money transfers such as ACH and wires.  A few have even looked into performing OOBA for all home and &#8230; <a href="http://stateofsecurity.com/?p=2388">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/ServerRoom.png"><img class="alignleft size-full wp-image-2390" title="ServerRoom" src="http://stateofsecurity.com/wp-content/uploads/2012/04/ServerRoom.png" alt="" width="300" height="200" /></a><strong></strong></p>
<p><strong>Many of our client financial organizations have been working on implementing out of band authentication (OOBA) mechanisms for specific kinds of money transfers such as ACH and wires.</strong></p>
<p> A few have even looked into performing OOBA for all home and mobile banking access. While this authentication method does add some security to the process, effectively raising the bar for credential theft by the bad guys, it does not come without its challenges.</p>
<div>For starters, the implementation and integration of some of the software designed for this purpose has been a little more difficult than expected by many of the teams working on the projects. We are hearing that in some cases, the vendors are having difficulty integrating into some of the site platforms, particularly those not using .NET. Other platforms have been successful, but over time (and many over budget), the lesson learned is this: <strong>communicate clearly about the platforms in use when discussing implementations with potential vendors.</strong></div>
<div> </div>
<div>Other problems we have been hearing about include: availability issues with the number of outbound phone connections during peak use periods, issues with cellular carriers &#8220;losing&#8221; SMS messages (particularly a few non-top tier carriers), and integrating solutions into VoIP networks and old-style traditional PBX systems.</div>
<div> </div>
<div>In many cases, these telephonic and cellular issues have caused the systems to be withdrawn during pilot, even turned off for peak periods during use and other &#8220;fit and start&#8221; approaches as the rough patches were worked out. The lesson in this area seems to be to design for peak use as a consideration, or at least understand and communicate acceptable delays, outages or round-robin processes, and make sure that your systems properly communicate these parameters to the user.</div>
<div> </div>
<div>In the long run, proper communication to the users will lower the impact of the onslaught some of these systems call to the customer support and help desk folks.</div>
<div> </div>
<div>It is getting better though. Vendors are learning to more easily and effectively develop and implement these solutions. The impact on account theft has been strong so far and customers seem to have a rapid adjustment curve. In fact, a few of our clients have shared that they have received kudos from their members/customers for implementing these new tools when they were announced, documented, and explained properly to the user base.</div>
<div> </div>
<div>If your organization is considering this technology and has struggled with it, or has emerged victorious in the mastery of it; please drop me a line on Twitter (<a href="http://twitter.com/#!/lbhuston">@lbhuston</a>) and let me know your thoughts. The more we share about these tools, the better we can all get at making the road less bumpy for the public.</div>
<div> </div>
<div>As always, thanks for reading and stay safe out there!</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&text=Financial+Organizations+Struggle+with+Out+of+Band+Authentication" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2388']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&title=Financial+Organizations+Struggle+with+Out+of+Band+Authentication&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388&name=Financial+Organizations+Struggle+with+Out+of+Band+Authentication&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2388']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2388" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2388</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Audio Blog Post: How to Safeguard Your Data From Credit Card Theft</title>
		<link>http://stateofsecurity.com/?p=2379&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=audio-blog-post-how-to-safeguard-your-data-from-credit-card-theft</link>
		<comments>http://stateofsecurity.com/?p=2379#comments</comments>
		<pubDate>Wed, 18 Apr 2012 10:00:24 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[Audio Blog Post]]></category>
		<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Credit Card Theft]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2379</guid>
		<description><![CDATA[Cybercriminals continue to seek new opportunities to steal credit card data, highlighted recently in the largest credit card theft seen in two years &#8212; a 1.5 million loss from Global Payments, a third-party processor of transactions for Visa and Mastercard. &#8230; <a href="http://stateofsecurity.com/?p=2379">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2011/06/microphone.jpg"><img class="alignleft size-medium wp-image-1611" title="microphone" src="http://stateofsecurity.com/wp-content/uploads/2011/06/microphone-263x300.jpg" alt="" width="263" height="300" /></a><strong>Cybercriminals continue to seek new opportunities to steal credit card data, highlighted recently in the largest credit card theft seen in two years &#8212; <a href="http://www.csmonitor.com/USA/2012/0402/Global-Payments-credit-card-data-breach-How-big-is-the-theft">a 1.5 million loss from Global Payments</a>, a third-party processor of transactions for Visa and Mastercard.</strong></p>
<p>What can companies do? Also, what can you do to protect your credit card data?</p>
<p>I sat down with Brent Huston, CEO and Security Evangelist with MicroSolved, Inc. to discuss such questions. In this audio blog post, you&#8217;ll hear:</p>
<ol>
<li><strong>The current state of identity theft</strong></li>
<li><strong>Two primary ways credit cards get stolen</strong></li>
<li><strong>Skimming as a preferred model for theft and how to prevent it</strong></li>
<li><strong>Why being PCI-compliant is not a silver bullet</strong></li>
</ol>
<p>And more!</p>
<p><span style="font-size: x-large;"><strong><a href="https://s3.amazonaws.com/MSIMedia/BHCreditCardTheft.mp3">Click here to listen.</a></strong></span></p>
<p>Take a listen to this informative 15-minute interview and learn how you can protect your organization from data theft!</p>
<p>Resources:</p>
<ul>
<li><a href="http://microsolved.com/?page_id=291">The 80/20 Rule of Information Security</a></li>
<li><a href="http://microsolved.com/?page_id=9">HoneyPoint Security Server</a> (a superior detection product)</li>
<li><a href="https://www.pcisecuritystandards.org/">PCI Security Standards Council</a></li>
</ul>
<p>&nbsp;</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&text=Audio+Blog+Post%3A+How+to+Safeguard+Your+Data+From+Credit+Card+Theft" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2379']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&title=Audio+Blog+Post%3A+How+to+Safeguard+Your+Data+From+Credit+Card+Theft&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379&name=Audio+Blog+Post%3A+How+to+Safeguard+Your+Data+From+Credit+Card+Theft&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2379']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2379" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2379</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Remember Public Cellular Networks in Smart Meter Adoption</title>
		<link>http://stateofsecurity.com/?p=2372&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=remember-public-cellular-networks-in-smart-meter-adoption</link>
		<comments>http://stateofsecurity.com/?p=2372#comments</comments>
		<pubDate>Mon, 16 Apr 2012 14:22:28 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[SCADA/ICS]]></category>
		<category><![CDATA[ICS]]></category>
		<category><![CDATA[Public Cellular Networks]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2372</guid>
		<description><![CDATA[One of the biggest discussion points at the recent MEA Summit was the reliance of Smart Meter technology on the public cellular networks for communication. There seemed to be a great deal of confusion about negotiating private cellular communications versus &#8230; <a href="http://stateofsecurity.com/?p=2372">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/Networktower.png"><img class="alignleft size-full wp-image-2373" title="Networktower" src="http://stateofsecurity.com/wp-content/uploads/2012/04/Networktower.png" alt="" width="255" height="191" /></a><strong>One of the biggest discussion points at <a href="http://bit.ly/HzVTzk">the recent MEA Summit</a> was the reliance of Smart Meter technology on the public cellular networks for communication.</strong></p>
<p>There seemed to be a great deal of confusion about negotiating private cellular communications versus dependence on fully public networks. Many folks also described putting in their own femtocell and microcell deployments to greatly reduce the dependence on communication assets that they did not own. However, as you might expect, the purchase, install, management, and maintenance of private cellular infrastructure is expensive, requires skilled personnel, and often bumps into regulatory issues with frequency control and saturation.</p>
<div>Other considerations than cost also emerged with several ICS/SCADA owners discussing prioritization of repair issues versus consumer deployments, problems with negotiating effective, acceptable Service Level Agreements with the cell network vendors and a lack of understanding on the cell vendors&#8217; part about ICS/SCADA deployments/integration/criticality in general.</div>
<div> </div>
<div>Clearly, more analysis, study, and communication needs to occur between ICS/SCADA researchers/owners/developers and the relevant cellular network engineers/implementation teams to grow mutual knowledge and understanding between the parties. In the meantime, ICS/SCADA owners must strive to clearly identify their needs around cellular technologies, clearly demarcate the requirements for private/segmented/public cellular network use and understand the benefits/issues and threats of what they are utilizing. Cellular communications has a clear role to play in the future of ICS/SCADA, but the waters of how it will be managed, how it will be secured and how smaller organizations can obtain it affordably remain a bit muddy for now.</div>
<div> </div>
<div>If your organization has winning strategies or has concerns that have arisen with the use of cellular networks, we would love to hear about them in the comments. The more ICS/SCADA owners work together to bring this knowledge forward, the more quickly and effectively we can resolve many of the issues that utilities and other organizations are encountering.</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&text=Remember+Public+Cellular+Networks+in+Smart+Meter+Adoption" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2372']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&title=Remember+Public+Cellular+Networks+in+Smart+Meter+Adoption&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372&name=Remember+Public+Cellular+Networks+in+Smart+Meter+Adoption&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2372']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2372" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2372</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Getting Your ICS/SCADA Components Security Tested</title>
		<link>http://stateofsecurity.com/?p=2366&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=getting-your-icsscada-components-security-tested</link>
		<comments>http://stateofsecurity.com/?p=2366#comments</comments>
		<pubDate>Fri, 13 Apr 2012 18:57:11 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[SCADA/ICS]]></category>
		<category><![CDATA[ICS]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2366</guid>
		<description><![CDATA[Recently, at the MEA Summit, I had the opportunity to engage in a great discussion with a number of SCADA owners about security testing of their devices. Given all of the big changes underway concerning SCADA equipment, connectivity and the &#8230; <a href="http://stateofsecurity.com/?p=2366">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2010/07/j0316739.jpg"><img class="alignleft size-medium wp-image-1118" title="j0316739" src="http://stateofsecurity.com/wp-content/uploads/2010/07/j0316739-300x202.jpg" alt="" width="300" height="202" /></a>Recently, <a href="http://stateofsecurity.com/?p=2362">at the MEA Summit</a>, I had the opportunity to engage in a great discussion with a number of SCADA owners about security testing of their devices. Given all of the big changes underway concerning SCADA equipment, connectivity and the greater focus on these systems by attackers; the crowd had a number of questions about how they could get their new components tested in a lab environment prior to production deployment.</p>
<div>Device and application testing is something that MicroSolved has done for more than a decade. We have tested hundreds of IT hardware products, commercial software loads, web/mobile applications, consumer products, and for the last several years, ICS/SCADA and Smart Grid components. Our lab environments are suitable for a wide variety of testing scenarios and are used by utility companies, manufacturers and software developers from around the world as a trusted source for rational security testing and relevant threat analysis. We have a firm non-disclosure policy for client systems tested and the relevant vulnerabilities discovered and we often work hand in hand with the developers/design engineers to work through both mitigation and/or compensating control development.</div>
<div> </div>
<div>ICS/SCADA owners should have any new designs assessed prior to implementation, they should have some form of ongoing security assessment (analysis &#8211; NOT scanning…) performed against current deployments/threats, plus they should be engaged in testing all new hardware and software platforms before production adoption. Developers, designers and manufacturers of ICS/SCADA/Smart Grid components should be engaging in a full set of product assessments, attack surface analysis, threat modeling and penetration testing prior to the release of the products to market. This will be a value-add to your customers, and ultimately, to the consumer. </div>
<div> </div>
<div>If your organization would like to have a device or software analysis performed, or would like to discuss how to engage with MicroSolved to have new equipment or ICS/SCADA deployment ideas modeled, tested and assessed, please contact us. </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&text=Getting+Your+ICS%2FSCADA+Components+Security+Tested" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2366']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&title=Getting+Your+ICS%2FSCADA+Components+Security+Tested&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366&name=Getting+Your+ICS%2FSCADA+Components+Security+Tested&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2366']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2366" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2366</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Presentations Given at Midwest Energy Association Summit</title>
		<link>http://stateofsecurity.com/?p=2362&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=presentations-given-at-midwest-energy-association-summit</link>
		<comments>http://stateofsecurity.com/?p=2362#comments</comments>
		<pubDate>Thu, 12 Apr 2012 17:35:20 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2362</guid>
		<description><![CDATA[On April 11, 2012, both Phil Grimes and Brent Huston were honored to present on the ICS/SCADA security topics at the Spring Gas Operations Summit in Indianapolis held by the Midwest Energy Association (MEA). Phil covered the process of scoping &#8230; <a href="http://stateofsecurity.com/?p=2362">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong><a href="http://stateofsecurity.com/wp-content/uploads/2009/09/j0316965.jpg"><img class="alignleft size-medium wp-image-789" title="j0316965" src="http://stateofsecurity.com/wp-content/uploads/2009/09/j0316965-300x240.jpg" alt="" width="300" height="240" /></a>On April 11, 2012, both Phil Grimes and Brent Huston were honored to present on the ICS/SCADA security topics at the Spring Gas Operations Summit in Indianapolis held by the <a href="http://www.midwestenergy.org/">Midwest Energy Association</a> (MEA).</strong></p>
<p><strong></strong>Phil covered the process of scoping security assessments for ICS/SCADA deployments and spent a lot of time with the crowd analyzing various scenarios for how to pick an assessment partner, how often to perform vulnerability assessments, how to closely control and properly use penetration testing and a variety of other topics specific to the crowd&#8217;s concerns.</p>
<div>Brent followed that presentation with a talk focused on honeypots in ICS/SCADA. He covered the history of honeypots in ICS deployments, the NIST guidance for honeypots (&#8220;canaries&#8221;) and the relevant locations and approaches to gathering attack data with them. The crowd also asked great questions about how to use the data from the systems, how to work together to leverage honeypot data as an industry and how to manage data anonymity for detected events. </div>
<div> </div>
<div>Further discussions followed, with the MSI team sitting in the crowd as a round table, which went really well. They had excellent conversations about the state of the threat, the reliance on public infrastructures, cellular communication threats, network enclaving, detection techniques and the safety of Internet exposed HMIs.</div>
<div> </div>
<div>MSI would like to thank MEA for allowing us to come in and engage with their attendees. It was a very interesting show and we think everyone learned a lot about where ICS/SCADA security is going in the next 1-3 years.</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&text=Presentations+Given+at+Midwest+Energy+Association+Summit" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2362']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&title=Presentations+Given+at+Midwest+Energy+Association+Summit&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362&name=Presentations+Given+at+Midwest+Energy+Association+Summit&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2362']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2362" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2362</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Poll: An Opportunity to Tell Us Which Content You Like Most!</title>
		<link>http://stateofsecurity.com/?p=2350&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=poll-an-opportunity-to-tell-us-which-content-you-like-most</link>
		<comments>http://stateofsecurity.com/?p=2350#comments</comments>
		<pubDate>Tue, 10 Apr 2012 21:13:32 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[Poll]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2350</guid>
		<description><![CDATA[We always strive to bring you the best information security content, complete with thoughtful analysis and relevant resources. Would you take a few minutes to participate in our poll? We&#8217;d appreciate it because it will help us deliver the most &#8230; <a href="http://stateofsecurity.com/?p=2350">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/handtakingnotes.jpg"><img class="alignleft size-full wp-image-2352" title="handtakingnotes" src="http://stateofsecurity.com/wp-content/uploads/2012/04/handtakingnotes.jpg" alt="" width="300" height="225" /></a>We always strive to bring you the best information security content, complete with thoughtful analysis and relevant resources. Would you take a few minutes to participate in our poll? We&#8217;d appreciate it because it will help us deliver the most useful content. Thank you!</strong></p>
<p>&nbsp;</p>
<div id="surveyMonkeyInfo">
<div><script src="http://www.surveymonkey.com/jsEmbed.aspx?sm=sfhA4Usx0T0_2frSEZHId7zw_3d_3d"> </script></div>
<p>Create your <a href="http://www.surveymonkey.com/">free online surveys</a> with SurveyMonkey, the world&#8217;s leading questionnaire tool.</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&text=Poll%3A+An+Opportunity+to+Tell+Us+Which+Content+You+Like+Most%21" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2350']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&title=Poll%3A+An+Opportunity+to+Tell+Us+Which+Content+You+Like+Most%21&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350&name=Poll%3A+An+Opportunity+to+Tell+Us+Which+Content+You+Like+Most%21&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2350']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2350" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2350</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t Forget About VoIP Exposures and PBX Hacking</title>
		<link>http://stateofsecurity.com/?p=2336&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dont-forget-about-voip-exposures-and-pbx-hacking</link>
		<comments>http://stateofsecurity.com/?p=2336#comments</comments>
		<pubDate>Fri, 06 Apr 2012 15:52:50 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[Pen Testing & Vuln Mgmt]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PBX]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2336</guid>
		<description><![CDATA[&#160; &#160; &#160; &#160; &#160; &#160; I was browsing my usual data alerts for the day and ran into this set of data. It motivated me to write a quick blog post to remind folks that VoIP scans and probes &#8230; <a href="http://stateofsecurity.com/?p=2336">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong><a href="http://stateofsecurity.com/wp-content/uploads/2012/04/DontForget300.jpg"><img class="alignleft size-full wp-image-2341" title="DontForget300" src="http://stateofsecurity.com/wp-content/uploads/2012/04/DontForget300.jpg" alt="" width="300" height="300" /></a></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>I was browsing my usual data alerts for the day and ran into <a href="http://atlas.arbor.net/attacks/2008578">this set of data</a>. It motivated me to write a quick blog post to remind folks that VoIP scans and probes are still going on out there in the wild. </strong></p>
<p>These days, with all of the attention to mass compromises, infected web sites and stolen credit card data, voice systems can sometimes slip out of sight.</p>
<div>VoIP compromises and intrusions remain a threat. There are now a variety of tools, exploits and frameworks built for attacking VoIP installations and they are a target for both automated tools and manual hacking. Access to VoIP systems can provide a great platform for intelligence, recon, industrial espionage and traditional toll fraud.</div>
<div> </div>
<div>While VoIP might be the state of the art for phone systems today, there are still plenty of traditional PBX, auto-attendant and dial-up voicemail systems around too. Now might be a good time to review when those systems were last reviewed, audited or pen-tested. Traditional toll fraud is still painful to manage and recover from, so it&#8217;s probably worth spending a few cycles on reviewing these devices and their security postures. </div>
<div> </div>
<div>Let us know if your organization could use assistance with these items or with hardening voice systems, implementing detection techniques for them or otherwise increasing voice system security.</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&text=Don%26%238217%3Bt+Forget+About+VoIP+Exposures+and+PBX+Hacking" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2336']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&title=Don%26%238217%3Bt+Forget+About+VoIP+Exposures+and+PBX+Hacking&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336&name=Don%26%238217%3Bt+Forget+About+VoIP+Exposures+and+PBX+Hacking&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2336']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2336" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2336</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>HoneyPoint and HITME Helps Clients Take Out Malware</title>
		<link>http://stateofsecurity.com/?p=2332&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=honeypoint-and-hitme-helps-clients-take-out-malware</link>
		<comments>http://stateofsecurity.com/?p=2332#comments</comments>
		<pubDate>Thu, 05 Apr 2012 12:41:08 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2332</guid>
		<description><![CDATA[I wanted to share some great feedback we received this week from a couple of sources. Both are regarding HoneyPoint &#8212; our product for creating a platform of nuance detection and visibility. The first came from a critical infrastructure team. &#8230; <a href="http://stateofsecurity.com/?p=2332">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2010/07/HPSSwords-e1305141375725.jpg"><img class="alignleft size-medium wp-image-1097" title="HPSSwords" src="http://stateofsecurity.com/wp-content/uploads/2010/07/HPSSwords-265x300.jpg" alt="" width="265" height="300" /></a><strong>I wanted to share some great feedback we received this week from a couple of sources. Both are regarding HoneyPoint &#8212; our product for creating a platform of nuance detection and visibility.</strong></p>
<div>The first came from a critical infrastructure team. We notified them of an attack from their environment which was detected on the HITME (HoneyPoint Internet Threat Monitoring Environment). Using our alert, they quickly identified, investigated and isolated a specific machine that been infected with a piece of malware and was now scanning the Internet for other potential victims. They thanked us for the notification and said they truly appreciated our efforts and the work of the HITME team to help protect US critical infrastructures.</div>
<div> </div>
<div>The second bit of feedback came from a long-time user of HoneyPoint Wasp, who suddenly began to see a piece of code propagate across a few machines in their workstation space. The code was rapidly identified as a piece of malware that had successfully evaded their anti-virus, but triggered the Wasp white list detection mechanism. Their team traced the infection back to a single USB key, which they impounded and sanitized. Thankfully, they found this infection before it was able to be leveraged by an attacker against them. They were very supportive of HoneyPoint and thanked us for assisting them in their investigation and for teaching them how to use Wasp through our installation services.</div>
<div> </div>
<div>Together, these represent just a couple of the stories where HoneyPoint has helped security teams. Some of the people who receive the benefit of our work are not even users of the product or MicroSolved clients at all. It&#8217;s just another way that we engage every single day to help make a difference in the security and safety of peoples&#8217; lives.</div>
<div> </div>
<div>At MSI, we don&#8217;t just make great tools and perform great services, we have spent the last 20 years working hard to help people with information security. It continues to be both our pleasure and our passion.</div>
<div> </div>
<div>Thanks for reading! </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&text=HoneyPoint+and+HITME+Helps+Clients+Take+Out+Malware" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2332']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&title=HoneyPoint+and+HITME+Helps+Clients+Take+Out+Malware&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332&name=HoneyPoint+and+HITME+Helps+Clients+Take+Out+Malware&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2332']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2332" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2332</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Three Sources to Help You Understand Cybercrime</title>
		<link>http://stateofsecurity.com/?p=2324&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=three-sources-to-help-you-understand-cybercrime</link>
		<comments>http://stateofsecurity.com/?p=2324#comments</comments>
		<pubDate>Tue, 03 Apr 2012 20:29:50 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[cybercrime]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2324</guid>
		<description><![CDATA[Cybercrime is a growing threat. I thought I would take a few moments and point you to three recent news articles that discuss U.S. Government views on just how information security is proceeding, how we are doing, and how we &#8230; <a href="http://stateofsecurity.com/?p=2324">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong><a href="http://stateofsecurity.com/wp-content/uploads/2011/03/j0309602.jpg"><img class="alignleft size-medium wp-image-1436" title="j0309602" src="http://stateofsecurity.com/wp-content/uploads/2011/03/j0309602-214x300.jpg" alt="" width="214" height="300" /></a>Cybercrime is a growing threat.</strong> I thought I would take a few moments and point you to three recent news articles that discuss U.S. Government views on just how information security is proceeding, how we are doing, and how we should think about the future of infosec. They are all three interesting points of view and represent a wide variety of data seen at high levels:</p>
<div> </div>
<div><strong><a href="http://money.cnn.com/2012/03/02/technology/fbi_cybersecurity/index.htm">FBI Director Mueller on cybercrime (RSA Conference, March 2012)</a> </strong></div>
<div> </div>
<div><strong><a href="http://www.nytimes.com/2012/04/03/opinion/how-china-steals-our-secrets.html?_r=3">Perspectives on intellectual property theft</a></strong></div>
<div> </div>
<div><strong><a href="http://www.govtech.com/blogs/lohrmann-on-cybersecurity/Is-America-Outgunned-in-032812.html">How the U.S. is outgunned in cyber-defense</a></strong></div>
<div> </div>
<div><strong>These three links are interesting perspectives on how infosec is changing from a focus on compliance and prevention techniques to fully embracing the need for cross-platform, security-focused initiatives.</strong> In addition, more emphasis is on threats and risk while balancing prevention, detection capability, and effective responses when things go wrong.</div>
<div> </div>
<div>Long term, this change is an important one if we are to protect ourselves and the data of our customers in the future. Cybercrime won&#8217;t go away, but if we can approach security with proactive strategies, we may minimize its effectiveness. </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&text=Three+Sources+to+Help+You+Understand+Cybercrime" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2324']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&title=Three+Sources+to+Help+You+Understand+Cybercrime&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324&name=Three+Sources+to+Help+You+Understand+Cybercrime&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2324']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2324" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2324</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>MSI Strategy &amp; Tactics Talk Ep. 27: The 2012 Verizon Data Breach Investigations Report</title>
		<link>http://stateofsecurity.com/?p=2318&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=msi-strategy-tactics-talk-ep-27-the-2012-verizon-data-breach-investigations-report</link>
		<comments>http://stateofsecurity.com/?p=2318#comments</comments>
		<pubDate>Fri, 30 Mar 2012 18:42:10 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[MicroSolved's Strategies & Tactics Talks]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2318</guid>
		<description><![CDATA[The 2012 Verizon Data Breach Investigations Report is out!  In this episode of MSI Strategy &#38; Tactics, Adam, Phil, and John discuss the newest report&#8217;s discoveries and some of the more interesting discoveries.  Discussion questions include: 1. What was the most &#8230; <a href="http://stateofsecurity.com/?p=2318">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2011/06/microphone.jpg"><img class="alignleft size-thumbnail wp-image-1611" title="microphone" src="http://stateofsecurity.com/wp-content/uploads/2011/06/microphone-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p><span style="font-size: medium;"><strong>The 2012 Verizon Data Breach Investigations Report is out! </strong> In this episode of MSI Strategy &amp; Tactics, Adam, Phil, and John discuss the newest report&#8217;s discoveries and some of the more interesting discoveries.  Discussion questions include:</span></p>
<p><strong>1. What was the most surprising finding?<br />2. What is different from the past, any trends?</strong></p>
<p>Listen in and let us know what you think!</p>
<p>Resource:</p>
<p><a href="http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf"><strong>The Verizon Data Breach Investigations Report</strong></a></p>
<p>Panelists:</p>
<div>Adam Hostetler, Network Engineer, Security Analyst</div>
<div>Phil Grimes, Security Analyst</div>
<div>John Davis, Risk Management Engineer</div>
<div>Mary Rose Maguire, Marketing Communication Specialist and moderator</div>
<div> </div>
<div>
<p>Click the embedded player to listen. Or <strong><a href="http://www.talkshoe.com/tc/98708">click this link</a></strong> to access downloads. Stay safe!</p>
<p><object id="LastFramePlayer" width="173" height="60" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="false" /><param name="quality" value="high" /><param name="wmode" value="transparent" /><param name="src" value="http://www.talkshoe.com/resources/talkshoe/images/swf/lastEpisodePlayer.swf?fileUrl=http://recordings.talkshoe.com/TC-98708/TS-608895.mp3" /><param name="play" value="true" /><param name="loop" value="loop" /><param name="scale" value="exactfit" /><param name="salign" value="lt" /><param name="allowscriptaccess" value="always" /><param name="allowfullscreen" value="false" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" /><embed id="LastFramePlayer" width="173" height="60" type="application/x-shockwave-flash" src="http://www.talkshoe.com/resources/talkshoe/images/swf/lastEpisodePlayer.swf?fileUrl=http://recordings.talkshoe.com/TC-98708/TS-608895.mp3" allowScriptAccess="always" allowFullScreen="false" quality="high" wmode="transparent" play="true" loop="loop" scale="exactfit" salign="lt" allowscriptaccess="always" allowfullscreen="false" pluginspage="http://www.macromedia.com/go/getflashplayer" /></object></p>
</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&text=MSI+Strategy+%26amp%3B+Tactics+Talk+Ep.+27%3A+The+2012+Verizon+Data+Breach+Investigations+Report" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2318']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&title=MSI+Strategy+%26amp%3B+Tactics+Talk+Ep.+27%3A+The+2012+Verizon+Data+Breach+Investigations+Report&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318&name=MSI+Strategy+%26amp%3B+Tactics+Talk+Ep.+27%3A+The+2012+Verizon+Data+Breach+Investigations+Report&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2318']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2318" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2318</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Mobile Apps Shouldn&#8217;t Roll Their Own Security</title>
		<link>http://stateofsecurity.com/?p=2312&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mobile-apps-shouldnt-roll-their-own-security</link>
		<comments>http://stateofsecurity.com/?p=2312#comments</comments>
		<pubDate>Thu, 29 Mar 2012 13:50:51 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[Mobile Application Security]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[Mobile Apps]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2312</guid>
		<description><![CDATA[An interesting problem is occurring in the mobile development space. Many of the applications being designed are being done so by scrappy, product oriented developers. This is not a bad thing for innovation (in fact just the opposite), but it &#8230; <a href="http://stateofsecurity.com/?p=2312">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/03/cigarette.png"><img class="alignleft size-full wp-image-2313" title="cigarette" src="http://stateofsecurity.com/wp-content/uploads/2012/03/cigarette.png" alt="" width="302" height="207" /></a><span style="font-size: medium;"><strong>An interesting problem is occurring in the mobile development space. Many of the applications being designed are being done so by scrappy, product oriented developers. This is <em>not</em> a bad thing for innovation (in fact just the opposite), <em>but</em> it can be a bad thing for safety, privacy and security.</strong></span></p>
<p>Right now, we are hearing from several cross platform mobile developers that the API sets across iOS, Android and others are so complex, that they are often skipping some of the APIs and rolling their own code methods for doing some of this work. For example, take crypto from a set of data on the device. In many cases, rather than using standard peer-reviewed routines and leveraging the strength of the OS and its controls, they are saying the job is too complex for them to manage across platforms so they&#8217;ll embed their own code routines for doing what they feel is basic in-app crypto. </p>
<div>Problems (like those with the password vault applications), are likely to emerge from this approach toward mobile apps. There is a reason crypto controls require peer review. They are difficult and often complex mechanisms where mistakes in the logic or data flows can have huge impacts on the security of the data. We learned these lessons long ago. Home-rolled crypto and other common security routines were a big problem in the desktop days and still remain so for many web applications, as well. Sadly, it looks like we might be learning those lessons again at the mobile application development layer as well.</div>
<div> </div>
<div>Basically, the bottom line is this; if you are coding a mobile application, or buying one to access critical data for your organization, make sure the developers use the API code for privacy, trust and security functions. Stay away from mobile apps where &#8220;roll your own/proprietary security code&#8221; is in use. The likelihood of getting it right is a LOT less than using the APIs, methods and code that the mobile OS vendors have made accessible. It&#8217;s likely that the OS vendors are using peer-reviewed, strongly tested code. Sadly, we can&#8217;t say that for all of the mobile app developer code we have seen.</div>
<div> </div>
<div>As always, thanks for reading and stay safe out there!</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&text=Mobile+Apps+Shouldn%26%238217%3Bt+Roll+Their+Own+Security" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2312']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&title=Mobile+Apps+Shouldn%26%238217%3Bt+Roll+Their+Own+Security&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312&name=Mobile+Apps+Shouldn%26%238217%3Bt+Roll+Their+Own+Security&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2312']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2312" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2312</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Disagreement on Password Vault Software Findings</title>
		<link>http://stateofsecurity.com/?p=2303&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=disagreement-on-password-vault-software-findings</link>
		<comments>http://stateofsecurity.com/?p=2303#comments</comments>
		<pubDate>Mon, 26 Mar 2012 14:08:08 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[Opinion]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2303</guid>
		<description><![CDATA[Recently, some researchers have been working on comparing password vault software products and have justifiably found some issues. However, many of the vendors are quickly moving to remediate the identified issues, many of which were simply improper use of proprietary &#8230; <a href="http://stateofsecurity.com/?p=2303">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2010/12/1208422_89744071.jpg"><img class="alignleft size-medium wp-image-1256" title="1208422_89744071" src="http://stateofsecurity.com/wp-content/uploads/2010/12/1208422_89744071-300x199.jpg" alt="" width="300" height="199" /></a><span style="font-size: medium;"><strong>Recently, some researchers have been working on comparing password vault software products and have justifiably found some issues. However, many of the vendors are quickly moving to remediate the identified issues, many of which were simply improper use of proprietary cryptography schemes.</strong></span></p>
<p>I agree that proprietary crypto is a bad thing, but I find fault with articles such as<strong><a href="http://www.novainfosecportal.com/2012/03/20/mobile-password-managers-fail/" target="_blank"> this one</a></strong> where the researchers suggest that using the built in iOS functions are safer than using a password vault tool.</p>
<div>Regardless of OS, platform or device, I fail to see how depending on simple OS embedded tools versus OS embedded tools, plus the additional layers of whatever mechanisms a password vault adds, reduces risk to the user. It would seem that the additional layers of control (regardless of their specific vulnerability to nuanced attacks against each control surface), would still add overall security for the user and complexity for the attacker to manage in a compromise.</div>
<div> </div>
<div>I would love to see a model on this scenario where the additional controls reduce the overall security of the data. I could be wrong (it happens), but in the models I have run, they all point to the idea that even a flawed password vault wrapped in the OS controls are stronger and safer than the bare OS controls alone.</div>
<div> </div>
<div>In the meantime, while the vendors work on patching their password vaults and embracing common crypto mechanisms, I&#8217;ll continue to use my password vault as is, wrapped in the additional layers of OS controls and added detection mechanisms my systems enjoy. I would suggest you and your organization&#8217;s users continue to do the same.</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&text=Disagreement+on+Password+Vault+Software+Findings" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2303']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&title=Disagreement+on+Password+Vault+Software+Findings&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303&name=Disagreement+on+Password+Vault+Software+Findings&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2303']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2303" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2303</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Security Is More Than Prevention</title>
		<link>http://stateofsecurity.com/?p=2290&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=information-security-is-more-than-prevention</link>
		<comments>http://stateofsecurity.com/?p=2290#comments</comments>
		<pubDate>Fri, 23 Mar 2012 09:45:48 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2290</guid>
		<description><![CDATA[&#160; &#160; &#160; &#160; &#160; &#160; One of the biggest signs that an organization&#8217;s information security program is immature is when they have an obsessive focus on prevention and they equate it specifically with security. The big signs of this &#8230; <a href="http://stateofsecurity.com/?p=2290">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/03/magnifyingglass400.jpg"><img class="alignleft size-full wp-image-2291" title="magnifyingglass400" src="http://stateofsecurity.com/wp-content/uploads/2012/03/magnifyingglass400.jpg" alt="" width="400" height="267" /></a><strong></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>One of the biggest signs that an organization&#8217;s information security program is immature is when they have an obsessive focus on prevention and they equate it specifically with security.</strong></p>
<p>The big signs of this issue are knee-jerk reactions to vulnerabilities, a never-ending set of emergency patching situations and continual fire-fighting mode of reactions to &#8220;incidents&#8221;. The security team (or usually the IT team) is overworked, under-communicates, is highly stressed, and lacks both resources and tools to adequately mature the process. Rarely does the security folks actually LIKE this environment, since it feeds their inner super hero complex.</p>
<div>However, time and time again, organizations that balance prevention efforts with rational detection and practiced, effective response programs perform better against today&#8217;s threats. Evidence from vendor reports like Verizon DBIR/Ponemon, law enforcement data, DHS studies, etc. have all supported that balanced program work much better. The current state of the threat easily demonstrates that you can&#8217;t prevent everything. Accidents and incidents do happen. </div>
<div> </div>
<div>When bad things do come knocking, no matter how much you have patched and scanned, it&#8217;s the preparation you have done that matters. It&#8217;s whether or not you have additional controls like enclaving in place. Do you have visibility at various layers for <a href="http://stateofsecurity.com/?p=1958">detection in depth</a>? Does your team know how to investigate, isolate and mitigate the threats? Will they do so in a timely manner that reduces the impact of the attacker or will they panic, knee-jerk their way through the process, often stumbling and leaving behind footholds of the attacker?</div>
<div> </div>
<div>How you perform in the future is largely up to you and your team. Raise your vision, embrace a balanced approach to security and step back from fighting fires. It&#8217;s a much nicer view from here. </div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&text=Information+Security+Is+More+Than+Prevention" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2290']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&title=Information+Security+Is+More+Than+Prevention&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290&name=Information+Security+Is+More+Than+Prevention&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2290']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2290" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2290</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Secure Networks: Remember the DMZ in 2012</title>
		<link>http://stateofsecurity.com/?p=2284&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=secure-networks-remember-the-dmz-in-2012</link>
		<comments>http://stateofsecurity.com/?p=2284#comments</comments>
		<pubDate>Wed, 21 Mar 2012 17:53:40 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[DMZ]]></category>
		<category><![CDATA[IT Network Design]]></category>
		<category><![CDATA[Network Segmentation]]></category>
		<category><![CDATA[Secure Networks]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2284</guid>
		<description><![CDATA[Just a quick post to readers to make sure that everyone (and I mean everyone), who reads this blog should be using a DMZ, enclaved, network segmentation approach for any and all Internet exposed systems today. This has been true &#8230; <a href="http://stateofsecurity.com/?p=2284">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2011/04/IsItSafeComputerLock.jpg"><img class="alignleft size-medium wp-image-1533" title="IsItSafeComputerLock" src="http://stateofsecurity.com/wp-content/uploads/2011/04/IsItSafeComputerLock-199x300.jpg" alt="" width="199" height="300" /></a><strong>Just a quick post to readers to make sure that everyone (and I mean <em>everyone</em>), who reads this blog should be using a DMZ, enclaved, network segmentation approach for any and all Internet exposed systems today.</strong> This has been true for several years, if not a decade. Just this week, I have talked to two companies who have been hit by malicious activity that compromised a web application and gave the attacker complete control over a box sitting INSIDE their primary business network with essentially unfettered access to the environment.</p>
<div>Folks, within IT network design, DMZ architectures are not just for best practices and regulatory requirements, but an essential survival tool for IT systems. Punching a hole from the Internet to your primary IT environment is not smart, safe, or in many cases, legal.</div>
<div> </div>
<div><strong>Today, enclaving the internal network is becoming best practice to secure networks.</strong> Enclaving/DMZ segmentation of Internet exposed systems is simply assumed. So, take an hour, review your perimeter, and if you find internally exposed systems &#8212; make a plan and execute it. In the meantime, I&#8217;d investigate those systems as if they were compromised, regardless of what you have seen from them. At least check them over with a cursory review and get them out of the business network ASAP.</div>
<div> </div>
<div>This should go without saying, but this especially applies to folks that have SCADA systems and critical infrastructure architectures.</div>
<div> </div>
<div>If you have any questions regarding how you can maintain secure networks with enclaving and network segmentation, <strong><a href="http://microsolved.com/?page_id=13">let us know</a></strong>. We&#8217;d love to help!</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&text=Secure+Networks%3A+Remember+the+DMZ+in+2012" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2284']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&title=Secure+Networks%3A+Remember+the+DMZ+in+2012&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284&name=Secure+Networks%3A+Remember+the+DMZ+in+2012&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2284']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2284" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2284</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>10 Ways to Handle Insider Threats</title>
		<link>http://stateofsecurity.com/?p=2273&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=10-ways-to-handle-insider-threats</link>
		<comments>http://stateofsecurity.com/?p=2273#comments</comments>
		<pubDate>Mon, 19 Mar 2012 22:13:33 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2273</guid>
		<description><![CDATA[&#160; &#160; &#160; &#160; &#160; &#160; As the economic crisis continues, the possibility of an insider threat occurring within a company increases. Close to 50% of all companies have been hit by insider attacks, according to a recent study by Carnegie &#8230; <a href="http://stateofsecurity.com/?p=2273">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2012/03/typiinghands.jpg"><img class="alignleft size-full wp-image-2276" title="typiinghands" src="http://stateofsecurity.com/wp-content/uploads/2012/03/typiinghands.jpg" alt="" width="400" height="263" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>As the economic crisis continues, the possibility of an insider threat occurring within a company increases. Close to 50% of all companies have been hit by insider attacks, according to a recent study by Carnegie Mellon&#8217;s CERT Insider Threat Center. (<a href="http://search.cert.org/search?q=fifty+percent+companies&amp;btnG=Search&amp;entqr=0&amp;sort=date%3AD%3AL%3Ad1&amp;output=xml_no_dtd&amp;btnG.y=0&amp;client=default_frontend&amp;btnG.x=0&amp;ud=1&amp;oe=UTF-8&amp;ie=UTF-8&amp;proxystylesheet=default_frontend&amp;site=default_collection">Click here</a> to access the page that has the PDF download, &#8220;Insider Threat Study.&#8221;)</p>
<p>It doesn’t help when companies are restructuring and handing out pink slips. The result of leaner departments means that often there are less employees to notice when someone is doing something wrong. Tough economic times may also make it tempting for an employee to switch his ‘white hat’ to a black one for financial gain. Insider threats include employees, contractors, auditors, and anyone who has authorized access to an organization’s computers. How can you minimize the risk? Here are a few tips:</p>
<p><strong>1.</strong> <strong>Monitor and enforce security policies. </strong>Update the controls and oversee implementation.</p>
<p><strong>2.</strong> <strong>Initiate employee awareness programs. </strong>Educate the staff about security awareness and the possibility of them being coerced into malicious activities.</p>
<p><strong>3.</strong> <strong>Start paying attention to new hires. </strong>Keep an eye out for repeated violations that may be laying the groundwork for more serious criminal activity.</p>
<p><strong>4.</strong> <strong>Work with human resources to monitor negative employee issues. </strong>Most insider IT sabotage attacks occur following a termination.</p>
<p><strong>5.</strong> <strong>Carefully distribute resources. </strong>Only give employees what they need to do their jobs. </p>
<p><strong>6.</strong> <strong>If your organization develops software, monitor the process. </strong>Pay attention to the service providers and vendors.</p>
<p><strong>7.</strong> <strong>Approach privileged users with extra care. </strong>Use the two-man rule for critical projects. Those who know technology are more likely to use technological means for revenge if they perceive they’ve been wronged.</p>
<p><strong>8.</strong> <strong>Monitor employees’ online activity, especially around the time an employee is terminated. </strong>There is a good chance the employee isn’t satisfied and may be tempted to engage in an attack. </p>
<p><strong>9.</strong> <strong>Go deep in your defense plan to </strong><strong>counter remote attacks. </strong>If employees know they are being monitored, there is a good possibility an unhappy worker will use remote control to gain access. </p>
<p><strong>10.</strong> <strong>Deactivate computer access once the employee is terminated. </strong>This will immediately end any malicious activity such as copying files or sabotaging the network.</p>
<p>Be vigilant with your security backup plan. There is no approach that will guarantee a complete defense against insider attacks, but if you continue to practice secure backup, you can decrease the damage. Stay safe!</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&text=10+Ways+to+Handle+Insider+Threats" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2273']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&title=10+Ways+to+Handle+Insider+Threats&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273&name=10+Ways+to+Handle+Insider+Threats&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2273']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2273" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2273</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>MSI Strategy &amp; Tactics Talk Ep. 26: Hacking Back or Strikeback Technologies</title>
		<link>http://stateofsecurity.com/?p=2271&#038;utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=msi-strategy-tactics-talk-ep-26-hacking-back-or-strikeback-technologies</link>
		<comments>http://stateofsecurity.com/?p=2271#comments</comments>
		<pubDate>Fri, 16 Mar 2012 16:25:25 +0000</pubDate>
		<dc:creator>Mary Rose Maguire</dc:creator>
				<category><![CDATA[MicroSolved's Strategies & Tactics Talks]]></category>
		<category><![CDATA[hacking back]]></category>
		<category><![CDATA[honey pot technology]]></category>
		<category><![CDATA[HoneyPoint]]></category>
		<category><![CDATA[strikeback]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=2271</guid>
		<description><![CDATA[Hacking back or strikeback technologies is a system  engineering term that could occur in a situation with a positive loop, whereby each component responds with an increased reaction to the response of the other component, and so the problem gets worse &#8230; <a href="http://stateofsecurity.com/?p=2271">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&amp;source=MicroSolved&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2011/06/microphone.jpg"><img class="alignleft size-thumbnail wp-image-1611" title="microphone" src="http://stateofsecurity.com/wp-content/uploads/2011/06/microphone-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p><span style="font-size: medium;"><strong>Hacking back or strikeback technologies is a system  engineering term that could occur in a situation with a positive loop, whereby each component responds with an increased reaction to the response of the other component, and so the problem gets worse and worse. (<em>The Information Security Dictionary: Defining the Terms That Define Security</em>, by Urs E. Gattiker) Recently, a honey pot was created with some strikeback technology in the code. </strong> In this episode of MSI Strategy &amp; Tactics, Brent Huston and the techs discuss the various aspects of this technology and how it would affect you.  Discussion questions include:</span></p>
<ol>
<li><strong>What is the history of strike back, hacking back and how does it apply to today when you have major teams working to take down bot nets and such?</strong></li>
<li><strong>HoneyPoint has a type of technology called &#8220;defensive fuzzing&#8221; which does something that has been compared to strikeback. How it is different than other technologies?</strong></li>
<li><strong>What is the current take on the legality of strikeback/hacking back? Are organizations being put at risk if they attack their attackers or if their security teams go on offense?</strong></li>
</ol>
<div>Panelists:</div>
<div>Brent Huston, CEO and Security Evangelist</div>
<div>Adam Hostetler, Network Engineer, Security Analyst</div>
<div>Phil Grimes, Security Analyst</div>
<div>John Davis, Risk Management Engineer</div>
<div>Mary Rose Maguire, Marketing Communication Specialist and moderator</div>
<div> </div>
<div>
<p>Click the embedded player to listen. Or <strong><a href="http://www.talkshoe.com/tc/98708">click this link</a></strong> to access downloads. Stay safe!</p>
<p><object id="LastFramePlayer" width="173" height="60" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="false" /><param name="quality" value="high" /><param name="wmode" value="transparent" /><param name="src" value="http://www.talkshoe.com/resources/talkshoe/images/swf/lastEpisodePlayer.swf?fileUrl=http://recordings.talkshoe.com/TC-98708/TS-603820.mp3" /><param name="play" value="true" /><param name="loop" value="loop" /><param name="scale" value="exactfit" /><param name="salign" value="lt" /><param name="allowscriptaccess" value="always" /><param name="allowfullscreen" value="false" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" /><embed id="LastFramePlayer" width="173" height="60" type="application/x-shockwave-flash" src="http://www.talkshoe.com/resources/talkshoe/images/swf/lastEpisodePlayer.swf?fileUrl=http://recordings.talkshoe.com/TC-98708/TS-603820.mp3" allowScriptAccess="always" allowFullScreen="false" quality="high" wmode="transparent" play="true" loop="loop" scale="exactfit" salign="lt" allowscriptaccess="always" allowfullscreen="false" pluginspage="http://www.macromedia.com/go/getflashplayer" /></object></p>
</div>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Facebook','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//facebook.png" alt="Facebook" width="52.285714285714" height="18"></a> <a href="http://twitter.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&text=MSI+Strategy+%26amp%3B+Tactics+Talk+Ep.+26%3A+Hacking+Back+or+Strikeback+Technologies" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Twitter','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//twitter.png" alt="Twitter" width="52.285714285714" height="18"></a> <a href="mailto:?subject=Check out http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271" style="text-decoration: none; white-space: nowrap;" title="Email" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Email','http://stateofsecurity.com/?p=2271']); "><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//email.png" alt="Email" width="52.285714285714" height="18"></a> <a href="http://www.linkedin.com/shareArticle?mini=true&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&ro=false&summary=&source=" style="text-decoration: none; white-space: nowrap;" title="Linkedin" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Linkedin','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//linkedin.png" alt="Linkedin" width="52.285714285714" height="18"></a> <a href="http://digg.com/submit?partner=addthis&url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&title=MSI+Strategy+%26amp%3B+Tactics+Talk+Ep.+26%3A+Hacking+Back+or+Strikeback+Technologies&bodytext=" style="text-decoration: none; white-space: nowrap;" title="Digg" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Digg','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//digg.png" alt="Digg" width="52.285714285714" height="18"></a> <a href="http://www.reddit.com/login?dest=%2Fsubmit%3Furl=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271" style="text-decoration: none; white-space: nowrap;" title="Reddit" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Reddit','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=700,height=500'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//reddit.png" alt="Reddit" width="52.285714285714" height="18"></a> <a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&title=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271" style="text-decoration: none; white-space: nowrap;" title="Stumbleupon" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Stumbleupon','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=750,height=450'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//stumbleupon.png" alt="Stumbleupon" width="52.285714285714" height="18"></a> <a href="http://www.tumblr.com/share/link?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271&name=MSI+Strategy+%26amp%3B+Tactics+Talk+Ep.+26%3A+Hacking+Back+or+Strikeback+Technologies&description=" style="text-decoration: none; white-space: nowrap;" title="Tumblr" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Tumblr','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=500,height=400'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//tumblr.png" alt="Tumblr" width="52.285714285714" height="18"></a> <a href="http://posterous.com/share?linkto=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271" style="text-decoration: none; white-space: nowrap;" title="Posterous" target="_blank" onclick="that=this;_gaq.push(['_trackEvent','SocialSharing','Posterous','http://stateofsecurity.com/?p=2271']); _trackableshare_window = window.open(this.href,'share','menubar=0,resizable=1,width=900,height=600'); _trackableshare_window.focus(); return false;"><img align="absmiddle" src="http://stateofsecurity.com/wp-content/plugins/trackable-social-share-icons/buttons/z1//posterous.png" alt="Posterous" width="52.285714285714" height="18"></a> <br /><div style="padding: 5px 0 0;"><fb:like href="http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D2271" send="true" width="450" show_faces="false" font=""></fb:like></div></div>]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&#038;p=2271</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

