<?xml version="1.0"?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/_common/xslt/rss.xslt"?>
<rss version="2.0">
<channel>
<title>Infosecurity - Blog</title>
<link>http://www.infosecurity-magazine.com/blog/</link>
<description></description>
<copyright>Copyright Elsevier Ltd</copyright>
<generator>Intuitiv Ltd (www.intuitiv.net)</generator>
<lastBuildDate>Thu, 17 May 2012 00:37:27 GMT</lastBuildDate>
<image>
<title>Infosecurity - Blog</title>
<link>http://www.infosecurity-magazine.com/blog/</link>
<url>http://www.infosecurity-magazine.com/_common/img/template/infosec-uk/site-logo.gif</url>
</image>
<item>
<title>Quocirca’s Report from Infosecurity Europe 2012</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/8/quocircas-report-from-infosecurity-europe-2012/548.aspx</link>
<description>&lt;p&gt;The end of April was a busy time for IT security analysts. April 24&lt;sup&gt;th&lt;/sup&gt; to 26&lt;sup&gt;th&lt;/sup&gt; was &lt;a href=&quot;http://www.infosec.co.uk/&quot;&gt;Infosecurity Europe&lt;/a&gt; (InfoSec) at Earl&amp;rsquo;s Court, the biggest such trade show in Europe and the following week was the Eskenzi PR annual IT Security A ...</description>
<pubDate>Tue, 08 May 2012 09:20:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/8/quocircas-report-from-infosecurity-europe-2012/548.aspx</guid>
</item>
<item>
<title>Apples and Oranges = Apple and Microsoft?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/2/apples-and-oranges--apple-and-microsoft/546.aspx</link>
<description>&lt;p&gt;Several people have asked me for a response to Eugene Kaspersky&amp;rsquo;s views on Apple, &lt;font color=&quot;#800080&quot;&gt;&lt;a href=&quot;http://malware.cbronline.com/news/apple-10-years-behind-microsoft-on-security-kaspersky-250412&quot;&gt;as expressed at Infosecurity Europe&lt;/a&gt;&lt;/font&gt;&amp;nbsp;last week, suggesting that App ...</description>
<pubDate>Wed, 02 May 2012 14:57:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/2/apples-and-oranges--apple-and-microsoft/546.aspx</guid>
</item>
<item>
<title>Outsourcing B2B Integration: The Forgotten Option</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/1/outsourcing-b2b-integration-the-forgotten-option/545.aspx</link>
<description>&lt;h5&gt;By Stuart Lisk&amp;nbsp;&lt;/h5&gt;
&lt;p&gt;Business continuity remains a major concern for enterprises as they move more mission-critical processes to the cloud. Outsourcing B2B integration while ensuring cloud security in order to effectively integrate business processes is challenging at best, and ambiguou ...</description>
<pubDate>Tue, 01 May 2012 20:19:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/1/outsourcing-b2b-integration-the-forgotten-option/545.aspx</guid>
</item>
<item>
<title>Addressing the Consumerization of IT</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/26/addressing-the-consumerization-of-it/543.aspx</link>
<description>&lt;p&gt;&lt;em&gt;Bring Your Own Device&lt;/em&gt; or &lt;em&gt;Consumerization of IT&lt;/em&gt; are fairly hot themes in a lot of customer organizations. When I talk to customers, there are typically different reactions, once we bring this up. Some tell us that it is not part of their strategy; some tell us that they plan to d ...</description>
<pubDate>Thu, 26 Apr 2012 18:50:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/26/addressing-the-consumerization-of-it/543.aspx</guid>
</item>
<item>
<title>Configuration Compliance in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/25/configuration-compliance-in-the-cloud/542.aspx</link>
<description>&lt;h5&gt;By David Meltzer&lt;/h5&gt;
&lt;p&gt;As a member solution provider in the Cloud Security Alliance, paying careful attention to risk and planning for improvement is second nature for my own companies&amp;rsquo; security services.  As a consumer of many start-up cloud services built completely outside the securi ...</description>
<pubDate>Wed, 25 Apr 2012 20:05:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/25/configuration-compliance-in-the-cloud/542.aspx</guid>
</item>
<item>
<title>Changing Workforce Dynamics: Unleash the Power of the Professional Community</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/19/changing-workforce-dynamics-unleash-the-power-of-the-professional-community/540.aspx</link>
<description>&lt;div&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau (EWB)&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;The title of a recent &lt;i&gt;InformationWeek &lt;/i&gt;article, &lt;a href=&quot;http://www.informationweek.com/news/global-cio/interviews/2326017 ...</description>
<pubDate>Thu, 19 Apr 2012 12:11:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/19/changing-workforce-dynamics-unleash-the-power-of-the-professional-community/540.aspx</guid>
</item>
<item>
<title>Pining for Failure in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/18/pining-for-failure-in-the-cloud/539.aspx</link>
<description>&lt;p&gt;I missed &lt;a href=&quot;http://www.cio.com/article/703064/How_Secure_Is_the_Cloud_IT_Pros_Speak_Up&quot;&gt;this info-graphic&lt;/a&gt; first time around, so thanks to &lt;a href=&quot;http://securecloudreview.com/&quot;&gt;securecloudreview.com&lt;/a&gt;&amp;nbsp;for posting a link. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Like all info-graphics, it makes the proces ...</description>
<pubDate>Wed, 18 Apr 2012 23:00:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/18/pining-for-failure-in-the-cloud/539.aspx</guid>
</item>
<item>
<title>Apple OS X and Risk Reduction</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/16/apple-os-x-and-risk-reduction/538.aspx</link>
<description>&lt;p&gt;Some of the confidence Mac users have in the security of their chosen operating system derives from over-reliance on proactive patching. This outbreak highlights the need to be aware that patching of known vulnerabilities in system software or applications is not necessarily prompt enough to fore ...</description>
<pubDate>Mon, 16 Apr 2012 13:07:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/16/apple-os-x-and-risk-reduction/538.aspx</guid>
</item>
<item>
<title>The Consequences of Failing to Backup Network and Security Devices</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/16/the-consequences-of-failing-to-backup-network-and-security-devices/537.aspx</link>
<description>&lt;p&gt;Most IT users will have suffered the frustration of losing work because their access device (PC, tablet, smartphone etc.) fails and has not been backed up, or indeed they may have deleted a file accidentally. This is inconvenient for the individual and those associated with the project they are w ...</description>
<pubDate>Mon, 16 Apr 2012 09:41:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/16/the-consequences-of-failing-to-backup-network-and-security-devices/537.aspx</guid>
</item>
<item>
<title>Cloud Security Requires All Hands on Deck </title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/13/cloud-security-requires-all-hands-on-deck-/536.aspx</link>
<description>&lt;h5&gt;By Andrew Wild&lt;/h5&gt;
&lt;p&gt;It&amp;rsquo;s clear there are many compelling reasons, both financial and productivity-related, for enterprises to move IT functionality into the cloud, so it&amp;rsquo;s not surprising that they&amp;rsquo;re moving quickly to adopt popular collaboration services like Box.net, Yamme ...</description>
<pubDate>Fri, 13 Apr 2012 16:11:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/13/cloud-security-requires-all-hands-on-deck-/536.aspx</guid>
</item>
<item>
<title>Flashbacks and Backtracks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/6/flashbacks-and-backtracks/535.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;font-family: 'Calibri','sans-serif'; font-size: 11pt&quot;&gt;If you follow my &lt;a href=&quot;http://macviruscom.wordpress.com/&quot;&gt;&lt;span style=&quot;color: purple&quot;&gt;Mac Virus blog&lt;/span&gt;&lt;/a&gt;, you&amp;rsquo;ll have noticed that I&amp;rsquo;ve been tracking some of the coverage of Mac malware incidents to hit my ra ...</description>
<pubDate>Fri, 06 Apr 2012 11:15:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/6/flashbacks-and-backtracks/535.aspx</guid>
</item>
<item>
<title>Hacktivists Fail to Uphold a Proud Tradition of Protest</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/3/hacktivists-fail-to-uphold-a-proud-tradition-of-protest/534.aspx</link>
<description>&lt;p&gt;A&amp;nbsp;recent law enforcement sting corralled 25 alleged members of the Anonymous hacktivist group. As it turns out, the information fed to the FBI and other participating agencies came from within: Hector Xavier Monsegur (aka, &amp;lsquo;Sabu&amp;rsquo;) leader of the Anonymous offshoot LulzSec, had app ...</description>
<pubDate>Tue, 03 Apr 2012 19:34:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/3/hacktivists-fail-to-uphold-a-proud-tradition-of-protest/534.aspx</guid>
</item>
<item>
<title>Windows Desktop Admin Rights – An Open Door for Malware?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/3/windows-desktop-admin-rights--an-open-door-for-malware/533.aspx</link>
<description>&lt;p&gt;Quocirca has written extensively about privileged user management over the years, including two research reports &lt;a href=&quot;http://www.osirium.com/alpha-files/wp&quot;&gt;Conquering the sys-admin challenge&lt;/a&gt; in 2011 and &lt;a href=&quot;http://www.quocirca.com/reports/430/privileged-user-management--its-time-to- ...</description>
<pubDate>Tue, 03 Apr 2012 18:09:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/3/windows-desktop-admin-rights--an-open-door-for-malware/533.aspx</guid>
</item>
<item>
<title>OS X Malware: A Steady Trickle</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/26/os-x-malware-a-steady-trickle/529.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;color: #1f497d&quot;&gt;I&amp;rsquo;m guessing that the myth of OS X invulnerability to malware is pretty much busted by now: at any rate, there has been wave after wave of OS X-related malware reports in the past week or two. &lt;a href=&quot;http://nakedsecurity.sophos.com/2012/03/20/topless-supermode ...</description>
<pubDate>Mon, 26 Mar 2012 13:52:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/26/os-x-malware-a-steady-trickle/529.aspx</guid>
</item>
<item>
<title>Secure Cloud – Myth or Reality?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/19/secure-cloud--myth-or-reality/528.aspx</link>
<description>&lt;h5&gt;By Chris Hinkley&lt;/h5&gt;
&lt;p&gt;Cloud Security is not a myth. It can be achieved. The biggest hindrance on debunking this myth is for enterprise businesses to begin thinking about the Cloud differently. It is not the equipment of co-location dedicated servers, or on-premises technology, as it is chang ...</description>
<pubDate>Mon, 19 Mar 2012 17:36:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/19/secure-cloud--myth-or-reality/528.aspx</guid>
</item>
<item>
<title>State and Local Governments Saying ‘Bye-bye’ to CISOs?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/17/state-and-local-governments-saying-byebye-to-cisos/527.aspx</link>
<description>&lt;h5&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;At a recent &lt;a href=&quot;http://www.governing.com/events/Outlook-in-the-States--Localities-Conference-2012.html?p=agenda&quot;&gt;GOVERNING&lt;/a&gt; Conference in DC, s ...</description>
<pubDate>Sat, 17 Mar 2012 12:57:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/17/state-and-local-governments-saying-byebye-to-cisos/527.aspx</guid>
</item>
<item>
<title>OSX/Imuler: the Image-Conscious Trojan</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/16/osximuler-the-imageconscious-trojan/526.aspx</link>
<description>&lt;p&gt;Intego recently posted some &lt;a href=&quot;http://blog.intego.com/new-version-of-imuler-trojan-horse-masquerades-as-image-files/&quot;&gt;information on its blog&lt;/a&gt; concerning the Imuler information-stealing Trojan. The variant that Intego calls OSX/Imuler.C uses a different stealth/social engineering techniq ...</description>
<pubDate>Fri, 16 Mar 2012 17:08:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/16/osximuler-the-imageconscious-trojan/526.aspx</guid>
</item>
<item>
<title>Reducing the Number of Sys-admin Errors</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/14/reducing-the-number-of-sysadmin-errors/525.aspx</link>
<description>&lt;p&gt;In recent &lt;a href=&quot;http://www.osirium.com/alpha-files/wp&quot;&gt;Quocirca research&lt;/a&gt;, businesses report that on average their system administrators (sys-admins) make errors carrying out about 6% of tasks. This might not sound like much, but actually it adds up to quite a big number.&lt;/p&gt;
&lt;div style=&quot;m ...</description>
<pubDate>Wed, 14 Mar 2012 08:42:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/14/reducing-the-number-of-sysadmin-errors/525.aspx</guid>
</item>
<item>
<title>Pennsylvania Voter ID Law: A Solution Without a Problem
</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/14/pennsylvania-voter-id-law-a-solution-without-a-problem/524.aspx</link>
<description>&lt;p&gt;I was driving home today from a conference on online copyright enforcement, and in case you missed our frenzy of Tweets ( &lt;a href=&quot;https://twitter.com/#!/InfosecurityMag&quot;&gt;#copyrightcitp&lt;/a&gt;) live from the event, I promise to write more about it in our upcoming news feature on anti-piracy legislat ...</description>
<pubDate>Wed, 14 Mar 2012 00:39:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/14/pennsylvania-voter-id-law-a-solution-without-a-problem/524.aspx</guid>
</item>
<item>
<title>Dogs Are for Life, ‘NOT’ Just for Christmas</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/13/dogs-are-for-life-not-just-for-christmas/523.aspx</link>
<description>&lt;p&gt;I believe security professionals have something special &amp;ndash; they have the knowledge to effect change, and to assist our individual communities, societies, and with proactive willingness to engage, to make that difference, no matter how small, to help secure those who may be exposed to bad thi ...</description>
<pubDate>Tue, 13 Mar 2012 20:11:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/13/dogs-are-for-life-not-just-for-christmas/523.aspx</guid>
</item>
<item>
<title>Security Professionals Do Use AV: Even On Macs…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/12/security-professionals-do-use-av-even-on-macs/522.aspx</link>
<description>&lt;p&gt;I&amp;rsquo;m slightly surprised to realize it&amp;rsquo;s almost exactly a month since I blogged here, but I was travelling for a lot of that time (a slightly confusing mixture of work and vacation). Still, I&amp;rsquo;m pleased to see that an email conversation I had with Esther Shein about OS X, security, ...</description>
<pubDate>Mon, 12 Mar 2012 22:20:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/12/security-professionals-do-use-av-even-on-macs/522.aspx</guid>
</item>
<item>
<title>Seeing Through the Clouds: Gaining Confidence when Physical Access to Your Data Is Removed</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/12/seeing-through-the-clouds-gaining-confidence-when-physical-access-to-your-data-is-removed/520.aspx</link>
<description>&lt;h5&gt;By David Lingenfelter&lt;/h5&gt;
&lt;p&gt;Cloud computing brings with it new opportunities, new frontiers, new challenges, and new chances for loss of intellectual property.  From hosting simple websites, to entire development environments, companies have been experimenting with cloud-based services for so ...</description>
<pubDate>Mon, 12 Mar 2012 19:44:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/12/seeing-through-the-clouds-gaining-confidence-when-physical-access-to-your-data-is-removed/520.aspx</guid>
</item>
<item>
<title>Lock Box: Where Should You Store Cloud Encryption Keys?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/12/lock-box-where-should-you-store-cloud-encryption-keys/519.aspx</link>
<description>&lt;h5&gt;By Todd Thiemann&lt;/h5&gt;
&lt;p&gt;Whether driven by regulatory compliance or corporate mandates, sensitive data in the cloud needs protection along with access control. This usually involves encrypting data in transit as well as data at rest in some way, shape or form, and then managing the encryption k ...</description>
<pubDate>Mon, 12 Mar 2012 19:07:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/12/lock-box-where-should-you-store-cloud-encryption-keys/519.aspx</guid>
</item>
<item>
<title>Satellite of the Motor </title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/8/satellite-of-the-motor-/517.aspx</link>
<description>&lt;p&gt;I watched some very interesting television this week on the, thus far ignored, potential danger posed by Solar Storms. This, however, for myself was a cast-back to 1998 when I was working with the industrial giant, General Motors (GM).&lt;/p&gt;
&lt;p&gt;GM, like a number of other &amp;lsquo;truly&amp;rsquo; global ...</description>
<pubDate>Thu, 08 Mar 2012 20:13:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/8/satellite-of-the-motor-/517.aspx</guid>
</item>
<item>
<title>Organisations Failing to Close-off the Risks of Legacy Privileged Accounts</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/7/organisations-failing-to-closeoff-the-risks-of-legacy-privileged-accounts/516.aspx</link>
<description>&lt;p&gt;If you are trying to compromise an organisation&amp;rsquo;s IT systems in some way, then you need to have access. Getting a given user&amp;rsquo;s log in details is a starting point but might not get you that far, unless they are a user with privilege. Privileged users have much wider ranging access than ...</description>
<pubDate>Wed, 07 Mar 2012 12:41:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/7/organisations-failing-to-closeoff-the-risks-of-legacy-privileged-accounts/516.aspx</guid>
</item>
<item>
<title>CSIRTainly no Chickens Welcome</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/3/csirtainly-no-chickens-welcome/515.aspx</link>
<description>&lt;p&gt;For some time now, and for some strange reason, there has been an opinion that the biggest threat organisations face was from within their own walls, originating from the very people who have been provisioned with authorised access to corporate systems and information assets. Whilst I agree that  ...</description>
<pubDate>Sat, 03 Mar 2012 13:49:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/3/csirtainly-no-chickens-welcome/515.aspx</guid>
</item>
<item>
<title>Facing Up to the Application Security Challenge</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/2/facing-up-to-the-application-security-challenge/514.aspx</link>
<description>&lt;div style=&quot;margin-bottom: 0.0001pt;&quot;&gt;A new Quocirca report underlines the scale of the application security challenge faced by businesses. The average enterprise tracks around 500 mission critical applications, in financial services organisations it is closer to 800. The security challenge arises b ...</description>
<pubDate>Fri, 02 Mar 2012 12:49:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/2/facing-up-to-the-application-security-challenge/514.aspx</guid>
</item>
<item>
<title>The Silver ‘Plated’ Bullet</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/23/the-silver-plated-bullet/512.aspx</link>
<description>&lt;p&gt;I am certain that each and every reader will be familiar with the Term &amp;lsquo;Penetration Testing&amp;rsquo;&amp;nbsp;&amp;ndash; that panacea of assurance, sometimes promised to deliver ultimate levels of security to protect systems and information assets alike. I am equally confident many, if not all, read ...</description>
<pubDate>Thu, 23 Feb 2012 20:56:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/23/the-silver-plated-bullet/512.aspx</guid>
</item>
<item>
<title>Deprovisioning in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/23/deprovisioning-in-the-cloud/511.aspx</link>
<description>&lt;h5&gt;By Jon-Michael C. Brook&lt;/h5&gt;
&lt;p&gt;Let's be honest: how many of you have tried logging in to one of your former employer&amp;rsquo;s accounts?  Maybe you had a CRM solution and you wanted to get the name of that guy who suggested he had the next hot idea.  You didn't set your out-of-office message wit ...</description>
<pubDate>Thu, 23 Feb 2012 20:20:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/23/deprovisioning-in-the-cloud/511.aspx</guid>
</item>
<item>
<title>Horror from Beyond the Cloud (with caffeine)</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/23/horror-from-beyond-the-cloud-with-caffeine/510.aspx</link>
<description>&lt;p&gt;Let me tell you what the work of a reclusive horror writer and a morning cup of coffee can teach us about attitudes toward cloud computing.&lt;/p&gt;
&lt;p&gt;The horror writer is &lt;a href=&quot;http://en.wikipedia.org/wiki/HPLovecraft&quot;&gt;Howard Phillips Lovecraft&lt;/a&gt; (known by his initials &amp;ldquo;H.P.&amp;rdquo;). In  ...</description>
<pubDate>Thu, 23 Feb 2012 15:40:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/23/horror-from-beyond-the-cloud-with-caffeine/510.aspx</guid>
</item>
<item>
<title>Xerox and McAfee: A joint force to integrate security into the print world</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/17/xerox-and-mcafee-a-joint-force-to-integrate-security-into-the-print-world/508.aspx</link>
<description>&lt;p&gt;This blog post was written by Quocirca's print speciailst, Louella Ferandes&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;text-align: justify; &quot;&gt;Despite a continued reliance on printing, many businesses overlook print security in their overall approach to data protection. This may be set to change with the recent announc ...</description>
<pubDate>Fri, 17 Feb 2012 10:48:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/17/xerox-and-mcafee-a-joint-force-to-integrate-security-into-the-print-world/508.aspx</guid>
</item>
<item>
<title>SIMple Insecurity</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/15/simple-insecurity/507.aspx</link>
<description>&lt;p&gt;Are Security Professional blessed with super-human power, or is it that they possess x-ray vision to see through the matrix of normality, seeing those wide open insecurities; or is it they possess some special sixth-sense which feels the 'presence' of exposures and vulnerabilities &amp;ndash; I wonde ...</description>
<pubDate>Wed, 15 Feb 2012 19:58:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/15/simple-insecurity/507.aspx</guid>
</item>
<item>
<title>Safe Authentication for Remote Sys-Admin Tasks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/15/safe-authentication-for-remote-sysadmin-tasks/506.aspx</link>
<description>&lt;p&gt;Not all systems administration (sys-admin) is done by people. Some applications need administrator access to communicate and make changes. Furthermore, remote management tasks are often carried out using pre-set procedures in sys-admin tools, for example the backup of branch office devices.&lt;/p&gt;
 ...</description>
<pubDate>Wed, 15 Feb 2012 15:56:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/15/safe-authentication-for-remote-sysadmin-tasks/506.aspx</guid>
</item>
<item>
<title>Malware: a Matter of Definition</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/13/malware-a-matter-of-definition/505.aspx</link>
<description>&lt;p&gt;Kurt Wismer has just put up a blog asking &lt;a href=&quot;http://anti-virus-rants.blogspot.com/2012/02/is-iphone-really-malware-free.html&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;is the iphone really malware free?&lt;/font&gt;&lt;/a&gt; (Don&amp;rsquo;t be put off by the trademark absence of capitalization). Wismer is not illiterate and ...</description>
<pubDate>Mon, 13 Feb 2012 18:33:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/13/malware-a-matter-of-definition/505.aspx</guid>
</item>
<item>
<title>Opportunity Knocks Once…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/10/opportunity-knocks-once/504.aspx</link>
<description>&lt;h5&gt;By Henry St. Andre&lt;/h5&gt;
&lt;p&gt;In 1983, I was a young electrical engineering student, when I took a job working for a small long distance company in Phoenix, Arizona.  For me, Opportunity had Knocked and I had just opened the door on an amazing future.  In the world of communications, things were a ...</description>
<pubDate>Fri, 10 Feb 2012 20:00:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/10/opportunity-knocks-once/504.aspx</guid>
</item>
<item>
<title>The Theme Continues – Internet D&#233;j&#224; Vu</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/7/the-theme-continues--internet-dj-vu/503.aspx</link>
<description>&lt;p&gt;Reading the observations, and recommendations of Dame Pauline Neville-Jones with respect of Internet Security, I must admit to having a flow of D&amp;eacute;j&amp;agrave; vu sweep over me. This driven by statements of a Government Minister who said &amp;ldquo;we need to speed up work on cyber security becaus ...</description>
<pubDate>Tue, 07 Feb 2012 20:55:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/7/the-theme-continues--internet-dj-vu/503.aspx</guid>
</item>
<item>
<title>What Can a Hacker Do with Stolen WiFi Credentials?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/3/what-can-a-hacker-do-with-stolen-wifi-credentials/502.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;Palatino Linotype&amp;quot;,&amp;quot;serif&amp;quot;&quot;&gt;Recently HTC acknowledged a vulnerability that can expose a user&amp;rsquo;s WiFi credentials, including the WiFi SSID and security passwords to a malicious app running on some of its Android phones. Th ...</description>
<pubDate>Fri, 03 Feb 2012 14:19:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/3/what-can-a-hacker-do-with-stolen-wifi-credentials/502.aspx</guid>
</item>
<item>
<title>Facebook Goes Public – Time to Pop the Privacy Champagne? </title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/2/facebook-goes-public--time-to-pop-the-privacy-champagne-/501.aspx</link>
<description>&lt;p&gt;First, please excuse me for letting my inner Archie Bunker vent a little. If you are anything like me, then you could care less about updating your Facebook page on an hourly basis. Sure, I have a page, but maintaining it is both a bore and a chore (pardon my weak rhyming scheme). What are even w ...</description>
<pubDate>Thu, 02 Feb 2012 19:46:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/2/facebook-goes-public--time-to-pop-the-privacy-champagne-/501.aspx</guid>
</item>
<item>
<title>Hacking Made Easy</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/2/hacking-made-easy/500.aspx</link>
<description>&lt;p&gt;I am honoured to have been invited back to present at the prestigious e-Crime Congress to be held in London, March this year. However it caused a flash-back to the last occasion I presented at Congress in 2009, when things seemed to be very different.&lt;/p&gt;
&lt;p&gt;It was around that time when myself,  ...</description>
<pubDate>Thu, 02 Feb 2012 09:21:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/2/hacking-made-easy/500.aspx</guid>
</item>
<item>
<title>Trustworthy Computing: Looking Back to Look Forward</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/1/trustworthy-computing-looking-back-to-look-forward/499.aspx</link>
<description>&lt;p&gt;Anniversaries are often a time to reflect on the past but also to look to the future. A major anniversary in the field of computer security was reached on the 15th of January this year. That date marked the 10th anniversary of Bill Gates' famous memo marking the start of Microsoft's &lt;a href=&quot;http ...</description>
<pubDate>Wed, 01 Feb 2012 17:14:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/1/trustworthy-computing-looking-back-to-look-forward/499.aspx</guid>
</item>
<item>
<title>Industrial Strength Insecurity – Coffee &amp; Pie</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/25/industrial-strength-insecurity--coffee--pie/497.aspx</link>
<description>&lt;p&gt;You can't make an omelette without breaking a few eggs, or in this case grating a few nerves. However, the 'King has no Clothes' approach has never really worked for me, or for that matter, as an instrument to cloak, what would seem to be a sprinkling of lacklustre strategies for defending agains ...</description>
<pubDate>Wed, 25 Jan 2012 11:48:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/25/industrial-strength-insecurity--coffee--pie/497.aspx</guid>
</item>
<item>
<title>iOS Jailbreaking: Does Absinthe Make the Heart Grow Fonder?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/23/ios-jailbreaking-does-absinthe-make-the-heart-grow-fonder/496.aspx</link>
<description>&lt;p&gt;Kevin Townsend asked me for my opinion on iGadget jailbreaking, in the light of the recent release of Absinthe, a jailbreaking tool for the iPhone 4s and iPad 2. As a result, I&amp;rsquo;m quoted in a &lt;a href=&quot;http://www.infosecurity-magazine.com/view/23391/jailbreak-for-iphone-4s-released/&quot;&gt;useful a ...</description>
<pubDate>Mon, 23 Jan 2012 19:22:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/23/ios-jailbreaking-does-absinthe-make-the-heart-grow-fonder/496.aspx</guid>
</item>
<item>
<title>Web of Protest</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/18/web-of-protest/495.aspx</link>
<description>&lt;p&gt;We have come to expect the Internet to be leveraged by Hacktivists to carry their political, or commercial bashing message forward to the masses. We realise that the opportunities presented by the global media channel of the Internet can be utilised to gain access to a reading public made up of b ...</description>
<pubDate>Wed, 18 Jan 2012 13:13:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/18/web-of-protest/495.aspx</guid>
</item>
<item>
<title>Organisational Responsibility
</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/18/organisational-responsibility/494.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;Message to &amp;lsquo;Wikipedia&amp;rsquo;, &amp;lsquo;Google&amp;rsquo;, and &amp;lsquo;Craigslist&amp;rsquo;:&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;We can all protest, but is it acceptable and professional to impact the public?&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;</description>
<pubDate>Wed, 18 Jan 2012 13:06:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/18/organisational-responsibility/494.aspx</guid>
</item>
<item>
<title>I Keep Getting Flashbacks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/16/i-keep-getting-flashbacks/492.aspx</link>
<description>&lt;p&gt;2012 was looking quite quiet in Apple security terms up to now, but I see that the guys behind the &lt;a href=&quot;http://blog.eset.com/2011/09/27/new-apple-os-x-malware-fake-adobe-flash-installer&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;OSX/Flashback Trojan&lt;/font&gt;&lt;/a&gt; are quietly beavering away. No sooner had &amp;nbsp;Appl ...</description>
<pubDate>Mon, 16 Jan 2012 17:19:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/16/i-keep-getting-flashbacks/492.aspx</guid>
</item>
<item>
<title>Computer says NO</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/13/computer-says-no/491.aspx</link>
<description>&lt;p&gt;It was back in 1999&amp;nbsp;I worked for General Motors (GM), when the topic of internet enabled automobiles entered my professional vocabulary. Around that era, GM were researching the future scene of the motor-car, leveraging a technology called OnStar. At that time, being one of only a few securi ...</description>
<pubDate>Fri, 13 Jan 2012 11:02:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/13/computer-says-no/491.aspx</guid>
</item>
<item>
<title>10 Years of Trustworthy Computing at Microsoft</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/12/10-years-of-trustworthy-computing-at-microsoft/490.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://aka.ms/twcnext&quot;&gt;&lt;img width=&quot;148&quot; vspace=&quot;5&quot; height=&quot;148&quot; border=&quot;0&quot; src=&quot;http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-50-43-twcnext/1488.TwC_2D00_Tile_5F00_148x148_2D00_wShadow.png&quot; alt=&quot;TwC Next&quot; style=&quot;margin: 0px 1 ...</description>
<pubDate>Thu, 12 Jan 2012 19:58:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/12/10-years-of-trustworthy-computing-at-microsoft/490.aspx</guid>
</item>
<item>
<title>Casablanca in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/11/casablanca-in-the-cloud/489.aspx</link>
<description>&lt;p&gt;I thought &lt;a href=&quot;http://searchcloudcomputing.techtarget.com/news/2240102241/To-cloud-skeptics-Dont-diss-Dropbox&quot;&gt;this piece&lt;/a&gt;&amp;nbsp;by Jo Maitland over at SearchCloudComputing.com was interesting, because it so closely reflects the experiences of a large number of businesses faced with the spe ...</description>
<pubDate>Wed, 11 Jan 2012 19:41:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/11/casablanca-in-the-cloud/489.aspx</guid>
</item>
<item>
<title>Implications of Wi-Fi Protected Setup Vulnerability </title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/9/implications-of-wifi-protected-setup-vulnerability-/488.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;Palatino Linotype&amp;quot;,&amp;quot;serif&amp;quot;&quot;&gt;&lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/12/29/enabling-wps-can-make-you-vulnerable/486.aspx&quot;&gt;After mentioning briefly&lt;/a&gt; about the recently discovered Wi-Fi Protected Setup (WPS) vulnerability due to certain design flaws in  ...</description>
<pubDate>Mon, 09 Jan 2012 14:38:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/9/implications-of-wifi-protected-setup-vulnerability-/488.aspx</guid>
</item>
<item>
<title>Yellow Dog-Food</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/9/yellow-dogfood/487.aspx</link>
<description>&lt;p&gt;You may have noticed that when it comes to security, 2011 was not one of the best years, with events occurring, ranging from Sony, through to HBGary, and RSA. However, the concern, and focus here is on the two events which impacted organisations that trade in security, as forgive me if I am being ...</description>
<pubDate>Mon, 09 Jan 2012 09:30:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/9/yellow-dogfood/487.aspx</guid>
</item>
<item>
<title>Enabling WPS Can Make You Vulnerable</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/29/enabling-wps-can-make-you-vulnerable/486.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;&quot;&gt;Adding to the users convenience, Wi-Fi is increasingly becoming a default capability of many consumer devices, including smartphones, printers, cameras, TVs, etc. to wirelessly share contents, access Internet or connect to a particular network. &amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div style=&quot;text-a ...</description>
<pubDate>Thu, 29 Dec 2011 16:29:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/29/enabling-wps-can-make-you-vulnerable/486.aspx</guid>
</item>
<item>
<title>DLP &amp; the Mega Plug</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/29/dlp--the-mega-plug/485.aspx</link>
<description>&lt;p&gt;It is every professional organisations desire to keep their valuable IPR safe, secure, and beyond the reach of compromise. To achieve this, many invest in some form of DLP application to assure security is accommodated. However, it is here where the creeping disease of over dependency on applicat ...</description>
<pubDate>Thu, 29 Dec 2011 11:43:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/29/dlp--the-mega-plug/485.aspx</guid>
</item>
<item>
<title>10 Reasons to Migrate Off Windows XP</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/22/10-reasons-to-migrate-off-windows-xp/483.aspx</link>
<description>&lt;p&gt;I would like you to sit back, close your eyes and think about the year 2001. Think about how you used technology back then, how you used the Internet. Now, let&amp;rsquo;s take it a little bit further back in history and think of the year 2000. Just after we realized that the Year-2000-Problem was ha ...</description>
<pubDate>Thu, 22 Dec 2011 10:48:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/22/10-reasons-to-migrate-off-windows-xp/483.aspx</guid>
</item>
<item>
<title>Looking Into The Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/21/looking-into-the-cloud/482.aspx</link>
<description>&lt;p&gt;As we roll up to the end of the year it's usually time to start making predictions about what will happen next year. But since Drew and the team already did a &lt;a href=&quot;http://www.infosecurity-magazine.com/view/22567/2012-threat-predictions-an-industry-roundup/&quot;&gt;great job of that&lt;/a&gt;&amp;nbsp;I'll ins ...</description>
<pubDate>Wed, 21 Dec 2011 21:20:32 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/21/looking-into-the-cloud/482.aspx</guid>
</item>
<item>
<title>On the Eighth day of Christmas my true love gave to me – ‘Dog Food!’</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/21/on-the-eighth-day-of-christmas-my-true-love-gave-to-me--dog-food/481.aspx</link>
<description>&lt;p&gt;Well, here we are at Christmas Blog number four, and in this run-up to the most magical time of the year, we have considered Security Awareness, Santa, and NORAD &amp;ndash; a very interesting mix. However, let&amp;rsquo;s move on to the really interesting bit &amp;ndash; the giving, and RECEIVING of present ...</description>
<pubDate>Wed, 21 Dec 2011 13:05:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/21/on-the-eighth-day-of-christmas-my-true-love-gave-to-me--dog-food/481.aspx</guid>
</item>
<item>
<title>Holiday Prediction Presents: Mind Your Website’s Navigation Layer</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/19/holiday-prediction-presents-mind-your-websites-navigation-layer/480.aspx</link>
<description>&lt;p&gt;From time to time, I try to share some of our reader feedback via this blog, whether it is positive or negative. As each year draws to a close, our editorial inbox gets bombarded with threat predictions of all kinds for the upcoming year. Some are company-wide predictions, others come from indivi ...</description>
<pubDate>Mon, 19 Dec 2011 17:04:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/19/holiday-prediction-presents-mind-your-websites-navigation-layer/480.aspx</guid>
</item>
<item>
<title>Small Eruption in Peru*: Not Many Infected</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/19/small-eruption-in-peru-not-many-infected/479.aspx</link>
<description>&lt;p&gt;[This is probably my last article here for 2011. Compliments of the season to you all.]&lt;/p&gt;
&lt;p&gt;Inevitably, my attention was drawn last week to an article on Mich Kabay&amp;rsquo;s &lt;a href=&quot;http://infosecreviews.com/perception/&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;Infosec Perception&lt;/font&gt;&lt;/a&gt; based on an essay by ...</description>
<pubDate>Mon, 19 Dec 2011 13:23:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/19/small-eruption-in-peru-not-many-infected/479.aspx</guid>
</item>
<item>
<title>Moving on Up   </title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/19/moving-on-up---/478.aspx</link>
<description>&lt;p&gt;&lt;strong&gt;Within industry circles, 2011 has become known as the year of the hack, or the year of the black hat if you prefer. &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Game-changing malware has exploded, proving that the critical national infrastructure is under threat and that cyber war and cyber espionage are very daunt ...</description>
<pubDate>Mon, 19 Dec 2011 11:31:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/19/moving-on-up---/478.aspx</guid>
</item>
<item>
<title>Should Cybersecurity be Treated as a Profession? Your Opinion Counts</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/16/should-cybersecurity-be-treated-as-a-profession-your-opinion-counts/477.aspx</link>
<description>&lt;h5&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;It takes many, many years for a business area of focus to emerge as a recognized profession. Certainly, cybersecurity is moving in that direction. How  ...</description>
<pubDate>Fri, 16 Dec 2011 14:45:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/16/should-cybersecurity-be-treated-as-a-profession-your-opinion-counts/477.aspx</guid>
</item>
<item>
<title>Giving Thanks to the Infosec Professionals </title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/giving-thanks-to-the-infosec-professionals-/476.aspx</link>
<description>&lt;p&gt;In what may qualify as a profound understatement, the past year has been challenging for security professionals across the globe. &lt;/p&gt;
&lt;p&gt;Much of what infosec professionals do goes unnoticed, except when things go wrong. And 2011 has had no shortage of these black-eye events. Allow me, however,  ...</description>
<pubDate>Wed, 14 Dec 2011 19:36:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/giving-thanks-to-the-infosec-professionals-/476.aspx</guid>
</item>
<item>
<title>On the Seventh day of Christmas my true love gave to me ‘A Trip to see Santa’
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/on-the-seventh-day-of-christmas-my-true-love-gave-to-me-a-trip-to-see-santa/475.aspx</link>
<description>&lt;p&gt;Well the Seventh day really did bring a prize, in the form of a trip to get close to that very special person who only works once a year. A person who travels faster than Superman &amp;ndash; a person every single kid in the world loves. Yes, you have got it, no other than Father Christmas &amp;ndash; AK ...</description>
<pubDate>Wed, 14 Dec 2011 15:25:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/on-the-seventh-day-of-christmas-my-true-love-gave-to-me-a-trip-to-see-santa/475.aspx</guid>
</item>
<item>
<title>Software Insecurity Thrives</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/software-insecurity-thrives/474.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The fourth half-yearly &lt;a href=&quot;http://www.infosecurity-magazine.com/view/22518/more-than-8-in-10-software-applications-fail-security-test-says-veracode/&quot;&gt;State of Software Security Report&lt;/a&gt; from cloud-based application security tester Veracode makes for painful reading. Based on ...</description>
<pubDate>Wed, 14 Dec 2011 13:02:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/software-insecurity-thrives/474.aspx</guid>
</item>
<item>
<title>Secure Disposal of Old IT Equipment</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/secure-disposal-of-old-it-equipment/473.aspx</link>
<description>&lt;p&gt;Network and security devices age just like any other IT equipment. As the IT industry moves toward 100 gigabit/second Ethernet and 100 megabit/second broadband connections, many existing devices will no longer cope with traffic volumes. The need to replace routers, firewalls, load-balancers, cont ...</description>
<pubDate>Wed, 14 Dec 2011 08:26:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/secure-disposal-of-old-it-equipment/473.aspx</guid>
</item>
<item>
<title>Implementing the Top 4 Defense Strategies</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/13/implementing-the-top-4-defense-strategies/472.aspx</link>
<description>&lt;p&gt;The Australian Defense Signals Directorate maintains a list of the &lt;a target=&quot;_blank&quot; href=&quot;http://www.dsd.gov.au/infosec/top35mitigationstrategies.htm&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Top 35 Mitigation Strategies&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; against targeted intrusions. This is just a reference to the top  ...</description>
<pubDate>Tue, 13 Dec 2011 13:57:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/13/implementing-the-top-4-defense-strategies/472.aspx</guid>
</item>
<item>
<title>Who Needs Hackers?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/12/who-needs-hackers/471.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;As a rule I don't comment on unproven allegations, but this time I'm breaking my rule. According to a District of New Hampshire indictment (&lt;a href=&quot;http://www.wired.com/images_blogs/threatlevel/2011/12/Indictment_Romanian-POS-Hackers.pdf&quot;&gt;downloadable from Wired&lt;/a&gt;), four Roman ...</description>
<pubDate>Mon, 12 Dec 2011 13:53:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/12/who-needs-hackers/471.aspx</guid>
</item>
<item>
<title>On the sixth day of Christmas my true love gave to me – Security Awareness…
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/6/on-the-sixth-day-of-christmas-my-true-love-gave-to-me--security-awareness/470.aspx</link>
<description>&lt;p&gt;Christmas is one of those occasions when people tend to have some spare time on their hands for indulging their passions and interests, which could take them on a journey of Internet discovery. It may well also be the case that a little communication with distant relatives is the order of the sea ...</description>
<pubDate>Tue, 06 Dec 2011 21:01:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/6/on-the-sixth-day-of-christmas-my-true-love-gave-to-me--security-awareness/470.aspx</guid>
</item>
<item>
<title>Carrier IQ: Not Just an Android Issue</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/carrier-iq-not-just-an-android-issue/469.aspx</link>
<description>&lt;p&gt;Unless you&amp;rsquo;re currently trekking through the Gobi, you&amp;rsquo;ve probably caught some of the fuss about Carrier IQ, accused of conduct resembling a rootkit more than legitimate logging. I think that some of the indignation has been a little overdone, as I commented &lt;a href=&quot;http://www.eweeke ...</description>
<pubDate>Thu, 01 Dec 2011 19:48:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/carrier-iq-not-just-an-android-issue/469.aspx</guid>
</item>
<item>
<title>Personal Data Exodus</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/personal-data-exodus/468.aspx</link>
<description>&lt;p&gt;I came across a couple of interesting stories this week, both of which are worth passing along.This first is from &lt;a href=&quot;http://www.geek.com/articles/mobile/security-researcher-responds-to-carrieriq-with-video-proof-20111129/&quot;&gt;geek.com&lt;/a&gt;&amp;nbsp;and is the latest in an &lt;a href=&quot;http://www.geek.c ...</description>
<pubDate>Thu, 01 Dec 2011 15:55:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/personal-data-exodus/468.aspx</guid>
</item>
<item>
<title> A critical software problem for banks</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/-a-critical-software-problem-for-banks/467.aspx</link>
<description>&lt;div style=&quot;margin-bottom: 0.0001pt;&quot;&gt;New Quocirca research (sponsored by on-demand software code security specialist, Veracode) underlines a problem faced by financial services organisations when it comes to security and compliance; they track getting on for twice as many critical software applicat ...</description>
<pubDate>Thu, 01 Dec 2011 10:35:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/-a-critical-software-problem-for-banks/467.aspx</guid>
</item>
<item>
<title>On the first day of Christmas my true love gave to me – An iPad2…</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/on-the-first-day-of-christmas-my-true-love-gave-to-me--an-ipad2/466.aspx</link>
<description>&lt;p&gt;On the second day, I got a Digital Camera, the third came in with a SmartPhone, the forth, a High Capacity Drive, and the fifth . . . . I guess you have got the picture. It&amp;rsquo;s that time of year again when Santa will be visiting all the boys and girls to empty his sleigh. So to get us all in  ...</description>
<pubDate>Thu, 01 Dec 2011 09:11:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/on-the-first-day-of-christmas-my-true-love-gave-to-me--an-ipad2/466.aspx</guid>
</item>
<item>
<title>Cloud Security:  An Oxymoron?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/29/cloud-security--an-oxymoron/465.aspx</link>
<description>&lt;h5&gt;By Torsten George&lt;/h5&gt;
&lt;p&gt;Cloud computing represents today's big innovation trend in the information technology (IT) space. Because it allows organizations to deploy quickly, move swiftly, and share resources, cloud computing is rapidly replacing conventional in-house facilities at organization ...</description>
<pubDate>Tue, 29 Nov 2011 19:21:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/29/cloud-security--an-oxymoron/465.aspx</guid>
</item>
<item>
<title>The UK Cyber Security Strategy – is this really progress?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/29/the-uk-cyber-security-strategy--is-this-really-progress/464.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;A &lt;a href=&quot;http://www.cabinetoffice.gov.uk/sites/default/files/resources/The%20UK%20Cyber%20Security%20Strategy-%20web%20ver.pdf&quot;&gt;UK Cyber Security Strategy&lt;/a&gt; has just been released by the Cabinet Office. The first thing I noted was that seven of its 43 pages are have a solid c ...</description>
<pubDate>Tue, 29 Nov 2011 12:28:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/29/the-uk-cyber-security-strategy--is-this-really-progress/464.aspx</guid>
</item>
<item>
<title>Could my Cloud Burst?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/25/could-my-cloud-burst/463.aspx</link>
<description>&lt;p&gt;2010 was the year we &amp;lsquo;thought&amp;rsquo; about cloud. 2011 was the era we realised it could be an option which could support improvements in operational efficiencies, whilst at the same time reducing running costs. 2012 'will' be the year when we will see the take up start to evolve and surge.  ...</description>
<pubDate>Fri, 25 Nov 2011 08:52:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/25/could-my-cloud-burst/463.aspx</guid>
</item>
<item>
<title>Council of Europe Octopus Conference- Some Thoughts</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/23/council-of-europe-octopus-conference-some-thoughts/462.aspx</link>
<description>&lt;p&gt;l am still sitting in the parliament room of the &lt;a href=&quot;http://www.coe.int/t/DGHL/cooperation/economiccrime/cybercrime/cy_Octopus_Interface_2011/Interface2011_en.asp&quot;&gt;Council of Europe at the celebration event for the Budapest Convention&lt;/a&gt;. It was another very good event advancing the challen ...</description>
<pubDate>Wed, 23 Nov 2011 11:38:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/23/council-of-europe-octopus-conference-some-thoughts/462.aspx</guid>
</item>
<item>
<title>Google’s Approach of a “_NOMAP” Wi-Fi ZONE</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/20/googles-approach-of-a-nomap-wifi-zone/460.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;&quot;&gt;&lt;a href=&quot;http://googleblog.blogspot.com/2011/11/greater-choice-for-wireless-access.html&quot;&gt;Google recently announced an approach&lt;/a&gt; to provide Wi-Fi Access Point owners an option to opt-out from the Google Location server, thereby addressing specific privacy concerns of certain Acce ...</description>
<pubDate>Sun, 20 Nov 2011 11:07:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/20/googles-approach-of-a-nomap-wifi-zone/460.aspx</guid>
</item>
<item>
<title>iPaddling in Corporate Waters</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/18/ipaddling-in-corporate-waters/459.aspx</link>
<description>&lt;p&gt;&lt;em&gt;Computer Weekly&lt;/em&gt;, in an article I mentioned in my previous blog here, notes that Tablet device ownership among mobile employees increased from 33% in the second quarter of 2011 to 44%.That statistic dovetails quite neatly with a study from ComScore on&lt;span style=&quot;color: #1f497d&quot;&gt; &lt;a href= ...</description>
<pubDate>Fri, 18 Nov 2011 11:35:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/18/ipaddling-in-corporate-waters/459.aspx</guid>
</item>
<item>
<title>Goodbye Blackberry Way?*</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/18/goodbye-blackberry-way/458.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.computerweekly.com/news/2240111024/Blackberry-grip-on-enterprise-snatched-by-Apple-iPhone&quot;&gt;iPass tells us&lt;/a&gt;&amp;nbsp;that a recent survey (n = 2,300) indicated that the iPhone now has 45% marketshare in the enterprise, whereas use of the Blackberry is down (slightly) to 35%. Whi ...</description>
<pubDate>Fri, 18 Nov 2011 10:50:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/18/goodbye-blackberry-way/458.aspx</guid>
</item>
<item>
<title>Cyber War Will Not Take Place</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/17/cyber-war-will-not-take-place/457.aspx</link>
<description>&lt;p&gt;I have to admit &amp;ndash; it is not my title but it caught my attention. Over the course of the last few years, the term &amp;ldquo;Cyberwar&amp;rdquo; came up all over the place. I was recently reading a book on it, where there was a chapter called &amp;ldquo;Definition of Cyberwar&amp;rdquo; and I thought that f ...</description>
<pubDate>Thu, 17 Nov 2011 10:39:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/17/cyber-war-will-not-take-place/457.aspx</guid>
</item>
<item>
<title>Auditors want to know about individuals, not groups</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/auditors-want-to-know-about-individuals-not-groups/456.aspx</link>
<description>&lt;p&gt;&amp;nbsp;It is pretty obvious that to audit the use of IT resources and applications you need to know who is doing what. This is especially true when it comes to system administrators (sys-admins) who are operating with increased levels of privilege.&lt;/p&gt;
&lt;div style=&quot;margin-bottom: 0.0001pt;&quot;&gt;&amp;nbsp; ...</description>
<pubDate>Wed, 16 Nov 2011 11:24:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/auditors-want-to-know-about-individuals-not-groups/456.aspx</guid>
</item>
<item>
<title>Cloud Security Considerations – a different view</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/cloud-security-considerations--a-different-view/455.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Yesterday, looking at my RSS-Feed I saw the post in here called &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/11/14/cloud-security-considerations/452.aspx&quot;&gt;Cloud Security Considerations&lt;/a&gt; &amp;ndash; and immediately wanted to read it as we (a friend of mine and me) wrote  ...</description>
<pubDate>Wed, 16 Nov 2011 11:07:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/cloud-security-considerations--a-different-view/455.aspx</guid>
</item>
<item>
<title>Blue Pill, White Rabbit</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/blue-pill-white-rabbit/454.aspx</link>
<description>&lt;p&gt;It has been said that 2011 is the year of insecurity, and I guess this is down to the number of successful unauthorised incursions that were &amp;lsquo;reported&amp;rsquo; by the press, and in the media. However, in my opinion, 2011 was &amp;lsquo;not&amp;rsquo; the year of insecurity, but the period in which we ...</description>
<pubDate>Wed, 16 Nov 2011 09:18:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/blue-pill-white-rabbit/454.aspx</guid>
</item>
<item>
<title>Cyberespionage: The Chinese State of Denial</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/cyberespionage-the-chinese-state-of-denial/453.aspx</link>
<description>&lt;p&gt;Today I spoke with Roger Cressey, a cybersecurity and counterterrorism expert for both the Clinton and Bush administrations, and now a senior VP with Booz Allen Hamilton. I asked him if he was equally amused by the Chinese government&amp;rsquo;s continuous denials that hackers within its borders acti ...</description>
<pubDate>Wed, 16 Nov 2011 01:28:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/cyberespionage-the-chinese-state-of-denial/453.aspx</guid>
</item>
<item>
<title>Cloud Security Considerations</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/14/cloud-security-considerations/452.aspx</link>
<description>&lt;h5&gt;By Ken Biery&lt;/h5&gt;
&lt;p&gt;Can a cloud be as secure as a traditional network?  In a word, yes!  I agree that some may find this statement surprising.  Depending on the network, that may be a low bar, but good security principles and approaches are just as applicable to cloud environments as they are  ...</description>
<pubDate>Mon, 14 Nov 2011 18:59:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/14/cloud-security-considerations/452.aspx</guid>
</item>
<item>
<title>How to Manage “Bring Your Own Device”</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/10/how-to-manage-bring-your-own-device/451.aspx</link>
<description>&lt;p&gt;Long time since I&amp;nbsp;blogged. It is time to &amp;quot;come back :-)&amp;quot;. The kick was that I&amp;nbsp;started to work on a Windows 8 Slate as a secondary PC and thought about the consumerization scenario once more:&lt;/p&gt;
&lt;p&gt;A few years back a customer&amp;rsquo;s CSO left the room when I said that this cu ...</description>
<pubDate>Thu, 10 Nov 2011 14:32:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/10/how-to-manage-bring-your-own-device/451.aspx</guid>
</item>
<item>
<title>The ‘Dragon’ has landed</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/8/the-dragon-has-landed/449.aspx</link>
<description>&lt;p&gt;On 2nd Novermber 2011 I was privileged to have visited, and to have participated in the eCrime Wales Summit, hosted at Cardiff Stadium. Before I add comment to the proceedings, I would really like to sing the praises of the very high levels of support the event received from the Minister for Busi ...</description>
<pubDate>Tue, 08 Nov 2011 08:57:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/8/the-dragon-has-landed/449.aspx</guid>
</item>
<item>
<title>Apple Content in Infosecurity Virtual Conference</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/7/apple-content-in-infosecurity-virtual-conference/448.aspx</link>
<description>&lt;p&gt;It occurs to me that something (else) I haven't mentioned here is that &lt;em&gt;Infosecurity&lt;/em&gt; magazine is running one of its &lt;a target=&quot;_blank&quot; href=&quot;http://bit.ly/qHW5LI&quot;&gt;&lt;font color=&quot;#7f1d1d&quot;&gt;virtual conferences&lt;/font&gt;&lt;/a&gt; on November 8th, with the virtual doors opening at 10.30 EST. If you're i ...</description>
<pubDate>Mon, 07 Nov 2011 19:01:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/7/apple-content-in-infosecurity-virtual-conference/448.aspx</guid>
</item>
<item>
<title>What the Devil(Robber)? </title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/7/what-the-devilrobber-/447.aspx</link>
<description>&lt;p&gt;It occurs to me that while I &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/10/28/osxtsunami-flooding-new-markets/439.aspx&quot;&gt;wrote here&lt;/a&gt; about the interesting but apparently work-in-progress OSX/Tsunami (or Kaiten) port from Linux to OSX a while back, I haven't had the chance to mentio ...</description>
<pubDate>Mon, 07 Nov 2011 18:52:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/7/what-the-devilrobber-/447.aspx</guid>
</item>
<item>
<title>Leveraging Managed Cloud Services to Meet Cloud Compliance Challenges</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/4/leveraging-managed-cloud-services-to-meet-cloud-compliance-challenges/446.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;p&gt;Regardless of your industry, customer base, or product, it is highly likely that you face regulatory compliance requirements.  If you handle Protected Health Information (PHI), the Health Insurance Portability and Accountability Act (HIPAA) &amp;ndash; along with the HITECH ...</description>
<pubDate>Fri, 04 Nov 2011 18:33:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/4/leveraging-managed-cloud-services-to-meet-cloud-compliance-challenges/446.aspx</guid>
</item>
<item>
<title>Cloud Security:  Confident, Fearful, or Surprised?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/4/cloud-security--confident-fearful-or-surprised/445.aspx</link>
<description>&lt;h5&gt;By Ken Biery&lt;/h5&gt;
&lt;p&gt;This two-part guest blog series explores the topic of cloud security.  Part one of the series focuses on the questions enterprise IT decision makers should ask when considering moving business applications to a cloud-based computing environment.&lt;/p&gt;
&lt;p&gt;There is no shortage ...</description>
<pubDate>Fri, 04 Nov 2011 18:10:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/4/cloud-security--confident-fearful-or-surprised/445.aspx</guid>
</item>
<item>
<title>IT security vendors can’t all be right, but they can all be wrong</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/1/it-security-vendors-cant-all-be-right-but-they-can-all-be-wrong/443.aspx</link>
<description>&lt;p&gt;From recent briefings with a number of IT security vendors it would seem that most can now identify any new threat immediately and that at the same time none of them can. This contradiction is down to the &amp;ldquo;&lt;i&gt;we can, they can&amp;rsquo;t&lt;/i&gt;&amp;rdquo; mantra that any vendor of any product is bound ...</description>
<pubDate>Tue, 01 Nov 2011 09:16:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/1/it-security-vendors-cant-all-be-right-but-they-can-all-be-wrong/443.aspx</guid>
</item>
<item>
<title>Dr Strangebug
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/1/dr-strangebug/442.aspx</link>
<description>&lt;p&gt;It would seem that in 2011,&amp;nbsp;hacking went up&amp;nbsp;in the world &amp;ndash; literally, with the DroneBug Malware entering the scene in November 2011, and then with the revelation that a hack had been carried out targeting a Satellite. Two scenarios which are also very similar in many ways, and I a ...</description>
<pubDate>Tue, 01 Nov 2011 09:09:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/1/dr-strangebug/442.aspx</guid>
</item>
<item>
<title>Attacking the Human Wall</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/28/attacking-the-human-wall/441.aspx</link>
<description>&lt;p&gt;Good post &lt;a href=&quot;https://www.brandenwilliams.com/blog/2011/10/11/attack-the-humans-first/&quot;&gt;here &lt;/a&gt;from Brandon Williams on the inherent weakness of security processes that ignores the human element.&lt;/p&gt;
&lt;p&gt;There's nothing new in saying that humans are the weakest link in the security chain ( ...</description>
<pubDate>Fri, 28 Oct 2011 22:31:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/28/attacking-the-human-wall/441.aspx</guid>
</item>
<item>
<title>The 1985 iPhone In a Truck</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/28/the-1985-iphone-in-a-truck/440.aspx</link>
<description>&lt;p&gt;&amp;nbsp;People of a certain age often enjoy recalling for younger folk the size of the early mobile phones that were lugged around in the mid-1980s, whilst marvelling at the latest smartphones. These brick-sized devices could not even send text (SMS) messages (the first of which was sent in 1992);  ...</description>
<pubDate>Fri, 28 Oct 2011 07:59:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/28/the-1985-iphone-in-a-truck/440.aspx</guid>
</item>
<item>
<title>OSX/Tsunami: flooding new markets</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/28/osxtsunami-flooding-new-markets/439.aspx</link>
<description>&lt;p&gt;Matt Hartley asks the question &amp;ldquo;&lt;a href=&quot;http://www.datamation.com/open-source/linux-malware-are-we-there-yet-1.html&quot;&gt;Linux Malware: Are We There Yet&lt;/a&gt;?&amp;rdquo;&amp;nbsp; It seems strange, after so much exposure to the view that OS X is intrinsically so much safer than Windows, to read a piece ...</description>
<pubDate>Fri, 28 Oct 2011 01:03:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/28/osxtsunami-flooding-new-markets/439.aspx</guid>
</item>
<item>
<title>Credit and Reservations
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/26/credit-and-reservations/437.aspx</link>
<description>&lt;p&gt;Week four October 2011 became infamous when, as part of Operation 'Darknet', Anonymous took down, what was referred to as a Child Pornography site (or as I refer, a Child &amp;lsquo;Abuse&amp;rsquo; Site). This was quickly followed by the release of some 1,589 names of subscribers in a mission of naming  ...</description>
<pubDate>Wed, 26 Oct 2011 08:30:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/26/credit-and-reservations/437.aspx</guid>
</item>
<item>
<title>Consumers Say No (to data leaks)</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/25/consumers-say-no-to-data-leaks/436.aspx</link>
<description>&lt;p&gt;A recent Quocirca &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/9/16/responsible-data-leak-disclosure/407.aspx&quot;&gt;blog post&lt;/a&gt; pointed out there were good business reasons for disclosing data breaches as well as an increasing number of regulatory ones. For those organisations not convinc ...</description>
<pubDate>Tue, 25 Oct 2011 08:14:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/25/consumers-say-no-to-data-leaks/436.aspx</guid>
</item>
<item>
<title>Don’t Forget the Network</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/21/dont-forget-the-network/435.aspx</link>
<description>&lt;p&gt;A &lt;a href=&quot;http://www.newscientist.com/article/mg21128324.700-light-is-not-fast-enough-for-highspeed-stock-trading.html&quot;&gt;recent news story in &lt;em&gt;New Scientist&lt;/em&gt;&lt;/a&gt; reminds us how important the speed of network communications has become for some organisations:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;helli ...</description>
<pubDate>Fri, 21 Oct 2011 09:36:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/21/dont-forget-the-network/435.aspx</guid>
</item>
<item>
<title>It’s NOT that Easy (to be an APT or AET)!! 
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/20/its-not-that-easy-to-be-an-apt-or-aet-/434.aspx</link>
<description>&lt;p&gt;As many of seasoned IT Pros may have noticed, the APT and AET debate has once again been given some tripping space on the boards of the IT security press. However, whenever this happens, the confusion that arises around what &amp;lsquo;they&amp;rsquo; are, and what constitutes the &amp;lsquo;label&amp;rsquo;, se ...</description>
<pubDate>Thu, 20 Oct 2011 08:35:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/20/its-not-that-easy-to-be-an-apt-or-aet-/434.aspx</guid>
</item>
<item>
<title>“Testing the Testers”: Certification and Cloud Computing</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/19/testing-the-testers-certification-and-cloud-computing/433.aspx</link>
<description>&lt;h5&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Cloud computing is becoming ubiquitous throughout the federal government, and while the adoption of this technology may be more widespre ...</description>
<pubDate>Wed, 19 Oct 2011 23:07:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/19/testing-the-testers-certification-and-cloud-computing/433.aspx</guid>
</item>
<item>
<title>Avoiding (awful) bad practice at audit time</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/18/avoiding-awful-bad-practice-at-audit-time/432.aspx</link>
<description>&lt;p&gt;Quocirca saw an estimate recently that IT security managers can spend as much as 30% of their time preparing for and delivering audits. This is mundane and uninteresting work and if it can be automated &amp;ndash; all the better. However, recent Quocirca research, sponsored by sys-admin tools vendor  ...</description>
<pubDate>Tue, 18 Oct 2011 16:54:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/18/avoiding-awful-bad-practice-at-audit-time/432.aspx</guid>
</item>
<item>
<title>Social Engineering: A Real Persistent Threat</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/15/social-engineering-a-real-persistent-threat/431.aspx</link>
<description>&lt;p&gt;I hear a great deal about 0-day attacks, and a great deal of security vendor PR is (depending on market sector) predicated on the assumption that 0-days are the most prevalent threat. Notwithstanding some highly visible 0-day attacks over the years, I don&amp;rsquo;t believe that to be true.&lt;/p&gt;
&lt;di ...</description>
<pubDate>Sat, 15 Oct 2011 14:12:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/15/social-engineering-a-real-persistent-threat/431.aspx</guid>
</item>
<item>
<title>Failing PCI Policy?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/13/failing-pci-policy/430.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.verizonbusiness.com/resources/reports/rp_2011-payment-card-industry-compliance-report_en_xg.pdf&quot;&gt;This is a good read &lt;/a&gt;if you missed it&amp;nbsp;&amp;ndash; the most recent report by the ever-interesting Verizon PCI and Risk Intelligence Teams on the state of PCI Compliance.&lt;/p&gt;
&lt;p ...</description>
<pubDate>Thu, 13 Oct 2011 20:34:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/13/failing-pci-policy/430.aspx</guid>
</item>
<item>
<title>Goodnight Irene: A Lesson in Disaster Planning</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/13/goodnight-irene-a-lesson-in-disaster-planning/429.aspx</link>
<description>&lt;p&gt;Many large organizations make preparations for disaster, but the recent hurricane that hit the East Coast of the US illustrates why long-term business continuity planning on a local level can be critical to survival &amp;ndash; and your employees&amp;rsquo; well being.&lt;/p&gt;
&lt;p&gt;While much of what we cover ...</description>
<pubDate>Thu, 13 Oct 2011 18:22:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/13/goodnight-irene-a-lesson-in-disaster-planning/429.aspx</guid>
</item>
<item>
<title>Things that go BUMP in the Night</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/12/things-that-go-bump-in-the-night/428.aspx</link>
<description>&lt;p&gt;I admit it, I am a worrier. Has my wife left her hair straighteners plugged in always jumps into my mind at a juncture when turning back would make not a jot of difference! Going on holiday, I always wonder if I really did close that window in the spare room &amp;ndash; and then there is the ever pre ...</description>
<pubDate>Wed, 12 Oct 2011 20:43:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/12/things-that-go-bump-in-the-night/428.aspx</guid>
</item>
<item>
<title>Virus Bulletin and the Mac, then and now</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/12/virus-bulletin-and-the-mac-then-and-now/427.aspx</link>
<description>&lt;p&gt;Last week I was in Barcelona for this year's &lt;a href=&quot;http://www.virusbtn.com/conference/vb2011&quot;&gt;Virus Bulletin conference&lt;/a&gt; (the 21st, which makes me feel very old even though I wasn't there at the beginning!). The first time I presented there was in 1997, when &lt;a href=&quot;http://macviruscom.file ...</description>
<pubDate>Wed, 12 Oct 2011 18:33:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/12/virus-bulletin-and-the-mac-then-and-now/427.aspx</guid>
</item>
<item>
<title>False Sense of Security among WiFi Users</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/11/false-sense-of-security-among-wifi-users/425.aspx</link>
<description>&lt;div style=&quot;text-align:justify&quot;&gt;&lt;a href=&quot;http://www.wi-fi.org/news_articles.php?f=media_news&amp;amp;news_id=1085&quot;&gt;A recent survey conducted by Wakefield Research&lt;/a&gt; for the WiFi Alliance has revealed that 97% of surveyed WiFi users believe that the data on their devices and networks is &amp;ldquo;safe and ...</description>
<pubDate>Tue, 11 Oct 2011 16:00:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/11/false-sense-of-security-among-wifi-users/425.aspx</guid>
</item>
<item>
<title>Test Accounts:  Another Compliance Risk</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/7/test-accounts--another-compliance-risk/424.aspx</link>
<description>&lt;h5&gt;By Merritt Maximi&lt;/h5&gt;
&lt;p&gt;A major benefit associated with deploying identity management and/or identity governance into an organization is that these solutions provide the ability to detect and remove orphan accounts.  Orphan accounts refer to active accounts belonging to a user who is no longe ...</description>
<pubDate>Fri, 07 Oct 2011 20:14:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/7/test-accounts--another-compliance-risk/424.aspx</guid>
</item>
<item>
<title>Fluxotonomy!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/5/fluxotonomy/423.aspx</link>
<description>&lt;p&gt;For more years now than I can to remember, operations have become focused on applications, equipment, and infrastructures to deliver security, and notwithstanding the ever constant warning that this, as a strategy is a flawed approach, nevertheless, organisations continue to follow this direction ...</description>
<pubDate>Wed, 05 Oct 2011 11:50:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/5/fluxotonomy/423.aspx</guid>
</item>
<item>
<title>HyperCard Viruses? You're History!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/3/hypercard-viruses-youre-history/422.aspx</link>
<description>&lt;p&gt;I see that Graham Cluley has revised his excellent timeline&amp;nbsp;article &lt;a data-mce-href=&quot;http://nakedsecurity.sophos.com/2011/10/03/mac-malware-history/&quot; rel=&quot;bookmark&quot; href=&quot;http://nakedsecurity.sophos.com/2011/10/03/mac-malware-history/&quot; title=&quot;Permalink to The short history of Mac malware: 1 ...</description>
<pubDate>Mon, 03 Oct 2011 15:07:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/3/hypercard-viruses-youre-history/422.aspx</guid>
</item>
<item>
<title>When It Comes To Cloud Security, Don’t Forget SSL</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/30/when-it-comes-to-cloud-security-dont-forget-ssl/421.aspx</link>
<description>&lt;h5&gt;By Michael Lin, Symantec&lt;/h5&gt;
&lt;p&gt;Cloud computing appears here to stay, bringing with it new challenges and security risks on one hand, while on the other hand boasting efficiencies, cost savings and competitive advantage. With the new security risks of cloud and the mounting skill and cunning o ...</description>
<pubDate>Fri, 30 Sep 2011 19:04:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/30/when-it-comes-to-cloud-security-dont-forget-ssl/421.aspx</guid>
</item>
<item>
<title>Securing Your File Transfer in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/30/securing-your-file-transfer-in-the-cloud/420.aspx</link>
<description>&lt;h5&gt;By Stuart Lisk&lt;/h5&gt;
&lt;p&gt;File transfer has been around since the beginning of time. Ok, well maybe that is an exaggeration, but the point is, file transfer was one of the earliest uses of &amp;ldquo;network&amp;rdquo; computing dating back to the early 1970&amp;rsquo;s when IBM introduced the floppy disk. Wh ...</description>
<pubDate>Fri, 30 Sep 2011 19:00:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/30/securing-your-file-transfer-in-the-cloud/420.aspx</guid>
</item>
<item>
<title>Apple Raises the &quot;Anti&quot; for Revir, but Intego gets Flashbacks</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/27/apple-raises-the-anti-for-revir-but-intego-gets-flashbacks/417.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.h-online.com/security/news/item/Apple-updates-malware-definition-list-to-defend-against-PDF-trojan-1350430.html&quot;&gt;The H&lt;/a&gt; (Heise) reported today that Apple has added detection for OSX/Revir to its XProtect facility, provided&amp;nbsp;in OS&amp;nbsp;X versions since Snow Leopard.&lt;/p&gt; ...</description>
<pubDate>Tue, 27 Sep 2011 18:16:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/27/apple-raises-the-anti-for-revir-but-intego-gets-flashbacks/417.aspx</guid>
</item>
<item>
<title>Revir's Ride not a Derby Winner</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/26/revirs-ride-not-a-derby-winner/415.aspx</link>
<description>&lt;p&gt;Since new Mac-specific malware is pretty rare, I suppose I can't really ignore the malware that most AV companies are calling Revir.A (the dropper and downloader) and Imuler.A (the backdoor that carries the sting, such as it is), though Sophos is calling it &lt;a href=&quot;http://nakedsecurity.sophos.co ...</description>
<pubDate>Mon, 26 Sep 2011 13:17:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/26/revirs-ride-not-a-derby-winner/415.aspx</guid>
</item>
<item>
<title>The Free Spirit</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/22/the-free-spirit/412.aspx</link>
<description>&lt;p&gt;Being a free spirit in the interesting, evolving world of cyber/information security (or is that insecurity?) I am privileged to work with some very interesting organisations, and the year 2011 has proven to be one of the best. The great thing about working with the experts, and visionaries of th ...</description>
<pubDate>Thu, 22 Sep 2011 19:53:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/22/the-free-spirit/412.aspx</guid>
</item>
<item>
<title>Insider Attack: Three Key Considerations</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/21/insider-attack-three-key-considerations/411.aspx</link>
<description>&lt;p&gt;&amp;ldquo;Insider attack&amp;rdquo; is back in the news, getting attention again, with good reason. This particular article, &amp;ldquo;&lt;a href=&quot;http://www.infosecurity-us.com/view/20811/insiders-increasingly-linked-to-data-breaches-in-the-financial-sector/&quot;&gt;Insiders increasingly linked to data breaches in  ...</description>
<pubDate>Wed, 21 Sep 2011 15:45:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/21/insider-attack-three-key-considerations/411.aspx</guid>
</item>
<item>
<title>Password Shadowing: The Lion Sleeps Tonight</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/20/password-shadowing-the-lion-sleeps-tonight/410.aspx</link>
<description>&lt;p&gt;Patrick Dunstan has put up a disquieting &lt;a href=&quot;http://www.defenceindepth.net/2011/09/cracking-os-x-lion-passwords.html&quot;&gt;post on Defence in Depth&lt;/a&gt;, following up on a &lt;a href=&quot;http://www.defenceindepth.net/2009/12/cracking-os-x-passwords.html&quot;&gt;2009 blog post&lt;/a&gt; on cracking OS X passwords. No ...</description>
<pubDate>Tue, 20 Sep 2011 20:42:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/20/password-shadowing-the-lion-sleeps-tonight/410.aspx</guid>
</item>
<item>
<title>OMG! TLS! You BEAST!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/20/omg-tls-you-beast/409.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;A couple of security researchers are due to present a way to compromise TLS 1.0 at a &lt;a href=&quot;http://ekoparty.org/cronograma.php&quot;&gt;conference in Argentina&lt;/a&gt; &amp;nbsp;next week (scroll to end of page). Thai Duong and Juliano Rizzo have found a way - codenamed &amp;quot;BEAST&amp;quot; - to  ...</description>
<pubDate>Tue, 20 Sep 2011 08:06:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/20/omg-tls-you-beast/409.aspx</guid>
</item>
<item>
<title>Responsible Data Leak Disclosure</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/16/responsible-data-leak-disclosure/407.aspx</link>
<description>&lt;p&gt;There has been plenty written, not least by Quocirca, on the danger of data loss and how to prevent it. Less has been said about how to clear up afterwards; when the measures taken to protect a business from such losses have failed or were not present in the first place. In particular the respons ...</description>
<pubDate>Fri, 16 Sep 2011 12:48:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/16/responsible-data-leak-disclosure/407.aspx</guid>
</item>
<item>
<title>The “Don’t Trust Model” of Cloud Computing</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/14/the-dont-trust-model-of-cloud-computing/406.aspx</link>
<description>&lt;h5&gt;By&amp;nbsp;Ed King&lt;/h5&gt;
&lt;p&gt;The elephant in the room when it comes to barriers to the growth and adoption of cloud computing by enterprises is the lack of trust held for cloud service providers.  Enterprise IT has legitimate concerns over the security, integrity, and reliability of cloud-based serv ...</description>
<pubDate>Wed, 14 Sep 2011 20:03:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/14/the-dont-trust-model-of-cloud-computing/406.aspx</guid>
</item>
<item>
<title>Disconnect of the RAT</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/13/disconnect-of-the-rat/405.aspx</link>
<description>&lt;p&gt;When I think back to the early days of the Anti-Virus industry, I recall there were lots of good intentions to standardise, and work as a closed community &amp;ndash; but of course, where there are interests of commercial implication, profit, and of course leading edge competitive advantage, there is ...</description>
<pubDate>Tue, 13 Sep 2011 17:34:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/13/disconnect-of-the-rat/405.aspx</guid>
</item>
<item>
<title>Marketing and Upgrades</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/13/marketing-and-upgrades/404.aspx</link>
<description>&lt;p&gt;Jonny Evans has made some interesting points at &lt;a href=&quot;http://blogs.computerworld.com/18927/has_apple_handled_the_diginotar_attack_effectively&quot;&gt;Computer World&lt;/a&gt;&amp;nbsp;regarding Apple's belated removal of DigiNotar root certificates from OS&amp;nbsp;X (specifically Lion and Snow Leopard). Clearly,  ...</description>
<pubDate>Tue, 13 Sep 2011 17:24:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/13/marketing-and-upgrades/404.aspx</guid>
</item>
<item>
<title>Seven Steps to Securing File Transfer’s Journey to the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/12/seven-steps-to-securing-file-transfers-journey-to-the-cloud/402.aspx</link>
<description>&lt;h5&gt;By Oded Valin&lt;/h5&gt;
&lt;p&gt;&amp;ldquo;When it absolutely, positively has to be there overnight.&amp;rdquo;  There&amp;rsquo;s a lot we can identify with when it comes to reciting FedEx&amp;rsquo;s famous slogan, especially as it relates to modern file transfer processes. When you think about sharing health care rec ...</description>
<pubDate>Mon, 12 Sep 2011 19:58:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/12/seven-steps-to-securing-file-transfers-journey-to-the-cloud/402.aspx</guid>
</item>
<item>
<title>The un-Skilling of Information Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/9/the-unskilling-of-information-security/400.aspx</link>
<description>&lt;p&gt;In the last few months, I have noticed there has been a push against, what we term &amp;lsquo;Security Certifications&amp;rsquo;, insofar it has been inferred they have very little value. However, whilst I can see the argument, I do both &amp;lsquo;agree&amp;rsquo;, and &amp;lsquo;disagree&amp;rsquo; with the observatio ...</description>
<pubDate>Fri, 09 Sep 2011 14:36:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/9/the-unskilling-of-information-security/400.aspx</guid>
</item>
<item>
<title>Now You See It, Now You Don't...</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/7/now-you-see-it-now-you-dont/399.aspx</link>
<description>&lt;p&gt;Apple security, that is.&lt;/p&gt;
&lt;p&gt;Clearly, the company's &lt;a href=&quot;http://jobs.apple.com/index.ajs?BID=1&amp;amp;method=mExternal.showJob&amp;amp;RID=91081&amp;amp;CurrentPage=1&quot;&gt;hiring&lt;/a&gt; of a product security manager carries a very clear &amp;quot;we need to improve&amp;quot; message, but it's clearly tied to a mar ...</description>
<pubDate>Wed, 07 Sep 2011 18:26:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/7/now-you-see-it-now-you-dont/399.aspx</guid>
</item>
<item>
<title>MiFi Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/7/mifi-security/398.aspx</link>
<description>&lt;p&gt;Some years ago, I attended an Information Security Event in Paris, hosted by a very well-known Research Institute. On day one, I received an enquiry to ascertain if I was interested in WiFi Security, and if so, the hosting representative went to say they had a number of slots available the follow ...</description>
<pubDate>Wed, 07 Sep 2011 15:27:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/7/mifi-security/398.aspx</guid>
</item>
<item>
<title>How Not to Secure a CA</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/7/how-not-to-secure-a-ca/397.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Fox-IT have published a preliminary report on the &lt;a href=&quot;http://infosecreviews.com/blog/?p=44&quot;&gt;DigiNotar breach&lt;/a&gt;. It appears that the number of spoofed certificates is much greater than previously suspected, and Iran was a prime target, so once again we may have an example o ...</description>
<pubDate>Wed, 07 Sep 2011 12:10:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/7/how-not-to-secure-a-ca/397.aspx</guid>
</item>
<item>
<title>How Signify weathered the RSA breach storm: Eleanor Dallaway chats to Dave Abraham, co-founder and CEO of Signify </title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/1/how-signify-weathered-the-rsa-breach-storm-eleanor-dallaway-chats-to-dave-abraham-cofounder-and-ceo-of-signify-/394.aspx</link>
<description>&lt;p&gt;
&lt;div&gt;Last week, I went to lunch with Dave Abraham, &lt;a href=&quot;http://www.infosecurity-magazine.com/view/19461/signify-moves-2fa-onto-android-smartphones-and-tablets&quot;&gt;co-founder and CEO of Signify,&lt;/a&gt; an information security company that delivers two-factor authentication.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div ...</description>
<pubDate>Thu, 01 Sep 2011 11:50:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/1/how-signify-weathered-the-rsa-breach-storm-eleanor-dallaway-chats-to-dave-abraham-cofounder-and-ceo-of-signify-/394.aspx</guid>
</item>
<item>
<title>George and Ian</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/1/george-and-ian/393.aspx</link>
<description>&lt;p&gt;When I was young, whilst most boys were interested in train sets, cars, not I &amp;ndash; my real interest, and passions were 1) H.G Wells, and 2) Spying! I guess with Mr Wells, it was his predictions of what could be the future, looking out toward the potential dangers that the world may face. Howev ...</description>
<pubDate>Thu, 01 Sep 2011 11:09:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/1/george-and-ian/393.aspx</guid>
</item>
<item>
<title>Don’t let your brand name be flushed away</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/1/dont-let-your-brand-name-be-flushed-away/392.aspx</link>
<description>&lt;p&gt;&amp;nbsp;A snippet in Private Eye earlier this year (July 8&lt;sup&gt;th&lt;/sup&gt;, 2011) showed how touchy companies can get about the use of their brand names. Following the unfortunate death of a festival goer in a toilet at Glastonbury (who also happened to be political activist and friend of the UK&amp;rsquo ...</description>
<pubDate>Thu, 01 Sep 2011 08:12:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/1/dont-let-your-brand-name-be-flushed-away/392.aspx</guid>
</item>
<item>
<title>Comex: Scrumper turned Gamekeeper</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/26/comex-scrumper-turned-gamekeeper/391.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;font-size: 9pt&quot;&gt;So can I resist the temptation to blog about the departure of Steve Jobs? Well, yes, though I wish Jobs, his successor, and the company well. But I'm not really qualified to add to the flurry of business analysis that has preoccupied the media since the announcement.  ...</description>
<pubDate>Fri, 26 Aug 2011 20:30:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/26/comex-scrumper-turned-gamekeeper/391.aspx</guid>
</item>
<item>
<title>Five Ways to Achieve Cloud Compliance</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/26/five-ways-to-achieve-cloud-compliance/390.aspx</link>
<description>&lt;h5&gt;By Allen Allison &lt;/h5&gt;
&lt;p&gt;With the rapid adoption of cloud computing technologies, IT organizations have found a way to deliver applications and services more quickly and efficiently to their customers, incorporating the nearly ubiquitous utility-like platforms of managed cloud services compani ...</description>
<pubDate>Fri, 26 Aug 2011 19:27:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/26/five-ways-to-achieve-cloud-compliance/390.aspx</guid>
</item>
<item>
<title>Earthquakes and Cloud Servers</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/24/earthquakes-and-cloud-servers/389.aspx</link>
<description>&lt;p&gt;It was at about 2 PM when I had settled into my chair to begin moderating our latest webinar on securing cloud servers. Not far into my introductions, I noticed a bit of a rumble beneath my feet, as if someone where taking a jackhammer to the ceiling on the floor below. It was a slight hum at fir ...</description>
<pubDate>Wed, 24 Aug 2011 20:03:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/24/earthquakes-and-cloud-servers/389.aspx</guid>
</item>
<item>
<title>My gift to you: Attend a world-class information security conference in your slippers! </title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/23/my-gift-to-you-attend-a-worldclass-information-security-conference-in-your-slippers-/388.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;It's that time of year again. As the rain cruelly chucks itself at our office windows in Richmond, I'm reminded that summer (or what we've had of it) is starting to surrender itself to Autumn, which means that our &lt;a href=&quot;http://www.infosecurity-magazine.com/virtualconference/20 ...</description>
<pubDate>Tue, 23 Aug 2011 15:41:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/23/my-gift-to-you-attend-a-worldclass-information-security-conference-in-your-slippers-/388.aspx</guid>
</item>
<item>
<title>Dropping In</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/22/dropping-in/387.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.stjernstrom.com&quot;&gt;Magnus Stjernstrom&amp;nbsp;&lt;/a&gt;recently pointed out Cisco&amp;rsquo;s advice on how to &lt;a href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=23896&quot;&gt;detect Dropbox traffic &lt;/a&gt;originating in your network.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s interesting given what it tell ...</description>
<pubDate>Mon, 22 Aug 2011 14:47:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/22/dropping-in/387.aspx</guid>
</item>
<item>
<title>So, What Makes You a Cyber ‘Expert’?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/22/so-what-makes-you-a-cyber-expert/386.aspx</link>
<description>&lt;h5&gt;
&lt;title&gt;&lt;/title&gt;
By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;How many cybersecurity practitioners have had a colleague either in information technology (IT), or worse yet, from a ...</description>
<pubDate>Mon, 22 Aug 2011 13:25:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/22/so-what-makes-you-a-cyber-expert/386.aspx</guid>
</item>
<item>
<title>Shhh!!! No Roaring in the Library!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/19/shhh-no-roaring-in-the-library/385.aspx</link>
<description>&lt;p&gt;It may lack drama after all the excitement of BlackHat (which is my excuse for not having noticed it earlier), but Apple QuickTime 7.7 &lt;a href=&quot;http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html&quot;&gt;fixes&lt;/a&gt; a stack-based buffer overflow&amp;nbsp;issue that was flagged officially ...</description>
<pubDate>Fri, 19 Aug 2011 11:55:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/19/shhh-no-roaring-in-the-library/385.aspx</guid>
</item>
<item>
<title>Hero-to-Zero</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/18/herotozero/384.aspx</link>
<description>&lt;p&gt;Let us set the scene. You are an IT Manager working for a very successful SME, who notwithstanding the economic downturn are commercially flourishing. Keen to maintain the competitive edge, Monday morning the MD sends out a mail to all teams to tease out any ideas which could improve their servic ...</description>
<pubDate>Thu, 18 Aug 2011 13:35:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/18/herotozero/384.aspx</guid>
</item>
<item>
<title>Rethinking Information Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/15/rethinking-information-security/383.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I was reminded the other day that the World Wide Web is 20 years old this month, and it came as a shock to realise I've been involved with it for all but the first three years.&lt;br /&gt;
&lt;br /&gt;
Things move very fast in IT: ten years is a lifetime, and 20 is a whole era. Why then, aft ...</description>
<pubDate>Mon, 15 Aug 2011 20:00:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/15/rethinking-information-security/383.aspx</guid>
</item>
<item>
<title>The Problem with Black Hat &amp; Defcon - Time to buy a T-Shirt Mr CISO</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/12/the-problem-with-black-hat--defcon--time-to-buy-a-tshirt-mr-ciso/382.aspx</link>
<description>&lt;p&gt;OK, I admit it - over the years I have been to most of the security events, and conferences &amp;ndash; RSA, ISACA-EuroCACS, BCS, and of course, it simply would not do to miss the annual pilgrimage to Infosecurity Europe in London every April, which for me is an absolute must do! &lt;/p&gt;
&lt;p&gt;However, of ...</description>
<pubDate>Fri, 12 Aug 2011 20:12:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/12/the-problem-with-black-hat--defcon--time-to-buy-a-tshirt-mr-ciso/382.aspx</guid>
</item>
<item>
<title>Not with a Bang, but a Whimper</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/10/not-with-a-bang-but-a-whimper/380.aspx</link>
<description>&lt;p&gt;The high-profile security conference season is usually enlivened with a few Mac attacks, Apple app attacks, and other euphonious assonances. While the most consistent source of such diversions is probably &lt;a href=&quot;http://macviruscom.wordpress.com/2011/03/14/pwn2own-hackers-vs-apple-ipv6-privacy/&quot; ...</description>
<pubDate>Wed, 10 Aug 2011 09:57:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/10/not-with-a-bang-but-a-whimper/380.aspx</guid>
</item>
<item>
<title>The Feeding Frenzy</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/3/the-feeding-frenzy/378.aspx</link>
<description>&lt;p&gt;In 2008 I had the honour to deliver a Keynote at the E-COPP Security event, hosted by Loughborough University. This presentation discussed the aspect of Cyber Crime, and&amp;nbsp;the associated threats that were impacting the interconnected world, users, and global organisations. The theme of this pr ...</description>
<pubDate>Wed, 03 Aug 2011 18:30:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/3/the-feeding-frenzy/378.aspx</guid>
</item>
<item>
<title>Hyperjack of Flickwhitery</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/2/hyperjack-of-flickwhitery/377.aspx</link>
<description>&lt;p&gt;I have been involved with virtual environments for about a decade now, supporting client consultations, and implementations. Over this period, I have observed growth, from what was once considered a novelty technology, through to today&amp;rsquo;s technological solutions supporting leading edge opera ...</description>
<pubDate>Tue, 02 Aug 2011 21:03:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/2/hyperjack-of-flickwhitery/377.aspx</guid>
</item>
<item>
<title>Losing Control</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/2/losing-control/376.aspx</link>
<description>&lt;p&gt;I saw &lt;a href=&quot;http://www.zdnet.com/blog/igeneration/microsoft-admits-patriot-act-can-access-eu-based-cloud-data/11225&quot;&gt;this&amp;nbsp;&lt;/a&gt;recently and it really drove home on the key truths about cloud computing when it comes to control over your information.&lt;/p&gt;
&lt;p&gt;Here's a great quote:&lt;/p&gt;
&lt;p sty ...</description>
<pubDate>Tue, 02 Aug 2011 19:50:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/2/losing-control/376.aspx</guid>
</item>
<item>
<title> Beyond black-hat bravado</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/29/-beyond-blackhat-bravado/375.aspx</link>
<description>&lt;div&gt;Another week, another monumental hack. This time it was Italy&amp;rsquo;s cybercrime unit, the Centro Nazionale Anticrimine Informatico per la Protezione delle Infrastrutture Critiche (CNAIPIC), that &lt;a href=&quot;http://www.infosecurity-magazine.com/view/19653/anonymous-and-lulzsec-hackers-hit-italian- ...</description>
<pubDate>Fri, 29 Jul 2011 16:03:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/29/-beyond-blackhat-bravado/375.aspx</guid>
</item>
<item>
<title>AET – The Next Level</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/28/aet--the-next-level/374.aspx</link>
<description>&lt;p&gt;For some reason, not all security vendors acknowledge the reality, of possible existence of the Advanced Evasion Technique (AET). The question is, have AET&amp;rsquo;s actually been amongst us for some time now, delivering their adverse payloads to circumvent our trusted levels of perceived security? ...</description>
<pubDate>Thu, 28 Jul 2011 21:12:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/28/aet--the-next-level/374.aspx</guid>
</item>
<item>
<title>Do the goings-on in student dorms spell the end for Microsoft?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/28/do-the-goingson-in-student-dorms-spell-the-end-for-microsoft/373.aspx</link>
<description>&lt;p&gt;This week Quocirca had a briefing with a security vendor which provided an insight into a fundamental change going on in the use of IT and one of the major drivers for that change. The vendor was Bradford Networks, (named not for the city in Yorkshire UK, but small town in New Hampshire USA).&lt;/p&gt; ...</description>
<pubDate>Thu, 28 Jul 2011 15:53:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/28/do-the-goingson-in-student-dorms-spell-the-end-for-microsoft/373.aspx</guid>
</item>
<item>
<title>Cloud Signaling – The Data Center’s Best Defense</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/27/cloud-signaling--the-data-centers-best-defense/372.aspx</link>
<description>&lt;h5&gt;By Rakesh Shah&lt;/h5&gt;
&lt;p&gt;Recent high-profile security incidents heightened awareness of how Distributed Denial of Service (DDoS) attacks can compromise the availability of critical websites, applications and services.  Any downtime can result in lost business, brand damage, financial penalties, a ...</description>
<pubDate>Wed, 27 Jul 2011 19:39:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/27/cloud-signaling--the-data-centers-best-defense/372.aspx</guid>
</item>
<item>
<title>Pass the Buck: Who 's Responsible for Security in the Cloud? </title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/27/pass-the-buck-who-s-responsible-for-security-in-the-cloud-/371.aspx</link>
<description>&lt;h5&gt;By Todd Thiemann&lt;/h5&gt;
&lt;p&gt;Cloud computing changes the equation of responsibility and accountability for information security and poses some new challenges for enterprise IT. At Vormetric we are working with service providers and enterprises to help them secure and control sensitive data in the c ...</description>
<pubDate>Wed, 27 Jul 2011 19:30:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/27/pass-the-buck-who-s-responsible-for-security-in-the-cloud-/371.aspx</guid>
</item>
<item>
<title>Federal Agency Recognizes Information Security as a Separate, Distinct Career Field – But it’s not OPM </title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/26/federal-agency-recognizes-information-security-as-a-separate-distinct-career-field--but-its-not-opm-/369.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;In a recent article, &lt;a href=&quot;http://www.govinfosecurity.com/articles.php?art_id=3833&quot;&gt;&amp;quot;Infosec Joblessness  ...</description>
<pubDate>Tue, 26 Jul 2011 01:22:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/26/federal-agency-recognizes-information-security-as-a-separate-distinct-career-field--but-its-not-opm-/369.aspx</guid>
</item>
<item>
<title>A Blast from the Past – Gary and the Egg</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/25/a-blast-from-the-past--gary-and-the-egg/368.aspx</link>
<description>&lt;p&gt;There would seem to be a suggested lack of understanding as to how&amp;nbsp;the sources are for Cyber Crime&amp;nbsp;flourish. This is linked to a suggested lack of appreciation of what should be considered as 'adequate' levels of Corporate Responsibility for securing the operational enterprise, and othe ...</description>
<pubDate>Mon, 25 Jul 2011 22:44:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/25/a-blast-from-the-past--gary-and-the-egg/368.aspx</guid>
</item>
<item>
<title>Spies like Us</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/21/spies-like-us/367.aspx</link>
<description>&lt;p&gt;The discoveries of widespread hacking, and concerns about Cell, and SmartPhone security have set a notable mood of paranoia in motion, with concerns around the security aspects of telephony.&amp;nbsp; However, this exposure is absolutely nothing new, and the associated threats posed today, have in fa ...</description>
<pubDate>Thu, 21 Jul 2011 22:17:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/21/spies-like-us/367.aspx</guid>
</item>
<item>
<title>Black, Yellow, Blue: By John Walker</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/21/black-yellow-blue-by-john-walker/366.aspx</link>
<description>&lt;p&gt;&lt;strong&gt;&lt;em&gt;I'm posting this blog on behalf of John&amp;nbsp;Walker, whose account is temporarily having some 'down time'...&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Recent reports have stated that the Anonymous Hacktivists group is to set up its own social networking site and service, after they were understandably re ...</description>
<pubDate>Thu, 21 Jul 2011 15:23:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/21/black-yellow-blue-by-john-walker/366.aspx</guid>
</item>
<item>
<title>Phantom pie-throwers and keystroke cops</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/20/phantom-piethrowers-and-keystroke-cops/365.aspx</link>
<description>&lt;p&gt;About 12 hours before some prankster shoved a pie in Rupert Murdoch&amp;rsquo;s face, some other pranksters (namely LulzSec, back in operation after their brief &amp;lsquo;retirement&amp;rsquo;) shoved a virtual pie in the face of his organisation. In the early hours of Tuesday morning, the group managed to  ...</description>
<pubDate>Wed, 20 Jul 2011 14:39:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/20/phantom-piethrowers-and-keystroke-cops/365.aspx</guid>
</item>
<item>
<title>PKI Still Matters, Especially in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/15/pki-still-matters-especially-in-the-cloud/364.aspx</link>
<description>&lt;p&gt;&amp;nbsp;By:  Merritt Maxim&lt;br /&gt;
Director of IAM Product Marketing&lt;br /&gt;
CA Technologies Inc.&lt;/p&gt;
&lt;p&gt;Infosec veterans probably remember (with a smirk) how Public Key Infrastructure (PKI) was heralded as the next &amp;ldquo;big thing&amp;rdquo; in information security at the dawn of the 21st century.  Wh ...</description>
<pubDate>Fri, 15 Jul 2011 19:55:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/15/pki-still-matters-especially-in-the-cloud/364.aspx</guid>
</item>
<item>
<title>Mist and Cloud Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/13/mist-and-cloud-security/363.aspx</link>
<description>&lt;p&gt;When it comes to engaging with any new way of working, &amp;lsquo;security&amp;rsquo; will always be of interest. However, when it comes to that magic mist called Cloud Computing, this is very much the case. But what has changed here is, it is not necessarily the CISO who is raising the concern, but thos ...</description>
<pubDate>Wed, 13 Jul 2011 17:34:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/13/mist-and-cloud-security/363.aspx</guid>
</item>
<item>
<title>Press regulation won't protect our data privacy</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/13/press-regulation-wont-protect-our-data-privacy/362.aspx</link>
<description>&lt;p&gt;
&lt;meta charset=&quot;utf-8&quot;&gt;  &lt;/meta&gt;
&lt;/p&gt;
&lt;p&gt;The current phone hacking scandal has once again propelled data privacy and security issues to the top of the public agenda. While there are many calls for tighter regulation of the press in a bid to prevent any future use of such tactics, I fear such a ...</description>
<pubDate>Wed, 13 Jul 2011 12:53:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/13/press-regulation-wont-protect-our-data-privacy/362.aspx</guid>
</item>
<item>
<title>Mitigating denial of service attacks</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/13/mitigating-denial-of-service-attacks/361.aspx</link>
<description>&lt;p&gt;The common view of a denial of service (DoS) attack is that of a flood of requests to a given web server that overwhelms it and render it useless, at least temporarily. Such attacks have most commonly been perpetrated via botnets, a network of hijacked computers compromised by malware coordinated ...</description>
<pubDate>Wed, 13 Jul 2011 12:18:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/13/mitigating-denial-of-service-attacks/361.aspx</guid>
</item>
<item>
<title>Understanding Best-in-Class Cloud Security Measures and How to Evaluate Providers</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/11/understanding-bestinclass-cloud-security-measures-and-how-to-evaluate-providers/360.aspx</link>
<description>&lt;p&gt;&amp;nbsp;By Fahim Siddiqui&lt;/p&gt;
&lt;p&gt;Despite a broader interest in cloud computing, many organizations have been reluctant to embrace the technology due to security concerns. While today&amp;rsquo;s businesses can benefit from cloud computing&amp;rsquo;s on-demand capacity and economies of scale, the model do ...</description>
<pubDate>Mon, 11 Jul 2011 20:09:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/11/understanding-bestinclass-cloud-security-measures-and-how-to-evaluate-providers/360.aspx</guid>
</item>
<item>
<title>Watch Out for the Top 6 Cloud Gotchas!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/11/watch-out-for-the-top-6-cloud-gotchas/359.aspx</link>
<description>&lt;h5&gt;&amp;nbsp;By Margaret Dawson&lt;/h5&gt;
&lt;p&gt;I am a huge proponent of cloud-based solutions, but I also have a bailiwick for people who look to the cloud just for cloud&amp;rsquo;s sake, and do not take time to do the due diligence.  While the cloud can bring strong technical, economic and business benefits if ...</description>
<pubDate>Mon, 11 Jul 2011 19:56:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/11/watch-out-for-the-top-6-cloud-gotchas/359.aspx</guid>
</item>
<item>
<title>The Cost of a Data Breach</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/8/the-cost-of-a-data-breach/358.aspx</link>
<description>&lt;p&gt;As I have done in a previous post, I am taking this opportunity to share with our online audience some of the letters we receive regarding our online and print coverage. This letter comes from a reader of our most recent issue, and my response to his comments can be found below the letter. As alw ...</description>
<pubDate>Fri, 08 Jul 2011 18:38:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/8/the-cost-of-a-data-breach/358.aspx</guid>
</item>
<item>
<title>Editor's perspective: Infosecurity Europe Joins Forces with Infosecurity Magazine</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/6/editors-perspective-infosecurity-europe-joins-forces-with-infosecurity-magazine/357.aspx</link>
<description>&lt;p&gt;
&lt;div style=&quot;text-align: justify;&quot;&gt;I hope that by now you have heard the &lt;a href=&quot;http://www.infosecurity-magazine.com/view/19190/infosecurity-europe-joins-forces-with-infosecurity-magazine-online-news-site-to-create-stronger-united-market-offering-/&quot;&gt;good news?&lt;/a&gt; &lt;a href=&quot;http://www.infosecur ...</description>
<pubDate>Wed, 06 Jul 2011 14:09:02 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/6/editors-perspective-infosecurity-europe-joins-forces-with-infosecurity-magazine/357.aspx</guid>
</item>
<item>
<title>Smart Thinking</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/1/smart-thinking/356.aspx</link>
<description>&lt;p&gt;Most people may not immediately recognize the name Reinhold Niebuhr, but they are probably familiar with some version of his best known prayer:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;quot;God grant me the serenity to accept the things I cannot change, courage to change the things I can change, and the wisdom to  ...</description>
<pubDate>Fri, 01 Jul 2011 20:09:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/1/smart-thinking/356.aspx</guid>
</item>
<item>
<title>Make the wrong career move, and you just may become structurally unemployed</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/30/make-the-wrong-career-move-and-you-just-may-become-structurally-unemployed/355.aspx</link>
<description>&lt;p class=&quot;p1&quot;&gt;A recent &lt;em&gt;Washington Post&lt;/em&gt; article, &amp;ldquo;&lt;a href=&quot;http://www.washingtonpost.com/opinions/the-great-jobs-mismatch/2011/06/19/AGWdB3bH_story.html&quot;&gt;&lt;span class=&quot;s1&quot;&gt;The great jobs mismatch&lt;/span&gt;&lt;/a&gt;&amp;rdquo;, points out that structural unemployment is caused by a mismatch between  ...</description>
<pubDate>Thu, 30 Jun 2011 20:17:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/30/make-the-wrong-career-move-and-you-just-may-become-structurally-unemployed/355.aspx</guid>
</item>
<item>
<title>In people we trust...</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/29/in-people-we-trust/354.aspx</link>
<description>&lt;p&gt;&amp;nbsp;So, thus begins my blog. Admittedly, it&amp;rsquo;s long overdue. My intention to blog has been very honourable (honestly), it&amp;rsquo;s just the &amp;lsquo;actually doing it&amp;rsquo; bit which has been a little slack, to say the least.&lt;br /&gt;
&lt;br /&gt;
Yesterday, I spent the day at &lt;a href=&quot;http://www.t ...</description>
<pubDate>Wed, 29 Jun 2011 12:52:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/29/in-people-we-trust/354.aspx</guid>
</item>
<item>
<title>How Public Cloud Providers Can Improve Their Trustworthiness</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/28/how-public-cloud-providers-can-improve-their-trustworthiness/353.aspx</link>
<description>&lt;h5&gt;By Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;When you meet someone you have never met for the first time, in a place you have never been to, do you trust him?  Would you have him hold your wallet for you or would you share some sensitive personal information with him?  Of course not. Obviously this person is no ...</description>
<pubDate>Tue, 28 Jun 2011 20:42:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/28/how-public-cloud-providers-can-improve-their-trustworthiness/353.aspx</guid>
</item>
<item>
<title>Weinergate and The Case for Full Disclosure of Data Breaches</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/23/weinergate-and-the-case-for-full-disclosure-of-data-breaches/352.aspx</link>
<description>&lt;p&gt;Often when I chat with people within the industry, the one thing I expect is a consistent message akin to a broken record. &lt;/p&gt;
&lt;p&gt;De-perimiterization, consumerization, defense in depth &amp;ndash; the list of things I hear brought up in nearly every conversation is as fine tuned as a political cand ...</description>
<pubDate>Thu, 23 Jun 2011 20:26:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/23/weinergate-and-the-case-for-full-disclosure-of-data-breaches/352.aspx</guid>
</item>
<item>
<title>Unhealthy Irritation</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/20/unhealthy-irritation/350.aspx</link>
<description>&lt;p&gt;I have to admit, I find this sort of thing just irritating:&lt;/p&gt;
&lt;p&gt;The Register last week &lt;a href=&quot;http://www.theregister.co.uk/2011/06/15/eight_million_health_records/&quot;&gt;reported &lt;/a&gt;that eight million patient records were lost on a laptop. Unencrypted records.&amp;nbsp; No, really.&lt;/p&gt;
&lt;p&gt;As a spo ...</description>
<pubDate>Mon, 20 Jun 2011 21:18:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/20/unhealthy-irritation/350.aspx</guid>
</item>
<item>
<title>Privacy Consequences of WiFi MAC Availability Over the Air</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/16/privacy-consequences-of-wifi-mac-availability-over-the-air/348.aspx</link>
<description>&lt;p&gt;In a recently released report titled &lt;a href=&quot;http://www.newswire.ca/en/releases/archive/June2011/14/c5709.html&quot;&gt;&amp;ldquo;Wi-Fi Positioning Systems: Beware of Unintended Consequences&amp;rdquo;&lt;/a&gt;&amp;nbsp; &amp;ndash; by Ontario's Information and Privacy Commissioner, Dr. Ann Cavoukian, and Kim Cameron, a le ...</description>
<pubDate>Thu, 16 Jun 2011 09:33:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/16/privacy-consequences-of-wifi-mac-availability-over-the-air/348.aspx</guid>
</item>
<item>
<title>The Human Factor Reigns Supreme!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/9/the-human-factor-reigns-supreme/346.aspx</link>
<description>&lt;p&gt;Do you know who has access to your computer? Many agencies and corporations spend a majority of their budgets on new technological security software gimmicks while forgetting the human factor.  Personnel security must be included as an integral part of information security. All of the technologic ...</description>
<pubDate>Thu, 09 Jun 2011 21:23:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/9/the-human-factor-reigns-supreme/346.aspx</guid>
</item>
<item>
<title>Wild West of Data Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/31/wild-west-of-data-security/343.aspx</link>
<description>&lt;p&gt;Question for the day: What can the turn-of-the century cattle industry teach us about cloud security? Quite a lot, I believe&amp;nbsp;&amp;ndash; especially by the ways in which driving cattle and keeping data secure are so very different.&lt;/p&gt;
&lt;p&gt;Back in the 1880s driving cattle across the US was big bu ...</description>
<pubDate>Tue, 31 May 2011 15:56:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/31/wild-west-of-data-security/343.aspx</guid>
</item>
<item>
<title>Finding a Home for BitLocker</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/17/finding-a-home-for-bitlocker/339.aspx</link>
<description>&lt;p&gt;With the last several &lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/4/14/opening-up-bitlocker-part-2--recovery-keys/317.aspx&quot;&gt;posts &lt;/a&gt;being about &lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/4/1/opening-up-bitlocker/311.aspx&quot;&gt;BitLocker&lt;/a&gt;&amp;nbsp;&amp;nbsp;(and especially Recovery Keys) hope ...</description>
<pubDate>Tue, 17 May 2011 15:54:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/17/finding-a-home-for-bitlocker/339.aspx</guid>
</item>
<item>
<title>What, if Any, Cybersecurity Workforce Implications Resulted From the Averted Government Shutdown?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/12/what-if-any-cybersecurity-workforce-implications-resulted-from-the-averted-government-shutdown/338.aspx</link>
<description>&lt;p&gt;While the Federal Government shutdown was averted thanks to some last-minute political gerrymandering and concessions by both sides of the aisle, it&amp;rsquo;s quite instructive to reflect on the implications of shutdown on the federal cybersecurity workforce, including contracts and contractors.&lt;/p ...</description>
<pubDate>Thu, 12 May 2011 03:47:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/12/what-if-any-cybersecurity-workforce-implications-resulted-from-the-averted-government-shutdown/338.aspx</guid>
</item>
<item>
<title>Security Standards – Why they are so Critical for the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/9/security-standards--why-they-are-so-critical-for-the-cloud/337.aspx</link>
<description>&lt;h5&gt;By&amp;nbsp;Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;Everyone loves standards, right?  When is the last time you heard a vendor proudly say that their product or service was closed and proprietary?  However, it also seems that every time a new IT architecture sweeps through the market, this time one based on cloud ...</description>
<pubDate>Mon, 09 May 2011 19:32:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/9/security-standards--why-they-are-so-critical-for-the-cloud/337.aspx</guid>
</item>
<item>
<title>OAuth – authentication and authorization for mobile applications</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/3/oauth--authentication-and-authorization-for-mobile-applications/335.aspx</link>
<description>&lt;h5&gt;By Paul Madsen&lt;/h5&gt;
&lt;p&gt;Federation is a model of identity management that distributes the various individual components of an identity operation amongst different actors. The presumption being that the jobs can be distributed according to which actors are best suited or positioned to take them o ...</description>
<pubDate>Tue, 03 May 2011 20:32:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/3/oauth--authentication-and-authorization-for-mobile-applications/335.aspx</guid>
</item>
<item>
<title>Who Moved My Cloud?
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/3/who-moved-my-cloud/334.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;p&gt;Managed cloud services are quickly being adopted by large enterprises.  Organizations are increasingly embracing cloud technologies for core services like financial systems, IT infrastructure, online merchant sites, and messaging solutions.  This adoption rate is creati ...</description>
<pubDate>Tue, 03 May 2011 19:27:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/3/who-moved-my-cloud/334.aspx</guid>
</item>
<item>
<title>Five Guidelines for Cloud Computing and Device Security in The “Always Able” Era</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/29/five-guidelines-for-cloud-computing-and-device-security-in-the-always-able-era/332.aspx</link>
<description>&lt;h5&gt;By Mark Bregman&lt;/h5&gt;
&lt;p&gt;Chief Information Security Officers know instinctively that the world under their purview is undergoing a shift every bit as significant as the rise of the World Wide Web more than 15 years ago. The demand on our workforce to be ever more productive is driving us to reth ...</description>
<pubDate>Fri, 29 Apr 2011 18:35:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/29/five-guidelines-for-cloud-computing-and-device-security-in-the-always-able-era/332.aspx</guid>
</item>
<item>
<title>Amazon Sneezed (and the Cloud Caught a Cold?)</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/28/amazon-sneezed-and-the-cloud-caught-a-cold/329.aspx</link>
<description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Never confuse a single defeat with a final defeat.&lt;/em&gt;&lt;br /&gt;
&amp;nbsp;&amp;ndash; F. Scott Fitzgerald&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So last week was, depending on who you ask, a terrible week for &amp;quot;The Cloud,&amp;quot; a wakeup call for businesses who want to use cloud services, or nothing  ...</description>
<pubDate>Thu, 28 Apr 2011 17:06:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/28/amazon-sneezed-and-the-cloud-caught-a-cold/329.aspx</guid>
</item>
<item>
<title>Protect the API Keys to your Cloud Kingdom</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/20/protect-the-api-keys-to-your-cloud-kingdom/322.aspx</link>
<description>&lt;div style=&quot;background-color: rgb(255, 255, 255); padding-top: 5px; padding-right: 5px; padding-bottom: 5px; padding-left: 5px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;
&lt;h5&gt;By Mark O&amp;rsquo;Neill&lt;/h5&gt;
&lt;p&gt;Much lip service is paid to protecting information in the C ...</description>
<pubDate>Wed, 20 Apr 2011 19:08:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/20/protect-the-api-keys-to-your-cloud-kingdom/322.aspx</guid>
</item>
<item>
<title>Is Tokenization or Encryption Keeping You Up at Night?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/20/is-tokenization-or-encryption-keeping-you-up-at-night/321.aspx</link>
<description>&lt;h5&gt;By Stuart Lisk, Senior Product Manager, Hubspan&lt;/h5&gt;
&lt;div&gt;Are you losing sleep over whether to implement tokenization or full encryption as your cloud security methodology? Do you find yourself lying awake wondering if you locked all the doors to your sensitive data? Your &amp;ldquo;sleepless with  ...</description>
<pubDate>Wed, 20 Apr 2011 18:27:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/20/is-tokenization-or-encryption-keeping-you-up-at-night/321.aspx</guid>
</item>
<item>
<title>Constant Vigilance</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/14/constant-vigilance/318.aspx</link>
<description>&lt;h5&gt;&lt;b&gt;&lt;span style=&quot;&quot;&gt;By Jon Heimerl &lt;/span&gt;&lt;/b&gt;&lt;/h5&gt;
&lt;h5&gt;&amp;nbsp;&lt;/h5&gt;
&lt;p&gt;&lt;span style=&quot;&quot;&gt;Constant Vigilance. Mad-Eye Moody puts it very well. Constant Vigilance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;&quot;&gt;Unfortunately, these days we need constant vigilance to help protect ourselves and companies from peril. Th ...</description>
<pubDate>Thu, 14 Apr 2011 20:00:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/14/constant-vigilance/318.aspx</guid>
</item>
<item>
<title>Opening up BitLocker, part 2 – Recovery Keys</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/14/opening-up-bitlocker-part-2--recovery-keys/317.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/4/1/opening-up-bitlocker/311.aspx&quot;&gt;Last time&amp;nbsp;&lt;/a&gt; I covered an introduction to BitLocker, the Trusted Platform Module (TPM) and what TPM does to assist in keeping your system secure. This time I'm writing about the most important aspect of Bi ...</description>
<pubDate>Thu, 14 Apr 2011 17:54:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/14/opening-up-bitlocker-part-2--recovery-keys/317.aspx</guid>
</item>
<item>
<title>Cybersecurity: The Road Ahead</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/14/cybersecurity-the-road-ahead/316.aspx</link>
<description>&lt;p&gt;This paper by the &lt;a target=&quot;_blank&quot; href=&quot;http://www.dcaf.ch/Publications/Publication-Detail?lng=en&amp;amp;id=126370&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Geneva Centre for the Democratic Control of Armed Forces  (DCAF)&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; was just brought to my attention. A piece of work that is  definit ...</description>
<pubDate>Thu, 14 Apr 2011 11:07:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/14/cybersecurity-the-road-ahead/316.aspx</guid>
</item>
<item>
<title>Cloud Annexation</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/12/cloud-annexation/315.aspx</link>
<description>&lt;h5&gt;By Stephen R Carter&lt;/h5&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;The Cloud is the next evolutionary step in the life of the Internet. From the experimental ARPANET (Advanced Research Projects Agency Network) to the Internet to the Web &amp;ndash; and now to the Cloud &amp;ndash; the evolution continues to advance inte ...</description>
<pubDate>Tue, 12 Apr 2011 20:47:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/12/cloud-annexation/315.aspx</guid>
</item>
<item>
<title>The Future of Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/11/the-future-of-security/314.aspx</link>
<description>&lt;p&gt;Visitors to the recent RSA Conference in San Francisco were treated to a forward-looking &lt;a href=&quot;http://media.omediaweb.com/rsa2011/keynotes/webcast.htm?id=3-5&quot;&gt;keynote&lt;/a&gt; by City University of New York professor and television personality Michio Kaku. His presentation on the next 20 years of c ...</description>
<pubDate>Mon, 11 Apr 2011 16:44:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/11/the-future-of-security/314.aspx</guid>
</item>
<item>
<title>On First Base with Stolen Email Addresses</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/4/on-first-base-with-stolen-email-addresses/313.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.cnn.com/2011/TECH/web/04/04/epsilon.stolen.emails/&quot;&gt;CNN continues to report&lt;/a&gt; on the compromise of email addresses and names from Epsilon systems over the weekend and the potential impact it may have on net citizens. There is fear and uncertainty that comes with any compromi ...</description>
<pubDate>Mon, 04 Apr 2011 19:22:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/4/on-first-base-with-stolen-email-addresses/313.aspx</guid>
</item>
<item>
<title>Privileged Administrators and the Cloud: Who will Watch the Watchmen?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/1/privileged-administrators-and-the-cloud-who-will-watch-the-watchmen/312.aspx</link>
<description>&lt;h5&gt;By Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;One of the key advantages of the cloud, whether public or private, flows from a well-known econometric concept known as &amp;ldquo;economies of scale.&amp;rdquo; The concept of economies of scale refers to an operation that to a point gets more efficient as it gets bigger &amp;n ...</description>
<pubDate>Fri, 01 Apr 2011 19:52:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/1/privileged-administrators-and-the-cloud-who-will-watch-the-watchmen/312.aspx</guid>
</item>
<item>
<title>Opening up BitLocker</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/1/opening-up-bitlocker/311.aspx</link>
<description>&lt;p&gt;It's hard to avoid the flurry of bad press following the recent loss of a laptop by a &lt;a href=&quot;http://www.infosecurity-us.com/view/16946/bp-loses-laptop-containing-details-of-13000-oil-spill-victims/&quot;&gt;BP employee.&lt;/a&gt; Unfortunately for all concerned, the lost laptop contained the names and person ...</description>
<pubDate>Fri, 01 Apr 2011 18:44:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/1/opening-up-bitlocker/311.aspx</guid>
</item>
<item>
<title>Debunking the Top Three Cloud Security Myths</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/30/debunking-the-top-three-cloud-security-myths/308.aspx</link>
<description>&lt;h5&gt;By Margaret Dawson&lt;/h5&gt;
&lt;p&gt;The &amp;ldquo;cloud&amp;rdquo; is one of the most discussed topics among IT professionals today, and organizations are increasingly exploring the potential benefits of using cloud computing or solutions for their businesses. It&amp;rsquo;s no surprise &lt;a href=&quot;http://www.gartner ...</description>
<pubDate>Wed, 30 Mar 2011 20:06:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/30/debunking-the-top-three-cloud-security-myths/308.aspx</guid>
</item>
<item>
<title>[How to] Be Confident When Storing Information in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/29/how-to-be-confident-when-storing-information-in-the-cloud/306.aspx</link>
<description>&lt;h5&gt;By Anil Chakravarthy and Deepak Mohan&lt;/h5&gt;
&lt;p&gt;Over the past few years, information explosion has inhibited organizations&amp;rsquo; ability to effectively secure, manage and recover data. This complexity is only increasing as organizations try to manage the data growth by moving it to the cloud. It ...</description>
<pubDate>Tue, 29 Mar 2011 20:16:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/29/how-to-be-confident-when-storing-information-in-the-cloud/306.aspx</guid>
</item>
<item>
<title>Revisiting Data Privacy Day</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/28/revisiting-data-privacy-day/305.aspx</link>
<description>&lt;p&gt;We regret that we did not have space to publish this in our upcoming print edition, but we here at &lt;em&gt;Infosecurity&lt;/em&gt; nonetheless thought it was important to provide our readers with this feedback we received recently on one of our web news items. Since it is in reference to an online item, we ...</description>
<pubDate>Mon, 28 Mar 2011 17:53:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/28/revisiting-data-privacy-day/305.aspx</guid>
</item>
<item>
<title>Data Sinks and Data Leakage – The Effect of Poisoned Links</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/25/data-sinks-and-data-leakage--the-effect-of-poisoned-links/304.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Gone are the days of text user interfaces for exchanging data or email over the Internet. Now, users are hard pressed to exchange information without using HTML or any of the Web 2.0 features. When the WWW was in its infancy, our ability to share and download information propelle ...</description>
<pubDate>Fri, 25 Mar 2011 21:22:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/25/data-sinks-and-data-leakage--the-effect-of-poisoned-links/304.aspx</guid>
</item>
<item>
<title>WPA2 Secured Hotspots: Feasible with New WiFi Alliance Hotspot Certification</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/23/wpa2-secured-hotspots-feasible-with-new-wifi-alliance-hotspot-certification/303.aspx</link>
<description>&lt;p&gt;Public WiFi hotspots have shown tremendous growth in recent years. Much of this can be attributed to growing number of people carrying smart mobile devices (such as smartphones and tablets) and using bandwidth-consuming internet applications (such as gaming, social networking sites and audio/vide ...</description>
<pubDate>Wed, 23 Mar 2011 14:50:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/23/wpa2-secured-hotspots-feasible-with-new-wifi-alliance-hotspot-certification/303.aspx</guid>
</item>
<item>
<title>Hey, You, Get off of My Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/22/hey-you-get-off-of-my-cloud/302.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;div&gt;The emerging Public Cloud versus Private Cloud debate is not just about which solution is best. It extends to the very definition of cloud.&amp;nbsp;I won&amp;rsquo;t pretend that my definitions of public cloud and private cloud match everybody elses, but I would like to begi ...</description>
<pubDate>Tue, 22 Mar 2011 18:08:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/22/hey-you-get-off-of-my-cloud/302.aspx</guid>
</item>
<item>
<title>Three Cloud-Computing Data Security Risks That Can’t be Overlooked</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/21/three-cloudcomputing-data-security-risks-that-cant-be-overlooked/301.aspx</link>
<description>&lt;h5&gt;&amp;nbsp;By&amp;nbsp;Slavik Markovich&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/h5&gt;
&lt;div&gt;The move to cloud computing brings with it a number of attributes that require special consideration when it comes to securing data.&amp;nbsp;And since in nearly every organization, their most sensitive data will be stored either directly in a ...</description>
<pubDate>Mon, 21 Mar 2011 16:12:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/21/three-cloudcomputing-data-security-risks-that-cant-be-overlooked/301.aspx</guid>
</item>
<item>
<title>WiFi Hacking not Always a Cyber Crime</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/19/wifi-hacking-not-always-a-cyber-crime/299.aspx</link>
<description>&lt;p&gt;If someone is assuming that hacking/breaking into a WiFi router for piggybacking on the router&amp;rsquo;s internet connection is illegal, then he/she needs to double check the same with the applicable CyberLaw. This was highlighted in view of a &lt;a href=&quot;http://www.pcworld.com/article/222589/dutch_co ...</description>
<pubDate>Sat, 19 Mar 2011 11:09:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/19/wifi-hacking-not-always-a-cyber-crime/299.aspx</guid>
</item>
<item>
<title>WiFi Security Still Elusive for Many Users

</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/18/wifi-security-still-elusive-for-many-users/298.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;WiFi security continues to hog the limelight with the &lt;a href=&quot;http://www.infosecurity-us.com/blog/2010/12/28/summarizing-wifi-security-revelations-for-the-year-2010/262.aspx&quot;&gt;series of related revelations and incidents&lt;/a&gt; happening periodically. And the latest in this series ar ...</description>
<pubDate>Fri, 18 Mar 2011 15:21:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/18/wifi-security-still-elusive-for-many-users/298.aspx</guid>
</item>
<item>
<title>Does a High-Performance Cloud Make For More Work?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/11/does-a-highperformance-cloud-make-for-more-work/295.aspx</link>
<description>&lt;p&gt;A couple of quick thoughts here, mostly around the changing scale of the task of securing information in the cloud.&lt;/p&gt;
&lt;p&gt;I think we see a couple of interesting trends here and they are, well, not necessarily complementary. The first is that the cloud providers are getting serious about scaling ...</description>
<pubDate>Fri, 11 Mar 2011 21:05:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/11/does-a-highperformance-cloud-make-for-more-work/295.aspx</guid>
</item>
<item>
<title>SEC and the Porn Farm</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/10/sec-and-the-porn-farm/294.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Thirty-three people at the SEC were found to have been looking at porn at work over the past five years according the a summary of internal probes conducted by the SEC&amp;rsquo;s inspector general and reported by the &lt;a href=&quot;http://online.wsj.com/article/SB1000142405274870438830457 ...</description>
<pubDate>Thu, 10 Mar 2011 20:59:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/10/sec-and-the-porn-farm/294.aspx</guid>
</item>
<item>
<title>Cloud Security: The Identity Factor</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/10/cloud-security-the-identity-factor/293.aspx</link>
<description>&lt;h5&gt;By Patrick Harding&lt;/h5&gt;
&lt;h3&gt;The Problem with Passwords&lt;/h3&gt;
&lt;p&gt;The average enterprise employee uses 12 userid/password pairs for accessing the many applications required to perform his or her job (Osterman Research 2009). It is unreasonable to expect anyone to create, regularly change (also a  ...</description>
<pubDate>Thu, 10 Mar 2011 15:34:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/10/cloud-security-the-identity-factor/293.aspx</guid>
</item>
<item>
<title>Navigating Cloud Application Security: Myths vs. Realities </title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/8/navigating-cloud-application-security-myths-vs-realities-/290.aspx</link>
<description>&lt;h5&gt;By Chris Wysopal&lt;/h5&gt;
&lt;p&gt;Developers and IT departments are being told they need to move applications to the cloud and are often left on their own to navigate the challenges related to developing and managing the security of applications in those environments.  Because no one should have to fly  ...</description>
<pubDate>Tue, 08 Mar 2011 16:14:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/8/navigating-cloud-application-security-myths-vs-realities-/290.aspx</guid>
</item>
<item>
<title>Keeping Control in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/4/keeping-control-in-the-cloud/287.aspx</link>
<description>&lt;p&gt;I had a great talk with &lt;a href=&quot;http://www.infosecurity-us.com/view/16323/risks-discourage-firms-from-taking-advantage-of-cloud-benefits-/&quot;&gt;Fred Donovan &lt;/a&gt;this week regarding cloud security.&lt;/p&gt;
&lt;p&gt;It's pretty clear that organizations of all kinds are very concerned about the risks (and the c ...</description>
<pubDate>Fri, 04 Mar 2011 21:58:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/4/keeping-control-in-the-cloud/287.aspx</guid>
</item>
<item>
<title>Trusted Client to Cloud Access</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/2/trusted-client-to-cloud-access/286.aspx</link>
<description>&lt;h5&gt;By Vikas Jain&lt;/h5&gt;
&lt;p&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Cloud_computing&quot;&gt;&lt;span style=&quot;text-decoration: underline;&quot;&gt;C&lt;/span&gt;loud computing&lt;/a&gt; has become an integral part of all IT decision making today across industries and geographies. This market is growing at a rapid pace. By 2014, IDC e ...</description>
<pubDate>Wed, 02 Mar 2011 17:10:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/2/trusted-client-to-cloud-access/286.aspx</guid>
</item>
<item>
<title>Aligning Security with the Business</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/1/aligning-security-with-the-business/285.aspx</link>
<description>&lt;p&gt;Do you know the feeling? You should share a large file with somebody outside your organization. The file is too big to be sent by e-mail. What can you do? Well, you might have a service by internal IT (we have one) that is not really user-friendly, hard to use and &amp;ndash; as you do not need it to ...</description>
<pubDate>Tue, 01 Mar 2011 16:41:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/1/aligning-security-with-the-business/285.aspx</guid>
</item>
<item>
<title>Senator Schumer Calls for Increased Public WiFi Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/28/senator-schumer-calls-for-increased-public-wifi-security/284.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;Increased use of public WiFi access at hotspots, retail stores, hotels and other similar establishments has recently motivated &lt;a href=&quot;http://uk.reuters.com/article/2011/02/27/tech-us-schumer-wifi-idUKTRE71Q2N420110227&quot;&gt;New York Democrat, Sen. Charles S ...</description>
<pubDate>Mon, 28 Feb 2011 13:51:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/28/senator-schumer-calls-for-increased-public-wifi-security/284.aspx</guid>
</item>
<item>
<title>And the Thunder Rolls: All the Noise about Cloud and What that Means When Lightning Strikes</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/23/and-the-thunder-rolls-all-the-noise-about-cloud-and-what-that-means-when-lightning-strikes/283.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;p&gt;Disaster Recovery (DR) and Business Continuity Planning (BCP) continue to be driving factors for some organizations looking to move to the cloud. Many are looking to manage their Disaster Recovery planning through extensive use of managed cloud services &amp;ndash; and for  ...</description>
<pubDate>Wed, 23 Feb 2011 16:35:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/23/and-the-thunder-rolls-all-the-noise-about-cloud-and-what-that-means-when-lightning-strikes/283.aspx</guid>
</item>
<item>
<title>Top Six Security Questions Every CIO Should Ask a Cloud Vendor </title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/23/top-six-security-questions-every-cio-should-ask-a-cloud-vendor-/282.aspx</link>
<description>&lt;h5&gt;&lt;span style=&quot;color: black;&quot;&gt;By &lt;/span&gt;Ian Huynh&lt;/h5&gt;
&lt;div&gt;&lt;span style=&quot;color: black;&quot;&gt;Cloud computing has become an integrated part of IT strategy for companies in every sector of our economy.&amp;nbsp;By 2012, IDC predicts that IT spending on cloud services will grow almost threefold, to $42 billi ...</description>
<pubDate>Wed, 23 Feb 2011 16:18:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/23/top-six-security-questions-every-cio-should-ask-a-cloud-vendor-/282.aspx</guid>
</item>
<item>
<title>Cloud, here we come!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/11/cloud-here-we-come/281.aspx</link>
<description>&lt;p&gt;Cloud, here we come!&amp;nbsp; Or is it rather more a case of &amp;quot;We're already here, so make the best of it...&amp;quot;?&lt;/p&gt;
&lt;p&gt;I spent some time today talking to a good friend of mine who also happens to be the head of security for a large European financial services business. Unsurprisingly we got ...</description>
<pubDate>Fri, 11 Feb 2011 23:22:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/11/cloud-here-we-come/281.aspx</guid>
</item>
<item>
<title>Quit Worrying About Cloud Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/4/quit-worrying-about-cloud-security/278.aspx</link>
<description>&lt;p&gt;Well, it is not THAT easy but at least there are people starting to claim that it is not as hard as it seems to be sometimes. I stumbled across the following article: &lt;a target=&quot;_blank&quot; href=&quot;http://fcw.com/articles/2011/01/31/cloud-security.aspx?s=security_030211&amp;amp;admgarea=TC_SECCYBERSEC&quot;&gt;&lt;st ...</description>
<pubDate>Fri, 04 Feb 2011 11:03:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/4/quit-worrying-about-cloud-security/278.aspx</guid>
</item>
<item>
<title>Buying the Security Farm</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/2/buying-the-security-farm/277.aspx</link>
<description>&lt;p&gt;The landscape of &lt;a href=&quot;http://www.esoft.com/&quot;&gt;network security&lt;/a&gt;  is a world of transition. However, one thing we know for certain is that  the threats are becoming more organized, more advanced, and more  focused on obtaining one thing: information the attacker can sell. &lt;/p&gt;
&lt;p&gt;What  do t ...</description>
<pubDate>Wed, 02 Feb 2011 22:52:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/2/buying-the-security-farm/277.aspx</guid>
</item>
<item>
<title>Extend the Enterprise into the Cloud with Single Sign-On to Cloud-Based Services</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/1/extend-the-enterprise-into-the-cloud-with-single-signon-to-cloudbased-services/276.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;b&gt;By Mark O&amp;rsquo;Neill&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;In this blog post we examine how Single Sign-On from the enterprise to Cloud-based services is enabled. Single Sign-On is a critical component for any organization wishing to leverage Cloud services. In fact, an organization accessing Cloud-based service ...</description>
<pubDate>Tue, 01 Feb 2011 16:18:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/1/extend-the-enterprise-into-the-cloud-with-single-signon-to-cloudbased-services/276.aspx</guid>
</item>
<item>
<title>Dining in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/28/dining-in-the-cloud/274.aspx</link>
<description>&lt;p&gt;I enjoyed &lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/1/19/will-the-cloud-cause-the-reemergence-of-security-silos/266.aspx&quot;&gt;Matthew Gardener's blog &lt;/a&gt;this week on the potential for the re-emergence of security silos as a result of the growing move out into the cloud. I think he's right, o ...</description>
<pubDate>Fri, 28 Jan 2011 15:08:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/28/dining-in-the-cloud/274.aspx</guid>
</item>
<item>
<title>Are You Focused On The Wrong Security Risks?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/28/are-you-focused-on-the-wrong-security-risks/273.aspx</link>
<description>&lt;p&gt;There is an good article on CIO Central: &lt;a target=&quot;_blank&quot; href=&quot;http://blogs.forbes.com/ciocentral/2011/01/27/are-you-focused-on-the-wrong-security-risks/&quot;&gt;Are You Focused On The Wrong Security Risks?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;An interesting discussion, and I partly agree that we have to challenge the way  w ...</description>
<pubDate>Fri, 28 Jan 2011 09:34:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/28/are-you-focused-on-the-wrong-security-risks/273.aspx</guid>
</item>
<item>
<title>Building a Secure Future in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/27/building-a-secure-future-in-the-cloud/271.aspx</link>
<description>&lt;h5&gt;By Mark Bregman&lt;/h5&gt;
&lt;p&gt;Cloud computing offers clear and powerful benefits to IT organizations of all sizes, but the path to cloud computing &amp;ndash; please excuse the pun &amp;ndash; is often cloudy.&lt;/p&gt;
&lt;p&gt;With cloud computing, IT resources can scale almost immediately in response to business nee ...</description>
<pubDate>Thu, 27 Jan 2011 16:33:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/27/building-a-secure-future-in-the-cloud/271.aspx</guid>
</item>
<item>
<title>Moving to the Cloud? Take Your Application Security With You</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/27/moving-to-the-cloud-take-your-application-security-with-you/270.aspx</link>
<description>&lt;h5&gt;By Bill Pennington&lt;/h5&gt;
&lt;p&gt;Cloud computing is becoming a fundamental part of information technology. Nearly every enterprise is evaluating or deploying cloud solutions. Even as business managers turn to the cloud to reduce costs, streamline staff, and increase efficiencies, they remain wary abo ...</description>
<pubDate>Thu, 27 Jan 2011 16:20:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/27/moving-to-the-cloud-take-your-application-security-with-you/270.aspx</guid>
</item>
<item>
<title>Moving to a “Show Me” State – Gaining Control and Visibility in Cloud Services</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/25/moving-to-a-show-me-state--gaining-control-and-visibility-in-cloud-services/268.aspx</link>
<description>&lt;h5&gt;By Eric Baize&lt;/h5&gt;
&lt;p&gt;&lt;a href=&quot;http://www.emc.com/collateral/analyst-reports/emc-seeding-the-cloud-forbes-report.pdf&quot;&gt;In Survey &lt;/a&gt;after &lt;a href=&quot;http://securecloudreview.com/2010/09/cloud-adoption-still-struggles-with-security-issues-in-cso-survey/&quot;&gt;survey&lt;/a&gt;, security and more specifically  ...</description>
<pubDate>Tue, 25 Jan 2011 16:29:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/25/moving-to-a-show-me-state--gaining-control-and-visibility-in-cloud-services/268.aspx</guid>
</item>
<item>
<title>Neuroprivilogy: The New Frontier of Cyber Crime </title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/21/neuroprivilogy-the-new-frontier-of-cyber-crime-/267.aspx</link>
<description>&lt;h5&gt;By Shlomi Dinoor&lt;/h5&gt;
&lt;p&gt;Is your Neuroprivilogy vulnerable? The answer is most probably yes, you simply have no clue what Neuroprivilogy is (yet)&amp;hellip;&lt;/p&gt;
&lt;p&gt;The first step of this discussion is defining a fancy term to help educate and describe this new phenomenon.  As the name suggests, N ...</description>
<pubDate>Fri, 21 Jan 2011 14:12:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/21/neuroprivilogy-the-new-frontier-of-cyber-crime-/267.aspx</guid>
</item>
<item>
<title>Will the Cloud Cause the Reemergence of Security Silos?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/19/will-the-cloud-cause-the-reemergence-of-security-silos/266.aspx</link>
<description>&lt;h5&gt;By Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;Generally speaking, in the world silos relate to things that are beneficial, such as silos for grain or corn. In the world of IT security, however, silos are very bad. In many forensic investigations, application silos turn up as a key culprit that enabled data leaka ...</description>
<pubDate>Wed, 19 Jan 2011 18:07:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/19/will-the-cloud-cause-the-reemergence-of-security-silos/266.aspx</guid>
</item>
<item>
<title>UNODC: Open Ended Expert Group on Cybercrime
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/16/unodc-open-ended-expert-group-on-cybercrime/265.aspx</link>
<description>&lt;p&gt;From tomorrow on, UNDOC invited for an &lt;a target=&quot;_blank&quot; href=&quot;http://www.unodc.org/unodc/en/treaties/expert-group-on-cybercrime.html&quot; onclick=&quot;javascript:_gaq.push(['_trackEvent','outbound-article','www.unodc.org']);&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Open Ended Expert Group on Cybercrime&lt;/font&gt;&lt;/s ...</description>
<pubDate>Sun, 16 Jan 2011 21:43:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/16/unodc-open-ended-expert-group-on-cybercrime/265.aspx</guid>
</item>
<item>
<title>Certifiable in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/13/certifiable-in-the-cloud/264.aspx</link>
<description>&lt;h5&gt;By Pamela Fusco&lt;/h5&gt;
&lt;div&gt;&lt;span style=&quot;&quot;&gt;Cloud computing remains as much a mystery to some as it is a part of others&amp;rsquo; daily lexicon. I spend a lot of time working with people who have connections to various offices of the US government and I find that regardless of the topic, or the backg ...</description>
<pubDate>Thu, 13 Jan 2011 18:35:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/13/certifiable-in-the-cloud/264.aspx</guid>
</item>
<item>
<title>Cybercrime as a Service – Our Future?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/12/cybercrime-as-a-service--our-future/263.aspx</link>
<description>&lt;p&gt;It is not really surprising that criminals will leverage the economy of Cloud Computing for their illegal purposes. Especially activities that consume a lot of processor power will be moved to the Cloud &amp;ndash; like any other business.&lt;/p&gt;
&lt;p&gt;Some way back, there were discussions on how to lever ...</description>
<pubDate>Wed, 12 Jan 2011 09:05:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/12/cybercrime-as-a-service--our-future/263.aspx</guid>
</item>
<item>
<title>Summarizing WiFi security revelations for the year 2010</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/28/summarizing-wifi-security-revelations-for-the-year-2010/262.aspx</link>
<description>&lt;p&gt;WiFi security remained in focus with noticeable and widely discussed &lt;a href=&quot;http://blog.airtightnetworks.com/wi-fi-insecurity-wrap-up-for-2010/&quot;&gt;incidents and revelations&lt;/a&gt; happening all throughout the year. These events will surely provide strong testimony for advocating the importance of se ...</description>
<pubDate>Tue, 28 Dec 2010 14:39:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/28/summarizing-wifi-security-revelations-for-the-year-2010/262.aspx</guid>
</item>
<item>
<title>Insider attack, staplers, and something cloudy</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/22/insider-attack-staplers-and-something-cloudy/261.aspx</link>
<description>&lt;p&gt;This piece in &lt;a href=&quot;http://www.infosecurity-us.com/view/14815/inadvertent-data-disclosure-by-employees-poses-growing-risk/&quot;&gt;InfoSecurity&amp;nbsp;&lt;/a&gt;reminded me of a recent webinar I did with Jake Kouns of the Open Security Foundation.&amp;nbsp; (An &lt;a href=&quot;http://www.credant.com/news-a-events/event ...</description>
<pubDate>Wed, 22 Dec 2010 21:56:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/22/insider-attack-staplers-and-something-cloudy/261.aspx</guid>
</item>
<item>
<title>Mitigating the use of Local Admin</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/5/mitigating-the-use-of-local-admin/258.aspx</link>
<description>&lt;p&gt;We recently had internal discussions on the use of local admin and how to mitigate it. During this, Richard Diver, a Premier Field Engineer in APAC, wrote a great article how to do it. I wanted to make sure you can all see this as well. So, this is a guest blog.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Genera ...</description>
<pubDate>Sun, 05 Dec 2010 21:22:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/5/mitigating-the-use-of-local-admin/258.aspx</guid>
</item>
<item>
<title>Wikileakage</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/2/wikileakage/257.aspx</link>
<description>&lt;p&gt;In all the furor (or possibly storm-in-a-teacup) over the recent WikiLeaks revelations it's interesting, but probably not that surprising, that so much emphasis has been put on the content and far less, at least publicly, on the event itself; by which I mean the actual leak.&lt;/p&gt;
&lt;p&gt;Based on the  ...</description>
<pubDate>Thu, 02 Dec 2010 14:32:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/2/wikileakage/257.aspx</guid>
</item>
<item>
<title>The Cloud is Also Green</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/22/the-cloud-is-also-green/254.aspx</link>
<description>&lt;p&gt;Yes, not only gray :-)&lt;/p&gt;
&lt;p&gt;Seriously, we commissioned a study to see what the impact of cloud computing is not only to efficiency but the the environment. Can you save CO&lt;sub&gt;2&lt;/sub&gt; by moving to the cloud? I think its something we do not look at often enough. As pictures say more than 1000 w ...</description>
<pubDate>Mon, 22 Nov 2010 07:35:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/22/the-cloud-is-also-green/254.aspx</guid>
</item>
<item>
<title>Password Security Goes Prime Time </title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/19/password-security-goes-prime-time-/253.aspx</link>
<description>&lt;p&gt;Here's an end-of-week musing for you all. Did anyone happen to see last night&amp;rsquo;s episode of &lt;em&gt;The Office&lt;/em&gt;? (Yes, I watch television, and I&amp;rsquo;m not afraid to admit it!)&lt;/p&gt;
&lt;p&gt;If you did, then the intro illustrated one of the most common security faux-pas out there. In the opening  ...</description>
<pubDate>Fri, 19 Nov 2010 21:09:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/19/password-security-goes-prime-time-/253.aspx</guid>
</item>
<item>
<title>Firesheep Add-on:  Exploiting Security Vulnerabilities of Websites over Insecure WiFi Networks</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/16/firesheep-addon--exploiting-security-vulnerabilities-of-websites-over-insecure-wifi-networks/251.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;i&gt;&lt;a href=&quot;http://codebutler.github.com/firesheep/&quot;&gt;Firesheep&lt;/a&gt;&lt;/i&gt; is a recently released Firefox add-on/extension, developed by software freelancer &lt;a href=&quot;http://codebutler.com/&quot;&gt;Eric Butler&lt;/a&gt;. The intention behind the add-on was to expose the gravity of commonly found security vul ...</description>
<pubDate>Tue, 16 Nov 2010 14:41:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/16/firesheep-addon--exploiting-security-vulnerabilities-of-websites-over-insecure-wifi-networks/251.aspx</guid>
</item>
<item>
<title>Fixing Risk Management</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/15/fixing-risk-management/248.aspx</link>
<description>&lt;p&gt;I am not satisfied with the way we (in the industry) are doing risk management. In my early days, before I was actually entering the security space, I was doing project management and as part of it, risk management. The way we did it was fairly simple (as probably most of you do): We had an impac ...</description>
<pubDate>Mon, 15 Nov 2010 07:22:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/15/fixing-risk-management/248.aspx</guid>
</item>
<item>
<title>Cyber attacks, power grids, and Mary Poppins</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/12/cyber-attacks-power-grids-and-mary-poppins/247.aspx</link>
<description>&lt;p&gt;&amp;quot;A spoonful of sugar helps the medicine go down..&amp;quot;&lt;/p&gt;
&lt;p&gt;Or at least, that's what Mary Poppins says.&amp;nbsp; Personally, I have my doubts about her training as a medical professional&amp;nbsp;&amp;ndash; anyone who talks to their umbrella really shouldn't be prescribing drugs to minors if you a ...</description>
<pubDate>Fri, 12 Nov 2010 17:16:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/12/cyber-attacks-power-grids-and-mary-poppins/247.aspx</guid>
</item>
<item>
<title>The Value of Government Clouds</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/12/the-value-of-government-clouds/246.aspx</link>
<description>&lt;p&gt;Microsoft recently released a paper called &lt;a href=&quot;http://microsoft.eu/Cloudeconomics.aspx&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;The Economics of Cloud Computing for the EU Public Sector&lt;/font&gt;&lt;/a&gt;, which is actually valid for every other European country as well, as it is not too narrowly focused on the EU on ...</description>
<pubDate>Fri, 12 Nov 2010 12:01:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/12/the-value-of-government-clouds/246.aspx</guid>
</item>
<item>
<title>Turkey signed Cybercrime Convention</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/11/turkey-signed-cybercrime-convention/245.aspx</link>
<description>&lt;p&gt;We are huge supporter of the Convention on Cybercrime by the &lt;a onclick=&quot;javascript:_gaq.push(['_trackEvent','outbound-article','www.coe.int']);&quot; href=&quot;http://www.coe.int/t/DGHL/cooperation/economiccrime/cybercrime/default_en.asp&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Council of Europe&lt;/font&gt;&lt;/strong&gt;&lt;/a ...</description>
<pubDate>Thu, 11 Nov 2010 16:43:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/11/turkey-signed-cybercrime-convention/245.aspx</guid>
</item>
<item>
<title>Russia to revise Cybercrime Legislation?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/5/russia-to-revise-cybercrime-legislation/243.aspx</link>
<description>&lt;p&gt;You know that I am propagating the adoption of cybercrime legislation, which is aligned across the Globe. Something, which is absolutely necessary if we want to fight Cybercrime. Basically we are asking governments to consider the Cybercrime Convention (also known as Budapest Convention) by the C ...</description>
<pubDate>Fri, 05 Nov 2010 08:19:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/5/russia-to-revise-cybercrime-legislation/243.aspx</guid>
</item>
<item>
<title>Bad Week For USB Security</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/22/bad-week-for-usb-security/234.aspx</link>
<description>&lt;p&gt;It's been a bad week for USB device security.&lt;/p&gt;
&lt;p&gt;A couple of potentially ugly breaches have highlighted, once more, the trouble organizations are having with managing removable media security.&amp;nbsp; Over in the UK, the &lt;a href=&quot;http://www.sellafieldsites.com/&quot;&gt;Sellafield &lt;/a&gt;nuclear reproces ...</description>
<pubDate>Fri, 22 Oct 2010 19:13:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/22/bad-week-for-usb-security/234.aspx</guid>
</item>
<item>
<title>Crimeware-as-a-Service</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/14/crimewareasaservice/233.aspx</link>
<description>&lt;p&gt;There is no doubt that the ingenuity of cyber criminals has always been ahead of the game. In many cases this can leave the less-than-prepared security professional/organisation left playing cat-and-mouse, and open to exploitation, and vulnerabilities. &lt;/p&gt;
&lt;p&gt;The opposing side is the world of h ...</description>
<pubDate>Thu, 14 Oct 2010 19:33:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/14/crimewareasaservice/233.aspx</guid>
</item>
<item>
<title>Stuxnet talks – do we listen?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/12/stuxnet-talks--do-we-listen/232.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32%2fStuxnet&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Stuxnet&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; is a severe threat &amp;ndash; that&amp;rsquo;s something we know for sure. But if we look at it, &amp;nbsp;what do we really know? What can we lear ...</description>
<pubDate>Tue, 12 Oct 2010 15:47:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/12/stuxnet-talks--do-we-listen/232.aspx</guid>
</item>
<item>
<title>PCI and Breach Data</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/11/pci-and-breach-data/231.aspx</link>
<description>&lt;p&gt;Last week the Verizon Risk Team released an &lt;a href=&quot;http://securityblog.verizonbusiness.com/&quot;&gt;interesting report&amp;nbsp;&lt;/a&gt;in which, among other things, they compared breach result information against norms for PCI DSS compliance.&amp;nbsp;I can't imagine anyone is really all that surprised to see th ...</description>
<pubDate>Mon, 11 Oct 2010 22:28:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/11/pci-and-breach-data/231.aspx</guid>
</item>
<item>
<title>Practicing Continuous PCI DSS Compliance</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/7/practicing-continuous-pci-dss-compliance/229.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The importance of ongoing/continuous PCI DSS compliance processes as an effective means to curb security breaches at a merchant&amp;rsquo;s site is being touted by many experts in the PCI field lately. &lt;a href=&quot;http://www.verizonbusiness.com/about/news/pr-25614-en-First+of+its+Kind+V ...</description>
<pubDate>Thu, 07 Oct 2010 13:53:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/7/practicing-continuous-pci-dss-compliance/229.aspx</guid>
</item>
<item>
<title>Cloud Computing main legal concerns</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/6/cloud-computing-main-legal-concerns/227.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;span style=&quot;font-size: 8pt;&quot;&gt;The main legal concerns related to the cloud model are related to data protection and data security; confidentiality of the information and intellectual property; law enforcement access; cloud service providers (CSPs) professional negligence; subcontracting of  ...</description>
<pubDate>Wed, 06 Oct 2010 18:46:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/6/cloud-computing-main-legal-concerns/227.aspx</guid>
</item>
<item>
<title>The ultimate expression of outsourcing</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/6/the-ultimate-expression-of-outsourcing/226.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;span style=&quot;font-size: 8pt;&quot;&gt;Cloud computing can be defined as the ultimate expression of outsourcing. Whereby the customer contracts out to the cloud service providers (CSPs) computing resources (e.g., networks, servers, storage, applications, and services), which are fundamental to run c ...</description>
<pubDate>Wed, 06 Oct 2010 18:44:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/6/the-ultimate-expression-of-outsourcing/226.aspx</guid>
</item>
<item>
<title>Cloud Computing Legal Issues</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/6/cloud-computing-legal-issues/225.aspx</link>
<description>&lt;p&gt;Cloud computing seems an unavoidable fast-paced revolution. Analysts estimate that in 2012, the size of the enterprise cloud-computing business may reach $60 billion to $80 billion &amp;ndash; or about 10% of the global IT-service and enterprise-software market (BCG 2009 &lt;a href=&quot;http://www.bcg.com/d ...</description>
<pubDate>Wed, 06 Oct 2010 18:42:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/6/cloud-computing-legal-issues/225.aspx</guid>
</item>
<item>
<title>The Power of Security Education</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/6/the-power-of-security-education/224.aspx</link>
<description>&lt;p&gt;While doing research for an upcoming feature on insider threats, I had a conversation with Nick Levay, information security and operations manager at the &lt;a href=&quot;http://www.americanprogress.org/&quot;&gt;Center for American Progress&lt;/a&gt; (CAP), a DC-based think tank. Although some of what he shared could ...</description>
<pubDate>Wed, 06 Oct 2010 17:47:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/6/the-power-of-security-education/224.aspx</guid>
</item>
<item>
<title>Path to PCI DSS Compliance: High Incidence of WiFi Vulnerabilities </title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/4/path-to-pci-dss-compliance-high-incidence-of-wifi-vulnerabilities-/223.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The Deadline to comply with PCI DSS requirements, set for Level 1 Merchants by VISA, recently passed on Sept. 30,&amp;nbsp;2010. However,&amp;nbsp;what we do not yet know is&amp;nbsp;how many of these merchants have successfully met the compliance requirements.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div ...</description>
<pubDate>Mon, 04 Oct 2010 13:51:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/4/path-to-pci-dss-compliance-high-incidence-of-wifi-vulnerabilities-/223.aspx</guid>
</item>
<item>
<title>WiFi consumerization raising security concerns</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/29/wifi-consumerization-raising-security-concerns/221.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The growing WiFi capability in the variety of consumer devices is readily evident nowadays. These devices include cameras, camcorders, printers, scanners, smartphones, televisions, music/video players, e-book readers and many more. Having been equipped with WiFi capability, these ...</description>
<pubDate>Wed, 29 Sep 2010 12:37:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/29/wifi-consumerization-raising-security-concerns/221.aspx</guid>
</item>
<item>
<title>Customer Experience: Security Can Improve in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/28/customer-experience-security-can-improve-in-the-cloud/220.aspx</link>
<description>&lt;p&gt;Last week, when I was in South Africa, a partner of us pointed me to a very interesting paper by KPMG called &lt;a target=&quot;_blank&quot; href=&quot;http://www.kpmg.com/AU/en/IssuesAndInsights/ArticlesPublications/Pages/Cloud-computing-Australian-lessons-and-experiences.aspx&quot; onclick=&quot;javascript:_gaq.push(['_tr ...</description>
<pubDate>Tue, 28 Sep 2010 15:03:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/28/customer-experience-security-can-improve-in-the-cloud/220.aspx</guid>
</item>
<item>
<title>Bigger than the Cloud?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/23/bigger-than-the-cloud/218.aspx</link>
<description>&lt;p&gt;Laura Smith over at &lt;a href=&quot;http://:http://searchcio.techtarget.com/news/2240022577/Mobile-phone-security-policies-give-IT-some-control-over-the-influx&quot;&gt;SearchCIO&amp;nbsp;&lt;/a&gt; recently covered the explosive growth of the iPhone and other smartphones in the business sector, and how that growth is re ...</description>
<pubDate>Thu, 23 Sep 2010 22:16:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/23/bigger-than-the-cloud/218.aspx</guid>
</item>
<item>
<title>The Risks of Unofficial Patches</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/17/the-risks-of-unofficial-patches/215.aspx</link>
<description>&lt;p&gt;This is quite a normal scenario: A zero-day pops up on the Internet by a security researcher. Immediately afterwards we see the first exploits appearing and being integrated into the different attack tools. Now, the race has started: The vendor has to develop a security update, the criminals try  ...</description>
<pubDate>Fri, 17 Sep 2010 09:09:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/17/the-risks-of-unofficial-patches/215.aspx</guid>
</item>
<item>
<title>One-sided Explosion</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/9/onesided-explosion/207.aspx</link>
<description>&lt;p&gt;Consumerization&amp;nbsp;&amp;ndash; the use of consumer products within the corporate environment, is one of the more challenging issues for security teams to deal with. While a standard, well-defined, and well-protected infrastrucutre is a nice idea, there is more and more pressure to open up the netwo ...</description>
<pubDate>Thu, 09 Sep 2010 20:43:08 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/9/onesided-explosion/207.aspx</guid>
</item>
<item>
<title>PCI, AV and a life vest</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/25/pci-av-and-a-life-vest/201.aspx</link>
<description>&lt;p&gt;A good friend of mine over at &lt;a href=&quot;http://www.netiq.com&quot;&gt;NetIQ&lt;/a&gt;, Todd Tucker, recently &lt;a href=&quot;http://community.netiq.com/blogs/security_webb/archive/2010/08/23/reliance-on-antivirus-software-the-real-failure-of-pci-dss.aspx&quot;&gt;blogged&lt;/a&gt;&amp;nbsp;about some of the frustrations he sees when lo ...</description>
<pubDate>Wed, 25 Aug 2010 14:38:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/25/pci-av-and-a-life-vest/201.aspx</guid>
</item>
<item>
<title>The Importance of Application Security</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/24/the-importance-of-application-security/200.aspx</link>
<description>&lt;p&gt;I think I told this story thousands of times, and everybody knows it, but I will do it for the 1001&lt;sup&gt;&lt;font size=&quot;2&quot;&gt;st&lt;/font&gt;&lt;/sup&gt; time now. When I joined Microsoft and became what is the Chief Security Advisor for Switzerland today, we had an airlift for Windows Server 2003. The Product Mana ...</description>
<pubDate>Tue, 24 Aug 2010 15:53:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/24/the-importance-of-application-security/200.aspx</guid>
</item>
<item>
<title>Should RIM hold its line on the BlackBerry?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/18/should-rim-hold-its-line-on-the-blackberry/198.aspx</link>
<description>&lt;p&gt;Encryption is the sort of topic that rarely makes it into the mainstream media, but the recent hoopla over BlackBerry security, namely its encryption procedures, has drawn the ire of governments throughout Asia. &lt;/p&gt;
&lt;p&gt;India, the UAE, Saudi Arabia &amp;ndash; all have taken issue with BlackBerry se ...</description>
<pubDate>Wed, 18 Aug 2010 16:17:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/18/should-rim-hold-its-line-on-the-blackberry/198.aspx</guid>
</item>
<item>
<title>Blocking Social Media Sites–a False Sense of Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/14/blocking-social-media-sitesa-false-sense-of-security/196.aspx</link>
<description>&lt;p&gt;I blog often about it: Blocking certain websites today can fire back in different ways. The CIO published an article called &lt;a target=&quot;_blank&quot; href=&quot;http://www.cio.com/article/603054/Workarounds_5_Ways_Employees_Try_to_Access_Restricted_Sites&quot;&gt;Workarounds: 5 Ways Employees Try to Access Restricte ...</description>
<pubDate>Sat, 14 Aug 2010 18:28:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/14/blocking-social-media-sitesa-false-sense-of-security/196.aspx</guid>
</item>
<item>
<title>I-Coverage</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/13/icoverage/195.aspx</link>
<description>&lt;p&gt;I wanted to comment a little on the &lt;a href=&quot;http://www.infosecurity-us.com/view/11728/apple-pushes-security-updates-for-mobile-devices/&quot;&gt;recent stir &lt;/a&gt;concerning the vulnerabilities on the iPhone (iPad, iTouch, I-Robot.&amp;nbsp; No, wait, that's a movie.)&lt;/p&gt;
&lt;p&gt;I think the level of interest in  ...</description>
<pubDate>Fri, 13 Aug 2010 14:31:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/13/icoverage/195.aspx</guid>
</item>
<item>
<title>Adobe CS7 Searches Saturated With Dangerous Results</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/30/adobe-cs7-searches-saturated-with-dangerous-results/192.aspx</link>
<description>&lt;p&gt;Looking to save a few bucks on software will almost always lead users down a dangerous path.&amp;nbsp;Users either end up at &amp;ldquo;OEM Software&amp;rdquo; sites offering unlicensed and illegal software, or to downloading cracks or keygens laced with malware.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
One of the big issues h ...</description>
<pubDate>Fri, 30 Jul 2010 14:02:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/30/adobe-cs7-searches-saturated-with-dangerous-results/192.aspx</guid>
</item>
<item>
<title>Microsoft and Adobe: Collaboration Against Threats</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/28/microsoft-and-adobe-collaboration-against-threats/191.aspx</link>
<description>&lt;p&gt;You know my opinion on collaboration between countries, on public-private-partnerships, as well as on collaboration between companies.&lt;/p&gt;
&lt;p&gt;For&amp;nbsp;quite a while we have been running&amp;nbsp;a program called MAPP &amp;ndash; the &lt;a href=&quot;http://www.microsoft.com/security/msrc/collaboration/mapp.aspx ...</description>
<pubDate>Wed, 28 Jul 2010 17:39:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/28/microsoft-and-adobe-collaboration-against-threats/191.aspx</guid>
</item>
<item>
<title>WPA2 Exposed with 'Hole 196' Vulnerability</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/23/wpa2-exposed-with-hole-196-vulnerability/189.aspx</link>
<description>&lt;p&gt;Until now, the WPA security version known as &amp;lsquo;WPA2 (AES encryption) with 802.1x authentication&amp;rsquo;&amp;nbsp;was considered as one of most secure WiFi deployments by most wireless security experts. This is due to the resilience of this version to brute force dictionary attacks that can possib ...</description>
<pubDate>Fri, 23 Jul 2010 06:06:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/23/wpa2-exposed-with-hole-196-vulnerability/189.aspx</guid>
</item>
<item>
<title>It's all about WHO</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/8/its-all-about-who/186.aspx</link>
<description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;I KEEP six honest serving-men&lt;br /&gt;
&amp;nbsp;(They taught me all I knew);&lt;br /&gt;
Their names are What and Why and When &lt;br /&gt;
&amp;nbsp;And How and Where and Who.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;&lt;blockquote&gt;
&lt;p&gt;&lt;a href=&quot;http://www.kipling.org.uk/poems_serving.htm&quot;&gt;&amp;ndash; Rudya ...</description>
<pubDate>Thu, 08 Jul 2010 21:13:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/8/its-all-about-who/186.aspx</guid>
</item>
<item>
<title>Cloud Computing: Benefits and Risks of Moving Federal IT into the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/6/cloud-computing-benefits-and-risks-of-moving-federal-it-into-the-cloud/184.aspx</link>
<description>&lt;p&gt;July 1st: Scott Charney, Corporate Vice President Trustworthy Computing was testifying at a hearing of the House Committee on Oversight and Government Reform. Basically the hearing was on the benefits and risk of Cloud adoption for the US government. If you are interested in reading his full test ...</description>
<pubDate>Tue, 06 Jul 2010 14:17:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/6/cloud-computing-benefits-and-risks-of-moving-federal-it-into-the-cloud/184.aspx</guid>
</item>
<item>
<title>Secure WiFi Networks: WiFi Alliance and Legal Authorities Coming Forward</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/5/secure-wifi-networks-wifi-alliance-and-legal-authorities-coming-forward/183.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;WiFi, today, has become a &lt;a href=&quot;http://gigaom.com/2009/08/23/look-how-ubiquitous-wi-fi-has-become/&quot;&gt;near ubiquitous technology&lt;/a&gt;, used by most of us, with our WiFi enabled gadgets, while we are at offices, homes, public places or while traveling. However, awareness about WiF ...</description>
<pubDate>Mon, 05 Jul 2010 08:12:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/5/secure-wifi-networks-wifi-alliance-and-legal-authorities-coming-forward/183.aspx</guid>
</item>
<item>
<title>Do Enjoy 'One Click' Free WiFi at Starbucks, but Safeguard Your Privacy </title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/1/do-enjoy-one-click-free-wifi-at-starbucks-but-safeguard-your-privacy-/182.aspx</link>
<description>&lt;p&gt;Six months after McDonalds started offering free WiFi, Starbucks also announced&amp;nbsp;it would provide&amp;nbsp;complimentary&amp;nbsp;WiFi service, starting July 1, 2010. &lt;a href=&quot;http://www.starbucks.com/coffeehouse/wireless-internet&quot;&gt;As mentioned by Starbucks&lt;/a&gt;, the free WiFi will be unlimited and re ...</description>
<pubDate>Thu, 01 Jul 2010 15:43:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/1/do-enjoy-one-click-free-wifi-at-starbucks-but-safeguard-your-privacy-/182.aspx</guid>
</item>
<item>
<title>Russian Spies in the US: Corporate Spies Could Follow their Communication Methods</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/30/russian-spies-in-the-us-corporate-spies-could-follow-their-communication-methods/181.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/world/us_and_canada/10442869.stm&quot;&gt;As reported recently&lt;/a&gt;, Russian spies in US used private WiFi networks as a means for secret communications. These networks were found to be operating in &lt;a href=&quot;http://www.wi-fiplanet.com/tutorials/article.php/1451421/Under ...</description>
<pubDate>Wed, 30 Jun 2010 14:05:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/30/russian-spies-in-the-us-corporate-spies-could-follow-their-communication-methods/181.aspx</guid>
</item>
<item>
<title>Red Button SEO Poisoning and Malware Campaign</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/30/red-button-seo-poisoning-and-malware-campaign/180.aspx</link>
<description>&lt;p&gt;eSoft researchers have been tracking a new campaign by cybercrooks, compromising and creating websites for use in SEO poisoning and malware distribution. Thousands of these sites have been detected&amp;nbsp;that&amp;nbsp;use elaborate techniques to trick search engines and are ready to serve malware in a ...</description>
<pubDate>Wed, 30 Jun 2010 02:56:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/30/red-button-seo-poisoning-and-malware-campaign/180.aspx</guid>
</item>
<item>
<title>WiFi malfunction at iPhone 4 launch reinforced the need of Wireless Intrusion Detection Systems (WIDS)</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/29/wifi-malfunction-at-iphone-4-launch-reinforced-the-need-of-wireless-intrusion-detection-systems-wids/179.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://futuretense.publicradio.org/blog/index.php?id=677444556&quot;&gt;An after look&lt;/a&gt; into the cause of WiFi malfunction experienced by Steve Jobs&amp;nbsp;during the&amp;nbsp;recently conducted iPhone 4 launch at Apple's flagship Worldwide Developers Conference (WWDC) has revealed that around 500 m ...</description>
<pubDate>Tue, 29 Jun 2010 06:04:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/29/wifi-malfunction-at-iphone-4-launch-reinforced-the-need-of-wireless-intrusion-detection-systems-wids/179.aspx</guid>
</item>
<item>
<title>Google’s WiFi Snooping Controversy Is a Wake-up Call to Stop WiFi Malpractices

</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/25/googles-wifi-snooping-controversy-is-a-wakeup-call-to-stop-wifi-malpractices/178.aspx</link>
<description>&lt;p&gt;The ongoing storm over Google's collection of private WiFi data doesn't seems to be ending anytime soon. It all started when German authorities asked Google to audit the WiFi data collected by Google's Street View cars and Google responded to this by re-examining the collected data. The re-examin ...</description>
<pubDate>Fri, 25 Jun 2010 11:33:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/25/googles-wifi-snooping-controversy-is-a-wakeup-call-to-stop-wifi-malpractices/178.aspx</guid>
</item>
<item>
<title>Proposed cybersecurity bill: stop calling it a “Kill Switch”</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/22/proposed-cybersecurity-bill-stop-calling-it-a-kill-switch/176.aspx</link>
<description>&lt;p&gt;Unless I am mistaken &amp;ndash; and not being a lawyer, this is a distinct possibility &amp;ndash; but the &lt;a href=&quot;http://www.infosecurity-us.com/view/10217/senate-introduces-sweeping-cybersecurity-bill/&quot;&gt;cybersecurity bill proposed in the senate earlier this month&lt;/a&gt; does nothing to create a so-calle ...</description>
<pubDate>Tue, 22 Jun 2010 21:23:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/22/proposed-cybersecurity-bill-stop-calling-it-a-kill-switch/176.aspx</guid>
</item>
<item>
<title>Raid against Piracy</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/22/raid-against-piracy/175.aspx</link>
<description>&lt;p&gt;There seem to be policy organizations&amp;nbsp;that are&amp;nbsp;serious about fighting piracy! Hungary, actually with 41% pirated software &amp;ldquo;not even that bad&amp;rdquo;, seems to be really serious. But first, let me just take those 41% up for a second: This means that 41% of the work you do is stolen. ...</description>
<pubDate>Tue, 22 Jun 2010 21:00:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/22/raid-against-piracy/175.aspx</guid>
</item>
<item>
<title>Who's On First?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/18/whos-on-first/174.aspx</link>
<description>&lt;p&gt;It&amp;rsquo;s hard not to love Abbott and Costello.&lt;/p&gt;
&lt;p&gt;The&lt;a href=&quot;http://en.wikipedia.org/wiki/Whos_on_first&quot;&gt;&amp;ldquo;Who&amp;rsquo;s on first&amp;rdquo;&lt;/a&gt; routine has become a staple of Americana even for foreign transplants like me. But if figuring out the identity of who is on second base (no, wai ...</description>
<pubDate>Fri, 18 Jun 2010 17:12:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/18/whos-on-first/174.aspx</guid>
</item>
<item>
<title>The Importance of International Collaboration –Even in Exercises</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/16/the-importance-of-international-collaboration-even-in-exercises/173.aspx</link>
<description>&lt;p&gt;One of the biggest challenges in Critical Infrastructure Protection or Incident Response is collaboration. Collaboration between the public and the private sector as the private sector is most often running the critical infrastructure; collaboration between different governments as well, as incid ...</description>
<pubDate>Wed, 16 Jun 2010 02:52:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/16/the-importance-of-international-collaboration-even-in-exercises/173.aspx</guid>
</item>
<item>
<title>Should the Government be able to enforce security updates?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/12/should-the-government-be-able-to-enforce-security-updates/172.aspx</link>
<description>&lt;p&gt;This is actually an interesting question. A lot of governments enforce rules and regulations on how you have to run your car, how often you have to check it, in which condition you have to keep your tires, etc. The same is true for a lot of other devices we are using.&lt;/p&gt;
&lt;p&gt;Now, it seems that t ...</description>
<pubDate>Sat, 12 Jun 2010 07:58:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/12/should-the-government-be-able-to-enforce-security-updates/172.aspx</guid>
</item>
<item>
<title>Open Source and Hackers</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/8/open-source-and-hackers/170.aspx</link>
<description>&lt;p&gt;The debate is probably as old as the Open Source software development model &amp;ndash; Which one is more secure: Open Source or shared source as we at Microsoft run it? I know that we could now enter a religious debate about that, which I do not want to as I do not really believe in the value of suc ...</description>
<pubDate>Tue, 08 Jun 2010 12:49:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/8/open-source-and-hackers/170.aspx</guid>
</item>
<item>
<title>New Email Phish Targets Twitter Users, Abuses Google Groups</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/8/new-email-phish-targets-twitter-users-abuses-google-groups/169.aspx</link>
<description>&lt;p&gt;A new twitter spam campaign is making rounds, infecting users with rogue anti-virus malware. The spam mail attempts to convince the user that someone was trying to steal their Twitter account information, and to download a &amp;ldquo;secure module&amp;rdquo; to protect their account. &lt;br /&gt;
&lt;br /&gt;
The  ...</description>
<pubDate>Tue, 08 Jun 2010 01:17:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/8/new-email-phish-targets-twitter-users-abuses-google-groups/169.aspx</guid>
</item>
<item>
<title>135 000 Fake YouTube Pages Delivering Malware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/7/135-000-fake-youtube-pages-delivering-malware/168.aspx</link>
<description>&lt;p&gt;The eSoft Threat Prevention Team has uncovered thousands compromised web servers hosting fake YouTube pages.&amp;nbsp;Attempting to play the video on these fake pages prompts the user to install a &amp;lsquo;media codec&amp;rsquo; which then infects the machine with malware. &lt;br /&gt;
&lt;br /&gt;
The fake YouTube  ...</description>
<pubDate>Mon, 07 Jun 2010 20:42:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/7/135-000-fake-youtube-pages-delivering-malware/168.aspx</guid>
</item>
<item>
<title>Security, Cloud and a Little Pixie Dust</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/1/security-cloud-and-a-little-pixie-dust/167.aspx</link>
<description>&lt;p&gt;When Peter Pan is trying to convince Wendy to fly, he tells her all she needs is &amp;ldquo;Faith, trust, and a little Pixie dust.&amp;rdquo;&amp;nbsp; Which, to be fair, appeared to work for the lost boys.&amp;nbsp; In &lt;a href=&quot;http://www.infosecurity-us.com/view/9824/cloud-computing-could-help-improve-security ...</description>
<pubDate>Tue, 01 Jun 2010 14:51:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/1/security-cloud-and-a-little-pixie-dust/167.aspx</guid>
</item>
<item>
<title>Hacking the human body</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/27/hacking-the-human-body/166.aspx</link>
<description>&lt;p&gt;Years ago I was sitting in a healthcare event, when a researcher was talking (very excited) about the idea of having a pacemaker with Bluetooth access to fine-tune the system and read information from the sensors. Even though this might medically be a great idea, I would be fairly reluctant havin ...</description>
<pubDate>Thu, 27 May 2010 06:51:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/27/hacking-the-human-body/166.aspx</guid>
</item>
<item>
<title>Identity in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/25/identity-in-the-cloud/165.aspx</link>
<description>&lt;p&gt;Kim Cameron, one of our key identity architects had an interesting presentation on identity in the cloud and a corresponding interview. Both are worth looking at if you are planning to move into the direction of the cloud. Especially as it is definitely one of the key challenges:&lt;/p&gt;
&lt;p&gt;This is  ...</description>
<pubDate>Tue, 25 May 2010 20:57:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/25/identity-in-the-cloud/165.aspx</guid>
</item>
<item>
<title>Outsourcing Insider Attack?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/20/outsourcing-insider-attack/164.aspx</link>
<description>&lt;p&gt;I know one or two other bloggers have spotted the following news piece too, notably Bruce Schneier, but it&amp;rsquo;s hard to pass up an opportunity to not only comment, but to draw some wider parallels with other market trends in IT. The &lt;a href=&quot;http://news.bbc.co.uk/2/hi/south_asia/8677486.stm&quot;&gt;B ...</description>
<pubDate>Thu, 20 May 2010 17:34:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/20/outsourcing-insider-attack/164.aspx</guid>
</item>
<item>
<title>Customer Stories: Why it is not THAT easy to move to the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud/162.aspx</link>
<description>&lt;p&gt;As you know from my postings on Cloud and security and the paper on the &lt;a href=&quot;http://go.microsoft.com/?linkid=9708479&quot; target=&quot;_blank&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Cloud Security Considerations&lt;/font&gt;&lt;/a&gt; we wrote, I am convinced that there are five areas you should look at when you try to migrate to ...</description>
<pubDate>Wed, 19 May 2010 10:33:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud/162.aspx</guid>
</item>
<item>
<title>Phishing Scams Lure Twitter Users</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/14/phishing-scams-lure-twitter-users/161.aspx</link>
<description>&lt;p&gt;The newest phishing scam on Twitter has snared thousands of users hoping to increase their number of followers.&amp;nbsp; Instead, users are sent off to a phishing page where cybercriminals steal their Twitter logins using them to generate more spam.&lt;br /&gt;
&lt;br /&gt;
Thousands of spam messages are floa ...</description>
<pubDate>Fri, 14 May 2010 20:05:08 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/14/phishing-scams-lure-twitter-users/161.aspx</guid>
</item>
<item>
<title>HITECH, breaches, and a little sunlight</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/13/hitech-breaches-and-a-little-sunlight/160.aspx</link>
<description>&lt;p&gt;A good article in &lt;a href=&quot;http://www.infosecurity-us.com/view/9233/&quot;&gt;InfoSecurity &lt;/a&gt;on May 5th on the &lt;a href=&quot;http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/hitechenforcementifr.html&quot;&gt;HITECH &lt;/a&gt;act got me thinking (as good articles should) about health records, security, ...</description>
<pubDate>Thu, 13 May 2010 23:06:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/13/hitech-breaches-and-a-little-sunlight/160.aspx</guid>
</item>
<item>
<title>Google Groups Latest Hot Spot for Rogue AV and Malware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/12/google-groups-latest-hot-spot-for-rogue-av-and-malware/159.aspx</link>
<description>&lt;p&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;word-spacing: 0px; font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: medium; line-height: normal; font-size-adjust: none; font-stretch: normal; text-transform: none; color: rgb(0, 0, 0); text-indent: 0px ...</description>
<pubDate>Wed, 12 May 2010 19:06:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/12/google-groups-latest-hot-spot-for-rogue-av-and-malware/159.aspx</guid>
</item>
<item>
<title>Looking back at Infosecurity Europe 2010</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/10/looking-back-at-infosecurity-europe-2010/158.aspx</link>
<description>&lt;p&gt;Late April was highlighted by my first trip to &lt;a href=&quot;http://www.infosec.co.uk/&quot;&gt;Infosecurity Europe&lt;/a&gt; in London. While I understand that this event received its fair share of criticism in the press for being past its prime, there were certainly aspects of the conference that made it worthwhi ...</description>
<pubDate>Mon, 10 May 2010 18:29:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/10/looking-back-at-infosecurity-europe-2010/158.aspx</guid>
</item>
<item>
<title>Pharma-Fraud Continues to Dominate Spam</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/22/pharmafraud-continues-to-dominate-spam/156.aspx</link>
<description>&lt;p&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;word-spacing: 0px; font: medium 'Times New Roman'; text-transform: none; color: rgb(0,0,0); text-indent: 0px; white-space: normal; letter-spacing: normal; border-collapse: separate; orphans: 2; widows: 2&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 13px; ...</description>
<pubDate>Thu, 22 Apr 2010 18:05:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/22/pharmafraud-continues-to-dominate-spam/156.aspx</guid>
</item>
<item>
<title>A Detailed Analysis of an Attack – Do We Need an International Incident Sharing Database?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/21/a-detailed-analysis-of-an-attack--do-we-need-an-international-incident-sharing-database/155.aspx</link>
<description>&lt;p&gt;I recently came across a paper called &lt;a target=&quot;_blank&quot; href=&quot;http://www.shadows-in-the-cloud.net/&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Shadows in the Cloud&lt;/font&gt;&lt;/a&gt;, which is actually a follow-up report of &lt;a target=&quot;_blank&quot; href=&quot;http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-E ...</description>
<pubDate>Wed, 21 Apr 2010 13:51:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/21/a-detailed-analysis-of-an-attack--do-we-need-an-international-incident-sharing-database/155.aspx</guid>
</item>
<item>
<title>Tiger Woods (Searches) Not to Be Trusted</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/8/tiger-woods-searches-not-to-be-trusted/153.aspx</link>
<description>&lt;p&gt;Tiger Woods&amp;rsquo; personal life and marital affairs have attracted constant  attention from the press and has certainly damaged his public  reputation.&amp;nbsp; With his return to the Masters, Nike has  released a new commercial in an effort to rebuild Woods&amp;rsquo; image.&amp;nbsp; This  compelling com ...</description>
<pubDate>Thu, 08 Apr 2010 21:32:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/8/tiger-woods-searches-not-to-be-trusted/153.aspx</guid>
</item>
<item>
<title>Affiliate Programs Rising Cause of Fraud and Abuse</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/5/affiliate-programs-rising-cause-of-fraud-and-abuse/151.aspx</link>
<description>&lt;p&gt;What happens when you offer up money to anyone who can drive traffic to your website?&amp;nbsp;Hackers, scammers, spammers and fraudsters come to your aid.&amp;nbsp;That&amp;rsquo;s the case with online movie site &lt;a href=&quot;http://www.zml.com/&quot;&gt;zml.com&lt;/a&gt;, which offers 30% of each sale and 5% of rebills paid ...</description>
<pubDate>Mon, 05 Apr 2010 14:15:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/5/affiliate-programs-rising-cause-of-fraud-and-abuse/151.aspx</guid>
</item>
<item>
<title>Council of Europe – Octopus Conference (Cooperation against Cybercrime) – Key Messages</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/26/council-of-europe--octopus-conference-cooperation-against-cybercrime--key-messages/150.aspx</link>
<description>&lt;p&gt;I blogged on &lt;a target=&quot;_blank&quot; href=&quot;http://www.halbheer.info/security/2010/03/23/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-1&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Day 1&lt;/font&gt;&lt;/a&gt; and &lt;a target=&quot;_blank&quot; href=&quot;http://www.halbheer.info/security/2010/03/24/council-of-europe-octopus- ...</description>
<pubDate>Fri, 26 Mar 2010 20:51:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/26/council-of-europe--octopus-conference-cooperation-against-cybercrime--key-messages/150.aspx</guid>
</item>
<item>
<title>Council of Europe – Octopus Conference (Cooperation against Cybercrime) Day 2</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-2/149.aspx</link>
<description>&lt;p&gt;And the second day starts. I just met with Jeremy Kirk from IDG and it is great to see that the press is actually interested in such a conference as well.&lt;/p&gt;
&lt;p&gt;The day today started with a long session on different initiatives against cybercrime. A lot of good information:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt; ...</description>
<pubDate>Wed, 24 Mar 2010 16:12:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-2/149.aspx</guid>
</item>
<item>
<title>Council of Europe: We need ONE Cybercrime Convention</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe-we-need-one-cybercrime-convention/148.aspx</link>
<description>&lt;p&gt;As you saw from previous posts, I am at the Octopus Conference on Cooperation against Cybercrime at the moment. We had yesterday the Deputy Secretary General of the Council of Europe and one of her key statements was that different bodies (like the Council of Europe, UN etc.) should not compete.  ...</description>
<pubDate>Wed, 24 Mar 2010 08:31:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe-we-need-one-cybercrime-convention/148.aspx</guid>
</item>
<item>
<title>Council of Europe – Octopus Conference (Cooperation against Cybercrime) Day 1</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/23/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-1/147.aspx</link>
<description>&lt;p&gt;A few years ago, the Budapest Convention on Cybercrime was signed within the Council of Europe. Since then it was ratified all across the globe by a lot of countries or at least used as the base for legislation. The Council of Europe is organising a conference on &lt;a target=&quot;_blank&quot; href=&quot;http://w ...</description>
<pubDate>Tue, 23 Mar 2010 15:22:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/23/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-1/147.aspx</guid>
</item>
<item>
<title>Cinderella Story Leads to March Madness Malware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/22/cinderella-story-leads-to-march-madness-malware/146.aspx</link>
<description>&lt;p&gt;The first week of March Madness has brought about many compelling stories, with a good deal of upsets and bracket busters. The most newsworthy of these has been the University of Northern Iowa&amp;rsquo;s ousting of #1 overall seed Kansas. This &amp;lsquo;Cinderella&amp;rsquo; story has deservedly gotten a g ...</description>
<pubDate>Mon, 22 Mar 2010 13:33:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/22/cinderella-story-leads-to-march-madness-malware/146.aspx</guid>
</item>
<item>
<title>Results of Operation b49 (Botnet Takedown)</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/20/results-of-operation-b49-botnet-takedown/145.aspx</link>
<description>&lt;p&gt;On February 24th we announced the work we did on taking down Waledac &amp;ndash; read Tim Cranton&amp;rsquo;s blog post called &lt;a target=&quot;_blank&quot; href=&quot;http://microsoftontheissues.com/cs/blogs/mscorp/archive/2010/02/24/cracking-down-on-botnets.aspx&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Cracking Down on Botnets&lt;/font&gt;&lt;/ ...</description>
<pubDate>Sat, 20 Mar 2010 14:06:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/20/results-of-operation-b49-botnet-takedown/145.aspx</guid>
</item>
<item>
<title>Strong Authentication and Privacy – A Contradiction in Terms?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/17/strong-authentication-and-privacy--a-contradiction-in-terms/144.aspx</link>
<description>&lt;p style=&quot;text-align: left&quot;&gt;You know that I am not a big fan of the requirement for having all Internet users authenticate strongly. There are people in the security arena who think that this is the only way to fight cybercrime &amp;ndash; and in parallel accept that they would kill freedom of speech.&lt;/ ...</description>
<pubDate>Wed, 17 Mar 2010 21:32:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/17/strong-authentication-and-privacy--a-contradiction-in-terms/144.aspx</guid>
</item>
<item>
<title>Insider Threat of Cloud Computing</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/11/insider-threat-of-cloud-computing/142.aspx</link>
<description>&lt;p&gt;Tonight I got this&amp;nbsp;article forwarded to me: &lt;a target=&quot;_blank&quot; href=&quot;http://www.infoworld.com/d/cloud-computing/afraid-outside-cloud-attacks-youre-missing-real-threat-894?source=IFWNLE_nlt_daily_2010-03-10&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Afraid of outside cloud attacks? You're missing the real threat ...</description>
<pubDate>Thu, 11 Mar 2010 09:19:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/11/insider-threat-of-cloud-computing/142.aspx</guid>
</item>
<item>
<title>Data Protection Heat Map</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/9/data-protection-heat-map/141.aspx</link>
<description>&lt;p&gt;I was looking at some research done by Forrester, which could be interesting for you as well. They try to lay out the landscape with regards to data protection for you and it looks fairly compelling. So if you are interested in the situation of the different Privacy laws across the globe and how  ...</description>
<pubDate>Tue, 09 Mar 2010 20:27:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/9/data-protection-heat-map/141.aspx</guid>
</item>
<item>
<title>Why it pays to be secure – Chapter 5 – I need tools!</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/6/why-it-pays-to-be-secure--chapter-5--i-need-tools/140.aspx</link>
<description>&lt;p&gt;Our EMEA Security Program Manager, Henk van Roest, started this series internally and with his consent I am publishing it here in my blog as I think it contains a lot of great information for you to use.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;So far, in the first 4 chapters, we have addressed the usual excuses for not  ...</description>
<pubDate>Sat, 06 Mar 2010 23:25:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/6/why-it-pays-to-be-secure--chapter-5--i-need-tools/140.aspx</guid>
</item>
<item>
<title>Virus Alert! Twitter, Google, Hallmark and Others Subject To Attack</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/5/virus-alert-twitter-google-hallmark-and-others-subject-to-attack/139.aspx</link>
<description>&lt;p&gt;The eSoft Threat Prevention Team is warning customers today of a new email scam circulating very quickly. &amp;nbsp;These fraudulent emails claim to be from Google Staffing, Hallmark, Twitter as well as other social networks and legitimate businesses.&lt;br /&gt;
&lt;br /&gt;
The email persuades the user to op ...</description>
<pubDate>Fri, 05 Mar 2010 22:12:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/5/virus-alert-twitter-google-hallmark-and-others-subject-to-attack/139.aspx</guid>
</item>
<item>
<title>Making the Management of Security Compliance Easier!</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/18/making-the-management-of-security-compliance-easier/138.aspx</link>
<description>&lt;p&gt;As you all know, I have two main pet themes: Risk Management and Compliance Management as I see very often that there is room for improvement when it comes to such processes within our customers. Internally, we often think about how we can make it easier for our customers to manage compliance in  ...</description>
<pubDate>Thu, 18 Feb 2010 19:59:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/18/making-the-management-of-security-compliance-easier/138.aspx</guid>
</item>
<item>
<title>SANS Top 25 Most Dangerous Programming Errors – the same as very often…</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/17/sans-top-25-most-dangerous-programming-errors--the-same-as-very-often/137.aspx</link>
<description>&lt;p&gt;I just worked my way through the &lt;a target=&quot;_blank&quot; href=&quot;http://cwe.mitre.org/top25/&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;list SANS published&lt;/font&gt;&lt;/a&gt;. Looking at the list it is not surprising but scary to see which errors made it to the top of the list:&lt;/p&gt;
&lt;ol&gt;
    &lt;li&gt;Cross-site Scripting&lt;/li&gt;
    &lt;li ...</description>
<pubDate>Wed, 17 Feb 2010 16:42:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/17/sans-top-25-most-dangerous-programming-errors--the-same-as-very-often/137.aspx</guid>
</item>
<item>
<title>Hotmail Users Look for Answers in Dangerous Places</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/17/hotmail-users-look-for-answers-in-dangerous-places/136.aspx</link>
<description>&lt;p&gt;An &lt;a href=&quot;http://windowsteamblog.com/blogs/windowslive/archive/2010/02/16/short-outage-now-resolved.aspx&quot;&gt;outage&lt;/a&gt; of the Windows Live ID service affected a large number of MSN users today, including users of the popular Hotmail email service. Hotmail is one of the largest web-based email out ...</description>
<pubDate>Wed, 17 Feb 2010 13:57:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/17/hotmail-users-look-for-answers-in-dangerous-places/136.aspx</guid>
</item>
<item>
<title>Children – A Threat For Corporate Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/10/children--a-threat-for-corporate-security/131.aspx</link>
<description>&lt;p&gt;I read this article this morning: &lt;a target=&quot;_blank&quot; href=&quot;http://www.computerweekly.com/Articles/2010/02/09/240236/Safer-Internet-Day-How-children-can-undermine-corporate.htm&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Safer Internet Day: How children can undermine corporate security&lt;/font&gt;&lt;/a&gt; and it actually remin ...</description>
<pubDate>Wed, 10 Feb 2010 12:28:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/10/children--a-threat-for-corporate-security/131.aspx</guid>
</item>
<item>
<title>Use Music to Fight Cybercrime: ‘Maga No Need Pay’</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/9/use-music-to-fight-cybercrime-maga-no-need-pay/130.aspx</link>
<description>&lt;p&gt;When I travel through Africa, the high piracy rate is often something we address. Not necessarily from a commercial perspective but much more from a security angle. We know that pirated software is often infected with malware and therefore used for criminal activities. However, the discussion is  ...</description>
<pubDate>Tue, 09 Feb 2010 12:34:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/9/use-music-to-fight-cybercrime-maga-no-need-pay/130.aspx</guid>
</item>
<item>
<title>IRS Tax Avoidance Scam</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/8/irs-tax-avoidance-scam/129.aspx</link>
<description>&lt;p&gt;Today, eSoft is alerting customers to a new targeted email scam. This newest twist to the common IRS email scam seems to be targeted to organizations, notifying the recipient of a tax evasion complaint being filed against the company.&amp;nbsp;Opening the file infects the user's machine with dangerou ...</description>
<pubDate>Mon, 08 Feb 2010 15:11:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/8/irs-tax-avoidance-scam/129.aspx</guid>
</item>
<item>
<title>Targeted Attacks – the “Real” Problem</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/5/targeted-attacks--the-real-problem/128.aspx</link>
<description>&lt;p&gt;When I talk to customers, the different attacks are often something we discuss (obviously). I often mention that Virus and Worm attacks on a broad scale (like Conficker, etc.) are a serious problem, but at least they are ones we see, understand, and can fight (because we see and understand it).&lt;/ ...</description>
<pubDate>Fri, 05 Feb 2010 11:00:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/5/targeted-attacks--the-real-problem/128.aspx</guid>
</item>
<item>
<title>Fake Firefox Update Pages Push Adware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/3/fake-firefox-update-pages-push-adware/126.aspx</link>
<description>&lt;p&gt;Since its&amp;rsquo; release on January 21st, the newest version of the Firefox web browser has received a great deal of attention.&amp;nbsp;In just a short time it has achieved over 30 million downloads. Adware pushers are capitalizing on the success of Firefox, packing ad serving software in with the p ...</description>
<pubDate>Wed, 03 Feb 2010 17:52:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/3/fake-firefox-update-pages-push-adware/126.aspx</guid>
</item>
<item>
<title>SPAM! Well, it's finally caught up with me -  as confirmed by the research</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/2/spam-well-its-finally-caught-up-with-me---as-confirmed-by-the-research/124.aspx</link>
<description>&lt;p&gt;I have lots of email addresses, but there's one that I use as the main catch all one, it&amp;rsquo;s the one I usually give to most people, and it's the one account I like to clean and clear out regularly. Because it is the most publicised one of all my many accounts, it's the only one that I receive ...</description>
<pubDate>Tue, 02 Feb 2010 16:15:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/2/spam-well-its-finally-caught-up-with-me---as-confirmed-by-the-research/124.aspx</guid>
</item>
<item>
<title>I've been hacked - Give me back my money</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/2/ive-been-hacked--give-me-back-my-money/123.aspx</link>
<description>&lt;p&gt;I recently read a story where a business bank customer had $800K stolen from her business account, and although the bank has been able to recover $600K, there is still the outstanding $200K. The customer is claiming that the bank lacked good security, and the bank is claiming that it had good sec ...</description>
<pubDate>Tue, 02 Feb 2010 11:45:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/2/ive-been-hacked--give-me-back-my-money/123.aspx</guid>
</item>
<item>
<title>Cloud Security Paper: Looking for Feedback</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/30/cloud-security-paper-looking-for-feedback/117.aspx</link>
<description>&lt;p&gt;As most of you well know, I was looking for information and opinions on Cloud Security over the last year. I found a lot of papers, but when I talk to our customers I realize that they think about the Cloud but Cloud Security is mainly something for the specialists &amp;ndash; which it is not for me. ...</description>
<pubDate>Sat, 30 Jan 2010 11:58:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/30/cloud-security-paper-looking-for-feedback/117.aspx</guid>
</item>
<item>
<title>Data Protection Day: An Interesting Study</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/29/data-protection-day-an-interesting-study/116.aspx</link>
<description>&lt;p&gt;As you might know, it was time for the &lt;a target=&quot;_blank&quot; href=&quot;http://dpd.eun.org/web/guest&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Data Protection Day&lt;/font&gt;&lt;/a&gt; in Europe again. Unfortunately I did not find the videos from this year&amp;rsquo;s competition, yet but I guess we will find them later on the page and o ...</description>
<pubDate>Fri, 29 Jan 2010 10:24:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/29/data-protection-day-an-interesting-study/116.aspx</guid>
</item>
<item>
<title>Super Bowl associations: football, nachos, big screens and … malware?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/19/super-bowl-associations-football-nachos-big-screens-and--malware/113.aspx</link>
<description>&lt;p&gt;The Super Bowl is the one of the biggest and most watched television events of the year in the United States. People everywhere scour the internet looking for predictions, gambling spreads and news before the event and scores, stories and clips after the event.&amp;nbsp;In anticipation of the increas ...</description>
<pubDate>Tue, 19 Jan 2010 19:29:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/19/super-bowl-associations-football-nachos-big-screens-and--malware/113.aspx</guid>
</item>
<item>
<title>Lack of Egress Filtering Spurs Success of Injected IFrame Attack</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/18/lack-of-egress-filtering-spurs-success-of-injected-iframe-attack/112.aspx</link>
<description>&lt;p&gt;The security community at large and the eSoft Threat Prevention Team have recently noticed an uptick in sites compromised by a new injection attack that results in an injected iframe. This attack can be recognised by its attempts to masquerade the malicious script as GNU, GPL or LGPL. &amp;nbsp;GPL a ...</description>
<pubDate>Mon, 18 Jan 2010 22:13:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/18/lack-of-egress-filtering-spurs-success-of-injected-iframe-attack/112.aspx</guid>
</item>
<item>
<title>MTaS: Malware Testing as a Service</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/5/mtas-malware-testing-as-a-service/111.aspx</link>
<description>&lt;p&gt;Well, in my last post I wrote about the prices for malware. Today I read the next evolution of this: The possibility of having malware tested against anti-malware tools &amp;ndash; not to make sure malware is really recognised, no, the other way round: To make sure it is not recognised.&lt;/p&gt;
&lt;p&gt;I rea ...</description>
<pubDate>Tue, 05 Jan 2010 21:10:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/5/mtas-malware-testing-as-a-service/111.aspx</guid>
</item>
<item>
<title>The Cybercriminal’s Wish List</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/1/the-cybercriminals-wish-list/109.aspx</link>
<description>&lt;p&gt;I know that Christmas is over and I know how my kids actually compile a Wish List: They take most of the ads (which are targeted to them) and glue them onto a piece of paper for mum and dad to make sure that everything can be found under the Christmas tree&amp;hellip; I guess you know the drill.&lt;/p&gt; ...</description>
<pubDate>Fri, 01 Jan 2010 11:52:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/1/the-cybercriminals-wish-list/109.aspx</guid>
</item>
<item>
<title>Live.com Exploited as Pharma-Fraud Cover</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/23/livecom-exploited-as-pharmafraud-cover/108.aspx</link>
<description>&lt;p&gt;The FDA crackdown on online pharmacy sites has driven a lot of attention to illegal and fraudulent online pharmacies and in particular to their methods for tricking people to visit their sites. These practices include prolific spam and search engine poisoning.&lt;/p&gt;
&lt;p&gt;eSoft&amp;rsquo;s Threat Prevent ...</description>
<pubDate>Wed, 23 Dec 2009 17:59:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/23/livecom-exploited-as-pharmafraud-cover/108.aspx</guid>
</item>
<item>
<title>Algeria: Conference on Certification (eID) </title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/17/algeria-conference-on-certification-eid-/103.aspx</link>
<description>&lt;p&gt;When I &lt;a target=&quot;_blank&quot; href=&quot;file:///C:/Users/rhalbh/AppData/Local/Temp/WindowsLiveWriter1286139640/D04DA26D57B0/www.twitter.com/rhalbheer&quot;&gt;tweeted&lt;/a&gt; last week that I am on my way to Algeria, I got quite some reactions and questions that I should report how it was. So, let me try to briefly  ...</description>
<pubDate>Thu, 17 Dec 2009 15:05:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/17/algeria-conference-on-certification-eid-/103.aspx</guid>
</item>
<item>
<title>Boeing 787 searches hijacked by rogue anti-virus</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/16/boeing-787-searches-hijacked-by-rogue-antivirus/99.aspx</link>
<description>&lt;p&gt;Today, the Boeing 787 Dreamliner jet completed its much awaited first flight. As users searched to find videos and news articles related to the story, blackhats quickly moved in for yet another attack against Google search results.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;&quot; style=&quot;width: 200px; height: 195px;&quot; src=&quot;/_c ...</description>
<pubDate>Wed, 16 Dec 2009 17:52:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/16/boeing-787-searches-hijacked-by-rogue-antivirus/99.aspx</guid>
</item>
<item>
<title>Beware of MySpace JPG File Downloader - GTALK Messenger Infection</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/15/beware-of-myspace-jpg-file-downloader--gtalk-messenger-infection/96.aspx</link>
<description>&lt;p&gt;The malware infection attack surface is increasing day by day. Recently, some of the infected machines with different malware classes such as file downloader are using GTALK for downloading JPG based files from the internet.&lt;/p&gt;
&lt;p&gt;Actually this file is not a JPG file but a zipped file that cont ...</description>
<pubDate>Tue, 15 Dec 2009 04:46:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/15/beware-of-myspace-jpg-file-downloader--gtalk-messenger-infection/96.aspx</guid>
</item>
<item>
<title>CIO required - security background essential</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/11/cio-required--security-background-essential/93.aspx</link>
<description>&lt;p&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot;&gt;
&lt;meta name=&quot;ProgId&quot; content=&quot;Word.Document&quot;&gt;
&lt;meta name=&quot;Generator&quot; content=&quot;Microsoft Word 12&quot;&gt;
&lt;meta name=&quot;Originator&quot; content=&quot;Microsoft Word 12&quot;&gt;
&lt;link rel=&quot;File-List&quot; href=&quot;file:///C:%5CUsers%5Cuser3%5CAppData%5CLocal% ...</description>
<pubDate>Fri, 11 Dec 2009 16:33:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/11/cio-required--security-background-essential/93.aspx</guid>
</item>
<item>
<title>Dedicated Spamming - NING House of Hackers Network</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/11/dedicated-spamming--ning-house-of-hackers-network/90.aspx</link>
<description>&lt;p&gt;The internet world has become a playground for spammers. Every day there is a new attack pattern. You will find one or another social networking website facing this problem. The reason for this trend is the centralised working of these websites. The interconnection among identities have helped th ...</description>
<pubDate>Fri, 11 Dec 2009 04:19:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/11/dedicated-spamming--ning-house-of-hackers-network/90.aspx</guid>
</item>
<item>
<title>Get Safe Online: Don’t be a Money Mule</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/4/get-safe-online-dont-be-a-money-mule/70.aspx</link>
<description>&lt;p&gt;You know, there are people who blog late, there are people who blog very late and then there is me&amp;hellip;&lt;/p&gt;
&lt;p&gt;I actually missed that one even though I was triggered: Mid November there was the Get Safe Online Week 2009 in the UK. Usually they do really good stuff and this is the reason I usu ...</description>
<pubDate>Fri, 04 Dec 2009 12:00:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/4/get-safe-online-dont-be-a-money-mule/70.aspx</guid>
</item>
<item>
<title>Practical working Security Policies</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/3/practical-working-security-policies/69.aspx</link>
<description>&lt;p&gt;Effective working policies are a very difficult thing to achieve, whether they are security policies, or any other policies. We've all seen them in our own organisations, employment policies contradict security policies, or ethical policies contradict investment policies, etc. etc.&lt;/p&gt;
&lt;p&gt;The sc ...</description>
<pubDate>Thu, 03 Dec 2009 16:32:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/3/practical-working-security-policies/69.aspx</guid>
</item>
<item>
<title>“Black Screen of Death” Reports</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/1/black-screen-of-death-reports/68.aspx</link>
<description>&lt;p&gt;Oh, wow &amp;ndash; sometimes the power of social media, the blogs and the internet can backfire. I guess in the meantime you have seen the claims by Prevx that approx. 80 million of PCs are affected by the &lt;em&gt;Black Screen of Death&lt;/em&gt; problems supposedly caused by our November Security Updates. Th ...</description>
<pubDate>Tue, 01 Dec 2009 20:18:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/1/black-screen-of-death-reports/68.aspx</guid>
</item>
<item>
<title>Questions to Ask your (Security) Vendor</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/1/questions-to-ask-your-security-vendor/67.aspx</link>
<description>&lt;p&gt;You know that I am a big fan of Security Development Lifecycles as we run it internally to build code which is more resilient against attacks. And I recently blogged on &lt;a target=&quot;_blank&quot; href=&quot;http://www.halbheer.info/security/archive/2009/11/19/security-a-feature-discussion-some-thoughts-on-goo ...</description>
<pubDate>Tue, 01 Dec 2009 10:04:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/1/questions-to-ask-your-security-vendor/67.aspx</guid>
</item>
<item>
<title>Security and Usability</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/26/security-and-usability/66.aspx</link>
<description>&lt;p&gt;It is not a new concept: The secure way is only secure if it is the easiest way. I have seen a lot of solutions which are extremely secure &amp;ndash; in the eyes of the security people.&lt;/p&gt;
&lt;p&gt;However, the users find a lot of ways to circumvent the security measures because they are too complex to  ...</description>
<pubDate>Thu, 26 Nov 2009 21:08:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/26/security-and-usability/66.aspx</guid>
</item>
<item>
<title>Reverse Honey Traps - Beating Online Anti-virus Engine in its Own Game</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/25/reverse-honey-traps--beating-online-antivirus-engine-in-its-own-game/65.aspx</link>
<description>&lt;p&gt;The web is ever changing arena. Online anti-virus engines provide a diversified functioning of analysing a malware executable thereby providing efficient analysis.&lt;/p&gt;
&lt;p&gt;This is an online democracy of anti-virus engines. But every positive entity can be transformed into a playground and players ...</description>
<pubDate>Wed, 25 Nov 2009 11:47:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/25/reverse-honey-traps--beating-online-antivirus-engine-in-its-own-game/65.aspx</guid>
</item>
<item>
<title>Board Level Security Metrics</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/23/board-level-security-metrics/63.aspx</link>
<description>&lt;p&gt;Last week I attended the Infosecurity Council and had the previlege of spending some time with many security leaders, and I always find these meeting very interesting, as Iwill always learn something that I&amp;nbsp;didn't know before. This meeting was no exception, before the meeting started, I was  ...</description>
<pubDate>Mon, 23 Nov 2009 15:11:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/23/board-level-security-metrics/63.aspx</guid>
</item>
<item>
<title>Security – A feature discussion? Some thoughts on Google’s Chrome OS</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/19/security--a-feature-discussion-some-thoughts-on-googles-chrome-os/61.aspx</link>
<description>&lt;p&gt;To be clear upfront: This is not a 'Microsoft versus Google' post. I cannot even judge how far Google pushed security with the Chrome OS. But the following article raised quite some questions how we look at security: &lt;a href=&quot;http://blogs.zdnet.com/security/?p=4969&amp;amp;utm_source=feedburner&amp;amp;u ...</description>
<pubDate>Thu, 19 Nov 2009 21:21:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/19/security--a-feature-discussion-some-thoughts-on-googles-chrome-os/61.aspx</guid>
</item>
<item>
<title>Blackhats Unleash Fake Blog Campaign Spreading Rogue AV</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/18/blackhats-unleash-fake-blog-campaign-spreading-rogue-av/60.aspx</link>
<description>&lt;p&gt;In September, eSoft reported as many as &lt;a href=&quot;http://threatcenter.blogspot.com/2009/09/fake-blogs-serve-rogue-malware.html&quot;&gt;720,000 compromised sites&lt;/a&gt; hosting fake blog pages and being used to distribute rogue anti-virus programmes. Many of these sites are still active and continue to plagu ...</description>
<pubDate>Wed, 18 Nov 2009 16:17:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/18/blackhats-unleash-fake-blog-campaign-spreading-rogue-av/60.aspx</guid>
</item>
<item>
<title>CoolerEmail Hit by Phishing Scam</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/13/cooleremail-hit-by-phishing-scam/57.aspx</link>
<description>&lt;p&gt;CoolerEmail is notifying customers of a new phishing scam used to steal login credentials. The web based email marketing programme carries an impressive client list including Walmart, Toyota, Pepsi and dozens of other big name brands. Any phished credentials can be used to impersonate these compa ...</description>
<pubDate>Fri, 13 Nov 2009 15:36:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/13/cooleremail-hit-by-phishing-scam/57.aspx</guid>
</item>
<item>
<title>Why it pays to be secure – Chapter 4 – I want to learn!</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/13/why-it-pays-to-be-secure--chapter-4--i-want-to-learn/55.aspx</link>
<description>&lt;p&gt;Use these Learning Paths to find a range of Microsoft training references and resources on information security threats and appropriate countermeasures. Learning resources are organised by level (from basic to expert) and provide information on the planning, prevention, detection, and response ph ...</description>
<pubDate>Fri, 13 Nov 2009 14:18:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/13/why-it-pays-to-be-secure--chapter-4--i-want-to-learn/55.aspx</guid>
</item>
<item>
<title>Embedded open type fonts - The risk lurking up</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/13/embedded-open-type-fonts--the-risk-lurking-up/54.aspx</link>
<description>&lt;p&gt;The web is getting a playground for different type of attacks. There is lot of talks going around about Microsoft EOT fonts realm which are being used for launching different type of attacks.&lt;/p&gt;
&lt;p&gt;Recently I gave a talk at the Excalibur Conference, China in which I talked about launching a CSR ...</description>
<pubDate>Fri, 13 Nov 2009 11:31:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/13/embedded-open-type-fonts--the-risk-lurking-up/54.aspx</guid>
</item>
<item>
<title>How does Google use your information? </title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/6/how-does-google-use-your-information-/49.aspx</link>
<description>&lt;p&gt;Following growing concerns on how the web giants Google are using it&amp;rsquo;s users information, they have launched Google Dashboard; a service which allows users with a Google account to view the information that Google has stored on them, It also allows users to delete any information that they  ...</description>
<pubDate>Fri, 06 Nov 2009 12:40:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/6/how-does-google-use-your-information-/49.aspx</guid>
</item>
<item>
<title>International Collaboration on Policies for Cybersecurity and Data Protection</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/5/international-collaboration-on-policies-for-cybersecurity-and-data-protection/48.aspx</link>
<description>&lt;p&gt;For&amp;nbsp;a few years we&amp;nbsp;have been&amp;nbsp;working with the Council of Europe in a partnership to help to drive a Cybersecurity treaty. We realise that a problem a lot of law enforcement agencies have is inconsistent legislation, which makes&amp;nbsp;it unbelievably hard to catch cybercriminals. The ...</description>
<pubDate>Thu, 05 Nov 2009 20:44:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/5/international-collaboration-on-policies-for-cybersecurity-and-data-protection/48.aspx</guid>
</item>
<item>
<title>Power of Knowledge: Security Intelligence Report v7</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/2/power-of-knowledge-security-intelligence-report-v7/47.aspx</link>
<description>&lt;p&gt;It has been a good tradition for quite a while that we make the intelligence we (Microsoft) have available accessible to the broad public. This will help our customers to protect themselves much better. The Security Intelligence Report (SIR) is built on a unparalleled set of sensors out there on  ...</description>
<pubDate>Mon, 02 Nov 2009 16:15:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/2/power-of-knowledge-security-intelligence-report-v7/47.aspx</guid>
</item>
<item>
<title>When is a firewall not enough?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/30/when-is-a-firewall-not-enough/40.aspx</link>
<description>&lt;p&gt;When your employees have laptops, when large quantities of data can be moved around on tiny USB devices, never even touching the network, when malicious outsiders can compromise your servers through the front door, when malware has been specifically designed to be delivered via the web and to avo ...</description>
<pubDate>Fri, 30 Oct 2009 11:29:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/30/when-is-a-firewall-not-enough/40.aspx</guid>
</item>
<item>
<title>Ten Computer Hacks In The Movies</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/29/ten-computer-hacks-in-the-movies/39.aspx</link>
<description>&lt;!--StartFragment--&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;img src=&quot;http://l.yimg.com/g/images/spaceball.gif&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;/b&gt;&lt;!--StartFragment--&gt;Some of the most successful blockbuster films released in the last two decades have been themed on the potential destruction that computer hackers can cause. Her ...</description>
<pubDate>Thu, 29 Oct 2009 12:20:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/29/ten-computer-hacks-in-the-movies/39.aspx</guid>
</item>
<item>
<title>Could Microsoft solve the scareware problem?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/22/could-microsoft-solve-the-scareware-problem/38.aspx</link>
<description>&lt;p&gt;This morning I read the following article: &lt;a href=&quot;http://www.itnews.com.au/News/158689,commentary-microsoft-can-help-kill-fake-antivirus-threat.aspx&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Microsoft can help kill fake antivirus threat&lt;/font&gt;&lt;/a&gt;. And interesting approach. The proposal is that we could white-lis ...</description>
<pubDate>Thu, 22 Oct 2009 07:58:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/22/could-microsoft-solve-the-scareware-problem/38.aspx</guid>
</item>
<item>
<title>Compromised Web Servers Host Koobface Malware Cocktail</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/21/compromised-web-servers-host-koobface-malware-cocktail/37.aspx</link>
<description>&lt;p&gt;The Koobface gang has struck again using compromised web servers to deliver a potent mix of malware. eSoft threat researchers have found hundreds of newly exploited sites hosting malware which includes downloaders, keyloggers and multiple variants of the Koobface worm.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;
Attackers u ...</description>
<pubDate>Wed, 21 Oct 2009 22:59:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/21/compromised-web-servers-host-koobface-malware-cocktail/37.aspx</guid>
</item>
<item>
<title>Why it pays to be secure – Chapter 3 – But how do I?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/18/why-it-pays-to-be-secure--chapter-3--but-how-do-i/36.aspx</link>
<description>&lt;p&gt;Security &amp;mdash; you hear about it every day. Being responsible for information security can be a daunting task, so where do you begin?&lt;/p&gt;
&lt;p&gt;From the design of acceptable use policies to preventing insiders from stealing data, the job can be a challenging one. Join Senior Security Strategist w ...</description>
<pubDate>Sun, 18 Oct 2009 19:32:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/18/why-it-pays-to-be-secure--chapter-3--but-how-do-i/36.aspx</guid>
</item>
<item>
<title>Unresolved Compromised Fox Sports Host Heading Into Third Week</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/17/unresolved-compromised-fox-sports-host-heading-into-third-week/35.aspx</link>
<description>&lt;p&gt;eSoft &lt;a href=&quot;http://threatcenter.blogspot.com/2009/10/foxsportscom-used-to-serve-malware.html&quot;&gt;first detected a compromise&lt;/a&gt; on the Fox Sports website two weeks ago and as of today, at least one Fox Sports host continues to contain automatic links to a multitude of dangerous exploits.&amp;nbsp; E ...</description>
<pubDate>Sat, 17 Oct 2009 01:17:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/17/unresolved-compromised-fox-sports-host-heading-into-third-week/35.aspx</guid>
</item>
<item>
<title>How the US military has weaponised hacking</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/16/how-the-us-military-has-weaponised-hacking/34.aspx</link>
<description>&lt;p&gt;&lt;em&gt;&amp;ldquo;Our technological advantage is a key to America's military dominance.&amp;nbsp; But our defence and military networks are under constant attack.&amp;nbsp; Al Qaeda and other terrorist groups have spoken of their desire to unleash a cyber attack on our country -- attacks that are harder to dete ...</description>
<pubDate>Fri, 16 Oct 2009 09:33:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/16/how-the-us-military-has-weaponised-hacking/34.aspx</guid>
</item>
<item>
<title>How common is the hacking of secure wifi?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/16/how-common-is-the-hacking-of-secure-wifi/33.aspx</link>
<description>&lt;p&gt;
&lt;meta content=&quot;&quot; name=&quot;Title&quot; /&gt;
&lt;meta content=&quot;&quot; name=&quot;Keywords&quot; /&gt;
&lt;meta content=&quot;text/html; charset=utf-8&quot; http-equiv=&quot;Content-Type&quot; /&gt;
&lt;meta content=&quot;Word.Document&quot; name=&quot;ProgId&quot; /&gt;
&lt;meta content=&quot;Microsoft Word 2008&quot; name=&quot;Generator&quot; /&gt;
&lt;meta content=&quot;Microsoft Word 2008&quot; name=&quot;Origin ...</description>
<pubDate>Fri, 16 Oct 2009 09:15:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/16/how-common-is-the-hacking-of-secure-wifi/33.aspx</guid>
</item>
<item>
<title>Software Piracy – A Threat to Security!</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/14/software-piracy--a-threat-to-security/32.aspx</link>
<description>&lt;p&gt;Beginning of this year, I tried to understand, whether we can show a collaboration between Piracy (stolen software) and Malware Infections. I played a little bit with the data I had available and came to the conclusion, that there most probably is: &lt;a href=&quot;http://www.halbheer.info/security/archi ...</description>
<pubDate>Wed, 14 Oct 2009 13:11:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/14/software-piracy--a-threat-to-security/32.aspx</guid>
</item>
<item>
<title>AJAX-JSON - Inside Crux</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/13/ajaxjson--inside-crux/31.aspx</link>
<description>&lt;p&gt;The development is occurring at a rapid pace. The innovation is going on. The web is transitioning from the web 1.0 to web 2.0. The implementation structures of various technologies have changed. The Web 2.0 has revolutionized the web in a stringent manner from all the perspectives. The Asynchron ...</description>
<pubDate>Tue, 13 Oct 2009 08:34:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/13/ajaxjson--inside-crux/31.aspx</guid>
</item>
<item>
<title>Recapping the Fox Sports Website Compromise</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/9/recapping-the-fox-sports-website-compromise/30.aspx</link>
<description>&lt;p&gt;On October 2nd eSoft published a &lt;a href=&quot;http://www.threatcenter.blogspot.com/2009/10/foxsportscom-used-to-serve-malware.html&quot;&gt;blog&lt;/a&gt; warning visitors of the Fox Sports website about compromised pages with the potential to serve malicious software. To date, the threat remains on their website  ...</description>
<pubDate>Fri, 09 Oct 2009 16:18:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/9/recapping-the-fox-sports-website-compromise/30.aspx</guid>
</item>
<item>
<title>Web 2.0 – Truth and Lies in AJAX World</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/8/web-20--truth-and-lies-in-ajax-world/29.aspx</link>
<description>&lt;p&gt;&lt;em&gt;Web 2.0 has metamorphosed the complete scenario of internet.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In the AJAX world, most of the working functionality is derived by efficient technology methods and ingrained software dependency. In order to scratch deep down the bottom the differential aspect of this technology must ...</description>
<pubDate>Thu, 08 Oct 2009 04:41:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/8/web-20--truth-and-lies-in-ajax-world/29.aspx</guid>
</item>
<item>
<title>The Africa Cable – A Chance for Africa! – A Threat for the Internet?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/7/the-africa-cable--a-chance-for-africa--a-threat-for-the-internet/28.aspx</link>
<description>&lt;p&gt;The development in Africa especially with the new broadband services to me is a huge chance for the whole continent.&lt;/p&gt;
&lt;p&gt;I just found a map (Image 1) on the next two years.&lt;/p&gt;
&lt;p&gt;Even though I have not been in Africa over the last few months, I heard that in different cities fiber is brough ...</description>
<pubDate>Wed, 07 Oct 2009 15:15:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/7/the-africa-cable--a-chance-for-africa--a-threat-for-the-internet/28.aspx</guid>
</item>
<item>
<title>Why Linux servers are more secure than Windows</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/why-linux-servers-are-more-secure-than-windows/27.aspx</link>
<description>&lt;!--StartFragment--&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;The Linux/Windows debate is an oldie but a goodie, and there have been many long threads on most computer related forums discussing their relative merits. Linux is free, open-source and community based. Windows is expensive, professionally developed and has ...</description>
<pubDate>Tue, 06 Oct 2009 13:49:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/why-linux-servers-are-more-secure-than-windows/27.aspx</guid>
</item>
<item>
<title>Your password isn't safe - take this simple test to find out how many minutes it would take to crack</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/your-password-isnt-safe--take-this-simple-test-to-find-out-how-many-minutes-it-would-take-to-crack/26.aspx</link>
<description>&lt;p&gt;There's a well-known saying in information security that the weakest part of any computer system is the person using it. One area where this becomes abundantly clear is in the use of passwords. Allowing users to choose their own passwords can be fatal, with most people not having the first clue a ...</description>
<pubDate>Tue, 06 Oct 2009 13:42:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/your-password-isnt-safe--take-this-simple-test-to-find-out-how-many-minutes-it-would-take-to-crack/26.aspx</guid>
</item>
<item>
<title>When hacking is legal</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/when-hacking-is-legal/25.aspx</link>
<description>&lt;p&gt;The Merriam-Webster dictionary gives two different definitions of &amp;ldquo;hacker&amp;rdquo; related to computer security. A hacker is either &amp;ldquo;an expert at programming and solving problems with a computer&amp;rdquo; or &amp;ldquo;a person who illegally gains access to and sometimes tampers with informati ...</description>
<pubDate>Tue, 06 Oct 2009 13:37:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/when-hacking-is-legal/25.aspx</guid>
</item>
<item>
<title>Why retina scanning works better for James Bond than it ever would for us</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/why-retina-scanning-works-better-for-james-bond-than-it-ever-would-for-us/24.aspx</link>
<description>&lt;p&gt;Since the late 80s retinal scanning has been featured in a whole bevy of sci-fi and action films. It's been the security system of choice for some of the silver screen's top spies: James Bond used it in GoldenEye and Ethan Hunt in the Mission Impossible movies. As a result, whilst retinal scannin ...</description>
<pubDate>Tue, 06 Oct 2009 12:18:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/why-retina-scanning-works-better-for-james-bond-than-it-ever-would-for-us/24.aspx</guid>
</item>
<item>
<title>Which famous Twitter accounts have been hacked?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/5/which-famous-twitter-accounts-have-been-hacked/23.aspx</link>
<description>&lt;p&gt;Early in 2009, Twitter suffered two major security lapses. Once when a wave of highly successful phishing campaigns were successful in obtaining a lot of Twitter passwords, and then again when an 18 year old hacker and student of computer games development brute-force'd an administrator account.  ...</description>
<pubDate>Mon, 05 Oct 2009 16:41:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/5/which-famous-twitter-accounts-have-been-hacked/23.aspx</guid>
</item>
<item>
<title>Thoughts on the registered traveler programmes at airports</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/30/thoughts-on-the-registered-traveler-programmes-at-airports/22.aspx</link>
<description>&lt;p&gt;When I entered the US this time, I got a brochure on how I could avoid the line at immigration and just get a fast track by registering with the &lt;a href=&quot;http://www.cbp.gov/xp/cgov/travel/trusted_traveler/global_entry/&quot; target=&quot;_blank&quot;&gt;Global Entry Program&lt;/a&gt;, a programme, which would pre-screen ...</description>
<pubDate>Wed, 30 Sep 2009 17:07:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/30/thoughts-on-the-registered-traveler-programmes-at-airports/22.aspx</guid>
</item>
<item>
<title>Hey, You, Get Off of My Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/27/hey-you-get-off-of-my-cloud/21.aspx</link>
<description>&lt;p&gt;I recently had different discussions with different customers and we were looking into the key questions to ask, when you plan to move to the cloud (yes, I am working on a corresponding blog post). I was then asked whether we have an answer to these questions&amp;nbsp;&amp;ndash; well no. For sure not fo ...</description>
<pubDate>Sun, 27 Sep 2009 00:47:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/27/hey-you-get-off-of-my-cloud/21.aspx</guid>
</item>
<item>
<title>Why it pays to be secure - Chapter 2 - Vulnerabilities</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/23/why-it-pays-to-be-secure--chapter-2--vulnerabilities/20.aspx</link>
<description>&lt;p&gt;The Microsoft Security Intelligence Report (SIR) provides an in-depth perspective on the changing threat landscape including software vulnerability disclosures and exploits, malicious software (malware), and potentially unwanted software.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.microsoft.com/security/portal/ ...</description>
<pubDate>Wed, 23 Sep 2009 23:05:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/23/why-it-pays-to-be-secure--chapter-2--vulnerabilities/20.aspx</guid>
</item>
<item>
<title>Moving to the Cloud: Where it worked and where I was challenged</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/21/moving-to-the-cloud-where-it-worked-and-where-i-was-challenged/19.aspx</link>
<description>&lt;p&gt;I am running a whole environment at home to experience our technology. However, up to now it was all &amp;ldquo;on premise&amp;rdquo;, no Cloud integration. This has to change. Therefore I was more than happy to join our internal&amp;nbsp; Hosted Exchange 14 beta program. We are offering the hosted Exchange  ...</description>
<pubDate>Mon, 21 Sep 2009 09:07:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/21/moving-to-the-cloud-where-it-worked-and-where-i-was-challenged/19.aspx</guid>
</item>
<item>
<title>Microsoft SDL Team Releases New Security Testing Tools</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/16/microsoft-sdl-team-releases-new-security-testing-tools/18.aspx</link>
<description>&lt;p&gt;I often mention that we try to give you all the tools we have as long as it makes sense form a risk perspective. The risk perspective is a simple one: If we give it to you as our customer, we give it as well to the criminals.&lt;/p&gt;
&lt;p&gt;There are two new tools which just made the bar and which are n ...</description>
<pubDate>Wed, 16 Sep 2009 14:11:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/16/microsoft-sdl-team-releases-new-security-testing-tools/18.aspx</guid>
</item>
<item>
<title>H1N1 (Swine) Flu Preparedness - Guide for Critical Infrastructure and Key Resources</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/16/h1n1-swine-flu-preparedness--guide-for-critical-infrastructure-and-key-resources/17.aspx</link>
<description>&lt;p&gt;This morning I stumbled across a guide by the US Health &amp;amp; Human Services with regards to H1N1. Even though it did not catch much news lately I am not sure whether it is really over. Staying prepared it definitely not a bad thing. Even though it is US-centric, you should probably look into it: ...</description>
<pubDate>Wed, 16 Sep 2009 06:33:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/16/h1n1-swine-flu-preparedness--guide-for-critical-infrastructure-and-key-resources/17.aspx</guid>
</item>
<item>
<title>Why it pays to be secure - Chapter 1 - Data Breaches</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/14/why-it-pays-to-be-secure--chapter-1--data-breaches/15.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2009/9/11/why-it-pays-to-be-secure/13.aspx&quot;&gt;In my first post here&lt;/a&gt;, I opened the field for a series on &amp;ldquo;Why it pays to be secure&amp;rdquo;. As I told you there, Henk van Roest, our Security Support Program Manage ...</description>
<pubDate>Mon, 14 Sep 2009 10:43:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/14/why-it-pays-to-be-secure--chapter-1--data-breaches/15.aspx</guid>
</item>
<item>
<title>Why it pays to be secure</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/11/why-it-pays-to-be-secure/13.aspx</link>
<description>&lt;p&gt;You might all know that feeling: You need money to finance security activities and you are asked why this money shall be invested. And then we start to argue that if we do not do it &amp;ndash; bad things happen. These are questions that myself and our support get often. That was the reason why we st ...</description>
<pubDate>Fri, 11 Sep 2009 10:59:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/11/why-it-pays-to-be-secure/13.aspx</guid>
</item>
</channel>
</rss>

