<?xml version="1.0"?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/_common/xslt/rss.xslt"?>
<rss version="2.0">
<channel>
<title>Infosecurity - Blog</title>
<link>http://www.infosecurity-magazine.com/blog/</link>
<description></description>
<copyright>Copyright Elsevier Ltd</copyright>
<generator>Intuitiv Ltd (www.intuitiv.net)</generator>
<lastBuildDate>Fri, 24 May 2013 22:59:56 GMT</lastBuildDate>
<image>
<title>Infosecurity - Blog</title>
<link>http://www.infosecurity-magazine.com/blog/</link>
<url>http://www.infosecurity-magazine.com/_common/img/template/infosec-uk/site-logo.gif</url>
</image>
<item>
<title>Russia Uses 'Single Register' Law To Selectively Block Internet Content</title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/22/russia-uses-single-register-law-to-selectively-block-internet-content/905.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;
&lt;div&gt;&lt;span style=&quot;font-size: 9pt;&quot;&gt;&amp;ldquo;Won't somebody please think of the children?&amp;rdquo; seems to be Russia's refrain when it comes to their&amp;nbsp;&lt;a href=&quot;http://www.wired.com/dangerroom/2012/11/russia-surveillance/&quot;&gt;recent inception of internet censorship laws&lt;/a&gt;.&amp;nbsp;I ...</description>
<pubDate>Wed, 22 May 2013 15:53:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/22/russia-uses-single-register-law-to-selectively-block-internet-content/905.aspx</guid>
</item>
<item>
<title>Building Trust and Security through Transparency of Service</title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/21/building-trust-and-security-through-transparency-of-service/903.aspx</link>
<description>&lt;h5&gt;By David Baker&lt;/h5&gt;
&lt;p&gt;With the growing movement of enterprises to the cloud, it&amp;rsquo;s more important than ever that service providers demonstrate and prove good security practices to their customers, in good times and in bad. During an incident, how a cloud provider communicates to its custo ...</description>
<pubDate>Tue, 21 May 2013 19:36:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/21/building-trust-and-security-through-transparency-of-service/903.aspx</guid>
</item>
<item>
<title>Liability and the “Commercially Reasonable” Standard</title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/20/liability-and-the-commercially-reasonable-standard/901.aspx</link>
<description>&lt;div&gt;When new technology introduces new legal questions, it can take a long time for courts to sort matters out, and cybersecurity is no exception to the rule. Cyberattacks that yielded major breaches of financial companies in 2008 or 2009 have spawned a series of lawsuits that aim to determine liab ...</description>
<pubDate>Mon, 20 May 2013 13:31:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/20/liability-and-the-commercially-reasonable-standard/901.aspx</guid>
</item>
<item>
<title>Plugging &quot;Cloud Identity Leaks&quot;: Why Your Business Should Become an Identity Provider</title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/15/plugging-cloud-identity-leaks-why-your-business-should-become-an-identity-provider/896.aspx</link>
<description>&lt;h5&gt;By Mark O&amp;rsquo;Neill&lt;/h5&gt;
&lt;p&gt;Most people have used the Facebook, Twitter, or Google Apps buttons located on websites to log into third-party services. This approach is useful within consumer IT as it enables the user to access various services via their own Facebook, Twitter or Google Apps pas ...</description>
<pubDate>Wed, 15 May 2013 18:43:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/15/plugging-cloud-identity-leaks-why-your-business-should-become-an-identity-provider/896.aspx</guid>
</item>
<item>
<title>Securing Credit Card Voice Transactions </title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/9/securing-credit-card-voice-transactions-/892.aspx</link>
<description>&lt;p&gt;This afternoon, I met the CEO (and co-founder) of &lt;a href=&quot;http://www.semafone.com/&quot;&gt;Semafone&lt;/a&gt;, &lt;a href=&quot;http://www.semafone.com/about-us/management-team/&quot;&gt;Tim Critchley&lt;/a&gt;. When the invitation to interview him landed in my inbox, I was all set to turn it down. As Critchley himself admits, ca ...</description>
<pubDate>Thu, 09 May 2013 11:20:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/9/securing-credit-card-voice-transactions-/892.aspx</guid>
</item>
<item>
<title>Talking Infosec Awareness and Training with Kaspersky Labs’ David Emm </title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/3/talking-infosec-awareness-and-training-with-kaspersky-labs-david-emm-/889.aspx</link>
<description>&lt;p&gt;Shortly before the chaos of &lt;a href=&quot;http://www.infosec.co.uk&quot;&gt;Infosecurity Europe&lt;/a&gt;, I joined &lt;a href=&quot;http://www.kaspersky.co.uk/about/security_experts&quot;&gt;David Emm&lt;/a&gt;, senior security researcher at &lt;a href=&quot;http://www.kaspersky.co.uk&quot;&gt;Kaspersky Lab&lt;/a&gt;, for lunch in a lovely quiet gastro pub  ...</description>
<pubDate>Fri, 03 May 2013 16:40:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/3/talking-infosec-awareness-and-training-with-kaspersky-labs-david-emm-/889.aspx</guid>
</item>
<item>
<title>Should Information Security Professionals be Licensed to Practice?</title>
<link>http://www.infosecurity-magazine.com/blog/2013/5/2/should-information-security-professionals-be-licensed-to-practice/886.aspx</link>
<description>&lt;p&gt;Last week we published accompanying editorials from our most recent print edition that asked a rather simple question: Should information security professionals be licensed to practice?&lt;/p&gt;
&lt;p&gt;Arguing in favor of such a licensing scheme, &lt;a href=&quot;http://www.infosecurity-magazine.com/view/32041/a ...</description>
<pubDate>Thu, 02 May 2013 21:08:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/5/2/should-information-security-professionals-be-licensed-to-practice/886.aspx</guid>
</item>
<item>
<title>Security Check List: An Ounce of Prevention is Better than a Pound of Cure</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/30/security-check-list-an-ounce-of-prevention-is-better-than-a-pound-of-cure/883.aspx</link>
<description>&lt;h5&gt;By Wolfgang Kandek&lt;/h5&gt;
&lt;p&gt;It is common belief that buying more robust and expensive security products will offer the best protection from computer-based attacks; that ultimately the expenditure pays off by preventing data theft. According to &lt;a href=&quot;http://www.gartner.com/newsroom/id/2156915&quot; ...</description>
<pubDate>Tue, 30 Apr 2013 15:26:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/30/security-check-list-an-ounce-of-prevention-is-better-than-a-pound-of-cure/883.aspx</guid>
</item>
<item>
<title>Identity Management Plays a Key Role in Mobile Device Management (MDM)</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/30/identity-management-plays-a-key-role-in-mobile-device-management-mdm/882.aspx</link>
<description>&lt;h5&gt;By Dan Dagnall&lt;/h5&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;As &lt;a href=&quot;http://www.infosecurity-magazine.com/view/32031/infosecurity-europe-2013-byod-is-the-new-normal&quot;&gt;BYOD&lt;/a&gt; and other mobile device related initiatives take hold, sooner rather than later, identity management will once again be considered as an ...</description>
<pubDate>Tue, 30 Apr 2013 15:21:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/30/identity-management-plays-a-key-role-in-mobile-device-management-mdm/882.aspx</guid>
</item>
<item>
<title>How to Adopt the Public Cloud While Attaining Private Cloud Control and Security</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/26/how-to-adopt-the-public-cloud-while-attaining-private-cloud-control-and-security/880.aspx</link>
<description>&lt;h5&gt;By Gerry Grealish&lt;/h5&gt;
&lt;p&gt;Earlier this year, McKinsey &amp;amp; Company released an article titled &amp;ldquo;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;a href=&quot;http://www.mckinseyquarterly.com/Protecting_information_in_the_cloud_3041&quot;&gt;Protecting information in the cloud&lt;/a&gt;&lt;/span&gt;,&amp;rdquo; discussing the increased us ...</description>
<pubDate>Fri, 26 Apr 2013 16:44:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/26/how-to-adopt-the-public-cloud-while-attaining-private-cloud-control-and-security/880.aspx</guid>
</item>
<item>
<title>Cloud-Based Identity Management: Best Practices for Rapid End-User Adoption
</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/26/cloudbased-identity-management-best-practices-for-rapid-enduser-adoption/879.aspx</link>
<description>&lt;h5&gt;By Glenn Choquette&lt;/h5&gt;
&lt;p&gt;Identity Management (IdM) is not new. Yet, after all this time on the market, organizations still have mixed results for end-user adoption, as many organizations that rolled-out IdM years ago still haven&amp;rsquo;t achieved their goals: end-users keep calling the help de ...</description>
<pubDate>Fri, 26 Apr 2013 16:21:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/26/cloudbased-identity-management-best-practices-for-rapid-enduser-adoption/879.aspx</guid>
</item>
<item>
<title>Will CISPA pass this time?</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/22/will-cispa-pass-this-time/873.aspx</link>
<description>&lt;p&gt;Recently the controversial Cyber Information Sharing and Protection Act (CISPA) was &lt;a href=&quot;http://www.infosecurity-magazine.com/view/31934/cispa-passes-us-house-under-veto-threat&quot;&gt;passed by the US House&lt;/a&gt; of Representatives for the second time. The bill would mean that technology and web comp ...</description>
<pubDate>Mon, 22 Apr 2013 16:22:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/22/will-cispa-pass-this-time/873.aspx</guid>
</item>
<item>
<title>Live on-stand interviews &amp; wine: What we're up to at Infosecurity Europe...</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/19/live-onstand-interviews--wine-what-were-up-to-at-infosecurity-europe/870.aspx</link>
<description>&lt;p&gt;Well, it's our last day in the office before we all go on site for &lt;a href=&quot;http://www.infosec.co.uk &quot;&gt;Infosecurity Europe&lt;/a&gt; next week. There's a lot of excitement (and panic!) in the air...A few bits of news about what myself and the rest of team&lt;em&gt; Infosecurity &lt;/em&gt;will be up to at the even ...</description>
<pubDate>Fri, 19 Apr 2013 11:45:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/19/live-onstand-interviews--wine-what-were-up-to-at-infosecurity-europe/870.aspx</guid>
</item>
<item>
<title>At War with the World</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/18/at-war-with-the-world/869.aspx</link>
<description>&lt;p&gt;In February, security firm Mandiant made headlines when&lt;a href=&quot;http://www.infosecurity-magazine.com/view/30797/security-firm-accuses-chinese-military-of-involvement-in-worldwide-hacking&quot;&gt; they declared the hacking team APT1, &amp;ldquo;likely government-sponsored and one of the most persistent of Ch ...</description>
<pubDate>Thu, 18 Apr 2013 15:45:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/18/at-war-with-the-world/869.aspx</guid>
</item>
<item>
<title>Web Scrubbing in China</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/15/web-scrubbing-in-china/866.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;&quot;&gt;Within days of China being pinpointed as the home of a massive hacking base, the BBC has alleged that China has been regularly blocking their radio and TV broadcasts and their Chinese-language website.&amp;nbsp;A BBC news crew &lt;/span&gt;&lt;a href=&quot;http://www.pressgazette.co.uk/bbc-china-cre ...</description>
<pubDate>Mon, 15 Apr 2013 15:03:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/15/web-scrubbing-in-china/866.aspx</guid>
</item>
<item>
<title>Cloud APIs - the Next Battleground for Denial-of-Service Attacks </title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/13/cloud-apis--the-next-battleground-for-denialofservice-attacks-/865.aspx</link>
<description>&lt;h5&gt;By Mark O&amp;rsquo;Neill&lt;/h5&gt;
&lt;p&gt;In recent months, there have been a number of &lt;a href=&quot;http://www.infosecurity-magazine.com/view/30130/wave-of-hacking-attacks-on-us-banks-continues-with-botnet-addition&quot;&gt;highly publicized cyber attacks on US banks&lt;/a&gt;. These attacks took the form of Distributed De ...</description>
<pubDate>Sat, 13 Apr 2013 15:00:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/13/cloud-apis--the-next-battleground-for-denialofservice-attacks-/865.aspx</guid>
</item>
<item>
<title>All that Glitters is Not Gold</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/12/all-that-glitters-is-not-gold/863.aspx</link>
<description>&lt;p&gt;The old saying &amp;ldquo;all that glitters is not gold&amp;rdquo; can have a particular resonance with us in the Information Security profession, especially at this time of the year. I say this as we are now starting to move into the heart of the information security conference season; the RSA Conferenc ...</description>
<pubDate>Fri, 12 Apr 2013 01:29:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/12/all-that-glitters-is-not-gold/863.aspx</guid>
</item>
<item>
<title>Policing the Virtual Perimeter</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/11/policing-the-virtual-perimeter/862.aspx</link>
<description>&lt;p&gt;A recent spate of targeted denial of service attacks on organisations such as &lt;a href=&quot;http://www.infosecurity-magazine.com/view/31522/spamhaus-suffers-largest-ddos-attack-in-history-entire-internet-affected&quot;&gt;Spamhaus&lt;/a&gt; and &lt;a href=&quot;http://www.infosecurity-magazine.com/view/31633/bitcoin-hacker ...</description>
<pubDate>Thu, 11 Apr 2013 18:01:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/11/policing-the-virtual-perimeter/862.aspx</guid>
</item>
<item>
<title>Kaspersky Lab – Russia’s IT Security Jewel</title>
<link>http://www.infosecurity-magazine.com/blog/2013/4/10/kaspersky-lab--russias-it-security-jewel/860.aspx</link>
<description>&lt;p&gt;Naming a company you founded after yourself can be problematic. OK, no one tries to place the blame for HP&amp;rsquo;s recent woes on Bill Hewlett or Dave Packard (anyway, &lt;a href=&quot;http://www.hpnext.com&quot;&gt;according to HP&amp;rsquo;s current management&lt;/a&gt; a big turnaround in fortune is underway). However, ...</description>
<pubDate>Wed, 10 Apr 2013 14:05:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/4/10/kaspersky-lab--russias-it-security-jewel/860.aspx</guid>
</item>
<item>
<title>A Little too Much Access, Thank You</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/29/a-little-too-much-access-thank-you/849.aspx</link>
<description>&lt;p&gt;So now that it appears the &lt;a href=&quot;http://www.nytimes.com/2013/03/27/technology/internet/online-dispute-becomes-internet-snarling-attack.html?_r=0&quot;&gt;Internet Apocalypse &lt;/a&gt;is over and we can all return to life as we know it, (assuming we &lt;a href=&quot;https://securosis.com/blog/ddos-attack-overblown&quot; ...</description>
<pubDate>Fri, 29 Mar 2013 15:14:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/29/a-little-too-much-access-thank-you/849.aspx</guid>
</item>
<item>
<title>Of Sequestration &amp; Cybersecurity Frustrations…</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/29/of-sequestration--cybersecurity-frustrations/848.aspx</link>
<description>&lt;div&gt;With sequestration cuts underway across the federal government, and the plight of the federal information security workforce being traditionally viewed as non-mission essential, one can only hope that the historically underfunded budgets of the federal CISO will survive the carving knives of th ...</description>
<pubDate>Fri, 29 Mar 2013 14:36:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/29/of-sequestration--cybersecurity-frustrations/848.aspx</guid>
</item>
<item>
<title>Going Up? Safety First, then Send your Data to the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/28/going-up-safety-first-then-send-your-data-to-the-cloud/847.aspx</link>
<description>&lt;h5&gt;By Joe Sturonas&lt;/h5&gt;
&lt;p&gt;As the proliferation of data continues to plague businesses, the pressure is on for companies to migrate away from their physical data centers. Cloud computing is being adopted at a rapid rate because it addresses not only the costs for physical space, but also rising en ...</description>
<pubDate>Thu, 28 Mar 2013 15:02:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/28/going-up-safety-first-then-send-your-data-to-the-cloud/847.aspx</guid>
</item>
<item>
<title> A Chat with Dimension Data: Data Centric Security, Data Breaches, and Why Old is New in Security </title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/27/-a-chat-with-dimension-data-data-centric-security-data-breaches-and-why-old-is-new-in-security-/845.aspx</link>
<description>&lt;div&gt;This week I sat down with &lt;a href=&quot;http://blog.dimensiondata.com/2012/05/enterprise-security-the-usual-suspects-still-dominate/&quot;&gt;Anna Watson&lt;/a&gt;, general manager of security solutions, Europe, at &lt;a href=&quot;http://www.dimensiondata.com/rgn/uk/Pages/Home.aspx&quot;&gt;Dimension Data&lt;/a&gt;, to have a chat ab ...</description>
<pubDate>Wed, 27 Mar 2013 09:23:48 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/27/-a-chat-with-dimension-data-data-centric-security-data-breaches-and-why-old-is-new-in-security-/845.aspx</guid>
</item>
<item>
<title>How to Harden Your APIs</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/26/how-to-harden-your-apis/844.aspx</link>
<description>&lt;h5&gt;By Andy Thurai&lt;/h5&gt;
&lt;p&gt;The market for APIs has experienced explosive growth in recent years, yet the major issues that providers still face are protection and hardening of the APIs that they expose to users. In particular, when you are exposing APIs from a cloud-based platform, this becomes ver ...</description>
<pubDate>Tue, 26 Mar 2013 18:04:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/26/how-to-harden-your-apis/844.aspx</guid>
</item>
<item>
<title>If Your iPhone Could Talk...</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/25/if-your-iphone-could-talk/843.aspx</link>
<description>&lt;p&gt;Andy Greenberg at &lt;a href=&quot;http://www.forbes.com/sites/andygreenberg/2013/02/26/heres-what-law-enforcement-can-recover-from-a-seized-iphone/&quot;&gt;&lt;em&gt;Forbes&lt;/em&gt;&lt;/a&gt; has shown us the information that law enforcement can recover via a seized iPhone. The article is essentially in response to one &lt;a hre ...</description>
<pubDate>Mon, 25 Mar 2013 18:56:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/25/if-your-iphone-could-talk/843.aspx</guid>
</item>
<item>
<title>Three Critical Features that Define an Enterprise-Grade Cloud Service</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/22/three-critical-features-that-define-an-enterprisegrade-cloud-service/841.aspx</link>
<description>&lt;h5&gt;By David Baker&lt;/h5&gt;
&lt;p&gt;The line between enterprise and consumer is fading as employees work from all manner of devices to access the on-premises, cloud and even consumer applications needed to get work done. But it&amp;rsquo;s important to not confuse enterprise and consumer services from a securit ...</description>
<pubDate>Fri, 22 Mar 2013 19:32:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/22/three-critical-features-that-define-an-enterprisegrade-cloud-service/841.aspx</guid>
</item>
<item>
<title>Why Should I Get My Certificate of Cloud Security Knowledge (CCSK)? Or Train to be a CCSK Trainer?</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/20/why-should-i-get-my-certificate-of-cloud-security-knowledge-ccsk-or-train-to-be-a-ccsk-trainer/837.aspx</link>
<description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;The CSA, in providing a set of goals through the CCSK, is challenging security practitioners to become the cloud thought-leaders we need today and tomorrow to ensure safe and secure cloud environments. In developing the CCSK, CSA is 'setting the bar' for security professi ...</description>
<pubDate>Wed, 20 Mar 2013 20:14:02 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/20/why-should-i-get-my-certificate-of-cloud-security-knowledge-ccsk-or-train-to-be-a-ccsk-trainer/837.aspx</guid>
</item>
<item>
<title>The Shrinking Security Model: Micro-perimeters</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/20/the-shrinking-security-model-microperimeters/836.aspx</link>
<description>&lt;h5&gt;By Ed King&lt;/h5&gt;
&lt;p&gt;As cloud and mobile computing make enterprise IT ever more extended, the traditional security model of keeping the bad guys out and allowing only the good guys in no longer works well.  While the reach of the enterprise has expanded, the security perimeter may actually have t ...</description>
<pubDate>Wed, 20 Mar 2013 19:14:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/20/the-shrinking-security-model-microperimeters/836.aspx</guid>
</item>
<item>
<title>
My morning at CrestCon/IISP Conference 
</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/20/my-morning-at-crestconiisp-conference-/835.aspx</link>
<description>&lt;p&gt;So far, I&amp;rsquo;ve listened to three talks - sadly I wasn&amp;rsquo;t allowed to attend the keynote given by CESG &amp;ndash; and will be returning after lunch (I&amp;rsquo;m currently camped out in Caf&amp;eacute; Nero regaining some charge on my laptop and iPhone) to hear some more.&lt;/p&gt;
&lt;h4&gt;Information securi ...</description>
<pubDate>Wed, 20 Mar 2013 14:29:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/20/my-morning-at-crestconiisp-conference-/835.aspx</guid>
</item>
<item>
<title>Net Neutrality: Is it Necessary?</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/15/net-neutrality-is-it-necessary/833.aspx</link>
<description>&lt;p&gt;At the moment, the US Federal Communications Commission (FCC) is fighting an on-going legal battle with the telecommunications company Verizon over their &lt;a href=&quot;http://gigaom.com/2012/07/03/inside-verizons-attack-on-network-neutrality/&quot;&gt;net neutrality rules&lt;/a&gt;, which were initially proposed in ...</description>
<pubDate>Fri, 15 Mar 2013 16:22:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/15/net-neutrality-is-it-necessary/833.aspx</guid>
</item>
<item>
<title>I Want My Nua Mek 2...Yes, Hackers Watch TV Too
</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/14/i-want-my-nua-mek-2yes-hackers-watch-tv-too/831.aspx</link>
<description>&lt;p&gt;We&amp;rsquo;ve all been disappointed when a favorite show is canceled, be it &lt;em&gt;Arrested Development&lt;/em&gt;, &lt;em&gt;Freaks and Geeks&lt;/em&gt; or, more recently, &lt;em&gt;666 Park Avenue&lt;/em&gt; (err&amp;hellip;or is that just me?). But Thailand&amp;rsquo;s National Broadcasting Commission (NBC) got more than it bargained f ...</description>
<pubDate>Thu, 14 Mar 2013 19:11:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/14/i-want-my-nua-mek-2yes-hackers-watch-tv-too/831.aspx</guid>
</item>
<item>
<title>The Age of Bring-Your-Own-Identity (BYOID)</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/11/the-age-of-bringyourownidentity-byoid/825.aspx</link>
<description>&lt;p&gt;Sellers of computer security products and services sometimes fret that their messaging is too scary as they go on about risk, data loss and regulatory fines. To get around this, every so often they like to remind potential buyers that their wares are also business enablers. The case is easier to  ...</description>
<pubDate>Mon, 11 Mar 2013 11:19:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/11/the-age-of-bringyourownidentity-byoid/825.aspx</guid>
</item>
<item>
<title>It’s McAfee. James McAfee.</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/5/its-mcafee-james-mcafee/823.aspx</link>
<description>&lt;p&gt;A game of high-stakes, technical espionage that targets the highest levels of government? A bevy of presumably beautiful female double agents? A nefarious foe bent on the destruction of the US, operating in the shadows under a cover of legitimacy? These are not the trappings of a new James Bond i ...</description>
<pubDate>Tue, 05 Mar 2013 20:34:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/5/its-mcafee-james-mcafee/823.aspx</guid>
</item>
<item>
<title>APTs and Oscar Wilde</title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/1/apts-and-oscar-wilde/820.aspx</link>
<description>&lt;p&gt;&amp;ldquo;The only thing worse than being the victim of an APT is *not* being the victim of an APT.&amp;rdquo;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Or, at least, that&amp;rsquo;s probably how Oscar Wilde would have seen it, had he been following the news recently.&lt;br /&gt;
(He rather famously said something similar when told that a ...</description>
<pubDate>Fri, 01 Mar 2013 19:54:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/1/apts-and-oscar-wilde/820.aspx</guid>
</item>
<item>
<title>The Trouble Heading for your Business in 2013 </title>
<link>http://www.infosecurity-magazine.com/blog/2013/3/1/the-trouble-heading-for-your-business-in-2013-/818.aspx</link>
<description>&lt;div style=&quot;margin-bottom:0cm;margin-bottom:.0001pt&quot;&gt;Facebook, Twitter, Apple and Microsoft: all icons of the information technology industry and all the focus of targeted attacks in Feb 2013. The bad news for us all is, that even those that should be some of the most tech-savvy companies in the wor ...</description>
<pubDate>Fri, 01 Mar 2013 13:58:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/3/1/the-trouble-heading-for-your-business-in-2013-/818.aspx</guid>
</item>
<item>
<title>Cruising the Misinformation Superhighway</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/28/cruising-the-misinformation-superhighway/817.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Long before there was a World Wide Web, when the internet was largely a playground for academics and the military, and most people still thought spam was a canned meat, there were already hoaxes and scams (pyramid schemes, Ponzi schemes, lures into premium rate phone services, fa ...</description>
<pubDate>Thu, 28 Feb 2013 13:23:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/28/cruising-the-misinformation-superhighway/817.aspx</guid>
</item>
<item>
<title>Censorship’s Losing Battle in China</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/27/censorships-losing-battle-in-china/816.aspx</link>
<description>&lt;p&gt;Recently, &lt;a href=&quot;http://www.telegraph.co.uk/technology/twitter/9787989/Twitter-of-the-East-enjoys-the-last-word.html&quot;&gt;Brad Pitt was the latest celebrity to join up to China&amp;rsquo;s foremost micro-blogging platform, Sina Weibo&lt;/a&gt;, joining the likes of Selena Gomez, Paris Hilton, Emma Watson, an ...</description>
<pubDate>Wed, 27 Feb 2013 15:49:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/27/censorships-losing-battle-in-china/816.aspx</guid>
</item>
<item>
<title>
RSA 2013: Interview with security evangelist Stephen Cobb </title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/27/rsa-2013-interview-with-security-evangelist-stephen-cobb-/814.aspx</link>
<description>&lt;p&gt;
&lt;p&gt;I&amp;rsquo;ve just spent a fascinating 45 minutes picking the brain of ESET security evangelist, Stephen Cobb.&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;Below are the key statements made by &lt;a href=&quot;http://www.eset.co.uk/&quot;&gt;ESET&lt;/a&gt;'s &lt;a href=&quot;http://www.welivesecurity.com/author/scobb/page/2/?wpmp_switcher=desktop&quot;&gt; ...</description>
<pubDate>Wed, 27 Feb 2013 02:04:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/27/rsa-2013-interview-with-security-evangelist-stephen-cobb-/814.aspx</guid>
</item>
<item>
<title>Language is a Virus (Editorial from Q1 issue)</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/25/language-is-a-virus-editorial-from-q1-issue/810.aspx</link>
<description>&lt;p&gt;This year we are scaling back on the quantity of issues produced (the magazine will now&amp;nbsp;be published quarterly) in order to allow the editorial team to increase the output of online content.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Not only will we be producing more daily news stories, but we will be publishing featur ...</description>
<pubDate>Mon, 25 Feb 2013 02:25:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/25/language-is-a-virus-editorial-from-q1-issue/810.aspx</guid>
</item>
<item>
<title>Finally, a Step Forward in Cybersecurity</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/21/finally-a-step-forward-in-cybersecurity/808.aspx</link>
<description>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:DocumentProperties&gt;
  &lt;o:Revision&gt;0&lt;/o:Revision&gt;
  &lt;o:TotalTime&gt;0&lt;/o:TotalTime&gt;
  &lt;o:Pages&gt;1&lt;/o:Pages&gt;
  &lt;o:Words&gt;502&lt;/o:Words&gt;
  &lt;o:Characters&gt;2784&lt;/o:Characters&gt;
  &lt;o:Company&gt;Extension Group&lt;/o:Company&gt;
  &lt;o:Lines&gt;48&lt;/o:Lines&gt;
  &lt;o:Paragraphs&gt;7&lt;/o:Paragraphs&gt; ...</description>
<pubDate>Thu, 21 Feb 2013 22:30:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/21/finally-a-step-forward-in-cybersecurity/808.aspx</guid>
</item>
<item>
<title>When Good Is Not Good Enough: NIST Raises the Bar for Cloud Data Protection Vendors</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/21/when-good-is-not-good-enough-nist-raises-the-bar-for-cloud-data-protection-vendors/807.aspx</link>
<description>&lt;h5&gt;By David Stott&lt;/h5&gt;
&lt;p&gt;Earlier this year, the US&amp;nbsp;National Institute of Standards and Technology (NIST) released a publication titled &lt;a href=&quot;http://www.nist.gov/customcf/get_pdf.cfm?pub_id=911075&quot;&gt;Cloud Computing Synopsis &amp;amp; Recommendations (Special Publication 800-146)&lt;/a&gt; describing  ...</description>
<pubDate>Thu, 21 Feb 2013 21:01:02 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/21/when-good-is-not-good-enough-nist-raises-the-bar-for-cloud-data-protection-vendors/807.aspx</guid>
</item>
<item>
<title>The Low-down on the Booth Babe Crack-down</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/20/the-lowdown-on-the-booth-babe-crackdown/802.aspx</link>
<description>&lt;p&gt;This week, Reed Exhibitions, organisers of the&lt;a href=&quot;http://www.infosec.co.uk/&quot;&gt; Infosecurity Europe&lt;/a&gt; event, announced changes to their Ts and Cs that outlaw the use of &amp;lsquo;booth babes&amp;rsquo; (more formally known as scantily clad women) to attract foot traffic to their booth. (The use of  ...</description>
<pubDate>Wed, 20 Feb 2013 12:30:48 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/20/the-lowdown-on-the-booth-babe-crackdown/802.aspx</guid>
</item>
<item>
<title>ISSA European Conference: A talk from Right Honorurable David Davis, MP</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/14/issa-european-conference-a-talk-from-right-honorurable-david-davis-mp/800.aspx</link>
<description>&lt;p&gt;I attended the &lt;a href=&quot;http://www.issa.org/events/event_details.asp?id=278091&quot;&gt;ISSA European Conference&lt;/a&gt; last week, and was pleasantly surprised by a fantastic speaker line-up and some excellent content.&lt;/p&gt;
&lt;p&gt;The agenda was kicked off by &lt;a href=&quot;http://en.wikipedia.org/wiki/David_Davis_(B ...</description>
<pubDate>Thu, 14 Feb 2013 16:51:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/14/issa-european-conference-a-talk-from-right-honorurable-david-davis-mp/800.aspx</guid>
</item>
<item>
<title>Internet Pioneer Speaks Out on Privacy, Governance, and Internet Tax</title>
<link>http://www.infosecurity-magazine.com/blog/2013/2/11/internet-pioneer-speaks-out-on-privacy-governance-and-internet-tax/795.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;&quot;&gt;In an interesting addition to the everlasting debate about internet censorship &amp;ndash; specifically on the idea of an 'Internet Tax' &amp;ndash; one of the creators of the internet has spoken out about his views on how strange the notion is, a ...</description>
<pubDate>Mon, 11 Feb 2013 17:48:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/2/11/internet-pioneer-speaks-out-on-privacy-governance-and-internet-tax/795.aspx</guid>
</item>
<item>
<title>Mac AV Testing: How Useful Is It?</title>
<link>http://www.infosecurity-magazine.com/blog/2013/1/29/mac-av-testing-how-useful-is-it/781.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;&lt;span style=&quot;Times New Roman&amp;quot;;Times New Roman&amp;quot;&quot;&gt;I &lt;a href=&quot;http://antimalwaretesting.wordpress.com/2013/01/10/mac-testing-static-versus-dynamic/&quot;&gt;commented recently&lt;/a&gt; (on an independent AV testing-related blog) on a &lt;a href=&quot;http://www.intego.com/mac-security-blog/tha ...</description>
<pubDate>Tue, 29 Jan 2013 13:33:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/1/29/mac-av-testing-how-useful-is-it/781.aspx</guid>
</item>
<item>
<title>Brace Yourselves, Europe: The Lawyers are Coming</title>
<link>http://www.infosecurity-magazine.com/blog/2013/1/23/brace-yourselves-europe-the-lawyers-are-coming/775.aspx</link>
<description>&lt;p&gt;Peter Fleischer, an American in Paris who is also Google&amp;rsquo;s Global Privacy Counsel, knows a bit about privacy and law. &lt;a href=&quot;http://peterfleischer.blogspot.co.uk/2012/10/privacy-litigation-get-ready-for.html&quot;&gt;Writing in his own blog&lt;/a&gt;, he has warned Europe to expect a litigious explosio ...</description>
<pubDate>Wed, 23 Jan 2013 19:51:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/1/23/brace-yourselves-europe-the-lawyers-are-coming/775.aspx</guid>
</item>
<item>
<title>Censorship in China: What is Really at Stake?</title>
<link>http://www.infosecurity-magazine.com/blog/2013/1/21/censorship-in-china-what-is-really-at-stake/764.aspx</link>
<description>&lt;p&gt;Recently, &lt;a href=&quot;http://www.guardian.co.uk/technology/2012/dec/14/china-tightens-great-firewall-internet-control&quot;&gt;China has tightened its control over VPNs&lt;/a&gt;&amp;nbsp;(virtual private networks), the systems that allowed many of its people to access banned sites. Basically, a VPN is a private netw ...</description>
<pubDate>Mon, 21 Jan 2013 16:30:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/1/21/censorship-in-china-what-is-really-at-stake/764.aspx</guid>
</item>
<item>
<title>RSA: The Light at the End of the Tunnel </title>
<link>http://www.infosecurity-magazine.com/blog/2013/1/11/rsa-the-light-at-the-end-of-the-tunnel-/758.aspx</link>
<description>&lt;p&gt;I&amp;rsquo;m a great sufferer of the January blues and associate them with many negative connotations. However, the one bit of sunshine at the end of the tunnel every January is the imminent RSA Conference in San Francisco.&lt;/p&gt;
&lt;p&gt;It doesn&amp;rsquo;t take a genius to work out why the promise of a week ...</description>
<pubDate>Fri, 11 Jan 2013 17:58:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/1/11/rsa-the-light-at-the-end-of-the-tunnel-/758.aspx</guid>
</item>
<item>
<title>Pirates in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2013/1/10/pirates-in-the-cloud/756.aspx</link>
<description>&lt;p&gt;The &lt;a href=&quot;http://www.infosecurity-magazine.com/view/23371/anonymous-launches-attack-in-response-to-fbis-megaupload-takedown&quot;&gt;FBI takedown of Megaupload&lt;/a&gt; one year ago was a PR fiasco, and quite possibly, a practical disaster for law enforcement and rights holders. The image of armed police s ...</description>
<pubDate>Thu, 10 Jan 2013 17:55:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/1/10/pirates-in-the-cloud/756.aspx</guid>
</item>
<item>
<title>Jailbreaking: Not Just a Sport for iPhone Users</title>
<link>http://www.infosecurity-magazine.com/blog/2013/1/9/jailbreaking-not-just-a-sport-for-iphone-users/754.aspx</link>
<description>&lt;p&gt;I just came across an interesting blog by Lysa Myers (for Intego) on jailbreaking: &lt;a data-mce-href=&quot;http://www.intego.com/mac-security-blog/the-latest-in-jailbreaking-will-malware-follow/&quot; rel=&quot;bookmark&quot; href=&quot;http://www.intego.com/mac-security-blog/the-latest-in-jailbreaking-will-malware-follow ...</description>
<pubDate>Wed, 09 Jan 2013 12:00:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2013/1/9/jailbreaking-not-just-a-sport-for-iphone-users/754.aspx</guid>
</item>
<item>
<title>The Western Machinery of Surveillance Weapons</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/21/the-western-machinery-of-surveillance-weapons/747.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;On December 11 of this year, Reporters Without Borders and Human Rights Watch jointly released a press release calling for the EU to enact new controls on internet censorship and surveillance technologies that are regularly being &lt;a href=&quot;http://www.hrw.org/news/2012/12/11/eu-ena ...</description>
<pubDate>Fri, 21 Dec 2012 16:09:32 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/21/the-western-machinery-of-surveillance-weapons/747.aspx</guid>
</item>
<item>
<title>1.5 Factor Authentication: Myth or Fact?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/20/15-factor-authentication-myth-or-fact/746.aspx</link>
<description>&lt;p&gt;&amp;nbsp;Last week, I met with Steven Hope, technical director at &lt;a href=&quot;http://www.winfrasoft.com/&quot;&gt;Winfrasoft&lt;/a&gt;, a multi-factor authentication company.&lt;/p&gt;
&lt;p&gt;As Hope was introducing me to the company and their suite of products, he listed everything they offer: &amp;ldquo;PINgrid, PINphrase and  ...</description>
<pubDate>Thu, 20 Dec 2012 17:53:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/20/15-factor-authentication-myth-or-fact/746.aspx</guid>
</item>
<item>
<title>False Positives and the Disposition Matrix</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/20/false-positives-and-the-disposition-matrix/745.aspx</link>
<description>&lt;p&gt;The bane of databases is the false positive &amp;ndash; the inclusion of an entry that shouldn&amp;rsquo;t be there. For anti-malware databases, false positives are inconvenient: good software is blocked because it is believed to be bad. For human databases it can be equally inconvenient: a false positiv ...</description>
<pubDate>Thu, 20 Dec 2012 16:49:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/20/false-positives-and-the-disposition-matrix/745.aspx</guid>
</item>
<item>
<title>CipherCloud: Expansion into Europe, Investment, and The Cost of a Data Breach </title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/20/ciphercloud-expansion-into-europe-investment-and-the-cost-of-a-data-breach-/744.aspx</link>
<description>&lt;p&gt;The week that &lt;a href=&quot;http://www.ciphercloud.com/&quot;&gt;CipherCloud&lt;/a&gt; announced it had received &lt;a href=&quot;http://www.ciphercloud.com/Company/PressReleases/tabid/106/NewsId/39/CipherCloud-Closes-30-Million-Investment-Round-with-Andreessen-Horowitz.aspx&quot;&gt;$30 million in new funding&lt;/a&gt; from Andreessen  ...</description>
<pubDate>Thu, 20 Dec 2012 16:30:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/20/ciphercloud-expansion-into-europe-investment-and-the-cost-of-a-data-breach-/744.aspx</guid>
</item>
<item>
<title>Commercial Anti-virus vs. Microsoft</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/19/commercial-antivirus-vs-microsoft/743.aspx</link>
<description>&lt;p&gt;It&amp;rsquo;s often the case when I set out and write a news feature that I typically end up with far more copy than space allotted in our print edition. My most recent &lt;a href=&quot;http://www.infosecurity-magazine.com/view/29913/in-windows-we-trust/&quot;&gt;feature on Windows 8 security&lt;/a&gt; is no exception. T ...</description>
<pubDate>Wed, 19 Dec 2012 18:32:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/19/commercial-antivirus-vs-microsoft/743.aspx</guid>
</item>
<item>
<title>Mayan Hangover</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/18/mayan-hangover/741.aspx</link>
<description>&lt;p&gt;It&amp;rsquo;s not often that having a background in both archeology and technology seems useful, but when you&amp;rsquo;re facing the end-of-the-world-as-we-know-it, then it&amp;rsquo;s surprising what becomes relevant.&lt;/p&gt;
&lt;p&gt;On Dec 21st, the 13th b'ak'tun in the Mayan calendar comes to an end and the fol ...</description>
<pubDate>Tue, 18 Dec 2012 21:38:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/18/mayan-hangover/741.aspx</guid>
</item>
<item>
<title>2013: The Year for Privacy?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/18/2013-the-year-for-privacy/740.aspx</link>
<description>&lt;p&gt;As we approach the end of the year it is only natural that people start looking forward to what may happen in the upcoming New Year. My inbox, like everyone else&amp;rsquo;s, has been flooded with messages from vendors predicting the threats that we will face in 2013, and by some strange twist of fat ...</description>
<pubDate>Tue, 18 Dec 2012 16:35:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/18/2013-the-year-for-privacy/740.aspx</guid>
</item>
<item>
<title>Send in the Clones</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/17/send-in-the-clones/735.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The longer you stay in this game, the more obsolete information you have cluttering up your memory cells. Technology moves quickly, and in the tug o&amp;rsquo; war o&amp;rsquo; attrition between malware and anti-malware, the effective lifetime of a specific malicious binary is often very ...</description>
<pubDate>Mon, 17 Dec 2012 14:40:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/17/send-in-the-clones/735.aspx</guid>
</item>
<item>
<title>An Interview with Jamie Pearce, WatchGuard Technologies</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/14/an-interview-with-jamie-pearce-watchguard-technologies/731.aspx</link>
<description>&lt;p&gt;During a lovely lunch at Kettners with &lt;a href=&quot;http://www.watchguard.com/&quot;&gt;WatchGuard&amp;rsquo;&lt;/a&gt;s UK &amp;amp; Ireland regional sales manager, Jamie Pearce, we talked UTM performance issues, 2013 threats, and the advantages of an industry rich in M&amp;amp;A&amp;hellip;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.infosecur ...</description>
<pubDate>Fri, 14 Dec 2012 09:54:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/14/an-interview-with-jamie-pearce-watchguard-technologies/731.aspx</guid>
</item>
<item>
<title>Cybersecurity’s “Fiscal Cliff”</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/13/cybersecuritys-fiscal-cliff/729.aspx</link>
<description>&lt;p&gt;Regardless of how the profession has evolved, or what the specific challenges are facing your sector, one thing has remained constant in the information security field for some time: the demand for qualified professionals has generated nearly full employment for the industry. This comes at a time ...</description>
<pubDate>Thu, 13 Dec 2012 15:26:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/13/cybersecuritys-fiscal-cliff/729.aspx</guid>
</item>
<item>
<title>An Interview with Aidan Simister, Netwrix </title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/12/an-interview-with-aidan-simister-netwrix-/728.aspx</link>
<description>&lt;p&gt;I recently met with &lt;a href=&quot;http://www.youtube.com/watch?v=fdGoDvS6JV4&quot;&gt;Aidan Simister&lt;/a&gt;, country manager, UK &amp;amp; Ireland,&lt;a href=&quot;http://www.netwrix.com/uk/change_auditing.html&quot;&gt; NetWrix&lt;/a&gt;, at the W hotel in Leicester Square.&lt;/p&gt;
&lt;p&gt;You may not be familiar with NetWrix if you are UK-base ...</description>
<pubDate>Wed, 12 Dec 2012 14:27:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/12/an-interview-with-aidan-simister-netwrix-/728.aspx</guid>
</item>
<item>
<title>It’s a Man’s Man’s World</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/10/its-a-mans-mans-world/724.aspx</link>
<description>&lt;p&gt;&amp;nbsp;So, I should probably begin with a disclaimer. I am a woman working in the infosecurity industry, which arguably makes me biased, but certainly puts me in a position to comment on this much-debated topic: the lack of women in information security.&lt;/p&gt;
&lt;p&gt;At the &lt;a href=&quot;http://www.rsaconfe ...</description>
<pubDate>Mon, 10 Dec 2012 15:16:08 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/10/its-a-mans-mans-world/724.aspx</guid>
</item>
<item>
<title>OSX/Flashback isn't Necessarily the Newsflash</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/7/osxflashback-isnt-necessarily-the-newsflash/722.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;As the pseudonymous Old Mac Bloggit &amp;ndash; my colleague at Mac Virus &amp;ndash; has &lt;a href=&quot;https://macviruscom.wordpress.com/2012/12/07/sophos-threat-report/&quot;&gt;already noted&lt;/a&gt;, there&amp;rsquo;s some interesting Mac-related content included in the Sophos Security Threat Report 2012  ...</description>
<pubDate>Fri, 07 Dec 2012 18:08:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/7/osxflashback-isnt-necessarily-the-newsflash/722.aspx</guid>
</item>
<item>
<title>Is Your Computer Photochromatic?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/6/is-your-computer-photochromatic/721.aspx</link>
<description>&lt;p&gt;Earlier this year Google showed off its prototype for the long-awaited Google Glass, described as &amp;ldquo;a stamp-sized electronic screen mounted on the left side of a pair of eyeglass frames which can record video, access email and messages, and retrieve information from the Web.&amp;rdquo; The glass ...</description>
<pubDate>Thu, 06 Dec 2012 19:54:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/6/is-your-computer-photochromatic/721.aspx</guid>
</item>
<item>
<title>Apple’s Next Target? A Polish Grocer</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/6/apples-next-target-a-polish-grocer/720.aspx</link>
<description>&lt;p&gt;Cult of Android, the online antidote to the online Cult of Mac, &lt;a href=&quot;http://www.cultofandroid.com/16057/not-even-polish-sausage-is-safe-from-apples-ego/&quot;&gt;announced&lt;/a&gt; on September 13: &amp;ldquo;Ladies and gentlemen, I wish I was making this up, but unfortunately I&amp;rsquo;m not... They&amp;rsquo;ve a ...</description>
<pubDate>Thu, 06 Dec 2012 19:49:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/6/apples-next-target-a-polish-grocer/720.aspx</guid>
</item>
<item>
<title>OSX/Dockster Spyware</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/3/osxdockster-spyware/715.aspx</link>
<description>&lt;p&gt;On November 30th, Intego blogged about OS X spyware it calls &lt;a href=&quot;http://www.intego.com/mac-security-blog/new-mac-spyware-discovered-osxdockster-a/&quot;&gt;OSX/Dockster.A&lt;/a&gt;. This relatively simple backdoor trojan, found on&lt;a href=&quot;http://virustotal.com/&quot;&gt; Virus Total&lt;/a&gt;, provides a remote shell t ...</description>
<pubDate>Mon, 03 Dec 2012 21:24:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/3/osxdockster-spyware/715.aspx</guid>
</item>
<item>
<title>Could Censorship be Necessary?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/12/3/could-censorship-be-necessary/714.aspx</link>
<description>&lt;p&gt;On the first of November this year, &lt;a href=&quot;http://www.guardian.co.uk/world/2012/nov/12/censorship-row-russian-internet-blacklist&quot;&gt;a law was passed&lt;/a&gt; in Russia banning certain internet sites devoted to drug-use, pornography, and suicide. Experts have warned that this law could be used as a pre ...</description>
<pubDate>Mon, 03 Dec 2012 15:39:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/12/3/could-censorship-be-necessary/714.aspx</guid>
</item>
<item>
<title>In Deep Space, No-one Can See You Surf</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/27/in-deep-space-noone-can-see-you-surf/710.aspx</link>
<description>&lt;p&gt;The web is often described as cyberspace. Hold that image, and then travel into deep space &amp;ndash; the dark web. You might see what looks like Saturn, surrounded by rings. But look closer and you&amp;rsquo;ll find it&amp;rsquo;s a black hole protected by onion rings.&lt;/p&gt;
&lt;p&gt;Enter Tor (the name is an acr ...</description>
<pubDate>Tue, 27 Nov 2012 17:46:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/27/in-deep-space-noone-can-see-you-surf/710.aspx</guid>
</item>
<item>
<title>What's the Main Cause of Movie Piracy?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/27/whats-the-main-cause-of-movie-piracy/709.aspx</link>
<description>&lt;p&gt;The main cause of movie piracy, says &lt;a href=&quot;http://www.scientificamerican.com/article.cfm?id=how-hollywood-encouraging-onine-piracy&quot;&gt;&lt;em&gt;Scientific American&lt;/em&gt;&lt;/a&gt;,  is movie makers themselves. DVDs are dying primarily because phones, tablets, netbooks and many new laptops simply don&amp;rsquo;t  ...</description>
<pubDate>Tue, 27 Nov 2012 17:38:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/27/whats-the-main-cause-of-movie-piracy/709.aspx</guid>
</item>
<item>
<title>Symantec versus CA</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/27/symantec-versus-ca/708.aspx</link>
<description>&lt;p&gt;Two back-to-back events recently saw Quocirca talking to veterans of the software industry: CA and Symantec. The high-level message from both is pretty much to same &amp;ndash;&amp;nbsp;we help to secure and manage your data and IT infrastructure. Yet, it is rare to find these two head-to-head; because,  ...</description>
<pubDate>Tue, 27 Nov 2012 12:02:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/27/symantec-versus-ca/708.aspx</guid>
</item>
<item>
<title>An Interview with Bernard Parsons, CEO, BeCrypt…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/26/an-interview-with-bernard-parsons-ceo-becrypt/707.aspx</link>
<description>&lt;p&gt;In the wonderfully opulent setting of the Savoy hotel, London, I recently met with the co-founder and CEO of &lt;a href=&quot;http://www.becrypt.com/about-us/management-team&quot;&gt;BeCrypt, Bernard Parsons,&lt;/a&gt; and his colleague Keith Ricketts, head of marketing.&lt;/p&gt;
&lt;p&gt;Bernard Parsons isn&amp;rsquo;t your typica ...</description>
<pubDate>Mon, 26 Nov 2012 15:11:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/26/an-interview-with-bernard-parsons-ceo-becrypt/707.aspx</guid>
</item>
<item>
<title>A chat with Wolfgang Kandek, CTO, Qualys…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/26/a-chat-with-wolfgang-kandek-cto-qualys/703.aspx</link>
<description>&lt;p&gt;On November 8th, I attended the &lt;a href=&quot;http://www.qualys.com/company/events/tradeshows/2012/qsc/&quot;&gt;Qualys Security Conference 2012 &lt;/a&gt;at the Berkeley hotel in London. At the end of the day, I was lucky enough to catch up with &lt;a href=&quot;http://laws.qualys.com/2012/02/february-patch-tuesday-2012-f ...</description>
<pubDate>Mon, 26 Nov 2012 01:24:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/26/a-chat-with-wolfgang-kandek-cto-qualys/703.aspx</guid>
</item>
<item>
<title>An Interview with ForgeRock…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/21/an-interview-with-forgerock/699.aspx</link>
<description>&lt;p&gt;Last week, I met with &lt;a href=&quot;http://forgerock.com/who-we-are/team/&quot;&gt;Daniel Raskin, VP marketing &lt;/a&gt;at &lt;a href=&quot;http://forgerock.com/&quot;&gt;ForgeRock,&lt;/a&gt; and John Barco, director of product marketing.&lt;/p&gt;
&lt;p&gt;You may not have heard of ForgeRock, I hadn&amp;rsquo;t either, but that&amp;rsquo;s because they&amp; ...</description>
<pubDate>Wed, 21 Nov 2012 11:13:32 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/21/an-interview-with-forgerock/699.aspx</guid>
</item>
<item>
<title>McAfee &amp; Michelangelo</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/19/mcafee--michelangelo/696.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Without breaking any confidences, it&amp;rsquo;s fair to say that the &lt;a href=&quot;http://www.telegraph.co.uk/technology/internet-security/9680870/John-McAfee-sex-drugs-and-anti-virus-software.html&quot;&gt;present troubles&lt;/a&gt; of John McAfee, founder of the AV company that still bears his name, ...</description>
<pubDate>Mon, 19 Nov 2012 18:52:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/19/mcafee--michelangelo/696.aspx</guid>
</item>
<item>
<title>Mobility, Cloud, and Elephants</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/16/mobility-cloud-and-elephants/695.aspx</link>
<description>&lt;p&gt;So the common response on how to handle big problems has always been the old adage of how to eat an elephant &amp;ndash; one bite at a time.&lt;/p&gt;
&lt;p&gt;For most problems (and I presume, pachyderm gastronomes too) this seems to work well. However, we&amp;rsquo;re facing a set of challenges for which that wis ...</description>
<pubDate>Fri, 16 Nov 2012 22:09:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/16/mobility-cloud-and-elephants/695.aspx</guid>
</item>
<item>
<title>Are Operating System Vendors Really Selling Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/8/are-operating-system-vendors-really-selling-security/686.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;&lt;span style=&quot;Times New Roman&amp;quot;;Times New Roman&amp;quot;&quot;&gt;In an IT Pro Portal article whose title says it all&amp;nbsp;&lt;/span&gt;&amp;ndash;&amp;nbsp;&lt;a href=&quot;http://www.itproportal.com/2012/11/07/windows-vs-apple-os-x-security-market-share-more-important-than-product/&quot;&gt;Windows vs Apple OS X se ...</description>
<pubDate>Thu, 08 Nov 2012 11:20:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/8/are-operating-system-vendors-really-selling-security/686.aspx</guid>
</item>
<item>
<title>Absorbing DDoS; Akamai’s Kona security service</title>
<link>http://www.infosecurity-magazine.com/blog/2012/11/7/absorbing-ddos-akamais-kona-security-service/684.aspx</link>
<description>&lt;p&gt;Even amongst those outside the IT industry, it is popular to speculate where we would be without the internet; what would happen if you could switch if off over night? Those in the know like to point out that fault tolerance, through alternative routing, was one of this reasons for the internet&amp;r ...</description>
<pubDate>Wed, 07 Nov 2012 17:44:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/11/7/absorbing-ddos-akamais-kona-security-service/684.aspx</guid>
</item>
<item>
<title>The Battle of the Titans: What it all means for IT managers caught in the middle</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/31/the-battle-of-the-titans-what-it-all-means-for-it-managers-caught-in-the-middle/678.aspx</link>
<description>&lt;h5&gt;By Cesare Garlati&lt;/h5&gt;
&lt;p&gt;Adapt, accept and manage: a BYOD mantra for corporate IT&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;/_virtual/ck/image005.jpg&quot; width=&quot;250&quot; height=&quot;188&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;RIM and Apple: two firms with more contrasting current fortunes you could not wish to imagine. The once high-flying Canadian ...</description>
<pubDate>Wed, 31 Oct 2012 18:52:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/31/the-battle-of-the-titans-what-it-all-means-for-it-managers-caught-in-the-middle/678.aspx</guid>
</item>
<item>
<title>The High Costs of Securing Identities: 
How to Fix the Problem Using the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/26/the-high-costs-of-securing-identities-how-to-fix-the-problem-using-the-cloud/676.aspx</link>
<description>&lt;h5&gt;By Dan Dagnall&lt;/h5&gt;
&lt;p&gt;Identity management is well down the path of a mature market space.  But I believe there is still one final, fundamental disconnect that is driving up the cost of deploying and maintaining an identity management solution, and that is programming and customization.&lt;/p&gt;
&lt;p ...</description>
<pubDate>Fri, 26 Oct 2012 20:17:48 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/26/the-high-costs-of-securing-identities-how-to-fix-the-problem-using-the-cloud/676.aspx</guid>
</item>
<item>
<title>How Do You Define a Data Breach?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/19/how-do-you-define-a-data-breach/673.aspx</link>
<description>&lt;p&gt;As I have promised in previous posts, I will continue to use this space to publish comments and letters we receive on our coverage. This most recent comment came from someone read our news item a few weeks ago about the &lt;a href=&quot;http://www.infosecurity-magazine.com/view/28544/white-house-targette ...</description>
<pubDate>Fri, 19 Oct 2012 19:47:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/19/how-do-you-define-a-data-breach/673.aspx</guid>
</item>
<item>
<title>The Nature of Political Censorship</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/19/the-nature-of-political-censorship/672.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left; &quot;&gt;&lt;span style=&quot;&quot;&gt;When it comes to internet censorship, of course the first apparent problem is the infringement of basic human rights, including freedom of speech and the sharing of information.&amp;nbsp;However, when it comes to practical attempts to censor  ...</description>
<pubDate>Fri, 19 Oct 2012 07:10:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/19/the-nature-of-political-censorship/672.aspx</guid>
</item>
<item>
<title>Context + Analytics = Good Security</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/17/context--analytics--good-security/671.aspx</link>
<description>&lt;h5&gt;By Jon-Louis Heimerl&lt;/h5&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Data&lt;/strong&gt; [dey-tuh] noun: individual facts or statistics&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Information&lt;/strong&gt; [in-fer-mey-shuhn] noun: knowledge concerning a particular fact or circumstance&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When does data become consumable informatio ...</description>
<pubDate>Wed, 17 Oct 2012 18:35:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/17/context--analytics--good-security/671.aspx</guid>
</item>
<item>
<title>The Test of Time</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/13/the-test-of-time/668.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;So you&amp;rsquo;ve seen all the stories about the rising tide of Mac malware. Maybe you&amp;rsquo;ve noticed that the fanboi cries of &amp;ldquo;Macs are secure! There are no Mac viruses!&amp;rdquo; have been a little muted lately, and that OSX/Flashback managed to recruit a sizeable number of  ...</description>
<pubDate>Sat, 13 Oct 2012 17:51:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/13/the-test-of-time/668.aspx</guid>
</item>
<item>
<title>Removing Cloud Barriers in Europe</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/10/removing-cloud-barriers-in-europe/665.aspx</link>
<description>&lt;h5&gt;By David Stott&lt;/h5&gt;
&lt;p&gt;No one is immune to the ever-changing technology forecast, but one constant (at least for the near future) appears to be global cloud cover. Cloud computing is arguably the most dominant theme  on every enterprise&amp;rsquo;s IT list, but in Europe, it&amp;rsquo;s being met with  ...</description>
<pubDate>Wed, 10 Oct 2012 20:08:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/10/removing-cloud-barriers-in-europe/665.aspx</guid>
</item>
<item>
<title>Risking It All</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/9/risking-it-all/662.aspx</link>
<description>&lt;p&gt;Ray Bradbury said &amp;ldquo;Living at risk is jumping off the cliff and building your wings on the way down.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s hard to imagine a better analogy for the challenges that information security faces today. Whether we want to or not, the business drive to adopt disruptive technolo ...</description>
<pubDate>Tue, 09 Oct 2012 17:21:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/9/risking-it-all/662.aspx</guid>
</item>
<item>
<title>Tales of Infosec Embarrassment from the US Presidential Election</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/9/tales-of-infosec-embarrassment-from-the-us-presidential-election/661.aspx</link>
<description>&lt;p&gt;What exactly constitutes a data breach? How do we define it? Is it simply when an attacker runs off with thousands of customer details, or does it also include the theft of IP? Perhaps it&amp;rsquo;s any action that leads to the compromise of organizational data, networks, or assets? What about when  ...</description>
<pubDate>Tue, 09 Oct 2012 11:20:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/9/tales-of-infosec-embarrassment-from-the-us-presidential-election/661.aspx</guid>
</item>
<item>
<title>Riding the Consumerization Wave</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/7/riding-the-consumerization-wave/659.aspx</link>
<description>&lt;h5&gt;By Cesare Garlati&lt;/h5&gt;
&lt;p&gt;Rather than resist it, organizations should embrace Consumerization to unlock its business potential. This requires a strategic approach, flexible policies and appropriate security and management tools.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;http://bringyourownit.com/category/consumeriz ...</description>
<pubDate>Sun, 07 Oct 2012 01:21:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/7/riding-the-consumerization-wave/659.aspx</guid>
</item>
<item>
<title>The Identity Bridge – The Extended Value of Single Sign On</title>
<link>http://www.infosecurity-magazine.com/blog/2012/10/1/the-identity-bridge--the-extended-value-of-single-sign-on/658.aspx</link>
<description>&lt;p&gt;There is nothing new about single sign on (SSO) systems; they have been on the market for many years as a way to provide a single point of authentication for users before providing them access to IT resources. What is new is the increasing capability of SSO systems to better manage the changing w ...</description>
<pubDate>Mon, 01 Oct 2012 14:41:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/10/1/the-identity-bridge--the-extended-value-of-single-sign-on/658.aspx</guid>
</item>
<item>
<title>The Impact of Computing Power on Cryptography</title>
<link>http://www.infosecurity-magazine.com/blog/2012/9/21/the-impact-of-computing-power-on-cryptography/653.aspx</link>
<description>&lt;h5&gt;By Eric Hay&lt;/h5&gt;
&lt;p&gt;Advanced technology is a beautiful thing. Not only has it enabled the creation of new, more efficient methods of application delivery and data storage (the Cloud is a prime example), but it&amp;rsquo;s also helped propel the development of more sophisticated solutions for data p ...</description>
<pubDate>Fri, 21 Sep 2012 19:27:02 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/9/21/the-impact-of-computing-power-on-cryptography/653.aspx</guid>
</item>
<item>
<title>Managing Consumer Technology in the Enterprise - Why IT Needs to Change its Mindset </title>
<link>http://www.infosecurity-magazine.com/blog/2012/9/19/managing-consumer-technology-in-the-enterprise--why-it-needs-to-change-its-mindset-/652.aspx</link>
<description>&lt;h5&gt;By Cesare Garlati&lt;/h5&gt;
&lt;p&gt;Talking regularly about the &lt;a href=&quot;http://bringyourownit.com/&quot;&gt;consumerization of IT&lt;/a&gt; can often make one sound like a broken record, but the economic, security and management challenges it throws up for enterprises are too important to ignore.&lt;/p&gt;
&lt;p&gt;The problems ...</description>
<pubDate>Wed, 19 Sep 2012 20:45:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/9/19/managing-consumer-technology-in-the-enterprise--why-it-needs-to-change-its-mindset-/652.aspx</guid>
</item>
<item>
<title>A New Starting Point: Re-booting to Help Transition Veterans</title>
<link>http://www.infosecurity-magazine.com/blog/2012/9/12/a-new-starting-point-rebooting-to-help-transition-veterans/650.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;&lt;span style=&quot;Times New Roman&amp;quot;;Times New Roman&amp;quot;&quot;&gt;Going back as far as 2007, the (ISC)&lt;/span&gt;&amp;sup2;&amp;nbsp;Government Advisory Board (GAB) along with the ISSA-Northern Virginia Chapter Board, have been attempting to develop partnerships with veterans&amp;rsquo; organizations in ...</description>
<pubDate>Wed, 12 Sep 2012 15:56:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/9/12/a-new-starting-point-rebooting-to-help-transition-veterans/650.aspx</guid>
</item>
<item>
<title>7 Steps to Developing a Cloud Security Plan</title>
<link>http://www.infosecurity-magazine.com/blog/2012/9/10/7-steps-to-developing-a-cloud-security-plan/648.aspx</link>
<description>&lt;h5&gt;By David Grimes&lt;/h5&gt;
&lt;p&gt;In IT, the easiest way to stop a new technology or solution from being implemented is to raise a security red flag. As soon as someone mentions concerns around a new IT solution not being &amp;ldquo;secure&amp;rdquo; the project can come to a screeching halt. So as cloud infrast ...</description>
<pubDate>Mon, 10 Sep 2012 19:03:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/9/10/7-steps-to-developing-a-cloud-security-plan/648.aspx</guid>
</item>
<item>
<title>Broken WEP WiFi Encryption Still Operational in Large Numbers</title>
<link>http://www.infosecurity-magazine.com/blog/2012/9/7/broken-wep-wifi-encryption-still-operational-in-large-numbers/647.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;&quot;&gt;Even after the world has witnessed major Wi-Fi security incidents, such as &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2010/6/25/googles-wifi-snooping-controversy-is-a-wakeup-call-to-stop-wifi-malpractices/178.aspx&quot;&gt;Google&amp;rsquo;s W ...</description>
<pubDate>Fri, 07 Sep 2012 16:38:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/9/7/broken-wep-wifi-encryption-still-operational-in-large-numbers/647.aspx</guid>
</item>
<item>
<title>Trusting the Oracle: Truth or Dare</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/30/trusting-the-oracle-truth-or-dare/644.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;It&amp;rsquo;s been claimed that &lt;a href=&quot;#http://www.pcworld.com/businesscenter/article/261612/oracle_knew_about_currently_exploited_java_vulnerabilities_for_months_researcher_says.html&quot;&gt;&lt;span style=&quot;&quot;&gt;Oracle has known since April&lt;/span&gt;&lt;/a&gt; about the &lt;a href=&quot;http://krebsonsecurity ...</description>
<pubDate>Thu, 30 Aug 2012 17:48:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/30/trusting-the-oracle-truth-or-dare/644.aspx</guid>
</item>
<item>
<title>Compliance in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/30/compliance-in-the-cloud/642.aspx</link>
<description>&lt;div&gt;Earlier in the year Quocirca was asked a surprising question along these lines: &amp;ldquo;If we use a cloud-based storage service and there is a leak of personal data, who is responsible, us or them?&amp;rdquo; Make no mistake, the answer is, that regardless of how and where data is stored, the respon ...</description>
<pubDate>Thu, 30 Aug 2012 09:50:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/30/compliance-in-the-cloud/642.aspx</guid>
</item>
<item>
<title>Can You Be Sued for Using the Cloud?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/29/can-you-be-sued-for-using-the-cloud/640.aspx</link>
<description>&lt;h5&gt;By Gerry Grealish&lt;/h5&gt;
&lt;p&gt;We all know that adopting the Cloud comes with some risks &amp;ndash; security, reliability and scalability have, to-date, been the most popular complaints. But now, we can add a new one to the mix: litigation. Case in point, companies doing business in Australia, known fo ...</description>
<pubDate>Wed, 29 Aug 2012 20:12:48 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/29/can-you-be-sued-for-using-the-cloud/640.aspx</guid>
</item>
<item>
<title>Is Crypto in the Cloud Enough? </title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/27/is-crypto-in-the-cloud-enough-/639.aspx</link>
<description>&lt;h3&gt;By Jon-Michael C. Brook&lt;/h3&gt;
&lt;p&gt;Box.net, DropBox, iCloud, SkyDrive, Amazon Cloud Drive... the list goes on for convenient cloud storage options. Some have had a security incident; the rest will. All implement some form of protection against accidental exposure with varying degrees of protection ...</description>
<pubDate>Mon, 27 Aug 2012 21:04:48 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/27/is-crypto-in-the-cloud-enough-/639.aspx</guid>
</item>
<item>
<title>Debunking the Gospel of Security Marketing</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/27/debunking-the-gospel-of-security-marketing/638.aspx</link>
<description>&lt;p&gt;Identity and access management are critical for most, if not all organizations &amp;ndash; whether its employee access to enterprise networks, or customers who need access to your products and services. Authentication &amp;ndash; and the credentials that make it possible &amp;ndash; is at the heart of many d ...</description>
<pubDate>Mon, 27 Aug 2012 18:04:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/27/debunking-the-gospel-of-security-marketing/638.aspx</guid>
</item>
<item>
<title>Your Cloud Provider is a Partner…Not a One-Night Stand</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/21/your-cloud-provider-is-a-partnernot-a-onenight-stand/634.aspx</link>
<description>&lt;h5&gt;By Eric Sheridan&lt;/h5&gt;
&lt;p&gt;&amp;ldquo;We programmatically interface with Cloud Providers to manage our customer data, so we can rely on them for securing our services right?&amp;rdquo; Wrong!&lt;/p&gt;
&lt;p&gt;The moment you start interfacing with a Cloud Provider you immediately inherit the risks associated with  ...</description>
<pubDate>Tue, 21 Aug 2012 19:41:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/21/your-cloud-provider-is-a-partnernot-a-onenight-stand/634.aspx</guid>
</item>
<item>
<title>Lunch with Cryptography Research </title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/21/lunch-with-cryptography-research-/633.aspx</link>
<description>&lt;p&gt;On Friday, I had lunch with Ken Warren, marketing director,&lt;a href=&quot;http://www.cryptography.com/&quot;&gt; Cryptography Research (CRI). &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There was no topic agenda (just the way I like it) and we had an informal and enjoyable lunch, with conversation dancing around social networking, consumeri ...</description>
<pubDate>Tue, 21 Aug 2012 12:52:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/21/lunch-with-cryptography-research-/633.aspx</guid>
</item>
<item>
<title>BYOD, Big Data, and My Breakfast with Steve</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/20/byod-big-data-and-my-breakfast-with-steve/632.aspx</link>
<description>&lt;p&gt;Our digital world makes frequent communications with colleagues across the globe a seamless occurrence these days. Yet, it&amp;rsquo;s still nice &amp;ndash; and my preferred method &amp;ndash; to meet with people face to face. So when the Information Security Forum&amp;rsquo;s global executive VP, Steve Durbin, ...</description>
<pubDate>Mon, 20 Aug 2012 18:09:48 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/20/byod-big-data-and-my-breakfast-with-steve/632.aspx</guid>
</item>
<item>
<title>The Highly Secure Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/20/the-highly-secure-cloud/631.aspx</link>
<description>&lt;p&gt;Surveys by Quocirca and other research firms constantly show that &amp;ldquo;security&amp;rdquo; is THE biggest concern when it comes to making use of cloud services. Why is this, and is the perception that cloud services are inherently less secure than internally managed ones justified?&lt;/p&gt;
&lt;p&gt;There ar ...</description>
<pubDate>Mon, 20 Aug 2012 12:53:32 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/20/the-highly-secure-cloud/631.aspx</guid>
</item>
<item>
<title>Avoiding Storms in the Cloud: The Critical Need for Independent Verification</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/16/avoiding-storms-in-the-cloud-the-critical-need-for-independent-verification/629.aspx</link>
<description>&lt;p&gt;By Chris Wysopal&lt;/p&gt;
&lt;p&gt;Last year, Forrester predicted that &lt;a href=&quot;http://www.cloudtweaks.com/2011/04/cloud-computing-market-will-top-241-billion-in-2020/&quot;&gt;cloud computing would top $240 billion in 2020&lt;/a&gt;. Market Research Media came up with a &lt;a href=&quot;http://www.marketresearchmedia.com/?p=83 ...</description>
<pubDate>Thu, 16 Aug 2012 20:57:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/16/avoiding-storms-in-the-cloud-the-critical-need-for-independent-verification/629.aspx</guid>
</item>
<item>
<title>Big Data, Big Cloud, Big Problem</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/15/big-data-big-cloud-big-problem/625.aspx</link>
<description>&lt;h5&gt;By Todd Thiemann&lt;/h5&gt;
&lt;p&gt;Big Data presents a big opportunity for businesses to mine large volumes of data from a variety of sources to make better and more high-velocity decisions. Since big data implementations are practically always deployed in a cloud environment, be it a private cloud or pu ...</description>
<pubDate>Wed, 15 Aug 2012 20:12:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/15/big-data-big-cloud-big-problem/625.aspx</guid>
</item>
<item>
<title>Deploying Advanced Cybersecurity Intelligence</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/14/deploying-advanced-cybersecurity-intelligence/623.aspx</link>
<description>&lt;p&gt;During a speech in June 2012, Jonathan Evans, the chief of the UK&amp;rsquo;s home security agency MI5, stated that it was &amp;ldquo;&lt;i&gt;fighting 'astonishing' levels of cyber-attacks&lt;/i&gt;&amp;rdquo;. The worry is not just about the number, but the sophistication and the degree of targeting of individual peop ...</description>
<pubDate>Tue, 14 Aug 2012 14:46:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/14/deploying-advanced-cybersecurity-intelligence/623.aspx</guid>
</item>
<item>
<title>Best Practices to Secure the Cloud with Identity Management         </title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/13/best-practices-to-secure-the-cloud-with-identity-management---------/621.aspx</link>
<description>&lt;h5&gt;By Dan Dagnall&lt;/h5&gt;
&lt;p&gt;What is the &amp;ldquo;cloud identity?&amp;rdquo; The &amp;ldquo;cloud identity&amp;rdquo; begins at the birth of the user&amp;rsquo;s &amp;ldquo;digital identity&amp;rdquo; and includes the attributes to define &amp;ldquo;who you are.&amp;rdquo; &amp;ldquo;Cloud Identity&amp;rdquo; is not a new term to those in th ...</description>
<pubDate>Mon, 13 Aug 2012 19:34:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/13/best-practices-to-secure-the-cloud-with-identity-management---------/621.aspx</guid>
</item>
<item>
<title>Who Are You, and Who is that Woman?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/9/who-are-you-and-who-is-that-woman/620.aspx</link>
<description>&lt;p&gt;A few weeks ago I found myself in the rather odd position of not being able to prove who I am.&amp;nbsp;At the time I was talking to a company of which I had been a loyal customer for the better part of fifteen years.&amp;nbsp;And they didn&amp;rsquo;t believe me when I said I was me.&lt;/p&gt;
&lt;p&gt;Unsurprisingly  ...</description>
<pubDate>Thu, 09 Aug 2012 21:38:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/9/who-are-you-and-who-is-that-woman/620.aspx</guid>
</item>
<item>
<title>Application-Aware Firewalls</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/9/applicationaware-firewalls/619.aspx</link>
<description>&lt;h5&gt;By Andy Thurai&lt;/h5&gt;
&lt;p&gt;You may have heard this term recently and wondered what it meant. When it comes to security, everyone thinks of Firewalls, Proxies, IPS, IDS, Honeypots, VPN devices, email security and even Web security, but most people don&amp;rsquo;t think in terms of application level secu ...</description>
<pubDate>Thu, 09 Aug 2012 19:34:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/9/applicationaware-firewalls/619.aspx</guid>
</item>
<item>
<title>Apple Support and Anti-Social Engineering</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/8/apple-support-and-antisocial-engineering/617.aspx</link>
<description>&lt;p&gt;When &lt;a href=&quot;http://www.infosecurity-magazine.com/view/27406/tech-journalist-gets-hacked-apple-tech-support-to-blame-&quot;&gt;&lt;em&gt;&lt;span style=&quot;font-size: 10pt&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;Infosecurity&lt;/font&gt;&lt;/span&gt;&lt;/em&gt;&lt;span style=&quot;font-size: 10pt&quot;&gt;&lt;font color=&quot;#800080&quot;&gt; Magazine originally wrote&lt;/font&gt;&lt;/spa ...</description>
<pubDate>Wed, 08 Aug 2012 22:28:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/8/apple-support-and-antisocial-engineering/617.aspx</guid>
</item>
<item>
<title>Money, money, money...</title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/7/money-money-money/614.aspx</link>
<description>&lt;p&gt;Venture capital in the Silicon Valley is akin to a heart in the human body. If it fails to contract effectively, and thus normal circulation of the blood/money is deterred, you experience cardiac arrest.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m writing this in a Starbucks in &lt;a href=&quot;https://maps.google.co.uk/maps?oe=u ...</description>
<pubDate>Tue, 07 Aug 2012 15:29:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/7/money-money-money/614.aspx</guid>
</item>
<item>
<title>Black Hat and Silicon Valley 2012: Part One </title>
<link>http://www.infosecurity-magazine.com/blog/2012/8/6/black-hat-and-silicon-valley-2012-part-one-/611.aspx</link>
<description>&lt;p&gt;I&amp;rsquo;m writing this on the plane back from Las Vegas. People can hang up their &lt;a href=&quot;http://www.blackhat.com/&quot;&gt;Black Hat &lt;/a&gt;t-shirts until next summer (although I suspect many of the delegates wear them year-round. It always amazes me how they are worn with pride like rock t-shirts, with i ...</description>
<pubDate>Mon, 06 Aug 2012 13:40:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/8/6/black-hat-and-silicon-valley-2012-part-one-/611.aspx</guid>
</item>
<item>
<title>Consumerization 101 – Employee Privacy vs. Corporate Liability</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/31/consumerization-101--employee-privacy-vs-corporate-liability/609.aspx</link>
<description>&lt;h5&gt;By Cesare Garlati&lt;/h5&gt;
&lt;p&gt;Mary D. joined MD&amp;amp;M Inc. in 2009. Being an Apple enthusiast, she was quite excited to learn that the company offered an innovative BYOD program that allows employees to use their own iPhone for work. As part of the new hire package, Mary signed the acceptable use p ...</description>
<pubDate>Tue, 31 Jul 2012 19:30:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/31/consumerization-101--employee-privacy-vs-corporate-liability/609.aspx</guid>
</item>
<item>
<title>Pickpockets in the (app) Marketplace</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/20/pickpockets-in-the-app-marketplace/602.aspx</link>
<description>&lt;p&gt;Suddenly, it seems, the App Store is having a (very small) taste of the sort of criticism previously reserved for Android outlets, recently with regard to ZonD80&amp;rsquo;s provision of a service by which Apple&amp;rsquo;s in-app purchasing mechanism can be subverted, hard on the heels of reports of a p ...</description>
<pubDate>Fri, 20 Jul 2012 12:43:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/20/pickpockets-in-the-app-marketplace/602.aspx</guid>
</item>
<item>
<title>Security Considerations When Evaluating Applications on the Google Apps Marketplace</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/19/security-considerations-when-evaluating-applications-on-the-google-apps-marketplace/600.aspx</link>
<description>&lt;h5&gt;&amp;nbsp;By Tsahy Shapsa&lt;/h5&gt;
&lt;p&gt;&lt;br /&gt;
&lt;img src=&quot;/_virtual/ck/a1.JPG&quot; width=&quot;211&quot; height=&quot;191&quot; align=&quot;left&quot; alt=&quot;&quot; /&gt;Customers care about the security of their data in the cloud, and security of customer data is obviously important to Google, which is why Google has invested in completing numero ...</description>
<pubDate>Thu, 19 Jul 2012 21:39:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/19/security-considerations-when-evaluating-applications-on-the-google-apps-marketplace/600.aspx</guid>
</item>
<item>
<title>Some Things To Consider When Extending Your IdM Into the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/19/some-things-to-consider-when-extending-your-idm-into-the-cloud/599.aspx</link>
<description>&lt;h5&gt;By Mark O&amp;rsquo;Neill&lt;/h5&gt;
&lt;p&gt;Like many organizations, you no doubt face the challenge of extending your IT operations into the cloud to take advantage of the many cloud-based services demanded by your users today. As you make the transition from a firewall-protected in-house IT infrastructure  ...</description>
<pubDate>Thu, 19 Jul 2012 21:11:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/19/some-things-to-consider-when-extending-your-idm-into-the-cloud/599.aspx</guid>
</item>
<item>
<title>Is it Time to License Cyber Security Professionals?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/9/is-it-time-to-license-cyber-security-professionals/593.aspx</link>
<description>&lt;div&gt;At the&amp;nbsp;&lt;a href=&quot;http://www.cisse.info/colloquium/&quot;&gt;2012&amp;nbsp;Colloquium for Information Systems Security Education&amp;nbsp;(CISSE)&lt;/a&gt;&amp;nbsp;last month, a speaker from the US&amp;nbsp;Department of Homeland Security (DHS), National Cyber Security Division, provided a glimpse of a study that was be ...</description>
<pubDate>Mon, 09 Jul 2012 23:51:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/9/is-it-time-to-license-cyber-security-professionals/593.aspx</guid>
</item>
<item>
<title>Think Beyond the Enterprise: It's Time to Secure the &quot;Edge of the Cloud&quot;</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/9/think-beyond-the-enterprise-its-time-to-secure-the-edge-of-the-cloud/592.aspx</link>
<description>&lt;h5&gt;By Ed King&lt;/h5&gt;
&lt;p&gt;Everyone is familiar with the notion of securing the edge of the enterprise.  With the growing adoption of cloud technologies, IT must now also think about securing the &amp;quot;edge of the Cloud&amp;quot;.  The edge of the Cloud is the perimeter around any Cloud environment where i ...</description>
<pubDate>Mon, 09 Jul 2012 21:13:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/9/think-beyond-the-enterprise-its-time-to-secure-the-edge-of-the-cloud/592.aspx</guid>
</item>
<item>
<title>Apple Tiptoes Out of the Pavilion and onto the Sports Field</title>
<link>http://www.infosecurity-magazine.com/blog/2012/7/2/apple-tiptoes-out-of-the-pavilion-and-onto-the-sports-field/586.aspx</link>
<description>&lt;p&gt;Kelly Jackson Higgins has noted &amp;ldquo;&lt;a href=&quot;http://www.darkreading.com/advanced-threats/167901091/security/vulnerabilities/240002945/4-signs-that-apple-s-sharpening-its-security-game.html&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;4 Signs That Apple's Sharpening Its Security Game&lt;/font&gt;&lt;/a&gt;&amp;rdquo;. And indeed, t ...</description>
<pubDate>Mon, 02 Jul 2012 12:33:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/7/2/apple-tiptoes-out-of-the-pavilion-and-onto-the-sports-field/586.aspx</guid>
</item>
<item>
<title>Discovering an Old Flame</title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/26/discovering-an-old-flame/577.aspx</link>
<description>&lt;p&gt;Computer malware programmes only take on a name and a personality after they have been discovered. These are bestowed by the IT security industry, our would-be defenders. Before this, malware is anonymous and unknown, just the way the perpetrators want it.&lt;/p&gt;
&lt;p&gt;Such was the case with &lt;a href=&quot; ...</description>
<pubDate>Tue, 26 Jun 2012 11:38:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/26/discovering-an-old-flame/577.aspx</guid>
</item>
<item>
<title>Free Your Data &amp; the Apps Will Follow – But what About Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/22/free-your-data--the-apps-will-follow--but-what-about-security/576.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h5&gt;By Mark O'Neill&lt;/h5&gt;
&lt;p&gt;Application Programming Interfaces (API) represent such an important technology trend, that new business models are evolving on top of them, and this has led to the term &amp;ldquo;the API economy&amp;rdquo;. The API economy encompasses API developers, the busines ...</description>
<pubDate>Fri, 22 Jun 2012 20:41:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/22/free-your-data--the-apps-will-follow--but-what-about-security/576.aspx</guid>
</item>
<item>
<title>The Weakest LinkedIn</title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/18/the-weakest-linkedin/565.aspx</link>
<description>&lt;p&gt;If you missed the news (and I bet you didn&amp;rsquo;t) then here it is &amp;ndash; LinkedIn recently had its very own digital moment of truth, when hackers &lt;a href=&quot;http://www.infosecurity-magazine.com/view/26317/linkedin-defends-response-to-password-security-breach-in-face-of-criticism&quot;&gt;stole around 6  ...</description>
<pubDate>Mon, 18 Jun 2012 15:44:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/18/the-weakest-linkedin/565.aspx</guid>
</item>
<item>
<title>Centralized Decision-making Is Essential to Cybersecurity</title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/13/centralized-decisionmaking-is-essential-to-cybersecurity/564.aspx</link>
<description>&lt;p&gt;American politicians love to bash the Europeans. A common refrain during many campaigns here in the states is &amp;lsquo;my opponent&amp;rsquo;s policies will make us more like Europe&amp;rsquo;, as if the entire continent was a monolithic monster spewing forth a subversive socialist agenda. I would like to  ...</description>
<pubDate>Wed, 13 Jun 2012 17:57:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/13/centralized-decisionmaking-is-essential-to-cybersecurity/564.aspx</guid>
</item>
<item>
<title>An Interview with Centrify CEO, Tom Kemp </title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/11/an-interview-with-centrify-ceo-tom-kemp-/562.aspx</link>
<description>&lt;p&gt;I get invitations to sit down with industry CEOs all the time. There&amp;rsquo;s no real secret as to why I accept some and not others &amp;ndash; a lot of the time it&amp;rsquo;s just timing. Truth be told, I&amp;rsquo;d like to accept a lot more &amp;ndash; if time was no object.&lt;/p&gt;
&lt;p&gt;Of the many vendor CEOs I&amp; ...</description>
<pubDate>Mon, 11 Jun 2012 18:39:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/11/an-interview-with-centrify-ceo-tom-kemp-/562.aspx</guid>
</item>
<item>
<title>Beyond Point Security: Advanced IT Security Intelligence</title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/11/beyond-point-security-advanced-it-security-intelligence/560.aspx</link>
<description>&lt;p&gt;Point security products such as firewalls, host-based anti-virus and email filtering have a job to do and often do it reasonably well. Arguably if they did not, then businesses would not buy them, although sometimes purchases are made more for compliance purposes than security ones&amp;nbsp;&amp;ndash; f ...</description>
<pubDate>Mon, 11 Jun 2012 11:14:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/11/beyond-point-security-advanced-it-security-intelligence/560.aspx</guid>
</item>
<item>
<title>Hacktivism: Shades of Gray </title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/7/hacktivism-shades-of-gray-/559.aspx</link>
<description>&lt;p&gt;Allow me to let you in on a little secret. More often than not, I see the world in black and white. Very rarely do I see shades of gray. I tend to categorize things into boxes according to right, wrong, love, hate, agree, disagree. I am very aware that this isn&amp;rsquo;t necessarily a good quality  ...</description>
<pubDate>Thu, 07 Jun 2012 11:49:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/7/hacktivism-shades-of-gray-/559.aspx</guid>
</item>
<item>
<title>Businesses Are Over-granting Privilege and Failing to Limit Sys-admin Access</title>
<link>http://www.infosecurity-magazine.com/blog/2012/6/5/businesses-are-overgranting-privilege-and-failing-to-limit-sysadmin-access/557.aspx</link>
<description>&lt;p&gt;System administrators will often need wide ranging access to systems and devices to do their jobs, but systems are not the same as data. Many individuals working in IT departments will in fact be in relatively junior roles. Indeed, they may often be contractors from third parties. Access to confi ...</description>
<pubDate>Tue, 05 Jun 2012 08:23:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/6/5/businesses-are-overgranting-privilege-and-failing-to-limit-sysadmin-access/557.aspx</guid>
</item>
<item>
<title>A Report from the IT Security Analyst’s Forum 2012</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/22/a-report-from-the-it-security-analysts-forum-2012/554.aspx</link>
<description>&lt;p&gt;Following hot on from the InfoSec Europe trade show at the start of May 2012 was the IT Security Analyst&amp;rsquo;s forum, organised by Eskenzi PR, brought forward this year to avoid the Olympic events over the summer. As usual, the forum attracted analysts from most of the well-known firms from bot ...</description>
<pubDate>Tue, 22 May 2012 07:19:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/22/a-report-from-the-it-security-analysts-forum-2012/554.aspx</guid>
</item>
<item>
<title>Organisations Struggle to Safely and Securely Delegate Sys-admin Tasks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/18/organisations-struggle-to-safely-and-securely-delegate-sysadmin-tasks/553.aspx</link>
<description>&lt;p&gt;Many system administrator tasks are a repetitive drudge. Senior IT managers do not want to be doing such tasks on a day-to-day basis and would prefer to delegate these to junior staff or contractors from 3rd parties. However, they need to be confident that such tasks can be safely delegated by li ...</description>
<pubDate>Fri, 18 May 2012 09:12:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/18/organisations-struggle-to-safely-and-securely-delegate-sysadmin-tasks/553.aspx</guid>
</item>
<item>
<title>Betting on a Breach</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/14/betting-on-a-breach/552.aspx</link>
<description>&lt;p&gt;In February of this year, the University of North Carolina-Charlotte issued a statement that a breach had occurred. It now seems to have been a serious one. &amp;nbsp;As of the &lt;a href=&quot;http://itservices.uncc.edu/sites/itservices.uncc.edu/files/UNC-Charlotte_Security_Incident_Press_Release_05092012.p ...</description>
<pubDate>Mon, 14 May 2012 20:13:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/14/betting-on-a-breach/552.aspx</guid>
</item>
<item>
<title>Are Network Perimeters the Berlin Walls of Cloud IAM?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/14/are-network-perimeters-the-berlin-walls-of-cloud-iam/551.aspx</link>
<description>&lt;h5&gt;By Ed King&lt;/h5&gt;
&lt;p&gt;A single enterprise wide identity and access management (IAM) platform is a noble but unattainable goal. The network perimeter is now a metaphorical &amp;ldquo;Berlin Wall&amp;rdquo; between the two identity platform domains of Cloud and On-Premise. It is time for enterprises to form ...</description>
<pubDate>Mon, 14 May 2012 19:36:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/14/are-network-perimeters-the-berlin-walls-of-cloud-iam/551.aspx</guid>
</item>
<item>
<title>Quocirca’s Report from Infosecurity Europe 2012</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/8/quocircas-report-from-infosecurity-europe-2012/548.aspx</link>
<description>&lt;p&gt;The end of April was a busy time for IT security analysts. April 24&lt;sup&gt;th&lt;/sup&gt; to 26&lt;sup&gt;th&lt;/sup&gt; was &lt;a href=&quot;http://www.infosec.co.uk/&quot;&gt;Infosecurity Europe&lt;/a&gt; (InfoSec) at Earl&amp;rsquo;s Court, the biggest such trade show in Europe and the following week was the Eskenzi PR annual IT Security A ...</description>
<pubDate>Tue, 08 May 2012 09:20:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/8/quocircas-report-from-infosecurity-europe-2012/548.aspx</guid>
</item>
<item>
<title>Apples and Oranges = Apple and Microsoft?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/2/apples-and-oranges--apple-and-microsoft/546.aspx</link>
<description>&lt;p&gt;Several people have asked me for a response to Eugene Kaspersky&amp;rsquo;s views on Apple, &lt;font color=&quot;#800080&quot;&gt;&lt;a href=&quot;http://malware.cbronline.com/news/apple-10-years-behind-microsoft-on-security-kaspersky-250412&quot;&gt;as expressed at Infosecurity Europe&lt;/a&gt;&lt;/font&gt;&amp;nbsp;last week, suggesting that App ...</description>
<pubDate>Wed, 02 May 2012 14:57:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/2/apples-and-oranges--apple-and-microsoft/546.aspx</guid>
</item>
<item>
<title>Outsourcing B2B Integration: The Forgotten Option</title>
<link>http://www.infosecurity-magazine.com/blog/2012/5/1/outsourcing-b2b-integration-the-forgotten-option/545.aspx</link>
<description>&lt;h5&gt;By Stuart Lisk&amp;nbsp;&lt;/h5&gt;
&lt;p&gt;Business continuity remains a major concern for enterprises as they move more mission-critical processes to the cloud. Outsourcing B2B integration while ensuring cloud security in order to effectively integrate business processes is challenging at best, and ambiguou ...</description>
<pubDate>Tue, 01 May 2012 20:19:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/5/1/outsourcing-b2b-integration-the-forgotten-option/545.aspx</guid>
</item>
<item>
<title>Addressing the Consumerization of IT</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/26/addressing-the-consumerization-of-it/543.aspx</link>
<description>&lt;p&gt;&lt;em&gt;Bring Your Own Device&lt;/em&gt; or &lt;em&gt;Consumerization of IT&lt;/em&gt; are fairly hot themes in a lot of customer organizations. When I talk to customers, there are typically different reactions, once we bring this up. Some tell us that it is not part of their strategy; some tell us that they plan to d ...</description>
<pubDate>Thu, 26 Apr 2012 18:50:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/26/addressing-the-consumerization-of-it/543.aspx</guid>
</item>
<item>
<title>Configuration Compliance in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/25/configuration-compliance-in-the-cloud/542.aspx</link>
<description>&lt;h5&gt;By David Meltzer&lt;/h5&gt;
&lt;p&gt;As a member solution provider in the Cloud Security Alliance, paying careful attention to risk and planning for improvement is second nature for my own companies&amp;rsquo; security services.  As a consumer of many start-up cloud services built completely outside the securi ...</description>
<pubDate>Wed, 25 Apr 2012 20:05:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/25/configuration-compliance-in-the-cloud/542.aspx</guid>
</item>
<item>
<title>Changing Workforce Dynamics: Unleash the Power of the Professional Community</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/19/changing-workforce-dynamics-unleash-the-power-of-the-professional-community/540.aspx</link>
<description>&lt;div&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau (EWB)&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;The title of a recent &lt;i&gt;InformationWeek &lt;/i&gt;article, &lt;a href=&quot;http://www.informationweek.com/news/global-cio/interviews/2326017 ...</description>
<pubDate>Thu, 19 Apr 2012 12:11:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/19/changing-workforce-dynamics-unleash-the-power-of-the-professional-community/540.aspx</guid>
</item>
<item>
<title>Pining for Failure in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/18/pining-for-failure-in-the-cloud/539.aspx</link>
<description>&lt;p&gt;I missed &lt;a href=&quot;http://www.cio.com/article/703064/How_Secure_Is_the_Cloud_IT_Pros_Speak_Up&quot;&gt;this info-graphic&lt;/a&gt; first time around, so thanks to &lt;a href=&quot;http://securecloudreview.com/&quot;&gt;securecloudreview.com&lt;/a&gt;&amp;nbsp;for posting a link. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Like all info-graphics, it makes the proces ...</description>
<pubDate>Wed, 18 Apr 2012 23:00:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/18/pining-for-failure-in-the-cloud/539.aspx</guid>
</item>
<item>
<title>Apple OS X and Risk Reduction</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/16/apple-os-x-and-risk-reduction/538.aspx</link>
<description>&lt;p&gt;Some of the confidence Mac users have in the security of their chosen operating system derives from over-reliance on proactive patching. This outbreak highlights the need to be aware that patching of known vulnerabilities in system software or applications is not necessarily prompt enough to fore ...</description>
<pubDate>Mon, 16 Apr 2012 13:07:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/16/apple-os-x-and-risk-reduction/538.aspx</guid>
</item>
<item>
<title>The Consequences of Failing to Backup Network and Security Devices</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/16/the-consequences-of-failing-to-backup-network-and-security-devices/537.aspx</link>
<description>&lt;p&gt;Most IT users will have suffered the frustration of losing work because their access device (PC, tablet, smartphone etc.) fails and has not been backed up, or indeed they may have deleted a file accidentally. This is inconvenient for the individual and those associated with the project they are w ...</description>
<pubDate>Mon, 16 Apr 2012 09:41:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/16/the-consequences-of-failing-to-backup-network-and-security-devices/537.aspx</guid>
</item>
<item>
<title>Cloud Security Requires All Hands on Deck </title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/13/cloud-security-requires-all-hands-on-deck-/536.aspx</link>
<description>&lt;h5&gt;By Andrew Wild&lt;/h5&gt;
&lt;p&gt;It&amp;rsquo;s clear there are many compelling reasons, both financial and productivity-related, for enterprises to move IT functionality into the cloud, so it&amp;rsquo;s not surprising that they&amp;rsquo;re moving quickly to adopt popular collaboration services like Box.net, Yamme ...</description>
<pubDate>Fri, 13 Apr 2012 16:11:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/13/cloud-security-requires-all-hands-on-deck-/536.aspx</guid>
</item>
<item>
<title>Flashbacks and Backtracks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/6/flashbacks-and-backtracks/535.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;font-family: 'Calibri','sans-serif'; font-size: 11pt&quot;&gt;If you follow my &lt;a href=&quot;http://macviruscom.wordpress.com/&quot;&gt;&lt;span style=&quot;color: purple&quot;&gt;Mac Virus blog&lt;/span&gt;&lt;/a&gt;, you&amp;rsquo;ll have noticed that I&amp;rsquo;ve been tracking some of the coverage of Mac malware incidents to hit my ra ...</description>
<pubDate>Fri, 06 Apr 2012 11:15:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/6/flashbacks-and-backtracks/535.aspx</guid>
</item>
<item>
<title>Hacktivists Fail to Uphold a Proud Tradition of Protest</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/3/hacktivists-fail-to-uphold-a-proud-tradition-of-protest/534.aspx</link>
<description>&lt;p&gt;A&amp;nbsp;recent law enforcement sting corralled 25 alleged members of the Anonymous hacktivist group. As it turns out, the information fed to the FBI and other participating agencies came from within: Hector Xavier Monsegur (aka, &amp;lsquo;Sabu&amp;rsquo;) leader of the Anonymous offshoot LulzSec, had app ...</description>
<pubDate>Tue, 03 Apr 2012 19:34:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/3/hacktivists-fail-to-uphold-a-proud-tradition-of-protest/534.aspx</guid>
</item>
<item>
<title>Windows Desktop Admin Rights – An Open Door for Malware?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/4/3/windows-desktop-admin-rights--an-open-door-for-malware/533.aspx</link>
<description>&lt;p&gt;Quocirca has written extensively about privileged user management over the years, including two research reports &lt;a href=&quot;http://www.osirium.com/alpha-files/wp&quot;&gt;Conquering the sys-admin challenge&lt;/a&gt; in 2011 and &lt;a href=&quot;http://www.quocirca.com/reports/430/privileged-user-management--its-time-to- ...</description>
<pubDate>Tue, 03 Apr 2012 18:09:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/4/3/windows-desktop-admin-rights--an-open-door-for-malware/533.aspx</guid>
</item>
<item>
<title>OS X Malware: A Steady Trickle</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/26/os-x-malware-a-steady-trickle/529.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;color: #1f497d&quot;&gt;I&amp;rsquo;m guessing that the myth of OS X invulnerability to malware is pretty much busted by now: at any rate, there has been wave after wave of OS X-related malware reports in the past week or two. &lt;a href=&quot;http://nakedsecurity.sophos.com/2012/03/20/topless-supermode ...</description>
<pubDate>Mon, 26 Mar 2012 13:52:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/26/os-x-malware-a-steady-trickle/529.aspx</guid>
</item>
<item>
<title>Secure Cloud – Myth or Reality?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/19/secure-cloud--myth-or-reality/528.aspx</link>
<description>&lt;h5&gt;By Chris Hinkley&lt;/h5&gt;
&lt;p&gt;Cloud Security is not a myth. It can be achieved. The biggest hindrance on debunking this myth is for enterprise businesses to begin thinking about the Cloud differently. It is not the equipment of co-location dedicated servers, or on-premises technology, as it is chang ...</description>
<pubDate>Mon, 19 Mar 2012 17:36:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/19/secure-cloud--myth-or-reality/528.aspx</guid>
</item>
<item>
<title>State and Local Governments Saying ‘Bye-bye’ to CISOs?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/17/state-and-local-governments-saying-byebye-to-cisos/527.aspx</link>
<description>&lt;h5&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;At a recent &lt;a href=&quot;http://www.governing.com/events/Outlook-in-the-States--Localities-Conference-2012.html?p=agenda&quot;&gt;GOVERNING&lt;/a&gt; Conference in DC, s ...</description>
<pubDate>Sat, 17 Mar 2012 12:57:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/17/state-and-local-governments-saying-byebye-to-cisos/527.aspx</guid>
</item>
<item>
<title>OSX/Imuler: the Image-Conscious Trojan</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/16/osximuler-the-imageconscious-trojan/526.aspx</link>
<description>&lt;p&gt;Intego recently posted some &lt;a href=&quot;http://blog.intego.com/new-version-of-imuler-trojan-horse-masquerades-as-image-files/&quot;&gt;information on its blog&lt;/a&gt; concerning the Imuler information-stealing Trojan. The variant that Intego calls OSX/Imuler.C uses a different stealth/social engineering techniq ...</description>
<pubDate>Fri, 16 Mar 2012 17:08:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/16/osximuler-the-imageconscious-trojan/526.aspx</guid>
</item>
<item>
<title>Reducing the Number of Sys-admin Errors</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/14/reducing-the-number-of-sysadmin-errors/525.aspx</link>
<description>&lt;p&gt;In recent &lt;a href=&quot;http://www.osirium.com/alpha-files/wp&quot;&gt;Quocirca research&lt;/a&gt;, businesses report that on average their system administrators (sys-admins) make errors carrying out about 6% of tasks. This might not sound like much, but actually it adds up to quite a big number.&lt;/p&gt;
&lt;div style=&quot;m ...</description>
<pubDate>Wed, 14 Mar 2012 08:42:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/14/reducing-the-number-of-sysadmin-errors/525.aspx</guid>
</item>
<item>
<title>Pennsylvania Voter ID Law: A Solution Without a Problem
</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/14/pennsylvania-voter-id-law-a-solution-without-a-problem/524.aspx</link>
<description>&lt;p&gt;I was driving home today from a conference on online copyright enforcement, and in case you missed our frenzy of Tweets ( &lt;a href=&quot;https://twitter.com/#!/InfosecurityMag&quot;&gt;#copyrightcitp&lt;/a&gt;) live from the event, I promise to write more about it in our upcoming news feature on anti-piracy legislat ...</description>
<pubDate>Wed, 14 Mar 2012 00:39:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/14/pennsylvania-voter-id-law-a-solution-without-a-problem/524.aspx</guid>
</item>
<item>
<title>Security Professionals Do Use AV: Even On Macs…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/12/security-professionals-do-use-av-even-on-macs/522.aspx</link>
<description>&lt;p&gt;I&amp;rsquo;m slightly surprised to realize it&amp;rsquo;s almost exactly a month since I blogged here, but I was travelling for a lot of that time (a slightly confusing mixture of work and vacation). Still, I&amp;rsquo;m pleased to see that an email conversation I had with Esther Shein about OS X, security, ...</description>
<pubDate>Mon, 12 Mar 2012 22:20:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/12/security-professionals-do-use-av-even-on-macs/522.aspx</guid>
</item>
<item>
<title>Seeing Through the Clouds: Gaining Confidence when Physical Access to Your Data Is Removed</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/12/seeing-through-the-clouds-gaining-confidence-when-physical-access-to-your-data-is-removed/520.aspx</link>
<description>&lt;h5&gt;By David Lingenfelter&lt;/h5&gt;
&lt;p&gt;Cloud computing brings with it new opportunities, new frontiers, new challenges, and new chances for loss of intellectual property.  From hosting simple websites, to entire development environments, companies have been experimenting with cloud-based services for so ...</description>
<pubDate>Mon, 12 Mar 2012 19:44:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/12/seeing-through-the-clouds-gaining-confidence-when-physical-access-to-your-data-is-removed/520.aspx</guid>
</item>
<item>
<title>Lock Box: Where Should You Store Cloud Encryption Keys?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/12/lock-box-where-should-you-store-cloud-encryption-keys/519.aspx</link>
<description>&lt;h5&gt;By Todd Thiemann&lt;/h5&gt;
&lt;p&gt;Whether driven by regulatory compliance or corporate mandates, sensitive data in the cloud needs protection along with access control. This usually involves encrypting data in transit as well as data at rest in some way, shape or form, and then managing the encryption k ...</description>
<pubDate>Mon, 12 Mar 2012 19:07:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/12/lock-box-where-should-you-store-cloud-encryption-keys/519.aspx</guid>
</item>
<item>
<title>Organisations Failing to Close-off the Risks of Legacy Privileged Accounts</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/7/organisations-failing-to-closeoff-the-risks-of-legacy-privileged-accounts/516.aspx</link>
<description>&lt;p&gt;If you are trying to compromise an organisation&amp;rsquo;s IT systems in some way, then you need to have access. Getting a given user&amp;rsquo;s log in details is a starting point but might not get you that far, unless they are a user with privilege. Privileged users have much wider ranging access than ...</description>
<pubDate>Wed, 07 Mar 2012 12:41:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/7/organisations-failing-to-closeoff-the-risks-of-legacy-privileged-accounts/516.aspx</guid>
</item>
<item>
<title>Facing Up to the Application Security Challenge</title>
<link>http://www.infosecurity-magazine.com/blog/2012/3/2/facing-up-to-the-application-security-challenge/514.aspx</link>
<description>&lt;div style=&quot;margin-bottom: 0.0001pt;&quot;&gt;A new Quocirca report underlines the scale of the application security challenge faced by businesses. The average enterprise tracks around 500 mission critical applications, in financial services organisations it is closer to 800. The security challenge arises b ...</description>
<pubDate>Fri, 02 Mar 2012 12:49:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/3/2/facing-up-to-the-application-security-challenge/514.aspx</guid>
</item>
<item>
<title>Deprovisioning in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/23/deprovisioning-in-the-cloud/511.aspx</link>
<description>&lt;h5&gt;By Jon-Michael C. Brook&lt;/h5&gt;
&lt;p&gt;Let's be honest: how many of you have tried logging in to one of your former employer&amp;rsquo;s accounts?  Maybe you had a CRM solution and you wanted to get the name of that guy who suggested he had the next hot idea.  You didn't set your out-of-office message wit ...</description>
<pubDate>Thu, 23 Feb 2012 20:20:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/23/deprovisioning-in-the-cloud/511.aspx</guid>
</item>
<item>
<title>Horror from Beyond the Cloud (with caffeine)</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/23/horror-from-beyond-the-cloud-with-caffeine/510.aspx</link>
<description>&lt;p&gt;Let me tell you what the work of a reclusive horror writer and a morning cup of coffee can teach us about attitudes toward cloud computing.&lt;/p&gt;
&lt;p&gt;The horror writer is &lt;a href=&quot;http://en.wikipedia.org/wiki/HPLovecraft&quot;&gt;Howard Phillips Lovecraft&lt;/a&gt; (known by his initials &amp;ldquo;H.P.&amp;rdquo;). In  ...</description>
<pubDate>Thu, 23 Feb 2012 15:40:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/23/horror-from-beyond-the-cloud-with-caffeine/510.aspx</guid>
</item>
<item>
<title>Xerox and McAfee: A joint force to integrate security into the print world</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/17/xerox-and-mcafee-a-joint-force-to-integrate-security-into-the-print-world/508.aspx</link>
<description>&lt;p&gt;This blog post was written by Quocirca's print speciailst, Louella Ferandes&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;text-align: justify; &quot;&gt;Despite a continued reliance on printing, many businesses overlook print security in their overall approach to data protection. This may be set to change with the recent announc ...</description>
<pubDate>Fri, 17 Feb 2012 10:48:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/17/xerox-and-mcafee-a-joint-force-to-integrate-security-into-the-print-world/508.aspx</guid>
</item>
<item>
<title>Safe Authentication for Remote Sys-Admin Tasks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/15/safe-authentication-for-remote-sysadmin-tasks/506.aspx</link>
<description>&lt;p&gt;Not all systems administration (sys-admin) is done by people. Some applications need administrator access to communicate and make changes. Furthermore, remote management tasks are often carried out using pre-set procedures in sys-admin tools, for example the backup of branch office devices.&lt;/p&gt;
 ...</description>
<pubDate>Wed, 15 Feb 2012 15:56:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/15/safe-authentication-for-remote-sysadmin-tasks/506.aspx</guid>
</item>
<item>
<title>Malware: a Matter of Definition</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/13/malware-a-matter-of-definition/505.aspx</link>
<description>&lt;p&gt;Kurt Wismer has just put up a blog asking &lt;a href=&quot;http://anti-virus-rants.blogspot.com/2012/02/is-iphone-really-malware-free.html&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;is the iphone really malware free?&lt;/font&gt;&lt;/a&gt; (Don&amp;rsquo;t be put off by the trademark absence of capitalization). Wismer is not illiterate and ...</description>
<pubDate>Mon, 13 Feb 2012 18:33:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/13/malware-a-matter-of-definition/505.aspx</guid>
</item>
<item>
<title>Opportunity Knocks Once…</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/10/opportunity-knocks-once/504.aspx</link>
<description>&lt;h5&gt;By Henry St. Andre&lt;/h5&gt;
&lt;p&gt;In 1983, I was a young electrical engineering student, when I took a job working for a small long distance company in Phoenix, Arizona.  For me, Opportunity had Knocked and I had just opened the door on an amazing future.  In the world of communications, things were a ...</description>
<pubDate>Fri, 10 Feb 2012 20:00:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/10/opportunity-knocks-once/504.aspx</guid>
</item>
<item>
<title>What Can a Hacker Do with Stolen WiFi Credentials?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/3/what-can-a-hacker-do-with-stolen-wifi-credentials/502.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;Palatino Linotype&amp;quot;,&amp;quot;serif&amp;quot;&quot;&gt;Recently HTC acknowledged a vulnerability that can expose a user&amp;rsquo;s WiFi credentials, including the WiFi SSID and security passwords to a malicious app running on some of its Android phones. Th ...</description>
<pubDate>Fri, 03 Feb 2012 14:19:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/3/what-can-a-hacker-do-with-stolen-wifi-credentials/502.aspx</guid>
</item>
<item>
<title>Facebook Goes Public – Time to Pop the Privacy Champagne? </title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/2/facebook-goes-public--time-to-pop-the-privacy-champagne-/501.aspx</link>
<description>&lt;p&gt;First, please excuse me for letting my inner Archie Bunker vent a little. If you are anything like me, then you could care less about updating your Facebook page on an hourly basis. Sure, I have a page, but maintaining it is both a bore and a chore (pardon my weak rhyming scheme). What are even w ...</description>
<pubDate>Thu, 02 Feb 2012 19:46:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/2/facebook-goes-public--time-to-pop-the-privacy-champagne-/501.aspx</guid>
</item>
<item>
<title>Trustworthy Computing: Looking Back to Look Forward</title>
<link>http://www.infosecurity-magazine.com/blog/2012/2/1/trustworthy-computing-looking-back-to-look-forward/499.aspx</link>
<description>&lt;p&gt;Anniversaries are often a time to reflect on the past but also to look to the future. A major anniversary in the field of computer security was reached on the 15th of January this year. That date marked the 10th anniversary of Bill Gates' famous memo marking the start of Microsoft's &lt;a href=&quot;http ...</description>
<pubDate>Wed, 01 Feb 2012 17:14:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/2/1/trustworthy-computing-looking-back-to-look-forward/499.aspx</guid>
</item>
<item>
<title>iOS Jailbreaking: Does Absinthe Make the Heart Grow Fonder?</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/23/ios-jailbreaking-does-absinthe-make-the-heart-grow-fonder/496.aspx</link>
<description>&lt;p&gt;Kevin Townsend asked me for my opinion on iGadget jailbreaking, in the light of the recent release of Absinthe, a jailbreaking tool for the iPhone 4s and iPad 2. As a result, I&amp;rsquo;m quoted in a &lt;a href=&quot;http://www.infosecurity-magazine.com/view/23391/jailbreak-for-iphone-4s-released/&quot;&gt;useful a ...</description>
<pubDate>Mon, 23 Jan 2012 19:22:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/23/ios-jailbreaking-does-absinthe-make-the-heart-grow-fonder/496.aspx</guid>
</item>
<item>
<title>I Keep Getting Flashbacks</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/16/i-keep-getting-flashbacks/492.aspx</link>
<description>&lt;p&gt;2012 was looking quite quiet in Apple security terms up to now, but I see that the guys behind the &lt;a href=&quot;http://blog.eset.com/2011/09/27/new-apple-os-x-malware-fake-adobe-flash-installer&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;OSX/Flashback Trojan&lt;/font&gt;&lt;/a&gt; are quietly beavering away. No sooner had &amp;nbsp;Appl ...</description>
<pubDate>Mon, 16 Jan 2012 17:19:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/16/i-keep-getting-flashbacks/492.aspx</guid>
</item>
<item>
<title>10 Years of Trustworthy Computing at Microsoft</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/12/10-years-of-trustworthy-computing-at-microsoft/490.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://aka.ms/twcnext&quot;&gt;&lt;img width=&quot;148&quot; vspace=&quot;5&quot; height=&quot;148&quot; border=&quot;0&quot; src=&quot;http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-50-43-twcnext/1488.TwC_2D00_Tile_5F00_148x148_2D00_wShadow.png&quot; alt=&quot;TwC Next&quot; style=&quot;margin: 0px 1 ...</description>
<pubDate>Thu, 12 Jan 2012 19:58:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/12/10-years-of-trustworthy-computing-at-microsoft/490.aspx</guid>
</item>
<item>
<title>Casablanca in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/11/casablanca-in-the-cloud/489.aspx</link>
<description>&lt;p&gt;I thought &lt;a href=&quot;http://searchcloudcomputing.techtarget.com/news/2240102241/To-cloud-skeptics-Dont-diss-Dropbox&quot;&gt;this piece&lt;/a&gt;&amp;nbsp;by Jo Maitland over at SearchCloudComputing.com was interesting, because it so closely reflects the experiences of a large number of businesses faced with the spe ...</description>
<pubDate>Wed, 11 Jan 2012 19:41:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/11/casablanca-in-the-cloud/489.aspx</guid>
</item>
<item>
<title>Implications of Wi-Fi Protected Setup Vulnerability </title>
<link>http://www.infosecurity-magazine.com/blog/2012/1/9/implications-of-wifi-protected-setup-vulnerability-/488.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;Palatino Linotype&amp;quot;,&amp;quot;serif&amp;quot;&quot;&gt;&lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/12/29/enabling-wps-can-make-you-vulnerable/486.aspx&quot;&gt;After mentioning briefly&lt;/a&gt; about the recently discovered Wi-Fi Protected Setup (WPS) vulnerability due to certain design flaws in  ...</description>
<pubDate>Mon, 09 Jan 2012 14:38:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2012/1/9/implications-of-wifi-protected-setup-vulnerability-/488.aspx</guid>
</item>
<item>
<title>Enabling WPS Can Make You Vulnerable</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/29/enabling-wps-can-make-you-vulnerable/486.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;&quot;&gt;Adding to the users convenience, Wi-Fi is increasingly becoming a default capability of many consumer devices, including smartphones, printers, cameras, TVs, etc. to wirelessly share contents, access Internet or connect to a particular network. &amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div style=&quot;text-a ...</description>
<pubDate>Thu, 29 Dec 2011 16:29:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/29/enabling-wps-can-make-you-vulnerable/486.aspx</guid>
</item>
<item>
<title>10 Reasons to Migrate Off Windows XP</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/22/10-reasons-to-migrate-off-windows-xp/483.aspx</link>
<description>&lt;p&gt;I would like you to sit back, close your eyes and think about the year 2001. Think about how you used technology back then, how you used the Internet. Now, let&amp;rsquo;s take it a little bit further back in history and think of the year 2000. Just after we realized that the Year-2000-Problem was ha ...</description>
<pubDate>Thu, 22 Dec 2011 10:48:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/22/10-reasons-to-migrate-off-windows-xp/483.aspx</guid>
</item>
<item>
<title>Looking Into The Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/21/looking-into-the-cloud/482.aspx</link>
<description>&lt;p&gt;As we roll up to the end of the year it's usually time to start making predictions about what will happen next year. But since Drew and the team already did a &lt;a href=&quot;http://www.infosecurity-magazine.com/view/22567/2012-threat-predictions-an-industry-roundup/&quot;&gt;great job of that&lt;/a&gt;&amp;nbsp;I'll ins ...</description>
<pubDate>Wed, 21 Dec 2011 21:20:32 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/21/looking-into-the-cloud/482.aspx</guid>
</item>
<item>
<title>Holiday Prediction Presents: Mind Your Website’s Navigation Layer</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/19/holiday-prediction-presents-mind-your-websites-navigation-layer/480.aspx</link>
<description>&lt;p&gt;From time to time, I try to share some of our reader feedback via this blog, whether it is positive or negative. As each year draws to a close, our editorial inbox gets bombarded with threat predictions of all kinds for the upcoming year. Some are company-wide predictions, others come from indivi ...</description>
<pubDate>Mon, 19 Dec 2011 17:04:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/19/holiday-prediction-presents-mind-your-websites-navigation-layer/480.aspx</guid>
</item>
<item>
<title>Small Eruption in Peru*: Not Many Infected</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/19/small-eruption-in-peru-not-many-infected/479.aspx</link>
<description>&lt;p&gt;[This is probably my last article here for 2011. Compliments of the season to you all.]&lt;/p&gt;
&lt;p&gt;Inevitably, my attention was drawn last week to an article on Mich Kabay&amp;rsquo;s &lt;a href=&quot;http://infosecreviews.com/perception/&quot;&gt;&lt;font color=&quot;#800080&quot;&gt;Infosec Perception&lt;/font&gt;&lt;/a&gt; based on an essay by ...</description>
<pubDate>Mon, 19 Dec 2011 13:23:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/19/small-eruption-in-peru-not-many-infected/479.aspx</guid>
</item>
<item>
<title>Moving on Up   </title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/19/moving-on-up---/478.aspx</link>
<description>&lt;p&gt;&lt;strong&gt;Within industry circles, 2011 has become known as the year of the hack, or the year of the black hat if you prefer. &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Game-changing malware has exploded, proving that the critical national infrastructure is under threat and that cyber war and cyber espionage are very daunt ...</description>
<pubDate>Mon, 19 Dec 2011 11:31:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/19/moving-on-up---/478.aspx</guid>
</item>
<item>
<title>Should Cybersecurity be Treated as a Profession? Your Opinion Counts</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/16/should-cybersecurity-be-treated-as-a-profession-your-opinion-counts/477.aspx</link>
<description>&lt;h5&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;It takes many, many years for a business area of focus to emerge as a recognized profession. Certainly, cybersecurity is moving in that direction. How  ...</description>
<pubDate>Fri, 16 Dec 2011 14:45:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/16/should-cybersecurity-be-treated-as-a-profession-your-opinion-counts/477.aspx</guid>
</item>
<item>
<title>Giving Thanks to the Infosec Professionals </title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/giving-thanks-to-the-infosec-professionals-/476.aspx</link>
<description>&lt;p&gt;In what may qualify as a profound understatement, the past year has been challenging for security professionals across the globe. &lt;/p&gt;
&lt;p&gt;Much of what infosec professionals do goes unnoticed, except when things go wrong. And 2011 has had no shortage of these black-eye events. Allow me, however,  ...</description>
<pubDate>Wed, 14 Dec 2011 19:36:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/giving-thanks-to-the-infosec-professionals-/476.aspx</guid>
</item>
<item>
<title>Software Insecurity Thrives</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/software-insecurity-thrives/474.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The fourth half-yearly &lt;a href=&quot;http://www.infosecurity-magazine.com/view/22518/more-than-8-in-10-software-applications-fail-security-test-says-veracode/&quot;&gt;State of Software Security Report&lt;/a&gt; from cloud-based application security tester Veracode makes for painful reading. Based on ...</description>
<pubDate>Wed, 14 Dec 2011 13:02:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/software-insecurity-thrives/474.aspx</guid>
</item>
<item>
<title>Secure Disposal of Old IT Equipment</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/14/secure-disposal-of-old-it-equipment/473.aspx</link>
<description>&lt;p&gt;Network and security devices age just like any other IT equipment. As the IT industry moves toward 100 gigabit/second Ethernet and 100 megabit/second broadband connections, many existing devices will no longer cope with traffic volumes. The need to replace routers, firewalls, load-balancers, cont ...</description>
<pubDate>Wed, 14 Dec 2011 08:26:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/14/secure-disposal-of-old-it-equipment/473.aspx</guid>
</item>
<item>
<title>Implementing the Top 4 Defense Strategies</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/13/implementing-the-top-4-defense-strategies/472.aspx</link>
<description>&lt;p&gt;The Australian Defense Signals Directorate maintains a list of the &lt;a target=&quot;_blank&quot; href=&quot;http://www.dsd.gov.au/infosec/top35mitigationstrategies.htm&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Top 35 Mitigation Strategies&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; against targeted intrusions. This is just a reference to the top  ...</description>
<pubDate>Tue, 13 Dec 2011 13:57:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/13/implementing-the-top-4-defense-strategies/472.aspx</guid>
</item>
<item>
<title>Who Needs Hackers?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/12/who-needs-hackers/471.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;As a rule I don't comment on unproven allegations, but this time I'm breaking my rule. According to a District of New Hampshire indictment (&lt;a href=&quot;http://www.wired.com/images_blogs/threatlevel/2011/12/Indictment_Romanian-POS-Hackers.pdf&quot;&gt;downloadable from Wired&lt;/a&gt;), four Roman ...</description>
<pubDate>Mon, 12 Dec 2011 13:53:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/12/who-needs-hackers/471.aspx</guid>
</item>
<item>
<title>Carrier IQ: Not Just an Android Issue</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/carrier-iq-not-just-an-android-issue/469.aspx</link>
<description>&lt;p&gt;Unless you&amp;rsquo;re currently trekking through the Gobi, you&amp;rsquo;ve probably caught some of the fuss about Carrier IQ, accused of conduct resembling a rootkit more than legitimate logging. I think that some of the indignation has been a little overdone, as I commented &lt;a href=&quot;http://www.eweeke ...</description>
<pubDate>Thu, 01 Dec 2011 19:48:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/carrier-iq-not-just-an-android-issue/469.aspx</guid>
</item>
<item>
<title>Personal Data Exodus</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/personal-data-exodus/468.aspx</link>
<description>&lt;p&gt;I came across a couple of interesting stories this week, both of which are worth passing along.This first is from &lt;a href=&quot;http://www.geek.com/articles/mobile/security-researcher-responds-to-carrieriq-with-video-proof-20111129/&quot;&gt;geek.com&lt;/a&gt;&amp;nbsp;and is the latest in an &lt;a href=&quot;http://www.geek.c ...</description>
<pubDate>Thu, 01 Dec 2011 15:55:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/personal-data-exodus/468.aspx</guid>
</item>
<item>
<title> A critical software problem for banks</title>
<link>http://www.infosecurity-magazine.com/blog/2011/12/1/-a-critical-software-problem-for-banks/467.aspx</link>
<description>&lt;div style=&quot;margin-bottom: 0.0001pt;&quot;&gt;New Quocirca research (sponsored by on-demand software code security specialist, Veracode) underlines a problem faced by financial services organisations when it comes to security and compliance; they track getting on for twice as many critical software applicat ...</description>
<pubDate>Thu, 01 Dec 2011 10:35:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/12/1/-a-critical-software-problem-for-banks/467.aspx</guid>
</item>
<item>
<title>Cloud Security:  An Oxymoron?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/29/cloud-security--an-oxymoron/465.aspx</link>
<description>&lt;h5&gt;By Torsten George&lt;/h5&gt;
&lt;p&gt;Cloud computing represents today's big innovation trend in the information technology (IT) space. Because it allows organizations to deploy quickly, move swiftly, and share resources, cloud computing is rapidly replacing conventional in-house facilities at organization ...</description>
<pubDate>Tue, 29 Nov 2011 19:21:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/29/cloud-security--an-oxymoron/465.aspx</guid>
</item>
<item>
<title>The UK Cyber Security Strategy – is this really progress?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/29/the-uk-cyber-security-strategy--is-this-really-progress/464.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;A &lt;a href=&quot;http://www.cabinetoffice.gov.uk/sites/default/files/resources/The%20UK%20Cyber%20Security%20Strategy-%20web%20ver.pdf&quot;&gt;UK Cyber Security Strategy&lt;/a&gt; has just been released by the Cabinet Office. The first thing I noted was that seven of its 43 pages are have a solid c ...</description>
<pubDate>Tue, 29 Nov 2011 12:28:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/29/the-uk-cyber-security-strategy--is-this-really-progress/464.aspx</guid>
</item>
<item>
<title>Council of Europe Octopus Conference- Some Thoughts</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/23/council-of-europe-octopus-conference-some-thoughts/462.aspx</link>
<description>&lt;p&gt;l am still sitting in the parliament room of the &lt;a href=&quot;http://www.coe.int/t/DGHL/cooperation/economiccrime/cybercrime/cy_Octopus_Interface_2011/Interface2011_en.asp&quot;&gt;Council of Europe at the celebration event for the Budapest Convention&lt;/a&gt;. It was another very good event advancing the challen ...</description>
<pubDate>Wed, 23 Nov 2011 11:38:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/23/council-of-europe-octopus-conference-some-thoughts/462.aspx</guid>
</item>
<item>
<title>Google’s Approach of a “_NOMAP” Wi-Fi ZONE</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/20/googles-approach-of-a-nomap-wifi-zone/460.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;&quot;&gt;&lt;a href=&quot;http://googleblog.blogspot.com/2011/11/greater-choice-for-wireless-access.html&quot;&gt;Google recently announced an approach&lt;/a&gt; to provide Wi-Fi Access Point owners an option to opt-out from the Google Location server, thereby addressing specific privacy concerns of certain Acce ...</description>
<pubDate>Sun, 20 Nov 2011 11:07:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/20/googles-approach-of-a-nomap-wifi-zone/460.aspx</guid>
</item>
<item>
<title>iPaddling in Corporate Waters</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/18/ipaddling-in-corporate-waters/459.aspx</link>
<description>&lt;p&gt;&lt;em&gt;Computer Weekly&lt;/em&gt;, in an article I mentioned in my previous blog here, notes that Tablet device ownership among mobile employees increased from 33% in the second quarter of 2011 to 44%.That statistic dovetails quite neatly with a study from ComScore on&lt;span style=&quot;color: #1f497d&quot;&gt; &lt;a href= ...</description>
<pubDate>Fri, 18 Nov 2011 11:35:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/18/ipaddling-in-corporate-waters/459.aspx</guid>
</item>
<item>
<title>Goodbye Blackberry Way?*</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/18/goodbye-blackberry-way/458.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.computerweekly.com/news/2240111024/Blackberry-grip-on-enterprise-snatched-by-Apple-iPhone&quot;&gt;iPass tells us&lt;/a&gt;&amp;nbsp;that a recent survey (n = 2,300) indicated that the iPhone now has 45% marketshare in the enterprise, whereas use of the Blackberry is down (slightly) to 35%. Whi ...</description>
<pubDate>Fri, 18 Nov 2011 10:50:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/18/goodbye-blackberry-way/458.aspx</guid>
</item>
<item>
<title>Cyber War Will Not Take Place</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/17/cyber-war-will-not-take-place/457.aspx</link>
<description>&lt;p&gt;I have to admit &amp;ndash; it is not my title but it caught my attention. Over the course of the last few years, the term &amp;ldquo;Cyberwar&amp;rdquo; came up all over the place. I was recently reading a book on it, where there was a chapter called &amp;ldquo;Definition of Cyberwar&amp;rdquo; and I thought that f ...</description>
<pubDate>Thu, 17 Nov 2011 10:39:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/17/cyber-war-will-not-take-place/457.aspx</guid>
</item>
<item>
<title>Auditors want to know about individuals, not groups</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/auditors-want-to-know-about-individuals-not-groups/456.aspx</link>
<description>&lt;p&gt;&amp;nbsp;It is pretty obvious that to audit the use of IT resources and applications you need to know who is doing what. This is especially true when it comes to system administrators (sys-admins) who are operating with increased levels of privilege.&lt;/p&gt;
&lt;div style=&quot;margin-bottom: 0.0001pt;&quot;&gt;&amp;nbsp; ...</description>
<pubDate>Wed, 16 Nov 2011 11:24:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/auditors-want-to-know-about-individuals-not-groups/456.aspx</guid>
</item>
<item>
<title>Cloud Security Considerations – a different view</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/cloud-security-considerations--a-different-view/455.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Yesterday, looking at my RSS-Feed I saw the post in here called &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/11/14/cloud-security-considerations/452.aspx&quot;&gt;Cloud Security Considerations&lt;/a&gt; &amp;ndash; and immediately wanted to read it as we (a friend of mine and me) wrote  ...</description>
<pubDate>Wed, 16 Nov 2011 11:07:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/cloud-security-considerations--a-different-view/455.aspx</guid>
</item>
<item>
<title>Cyberespionage: The Chinese State of Denial</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/16/cyberespionage-the-chinese-state-of-denial/453.aspx</link>
<description>&lt;p&gt;Today I spoke with Roger Cressey, a cybersecurity and counterterrorism expert for both the Clinton and Bush administrations, and now a senior VP with Booz Allen Hamilton. I asked him if he was equally amused by the Chinese government&amp;rsquo;s continuous denials that hackers within its borders acti ...</description>
<pubDate>Wed, 16 Nov 2011 01:28:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/16/cyberespionage-the-chinese-state-of-denial/453.aspx</guid>
</item>
<item>
<title>Cloud Security Considerations</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/14/cloud-security-considerations/452.aspx</link>
<description>&lt;h5&gt;By Ken Biery&lt;/h5&gt;
&lt;p&gt;Can a cloud be as secure as a traditional network?  In a word, yes!  I agree that some may find this statement surprising.  Depending on the network, that may be a low bar, but good security principles and approaches are just as applicable to cloud environments as they are  ...</description>
<pubDate>Mon, 14 Nov 2011 18:59:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/14/cloud-security-considerations/452.aspx</guid>
</item>
<item>
<title>How to Manage “Bring Your Own Device”</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/10/how-to-manage-bring-your-own-device/451.aspx</link>
<description>&lt;p&gt;Long time since I&amp;nbsp;blogged. It is time to &amp;quot;come back :-)&amp;quot;. The kick was that I&amp;nbsp;started to work on a Windows 8 Slate as a secondary PC and thought about the consumerization scenario once more:&lt;/p&gt;
&lt;p&gt;A few years back a customer&amp;rsquo;s CSO left the room when I said that this cu ...</description>
<pubDate>Thu, 10 Nov 2011 14:32:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/10/how-to-manage-bring-your-own-device/451.aspx</guid>
</item>
<item>
<title>Apple Content in Infosecurity Virtual Conference</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/7/apple-content-in-infosecurity-virtual-conference/448.aspx</link>
<description>&lt;p&gt;It occurs to me that something (else) I haven't mentioned here is that &lt;em&gt;Infosecurity&lt;/em&gt; magazine is running one of its &lt;a target=&quot;_blank&quot; href=&quot;http://bit.ly/qHW5LI&quot;&gt;&lt;font color=&quot;#7f1d1d&quot;&gt;virtual conferences&lt;/font&gt;&lt;/a&gt; on November 8th, with the virtual doors opening at 10.30 EST. If you're i ...</description>
<pubDate>Mon, 07 Nov 2011 19:01:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/7/apple-content-in-infosecurity-virtual-conference/448.aspx</guid>
</item>
<item>
<title>What the Devil(Robber)? </title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/7/what-the-devilrobber-/447.aspx</link>
<description>&lt;p&gt;It occurs to me that while I &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/10/28/osxtsunami-flooding-new-markets/439.aspx&quot;&gt;wrote here&lt;/a&gt; about the interesting but apparently work-in-progress OSX/Tsunami (or Kaiten) port from Linux to OSX a while back, I haven't had the chance to mentio ...</description>
<pubDate>Mon, 07 Nov 2011 18:52:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/7/what-the-devilrobber-/447.aspx</guid>
</item>
<item>
<title>Leveraging Managed Cloud Services to Meet Cloud Compliance Challenges</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/4/leveraging-managed-cloud-services-to-meet-cloud-compliance-challenges/446.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;p&gt;Regardless of your industry, customer base, or product, it is highly likely that you face regulatory compliance requirements.  If you handle Protected Health Information (PHI), the Health Insurance Portability and Accountability Act (HIPAA) &amp;ndash; along with the HITECH ...</description>
<pubDate>Fri, 04 Nov 2011 18:33:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/4/leveraging-managed-cloud-services-to-meet-cloud-compliance-challenges/446.aspx</guid>
</item>
<item>
<title>Cloud Security:  Confident, Fearful, or Surprised?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/4/cloud-security--confident-fearful-or-surprised/445.aspx</link>
<description>&lt;h5&gt;By Ken Biery&lt;/h5&gt;
&lt;p&gt;This two-part guest blog series explores the topic of cloud security.  Part one of the series focuses on the questions enterprise IT decision makers should ask when considering moving business applications to a cloud-based computing environment.&lt;/p&gt;
&lt;p&gt;There is no shortage ...</description>
<pubDate>Fri, 04 Nov 2011 18:10:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/4/cloud-security--confident-fearful-or-surprised/445.aspx</guid>
</item>
<item>
<title>IT security vendors can’t all be right, but they can all be wrong</title>
<link>http://www.infosecurity-magazine.com/blog/2011/11/1/it-security-vendors-cant-all-be-right-but-they-can-all-be-wrong/443.aspx</link>
<description>&lt;p&gt;From recent briefings with a number of IT security vendors it would seem that most can now identify any new threat immediately and that at the same time none of them can. This contradiction is down to the &amp;ldquo;&lt;i&gt;we can, they can&amp;rsquo;t&lt;/i&gt;&amp;rdquo; mantra that any vendor of any product is bound ...</description>
<pubDate>Tue, 01 Nov 2011 09:16:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/11/1/it-security-vendors-cant-all-be-right-but-they-can-all-be-wrong/443.aspx</guid>
</item>
<item>
<title>Attacking the Human Wall</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/28/attacking-the-human-wall/441.aspx</link>
<description>&lt;p&gt;Good post &lt;a href=&quot;https://www.brandenwilliams.com/blog/2011/10/11/attack-the-humans-first/&quot;&gt;here &lt;/a&gt;from Brandon Williams on the inherent weakness of security processes that ignores the human element.&lt;/p&gt;
&lt;p&gt;There's nothing new in saying that humans are the weakest link in the security chain ( ...</description>
<pubDate>Fri, 28 Oct 2011 22:31:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/28/attacking-the-human-wall/441.aspx</guid>
</item>
<item>
<title>The 1985 iPhone In a Truck</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/28/the-1985-iphone-in-a-truck/440.aspx</link>
<description>&lt;p&gt;&amp;nbsp;People of a certain age often enjoy recalling for younger folk the size of the early mobile phones that were lugged around in the mid-1980s, whilst marvelling at the latest smartphones. These brick-sized devices could not even send text (SMS) messages (the first of which was sent in 1992);  ...</description>
<pubDate>Fri, 28 Oct 2011 07:59:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/28/the-1985-iphone-in-a-truck/440.aspx</guid>
</item>
<item>
<title>OSX/Tsunami: flooding new markets</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/28/osxtsunami-flooding-new-markets/439.aspx</link>
<description>&lt;p&gt;Matt Hartley asks the question &amp;ldquo;&lt;a href=&quot;http://www.datamation.com/open-source/linux-malware-are-we-there-yet-1.html&quot;&gt;Linux Malware: Are We There Yet&lt;/a&gt;?&amp;rdquo;&amp;nbsp; It seems strange, after so much exposure to the view that OS X is intrinsically so much safer than Windows, to read a piece ...</description>
<pubDate>Fri, 28 Oct 2011 01:03:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/28/osxtsunami-flooding-new-markets/439.aspx</guid>
</item>
<item>
<title>Consumers Say No (to data leaks)</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/25/consumers-say-no-to-data-leaks/436.aspx</link>
<description>&lt;p&gt;A recent Quocirca &lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2011/9/16/responsible-data-leak-disclosure/407.aspx&quot;&gt;blog post&lt;/a&gt; pointed out there were good business reasons for disclosing data breaches as well as an increasing number of regulatory ones. For those organisations not convinc ...</description>
<pubDate>Tue, 25 Oct 2011 08:14:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/25/consumers-say-no-to-data-leaks/436.aspx</guid>
</item>
<item>
<title>Don’t Forget the Network</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/21/dont-forget-the-network/435.aspx</link>
<description>&lt;p&gt;A &lt;a href=&quot;http://www.newscientist.com/article/mg21128324.700-light-is-not-fast-enough-for-highspeed-stock-trading.html&quot;&gt;recent news story in &lt;em&gt;New Scientist&lt;/em&gt;&lt;/a&gt; reminds us how important the speed of network communications has become for some organisations:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;helli ...</description>
<pubDate>Fri, 21 Oct 2011 09:36:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/21/dont-forget-the-network/435.aspx</guid>
</item>
<item>
<title>“Testing the Testers”: Certification and Cloud Computing</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/19/testing-the-testers-certification-and-cloud-computing/433.aspx</link>
<description>&lt;h5&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Cloud computing is becoming ubiquitous throughout the federal government, and while the adoption of this technology may be more widespre ...</description>
<pubDate>Wed, 19 Oct 2011 23:07:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/19/testing-the-testers-certification-and-cloud-computing/433.aspx</guid>
</item>
<item>
<title>Avoiding (awful) bad practice at audit time</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/18/avoiding-awful-bad-practice-at-audit-time/432.aspx</link>
<description>&lt;p&gt;Quocirca saw an estimate recently that IT security managers can spend as much as 30% of their time preparing for and delivering audits. This is mundane and uninteresting work and if it can be automated &amp;ndash; all the better. However, recent Quocirca research, sponsored by sys-admin tools vendor  ...</description>
<pubDate>Tue, 18 Oct 2011 16:54:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/18/avoiding-awful-bad-practice-at-audit-time/432.aspx</guid>
</item>
<item>
<title>Social Engineering: A Real Persistent Threat</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/15/social-engineering-a-real-persistent-threat/431.aspx</link>
<description>&lt;p&gt;I hear a great deal about 0-day attacks, and a great deal of security vendor PR is (depending on market sector) predicated on the assumption that 0-days are the most prevalent threat. Notwithstanding some highly visible 0-day attacks over the years, I don&amp;rsquo;t believe that to be true.&lt;/p&gt;
&lt;di ...</description>
<pubDate>Sat, 15 Oct 2011 14:12:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/15/social-engineering-a-real-persistent-threat/431.aspx</guid>
</item>
<item>
<title>Failing PCI Policy?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/13/failing-pci-policy/430.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.verizonbusiness.com/resources/reports/rp_2011-payment-card-industry-compliance-report_en_xg.pdf&quot;&gt;This is a good read &lt;/a&gt;if you missed it&amp;nbsp;&amp;ndash; the most recent report by the ever-interesting Verizon PCI and Risk Intelligence Teams on the state of PCI Compliance.&lt;/p&gt;
&lt;p ...</description>
<pubDate>Thu, 13 Oct 2011 20:34:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/13/failing-pci-policy/430.aspx</guid>
</item>
<item>
<title>Goodnight Irene: A Lesson in Disaster Planning</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/13/goodnight-irene-a-lesson-in-disaster-planning/429.aspx</link>
<description>&lt;p&gt;Many large organizations make preparations for disaster, but the recent hurricane that hit the East Coast of the US illustrates why long-term business continuity planning on a local level can be critical to survival &amp;ndash; and your employees&amp;rsquo; well being.&lt;/p&gt;
&lt;p&gt;While much of what we cover ...</description>
<pubDate>Thu, 13 Oct 2011 18:22:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/13/goodnight-irene-a-lesson-in-disaster-planning/429.aspx</guid>
</item>
<item>
<title>Virus Bulletin and the Mac, then and now</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/12/virus-bulletin-and-the-mac-then-and-now/427.aspx</link>
<description>&lt;p&gt;Last week I was in Barcelona for this year's &lt;a href=&quot;http://www.virusbtn.com/conference/vb2011&quot;&gt;Virus Bulletin conference&lt;/a&gt; (the 21st, which makes me feel very old even though I wasn't there at the beginning!). The first time I presented there was in 1997, when &lt;a href=&quot;http://macviruscom.file ...</description>
<pubDate>Wed, 12 Oct 2011 18:33:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/12/virus-bulletin-and-the-mac-then-and-now/427.aspx</guid>
</item>
<item>
<title>False Sense of Security among WiFi Users</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/11/false-sense-of-security-among-wifi-users/425.aspx</link>
<description>&lt;div style=&quot;text-align:justify&quot;&gt;&lt;a href=&quot;http://www.wi-fi.org/news_articles.php?f=media_news&amp;amp;news_id=1085&quot;&gt;A recent survey conducted by Wakefield Research&lt;/a&gt; for the WiFi Alliance has revealed that 97% of surveyed WiFi users believe that the data on their devices and networks is &amp;ldquo;safe and ...</description>
<pubDate>Tue, 11 Oct 2011 16:00:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/11/false-sense-of-security-among-wifi-users/425.aspx</guid>
</item>
<item>
<title>Test Accounts:  Another Compliance Risk</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/7/test-accounts--another-compliance-risk/424.aspx</link>
<description>&lt;h5&gt;By Merritt Maximi&lt;/h5&gt;
&lt;p&gt;A major benefit associated with deploying identity management and/or identity governance into an organization is that these solutions provide the ability to detect and remove orphan accounts.  Orphan accounts refer to active accounts belonging to a user who is no longe ...</description>
<pubDate>Fri, 07 Oct 2011 20:14:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/7/test-accounts--another-compliance-risk/424.aspx</guid>
</item>
<item>
<title>HyperCard Viruses? You're History!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/10/3/hypercard-viruses-youre-history/422.aspx</link>
<description>&lt;p&gt;I see that Graham Cluley has revised his excellent timeline&amp;nbsp;article &lt;a data-mce-href=&quot;http://nakedsecurity.sophos.com/2011/10/03/mac-malware-history/&quot; rel=&quot;bookmark&quot; href=&quot;http://nakedsecurity.sophos.com/2011/10/03/mac-malware-history/&quot; title=&quot;Permalink to The short history of Mac malware: 1 ...</description>
<pubDate>Mon, 03 Oct 2011 15:07:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/10/3/hypercard-viruses-youre-history/422.aspx</guid>
</item>
<item>
<title>When It Comes To Cloud Security, Don’t Forget SSL</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/30/when-it-comes-to-cloud-security-dont-forget-ssl/421.aspx</link>
<description>&lt;h5&gt;By Michael Lin, Symantec&lt;/h5&gt;
&lt;p&gt;Cloud computing appears here to stay, bringing with it new challenges and security risks on one hand, while on the other hand boasting efficiencies, cost savings and competitive advantage. With the new security risks of cloud and the mounting skill and cunning o ...</description>
<pubDate>Fri, 30 Sep 2011 19:04:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/30/when-it-comes-to-cloud-security-dont-forget-ssl/421.aspx</guid>
</item>
<item>
<title>Securing Your File Transfer in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/30/securing-your-file-transfer-in-the-cloud/420.aspx</link>
<description>&lt;h5&gt;By Stuart Lisk&lt;/h5&gt;
&lt;p&gt;File transfer has been around since the beginning of time. Ok, well maybe that is an exaggeration, but the point is, file transfer was one of the earliest uses of &amp;ldquo;network&amp;rdquo; computing dating back to the early 1970&amp;rsquo;s when IBM introduced the floppy disk. Wh ...</description>
<pubDate>Fri, 30 Sep 2011 19:00:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/30/securing-your-file-transfer-in-the-cloud/420.aspx</guid>
</item>
<item>
<title>Apple Raises the &quot;Anti&quot; for Revir, but Intego gets Flashbacks</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/27/apple-raises-the-anti-for-revir-but-intego-gets-flashbacks/417.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.h-online.com/security/news/item/Apple-updates-malware-definition-list-to-defend-against-PDF-trojan-1350430.html&quot;&gt;The H&lt;/a&gt; (Heise) reported today that Apple has added detection for OSX/Revir to its XProtect facility, provided&amp;nbsp;in OS&amp;nbsp;X versions since Snow Leopard.&lt;/p&gt; ...</description>
<pubDate>Tue, 27 Sep 2011 18:16:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/27/apple-raises-the-anti-for-revir-but-intego-gets-flashbacks/417.aspx</guid>
</item>
<item>
<title>Revir's Ride not a Derby Winner</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/26/revirs-ride-not-a-derby-winner/415.aspx</link>
<description>&lt;p&gt;Since new Mac-specific malware is pretty rare, I suppose I can't really ignore the malware that most AV companies are calling Revir.A (the dropper and downloader) and Imuler.A (the backdoor that carries the sting, such as it is), though Sophos is calling it &lt;a href=&quot;http://nakedsecurity.sophos.co ...</description>
<pubDate>Mon, 26 Sep 2011 13:17:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/26/revirs-ride-not-a-derby-winner/415.aspx</guid>
</item>
<item>
<title>Insider Attack: Three Key Considerations</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/21/insider-attack-three-key-considerations/411.aspx</link>
<description>&lt;p&gt;&amp;ldquo;Insider attack&amp;rdquo; is back in the news, getting attention again, with good reason. This particular article, &amp;ldquo;&lt;a href=&quot;http://www.infosecurity-us.com/view/20811/insiders-increasingly-linked-to-data-breaches-in-the-financial-sector/&quot;&gt;Insiders increasingly linked to data breaches in  ...</description>
<pubDate>Wed, 21 Sep 2011 15:45:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/21/insider-attack-three-key-considerations/411.aspx</guid>
</item>
<item>
<title>Password Shadowing: The Lion Sleeps Tonight</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/20/password-shadowing-the-lion-sleeps-tonight/410.aspx</link>
<description>&lt;p&gt;Patrick Dunstan has put up a disquieting &lt;a href=&quot;http://www.defenceindepth.net/2011/09/cracking-os-x-lion-passwords.html&quot;&gt;post on Defence in Depth&lt;/a&gt;, following up on a &lt;a href=&quot;http://www.defenceindepth.net/2009/12/cracking-os-x-passwords.html&quot;&gt;2009 blog post&lt;/a&gt; on cracking OS X passwords. No ...</description>
<pubDate>Tue, 20 Sep 2011 20:42:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/20/password-shadowing-the-lion-sleeps-tonight/410.aspx</guid>
</item>
<item>
<title>OMG! TLS! You BEAST!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/20/omg-tls-you-beast/409.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;A couple of security researchers are due to present a way to compromise TLS 1.0 at a &lt;a href=&quot;http://ekoparty.org/cronograma.php&quot;&gt;conference in Argentina&lt;/a&gt; &amp;nbsp;next week (scroll to end of page). Thai Duong and Juliano Rizzo have found a way - codenamed &amp;quot;BEAST&amp;quot; - to  ...</description>
<pubDate>Tue, 20 Sep 2011 08:06:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/20/omg-tls-you-beast/409.aspx</guid>
</item>
<item>
<title>Responsible Data Leak Disclosure</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/16/responsible-data-leak-disclosure/407.aspx</link>
<description>&lt;p&gt;There has been plenty written, not least by Quocirca, on the danger of data loss and how to prevent it. Less has been said about how to clear up afterwards; when the measures taken to protect a business from such losses have failed or were not present in the first place. In particular the respons ...</description>
<pubDate>Fri, 16 Sep 2011 12:48:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/16/responsible-data-leak-disclosure/407.aspx</guid>
</item>
<item>
<title>The “Don’t Trust Model” of Cloud Computing</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/14/the-dont-trust-model-of-cloud-computing/406.aspx</link>
<description>&lt;h5&gt;By&amp;nbsp;Ed King&lt;/h5&gt;
&lt;p&gt;The elephant in the room when it comes to barriers to the growth and adoption of cloud computing by enterprises is the lack of trust held for cloud service providers.  Enterprise IT has legitimate concerns over the security, integrity, and reliability of cloud-based serv ...</description>
<pubDate>Wed, 14 Sep 2011 20:03:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/14/the-dont-trust-model-of-cloud-computing/406.aspx</guid>
</item>
<item>
<title>Marketing and Upgrades</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/13/marketing-and-upgrades/404.aspx</link>
<description>&lt;p&gt;Jonny Evans has made some interesting points at &lt;a href=&quot;http://blogs.computerworld.com/18927/has_apple_handled_the_diginotar_attack_effectively&quot;&gt;Computer World&lt;/a&gt;&amp;nbsp;regarding Apple's belated removal of DigiNotar root certificates from OS&amp;nbsp;X (specifically Lion and Snow Leopard). Clearly,  ...</description>
<pubDate>Tue, 13 Sep 2011 17:24:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/13/marketing-and-upgrades/404.aspx</guid>
</item>
<item>
<title>Seven Steps to Securing File Transfer’s Journey to the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/12/seven-steps-to-securing-file-transfers-journey-to-the-cloud/402.aspx</link>
<description>&lt;h5&gt;By Oded Valin&lt;/h5&gt;
&lt;p&gt;&amp;ldquo;When it absolutely, positively has to be there overnight.&amp;rdquo;  There&amp;rsquo;s a lot we can identify with when it comes to reciting FedEx&amp;rsquo;s famous slogan, especially as it relates to modern file transfer processes. When you think about sharing health care rec ...</description>
<pubDate>Mon, 12 Sep 2011 19:58:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/12/seven-steps-to-securing-file-transfers-journey-to-the-cloud/402.aspx</guid>
</item>
<item>
<title>Now You See It, Now You Don't...</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/7/now-you-see-it-now-you-dont/399.aspx</link>
<description>&lt;p&gt;Apple security, that is.&lt;/p&gt;
&lt;p&gt;Clearly, the company's &lt;a href=&quot;http://jobs.apple.com/index.ajs?BID=1&amp;amp;method=mExternal.showJob&amp;amp;RID=91081&amp;amp;CurrentPage=1&quot;&gt;hiring&lt;/a&gt; of a product security manager carries a very clear &amp;quot;we need to improve&amp;quot; message, but it's clearly tied to a mar ...</description>
<pubDate>Wed, 07 Sep 2011 18:26:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/7/now-you-see-it-now-you-dont/399.aspx</guid>
</item>
<item>
<title>How Not to Secure a CA</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/7/how-not-to-secure-a-ca/397.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Fox-IT have published a preliminary report on the &lt;a href=&quot;http://infosecreviews.com/blog/?p=44&quot;&gt;DigiNotar breach&lt;/a&gt;. It appears that the number of spoofed certificates is much greater than previously suspected, and Iran was a prime target, so once again we may have an example o ...</description>
<pubDate>Wed, 07 Sep 2011 12:10:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/7/how-not-to-secure-a-ca/397.aspx</guid>
</item>
<item>
<title>How Signify weathered the RSA breach storm: Eleanor Dallaway chats to Dave Abraham, co-founder and CEO of Signify </title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/1/how-signify-weathered-the-rsa-breach-storm-eleanor-dallaway-chats-to-dave-abraham-cofounder-and-ceo-of-signify-/394.aspx</link>
<description>&lt;p&gt;
&lt;div&gt;Last week, I went to lunch with Dave Abraham, &lt;a href=&quot;http://www.infosecurity-magazine.com/view/19461/signify-moves-2fa-onto-android-smartphones-and-tablets&quot;&gt;co-founder and CEO of Signify,&lt;/a&gt; an information security company that delivers two-factor authentication.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div ...</description>
<pubDate>Thu, 01 Sep 2011 11:50:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/1/how-signify-weathered-the-rsa-breach-storm-eleanor-dallaway-chats-to-dave-abraham-cofounder-and-ceo-of-signify-/394.aspx</guid>
</item>
<item>
<title>Don’t let your brand name be flushed away</title>
<link>http://www.infosecurity-magazine.com/blog/2011/9/1/dont-let-your-brand-name-be-flushed-away/392.aspx</link>
<description>&lt;p&gt;&amp;nbsp;A snippet in Private Eye earlier this year (July 8&lt;sup&gt;th&lt;/sup&gt;, 2011) showed how touchy companies can get about the use of their brand names. Following the unfortunate death of a festival goer in a toilet at Glastonbury (who also happened to be political activist and friend of the UK&amp;rsquo ...</description>
<pubDate>Thu, 01 Sep 2011 08:12:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/9/1/dont-let-your-brand-name-be-flushed-away/392.aspx</guid>
</item>
<item>
<title>Comex: Scrumper turned Gamekeeper</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/26/comex-scrumper-turned-gamekeeper/391.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;font-size: 9pt&quot;&gt;So can I resist the temptation to blog about the departure of Steve Jobs? Well, yes, though I wish Jobs, his successor, and the company well. But I'm not really qualified to add to the flurry of business analysis that has preoccupied the media since the announcement.  ...</description>
<pubDate>Fri, 26 Aug 2011 20:30:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/26/comex-scrumper-turned-gamekeeper/391.aspx</guid>
</item>
<item>
<title>Five Ways to Achieve Cloud Compliance</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/26/five-ways-to-achieve-cloud-compliance/390.aspx</link>
<description>&lt;h5&gt;By Allen Allison &lt;/h5&gt;
&lt;p&gt;With the rapid adoption of cloud computing technologies, IT organizations have found a way to deliver applications and services more quickly and efficiently to their customers, incorporating the nearly ubiquitous utility-like platforms of managed cloud services compani ...</description>
<pubDate>Fri, 26 Aug 2011 19:27:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/26/five-ways-to-achieve-cloud-compliance/390.aspx</guid>
</item>
<item>
<title>Earthquakes and Cloud Servers</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/24/earthquakes-and-cloud-servers/389.aspx</link>
<description>&lt;p&gt;It was at about 2 PM when I had settled into my chair to begin moderating our latest webinar on securing cloud servers. Not far into my introductions, I noticed a bit of a rumble beneath my feet, as if someone where taking a jackhammer to the ceiling on the floor below. It was a slight hum at fir ...</description>
<pubDate>Wed, 24 Aug 2011 20:03:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/24/earthquakes-and-cloud-servers/389.aspx</guid>
</item>
<item>
<title>My gift to you: Attend a world-class information security conference in your slippers! </title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/23/my-gift-to-you-attend-a-worldclass-information-security-conference-in-your-slippers-/388.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;It's that time of year again. As the rain cruelly chucks itself at our office windows in Richmond, I'm reminded that summer (or what we've had of it) is starting to surrender itself to Autumn, which means that our &lt;a href=&quot;http://www.infosecurity-magazine.com/virtualconference/20 ...</description>
<pubDate>Tue, 23 Aug 2011 15:41:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/23/my-gift-to-you-attend-a-worldclass-information-security-conference-in-your-slippers-/388.aspx</guid>
</item>
<item>
<title>Dropping In</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/22/dropping-in/387.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.stjernstrom.com&quot;&gt;Magnus Stjernstrom&amp;nbsp;&lt;/a&gt;recently pointed out Cisco&amp;rsquo;s advice on how to &lt;a href=&quot;http://tools.cisco.com/security/center/viewAlert.x?alertId=23896&quot;&gt;detect Dropbox traffic &lt;/a&gt;originating in your network.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s interesting given what it tell ...</description>
<pubDate>Mon, 22 Aug 2011 14:47:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/22/dropping-in/387.aspx</guid>
</item>
<item>
<title>So, What Makes You a Cyber ‘Expert’?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/22/so-what-makes-you-a-cyber-expert/386.aspx</link>
<description>&lt;h5&gt;
&lt;title&gt;&lt;/title&gt;
By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/h5&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;How many cybersecurity practitioners have had a colleague either in information technology (IT), or worse yet, from a ...</description>
<pubDate>Mon, 22 Aug 2011 13:25:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/22/so-what-makes-you-a-cyber-expert/386.aspx</guid>
</item>
<item>
<title>Shhh!!! No Roaring in the Library!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/19/shhh-no-roaring-in-the-library/385.aspx</link>
<description>&lt;p&gt;It may lack drama after all the excitement of BlackHat (which is my excuse for not having noticed it earlier), but Apple QuickTime 7.7 &lt;a href=&quot;http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html&quot;&gt;fixes&lt;/a&gt; a stack-based buffer overflow&amp;nbsp;issue that was flagged officially ...</description>
<pubDate>Fri, 19 Aug 2011 11:55:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/19/shhh-no-roaring-in-the-library/385.aspx</guid>
</item>
<item>
<title>Rethinking Information Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/15/rethinking-information-security/383.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I was reminded the other day that the World Wide Web is 20 years old this month, and it came as a shock to realise I've been involved with it for all but the first three years.&lt;br /&gt;
&lt;br /&gt;
Things move very fast in IT: ten years is a lifetime, and 20 is a whole era. Why then, aft ...</description>
<pubDate>Mon, 15 Aug 2011 20:00:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/15/rethinking-information-security/383.aspx</guid>
</item>
<item>
<title>Not with a Bang, but a Whimper</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/10/not-with-a-bang-but-a-whimper/380.aspx</link>
<description>&lt;p&gt;The high-profile security conference season is usually enlivened with a few Mac attacks, Apple app attacks, and other euphonious assonances. While the most consistent source of such diversions is probably &lt;a href=&quot;http://macviruscom.wordpress.com/2011/03/14/pwn2own-hackers-vs-apple-ipv6-privacy/&quot; ...</description>
<pubDate>Wed, 10 Aug 2011 09:57:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/10/not-with-a-bang-but-a-whimper/380.aspx</guid>
</item>
<item>
<title>Losing Control</title>
<link>http://www.infosecurity-magazine.com/blog/2011/8/2/losing-control/376.aspx</link>
<description>&lt;p&gt;I saw &lt;a href=&quot;http://www.zdnet.com/blog/igeneration/microsoft-admits-patriot-act-can-access-eu-based-cloud-data/11225&quot;&gt;this&amp;nbsp;&lt;/a&gt;recently and it really drove home on the key truths about cloud computing when it comes to control over your information.&lt;/p&gt;
&lt;p&gt;Here's a great quote:&lt;/p&gt;
&lt;p sty ...</description>
<pubDate>Tue, 02 Aug 2011 19:50:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/8/2/losing-control/376.aspx</guid>
</item>
<item>
<title>Do the goings-on in student dorms spell the end for Microsoft?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/28/do-the-goingson-in-student-dorms-spell-the-end-for-microsoft/373.aspx</link>
<description>&lt;p&gt;This week Quocirca had a briefing with a security vendor which provided an insight into a fundamental change going on in the use of IT and one of the major drivers for that change. The vendor was Bradford Networks, (named not for the city in Yorkshire UK, but small town in New Hampshire USA).&lt;/p&gt; ...</description>
<pubDate>Thu, 28 Jul 2011 15:53:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/28/do-the-goingson-in-student-dorms-spell-the-end-for-microsoft/373.aspx</guid>
</item>
<item>
<title>Cloud Signaling – The Data Center’s Best Defense</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/27/cloud-signaling--the-data-centers-best-defense/372.aspx</link>
<description>&lt;h5&gt;By Rakesh Shah&lt;/h5&gt;
&lt;p&gt;Recent high-profile security incidents heightened awareness of how Distributed Denial of Service (DDoS) attacks can compromise the availability of critical websites, applications and services.  Any downtime can result in lost business, brand damage, financial penalties, a ...</description>
<pubDate>Wed, 27 Jul 2011 19:39:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/27/cloud-signaling--the-data-centers-best-defense/372.aspx</guid>
</item>
<item>
<title>Pass the Buck: Who 's Responsible for Security in the Cloud? </title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/27/pass-the-buck-who-s-responsible-for-security-in-the-cloud-/371.aspx</link>
<description>&lt;h5&gt;By Todd Thiemann&lt;/h5&gt;
&lt;p&gt;Cloud computing changes the equation of responsibility and accountability for information security and poses some new challenges for enterprise IT. At Vormetric we are working with service providers and enterprises to help them secure and control sensitive data in the c ...</description>
<pubDate>Wed, 27 Jul 2011 19:30:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/27/pass-the-buck-who-s-responsible-for-security-in-the-cloud-/371.aspx</guid>
</item>
<item>
<title>Federal Agency Recognizes Information Security as a Separate, Distinct Career Field – But it’s not OPM </title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/26/federal-agency-recognizes-information-security-as-a-separate-distinct-career-field--but-its-not-opm-/369.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;By the &lt;a href=&quot;https://www.isc2.org/gabewb/Default.aspx&quot;&gt;(ISC)&amp;sup2; U.S. Government Advisory Board Executive Writers Bureau&lt;/a&gt; (EWB)&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;In a recent article, &lt;a href=&quot;http://www.govinfosecurity.com/articles.php?art_id=3833&quot;&gt;&amp;quot;Infosec Joblessness  ...</description>
<pubDate>Tue, 26 Jul 2011 01:22:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/26/federal-agency-recognizes-information-security-as-a-separate-distinct-career-field--but-its-not-opm-/369.aspx</guid>
</item>
<item>
<title>Black, Yellow, Blue: By John Walker</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/21/black-yellow-blue-by-john-walker/366.aspx</link>
<description>&lt;p&gt;&lt;strong&gt;&lt;em&gt;I'm posting this blog on behalf of John&amp;nbsp;Walker, whose account is temporarily having some 'down time'...&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Recent reports have stated that the Anonymous Hacktivists group is to set up its own social networking site and service, after they were understandably re ...</description>
<pubDate>Thu, 21 Jul 2011 15:23:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/21/black-yellow-blue-by-john-walker/366.aspx</guid>
</item>
<item>
<title>PKI Still Matters, Especially in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/15/pki-still-matters-especially-in-the-cloud/364.aspx</link>
<description>&lt;p&gt;&amp;nbsp;By:  Merritt Maxim&lt;br /&gt;
Director of IAM Product Marketing&lt;br /&gt;
CA Technologies Inc.&lt;/p&gt;
&lt;p&gt;Infosec veterans probably remember (with a smirk) how Public Key Infrastructure (PKI) was heralded as the next &amp;ldquo;big thing&amp;rdquo; in information security at the dawn of the 21st century.  Wh ...</description>
<pubDate>Fri, 15 Jul 2011 19:55:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/15/pki-still-matters-especially-in-the-cloud/364.aspx</guid>
</item>
<item>
<title>Mitigating denial of service attacks</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/13/mitigating-denial-of-service-attacks/361.aspx</link>
<description>&lt;p&gt;The common view of a denial of service (DoS) attack is that of a flood of requests to a given web server that overwhelms it and render it useless, at least temporarily. Such attacks have most commonly been perpetrated via botnets, a network of hijacked computers compromised by malware coordinated ...</description>
<pubDate>Wed, 13 Jul 2011 12:18:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/13/mitigating-denial-of-service-attacks/361.aspx</guid>
</item>
<item>
<title>Understanding Best-in-Class Cloud Security Measures and How to Evaluate Providers</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/11/understanding-bestinclass-cloud-security-measures-and-how-to-evaluate-providers/360.aspx</link>
<description>&lt;p&gt;&amp;nbsp;By Fahim Siddiqui&lt;/p&gt;
&lt;p&gt;Despite a broader interest in cloud computing, many organizations have been reluctant to embrace the technology due to security concerns. While today&amp;rsquo;s businesses can benefit from cloud computing&amp;rsquo;s on-demand capacity and economies of scale, the model do ...</description>
<pubDate>Mon, 11 Jul 2011 20:09:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/11/understanding-bestinclass-cloud-security-measures-and-how-to-evaluate-providers/360.aspx</guid>
</item>
<item>
<title>Watch Out for the Top 6 Cloud Gotchas!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/11/watch-out-for-the-top-6-cloud-gotchas/359.aspx</link>
<description>&lt;h5&gt;&amp;nbsp;By Margaret Dawson&lt;/h5&gt;
&lt;p&gt;I am a huge proponent of cloud-based solutions, but I also have a bailiwick for people who look to the cloud just for cloud&amp;rsquo;s sake, and do not take time to do the due diligence.  While the cloud can bring strong technical, economic and business benefits if ...</description>
<pubDate>Mon, 11 Jul 2011 19:56:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/11/watch-out-for-the-top-6-cloud-gotchas/359.aspx</guid>
</item>
<item>
<title>The Cost of a Data Breach</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/8/the-cost-of-a-data-breach/358.aspx</link>
<description>&lt;p&gt;As I have done in a previous post, I am taking this opportunity to share with our online audience some of the letters we receive regarding our online and print coverage. This letter comes from a reader of our most recent issue, and my response to his comments can be found below the letter. As alw ...</description>
<pubDate>Fri, 08 Jul 2011 18:38:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/8/the-cost-of-a-data-breach/358.aspx</guid>
</item>
<item>
<title>Editor's perspective: Infosecurity Europe Joins Forces with Infosecurity Magazine</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/6/editors-perspective-infosecurity-europe-joins-forces-with-infosecurity-magazine/357.aspx</link>
<description>&lt;p&gt;
&lt;div style=&quot;text-align: justify;&quot;&gt;I hope that by now you have heard the &lt;a href=&quot;http://www.infosecurity-magazine.com/view/19190/infosecurity-europe-joins-forces-with-infosecurity-magazine-online-news-site-to-create-stronger-united-market-offering-/&quot;&gt;good news?&lt;/a&gt; &lt;a href=&quot;http://www.infosecur ...</description>
<pubDate>Wed, 06 Jul 2011 14:09:02 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/6/editors-perspective-infosecurity-europe-joins-forces-with-infosecurity-magazine/357.aspx</guid>
</item>
<item>
<title>Smart Thinking</title>
<link>http://www.infosecurity-magazine.com/blog/2011/7/1/smart-thinking/356.aspx</link>
<description>&lt;p&gt;Most people may not immediately recognize the name Reinhold Niebuhr, but they are probably familiar with some version of his best known prayer:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;quot;God grant me the serenity to accept the things I cannot change, courage to change the things I can change, and the wisdom to  ...</description>
<pubDate>Fri, 01 Jul 2011 20:09:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/7/1/smart-thinking/356.aspx</guid>
</item>
<item>
<title>Make the wrong career move, and you just may become structurally unemployed</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/30/make-the-wrong-career-move-and-you-just-may-become-structurally-unemployed/355.aspx</link>
<description>&lt;p class=&quot;p1&quot;&gt;A recent &lt;em&gt;Washington Post&lt;/em&gt; article, &amp;ldquo;&lt;a href=&quot;http://www.washingtonpost.com/opinions/the-great-jobs-mismatch/2011/06/19/AGWdB3bH_story.html&quot;&gt;&lt;span class=&quot;s1&quot;&gt;The great jobs mismatch&lt;/span&gt;&lt;/a&gt;&amp;rdquo;, points out that structural unemployment is caused by a mismatch between  ...</description>
<pubDate>Thu, 30 Jun 2011 20:17:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/30/make-the-wrong-career-move-and-you-just-may-become-structurally-unemployed/355.aspx</guid>
</item>
<item>
<title>In people we trust...</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/29/in-people-we-trust/354.aspx</link>
<description>&lt;p&gt;&amp;nbsp;So, thus begins my blog. Admittedly, it&amp;rsquo;s long overdue. My intention to blog has been very honourable (honestly), it&amp;rsquo;s just the &amp;lsquo;actually doing it&amp;rsquo; bit which has been a little slack, to say the least.&lt;br /&gt;
&lt;br /&gt;
Yesterday, I spent the day at &lt;a href=&quot;http://www.t ...</description>
<pubDate>Wed, 29 Jun 2011 12:52:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/29/in-people-we-trust/354.aspx</guid>
</item>
<item>
<title>How Public Cloud Providers Can Improve Their Trustworthiness</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/28/how-public-cloud-providers-can-improve-their-trustworthiness/353.aspx</link>
<description>&lt;h5&gt;By Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;When you meet someone you have never met for the first time, in a place you have never been to, do you trust him?  Would you have him hold your wallet for you or would you share some sensitive personal information with him?  Of course not. Obviously this person is no ...</description>
<pubDate>Tue, 28 Jun 2011 20:42:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/28/how-public-cloud-providers-can-improve-their-trustworthiness/353.aspx</guid>
</item>
<item>
<title>Weinergate and The Case for Full Disclosure of Data Breaches</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/23/weinergate-and-the-case-for-full-disclosure-of-data-breaches/352.aspx</link>
<description>&lt;p&gt;Often when I chat with people within the industry, the one thing I expect is a consistent message akin to a broken record. &lt;/p&gt;
&lt;p&gt;De-perimiterization, consumerization, defense in depth &amp;ndash; the list of things I hear brought up in nearly every conversation is as fine tuned as a political cand ...</description>
<pubDate>Thu, 23 Jun 2011 20:26:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/23/weinergate-and-the-case-for-full-disclosure-of-data-breaches/352.aspx</guid>
</item>
<item>
<title>Unhealthy Irritation</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/20/unhealthy-irritation/350.aspx</link>
<description>&lt;p&gt;I have to admit, I find this sort of thing just irritating:&lt;/p&gt;
&lt;p&gt;The Register last week &lt;a href=&quot;http://www.theregister.co.uk/2011/06/15/eight_million_health_records/&quot;&gt;reported &lt;/a&gt;that eight million patient records were lost on a laptop. Unencrypted records.&amp;nbsp; No, really.&lt;/p&gt;
&lt;p&gt;As a spo ...</description>
<pubDate>Mon, 20 Jun 2011 21:18:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/20/unhealthy-irritation/350.aspx</guid>
</item>
<item>
<title>Privacy Consequences of WiFi MAC Availability Over the Air</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/16/privacy-consequences-of-wifi-mac-availability-over-the-air/348.aspx</link>
<description>&lt;p&gt;In a recently released report titled &lt;a href=&quot;http://www.newswire.ca/en/releases/archive/June2011/14/c5709.html&quot;&gt;&amp;ldquo;Wi-Fi Positioning Systems: Beware of Unintended Consequences&amp;rdquo;&lt;/a&gt;&amp;nbsp; &amp;ndash; by Ontario's Information and Privacy Commissioner, Dr. Ann Cavoukian, and Kim Cameron, a le ...</description>
<pubDate>Thu, 16 Jun 2011 09:33:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/16/privacy-consequences-of-wifi-mac-availability-over-the-air/348.aspx</guid>
</item>
<item>
<title>The Human Factor Reigns Supreme!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/6/9/the-human-factor-reigns-supreme/346.aspx</link>
<description>&lt;p&gt;Do you know who has access to your computer? Many agencies and corporations spend a majority of their budgets on new technological security software gimmicks while forgetting the human factor.  Personnel security must be included as an integral part of information security. All of the technologic ...</description>
<pubDate>Thu, 09 Jun 2011 21:23:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/6/9/the-human-factor-reigns-supreme/346.aspx</guid>
</item>
<item>
<title>Wild West of Data Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/31/wild-west-of-data-security/343.aspx</link>
<description>&lt;p&gt;Question for the day: What can the turn-of-the century cattle industry teach us about cloud security? Quite a lot, I believe&amp;nbsp;&amp;ndash; especially by the ways in which driving cattle and keeping data secure are so very different.&lt;/p&gt;
&lt;p&gt;Back in the 1880s driving cattle across the US was big bu ...</description>
<pubDate>Tue, 31 May 2011 15:56:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/31/wild-west-of-data-security/343.aspx</guid>
</item>
<item>
<title>Finding a Home for BitLocker</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/17/finding-a-home-for-bitlocker/339.aspx</link>
<description>&lt;p&gt;With the last several &lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/4/14/opening-up-bitlocker-part-2--recovery-keys/317.aspx&quot;&gt;posts &lt;/a&gt;being about &lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/4/1/opening-up-bitlocker/311.aspx&quot;&gt;BitLocker&lt;/a&gt;&amp;nbsp;&amp;nbsp;(and especially Recovery Keys) hope ...</description>
<pubDate>Tue, 17 May 2011 15:54:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/17/finding-a-home-for-bitlocker/339.aspx</guid>
</item>
<item>
<title>What, if Any, Cybersecurity Workforce Implications Resulted From the Averted Government Shutdown?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/12/what-if-any-cybersecurity-workforce-implications-resulted-from-the-averted-government-shutdown/338.aspx</link>
<description>&lt;p&gt;While the Federal Government shutdown was averted thanks to some last-minute political gerrymandering and concessions by both sides of the aisle, it&amp;rsquo;s quite instructive to reflect on the implications of shutdown on the federal cybersecurity workforce, including contracts and contractors.&lt;/p ...</description>
<pubDate>Thu, 12 May 2011 03:47:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/12/what-if-any-cybersecurity-workforce-implications-resulted-from-the-averted-government-shutdown/338.aspx</guid>
</item>
<item>
<title>Security Standards – Why they are so Critical for the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/9/security-standards--why-they-are-so-critical-for-the-cloud/337.aspx</link>
<description>&lt;h5&gt;By&amp;nbsp;Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;Everyone loves standards, right?  When is the last time you heard a vendor proudly say that their product or service was closed and proprietary?  However, it also seems that every time a new IT architecture sweeps through the market, this time one based on cloud ...</description>
<pubDate>Mon, 09 May 2011 19:32:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/9/security-standards--why-they-are-so-critical-for-the-cloud/337.aspx</guid>
</item>
<item>
<title>OAuth – authentication and authorization for mobile applications</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/3/oauth--authentication-and-authorization-for-mobile-applications/335.aspx</link>
<description>&lt;h5&gt;By Paul Madsen&lt;/h5&gt;
&lt;p&gt;Federation is a model of identity management that distributes the various individual components of an identity operation amongst different actors. The presumption being that the jobs can be distributed according to which actors are best suited or positioned to take them o ...</description>
<pubDate>Tue, 03 May 2011 20:32:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/3/oauth--authentication-and-authorization-for-mobile-applications/335.aspx</guid>
</item>
<item>
<title>Who Moved My Cloud?
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/5/3/who-moved-my-cloud/334.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;p&gt;Managed cloud services are quickly being adopted by large enterprises.  Organizations are increasingly embracing cloud technologies for core services like financial systems, IT infrastructure, online merchant sites, and messaging solutions.  This adoption rate is creati ...</description>
<pubDate>Tue, 03 May 2011 19:27:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/5/3/who-moved-my-cloud/334.aspx</guid>
</item>
<item>
<title>Five Guidelines for Cloud Computing and Device Security in The “Always Able” Era</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/29/five-guidelines-for-cloud-computing-and-device-security-in-the-always-able-era/332.aspx</link>
<description>&lt;h5&gt;By Mark Bregman&lt;/h5&gt;
&lt;p&gt;Chief Information Security Officers know instinctively that the world under their purview is undergoing a shift every bit as significant as the rise of the World Wide Web more than 15 years ago. The demand on our workforce to be ever more productive is driving us to reth ...</description>
<pubDate>Fri, 29 Apr 2011 18:35:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/29/five-guidelines-for-cloud-computing-and-device-security-in-the-always-able-era/332.aspx</guid>
</item>
<item>
<title>Amazon Sneezed (and the Cloud Caught a Cold?)</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/28/amazon-sneezed-and-the-cloud-caught-a-cold/329.aspx</link>
<description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Never confuse a single defeat with a final defeat.&lt;/em&gt;&lt;br /&gt;
&amp;nbsp;&amp;ndash; F. Scott Fitzgerald&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So last week was, depending on who you ask, a terrible week for &amp;quot;The Cloud,&amp;quot; a wakeup call for businesses who want to use cloud services, or nothing  ...</description>
<pubDate>Thu, 28 Apr 2011 17:06:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/28/amazon-sneezed-and-the-cloud-caught-a-cold/329.aspx</guid>
</item>
<item>
<title>Protect the API Keys to your Cloud Kingdom</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/20/protect-the-api-keys-to-your-cloud-kingdom/322.aspx</link>
<description>&lt;div style=&quot;background-color: rgb(255, 255, 255); padding-top: 5px; padding-right: 5px; padding-bottom: 5px; padding-left: 5px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; &quot;&gt;
&lt;h5&gt;By Mark O&amp;rsquo;Neill&lt;/h5&gt;
&lt;p&gt;Much lip service is paid to protecting information in the C ...</description>
<pubDate>Wed, 20 Apr 2011 19:08:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/20/protect-the-api-keys-to-your-cloud-kingdom/322.aspx</guid>
</item>
<item>
<title>Is Tokenization or Encryption Keeping You Up at Night?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/20/is-tokenization-or-encryption-keeping-you-up-at-night/321.aspx</link>
<description>&lt;h5&gt;By Stuart Lisk, Senior Product Manager, Hubspan&lt;/h5&gt;
&lt;div&gt;Are you losing sleep over whether to implement tokenization or full encryption as your cloud security methodology? Do you find yourself lying awake wondering if you locked all the doors to your sensitive data? Your &amp;ldquo;sleepless with  ...</description>
<pubDate>Wed, 20 Apr 2011 18:27:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/20/is-tokenization-or-encryption-keeping-you-up-at-night/321.aspx</guid>
</item>
<item>
<title>Constant Vigilance</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/14/constant-vigilance/318.aspx</link>
<description>&lt;h5&gt;&lt;b&gt;&lt;span style=&quot;&quot;&gt;By Jon Heimerl &lt;/span&gt;&lt;/b&gt;&lt;/h5&gt;
&lt;h5&gt;&amp;nbsp;&lt;/h5&gt;
&lt;p&gt;&lt;span style=&quot;&quot;&gt;Constant Vigilance. Mad-Eye Moody puts it very well. Constant Vigilance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;&quot;&gt;Unfortunately, these days we need constant vigilance to help protect ourselves and companies from peril. Th ...</description>
<pubDate>Thu, 14 Apr 2011 20:00:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/14/constant-vigilance/318.aspx</guid>
</item>
<item>
<title>Opening up BitLocker, part 2 – Recovery Keys</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/14/opening-up-bitlocker-part-2--recovery-keys/317.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/4/1/opening-up-bitlocker/311.aspx&quot;&gt;Last time&amp;nbsp;&lt;/a&gt; I covered an introduction to BitLocker, the Trusted Platform Module (TPM) and what TPM does to assist in keeping your system secure. This time I'm writing about the most important aspect of Bi ...</description>
<pubDate>Thu, 14 Apr 2011 17:54:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/14/opening-up-bitlocker-part-2--recovery-keys/317.aspx</guid>
</item>
<item>
<title>Cybersecurity: The Road Ahead</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/14/cybersecurity-the-road-ahead/316.aspx</link>
<description>&lt;p&gt;This paper by the &lt;a target=&quot;_blank&quot; href=&quot;http://www.dcaf.ch/Publications/Publication-Detail?lng=en&amp;amp;id=126370&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Geneva Centre for the Democratic Control of Armed Forces  (DCAF)&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; was just brought to my attention. A piece of work that is  definit ...</description>
<pubDate>Thu, 14 Apr 2011 11:07:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/14/cybersecurity-the-road-ahead/316.aspx</guid>
</item>
<item>
<title>Cloud Annexation</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/12/cloud-annexation/315.aspx</link>
<description>&lt;h5&gt;By Stephen R Carter&lt;/h5&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;The Cloud is the next evolutionary step in the life of the Internet. From the experimental ARPANET (Advanced Research Projects Agency Network) to the Internet to the Web &amp;ndash; and now to the Cloud &amp;ndash; the evolution continues to advance inte ...</description>
<pubDate>Tue, 12 Apr 2011 20:47:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/12/cloud-annexation/315.aspx</guid>
</item>
<item>
<title>The Future of Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/11/the-future-of-security/314.aspx</link>
<description>&lt;p&gt;Visitors to the recent RSA Conference in San Francisco were treated to a forward-looking &lt;a href=&quot;http://media.omediaweb.com/rsa2011/keynotes/webcast.htm?id=3-5&quot;&gt;keynote&lt;/a&gt; by City University of New York professor and television personality Michio Kaku. His presentation on the next 20 years of c ...</description>
<pubDate>Mon, 11 Apr 2011 16:44:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/11/the-future-of-security/314.aspx</guid>
</item>
<item>
<title>On First Base with Stolen Email Addresses</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/4/on-first-base-with-stolen-email-addresses/313.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.cnn.com/2011/TECH/web/04/04/epsilon.stolen.emails/&quot;&gt;CNN continues to report&lt;/a&gt; on the compromise of email addresses and names from Epsilon systems over the weekend and the potential impact it may have on net citizens. There is fear and uncertainty that comes with any compromi ...</description>
<pubDate>Mon, 04 Apr 2011 19:22:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/4/on-first-base-with-stolen-email-addresses/313.aspx</guid>
</item>
<item>
<title>Privileged Administrators and the Cloud: Who will Watch the Watchmen?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/1/privileged-administrators-and-the-cloud-who-will-watch-the-watchmen/312.aspx</link>
<description>&lt;h5&gt;By Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;One of the key advantages of the cloud, whether public or private, flows from a well-known econometric concept known as &amp;ldquo;economies of scale.&amp;rdquo; The concept of economies of scale refers to an operation that to a point gets more efficient as it gets bigger &amp;n ...</description>
<pubDate>Fri, 01 Apr 2011 19:52:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/1/privileged-administrators-and-the-cloud-who-will-watch-the-watchmen/312.aspx</guid>
</item>
<item>
<title>Opening up BitLocker</title>
<link>http://www.infosecurity-magazine.com/blog/2011/4/1/opening-up-bitlocker/311.aspx</link>
<description>&lt;p&gt;It's hard to avoid the flurry of bad press following the recent loss of a laptop by a &lt;a href=&quot;http://www.infosecurity-us.com/view/16946/bp-loses-laptop-containing-details-of-13000-oil-spill-victims/&quot;&gt;BP employee.&lt;/a&gt; Unfortunately for all concerned, the lost laptop contained the names and person ...</description>
<pubDate>Fri, 01 Apr 2011 18:44:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/4/1/opening-up-bitlocker/311.aspx</guid>
</item>
<item>
<title>Debunking the Top Three Cloud Security Myths</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/30/debunking-the-top-three-cloud-security-myths/308.aspx</link>
<description>&lt;h5&gt;By Margaret Dawson&lt;/h5&gt;
&lt;p&gt;The &amp;ldquo;cloud&amp;rdquo; is one of the most discussed topics among IT professionals today, and organizations are increasingly exploring the potential benefits of using cloud computing or solutions for their businesses. It&amp;rsquo;s no surprise &lt;a href=&quot;http://www.gartner ...</description>
<pubDate>Wed, 30 Mar 2011 20:06:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/30/debunking-the-top-three-cloud-security-myths/308.aspx</guid>
</item>
<item>
<title>[How to] Be Confident When Storing Information in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/29/how-to-be-confident-when-storing-information-in-the-cloud/306.aspx</link>
<description>&lt;h5&gt;By Anil Chakravarthy and Deepak Mohan&lt;/h5&gt;
&lt;p&gt;Over the past few years, information explosion has inhibited organizations&amp;rsquo; ability to effectively secure, manage and recover data. This complexity is only increasing as organizations try to manage the data growth by moving it to the cloud. It ...</description>
<pubDate>Tue, 29 Mar 2011 20:16:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/29/how-to-be-confident-when-storing-information-in-the-cloud/306.aspx</guid>
</item>
<item>
<title>Revisiting Data Privacy Day</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/28/revisiting-data-privacy-day/305.aspx</link>
<description>&lt;p&gt;We regret that we did not have space to publish this in our upcoming print edition, but we here at &lt;em&gt;Infosecurity&lt;/em&gt; nonetheless thought it was important to provide our readers with this feedback we received recently on one of our web news items. Since it is in reference to an online item, we ...</description>
<pubDate>Mon, 28 Mar 2011 17:53:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/28/revisiting-data-privacy-day/305.aspx</guid>
</item>
<item>
<title>Data Sinks and Data Leakage – The Effect of Poisoned Links</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/25/data-sinks-and-data-leakage--the-effect-of-poisoned-links/304.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Gone are the days of text user interfaces for exchanging data or email over the Internet. Now, users are hard pressed to exchange information without using HTML or any of the Web 2.0 features. When the WWW was in its infancy, our ability to share and download information propelle ...</description>
<pubDate>Fri, 25 Mar 2011 21:22:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/25/data-sinks-and-data-leakage--the-effect-of-poisoned-links/304.aspx</guid>
</item>
<item>
<title>WPA2 Secured Hotspots: Feasible with New WiFi Alliance Hotspot Certification</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/23/wpa2-secured-hotspots-feasible-with-new-wifi-alliance-hotspot-certification/303.aspx</link>
<description>&lt;p&gt;Public WiFi hotspots have shown tremendous growth in recent years. Much of this can be attributed to growing number of people carrying smart mobile devices (such as smartphones and tablets) and using bandwidth-consuming internet applications (such as gaming, social networking sites and audio/vide ...</description>
<pubDate>Wed, 23 Mar 2011 14:50:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/23/wpa2-secured-hotspots-feasible-with-new-wifi-alliance-hotspot-certification/303.aspx</guid>
</item>
<item>
<title>Hey, You, Get off of My Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/22/hey-you-get-off-of-my-cloud/302.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;div&gt;The emerging Public Cloud versus Private Cloud debate is not just about which solution is best. It extends to the very definition of cloud.&amp;nbsp;I won&amp;rsquo;t pretend that my definitions of public cloud and private cloud match everybody elses, but I would like to begi ...</description>
<pubDate>Tue, 22 Mar 2011 18:08:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/22/hey-you-get-off-of-my-cloud/302.aspx</guid>
</item>
<item>
<title>Three Cloud-Computing Data Security Risks That Can’t be Overlooked</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/21/three-cloudcomputing-data-security-risks-that-cant-be-overlooked/301.aspx</link>
<description>&lt;h5&gt;&amp;nbsp;By&amp;nbsp;Slavik Markovich&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/h5&gt;
&lt;div&gt;The move to cloud computing brings with it a number of attributes that require special consideration when it comes to securing data.&amp;nbsp;And since in nearly every organization, their most sensitive data will be stored either directly in a ...</description>
<pubDate>Mon, 21 Mar 2011 16:12:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/21/three-cloudcomputing-data-security-risks-that-cant-be-overlooked/301.aspx</guid>
</item>
<item>
<title>WiFi Hacking not Always a Cyber Crime</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/19/wifi-hacking-not-always-a-cyber-crime/299.aspx</link>
<description>&lt;p&gt;If someone is assuming that hacking/breaking into a WiFi router for piggybacking on the router&amp;rsquo;s internet connection is illegal, then he/she needs to double check the same with the applicable CyberLaw. This was highlighted in view of a &lt;a href=&quot;http://www.pcworld.com/article/222589/dutch_co ...</description>
<pubDate>Sat, 19 Mar 2011 11:09:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/19/wifi-hacking-not-always-a-cyber-crime/299.aspx</guid>
</item>
<item>
<title>WiFi Security Still Elusive for Many Users

</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/18/wifi-security-still-elusive-for-many-users/298.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;WiFi security continues to hog the limelight with the &lt;a href=&quot;http://www.infosecurity-us.com/blog/2010/12/28/summarizing-wifi-security-revelations-for-the-year-2010/262.aspx&quot;&gt;series of related revelations and incidents&lt;/a&gt; happening periodically. And the latest in this series ar ...</description>
<pubDate>Fri, 18 Mar 2011 15:21:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/18/wifi-security-still-elusive-for-many-users/298.aspx</guid>
</item>
<item>
<title>Does a High-Performance Cloud Make For More Work?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/11/does-a-highperformance-cloud-make-for-more-work/295.aspx</link>
<description>&lt;p&gt;A couple of quick thoughts here, mostly around the changing scale of the task of securing information in the cloud.&lt;/p&gt;
&lt;p&gt;I think we see a couple of interesting trends here and they are, well, not necessarily complementary. The first is that the cloud providers are getting serious about scaling ...</description>
<pubDate>Fri, 11 Mar 2011 21:05:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/11/does-a-highperformance-cloud-make-for-more-work/295.aspx</guid>
</item>
<item>
<title>SEC and the Porn Farm</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/10/sec-and-the-porn-farm/294.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;Thirty-three people at the SEC were found to have been looking at porn at work over the past five years according the a summary of internal probes conducted by the SEC&amp;rsquo;s inspector general and reported by the &lt;a href=&quot;http://online.wsj.com/article/SB1000142405274870438830457 ...</description>
<pubDate>Thu, 10 Mar 2011 20:59:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/10/sec-and-the-porn-farm/294.aspx</guid>
</item>
<item>
<title>Cloud Security: The Identity Factor</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/10/cloud-security-the-identity-factor/293.aspx</link>
<description>&lt;h5&gt;By Patrick Harding&lt;/h5&gt;
&lt;h3&gt;The Problem with Passwords&lt;/h3&gt;
&lt;p&gt;The average enterprise employee uses 12 userid/password pairs for accessing the many applications required to perform his or her job (Osterman Research 2009). It is unreasonable to expect anyone to create, regularly change (also a  ...</description>
<pubDate>Thu, 10 Mar 2011 15:34:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/10/cloud-security-the-identity-factor/293.aspx</guid>
</item>
<item>
<title>Navigating Cloud Application Security: Myths vs. Realities </title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/8/navigating-cloud-application-security-myths-vs-realities-/290.aspx</link>
<description>&lt;h5&gt;By Chris Wysopal&lt;/h5&gt;
&lt;p&gt;Developers and IT departments are being told they need to move applications to the cloud and are often left on their own to navigate the challenges related to developing and managing the security of applications in those environments.  Because no one should have to fly  ...</description>
<pubDate>Tue, 08 Mar 2011 16:14:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/8/navigating-cloud-application-security-myths-vs-realities-/290.aspx</guid>
</item>
<item>
<title>Keeping Control in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/4/keeping-control-in-the-cloud/287.aspx</link>
<description>&lt;p&gt;I had a great talk with &lt;a href=&quot;http://www.infosecurity-us.com/view/16323/risks-discourage-firms-from-taking-advantage-of-cloud-benefits-/&quot;&gt;Fred Donovan &lt;/a&gt;this week regarding cloud security.&lt;/p&gt;
&lt;p&gt;It's pretty clear that organizations of all kinds are very concerned about the risks (and the c ...</description>
<pubDate>Fri, 04 Mar 2011 21:58:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/4/keeping-control-in-the-cloud/287.aspx</guid>
</item>
<item>
<title>Trusted Client to Cloud Access</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/2/trusted-client-to-cloud-access/286.aspx</link>
<description>&lt;h5&gt;By Vikas Jain&lt;/h5&gt;
&lt;p&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Cloud_computing&quot;&gt;&lt;span style=&quot;text-decoration: underline;&quot;&gt;C&lt;/span&gt;loud computing&lt;/a&gt; has become an integral part of all IT decision making today across industries and geographies. This market is growing at a rapid pace. By 2014, IDC e ...</description>
<pubDate>Wed, 02 Mar 2011 17:10:28 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/2/trusted-client-to-cloud-access/286.aspx</guid>
</item>
<item>
<title>Aligning Security with the Business</title>
<link>http://www.infosecurity-magazine.com/blog/2011/3/1/aligning-security-with-the-business/285.aspx</link>
<description>&lt;p&gt;Do you know the feeling? You should share a large file with somebody outside your organization. The file is too big to be sent by e-mail. What can you do? Well, you might have a service by internal IT (we have one) that is not really user-friendly, hard to use and &amp;ndash; as you do not need it to ...</description>
<pubDate>Tue, 01 Mar 2011 16:41:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/3/1/aligning-security-with-the-business/285.aspx</guid>
</item>
<item>
<title>Senator Schumer Calls for Increased Public WiFi Security</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/28/senator-schumer-calls-for-increased-public-wifi-security/284.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;Increased use of public WiFi access at hotspots, retail stores, hotels and other similar establishments has recently motivated &lt;a href=&quot;http://uk.reuters.com/article/2011/02/27/tech-us-schumer-wifi-idUKTRE71Q2N420110227&quot;&gt;New York Democrat, Sen. Charles S ...</description>
<pubDate>Mon, 28 Feb 2011 13:51:22 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/28/senator-schumer-calls-for-increased-public-wifi-security/284.aspx</guid>
</item>
<item>
<title>And the Thunder Rolls: All the Noise about Cloud and What that Means When Lightning Strikes</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/23/and-the-thunder-rolls-all-the-noise-about-cloud-and-what-that-means-when-lightning-strikes/283.aspx</link>
<description>&lt;h5&gt;By Allen Allison&lt;/h5&gt;
&lt;p&gt;Disaster Recovery (DR) and Business Continuity Planning (BCP) continue to be driving factors for some organizations looking to move to the cloud. Many are looking to manage their Disaster Recovery planning through extensive use of managed cloud services &amp;ndash; and for  ...</description>
<pubDate>Wed, 23 Feb 2011 16:35:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/23/and-the-thunder-rolls-all-the-noise-about-cloud-and-what-that-means-when-lightning-strikes/283.aspx</guid>
</item>
<item>
<title>Top Six Security Questions Every CIO Should Ask a Cloud Vendor </title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/23/top-six-security-questions-every-cio-should-ask-a-cloud-vendor-/282.aspx</link>
<description>&lt;h5&gt;&lt;span style=&quot;color: black;&quot;&gt;By &lt;/span&gt;Ian Huynh&lt;/h5&gt;
&lt;div&gt;&lt;span style=&quot;color: black;&quot;&gt;Cloud computing has become an integrated part of IT strategy for companies in every sector of our economy.&amp;nbsp;By 2012, IDC predicts that IT spending on cloud services will grow almost threefold, to $42 billi ...</description>
<pubDate>Wed, 23 Feb 2011 16:18:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/23/top-six-security-questions-every-cio-should-ask-a-cloud-vendor-/282.aspx</guid>
</item>
<item>
<title>Cloud, here we come!</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/11/cloud-here-we-come/281.aspx</link>
<description>&lt;p&gt;Cloud, here we come!&amp;nbsp; Or is it rather more a case of &amp;quot;We're already here, so make the best of it...&amp;quot;?&lt;/p&gt;
&lt;p&gt;I spent some time today talking to a good friend of mine who also happens to be the head of security for a large European financial services business. Unsurprisingly we got ...</description>
<pubDate>Fri, 11 Feb 2011 23:22:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/11/cloud-here-we-come/281.aspx</guid>
</item>
<item>
<title>Quit Worrying About Cloud Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/4/quit-worrying-about-cloud-security/278.aspx</link>
<description>&lt;p&gt;Well, it is not THAT easy but at least there are people starting to claim that it is not as hard as it seems to be sometimes. I stumbled across the following article: &lt;a target=&quot;_blank&quot; href=&quot;http://fcw.com/articles/2011/01/31/cloud-security.aspx?s=security_030211&amp;amp;admgarea=TC_SECCYBERSEC&quot;&gt;&lt;st ...</description>
<pubDate>Fri, 04 Feb 2011 11:03:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/4/quit-worrying-about-cloud-security/278.aspx</guid>
</item>
<item>
<title>Buying the Security Farm</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/2/buying-the-security-farm/277.aspx</link>
<description>&lt;p&gt;The landscape of &lt;a href=&quot;http://www.esoft.com/&quot;&gt;network security&lt;/a&gt;  is a world of transition. However, one thing we know for certain is that  the threats are becoming more organized, more advanced, and more  focused on obtaining one thing: information the attacker can sell. &lt;/p&gt;
&lt;p&gt;What  do t ...</description>
<pubDate>Wed, 02 Feb 2011 22:52:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/2/buying-the-security-farm/277.aspx</guid>
</item>
<item>
<title>Extend the Enterprise into the Cloud with Single Sign-On to Cloud-Based Services</title>
<link>http://www.infosecurity-magazine.com/blog/2011/2/1/extend-the-enterprise-into-the-cloud-with-single-signon-to-cloudbased-services/276.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;b&gt;By Mark O&amp;rsquo;Neill&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;In this blog post we examine how Single Sign-On from the enterprise to Cloud-based services is enabled. Single Sign-On is a critical component for any organization wishing to leverage Cloud services. In fact, an organization accessing Cloud-based service ...</description>
<pubDate>Tue, 01 Feb 2011 16:18:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/2/1/extend-the-enterprise-into-the-cloud-with-single-signon-to-cloudbased-services/276.aspx</guid>
</item>
<item>
<title>Dining in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/28/dining-in-the-cloud/274.aspx</link>
<description>&lt;p&gt;I enjoyed &lt;a href=&quot;http://www.infosecurity-us.com/blog/2011/1/19/will-the-cloud-cause-the-reemergence-of-security-silos/266.aspx&quot;&gt;Matthew Gardener's blog &lt;/a&gt;this week on the potential for the re-emergence of security silos as a result of the growing move out into the cloud. I think he's right, o ...</description>
<pubDate>Fri, 28 Jan 2011 15:08:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/28/dining-in-the-cloud/274.aspx</guid>
</item>
<item>
<title>Are You Focused On The Wrong Security Risks?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/28/are-you-focused-on-the-wrong-security-risks/273.aspx</link>
<description>&lt;p&gt;There is an good article on CIO Central: &lt;a target=&quot;_blank&quot; href=&quot;http://blogs.forbes.com/ciocentral/2011/01/27/are-you-focused-on-the-wrong-security-risks/&quot;&gt;Are You Focused On The Wrong Security Risks?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;An interesting discussion, and I partly agree that we have to challenge the way  w ...</description>
<pubDate>Fri, 28 Jan 2011 09:34:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/28/are-you-focused-on-the-wrong-security-risks/273.aspx</guid>
</item>
<item>
<title>Building a Secure Future in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/27/building-a-secure-future-in-the-cloud/271.aspx</link>
<description>&lt;h5&gt;By Mark Bregman&lt;/h5&gt;
&lt;p&gt;Cloud computing offers clear and powerful benefits to IT organizations of all sizes, but the path to cloud computing &amp;ndash; please excuse the pun &amp;ndash; is often cloudy.&lt;/p&gt;
&lt;p&gt;With cloud computing, IT resources can scale almost immediately in response to business nee ...</description>
<pubDate>Thu, 27 Jan 2011 16:33:40 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/27/building-a-secure-future-in-the-cloud/271.aspx</guid>
</item>
<item>
<title>Moving to the Cloud? Take Your Application Security With You</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/27/moving-to-the-cloud-take-your-application-security-with-you/270.aspx</link>
<description>&lt;h5&gt;By Bill Pennington&lt;/h5&gt;
&lt;p&gt;Cloud computing is becoming a fundamental part of information technology. Nearly every enterprise is evaluating or deploying cloud solutions. Even as business managers turn to the cloud to reduce costs, streamline staff, and increase efficiencies, they remain wary abo ...</description>
<pubDate>Thu, 27 Jan 2011 16:20:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/27/moving-to-the-cloud-take-your-application-security-with-you/270.aspx</guid>
</item>
<item>
<title>Moving to a “Show Me” State – Gaining Control and Visibility in Cloud Services</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/25/moving-to-a-show-me-state--gaining-control-and-visibility-in-cloud-services/268.aspx</link>
<description>&lt;h5&gt;By Eric Baize&lt;/h5&gt;
&lt;p&gt;&lt;a href=&quot;http://www.emc.com/collateral/analyst-reports/emc-seeding-the-cloud-forbes-report.pdf&quot;&gt;In Survey &lt;/a&gt;after &lt;a href=&quot;http://securecloudreview.com/2010/09/cloud-adoption-still-struggles-with-security-issues-in-cso-survey/&quot;&gt;survey&lt;/a&gt;, security and more specifically  ...</description>
<pubDate>Tue, 25 Jan 2011 16:29:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/25/moving-to-a-show-me-state--gaining-control-and-visibility-in-cloud-services/268.aspx</guid>
</item>
<item>
<title>Neuroprivilogy: The New Frontier of Cyber Crime </title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/21/neuroprivilogy-the-new-frontier-of-cyber-crime-/267.aspx</link>
<description>&lt;h5&gt;By Shlomi Dinoor&lt;/h5&gt;
&lt;p&gt;Is your Neuroprivilogy vulnerable? The answer is most probably yes, you simply have no clue what Neuroprivilogy is (yet)&amp;hellip;&lt;/p&gt;
&lt;p&gt;The first step of this discussion is defining a fancy term to help educate and describe this new phenomenon.  As the name suggests, N ...</description>
<pubDate>Fri, 21 Jan 2011 14:12:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/21/neuroprivilogy-the-new-frontier-of-cyber-crime-/267.aspx</guid>
</item>
<item>
<title>Will the Cloud Cause the Reemergence of Security Silos?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/19/will-the-cloud-cause-the-reemergence-of-security-silos/266.aspx</link>
<description>&lt;h5&gt;By Matthew Gardiner&lt;/h5&gt;
&lt;p&gt;Generally speaking, in the world silos relate to things that are beneficial, such as silos for grain or corn. In the world of IT security, however, silos are very bad. In many forensic investigations, application silos turn up as a key culprit that enabled data leaka ...</description>
<pubDate>Wed, 19 Jan 2011 18:07:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/19/will-the-cloud-cause-the-reemergence-of-security-silos/266.aspx</guid>
</item>
<item>
<title>UNODC: Open Ended Expert Group on Cybercrime
</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/16/unodc-open-ended-expert-group-on-cybercrime/265.aspx</link>
<description>&lt;p&gt;From tomorrow on, UNDOC invited for an &lt;a target=&quot;_blank&quot; href=&quot;http://www.unodc.org/unodc/en/treaties/expert-group-on-cybercrime.html&quot; onclick=&quot;javascript:_gaq.push(['_trackEvent','outbound-article','www.unodc.org']);&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Open Ended Expert Group on Cybercrime&lt;/font&gt;&lt;/s ...</description>
<pubDate>Sun, 16 Jan 2011 21:43:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/16/unodc-open-ended-expert-group-on-cybercrime/265.aspx</guid>
</item>
<item>
<title>Certifiable in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/13/certifiable-in-the-cloud/264.aspx</link>
<description>&lt;h5&gt;By Pamela Fusco&lt;/h5&gt;
&lt;div&gt;&lt;span style=&quot;&quot;&gt;Cloud computing remains as much a mystery to some as it is a part of others&amp;rsquo; daily lexicon. I spend a lot of time working with people who have connections to various offices of the US government and I find that regardless of the topic, or the backg ...</description>
<pubDate>Thu, 13 Jan 2011 18:35:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/13/certifiable-in-the-cloud/264.aspx</guid>
</item>
<item>
<title>Cybercrime as a Service – Our Future?</title>
<link>http://www.infosecurity-magazine.com/blog/2011/1/12/cybercrime-as-a-service--our-future/263.aspx</link>
<description>&lt;p&gt;It is not really surprising that criminals will leverage the economy of Cloud Computing for their illegal purposes. Especially activities that consume a lot of processor power will be moved to the Cloud &amp;ndash; like any other business.&lt;/p&gt;
&lt;p&gt;Some way back, there were discussions on how to lever ...</description>
<pubDate>Wed, 12 Jan 2011 09:05:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2011/1/12/cybercrime-as-a-service--our-future/263.aspx</guid>
</item>
<item>
<title>Summarizing WiFi security revelations for the year 2010</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/28/summarizing-wifi-security-revelations-for-the-year-2010/262.aspx</link>
<description>&lt;p&gt;WiFi security remained in focus with noticeable and widely discussed &lt;a href=&quot;http://blog.airtightnetworks.com/wi-fi-insecurity-wrap-up-for-2010/&quot;&gt;incidents and revelations&lt;/a&gt; happening all throughout the year. These events will surely provide strong testimony for advocating the importance of se ...</description>
<pubDate>Tue, 28 Dec 2010 14:39:45 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/28/summarizing-wifi-security-revelations-for-the-year-2010/262.aspx</guid>
</item>
<item>
<title>Insider attack, staplers, and something cloudy</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/22/insider-attack-staplers-and-something-cloudy/261.aspx</link>
<description>&lt;p&gt;This piece in &lt;a href=&quot;http://www.infosecurity-us.com/view/14815/inadvertent-data-disclosure-by-employees-poses-growing-risk/&quot;&gt;InfoSecurity&amp;nbsp;&lt;/a&gt;reminded me of a recent webinar I did with Jake Kouns of the Open Security Foundation.&amp;nbsp; (An &lt;a href=&quot;http://www.credant.com/news-a-events/event ...</description>
<pubDate>Wed, 22 Dec 2010 21:56:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/22/insider-attack-staplers-and-something-cloudy/261.aspx</guid>
</item>
<item>
<title>Mitigating the use of Local Admin</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/5/mitigating-the-use-of-local-admin/258.aspx</link>
<description>&lt;p&gt;We recently had internal discussions on the use of local admin and how to mitigate it. During this, Richard Diver, a Premier Field Engineer in APAC, wrote a great article how to do it. I wanted to make sure you can all see this as well. So, this is a guest blog.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Genera ...</description>
<pubDate>Sun, 05 Dec 2010 21:22:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/5/mitigating-the-use-of-local-admin/258.aspx</guid>
</item>
<item>
<title>Wikileakage</title>
<link>http://www.infosecurity-magazine.com/blog/2010/12/2/wikileakage/257.aspx</link>
<description>&lt;p&gt;In all the furor (or possibly storm-in-a-teacup) over the recent WikiLeaks revelations it's interesting, but probably not that surprising, that so much emphasis has been put on the content and far less, at least publicly, on the event itself; by which I mean the actual leak.&lt;/p&gt;
&lt;p&gt;Based on the  ...</description>
<pubDate>Thu, 02 Dec 2010 14:32:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/12/2/wikileakage/257.aspx</guid>
</item>
<item>
<title>The Cloud is Also Green</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/22/the-cloud-is-also-green/254.aspx</link>
<description>&lt;p&gt;Yes, not only gray :-)&lt;/p&gt;
&lt;p&gt;Seriously, we commissioned a study to see what the impact of cloud computing is not only to efficiency but the the environment. Can you save CO&lt;sub&gt;2&lt;/sub&gt; by moving to the cloud? I think its something we do not look at often enough. As pictures say more than 1000 w ...</description>
<pubDate>Mon, 22 Nov 2010 07:35:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/22/the-cloud-is-also-green/254.aspx</guid>
</item>
<item>
<title>Password Security Goes Prime Time </title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/19/password-security-goes-prime-time-/253.aspx</link>
<description>&lt;p&gt;Here's an end-of-week musing for you all. Did anyone happen to see last night&amp;rsquo;s episode of &lt;em&gt;The Office&lt;/em&gt;? (Yes, I watch television, and I&amp;rsquo;m not afraid to admit it!)&lt;/p&gt;
&lt;p&gt;If you did, then the intro illustrated one of the most common security faux-pas out there. In the opening  ...</description>
<pubDate>Fri, 19 Nov 2010 21:09:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/19/password-security-goes-prime-time-/253.aspx</guid>
</item>
<item>
<title>Firesheep Add-on:  Exploiting Security Vulnerabilities of Websites over Insecure WiFi Networks</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/16/firesheep-addon--exploiting-security-vulnerabilities-of-websites-over-insecure-wifi-networks/251.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;i&gt;&lt;a href=&quot;http://codebutler.github.com/firesheep/&quot;&gt;Firesheep&lt;/a&gt;&lt;/i&gt; is a recently released Firefox add-on/extension, developed by software freelancer &lt;a href=&quot;http://codebutler.com/&quot;&gt;Eric Butler&lt;/a&gt;. The intention behind the add-on was to expose the gravity of commonly found security vul ...</description>
<pubDate>Tue, 16 Nov 2010 14:41:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/16/firesheep-addon--exploiting-security-vulnerabilities-of-websites-over-insecure-wifi-networks/251.aspx</guid>
</item>
<item>
<title>Fixing Risk Management</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/15/fixing-risk-management/248.aspx</link>
<description>&lt;p&gt;I am not satisfied with the way we (in the industry) are doing risk management. In my early days, before I was actually entering the security space, I was doing project management and as part of it, risk management. The way we did it was fairly simple (as probably most of you do): We had an impac ...</description>
<pubDate>Mon, 15 Nov 2010 07:22:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/15/fixing-risk-management/248.aspx</guid>
</item>
<item>
<title>Cyber attacks, power grids, and Mary Poppins</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/12/cyber-attacks-power-grids-and-mary-poppins/247.aspx</link>
<description>&lt;p&gt;&amp;quot;A spoonful of sugar helps the medicine go down..&amp;quot;&lt;/p&gt;
&lt;p&gt;Or at least, that's what Mary Poppins says.&amp;nbsp; Personally, I have my doubts about her training as a medical professional&amp;nbsp;&amp;ndash; anyone who talks to their umbrella really shouldn't be prescribing drugs to minors if you a ...</description>
<pubDate>Fri, 12 Nov 2010 17:16:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/12/cyber-attacks-power-grids-and-mary-poppins/247.aspx</guid>
</item>
<item>
<title>The Value of Government Clouds</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/12/the-value-of-government-clouds/246.aspx</link>
<description>&lt;p&gt;Microsoft recently released a paper called &lt;a href=&quot;http://microsoft.eu/Cloudeconomics.aspx&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;The Economics of Cloud Computing for the EU Public Sector&lt;/font&gt;&lt;/a&gt;, which is actually valid for every other European country as well, as it is not too narrowly focused on the EU on ...</description>
<pubDate>Fri, 12 Nov 2010 12:01:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/12/the-value-of-government-clouds/246.aspx</guid>
</item>
<item>
<title>Turkey signed Cybercrime Convention</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/11/turkey-signed-cybercrime-convention/245.aspx</link>
<description>&lt;p&gt;We are huge supporter of the Convention on Cybercrime by the &lt;a onclick=&quot;javascript:_gaq.push(['_trackEvent','outbound-article','www.coe.int']);&quot; href=&quot;http://www.coe.int/t/DGHL/cooperation/economiccrime/cybercrime/default_en.asp&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Council of Europe&lt;/font&gt;&lt;/strong&gt;&lt;/a ...</description>
<pubDate>Thu, 11 Nov 2010 16:43:09 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/11/turkey-signed-cybercrime-convention/245.aspx</guid>
</item>
<item>
<title>Russia to revise Cybercrime Legislation?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/11/5/russia-to-revise-cybercrime-legislation/243.aspx</link>
<description>&lt;p&gt;You know that I am propagating the adoption of cybercrime legislation, which is aligned across the Globe. Something, which is absolutely necessary if we want to fight Cybercrime. Basically we are asking governments to consider the Cybercrime Convention (also known as Budapest Convention) by the C ...</description>
<pubDate>Fri, 05 Nov 2010 08:19:31 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/11/5/russia-to-revise-cybercrime-legislation/243.aspx</guid>
</item>
<item>
<title>Bad Week For USB Security</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/22/bad-week-for-usb-security/234.aspx</link>
<description>&lt;p&gt;It's been a bad week for USB device security.&lt;/p&gt;
&lt;p&gt;A couple of potentially ugly breaches have highlighted, once more, the trouble organizations are having with managing removable media security.&amp;nbsp; Over in the UK, the &lt;a href=&quot;http://www.sellafieldsites.com/&quot;&gt;Sellafield &lt;/a&gt;nuclear reproces ...</description>
<pubDate>Fri, 22 Oct 2010 19:13:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/22/bad-week-for-usb-security/234.aspx</guid>
</item>
<item>
<title>Stuxnet talks – do we listen?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/12/stuxnet-talks--do-we-listen/232.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32%2fStuxnet&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#365da0&quot;&gt;Stuxnet&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; is a severe threat &amp;ndash; that&amp;rsquo;s something we know for sure. But if we look at it, &amp;nbsp;what do we really know? What can we lear ...</description>
<pubDate>Tue, 12 Oct 2010 15:47:57 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/12/stuxnet-talks--do-we-listen/232.aspx</guid>
</item>
<item>
<title>PCI and Breach Data</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/11/pci-and-breach-data/231.aspx</link>
<description>&lt;p&gt;Last week the Verizon Risk Team released an &lt;a href=&quot;http://securityblog.verizonbusiness.com/&quot;&gt;interesting report&amp;nbsp;&lt;/a&gt;in which, among other things, they compared breach result information against norms for PCI DSS compliance.&amp;nbsp;I can't imagine anyone is really all that surprised to see th ...</description>
<pubDate>Mon, 11 Oct 2010 22:28:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/11/pci-and-breach-data/231.aspx</guid>
</item>
<item>
<title>Practicing Continuous PCI DSS Compliance</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/7/practicing-continuous-pci-dss-compliance/229.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The importance of ongoing/continuous PCI DSS compliance processes as an effective means to curb security breaches at a merchant&amp;rsquo;s site is being touted by many experts in the PCI field lately. &lt;a href=&quot;http://www.verizonbusiness.com/about/news/pr-25614-en-First+of+its+Kind+V ...</description>
<pubDate>Thu, 07 Oct 2010 13:53:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/7/practicing-continuous-pci-dss-compliance/229.aspx</guid>
</item>
<item>
<title>The Power of Security Education</title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/6/the-power-of-security-education/224.aspx</link>
<description>&lt;p&gt;While doing research for an upcoming feature on insider threats, I had a conversation with Nick Levay, information security and operations manager at the &lt;a href=&quot;http://www.americanprogress.org/&quot;&gt;Center for American Progress&lt;/a&gt; (CAP), a DC-based think tank. Although some of what he shared could ...</description>
<pubDate>Wed, 06 Oct 2010 17:47:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/6/the-power-of-security-education/224.aspx</guid>
</item>
<item>
<title>Path to PCI DSS Compliance: High Incidence of WiFi Vulnerabilities </title>
<link>http://www.infosecurity-magazine.com/blog/2010/10/4/path-to-pci-dss-compliance-high-incidence-of-wifi-vulnerabilities-/223.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The Deadline to comply with PCI DSS requirements, set for Level 1 Merchants by VISA, recently passed on Sept. 30,&amp;nbsp;2010. However,&amp;nbsp;what we do not yet know is&amp;nbsp;how many of these merchants have successfully met the compliance requirements.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div ...</description>
<pubDate>Mon, 04 Oct 2010 13:51:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/10/4/path-to-pci-dss-compliance-high-incidence-of-wifi-vulnerabilities-/223.aspx</guid>
</item>
<item>
<title>WiFi consumerization raising security concerns</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/29/wifi-consumerization-raising-security-concerns/221.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;The growing WiFi capability in the variety of consumer devices is readily evident nowadays. These devices include cameras, camcorders, printers, scanners, smartphones, televisions, music/video players, e-book readers and many more. Having been equipped with WiFi capability, these ...</description>
<pubDate>Wed, 29 Sep 2010 12:37:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/29/wifi-consumerization-raising-security-concerns/221.aspx</guid>
</item>
<item>
<title>Customer Experience: Security Can Improve in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/28/customer-experience-security-can-improve-in-the-cloud/220.aspx</link>
<description>&lt;p&gt;Last week, when I was in South Africa, a partner of us pointed me to a very interesting paper by KPMG called &lt;a target=&quot;_blank&quot; href=&quot;http://www.kpmg.com/AU/en/IssuesAndInsights/ArticlesPublications/Pages/Cloud-computing-Australian-lessons-and-experiences.aspx&quot; onclick=&quot;javascript:_gaq.push(['_tr ...</description>
<pubDate>Tue, 28 Sep 2010 15:03:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/28/customer-experience-security-can-improve-in-the-cloud/220.aspx</guid>
</item>
<item>
<title>Bigger than the Cloud?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/23/bigger-than-the-cloud/218.aspx</link>
<description>&lt;p&gt;Laura Smith over at &lt;a href=&quot;http://:http://searchcio.techtarget.com/news/2240022577/Mobile-phone-security-policies-give-IT-some-control-over-the-influx&quot;&gt;SearchCIO&amp;nbsp;&lt;/a&gt; recently covered the explosive growth of the iPhone and other smartphones in the business sector, and how that growth is re ...</description>
<pubDate>Thu, 23 Sep 2010 22:16:38 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/23/bigger-than-the-cloud/218.aspx</guid>
</item>
<item>
<title>The Risks of Unofficial Patches</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/17/the-risks-of-unofficial-patches/215.aspx</link>
<description>&lt;p&gt;This is quite a normal scenario: A zero-day pops up on the Internet by a security researcher. Immediately afterwards we see the first exploits appearing and being integrated into the different attack tools. Now, the race has started: The vendor has to develop a security update, the criminals try  ...</description>
<pubDate>Fri, 17 Sep 2010 09:09:42 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/17/the-risks-of-unofficial-patches/215.aspx</guid>
</item>
<item>
<title>One-sided Explosion</title>
<link>http://www.infosecurity-magazine.com/blog/2010/9/9/onesided-explosion/207.aspx</link>
<description>&lt;p&gt;Consumerization&amp;nbsp;&amp;ndash; the use of consumer products within the corporate environment, is one of the more challenging issues for security teams to deal with. While a standard, well-defined, and well-protected infrastrucutre is a nice idea, there is more and more pressure to open up the netwo ...</description>
<pubDate>Thu, 09 Sep 2010 20:43:08 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/9/9/onesided-explosion/207.aspx</guid>
</item>
<item>
<title>PCI, AV and a life vest</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/25/pci-av-and-a-life-vest/201.aspx</link>
<description>&lt;p&gt;A good friend of mine over at &lt;a href=&quot;http://www.netiq.com&quot;&gt;NetIQ&lt;/a&gt;, Todd Tucker, recently &lt;a href=&quot;http://community.netiq.com/blogs/security_webb/archive/2010/08/23/reliance-on-antivirus-software-the-real-failure-of-pci-dss.aspx&quot;&gt;blogged&lt;/a&gt;&amp;nbsp;about some of the frustrations he sees when lo ...</description>
<pubDate>Wed, 25 Aug 2010 14:38:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/25/pci-av-and-a-life-vest/201.aspx</guid>
</item>
<item>
<title>The Importance of Application Security</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/24/the-importance-of-application-security/200.aspx</link>
<description>&lt;p&gt;I think I told this story thousands of times, and everybody knows it, but I will do it for the 1001&lt;sup&gt;&lt;font size=&quot;2&quot;&gt;st&lt;/font&gt;&lt;/sup&gt; time now. When I joined Microsoft and became what is the Chief Security Advisor for Switzerland today, we had an airlift for Windows Server 2003. The Product Mana ...</description>
<pubDate>Tue, 24 Aug 2010 15:53:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/24/the-importance-of-application-security/200.aspx</guid>
</item>
<item>
<title>Should RIM hold its line on the BlackBerry?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/18/should-rim-hold-its-line-on-the-blackberry/198.aspx</link>
<description>&lt;p&gt;Encryption is the sort of topic that rarely makes it into the mainstream media, but the recent hoopla over BlackBerry security, namely its encryption procedures, has drawn the ire of governments throughout Asia. &lt;/p&gt;
&lt;p&gt;India, the UAE, Saudi Arabia &amp;ndash; all have taken issue with BlackBerry se ...</description>
<pubDate>Wed, 18 Aug 2010 16:17:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/18/should-rim-hold-its-line-on-the-blackberry/198.aspx</guid>
</item>
<item>
<title>Blocking Social Media Sites–a False Sense of Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/14/blocking-social-media-sitesa-false-sense-of-security/196.aspx</link>
<description>&lt;p&gt;I blog often about it: Blocking certain websites today can fire back in different ways. The CIO published an article called &lt;a target=&quot;_blank&quot; href=&quot;http://www.cio.com/article/603054/Workarounds_5_Ways_Employees_Try_to_Access_Restricted_Sites&quot;&gt;Workarounds: 5 Ways Employees Try to Access Restricte ...</description>
<pubDate>Sat, 14 Aug 2010 18:28:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/14/blocking-social-media-sitesa-false-sense-of-security/196.aspx</guid>
</item>
<item>
<title>I-Coverage</title>
<link>http://www.infosecurity-magazine.com/blog/2010/8/13/icoverage/195.aspx</link>
<description>&lt;p&gt;I wanted to comment a little on the &lt;a href=&quot;http://www.infosecurity-us.com/view/11728/apple-pushes-security-updates-for-mobile-devices/&quot;&gt;recent stir &lt;/a&gt;concerning the vulnerabilities on the iPhone (iPad, iTouch, I-Robot.&amp;nbsp; No, wait, that's a movie.)&lt;/p&gt;
&lt;p&gt;I think the level of interest in  ...</description>
<pubDate>Fri, 13 Aug 2010 14:31:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/8/13/icoverage/195.aspx</guid>
</item>
<item>
<title>Adobe CS7 Searches Saturated With Dangerous Results</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/30/adobe-cs7-searches-saturated-with-dangerous-results/192.aspx</link>
<description>&lt;p&gt;Looking to save a few bucks on software will almost always lead users down a dangerous path.&amp;nbsp;Users either end up at &amp;ldquo;OEM Software&amp;rdquo; sites offering unlicensed and illegal software, or to downloading cracks or keygens laced with malware.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
One of the big issues h ...</description>
<pubDate>Fri, 30 Jul 2010 14:02:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/30/adobe-cs7-searches-saturated-with-dangerous-results/192.aspx</guid>
</item>
<item>
<title>Microsoft and Adobe: Collaboration Against Threats</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/28/microsoft-and-adobe-collaboration-against-threats/191.aspx</link>
<description>&lt;p&gt;You know my opinion on collaboration between countries, on public-private-partnerships, as well as on collaboration between companies.&lt;/p&gt;
&lt;p&gt;For&amp;nbsp;quite a while we have been running&amp;nbsp;a program called MAPP &amp;ndash; the &lt;a href=&quot;http://www.microsoft.com/security/msrc/collaboration/mapp.aspx ...</description>
<pubDate>Wed, 28 Jul 2010 17:39:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/28/microsoft-and-adobe-collaboration-against-threats/191.aspx</guid>
</item>
<item>
<title>WPA2 Exposed with 'Hole 196' Vulnerability</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/23/wpa2-exposed-with-hole-196-vulnerability/189.aspx</link>
<description>&lt;p&gt;Until now, the WPA security version known as &amp;lsquo;WPA2 (AES encryption) with 802.1x authentication&amp;rsquo;&amp;nbsp;was considered as one of most secure WiFi deployments by most wireless security experts. This is due to the resilience of this version to brute force dictionary attacks that can possib ...</description>
<pubDate>Fri, 23 Jul 2010 06:06:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/23/wpa2-exposed-with-hole-196-vulnerability/189.aspx</guid>
</item>
<item>
<title>It's all about WHO</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/8/its-all-about-who/186.aspx</link>
<description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;I KEEP six honest serving-men&lt;br /&gt;
&amp;nbsp;(They taught me all I knew);&lt;br /&gt;
Their names are What and Why and When &lt;br /&gt;
&amp;nbsp;And How and Where and Who.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;&lt;blockquote&gt;
&lt;p&gt;&lt;a href=&quot;http://www.kipling.org.uk/poems_serving.htm&quot;&gt;&amp;ndash; Rudya ...</description>
<pubDate>Thu, 08 Jul 2010 21:13:30 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/8/its-all-about-who/186.aspx</guid>
</item>
<item>
<title>Cloud Computing: Benefits and Risks of Moving Federal IT into the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/6/cloud-computing-benefits-and-risks-of-moving-federal-it-into-the-cloud/184.aspx</link>
<description>&lt;p&gt;July 1st: Scott Charney, Corporate Vice President Trustworthy Computing was testifying at a hearing of the House Committee on Oversight and Government Reform. Basically the hearing was on the benefits and risk of Cloud adoption for the US government. If you are interested in reading his full test ...</description>
<pubDate>Tue, 06 Jul 2010 14:17:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/6/cloud-computing-benefits-and-risks-of-moving-federal-it-into-the-cloud/184.aspx</guid>
</item>
<item>
<title>Secure WiFi Networks: WiFi Alliance and Legal Authorities Coming Forward</title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/5/secure-wifi-networks-wifi-alliance-and-legal-authorities-coming-forward/183.aspx</link>
<description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;WiFi, today, has become a &lt;a href=&quot;http://gigaom.com/2009/08/23/look-how-ubiquitous-wi-fi-has-become/&quot;&gt;near ubiquitous technology&lt;/a&gt;, used by most of us, with our WiFi enabled gadgets, while we are at offices, homes, public places or while traveling. However, awareness about WiF ...</description>
<pubDate>Mon, 05 Jul 2010 08:12:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/5/secure-wifi-networks-wifi-alliance-and-legal-authorities-coming-forward/183.aspx</guid>
</item>
<item>
<title>Do Enjoy 'One Click' Free WiFi at Starbucks, but Safeguard Your Privacy </title>
<link>http://www.infosecurity-magazine.com/blog/2010/7/1/do-enjoy-one-click-free-wifi-at-starbucks-but-safeguard-your-privacy-/182.aspx</link>
<description>&lt;p&gt;Six months after McDonalds started offering free WiFi, Starbucks also announced&amp;nbsp;it would provide&amp;nbsp;complimentary&amp;nbsp;WiFi service, starting July 1, 2010. &lt;a href=&quot;http://www.starbucks.com/coffeehouse/wireless-internet&quot;&gt;As mentioned by Starbucks&lt;/a&gt;, the free WiFi will be unlimited and re ...</description>
<pubDate>Thu, 01 Jul 2010 15:43:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/7/1/do-enjoy-one-click-free-wifi-at-starbucks-but-safeguard-your-privacy-/182.aspx</guid>
</item>
<item>
<title>Russian Spies in the US: Corporate Spies Could Follow their Communication Methods</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/30/russian-spies-in-the-us-corporate-spies-could-follow-their-communication-methods/181.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/world/us_and_canada/10442869.stm&quot;&gt;As reported recently&lt;/a&gt;, Russian spies in US used private WiFi networks as a means for secret communications. These networks were found to be operating in &lt;a href=&quot;http://www.wi-fiplanet.com/tutorials/article.php/1451421/Under ...</description>
<pubDate>Wed, 30 Jun 2010 14:05:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/30/russian-spies-in-the-us-corporate-spies-could-follow-their-communication-methods/181.aspx</guid>
</item>
<item>
<title>Red Button SEO Poisoning and Malware Campaign</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/30/red-button-seo-poisoning-and-malware-campaign/180.aspx</link>
<description>&lt;p&gt;eSoft researchers have been tracking a new campaign by cybercrooks, compromising and creating websites for use in SEO poisoning and malware distribution. Thousands of these sites have been detected&amp;nbsp;that&amp;nbsp;use elaborate techniques to trick search engines and are ready to serve malware in a ...</description>
<pubDate>Wed, 30 Jun 2010 02:56:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/30/red-button-seo-poisoning-and-malware-campaign/180.aspx</guid>
</item>
<item>
<title>WiFi malfunction at iPhone 4 launch reinforced the need of Wireless Intrusion Detection Systems (WIDS)</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/29/wifi-malfunction-at-iphone-4-launch-reinforced-the-need-of-wireless-intrusion-detection-systems-wids/179.aspx</link>
<description>&lt;p&gt;&lt;a href=&quot;http://futuretense.publicradio.org/blog/index.php?id=677444556&quot;&gt;An after look&lt;/a&gt; into the cause of WiFi malfunction experienced by Steve Jobs&amp;nbsp;during the&amp;nbsp;recently conducted iPhone 4 launch at Apple's flagship Worldwide Developers Conference (WWDC) has revealed that around 500 m ...</description>
<pubDate>Tue, 29 Jun 2010 06:04:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/29/wifi-malfunction-at-iphone-4-launch-reinforced-the-need-of-wireless-intrusion-detection-systems-wids/179.aspx</guid>
</item>
<item>
<title>Google’s WiFi Snooping Controversy Is a Wake-up Call to Stop WiFi Malpractices

</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/25/googles-wifi-snooping-controversy-is-a-wakeup-call-to-stop-wifi-malpractices/178.aspx</link>
<description>&lt;p&gt;The ongoing storm over Google's collection of private WiFi data doesn't seems to be ending anytime soon. It all started when German authorities asked Google to audit the WiFi data collected by Google's Street View cars and Google responded to this by re-examining the collected data. The re-examin ...</description>
<pubDate>Fri, 25 Jun 2010 11:33:21 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/25/googles-wifi-snooping-controversy-is-a-wakeup-call-to-stop-wifi-malpractices/178.aspx</guid>
</item>
<item>
<title>Proposed cybersecurity bill: stop calling it a “Kill Switch”</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/22/proposed-cybersecurity-bill-stop-calling-it-a-kill-switch/176.aspx</link>
<description>&lt;p&gt;Unless I am mistaken &amp;ndash; and not being a lawyer, this is a distinct possibility &amp;ndash; but the &lt;a href=&quot;http://www.infosecurity-us.com/view/10217/senate-introduces-sweeping-cybersecurity-bill/&quot;&gt;cybersecurity bill proposed in the senate earlier this month&lt;/a&gt; does nothing to create a so-calle ...</description>
<pubDate>Tue, 22 Jun 2010 21:23:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/22/proposed-cybersecurity-bill-stop-calling-it-a-kill-switch/176.aspx</guid>
</item>
<item>
<title>Raid against Piracy</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/22/raid-against-piracy/175.aspx</link>
<description>&lt;p&gt;There seem to be policy organizations&amp;nbsp;that are&amp;nbsp;serious about fighting piracy! Hungary, actually with 41% pirated software &amp;ldquo;not even that bad&amp;rdquo;, seems to be really serious. But first, let me just take those 41% up for a second: This means that 41% of the work you do is stolen. ...</description>
<pubDate>Tue, 22 Jun 2010 21:00:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/22/raid-against-piracy/175.aspx</guid>
</item>
<item>
<title>Who's On First?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/18/whos-on-first/174.aspx</link>
<description>&lt;p&gt;It&amp;rsquo;s hard not to love Abbott and Costello.&lt;/p&gt;
&lt;p&gt;The&lt;a href=&quot;http://en.wikipedia.org/wiki/Whos_on_first&quot;&gt;&amp;ldquo;Who&amp;rsquo;s on first&amp;rdquo;&lt;/a&gt; routine has become a staple of Americana even for foreign transplants like me. But if figuring out the identity of who is on second base (no, wai ...</description>
<pubDate>Fri, 18 Jun 2010 17:12:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/18/whos-on-first/174.aspx</guid>
</item>
<item>
<title>The Importance of International Collaboration –Even in Exercises</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/16/the-importance-of-international-collaboration-even-in-exercises/173.aspx</link>
<description>&lt;p&gt;One of the biggest challenges in Critical Infrastructure Protection or Incident Response is collaboration. Collaboration between the public and the private sector as the private sector is most often running the critical infrastructure; collaboration between different governments as well, as incid ...</description>
<pubDate>Wed, 16 Jun 2010 02:52:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/16/the-importance-of-international-collaboration-even-in-exercises/173.aspx</guid>
</item>
<item>
<title>Should the Government be able to enforce security updates?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/12/should-the-government-be-able-to-enforce-security-updates/172.aspx</link>
<description>&lt;p&gt;This is actually an interesting question. A lot of governments enforce rules and regulations on how you have to run your car, how often you have to check it, in which condition you have to keep your tires, etc. The same is true for a lot of other devices we are using.&lt;/p&gt;
&lt;p&gt;Now, it seems that t ...</description>
<pubDate>Sat, 12 Jun 2010 07:58:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/12/should-the-government-be-able-to-enforce-security-updates/172.aspx</guid>
</item>
<item>
<title>Open Source and Hackers</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/8/open-source-and-hackers/170.aspx</link>
<description>&lt;p&gt;The debate is probably as old as the Open Source software development model &amp;ndash; Which one is more secure: Open Source or shared source as we at Microsoft run it? I know that we could now enter a religious debate about that, which I do not want to as I do not really believe in the value of suc ...</description>
<pubDate>Tue, 08 Jun 2010 12:49:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/8/open-source-and-hackers/170.aspx</guid>
</item>
<item>
<title>New Email Phish Targets Twitter Users, Abuses Google Groups</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/8/new-email-phish-targets-twitter-users-abuses-google-groups/169.aspx</link>
<description>&lt;p&gt;A new twitter spam campaign is making rounds, infecting users with rogue anti-virus malware. The spam mail attempts to convince the user that someone was trying to steal their Twitter account information, and to download a &amp;ldquo;secure module&amp;rdquo; to protect their account. &lt;br /&gt;
&lt;br /&gt;
The  ...</description>
<pubDate>Tue, 08 Jun 2010 01:17:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/8/new-email-phish-targets-twitter-users-abuses-google-groups/169.aspx</guid>
</item>
<item>
<title>135 000 Fake YouTube Pages Delivering Malware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/7/135-000-fake-youtube-pages-delivering-malware/168.aspx</link>
<description>&lt;p&gt;The eSoft Threat Prevention Team has uncovered thousands compromised web servers hosting fake YouTube pages.&amp;nbsp;Attempting to play the video on these fake pages prompts the user to install a &amp;lsquo;media codec&amp;rsquo; which then infects the machine with malware. &lt;br /&gt;
&lt;br /&gt;
The fake YouTube  ...</description>
<pubDate>Mon, 07 Jun 2010 20:42:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/7/135-000-fake-youtube-pages-delivering-malware/168.aspx</guid>
</item>
<item>
<title>Security, Cloud and a Little Pixie Dust</title>
<link>http://www.infosecurity-magazine.com/blog/2010/6/1/security-cloud-and-a-little-pixie-dust/167.aspx</link>
<description>&lt;p&gt;When Peter Pan is trying to convince Wendy to fly, he tells her all she needs is &amp;ldquo;Faith, trust, and a little Pixie dust.&amp;rdquo;&amp;nbsp; Which, to be fair, appeared to work for the lost boys.&amp;nbsp; In &lt;a href=&quot;http://www.infosecurity-us.com/view/9824/cloud-computing-could-help-improve-security ...</description>
<pubDate>Tue, 01 Jun 2010 14:51:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/6/1/security-cloud-and-a-little-pixie-dust/167.aspx</guid>
</item>
<item>
<title>Hacking the human body</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/27/hacking-the-human-body/166.aspx</link>
<description>&lt;p&gt;Years ago I was sitting in a healthcare event, when a researcher was talking (very excited) about the idea of having a pacemaker with Bluetooth access to fine-tune the system and read information from the sensors. Even though this might medically be a great idea, I would be fairly reluctant havin ...</description>
<pubDate>Thu, 27 May 2010 06:51:51 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/27/hacking-the-human-body/166.aspx</guid>
</item>
<item>
<title>Identity in the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/25/identity-in-the-cloud/165.aspx</link>
<description>&lt;p&gt;Kim Cameron, one of our key identity architects had an interesting presentation on identity in the cloud and a corresponding interview. Both are worth looking at if you are planning to move into the direction of the cloud. Especially as it is definitely one of the key challenges:&lt;/p&gt;
&lt;p&gt;This is  ...</description>
<pubDate>Tue, 25 May 2010 20:57:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/25/identity-in-the-cloud/165.aspx</guid>
</item>
<item>
<title>Outsourcing Insider Attack?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/20/outsourcing-insider-attack/164.aspx</link>
<description>&lt;p&gt;I know one or two other bloggers have spotted the following news piece too, notably Bruce Schneier, but it&amp;rsquo;s hard to pass up an opportunity to not only comment, but to draw some wider parallels with other market trends in IT. The &lt;a href=&quot;http://news.bbc.co.uk/2/hi/south_asia/8677486.stm&quot;&gt;B ...</description>
<pubDate>Thu, 20 May 2010 17:34:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/20/outsourcing-insider-attack/164.aspx</guid>
</item>
<item>
<title>Customer Stories: Why it is not THAT easy to move to the Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud/162.aspx</link>
<description>&lt;p&gt;As you know from my postings on Cloud and security and the paper on the &lt;a href=&quot;http://go.microsoft.com/?linkid=9708479&quot; target=&quot;_blank&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Cloud Security Considerations&lt;/font&gt;&lt;/a&gt; we wrote, I am convinced that there are five areas you should look at when you try to migrate to ...</description>
<pubDate>Wed, 19 May 2010 10:33:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud/162.aspx</guid>
</item>
<item>
<title>Phishing Scams Lure Twitter Users</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/14/phishing-scams-lure-twitter-users/161.aspx</link>
<description>&lt;p&gt;The newest phishing scam on Twitter has snared thousands of users hoping to increase their number of followers.&amp;nbsp; Instead, users are sent off to a phishing page where cybercriminals steal their Twitter logins using them to generate more spam.&lt;br /&gt;
&lt;br /&gt;
Thousands of spam messages are floa ...</description>
<pubDate>Fri, 14 May 2010 20:05:08 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/14/phishing-scams-lure-twitter-users/161.aspx</guid>
</item>
<item>
<title>HITECH, breaches, and a little sunlight</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/13/hitech-breaches-and-a-little-sunlight/160.aspx</link>
<description>&lt;p&gt;A good article in &lt;a href=&quot;http://www.infosecurity-us.com/view/9233/&quot;&gt;InfoSecurity &lt;/a&gt;on May 5th on the &lt;a href=&quot;http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/hitechenforcementifr.html&quot;&gt;HITECH &lt;/a&gt;act got me thinking (as good articles should) about health records, security, ...</description>
<pubDate>Thu, 13 May 2010 23:06:58 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/13/hitech-breaches-and-a-little-sunlight/160.aspx</guid>
</item>
<item>
<title>Google Groups Latest Hot Spot for Rogue AV and Malware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/12/google-groups-latest-hot-spot-for-rogue-av-and-malware/159.aspx</link>
<description>&lt;p&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;word-spacing: 0px; font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: medium; line-height: normal; font-size-adjust: none; font-stretch: normal; text-transform: none; color: rgb(0, 0, 0); text-indent: 0px ...</description>
<pubDate>Wed, 12 May 2010 19:06:47 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/12/google-groups-latest-hot-spot-for-rogue-av-and-malware/159.aspx</guid>
</item>
<item>
<title>Looking back at Infosecurity Europe 2010</title>
<link>http://www.infosecurity-magazine.com/blog/2010/5/10/looking-back-at-infosecurity-europe-2010/158.aspx</link>
<description>&lt;p&gt;Late April was highlighted by my first trip to &lt;a href=&quot;http://www.infosec.co.uk/&quot;&gt;Infosecurity Europe&lt;/a&gt; in London. While I understand that this event received its fair share of criticism in the press for being past its prime, there were certainly aspects of the conference that made it worthwhi ...</description>
<pubDate>Mon, 10 May 2010 18:29:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/5/10/looking-back-at-infosecurity-europe-2010/158.aspx</guid>
</item>
<item>
<title>Pharma-Fraud Continues to Dominate Spam</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/22/pharmafraud-continues-to-dominate-spam/156.aspx</link>
<description>&lt;p&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;word-spacing: 0px; font: medium 'Times New Roman'; text-transform: none; color: rgb(0,0,0); text-indent: 0px; white-space: normal; letter-spacing: normal; border-collapse: separate; orphans: 2; widows: 2&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: 13px; ...</description>
<pubDate>Thu, 22 Apr 2010 18:05:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/22/pharmafraud-continues-to-dominate-spam/156.aspx</guid>
</item>
<item>
<title>A Detailed Analysis of an Attack – Do We Need an International Incident Sharing Database?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/21/a-detailed-analysis-of-an-attack--do-we-need-an-international-incident-sharing-database/155.aspx</link>
<description>&lt;p&gt;I recently came across a paper called &lt;a target=&quot;_blank&quot; href=&quot;http://www.shadows-in-the-cloud.net/&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Shadows in the Cloud&lt;/font&gt;&lt;/a&gt;, which is actually a follow-up report of &lt;a target=&quot;_blank&quot; href=&quot;http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-E ...</description>
<pubDate>Wed, 21 Apr 2010 13:51:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/21/a-detailed-analysis-of-an-attack--do-we-need-an-international-incident-sharing-database/155.aspx</guid>
</item>
<item>
<title>Tiger Woods (Searches) Not to Be Trusted</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/8/tiger-woods-searches-not-to-be-trusted/153.aspx</link>
<description>&lt;p&gt;Tiger Woods&amp;rsquo; personal life and marital affairs have attracted constant  attention from the press and has certainly damaged his public  reputation.&amp;nbsp; With his return to the Masters, Nike has  released a new commercial in an effort to rebuild Woods&amp;rsquo; image.&amp;nbsp; This  compelling com ...</description>
<pubDate>Thu, 08 Apr 2010 21:32:04 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/8/tiger-woods-searches-not-to-be-trusted/153.aspx</guid>
</item>
<item>
<title>Affiliate Programs Rising Cause of Fraud and Abuse</title>
<link>http://www.infosecurity-magazine.com/blog/2010/4/5/affiliate-programs-rising-cause-of-fraud-and-abuse/151.aspx</link>
<description>&lt;p&gt;What happens when you offer up money to anyone who can drive traffic to your website?&amp;nbsp;Hackers, scammers, spammers and fraudsters come to your aid.&amp;nbsp;That&amp;rsquo;s the case with online movie site &lt;a href=&quot;http://www.zml.com/&quot;&gt;zml.com&lt;/a&gt;, which offers 30% of each sale and 5% of rebills paid ...</description>
<pubDate>Mon, 05 Apr 2010 14:15:03 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/4/5/affiliate-programs-rising-cause-of-fraud-and-abuse/151.aspx</guid>
</item>
<item>
<title>Council of Europe – Octopus Conference (Cooperation against Cybercrime) – Key Messages</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/26/council-of-europe--octopus-conference-cooperation-against-cybercrime--key-messages/150.aspx</link>
<description>&lt;p&gt;I blogged on &lt;a target=&quot;_blank&quot; href=&quot;http://www.halbheer.info/security/2010/03/23/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-1&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Day 1&lt;/font&gt;&lt;/a&gt; and &lt;a target=&quot;_blank&quot; href=&quot;http://www.halbheer.info/security/2010/03/24/council-of-europe-octopus- ...</description>
<pubDate>Fri, 26 Mar 2010 20:51:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/26/council-of-europe--octopus-conference-cooperation-against-cybercrime--key-messages/150.aspx</guid>
</item>
<item>
<title>Council of Europe – Octopus Conference (Cooperation against Cybercrime) Day 2</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-2/149.aspx</link>
<description>&lt;p&gt;And the second day starts. I just met with Jeremy Kirk from IDG and it is great to see that the press is actually interested in such a conference as well.&lt;/p&gt;
&lt;p&gt;The day today started with a long session on different initiatives against cybercrime. A lot of good information:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt; ...</description>
<pubDate>Wed, 24 Mar 2010 16:12:39 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-2/149.aspx</guid>
</item>
<item>
<title>Council of Europe: We need ONE Cybercrime Convention</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe-we-need-one-cybercrime-convention/148.aspx</link>
<description>&lt;p&gt;As you saw from previous posts, I am at the Octopus Conference on Cooperation against Cybercrime at the moment. We had yesterday the Deputy Secretary General of the Council of Europe and one of her key statements was that different bodies (like the Council of Europe, UN etc.) should not compete.  ...</description>
<pubDate>Wed, 24 Mar 2010 08:31:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/24/council-of-europe-we-need-one-cybercrime-convention/148.aspx</guid>
</item>
<item>
<title>Council of Europe – Octopus Conference (Cooperation against Cybercrime) Day 1</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/23/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-1/147.aspx</link>
<description>&lt;p&gt;A few years ago, the Budapest Convention on Cybercrime was signed within the Council of Europe. Since then it was ratified all across the globe by a lot of countries or at least used as the base for legislation. The Council of Europe is organising a conference on &lt;a target=&quot;_blank&quot; href=&quot;http://w ...</description>
<pubDate>Tue, 23 Mar 2010 15:22:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/23/council-of-europe--octopus-conference-cooperation-against-cybercrime-day-1/147.aspx</guid>
</item>
<item>
<title>Cinderella Story Leads to March Madness Malware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/22/cinderella-story-leads-to-march-madness-malware/146.aspx</link>
<description>&lt;p&gt;The first week of March Madness has brought about many compelling stories, with a good deal of upsets and bracket busters. The most newsworthy of these has been the University of Northern Iowa&amp;rsquo;s ousting of #1 overall seed Kansas. This &amp;lsquo;Cinderella&amp;rsquo; story has deservedly gotten a g ...</description>
<pubDate>Mon, 22 Mar 2010 13:33:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/22/cinderella-story-leads-to-march-madness-malware/146.aspx</guid>
</item>
<item>
<title>Results of Operation b49 (Botnet Takedown)</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/20/results-of-operation-b49-botnet-takedown/145.aspx</link>
<description>&lt;p&gt;On February 24th we announced the work we did on taking down Waledac &amp;ndash; read Tim Cranton&amp;rsquo;s blog post called &lt;a target=&quot;_blank&quot; href=&quot;http://microsoftontheissues.com/cs/blogs/mscorp/archive/2010/02/24/cracking-down-on-botnets.aspx&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Cracking Down on Botnets&lt;/font&gt;&lt;/ ...</description>
<pubDate>Sat, 20 Mar 2010 14:06:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/20/results-of-operation-b49-botnet-takedown/145.aspx</guid>
</item>
<item>
<title>Strong Authentication and Privacy – A Contradiction in Terms?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/17/strong-authentication-and-privacy--a-contradiction-in-terms/144.aspx</link>
<description>&lt;p style=&quot;text-align: left&quot;&gt;You know that I am not a big fan of the requirement for having all Internet users authenticate strongly. There are people in the security arena who think that this is the only way to fight cybercrime &amp;ndash; and in parallel accept that they would kill freedom of speech.&lt;/ ...</description>
<pubDate>Wed, 17 Mar 2010 21:32:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/17/strong-authentication-and-privacy--a-contradiction-in-terms/144.aspx</guid>
</item>
<item>
<title>Insider Threat of Cloud Computing</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/11/insider-threat-of-cloud-computing/142.aspx</link>
<description>&lt;p&gt;Tonight I got this&amp;nbsp;article forwarded to me: &lt;a target=&quot;_blank&quot; href=&quot;http://www.infoworld.com/d/cloud-computing/afraid-outside-cloud-attacks-youre-missing-real-threat-894?source=IFWNLE_nlt_daily_2010-03-10&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Afraid of outside cloud attacks? You're missing the real threat ...</description>
<pubDate>Thu, 11 Mar 2010 09:19:54 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/11/insider-threat-of-cloud-computing/142.aspx</guid>
</item>
<item>
<title>Data Protection Heat Map</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/9/data-protection-heat-map/141.aspx</link>
<description>&lt;p&gt;I was looking at some research done by Forrester, which could be interesting for you as well. They try to lay out the landscape with regards to data protection for you and it looks fairly compelling. So if you are interested in the situation of the different Privacy laws across the globe and how  ...</description>
<pubDate>Tue, 09 Mar 2010 20:27:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/9/data-protection-heat-map/141.aspx</guid>
</item>
<item>
<title>Why it pays to be secure – Chapter 5 – I need tools!</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/6/why-it-pays-to-be-secure--chapter-5--i-need-tools/140.aspx</link>
<description>&lt;p&gt;Our EMEA Security Program Manager, Henk van Roest, started this series internally and with his consent I am publishing it here in my blog as I think it contains a lot of great information for you to use.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;So far, in the first 4 chapters, we have addressed the usual excuses for not  ...</description>
<pubDate>Sat, 06 Mar 2010 23:25:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/6/why-it-pays-to-be-secure--chapter-5--i-need-tools/140.aspx</guid>
</item>
<item>
<title>Virus Alert! Twitter, Google, Hallmark and Others Subject To Attack</title>
<link>http://www.infosecurity-magazine.com/blog/2010/3/5/virus-alert-twitter-google-hallmark-and-others-subject-to-attack/139.aspx</link>
<description>&lt;p&gt;The eSoft Threat Prevention Team is warning customers today of a new email scam circulating very quickly. &amp;nbsp;These fraudulent emails claim to be from Google Staffing, Hallmark, Twitter as well as other social networks and legitimate businesses.&lt;br /&gt;
&lt;br /&gt;
The email persuades the user to op ...</description>
<pubDate>Fri, 05 Mar 2010 22:12:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/3/5/virus-alert-twitter-google-hallmark-and-others-subject-to-attack/139.aspx</guid>
</item>
<item>
<title>Making the Management of Security Compliance Easier!</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/18/making-the-management-of-security-compliance-easier/138.aspx</link>
<description>&lt;p&gt;As you all know, I have two main pet themes: Risk Management and Compliance Management as I see very often that there is room for improvement when it comes to such processes within our customers. Internally, we often think about how we can make it easier for our customers to manage compliance in  ...</description>
<pubDate>Thu, 18 Feb 2010 19:59:26 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/18/making-the-management-of-security-compliance-easier/138.aspx</guid>
</item>
<item>
<title>SANS Top 25 Most Dangerous Programming Errors – the same as very often…</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/17/sans-top-25-most-dangerous-programming-errors--the-same-as-very-often/137.aspx</link>
<description>&lt;p&gt;I just worked my way through the &lt;a target=&quot;_blank&quot; href=&quot;http://cwe.mitre.org/top25/&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;list SANS published&lt;/font&gt;&lt;/a&gt;. Looking at the list it is not surprising but scary to see which errors made it to the top of the list:&lt;/p&gt;
&lt;ol&gt;
    &lt;li&gt;Cross-site Scripting&lt;/li&gt;
    &lt;li ...</description>
<pubDate>Wed, 17 Feb 2010 16:42:00 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/17/sans-top-25-most-dangerous-programming-errors--the-same-as-very-often/137.aspx</guid>
</item>
<item>
<title>Hotmail Users Look for Answers in Dangerous Places</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/17/hotmail-users-look-for-answers-in-dangerous-places/136.aspx</link>
<description>&lt;p&gt;An &lt;a href=&quot;http://windowsteamblog.com/blogs/windowslive/archive/2010/02/16/short-outage-now-resolved.aspx&quot;&gt;outage&lt;/a&gt; of the Windows Live ID service affected a large number of MSN users today, including users of the popular Hotmail email service. Hotmail is one of the largest web-based email out ...</description>
<pubDate>Wed, 17 Feb 2010 13:57:33 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/17/hotmail-users-look-for-answers-in-dangerous-places/136.aspx</guid>
</item>
<item>
<title>Children – A Threat For Corporate Security?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/10/children--a-threat-for-corporate-security/131.aspx</link>
<description>&lt;p&gt;I read this article this morning: &lt;a target=&quot;_blank&quot; href=&quot;http://www.computerweekly.com/Articles/2010/02/09/240236/Safer-Internet-Day-How-children-can-undermine-corporate.htm&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Safer Internet Day: How children can undermine corporate security&lt;/font&gt;&lt;/a&gt; and it actually remin ...</description>
<pubDate>Wed, 10 Feb 2010 12:28:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/10/children--a-threat-for-corporate-security/131.aspx</guid>
</item>
<item>
<title>Use Music to Fight Cybercrime: ‘Maga No Need Pay’</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/9/use-music-to-fight-cybercrime-maga-no-need-pay/130.aspx</link>
<description>&lt;p&gt;When I travel through Africa, the high piracy rate is often something we address. Not necessarily from a commercial perspective but much more from a security angle. We know that pirated software is often infected with malware and therefore used for criminal activities. However, the discussion is  ...</description>
<pubDate>Tue, 09 Feb 2010 12:34:59 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/9/use-music-to-fight-cybercrime-maga-no-need-pay/130.aspx</guid>
</item>
<item>
<title>IRS Tax Avoidance Scam</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/8/irs-tax-avoidance-scam/129.aspx</link>
<description>&lt;p&gt;Today, eSoft is alerting customers to a new targeted email scam. This newest twist to the common IRS email scam seems to be targeted to organizations, notifying the recipient of a tax evasion complaint being filed against the company.&amp;nbsp;Opening the file infects the user's machine with dangerou ...</description>
<pubDate>Mon, 08 Feb 2010 15:11:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/8/irs-tax-avoidance-scam/129.aspx</guid>
</item>
<item>
<title>Targeted Attacks – the “Real” Problem</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/5/targeted-attacks--the-real-problem/128.aspx</link>
<description>&lt;p&gt;When I talk to customers, the different attacks are often something we discuss (obviously). I often mention that Virus and Worm attacks on a broad scale (like Conficker, etc.) are a serious problem, but at least they are ones we see, understand, and can fight (because we see and understand it).&lt;/ ...</description>
<pubDate>Fri, 05 Feb 2010 11:00:23 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/5/targeted-attacks--the-real-problem/128.aspx</guid>
</item>
<item>
<title>Fake Firefox Update Pages Push Adware</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/3/fake-firefox-update-pages-push-adware/126.aspx</link>
<description>&lt;p&gt;Since its&amp;rsquo; release on January 21st, the newest version of the Firefox web browser has received a great deal of attention.&amp;nbsp;In just a short time it has achieved over 30 million downloads. Adware pushers are capitalizing on the success of Firefox, packing ad serving software in with the p ...</description>
<pubDate>Wed, 03 Feb 2010 17:52:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/3/fake-firefox-update-pages-push-adware/126.aspx</guid>
</item>
<item>
<title>SPAM! Well, it's finally caught up with me -  as confirmed by the research</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/2/spam-well-its-finally-caught-up-with-me---as-confirmed-by-the-research/124.aspx</link>
<description>&lt;p&gt;I have lots of email addresses, but there's one that I use as the main catch all one, it&amp;rsquo;s the one I usually give to most people, and it's the one account I like to clean and clear out regularly. Because it is the most publicised one of all my many accounts, it's the only one that I receive ...</description>
<pubDate>Tue, 02 Feb 2010 16:15:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/2/spam-well-its-finally-caught-up-with-me---as-confirmed-by-the-research/124.aspx</guid>
</item>
<item>
<title>I've been hacked - Give me back my money</title>
<link>http://www.infosecurity-magazine.com/blog/2010/2/2/ive-been-hacked--give-me-back-my-money/123.aspx</link>
<description>&lt;p&gt;I recently read a story where a business bank customer had $800K stolen from her business account, and although the bank has been able to recover $600K, there is still the outstanding $200K. The customer is claiming that the bank lacked good security, and the bank is claiming that it had good sec ...</description>
<pubDate>Tue, 02 Feb 2010 11:45:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/2/2/ive-been-hacked--give-me-back-my-money/123.aspx</guid>
</item>
<item>
<title>Cloud Security Paper: Looking for Feedback</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/30/cloud-security-paper-looking-for-feedback/117.aspx</link>
<description>&lt;p&gt;As most of you well know, I was looking for information and opinions on Cloud Security over the last year. I found a lot of papers, but when I talk to our customers I realize that they think about the Cloud but Cloud Security is mainly something for the specialists &amp;ndash; which it is not for me. ...</description>
<pubDate>Sat, 30 Jan 2010 11:58:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/30/cloud-security-paper-looking-for-feedback/117.aspx</guid>
</item>
<item>
<title>Data Protection Day: An Interesting Study</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/29/data-protection-day-an-interesting-study/116.aspx</link>
<description>&lt;p&gt;As you might know, it was time for the &lt;a target=&quot;_blank&quot; href=&quot;http://dpd.eun.org/web/guest&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Data Protection Day&lt;/font&gt;&lt;/a&gt; in Europe again. Unfortunately I did not find the videos from this year&amp;rsquo;s competition, yet but I guess we will find them later on the page and o ...</description>
<pubDate>Fri, 29 Jan 2010 10:24:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/29/data-protection-day-an-interesting-study/116.aspx</guid>
</item>
<item>
<title>Super Bowl associations: football, nachos, big screens and … malware?</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/19/super-bowl-associations-football-nachos-big-screens-and--malware/113.aspx</link>
<description>&lt;p&gt;The Super Bowl is the one of the biggest and most watched television events of the year in the United States. People everywhere scour the internet looking for predictions, gambling spreads and news before the event and scores, stories and clips after the event.&amp;nbsp;In anticipation of the increas ...</description>
<pubDate>Tue, 19 Jan 2010 19:29:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/19/super-bowl-associations-football-nachos-big-screens-and--malware/113.aspx</guid>
</item>
<item>
<title>Lack of Egress Filtering Spurs Success of Injected IFrame Attack</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/18/lack-of-egress-filtering-spurs-success-of-injected-iframe-attack/112.aspx</link>
<description>&lt;p&gt;The security community at large and the eSoft Threat Prevention Team have recently noticed an uptick in sites compromised by a new injection attack that results in an injected iframe. This attack can be recognised by its attempts to masquerade the malicious script as GNU, GPL or LGPL. &amp;nbsp;GPL a ...</description>
<pubDate>Mon, 18 Jan 2010 22:13:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/18/lack-of-egress-filtering-spurs-success-of-injected-iframe-attack/112.aspx</guid>
</item>
<item>
<title>MTaS: Malware Testing as a Service</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/5/mtas-malware-testing-as-a-service/111.aspx</link>
<description>&lt;p&gt;Well, in my last post I wrote about the prices for malware. Today I read the next evolution of this: The possibility of having malware tested against anti-malware tools &amp;ndash; not to make sure malware is really recognised, no, the other way round: To make sure it is not recognised.&lt;/p&gt;
&lt;p&gt;I rea ...</description>
<pubDate>Tue, 05 Jan 2010 21:10:36 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/5/mtas-malware-testing-as-a-service/111.aspx</guid>
</item>
<item>
<title>The Cybercriminal’s Wish List</title>
<link>http://www.infosecurity-magazine.com/blog/2010/1/1/the-cybercriminals-wish-list/109.aspx</link>
<description>&lt;p&gt;I know that Christmas is over and I know how my kids actually compile a Wish List: They take most of the ads (which are targeted to them) and glue them onto a piece of paper for mum and dad to make sure that everything can be found under the Christmas tree&amp;hellip; I guess you know the drill.&lt;/p&gt; ...</description>
<pubDate>Fri, 01 Jan 2010 11:52:43 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2010/1/1/the-cybercriminals-wish-list/109.aspx</guid>
</item>
<item>
<title>Live.com Exploited as Pharma-Fraud Cover</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/23/livecom-exploited-as-pharmafraud-cover/108.aspx</link>
<description>&lt;p&gt;The FDA crackdown on online pharmacy sites has driven a lot of attention to illegal and fraudulent online pharmacies and in particular to their methods for tricking people to visit their sites. These practices include prolific spam and search engine poisoning.&lt;/p&gt;
&lt;p&gt;eSoft&amp;rsquo;s Threat Prevent ...</description>
<pubDate>Wed, 23 Dec 2009 17:59:27 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/23/livecom-exploited-as-pharmafraud-cover/108.aspx</guid>
</item>
<item>
<title>Algeria: Conference on Certification (eID) </title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/17/algeria-conference-on-certification-eid-/103.aspx</link>
<description>&lt;p&gt;When I &lt;a target=&quot;_blank&quot; href=&quot;file:///C:/Users/rhalbh/AppData/Local/Temp/WindowsLiveWriter1286139640/D04DA26D57B0/www.twitter.com/rhalbheer&quot;&gt;tweeted&lt;/a&gt; last week that I am on my way to Algeria, I got quite some reactions and questions that I should report how it was. So, let me try to briefly  ...</description>
<pubDate>Thu, 17 Dec 2009 15:05:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/17/algeria-conference-on-certification-eid-/103.aspx</guid>
</item>
<item>
<title>Boeing 787 searches hijacked by rogue anti-virus</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/16/boeing-787-searches-hijacked-by-rogue-antivirus/99.aspx</link>
<description>&lt;p&gt;Today, the Boeing 787 Dreamliner jet completed its much awaited first flight. As users searched to find videos and news articles related to the story, blackhats quickly moved in for yet another attack against Google search results.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;&quot; style=&quot;width: 200px; height: 195px;&quot; src=&quot;/_c ...</description>
<pubDate>Wed, 16 Dec 2009 17:52:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/16/boeing-787-searches-hijacked-by-rogue-antivirus/99.aspx</guid>
</item>
<item>
<title>Beware of MySpace JPG File Downloader - GTALK Messenger Infection</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/15/beware-of-myspace-jpg-file-downloader--gtalk-messenger-infection/96.aspx</link>
<description>&lt;p&gt;The malware infection attack surface is increasing day by day. Recently, some of the infected machines with different malware classes such as file downloader are using GTALK for downloading JPG based files from the internet.&lt;/p&gt;
&lt;p&gt;Actually this file is not a JPG file but a zipped file that cont ...</description>
<pubDate>Tue, 15 Dec 2009 04:46:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/15/beware-of-myspace-jpg-file-downloader--gtalk-messenger-infection/96.aspx</guid>
</item>
<item>
<title>CIO required - security background essential</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/11/cio-required--security-background-essential/93.aspx</link>
<description>&lt;p&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot;&gt;
&lt;meta name=&quot;ProgId&quot; content=&quot;Word.Document&quot;&gt;
&lt;meta name=&quot;Generator&quot; content=&quot;Microsoft Word 12&quot;&gt;
&lt;meta name=&quot;Originator&quot; content=&quot;Microsoft Word 12&quot;&gt;
&lt;link rel=&quot;File-List&quot; href=&quot;file:///C:%5CUsers%5Cuser3%5CAppData%5CLocal% ...</description>
<pubDate>Fri, 11 Dec 2009 16:33:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/11/cio-required--security-background-essential/93.aspx</guid>
</item>
<item>
<title>Dedicated Spamming - NING House of Hackers Network</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/11/dedicated-spamming--ning-house-of-hackers-network/90.aspx</link>
<description>&lt;p&gt;The internet world has become a playground for spammers. Every day there is a new attack pattern. You will find one or another social networking website facing this problem. The reason for this trend is the centralised working of these websites. The interconnection among identities have helped th ...</description>
<pubDate>Fri, 11 Dec 2009 04:19:29 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/11/dedicated-spamming--ning-house-of-hackers-network/90.aspx</guid>
</item>
<item>
<title>Get Safe Online: Don’t be a Money Mule</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/4/get-safe-online-dont-be-a-money-mule/70.aspx</link>
<description>&lt;p&gt;You know, there are people who blog late, there are people who blog very late and then there is me&amp;hellip;&lt;/p&gt;
&lt;p&gt;I actually missed that one even though I was triggered: Mid November there was the Get Safe Online Week 2009 in the UK. Usually they do really good stuff and this is the reason I usu ...</description>
<pubDate>Fri, 04 Dec 2009 12:00:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/4/get-safe-online-dont-be-a-money-mule/70.aspx</guid>
</item>
<item>
<title>Practical working Security Policies</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/3/practical-working-security-policies/69.aspx</link>
<description>&lt;p&gt;Effective working policies are a very difficult thing to achieve, whether they are security policies, or any other policies. We've all seen them in our own organisations, employment policies contradict security policies, or ethical policies contradict investment policies, etc. etc.&lt;/p&gt;
&lt;p&gt;The sc ...</description>
<pubDate>Thu, 03 Dec 2009 16:32:53 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/3/practical-working-security-policies/69.aspx</guid>
</item>
<item>
<title>“Black Screen of Death” Reports</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/1/black-screen-of-death-reports/68.aspx</link>
<description>&lt;p&gt;Oh, wow &amp;ndash; sometimes the power of social media, the blogs and the internet can backfire. I guess in the meantime you have seen the claims by Prevx that approx. 80 million of PCs are affected by the &lt;em&gt;Black Screen of Death&lt;/em&gt; problems supposedly caused by our November Security Updates. Th ...</description>
<pubDate>Tue, 01 Dec 2009 20:18:37 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/1/black-screen-of-death-reports/68.aspx</guid>
</item>
<item>
<title>Questions to Ask your (Security) Vendor</title>
<link>http://www.infosecurity-magazine.com/blog/2009/12/1/questions-to-ask-your-security-vendor/67.aspx</link>
<description>&lt;p&gt;You know that I am a big fan of Security Development Lifecycles as we run it internally to build code which is more resilient against attacks. And I recently blogged on &lt;a target=&quot;_blank&quot; href=&quot;http://www.halbheer.info/security/archive/2009/11/19/security-a-feature-discussion-some-thoughts-on-goo ...</description>
<pubDate>Tue, 01 Dec 2009 10:04:12 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/12/1/questions-to-ask-your-security-vendor/67.aspx</guid>
</item>
<item>
<title>Security and Usability</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/26/security-and-usability/66.aspx</link>
<description>&lt;p&gt;It is not a new concept: The secure way is only secure if it is the easiest way. I have seen a lot of solutions which are extremely secure &amp;ndash; in the eyes of the security people.&lt;/p&gt;
&lt;p&gt;However, the users find a lot of ways to circumvent the security measures because they are too complex to  ...</description>
<pubDate>Thu, 26 Nov 2009 21:08:06 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/26/security-and-usability/66.aspx</guid>
</item>
<item>
<title>Reverse Honey Traps - Beating Online Anti-virus Engine in its Own Game</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/25/reverse-honey-traps--beating-online-antivirus-engine-in-its-own-game/65.aspx</link>
<description>&lt;p&gt;The web is ever changing arena. Online anti-virus engines provide a diversified functioning of analysing a malware executable thereby providing efficient analysis.&lt;/p&gt;
&lt;p&gt;This is an online democracy of anti-virus engines. But every positive entity can be transformed into a playground and players ...</description>
<pubDate>Wed, 25 Nov 2009 11:47:50 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/25/reverse-honey-traps--beating-online-antivirus-engine-in-its-own-game/65.aspx</guid>
</item>
<item>
<title>Board Level Security Metrics</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/23/board-level-security-metrics/63.aspx</link>
<description>&lt;p&gt;Last week I attended the Infosecurity Council and had the previlege of spending some time with many security leaders, and I always find these meeting very interesting, as Iwill always learn something that I&amp;nbsp;didn't know before. This meeting was no exception, before the meeting started, I was  ...</description>
<pubDate>Mon, 23 Nov 2009 15:11:46 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/23/board-level-security-metrics/63.aspx</guid>
</item>
<item>
<title>Security – A feature discussion? Some thoughts on Google’s Chrome OS</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/19/security--a-feature-discussion-some-thoughts-on-googles-chrome-os/61.aspx</link>
<description>&lt;p&gt;To be clear upfront: This is not a 'Microsoft versus Google' post. I cannot even judge how far Google pushed security with the Chrome OS. But the following article raised quite some questions how we look at security: &lt;a href=&quot;http://blogs.zdnet.com/security/?p=4969&amp;amp;utm_source=feedburner&amp;amp;u ...</description>
<pubDate>Thu, 19 Nov 2009 21:21:17 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/19/security--a-feature-discussion-some-thoughts-on-googles-chrome-os/61.aspx</guid>
</item>
<item>
<title>Blackhats Unleash Fake Blog Campaign Spreading Rogue AV</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/18/blackhats-unleash-fake-blog-campaign-spreading-rogue-av/60.aspx</link>
<description>&lt;p&gt;In September, eSoft reported as many as &lt;a href=&quot;http://threatcenter.blogspot.com/2009/09/fake-blogs-serve-rogue-malware.html&quot;&gt;720,000 compromised sites&lt;/a&gt; hosting fake blog pages and being used to distribute rogue anti-virus programmes. Many of these sites are still active and continue to plagu ...</description>
<pubDate>Wed, 18 Nov 2009 16:17:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/18/blackhats-unleash-fake-blog-campaign-spreading-rogue-av/60.aspx</guid>
</item>
<item>
<title>CoolerEmail Hit by Phishing Scam</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/13/cooleremail-hit-by-phishing-scam/57.aspx</link>
<description>&lt;p&gt;CoolerEmail is notifying customers of a new phishing scam used to steal login credentials. The web based email marketing programme carries an impressive client list including Walmart, Toyota, Pepsi and dozens of other big name brands. Any phished credentials can be used to impersonate these compa ...</description>
<pubDate>Fri, 13 Nov 2009 15:36:52 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/13/cooleremail-hit-by-phishing-scam/57.aspx</guid>
</item>
<item>
<title>Why it pays to be secure – Chapter 4 – I want to learn!</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/13/why-it-pays-to-be-secure--chapter-4--i-want-to-learn/55.aspx</link>
<description>&lt;p&gt;Use these Learning Paths to find a range of Microsoft training references and resources on information security threats and appropriate countermeasures. Learning resources are organised by level (from basic to expert) and provide information on the planning, prevention, detection, and response ph ...</description>
<pubDate>Fri, 13 Nov 2009 14:18:34 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/13/why-it-pays-to-be-secure--chapter-4--i-want-to-learn/55.aspx</guid>
</item>
<item>
<title>Embedded open type fonts - The risk lurking up</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/13/embedded-open-type-fonts--the-risk-lurking-up/54.aspx</link>
<description>&lt;p&gt;The web is getting a playground for different type of attacks. There is lot of talks going around about Microsoft EOT fonts realm which are being used for launching different type of attacks.&lt;/p&gt;
&lt;p&gt;Recently I gave a talk at the Excalibur Conference, China in which I talked about launching a CSR ...</description>
<pubDate>Fri, 13 Nov 2009 11:31:44 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/13/embedded-open-type-fonts--the-risk-lurking-up/54.aspx</guid>
</item>
<item>
<title>How does Google use your information? </title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/6/how-does-google-use-your-information-/49.aspx</link>
<description>&lt;p&gt;Following growing concerns on how the web giants Google are using it&amp;rsquo;s users information, they have launched Google Dashboard; a service which allows users with a Google account to view the information that Google has stored on them, It also allows users to delete any information that they  ...</description>
<pubDate>Fri, 06 Nov 2009 12:40:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/6/how-does-google-use-your-information-/49.aspx</guid>
</item>
<item>
<title>International Collaboration on Policies for Cybersecurity and Data Protection</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/5/international-collaboration-on-policies-for-cybersecurity-and-data-protection/48.aspx</link>
<description>&lt;p&gt;For&amp;nbsp;a few years we&amp;nbsp;have been&amp;nbsp;working with the Council of Europe in a partnership to help to drive a Cybersecurity treaty. We realise that a problem a lot of law enforcement agencies have is inconsistent legislation, which makes&amp;nbsp;it unbelievably hard to catch cybercriminals. The ...</description>
<pubDate>Thu, 05 Nov 2009 20:44:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/5/international-collaboration-on-policies-for-cybersecurity-and-data-protection/48.aspx</guid>
</item>
<item>
<title>Power of Knowledge: Security Intelligence Report v7</title>
<link>http://www.infosecurity-magazine.com/blog/2009/11/2/power-of-knowledge-security-intelligence-report-v7/47.aspx</link>
<description>&lt;p&gt;It has been a good tradition for quite a while that we make the intelligence we (Microsoft) have available accessible to the broad public. This will help our customers to protect themselves much better. The Security Intelligence Report (SIR) is built on a unparalleled set of sensors out there on  ...</description>
<pubDate>Mon, 02 Nov 2009 16:15:55 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/11/2/power-of-knowledge-security-intelligence-report-v7/47.aspx</guid>
</item>
<item>
<title>Ten Computer Hacks In The Movies</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/29/ten-computer-hacks-in-the-movies/39.aspx</link>
<description>&lt;!--StartFragment--&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;img src=&quot;http://l.yimg.com/g/images/spaceball.gif&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;/b&gt;&lt;!--StartFragment--&gt;Some of the most successful blockbuster films released in the last two decades have been themed on the potential destruction that computer hackers can cause. Her ...</description>
<pubDate>Thu, 29 Oct 2009 12:20:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/29/ten-computer-hacks-in-the-movies/39.aspx</guid>
</item>
<item>
<title>Could Microsoft solve the scareware problem?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/22/could-microsoft-solve-the-scareware-problem/38.aspx</link>
<description>&lt;p&gt;This morning I read the following article: &lt;a href=&quot;http://www.itnews.com.au/News/158689,commentary-microsoft-can-help-kill-fake-antivirus-threat.aspx&quot;&gt;&lt;font color=&quot;#669966&quot;&gt;Microsoft can help kill fake antivirus threat&lt;/font&gt;&lt;/a&gt;. And interesting approach. The proposal is that we could white-lis ...</description>
<pubDate>Thu, 22 Oct 2009 07:58:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/22/could-microsoft-solve-the-scareware-problem/38.aspx</guid>
</item>
<item>
<title>Compromised Web Servers Host Koobface Malware Cocktail</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/21/compromised-web-servers-host-koobface-malware-cocktail/37.aspx</link>
<description>&lt;p&gt;The Koobface gang has struck again using compromised web servers to deliver a potent mix of malware. eSoft threat researchers have found hundreds of newly exploited sites hosting malware which includes downloaders, keyloggers and multiple variants of the Koobface worm.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;
Attackers u ...</description>
<pubDate>Wed, 21 Oct 2009 22:59:35 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/21/compromised-web-servers-host-koobface-malware-cocktail/37.aspx</guid>
</item>
<item>
<title>Why it pays to be secure – Chapter 3 – But how do I?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/18/why-it-pays-to-be-secure--chapter-3--but-how-do-i/36.aspx</link>
<description>&lt;p&gt;Security &amp;mdash; you hear about it every day. Being responsible for information security can be a daunting task, so where do you begin?&lt;/p&gt;
&lt;p&gt;From the design of acceptable use policies to preventing insiders from stealing data, the job can be a challenging one. Join Senior Security Strategist w ...</description>
<pubDate>Sun, 18 Oct 2009 19:32:16 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/18/why-it-pays-to-be-secure--chapter-3--but-how-do-i/36.aspx</guid>
</item>
<item>
<title>Unresolved Compromised Fox Sports Host Heading Into Third Week</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/17/unresolved-compromised-fox-sports-host-heading-into-third-week/35.aspx</link>
<description>&lt;p&gt;eSoft &lt;a href=&quot;http://threatcenter.blogspot.com/2009/10/foxsportscom-used-to-serve-malware.html&quot;&gt;first detected a compromise&lt;/a&gt; on the Fox Sports website two weeks ago and as of today, at least one Fox Sports host continues to contain automatic links to a multitude of dangerous exploits.&amp;nbsp; E ...</description>
<pubDate>Sat, 17 Oct 2009 01:17:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/17/unresolved-compromised-fox-sports-host-heading-into-third-week/35.aspx</guid>
</item>
<item>
<title>How the US military has weaponised hacking</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/16/how-the-us-military-has-weaponised-hacking/34.aspx</link>
<description>&lt;p&gt;&lt;em&gt;&amp;ldquo;Our technological advantage is a key to America's military dominance.&amp;nbsp; But our defence and military networks are under constant attack.&amp;nbsp; Al Qaeda and other terrorist groups have spoken of their desire to unleash a cyber attack on our country -- attacks that are harder to dete ...</description>
<pubDate>Fri, 16 Oct 2009 09:33:41 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/16/how-the-us-military-has-weaponised-hacking/34.aspx</guid>
</item>
<item>
<title>How common is the hacking of secure wifi?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/16/how-common-is-the-hacking-of-secure-wifi/33.aspx</link>
<description>&lt;p&gt;
&lt;meta content=&quot;&quot; name=&quot;Title&quot; /&gt;
&lt;meta content=&quot;&quot; name=&quot;Keywords&quot; /&gt;
&lt;meta content=&quot;text/html; charset=utf-8&quot; http-equiv=&quot;Content-Type&quot; /&gt;
&lt;meta content=&quot;Word.Document&quot; name=&quot;ProgId&quot; /&gt;
&lt;meta content=&quot;Microsoft Word 2008&quot; name=&quot;Generator&quot; /&gt;
&lt;meta content=&quot;Microsoft Word 2008&quot; name=&quot;Origin ...</description>
<pubDate>Fri, 16 Oct 2009 09:15:56 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/16/how-common-is-the-hacking-of-secure-wifi/33.aspx</guid>
</item>
<item>
<title>Software Piracy – A Threat to Security!</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/14/software-piracy--a-threat-to-security/32.aspx</link>
<description>&lt;p&gt;Beginning of this year, I tried to understand, whether we can show a collaboration between Piracy (stolen software) and Malware Infections. I played a little bit with the data I had available and came to the conclusion, that there most probably is: &lt;a href=&quot;http://www.halbheer.info/security/archi ...</description>
<pubDate>Wed, 14 Oct 2009 13:11:19 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/14/software-piracy--a-threat-to-security/32.aspx</guid>
</item>
<item>
<title>AJAX-JSON - Inside Crux</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/13/ajaxjson--inside-crux/31.aspx</link>
<description>&lt;p&gt;The development is occurring at a rapid pace. The innovation is going on. The web is transitioning from the web 1.0 to web 2.0. The implementation structures of various technologies have changed. The Web 2.0 has revolutionized the web in a stringent manner from all the perspectives. The Asynchron ...</description>
<pubDate>Tue, 13 Oct 2009 08:34:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/13/ajaxjson--inside-crux/31.aspx</guid>
</item>
<item>
<title>Recapping the Fox Sports Website Compromise</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/9/recapping-the-fox-sports-website-compromise/30.aspx</link>
<description>&lt;p&gt;On October 2nd eSoft published a &lt;a href=&quot;http://www.threatcenter.blogspot.com/2009/10/foxsportscom-used-to-serve-malware.html&quot;&gt;blog&lt;/a&gt; warning visitors of the Fox Sports website about compromised pages with the potential to serve malicious software. To date, the threat remains on their website  ...</description>
<pubDate>Fri, 09 Oct 2009 16:18:13 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/9/recapping-the-fox-sports-website-compromise/30.aspx</guid>
</item>
<item>
<title>Web 2.0 – Truth and Lies in AJAX World</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/8/web-20--truth-and-lies-in-ajax-world/29.aspx</link>
<description>&lt;p&gt;&lt;em&gt;Web 2.0 has metamorphosed the complete scenario of internet.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In the AJAX world, most of the working functionality is derived by efficient technology methods and ingrained software dependency. In order to scratch deep down the bottom the differential aspect of this technology must ...</description>
<pubDate>Thu, 08 Oct 2009 04:41:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/8/web-20--truth-and-lies-in-ajax-world/29.aspx</guid>
</item>
<item>
<title>The Africa Cable – A Chance for Africa! – A Threat for the Internet?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/7/the-africa-cable--a-chance-for-africa--a-threat-for-the-internet/28.aspx</link>
<description>&lt;p&gt;The development in Africa especially with the new broadband services to me is a huge chance for the whole continent.&lt;/p&gt;
&lt;p&gt;I just found a map (Image 1) on the next two years.&lt;/p&gt;
&lt;p&gt;Even though I have not been in Africa over the last few months, I heard that in different cities fiber is brough ...</description>
<pubDate>Wed, 07 Oct 2009 15:15:25 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/7/the-africa-cable--a-chance-for-africa--a-threat-for-the-internet/28.aspx</guid>
</item>
<item>
<title>Why Linux servers are more secure than Windows</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/why-linux-servers-are-more-secure-than-windows/27.aspx</link>
<description>&lt;!--StartFragment--&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;The Linux/Windows debate is an oldie but a goodie, and there have been many long threads on most computer related forums discussing their relative merits. Linux is free, open-source and community based. Windows is expensive, professionally developed and has ...</description>
<pubDate>Tue, 06 Oct 2009 13:49:18 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/why-linux-servers-are-more-secure-than-windows/27.aspx</guid>
</item>
<item>
<title>Your password isn't safe - take this simple test to find out how many minutes it would take to crack</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/your-password-isnt-safe--take-this-simple-test-to-find-out-how-many-minutes-it-would-take-to-crack/26.aspx</link>
<description>&lt;p&gt;There's a well-known saying in information security that the weakest part of any computer system is the person using it. One area where this becomes abundantly clear is in the use of passwords. Allowing users to choose their own passwords can be fatal, with most people not having the first clue a ...</description>
<pubDate>Tue, 06 Oct 2009 13:42:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/your-password-isnt-safe--take-this-simple-test-to-find-out-how-many-minutes-it-would-take-to-crack/26.aspx</guid>
</item>
<item>
<title>When hacking is legal</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/when-hacking-is-legal/25.aspx</link>
<description>&lt;p&gt;The Merriam-Webster dictionary gives two different definitions of &amp;ldquo;hacker&amp;rdquo; related to computer security. A hacker is either &amp;ldquo;an expert at programming and solving problems with a computer&amp;rdquo; or &amp;ldquo;a person who illegally gains access to and sometimes tampers with informati ...</description>
<pubDate>Tue, 06 Oct 2009 13:37:20 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/when-hacking-is-legal/25.aspx</guid>
</item>
<item>
<title>Why retina scanning works better for James Bond than it ever would for us</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/6/why-retina-scanning-works-better-for-james-bond-than-it-ever-would-for-us/24.aspx</link>
<description>&lt;p&gt;Since the late 80s retinal scanning has been featured in a whole bevy of sci-fi and action films. It's been the security system of choice for some of the silver screen's top spies: James Bond used it in GoldenEye and Ethan Hunt in the Mission Impossible movies. As a result, whilst retinal scannin ...</description>
<pubDate>Tue, 06 Oct 2009 12:18:10 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/6/why-retina-scanning-works-better-for-james-bond-than-it-ever-would-for-us/24.aspx</guid>
</item>
<item>
<title>Which famous Twitter accounts have been hacked?</title>
<link>http://www.infosecurity-magazine.com/blog/2009/10/5/which-famous-twitter-accounts-have-been-hacked/23.aspx</link>
<description>&lt;p&gt;Early in 2009, Twitter suffered two major security lapses. Once when a wave of highly successful phishing campaigns were successful in obtaining a lot of Twitter passwords, and then again when an 18 year old hacker and student of computer games development brute-force'd an administrator account.  ...</description>
<pubDate>Mon, 05 Oct 2009 16:41:01 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/10/5/which-famous-twitter-accounts-have-been-hacked/23.aspx</guid>
</item>
<item>
<title>Thoughts on the registered traveler programmes at airports</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/30/thoughts-on-the-registered-traveler-programmes-at-airports/22.aspx</link>
<description>&lt;p&gt;When I entered the US this time, I got a brochure on how I could avoid the line at immigration and just get a fast track by registering with the &lt;a href=&quot;http://www.cbp.gov/xp/cgov/travel/trusted_traveler/global_entry/&quot; target=&quot;_blank&quot;&gt;Global Entry Program&lt;/a&gt;, a programme, which would pre-screen ...</description>
<pubDate>Wed, 30 Sep 2009 17:07:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/30/thoughts-on-the-registered-traveler-programmes-at-airports/22.aspx</guid>
</item>
<item>
<title>Hey, You, Get Off of My Cloud</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/27/hey-you-get-off-of-my-cloud/21.aspx</link>
<description>&lt;p&gt;I recently had different discussions with different customers and we were looking into the key questions to ask, when you plan to move to the cloud (yes, I am working on a corresponding blog post). I was then asked whether we have an answer to these questions&amp;nbsp;&amp;ndash; well no. For sure not fo ...</description>
<pubDate>Sun, 27 Sep 2009 00:47:15 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/27/hey-you-get-off-of-my-cloud/21.aspx</guid>
</item>
<item>
<title>Why it pays to be secure - Chapter 2 - Vulnerabilities</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/23/why-it-pays-to-be-secure--chapter-2--vulnerabilities/20.aspx</link>
<description>&lt;p&gt;The Microsoft Security Intelligence Report (SIR) provides an in-depth perspective on the changing threat landscape including software vulnerability disclosures and exploits, malicious software (malware), and potentially unwanted software.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.microsoft.com/security/portal/ ...</description>
<pubDate>Wed, 23 Sep 2009 23:05:49 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/23/why-it-pays-to-be-secure--chapter-2--vulnerabilities/20.aspx</guid>
</item>
<item>
<title>Moving to the Cloud: Where it worked and where I was challenged</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/21/moving-to-the-cloud-where-it-worked-and-where-i-was-challenged/19.aspx</link>
<description>&lt;p&gt;I am running a whole environment at home to experience our technology. However, up to now it was all &amp;ldquo;on premise&amp;rdquo;, no Cloud integration. This has to change. Therefore I was more than happy to join our internal&amp;nbsp; Hosted Exchange 14 beta program. We are offering the hosted Exchange  ...</description>
<pubDate>Mon, 21 Sep 2009 09:07:05 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/21/moving-to-the-cloud-where-it-worked-and-where-i-was-challenged/19.aspx</guid>
</item>
<item>
<title>Microsoft SDL Team Releases New Security Testing Tools</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/16/microsoft-sdl-team-releases-new-security-testing-tools/18.aspx</link>
<description>&lt;p&gt;I often mention that we try to give you all the tools we have as long as it makes sense form a risk perspective. The risk perspective is a simple one: If we give it to you as our customer, we give it as well to the criminals.&lt;/p&gt;
&lt;p&gt;There are two new tools which just made the bar and which are n ...</description>
<pubDate>Wed, 16 Sep 2009 14:11:24 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/16/microsoft-sdl-team-releases-new-security-testing-tools/18.aspx</guid>
</item>
<item>
<title>H1N1 (Swine) Flu Preparedness - Guide for Critical Infrastructure and Key Resources</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/16/h1n1-swine-flu-preparedness--guide-for-critical-infrastructure-and-key-resources/17.aspx</link>
<description>&lt;p&gt;This morning I stumbled across a guide by the US Health &amp;amp; Human Services with regards to H1N1. Even though it did not catch much news lately I am not sure whether it is really over. Staying prepared it definitely not a bad thing. Even though it is US-centric, you should probably look into it: ...</description>
<pubDate>Wed, 16 Sep 2009 06:33:11 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/16/h1n1-swine-flu-preparedness--guide-for-critical-infrastructure-and-key-resources/17.aspx</guid>
</item>
<item>
<title>Why it pays to be secure - Chapter 1 - Data Breaches</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/14/why-it-pays-to-be-secure--chapter-1--data-breaches/15.aspx</link>
<description>&lt;p&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;a href=&quot;http://www.infosecurity-magazine.com/blog/2009/9/11/why-it-pays-to-be-secure/13.aspx&quot;&gt;In my first post here&lt;/a&gt;, I opened the field for a series on &amp;ldquo;Why it pays to be secure&amp;rdquo;. As I told you there, Henk van Roest, our Security Support Program Manage ...</description>
<pubDate>Mon, 14 Sep 2009 10:43:14 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/14/why-it-pays-to-be-secure--chapter-1--data-breaches/15.aspx</guid>
</item>
<item>
<title>Why it pays to be secure</title>
<link>http://www.infosecurity-magazine.com/blog/2009/9/11/why-it-pays-to-be-secure/13.aspx</link>
<description>&lt;p&gt;You might all know that feeling: You need money to finance security activities and you are asked why this money shall be invested. And then we start to argue that if we do not do it &amp;ndash; bad things happen. These are questions that myself and our support get often. That was the reason why we st ...</description>
<pubDate>Fri, 11 Sep 2009 10:59:07 GMT</pubDate>
<guid>http://www.infosecurity-magazine.com/blog/2009/9/11/why-it-pays-to-be-secure/13.aspx</guid>
</item>
</channel>
</rss>
