<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>InfoSecPodcast.com</title>
	
	<link>http://www.infosecpodcast.com</link>
	<description>Information Security related news, opinions and ramblings</description>
	<pubDate>Tue, 11 Nov 2008 02:51:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<geo:lat>43.045076</geo:lat><geo:long>-71.070957</geo:long><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.0/</creativeCommons:license><image><link>http://www.infosecpodcast.com</link><url>http://www.infosecpodcast.com/images/pod_feed_logo.gif</url><title>InfoSecPodcast.com</title></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Wwwinfosecpodcastcom" type="application/rss+xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.rojo.com/add-subscription?resource=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://blog.rojo.com/RojoWideRed.gif">Subscribe with Rojo</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Wwwinfosecpodcastcom" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://my.feedlounge.com/external/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://static.feedlounge.com/buttons/subscribe_0.gif">Subscribe with FeedLounge</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.yourminis.com/subscribe.aspx?u=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.yourminis.com/images/addtoyourminisbadge.gif">Subscribe with Yourminis.com</feedburner:feedFlare><feedburner:feedFlare href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://hub.netomat.net/account/account.autoSubscribe.jspa?urls=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.netomat.net/blogger/images/icon_netomat_feedbutton.gif">Subscribe with netomat Hub</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><feedburner:feedFlare href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Ffeeds.feedburner.com%2FWwwinfosecpodcastcom" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><item>
		<title>3 open InfoSec positions at MIT Lincoln Laboratory</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/449062099/</link>
		<comments>http://www.infosecpodcast.com/2008/11/3-infosec-positions-mit-lincoln-laboratory/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 02:48:47 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Employment]]></category>

		<category><![CDATA[IDS]]></category>

		<category><![CDATA[IPS]]></category>

		<category><![CDATA[MIT Lincoln Laboratory]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=188</guid>
		<description>We currently have 3 Information Security positions open at MIT Lincoln Laboratory. The first position is Information Technology Security Team Lead. It is position #914 on the Employment page. Rather than re-hashing all the details you can read about it there. The other 2 positions do not have job postings up yet. We need 2 [...]</description>
			<content:encoded><![CDATA[<p><a href="http://www.ll.mit.edu" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.ll.mit.edu');"><img class="alignnone size-medium wp-image-189" title="MIT LL" src="http://www.infosecpodcast.com/wp-content/uploads/logo_print-300x45.gif" alt="" width="300" height="45" /></a></p>
<p>We currently have 3 Information Security positions open at <a href="http://www.ll.mit.edu" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.ll.mit.edu');">MIT Lincoln Laboratory</a>. The first position is Information Technology Security Team Lead. It is position #914 on the <a href="http://www.ll.mit.edu/employment/jobs.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.ll.mit.edu');">Employment page</a>. Rather than re-hashing all the details you can read about it there. The other 2 positions do not have job postings up yet. We need 2 IDS / IPS analysts full time. Details of the positions should be posted soon.</p>
<p>All 3 positions are in Lexington, MA and will require the candidates to be able to obtain at least a SECRET level security clearance. If you or anybody you know may be interested please contact me at: chris.harrington AT <a href="http://ll.mit.edu" title="http://ll.mit.edu" target="_blank">ll.mit.edu</a></p>
<p>Thanks!</p>
<p>&#8211;Chris</p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=bwRAcm"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=bwRAcm" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=7kBzN"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=7kBzN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=Bh0JN"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=Bh0JN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=3Aa8N"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=3Aa8N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=kt42n"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=kt42n" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/449062099" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/11/3-infosec-positions-mit-lincoln-laboratory/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/11/3-infosec-positions-mit-lincoln-laboratory/</feedburner:origLink></item>
		<item>
		<title>NAC Panel Discussion: What is the state of NAC?</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/436335491/</link>
		<comments>http://www.infosecpodcast.com/2008/10/nac-panel-discussion-what-is-the-state-of-nac/#comments</comments>
		<pubDate>Wed, 29 Oct 2008 23:07:22 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[NAC]]></category>

		<category><![CDATA[LinkedIn]]></category>

		<category><![CDATA[Network Access Control]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=184</guid>
		<description>This morning at work I moderated a panel discussion on Network Access Control. The audience was made up of IT Security staff from several research and development organizations. There were representatives from 3 vendors in attendance as well. The audience represented a good cross section of NAC adopters. Some have had it for 2 years, [...]</description>
			<content:encoded><![CDATA[<p>This morning at work I moderated a panel discussion on Network Access Control. The audience was made up of IT Security staff from several research and development organizations. There were representatives from 3 vendors in attendance as well. The audience represented a good cross section of NAC adopters. Some have had it for 2 years, some deploying this year while others had future or no plans to deploy NAC.</p>
<p>There was good audience participation so I only had to pull out 1 or 2 &#8220;canned&#8221; questions in the time allotted. I&#8217;ve tried to summarize the points and information that we learned from this exercise below. These are in no particular order.</p>
<p>1. No clear definition of NAC<br />
One of the first questions from the audience was about barriers to NAC adoption. One of the vendors replied with the question &#8220;what does NAC mean to you?” This person wanted NAC to do machine based authentication with no posture assessment. The next speaker wanted user authentication and posture assessment. A third was looking for post-connect NAC, *cough* IPS *cough*. Yet another wanted machine based authentication followed by user authentication. There was also discussion of machine provisioning on the network based on an HR event. As we have heard before, the definition of NAC is a moving target.</p>
<p>2. Lack of executive buy-in kills<br />
No big revelation here. Without proper senior management participation, understanding and approval almost any initiative will fail. What is interesting is the fact that within this group the challenge of selling NAC to upper management seemed to be more of a barrier to deployment than cost or complexity, the ones usually cited. My guess is that NAC may be an organizational or cultural challenge that is more common in &#8220;academic&#8221; environments where people may be used to doing what they want with less oversight. That is just a guess on my part. Cost was not mentioned once as an issue.</p>
<p>3. 802.1x is still a long way out for wired deployments<br />
Most security professionals will agree that 802.1x authentication is the preferred enforcement mechanism for NAC. IP&#8217;s can be changed, MAC&#8217;s can be spoofed but digital certificates pose a formidable challenge to forge. All 3 vendors said that in their experience 90% of wireless NAC deployments use 802.1x. The reason cited was ease of configuration on the client side and general wider acceptance of the protocol. On the wired side that equation was reversed with only 10% deploying 802.1x. Supplicant issues and the prevalence of devices that may not be able to have a supplicant (printers, VOIP phones, etc.) were said to be big issues.</p>
<p>4. Support for non-Windows clients still developing<br />
The majority of the audience organizations have significant numbers of non-Windows clients, specifically Mac&#8217;s. We get it. Windows is on 90 something percent of the enterprise desktops. That number is changing. More and more companies are offering choices on the desktop / laptop. The NAC vendors present had different levels of support for non-Windows. Some could do authentication only and some could do posture checking if the NAC device was in-line. Note to NAC vendors: Mac support is not a nice to have any more. Mac will have an ever increasing presence on the desktop. The NAC options should be the same for Windows and non-Windows. I do recognize that Linux is a little more of a challenge due to the variants and much further behind Mac in the desktop OS race.</p>
<p>Some of the other take-aways were:<br />
Make sure you have an accurate inventory of network connected devices<br />
Do not underestimate the increased help desk utilization<br />
Automated remediation is not as common as self-remediation in deployments</p>
<p>Those were the ones worth mentioning. Let me know if any of these jump out at you.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/NAC" rel="tag"> NAC</a>, <a href="http://technorati.com/tag/Network+Access+Control" rel="tag"> Network Access Control </a></p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=YoJDmS"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=YoJDmS" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=yp7dM"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=yp7dM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=blDtM"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=blDtM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=LKmTM"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=LKmTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=2jlXm"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=2jlXm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/436335491" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/10/nac-panel-discussion-what-is-the-state-of-nac/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/10/nac-panel-discussion-what-is-the-state-of-nac/</feedburner:origLink></item>
		<item>
		<title>Record IM video on the network?</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/324120871/</link>
		<comments>http://www.infosecpodcast.com/2008/07/record-im-video-on-the-network/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 15:23:03 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>

		<category><![CDATA[AIM video]]></category>

		<category><![CDATA[MSN Messenger]]></category>

		<category><![CDATA[record]]></category>
<category>AIM video</category><category>MSN Messenger</category><category>record</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=183</guid>
		<description>A friend of mine is works in the financial services market. His company has a need to record Instant Messenger video sessions (think AOL and MSN webcam ) and archive them. They need to do this on the network as opposed to having client software do it locally on the desktop. This is due to [...]</description>
			<content:encoded><![CDATA[<p>A friend of mine is works in the financial services market. His company has a need to record Instant Messenger video sessions (think AOL and MSN webcam ) and archive them. They need to do this on the network as opposed to having client software do it locally on the desktop. This is due to the varied desktop systems, only half are Windows based.</p>
<p>Anyone know of a commercial solution or open source libraries that could do this? I know many IPS&#8217; can detect IM video but he needs to record. Is IM video even encrypted? Before you start with the privacy concerns this is done with full knowledge of both parties who are also employees of the same company. It is a pilot program at this point.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/AIM+video" rel="tag"> AIM video</a>, <a href="http://technorati.com/tag/record" rel="tag"> record</a>, <a href="http://technorati.com/tag/MSN+Messenger" rel="tag"> MSN Messenger </a></p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=HVmbNt"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=HVmbNt" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=J2NjEJ"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=J2NjEJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=frdK8J"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=frdK8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=uCmyzJ"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=uCmyzJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=DBLqtj"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=DBLqtj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/324120871" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/07/record-im-video-on-the-network/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/07/record-im-video-on-the-network/</feedburner:origLink></item>
		<item>
		<title>WoW adds 2 factor authentication</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/324114351/</link>
		<comments>http://www.infosecpodcast.com/2008/07/wow-adds-2-factor-authentication/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 15:12:23 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[2 form factor]]></category>

		<category><![CDATA[world of warcraft]]></category>

		<category><![CDATA[wow]]></category>
<category>2 form factor</category><category>world of warcraft</category><category>wow</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=181</guid>
		<description>World of Warcraft creator Blizzard Entertainment is selling hardware security devices. These small devices can fit on a key ring and provide a second form factor for authentication using something similar to a one time pad. The cost&amp;#8230;..6 EUR.  Robert over at Errata Security has a pretty good write up on it.
Now if only [...]</description>
			<content:encoded><![CDATA[<p><a href="http://www.worldofwarcraft.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.worldofwarcraft.com');"></a><a href="http://www.infosecpodcast.com/wp-content/uploads/index-world-of-warcraft-logo.jpg"><img class="alignnone size-medium wp-image-182" title="World of Warcraft" src="http://www.infosecpodcast.com/wp-content/uploads/index-world-of-warcraft-logo-300x170.jpg" alt="" width="208" height="119" /></a><a href="http://www.worldofwarcraft.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.worldofwarcraft.com');"></a></p>
<p><a href="http://www.worldofwarcraft.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.worldofwarcraft.com');">World of Warcraft</a> creator Blizzard Entertainment is selling hardware security devices. These small devices can fit on a key ring and provide a second form factor for authentication using something similar to a one time pad. The cost&#8230;..6 EUR.  Robert over at Errata Security has a pretty good <a href="http://erratasec.blogspot.com/2008/06/blizzards-two-factor-authentication.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/erratasec.blogspot.com');">write up</a> on it.</p>
<p>Now if only my bank could figure this out. Wait a minute&#8230;.don&#8217;t they have to under PCI?? <img src='http://www.infosecpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/WoW" rel="tag"> WoW</a>, <a href="http://technorati.com/tag/World+of+Warcraft" rel="tag"> World of Warcraft</a>, <a href="http://technorati.com/tag/Blizzard+Entertainment" rel="tag"> Blizzard Entertainment</a>, <a href="http://technorati.com/tag/2+form+factor" rel="tag"> 2 form factor </a></p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=ju9ixP"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=ju9ixP" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=WByZ4J"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=WByZ4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=PTE5PJ"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=PTE5PJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=uBP9mJ"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=uBP9mJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=yEgzuj"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=yEgzuj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/324114351" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/07/wow-adds-2-factor-authentication/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/07/wow-adds-2-factor-authentication/</feedburner:origLink></item>
		<item>
		<title>New blog theme</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/320589342/</link>
		<comments>http://www.infosecpodcast.com/2008/06/new-blog-theme/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:06:09 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Education]]></category>

		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=180</guid>
		<description>I&amp;#8217;ve been working on a new theme for the blog. Please let me know what you think of the new theme!
Thanks!
&amp;#8211;Chris</description>
			<content:encoded><![CDATA[<p>I&#8217;ve been working on a new theme for the blog. Please let me know what you think of the new theme!</p>
<p>Thanks!</p>
<p>&#8211;Chris</p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=Cwt24f"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=Cwt24f" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=w9z7uI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=w9z7uI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=Nymy4I"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=Nymy4I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=ZcYGMI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=ZcYGMI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=zCvBSi"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=zCvBSi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/320589342" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/06/new-blog-theme/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/06/new-blog-theme/</feedburner:origLink></item>
		<item>
		<title>Twitter + Security = Security Twits</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/320565789/</link>
		<comments>http://www.infosecpodcast.com/2008/06/twitter-security-security-twits/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 14:29:12 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Industry News]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Security Twits]]></category>

		<category><![CDATA[Twitter]]></category>
<category>Security</category><category>Security Twits</category><category>Twitter</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=179</guid>
		<description>When I first read about Twitter I didn&amp;#8217;t see much value in it for me. It wasn&amp;#8217;t until I started using it last year when I saw the usefulness for me. Twitter is an interesting communicaiton tool. I call it a cross between an IM client and a Bulletin Board. There are a lot of [...]</description>
			<content:encoded><![CDATA[<p>When I first read about <a href="http://www.twitter.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.twitter.com');">Twitter</a> I didn&#8217;t see much value in it for me. It wasn&#8217;t until I started using it last year when I saw the usefulness for me. Twitter is an interesting communicaiton tool. I call it a cross between an IM client and a Bulletin Board. There are a lot of informal groups that use twitter. One of them is the Security Twits.</p>
<p><a href="http://mediaphyter.wordpress.com/security-twits/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/mediaphyter.wordpress.com');">Security Twits</a> are people in security related jobs, companies, etc that use Twitter.  We can thank Jennifer, aka <a href="http://twitter.com/mediaphyter" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/twitter.com');">Mediaphyter</a>, for the name and the <a href="http://mediaphyter.wordpress.com/2008/02/01/security-twits/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/mediaphyter.wordpress.com');">original blog post</a> on the Twits. It&#8217;s actually a pretty impressive list of security folks using it.</p>
<p>If you have not tried Twitter you should. You may just find it useful if not downright addictive.</p>
<p>&#8211; Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/Twitter" rel="tag"> Twitter</a>, <a href="http://technorati.com/tag/Security" rel="tag"> Security</a>, <a href="http://technorati.com/tag/Security+Twits" rel="tag"> Security Twits </a></p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=UCrx71"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=UCrx71" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=rGQ5nI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=rGQ5nI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=MP2myI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=MP2myI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=7ISYFI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=7ISYFI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=OCwfmi"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=OCwfmi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/320565789" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/06/twitter-security-security-twits/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/06/twitter-security-security-twits/</feedburner:origLink></item>
		<item>
		<title>Security for Web Meetings?</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/319787202/</link>
		<comments>http://www.infosecpodcast.com/2008/06/security-for-web-meetings/#comments</comments>
		<pubDate>Wed, 25 Jun 2008 15:25:04 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<category><![CDATA[GoToMeeting]]></category>

		<category><![CDATA[Web Meeting]]></category>

		<category><![CDATA[WebEx]]></category>
<category>GoToMeeting</category><category>Web Meeting</category><category>WebEx</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=174</guid>
		<description>I am seeing an increased need and proliferation of web based collaboration tools. WebEx, GoToMeeting, MS LiveMeeting, etc. While these tools are necessary as we see people and organizations looking for collaboration, how secure are they? A couple concerns come to mind. NOTE: I have not done any research into this nor read much of [...]</description>
			<content:encoded><![CDATA[<p>I am seeing an increased need and proliferation of web based collaboration tools. WebEx, GoToMeeting, MS LiveMeeting, etc. While these tools are necessary as we see people and organizations looking for collaboration, how secure are they? A couple concerns come to mind. NOTE: I have not done any research into this nor read much of the product literature.</p>
<p>What can these services see?<br />
In a hosted model these companies act a the middle man between the person giving a PowerPoint presentation and the ones viewing it, as an example. Can WebEx or GoToMeeting see the presentation? If so, is it done overtly or covertly? Any audit trail? Is the presentation stored on their servers?</p>
<p>Sharing of desktops?<br />
I know some of these services have the ability to share their desktops or applications. Some can even give control of their entire PC over to another person in the meeting. That could have some significant security implications in certain environments.</p>
<p>How do you handle these technologies? Do you block them? Have an approved one and block the rest?</p>
<p>I would love to hear what you do.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/GoToMeeting" rel="tag"> GoToMeeting</a>, <a href="http://technorati.com/tag/WebEx" rel="tag"> WebEx</a>, <a href="http://technorati.com/tag/Web+Meeting" rel="tag"> Web Meeting </a></p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=gJgPGd"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=gJgPGd" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=NYEcwI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=NYEcwI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=Z71xbI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=Z71xbI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=GIB5xI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=GIB5xI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=Whhe1i"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=Whhe1i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/319787202" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/06/security-for-web-meetings/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/06/security-for-web-meetings/</feedburner:origLink></item>
		<item>
		<title>ICANN shutting down a Chinese registrar?</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/319362156/</link>
		<comments>http://www.infosecpodcast.com/2008/06/icann-shutting-down-a-chinese-registrar/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 13:33:42 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[ICANN]]></category>

		<category><![CDATA[Spammer]]></category>

		<category><![CDATA[Xinnet]]></category>
<category>ICANN</category><category>Spammer</category><category>Xinnet</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=171</guid>
		<description>I saw this today on Slashdot. There is an ICANN registrar in China who is apparently not living up to its obligations to verify proper contact information for people registering domain names. The registrar is Xinnet Bei Gong Da Software. How bad is it you ask?

Of 11,000 suspected spam domains registered through them, NONE were [...]</description>
			<content:encoded><![CDATA[<p>I saw <a href="http://it.slashdot.org/article.pl?sid=08/06/23/0248248&amp;from=rss" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/it.slashdot.org');">this today on Slashdot</a>. There is an ICANN registrar in China who is apparently not living up to its obligations to verify proper contact information for people registering domain names. The registrar is <em>Xinnet Bei Gong Da Software. </em>How bad is it you ask?</p>
<ul>
<li>Of 11,000 suspected spam domains registered through them, NONE were taken down in a 6 month period.</li>
</ul>
<ul>
<li> Approximately 100 new spam sites per day being registered.</li>
</ul>
<ul>
<li> A &#8220;significant&#8221; number of those domain registrations have apparent bogus contact information</li>
</ul>
<p>What makes matters worse is that there appears to be some interesting langauge in the ICANN agreement that registrars are supposed to comply with:</p>
<blockquote>
<p style="text-align: left;"><em>&#8220;Registrar shall, upon notification by any person of an inaccuracy in the contact information associated with a Registered Name sponsored by Registrar, take reasonable steps to investigate that claimed inaccuracy. In the event Registrar learns of inaccurate contact information associated with a Registered Name it sponsors, it shall take reasonable steps to correct that inaccuracy.&#8221;</em></p>
</blockquote>
<p>Reasonable steps?  A little vague don&#8217;t you think? It will be interesting to see if ICANN does something here. Why does the prhase &#8220;Stop or I&#8217;ll yell Stop again!!!&#8221; come to my mind here?</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/ICANN" rel="tag"> ICANN</a>, <a href="http://technorati.com/tag/Spammer" rel="tag"> Spammer</a>, <a href="http://technorati.com/tag/Xinnet" rel="tag"> Xinnet </a></p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=DJiBQb"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=DJiBQb" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=WgaCEI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=WgaCEI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=tqNnNI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=tqNnNI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=JUW1HI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=JUW1HI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=H7eJai"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=H7eJai" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/319362156" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/06/icann-shutting-down-a-chinese-registrar/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/06/icann-shutting-down-a-chinese-registrar/</feedburner:origLink></item>
		<item>
		<title>New job for me :)</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/319362157/</link>
		<comments>http://www.infosecpodcast.com/2008/06/new-job-for-me/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 01:52:30 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Employment]]></category>

		<category><![CDATA[MIT]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=170</guid>
		<description>Yup&amp;#8230;.I&amp;#8217;m still around. For the record, working for a VAR is NOT for me. It has taken a couple of them to make me realize that if I am going to sell / represent a product it needs to be my product. Both of the VAR&amp;#8217;s I worked for recently, GreenPages and Focus Technology Solutions [...]</description>
			<content:encoded><![CDATA[<p>Yup&#8230;.I&#8217;m still around. For the record, working for a VAR is NOT for me. It has taken a couple of them to make me realize that if I am going to sell / represent a product it needs to be my product. Both of the VAR&#8217;s I worked for recently, GreenPages and Focus Technology Solutions were good companies to work for&#8230;.it just wasn&#8217;t for me.</p>
<p>So I am working in an Information Security position at MIT Lincoln Laboratory. It&#8217;s a very interesting mix of Academia and Military. We have a new CIO (as of last fall) and he really seems to be shaking things up and making some improvements. The environment is similar in feel to the NSA which is no surprise given the classified research that is done there. So far I am enjoying it. I do not enjoy the commute&#8230;about 60 miles each way with 12 of it being on 128. Those in the Boston area know all too well what I am talking about.</p>
<p>I&#8217;ve got a couple of posts in the works to try and freshen things up around here. The site is also going to get a fresh look and feel. Who knows, I might even get a podcast or two up <img src='http://www.infosecpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8211;Chris</p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=SUuMoK"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=SUuMoK" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=RaYE4I"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=RaYE4I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=c9j33I"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=c9j33I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=vpWdaI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=vpWdaI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=N0grmi"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=N0grmi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/319362157" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/06/new-job-for-me/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/06/new-job-for-me/</feedburner:origLink></item>
		<item>
		<title>Funny comment Spam</title>
		<link>http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~3/319362158/</link>
		<comments>http://www.infosecpodcast.com/2008/05/funny-comment-spam/#comments</comments>
		<pubDate>Tue, 13 May 2008 13:19:09 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Administrative]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/administrative/2008/05/funny-comment-spam/</guid>
		<description>I am doing some housecleaning (in more ways than one) and came across this comment awaiting approval from yesterday.
 &amp;#8221;Your previous posts were real rubbish, but this is good. This one is brilliant. Your blog is getting really better.&amp;#8221; 
The email address was a fake and the URL they left was to a porn site. Made [...]</description>
			<content:encoded><![CDATA[<p>I am doing some housecleaning (in more ways than one) and came across this comment awaiting approval from yesterday.</p>
<p><em> &#8221;Your previous posts were real rubbish, but this is good. This one is brilliant. Your blog is getting really better.&#8221; </em><br />
The email address was a fake and the URL they left was to a porn site. Made my morning.</p>
<p>And yes,  I am still alive.</p>
<p>&#8211;Chris</p>

<p><a href="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?a=io9aVE"><img src="http://feeds.feedburner.com/~a/Wwwinfosecpodcastcom?i=io9aVE" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=WEWZYI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=WEWZYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=Em1ctI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=Em1ctI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=kCKnDI"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=kCKnDI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?a=FJEuai"><img src="http://feeds.feedburner.com/~f/Wwwinfosecpodcastcom?i=FJEuai" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Wwwinfosecpodcastcom/~4/319362158" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/05/funny-comment-spam/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.infosecpodcast.com/2008/05/funny-comment-spam/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic Page Served (once) in 0.877 seconds --><!-- Cached page served by WP-Cache -->
