<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;D0UDSX0_cSp7ImA9WxNaEUs.&quot;"><id>tag:blogger.com,1999:blog-34349059</id><updated>2009-11-25T11:07:58.349-05:00</updated><title>Beau's Computer Security Blog</title><subtitle type="html">This blog will offer tips, tricks, and stories for folks who aren't as focused on computer security as I am.  Nothing here is cutting edge, but hopefully everybody can take something away.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://beauwoods.blogspot.com/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>30</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/BeausComputerSecurityBlog" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by-nc-sa/3.0/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry gd:etag="W/&quot;CUcNRXw4cCp7ImA9WxJXE0Q.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-648632860928719784</id><published>2009-06-07T12:38:00.003-04:00</published><updated>2009-06-07T12:44:54.238-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-07T12:44:54.238-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spam" /><category scheme="http://www.blogger.com/atom/ns#" term="comment spam" /><title>Blog Comment Spammer Strikes</title><content type="html">There's a comment spammer hitting my blog. Some anti-virus company I've never heard of, possibly some rogue anti-malware. Lame. So I've turned on moderation for my old posts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-648632860928719784?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=n_7QtQ82JaE:8SspPYcngjU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=n_7QtQ82JaE:8SspPYcngjU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=n_7QtQ82JaE:8SspPYcngjU:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=n_7QtQ82JaE:8SspPYcngjU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=n_7QtQ82JaE:8SspPYcngjU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=n_7QtQ82JaE:8SspPYcngjU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=n_7QtQ82JaE:8SspPYcngjU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=n_7QtQ82JaE:8SspPYcngjU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/n_7QtQ82JaE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/648632860928719784/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=648632860928719784" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/648632860928719784?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/648632860928719784?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/n_7QtQ82JaE/blog-comment-spammer-strikes.html" title="Blog Comment Spammer Strikes" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2009/06/blog-comment-spammer-strikes.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08BQH09fCp7ImA9WxZRFk4.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-8669830375191921322</id><published>2008-02-09T23:29:00.000-05:00</published><updated>2008-02-10T03:24:11.364-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-10T03:24:11.364-05:00</app:edited><title>Wordlist Manipulation</title><content type="html">Today I wanted to append and/or prefix a &lt;a href="http://en.wikipedia.org/wiki/Brute_force_attack"&gt;brute force&lt;/a&gt; &lt;a href="http://packetstormsecurity.org/Crackers/wordlists/"&gt;wordlist&lt;/a&gt; with some numbers, to generate some likely passwords. I couldn't find a good program to do this, so I tried my hand at some shell scripting. I got too ambitious and tried to add functions to remove duplicates (using the '&lt;a href="http://unixhelp.ed.ac.uk/CGI/man-cgi?uniq"&gt;uniq&lt;/a&gt;' Unix command), sort the list (using the '&lt;a href="http://unixhelp.ed.ac.uk/CGI/man-cgi?sort"&gt;sort&lt;/a&gt;' Unix command) and do replacement (using the '&lt;a href="http://unixhelp.ed.ac.uk/CGI/man-cgi?sed"&gt;sed&lt;/a&gt;' Unix command). But all of these proved too time consuming to do right. I didn't want to force the list to be sorted alphabetically in case it was already sorted in a different way (likelihood of use, for example), so the 'uniq' command was useless. And the 'sort' command is so easy you might as well just use it alone.  I didn't feel like putting the time into developing the "replace" function since I don't use it all that often (except for capitalizing the first letter, but &lt;a href="http://www.hoobie.net/brutus/"&gt;Brutus&lt;/a&gt; has a tool to do that). So here's my script. Don't laugh, it's the first coding I've done since &lt;a href="http://www.drscheme.org/"&gt;Dr. Scheme&lt;/a&gt;, about 5 years ago.&lt;br /&gt;&lt;pre&gt;&lt;blockquote&gt;&lt;br /&gt;#!/bin/sh&lt;br /&gt;&lt;br /&gt;##  listperm.sh - Takes a wordlist and performs permutations on it&lt;br /&gt;##  Copyright (C) 2008 Beau Woods (beauwoods.com)&lt;br /&gt;##&lt;br /&gt;##  This program is free software: you can redistribute it and/or modify&lt;br /&gt;##  it under the terms of the GNU General Public License as published by&lt;br /&gt;##  the Free Software Foundation, either version 3 of the License, or&lt;br /&gt;##  (at your option) any later version.&lt;br /&gt;##&lt;br /&gt;##  This program is distributed in the hope that it will be useful,&lt;br /&gt;##  but WITHOUT ANY WARRANTY; without even the implied warranty of&lt;br /&gt;##  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the&lt;br /&gt;##  GNU General Public License for more details.&lt;br /&gt;##&lt;br /&gt;##  You should have received a copy of the GNU General Public License&lt;br /&gt;##  along with this program.  If not, see http://www.gnu.org/licenses/.&lt;br /&gt;&lt;br /&gt;##  This script will take a wordlist and either prefix (-p) or append (-P)&lt;br /&gt;##  each line with each line of the file it is to be combined with. For&lt;br /&gt;##  modularity, it will generate new lists rather than overwriting the&lt;br /&gt;##  old ones.&lt;br /&gt;&lt;br /&gt;##  Command line options:&lt;br /&gt;##  -in [filename] - This is the wordlist you want to permutate.&lt;br /&gt;##  -out [filename] - This is the list of characters to add.&lt;br /&gt;##  -p [filename] - This will prefix the wordlist with another list.&lt;br /&gt;##  -P [filename] - This will append the wordlist with another list.&lt;br /&gt;&lt;br /&gt;vflag=on&lt;br /&gt;ops=0&lt;br /&gt;while [ $# -gt 0 ]&lt;br /&gt;do&lt;br /&gt; case "$1" in&lt;br /&gt;  -in) infile=$2; shift;;&lt;br /&gt;  -out) outfile=$2; shift;;&lt;br /&gt;  -p) prefile=$2; shift;;&lt;br /&gt;  -P) postfile=$2; shift;;&lt;br /&gt;  *) echo "Error: Unexpected Argument: "$1; error=1; break;;&lt;br /&gt; esac&lt;br /&gt; shift&lt;br /&gt;done&lt;br /&gt; &lt;br /&gt;##  This if block will check to see if the input file is given and will&lt;br /&gt;##  throw an error if not.&lt;br /&gt;if [ -z $infile ]; then&lt;br /&gt; echo "Error: No input file specified."&lt;br /&gt; error=1;&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;##  This if block will check to see if the output file is given and will&lt;br /&gt;##  throw an error if not.&lt;br /&gt;if [ -z $outfile ]; then&lt;br /&gt; echo "Error: No output file specified."&lt;br /&gt; error=1;&lt;br /&gt; else&lt;br /&gt; ##  This checks to see if the output file exists and if it does, throws&lt;br /&gt; ##  an error and exits the program. I don't want to clobber the file.&lt;br /&gt; if [ -f $outfile ]; then&lt;br /&gt;  echo "Error: The output file already exists. Please delete it"&lt;br /&gt;  echo "       and rerun the script."&lt;br /&gt;  error=1;&lt;br /&gt; fi&lt;br /&gt; ##  OK, now that we know the file doesn't exist, let's create it!&lt;br /&gt; touch $outfile&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;##  This if block checks to see if more than one permeutation operation&lt;br /&gt;##  is called and if so, throws an error message.&lt;br /&gt;if [ $ops -gt 1 ]; then&lt;br /&gt; echo "Error: Only one permeutation option may be run at once."&lt;br /&gt; error=1;&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;if [ $error ]; then&lt;br /&gt; echo &gt;&amp;amp;2&lt;br /&gt; echo "Options: -in [filename] -out [filename] -p [filename] -P [filename]"&lt;br /&gt; echo ""&lt;br /&gt; echo "  This script will take a wordlist and either prefix (-p) or append (-P)"&lt;br /&gt; echo "  each line with each line of the file it is to be combined with. For"&lt;br /&gt; echo "  modularity, it will generate new lists rather than overwriting the"&lt;br /&gt; echo "  old ones."&lt;br /&gt; echo ""&lt;br /&gt; echo "  Command line options:"&lt;br /&gt; echo "  -in [filename] - This is the wordlist you want to permutate."&lt;br /&gt; echo "  -out [filename] - This is the output file."&lt;br /&gt; echo "  -p [filename] - This will prefix the wordlist with another list."&lt;br /&gt; echo "  -P [filename] - This will append the wordlist with another list."&lt;br /&gt; echo ""&lt;br /&gt; exit 1;&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;##  This will determine if we are doing a prefix or append operation and will&lt;br /&gt;##  set the input file correctly. We could do this at the beginning, but if&lt;br /&gt;##  the arguments are out of order then something might get clobbered.&lt;br /&gt;if [ $prefile ]; then&lt;br /&gt; postfile=$infile;&lt;br /&gt; else&lt;br /&gt; if [ $postfile ]; then&lt;br /&gt;  prefile=$infile;&lt;br /&gt; fi&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;#####&lt;br /&gt;##  OK, time to start doing work!&lt;br /&gt;#####&lt;br /&gt;&lt;br /&gt;##  This checks to see if the operation is a concatenation and combines the files.&lt;br /&gt;for word in $(cat $prefile); do&lt;br /&gt; for i in $(cat $postfile); do&lt;br /&gt;  echo "$word""$i" &gt;&gt; $outfile&lt;br /&gt; done&lt;br /&gt;done&lt;br /&gt;&lt;/blockquote&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-8669830375191921322?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_UHF2yu6hII:IwcWQqR1P0w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_UHF2yu6hII:IwcWQqR1P0w:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_UHF2yu6hII:IwcWQqR1P0w:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_UHF2yu6hII:IwcWQqR1P0w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=_UHF2yu6hII:IwcWQqR1P0w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_UHF2yu6hII:IwcWQqR1P0w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=_UHF2yu6hII:IwcWQqR1P0w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_UHF2yu6hII:IwcWQqR1P0w:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/_UHF2yu6hII" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/8669830375191921322/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=8669830375191921322" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/8669830375191921322?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/8669830375191921322?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/_UHF2yu6hII/wordlist-manipulation.html" title="Wordlist Manipulation" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2008/02/wordlist-manipulation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMCQ3g4cCp7ImA9WxZSF00.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-3320457608644616497</id><published>2008-01-30T09:45:00.001-05:00</published><updated>2008-01-30T09:47:42.638-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-01-30T09:47:42.638-05:00</app:edited><title>Shmoocon</title><content type="html">I'll be at &lt;a href="http://www.shmoocon.org/"&gt;Shmoocon&lt;/a&gt; in Washington, DC on the weekend after Valentine's Day. If anybody wants to meet up or something, get in touch with me.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-3320457608644616497?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=rgISQwf6MJg:th_YtlU0QXk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=rgISQwf6MJg:th_YtlU0QXk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=rgISQwf6MJg:th_YtlU0QXk:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=rgISQwf6MJg:th_YtlU0QXk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=rgISQwf6MJg:th_YtlU0QXk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=rgISQwf6MJg:th_YtlU0QXk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=rgISQwf6MJg:th_YtlU0QXk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=rgISQwf6MJg:th_YtlU0QXk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/rgISQwf6MJg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/3320457608644616497/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=3320457608644616497" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3320457608644616497?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3320457608644616497?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/rgISQwf6MJg/shmoocon.html" title="Shmoocon" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2008/01/shmoocon.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8CR3w8cSp7ImA9WB9XFEs.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-3363242410852115280</id><published>2007-11-07T13:41:00.000-05:00</published><updated>2007-11-07T13:41:06.279-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-11-07T13:41:06.279-05:00</app:edited><title>Mac OS X Trojan Horse - Wolf in Sheep's Clothing?</title><content type="html">Recently, a Mac OS X Trojan Horse was spotted in the wild. &lt;a href="http://www.f-secure.com/v-descs/trojan_osx_dnschanger.shtml"&gt;Pretty&lt;/a&gt; &lt;a href="http://vil.nai.com/vil/content/v_143511.htm"&gt;much&lt;/a&gt; &lt;a href="http://www.us-cert.gov/current/#mac_dns_changer_trojan"&gt;everyone&lt;/a&gt; &lt;a href="http://sunbeltblog.blogspot.com/2007/10/mac-trojan-overhype-you-tell-me.html"&gt;reported&lt;/a&gt; &lt;a href="http://isc.sans.org/diary.html?storyid=3595"&gt;on&lt;/a&gt; &lt;a href="http://securityincite.com/TDI-2007-11-01#TSN1"&gt;it&lt;/a&gt;. But the best analysis I've seen is at &lt;a href="http://blogs.securiteam.com/index.php/archives/1029"&gt;SecuriTeam&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This is not a new type of attack. There is no new vulnerability exploited. This is not a novel attack, such as a driver exploit. This does not use some new social engineering technique or distribution method. This is not the first instance of organized crime (presumably) attempting to make money from exploiting systems. So why is everybody making a big deal about the new malware? People are making a big deal about this one because of what it is not:  a Microsoft attack.&lt;br /&gt;&lt;br /&gt;This new Trojan Horse is the first one to take an established commercial malware framework to the Apple platform. For years, these fake &lt;a href="http://en.wikipedia.org/wiki/Codec"&gt;codecs&lt;/a&gt; have troubled the Windows platform, making untold amounts of money for their creators. They hijack the user's Internet experience and target people inexperienced with computers. But until now, the relatively simple task of adapting these programs for the decade old operating system has been left undone. I believe that there are two reasons for this shift.&lt;br /&gt;&lt;br /&gt;The number of people using Apple computers (and therefore OS X) has exploded over the last year and a half. I am currently sitting at a coffee shop and an informal survey shows that there are 12 Macs and only 6 PCs (including, unfortunately, mine). While this is an atypical distribution of hardware, it underscores the point. I know that most of these have been purchased within the last year and a half because they are almost all running on the Intel platform.&lt;br /&gt;&lt;br /&gt;As the proportion of Mac users increases, the community is bound to decrease in computer experience. For the last few years, Apple has had a loyal core of customers who are technologically savvy and educated about proper use and maintenance of their machines. However, the recent adopters are typically more casual computer users. This statistic is based on anecdotal evidence, but it seems that most other observers have drawn the same conclusion.&lt;br /&gt;&lt;br /&gt;These two trends, increased install base and decreased expertise, will continue upward as computer activities become increasingly platform independent. As more and more services are moved to a Web based format, the importance of a single operating system will diminish. However, malware will continue to exploit the underlying system resources because this is a viable source of income.&lt;br /&gt;&lt;br /&gt;Criminal organizations' involvement in computer based crime has drastically risen in prevalence and sophistication over the last few years and there is no reason to believe that this will change. Just like with any money-making organization, these enterprises wish to maximize their revenue streams by exploiting new markets. In order to grow, new resources must be acquired. It appears that Apple computers have been firmly identified as a new resource for criminals.&lt;br /&gt;&lt;br /&gt;And like any other emerging market, what is pioneered by one group will quickly be followed by other players. In other words, other criminal organizations will follow suit and develop their software for the OS X operating system to compete with this group's product offering. Eventually, this market segment will become more mature with a high percentage of organized criminals developing for both Windows and OS X platforms the way that other software makers do. What used to be a hobbiest market will be filled by mature product offerings.&lt;br /&gt;&lt;br /&gt;If there is nothing new about a piece of malware, it should not be a big deal. But this one &lt;u&gt;is&lt;/u&gt; a big deal that many people will only recognize too late. This Trojan Horse is something new precisely because it's just business as usual.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-3363242410852115280?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zSDks419mOU:VC-Fda-GQqk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zSDks419mOU:VC-Fda-GQqk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zSDks419mOU:VC-Fda-GQqk:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zSDks419mOU:VC-Fda-GQqk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=zSDks419mOU:VC-Fda-GQqk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zSDks419mOU:VC-Fda-GQqk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=zSDks419mOU:VC-Fda-GQqk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zSDks419mOU:VC-Fda-GQqk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/zSDks419mOU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/3363242410852115280/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=3363242410852115280" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3363242410852115280?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3363242410852115280?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/zSDks419mOU/mac-os-x-trojan-horse-wolf-in-sheeps.html" title="Mac OS X Trojan Horse - Wolf in Sheep's Clothing?" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/11/mac-os-x-trojan-horse-wolf-in-sheeps.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMMR309fip7ImA9WB9XEk4.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-2773453110797016160</id><published>2007-11-04T23:46:00.000-05:00</published><updated>2007-11-04T23:54:46.366-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-11-04T23:54:46.366-05:00</app:edited><title>Long Time, No Post</title><content type="html">It's been quite a while since I posted last. Sorry, I've been busy. But I do keep my "Interesting Articles" section updated. That is over on the right side of your screen (assuming you're looking at my blog and not the RSS feed). That list is all of the articles that I have read in Google Reader and chosen to "share" via the button at the bottom of each story. I wish that there was a way that you could click to get all of the links, not just the last five or so. I'm sure that there is, I just don't know how to do it so if anybody does, drop me a line.&lt;br /&gt;&lt;br /&gt;For the record, I &lt;span style="font-style:italic;"&gt;am&lt;/span&gt; working on some other public stuff, but I'm going to keep that under wraps for now. Nothing groundbreaking or significant, just adding to the general InfoSec fluff out there. If I had as much time as I do ideas I'd live forever. Hopefully I can gt better at figuring out which ones are worth pursuing so I don't spend my time starting into things that I don't end up finishing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-2773453110797016160?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=jnVJoQLFExQ:x-TBuPEnshs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=jnVJoQLFExQ:x-TBuPEnshs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=jnVJoQLFExQ:x-TBuPEnshs:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=jnVJoQLFExQ:x-TBuPEnshs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=jnVJoQLFExQ:x-TBuPEnshs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=jnVJoQLFExQ:x-TBuPEnshs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=jnVJoQLFExQ:x-TBuPEnshs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=jnVJoQLFExQ:x-TBuPEnshs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/jnVJoQLFExQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/2773453110797016160/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=2773453110797016160" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/2773453110797016160?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/2773453110797016160?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/jnVJoQLFExQ/long-time-no-post.html" title="Long Time, No Post" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/11/long-time-no-post.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUBQH4_fCp7ImA9WB5bGEo.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-7874444310528273167</id><published>2007-09-03T21:11:00.000-04:00</published><updated>2007-09-03T22:17:31.044-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-09-03T22:17:31.044-04:00</app:edited><title>Perfect Security Is Impossible</title><content type="html">I saw &lt;a href="http://securosis.com/2007/09/03/certified-site-hacked-no-compliance-checklist-or-certification-can-ever-make-you-totally-secure/"&gt;this post on securosis.com&lt;/a&gt; and it seemed like a great launching point for a discussion here.  I want to take one point that he makes, that people seem to ask "what can I do to fix problems after the fact?"  The fact that people ask this question hides a couple of addressable assumptions they often make about computer security.&lt;br /&gt;&lt;br /&gt;The first of these is that computer problems should be addressed reactively, rather than proactively.  Some people take the stance that they will always be vigilant, but many realize that they don't always do what they should.  For example, most people know that they should have their vehicles serviced regularly for a multitude of maintenance issues, such as oil changes, brake replacement, tire rotation, check fluids, etc.  But many of the drivers out there do not take these precautions as often as they should.  Instead, they may take the attitude of "I'll fix it if it breaks."  This may not necessarily be conscious decision, either; it may be that the "out of sight, out of mind" rule takes over, or that the owner is too busy to attend to it at the moment.&lt;br /&gt;&lt;br /&gt;The reactive attitude also assumes that everything can be fixed and put back perfectly in place as it was.  This assumption runs a little bit deeper in most people, because they do not really know how computers operate.  On a car, a bent frame is not perfectly repairable; in our bodies, a removed organ does not grow back; in the universe, time flows only in one direction.  Yet even mechanics, doctors, and scientists may not really understand that a computer can be broken in a way that is irreparable.&lt;br /&gt;&lt;br /&gt;Fortunately, with computers we can address problems proactively.  Computer security deals with protecting Confidentiality, Integrity, and Availability (the so-called C.I.A. triad).  These are the three aspects of the rest of our lives that most of us attempt to protect, as well.  It follows, then, that we should view our responsibilities towards our computers safe as we do our responsibilities to keeping ourselves safe.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Using caution&lt;/span&gt; applies to technology as with anything.  Stay away from the seedier side of the Internet as you would stay away from the seedier side of the city you live in.  If you need a hand deciding which are the well-lit streets and which are the back alleys, there are tools to help.  &lt;a href="http://www.siteadvisor.com/"&gt;McAfee Site Advisor&lt;/a&gt; is an excellent tool, and tends to err on the side of caution.  &lt;a href="http://www.k9webprotection.com/"&gt;K9 Web Protection&lt;/a&gt; will actually block many sites that you may wish to avoid, though it's not fool proof.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Be observant&lt;/span&gt; of your surroundings.  If something seems not quite right, don't be afraid to be suspicious.  If your computer is acting strangely or if the email from the IRS sounds fishy (&lt;a href="http://www.google.com/search?hl=en&amp;q=IRS+Phishing"&gt;phishy&lt;/a&gt;), then investigate the problem.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Be ready&lt;/span&gt; to &lt;span style="font-weight: bold;"&gt;take action&lt;/span&gt;.  When you have determined that something strange is definitely going on, make sure you know what to do.  If you don't know what to do, then know who you can speak with to find out.  But more importantly, when you have figured out the proper action to take, don't delay!  Many issues are exacerbated by doing nothing when you should be doing something (or vice-versa).&lt;br /&gt;&lt;br /&gt;Finally, &lt;span style="font-weight: bold;"&gt;be prepared&lt;/span&gt; to fix or workaround the problem.  Something will happen someday that will compromise the C.I.A. of your computer.  Whether that means you delete the wrong files, you get a virus, or your house burns down, something will happen to your digital life someday.  No one, even us geeks, is immune.  Have backups, antivirus, etc. ready when you need them.&lt;br /&gt;&lt;br /&gt;All of these lessons can, and should, be applied to the real world.  Most of us understand this, even if we don't practice it every day.  But too many people don't seem to realize that computers are not immune from the same physical realities of everything else.  Either that or they are afraid to ask about these things.  But Murphy's Law still applies, as does the principle that anyone can learn how to defend themselves against it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-7874444310528273167?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=1cpmDyAh3EE:f_IXXPu14nc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=1cpmDyAh3EE:f_IXXPu14nc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=1cpmDyAh3EE:f_IXXPu14nc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=1cpmDyAh3EE:f_IXXPu14nc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=1cpmDyAh3EE:f_IXXPu14nc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=1cpmDyAh3EE:f_IXXPu14nc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=1cpmDyAh3EE:f_IXXPu14nc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=1cpmDyAh3EE:f_IXXPu14nc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/1cpmDyAh3EE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/7874444310528273167/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=7874444310528273167" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7874444310528273167?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7874444310528273167?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/1cpmDyAh3EE/perfect-security-is-impossible.html" title="Perfect Security Is Impossible" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/09/perfect-security-is-impossible.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMARXw8cCp7ImA9WB5UEEQ.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-3304264282365588363</id><published>2007-08-14T18:45:00.000-04:00</published><updated>2007-08-14T07:54:04.278-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-08-14T07:54:04.278-04:00</app:edited><title>More On What IT Wants To Tell You</title><content type="html">Last Tuesday, I was contacted by &lt;a href="mailto:vauhini.vara@wsj.com"&gt;Vauhini Vara&lt;/a&gt;, author of the now infamous &lt;a href="http://online.wsj.com/article/SB118539543272477927.html?mod=fpa_mostpop"&gt;WSJ article&lt;/a&gt; published last week (FYI, if you haven't listened to the podcast related to the article, it's worth it) with advice on how to circumvent the IT security controls their companies had put in place.  The email thanked me for my comments and asked for some help in writing &lt;a href="http://wsjonline.com/"&gt;a response to that article&lt;/a&gt;.  I took a long time creating a response before realizing that I'd gotten way off topic from the request.  So I have cleaned it up a bit and posted it below.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://online.wsj.com/article/SB118705744702696863.html?mod=hpp_us_editors_picks"&gt;follow up article&lt;/a&gt; was published today and is available to everyone for free, just as was the original article.  While the latest does give a voice to some of the concerns many security professionals had, it seems to serve mainly to placate those with concerns.  I don't believe this is something the author should be faulted for, but merely reflects everyone's interest in seeing the story be over.  At the risk of seeming unappeasable, I think that the article lacks the intensity of the first and seems to demonstrate a lack of true understanding of the topic.&lt;br /&gt;&lt;br /&gt;Again, I don't see this as Vauhini's fault, she has the near impossible task of taking something some people spend their entire lives doing and tries to boil it down to a couple of hundred words to fit into a column.  Without an in depth understanding of the subject and a gift for succinctness (which I don't have), this is incredibly difficult to do.  I would imagine that the only way to get this right would be to collaborate with a subject matter expert, allowing editing and revisions.  But this is not appropriate to the typical journalistic process.&lt;br /&gt;&lt;br /&gt;I won't spend any more time talking about this subject because there will never be complete agreement between IT security people and the employees over where an acceptable boundary is between protecting the organization and ease and freedom of use.  There isn't even total agreement between employees or between IT security folks.  So this post will, thankfully, be my last on the subject.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;More thoughts on the topic&lt;/span&gt;&lt;br /&gt;As I mentioned in &lt;a href="http://beauwoods.blogspot.com/2007/07/at-least-ten-things-wsj-got-wrong.html"&gt;my earlier post&lt;/a&gt;, the IT department is involved in businesses to enable productivity and to contribute to the bottom line.  The information security professionals are there to provide technical oversight in the way that the physical security people do.  Several things are involved in this oversight, like being involved in the design process, putting in place administrative and technical controls, and auditing the organization's procedures.&lt;br /&gt;&lt;br /&gt;The difference between the physical security and information security is that physical security is something we are born and bred to recognize and respond to.  Things like protecting valuable assets, restricting access to locations, and preventing attacks are well understood by people because they have had to deal with these issues all their lives.  However, when computers are involved, it makes these same principles seem alien.  Computers and information networks are incredibly complicated systems and understanding them is too large a task.  Therefore it is difficult for people to have an intuitive sense of what security and usability balances are made.&lt;br /&gt;&lt;br /&gt;In designing a good access control system, for example, it is widely acknowledged that access to a facility should be granted only to those people who have a need to be there.  So systems have been put in place to make sure people walking into the building should be there, whether it is a security guard, an ID badge reader, etc.  IT security is no different in practice.  When we design, say wireless network, we also want to make sure that these precautions are taken.  Having access to an organization's network can be just as damaging, more or less, as having physical access to the home office.  While employees may recognize the potential danger in propping open a door to the outside, they may not realize that this is the same principle as bringing in a wireless access point from home.&lt;br /&gt;&lt;br /&gt;One of the main interfaces, and problems, people have with IT security is web page filtering.  They typically don't view it as anything but trying to keep them productive on the job.  So they view circumventing this technology as a relatively benign thing to do, especially if they are taking a break.  But productivity is almost certainly not the reason why the web blocker was brought into the network.  Malicious content (whether hosted on reputable sites or on maliciously designed sites) and legal precautions (regulatory requirements, sexual discrimination law, etc.) top the list of reasons why IT security departments want to be able to block certain websites.&lt;br /&gt;&lt;br /&gt;Along with filtering web content, monitoring Internet traffic is one of the important tasks that IT security personnel perform.  In some industries, this is driven more by organizational needs than by regulatory requirements.  Many companies and governmental institutions have a need to know what comes in and goes out of their network.  Internet monitoring is one tool to help with this.  In cases where secret, confidential, or regulated information is involved, knowing if it escapes the network is critical.  This can be accidental, like a consultant emailing important documents to himself, or it can be malicious, like a key logging program transmitting credit card numbers a half a world away.&lt;br /&gt;&lt;br /&gt;However, web filtering and monitoring devices have been tasked to try and decrease the amount of time employees spend not working while they are at work.  And this is when most people come into conflict with the technology.  A worker who wants to visit the New York Times webpage and finds it blocked may feel that these technical controls are unreasonable.  This may, in turn, cause him or her to try to circumvent them in the process of doing normal business.  For example, if an employee needs to send a log file to a vendor and it is too large to go out through the email system, using a web page to host the file might seem like an ideal way to get this done.  However, if we pretend in this scenario that the log contains records of all patients admitted to the Emergency Department of a hospital, those records are exposed on the Internet for anyone to access.&lt;br /&gt;&lt;br /&gt;With those things in mind, here are some tips to help people to work with, instead of against your IT security people.  These positive suggestions will likely work better than their "don't do this" counterparts.&lt;br /&gt;&lt;br /&gt;1.  We're here to help you help the company make money.  That's how we get fat bonuses and better toys!  If you have a legitimate business need to do something that we're preventing, talk to us.&lt;br /&gt;&lt;br /&gt;2.  We love playing with new toys!  We'd love to spend 50 grand on new wireless access points and have them around to play with.  If you can help us build a business case to do that, we'll work with you.&lt;br /&gt;&lt;br /&gt;3.  Come to us with your problems and ask us to help.  We may know an easier way of doing something through automation or simplification.  Give us the opportunity and freedom to be flexible and creative when fixing your problem and we might amaze you!&lt;br /&gt;&lt;br /&gt;4.  We take our jobs seriously and have pride in our knowledge and skills.  If you treat us with professional respect, we will do the same for you.  If you are patient and friendly with us, we are more likely to want to help you.  If you treat us well consistently, we don't forget it.&lt;br /&gt;&lt;br /&gt;5.  We enjoy being thanked and appreciated.  Some things might take a lot of work or be especially challenging.  Thanking us sincerely is the easiest way to show you recognize this.  Baked goods and complimenting us to our boss is the best way to get us to work twice as hard for you next time!&lt;br /&gt;&lt;br /&gt;Working in IT can give you quite a few good horror stories to share.  IT security can produce some especially gruesome ones.  Some of the stories are protected by confidentiality agreements or legal order, but many of these would not be safe to print anyway.&lt;br /&gt;&lt;br /&gt;I won't give any specific stories about the type of pornography that I have seen in my job, but I have to say that I've seen more things than I could have imagined existed.  While I haven't seen anything that would be illegal, I have certainly had my eyes opened to the variety of things that people find erotic.&lt;br /&gt;&lt;br /&gt;My organization fought a network worm shortly after I became involved with information security.  It wasn't a terribly destructive or widespread one, but we spent over 200 hours cleaning it up.  After some investigation, it was determined that the worm exploited a new vulnerability and was probably brought in by someone using a personal laptop.&lt;br /&gt;&lt;br /&gt;Several times a day, the Internet monitor alerts me to the fact that someone has sent their own (or sometimes a friend or associate) personal information out on the Internet.  Whether it is their tax return being sent to their webmail address, their application for a car or payday loan or job, a background check for a tenant, many people don't realize that the information they send out can be seen by many people they don't intend.  Most of the time we, try to contact the person or company responsible for the information to make sure that they are aware of the issue.&lt;br /&gt;&lt;br /&gt;Occasionally, we have had viruses or spyware infect computers embedded in products that we are prohibited from working on and to which we do not have access.  In these cases, we attempt to contact the vendor and, depending on the severity of the attack, treat the device as if it were nonfunctional, remove it from the workflow, and power it off.&lt;br /&gt;&lt;br /&gt;Lack of communication is one of the biggest problems that we have.  From things as simple as a vendor needing Internet access to do a presentation to departmental changes that will require hardware moves and substantial changes to organization software, sometimes people don't understand what is involved for us in doing that work.  We can't always fix a problem immediately, even if we don't have a full schedule -- they take real time and effort.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-3304264282365588363?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=ZkMQGJeYDro:dPBRQ3cV11Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=ZkMQGJeYDro:dPBRQ3cV11Q:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=ZkMQGJeYDro:dPBRQ3cV11Q:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=ZkMQGJeYDro:dPBRQ3cV11Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=ZkMQGJeYDro:dPBRQ3cV11Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=ZkMQGJeYDro:dPBRQ3cV11Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=ZkMQGJeYDro:dPBRQ3cV11Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=ZkMQGJeYDro:dPBRQ3cV11Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/ZkMQGJeYDro" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/3304264282365588363/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=3304264282365588363" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3304264282365588363?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3304264282365588363?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/ZkMQGJeYDro/more-on-what-it-wants-to-tell-you.html" title="More On What IT Wants To Tell You" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/08/more-on-what-it-wants-to-tell-you.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUEHRHY7fSp7ImA9WB5VE04.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-7538010519988810565</id><published>2007-08-05T14:13:00.000-04:00</published><updated>2007-08-05T14:13:55.805-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-08-05T14:13:55.805-04:00</app:edited><title>How To Explain The Internet To Your Grandmother</title><content type="html">In an interview for &lt;a href="http://beauwoods.blogspot.com/2007/07/new-job.html"&gt;my new job&lt;/a&gt;, I was asked how I would explain the Internet to my Grandmother.  Wow, that one caught me unprepared.  How would I even go about explaining something which has such great complexity to someone utterly unfamiliar with the concept?  How would you do it?  How do we explain technology to the technologically challenged?&lt;br /&gt;&lt;br /&gt;I began by talking about the physical structure of the Internet: general purpose computing devices connected by optical and copper transmission conduits.  I realized that it was wrong, so I began talking about what the Internet does: connecting people, organizations, data stores, etc.  That wasn't quite right either, so I went on to explain what the Internet allows:  shopping, chatting, referencing information, etc.  This was better, but still not great.  I made analogies to talking on the phone with a network of friends and to looking up words or concepts in an encyclopedia.  Still not perfect, but I made an impression on the interviewer that was good enough to get a job offer.&lt;br /&gt;&lt;br /&gt;But the question remained with me and I have thought about it quite a bit.  The problem of how to explain anything to anyone is one that &lt;a href="http://www.google.com/search?q=%22how+to+explain+anything+to+anyone%22"&gt;almost nobody is talking about how to do this&lt;/a&gt;.  It really boils down to about three components:  a near complete knowledge of the material, adequate knowledge of the audience, and an ability to relate the two.  In answering my question, my problem was that I didn't do the latter two very well.  I really don't know enough about what problems my Grandmother faces (out of milk, how to take care of a diabetic, what to do on Tuesday afternoon with the Great-Grandkids), how she solves them (going to the store, asking a physician, reading the local paper), how well her solutions take care of the problems (very well, moderately well, poorly), and what outstanding problems she still has (how to keep someone from wanting to eat cookies, nothing going on in town this Tuesday).  And so not knowing these things, I cannot adequately explain to her how the Internet works in a way that she will understand as being relevant to her (posting questions on forums, researching helpful websites; lesser known events, new fun things to do around the house).  Instead of doing this, I was trying to explain it to her from my point of view and taking only my concerns into account.&lt;br /&gt;&lt;br /&gt;After doing some more thinking, I came to the conclusion that I was on the right track with my explanation, but for the wrong reason.  I had the general groups right, but the format was all wrong.  The key to understanding many systems is to think about them in three layers:  What something is, what it does, and what it makes possible. The Internet then is a large number of copper, radio, or optical connections for a large number of general purpose machines around the world.  It allows communication between these disparate machines by automated processes or by human users.  It makes possible things like shopping, referencing, entertaining, etc.  There is overlap between these categories, for example protocols could fit in the "what it is" and the "what it does" but in general, this is a good way to categorize and conceptualize these divisions.&lt;br /&gt;&lt;br /&gt;The right way to come at explaining this system is to begin with the higher level, the "what it makes possible" part of the equation -- this is another reason why my explanation failed.  Analogies can be an important part of this to make sure the audience understands.  So I would begin by explaining to my Grandmother that she can order things online as she could do in a catalog.  Or she can research and ask questions of doctors, others taking care of diabetics, researchers, etc.  And she could find more local information, so maybe she could find a regular local event that the papers don't bother to include.  This way, I have her attention and she is interested in learning how all of this is made possible.&lt;br /&gt;&lt;br /&gt;That is when I would begin to explain the details of databases, webfront shopping, user generated content sites, trustworthiness of information, etc.  I can tell her how Amazon is able to offer that reprint of a book she read as a girl when no local stores have even seemed to be able to order it for her.  I can tell her that she can share her experiences caring for a diabetic with others to help them learn from her great experience.  I can show her how her computer is a part of the global network and what that means in terms of responsibilities and freedoms.&lt;br /&gt;&lt;br /&gt;Then if she is interested in learning the technical details and inner workings of the Internet (and what Grandmother wouldn't be), I can describe these things.  I can talk to her about protocols, the OSI model, and the benefits of optical versus copper for data distribution.  As this will probably be later in the day, it will be a perfect time to address these issues as they will ease her way into sleep.  We may both pass out simultaneously when I get to the rainbow series of books.&lt;br /&gt;&lt;br /&gt;If there is an information security lesson here, it is that you really can explain to others how technology works.  You have to know your subject well, know your audience, and know how to connect the two.  But the most important part of this is to get the audience interested quickly and draw them in by connecting the audience to the subject in a way that is meaningful to them.  You can do this using third layer of my system model, the "what does it make possible" layer.  Then you can delve deeper as is appropriate.  It might be more difficult at first, but I think that it will become easier with more practice.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-7538010519988810565?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=HfcVAw88MLo:P-PJcDlBuX8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=HfcVAw88MLo:P-PJcDlBuX8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=HfcVAw88MLo:P-PJcDlBuX8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=HfcVAw88MLo:P-PJcDlBuX8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=HfcVAw88MLo:P-PJcDlBuX8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=HfcVAw88MLo:P-PJcDlBuX8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=HfcVAw88MLo:P-PJcDlBuX8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=HfcVAw88MLo:P-PJcDlBuX8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/HfcVAw88MLo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/7538010519988810565/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=7538010519988810565" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7538010519988810565?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7538010519988810565?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/HfcVAw88MLo/how-to-explain-internet-to-your.html" title="How To Explain The Internet To Your Grandmother" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/how-to-explain-internet-to-your.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMERnozcCp7ImA9WB5VE0g.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-2708307923942582934</id><published>2007-08-03T21:50:00.000-04:00</published><updated>2007-08-05T18:20:07.488-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-08-05T18:20:07.488-04:00</app:edited><title>Don't Try To Con A Con Man</title><content type="html">Don't try to con a con man.  This is the lesson learned from the 1988 movie, &lt;a href="http://imdb.com/title/tt0095031/"&gt;Dirty Rotten Scoundrels&lt;/a&gt;, starring &lt;a href="http://www.compleatsteve.com/essays/banjo.htm"&gt;Steve Martin&lt;/a&gt; and &lt;a href="http://www.michaelcaine.com/Projects.php"&gt;Michael Caine&lt;/a&gt;.  (BTW, &lt;a href="http://www.stevemartin.com/"&gt;Steve's official website&lt;/a&gt; wins the prize of funniest and most bizarre of the week, narrowly edging out &lt;a href="http://sunbeltblog.blogspot.com/2007/08/seen-in-wild-bizarre-scam-site.html"&gt;this one&lt;/a&gt; -- it's been a busy week, folks.)  This lesson is &lt;a href="http://imdb.com/title/tt0093779/quotes"&gt;one of the classic blunders&lt;/a&gt;.  Unfortunately for one of &lt;a href="http://www.msnbc.msn.com/id/3032600/"&gt;Dateline NBC&lt;/a&gt;'s producers, &lt;a href="http://tv.yahoo.com/michelle-madigan/contributor/1297133"&gt;Michelle Madigan&lt;/a&gt;, she'd never heard the corollary "&lt;a href="http://blog.wired.com/27bstroke6/2007/08/media-mole-at-d.html"&gt;never try to social engineer a hacker&lt;/a&gt;."&lt;br /&gt;&lt;br /&gt;You see, the trouble started when Ms. Madigan decided to try to infiltrate the (in)famous technology security convention, &lt;a href="http://www.defcon.org/"&gt;DefCon&lt;/a&gt; to get a story about the participants breaking the law.  Of course this wouldn't be news, but neither is Dateline NBC (yes, a cheap shot, but c'mon -- have you &lt;a href="http://www.msnbc.msn.com/id/20078671/"&gt;seen this&lt;/a&gt;?).  Apparently, the DefCon organizers have their own mole deep inside Dateline HQ who alerted them to the plan and sent along a picture.  &lt;a href="http://blog.wired.com/photos/uncategorized/2007/08/03/dateline_mole.jpg"&gt;This photo&lt;/a&gt; was displayed before each lecture along with the message that she was attempting to deceptively gather information for a report.  Apparently the assistant producer was lured to an ambush, was confronted, fled, and was hounded by people taking photos and videos.  &lt;a href="http://www.msnbc.msn.com/id/10912603/"&gt;Sound familiar&lt;/a&gt;?&lt;br /&gt;&lt;br /&gt;The takeaway here is that confronting an opponent on their own turf is a great way to get the opposite of the result you want.  There have been &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/02/14/AR2006021401342.html"&gt;several&lt;/a&gt; &lt;a href="http://www.cnn.com/2005/TECH/internet/10/07/kevin.mitnick.cnna/index.html"&gt;legitimate&lt;/a&gt; &lt;a href="http://www.pbs.org/wgbh/pages/frontline/shows/cyberwar/interviews/hacker.html"&gt;reporters&lt;/a&gt; (&lt;a href="http://www.snn-rdr.ca/snn/old/september/scottbrampton.html"&gt;even kids!&lt;/a&gt;) and bloggers who have spoken with the kind of people who populate the virtual back alleys of the Internet.  By being open and honest about their intentions, they usually manage to get a worthwhile interview.  There are also several bloggers who have misrepresented themselves to get access to material from these people.  But they were very careful about doing it and built up a trust relationship.  I think the best advice here is to just be forthright and honest and leave the tricky and manipulative stuff to the professionals.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;update:&lt;/span&gt;  &lt;a href="http://www.youtube.com/watch?v=nCvmkxO5hoQ"&gt;Here's a video&lt;/a&gt;, complete with crappy crowd participation boos and hisses, amateur videography, paparazzi style ambush journalism, etc.  While turnabout is fair play, do you think that she's the only person who's misrepresented herself at DefCon? I doubt it.  Show's over, get back to the presentations, folks.  That's what we'll all be thinking about on Monday.&lt;br /&gt;&lt;br /&gt;Of course, &lt;a href="http://www.hackaday.com/2007/08/03/defcon-15-undercover-reporter-flees/"&gt;Elliot&lt;/a&gt; brings up some good points about her refusing press credentials, the irony of the "spot the Fed" competition she hoped to join, and the fact that even bloggers apply for press passes to avoid this treatment.  So maybe I'm off base by thinking that it's only a funny story with the slow news weekend coming up.  Decide for yourselves, folks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-2708307923942582934?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=MkWK615OwM0:-JyLJCTQCxQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=MkWK615OwM0:-JyLJCTQCxQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=MkWK615OwM0:-JyLJCTQCxQ:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=MkWK615OwM0:-JyLJCTQCxQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=MkWK615OwM0:-JyLJCTQCxQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=MkWK615OwM0:-JyLJCTQCxQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=MkWK615OwM0:-JyLJCTQCxQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=MkWK615OwM0:-JyLJCTQCxQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/MkWK615OwM0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/2708307923942582934/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=2708307923942582934" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/2708307923942582934?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/2708307923942582934?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/MkWK615OwM0/dont-try-to-con-con-man.html" title="Don't Try To Con A Con Man" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/08/dont-try-to-con-con-man.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEACQHg6eSp7ImA9WB5VFks.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-4663037219082443928</id><published>2007-07-31T09:46:00.001-04:00</published><updated>2007-08-09T09:39:21.611-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-08-09T09:39:21.611-04:00</app:edited><title>(At Least) Ten Things The WSJ Got Wrong</title><content type="html">I have just been reading an article on the Wall Street Journal site called "&lt;a href="http://online.wsj.com/article/SB118539543272477927.html?mod=fpa_mostpop"&gt;Ten Things Your IT Department Won't Tell You&lt;/a&gt;." The article is about how and why companies don't let you do certain things on their computers and on their networks, and how you can get around these security controls.  The article completely misses the point of the security controls.    I'm with the IT department, and I want to tell you why and how the WSJ got it wrong.&lt;br /&gt;&lt;br /&gt;Security features are put in place to protect the confidentiality, integrity, and availability of assets of a company.  This does not vary much from place to place, this is the stated reason for putting most security measures in place.  Most security practitioners don't even view employees' productivity as an asset; if there is a productivity problem, the burden of enforcement lies with the employee's manager or supervisor.  From personal experience, I can tell you that I have much better things to do with my time than to try and see who has been trying to get to &lt;a href="http://youtube.com/"&gt;YouTube&lt;/a&gt; or &lt;a href="http://playboy.com/"&gt;Playboy&lt;/a&gt;.  But if you circumvent our security measures, I'm required by regulations, guidelines, and company procedures to investigate the incident.&lt;br /&gt;&lt;br /&gt;This brings me to one of the biggest things that the WSJ article seems to miss:  We can see you doing what you are doing!  Many organizations, due to regulations such as &lt;a href="http://www.hhs.gov/ocr/hipaa/"&gt;HIPAA&lt;/a&gt;, &lt;a href="http://www.sec.gov/spotlight/sarbanes-oxley.htm"&gt;SOX&lt;/a&gt;, &lt;a href="http://www.ftc.gov/privacy/privacyinitiatives/glbact.html"&gt;GLBA&lt;/a&gt;, &lt;a href="https://www.pcisecuritystandards.org/"&gt;PCI DSS&lt;/a&gt;, etc. are required to put in place tools to give visibility into electronic communications.  This means that wherever you work, you probably have somebody looking over your shoulder.  In my organization, we use a monitor that lets us see any &lt;a href="http://en.wikipedia.org/wiki/Encryption"&gt;unencrypted&lt;/a&gt; communication going out to the Internet.  We have rules built in the monitor that will log and alert us when certain keywords or other data are transmitted.&lt;br /&gt;&lt;br /&gt;For instance we have rules built to detect people circumventing our website blocker by using a proxy site or software.  This is relatively easy most of the time because the transmission still goes in &lt;a href="http://en.wikipedia.org/wiki/Cleartext"&gt;cleartext&lt;/a&gt; and so the monitor picks up on the site categories. And if you use an encrypted proxy, we can usually still see that because we have access to all of the proxy lists that are available, just like everyone else does.  We can still tell that people are circumventing our security tools.&lt;br /&gt;&lt;br /&gt;Our policies and the regulations we follow require that these violations to be documented and reported.  In many cases, this leads to disciplinary action against en employee.  Several people here have been fired for violating our security measures.  This does not just include the use of proxy servers, but extends to unauthorized use of &lt;a href="http://en.wikipedia.org/wiki/USB_flash_drive"&gt;USB drives&lt;/a&gt;, installing unlicensed and unapproved software, bringing in a laptop to use peer-to-peer software, etc.  Just because you are able to do something doesn't mean you are authorized to do it.  And just because you get away with it the first time with no repercussions doesn't mean that we don't care or don't know.&lt;br /&gt;&lt;br /&gt;Now that I have established that point, let me address the first point that I made:  the policies and procedures we institute are not arbitrary!  Aside from the regulatory requirements I listed above, we have good reasons for putting in place the restrictions that we do.  These policies are designed to reduce support costs, protect the computers and network from viruses and malware, decrease the likelihood of an unintended information disclosure, and reduce bandwidth costs.&lt;span class="on" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;br /&gt;So here's "(At Least) Ten Things The WSJ Got Wrong."&lt;br /&gt;1.  &lt;span style="font-weight: bold;"&gt;We don't want you sending big files through email because it is expensive&lt;/span&gt;.  Do you know how much it costs to buy more disk space for your email server?  About $4 per GB (2x 300GB Ultra SCSI 320).  If you have a legitimate business purpose for sending a large file, call us up.  We'd love to help you and make sure that the file gets sent the right way.  Especially if it is a case where the release of the information must be regulated.  Just don't ask us to help you forward the latest movie trailer or funny video clip you downloaded.&lt;br /&gt;&lt;br /&gt;2. &lt;span style="font-weight: bold;"&gt;We don't want you to use unauthorized software because it drives support costs up and could get us into a lot of trouble&lt;/span&gt;.  No, we won't let you use Limewire to download the hottest software, songs, and movies.  If the &lt;a href="http://www.bsa.org/"&gt;BSA&lt;/a&gt;, &lt;a href="http://consumerist.com/consumer/riaa/"&gt;RIAA&lt;/a&gt;, or &lt;a href="http://www.mpaa.org/"&gt;MPAA&lt;/a&gt; catch you, we are the ones who get sued -- that's a huge liability!  Not to mention the performance hit on the network and the bandwidth costs.&lt;br /&gt;&lt;br /&gt;If something you use or install causes conflicts with one of our applications or changes some obscure settings, are you going to pay to get the computer back up and running properly?  Nope, we eat that cost too.  We have a limited set of software that we approve because this is what we support and it is what our software vendors support.  If &lt;a href="http://www.microsoft.com/windows/products/winfamily/ie/default.mspx"&gt;IE7&lt;/a&gt; or &lt;a href="http://www.mozilla.com/en-US/firefox/"&gt;Firefox&lt;/a&gt; won't work with the web application somebody else built, we don't have the resources to fix it.&lt;br /&gt;&lt;br /&gt;3. &lt;span style="font-weight: bold;"&gt;We block certain websites because they could create a hostile workplace, are associated with virues or spyware, or suck up all our bandwidth&lt;/span&gt;.  If someone visits an adult website and another employee or customer sees it, we can be sued.  Do you really need to do that at work anyway?&lt;br /&gt;&lt;br /&gt;Quite a few of the websites that we block host viruses or spyware or act as relay points for &lt;a href="http://en.wikipedia.org/wiki/Keystroke_logging"&gt;keystroke loggers&lt;/a&gt;.  Anti-Virus won't catch everything -- it has to update multiple times per day just to stay abreast of the latest threats, some of which can shut down the protective software altogether.&lt;br /&gt;&lt;br /&gt;Streaming video and audio sites can consume huge amounts of bandwidth.  Even though they are streamlined for distribution, they can still be hogs if several people are using them at once.  For simplicity's sake, let's assume that streaming audio will eat up 64kbps and streaming video uses 128kbps.  Some use more, very few use less.  And let's assume that your company has a 10mbps connection to the Internet.  Some simple math says that 150 listeners or 75 viewers will totally saturate the connection.  But this doesn't count those people visiting websites, any applications which require Internet connectivity, email, etc.  Not only that, but the streaming media protocols typically try and gulp up as much bandwidth as they can at once, which may generate 5-10x as much traffic at any one time.  In practice, if about 20 people on this Internet connection are using YouTube or listening to a radio station, you will notice a big slowdown when visiting websites.&lt;br /&gt;&lt;br /&gt;4. &lt;span style="font-weight: bold;"&gt;Most of the time, clearing out your Internet Browser files doesn't help anyone&lt;/span&gt;.  If you get a virus or any other nasty malicious software on your computer, clearing out your browser files makes it harder for us to track down and prevent next time.  And most of the time, it won't even cover your tracks if you've been someplace you shouldn't have been.  There's a reason we've got forensic tools at our disposal.  We can usually get that information off your hard drive, and even if we can't your activity is still being logged by our network forensic tools.  If you don't want your employer to know what sites you visit, don't go there on his dime.&lt;br /&gt;&lt;br /&gt;5. &lt;span style="font-weight: bold;"&gt;Don't cause a data leak by taking your documents home without checking with us first&lt;/span&gt;.  Call your IT department and see how they want you to work at home.  Odds are, we have a way to do this or can come up with something to allow it.  If we can't, talk to your boss about it and make sure they know you'll be working on your own time to increase your productivity.  Doing one of these two things will help to make sure you can get your work done and that we can keep the data protected.  Email, portable storage, online file sharing, and other methods are NOT designed to keep confidential information safe, they're designed to spread this information as easily as possible!  You'll do yourself and your organization a favor if you play by the rules on this one.&lt;br /&gt;&lt;br /&gt;6. &lt;span style="font-weight: bold;"&gt;If you store your work documents online, a hundred bad things can happen to them&lt;/span&gt;.  In addition to the reasons I mentioned in #5, there are other things that can go wrong with online storage.  If you're storing your important files with a free online storage site for a backup or as your only copy, don't.  Encrypted data needs a key to unlock it -- are you going to make sure it's safely and securely stored?  These things get lost or stolen all the time and then the data is gone or is available to anyone.  And online companies don't have the best track record for keeping your data available.  Google, who tries to permanently store all online data, has lost accounts, messages, and files many times from Blogger and Gmail.  Your organization backs up the data stored with them (or should) and those backups are ensured against loss or theft.  This is the right way to go about it.&lt;br /&gt;&lt;br /&gt;7. &lt;span style="font-weight: bold;"&gt;Web mail and instant messenger conversations should never be used to send private or confidential data&lt;/span&gt;.  Only a few web mail providers, such as &lt;a href="http://www.hushmail.com/"&gt;Hushmail&lt;/a&gt;, provide SSL encrypted communication by default.  This means that anything you view in your web mail can be viewed by our monitoring tools.  Yup, from that email confirmation when you applied to our competitor to the naughty photos your girlfriend sent you, we can see it.  And web mail doesn't have a great record for privacy anyway; Hotmail and Gmail have had several flaws that have allowed attackers to gain access to hundreds or thousands of mailboxes at a time.  Not great if you've got any emails with your Social Security Number, bank account number, credit card online account password, etc.&lt;br /&gt;&lt;br /&gt;Instant messaging isn't much better.  Though you can add encryption to your conversations, the software tends to fail silently, not alerting you to the fact that the messages you're sending are unencrypted.  Also, the person on the other side has to have set up their client to encrypt the messages too.  If you're going to chat with your buddies, do it outside of work for your own benefit.&lt;br /&gt;&lt;br /&gt;8. &lt;span style="font-weight: bold;"&gt;Forwarding your company email to your personal account is a bad idea&lt;/span&gt;.  If an email is sent from one email box to another on the same system, the message stays as safe as your email system.  However if you forward that outside your organization's security perimeter, it can be very bad news.  To begin with, you're probably going to be sending the message unencrypted to your personal mail server.  From there, when you check your mail it will probably be unencrypted.  Then if that mail is forwarded to your cell phone or PDA it is probaly left unencrypted on the mobile data network.  This is just a bad idea all the way around.  If getting your email outside of work will help you do work, odds are your IT department and/or your boss will help to accommodate you to increase your productivity.  Just ask.&lt;br /&gt;&lt;br /&gt;9. &lt;span style="font-weight: bold;"&gt;Checking personal mail on your company PDA or Blackberry isn't all that bad, just don't expect the IT staff to help you do it&lt;/span&gt;.  The only places where this would be a bad idea from a security standpoint is in highly secure environments where secret or top secret information is being passed around.  But that doesn't just include the military, it also applies to anyone who has access to information that might be highly desirable to others.  There are not many viruses out there that target mobile platforms and those that do don't spread by email.  However, it is conceivable that a specifically created multi platform virus could work its way into your network this way.&lt;br /&gt;&lt;br /&gt;But you'll want to think about things carefully before you do this.  Many organizations have a Blackberry Enterprise Server that controls the flow of data to and from the handheld device.  So it might be that your mail is going through your company's network to get to you.  If that bothers you, don't set it up this way.&lt;br /&gt;&lt;br /&gt;10. &lt;span style="font-weight: bold;"&gt;We don't care about your productivity unless you work for the IT department&lt;/span&gt;.  Your productivity is your boss's problem.  We may help him or her to trace your online activity, but we don't really care.  But keep in mind that we can still see what you're doing on the Internet, and part of somebody's job might be to generate reports for managers so that they can see what you are doing.&lt;br /&gt;&lt;br /&gt;11.  &lt;span style="font-weight: bold;"&gt;The IT Department should be your friend, not your enemy&lt;/span&gt;!  Information Technology is a business enabling tool for your organization.  We're here to make the business more profitable and to help you do your job.  Sometimes it doesn't come across that way, but I can guarantee that this is the way your CEO sees it.  If you can make a good case that something would increase your productivity and improve the business appreciably, odds are you can get it implemented.&lt;br /&gt;&lt;br /&gt;Just because you don't know a way to do something doesn't mean we don't have a good way to do it.  One of the things that strikes me most about these points is that many IT shops already have approved methods to do them.  If you have a legitimate business use for doing something, odds are we've got you covered.  Whether it's getting to your documents at home, checking email from the road, or surfing the 'net in your free time, ask us!  If we can reduce the amount of work we have to and help you out at the same time, it'd be silly not to.&lt;br /&gt;&lt;br /&gt;Remember, your IT staff is comprised of people who have the same desires and face the same problems.  We have motivations to do things, and figuring those out can help you get what you want.  Pitch the same thing two different ways and you can get two different responses.  If you are able to let us know how it benefits us, you're much more likely to get your way.  Together we can figure out a system that can make it possible.  Treat us like a friend and you might be surprised what we'll help you with.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;update:&lt;/span&gt; There are lots of other good responses to this article out in the Blogosphere, some of which I have listed below.  Security violations are up today, as is the paperwork I've now got to do to report them.  But this can be a good thing for those of us who are out there protecting our networks.  We can help educate the people who have the power to change these things as well as the people who want to get around the security measures.  We have to work a little harder on the front end, but it pays off in the long run.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://andyitguy.blogspot.com/2007/08/on-open-letter-to-wsj.html"&gt;Andy, IT Guy&lt;/a&gt;&lt;br /&gt;&lt;a href="http://securityincite.com/TDI-2007-08-02#TBP1"&gt;The Daily Incite&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.terminal23.net/2007/08/the_good_and_bad_of_the_wsj_ar.html"&gt;terminal23&lt;/a&gt;&lt;br /&gt;&lt;a href="http://riskmanagementinsight.com/riskanalysis/?p=250"&gt;RiskAnalys.is&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.realtime-itcompliance.com/information_security/2007/07/insider_threat_and_cowboys_the.htm"&gt;Realtime Community&lt;/a&gt;&lt;br /&gt;&lt;a href="http://layer8.itsecuritygeek.com/index/layer8/defending-policy-makers/"&gt;Layer 8&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.bloginfosec.com/2007/08/06/some-insight-incite-on-the-wsj-it-security-controls-article/"&gt;bloginfosec.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.infoworld.com/article/07/08/02/31OPentinsight_1.html?source=rss&amp;amp;url=http://www.infoworld.com/article/07/08/02/31OPentinsight_1.html"&gt;InfoWorld&lt;/a&gt;&lt;br /&gt;&lt;a href="http://robnewby.blogspot.com/2007/08/courting-wsj.html"&gt;IT Security, the view from here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-4663037219082443928?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SN-0IGShkvw:6D2PAy_pIms:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SN-0IGShkvw:6D2PAy_pIms:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SN-0IGShkvw:6D2PAy_pIms:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SN-0IGShkvw:6D2PAy_pIms:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=SN-0IGShkvw:6D2PAy_pIms:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SN-0IGShkvw:6D2PAy_pIms:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=SN-0IGShkvw:6D2PAy_pIms:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SN-0IGShkvw:6D2PAy_pIms:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/SN-0IGShkvw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/4663037219082443928/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=4663037219082443928" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/4663037219082443928?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/4663037219082443928?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/SN-0IGShkvw/at-least-ten-things-wsj-got-wrong.html" title="(At Least) Ten Things The WSJ Got Wrong" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">6</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/at-least-ten-things-wsj-got-wrong.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMBQH8_cSp7ImA9WB5WGEw.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-5907752343003951419</id><published>2007-07-30T14:00:00.000-04:00</published><updated>2007-07-30T14:00:51.149-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-30T14:00:51.149-04:00</app:edited><title>A New Job</title><content type="html">As of August 10th, I will no longer be in my old position, and on August 13th, I will begin at a new job with a different company.  This job will give me a better chance to work with people in my industry, as well as afford me the chance to travel more.  While it was a hard decision, it was ultimately the right choice for me.  I loved working with the folks I have and working for my boss, but it is time to move on.  Hopefully both this and my &lt;a href="http://www.meanderingwoods.com/"&gt;travel blog&lt;/a&gt; will become more active as I have more relevant experiences to share.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-5907752343003951419?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=EvN20NdIWPE:1Pzmf87Ynq4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=EvN20NdIWPE:1Pzmf87Ynq4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=EvN20NdIWPE:1Pzmf87Ynq4:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=EvN20NdIWPE:1Pzmf87Ynq4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=EvN20NdIWPE:1Pzmf87Ynq4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=EvN20NdIWPE:1Pzmf87Ynq4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=EvN20NdIWPE:1Pzmf87Ynq4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=EvN20NdIWPE:1Pzmf87Ynq4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/EvN20NdIWPE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/5907752343003951419/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=5907752343003951419" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/5907752343003951419?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/5907752343003951419?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/EvN20NdIWPE/new-job.html" title="A New Job" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/new-job.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkcNQX86fCp7ImA9WB5WGE0.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-7552722395700101720</id><published>2007-07-30T09:44:00.000-04:00</published><updated>2007-07-30T10:01:30.114-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-30T10:01:30.114-04:00</app:edited><title>Schneier on the TSA</title><content type="html">Bruce Schneier has been quite vocally critical of the Transportation Safety Administration in the past about what he calls "security theater."  Well it appears that somebody over there was listening and wanted to address it.  That somebody was the &lt;a href="http://www.tsa.gov/who_we_are/people/bios/kip_hawley_bio.shtm"&gt;head of the administration&lt;/a&gt;.  He invited Bruce to have a conversation with him and publish it on the blog in order to increase the transparency of the department.  The &lt;a href="http://www.schneier.com/blog/archives/2007/07/conversation_wi_4.html"&gt;first post&lt;/a&gt; in this series shows that even the TSA has a sense of humor about itself and makes a fairly persuasive argument that they actually &lt;span style="font-weight: bold;"&gt;are&lt;/span&gt; trying to keep us safe, not just piss everybody off. &lt;br /&gt;&lt;br /&gt;I'm really looking forward to seeing the rest of the conversation and hope that it helps to make the public more aware of the incredibly difficult job that these guys are trying to do.  To actually be effective as a government agency requires a ton of work and dedication.  But I think the TSA has begun to turn a corner and is headed in the right direction.  After seeing &lt;a href="http://consumerist.com/consumer/he-said%2C-she-said/tsa-uploads-video-of-sippy-cup-incident-on-special-mythbusting-website-269533.php"&gt;their response&lt;/a&gt; to the &lt;a href="http://www.nowpublic.com/nightmare_at_reagan_national_airport_a_security_story_to_end_all_security_stories"&gt;"sippy cup"&lt;/a&gt; story, I realized that somebody over there was paying attention.  They've got a &lt;a href="http://www.tsa.gov/approach/mythbusters/index.shtm"&gt;website up now&lt;/a&gt; to set the record straight, or at least tell their side of the story and defend themselves.  They've also been vocal about having security that actually, you know, &lt;a href="http://www.usatoday.com/news/washington/2006-06-28-lighter-ban_x.htm?csp=1"&gt;makes us safer&lt;/a&gt; rather than just looks good.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-7552722395700101720?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=3DvXbzpeYdY:fqTNY4U7YtM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=3DvXbzpeYdY:fqTNY4U7YtM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=3DvXbzpeYdY:fqTNY4U7YtM:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=3DvXbzpeYdY:fqTNY4U7YtM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=3DvXbzpeYdY:fqTNY4U7YtM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=3DvXbzpeYdY:fqTNY4U7YtM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=3DvXbzpeYdY:fqTNY4U7YtM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=3DvXbzpeYdY:fqTNY4U7YtM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/3DvXbzpeYdY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/7552722395700101720/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=7552722395700101720" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7552722395700101720?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7552722395700101720?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/3DvXbzpeYdY/schneier-on-tsa.html" title="Schneier on the TSA" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/schneier-on-tsa.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4FQHkzfyp7ImA9WB5WE0o.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-253383455332303003</id><published>2007-07-25T10:13:00.000-04:00</published><updated>2007-07-25T10:15:11.787-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-25T10:15:11.787-04:00</app:edited><title>Reminder:  CitySec Tonight!</title><content type="html">&lt;strong&gt;&lt;span class="caps"&gt;REMINDER&lt;/span&gt;:&lt;/strong&gt;  &lt;a href="http://citysec.org/forums/1/topics/20?page=2#posts-287"&gt;CitySec Atlanta&lt;/a&gt; tonight!  Show up at &lt;a href="http://brickstorepub.com/"&gt;The Brick Store Pub&lt;/a&gt; at 6pm for some HotHillBillySec.  Does that sound dirty to anybody else or do I just have a dirty mind?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-253383455332303003?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=xffe2Ugmj9o:Zt2w1TP7-IU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=xffe2Ugmj9o:Zt2w1TP7-IU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=xffe2Ugmj9o:Zt2w1TP7-IU:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=xffe2Ugmj9o:Zt2w1TP7-IU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=xffe2Ugmj9o:Zt2w1TP7-IU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=xffe2Ugmj9o:Zt2w1TP7-IU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=xffe2Ugmj9o:Zt2w1TP7-IU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=xffe2Ugmj9o:Zt2w1TP7-IU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/xffe2Ugmj9o" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/253383455332303003/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=253383455332303003" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/253383455332303003?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/253383455332303003?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/xffe2Ugmj9o/reminder-citysec-tonight.html" title="Reminder:  CitySec Tonight!" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/reminder-citysec-tonight.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8HRHY6fyp7ImA9WB5XGEs.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-258027345173464620</id><published>2007-07-19T12:55:00.001-04:00</published><updated>2007-07-19T13:07:15.817-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-19T13:07:15.817-04:00</app:edited><title>Google Declares Sister Website "great website"</title><content type="html">It's official!  My &lt;a href="http://meanderingwoods.blogspot.com/"&gt;travel blog&lt;/a&gt; has been given the extraordinary epithet &lt;a href="http://www.google.com/search?q=%22great+website%22"&gt;"great website"&lt;/a&gt; by the all-knowing Google.  Actually, it wasn't Google, but a search user.&lt;br /&gt;&lt;br /&gt;I was digging through my Analytics report this morning and saw this gem:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_lDv8tYQkm2Q/Rp-YfYK9MpI/AAAAAAAAABE/_fYoxAG6_Pc/s1600-h/Picture+2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_lDv8tYQkm2Q/Rp-YfYK9MpI/AAAAAAAAABE/_fYoxAG6_Pc/s320/Picture+2.png" alt="" id="BLOGGER_PHOTO_ID_5088953768783721106" border="0" /&gt;&lt;/a&gt;This says that someone found my website by searching for the term "great website".  Two someone, actually.  While that is a great compliment, a little looking revealed that it was because I linked to National Geographic's Picture of the Day site and called it great.&lt;br /&gt;&lt;br /&gt;I searched the first 20 pages of Google results for my website but couldn't find it.  I figured that the people who found the site by that link must have looked awful hard for it.  But then I realized that their results were likely different from mine the way the search giant's algorithms work.  From what I've read, they calculate probabilities of what you're actually looking for using your unique site visits to guide them.  All of this is really just a fancy way of saying "Google tracks you."&lt;br /&gt;&lt;br /&gt;There's probably a good post to be made about how Google's privacy policies leave you vulnerable to all kinds of information disclosure vulnerabilities.  Or about how these meta search words can be skewed in subtle ways to target less sophistocated users with malware.  But I don't have the time right now to work those up, so use those analytical skills &lt;a href="http://beauwoods.blogspot.com/2006/09/my-first-post-tip-0-this-is-my-first.html"&gt;I've been urging you to develop&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-258027345173464620?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=cVNFXM6wyrY:wbyItBcW_d8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=cVNFXM6wyrY:wbyItBcW_d8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=cVNFXM6wyrY:wbyItBcW_d8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=cVNFXM6wyrY:wbyItBcW_d8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=cVNFXM6wyrY:wbyItBcW_d8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=cVNFXM6wyrY:wbyItBcW_d8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=cVNFXM6wyrY:wbyItBcW_d8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=cVNFXM6wyrY:wbyItBcW_d8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/cVNFXM6wyrY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/258027345173464620/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=258027345173464620" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/258027345173464620?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/258027345173464620?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/cVNFXM6wyrY/google-declares-sister-website-great.html" title="Google Declares Sister Website &quot;great website&quot;" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp3.blogger.com/_lDv8tYQkm2Q/Rp-YfYK9MpI/AAAAAAAAABE/_fYoxAG6_Pc/s72-c/Picture+2.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/google-declares-sister-website-great.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIDQHs-eip7ImA9WB5XEEo.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-7566397237127845683</id><published>2007-07-10T08:15:00.000-04:00</published><updated>2007-07-10T09:36:11.552-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-10T09:36:11.552-04:00</app:edited><title>It's Not In The Blinky Things</title><content type="html">I read a really good passage today from a book called "&lt;a href="http://www.amazon.com/Zen-24-All-Time/dp/0060778784"&gt;Zen 24/7&lt;/a&gt;" by &lt;a href="http://www.amazon.com/s/ref=nb_ss_gw/105-5795755-0590811?initialSearch=1&amp;url=search-alias%3Daps&amp;amp;field-keywords=Philip+Toshio+Sudo&amp;Go.x=0&amp;amp;Go.y=0&amp;Go=Go"&gt;Philip Toshio Sudo&lt;/a&gt;.  It was talking about how Zen views security.  In this philosophy, security is viewed as a part of self-reliance and individual responsibility.  You are responsible for your own security because you, and only you, are responsible for you.  In this Zen passage, Sudo says "Lose your money, you still have the means to live.  Lose your identification, you still have your identity " &lt;br /&gt;&lt;br /&gt;The line about money may or may not apply to people in our world, but it will always be relevant to those who live by the simple ways the book advocates.  If you lose all of your money, you still have yourself, and you can make the money again.  If you are stripped of all your possessions, you are left naked to the bare substance of who you are.  If you know yourself as who you are, as opposed to what you own, this is not a crippling turn of events.&lt;br /&gt;&lt;br /&gt;The line about identification is a little more difficult and requires some clarification.  Sudo is not talking about identity the way security professionals and the media does, in the vein of identity theft.  Instead, he and the Zen philosophies think of identity of who you know yourself to be.  From this point of view, the word "identification" in the sentence can be thought of as "identity" the way the western world thinks of it.  In other words, "Lose your identity, you still have who you are."&lt;br /&gt;&lt;br /&gt;Zen is filled with this way of looking at the world:  "You are the only one who lives your life and who is wholly in charge of how it comes out, and you can not live for anyone else."  "No matter what happens to you, it is all just another step in the path along the journey that is your life."  These are two very different ways of thinking to the way we typically look at life.  Sometimes we are more connected to other peoples' lives than to our own -- even going so far as to try to tell others how to live them or to let them tell us how to live.  But in the end, no one but us lives through the ramifications of our decisions and behaviors.  And we cannot live through those that others make.&lt;br /&gt;&lt;br /&gt;We tend to think of security as someone else's responsibility, and that is how most voices on the Internet talk about it.  It is Amazon's responsibility, or Visa, or the government.  But it's not their responsibility to take care of us, it's ours.  We can change our behavior so that we only use &lt;a href="http://www.stretcher.com/stories/01/010212e.cfm"&gt;disposable credit card numbers&lt;/a&gt; online or just &lt;a href="http://en.wikipedia.org/wiki/Bricks_and_mortar_business"&gt;pay cash to an actual person&lt;/a&gt;.  We can &lt;a href="http://www.schneier.com/blog/archives/2006/11/tsa_security_ro_1.html"&gt;drive instead of fly&lt;/a&gt;, or &lt;a href="http://nhindymedia.org/newswire/display/2973/index.php"&gt;walk rather than drive&lt;/a&gt;.  Security always comes at its own price, whether that is &lt;a href="http://news-service.stanford.edu/news/2005/november2/security-110205.html"&gt;money&lt;/a&gt;, &lt;a href="http://joejennydc.blogspot.com/2007/02/inconvenient-security-that-wasnt.html"&gt;convenience&lt;/a&gt;, or &lt;a href="http://www.commondreams.org/views07/0211-22.htm"&gt;privacy&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So keep these things in mind when you are thinking about security.  Not all ways are right for all people.  You have to decide what is right for you because you have to do it and live with the results.  As Sudo tells us, "The security lies not in the money, the credit card, or the license.  It lies in you."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-7566397237127845683?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=UkRUMYDzZM0:jG4Zki5kzfI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=UkRUMYDzZM0:jG4Zki5kzfI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=UkRUMYDzZM0:jG4Zki5kzfI:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=UkRUMYDzZM0:jG4Zki5kzfI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=UkRUMYDzZM0:jG4Zki5kzfI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=UkRUMYDzZM0:jG4Zki5kzfI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=UkRUMYDzZM0:jG4Zki5kzfI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=UkRUMYDzZM0:jG4Zki5kzfI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/UkRUMYDzZM0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/7566397237127845683/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=7566397237127845683" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7566397237127845683?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7566397237127845683?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/UkRUMYDzZM0/its-not-in-blinky-things.html" title="It's Not In The Blinky Things" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/its-not-in-blinky-things.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUcGQH4yfSp7ImA9WB5XEE0.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-7003474965776895570</id><published>2007-07-09T13:43:00.001-04:00</published><updated>2007-07-09T13:43:41.095-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-09T13:43:41.095-04:00</app:edited><title>Atlanta CitySec</title><content type="html">This is to announce the first Atlanta meeting of a group called CitySec.  The group is a loose affiliation of people in the Information Security field who facilitate grass-roots meetings of others in the industry.  The meetings are very informal and usually take place in a bar or some similar laid-back setting.  Here is more information about the meetings in general:&lt;br /&gt;http://citysec.org/forums/1/topics/9&lt;br /&gt;&lt;br /&gt;And the thread for the Atlanta meeting, specifically:&lt;br /&gt;http://citysec.org/forums/1/topics/20&lt;br /&gt;&lt;br /&gt;The meeting will be held on Wednesday, July 25th, at 6pm at The Brick Store Pub in Downtown Decatur.  Their website is http://www.brickstorepub.com if you need directions or more information.  We hope to see you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-7003474965776895570?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SUXe4V54SGI:0S5W9e7Dhtk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SUXe4V54SGI:0S5W9e7Dhtk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SUXe4V54SGI:0S5W9e7Dhtk:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SUXe4V54SGI:0S5W9e7Dhtk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=SUXe4V54SGI:0S5W9e7Dhtk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SUXe4V54SGI:0S5W9e7Dhtk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=SUXe4V54SGI:0S5W9e7Dhtk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=SUXe4V54SGI:0S5W9e7Dhtk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/SUXe4V54SGI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/7003474965776895570/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=7003474965776895570" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7003474965776895570?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7003474965776895570?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/SUXe4V54SGI/atlanta-citysec.html" title="Atlanta CitySec" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/atlanta-citysec.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMNQHc7eCp7ImA9WB5QF0k.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-3184276223343464521</id><published>2007-07-06T09:50:00.000-04:00</published><updated>2007-07-06T12:48:11.900-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-06T12:48:11.900-04:00</app:edited><title>Online Storage Safe Isn't Safe</title><content type="html">Online storage has been around for a while.  It's the idea that you can put your digital stuff online and access it anywhere.  It's a great way to transfer files or to keep a backup of things you don't want to lose.  In addition to the sites which &lt;a href="http://www.idrive.com/"&gt;will&lt;/a&gt; &lt;a href="http://www.xdrive.com/"&gt;store&lt;/a&gt; &lt;a href="http://www.streamload.com/"&gt;any&lt;/a&gt; &lt;a href="http://mozy.com/"&gt;filetype&lt;/a&gt;, dedicated sites exist to store &lt;a href="http://reviews.cnet.com/4520-6451_7-6245115-1.html"&gt;photo&lt;/a&gt;, &lt;a href="http://www.lightreading.com/videoshare"&gt;video&lt;/a&gt;, &lt;a href="http://mp3tunes.com/"&gt;music&lt;/a&gt;, and &lt;a href="http://docs.google.com/"&gt;text documents&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;We've gotten so used to things being online that some people have put almost all their documents online.  I have plenty of pictures and videos stored there and am increasing the percentage of these things that I store there.  These services are making it easier and easier to store things online.  Youtube even has a feature called &lt;a href="http://youtube.com/results?search_query=quick+capture"&gt;Quick Capture&lt;/a&gt; that takes video directly from a webcam to the online service without storing it anywhere on your computer first. &lt;a href="http://www.eye.fi/"&gt;Eye-Fi&lt;/a&gt; is a product that can send photos direct from your camera to many photo sites.&lt;br /&gt;&lt;br /&gt;However, this can become a problem if people keep their ONLY copies of documents and media online.  This morning, Flickr was inaccessable for me -- I'm not sure if the site was down or if it was a localized issue (&lt;span style="font-weight: bold;"&gt;update:&lt;/span&gt; &lt;a href="http://www.yahoo.com/"&gt;Yahoo! &lt;/a&gt;was &lt;a href="http://isc.sans.org/diary.html?storyid=3100"&gt;down for a while&lt;/a&gt;). I was just trying to put up my latest &lt;a href="http://beausphotos.blogspot.com"&gt;photoblog entry&lt;/a&gt;, so it was not a big deal. But imagine if I'd been scheduled to make a presentation and stored my only copy on a site that was down.  I've seen similar things happen to presenters, it's not pretty.&lt;br /&gt;&lt;br /&gt;I'm able to get to Flickr now, and the presenters were eventually able to work through their technical glitches.  But what if the storage site lost all that data?  Most of them have clauses in the agreement you have to click through that indemnifies them in case of a loss of this kind.  Losing data is more common on the Internet than many people realize, especially with beta services.  Big companies are no less susceptible to this than the small startups.&lt;br /&gt;&lt;br /&gt;There are also privacy issues with these services.  If you post your company's financial reports to Google Docs, your CFO will probably be pretty upset with you.  If you accidentally upload very personal photos to one of the photo sharing sites, it may stay there forever.  If a prospective employer does a Google search and comes across a video of you in a manner not befitting their standards, they can refuse to hire you.  These things are not far fetched, similar things have all happened.&lt;br /&gt;&lt;br /&gt;Online media and file storage services are great for convenience and sharing.  But you should keep in mind that they are just as susceptible to failure as anything else.  And they are just as, in not more, accessible than public records.  That goes for any information you might post on the Internet.  So keep that in mind when you post the video of yourself drinking tequila with Paris Hilton and link it from your &lt;a href="http://www.myspace.com/"&gt;MySpace&lt;/a&gt; page.  And make sure you've got a backup of anything important you keep online.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-3184276223343464521?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_8RpwWfiIG0:94H-ZqPcepY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_8RpwWfiIG0:94H-ZqPcepY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_8RpwWfiIG0:94H-ZqPcepY:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_8RpwWfiIG0:94H-ZqPcepY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=_8RpwWfiIG0:94H-ZqPcepY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_8RpwWfiIG0:94H-ZqPcepY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=_8RpwWfiIG0:94H-ZqPcepY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=_8RpwWfiIG0:94H-ZqPcepY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/_8RpwWfiIG0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/3184276223343464521/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=3184276223343464521" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3184276223343464521?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3184276223343464521?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/_8RpwWfiIG0/online-storage-safe-isnt-safe.html" title="Online Storage Safe Isn't Safe" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/07/online-storage-safe-isnt-safe.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUAQn4ycCp7ImA9WB5QE00.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-7231262067523830634</id><published>2007-06-29T14:07:00.000-04:00</published><updated>2007-07-01T11:37:23.098-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-01T11:37:23.098-04:00</app:edited><title>Security Font</title><content type="html">I have just designed the most secure font ever.  At least it is to my knowledge.  You can get it &lt;a href="http://www.wikiupload.com/download_page.php?id=169044"&gt;here&lt;/a&gt;.  Below is a screenshot of the font in action.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;update:&lt;/span&gt; The screenshot was not showing up because either Firefox or Blogger decided that dragging and dropping a file into the blogger interface should try to link to the file on my computer rather than putting it on some photo upload site.  So now the pic is up there.  Sorry for the trouble and thanks to Anonymous for pointing it out.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img184.imageshack.us/img184/3528/picture1ls5.png" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-7231262067523830634?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zTU4rWkc_UY:kZEYjo8cKpc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zTU4rWkc_UY:kZEYjo8cKpc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zTU4rWkc_UY:kZEYjo8cKpc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zTU4rWkc_UY:kZEYjo8cKpc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=zTU4rWkc_UY:kZEYjo8cKpc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zTU4rWkc_UY:kZEYjo8cKpc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=zTU4rWkc_UY:kZEYjo8cKpc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=zTU4rWkc_UY:kZEYjo8cKpc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/zTU4rWkc_UY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/7231262067523830634/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=7231262067523830634" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7231262067523830634?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/7231262067523830634?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/zTU4rWkc_UY/security-font.html" title="Security Font" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">6</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/06/security-font.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIHRXY_cCp7ImA9WB5QFUg.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-5406072115006681264</id><published>2007-06-21T18:30:00.000-04:00</published><updated>2007-07-04T08:52:14.848-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-07-04T08:52:14.848-04:00</app:edited><title>If It's Not Verified, It's Not Secure</title><content type="html">Today at the data center, I was scheduled to upgrade one of our systems.  I was pretty well prepared and was just going through some final checks as I waited for the download of the new software to complete.  I had already shut down the services and made a final backup, so I decided to try the restore feature to make sure it would work later after the upgrade was complete.  It didn't work, and neither did the other 3 sets of backups I tried!&lt;br /&gt;&lt;br /&gt;As mistakes go, having not tested this backup would have been a huge one!  All of the data that was on the server would have been completely lost.  This represents not just the time to recreate some of the documents and settings, but would have involved several different groups and would have left the server down for at least 3-4 days!&lt;br /&gt;&lt;br /&gt;A call to the manufacturer's tech support line was helpful and it turned out that there was a hidden failure in the backups that can only be discovered on doing a test like I did.  This wasn't in their documentation for the backup feature, nor was it in their documentation for the upgrade procedure.  If I hadn't been diligent enough to test out the restore procedure, I would have had a major problem on my hands.  The fact that my boss just left for vacation and the vendor was about to close for the weekend would have made the problem worse.&lt;br /&gt;&lt;br /&gt;I trusted that the backup would work, but it didn't.  The reason why is a bit too obscure for this blog, but it is something I never could have imagined.  In fact, the engineers for the vendor seemed perplexed by it, too.  With all of the pieces still intact, it is easy to figure out why the system failed.  But if I had already installed the upgrade, there would be only guesses as to why the failure had happened.   This is why you should always test your backups to make sure they will do what you think they will.&lt;br /&gt;&lt;br /&gt;And you should check other systems that you use, too.  In the computer security world, &lt;a href="http://en.wikipedia.org/wiki/Penetration_Testing"&gt;penetration testers&lt;/a&gt; help check out our security.  Shows like "&lt;a href="http://dsc.discovery.com/fansites/ittakesathief/bios/bios.html"&gt;It Takes A Thief&lt;/a&gt;" do the same thing for peoples' home security.  In some cases, even the most well planned and implemented systems can be broken.  But most of the time there are holes in the design or execution that make the difference.&lt;br /&gt;&lt;br /&gt;Effective systems design the verification into them.  This is one of the strengths of the scientific process of &lt;a href="http://en.wikipedia.org/wiki/Peer_review"&gt;peer review&lt;/a&gt;.  It ensures that others can replicate results that one researcher finds.  Because fraud, mistakes, and interpretation can distort the facts, the scientific community needs to make sure that these things are minimized.  This ensures that our body of knowledge surges closer and closer to the truth of the world.&lt;br /&gt;&lt;br /&gt;This reminds me of a scene from "&lt;a href="http://www.imdb.com/title/tt0215129/"&gt;Road Trip&lt;/a&gt;" where the kids are talking about jumping over a broken bridge in a car.  They do a lot of calculating and thinking about it and decide that the distance really isn't that far and they can make it.  And then they just happen to test it out by putting just a little bit of weight on the other side of the bridge.  The bridge collapses.  That was the easy way to find out their plan would have fallen apart with the bridge.  Of course in the movie they went for it anyway, but at least they KNEW it wouldn't work.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;update:&lt;/span&gt;  It turns out that the backups were failing because they were being uploaded to a FTP server in the wrong mode.  The client didn't properly change to "binary" mode and instead was sending files as "ASCII".  Many servers automatically determine that the file is binary and transmit in the correct mode despite it being the client's responsibility.  However, ours doesn't.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-5406072115006681264?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=d_a3NaGo5EM:x5qNCIYE4Oo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=d_a3NaGo5EM:x5qNCIYE4Oo:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=d_a3NaGo5EM:x5qNCIYE4Oo:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=d_a3NaGo5EM:x5qNCIYE4Oo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=d_a3NaGo5EM:x5qNCIYE4Oo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=d_a3NaGo5EM:x5qNCIYE4Oo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=d_a3NaGo5EM:x5qNCIYE4Oo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=d_a3NaGo5EM:x5qNCIYE4Oo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/d_a3NaGo5EM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/5406072115006681264/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=5406072115006681264" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/5406072115006681264?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/5406072115006681264?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/d_a3NaGo5EM/if-its-not-verified-its-not-secure.html" title="If It's Not Verified, It's Not Secure" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/06/if-its-not-verified-its-not-secure.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04ERXs-cCp7ImA9WB5SFUo.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-8774741029706228098</id><published>2007-06-11T11:00:00.000-04:00</published><updated>2007-06-11T11:31:44.558-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-06-11T11:31:44.558-04:00</app:edited><title>Stop Swatting At Flies</title><content type="html">I saw a &lt;a href="http://blogs.ittoolbox.com/security/investigator/archives/inspiration-by-fly-16830"&gt;great post&lt;/a&gt; today over at the &lt;a href="http://www.ittoolbox.com/"&gt;IT Toolbox site&lt;/a&gt;.  It talks about stepping back and making sure you know the whole situation before you start acting.  It's well written and accessible to anyone.  If you don't understand the part about the proxy server and the help desk tickets, just skip it.  I can't say what he does any better, so I'll just let &lt;a href="http://www.ittoolbox.com/profiles/chiefmonkey"&gt;Chief, the Security Monkey&lt;/a&gt; do my talking for me.&lt;br /&gt;&lt;br /&gt;But since his &lt;a href="http://blogs.ittoolbox.com/security/investigator/archives/not-a-four-year-anniversary-post-16816"&gt;last post&lt;/a&gt; was about blogs not adding content, merely linking to sites with content, I guess I'll have to do some real work here.  The chief's blog is one of a handful which are informative, but not targeted at the latest research or trends.  Instead, these blogs usually focus on techniques instead of results.  I think everybody needs to have a few of these blogs in their regular reading list to make sure they remember the basics.  But maybe I'm biased, since that is what kind of a blog I run here.&lt;br /&gt;&lt;br /&gt;Knowing the processes that go into the results is the key to really understanding what the results say.  It is fine to read the conclusions that story authors come to, but unless you understand how they came to those conclusions and can form your own, you might as well just use a &lt;a href="http://www.imdb.com/title/tt0151804/quotes"&gt;Jump to Conclusions Mat&lt;/a&gt;. Understanding the basics and the underlying causes for things allows you to be skeptical and to see what people try to cover up, gloss over, or outright miss.  As the chief's post makes clear, when you know how and why something does what it does, it is much easier to know how to change it.  You can stop swatting at flies and get them out of your way for good.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-8774741029706228098?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=V9NTipLu7SY:mocBnLgLw0Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=V9NTipLu7SY:mocBnLgLw0Q:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=V9NTipLu7SY:mocBnLgLw0Q:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=V9NTipLu7SY:mocBnLgLw0Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=V9NTipLu7SY:mocBnLgLw0Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=V9NTipLu7SY:mocBnLgLw0Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=V9NTipLu7SY:mocBnLgLw0Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=V9NTipLu7SY:mocBnLgLw0Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/V9NTipLu7SY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/8774741029706228098/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=8774741029706228098" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/8774741029706228098?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/8774741029706228098?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/V9NTipLu7SY/swatting-flies.html" title="Stop Swatting At Flies" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/06/swatting-flies.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUGSH85eyp7ImA9WB5TF08.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-8297542817149428553</id><published>2007-05-24T16:48:00.001-04:00</published><updated>2007-06-01T15:30:29.123-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-06-01T15:30:29.123-04:00</app:edited><title>Finish The Job</title><content type="html">I'm a big fan of Tom Clancy type spy thriller novels.  I just read a book which reminds me of these, and which Clancy himself called "A spy story for the 90's -- and it's all true."  The book is called &lt;a href="http://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/0743411463"&gt;&lt;u&gt;The Cuckoo's Egg&lt;/u&gt;&lt;/a&gt; by Cliff Stoll.  I won't give away any spoilers here, but you can read the collective &lt;a href="http://en.wikipedia.org/wiki/The_Cuckoo%27s_Egg_%28book%29"&gt;summary&lt;/a&gt; if you want to know what happens.&lt;br /&gt;&lt;br /&gt;This is a classic story of what happens when you see something out of place and instead of just fixing the problem you really investigate.  You start digging and pretty soon you find that there are dozens of things that need to be reworked, and dozens more that need to be done and done right.  With no funding for a project, it can be damn near impossible to carve the time out of your paying job to do them, so most go undone.  In his book, Cliff doesn't let his main issues fall to the wayside, he sticks with them and sees that things get done as well as they can be.&lt;br /&gt;&lt;br /&gt;While the book is nearly 20 years old, the lessons it teaches are true today.  Cliff has to overcome sloppy practices, a determined and perseverant adversary, invasion of his personal life, lack of support from those he is trying to help, etc.  And in the end, he is essentially unrewarded for his efforts.  These are problems that security professionals -- and many others -- face every day.  But Cliff won't back down or give up, he is able to look at the problem as an opportunity to learn and explore.  His reward comes from the joy of discovery, from seeing the problem to its conclusion, and making connections with people in the same situation.&lt;br /&gt;&lt;br /&gt;It's easy to respect and admire someone like this, but it's not as easy to become them ourselves.  It is much easier to push things off to another day or let things drop by the wayside as we hurtle along through life.  But I think that one of the things that makes me happiest is when I pursue the things that Cliff did:  truth, discovery, and resolution.  It also tends to make the products of my work better because we care about what I am doing, not just trying to get it done so I can move on to something else.&lt;br /&gt;&lt;br /&gt;It's hard to be enthusiastic about every aspect of we all do for a living.  In fact, if we really enjoy doing something and decide to make money from it, we will soon find that we enjoy it less.  But what would it take to do every task like we enjoyed it?  Probably not that much more effort than we already put into it.  That could be changing the duty enough to make it more interesting, like turning it into a game.  Or it could mean trying to learn all you can from theories to history to other techniques.  Or it might just mean that you embrace the unembraceable and focus on being as good as you can.&lt;br /&gt;&lt;br /&gt;But you've got to find some way to persevere through the difficult jobs to get to the end.  In Information Security, it is absolutely essential to do things right and see them through to completion.  It is like that in many other fields and aspects of our lives.  If you give up or half-ass it at any point, it diminishes the results of your labor.  But working hard through every step gives a great feeling of accomplishment and self-esteem as well as makes for a better end result.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-8297542817149428553?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=QocYlySEADE:y2bQWwiUDa0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=QocYlySEADE:y2bQWwiUDa0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=QocYlySEADE:y2bQWwiUDa0:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=QocYlySEADE:y2bQWwiUDa0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=QocYlySEADE:y2bQWwiUDa0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=QocYlySEADE:y2bQWwiUDa0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=QocYlySEADE:y2bQWwiUDa0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=QocYlySEADE:y2bQWwiUDa0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/QocYlySEADE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/8297542817149428553/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=8297542817149428553" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/8297542817149428553?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/8297542817149428553?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/QocYlySEADE/finish-job.html" title="Finish The Job" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/05/finish-job.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUBR30zcSp7ImA9WB5TF08.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-857315130293031042</id><published>2007-05-22T13:31:00.000-04:00</published><updated>2007-06-01T15:30:56.389-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-06-01T15:30:56.389-04:00</app:edited><title>Simplify, Simplify, Simplify</title><content type="html">I am back from &lt;a href="http://meanderingwoods.blogspot.com/"&gt;my recent hiatus&lt;/a&gt; and have finally gotten caught up enough to write a couple of lines here.  While on trips, it always becomes obvious how much better a simple solution is when compared with a complicated one.  For example, when trying to backup images from a camera.  It was a hassle to try to get them onto the computer then to a jump drive or a &lt;a href="http://www.flickr.com/people/beauwoods"&gt;flickr.com account&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;A much easier solution would be to use a device to dump the pictures directly to an iPod.  The &lt;a href="http://store.apple.com/1-800-MY-APPLE/WebObjects/AppleStore.woa/wa/RSLID?mco=20538A8A&amp;amp;nplm=M9861G/B"&gt;Apple iPod Camera Connector&lt;/a&gt; is the descriptively named device made by Apple to do the job.  It works pretty well, too.  It will even move &lt;a href="http://en.wikipedia.org/wiki/RAW_image_format"&gt;RAW&lt;/a&gt; photos, though the iPod can't display them.  This helped out greatly since my friend had dozens of gigs worth of these large photos and no way to store them to make room for more.  While this certainly wasn't &lt;a href="http://www.engadget.com/2006/09/11/samsung-releases-32-and-64gb-compactflash-cards/"&gt;the simplest solution&lt;/a&gt;, it worked well and stayed within our budget.&lt;br /&gt;&lt;br /&gt;With simple solutions, it is easy to see their flaws and compensate.  The problems which can occur in a system increase exponentially with complexity.  In other words, the more things that are involved, the more likely something is to go wrong and the more difficult they will be to solve.  When giving directions to my house, I usually give them a route with very few turns.  Because the directions are simple, they can be more precise and are easier to follow.&lt;br /&gt;&lt;br /&gt;Also, the more difficult and complex something is to use, the less likely people are to use it.  To stay with the example above, I drive a very simple route home from work every day.  I could probably shave 5-10% off my trip time by taking alternate routes depending on conditions and using back streets rather than the main ones.  However, this adds stress to my drive and introduces frustrations.  Using the most direct route, I can sit back and relax on my drive, focusing instead on my music or on what I'll do with my free time.&lt;br /&gt;&lt;br /&gt;Reducing the complexity of a system usually increases its security (or decreases its likelihood of failure).  If a process requires four easy steps, it is much more likely to be followed closely than a similar process which requires several times more steps.  In automated systems, more steps means that there are more places to troubleshoot when a problem arises.  More worrisome, the more likely a single step is to fail silently and/or catastrophically.&lt;br /&gt;&lt;br /&gt;So &lt;a href="http://en.wikipedia.org/wiki/KISS_principle"&gt;KISS&lt;/a&gt;!  That Wikipedia link can elaborate for you if you are interested, but repeating what others have written is not keeping it simple.  I'd hate to &lt;a href="http://en.wikipedia.org/wiki/Occam%27s_Razor"&gt;multiply entities beyond necessity&lt;/a&gt;, so I'll quit while I'm ahead.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-857315130293031042?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=esTjCnId0jk:tEtQt9XOKzw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=esTjCnId0jk:tEtQt9XOKzw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=esTjCnId0jk:tEtQt9XOKzw:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=esTjCnId0jk:tEtQt9XOKzw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=esTjCnId0jk:tEtQt9XOKzw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=esTjCnId0jk:tEtQt9XOKzw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=esTjCnId0jk:tEtQt9XOKzw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=esTjCnId0jk:tEtQt9XOKzw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/esTjCnId0jk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/857315130293031042/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=857315130293031042" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/857315130293031042?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/857315130293031042?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/esTjCnId0jk/simplicity-simplicity-simplicity-tip-7.html" title="Simplify, Simplify, Simplify" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2007/05/simplicity-simplicity-simplicity-tip-7.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUCRnc-fip7ImA9WB5TF08.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-3882298344835662065</id><published>2006-11-07T22:36:00.000-05:00</published><updated>2007-06-01T15:31:07.956-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-06-01T15:31:07.956-04:00</app:edited><title>How Not to Fix a Problem</title><content type="html">I haven't posted in a couple of weeks (oops, I forgot!), so I figured I would put something up quickly that's fairly relevant to the typical blog posts and is somewhat topical.  Posting this last week would have given you, dear reader, time to observe more and be a bit more informed about the issues discussed.&lt;br /&gt;&lt;br /&gt;If you're in the United States, you had the opportunity to &lt;a href="http://en.wikipedia.org/wiki/Election_Day_%28United_States%29"&gt;choose the lesser of two evils today&lt;/a&gt; and vote for many of your government officials.  If you are in the rest of the world, I'm sure you can feel our pain.  But maybe not as much pain as many of us actually feel.  See we use these &lt;a href="http://en.wikipedia.org/wiki/Electronic_voting_machine"&gt;electronic voting machines&lt;/a&gt; here which are not very well liked.  If you haven't heard about this by now, consider yourself lucky.&lt;br /&gt;&lt;br /&gt;Now don't get me wrong, some of these things probably work well.  But nobody is ever going to hear about things that work as well as they should.  For those unsung heroes who designed these machines, I salute you.  For the others, please find a suicide cult and join it soon.&lt;br /&gt;&lt;br /&gt;I'm not going to go through and &lt;a href="http://www.wijvertrouwenstemcomputersniet.nl/English"&gt;rehash&lt;/a&gt; &lt;a href="http://rawstory.com/news/2005/Documents_show_Maryland_held_election_primary_0216.html"&gt;old&lt;/a&gt; &lt;a href="http://www.rollingstone.com/news/story/10432334/was_the_2004_election_stolen"&gt;arguments&lt;/a&gt; made by &lt;a href="http://www.bradblog.com/?p=2433"&gt;others&lt;/a&gt;.  If you &lt;a href="http://backslash.slashdot.org/article.pl?sid=06/08/01/191235"&gt;want&lt;/a&gt; &lt;a href="http://www.adn.com/news/politics/elections/story/8113627p-8006175c.html"&gt;to&lt;/a&gt; &lt;a href="http://vvnm.org/wiki/bevhacked.html"&gt;read&lt;/a&gt; &lt;a href="http://www.votersunite.org/info/ovrcstatement.asp"&gt;those&lt;/a&gt;, you'll &lt;a href="http://www.ddj.com/dept/security/193000399"&gt;find&lt;/a&gt; &lt;a href="http://www.us-cert.gov/cas/bulletins/SB04-252.html#diebold"&gt;plenty&lt;/a&gt; &lt;a href="http://it.slashdot.org/article.pl?sid=06/09/18/178218"&gt;of&lt;/a&gt; &lt;a href="http://www.blackboxvoting.com/s9/index.php?/archives/138-CONNECTING-MARYLANDS-ELECTION-DEBACLE-DOTS.html"&gt;links&lt;/a&gt;.  The basic problems are that the machines are difficult to use, they frequently break, and it's possible to manipulate the votes.  And instead of fixing the problems, the companies that make them are fighting people who expose the flaws.&lt;br /&gt;&lt;br /&gt;What the companies should be doing is making "bulletproof" devices and inviting people to try and break them.  There should be no question whatsoever that things are on the up-and-up when it comes to our freedom.  Further, there should be independent code audits and security tests to verify that there are no ways to breach the integrity of the machines.  In fact, I'm one of the people who thinks that the code should be opened up for review by everyone.  Why not leverage the power of a million or so people looking over the code for any problems?  Publish the code! You only have something to lose if it's broken and insecure and you've been &lt;span style="font-style: italic;"&gt;hiding&lt;/span&gt; that fact.&lt;br /&gt;&lt;br /&gt;With these devices, you don't design them so they can work, you design so they can't fail!  Take a look at ATMs -- they do this for the most part.  Very few people accidentally pull out stamps when they mean to withdraw money.  &lt;a href="http://www.diebold.com/"&gt;Diebold&lt;/a&gt;, one of the largest manufacturers of voting machines also makes ATMs.  They obviously have the expertise to make touch screen self service devices work, so why is it so hard to actually pull it off?&lt;br /&gt;&lt;br /&gt;Every system has its advantages and disadvantages when compared to others, but there is almost always a way to design a system that creates fewer disadvantages than the current system, while increasing the advantages.  When something works consistently and intuitively, there may still be ways to tweak the system to get greater efficiency.  But the electronic voting machines seem to have created a problem just as big as the one that they purport to solve.  Votes are still being counted inconsistently, ballot tampering is still possible, and the devices have added unreliability and complexity to the system.&lt;br /&gt;&lt;br /&gt;Ideally, a perfect solution will be efficient, simple to understand, intuitive to operate, and will minimize the possibility of mistakes.  Which brings us to our lesson for today:  A solution should not fix some problems only to create different, bigger ones!  That seems to obvious to have to state, but often times people lose sight of the basics and need to be reminded of them.  It happens to us all at one time or another, so it's worth pointing out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-3882298344835662065?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=huWwCzs7sf4:K4bz-KEpngg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=huWwCzs7sf4:K4bz-KEpngg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=huWwCzs7sf4:K4bz-KEpngg:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=huWwCzs7sf4:K4bz-KEpngg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=huWwCzs7sf4:K4bz-KEpngg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=huWwCzs7sf4:K4bz-KEpngg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=huWwCzs7sf4:K4bz-KEpngg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=huWwCzs7sf4:K4bz-KEpngg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/huWwCzs7sf4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/3882298344835662065/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=3882298344835662065" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3882298344835662065?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/3882298344835662065?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/huWwCzs7sf4/how-not-to-fix-problem-tip-6-i-havent.html" title="How Not to Fix a Problem" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2006/11/how-not-to-fix-problem-tip-6-i-havent.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUDRn45cSp7ImA9WB5TF08.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-116192130129131785</id><published>2006-10-26T21:28:00.000-04:00</published><updated>2007-06-01T15:31:17.029-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-06-01T15:31:17.029-04:00</app:edited><title>Lock Up Your Valuables</title><content type="html">If you're going to keep backups of your important information, it only makes sense to protect those backups.  This is doubly true if you're storing your backups off site.  If you have your backups on the internet, this is a no-brainer.  The best way to do this is to put the data in some kind of container that is locked away digitally.  No one can see through the container, and nobody can open it without the key.  In the digital world, this is accomplished by encryption.&lt;br /&gt;&lt;br /&gt;There are several types of stored data encryption software, from &lt;a href="http://en.wikipedia.org/wiki/FOSS"&gt;FOSS&lt;/a&gt; to &lt;a href="http://en.wikipedia.org/wiki/NSA_encryption_systems"&gt;Top Secret&lt;/a&gt;; from &lt;a href="http://www.blackberry.com/solutions/government/security.shtml"&gt;mobile&lt;/a&gt; &lt;a href="http://www.safeboot.com/products/device-encryption/symbian/"&gt;phone&lt;/a&gt; &lt;a href="http://www.rsasecurity.com/press_release.asp?doc_id=1236&amp;id=1034"&gt;software&lt;/a&gt; to &lt;a href="http://www.entrust.com/email-security/messaging-server/email-encryption.htm"&gt;hardened&lt;/a&gt; &lt;a href="http://www.pgp.com/products/universal_server/index.html"&gt;enterprise&lt;/a&gt; &lt;a href="http://www.ciphertrust.com/products/"&gt;appliances&lt;/a&gt;; from &lt;a href="http://en.wikipedia.org/wiki/Filesystem-level_encryption"&gt;file-by-file&lt;/a&gt; to &lt;a href="http://www.pgp.com/products/wholediskencryption/index.html"&gt;whole disk&lt;/a&gt;.  Each of these types has its place in the world of Information Security.  I will attempt to treat the most relevant ones here.  Hopefully by the end of this post you'll know what encryption is, why it's important to encrypt your valuable data, and what the best method is for you.&lt;br /&gt;&lt;br /&gt;Encryption and cryptography are much too broad to cover in depth here, but if you'd like to learn more about its history, it's details, and its uses, I recommend you start with the &lt;a href="http://en.wikipedia.org/wiki/Encryption"&gt;Wikipedia&lt;/a&gt; page and with &lt;a href="http://www.schneier.com/blog/"&gt;Bruce Schneier&lt;/a&gt;'s best known books, &lt;a href="http://www.schneier.com/book-applied.html"&gt;&lt;span style="font-style: italic;"&gt;Applied Cryptography&lt;/span&gt;&lt;/a&gt; and &lt;a href="http://www.schneier.com/book-practical.html"&gt;&lt;span style="font-style: italic;"&gt;Practical Cryptography&lt;/span&gt;&lt;/a&gt;.  I haven't read either of these, but I have a decent idea of the principle ideas behind cryptography and encryption.  I have neither the aptitude nor the desire to learn more about these fields.  Here is a very brief explanation and history of cryptography and encryption, which may or may not be technically accurate (but it's close enough).&lt;br /&gt;&lt;br /&gt;Cryptography is the use of codes or ciphers to transmit information between two parties in clear view in order to make the meaning of the message incomprehensible.  Both parties must have a key to decrypt the code.  This can be done by memorizing a substitution pattern, by using a physical device, by using a computer to keep track of the encryption and decryption code, by making use of a &lt;a href="http://en.wikipedia.org/wiki/One-time_pad"&gt;one-time pad&lt;/a&gt;, etc.  Each of these has its advantages and disadvantages.  As a general rule, usability comes at the cost of security.  All cryptographic techniques can be broken by modern computers given enough time, but some are easier than others due to &lt;a href="http://www.google.com/search?q=flawed+cryptography"&gt;flawed implementation&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The earliest cyphers were simple letter or word &lt;a href="http://en.wikipedia.org/wiki/Substitution_ciphers"&gt;substitute cyphers&lt;/a&gt;, such as replacing each character with a number or letter.  Julius Caesar used a &lt;a href="http://en.wikipedia.org/wiki/Caesar_cipher"&gt;cipher named after him&lt;/a&gt; which relied on both parties having a cylinder of equal size -- a physical decryption key of sorts.  Not a whole lot happened until the advent of basic computers -- &lt;a href="http://en.wikipedia.org/wiki/Difference_engine"&gt;in the mid 1800s&lt;/a&gt; &lt;span style="text-decoration: underline;"&gt;by Charles Babbage&lt;/span&gt;!  But during World War II, the use of cryptography (and &lt;a href="http://en.wikipedia.org/wiki/Cryptanalysis"&gt;cryptanalysis&lt;/a&gt;) really took off.  The most famous bits of cryptography during this era were the &lt;a href="http://en.wikipedia.org/wiki/Enigma_machine"&gt;Enigma machine&lt;/a&gt; and the &lt;a href="http://www.pan.net/history/enigma/index.htm"&gt;Polish mathematicians' breaking of this&lt;/a&gt; (by hand, no less), the &lt;a href="http://www.espionageinfo.com/Vo-Z/World-War-II-United-States-Breaking-of-Japanese-Naval-Codes.html"&gt;American decoding&lt;/a&gt; of the &lt;a href="http://en.wikipedia.org/wiki/Purple_code"&gt;Japanese diplomatic&lt;/a&gt; and, after Pearl Harbor, &lt;a href="http://en.wikipedia.org/wiki/JN-25"&gt;tactical&lt;/a&gt; encryption, and the American Marines' use of &lt;a href="http://www.history.navy.mil/faqs/faq61-2.htm"&gt;Navajo "Code Talkers"&lt;/a&gt; to relay messages to and from the front lines. Modern powerful multipurpose computing machines have ushered in the age of &lt;a href="http://en.wikipedia.org/wiki/History_of_cryptography#Modern_cryptography"&gt;Modern Cryptography&lt;/a&gt; and its various methods and techniques for encryption.&lt;br /&gt;&lt;br /&gt;Now that the obligatory background information, we can start on the meat of the post.  I find that it is best to think of encryption software by its functionality.  What does the software do and how can that be useful?  In this sense, there are three categories of stored data encryption: &lt;a href="http://en.wikipedia.org/wiki/Filesystem-level_encryption"&gt;file level encryption&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Disk_encryption_software"&gt;file vault encryption&lt;/a&gt;, and &lt;a href="http://en.wikipedia.org/wiki/Full_disk_encryption"&gt;whole disk encryption&lt;/a&gt;.  Note that I will not be discussing &lt;a href="http://en.wikipedia.org/wiki/Cryptographic_protocol"&gt;cryptographic protocols&lt;/a&gt;, such as &lt;a href="http://en.wikipedia.org/wiki/Transport_Layer_Security"&gt;SSL/TLS&lt;/a&gt;, for securing data as it crosses a network.&lt;br /&gt;&lt;br /&gt;File level encryption or filesystem level encryption is a method of encrypting individual files on a disk.  Usually this requires the user to manually select to encrypt a file.  Some software allows the user to specify that a directory in its entirety is encrypted, including new documents created or put into this directory.  Windows uses the &lt;a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/encrypt_overview.mspx"&gt;Encrypting File System&lt;/a&gt; (EFS), and OS X uses their &lt;a href="http://www.apple.com/macosx/features/filevault/"&gt;FileVault&lt;/a&gt;.  Each of these automate decryption when the user logs into the computer.  However, this means that anyone who has access to this login has access to the sensitive files.  It also makes transporting the files encrypted a challenge:  they are decrypted in transit, but are difficult to copy when encrypted (or rather, they are difficult to decrypt after they have been moved when encrypted).  Other programs can be used which can overcome the latter difficulty, but which do not solve the first one and may not provide the same ease of use as the integrated products.&lt;br /&gt;&lt;br /&gt;What I call "file vault encryption" others call "disk encryption".  I think this is easily confused with "full disk encryption" so I will continue to use my terminology, despite the possible confusion with Apple's FileVault.  Whatever you want to call it, file vault encryption creates a single file in which all data is stored encrypted.  Typically the software will &lt;a href="http://en.wikipedia.org/wiki/Mount_%28computing%29"&gt;mount&lt;/a&gt; this file as an additional hard drive in your computer, making access to the data easy.  This type of encryption is very easy to transfer to another computer or to medium -- you just copy the single file.  However, it typically requires entering a secondary password after logging into the computer.&lt;br /&gt;&lt;br /&gt;Full disk encryption or whole disk encryption usually refers to encrypting the entire &lt;a href="http://en.wikipedia.org/wiki/Boot_device"&gt;boot device&lt;/a&gt;.  This ensures that all of the data on the disk will be encrypted, including temporary files, working files like the ones Microsoft Word creates, and the &lt;a href="http://en.wikipedia.org/wiki/Scratch_disk"&gt;scratch disk&lt;/a&gt; or &lt;a href="http://en.wikipedia.org/wiki/Virtual_memory"&gt;virtual memory&lt;/a&gt;.  Encrypting all of this data is most appropriate for mobile computers which are likely to be lost or stolen.  However, this &lt;a href="http://www.full-disk-encryption.net/blog/index.php?action=viewtopic&amp;amp;id=250"&gt;security costs performance&lt;/a&gt;.  Also, once the user logs into the computer, all files are copied and transmitted unencrypted.  In addition to the fact that transporting the data requires additional encryption, if the hard drive is damaged or if the &lt;a href="http://en.wikipedia.org/wiki/Boot_sector"&gt;boot sector&lt;/a&gt; is overwritten, the data is essentially irretrievable.&lt;br /&gt;&lt;br /&gt;Of these three types, each has its proper use.  The least useful type of stored data encryption of the three is the file level encryption.  It offers the fewest benefits with the highest risks.  In fact, I would argue that it is completely useless in comparison with file vault encryption, which performs many of the same functions with the added bonus of transportability.  In addition, the fact that the vault is mounted to a drive letter clearly delineates which data is encrypted and which data is not encrypted.  Full disk encryption should be used anywhere the risk of computer theft or loss is moderate, in addition to some high security environments.  And some form of encryption should be used on all backed up data.&lt;br /&gt;&lt;br /&gt;Of the many dozens of attacks where &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;personal information has been lost&lt;/a&gt;, it is unclear how many were preventable by encrypting the data.  However, it is a good bet that every lost or stolen laptop or backup tape would have yielded no data if proper encryption methods had been used. And many of the hacking incidents may have been preventable if the sensitive information had been encrypted properly.  While it may seem costly for a company to implement, the encryption software and practices cost &lt;a href="http://www.techweb.com/wire/security/188702019"&gt;hardly anything&lt;/a&gt; compared to an incident like the &lt;a href="http://www.techweb.com/wire/security/188101069"&gt;Department of Veteran's Affairs suffered&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The take away lesson here is to keep your important stuff protected.  It's not enough to just keep it in a safe place, you should keep it in a secure place.  Whether that is a safety deposit box at your bank, a safe in your home, or a vault at Ft. Knox, you can't afford to let your valuables just sit around unprotected.  How cheap it would seem in retrospect to buy a safe than to try replacing a family heirloom after it is stolen.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-116192130129131785?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=F6kcRiwGF5E:hs6eA5rNkJ0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=F6kcRiwGF5E:hs6eA5rNkJ0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=F6kcRiwGF5E:hs6eA5rNkJ0:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=F6kcRiwGF5E:hs6eA5rNkJ0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=F6kcRiwGF5E:hs6eA5rNkJ0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=F6kcRiwGF5E:hs6eA5rNkJ0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=F6kcRiwGF5E:hs6eA5rNkJ0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=F6kcRiwGF5E:hs6eA5rNkJ0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/F6kcRiwGF5E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/116192130129131785/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=116192130129131785" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/116192130129131785?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/116192130129131785?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/F6kcRiwGF5E/lock-up-your-valuables-tip-5-if-youre.html" title="Lock Up Your Valuables" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2006/10/lock-up-your-valuables-tip-5-if-youre.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUMR3o7fCp7ImA9WB5TF08.&quot;"><id>tag:blogger.com,1999:blog-34349059.post-116001867469446664</id><published>2006-10-19T23:22:00.000-04:00</published><updated>2007-06-01T15:31:26.404-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-06-01T15:31:26.404-04:00</app:edited><title>Backups</title><content type="html">This tip will either be a waste of time or it will save you more grief than you can imagine.  Backing up your important information can make the difference between taking 10 minutes to restore your data versus weeks and hundreds of dollars to get none to all of it back.  I lost my data once and didn't have the money to spend restoring, so I spent over a year and a half trying out different software and techniques before I was finally able to rebuild the data I lost -- a lot of irreplacable pictures.&lt;br /&gt;&lt;br /&gt;So now that you know you should be backing up your data, how do you do that?  The first step is to identify what you want to back up.  This isn't as easy as it might sound at first.  Things tend to get scattered all across your hard drive, floppies, CDs, etc.  The only thing worse than not backing up anything is backing up everything but a key document -- by the time you realize you've lost it, it may be be too late to recover.  Once you've got it all collected, find a spot on your hard drive where you can store everything.&lt;br /&gt;&lt;br /&gt;Now that the first step is completed, it's time to look at your backup options.  Which backup method you choose is largely a matter of personal preference.  The four general ways to backup data are online, &lt;a href="http://en.wikipedia.org/wiki/Nearline_storage"&gt;nearline&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Nearline_storage"&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Offline_storage"&gt;offline&lt;/a&gt;, and offsite.  There are benefits to each, as well as drawbacks.  Here are some brief descriptions.&lt;br /&gt;&lt;br /&gt;Online storage backups are not really backups, they are redundancies in the way the data is stored, meaning that a single dead hard drive does not lead to data loss.  However, for the purposes of our discussion, it can be considered a method of backup.  Typical online storage would be something like an internal &lt;a href="http://en.wikipedia.org/wiki/RAID"&gt;RAID&lt;/a&gt; with &lt;a href="http://en.wikipedia.org/wiki/Fault_tolerance"&gt;fault tolerance&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Network-attached_storage"&gt;NAS&lt;/a&gt;/&lt;a href="http://en.wikipedia.org/wiki/Storage_area_network"&gt;SAN&lt;/a&gt;, or some other method of keeping data instantly accessible and current in the event of a failure.  Also, you don't have to think about performing backups, data is automatically backed up whenever you change or update it.  However, in the event of a complete system failure, all information will be lost.  This could be due to theft, lightning and other natural disasters, structure failure, fire, etc.&lt;br /&gt;&lt;br /&gt;Nearline storage allows you to keep data close at hand, but not fully current or instantly accessible.  This would be a true replication of data, so that it exists both on the computer and on another device.  Typical nearline storage devices are &lt;a href="http://en.wikipedia.org/wiki/Usb_flash_drive"&gt;USB flash drives&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Disk_enclosure"&gt;external hard drives&lt;/a&gt;,  secondary internal hard drives, or any other type of storage usually connected to the computer or across a network.  The backed up data is quick and easy to access in the event of a primary storage failure.  This type of backup is probably most common in home environments.&lt;br /&gt;&lt;br /&gt;Offline storage is that which is backed up, usually on removable media such as blank CDs or DVDs (optical media), floppy disks, &lt;a href="http://en.wikipedia.org/wiki/Zip_disk"&gt;zip disks&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Magnetic_tape"&gt;storage tapes&lt;/a&gt;, etc.  These media are easily stored elsewhere, since they are typically much cheaper and more portable than the other solutions.  Offline storage requires that you locate the media and put it in a reader attached to your computer.  One of the biggest problems with this type of storage is that sometimes the media goes bad.  This is especially true for optical media.&lt;br /&gt;&lt;br /&gt;Offsite storage is typically an offline storage system where some or all of the media is kept in another physical location.  For example, if you backup your home computer's data to DVD and store the DVD in your desk drawer at work, you have an offsite backup.  This may accomplish your goals just fine, or you may want to look at a more secure solution, such as a safety deposit box or a professional service which will pick up and store your media.&lt;br /&gt;&lt;br /&gt;Another form of offsite storage is internet-based storage.  There are plenty of sites out there that will give you free storage, from &lt;a href="http://www.free-webhosts.com/"&gt;free web hosts&lt;/a&gt;, to &lt;a href="http://rapidshare.de/"&gt;file&lt;/a&gt; &lt;a href="http://stashbox.org/"&gt;sharing&lt;/a&gt; &lt;a href="http://www.snapdrive.net/"&gt;sites&lt;/a&gt;, &lt;a href="http://storage.vmn.net/plans.php"&gt;to&lt;/a&gt; &lt;a href="http://www.streamload.com/"&gt;dedicated&lt;/a&gt; &lt;a href="http://www.xdrive.com/"&gt;backup&lt;/a&gt; &lt;a href="http://mozy.com/"&gt;sites&lt;/a&gt;, to &lt;a href="http://www.inbox.com/"&gt;jumbo&lt;/a&gt; &lt;a href="http://webmail.aol.com/"&gt;sized&lt;/a&gt; &lt;a href="http://mail.google.com/"&gt;email&lt;/a&gt; &lt;a href="http://www.yahoo.com/r/m1"&gt;hosts&lt;/a&gt;.  Some of these are better than others for keeping backups of sensitive information.  For example, the backup sites linked all claim to encrypt your data so that only you can retrieve it.  In general, I don't trust proprietary encryption and I don't trust somebody else to encrypt the data for me.  So you'll probably want to encrypt it before uploading (that's a topic for another day...).&lt;br /&gt;&lt;br /&gt;While any data backup is better than none at all, I recommend keeping a few different backups using different methods.  My important data resides in several locations.  First, it is on my local hard drive.  Once a week or so I copy this to a file server running a RAID.  Every once in a while I'll copy the backup to an internet-based offline storage system.  This ensures that I can survive several failures without loss of data.&lt;br /&gt;&lt;br /&gt;Don't forget how critical your backups are!  Don't store the backups where they may get stolen, lost, damaged, or otherwise be useless.  Also don't forget to keep this data secured and/or encrypted.  And it might be handy to test your backups regularly to make sure you can restore the information.  Many businesses learn these lessons the hard way by losing their only copy of data, by having the information leak out because they treated their backups as if they were blank, or by not being able to get their data back when they really needed it.  I warned you.&lt;br /&gt;&lt;br /&gt;Businesses pracitce "Risk Management," determining an acceptable amount of risk to allow as a tradeoff for cost.  But they're only protecting their money; you have to protect much more valuable property.  Whether you're backing up your Great Grandmother's cookie recipé, your college thesis paper, or your pictures of your kids' first Christmas, these things are irreplacable. With the free tools outlined here, the only cost to you is your time.&lt;br /&gt;&lt;br /&gt;The final lesson in data backup is trust.  Backups are an insurance policy and the most important part of insuring against loss is trust.  So don't listen to the lizard or the duck when they tell you that cheap insurance is better.  The truth is that if you ever have to cash in one of these things, they'd better pay off.  If you don't have 110% confidence that you can recover quickly and easily after a disaster, then it's time to start looking for somebody that you can trust to make that happen.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34349059-116001867469446664?l=beauwoods.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=iRUyjwr89ss:13GEivody2Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=iRUyjwr89ss:13GEivody2Y:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=iRUyjwr89ss:13GEivody2Y:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=iRUyjwr89ss:13GEivody2Y:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=iRUyjwr89ss:13GEivody2Y:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=iRUyjwr89ss:13GEivody2Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?i=iRUyjwr89ss:13GEivody2Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?a=iRUyjwr89ss:13GEivody2Y:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BeausComputerSecurityBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BeausComputerSecurityBlog/~4/iRUyjwr89ss" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://beauwoods.blogspot.com/feeds/116001867469446664/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=34349059&amp;postID=116001867469446664" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/116001867469446664?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/34349059/posts/default/116001867469446664?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/BeausComputerSecurityBlog/~3/iRUyjwr89ss/backups-tip-4-this-tip-will-either-be.html" title="Backups" /><author><name>Beau Woods</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="16474045815768281750" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://beauwoods.blogspot.com/2006/10/backups-tip-4-this-tip-will-either-be.html</feedburner:origLink></entry></feed>
