<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:posterous="http://posterous.com/help/rss/1.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>Caffeinated Security</title>
    <link>http://caffeinatedsecurity.posterous.com</link>
    <description>network security all night long.</description>
    <generator>posterous.com</generator>
    <link xmlns="http://www.w3.org/2005/Atom" href="http://posterous.com/api/sup_update#52a8a359e" type="application/json" rel="http://api.friendfeed.com/2008/03#sup" />
    
    
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/CaffeinatedSecurity" /><feedburner:info uri="caffeinatedsecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://posterous.superfeedr.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-sa/2.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-sa/2.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>CaffeinatedSecurity</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site.</feedburner:browserFriendly><item>
      <pubDate>Thu, 15 Apr 2010 10:02:21 -0700</pubDate>
      <title>apache.org incident report for 04/09/2010</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/rRFbI0hg2ts/apacheorg-incident-report-for-04092010</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/apacheorg-incident-report-for-04092010</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;Apache.org services recently suffered a direct, targeted attack against our infrastructure, specifically the server hosting our issue-tracking software.&lt;/p&gt;

&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="https://blogs.apache.org/infra/entry/apache_org_04_09_2010"&gt;blogs.apache.org&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;Great example of an incident report.&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/apacheorg-incident-report-for-04092010"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/apacheorg-incident-report-for-04092010#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=rRFbI0hg2ts:6zPGKgslLx4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=rRFbI0hg2ts:6zPGKgslLx4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=rRFbI0hg2ts:6zPGKgslLx4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=rRFbI0hg2ts:6zPGKgslLx4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=rRFbI0hg2ts:6zPGKgslLx4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/apacheorg-incident-report-for-04092010</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 09:48:24 -0700</pubDate>
      <title>SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/eoZY5T3rcWQ/shadows-in-the-cloud-investigating-cyber-espi-0</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/shadows-in-the-cloud-investigating-cyber-espi-0</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_medium_quote"&gt;Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised  government, business, academic, and other computer network systems in India, the Offices of the Dalai Lama,  the United Nations, and several other countries.&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0"&gt;scribd.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/shadows-in-the-cloud-investigating-cyber-espi-0"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/shadows-in-the-cloud-investigating-cyber-espi-0#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=eoZY5T3rcWQ:NE_T2avGGrA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=eoZY5T3rcWQ:NE_T2avGGrA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=eoZY5T3rcWQ:NE_T2avGGrA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=eoZY5T3rcWQ:NE_T2avGGrA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=eoZY5T3rcWQ:NE_T2avGGrA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/shadows-in-the-cloud-investigating-cyber-espi-0</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 09:43:56 -0700</pubDate>
      <title>Google CEO: 'We're now paranoid' about security</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/7pbNmPqT8zc/google-ceo-were-now-paranoid-about-security-2</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/google-ceo-were-now-paranoid-about-security-2</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;"Our Web services and Web platforms will be inherently more secure" than alternatives, Schmidt said. "Hold us to this."&lt;/p&gt;
 &lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://news.cnet.com/8301-30684_3-20002315-265.html"&gt;news.cnet.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;Okay.&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/google-ceo-were-now-paranoid-about-security-2"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/google-ceo-were-now-paranoid-about-security-2#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=7pbNmPqT8zc:eFcUqqoiTMs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=7pbNmPqT8zc:eFcUqqoiTMs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=7pbNmPqT8zc:eFcUqqoiTMs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=7pbNmPqT8zc:eFcUqqoiTMs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=7pbNmPqT8zc:eFcUqqoiTMs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/google-ceo-were-now-paranoid-about-security-2</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 09:38:57 -0700</pubDate>
      <title>Spy Network Pilfered Classified Docs From Indian Government and Others</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/sfnK24rV_iU/spy-network-pilfered-classified-docs-from-ind</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/spy-network-pilfered-classified-docs-from-ind</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;The researchers say the spying is an example of a sophisticated shift that has occurred in malware networks from “what were once primarily simple to increasingly complex, adaptive systems spread across redundant services and platforms” and from ones that primarily focused on exploitation for criminal purposes to ones that are focused on “political, military, and intelligence-focused espionage.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.wired.com/threatlevel/2010/04/shadow-network/"&gt;wired.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/spy-network-pilfered-classified-docs-from-ind"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/spy-network-pilfered-classified-docs-from-ind#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=sfnK24rV_iU:LNV-EYru2G4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=sfnK24rV_iU:LNV-EYru2G4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=sfnK24rV_iU:LNV-EYru2G4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=sfnK24rV_iU:LNV-EYru2G4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=sfnK24rV_iU:LNV-EYru2G4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/spy-network-pilfered-classified-docs-from-ind</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 09:34:47 -0700</pubDate>
      <title>Reaction to Cyber Shockwave</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/fzCPimfxxno/reaction-to-cyber-shockwave</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/reaction-to-cyber-shockwave</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_medium_quote"&gt;For me, the lesson of Cyber Shockwave is to first determine how your leaders think, then recommend policy actions.&amp;nbsp; In the realm of digital security, this requires identifying what priorities your management places on digital security.&amp;nbsp; With a better understanding of their thought process, you can tailor your message to match their strengths, weaknesses, hopes, fears, and biases.&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.btsecurethinking.com/2010/03/guest-post-reaction-to-cyber-shockwave-2/"&gt;btsecurethinking.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/reaction-to-cyber-shockwave"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/reaction-to-cyber-shockwave#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=fzCPimfxxno:3bX3phHuEKU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=fzCPimfxxno:3bX3phHuEKU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=fzCPimfxxno:3bX3phHuEKU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=fzCPimfxxno:3bX3phHuEKU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=fzCPimfxxno:3bX3phHuEKU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/reaction-to-cyber-shockwave</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 09:29:27 -0700</pubDate>
      <title>DHS studying global response to Conficker botnet</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/Uxlq6IKdUes/dhs-studying-global-response-to-conficker-bot</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/dhs-studying-global-response-to-conficker-bot</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p class="first"&gt;One year after the Conficker botnet was front-page news around the world, the U.S. Department of Homeland Security is preparing
   a report looking at the worldwide effort to keep it in check.
&lt;/p&gt;
&lt;p&gt;The report, to be published within the month, shows how an ad hoc group of security researchers and Internet infrastructure
   providers banded together into an organization they called the Conficker Working Group. Its goal was to address what was at
   the time the world's most serious cyberthreat.&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.networkworld.com/news/2010/040210-dhs-studying-global-response-to.html?source=NWWNLE_nlt_security_2010-04-05"&gt;networkworld.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/dhs-studying-global-response-to-conficker-bot"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/dhs-studying-global-response-to-conficker-bot#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=Uxlq6IKdUes:E2n92v7LvWs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=Uxlq6IKdUes:E2n92v7LvWs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=Uxlq6IKdUes:E2n92v7LvWs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=Uxlq6IKdUes:E2n92v7LvWs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=Uxlq6IKdUes:E2n92v7LvWs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/dhs-studying-global-response-to-conficker-bot</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 09:23:53 -0700</pubDate>
      <title>TaoSecurity: Time and Cost to Defend the Town</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/KiU6uWcfZpA/taosecurity-time-and-cost-to-defend-the-town</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/taosecurity-time-and-cost-to-defend-the-town</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;Consider the following scenario.  You're the mayor of a town.  You need to decide how much of your budget to allocate to the fire department.  To apply the most simplistic analysis to the problem, consider this scene.  As mayor you give the fire chief a simple goal: "protect us from fires!"  The fire chief asks you: "Mayor, on average, how fast do you want the fire department to respond to a fire?"&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://taosecurity.blogspot.com/2010/03/time-and-cost-to-defend-town.html"&gt;taosecurity.blogspot.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/taosecurity-time-and-cost-to-defend-the-town"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/taosecurity-time-and-cost-to-defend-the-town#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=KiU6uWcfZpA:Jejjdmcq6tU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=KiU6uWcfZpA:Jejjdmcq6tU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=KiU6uWcfZpA:Jejjdmcq6tU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=KiU6uWcfZpA:Jejjdmcq6tU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=KiU6uWcfZpA:Jejjdmcq6tU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/taosecurity-time-and-cost-to-defend-the-town</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 08:17:29 -0700</pubDate>
      <title>Firefox plugin decodes malicious Web sites</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/BaCXky91UC8/firefox-plugin-decodes-malicious-web-sites</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/firefox-plugin-decodes-malicious-web-sites</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;A computer &lt;a href="http://infoworld.com/d/security-central" target="_self"&gt;security&lt;/a&gt; researcher has released a plugin for &lt;a href="http://www.infoworld.com/t/firefox" target="_self"&gt;Firefox&lt;/a&gt; that provides a wealth of data on Web sites that may have been compromised with &lt;a href="http://www.infoworld.com/t/malware" target="_self"&gt;malicious code&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;The plugin, called Fireshark, was released on Wednesday at the Black Hat conference&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.infoworld.com/d/security-central/firefox-plugin-decodes-malicious-web-sites-815"&gt;infoworld.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/firefox-plugin-decodes-malicious-web-sites"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/firefox-plugin-decodes-malicious-web-sites#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=BaCXky91UC8:bZj_eL2FUDQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=BaCXky91UC8:bZj_eL2FUDQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=BaCXky91UC8:bZj_eL2FUDQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=BaCXky91UC8:bZj_eL2FUDQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=BaCXky91UC8:bZj_eL2FUDQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/firefox-plugin-decodes-malicious-web-sites</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 07:58:11 -0700</pubDate>
      <title>Germans Investigate H.P. Workers for Kickbacks - NYTimes.com</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/6ZObSKkId08/germans-investigate-hp-workers-for-kickbacks</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/germans-investigate-hp-workers-for-kickbacks</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_medium_quote"&gt;German authorities have arrested three people who worked for Hewlett-Packard as part of an investigation into alleged kickbacks paid in connection with a contract to supply equipment to Russian law enforcement.&lt;/blockquote&gt;&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.nytimes.com/2010/04/16/technology/16hewlett.html"&gt;nytimes.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/germans-investigate-hp-workers-for-kickbacks"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/germans-investigate-hp-workers-for-kickbacks#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=6ZObSKkId08:3lslxmJdmkY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=6ZObSKkId08:3lslxmJdmkY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=6ZObSKkId08:3lslxmJdmkY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=6ZObSKkId08:3lslxmJdmkY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=6ZObSKkId08:3lslxmJdmkY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/germans-investigate-hp-workers-for-kickbacks</feedburner:origLink></item>
    <item>
      <pubDate>Thu, 15 Apr 2010 07:53:33 -0700</pubDate>
      <title>NSA director to testify at Senate hearing on cyber command unit</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/e6SzXlMr2w0/nsa-director-to-testify-at-senate-hearing-on</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/nsa-director-to-testify-at-senate-hearing-on</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;Alexander is set to testify before the Senate Armed Services Committee on Thursday but has already provided written responses to questions from lawmakers.
&lt;/p&gt;
&lt;p&gt;
Among other things, he stated that, faced with a cyber attack, the military must be able to respond in kind. It is "reasonable to assume that returning fire in cyberspace" is lawful, as long as any actions comply with the laws of war, he said in a &lt;a href="http://www.washingtonpost.com/wp-srv/politics/documents/questions.pdf" target=""&gt;32-page document&lt;/a&gt;.&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/04/14/AR2010041404013.html?hpid=topnews"&gt;washingtonpost.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/nsa-director-to-testify-at-senate-hearing-on"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/nsa-director-to-testify-at-senate-hearing-on#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=e6SzXlMr2w0:6UeOqsMk3z4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=e6SzXlMr2w0:6UeOqsMk3z4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=e6SzXlMr2w0:6UeOqsMk3z4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=e6SzXlMr2w0:6UeOqsMk3z4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=e6SzXlMr2w0:6UeOqsMk3z4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/nsa-director-to-testify-at-senate-hearing-on</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 14 Apr 2010 19:44:12 -0700</pubDate>
      <title>10 signs that you work in computer forensics « Happy as a Monkey</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/7vsdCzgAXOU/10-signs-that-you-work-in-computer-forensics</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/10-signs-that-you-work-in-computer-forensics</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;1. You can’t search Google or visit a web site without worrying about how it’d look to someone analysing your machine.&lt;/p&gt;
&lt;p&gt;2. You get drunk and Google “normal-looking women with their clothes on” when your wife’s gone to bed.&lt;/p&gt;
&lt;p&gt;3. Someone is explaining a scenario to you that’s reaching its end with “and then he asked ‘do you want me to turn on my webcam, so you can see my face?’, and I said ‘OK’, and…” and you spend the next five minutes laughing hysterically then apologising profusely.&lt;/p&gt;
&lt;p&gt;4. None of your friends will lend you their camera memory card.&lt;/p&gt;
&lt;p&gt;5. You’ve got the most powerful workstation out of all your geek friends, but you’re the only one who doesn’t game online with it.&lt;/p&gt;
&lt;p&gt;6. People you meet at parties are interested when they hear your job title, then move away when you tell them how you actually spend your days.&lt;/p&gt;
&lt;p&gt;7. You wake a sleeping computer by pressing the ’shift’ key.&lt;/p&gt;
&lt;p&gt;8. You marvel at the tinyness of a 32GB microSD card, but are secretly thinking that you really need to start considering doing cavity searches on warrants&lt;/p&gt;
&lt;p&gt;9. The salesman is showing you a high-tech washing machine, and you’re wondering how you’d get and analyse the data off it&lt;/p&gt;
&lt;p&gt;10. You know at least one friend of a friend of a friend who always corners you to ask about the best wiping software.&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://happyasamonkey.wordpress.com/2010/03/12/10-signs-that-you-work-in-computer-forensics/"&gt;happyasamonkey.wordpress.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/10-signs-that-you-work-in-computer-forensics"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/10-signs-that-you-work-in-computer-forensics#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=7vsdCzgAXOU:XMzNsI2B_x8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=7vsdCzgAXOU:XMzNsI2B_x8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=7vsdCzgAXOU:XMzNsI2B_x8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=7vsdCzgAXOU:XMzNsI2B_x8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=7vsdCzgAXOU:XMzNsI2B_x8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/10-signs-that-you-work-in-computer-forensics</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 14 Apr 2010 19:40:37 -0700</pubDate>
      <title>Naming and Shaming ‘Bad’ ISPs</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/TzCMjUyH1rA/naming-and-shaming-bad-isps</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/naming-and-shaming-bad-isps</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_short_quote"&gt;I polled some of the most vigilant sources of this information for their recent data, and put together a rough chart indicating the Top Ten most prevalent ISPs from each of their vantage points.&lt;/blockquote&gt;

&lt;img src="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/WebRep.jpg" /&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://krebsonsecurity.com/2010/03/naming-and-shaming-bad-isps/"&gt;krebsonsecurity.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;Doesn't seem like we have a lot of defensive tools based on AS numbers, though.&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/naming-and-shaming-bad-isps"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/naming-and-shaming-bad-isps#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=TzCMjUyH1rA:dSrlqXsC5Pc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=TzCMjUyH1rA:dSrlqXsC5Pc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=TzCMjUyH1rA:dSrlqXsC5Pc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=TzCMjUyH1rA:dSrlqXsC5Pc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=TzCMjUyH1rA:dSrlqXsC5Pc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/naming-and-shaming-bad-isps</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 07 Apr 2010 08:02:55 -0700</pubDate>
      <title>TaoSecurity: Forget ROI and Risk. Consider Competitive Advantage</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/c9aaWsp-3U0/taosecurity-forget-roi-and-risk-consider-comp</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/taosecurity-forget-roi-and-risk-consider-comp</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote&gt;&lt;div&gt;
I've decided that &lt;strong&gt;competitiveness&lt;/strong&gt; is the new theme which I will use to justify my team's activities when discussing our mission with management.
&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://taosecurity.blogspot.com/2010/03/forget-roi-and-risk-consider.html"&gt;taosecurity.blogspot.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/taosecurity-forget-roi-and-risk-consider-comp"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/taosecurity-forget-roi-and-risk-consider-comp#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=c9aaWsp-3U0:fRDEcEVcwJc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=c9aaWsp-3U0:fRDEcEVcwJc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=c9aaWsp-3U0:fRDEcEVcwJc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=c9aaWsp-3U0:fRDEcEVcwJc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=c9aaWsp-3U0:fRDEcEVcwJc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/taosecurity-forget-roi-and-risk-consider-comp</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 31 Mar 2010 20:03:01 -0700</pubDate>
      <title>Microsoft runs fuzzing botnet, finds 1,800 Office bugs</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/Mbei8SWsvc8/microsoft-runs-fuzzing-botnet-finds-1800-offi</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/microsoft-runs-fuzzing-botnet-finds-1800-offi</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;"We call it a botnet for fuzzing," said Gallagher, referring to what Microsoft has formally dubbed Distributed Fuzzing Framework (DFF). The fuzzing network originated with work by David Conger, a software design engineer on the Access team.&lt;/p&gt; &lt;p&gt;Client software installed on systems throughout Microsoft's network automatically kicks in when the PCs are idle, such as on weekends, to run fuzzing tests "We would do millions of [fuzzing] iterations each weekend," Gallagher said -- up to 12 million in some cases.&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.computerworld.com/s/article/9174539/Microsoft_runs_fuzzing_botnet_finds_1_800_Office_bugs"&gt;computerworld.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/microsoft-runs-fuzzing-botnet-finds-1800-offi"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/microsoft-runs-fuzzing-botnet-finds-1800-offi#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=Mbei8SWsvc8:OGMki1CNV_k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=Mbei8SWsvc8:OGMki1CNV_k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=Mbei8SWsvc8:OGMki1CNV_k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=Mbei8SWsvc8:OGMki1CNV_k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=Mbei8SWsvc8:OGMki1CNV_k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/microsoft-runs-fuzzing-botnet-finds-1800-offi</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 31 Mar 2010 10:43:03 -0700</pubDate>
      <title>“It doesn’t matter how you define cyberwar,” says Amit Yoran | The New New Internet</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/rV8ZzLR1aSY/it-doesnt-matter-how-you-define-cyberwar-says</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/it-doesnt-matter-how-you-define-cyberwar-says</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;Amit Yoran, CEO of NetWitness, has now joined the debate. In an article published in Forbes, Yoran looks to provide a bit more perspective to both parties involved in the debate. For Yoran, “it doesn’t matter how you define cyberwar or whether you believe we are currently at a state of cyberwar or not.”&lt;/p&gt;
&lt;p&gt;Instead of focusing on this issue, Yoran believes that the focus should be on cybersecurity as not just a national security issue, but also an economic issue. Millions of dollars is stolen from the United States each month by cyber criminals.&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.thenewnewinternet.com/2010/03/29/it-doesn%E2%80%99t-matter-how-you-define-cyberwar-says-amit-yoran/"&gt;thenewnewinternet.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;I believe that Yoran is fundamentally wrong. Dealing with small criminals, organized crime, non-state ideologically-motivated actors, and nation-states all require different approaches in many areas.&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/it-doesnt-matter-how-you-define-cyberwar-says"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/it-doesnt-matter-how-you-define-cyberwar-says#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=rV8ZzLR1aSY:YOQaTT7FxFY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=rV8ZzLR1aSY:YOQaTT7FxFY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=rV8ZzLR1aSY:YOQaTT7FxFY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=rV8ZzLR1aSY:YOQaTT7FxFY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=rV8ZzLR1aSY:YOQaTT7FxFY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/it-doesnt-matter-how-you-define-cyberwar-says</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 31 Mar 2010 10:32:55 -0700</pubDate>
      <title>My SecTools</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/qamB5E6mFws/my-sectools</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/my-sectools</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p class="Body" style="padding-top: 0pt;"&gt;The MySecTools idea was born when a user sent an email to the handlers at the &lt;a href="http://isc.sans.org" title="http://isc.sans.org"&gt;SANS Internet Storm Center&lt;/a&gt; , where I am a volunteer handler, asking about an updated version of Sectools.org, which is a great website.&lt;br /&gt;&lt;/p&gt;
                &lt;p class="Body"&gt;I decided to create this site with my preferred Security tools, which will be in different sections, like Malware Analysis tools, Network tools,etc...&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.mysectools.com/MySecTools/The_Tools/The_Tools.html"&gt;mysectools.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/my-sectools"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/my-sectools#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=qamB5E6mFws:iSOcb8iEcGs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=qamB5E6mFws:iSOcb8iEcGs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=qamB5E6mFws:iSOcb8iEcGs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=qamB5E6mFws:iSOcb8iEcGs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=qamB5E6mFws:iSOcb8iEcGs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/my-sectools</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 31 Mar 2010 10:26:40 -0700</pubDate>
      <title>Is the cyber threat overblown? | Stephen M. Walt</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/sVpvKBSwVBM/is-the-cyber-threat-overblown-stephen-m-walt</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/is-the-cyber-threat-overblown-stephen-m-walt</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;div class="graphic-well"&gt;&lt;img src="http://walt.foreignpolicy.com/files/dhs.jpg" /&gt;&lt;/div&gt;&lt;p&gt;
Am I the only person -- well, besides &lt;a href="http://www.salon.com/news/opinion/glenn_greenwald/2010/03/29/mcconnell/index.html" target="_blank"&gt;Glenn Greenwald&lt;/a&gt; and&lt;a href="http://www.wired.com/threatlevel/2009/06/cyberthreat/" target="_blank"&gt; Kevin Poulson&lt;/a&gt; -- who thinks the "cyber-warfare" business may be overblown? It’s clear the U.S. national security establishment is paying a lot more attention to the issue, and colleagues of mine -- including some pretty serious and level-headed people -- are increasingly worried by the danger of some sort of "cyber-Katrina." I don't dismiss it entirely, but this sure looks to me like a classic opportunity for threat-inflation.&lt;/p&gt;&lt;p&gt;

Mind you, I'm not saying that there aren't a lot of shenanigans going on in cyber-space, or that various forms of cyber-warfare don't have military potential. So I'm not arguing for complete head-in-the-sand complacency. But here’s what makes me worry that the threat is being overstated.&lt;/p&gt;&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://walt.foreignpolicy.com/posts/2010/03/30/is_the_cyber_threat_overblown"&gt;walt.foreignpolicy.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;No, you're definitely not the only one.&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/is-the-cyber-threat-overblown-stephen-m-walt"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/is-the-cyber-threat-overblown-stephen-m-walt#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=sVpvKBSwVBM:j14-L9q82n0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=sVpvKBSwVBM:j14-L9q82n0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=sVpvKBSwVBM:j14-L9q82n0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=sVpvKBSwVBM:j14-L9q82n0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=sVpvKBSwVBM:j14-L9q82n0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/is-the-cyber-threat-overblown-stephen-m-walt</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 31 Mar 2010 10:24:28 -0700</pubDate>
      <title>Excerpts from s.773 as introduced in the U.S. Senate: Cybersecurity Act of 2009 « Payment Card Security &amp; IT Controls Explained</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/4ngD1oUKCMk/excerpts-from-s773-as-introduced-in-the-us-se</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/excerpts-from-s773-as-introduced-in-the-us-se</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;&lt;p&gt;The following are interesting excerpts from &lt;a href="http://www.opencongress.org/bill/111-s773/text"&gt;S.773&lt;/a&gt; that were of particular interest.  I strongly suggest reading the full bill and the included comments, as this will be impactful to global information technology security controls in the near future.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://pcidss.wordpress.com/2010/03/31/excerpts-from-s-773-as-introduced-in-the-u-s-senate-cybersecurity-act-of-2009/"&gt;pcidss.wordpress.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/excerpts-from-s773-as-introduced-in-the-us-se"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/excerpts-from-s773-as-introduced-in-the-us-se#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=4ngD1oUKCMk:D0dq0puSi9E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=4ngD1oUKCMk:D0dq0puSi9E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=4ngD1oUKCMk:D0dq0puSi9E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=4ngD1oUKCMk:D0dq0puSi9E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=4ngD1oUKCMk:D0dq0puSi9E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/excerpts-from-s773-as-introduced-in-the-us-se</feedburner:origLink></item>
    <item>
      <pubDate>Fri, 26 Mar 2010 09:39:25 -0700</pubDate>
      <title>ATA Secure Erase - ata Wiki</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/6q7VlSbaBx4/ata-secure-erase-ata-wiki</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/ata-secure-erase-ata-wiki</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote class="posterous_long_quote"&gt;This procedure describes how to use the &lt;a href="http://en.wikipedia.org/wiki/Hdparm" class="external text" title="http://en.wikipedia.org/wiki/Hdparm" rel="nofollow"&gt;hdparm&lt;/a&gt; command to issue a &lt;a href="http://en.wikipedia.org/wiki/AT_Attachment#HDD_Passwords_and_Security" class="external text" title="http://en.wikipedia.org/wiki/AT_Attachment#HDD_Passwords_and_Security" rel="nofollow"&gt;Secure Erase&lt;/a&gt; ATA instruction to a target storage device. When a Secure Erase is issued against a &lt;a href="http://en.wikipedia.org/wiki/Solid-state_drive" class="external text" title="http://en.wikipedia.org/wiki/Solid-state_drive" rel="nofollow"&gt;SSD&lt;/a&gt; drive all its cells will be marked as empty, restoring it to &lt;a href="http://www.anandtech.com/storage/showdoc.aspx?i=3531&amp;amp;p=8" class="external text" title="http://www.anandtech.com/storage/showdoc.aspx?i=3531&amp;amp;p=8" rel="nofollow"&gt;factory default write performance&lt;/a&gt;.&lt;/blockquote&gt;

&lt;div class="posterous_quote_citation"&gt;via &lt;a href="https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase"&gt;ata.wiki.kernel.org&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/ata-secure-erase-ata-wiki"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/ata-secure-erase-ata-wiki#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=6q7VlSbaBx4:c2g7cPWPiP8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=6q7VlSbaBx4:c2g7cPWPiP8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=6q7VlSbaBx4:c2g7cPWPiP8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=6q7VlSbaBx4:c2g7cPWPiP8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=6q7VlSbaBx4:c2g7cPWPiP8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/ata-secure-erase-ata-wiki</feedburner:origLink></item>
    <item>
      <pubDate>Wed, 24 Mar 2010 14:14:28 -0700</pubDate>
      <title>Law Enforcement Appliance Subverts SSL</title>
      <link>http://feedproxy.google.com/~r/CaffeinatedSecurity/~3/fky5Te7Iqwc/law-enforcement-appliance-subverts-ssl-0</link>
      <guid isPermaLink="false">http://caffeinatedsecurity.posterous.com/law-enforcement-appliance-subverts-ssl-0</guid>
      <description>&lt;p&gt;
	&lt;div class="posterous_bookmarklet_entry"&gt;
      &lt;blockquote&gt;&lt;div&gt;
            &lt;p&gt;&lt;a href="http://www.wired.com/images_blogs/threatlevel/2010/03/packet_forensics.jpg"&gt;&lt;img title="packet_forensics" src="http://www.wired.com/images_blogs/threatlevel/2010/03/packet_forensics.jpg" height="154" alt="packet_forensics" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.wired.com/images_blogs/threatlevel/2010/03/packet_forensics.jpg"&gt;&lt;/a&gt;That little lock on your browser window indicating you are communicating securely with your bank or e-mail account may not always mean what you think its means.&lt;/p&gt;
&lt;p&gt;Normally when a user visits a secure website, such as Bank of America, Gmail, PayPal or eBay, the browser examines the website’s certificate to verify its authenticity.&lt;/p&gt;
&lt;p&gt;At a recent wiretapping convention however, security researcher Chris Soghoian discovered that a small company was marketing internet spying boxes to the feds designed to intercept those communications, without breaking the encryption, by using forged security certificates, instead of the real ones that websites use to verify secure connections. To use the appliance, the government would need to acquire a forged certificate &amp;nbsp;from any one of more than 100 trusted Certificate Authorities.&lt;/p&gt;
&lt;p&gt;The attack is a classic man-in-the-middle attack, where Alice thinks she is talking directly to Bob, but instead Mallory found a way to get in the middle and pass the messages back and forth without Alice or Bob knowing she was there.&lt;/p&gt;
&lt;p&gt;The existence of a marketed product indicates the vulnerability is likely being exploited by more than just information-hungry governments, according to leading encryption expert &lt;a href="http://www.crypto.com/blog"&gt;Matt Blaze&lt;/a&gt;, a computer science professor at University of Pennsylvania.&lt;/p&gt;
&lt;p&gt;“If company is selling this to law enforcement and the intelligence community, it is not that large a leap to conclude that other, more malicious people have worked out the details of how to exploit this,” Blaze said.&lt;/p&gt;
&lt;p&gt;The company in question is known as Packet Forensics, which advertised its new Man-In-The-Middle capabilities in a brochure handed out at&amp;nbsp;the&amp;nbsp;&lt;a href="http://www.issworldtraining.com/ISS_WASH/"&gt;Intelligent Support Systems (ISS) conference&lt;/a&gt;,&amp;nbsp;a Washington DC wiretapping convention that typically bans the press. Soghoian attended the convention, notoriously capturing a &lt;a href="http://www.wired.com/threatlevel/2009/12/gps-data/"&gt;Sprint manager bragging&lt;/a&gt; about the huge volumes of surveillance requests it processes for the government.&lt;/p&gt;
&lt;p&gt;According to the flyer: “Users have the ability to import a copy of any legitimate key they obtain (potentially by court order) or they can generate ‘look-alike’ keys designed to give the subject a false sense of confidence in its authenticity.” The product is recommended to government investigators, saying “IP communication dictates the need to examine encrypted traffic at will” and “Your investigative staff will collect its best evidence while users are lulled into a false sense of security afforded by web, e-mail or VOIP encryption.”&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Packet Forensics doesn’t advertise the product on its website, and when contacted by Wired.com, asked how we found out about it. Company spokesman&amp;nbsp;Ray Saulino initially denied the product performed as advertised, or that anyone used it.&amp;nbsp;But in a follow-up call the next day, Saulino changed his stance.&lt;/p&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="posterous_quote_citation"&gt;via &lt;a href="http://www.wired.com/threatlevel/2010/03/packet-forensics/"&gt;wired.com&lt;/a&gt;&lt;/div&gt;
    &lt;p&gt;&lt;/p&gt;&lt;/div&gt;
	
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://caffeinatedsecurity.posterous.com/law-enforcement-appliance-subverts-ssl-0"&gt;Permalink&lt;/a&gt; 

	| &lt;a href="http://caffeinatedsecurity.posterous.com/law-enforcement-appliance-subverts-ssl-0#comment"&gt;Leave a comment&amp;nbsp;&amp;nbsp;&amp;raquo;&lt;/a&gt;

&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=fky5Te7Iqwc:6jU7wX-7u1k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=fky5Te7Iqwc:6jU7wX-7u1k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=fky5Te7Iqwc:6jU7wX-7u1k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?a=fky5Te7Iqwc:6jU7wX-7u1k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/CaffeinatedSecurity?i=fky5Te7Iqwc:6jU7wX-7u1k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
      <posterous:author>
        <posterous:userImage>http://files.posterous.com/user_profile_pics/409756/_Media_Card_BlackBerry_pictures_IMG00046.jpg</posterous:userImage>
        <posterous:profileUrl>http://posterous.com/users/36K9ZOAFtbjP</posterous:profileUrl>
        <posterous:firstName>Kyle</posterous:firstName>
        <posterous:lastName>Maxwell</posterous:lastName>
        <posterous:nickName>technoskald</posterous:nickName>
        <posterous:displayName>Kyle Maxwell</posterous:displayName>
      </posterous:author>
    <feedburner:origLink>http://caffeinatedsecurity.posterous.com/law-enforcement-appliance-subverts-ssl-0</feedburner:origLink></item>
  </channel>
</rss>

