<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Network Security Blog</title><link>http://www.mckeay.net</link><description>The views of one man on security, privacy and anything else that catches his attention</description><language>en</language><image><link>http://www.mckeay.net</link><url>http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo144.jpg</url><title>Network Security Blog</title><width>144</width><height>144</height></image><copyright>©</copyright><managingEditor>martin@mckeay.net</managingEditor><lastBuildDate>Wed, 15 Jul 2009 08:21:19 PDT</lastBuildDate><generator>http://wordpress.org/?v=abc</generator><sy:updatePeriod xmlns:sy="http://purl.org/rss/1.0/modules/syndication/">hourly</sy:updatePeriod><sy:updateFrequency xmlns:sy="http://purl.org/rss/1.0/modules/syndication/">1</sy:updateFrequency><itunes:keywords /><itunes:subtitle>Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.</itunes:subtitle><itunes:summary>Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.</itunes:summary><itunes:author>Martin McKeay</itunes:author><itunes:block>No</itunes:block><itunes:explicit>no</itunes:explicit><itunes:image href="http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo300.jpg" /><media:copyright>©</media:copyright><media:thumbnail url="http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo300.jpg" /><media:keywords></media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Tech News</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Tech News</media:category><itunes:owner><itunes:email>netsecpodcast@mckeay.net</itunes:email><itunes:name>Martin McKeay</itunes:name></itunes:owner><itunes:category text="Technology"><itunes:category text="Tech News" /></itunes:category><itunes:category text="Technology"><itunes:category text="Tech News" /></itunes:category><geo:lat>38.440111</geo:lat><geo:long>-122.745633</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/MartinMckeaysNetworkSecurityBlog" type="application/rss+xml" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>The Network Security Podcast, Episode 158</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/0GKR7WX3vWo/</link><category>Podcast</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Wed, 15 Jul 2009 05:54:17 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/07/15/the-network-security-podcast-episode-158/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>The bulk of this episode is an interview I did with Steve Ocepek, one of my <a href="http://www.trustwave.com">Trustwave coworkers</a> who is presenting at Black Hat this year. But before we get to the interview, we do spend a little time talking about some of this week&#8217;s security headlines. And if you are attending Black Hat, don&#8217;t forget to look us up.</p>
<p>
<p><a href="https://www.blackhat.com/html/bh-usa-09/bh-us-09-main.html"><img style="max-width: 800px;" src="http://netsecpodcast.com/wp-content/uploads/2009/07/bh09_468x601.gif" /></a></p>
<p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-071409-ep158.mp3">Network Security Podcast, Episode 158<br />Time:&nbsp; 45:35<br /></a></p>
<p>
<p></p>
<p><u><b>Show Notes</b></u>:</p>
<p>
<p></p>
<ul>
<li><a href="http://www.chron.com/disp/story.mpl/tech/news/6525301.html">Wardriving passports</a></li>
<p>
<p></p>
<li><a href="http://threatpost.com/blogs/microsoft-plugs-critical-windows-ie-vulnerabilities">Microsoft</a> and <a href="http://threatpost.com/blogs/highly-critical-bug-bites-firefox-35">Firefox</a> vulnerabilities (some unpatched) being exploited in the wild.</li>
<p>
<p></p>
<li><a href="http://blog.bkis.com/?p=718">What a shock, the DDoS attacks probably weren&#8217;t from North Korea.</a> I think their entire Internet connectivity is a phone line with an acoustic modem.</li>
<p>
<p></p>
<li>Tonight&#8217;s Music: <a href="http://www.musicalley.com/music/producers/producerLibrary/artistdetails.php?BandHash=e13783cc8cea6cb362080052f8451417">Impact at 1000mph by LtMeat</a></li>
<p>
<p></p>
<p></ul>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F15%2Fthe-network-security-podcast-episode-158%2F&amp;title=The+Network+Security+Podcast%2C+Episode+158" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/0GKR7WX3vWo" height="1" width="1"/>]]></content:encoded><description>The bulk of this episode is an interview I did with Steve Ocepek, one of my Trustwave coworkers who is presenting at Black Hat this year. But before we get to the interview, we do spend a little time talking about some of this week&amp;#8217;s security headlines. And if you are attending Black Hat, don&amp;#8217;t [...]</description><enclosure url="http://media.libsyn.com/media/mckeay/nsp-071409-ep158.mp3" length="43771925" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/07/15/the-network-security-podcast-episode-158/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><media:content url="http://media.libsyn.com/media/mckeay/nsp-071409-ep158.mp3" fileSize="43771925" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>Podcast</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2009/07/15/the-network-security-podcast-episode-158/</feedburner:origLink></item><item><title>Episodes 8 &amp; 9 of the FIRST Podcast</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/7Lx4Go6OFQE/</link><category>General</category><category>Podcast</category><category>Social Networking</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Mon, 13 Jul 2009 09:20:27 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/07/13/episodes-8-9-of-the-first-podcast/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Peter Allor is one of the two people who tapped me cover the 21st FIRST Conference in Kyoto.&nbsp; Pete is a member of the FIRST Steering Committee and the Conference Liaison and took a couple of minutes out of the conference to speak to me on how the conference was going.&nbsp; </p>
<p><a href="http://media.first.org/podcasts/FIRST2009-PeterAllor.mp3" target="_blank">Episode 8: Peter Allor, FIRST SC and Conference Liaison</a></p>
<p>Toby Weir-Jones from BT gave a talk titled &#8220;Deriving information from raw data: making business decisions with logs&#8221;.&nbsp; We consider why it&#8217;s so hard to translate our log files into something that we can use to communicate with other business units who don&#8217;t speak the same language.</p>
<p><a href="http://media.first.org/podcasts/FIRST2009-TobyWeirJones.mp3" target="_blank">Episode 9: Toby Weir-Jones, VP Product Development, Managed Security Solutions Group, BT</a></p>
<p></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F13%2Fepisodes-8-9-of-the-first-podcast%2F&amp;title=Episodes+8+%26%23038%3B+9+of+the+FIRST+Podcast" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/7Lx4Go6OFQE" height="1" width="1"/>]]></content:encoded><description>Peter Allor is one of the two people who tapped me cover the 21st FIRST Conference in Kyoto.&amp;#160; Pete is a member of the FIRST Steering Committee and the Conference Liaison and took a couple of minutes out of the conference to speak to me on how the conference was going.&amp;#160; 
Episode 8: Peter Allor, [...]</description><enclosure url="http://media.first.org/podcasts/FIRST2009-PeterAllor.mp3" length="5125250" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/07/13/episodes-8-9-of-the-first-podcast/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><media:content url="http://media.first.org/podcasts/FIRST2009-PeterAllor.mp3" fileSize="5125250" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>General, Podcast, Social Networking</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2009/07/13/episodes-8-9-of-the-first-podcast/</feedburner:origLink></item><item><title>You lick it, you keep it</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/_FCa1L_xSKg/</link><category>Humor</category><category>Phishing, scams, etc.</category><category>Risk</category><category>Simple Security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Sat, 11 Jul 2009 09:55:47 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/07/11/you-lick-it-you-keep-it/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Some encounters are almost too strange to believe.&nbsp; That doesn&#8217;t make them any less real.</p>
<p>I was walking down the street in San Francisco at lunch time Friday afternoon.&nbsp; As I came up to a busy street corner I saw a paper grocery bag sitting on a bench with no one around it.&nbsp; I walked up to the bag and peeked in to find three external hard drives, one Maxtor and two brands I didn&#8217;t recognize.&nbsp; The drives looked like they were either well used or the product of a dumpster dive.&nbsp; I knocked on the door of the one business nearby, but no one answered.&nbsp; After a few minutes someone came out who worked in the building; he said there&#8217;d been a break-in recently but that he didn&#8217;t know anything about the drives.&nbsp; I tried to call Rich for advice, but he was busy so I decided I&#8217;d finish my walk to lunch and think on the situation for a little while.</p>
<p>One burrito later, I walked up on the scene again.&nbsp; This time a homeless man in dirty, ripped slacks was surveying the bag of hard drives.&nbsp; He looked around much like I had done thirty minutes earlier, then scuttled up to the bag and pulled out one of the external hard drives.&nbsp; After sniffing it for a second, he licked one side of the drive and put it back in the bag.&nbsp; He then ran over to a parking meter and licked it, licked the taillights on both sides of an SUV and vanished from my sight behind the car.&nbsp; </p>
<p>I lost any interest in the hard drives at that point.&nbsp; That takes mom&#8217;s caution of &#8220;you don&#8217;t know where that&#8217;s been&#8221; to a whole new level.</p>
<p>Saliva incident aside, what would you do if you found a bag of hard drives in a park or public place?&nbsp; Calling 911 didn&#8217;t seem appropriate, though there is a slim possiblity of explosives.&nbsp; Taking the drives home and performing some forensics research on them crossed my mind; I have the technology if not much skill in the area.&nbsp; I tried to turn them in to the business, but there was no one there.&nbsp; I guess the gentlemen with the inquisitive taste buds saved me from a moral dilema.&nbsp; </p>
<p>What would you have done?</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F11%2Fyou-lick-it-you-keep-it%2F&amp;title=You+lick+it%2C+you+keep+it" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/_FCa1L_xSKg" height="1" width="1"/>]]></content:encoded><description>Some encounters are almost too strange to believe.&amp;#160; That doesn&amp;#8217;t make them any less real.
I was walking down the street in San Francisco at lunch time Friday afternoon.&amp;#160; As I came up to a busy street corner I saw a paper grocery bag sitting on a bench with no one around it.&amp;#160; I walked up [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/07/11/you-lick-it-you-keep-it/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">14</slash:comments><feedburner:origLink>http://www.mckeay.net/2009/07/11/you-lick-it-you-keep-it/</feedburner:origLink></item><item><title>Network Security Podcast, Episode 157</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/N2eS-qjtxGw/</link><category>Podcast</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 07 Jul 2009 20:39:30 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/07/07/network-security-podcast-episode-157/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I can&#8217;t entirely promise tonight&#8217;s episode makes a lot of sense. Martin is back from Kyoto, and seriously jetlagged, and I don&#8217;t think I was a whole lot better. Sure, we cover the usual collection of security news, but the episode is filled with non-sequitors and other dissociated transitions. On the other hand, we do stick fairly closely to security related topics. In other words, listen at your own risk.</p>
<p>[Martin]It made perfect sense before I said it out loud.&nbsp; Afterward, not so much.[/Martin]</p>
<p><a href="https://www.blackhat.com/html/bh-usa-09/bh-us-09-main.html"><img style="max-width: 800px;" src="http://netsecpodcast.com/wp-content/uploads/2009/07/bh09_468x601.gif" /></a></p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-070709-ep157.mp3">Network Security Podcast, Episode 157<br />Time:&nbsp; 25:08<br /></a></p>
<p><p><u><b>Show Notes</b></u>:</p>
<ul>
<li><a href="http://www.threatpost.com/blogs/mass-attacks-exploiting-0-day-directshow%3Cbr/%3E">Microsoft 0day being exploited in the wild.</a></li>
<li><a href="http://fcw.com/Articles/2009/07/06/COMMENT-China-fears-us-as-we-fear-them.aspx">China is as scared of us as we are of them.</a> See? Your mom was right.</li>
<li><a href="http://tech.yahoo.com/news/pcworld/20090702/tc_pcworld/applepatchingserioussmsvulnerabilityoniphone">iPhones are vulnerable over SMS.</a> I highly doubt the iPhone is the only phone with this problem.</li>
<li><a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml;jsessionid=EKENNIXYMP20MQSNDLOSKHSCJUNN2JVN?articleID=218300006">A &#8220;security guard&#8221; hacks a hospitals HVAC system.</a> Then goes to jail for additional stupidity. Good thing most bad guys are dumb, or we&#8217;d *really* be in trouble.</li>
<li><a href="http://arstechnica.com/tech-policy/news/2009/07/social-insecurity-numbers-open-to-hacking.ars">More nails in the coffin that holds your Social Security Number.</a></li>
</ul>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fnetwork-security-podcast-episode-157%2F&amp;title=Network+Security+Podcast%2C+Episode+157" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/N2eS-qjtxGw" height="1" width="1"/>]]></content:encoded><description>I can&amp;#8217;t entirely promise tonight&amp;#8217;s episode makes a lot of sense. Martin is back from Kyoto, and seriously jetlagged, and I don&amp;#8217;t think I was a whole lot better. Sure, we cover the usual collection of security news, but the episode is filled with non-sequitors and other dissociated transitions. On the other hand, we do [...]</description><enclosure url="http://media.libsyn.com/media/mckeay/nsp-070709-ep157.mp3" length="17642729" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/07/07/network-security-podcast-episode-157/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><media:content url="http://media.libsyn.com/media/mckeay/nsp-070709-ep157.mp3" fileSize="17642729" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>Podcast</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2009/07/07/network-security-podcast-episode-157/</feedburner:origLink></item><item><title>Back from the FIRST Conference</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/Ef9sp8twmAs/</link><category>Blogging</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 07 Jul 2009 06:25:25 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/07/07/back-from-the-first-conference/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Back from the FIRST Conference in Kyoto, Japan with a dozen interviews and over 1500 pictures.&nbsp; To be fair, my wife took a lot of the pictures.&nbsp; I haven&#8217;t had time to <a href="http://www.flickr.com/photos/mmckeay/sets/72157620885233886/"><img style="max-width: 800px; float: right; margin-top: 10px; margin-bottom: 10px; margin-left: 10px;" src="http://farm3.static.flickr.com/2454/3688170102_230cd2c94a_m.jpg" /></a>blog or while I was at FIRST, but you can get a very good idea of what was going on by checking out <a href="http://c22blog.wordpress.com/">Chris Riley&#8217;s blog</a>.&nbsp; He took awesome notes, something I&#8217;m only moderately successful at under the best of circumstances.&nbsp; I&#8217;ll be uploading the interviews over the next few weeks and have several follow up interviews to do with people who didn&#8217;t have the time necessary during the conference.&nbsp; But all of that has to wait until I&#8217;ve dug myself out from the pile of email that accumulated while I was on the road.&nbsp; In the mean time, check out some of the <a href="http://www.flickr.com/photos/mmckeay/sets/72157620885233886/">photos I&#8217;ve uploaded to Flickr</a> so far.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F07%2F07%2Fback-from-the-first-conference%2F&amp;title=Back+from+the+FIRST+Conference" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/Ef9sp8twmAs" height="1" width="1"/>]]></content:encoded><description>Back from the FIRST Conference in Kyoto, Japan with a dozen interviews and over 1500 pictures.&amp;#160; To be fair, my wife took a lot of the pictures.&amp;#160; I haven&amp;#8217;t had time to blog or while I was at FIRST, but you can get a very good idea of what was going on by checking out [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/07/07/back-from-the-first-conference/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><feedburner:origLink>http://www.mckeay.net/2009/07/07/back-from-the-first-conference/</feedburner:origLink></item><item><title>The Network Security Podcast, Episode 156</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/rJIYXQd405o/</link><category>Podcast</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 30 Jun 2009 17:18:52 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/06/30/the-network-security-podcast-episode-156/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Martin is off in Japan this week, so I&#8217;m joined by our good friend <a href="http://techbuddha.wordpress.com">Amrit Williams from BigFix and the Techbuddha blog</a>. Amrit and I start off by talking about the rolling blackouts in California and disaster preparedness, before jumping into the week&#8217;s security news. </p>
<p>&lt;Martin&gt;&nbsp; I&#8217;m off in Japan, but not forgotten.&nbsp; I&#8217;m almost afraid to listen to my podcast!&nbsp; You&#8217;d think that by now I&#8217;d have gotten comfortable handing off the podcast while I&#8217;m away by now&lt;/Martin&gt;</p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-063009-ep156.mp3">Network Security Podcast, Episode 156<br />Time:&nbsp; 41:28<br /></a></p>
<p><u><b>Show Notes</b></u>:</p>
<ul>
<li><a href="http://www.nytimes.com/2009/06/29/technology/internet/29wiki.html?_r=1">The New York Times and Wikipedia censor reports of a captured reporter to protect him.</a></li>
<p>
<li><a href="http://daveshackleford.com/?p=211">Dave Shackleford on 10 things your auditor doesn&#8217;t want you to know.</a></li>
<p>
<li><a href="http://www.eweek.com/c/a/Security/Trojan-Swipes-FTP-Credentials-for-Major-Companies-in-Malware-Attack-340752/">Trojan steals FTP credentials</a></li>
<p>
<li><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1360597,00.html?track=sy160">Juniper pulls ATM hacking talk from Black Hat</a></li>
<p>
<li><a href="http://blogs.zdnet.com/security/?p=3673">Most systems have unpatched software.</a> Is anyone surprised?</li>
<p>
<li>Tonight&#8217;s Music:&nbsp; <i>Since i haven&#8217;t figured out how to get the podcasting rights to Jimmy Buffett&#8217;s entire collection, there&#8217;s no music for tonight&#8217;s close.</i></li>
<p><i><br /></i>
</p>
</ul>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F30%2Fthe-network-security-podcast-episode-156%2F&amp;title=The+Network+Security+Podcast%2C+Episode+156" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/rJIYXQd405o" height="1" width="1"/>]]></content:encoded><description>Martin is off in Japan this week, so I&amp;#8217;m joined by our good friend Amrit Williams from BigFix and the Techbuddha blog. Amrit and I start off by talking about the rolling blackouts in California and disaster preparedness, before jumping into the week&amp;#8217;s security news. 
&amp;#60;Martin&amp;#62;&amp;#160; I&amp;#8217;m off in Japan, but not forgotten.&amp;#160; I&amp;#8217;m almost [...]</description><enclosure url="http://media.libsyn.com/media/mckeay/nsp-063009-ep156.mp3" length="38578888" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/06/30/the-network-security-podcast-episode-156/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><media:content url="http://media.libsyn.com/media/mckeay/nsp-063009-ep156.mp3" fileSize="38578888" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>Podcast</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2009/06/30/the-network-security-podcast-episode-156/</feedburner:origLink></item><item><title>FIRST 2009: Dr. Suguru Yamaguchi</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/Q0FXOa4skpA/</link><category>General</category><category>Podcast</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Mon, 29 Jun 2009 19:32:05 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/06/29/first-2009-dr-suguru-yamaguchi/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I had the opportunity to talk to Dr. Suguru Yamaguchi, Professor of the Graduate School of Information at the Nara Institute of Science and Technology, member of the JPCERT and advisor on Information Security for the National Information Security Center, Cabinet Office Japan.&nbsp; Dr. Yamaguchi presented the opening keynote for the FIRST 2009 Conference here in Kyoto, Japan and talked about Information Security Management&nbsp; and Economic Crisis.&nbsp; And at least as interesting for me was having my questions translated into Japanese and asked to Dr. Yamaguchi again to answer in his native language.&nbsp; </p>
<p>Two of the points I found intensely interesting about Dr. Yamaguchi&#8217;s talk were his assertion that businesses should be investing in technology during the down turn rather than cutting back, because the investment now may be what enables there survival and his observation that compromises have an affect on company sales in the Asia Pacific region.&nbsp; I don&#8217;t believe we&#8217;re seeing the same sort of downturn in sales when a compromise happens to an American company and would like to know why there is such a difference. <br /><a href="http://media.first.org/podcasts/FIRST2009-Dr-Yamaguchi-Japanese.mp3"><br />FIRST 2009 Episode 7:&nbsp; Interview with Dr. Suguru Yamaguchi &#8211; Japanese</a></p>
<p><a href="http://media.first.org/podcasts/FIRST2009-Dr-Yamaguchi-English.mp3">FIRST 2009 Episode 7:&nbsp; Interview with Dr. Suguru Yamaguchi &#8211; English</a></p>
<p></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F29%2Ffirst-2009-dr-suguru-yamaguchi%2F&amp;title=FIRST+2009%3A+Dr.+Suguru+Yamaguchi" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/Q0FXOa4skpA" height="1" width="1"/>]]></content:encoded><description>I had the opportunity to talk to Dr. Suguru Yamaguchi, Professor of the Graduate School of Information at the Nara Institute of Science and Technology, member of the JPCERT and advisor on Information Security for the National Information Security Center, Cabinet Office Japan.&amp;#160; Dr. Yamaguchi presented the opening keynote for the FIRST 2009 Conference here [...]</description><enclosure url="http://media.first.org/podcasts/FIRST2009-Dr-Yamaguchi-Japanese.mp3" length="12665234" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/06/29/first-2009-dr-suguru-yamaguchi/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><media:content url="http://media.first.org/podcasts/FIRST2009-Dr-Yamaguchi-Japanese.mp3" fileSize="12665234" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>General, Podcast</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2009/06/29/first-2009-dr-suguru-yamaguchi/</feedburner:origLink></item><item><title>Heading to Kyoto:  Who do you want to hear from?</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/wReTfUNUQz0/</link><category>Podcast</category><category>Simple Security</category><category>Social Networking</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Thu, 25 Jun 2009 06:10:50 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/06/25/heading-to-kyoto-who-do-you-want-to-hear-from/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>The wife and I are all packed, the house sitter has been briefed (&#8221;Just don&#8217;t burn down the house while we&#8217;re gone&#8221;) and we&#8217;re heading off to the airport in a few minutes to fly to Kyoto, Japan to attend the <a href="http://conference.first.org/">21st annual FIRST Conference</a>.&nbsp; The folks at FIRST have tapped me to be the media sponsor for the event this year and I&#8217;ll be blogging, tweeting and conducting interviews live on the floor of the conference.&nbsp; There is a very interesting group of international speakers who all work in the incident response field, some (like me) less than others.&nbsp; So here&#8217;s my question to you:&nbsp; Who would you like to hear me interview from the <a href="http://conference.first.org/program/program.aspx">list of speakers in Kyoto</a>?&nbsp; Leave a comment on the blog, tweet me (<a href="http://twitter.com/mckeay">@mckeay</a>) or send me an email and I&#8217;ll do my best to get an interview with your target of choice.&nbsp; The interviews will be posted within a few weeks after the conference and I&#8217;ll try to sneak one or two in while I&#8217;m there.</p>
<p>Note to <a href="http://securosis.com/">Rich</a>:&nbsp; Don&#8217;t burn down the <a href="http://netsecpodcast.com/">podcast</a> while I&#8217;m gone!</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2Fheading-to-kyoto-who-do-you-want-to-hear-from%2F&amp;title=Heading+to+Kyoto%3A++Who+do+you+want+to+hear+from%3F" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/wReTfUNUQz0" height="1" width="1"/>]]></content:encoded><description>The wife and I are all packed, the house sitter has been briefed (&amp;#8221;Just don&amp;#8217;t burn down the house while we&amp;#8217;re gone&amp;#8221;) and we&amp;#8217;re heading off to the airport in a few minutes to fly to Kyoto, Japan to attend the 21st annual FIRST Conference.&amp;#160; The folks at FIRST have tapped me to be the [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/06/25/heading-to-kyoto-who-do-you-want-to-hear-from/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.mckeay.net/2009/06/25/heading-to-kyoto-who-do-you-want-to-hear-from/</feedburner:origLink></item><item><title>10 Things Dave wants you to know about auditors</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/CRr3ZgSNnvU/</link><category>PCI</category><category>Simple Security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Thu, 25 Jun 2009 05:47:05 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/06/25/10-things-dave-wants-you-to-know-about-auditors/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><font face="sans-serif">I really wish I could disagree more with Dave Shackleford and his post, <a href="http://daveshackleford.com/?p=211">10 Things Your Auditor Isn&#8217;t Telling You</a>, but I think he&#8217;s really hit it on the head with this one.&nbsp; And hit it hard.&nbsp; </font>He starts the post by saying he&#8217;s not trying to be mean, but as a PCI QSA, there are a couple of times I had cringe, because it really hits close to home.&nbsp; It&#8217;s tough, because some of the points he makes are almost unavoidable in an audit process while others are signs of an industry that needs more skilled practitioners than are currently available.&nbsp; And his final point is definitely true: the people at a company I&#8217;m assessing may like me as a person, but I have yet to meet someone who actually likes the process of being assessed and doesn&#8217;t channel at least a little of the dislike back to the assessor.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F25%2F10-things-dave-wants-you-to-know-about-auditors%2F&amp;title=10+Things+Dave+wants+you+to+know+about+auditors" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/CRr3ZgSNnvU" height="1" width="1"/>]]></content:encoded><description>I really wish I could disagree more with Dave Shackleford and his post, 10 Things Your Auditor Isn&amp;#8217;t Telling You, but I think he&amp;#8217;s really hit it on the head with this one.&amp;#160; And hit it hard.&amp;#160; He starts the post by saying he&amp;#8217;s not trying to be mean, but as a PCI QSA, there [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/06/25/10-things-dave-wants-you-to-know-about-auditors/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><feedburner:origLink>http://www.mckeay.net/2009/06/25/10-things-dave-wants-you-to-know-about-auditors/</feedburner:origLink></item><item><title>The Network Security Podcast, Episode 155</title><link>http://feedproxy.google.com/~r/MartinMckeaysNetworkSecurityBlog/~3/YYAx2HytYe0/</link><category>Podcast</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 23 Jun 2009 16:57:54 PDT</pubDate><guid isPermaLink="false">http://www.mckeay.net/2009/06/23/the-network-security-podcast-episode-155/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>We start the show off by wishing Martin luck with his presentation at the FIRST conference in Kyoto, foolishly trusting Rich with the keys to the podcast. Then Rich fawns over his iPhone 3GS a little too much, but he does manage to talk about some cool new security features.</p>
<p>Rich also rants a little on one of our PCI stories, and Martin updates us on his XBox wireless situation. Finally, we geek out a bit on Adam Savage appearing at DefCon.</p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-062309-ep155.mp3">Network Security Podcast, Episode 155<br />Time:&nbsp; 35:28<br /></a></p>
<p><u><b>Show Notes</b></u>:</p>
<ul>
<li><a href="http://blogs.wsj.com/middleseat/2009/06/22/un-clear-registered-traveler-company-shuts-down/">The Clear Card finally dies.</a> What a scam.</li>
<li><a href="http://www.threatpost.com/blogs/mozilla-tackles-xss-vulnerabilities-clickjacking-attacks">Mozilla reveals some new ways of combating XSS and Clickjacking.</a> A positive move, but with a lot of caveats.</li>
<li><a href="http://www.infoworld.com/t/security/weve-been-blind-attacks-our-web-sites-516">An end user talks about his experiences with a WAF.</a></li>
<li><a href="http://www.dhs.gov/journal/theblog">DHS has a blog.</a></li>
<li><a href="http://www.boazgelbord.com/2009/06/nevada-mandates-pci-standard.html">Nevada mandates PCI.</a> Even for non-credit card PII that wouldn&#8217;t normally be covered.</li>
<li><a href="http://www.mckeay.net/2009/06/22/nfr-letter-to-the-pci-council/">The National Retail Foundation whines about PCI.</a> What a silly responses- back to the drawing board guys. I don&#8217;t think you&#8217;ve even read the standard.</li>
<li><a href="http://www.cafepress.com/asscert">Get your Certified Application Security Specialist hats, shirts, and other gear.</a></li>
<li>Tonight&#8217;s Music:&nbsp; <a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=03210c91c966b600854491407831d95d">Reggae Far East with Cost Cut Japan</a></li>
<p></ul>
<p></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2009%2F06%2F23%2Fthe-network-security-podcast-episode-155%2F&amp;title=The+Network+Security+Podcast%2C+Episode+155" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/YYAx2HytYe0" height="1" width="1"/>]]></content:encoded><description>We start the show off by wishing Martin luck with his presentation at the FIRST conference in Kyoto, foolishly trusting Rich with the keys to the podcast. Then Rich fawns over his iPhone 3GS a little too much, but he does manage to talk about some cool new security features.
Rich also rants a little on [...]</description><enclosure url="http://media.libsyn.com/media/mckeay/nsp-062309-ep155.mp3" length="34053956" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2009/06/23/the-network-security-podcast-episode-155/feed/</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><media:content url="http://media.libsyn.com/media/mckeay/nsp-062309-ep155.mp3" fileSize="34053956" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>Podcast</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2009/06/23/the-network-security-podcast-episode-155/</feedburner:origLink></item><media:credit role="author">Martin McKeay</media:credit><media:rating>nonadult</media:rating><media:description type="plain">Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.</media:description></channel></rss>
