<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>SecMusings</title>
	
	<link>http://shermansolutionsllc.com/secmusings</link>
	<description>Andy's Reflections on Technology and Security</description>
	<lastBuildDate>Fri, 10 Feb 2012 13:39:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Secmusings" /><feedburner:info uri="secmusings" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><geo:lat>40.798502</geo:lat><geo:long>-73.96811</geo:long><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecmusings" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecmusings" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecmusings" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Secmusings" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecmusings" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FSecmusings" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecmusings" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item>
		<title>FBI and the Yard vs Anonymous: a must-read analysis</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/dmdIATnpkY0/100</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/100#comments</comments>
		<pubDate>Fri, 10 Feb 2012 13:39:59 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=100</guid>
		<description><![CDATA[I&#8217;m not going to comment at length, just tell you that Steve Bellovin has a great analysis of the recent incident where Anonymous eavesdropped on a conference call between the FBI and Scotland Yard. As usual, Steve zeroes right in on the poor practices that allowed this to happen.  Go read it.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not going to comment at length, just tell you that Steve Bellovin has a great <a href="https://www.cs.columbia.edu/~smb/blog//2012-02/2012-02-05.html">analysis of the recent incident </a>where Anonymous eavesdropped on a conference call between the FBI and Scotland Yard. As usual, Steve zeroes right in on the poor practices that allowed this to happen.  Go read it.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=dmdIATnpkY0:DrLU7V2jJEI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/100/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/100</feedburner:origLink></item>
		<item>
		<title>The wider lesson from a college admissions glitch</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/CRe0gsODUn4/92</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/92#comments</comments>
		<pubDate>Wed, 01 Feb 2012 20:39:09 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Random Musings]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=92</guid>
		<description><![CDATA[My alma mater, Vassar College, has been in the news lately over an error in it&#8217;s admissions web site, which led 76 early decision applicants to believe they had been admitted when they had not. As the Times tells it: On Friday, around 4 p.m., 122 students who had applied for binding early admission to Vassar [...]]]></description>
			<content:encoded><![CDATA[<p>My alma mater,<em> </em>Vassar College, has been in the <a href="http://www.nytimes.com/2012/01/31/nyregion/after-mistake-a-mea-culpa-from-vassar.html#">news</a> <a href="http://www.pcmag.com/article2/0,2817,2399524,00.asp">lately</a> over an error in it&#8217;s admissions web site, which led 76 early decision applicants to believe they had been admitted when they had not. As the Times tells it:</p>
<blockquote><p>On Friday, around 4 p.m., 122 students who had applied for binding early admission to Vassar saw what the school later called a “test letter” congratulating them on their acceptance. Hours later, the students received a message saying the letter had been posted in error. Once the correct decisions were displayed, only 46 of the students were told they had been accepted.</p></blockquote>
<p>Vassar has since sent apologies to the students, to all of us alumnae/i, and other interested parties.  They are refunding the application fees for the rejected students. There has been some debate in the blogosphere and elsewhere about whether or not these applicants should have been admitted anyway.</p>
<p>For technologists, this speaks to the cost of the error, but the interesting part is the underlying cause.  This looks to me like yet another example of the bad things that happen when testing is done in the production environment. In this case 76 teenagers involved in what was already a very stressful process were forced to ride an emotional roller coaster of disappointment and embarrassment.  In other cases there can be large financial and even regulatory consequences when test transactions were accidentally put onto production systems and sent to counter-parties. Most senior technologists know a horror story or three on this topic, although they don&#8217;t like sharing them.</p>
<p>While there is increasing recognition of the need to better segregate production and test environments, it is both expensive and inconvenient to do so. In times of budgetary restraint, projects to fix this problem can get postponed until the next accident happens. I think companies would be wiser to work on this gradually and incrementally.  Trying to do nothing and trying to do everything all at once are equally unrealistic.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=CRe0gsODUn4:H6tbrWnFr1Y:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/92/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/92</feedburner:origLink></item>
		<item>
		<title>Security Thought Leadership</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/8JCJWI3OBg8/73</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/73#comments</comments>
		<pubDate>Sun, 27 Feb 2011 20:54:40 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Random Musings]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=73</guid>
		<description><![CDATA[Hat tip to Brian Krebs for this one.  Also congratulations to Brian for winning a security blogger award at the RSA Conference.  One of his fellow winners, Chris Eng, won an award for the best single blog post for this wonderful piece. (Thanks to xtranormal.com for providing the embedding code on their website.  The original post may [...]]]></description>
			<content:encoded><![CDATA[<p>Hat tip to <a href="http://krebsonsecurity.com/2011/02/krebsonsecurity-com-wins-award/" target="_blank">Brian Krebs</a> for this one.  Also congratulations to Brian for winning a security blogger award at the RSA Conference.  One of his fellow winners, Chris Eng, won an award for the best single blog post for this wonderful piece. (Thanks to xtranormal.com for providing the embedding code on their website.  The original post may be found at <a href="http://www.xtranormal.com/watch/7897173">http://www.xtranormal.com/watch/7897173</a>.)</p>
<p>
<object width="480" height="390"><param name="movie" value="http://www.xtranormal.com/site_media/players/jwplayer.swf"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><param name="flashvars"value="height=301&#038;width=499&#038;file=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.mp4&#038;image=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.jpg&#038;link=http://www.xtranormal.com/watch/7897173&#038;searchbar=false&#038;autostart=false"/><embed src="http://www.xtranormal.com/site_media/players/jwplayer.swf" width="499" height="301" allowscriptaccess="always" allowfullscreen="true" flashvars="height=301&#038;width=499&#038;file=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.mp4&#038;image=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.jpg&#038;link=http://www.xtranormal.com/watch/7897173&#038;searchbar=false&#038;autostart=false"></embed></object><object width="480" height="390"><param name="movie" value="http://www.xtranormal.com/site_media/players/embedded-xnl-stats.swf"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.xtranormal.com/site_media/players/embedded-xnl-stats.swf" width="1" height="1" allowscriptaccess="always"></embed></object></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=8JCJWI3OBg8:piJnuWIKu08:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/73/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/73</feedburner:origLink></item>
		<item>
		<title>Attachment or Link?</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/AJWNJg1Gou0/67</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/67#comments</comments>
		<pubDate>Mon, 27 Jul 2009 23:57:18 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=67</guid>
		<description><![CDATA[Steve Bellovin has an interesting analysis of the question &#8220;which is a better way to send a file, as an attachment or as a link?&#8221; The discussion centers around the process of opening a file in either a mail user agent or a web browser, and how vulnerabilities in each get tickled. There is no [...]]]></description>
			<content:encoded><![CDATA[<p>Steve Bellovin has an interesting analysis of the question <a href="http://www.cs.columbia.edu/~smb/blog/2009-07/2009-07-23.html">&#8220;which is a better way to send a file, as an attachment or as a link?&#8221;</a> The discussion centers around the process of opening a file in either a mail user agent or a web browser, and how vulnerabilities in each get tickled.  There is no clear hands down winner, although since sending links is also more courteous he gives that a slight nod.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=AJWNJg1Gou0:BFoFfKEmnDQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/67/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/67</feedburner:origLink></item>
		<item>
		<title>Password Security</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/Gn8BNjqVmdc/62</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/62#comments</comments>
		<pubDate>Fri, 24 Jul 2009 14:38:24 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=62</guid>
		<description><![CDATA[From our friends at XKCD:]]></description>
			<content:encoded><![CDATA[<p>From our friends at XKCD:</p>
<p><a href="http://xkcd.com/538/"><img src="http://imgs.xkcd.com/comics/security.png" alt="" /></a></p>
<p><a></a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=Gn8BNjqVmdc:IRRgdD_inRg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/62/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/62</feedburner:origLink></item>
		<item>
		<title>No Free Lunch</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/SAnR4Y6NDX0/57</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/57#comments</comments>
		<pubDate>Fri, 24 Jul 2009 13:58:39 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[General Technology]]></category>
		<category><![CDATA[We can't make this stuff up]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=57</guid>
		<description><![CDATA[A hat tip to Spaf for this one. Hillary Clinton held a town hall for State Department employees recently, where a recent transfer from one of the intelligence agencies asked why they couldn&#8217;t have Firefox, which was approved by NSA for use in the intel community.  Secretary Clinton turned to one of her aides, Patrick [...]]]></description>
			<content:encoded><![CDATA[<p>A hat tip to <a href="http://blog.spaf.us">Spaf</a> for this one.  Hillary Clinton held a town hall for State Department employees recently, where a recent transfer from one of the intelligence agencies asked why they couldn&#8217;t have Firefox, which was approved by NSA for use in the intel community.  Secretary Clinton turned to one of her aides, Patrick Kennedy, who replied that they had to look into the budgetary issues.  This drew cries of &#8220;but it&#8217;s free&#8221; from the crowd, which then got the &#8220;nothing is really free&#8221; explanation.</p>
<p>This explanation drew snarky hoots of derision from <a href="http://www.theregister.co.uk/2009/07/13/firefox_and_us_state_department/">The Register</a> and <a href="http://gizmodo.com/5315634/us-state-department-rejects-firefox-which-is-entirely-free-due-to-expense-questions">Gizmodo</a>, both of whom ridicule the notion that a piece of free software could cost anything to manage.</p>
<p>Clearly, you don&#8217;t have to actually know anything about managing IT to write about it for these publications.  <em>There is no such thing a &#8220;free&#8221; software, if by that you mean that the total cost of ownership is zero. </em>Here&#8217;s what it takes to deploy Firefox to tens of thousands of desktops:</p>
<ul>
<li>Decide what lockdowns you need in your environment and build a local build of Firefox that implements.</li>
<li>If you care about plugins, include in the lockdowns a restriction that plugins come from a local repository of approved ones.</li>
<li>Package it.</li>
<li>Distribute it.</li>
<li>Support it.</li>
<li>Rinse and repeat for each patch release.</li>
</ul>
<p>What you can&#8217;t do in an environment where the user desktop is a managed resource is have users download and self-maintain a complex security-sensitive piece of software.  I&#8217;ve worked in organizations that decided that the costs of doing the above was worth spending.  But there was no illusion that supporting Firefox was free.  Even a &#8220;best effort&#8221; support model requires people to execute it.</p>
<p>One encouraging note was that lots of IT professionals gave these articles the comments they deserved.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=SAnR4Y6NDX0:O2qIrxMXvBY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/57/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/57</feedburner:origLink></item>
		<item>
		<title>Cybersecurity Bill of 2009</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/QsLkLDjwePg/51</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/51#comments</comments>
		<pubDate>Mon, 27 Apr 2009 14:16:18 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Policy and Compliance]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=51</guid>
		<description><![CDATA[Steve Bellovin has an excellent analysis of the CyberSecurity Bill of 2009 on his blog. It is a long and thoughtful piece that you should read for yourself rather than having me try to summarize it.]]></description>
			<content:encoded><![CDATA[<p>Steve Bellovin has an excellent analysis of the <a href="http://www.cs.columbia.edu/~smb/blog/2009-04/2009-04-12.html">CyberSecurity Bill of 2009</a> on his blog.  It is a long and thoughtful piece that you should read for yourself rather than having me try to summarize it.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=QsLkLDjwePg:3yqhGCnkyus:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/51/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/51</feedburner:origLink></item>
		<item>
		<title>Devolution</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/_xlmg81SSyo/46</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/46#comments</comments>
		<pubDate>Thu, 23 Apr 2009 03:14:56 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[We can't make this stuff up]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=46</guid>
		<description><![CDATA[A hat tip to Bruce Schneir for spotting this one.  The BBC is reporting that the NHS Central Lancashire backed up health data on 6,360 prisoners and ex-prisoners by copying it on to a USB stick. They even encrypted the data. Then they lost the stick. With a yellow sticky attached to it with the [...]]]></description>
			<content:encoded><![CDATA[<p>A hat tip to <a href="http://www.schneier.com/blog/archives/2009/04/lessons_in_key.html">Bruce Schneir</a> for spotting this one.  The <a href="http://news.bbc.co.uk/1/hi/england/lancashire/8003757.stm">BBC</a> is reporting that the NHS Central Lancashire backed up health data on 6,360 prisoners and ex-prisoners by copying it on to a USB stick.  They even encrypted the data.</p>
<p>Then they lost the stick.</p>
<p>With a yellow sticky attached to it with the password.</p>
<p>We really can&#8217;t make this stuff up.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=_xlmg81SSyo:ezDtZmKYKiE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/46/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/46</feedburner:origLink></item>
		<item>
		<title>Captcha? Gotcha</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/NBRIJ9958Yw/36</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/36#comments</comments>
		<pubDate>Mon, 06 Apr 2009 13:04:09 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Random Musings]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=36</guid>
		<description><![CDATA[Beware of security questions that you didn&#8217;t create!  From XKCD (http://xkcd.com/565/)]]></description>
			<content:encoded><![CDATA[<p>Beware of security questions that you didn&#8217;t create!  From XKCD (http://xkcd.com/565/)</p>
<p><img class="alignnone" title="Security Question" src="http://imgs.xkcd.com/comics/security_question.png" alt="" width="459" height="133" /></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=NBRIJ9958Yw:C9-zsAJzLI8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/36/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/36</feedburner:origLink></item>
		<item>
		<title>Not out of the Conficker woods yet</title>
		<link>http://feedproxy.google.com/~r/Secmusings/~3/rPkrQ8E3Zlk/33</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/33#comments</comments>
		<pubDate>Sun, 05 Apr 2009 15:12:21 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=33</guid>
		<description><![CDATA[Dan Kaminsky has a very good call for continued vigilance against Conficker. Entitled &#8220;A Marathon, Not a Sprint&#8221; he writes: Of course, you may be thinking:  The world didn&#8217;t come to an end.  Clearly, this whole thing was just a Y2K hypefest.  I&#8217;m sorry the bad guys aren&#8217;t quite the eschatologists some people would like [...]]]></description>
			<content:encoded><![CDATA[<p>Dan Kaminsky has a very good <a href="http://www.doxpara.com/?p=1300/trackback/">call for continued vigilance against Conficker.</a> Entitled &#8220;A Marathon, Not a Sprint&#8221; he writes:</p>
<blockquote><p>Of course, you may be thinking:  The world didn&#8217;t come to an end.  Clearly, this whole thing was just a Y2K hypefest.  I&#8217;m sorry the bad guys aren&#8217;t quite the eschatologists some people would like them to be, but <em>somebody&#8217;s</em> been investing extraordinary amounts of resources making a worm very difficult to kill.  It&#8217;s not like there was a contingent of rogue coders, sitting around figuring out where they could put two-character date fields after January 1st, 2001.  There&#8217;s a bad guy out there, and while we shouldn&#8217;t panic, we shouldn&#8217;t quite ignore the situation either.</p></blockquote>
<p>I agree with his advice.  Don&#8217;t panic, but don&#8217;t drop your guard either.  Now that network based scanners can spot this, the owners of enterprise networks should be scanning and cleaning up.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Secmusings?a=rPkrQ8E3Zlk:sYmijJ5Jol4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Secmusings?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/33/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://shermansolutionsllc.com/secmusings/archives/33</feedburner:origLink></item>
	</channel>
</rss>

