<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-1170804302338772081</atom:id><lastBuildDate>Thu, 14 Jan 2010 07:33:23 +0000</lastBuildDate><title>Security Idiot</title><description>Stupidity In Depth: Tales of Woe About IT Security Pros.</description><link>http://www.securityidiot.com/</link><managingEditor>noreply@blogger.com (Security Idiot)</managingEditor><generator>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SecurityIdiot" /><feedburner:info uri="securityidiot" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>SecurityIdiot</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-333947178647626630</guid><pubDate>Tue, 13 Jan 2009 20:05:00 +0000</pubDate><atom:updated>2009-01-13T12:45:11.174-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">stud</category><category domain="http://www.blogger.com/atom/ns#">cosmetic surgery</category><category domain="http://www.blogger.com/atom/ns#">twitter</category><category domain="http://www.blogger.com/atom/ns#">rentboy</category><category domain="http://www.blogger.com/atom/ns#">playboy</category><title>Bring on the Hotness: Alex Sotirov</title><description>It gives us great pride and deep stirrings to draw your attention to a recent (ish) tweet by Alex Sotirov - formerly VMware playboy, now Independent Exploiter (watch out ladies) and www 0wner (now do it for SHA1 ;-).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_WucRlPJkB74/SWz5UXtkkrI/AAAAAAAAACo/GVjMWMyAkHI/s1600-h/Twitter+_+Alexander+Sotirov_+Check+out+who+made+it+into+....jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 199px;" src="http://4.bp.blogspot.com/_WucRlPJkB74/SWz5UXtkkrI/AAAAAAAAACo/GVjMWMyAkHI/s400/Twitter+_+Alexander+Sotirov_+Check+out+who+made+it+into+....jpg" alt="" id="BLOGGER_PHOTO_ID_5290877790611346098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Rarely does Tinyurl instill this much anticipation...&lt;br /&gt;&lt;br /&gt;Lo and behold...sure enough at no. 00000110:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_WucRlPJkB74/SWz7PwAAaLI/AAAAAAAAACw/gugIGoXG_TE/s1600-h/violet+blue+%C2%AE+__+open+source+sex+%7C+top+ten+sexy+geeks+2009.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 581px; height: 155px;" src="http://2.bp.blogspot.com/_WucRlPJkB74/SWz7PwAAaLI/AAAAAAAAACw/gugIGoXG_TE/s400/violet+blue+%C2%AE+__+open+source+sex+%7C+top+ten+sexy+geeks+2009.jpg" alt="" id="BLOGGER_PHOTO_ID_5290879910255028402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;We promise there was no Photoshop action involved here - and that doesn't look like the Alex that we've seen steaming up the Infosec conventions but hell, he made in the top 10 and you and me didn't.&lt;br /&gt;&lt;br /&gt;What a modest Twit!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-333947178647626630?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/ZspTK-6gydM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/ZspTK-6gydM/bring-on-hotness-alex-sotirov.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_WucRlPJkB74/SWz5UXtkkrI/AAAAAAAAACo/GVjMWMyAkHI/s72-c/Twitter+_+Alexander+Sotirov_+Check+out+who+made+it+into+....jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2009/01/bring-on-hotness-alex-sotirov.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-5899866595527222593</guid><pubDate>Tue, 14 Oct 2008 07:46:00 +0000</pubDate><atom:updated>2008-10-14T01:39:05.247-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">mitnick</category><title>Security Idiot Welcomes Kevin Mitnick!</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_WucRlPJkB74/SPRYDCxuMnI/AAAAAAAAACY/2XzRGw3Pg14/s1600-h/samp7b5b393bda12857a.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_WucRlPJkB74/SPRYDCxuMnI/AAAAAAAAACY/2XzRGw3Pg14/s320/samp7b5b393bda12857a.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5256923474356482674" /&gt;&lt;/a&gt;Kevin was recently travelling to a security conference where he was due to demonstrate his lock-picking equipment...ahem..."moderate a panel at a security conference sponsored by the American Society for Industrial Security (ASIS)" when his number came up.  As he arrived in Atlanta he was stopped by border security and invited to give a guided tour of his belongings.&lt;br /&gt;&lt;br /&gt;The highlight of the 'consultation' came when he was asked to provide evidence of his ASIS attendance.  Instead of travelling with a pre-printed itinerary and handing that to the border inspectors he had to pull his laptop and then right in front of the officials he...&lt;br /&gt;&lt;br /&gt;1. Deleted his firefox private data...("Just say Yes")&lt;br /&gt;2. Promptly hit the power off button as the officials grabbed the laptop suspecting he was erasing evidence.&lt;br /&gt;&lt;br /&gt;This tale could be called 'How To Freak Out Border Inspectors Who Already Suspect You Are Shady'.&lt;br /&gt;&lt;br /&gt;Nevertheless, Mitnick was keen to point out that client data was not exposed in any way (Ed: just copied) and that in future he plans to clone himself and travel as a Mitnick swarm in order to conduct birthday attacks on random border guards ("Is it me? Is it me?).&lt;br /&gt;&lt;br /&gt;We admire Kevin as he spoke with a CNet reporter:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"There was uncertainty, fear, and panic because I didn't know what was going on, and I didn't do anything wrong," he said in a recent telephone interview with CNET News. "In my mind, I thought I was being set up for something."&lt;/blockquote&gt;If you want to read the rest of the story, including the part about "his package" discovered to have traces of cocaine you won't find us talking about that here.  You'll have to go &lt;a href="http://news.cnet.com/8301-1009_3-10054569-83.html?part=rss&amp;amp;subj=news&amp;amp;tag=2547-1_3-0-20"&gt;here&lt;/a&gt; instead.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-5899866595527222593?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/PsaDBg0VeMk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/PsaDBg0VeMk/security-idiot-welcomes-kevin-mitnick.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_WucRlPJkB74/SPRYDCxuMnI/AAAAAAAAACY/2XzRGw3Pg14/s72-c/samp7b5b393bda12857a.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/10/security-idiot-welcomes-kevin-mitnick.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-1574946808876680353</guid><pubDate>Sun, 27 Jul 2008 16:02:00 +0000</pubDate><atom:updated>2008-07-27T09:31:03.317-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">dns</category><category domain="http://www.blogger.com/atom/ns#">ptacek</category><category domain="http://www.blogger.com/atom/ns#">halvar</category><category domain="http://www.blogger.com/atom/ns#">kaminsky</category><title>Thomas Ptacek: Too Quick By Far!</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_WucRlPJkB74/SIyik26eNXI/AAAAAAAAACQ/Zlzx2DLbTR8/s1600-h/samp5186073619f8ddb8.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_WucRlPJkB74/SIyik26eNXI/AAAAAAAAACQ/Zlzx2DLbTR8/s200/samp5186073619f8ddb8.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5227732021570057586" /&gt;&lt;/a&gt;&lt;br /&gt;This weeks nomination for SecurityIdiot (TM) goes to Thomas Ptacek.&lt;br /&gt;&lt;br /&gt;In fact, we think he nominated himself.&lt;br /&gt;&lt;br /&gt;Summary:&lt;br /&gt;- Dan finds big DNS bug&lt;br /&gt;- co-ordinates with Vixie, CERT et al - fixes get prepared&lt;br /&gt;- Dan announces to world + dog: "patch now, I'll disclose in 4 weeks at BlackHat" &lt;br /&gt;- Doubting Thomas proclaims the bug can't be all that serious&lt;br /&gt;- Dan confides in Thomas, who does an about turn and announces 'Its the real deal'&lt;br /&gt;- Mucho guessing on DailyDave mailing list&lt;br /&gt;- Halvar - who really should have been studying for his exams - chimes in with his theory&lt;br /&gt;- Thomas tells Halvar - via the Matasano blog - 'By jove, you've gone and guessed what that Kaminsky fella told me down the pub about his DNS sploit'.&lt;br /&gt;- Story catches fire, exploits are written&lt;br /&gt;- Thomas goes 'Duh' and publishes below apology...&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Earlier today, a security researcher posted their hypothesis regarding Dan Kaminsky’s DNS finding. Shortly afterwards, when the story began getting traction, a post appeared on our blog about that hypothesis. It was posted in error. We regret that it ran. We removed it from the blog as soon as we saw it. Unfortunately, it takes only seconds for Internet publications to spread.&lt;br /&gt;&lt;br /&gt;We dropped the ball here....&lt;/blockquote&gt;&lt;br /&gt;Continues at the &lt;a href="http://www.matasano.com/log/1105/regarding-the-post-on-chargen-earlier-today/"&gt;Matasano Chargen Blog&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-1574946808876680353?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/yns_2scqnc4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/yns_2scqnc4/thomas-ptacek-too-quick-by-far.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp3.blogger.com/_WucRlPJkB74/SIyik26eNXI/AAAAAAAAACQ/Zlzx2DLbTR8/s72-c/samp5186073619f8ddb8.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/thomas-ptacek-too-quick-by-far.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-8828076723705921837</guid><pubDate>Wed, 23 Jul 2008 19:31:00 +0000</pubDate><atom:updated>2008-07-23T12:38:25.388-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">word challenged</category><category domain="http://www.blogger.com/atom/ns#">haxxor</category><title>Future Vulnerability Researcher?</title><description>Grasping the linga franca of your mother tongue is sometimes a waste of neurons.&lt;br /&gt;&lt;br /&gt;If you want to be a kick-ass vulnerability researcher, less is sometimes more.&lt;br /&gt;&lt;br /&gt;Your formative years could be better spent studying Intel developer manuals.&lt;br /&gt;&lt;br /&gt;Watch this video to determine if you may be harbouring someone in your family that has haxxor tendancies...&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;object width="325" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/gKaUL2mtAqA&amp;#038;hl=en&amp;#038;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/gKaUL2mtAqA&amp;#038;hl=en&amp;#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="325" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;Courtesy of &lt;a href="http://beastorbuddha.com/2008/07/18/does-this-remind-me-of-some-haxors/"&gt;Beast or Bhudda&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-8828076723705921837?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/fnnAiZ6K-U8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/fnnAiZ6K-U8/future-vulnerability-researcher.html</link><author>noreply@blogger.com (Security Idiot)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/future-vulnerability-researcher.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-4377754228608458945</guid><pubDate>Wed, 23 Jul 2008 14:20:00 +0000</pubDate><atom:updated>2008-07-23T07:40:05.735-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">pwnie</category><category domain="http://www.blogger.com/atom/ns#">failures</category><title>Pwnie Awards: Keepin' It Real</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://pwnie-awards.org/2008/pwnie.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px;" src="http://pwnie-awards.org/2008/pwnie.png" alt="" border="0" /&gt;&lt;/a&gt;Back again at Black Hat this year, the Pwnie awards...&lt;br /&gt;&lt;br /&gt;"An annual awards ceremony celebrating and making fun of the achievements         and failures of security researchers and the wider security community".&lt;br /&gt;&lt;br /&gt;Look what you could have been nominated for:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Best Server-Side Bug&lt;/li&gt;&lt;li&gt;Best Client-Side Bug&lt;/li&gt;&lt;li&gt;Mass 0wnage&lt;/li&gt;&lt;li&gt;Most Innovative Research&lt;/li&gt;&lt;li&gt;Lamest Vendor Response&lt;/li&gt;&lt;li&gt;Most Overhyped Bug&lt;/li&gt;&lt;li&gt;Best Song&lt;/li&gt;&lt;li&gt;Most Epic FAIL&lt;/li&gt;&lt;li&gt;Lifetime Achievement Award&lt;/li&gt;&lt;/ul&gt;Obviously here at securityidiot.com, we're most interested in the 'Most Epic FAIL' category (although Best Song could swing it).  Lamest Vendor Response may feature but then we'd get lost in Press Release clippings.&lt;br /&gt;&lt;br /&gt;Stay tuned for further updates!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pwnie-awards.org/2008/index.html"&gt;Source&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-4377754228608458945?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/5ysAaEaQRZM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/5ysAaEaQRZM/pwnie-award-keepin-it-real.html</link><author>noreply@blogger.com (Security Idiot)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/pwnie-award-keepin-it-real.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-8700139932227845385</guid><pubDate>Thu, 17 Jul 2008 07:59:00 +0000</pubDate><atom:updated>2008-07-17T01:22:15.035-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">terminology</category><title>Impress Your Peers With Your Grasp of IT Security Terminology</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_WucRlPJkB74/SH8A6j0fi3I/AAAAAAAAACI/HZ8aN7bxKOY/s1600-h/samp94cfc7542e60241a.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_WucRlPJkB74/SH8A6j0fi3I/AAAAAAAAACI/HZ8aN7bxKOY/s200/samp94cfc7542e60241a.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5223895098820889458" /&gt;&lt;/a&gt;&lt;div&gt;To truly dominate in the IT security field, its vital to be able to 'talk the talk' - the rest can come later.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;What follows is an insiders guide to help you apply the right terminology at the right time.  Many people tie themselves up in knots with poor use of IT security terminology.  Frankly, there's a lot of misunderstanding out there.&lt;br /&gt;&lt;br /&gt;Cut through the fog with this helping list.  Impress you peers!&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;24/7&lt;/span&gt;&lt;br /&gt;The window of time in which systems are most vulnerable to attack.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;BC/DR (Business Continuity/Disaster Recovery Planning)&lt;/span&gt;&lt;br /&gt;An alternate spelling for "CISO".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Biometrics&lt;/span&gt;&lt;br /&gt;Strong authentication mechanism that streamlines insider attacks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Business case&lt;/span&gt;&lt;br /&gt;A creative writing project, the quality of which is directly proportional to your security budget.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Confidentiality, integrity and availability&lt;/span&gt;&lt;br /&gt;The three great myths of the Internet Age.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Cryptography&lt;/span&gt;&lt;br /&gt;The science of applying a complex set of mathematical algorithms to sensitive data with the aim of making Bruce Schneier exceedingly rich.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Cybercrime&lt;/span&gt;&lt;br /&gt;Crime.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Downtime&lt;/span&gt;&lt;br /&gt;Refers to computer systems' natural state; the opposite of anticipated downtime.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;E-Commerce&lt;/span&gt;&lt;br /&gt;A historical fad (fashion) from the late '90s meant to generate hundreds of billions of dollars in new profits; the inciting factor that generated hundreds of billions of dollars being spent on security products.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Firewalls&lt;/span&gt;&lt;br /&gt;Speed bumps.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Hackers&lt;/span&gt;&lt;br /&gt;Self-righteous crackers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Help desk&lt;/span&gt;&lt;br /&gt;A place where rude people read instruction manuals to confused people over the phone, for a fee.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Identity theft&lt;/span&gt;&lt;br /&gt;The transfer of your personally identifying information from corporations that want to exploit it to hackers who want to exploit it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Intrusion Detection Systems (IDS)&lt;/span&gt;&lt;br /&gt;Log file generators.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;JOOTT ("jute")&lt;/span&gt;&lt;br /&gt;Acronym for Just One Of Those Things; the primary explanation for most information security problems.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Laptop&lt;/span&gt;&lt;br /&gt;A computer designed to allow employees to easily store vast amounts of customer data in the backseat of a taxicab.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Logging&lt;/span&gt;&lt;br /&gt;The practice of filling shelves with printouts.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Logical security&lt;/span&gt;&lt;br /&gt;A goal; also, an oxymoron (contradition).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Mission critical&lt;/span&gt;&lt;br /&gt;Term used to help hackers identify their targets.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Non-repudiation&lt;/span&gt;&lt;br /&gt;The opposite of repudiation; repudiation, only not.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;O.S. hardening&lt;/span&gt;&lt;br /&gt;An attempt to secure your operating system against the next hack by closing the hole used by the previous one&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Passwords&lt;/span&gt;&lt;br /&gt;Authentication tool that, when properly implemented, drives growth at the help desk&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Patching&lt;/span&gt;&lt;br /&gt;A mandatory fool's errand.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Pharming and phishing&lt;/span&gt;&lt;br /&gt;Ways to obtain phood (i. e. food).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;PKI (Public-Key Infrastructure)&lt;/span&gt;&lt;br /&gt;A system designed to transfer all of the complexities of strong authentication onto end users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Regression testing&lt;/span&gt;&lt;br /&gt;The process by which you learn how the patches that fixed your system also broke your system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Road warriors&lt;/span&gt;&lt;br /&gt;Traveling employees responsible for delivering malicious code back to headquarters.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Scope creep&lt;/span&gt;&lt;br /&gt;Stage three of the standard software development model.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Security administrator&lt;/span&gt;&lt;br /&gt;Firefighter.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Security officer&lt;/span&gt;&lt;br /&gt;Fall guy.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Total Cost of Ownership (TCO)&lt;/span&gt;&lt;br /&gt;In security, an incalculable number always equal to or greater than the budget.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Upgrade&lt;/span&gt;&lt;br /&gt;The process by which you introduce new vulnerabilities into software.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Virus&lt;/span&gt;&lt;br /&gt;Sort of like a worm, but not exactly.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Worm&lt;/span&gt;&lt;br /&gt;Similar to a virus, but different.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Zombie&lt;/span&gt;&lt;br /&gt;See "Distributed Denial of Service".&lt;br /&gt;&lt;br /&gt;From &lt;a href="http://ismspt.blogspot.com/2006/01/funny-information-security-dictionary.html"&gt;Comunidade ISMS PT&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-8700139932227845385?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/qwJuNdyzJ3Q" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/qwJuNdyzJ3Q/impress-your-peers-with-your-grasp-of.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp2.blogger.com/_WucRlPJkB74/SH8A6j0fi3I/AAAAAAAAACI/HZ8aN7bxKOY/s72-c/samp94cfc7542e60241a.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/impress-your-peers-with-your-grasp-of.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-2331841844867992440</guid><pubDate>Tue, 15 Jul 2008 07:12:00 +0000</pubDate><atom:updated>2008-07-15T02:02:34.054-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">twitter</category><category domain="http://www.blogger.com/atom/ns#">hoff</category><title>Stop Following Me on Twitter: Hoff Launches Unprovoked Simile Attack On His Twitiples</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_WucRlPJkB74/SHxTOk1K2zI/AAAAAAAAACA/YF1rpY77m4U/s1600-h/unfollow.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_WucRlPJkB74/SHxTOk1K2zI/AAAAAAAAACA/YF1rpY77m4U/s200/unfollow.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5223141177712892722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Security is like Escargot. It's crunchy on the outside, chewy on the inside, and like everything else, should be blamed on the French!&lt;/li&gt;&lt;li&gt;Security is like Kimchee...to make it you have to slap it together, bury it and then dig it up when it smells to explain how special it is..&lt;/li&gt;&lt;li&gt;Security is like Durian: It's lousy in airports, stinks when exposed and looks oddly out of place no matter how you slice it...&lt;/li&gt;&lt;li&gt;Security is like fertilizer, the more shit you spread around the worse it gets and watering it down only makes it worse&lt;/li&gt;&lt;li&gt;Security is like a vibrator...&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Continued at &lt;a href="http://rationalsecurity.typepad.com/blog/2008/07/visualizing-sec.html"&gt;Rational Survivability&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-2331841844867992440?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/6hKIEAM5pCo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/6hKIEAM5pCo/stop-following-me-on-twitter-hoff.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp2.blogger.com/_WucRlPJkB74/SHxTOk1K2zI/AAAAAAAAACA/YF1rpY77m4U/s72-c/unfollow.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/stop-following-me-on-twitter-hoff.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-9084770054745574134</guid><pubDate>Fri, 11 Jul 2008 21:24:00 +0000</pubDate><atom:updated>2008-07-11T15:13:55.182-07:00</atom:updated><title>How I Lost a Contest Involving Chihuahuas</title><description>&lt;div align="left"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_WucRlPJkB74/SHfW66htvdI/AAAAAAAAABg/gropkdqNQiI/s1600-h/samp3a78858a1f78b939.jpg"&gt;&lt;img style="float:left; margin:0 0 10px 10px;cursor:pointer; cursor:hand;" src="http://bp1.blogger.com/_WucRlPJkB74/SHfW66htvdI/AAAAAAAAABg/gropkdqNQiI/s200/samp3a78858a1f78b939.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5221878600590802386" /&gt;&lt;/a&gt;&lt;br /&gt;"So my lovely gfnd’s co-worker enrolled her pet Chihuahua into a contest to rate the dog against others of the same breed in the local area. Vaguely amused, I took a look at the web application and sure enough, it pretty much sucked. &lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;The developers had used a client side code in Flash to make it so that you couldn’t submit twice, but in re-loading the app you could (and that’s how the newbs in her office were cheating). I, however, looked at what data it was sending and sure enough I could send votes by bypassing the client side app entirely. I took the cheating to a whole new level...."&lt;/div&gt;&lt;p&gt;&lt;a href="http://ha.ckers.org/blog/20080709/how-i-lost-a-contest-involving-chihuahuas/"&gt;Continued here&lt;/a&gt;&lt;/p&gt;&lt;p&gt;[kudos to the anonymous reader for the tip]&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-9084770054745574134?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/pZ6UnneWM8g" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/pZ6UnneWM8g/how-i-lost-contest-involving-chihuahuas.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp1.blogger.com/_WucRlPJkB74/SHfW66htvdI/AAAAAAAAABg/gropkdqNQiI/s72-c/samp3a78858a1f78b939.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/how-i-lost-contest-involving-chihuahuas.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-2712919648072345599</guid><pubDate>Fri, 11 Jul 2008 11:30:00 +0000</pubDate><atom:updated>2008-07-11T15:04:20.194-07:00</atom:updated><title>Is It Easier To Get Fired in IT Security As Say A Security Officer on a USAF Installation?</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_WucRlPJkB74/SHfYuOYU7PI/AAAAAAAAABw/yQbr6Slv3ik/s1600-h/samp801dc8fb2ec74194.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;" src="http://bp1.blogger.com/_WucRlPJkB74/SHfYuOYU7PI/AAAAAAAAABw/yQbr6Slv3ik/s200/samp801dc8fb2ec74194.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5221880581605092594" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;Or, what about getting fired on your day off?&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;You drop your wife at the hairdressers and you need to find something to do.  What could possibly go wrong?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;Favorite quote:&lt;/span&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px; font-size:14px;"&gt;“Hell no, we’re not conducting a sting operation in that area or any&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px; font-size:14px;"&gt;area for that matter.” He then ended the conversation with, “Arrest&lt;br /&gt;his ass, and confiscate his badge!”&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;a href="http://maoden99.wordpress.com/2008/07/11/how-a-security-officer-got-fired-on-his-day-off/"&gt;Source&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(68, 68, 68);  line-height: 23px;font-size:14px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-2712919648072345599?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/vhMQ20FmniI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/vhMQ20FmniI/is-it-easier-to-get-fired-in-it.html</link><author>noreply@blogger.com (Security Idiot)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp1.blogger.com/_WucRlPJkB74/SHfYuOYU7PI/AAAAAAAAABw/yQbr6Slv3ik/s72-c/samp801dc8fb2ec74194.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/is-it-easier-to-get-fired-in-it.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-2541686247215135599</guid><pubDate>Thu, 10 Jul 2008 17:21:00 +0000</pubDate><atom:updated>2008-07-10T10:32:45.298-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">defintion</category><title>Are You A Security Idiot?</title><description>&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold; "&gt;You Are "A Security Idiot" If&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold; "&gt;  you...&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Misspell both HIPAA and SOX (how the f does one misspell SOX?)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Confuse "risks" and "threats"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Think that "Trojan is a vulnerability" AND "DoS is a vulnerability"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Quote "Insiders are 80%" without thinking for one darn second&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Think that a loss of "$20 million is catastrophic to any company"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Talk about "NIST compliance"&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Consider IDS a network security control&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Shout that "perimeter is dead"&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Please add your faves to the list and we can create an official list to be used to expose fake experts. If you think that nobody in our industry is that stupid ... think again. F*ck!&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://chuvakin.blogspot.com/2008/06/you-are-security-idiot-if.html"&gt;Source&lt;/a&gt; (with permission)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;[update] More &lt;a href="http://chuvakin.blogspot.com/search/label/stupidity"&gt;Stupidity&lt;/a&gt; from Anton :P&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-2541686247215135599?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/7RlVAxPhLI8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/7RlVAxPhLI8/are-you-security-idiot.html</link><author>noreply@blogger.com (Security Idiot)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/are-you-security-idiot.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1170804302338772081.post-3679282778109307062</guid><pubDate>Thu, 10 Jul 2008 15:22:00 +0000</pubDate><atom:updated>2008-07-10T08:45:24.837-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">launch</category><title>Blog Launch</title><description>Greetings!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This blog is dedicated to IT Security Professionals that do stupid, idiotic, brain-dead security things.  These could be operational mishaps, dumb technology decisions or strategy decisions that leave an org more vulnerable (and poorer) than when the IT Pro walked in the door.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A few examples to whet the appetite:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;misconfiguring routing tables on mission critical firewalls to bring production networks to a screaching halt&lt;/li&gt;&lt;li&gt;implementing a non-SSL aware NIDS on a segment that only has HTTPS traffic&lt;/li&gt;&lt;li&gt;declaring to management that secure email best practices require selecting a white font color on a white background when sending sensitive messages&lt;/li&gt;&lt;li&gt;screwing up an arpspoof attack during a pen-test, becoming "man-on-the-end" and downing a production network&lt;/li&gt;&lt;li&gt;spending all the security budget on the latest network security gizmo when the outside door to the data center doesn't shut properly.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;It is *not* about non-IT Security Professionals that do stupid, idiotic, brain-dead security things.  This is assumed (no offense lusers!).&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The site is powered by you, the reader.  You submit stories and if they're funny enough we'll post 'em.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you have witnessed a truly idiotic action by someone that claims to be an IT Security Professional, email us at securityidiot@gmail.com.  No need to name names - in fact, if you do, we can't post it - sorry.  &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;All postings will be strictly anonymous.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Send us your "over beer" stories, we'll figure out what works as we go along...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The SecurityIdiot team.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;P.S Curious about the &lt;a href="http://www.secmeme.com/2008/07/new-meme-security-idiot.html"&gt;origin&lt;/a&gt; of "Security Idiot"? &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1170804302338772081-3679282778109307062?l=www.securityidiot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityIdiot/~4/iGROH8QCCHs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/SecurityIdiot/~3/iGROH8QCCHs/blog-launch.html</link><author>noreply@blogger.com (Security Idiot)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.securityidiot.com/2008/07/blog-launch.html</feedburner:origLink></item></channel></rss>
