<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>The Ashimmy Blog</title><link>http://www.ashimmy.com/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/StillsecureAfterAllTheseYears" /><description>Writings on work, kids and network security</description><language>en</language><lastBuildDate>Mon, 23 Jan 2012 10:52:32 PST</lastBuildDate><generator>TypePad http://www.typepad.com/</generator><feedburner:info uri="stillsecureafteralltheseyears" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>copyright 2010 all rights reserved</media:copyright><media:thumbnail url="http://ashimmy.podomatic.com/mymedia/thumb/1143272/460%3E_2340028.jpg" /><media:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Tech News</media:category><itunes:owner><itunes:email>ashimmy@hotmail.com</itunes:email><itunes:name>Alan Shimel</itunes:name></itunes:owner><itunes:author>Alan Shimel</itunes:author><itunes:explicit>no</itunes:explicit><itunes:image href="http://ashimmy.podomatic.com/mymedia/thumb/1143272/460%3E_2340028.jpg" /><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><itunes:subtitle>Security, technology and the state of things with Mitchell and Alan</itunes:subtitle><itunes:summary>Security, technology and the state of things with Mitchell and Alan</itunes:summary><itunes:category text="Technology"><itunes:category text="Tech News" /></itunes:category><creativeCommons:license>http://creativecommons.org/licenses/by/2.5/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by/2.5/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>StillsecureAfterAllTheseYears</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item><title>Just Another Risk Podcast  NOT</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/XKI5DNeMfKM/just-another-risk-podcast-not.html</link><category>podcasting</category><category>security tips</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 23 Jan 2012 10:54:33 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e20168e5f6e37f970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Continuing my series of podcasts on all things Risk, I have another great one in this episode.&#160; I am joined by an all star panel of <strong>HD Moore</strong>, CSO of <a href="http://www.rapid7.com">Rapid7</a> and founder of Metasploit, <strong>Ron Gula</strong>, CEO and CTO of <a href="http://www.tenable.com">Tenable Network Security</a> and <strong>Jody Brazil</strong>, founder and President of <a href="http://www.firemon.com/">Firemon</a>. With that kind of talent, this is not just another Risk Podcast!</p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20168e5f6e346970c-pi"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="hdjodyron" border="0" alt="hdjodyron" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20168e5f6e377970c-pi" width="535" height="260" /></a></p>  <p>The four of us discuss some common mistakes people make in risk management.&#160; How vulnerability and pen testing figure into the Risk equation. We even manage to discuss scenario based risk management as exemplified in the Firemon Risk Analyzer.&#160; </p>  <p>Having smart people on the show makes my job easy and fun. This was a very easy and fun podcast. I hope you enjoy!</p> <OBJECT width=440 height=85><PARAM NAME="wmode" VALUE="transparent"><PARAM NAME="menu" VALUE="false"><PARAM NAME="movie" VALUE="http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf"><PARAM NAME="flashvars" VALUE="minicast=false&amp;jsonLocation=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2012-01-23T08_24_00-08_00%3Fcolor%3D43bee7%26autoPlay%3Dfalse%26facebook%3Dtrue%26height%3D85%26minicast%3Dfalse%26objembed%3D1%26width%3D440"><PARAM NAME="allowFullScreen" VALUE="true"><PARAM NAME="allowscriptaccess" VALUE="always"> <embed src="http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf" flashvars="minicast=false&jsonLocation=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2012-01-23T08_24_00-08_00%3Fcolor%3D43bee7%26autoPlay%3Dfalse%26facebook%3Dtrue%26height%3D85%26minicast%3Dfalse%26objembed%3D1%26width%3D440" wmode="transparent" menu="false" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" version="10.0.0" width="440" height="85"></embed></embed></embed></embed></embed></embed> </OBJECT>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/have-we-got-risk-all-wrong.html">Have We Got Risk All Wrong?</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/risk-risk-risk.html">Risk, Risk, Risk</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-episode-108.html">Tenable Network Security Podcast Episode 108</a> (tenablesecurity.com) </li>      <li class="zemanta-article-ul-li"><a href="http://normanmarks.wordpress.com/2012/01/20/risk-objectives-strategy-and-performance/">The inter-relationships of risk, objectives, strategy and performance</a> (normanmarks.wordpress.com)</li>      <li class="zemanta-article-ul-li"><a href="https://community.rapid7.com/community/solutions/metasploit/blog/2012/01/19/metasploit-framework-updated">Metasploit Updated: Forensics, SCADA, SSH Public Keys, and More</a> (community.rapid7.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=2977e57e-2532-4a8e-96fd-0a265606ddbf" /></a></div></div>

<p><a href="http://feedads.g.doubleclick.net/~a/SiaJRdM-DcQUZa76K_ZJJT4W0lI/0/da"><img src="http://feedads.g.doubleclick.net/~a/SiaJRdM-DcQUZa76K_ZJJT4W0lI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/SiaJRdM-DcQUZa76K_ZJJT4W0lI/1/da"><img src="http://feedads.g.doubleclick.net/~a/SiaJRdM-DcQUZa76K_ZJJT4W0lI/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=XKI5DNeMfKM:yZs-zZGX-O0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=XKI5DNeMfKM:yZs-zZGX-O0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=XKI5DNeMfKM:yZs-zZGX-O0:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=XKI5DNeMfKM:yZs-zZGX-O0:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=XKI5DNeMfKM:yZs-zZGX-O0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=XKI5DNeMfKM:yZs-zZGX-O0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=XKI5DNeMfKM:yZs-zZGX-O0:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=XKI5DNeMfKM:yZs-zZGX-O0:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/XKI5DNeMfKM" height="1" width="1"/>]]></content:encoded><description>Continuing my series of podcasts on all things Risk, I have another great one in this episode. I am joined by an all star panel of HD Moore, CSO of Rapid7 and founder of Metasploit, Ron Gula, CEO and CTO...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/4NbC1OXGhMA/joeplayer_v18c.swf" fileSize="216836" type="application/x-shockwave-flash" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Continuing my series of podcasts on all things Risk, I have another great one in this episode. I am joined by an all star panel of HD Moore, CSO of Rapid7 and founder of Metasploit, Ron Gula, CEO and CTO...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>Continuing my series of podcasts on all things Risk, I have another great one in this episode. I am joined by an all star panel of HD Moore, CSO of Rapid7 and founder of Metasploit, Ron Gula, CEO and CTO...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2012/01/just-another-risk-podcast-not.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/4NbC1OXGhMA/joeplayer_v18c.swf" length="216836" type="application/x-shockwave-flash" /><feedburner:origEnclosureLink>http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf</feedburner:origEnclosureLink></item><item><title>Only One Week Left To Vote For Blogger Awards</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/_CqpAiMw-aE/only-one-week-left-to-vote-for-blogger-awards.html</link><category>security bloggers network</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 20 Jan 2012 07:03:03 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e20162ffe58ec1970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Wow, January is flying by! Today is the 20th of the month already. That means there is only one week left to vote for this years Social Security Bloggers Awards.  Of course winners will be announced at the Security Bloggers Meet up at the RSA Conference in San Francisco.</p>  <p>Here are the finalists as nominate by our judges, Kelly Jackson Higgins, Bill Brenner, Larry Walsh and Wendy Nather:</p>  <p><strong>Best Corporate Security Blog:</strong></p>  <p>Fortinet Security Blog <a href="http://blog.fortinet.com/">http://blog.fortinet.com/</a></p>  <p>Denim Group <a href="http://blog.denimgroup.com/">http://blog.denimgroup.com/</a></p>  <p>Trend Micro Cloud Security Blog <a href="http://cloudsecurity.trendmicro.com/">http://cloudsecurity.trendmicro.com/</a></p>  <p>Veracode Security Blog <a href="http://www.veracode.com/blog/">http://www.veracode.com/blog/</a></p>  <p>Kaspersky Lab Blog <a href="https://www.securelist.com/en/">https://www.securelist.com/en/</a></p>  <p>Sophos Naked Security Blog <a href="http://nakedsecurity.sophos.com/">http://nakedsecurity.sophos.com/</a></p>  <p><strong>Best Security Podcast:</strong></p>  <p>Threat Post <a href="http://threatpost.com/en_us/podcast">http://threatpost.com/en_us/podcast</a></p>  <p>The Network Security Podcast <a href="http://netsecpodcast.com/">http://netsecpodcast.com/</a></p>  <p>Eurotrash Security Podcast <a href="http://www.eurotrashsecurity.eu/index.php/Main_Page">http://www.eurotrashsecurity.eu/index.php/Main_Page</a></p>  <p>Pauldotcom <a href="http://pauldotcom.com/">http://pauldotcom.com/</a></p>  <p>Exotic Liability <a href="http://www.exoticliability.com/">http://www.exoticliability.com/</a></p>  <p>The Southern Fried Security Podcast <a href="http://www.southernfriedsecurity.com/">http://www.southernfriedsecurity.com/</a></p>  <p>You can also write in your podcast vote.</p>  <p><strong>The Most Educational Security Blog:</strong></p>  <p>Cognitive Dissidents <a href="http://blog.cognitivedissidents.com/">http://blog.cognitivedissidents.com/</a></p>  <p>Tao Security <a href="http://taosecurity.blogspot.com/">http://taosecurity.blogspot.com/</a></p>  <p>F-Secure blog <a href="http://www.f-secure.com/weblog/">http://www.f-secure.com/weblog/</a></p>  <p>The New School Security Blog <a href="http://newschoolsecurity.com/">http://newschoolsecurity.com/</a></p>  <p>AppSecInc Blog <a href="http://blog.appsecinc.com/">http://blog.appsecinc.com/</a></p>  <p>Evil Bytes/John Sawyer <a href="http://www.darkreading.com/blog/archives/evil-bytes/index.html">http://www.darkreading.com/blog/archives/evil-bytes/index.html</a></p>  <p><strong>The Most Entertaining Security Blog:</strong></p>  <p>Rational Survivability <a href="http://www.rationalsurvivability.com/blog/">http://www.rationalsurvivability.com/blog/</a></p>  <p>Andrew Hay's Blog <a href="http://www.andrewhay.ca/">http://www.andrewhay.ca/</a></p>  <p>Uncommon Sense Security/Jack Daniel <a href="http://blog.uncommonsensesecurity.com/">http://blog.uncommonsensesecurity.com/</a></p>  <p>New School Of Information Security/Adam Shostack <a href="http://newschoolsecurity.com/">http://newschoolsecurity.com/</a></p>  <p>Naked Security <a href="http://nakedsecurity.sophos.com/">http://nakedsecurity.sophos.com/</a></p>  <p>Securosis Blog <a href="http://securosis.com/blog">http://securosis.com/blog</a></p>  <p><strong>The Blog That Best Represents The Security Industry:</strong></p>  <p>Krebs On Security <a href="http://krebsonsecurity.com/">http://krebsonsecurity.com/</a></p>  <p>Uncommon Sense Security <a href="http://blog.uncommonsensesecurity.com/">http://blog.uncommonsensesecurity.com/</a></p>  <p>SANS Internet Storm Center <a href="http://isc.sans.org/">http://isc.sans.org/</a></p>  <p>Securosis blog <a href="https://securosis.com/blog">https://securosis.com/blog</a></p>  <p><strong>The Single Best Blog Post or Podcast Of The Year:</strong></p>  <p>Martin McKeay, Curing the Credit Card Cancer <a href="http://www.mckeay.net/2011/11/28/curing-the-credit-card-cancer/">http://www.mckeay.net/2011/11/28/curing-the-credit-card-cancer/</a></p>  <p>Veracode Blog <a href="http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/">http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/</a></p>  <p>Moxie Marlinspike's ThoughtCrime Labs <a href="http://blog.thoughtcrime.org/authenticity-is-broken-in-ssl-but-your-app-ha">http://blog.thoughtcrime.org/authenticity-is-broken-in-ssl-but-your-app-ha</a></p>  <p>Idoneous Security <a href="http://idoneous-security.blogspot.com/2011/12/what-your-analyst-wishes-you-knew.html">http://idoneous-security.blogspot.com/2011/12/what-your-analyst-wishes-you-knew.html</a></p>  <p><strong>The First Two Members Of The Security Bloggers Hall Of Fame:</strong> (please pick 2)</p>  <p>Adam Shostack (Emergent Chaos, New School of Security)</p>  <p>Brian Krebs (Washington Post, Krebs on Security)</p>  <p>Rich Bejtlich, Tao Security</p>  <p>Chris Hoff, Rational Survivability</p>  <p>Graham Cluley, Naked Security</p>  <p>Bruce Schneier, Schneier On Security</p>  <p>You can vote if you like, right now <a href="https://www.surveymonkey.com/s/2012securityblogger">by clicking here</a>. There is only a week left and most of the categories are very, very close.</p>
<p><a href="http://feedads.g.doubleclick.net/~a/OKs2F0WOIh2tswR9aBppc6kLZBY/0/da"><img src="http://feedads.g.doubleclick.net/~a/OKs2F0WOIh2tswR9aBppc6kLZBY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/OKs2F0WOIh2tswR9aBppc6kLZBY/1/da"><img src="http://feedads.g.doubleclick.net/~a/OKs2F0WOIh2tswR9aBppc6kLZBY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_CqpAiMw-aE:NeXKrRpHBk4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_CqpAiMw-aE:NeXKrRpHBk4:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_CqpAiMw-aE:NeXKrRpHBk4:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_CqpAiMw-aE:NeXKrRpHBk4:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_CqpAiMw-aE:NeXKrRpHBk4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=_CqpAiMw-aE:NeXKrRpHBk4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=_CqpAiMw-aE:NeXKrRpHBk4:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=_CqpAiMw-aE:NeXKrRpHBk4:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/_CqpAiMw-aE" height="1" width="1"/>]]></content:encoded><description>Wow, January is flying by! Today is the 20th of the month already. That means there is only one week left to vote for this years Social Security Bloggers Awards. Of course winners will be announced at the Security Bloggers...</description><feedburner:origLink>http://www.ashimmy.com/2012/01/only-one-week-left-to-vote-for-blogger-awards.html</feedburner:origLink></item><item><title>How Come My Blog/Podcast Wasnt Nominated?</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/zwoo6g9F5CA/how-come-my-blogpodcast-wasnt-nominated.html</link><category>awards and PR</category><category>podcasting</category><category>security bloggers network</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 12 Jan 2012 16:12:45 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e20162ff49ab66970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>With last weeks <a href="http://www.ashimmy.com/2012/01/and-the-nominees-are.html">announcement</a> of the finalists for this years Social Security Bloggers Awards there has been the usual buzz about the awards, the Security Bloggers Network and the bloggers meet up.  I want to say from the outset that in total all of the blogs/podcasts nominated as finalists belong there.</p>  <p>Of course there are so many blogs and podcasts that inevitably some worthy ones don’t make the list. This year there has been some questioning of how we pick the finalists and questioning of why certain blog/podcasts were left out. I should say that it seems mostly centered in the podcast category.</p>  <p>As a result I have made a write in option available for qualified voters(more on that in a second) to write in their own selection for best podcast. So far I have a received a handful of write in votes.  That being said though, I wanted to go over how we pick the finalists and what the Social Security Bloggers Awards are all about.</p>  <p>First of all you should know that this year at RSA Conference we will be hosting the 6th annual Security Bloggers Meet up.  You can find out more about it at the <a href="https://365.rsaconference.com/blogs/security-blogger-meetup">RSA Conference blog for Bloggers Meet up</a>, the Bloggers Meet up <a href="https://www.facebook.com/bloggersmeetup">Facebook page</a> and the <a href="http://www.securitybloggersnetwork.com">Security Bloggers Network</a>. </p>  <p>This is also the 4th year for the Social Security Bloggers Awards. Again you can read more about them on the links above. The idea behind the blogger awards was to recognize some of the leading bloggers in the security arena.  When I first came up with the idea I didn’t think people would get that excited about it. </p>  <p>In the first year of the awards we had judges nominate their choices for finalists (as we have every year since), then we let anyone who registered vote. Well it turned out like so many awards run by other organizations, nothing more than a popularity contest with some people trying to stuff the ballot box.  That was not the spirit that I envisioned with these awards. </p>  <p>The awards really grew out of the Security Bloggers Network which I started 6 or more years ago. While a blog or podcast does not have to be in the SBN to be considered or win an award, it was in that same sense of fostering a community among the security blogging space.  </p>  <p>So going forward I changed the voting for the awards. While our all star panel of judges still picked the finalists, voting was only open to security bloggers.  Each voter had to give their blog or podcast URL with their vote for us to verify. In this way it was an award “by the bloggers, for the bloggers”.  This of course drastically cut down the amount of votes cast, but made it a peer based award similar to the Screen Actor Guild SAG awards.  I thought that was pretty cool.</p>  <p>Each year I try to bring some fresh blood into the judges pool to get new views on what the best blogs and podcasts are.  I also refine and add new categories to hopefully better represent the market. But no matter what is done, there are always going to be some people who feel left out. </p>  <p>So for next year I am already thinking of how we can do this differently. I am open to suggestions. But I will reserve the right on behalf of myself and the bloggers meet up organizing committee to choose what we think is the best method. I want to keep the awards free from ballot box stuffing. </p>  <p>In the meantime I want you all to know that I and many others appreciate all of the great content that the security industry turns out in blogs and podcasts. Thanks to all of you for creating and consuming it. Being nominated or even winning an award is not the payback for why we do this, it is educating and joining in the conversation that keeps us doing it.  So please keep blogging and podcasting!</p>
<p><a href="http://feedads.g.doubleclick.net/~a/crKIZOP_LeLlytItuo9y4k6ezss/0/da"><img src="http://feedads.g.doubleclick.net/~a/crKIZOP_LeLlytItuo9y4k6ezss/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/crKIZOP_LeLlytItuo9y4k6ezss/1/da"><img src="http://feedads.g.doubleclick.net/~a/crKIZOP_LeLlytItuo9y4k6ezss/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=zwoo6g9F5CA:yWvLG_mWVkQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=zwoo6g9F5CA:yWvLG_mWVkQ:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=zwoo6g9F5CA:yWvLG_mWVkQ:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=zwoo6g9F5CA:yWvLG_mWVkQ:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=zwoo6g9F5CA:yWvLG_mWVkQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=zwoo6g9F5CA:yWvLG_mWVkQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=zwoo6g9F5CA:yWvLG_mWVkQ:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=zwoo6g9F5CA:yWvLG_mWVkQ:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/zwoo6g9F5CA" height="1" width="1"/>]]></content:encoded><description>With last weeks announcement of the finalists for this years Social Security Bloggers Awards there has been the usual buzz about the awards, the Security Bloggers Network and the bloggers meet up. I want to say from the outset that...</description><feedburner:origLink>http://www.ashimmy.com/2012/01/how-come-my-blogpodcast-wasnt-nominated.html</feedburner:origLink></item><item><title>And The Nominees Are . . .</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/eLVB95m8gxQ/and-the-nominees-are.html</link><category>awards and PR</category><category>Martin McKeay</category><category>rich mogull</category><category>security bloggers network</category><category>the security industry</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 06 Jan 2012 14:16:09 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201676012f3d8970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201676012f2de970b-pi"><img style="background-image: none; border-right-width: 0px; margin: 0px 0px 0px 5px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="social security bloggers awards 12" border="0" alt="social security bloggers awards 12" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20168e5141fce970c-pi" width="240" height="148"></img></a>No I am not announcing the choices for the Oscars.  Something even better.  It is time to announce the nominees for the 2012 Social Security Bloggers Awards.  Voting will open today and remain open until January 30th.  Of course the winners will be announced live at the 6th annual Security Bloggers Meet up at RSA Conference!</p>  <p>So before we get to our nominees, a word from our sponsors:</p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20162ff1e2025970d-pi"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="sponsors meetup" border="0" alt="sponsors meetup" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201676012f396970b-pi" width="511" height="30"></img></a></p>  <p>Actually a few other things to mention first as well:</p>  <p>1. Our judges - The nominees for the Social Security Blogger Awards are made by our blue ribbon panel of judges.  We did not announce their names before hand this year to limit the "lobbying" that they have been subjected to in the past. But now that the nominations are public, they are open to be influenced by food, liquor, baubles or other means.  Seriously a huge thank you to our judges:</p>  <p><strong>Kelly Jackson Higgins</strong></p>  <p><strong>Bill Brenner</strong></p>  <p><strong>Larry Walsh</strong></p>  <p>and special guest judge:</p>  <p><strong>Wendy Nather</strong></p>  <p>2. Eligibility - In years past anyone associated with organizing the bloggers meet up was DQ'ed from being nominated. Frankly that was silly. The fact is that Rich, Martin, Jen and Jeanne (my organizing committee fellow members), don't have a lot to do with the awards.  So the only one not eligible for any awards is me. It isn't fair to keep good blogs and people down.  Also judges could not nominate their own work, but other judges could nominate someone who is judging.  So for instance, Wendy Nather was nominated by another judge unbeknownst to her.</p>  <p>3. New Category - This year we are adding a new category for Security Bloggers Hall of Fame. I will be adding this to the Security Bloggers Network Site after RSA. This category is sort of a lifetime achievement award for security bloggers.  But it doesn't mean they are on their last leg.  This first year we are going to add two bloggers to the Hall of Fame.  In future years we will add one new blogger a year.</p>  <p>4. Who can vote - Again, I did not want to go through the ballot box stuffing that we had a few years back. So only security bloggers and podcasters can vote. If you write on security and have a URL to prove it, you can vote. Me and my election commission members will be going through each vote by hand, so please don't even bother trying to game this. Don't ruin a fun event with bad form.</p>  <p>OK with that out of the way, here are the nominations for the 2012 Social Security Bloggers Awards:</p>  <p><strong><font size="3">Best Corporate Security Blog:</font></strong></p>  <p>Fortinet Security Blog <a href="http://blog.fortinet.com/">http://blog.fortinet.com/</a></p>  <p>Denim Group <a href="http://blog.denimgroup.com/">http://blog.denimgroup.com/</a></p>  <p>Trend Micro Cloud Security Blog <a href="http://cloudsecurity.trendmicro.com/">http://cloudsecurity.trendmicro.com/</a></p>  <p>Veracode Security Blog <a href="http://www.veracode.com/blog/">http://www.veracode.com/blog/</a></p>  <p>Kaspersky Lab Blog <a href="https://www.securelist.com/en/">https://www.securelist.com/en/</a></p>  <p>Sophos Naked Security Blog <a href="http://nakedsecurity.sophos.com/">http://nakedsecurity.sophos.com/</a></p>  <p><strong><font size="3">Best Security Podcast:</font></strong></p>  <p>Threat Post <a href="http://threatpost.com/en_us/podcast">http://threatpost.com/en_us/podcast</a> </p>  <p>The Network Security Podcast <a href="http://netsecpodcast.com/">http://netsecpodcast.com/</a></p>  <p>Eurotrash Security Podcast <a href="http://www.eurotrashsecurity.eu/index.php/Main_Page">http://www.eurotrashsecurity.eu/index.php/Main_Page</a></p>  <p>Pauldotcom <a href="http://pauldotcom.com/">http://pauldotcom.com/</a></p>  <p>Exotic Liability <a href="http://www.exoticliability.com/">http://www.exoticliability.com/</a></p>  <p>The Southern Fried Security Podcast <a href="http://www.southernfriedsecurity.com/">http://www.southernfriedsecurity.com/</a></p>  <p><strong><font size="3">The Most Educational Security Blog:</font></strong></p>  <p>Cognitive Dissidents <a href="http://blog.cognitivedissidents.com/">http://blog.cognitivedissidents.com/</a></p>  <p>Tao Security <a href="http://taosecurity.blogspot.com/">http://taosecurity.blogspot.com/</a></p>  <p>F-Secure blog <a href="http://www.f-secure.com/weblog/">http://www.f-secure.com/weblog/</a></p>  <p>The New School Security Blog <a href="http://newschoolsecurity.com/">http://newschoolsecurity.com/</a></p>  <p>AppSecInc Blog <a href="http://blog.appsecinc.com/">http://blog.appsecinc.com/</a></p>  <p>Evil Bytes/John Sawyer <a href="http://www.darkreading.com/blog/archives/evil-bytes/index.html">http://www.darkreading.com/blog/archives/evil-bytes/index.html</a></p>  <p><strong><font size="3">The Most Entertaining Security Blog:</font></strong></p>  <p>Rational Survivability <a href="http://www.rationalsurvivability.com/blog/">http://www.rationalsurvivability.com/blog/</a></p>  <p>Andrew Hay's Blog <a href="http://www.andrewhay.ca/">http://www.andrewhay.ca/</a></p>  <p>Uncommon Sense Security/Jack Daniel <a href="http://blog.uncommonsensesecurity.com/">http://blog.uncommonsensesecurity.com/</a></p>  <p>New School Of Information Security/Adam Shostack <a href="http://newschoolsecurity.com/">http://newschoolsecurity.com/</a></p>  <p>Naked Security <a href="http://nakedsecurity.sophos.com/">http://nakedsecurity.sophos.com/</a></p>  <p>Securosis Blog <a href="http://securosis.com/blog">http://securosis.com/blog</a></p>  <p><strong><font size="3">The Blog That Best Represents The Security Industry:</font></strong></p>  <p>Krebs On Security <a href="http://krebsonsecurity.com/">http://krebsonsecurity.com/</a></p>  <p>Uncommon Sense Security <a href="http://blog.uncommonsensesecurity.com/">http://blog.uncommonsensesecurity.com/</a></p>  <p>SANS Internet Storm Center <a href="http://isc.sans.org/">http://isc.sans.org/</a></p>  <p>Securosis blog <a href="https://securosis.com/blog">https://securosis.com/blog</a></p>  <p><strong><font size="3">The Single Best Blog Post or Podcast Of The Year:</font></strong></p>  <p>Martin McKeay, Curing the Credit Card Cancer <a href="http://www.mckeay.net/2011/11/28/curing-the-credit-card-cancer/">http://www.mckeay.net/2011/11/28/curing-the-credit-card-cancer/</a></p>  <p>Veracode Blog <a href="http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/">http://www.veracode.com/blog/2011/08/musings-on-custers-last-stand/</a></p>  <p>Moxie Marlinspike's ThoughtCrime Labs <a href="http://blog.thoughtcrime.org/authenticity-is-broken-in-ssl-but-your-app-ha">http://blog.thoughtcrime.org/authenticity-is-broken-in-ssl-but-your-app-ha</a></p>  <p>Idoneous Security <a href="http://idoneous-security.blogspot.com/2011/12/what-your-analyst-wishes-you-knew.html">http://idoneous-security.blogspot.com/2011/12/what-your-analyst-wishes-you-knew.html</a></p>  <p><strong><font size="3">The First Two Members Of The Security Bloggers Hall Of Fame:</font></strong> (please pick 2)</p>  <p>Adam Shostack (Emergent Chaos, New School of Security)</p>  <p>Brian Krebs (Washington Post, Krebs on Security)</p>  <p>Rich Bejtlich, Tao Security </p>  <p>Chris Hoff, Rational Survivability</p>  <p>Graham Cluley, Naked Security</p>  <p>Bruce Schneier, Schneier On Security</p>  <p>OK, there you have it. Your 2012 Nominees for the Social Security Blogger Awards. You can vote if you like, right now <a href="https://www.surveymonkey.com/s/2012securityblogger">by clicking here</a></p>
<p><a href="http://feedads.g.doubleclick.net/~a/-PX0CHpvZyyUPju17R2BWakoxJE/0/da"><img src="http://feedads.g.doubleclick.net/~a/-PX0CHpvZyyUPju17R2BWakoxJE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/-PX0CHpvZyyUPju17R2BWakoxJE/1/da"><img src="http://feedads.g.doubleclick.net/~a/-PX0CHpvZyyUPju17R2BWakoxJE/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eLVB95m8gxQ:pfJh9Gj9Lac:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eLVB95m8gxQ:pfJh9Gj9Lac:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eLVB95m8gxQ:pfJh9Gj9Lac:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eLVB95m8gxQ:pfJh9Gj9Lac:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eLVB95m8gxQ:pfJh9Gj9Lac:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=eLVB95m8gxQ:pfJh9Gj9Lac:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eLVB95m8gxQ:pfJh9Gj9Lac:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=eLVB95m8gxQ:pfJh9Gj9Lac:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/eLVB95m8gxQ" height="1" width="1"/>]]></content:encoded><description>No I am not announcing the choices for the Oscars. Something even better. It is time to announce the nominees for the 2012 Social Security Bloggers Awards. Voting will open today and remain open until January 30th. Of course the...</description><feedburner:origLink>http://www.ashimmy.com/2012/01/and-the-nominees-are.html</feedburner:origLink></item><item><title>The B-sides Affair</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/JRC0ZzfPpMA/the-b-sides-affair.html</link><category>security bloggers network</category><category>the security industry</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 21 Dec 2011 07:38:59 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201675f1816f4970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>So the security twittersphere is a buzz this morning about <a href="http://securityerrata.org/errata/sec-co/mike_dahn-bsides/">a post by Brian Martin</a> on SecurityErrata raising some serious questions about the Security B-sides “organization” and Mike Dahn in particular. </p>  <p>Let me say from the outset that I don’t consider myself a B-sides insider and have only even attended a few B-sides events. The early ones were a bit too edgy for me. However, I have followed the growth of b-sides closely. I have been very proud of the way Mike, Jack Daniels and others have really taken these events up a notch.</p>  <p>Also from running the Security Bloggers Network and Bloggers Meet up and Awards at RSA these past years, I have a little experience with some of this type of stuff.</p>  <p>Rather than be constrained to 140 characters, I wanted to get my thoughts down here in long form. Call me old fashioned.</p>  <p>1. It is not easy setting up an organization as a non-profit, especially if you have never done it before. The smart thing is to hire a lawyer and accountant and let them deal with it, but that costs money too. It is especially harder if this is not your full time gig.</p>  <p>2. Running any organization including delegating responsibility and authority is also something that if you have not done it before is not easy.</p>  <p>3. Most sponsors for b-sides don’t sponsor because it is a non-profit. They sponsor to be associated and reach the attendees. Non-profit or not, they write off the sponsorship as marketing expense. I don’t think they take a tax write off as a charitable donation. In fact I have checked this with at least one sponsor of a b-sides event and the non-profit status was not an issue to them at all.</p>  <p>4. I know Jack Daniels and tend to believe him that the dollar amounts mentioned in the blog post are erroneous. I am waiting to see Mike Dahn’s response today and fully expect the facts around this to come out.</p>  <p>5. Running the bloggers meet up and awards we take in 20k to 30k a year for the party from sponsors. We don’t say we are a non-profit and we are not. However, we spend every cent every year on the party and awards(and sometimes poor Rich Mogul winds up with a tax liability). We are not transparent with the funding, but no one has ever asked frankly, including the sponsors. I would assume it is probably similar with B-sides.</p>  <p>6. I understand the echo chamber of Twitter, but 140 characters doesn’t give enough room for depth. Instead it shrieks loudly. Multiply that by the amount of people tweeting and it takes on a mob feel. Lets give pause and let Mike respond and let the facts come out. </p>  <p>7. I hope as a result of this B-sides will come out of it bigger and better than ever with a wider, deeper management team.</p>  <p>7. We have a great community in InfoSec, lets celebrate it at this time of year!</p>  <p>Happy Hanukah, Merry Christmas, Happy New Year and any other holiday you celebrate. Love your fellow man and give them the benefit of the doubt before rushing to judgement.</p>
<p><a href="http://feedads.g.doubleclick.net/~a/N0vvpU0IxCs2LrLPTFzz2kr-tQE/0/da"><img src="http://feedads.g.doubleclick.net/~a/N0vvpU0IxCs2LrLPTFzz2kr-tQE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/N0vvpU0IxCs2LrLPTFzz2kr-tQE/1/da"><img src="http://feedads.g.doubleclick.net/~a/N0vvpU0IxCs2LrLPTFzz2kr-tQE/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=JRC0ZzfPpMA:8RkHj2WW7tc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=JRC0ZzfPpMA:8RkHj2WW7tc:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=JRC0ZzfPpMA:8RkHj2WW7tc:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=JRC0ZzfPpMA:8RkHj2WW7tc:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=JRC0ZzfPpMA:8RkHj2WW7tc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=JRC0ZzfPpMA:8RkHj2WW7tc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=JRC0ZzfPpMA:8RkHj2WW7tc:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=JRC0ZzfPpMA:8RkHj2WW7tc:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/JRC0ZzfPpMA" height="1" width="1"/>]]></content:encoded><description>So the security twittersphere is a buzz this morning about a post by Brian Martin on SecurityErrata raising some serious questions about the Security B-sides “organization” and Mike Dahn in particular. Let me say from the outset that I don’t...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/the-b-sides-affair.html</feedburner:origLink></item><item><title>Risk, Risk, Risk</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/3-naiFNhz28/risk-risk-risk.html</link><category>podcasting</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 19 Dec 2011 09:22:04 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201675efea5e1970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20162fe0a8347970d-pi"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top: 0px; border-right: 0px; padding-top: 0px" title="securityexe podcast logo" border="0" alt="securityexe podcast logo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20162fe0a8354970d-pi" width="240" height="55"></img></a>In order to effectively manage risk, we need to be able to effectively measure risk.  Before we can ever hope to effectively measure risk, we should all agree on exactly what is the definition of risk.  When something as elementary as defining risk can sow confusion, caveats and so many questions, you know we need to do a better job.</p>  <p>I am joined on this episode of the Security.Exe Podcast by some experts in risk.  I have Alex Hutton, formerly of Verizon and now a top risk officer at a top 25 financial institution, Ben Tomhave (@falconsview) of <a href="http://www.lockpath.com">LockPath</a> and finally last but not least, Jody Brazil of <a href="http://firemon.com">Firemon</a>.</p>  <p>Of course as most of you know I have been looking at risk an awful lot lately as part of working with Jody and the Firemon guys around their <a href="http://firemon.com/products/riskanalyzer/">Risk Analyzer</a> product. But getting a few really smart people to talk about a concept is a great way to learn. I learned a lot listening to the folks on this episode. I think you will too!</p>  <p>I am thinking of expanding this discussion into perhaps a panel for a conference talk. Let me know what you think.</p>  <p>Enjoy!</p>  <p> </p> <iframe height="85" marginheight="0" src="http://ashimmy.podomatic.com/embed/frame/posting/2011-12-19T09_00_48-08_00?json_url=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2011-12-19T09_00_48-08_00%3Fcolor%3D1c60ff%26autoPlay%3Dfalse%26facebook%3Dtrue%26height%3D85%26minicast%3Dfalse%26width%3D440" frameborder="0" width="440" marginwidth="0" scrolling="no"></iframe>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/have-we-got-risk-all-wrong.html">Have We Got Risk All Wrong?</a> (ashimmy.com)</li>      <li class="zemanta-article-ul-li"><a href="http://fitforrandomness.wordpress.com/2011/09/09/risk-if-we-already-know-what-we-cant-but/">Risk: If we already "know" what we can't but...</a> (fitforrandomness.wordpress.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=e0dd9d7c-9c32-44e0-9a1c-786acb5c7988"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/Bq6zEt-w1mV9m1kf0wiXBMylZPA/0/da"><img src="http://feedads.g.doubleclick.net/~a/Bq6zEt-w1mV9m1kf0wiXBMylZPA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Bq6zEt-w1mV9m1kf0wiXBMylZPA/1/da"><img src="http://feedads.g.doubleclick.net/~a/Bq6zEt-w1mV9m1kf0wiXBMylZPA/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=3-naiFNhz28:eMgCYKsoIto:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=3-naiFNhz28:eMgCYKsoIto:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=3-naiFNhz28:eMgCYKsoIto:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=3-naiFNhz28:eMgCYKsoIto:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=3-naiFNhz28:eMgCYKsoIto:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=3-naiFNhz28:eMgCYKsoIto:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=3-naiFNhz28:eMgCYKsoIto:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=3-naiFNhz28:eMgCYKsoIto:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/3-naiFNhz28" height="1" width="1"/>]]></content:encoded><description>In order to effectively manage risk, we need to be able to effectively measure risk. Before we can ever hope to effectively measure risk, we should all agree on exactly what is the definition of risk. When something as elementary...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/risk-risk-risk.html</feedburner:origLink></item><item><title>Its That Magical Time of the Year</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/iEkTDMlY6rM/its-that-magical-time-of-the-year-1.html</link><category>security bloggers network</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 16 Dec 2011 08:40:47 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201543862871a970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>This is copied from the post I just put up at the RSA Conference Blog at:</p>  <p><a href="https://365.rsaconference.com/blogs/security-blogger-meetup/2011/12/16/its-that-time-of-the-year">https://365.rsaconference.com/blogs/security-blogger-meetup/2011/12/16/its-that-time-of-the-year</a></p>  <p>Christmas is just a week or so away, New Years is just around the corner.  You know what is next? Of course you do, it is RSA Conference Week and with that the 6th Annual Security Bloggers Meetup!   Can you believe it has been a whole year since we last gathered in San Francisco? More than that, can you believe this is the 6th annual Security Bloggers Meetup?  Of course the 4th annual Social Security Blogger Awards will be presented as well. </p>  <p>Our little get together has certainly grown since Martin McKeay, Rich Mogull and I talked about getting together with a few bloggers way back when. Of course it couldn't have gotten to where it is today without all of the hard work of Jennifer Leggio who does so much of the heavy lifting.  Add to the mix the tireless effort of Jeanne Friedman of RSA Conference and you have one hard working organizing committee.  We literally meet year round planning this event, lining up sponsors, entertainment, etc. </p>  <p>Speaking of sponsors, we are very proud to have a great mix of old and new sponsors for this years event.  Returning are RSA Conference, Qualys, Fortinet, Barracuda Networks and Core Trace.  Joining the mix this year are new sponsors Sourcefire and Akamai.  Thank you to each and everyone of them for allowing us to put this event on this year! </p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201675ed85343970b-pi"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="sponsors meetup" border="0" alt="sponsors meetup" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015438627201970c-pi" width="533" height="31"></img></a> </p>  <p>Well invites or more appropriately this year, registration requests are going out today. We are doing things a little differently this year. If you were on our list you will receive an event registration request. You need to follow the link and register for the event.  Let me warn you up front, you need to give your name, email address and blog URL.  Each registration will be reviewed by a live human (how quaint) and approved or disallowed. The usual no marketing/PR please rules apply.  Of course it is not that we don't love marketing/PR people, it is just that we built a tradition of a party by the bloggers, for the bloggers with the bloggers only. </p>  <p>If you think you should get a registration request but have not received one yet (check your spam folder, sometimes they get stuck there), please email Jennifer at <a href="mailto:mediaphyter@gmail.com">mediaphyter@gmail.com</a>. She will get one right out to you. </p>  <p>A couple of other things about this years event: </p>  <p>1. The Social Security Blogger Awards are back for their 4th year.  We will announce finalists for voting right after January 1. Our judges are already hard at work making their nominations. </p>  <p>2. Interesting entertainment and activities during the party </p>  <p>3. Hopefully same great food and drink </p>  <p>4. STILL THE BEST GROUP OF PEOPLE YOU WANT TO MINGLE WITH IN THE SECURITY INDUSTRY! </p>  <p>So don't wait, due to space we have to limit the number of people we can register to attend. If you got your invite, head on over and register now! </p>  <p>On behalf of Jennifer, Jeanne, Martin, Rich, myself and our sponsors, thanks and  can can't wait to see you! </p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/social-security-blogger-awards-2012.html">Social Security Blogger Awards 2012</a> (ashimmy.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/blogging-is-a-conversation.html">Blogging is a Conversation</a> (ashimmy.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=65088673-4f67-45c4-afa9-b8c8b278eb98"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/LmilLljzCEpUGawIv05oCQd4NH4/0/da"><img src="http://feedads.g.doubleclick.net/~a/LmilLljzCEpUGawIv05oCQd4NH4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/LmilLljzCEpUGawIv05oCQd4NH4/1/da"><img src="http://feedads.g.doubleclick.net/~a/LmilLljzCEpUGawIv05oCQd4NH4/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=iEkTDMlY6rM:2Lu5G6bajSA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=iEkTDMlY6rM:2Lu5G6bajSA:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=iEkTDMlY6rM:2Lu5G6bajSA:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=iEkTDMlY6rM:2Lu5G6bajSA:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=iEkTDMlY6rM:2Lu5G6bajSA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=iEkTDMlY6rM:2Lu5G6bajSA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=iEkTDMlY6rM:2Lu5G6bajSA:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=iEkTDMlY6rM:2Lu5G6bajSA:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/iEkTDMlY6rM" height="1" width="1"/>]]></content:encoded><description>This is copied from the post I just put up at the RSA Conference Blog at: https://365.rsaconference.com/blogs/security-blogger-meetup/2011/12/16/its-that-time-of-the-year Christmas is just a week or so away, New Years is just around the corner. You know what is next? Of course you...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/its-that-magical-time-of-the-year-1.html</feedburner:origLink></item><item><title>Its That Magical Time of the Year</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/WNkAfb-ckXQ/its-that-magical-time-of-the-year.html</link><category>security bloggers network</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 16 Dec 2011 08:33:03 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201675ed85382970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>This is copied from the post I just put up at the RSA Conference Blog at:</p>  <p><a href="https://365.rsaconference.com/blogs/security-blogger-meetup/2011/12/16/its-that-time-of-the-year">https://365.rsaconference.com/blogs/security-blogger-meetup/2011/12/16/its-that-time-of-the-year</a></p>  <p>Christmas is just a week or so away, New Years is just around the corner.  You know what is next? Of course you do, it is RSA Conference Week and with that the 6th Annual Security Bloggers Meetup!   Can you believe it has been a whole year since we last gathered in San Francisco? More than that, can you believe this is the 6th annual Security Bloggers Meetup?  Of course the 4th annual Social Security Blogger Awards will be presented as well. </p>  <p>Our little get together has certainly grown since Martin McKeay, Rich Mogull and I talked about getting together with a few bloggers way back when. Of course it couldn't have gotten to where it is today without all of the hard work of Jennifer Leggio who does so much of the heavy lifting.  Add to the mix the tireless effort of Jeanne Friedman of RSA Conference and you have one hard working organizing committee.  We literally meet year round planning this event, lining up sponsors, entertainment, etc. </p>  <p>Speaking of sponsors, we are very proud to have a great mix of old and new sponsors for this years event.  Returning are RSA Conference, Qualys, Fortinet, Barracuda Networks and Core Trace.  Joining the mix this year are new sponsors Sourcefire and Akamai.  Thank you to each and everyone of them for allowing us to put this event on this year! </p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201675ed85343970b-pi"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="sponsors meetup" border="0" alt="sponsors meetup" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015438627201970c-pi" width="533" height="31"></img></a> </p>  <p>Well invites or more appropriately this year, registration requests are going out today. We are doing things a little differently this year. If you were on our list you will receive an event registration request. You need to follow the link and register for the event.  Let me warn you up front, you need to give your name, email address and blog URL.  Each registration will be reviewed by a live human (how quaint) and approved or disallowed. The usual no marketing/PR please rules apply.  Of course it is not that we don't love marketing/PR people, it is just that we built a tradition of a party by the bloggers, for the bloggers with the bloggers only. </p>  <p>If you think you should get a registration request but have not received one yet (check your spam folder, sometimes they get stuck there), please email Jennifer at <a href="mailto:mediaphyter@gmail.com">mediaphyter@gmail.com</a>. She will get one right out to you. </p>  <p>A couple of other things about this years event: </p>  <p>1. The Social Security Blogger Awards are back for their 4th year.  We will announce finalists for voting right after January 1. Our judges are already hard at work making their nominations. </p>  <p>2. Interesting entertainment and activities during the party </p>  <p>3. Hopefully same great food and drink </p>  <p>4. STILL THE BEST GROUP OF PEOPLE YOU WANT TO MINGLE WITH IN THE SECURITY INDUSTRY! </p>  <p>So don't wait, due to space we have to limit the number of people we can register to attend. If you got your invite, head on over and register now! </p>  <p>On behalf of Jennifer, Jeanne, Martin, Rich, myself and our sponsors, thanks and  can can't wait to see you! </p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/social-security-blogger-awards-2012.html">Social Security Blogger Awards 2012</a> (ashimmy.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/blogging-is-a-conversation.html">Blogging is a Conversation</a> (ashimmy.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=65088673-4f67-45c4-afa9-b8c8b278eb98"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/eWIExfa1d8dZ7PJkc7oD1DhJNFY/0/da"><img src="http://feedads.g.doubleclick.net/~a/eWIExfa1d8dZ7PJkc7oD1DhJNFY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/eWIExfa1d8dZ7PJkc7oD1DhJNFY/1/da"><img src="http://feedads.g.doubleclick.net/~a/eWIExfa1d8dZ7PJkc7oD1DhJNFY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=WNkAfb-ckXQ:dVgPb_lkq-A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=WNkAfb-ckXQ:dVgPb_lkq-A:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=WNkAfb-ckXQ:dVgPb_lkq-A:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=WNkAfb-ckXQ:dVgPb_lkq-A:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=WNkAfb-ckXQ:dVgPb_lkq-A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=WNkAfb-ckXQ:dVgPb_lkq-A:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=WNkAfb-ckXQ:dVgPb_lkq-A:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=WNkAfb-ckXQ:dVgPb_lkq-A:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/WNkAfb-ckXQ" height="1" width="1"/>]]></content:encoded><description>This is copied from the post I just put up at the RSA Conference Blog at: https://365.rsaconference.com/blogs/security-blogger-meetup/2011/12/16/its-that-time-of-the-year Christmas is just a week or so away, New Years is just around the corner. You know what is next? Of course you...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/its-that-magical-time-of-the-year.html</feedburner:origLink></item><item><title>Social Security Blogger Awards 2012</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/eGm4f93GuwY/social-security-blogger-awards-2012.html</link><category>awards and PR</category><category>security bloggers network</category><category>the security industry</category><category>tradeshows</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 15 Dec 2011 07:42:39 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201543856e345970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Cooperstown, Canton, Springfield, Cleveland, what do all of these places have in common? They all are homes to a Hall of Fame. Now the Security Bloggers Awards will be joining them with Security Bloggers Hall of Fame too!  </p>  <p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201543856e338970c-pi"><img style="background-image: none; border-right-width: 0px; margin: 4px 0px 4px 5px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="social security bloggers awards 12" border="0" alt="social security bloggers awards 12" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201543856e340970c-pi" width="286" height="178"></img></a>It is Christmas time, so you know RSA Conference is not far away. If RSA is almost here, you know that is almost time for the annual Security Bloggers Meet up and Social Security Bloggers Awards.  </p>  <p>All of the plans have been made, the judges selected and the finalists will be announced after New Years.  As in years past all security bloggers are eligible to vote. But you will have to give your name, email and blog address.</p>  <p>Last years categories will return this year:</p>  <p><b>Best Corporate Security Blog</b> </p>  <p><b>Best Security podcast</b></p>  <p><b>Most educational security blog</b></p>  <p><b>Most entertaining security blog</b></p>  <p><b>Security Blog that best represents the industry</b></p>  <p><b>The single best security blog post of the year</b> </p>  <p>Additionally this year we will elect the first two members of the <strong>Security Bloggers Hall of Fame</strong>! </p>  <p>I will announce our judges and other information between Christmas and New Years.  This year all blogs are eligible except mine and the judges. Also be on the lookout for save the dates going out soon if you are on our list. If you are not on the list, send an email to <a href="mailto:info@securitybloggersnetwork.com">info@securitybloggersnetwork.com</a> or leave a comment requesting an invite. You must blog on security and no marketing/PR stuff please! </p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/blogging-is-a-conversation.html">Blogging is a Conversation</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="https://365.rsaconference.com/blogs/rsa-conference-blog/2011/12/14/new-for-rsa-conference-2012--the-author-s-studio">New for RSA Conference 2012 - the Author's Studio</a> (365.rsaconference.com) </li>      <li class="zemanta-article-ul-li"><a href="http://boxofmeat.net/post/8431658244/words">Securosis: Words matter: You stop attacks, not breaches</a> (boxofmeat.net)</li>      <li class="zemanta-article-ul-li"><a href="http://securosis.com/blog/friday-summary-december-9-2011">Friday Summary, December 9, 2011</a> (securosis.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=46adc087-bca0-426d-93c6-3909f89450dc"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/ut9B-E6Pw0sH7spdvf22rSLgx9w/0/da"><img src="http://feedads.g.doubleclick.net/~a/ut9B-E6Pw0sH7spdvf22rSLgx9w/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/ut9B-E6Pw0sH7spdvf22rSLgx9w/1/da"><img src="http://feedads.g.doubleclick.net/~a/ut9B-E6Pw0sH7spdvf22rSLgx9w/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eGm4f93GuwY:rWzlPDuocWg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eGm4f93GuwY:rWzlPDuocWg:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eGm4f93GuwY:rWzlPDuocWg:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eGm4f93GuwY:rWzlPDuocWg:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eGm4f93GuwY:rWzlPDuocWg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=eGm4f93GuwY:rWzlPDuocWg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=eGm4f93GuwY:rWzlPDuocWg:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=eGm4f93GuwY:rWzlPDuocWg:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/eGm4f93GuwY" height="1" width="1"/>]]></content:encoded><description>Cooperstown, Canton, Springfield, Cleveland, what do all of these places have in common? They all are homes to a Hall of Fame. Now the Security Bloggers Awards will be joining them with Security Bloggers Hall of Fame too! It is...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/social-security-blogger-awards-2012.html</feedburner:origLink></item><item><title>The Sleazy Dark Side of Product Reviews</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/SUowcz5f-MA/the-sleazy-dark-side-of-product-reviews.html</link><category>General Background</category><category>General Security</category><category>the security industry</category><category>Web/Tech</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 14 Dec 2011 05:33:48 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e20162fdcac84e970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Yesterday <a href="http://www.ashimmy.com/2011/12/the-death-of-product-reviews.html">I wrote</a> in response to <a href="http://blogs.csoonline.com/1860/browser_security_study_lacks_credibility_for_one_simple_reason">Bill Brenner’s Salted Hash post</a> about the Google-funded, Accuvant conducted browser security study which found (surprise) Chrome on top.</p>  <p>In my post yesterday I mentioned that one company that I thought is doing product  reviews right was NSS Labs.  Well Rick Moy of NSS Labs wrote me last night, having read my post.  The NSS Labs folks have had a look at what was publicly available. </p>  <p>Vik Phatak, CTO of NSS Labs has a blog post up on the subject <a href="http://www.nsslabs.com/blog/2011/12/did-google-take-out-a-hit-on-firefox.html">here</a>. More importantly Vik and team have put out a more complete analysis of problems they see with the way this study was conducted and some issues in Google’s behavior. You can read the analysis <a href="http://www.nsslabs.com/research/analysis-briefs/the-browser-wars-just-got-ugly.html">here</a>.</p>  <p>It is a very interesting read and you should take a look for sure.  It certainly raises some questions about what went on with this browser study and calls into question some very questionable practices by Google.  </p>  <p>It just proves that product reviews are a dirty business and why any reader has to look at and weigh all factors in deciding how much faith to put in them.</p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/12/the-death-of-product-reviews.html">The Death of Product Reviews</a> (ashimmy.com) </li>      <li class="zemanta-article-ul-li"><a href="http://lifehacker.com/5867545/whats-the-most-secure-web-browser">What's the Most Secure Web Browser? [Security]</a> (lifehacker.com) </li>      <li class="zemanta-article-ul-li"><a href="http://arstechnica.com/business/news/2011/12/chrome-sandboxing-makes-it-the-most-secure-browser-vendor-study-claims.ars">Chrome sandboxing makes it the most secure browser, vendor study claims</a> (arstechnica.com) </li>      <li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/security/nss-labs-claims-its-new-tool-can-detect-all-duqu-drivers-178269&amp;a=61485297&amp;rid=5355b8e7-e5b7-44a5-ac37-30e4910f51b3&amp;e=39a6942073dc29b7bb60548272a8bae8">NSS Labs claims its new tool can detect all Duqu drivers</a> (infoworld.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/243284/nss_labs_claims_its_new_tool_can_detect_all_duqu_drivers.html">NSS Labs Claims Its New Tool Can Detect All Duqu Drivers</a> (pcworld.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=5355b8e7-e5b7-44a5-ac37-30e4910f51b3"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/9OE5_tOyZrVcWP0wQN-ercgfP1M/0/da"><img src="http://feedads.g.doubleclick.net/~a/9OE5_tOyZrVcWP0wQN-ercgfP1M/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/9OE5_tOyZrVcWP0wQN-ercgfP1M/1/da"><img src="http://feedads.g.doubleclick.net/~a/9OE5_tOyZrVcWP0wQN-ercgfP1M/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=SUowcz5f-MA:ZFl8GQbVcrQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=SUowcz5f-MA:ZFl8GQbVcrQ:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=SUowcz5f-MA:ZFl8GQbVcrQ:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=SUowcz5f-MA:ZFl8GQbVcrQ:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=SUowcz5f-MA:ZFl8GQbVcrQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=SUowcz5f-MA:ZFl8GQbVcrQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=SUowcz5f-MA:ZFl8GQbVcrQ:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=SUowcz5f-MA:ZFl8GQbVcrQ:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/SUowcz5f-MA" height="1" width="1"/>]]></content:encoded><description>Yesterday I wrote in response to Bill Brenner’s Salted Hash post about the Google-funded, Accuvant conducted browser security study which found (surprise) Chrome on top. In my post yesterday I mentioned that one company that I thought is doing product...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/the-sleazy-dark-side-of-product-reviews.html</feedburner:origLink></item><item><title>The Death of Product Reviews</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/PSIkcyMszS4/the-death-of-product-reviews.html</link><category>awards and PR</category><category>General Background</category><category>General Security</category><category>marketing</category><category>rich mogull</category><category>Security Incite</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Tue, 13 Dec 2011 12:57:01 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e20154383fc37c970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div style="margin: 1em; width: 310px; display: block; float: right" class="zemanta-img"><a href="http://en.wikipedia.org/wiki/File:Google_Chrome_2011_Logo.svg"><img style="border-bottom: medium none; border-left: medium none; display: block; border-top: medium none; border-right: medium none" alt="English: This is a logo owned by Google Inc. f..." src="http://upload.wikimedia.org/wikipedia/en/thumb/b/b1/Google_Chrome_2011_Logo.svg/300px-Google_Chrome_2011_Logo.svg.png" width="300" height="79"></img></a>    <p style="font-size: 0.8em" class="zemanta-img-attribution">Image via <a href="http://en.wikipedia.org/wiki/File:Google_Chrome_2011_Logo.svg">Wikipedia</a></p> </div>  <p>My friend Bill Brenner has a <a href="http://blogs.csoonline.com/1860/browser_security_study_lacks_credibility_for_one_simple_reason">post up on his Salted Hash blog</a> today about a recent browser security study done by Accuvant LABS. The study shows that Google Chrome was the safest browser tested. Like Bill, I use Chrome too and agree with the Accuvant study.</p>  <p>The problem for Bill is that the study was sponsored by Google, the makers of Chrome. The fact that they paid for this study in Bill’s mind and in many other people’s minds calls the legitimacy of the entire study into question. Even if it is correct, it just doesn’t sit well with Bill.</p>  <p>Frankly I have the same problems with most product reviews, bake offs, analysis reports, etc. I have written about this before as well. In my mind it is a big reason why no one seems to pay attention to product reviews anymore. </p>  <p>It doesn’t make a difference if it is an “independent lab” doing the testing, a magazine’s testing department, industry awards or an analyst firm analyzing the market, the first thing I look at is who is paying for it. Sometimes finding out who is paying for it is not so easy or transparent either. </p>  <p>To be fair, some firms like Securosis for instance will say upfront that some research they are doing is being financed by a paying customer. Such was the case when Mike, Rich and Adrian did a dive on “<a href="http://securosis.com/research/publication/fact-based-network-security-metrics-and-the-pursuit-of-prioritization">fact based security security metrics</a>”. The boys said upfront and at the bottom of the page that they thanked Red Seal for sponsoring the research.</p>  <p>Now does that mean that everything they wrote was for the benefit of Red Seal? I know Rich, Mike and Adrian too well to believe that. But it does give me pause when I read the report to remember that fact. </p>  <p>But I will say that over time I have come to soften my attitude on this issue (I must be getting old). For me it is a case of forewarned is forearmed and I take that disclosure in terms of evaluating how much weight to give the research. The same way a juror has to weigh the testimony of a witness depending on their believability.</p>  <p>In the case of Bill’s browser study, same thing. The chances that Google had a heavy hand in the study by Accuvant is pretty low, but it is something to consider. That is just the way it is.</p>  <p>But for Bill and the other doubting Thomas’s out there, what is the alternative? </p>  <p>One alternative is what Rick Moy and the guys at NSS Labs are doing. They have turned this equation on its head. They make their money from the end user, so the vendors being tested have little to no influence. </p>  <p>As Bill says just because Google paid for it doesn’t mean the study is wrong, but it does give you something else to consider. But since no one wants to do these tests or studies for free, someone has to pay and that is the truth of it. </p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://lifehacker.com/5867545/whats-the-most-secure-web-browser">What's the Most Secure Web Browser? [Security]</a> (lifehacker.com) </li>      <li class="zemanta-article-ul-li"><a href="http://miguelalmeida.net/2011/12/accuvant-labs-chrome-is-the-most-secured-browser.html">Accuvant Labs: "Chrome is the most secured browser"</a> (miguelalmeida.net) </li>      <li class="zemanta-article-ul-li"><a href="http://arstechnica.com/business/news/2011/12/chrome-sandboxing-makes-it-the-most-secure-browser-vendor-study-claims.ars">Chrome sandboxing makes it the most secure browser, vendor study claims</a> (arstechnica.com) </li>      <li class="zemanta-article-ul-li"><a href="http://ostatic.com/blog/which-browser-is-most-secure-a-new-study-reports-a-surprise">Which Browser Is Most Secure? A New Study Reports A Surprise</a> (ostatic.com) </li>      <li class="zemanta-article-ul-li"><a href="http://news.slashdot.org/story/11/12/10/1349212/google-funded-study-knocks-firefox-security">Google-Funded Study Knocks Firefox Security</a> (news.slashdot.org) </li>      <li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/businesscenter/article/245856/chrome_is_most_secure_of_the_top_three_browsers_study_finds.html">Chrome Is Most Secure of the Top Three Browsers, Study Finds</a> (pcworld.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.zdnet.com/blog/security/new-study-claims-that-chrome-is-the-most-secure-browser/9839">New study claims that Chrome is the most secure browser</a> (zdnet.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=694d121b-1aad-4975-8348-2dbb7b1db87a"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/pLje0vF3RCUAANL-30yJPdUFz28/0/da"><img src="http://feedads.g.doubleclick.net/~a/pLje0vF3RCUAANL-30yJPdUFz28/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/pLje0vF3RCUAANL-30yJPdUFz28/1/da"><img src="http://feedads.g.doubleclick.net/~a/pLje0vF3RCUAANL-30yJPdUFz28/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=PSIkcyMszS4:LYnkyg5UlLA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=PSIkcyMszS4:LYnkyg5UlLA:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=PSIkcyMszS4:LYnkyg5UlLA:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=PSIkcyMszS4:LYnkyg5UlLA:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=PSIkcyMszS4:LYnkyg5UlLA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=PSIkcyMszS4:LYnkyg5UlLA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=PSIkcyMszS4:LYnkyg5UlLA:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=PSIkcyMszS4:LYnkyg5UlLA:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/PSIkcyMszS4" height="1" width="1"/>]]></content:encoded><description>Image via Wikipedia My friend Bill Brenner has a post up on his Salted Hash blog today about a recent browser security study done by Accuvant LABS. The study shows that Google Chrome was the safest browser tested. Like Bill,...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/the-death-of-product-reviews.html</feedburner:origLink></item><item><title>Blogging is a Conversation</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/HG7Dx26_yjQ/blogging-is-a-conversation.html</link><category>General Background</category><category>rich mogull</category><category>security bloggers network</category><category>Weblogs</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Mon, 12 Dec 2011 08:47:55 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201675eaa8f4b970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>For those of you who may be wondering, yes there will be a killer Security Bloggers Meet up at RSA this year. There will also be another Social Security Blogger Awards with some new categories as well. More on those in another blog. But the reason I write today is something Rich Mogull said on our blogger meet up organizing committee call.</p>  <p>Rich said “lets face it, the security blogger’s community isn’t what it used to be”. While I don’t disagree with Rich, I went back and looked at some of the numbers and some of the security blogs. While Rich is right, we don’t see as many as blog posts from the community as we used to, I think we all agree that Twitter probably plays a significant role in that. In fact the <a href="http://www.tripwire.com/state-of-security/it-security-data-protection/top-25-influencers-in-security-you-should-be-following/">Tripwire 25 most influential people in security list</a> seems pretty skewed towards twittter users. But that being said, there are still plenty of security blog posts being posted. The SBN feed is still fresh with lots of new posts every day.</p>  <p>One thing I do see is many of the posts come from corporate security blogs rather than individuals. Many of the corporate blogs don’t develop the personality that a good personal blog does. More importantly what has changed is another thing Rich brought up. We don’t comment anymore. We don’t blog back anymore.</p>  <p>People are blogging and putting their 2 cents into the conversation, but no one is repsonding. Oh, maybe they respond on twitter, on but it doesn’t make it into the blog. Blogging has always been and will always be a two way street. A blog should be a multi-party conversation with the blogger putting forth his ideas and others responding. They can agree, disagree, or concur, but they put their thoughts into the conversation.</p>  <p>One of the great things about reading a hot blog post was following the thread of comments, that was where the real action took place. Whether it was a Rothman post on Security Incite/Securosis or Tom Pcatek on Matasano, a good threat with 50 comments kept you reading for more.</p>  <p>Now maybe Twitter is where blog comments have gone and some of the discussion. Can we have a plug in that captures the real time of twitter comments and discussions back to the original blog post? Doesn’t sound too hard. </p>  <p>How about writing a blog post in response to another blog post? That is part of carrying on the conversation as well. Need something good to blog about? Go look at what your community is writing and join in.</p>  <p><a href="http://emergentchaos.com/archives/2011/12/threat-modeling-and-risk-assessment.html">Adam Shostack over on Emergent Chaos has a post up about Threat Modeling</a> as a result of a conversation he had with Wendy Nather, who has her own good blog post about “<a href="http://idoneous-security.blogspot.com/2011/12/what-your-analyst-wishes-you-knew.html">what your analyst wishes you knew</a>” (and she is not talking about your psychoanalyst either).</p>  <p>I am going over to both of those blogs and adding my voice to the conversation. I already tweeted Wendy’s post, but I realize that is not enough. If we are going to keep the Security blogging community strong and vibrant we have to add our voice on blogs.</p>  <p>What about you? Are you ready to rejoin the conversation?  If so, head over to your favorite security blog and join in.  Or better yet, write a blog in response to someone else’s blog.  It starts with you and you and you.</p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://lexisjen.wordpress.com/2011/12/09/reasons-to-blog-guest-post/">Reasons to Blog: Guest Post!</a> (lexisjen.wordpress.com)</li>      <li class="zemanta-article-ul-li"><a href="http://emergentchaos.com/archives/2011/11/email-chaos-how-to-reach-adam-shostack.html">Email chaos: How to reach Adam Shostack</a> (emergentchaos.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=05f35915-0aa5-42c4-964c-ccd37321f37d"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/Mga32iYcVqs-yaWKWOs7mMSRLuY/0/da"><img src="http://feedads.g.doubleclick.net/~a/Mga32iYcVqs-yaWKWOs7mMSRLuY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Mga32iYcVqs-yaWKWOs7mMSRLuY/1/da"><img src="http://feedads.g.doubleclick.net/~a/Mga32iYcVqs-yaWKWOs7mMSRLuY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=HG7Dx26_yjQ:bvRlLaF6Tb0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=HG7Dx26_yjQ:bvRlLaF6Tb0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=HG7Dx26_yjQ:bvRlLaF6Tb0:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=HG7Dx26_yjQ:bvRlLaF6Tb0:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=HG7Dx26_yjQ:bvRlLaF6Tb0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=HG7Dx26_yjQ:bvRlLaF6Tb0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=HG7Dx26_yjQ:bvRlLaF6Tb0:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=HG7Dx26_yjQ:bvRlLaF6Tb0:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/HG7Dx26_yjQ" height="1" width="1"/>]]></content:encoded><description>For those of you who may be wondering, yes there will be a killer Security Bloggers Meet up at RSA this year. There will also be another Social Security Blogger Awards with some new categories as well. More on those...</description><feedburner:origLink>http://www.ashimmy.com/2011/12/blogging-is-a-conversation.html</feedburner:origLink></item><item><title>Have We Got Risk All Wrong?</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/up1MpkGprgY/have-we-got-risk-all-wrong.html</link><category>podcasting</category><category>vulnerability management</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 01 Dec 2011 08:08:54 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2015437ad315a970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015393d9b0fe970b-pi"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top: 0px; border-right: 0px; padding-top: 0px" title="firemon_logo" border="0" alt="firemon_logo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015393d9b103970b-pi" width="240" height="35" /></a>Most of us in the information security industry long ago recognized that we could not eliminate every risk and threat to our data and networks. Instead we have tried to manage that risk to acceptable levels, with acceptable being in the eye of the beholder. An entire information security risk management industry has sprung up over this time. But, have we missed the boat on risk? Has the risk management space been hijacked by the vulnerability management crowd?</p>  <p>We have settled on a formula for risk being:</p>  <p>Risk (<strong>R</strong>)<strong>=</strong> Threat (<strong>T</strong>) <strong>x</strong> Vulnerability (<strong>V</strong>)</p>  <p>But is that the correct formula to use? Are there other factors that need to be considered?</p>  <p>I am joined on this podcast by Jody Brazil, President of Firemon and Gary Fish, CEO of Firemon to discuss these questions in light of Firemon's new Risk Analyzer product.</p>  <p>Risk Analyzer offers a new way to look at risk using risk based scenarios. Introducing concepts such as reachability, exposure and asset value into the equation, it gives us a better measure of risk. Risk Analyzer also gives us another way of prioritizing different risks to make us more efficient.</p>  <p>As many of you know, I have been working with Firemon for a few months and have watched Risk Analyzer develop. The folks at Firemon have taken a great engine that was developed at the MIT Lincoln Labs and developed some great front end features to make this a complete product. I am very excited by what it offers and I think you will be too.</p>  <p>Have a listen as I discuss this with Jody and Gary.</p>  <p><em>Also be advised that there was a clicking in the recording (which we obviously didn't know about when we recorded this). I have done my best using my not very considerable sound engineering skills to remove it. It is still there, but it is the best I can do and I thought the quality of the conversation was much more important than the quality of the sound.</em></p>  <p>Enjoy!</p> <OBJECT width=440 height=85><PARAM NAME="movie" VALUE="http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf"><PARAM NAME="flashvars" VALUE="minicast=false&amp;jsonLocation=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2011-12-01T07_05_55-08_00%26color%3D1c60ff%26autoPlay%3Dfalse%26width%3D440%26height%3D85"><PARAM NAME="allowFullScreen" VALUE="true"><PARAM NAME="allowscriptaccess" VALUE="always"><embed src="http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf" flashvars="minicast=false&jsonLocation=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2011-12-01T07_05_55-08_00%26color%3D1c60ff%26autoPlay%3Dfalse%26width%3D440%26height%3D85" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="440" height="85"></embed></embed></embed></OBJECT>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.ashimmy.com/2011/08/security-exe-podcast-with-ward-holloway-of-firemon.html">Security Exe Podcast With Ward Holloway of Firemon</a> (ashimmy.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.btsecurethinking.com/2011/11/debate-are-risk-assessments-an-outdated-approach-to-security/">Debate: Are Risk Assessments an Outdated Approach to Security?</a> (btsecurethinking.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=e0d71622-622e-4240-a6af-da3f984683dd" /></a></div></div>

<p><a href="http://feedads.g.doubleclick.net/~a/eV9QA28df-ifTg8Qdn9apLQ97mY/0/da"><img src="http://feedads.g.doubleclick.net/~a/eV9QA28df-ifTg8Qdn9apLQ97mY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/eV9QA28df-ifTg8Qdn9apLQ97mY/1/da"><img src="http://feedads.g.doubleclick.net/~a/eV9QA28df-ifTg8Qdn9apLQ97mY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=up1MpkGprgY:5aW6pHiefe0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=up1MpkGprgY:5aW6pHiefe0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=up1MpkGprgY:5aW6pHiefe0:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=up1MpkGprgY:5aW6pHiefe0:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=up1MpkGprgY:5aW6pHiefe0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=up1MpkGprgY:5aW6pHiefe0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=up1MpkGprgY:5aW6pHiefe0:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=up1MpkGprgY:5aW6pHiefe0:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/up1MpkGprgY" height="1" width="1"/>]]></content:encoded><description>Most of us in the information security industry long ago recognized that we could not eliminate every risk and threat to our data and networks. Instead we have tried to manage that risk to acceptable levels, with acceptable being in...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/4NbC1OXGhMA/joeplayer_v18c.swf" fileSize="216836" type="application/x-shockwave-flash" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Most of us in the information security industry long ago recognized that we could not eliminate every risk and threat to our data and networks. Instead we have tried to manage that risk to acceptable levels, with acceptable being in...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>Most of us in the information security industry long ago recognized that we could not eliminate every risk and threat to our data and networks. Instead we have tried to manage that risk to acceptable levels, with acceptable being in...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2011/12/have-we-got-risk-all-wrong.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/4NbC1OXGhMA/joeplayer_v18c.swf" length="216836" type="application/x-shockwave-flash" /><feedburner:origEnclosureLink>http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf</feedburner:origEnclosureLink></item><item><title>Microsofts Trustworthy Computing Supports the SBN</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/Cb_iCp7KK1I/microsofts-trustworthy-computing-supports-the-sbn.html</link><category>security bloggers network</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Tue, 08 Nov 2011 05:23:29 PST</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2015436b7c71e970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I am really happy to report that the Trustworthy Computing Group at Microsoft has decided to partner with and sponsor the Security Bloggers Network.  On behalf of the 300+ blogs in the SBN we are happy to have Microsoft as a sponsor and strongly encourage all of you to check out their new Security Intelligence Report. You can click the graphic below to head over to Microsoft and check out the report.</p>  <p><a href="http://www.microsoft.com/sir"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="New-SIR-graphic" border="0" alt="New-SIR-graphic" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015436b7c710970c-pi" width="143" height="240"></img></a></p>  <p>Also RSA Conference will be here before you know it and we are already planning on the next Security Bloggers Meet up and the Social Security Blogger Awards.  We will be announcing and sending out save the dates soon!</p>
<p><a href="http://feedads.g.doubleclick.net/~a/vMp77k8vyDR94yvOuhMYToudmTU/0/da"><img src="http://feedads.g.doubleclick.net/~a/vMp77k8vyDR94yvOuhMYToudmTU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/vMp77k8vyDR94yvOuhMYToudmTU/1/da"><img src="http://feedads.g.doubleclick.net/~a/vMp77k8vyDR94yvOuhMYToudmTU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Cb_iCp7KK1I:5DqNmF_IC4g:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Cb_iCp7KK1I:5DqNmF_IC4g:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Cb_iCp7KK1I:5DqNmF_IC4g:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Cb_iCp7KK1I:5DqNmF_IC4g:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Cb_iCp7KK1I:5DqNmF_IC4g:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=Cb_iCp7KK1I:5DqNmF_IC4g:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Cb_iCp7KK1I:5DqNmF_IC4g:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=Cb_iCp7KK1I:5DqNmF_IC4g:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/Cb_iCp7KK1I" height="1" width="1"/>]]></content:encoded><description>I am really happy to report that the Trustworthy Computing Group at Microsoft has decided to partner with and sponsor the Security Bloggers Network. On behalf of the 300+ blogs in the SBN we are happy to have Microsoft as...</description><feedburner:origLink>http://www.ashimmy.com/2011/11/microsofts-trustworthy-computing-supports-the-sbn.html</feedburner:origLink></item><item><title>Podcast: Can Open Source Provide The Protein For Security Below The Poverty Line</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/OHnOuVmOSW8/podcast-can-open-source-provide-the-protein-for-security-below-the-poverty-line.html</link><category>podcasting</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 20 Oct 2011 10:30:54 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e201539275bd9b970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><h3><a href="http://www.networkworld.com/community/blog/can-open-source-provide-protein-security-belo">Reprinted from my Network World Blog</a></h3>  <h3>Security costs too much for many organizations, is open source security the answer?</h3> By <a href="http://www.networkworld.com/community/user/11778">Alan Shimel</a> on Mon, 10/17/11 - 12:44pm.   <p>Having been in the infosec world for more than 10 years, I have<img style="margin: 3px 0px 5px 3px; display: inline; float: right" alt="" align="right" src="http://www.networkworld.com/community/files/imce/img_blogs/wendy-nather.jpg" width="149" height="149" /> learned the hard way that there are some real issues around effective security for everyone.&#160; One of them is that security is hard and seems to be getting harder. As a result security is also very expensive.&#160; So expensive that only the largest of organizations who put a high value on securing their assets can afford it.&#160; In fact some studies show that large organizations spend on average of about 3.5 million dollars a year on security.&#160; Frankly, even that is not enough given the current state of cybersecurity.&#160; But even assuming that number is adequate, who has 3.5 million to spend today?</p>  <p>The fact is that most organizations live &quot;below the security poverty line&quot;.&#160; One of my friends in the infosec world and someone who many follow is Wendy Nather, director of research for enterprise security at the 451 Group.&#160; Wendy has real world experience as a CISO at both private and public organizations. She is extremely bright and dialed into the infosec scene.&#160; She co-authored a report titled &quot;<a href="https://www.451research.com/t1r-insight-living-below-the-security-poverty-line">Security Below the Poverty Line</a>&quot;.&#160; Wendy's research shows that most organizations don't have anywhere near the resources required to do security right.&#160; </p>  <p>I actually wrote a follow on to Wendy's report on Secure Cloud Review (another place I blog) titled, &quot;<a href="http://securecloudreview.com/2011/06/brother-can-you-spare-a-dime-life-below-the-security-poverty-line/">Brother Can You Spare A Dime: Life Below The Security Poverty Line</a>&quot;. In it I detailed that like the real poor today, security poor organizations may make due on a &quot;high carb&quot; diet of security that lacks &quot;protein&quot;. By that I mean they have minimal security that gets them &quot;fat&quot; but doesn't really do the job. Anyone who is working in security recognizes this as a real problem we all face.</p>  <p>I wanted to speak to Wendy about what role open source security can play to raise organizations above the security poverty line.&#160; The open source security community has always been an innovative and dynamic one. In just about every security area there is a viable open source project.&#160; So could open source be the secret weapon in the war on security poverty?&#160; </p>  <p>Wendy and I discuss just this and what her research shows.&#160; You can listen to our 15 minute discussion below.&#160; But let me give you some insight even if you don't listen to the podcast.&#160; The costs of security are not only the hardware and software of the security products.&#160; The human costs of security are equally expensive.&#160; Even deploying open source security projects will take experienced, qualified security know how. That costs money, more money than many organizations can afford.&#160; So open source in and of itself is not going to be a panacea here.&#160; </p>  <p>There are other potential ways to address this problem. Outsourcing security is one way that can spread the cost of security over time. Buying security a slice at a time instead of the whole pie at once.&#160; But again even security as a service so to speak can be more than some companies will budget for security.&#160; </p>  <p>This is an age old problem that those of us in the security space no well.&#160; Every survey done always indicates that security is in the top two or three priorities for every CIO.&#160; However, when it comes time to pony up the money often times their arms are too short to reach their pockets.</p>  <p>Wendy Nather is a great person to learn from, please take the time to listen in and hear more pearls of wisdom from her in our discussion. Also, here is to a speedy and full recovery to Wendy, who was nice enough to record this with me just a few days before having some medical procedures performed. Good thoughts and prayers to you my friend! The security world will not be the same until you are back up to full speed!</p>  <p>Finally many thanks to The 451 Group for making<a href="https://www.451research.com/t1r-insight-living-below-the-security-poverty-line"> a copy of Wendy's report available for free</a> from the link in this post, it was previously only available to paying customers of the 451 Group.</p> <OBJECT width=440 height=85><PARAM NAME="wmode" VALUE="transparent"><PARAM NAME="menu" VALUE="false"><PARAM NAME="movie" VALUE="http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf"><PARAM NAME="flashvars" VALUE="minicast=false&amp;jsonLocation=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2011-10-17T08_54_24-07_00%3FautoPlay%3Dfalse%26facebook%3Dtrue%26height%3D85%26minicast%3Dfalse%26width%3D440"><PARAM NAME="allowFullScreen" VALUE="true"><PARAM NAME="allowscriptaccess" VALUE="always"><embed src="http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf" flashvars="minicast=false&jsonLocation=http%3A%2F%2Fashimmy.podomatic.com%2Fentry%2Fembed_params%2F2011-10-17T08_54_24-07_00%3FautoPlay%3Dfalse%26facebook%3Dtrue%26height%3D85%26minicast%3Dfalse%26width%3D440" wmode="transparent" menu="false" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" version="10.0.0" width="440" height="85"></embed></embed></OBJECT>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://securecloudreview.com/2011/10/security-below-the-poverty-line-podcast-with-wendy-nather/">Security Below The Poverty Line Podcast with Wendy Nather</a> (securecloudreview.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=ede8bb70-9183-4ded-8f78-3773a5f73c6d" /></a></div></div>

<p><a href="http://feedads.g.doubleclick.net/~a/VolMkqZyeU9E99NKwVVetpQeYaY/0/da"><img src="http://feedads.g.doubleclick.net/~a/VolMkqZyeU9E99NKwVVetpQeYaY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/VolMkqZyeU9E99NKwVVetpQeYaY/1/da"><img src="http://feedads.g.doubleclick.net/~a/VolMkqZyeU9E99NKwVVetpQeYaY/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OHnOuVmOSW8:MS6oGxszUfk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OHnOuVmOSW8:MS6oGxszUfk:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OHnOuVmOSW8:MS6oGxszUfk:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OHnOuVmOSW8:MS6oGxszUfk:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OHnOuVmOSW8:MS6oGxszUfk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=OHnOuVmOSW8:MS6oGxszUfk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=OHnOuVmOSW8:MS6oGxszUfk:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=OHnOuVmOSW8:MS6oGxszUfk:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/OHnOuVmOSW8" height="1" width="1"/>]]></content:encoded><description>Reprinted from my Network World Blog Security costs too much for many organizations, is open source security the answer? By Alan Shimel on Mon, 10/17/11 - 12:44pm. Having been in the infosec world for more than 10 years, I have...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/4NbC1OXGhMA/joeplayer_v18c.swf" fileSize="216836" type="application/x-shockwave-flash" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Reprinted from my Network World Blog Security costs too much for many organizations, is open source security the answer? By Alan Shimel on Mon, 10/17/11 - 12:44pm. Having been in the infosec world for more than 10 years, I have...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>Reprinted from my Network World Blog Security costs too much for many organizations, is open source security the answer? By Alan Shimel on Mon, 10/17/11 - 12:44pm. Having been in the infosec world for more than 10 years, I have...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2011/10/podcast-can-open-source-provide-the-protein-for-security-below-the-poverty-line.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/4NbC1OXGhMA/joeplayer_v18c.swf" length="216836" type="application/x-shockwave-flash" /><feedburner:origEnclosureLink>http://ashimmy.podomatic.com/swf/joeplayer_v18c.swf</feedburner:origEnclosureLink></item><item><title>Great Job For A PR Security Pro</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/Qcu2Ko-EWA0/great-job-for-a-pr-security-pro.html</link><category>employment</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 13 Oct 2011 13:53:17 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2014e8c3b66ad970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Trainer Communications and Susan Thomas who is always there to help out with the Security Bloggers Network and Bloggers Meet up is looking for an Account Director for their security practice.</p>  <p>Here is the description from Trainer:</p>  <p>Does the concept of “Crazy Good Client Satisfaction” seem natural to you?  If so, we should talk! Ready to take a strong group of PR executives and accelerate its growth?  This may be the job for you!  Growing wicked fast, Trainer Communications, is a national award-winning high tech PR and marketing agency seeking a seeking a rock star Director of our Security Practice. The perfect person for this position knows the ins and outs of vulnerability management to zero-day threats and CAs to access management and malvertizing plus can manage up to five account teams: ensuring all metrics, deliverables and deadlines are met; and instinctively keeps pushing themselves to deliver the next greatest thing in PR and marketing.</p>  <p>The person we are looking for will have the chops to be considered a technology insider in the security market, can counsel clients “on the fly,” can speak to the big picture while minding the details, and be fanatical about client satisfaction.  This person enjoys building and managing a team, and can evaluate the many new client opportunities that come into Trainer on a monthly basis.  We won’t keep you chained to a desk; our directors forge new partnerships with marketing and international PR companies, attend training to facilitate career growth, and routinely share their knowledge with team members and support the agency in bringing on new clients. </p>  <p>Not satisfied with status quo? That’s great – we significantly invest in training and development to ensure our team continues to grow. In fact, 50 percent of our Trainer team has been promoted in the last 18 months! </p>  <p><b>All About You!</b></p>  <ul>   <li>Agency history of managing a group of at least four accounts at once with strong client satisfaction </li>    <li>Can immediately get an audience with at least three prominent analysts or thought leaders </li>    <li>Has a reputation for being easy to work with – and has built loyal teams that will verify how they enjoyed working with this leader </li>    <li>Has committed to memory two or three personal facts about their top five “go-to” reporters and can score media results for clients very quickly </li>    <li>Understands the process for creating websites, sales enablement collateral, and direct email campaigns </li>    <li>Has current connections to deliver phenomenal lead gen results </li>    <li>Understands lead gen options, and can guide "newbie" clients through the process </li>    <li>Likes to compete and has a awards, trophies, and credentials to show for it </li>    <li>Is equally effective sharing opinions in an email, one-on-one, or presenting to a group </li> </ul>  <p>Trainer Communications is located in the heart of Silicon Valley East (Pleasanton-based headquarters) conveniently located near BART.  Trainer offers a no-politics culture, competitive compensation and an excellent benefits package.</p>  <p>If this sounds like something that is perfect for you, contact Trainer </p>  <p><strong>Trainer Communications</strong>    <br>5000 Hopyard Road    <br>Suite 125    <br>Pleasanton, California 94588    <br>925.271.8200</p>  <p><a href="mailto:hr@trainercomm.com">hr@trainercomm.com</a></p>
<p><a href="http://feedads.g.doubleclick.net/~a/joLOHu-8b8DqZXROq3OpC2QcO-g/0/da"><img src="http://feedads.g.doubleclick.net/~a/joLOHu-8b8DqZXROq3OpC2QcO-g/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/joLOHu-8b8DqZXROq3OpC2QcO-g/1/da"><img src="http://feedads.g.doubleclick.net/~a/joLOHu-8b8DqZXROq3OpC2QcO-g/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Qcu2Ko-EWA0:iVWkds-3cPg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Qcu2Ko-EWA0:iVWkds-3cPg:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Qcu2Ko-EWA0:iVWkds-3cPg:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Qcu2Ko-EWA0:iVWkds-3cPg:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Qcu2Ko-EWA0:iVWkds-3cPg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=Qcu2Ko-EWA0:iVWkds-3cPg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Qcu2Ko-EWA0:iVWkds-3cPg:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=Qcu2Ko-EWA0:iVWkds-3cPg:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/Qcu2Ko-EWA0" height="1" width="1"/>]]></content:encoded><description>Trainer Communications and Susan Thomas who is always there to help out with the Security Bloggers Network and Bloggers Meet up is looking for an Account Director for their security practice. Here is the description from Trainer: Does the concept...</description><feedburner:origLink>http://www.ashimmy.com/2011/10/great-job-for-a-pr-security-pro.html</feedburner:origLink></item><item><title>Marketing Security</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/sPpEFa9XHsY/marketing-security.html</link><category>Current Affairs</category><category>General Security</category><category>security tips</category><category>the security industry</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 13 Oct 2011 11:08:27 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2014e8c3ab846970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>No this is not about a new VP of marketing at some security vendor. I was reading an <a href="http://www.computing.co.uk/ctg/news/2116741/rsa-conference-marketing-strategies-increase-security-awareness">article</a> today about a presentation at RSA Europe by Lee Parrish, VP and CISO of construction firm Parsons Corporation. At a time when most of the departments and budgets in his company where shrinking, Parsons nearly doubled his security budget and was hiring more people.  </p>  <p>I know you think they must have had a really poor security department, suffered a breach and so finally security got the attention it deserved.  You would be wrong.  How did Parrish accomplish this feat?  Easily, he “marketed security” internally to the board and stakeholders at his company.</p>  <p>This is a topic I have written about over the years before.  Too many times we hear security folks lament the fact that they just can’t get management to take the threats seriously. They just don’t care enough to approve the budget and resources needed to do security right.</p>  <p>Usually these same people will turn their nose up at marketing types. The marketing and sales people are as reptilian as Queen Anna was in the V series to these folks.  Whether it be security vendors or not, often times security admins will want to take a long hot shower after spending time with marketing and sales types.  What a mistake!</p>  <p align="right">The point Parrish makes is that you need to market security. In the case of security admins you have to market to your own buyers. The decision makers and purse holders at your own company. </p>  <p align="right">Parrish gives a great example of seeing that apps were being downloaded that were not approved and presented a security issue.  But these rogue apps also were driving help desk call numbers through the roof.  So instead of talking about the security threat of these rogue apps he talked about buying technology that would thwart the downloading of rogue apps which would drive help desk calls down by X% saving Y$ per year.  That is the kind of message the business managers understood and they gladly approved the budget.</p>  <p align="right">If you are going to sell (and as I have said before we are all sales people in one way or another) you have to understand your customer. What is it that keeps him up at night, what are his buttons.  So start thinking of your stakeholders internally as your customers and you have to sell them. Before the sale, you have to market to them.  Think like a marketing person and you just might get the security budget you need to make your job fun again.    <br></p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://www.roer.com/node/661">RSA Europe, day one</a> (roer.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.roer.com/node/662">RSA Europe conference - a waste of time?</a> (roer.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/241705/security_on_a_shoestring_budget.html">Security on a Shoestring Budget</a> (pcworld.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=fa0b8335-8389-4379-8af4-f69a8bd90b44"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/Gin933TE-Z1Fi2-HEQ7-PQmh41Y/0/da"><img src="http://feedads.g.doubleclick.net/~a/Gin933TE-Z1Fi2-HEQ7-PQmh41Y/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Gin933TE-Z1Fi2-HEQ7-PQmh41Y/1/da"><img src="http://feedads.g.doubleclick.net/~a/Gin933TE-Z1Fi2-HEQ7-PQmh41Y/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=sPpEFa9XHsY:BHvSuRiALa8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=sPpEFa9XHsY:BHvSuRiALa8:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=sPpEFa9XHsY:BHvSuRiALa8:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=sPpEFa9XHsY:BHvSuRiALa8:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=sPpEFa9XHsY:BHvSuRiALa8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=sPpEFa9XHsY:BHvSuRiALa8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=sPpEFa9XHsY:BHvSuRiALa8:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=sPpEFa9XHsY:BHvSuRiALa8:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/sPpEFa9XHsY" height="1" width="1"/>]]></content:encoded><description>No this is not about a new VP of marketing at some security vendor. I was reading an article today about a presentation at RSA Europe by Lee Parrish, VP and CISO of construction firm Parsons Corporation. At a time...</description><feedburner:origLink>http://www.ashimmy.com/2011/10/marketing-security.html</feedburner:origLink></item><item><title>Steve Jobs: It can happen to you</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/EALSIHNSolk/steve-jobs-it-can-happen-to-you.html</link><category>Current Affairs</category><category>General Background</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 05 Oct 2011 21:38:53 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2015435ed6975970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div style="margin: 1em; width: 310px; display: block; float: right" class="zemanta-img"><a href="http://commons.wikipedia.org/wiki/File:Steve_Jobs_WWDC07.jpg"><img style="border-bottom: medium none; border-left: medium none; display: block; border-top: medium none; border-right: medium none" alt="Steve Jobs at the WWDC 07" src="http://upload.wikimedia.org/wikipedia/commons/thumb/e/e5/Steve_Jobs_WWDC07.jpg/300px-Steve_Jobs_WWDC07.jpg" width="300" height="295"></img></a>     <p style="font-size: 0.8em" class="zemanta-img-attribution">Image via <a href="http://commons.wikipedia.org/wiki/File:Steve_Jobs_WWDC07.jpg">Wikipedia</a></p> </div>  <p>First of all let me wish my condolences and sympathies to the family, friends and colleagues of Steve Jobs.  To say he was a visionary with a profound effect on the technology world for years to come, somehow comes up short to truly describe the genius of the man.</p>  <p>While I was never a big Apple fan, you have to admire what he accomplished in two different stints at the company. You also have to admire his vision in buying Pixar from George Lucas and turning into yet another multi-billion dollar property.</p>  <p>While there are no shortage of tributes and homages to Jobs being written tonight. I wanted to go on a slightly different path. That path is to challenge the next Steve Jobs out there to go out and grab greatness.</p>  <p>That is right, there might be more than one next Steve Jobs out there, there are even a few not Steve Jobs out there. But take the lessons of Job’s life and his advice, go out and make it happen. </p>  <p>This country, this world, humanity needs more Steve Jobs. We need them to imagine, create and give us ideas and products which will make the world better. To advance the human experience in ways that make us all better. </p>  <p>With all of the heartfelt sympathy pouring out about Steve Jobs now, I hope it does inspire others to be the next Steve Jobs.</p>  <p>There is also another lesson in this all to early death of Steve Jobs. That is at the end of the day, death is the great equalizer. It makes no difference how much money you have, how much of a genius you are or even how much good you did for your fellow man.  We are all here at the grace of God. When he decides it is time to go, we have no say, we obey. That is at the end of the day the ultimate human condition that not even Steve Jobs could avoid.</p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul" sizset="0" sizcache="5037">     <li class="zemanta-article-ul-li"><a href="http://www.shopify.com/technology/4241082-rest-in-peace-steve-jobs">Rest in Peace Steve Jobs</a> (shopify.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.it-sideways.com/2011/10/steve-job-passed-on.html">Steve Job Passed On</a> (it-sideways.com) </li>      <li class="zemanta-article-ul-li"><a href="http://pixartimes.com/2011/10/05/pixar-issues-statement-on-steve-jobs-passing/">Pixar Issues Statement on Steve Jobs' Passing</a> (pixartimes.com) </li>      <li class="zemanta-article-ul-li"><a href="http://justjared.buzznet.com/2011/10/05/celebs-react-to-steve-jobs-death/">Celebs React to Steve Jobs' Death</a> (justjared.buzznet.com) </li>      <li class="zemanta-article-ul-li"><a href="http://www.dailyblogtips.com/steve-jobs-passed-away-lessons-learned/">Steve Jobs Passed Away: Lessons Learned</a> (dailyblogtips.com) </li>      <li class="zemanta-article-ul-li"><a href="http://justjared.buzznet.com/2011/10/05/steve-jobs-dead-at-56/">Steve Jobs Dies At 56</a> (justjared.buzznet.com) </li>      <li class="zemanta-article-ul-li"><a href="http://workplacepsychology.net/2011/10/05/steve-jobs-of-apple-dies-at-56/">Steve Jobs of Apple dies at 56</a> (workplacepsychology.net) </li>      <li class="zemanta-article-ul-li"><a href="http://www.fool.com/investing/general/2011/10/05/live-blog-steve-jobs-1955-2011-share-your-thoughts.aspx">Live Blog: Steve Jobs, 1955-2011: Share Your Thoughts</a> (fool.com) </li>      <li class="zemanta-article-ul-li"><a href="http://mashable.com/2011/10/05/disney-ceo-jobs/">Disney CEO: "Jobs Was Such an Original"</a> (mashable.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=08fa0573-d2e7-457c-ba0b-dc71b26a2626"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/Cq3JHiebbohrXmzSEK1aVV9l1H8/0/da"><img src="http://feedads.g.doubleclick.net/~a/Cq3JHiebbohrXmzSEK1aVV9l1H8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Cq3JHiebbohrXmzSEK1aVV9l1H8/1/da"><img src="http://feedads.g.doubleclick.net/~a/Cq3JHiebbohrXmzSEK1aVV9l1H8/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=EALSIHNSolk:3KHlSrD-Nks:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=EALSIHNSolk:3KHlSrD-Nks:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=EALSIHNSolk:3KHlSrD-Nks:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=EALSIHNSolk:3KHlSrD-Nks:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=EALSIHNSolk:3KHlSrD-Nks:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=EALSIHNSolk:3KHlSrD-Nks:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=EALSIHNSolk:3KHlSrD-Nks:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=EALSIHNSolk:3KHlSrD-Nks:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/EALSIHNSolk" height="1" width="1"/>]]></content:encoded><description>Image via Wikipedia First of all let me wish my condolences and sympathies to the family, friends and colleagues of Steve Jobs. To say he was a visionary with a profound effect on the technology world for years to come,...</description><feedburner:origLink>http://www.ashimmy.com/2011/10/steve-jobs-it-can-happen-to-you.html</feedburner:origLink></item><item><title>Fixmo for Mobile Security</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/dAxK57gamSA/fixmo-for-mobile-security.html</link><category>other security companies</category><category>the security industry</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 23 Sep 2011 11:41:43 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2015391d2d727970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I just wanted to give a shout out to a new mobile security company I became aware of called <a href="http://www.fixmo.com">Fixmo</a>. Fixmo has several solutions around mobile security including some powered by technology acquired via a technology transfer agreement with the NSA.</p>  <p>As part of their relationship with the US Government, Fixmo offers mobile security solutions for free to government agencies.  Part of this is the Fixmo SafeZone. Fixmo SafeZone empowers the secure use of personal devices on a government networks by establishing a “secure container” on these devices. The organization controls the data and applications within the SafeZone, while employees control all their personal data and applications outside of this zone. This product was developed as a result of Fixmo’s CRADA with the NSA.</p>  <p>I am digging in trying to find out more about Fixmo, but for those who say innovation is not happening in security and that mobile needs to be more secure. Here is a new company that may be worth looking into!</p>
<p><a href="http://feedads.g.doubleclick.net/~a/eqgLXK9NTZcIhcsfluBD6KyVXvg/0/da"><img src="http://feedads.g.doubleclick.net/~a/eqgLXK9NTZcIhcsfluBD6KyVXvg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/eqgLXK9NTZcIhcsfluBD6KyVXvg/1/da"><img src="http://feedads.g.doubleclick.net/~a/eqgLXK9NTZcIhcsfluBD6KyVXvg/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=dAxK57gamSA:5ekwQCXvlOs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=dAxK57gamSA:5ekwQCXvlOs:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=dAxK57gamSA:5ekwQCXvlOs:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=dAxK57gamSA:5ekwQCXvlOs:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=dAxK57gamSA:5ekwQCXvlOs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=dAxK57gamSA:5ekwQCXvlOs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=dAxK57gamSA:5ekwQCXvlOs:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=dAxK57gamSA:5ekwQCXvlOs:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/dAxK57gamSA" height="1" width="1"/>]]></content:encoded><description>I just wanted to give a shout out to a new mobile security company I became aware of called Fixmo. Fixmo has several solutions around mobile security including some powered by technology acquired via a technology transfer agreement with the...</description><feedburner:origLink>http://www.ashimmy.com/2011/09/fixmo-for-mobile-security.html</feedburner:origLink></item><item><title>How About A Schmear With Lo(x)cks</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/AqzYLLfuzqc/how-about-a-schmear-with-loxcks.html</link><category>General Background</category><category>the security industry</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Thu, 22 Sep 2011 11:09:09 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2014e8bc08346970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015435a02b9c970c-pi"><img style="background-image: none; border-right-width: 0px; margin: 0px 0px 5px 5px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="locks" border="0" alt="locks" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015435a02ba0970c-pi" width="260" height="195"></img></a>Having gone to my share of security conferences over the years, I have seen more than my share of the “uniqueness” of the security industry.  I passed through the stage of the large multi-color Mohawks, the piercings that set off the metal detectors at TSA stations in a 75 mile radius and yes even the attraction to wearing a good, old kilt to let things “air out” a bit. </p>  <p>Over the years I have always liked to watch at BlackHat/Defcon all of the lock picking stuff.  I wasn’t quite sure if it made sense for HackKid Con, but hey who am I to judge if people want their kids to learn to pick locks.</p>  <p>However, I just don’t see why we are seeing such large crowds around the lock picking table at the recent security shows I have attended.  I mean really. Is that what we as an industry should be putting our time and focus into?  At the same time we run around as Chicken Little about how hard and insurmountable our jobs are, we devote hours picking deadbolts and other locks?</p>  <p>Figuring that I am just an old crab (not a security curmudgeon mind you, that is reserved for old guys with long beards) I thought I would ask some folks what is with the locks? The variety of answers confirmed my thoughts.  Security people play with locks for the same reasons dogs lick themselves, that is because they can.</p>  <p>Here is a sample of some of the answers I heard:</p>  <p><strong>1. Lock picking is sort of like security. It is about keeping people out from what you are trying to protect, so it is adjacent.</strong></p>  <p><strong>2. It keeps my kids interested in security and that is a good thing.  My kids need to know how these things work.</strong></p>  <p><strong>3. It is a great family fun activity</strong></p>  <p><strong>4. Security people love a good puzzle and picking locks is sort of like a good puzzle. It keeps us sharp</strong></p>  <p><strong>5. We fail so miserably at protecting our networks and data, it feels good to get a “win” when we pick a lock.</strong></p>  <p><strong>6. It is just a fetish and really has nothing to do with security at all (I respect the honesty)</strong></p>  <p>So, as you can see the answers were a bit all over the map. This leads me to believe we are grasping at straws to justify our behavior.  So lets just say picking locks does not help us manage risk on our networks. But it feels good.</p>  <p>OK, now that we have that out of the way, why stop at locks?  Andrew Storm would like a Makers Fair at his security shows.  Misha Govshteyn would like a “foodie” table. Security shows are what we make of them.</p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.bbc.co.uk/go/rss/int/news/-/news/magazine-14924443&amp;a=55466228&amp;rid=f2995f50-ec93-49a8-a988-1b168819cfed&amp;e=6360e5f69cbc867691ea436270c12ca6">VIDEO: Picking locks for sport</a> (bbc.co.uk) </li>      <li class="zemanta-article-ul-li"><a href="http://www.bbc.co.uk/news/technology-10554538">Analogue hacking</a> (bbc.co.uk)</li>      <li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//bits.blogs.nytimes.com/2011/08/06/picking-locks-and-hacking-servers-at-defcon/&amp;a=50993502&amp;rid=f2995f50-ec93-49a8-a988-1b168819cfed&amp;e=c98aac7ad1bc77513449fd11f87dcc29">Picking Locks and Hacking Servers at Defcon</a> (bits.blogs.nytimes.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=f2995f50-ec93-49a8-a988-1b168819cfed"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/f06Mx_M6g_nd_0x3WFWtQpPYQBo/0/da"><img src="http://feedads.g.doubleclick.net/~a/f06Mx_M6g_nd_0x3WFWtQpPYQBo/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/f06Mx_M6g_nd_0x3WFWtQpPYQBo/1/da"><img src="http://feedads.g.doubleclick.net/~a/f06Mx_M6g_nd_0x3WFWtQpPYQBo/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=AqzYLLfuzqc:VOUv6EATI44:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=AqzYLLfuzqc:VOUv6EATI44:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=AqzYLLfuzqc:VOUv6EATI44:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=AqzYLLfuzqc:VOUv6EATI44:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=AqzYLLfuzqc:VOUv6EATI44:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=AqzYLLfuzqc:VOUv6EATI44:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=AqzYLLfuzqc:VOUv6EATI44:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=AqzYLLfuzqc:VOUv6EATI44:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/AqzYLLfuzqc" height="1" width="1"/>]]></content:encoded><description>Having gone to my share of security conferences over the years, I have seen more than my share of the “uniqueness” of the security industry. I passed through the stage of the large multi-color Mohawks, the piercings that set off...</description><feedburner:origLink>http://www.ashimmy.com/2011/09/how-about-a-schmear-with-loxcks.html</feedburner:origLink></item><item><title>An Open Letter To The Security Industry: We Live In Amazing Times</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/uanRBfIJ_Ko/an-open-letter-to-the-security-industry-we-live-in-amazing-times.html</link><category>the security industry</category><category>tradeshows</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 21 Sep 2011 11:41:58 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2014e8bba79c1970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I just returned home from the UNITED Security Summit in San Francisco. Besides speaking myself at the show I had a chance to sit in on some great presentations by some familiar and some not so familiar (to me anyway) folks.  While overall the tracks were great, one theme that was pretty constant was the pessimism in general about the security industry.  The feeling was we are losing the battle, nothing is changing and without “radical change” we are doomed to repeat the same mistakes and failures.</p>  <p>This doom and gloom is contagious and becomes a self-fulfilling prophesy. I think while the challenges are certainly great, we should not forget where we came from.  I am reminded of a bit by the comedian Louis CK. </p>  <p><object width="420" height="315"><param name="movie" value="http://www.youtube.com/v/8r1CZTLk-Gk?version=3&amp;hl=en_US"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/8r1CZTLk-Gk?version=3&amp;hl=en_US" type="application/x-shockwave-flash" width="420" height="315" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>  <p>It is like the guy who complains about the WiFi not working on a plane.  Think about it. You are sitting on a huge hunk of metal, flying through the air at over 500 miles an hour at almost 40,000 feet altitude. The plane is directing an antenna at a satellite in space sending and receiving data at speeds that were unimaginable just 20 or 25 years ago even if you wired to a computer. Every once in a while it doesn’t work and you complain.  Hey guys we live in amazing times!</p>  <p>The same is true of IT in general. The speed of evolution (not revolution mind you) is staggering. Yes, the security industry has not been able to overtake the pace and is struggling to keep up, but we are running as fast as we can.  </p>  <p>Let us not forget that just 15 or 20 years ago there really wasn’t an information security industry to speak of. We have built and developed an awful lot in that time frame. I am not saying we need to rest on our laurels, but that half-empty glass is half-full too.</p>  <p>Another thing I hear at these shows is that the security industry is maturing and we crave better metrics to make better decisions and better strategies.  I agree with that, but for such a “mature” industry we are terribly self-centered. While security is the most important thing to us, in spite of the self-deluding analysis we receive, it truly is not the most important thing to business. The most important thing to business is profits, followed closely by revenue.  Dotted lines and potential liabilities are all fine and dandy. But at best organizations put a small (3% to 4%) of their budget into security.  If something only is taking 3 to 4 percent of your budget, it probably only gets 3 to 4 percent of your time and attention. </p>  <p>This is the sad truth that a “mature” industry like ours has to realize. Until the problems and threats are felt by the business owners to warrant more than 3 to 4 percent investment, we are not going to see a radical change. </p>  <p>So lets be more positive about what we can do. Lets take our small wins and build on them instead of ridiculing them. We have come a long way and yes we have a long way to go. The rest of IT and the world will not wait for us, they will continue evolving at the breakneck pace they have been.  </p>  <p>But setting attainable goals, taking our wins when we can and trying to keep people positive about the mission is I think a better strategy then preaching doom and gloom that the sky is falling, even if maybe some days it seems like it is.</p>
<p><a href="http://feedads.g.doubleclick.net/~a/sRf1KtTsT_GcI6CcWn6-HAHhPbg/0/da"><img src="http://feedads.g.doubleclick.net/~a/sRf1KtTsT_GcI6CcWn6-HAHhPbg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/sRf1KtTsT_GcI6CcWn6-HAHhPbg/1/da"><img src="http://feedads.g.doubleclick.net/~a/sRf1KtTsT_GcI6CcWn6-HAHhPbg/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=uanRBfIJ_Ko:pbl5Hb7qc6Y:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=uanRBfIJ_Ko:pbl5Hb7qc6Y:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=uanRBfIJ_Ko:pbl5Hb7qc6Y:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=uanRBfIJ_Ko:pbl5Hb7qc6Y:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=uanRBfIJ_Ko:pbl5Hb7qc6Y:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=uanRBfIJ_Ko:pbl5Hb7qc6Y:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=uanRBfIJ_Ko:pbl5Hb7qc6Y:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=uanRBfIJ_Ko:pbl5Hb7qc6Y:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/uanRBfIJ_Ko" height="1" width="1"/>]]></content:encoded><description>I just returned home from the UNITED Security Summit in San Francisco. Besides speaking myself at the show I had a chance to sit in on some great presentations by some familiar and some not so familiar (to me anyway)...</description><media:content url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/D5rD28siqHc/8r1CZTLk-Gk" fileSize="3206" type="application/x-shockwave-flash" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>I just returned home from the UNITED Security Summit in San Francisco. Besides speaking myself at the show I had a chance to sit in on some great presentations by some familiar and some not so familiar (to me anyway)...</itunes:subtitle><itunes:author>Alan Shimel</itunes:author><itunes:summary>I just returned home from the UNITED Security Summit in San Francisco. Besides speaking myself at the show I had a chance to sit in on some great presentations by some familiar and some not so familiar (to me anyway)...</itunes:summary><itunes:keywords>security,network,security,infosec,IDS,IPS,Vulnerability,endpoint,security,NAC,software</itunes:keywords><feedburner:origLink>http://www.ashimmy.com/2011/09/an-open-letter-to-the-security-industry-we-live-in-amazing-times.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~5/D5rD28siqHc/8r1CZTLk-Gk" length="3206" type="application/x-shockwave-flash" /><feedburner:origEnclosureLink>http://www.youtube.com/v/8r1CZTLk-Gk?version=3&amp;amp;hl=en_US</feedburner:origEnclosureLink></item><item><title>If ATT Really Gave A Crap About Customers</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/0gIB7p72XiY/if-att-really-gave-crap-about-customers.html</link><category>General Background</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Fri, 16 Sep 2011 20:40:58 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2014e8b9ec53e970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<div style="margin: 1em; width: 310px; display: block; float: right" class="zemanta-img"><a href="http://commons.wikipedia.org/wiki/File:At%26tPhone.JPG"><img style="border-bottom: medium none; border-left: medium none; display: block; border-top: medium none; border-right: medium none" alt="Southwestern Bell payphone with new AT&amp;T signage" src="http://upload.wikimedia.org/wikipedia/commons/thumb/6/65/At%26tPhone.JPG/300px-At%26tPhone.JPG" width="300" height="400"></img></a>     <p style="font-size: 0.8em" class="zemanta-img-attribution">Image via <a href="http://commons.wikipedia.org/wiki/File:At%26tPhone.JPG">Wikipedia</a></p> </div>  <p>I had yet another eye opening experience today dealing with <a class="zem_slink" title="AT&amp;T" href="http://www.att.com/" rel="homepage">AT&amp;T</a>. It showed me once again why at the end of the day AT&amp;T could care less about their customers and just want to grab as much money as they can.</p>  <p>Over the last year I have fired them from being my internet provider at home, my local and long distance phone company and even bundling my satellite TV through them. The only thing I am stuck with them with is our family cell service because we have <a class="zem_slink" title="iPhone" href="http://www.apple.com/iphone" rel="homepage">iPhones</a> from way back.</p>  <p>My son though doesn’t have an iPhone. I bought him an Android <a class="zem_slink" title="HTC" href="http://www.htc.com/" rel="homepage">HTC</a> phone a few months ago. Today his phone was stolen out of his backpack at school. We will dive more into that later on, but for now let me tell you about AT&amp;T.</p>  <p>I called the 611 number and pressed the option to report a lost or stolen phone. Of course I couldn’t get a live person with that option. The only I could do was deal with the automated service to shut off <a class="zem_slink" title="The Phone (U.S. TV series)" href="http://www.mtv.com/ontv/dyn/the_phone/series.jhtml" rel="homepage">the phone</a> number.  I did that but it wasn’t good enough for me. I called back and didn’t fall into the automated trap. I got a live person on the phone and asked what we could do.</p>  <p>The rep told me that I could have signed up for a 10 dollar a month phone location service, but since I didn’t there was nothing they could do. I would have to pay data and phone charges on the account for the rest of the term of the contract.</p>  <p>I then asked what if someone brought my son’s phone into an AT&amp;T store. Would they check and see the serial number was stolen? Like trying to register a stolen car. The rep said what a great idea, but no they wouldn’t do that. If someone wants to open an AT&amp;T account they don’t care what phone they use. Can you imagine? They condone people using stolen phones.</p>  <p>Think about it. If they would have a stolen phone registry that was checked when phones were turned on, that would take the bottom out of the stolen phone business. But AT&amp;T doesn’t care, so they won’t.</p>  <p>As it turns out the <a class="zem_slink" title="Android Market" href="http://www.android.com/market/" rel="homepage">Android Market</a> has a great free app called Plan B.  It installs over the air and locates your phone for you.  How cool was that.  Do you think the AT&amp;T rep might tell someone reporting a phone lost or stolen about it? Nah, no money it for them.</p>  <p>As it turns out my son’s phone wasn’t stolen. It was hidden in the bottom of his book bag.  But that is not the point. AT&amp;T should be better than this.</p>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=9bc9a1ff-858e-470f-947b-57ce7a1ee1a6"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/SYPeFg-qewjfNZIGRsdKapTqyjE/0/da"><img src="http://feedads.g.doubleclick.net/~a/SYPeFg-qewjfNZIGRsdKapTqyjE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/SYPeFg-qewjfNZIGRsdKapTqyjE/1/da"><img src="http://feedads.g.doubleclick.net/~a/SYPeFg-qewjfNZIGRsdKapTqyjE/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=0gIB7p72XiY:gHXo-nRhScI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=0gIB7p72XiY:gHXo-nRhScI:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=0gIB7p72XiY:gHXo-nRhScI:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=0gIB7p72XiY:gHXo-nRhScI:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=0gIB7p72XiY:gHXo-nRhScI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=0gIB7p72XiY:gHXo-nRhScI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=0gIB7p72XiY:gHXo-nRhScI:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=0gIB7p72XiY:gHXo-nRhScI:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/0gIB7p72XiY" height="1" width="1"/>]]></content:encoded><description>Image via Wikipedia I had yet another eye opening experience today dealing with AT&amp;amp;T. It showed me once again why at the end of the day AT&amp;amp;T could care less about their customers and just want to grab as much...</description><feedburner:origLink>http://www.ashimmy.com/2011/09/if-att-really-gave-crap-about-customers.html</feedburner:origLink></item><item><title>Calling All Security/Tech Media in the Bay Area  UNITED Summit</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/-lsfHXnrhMg/calling-all-securitytech-media-in-the-bay-areaunited-summit.html</link><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 14 Sep 2011 09:16:58 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2015391997969970b</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e20154356cb04e970c-pi"><img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px 0px 4px 4px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top: 0px; border-right: 0px; padding-top: 0px" title="united-security-summit-logo" border="0" alt="united-security-summit-logo" align="right" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e2015391998077970b-pi" width="244" height="94"></img></a>I wanted to drop a quick note to all of my friends and acquaintances in the Bay Area.  Especially those in the tech/security media and analyst space.  A cool new security summit is being put on by Rapid7, Firemon and some other companies called the <a href="http://www.unitedsummit.org/">UNITED Security Summit</a> on Sept 19th and 20th.</p>  <p>The show is unique in that it is anchored around the “anatomy of a breach”.  They have a great line up of speakers including HD Moore, Chris Hoff and others. Even I am speaking on the Risk Management Big Top.  If you are in the bay area, I think this is a great event to come on down to learn.</p>  <p>If you are in the media or analyst space, Rapid7 has media/analyst passes available. They are also really going the extra mile to help make it a great summit.  If you are in the area, you should most definitely attend!</p>
<p><a href="http://feedads.g.doubleclick.net/~a/jPQdf4VUwZPWXBSRq5PWJiIXFYk/0/da"><img src="http://feedads.g.doubleclick.net/~a/jPQdf4VUwZPWXBSRq5PWJiIXFYk/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/jPQdf4VUwZPWXBSRq5PWJiIXFYk/1/da"><img src="http://feedads.g.doubleclick.net/~a/jPQdf4VUwZPWXBSRq5PWJiIXFYk/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=-lsfHXnrhMg:JKjQDGqlXTY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=-lsfHXnrhMg:JKjQDGqlXTY:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=-lsfHXnrhMg:JKjQDGqlXTY:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=-lsfHXnrhMg:JKjQDGqlXTY:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=-lsfHXnrhMg:JKjQDGqlXTY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=-lsfHXnrhMg:JKjQDGqlXTY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=-lsfHXnrhMg:JKjQDGqlXTY:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=-lsfHXnrhMg:JKjQDGqlXTY:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/-lsfHXnrhMg" height="1" width="1"/>]]></content:encoded><description>I wanted to drop a quick note to all of my friends and acquaintances in the Bay Area. Especially those in the tech/security media and analyst space. A cool new security summit is being put on by Rapid7, Firemon and...</description><feedburner:origLink>http://www.ashimmy.com/2011/09/calling-all-securitytech-media-in-the-bay-areaunited-summit.html</feedburner:origLink></item><item><title>Alert Logic CAPP Service</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/g4uS9rJZuYM/alert-logic-capp-service.html</link><category>cloud</category><category>Current Affairs</category><category>other security companies</category><category>outsourcing security</category><category>the security industry</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Wed, 14 Sep 2011 08:43:36 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e2014e8b8cff9c970d</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>As I have written before I do some writing and consulting for several companies. One of them is Alert Logic, who offer a great line up of <a class="zem_slink" title="cloud computing software" href="http://www.symantec.com/business/theme.jsp?themeid=cloud" rel="symantec">cloud-based</a>, <a class="zem_slink" title="security solution" href="http://www.symantec.com/business/services/detail/detail.jsp?pcid=consulting_services&amp;pvid=svc_security_prgm_assmt" rel="symantec">Security</a>-as-a-Service solutions.  </p>  <p>Today Alert Logic announced their new CAPP program which allows most any security vendor to leverage the AL cloud based platform, turning their security solution into a cloud based managed security service.  </p>  <p>I wrote about over on SecureCloudReview.com, but wanted to mention it on here as well. Here is the article from over on SCR: </p>  <blockquote>   <p>Today Alert Logic<a href="http://www.alertlogic.com/alert-logic-cloud-acceleration-partner-program-capp-allows-3rd-party-security-solutions-to-be-delivered-as-a-cloud-service"> announced</a> a significant new program that they are calling CAPP (<a href="http://en.wikipedia.org/wiki/Cloud_acceleration">Cloud Acceleration</a> Partner Program). CAPP allows just about any security solution to plug into the Alert Logic <a href="http://www.symantec.com/business/services/detail/detail.jsp?pcid=consulting_services&amp;pvid=svc_security_prgm_assmt">Security</a>-as-a-Service, <a href="http://www.symantec.com/business/theme.jsp?themeid=cloud">cloud based</a> architecture and become a cloud-based <a href="http://www.symantec.com/business/services/managed_services.jsp">managed service</a>. </p>    <p>This should be a huge development in the security marketplace.  Using the rich APIs developed for the CAPP program, security vendors seeking to integrate into the Alert Logic Security-as-a-Service offering can allow the cloud based platform to “ingest, correlate and analyze security data from individual security tools”. </p>    <p>The first CAPP partner announced for the program is <a href="http://www.rapid7.com/">Rapid7</a>, the company behind the Nexpose VM solution and the <a href="http://www.metasploit.com/">Metasploit</a> pen testing suite (Rapid7 is also hosting an exciting new conference called<a href="http://www.net-security.org/conference.php?id=445"> UNITED</a> next week). Utilizing the CAPP API’s Alert Logic and Rapid7 now offer ASV PCI scanning as a service.  Other partners should be announced soon. </p>    <p>The CAPP program means that security solution providers don’t have to invest in developing a cloud-based delivery and management solution. They can concentrate on making their own solutions better, yet still enjoy a managed, cloud based option. </p>    <p>From the Alert Logic point of view it allows them to build on their strengths. They have invested millions of dollars and years of time developing their cloud-based Security-as-a-Service platform.  Now in addition to the solutions they already offered via this platform, a new wide range of solutions will be available as well. </p>    <p>It should be very interesting to see what new solutions come via the cloud as a result of CAPP.  It is certainly a program and technology whose time has come.</p> </blockquote>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://securecloudreview.com/2011/09/is-as-a-service-code-for-the-cloud-should-it-be/">Is "as-a-Service" Code for the Cloud? Should it be?</a> (securecloudreview.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=324bd369-b0d0-4349-beac-8e1d04bfabcd"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/fkaY2fn4DQ06-yxzp4XgbF0kS1E/0/da"><img src="http://feedads.g.doubleclick.net/~a/fkaY2fn4DQ06-yxzp4XgbF0kS1E/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/fkaY2fn4DQ06-yxzp4XgbF0kS1E/1/da"><img src="http://feedads.g.doubleclick.net/~a/fkaY2fn4DQ06-yxzp4XgbF0kS1E/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=g4uS9rJZuYM:2jURWXbSRew:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=g4uS9rJZuYM:2jURWXbSRew:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=g4uS9rJZuYM:2jURWXbSRew:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=g4uS9rJZuYM:2jURWXbSRew:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=g4uS9rJZuYM:2jURWXbSRew:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=g4uS9rJZuYM:2jURWXbSRew:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=g4uS9rJZuYM:2jURWXbSRew:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=g4uS9rJZuYM:2jURWXbSRew:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/g4uS9rJZuYM" height="1" width="1"/>]]></content:encoded><description>As I have written before I do some writing and consulting for several companies. One of them is Alert Logic, who offer a great line up of cloud-based, Security-as-a-Service solutions. Today Alert Logic announced their new CAPP program which allows...</description><feedburner:origLink>http://www.ashimmy.com/2011/09/alert-logic-capp-service.html</feedburner:origLink></item><item><title>10 Years After, Anger</title><link>http://feedproxy.google.com/~r/StillsecureAfterAllTheseYears/~3/Im8NrKRsnek/10-years-after-anger.html</link><category>Current Affairs</category><category>General Background</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ashimmy@hotmail.com (Alan Shimel)</dc:creator><pubDate>Sun, 11 Sep 2011 21:02:41 PDT</pubDate><guid isPermaLink="false">tag:typepad.com,2003:post-6a00d83451e4d369e20154355958b1970c</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I was going to rerun the 9/11 post I wrote 5 years ago to commemorate the 10th anniversary of that terrible terrorist attack that took my wife’s beautiful older sister from her family. But I am not going to post that, you can read it <a href="http://www.ashimmy.com/2010/09/a-reluctant-post-on-911.html">here</a> if you like.</p>  <p>Instead I want to write about a change of my world view with the passing of 10 years since that attack on our country and our way of life. Watching all of the 10 year anniversary stuff these past few days had a cumulative effect on me.  With each passing story of someone’s tragedy on 9/11, I grew more dark, more angry, more resentful.</p>  <p>On top of this I look around our world and realize that after 10 years of more families losing loved ones as they fight far from our own shores, what do we have to show for it? Yes we killed OBL.  We have even killed a decent amount of the leaders of the terrorists. But what have we really accomplished?</p>  <p>The system that spawned these monsters still exists. We have seen an “Arab Spring” overthrowing dictators in several Arab states. But what are they replaced with? We delude ourselves if we think pro-Western regimes are springing up in the MidEast.  Even Iraq where we have spent trillions of dollars and thousands of lives, is not a stable democracy.  As soon as we leave there, Iran will exert even more influence.  Egypt, that takes billions of dollars in aid from us every year is ruled by mobs that rape female journalists. Saudi Arabia, “our friend” in the Arab world buys off their people with the oil money they suck from our veins, but the kings of Arabia have a short horizon and are themselves radically out of line with our world view.</p>  <p>Afghanistan will be as twisted as it ever was on the day we finally leave there.  The fact is we have few if any friends in that part of the world. Lets stop spending our money trying to change an unchangeable fact. Lets not spill any more of our blood trying to make them “safe for democracy”.  We are going to be fighting a war against these anti-American, anti-Western foes for a long time.  </p>  <p align="center">The Hamas, Hezbollah and the rest are not going to be made over, they are what they are.  We need to treat them as such. They are our enemies and we need to destroy our enemies.  </p>  <p align="center">Let them build the next memorials to their dead and grieve for loved ones. I don’t want any more sacred memorials to our innocent dead here.</p>  <p align="center">Is that harsh? Is that just? Frankly I don’t care, it is what we need to do.</p>  <div class="zemanta-related">   <h6 style="font-size: 1em" class="zemanta-related-title">Related articles</h6>    <ul class="zemanta-article-ul">     <li class="zemanta-article-ul-li"><a href="http://lewrockwell.com/vance/vance257.html">Why They Hate Us</a> (lewrockwell.com)</li>      <li class="zemanta-article-ul-li"><a href="http://www.salon.com/news/feature/2011/09/06/9_11_saudia_arabia/index.html?aim=/news/feature">Saudi Arabia's 9/11 legacy</a> (salon.com)</li>   </ul> </div>  <div style="margin-top: 10px; height: 15px" class="zemanta-pixie"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img style="border-bottom-style: none; border-left-style: none; border-top-style: none; float: right; border-right-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=69411fbc-f1eb-401d-9d72-2878bfe8a126"></img></a></div>
<p><a href="http://feedads.g.doubleclick.net/~a/4yxhaRmQkc7WnOc4UQVNJOvILZs/0/da"><img src="http://feedads.g.doubleclick.net/~a/4yxhaRmQkc7WnOc4UQVNJOvILZs/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/4yxhaRmQkc7WnOc4UQVNJOvILZs/1/da"><img src="http://feedads.g.doubleclick.net/~a/4yxhaRmQkc7WnOc4UQVNJOvILZs/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Im8NrKRsnek:Myrkqadkzms:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Im8NrKRsnek:Myrkqadkzms:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Im8NrKRsnek:Myrkqadkzms:YwkR-u9nhCs"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=YwkR-u9nhCs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Im8NrKRsnek:Myrkqadkzms:dMcygGhlNJA"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?d=dMcygGhlNJA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Im8NrKRsnek:Myrkqadkzms:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=Im8NrKRsnek:Myrkqadkzms:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?a=Im8NrKRsnek:Myrkqadkzms:aZ45XMlo8-Q"><img src="http://feeds.feedburner.com/~ff/StillsecureAfterAllTheseYears?i=Im8NrKRsnek:Myrkqadkzms:aZ45XMlo8-Q" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/Im8NrKRsnek" height="1" width="1"/>]]></content:encoded><description>I was going to rerun the 9/11 post I wrote 5 years ago to commemorate the 10th anniversary of that terrible terrorist attack that took my wife’s beautiful older sister from her family. But I am not going to post...</description><feedburner:origLink>http://www.ashimmy.com/2011/09/10-years-after-anger.html</feedburner:origLink></item><copyright>copyright 2010 all rights reserved</copyright><media:credit role="author">Alan Shimel</media:credit><media:rating>nonadult</media:rating></channel></rss>

