<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CEIARn89cCp7ImA9WhdREUU.&quot;"><id>tag:blogger.com,1999:blog-14940812</id><updated>2011-08-01T11:09:07.168+04:00</updated><category term="visualization" /><category term="back security blog mobile website" /><category term="esgulf" /><category term="comment" /><category term="podcast" /><category term="month" /><category term="smart card" /><category term="security now" /><category term="security" /><category term="keynote" /><category term="policy" /><category term="skype" /><category term="monitoring" /><category term="conference" /><category term="jorge sebastiao" /><category term="awareness" /><category term="security awareness" /><category term="parents" /><category term="managed services" /><category term="psychology" /><category term="social networks" /><category term="background checks" /><category term="intrusion" /><category term="ips" /><category term="ids" /><category term="internet" /><category term="bruce schneiner" /><category term="video" /><category term="identity theft" /><category term="screen passwords" /><category term="warriorsofthenet" /><category term="kids" /><title>4Sec - 4 Seconds -- For Security</title><subtitle type="html">In today's complex world security is elusive. We use the latest electronics, mobiles and internet. It can take as little as 4 Seconds to gain or lose security...</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://4sec.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>64</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/blogspot/aTQX" /><feedburner:info uri="blogspot/atqx" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;DEQDRHc-cSp7ImA9WhZSEU4.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-897705552096462200</id><published>2011-03-26T13:46:00.001+03:00</published><updated>2011-03-26T13:46:15.959+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-26T13:46:15.959+03:00</app:edited><title /><content type="html">The arms race used by ME event organizers to protect access to social networks &lt;a href="http://ping.fm/0i1Da"&gt;http://ping.fm/0i1Da&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-897705552096462200?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/7jwMVbd1GKE8G3WLRnoYBi1dm0c/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7jwMVbd1GKE8G3WLRnoYBi1dm0c/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/7jwMVbd1GKE8G3WLRnoYBi1dm0c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7jwMVbd1GKE8G3WLRnoYBi1dm0c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/a0cDR5vTSsc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/897705552096462200/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=897705552096462200" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/897705552096462200?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/897705552096462200?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/a0cDR5vTSsc/arms-race-used-by-me-event-organizers.html" title="" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2011/03/arms-race-used-by-me-event-organizers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0MHQ3k6cSp7ImA9Wx9aF0o.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-7819242121915405731</id><published>2011-03-10T20:50:00.001+03:00</published><updated>2011-03-10T20:50:32.719+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-10T20:50:32.719+03:00</app:edited><title /><content type="html">Anonymous group will also now focus on large business and US Gov. &lt;a href="http://ping.fm/RWrkJ"&gt;http://ping.fm/RWrkJ&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-7819242121915405731?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Dr5rrDkWWxUXEYxgB8Fz21wtL3s/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Dr5rrDkWWxUXEYxgB8Fz21wtL3s/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Dr5rrDkWWxUXEYxgB8Fz21wtL3s/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Dr5rrDkWWxUXEYxgB8Fz21wtL3s/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/K_FkyG2v7OI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/7819242121915405731/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=7819242121915405731" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/7819242121915405731?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/7819242121915405731?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/K_FkyG2v7OI/anonymous-group-will-also-now-focus-on.html" title="" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2011/03/anonymous-group-will-also-now-focus-on.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQDR3czeCp7ImA9WxBQEUs.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-2582591235631125843</id><published>2010-01-11T02:46:00.001+03:00</published><updated>2010-01-11T02:49:36.980+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-11T02:49:36.980+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="visualization" /><category scheme="http://www.blogger.com/atom/ns#" term="managed services" /><category scheme="http://www.blogger.com/atom/ns#" term="ips" /><category scheme="http://www.blogger.com/atom/ns#" term="intrusion" /><category scheme="http://www.blogger.com/atom/ns#" term="ids" /><title>The value of IDS/IPS visualization in Managed Services</title><content type="html">&lt;object width="705" height="660"&gt; &lt;param name="movie" value="http://www.brighttalk.com/dc/swf/dotcom_base.swf?212"&gt; &lt;/param&gt; &lt;param name="flashvars" value="channelid=288&amp;commid=6203&amp;autoStart=FALSE"&gt; &lt;/param&gt; &lt;embed src="http://www.brighttalk.com/dc/swf/dotcom_base.swf?234" type="application/x-shockwave-flash" width="705" height="660" wmode="transparent" flashvars="channelid=288&amp;commid=6203&amp;autoStart=FALSE"&gt; &lt;/embed&gt; &lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-2582591235631125843?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qQMSvhrd1ZQODAyqB9YdUv8MsNk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qQMSvhrd1ZQODAyqB9YdUv8MsNk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qQMSvhrd1ZQODAyqB9YdUv8MsNk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qQMSvhrd1ZQODAyqB9YdUv8MsNk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/gWsKK1Y8pTs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/2582591235631125843/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=2582591235631125843" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2582591235631125843?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2582591235631125843?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/gWsKK1Y8pTs/value-of-idsips-visualization-in.html" title="The value of IDS/IPS visualization in Managed Services" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2010/01/value-of-idsips-visualization-in.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QGSHY6cCp7ImA9WxNaEEo.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-8975718862651258229</id><published>2009-11-24T18:05:00.003+03:00</published><updated>2009-11-24T18:08:49.818+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-24T18:08:49.818+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="kids" /><category scheme="http://www.blogger.com/atom/ns#" term="parents" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="awareness" /><title>Parents responsibility and security</title><content type="html">Are parents being responsible for the security of their kids online? As a parent you must take responsibility for your kids actions online. The following video from Winn highlights this in a practical educational way:&lt;br /&gt;&lt;object width="560" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/YRcqlf2e50o&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/YRcqlf2e50o&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-8975718862651258229?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/UKY_RG6KWGTTJjd0FamGi_exZHg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UKY_RG6KWGTTJjd0FamGi_exZHg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/UKY_RG6KWGTTJjd0FamGi_exZHg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UKY_RG6KWGTTJjd0FamGi_exZHg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/DYfdHKYPeV8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/8975718862651258229/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=8975718862651258229" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/8975718862651258229?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/8975718862651258229?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/DYfdHKYPeV8/parents-responsibility-and-security.html" title="Parents responsibility and security" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/11/parents-responsibility-and-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcAR3w7fip7ImA9WxNaEEo.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-2766050256136358163</id><published>2009-11-03T18:16:00.001+03:00</published><updated>2009-11-24T18:20:46.206+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-24T18:20:46.206+03:00</app:edited><title>Patch, Patch, Patch, Tuesday?</title><content type="html">&lt;div&gt;It is Tuesday? what is on the menu? Patches&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;In the world of security awareness metrics are sometimes important. One of these metrics comes from using the Microsoft operating system and having to patch it every tuesday.&lt;br /&gt;&lt;br /&gt;The article to computer world brings in the numbers:&lt;br /&gt;- 6 years of Patch Tuesdays,&lt;br /&gt;- 400 security bulletins,&lt;br /&gt;- 745 vulnerabilities&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computerworld.com/s/article/9139364/In_six_years_of_Patch_Tuesdays_400_security_bulletins_745_vulnerabilities"&gt;Patch Tuesday Article&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-2766050256136358163?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6FtLymD-GUXCW8Sfxc-aYXW-low/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6FtLymD-GUXCW8Sfxc-aYXW-low/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6FtLymD-GUXCW8Sfxc-aYXW-low/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6FtLymD-GUXCW8Sfxc-aYXW-low/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/NpuTCnwA3ME" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/2766050256136358163/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=2766050256136358163" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2766050256136358163?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2766050256136358163?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/NpuTCnwA3ME/patch-patch-patch-tuesday.html" title="Patch, Patch, Patch, Tuesday?" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/11/patch-patch-patch-tuesday.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08DQnk5eCp7ImA9WxNaFk0.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-7044782313961496777</id><published>2009-10-15T22:33:00.000+04:00</published><updated>2009-11-30T22:37:53.720+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T22:37:53.720+03:00</app:edited><title>Importance of Security Awareness at highest levels.</title><content type="html">&lt;div&gt;When Obama talks people listen, not only because he is a well versed speaker but also because he holds a post of the highest responsibility. So getting a message of security awareness at not only the individual, corporate, regional, state/province but country level raises the importance of the message it provides. Enjoy and take action &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;object width="560" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/UIIY9AQSqbY&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/UIIY9AQSqbY&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-7044782313961496777?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Wn-DFrcdCdTyJVSnWqbFc5zBJiU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Wn-DFrcdCdTyJVSnWqbFc5zBJiU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Wn-DFrcdCdTyJVSnWqbFc5zBJiU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Wn-DFrcdCdTyJVSnWqbFc5zBJiU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/NfGV7fZ2u0A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/7044782313961496777/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=7044782313961496777" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/7044782313961496777?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/7044782313961496777?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/NfGV7fZ2u0A/importance-of-security-awareness-at.html" title="Importance of Security Awareness at highest levels." /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/10/importance-of-security-awareness-at.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IDR306fSp7ImA9WxNaFk0.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-1567629903816552604</id><published>2009-09-30T18:10:00.000+04:00</published><updated>2009-11-30T22:32:56.315+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T22:32:56.315+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="month" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="awareness" /><title>October is security awareness month!</title><content type="html">October is security awareness month, so here is a top 10 presentation and movie trailer from Winn Security Awareness blog:&lt;br /&gt;&lt;object width="560" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/F6doO9hVQjE&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/F6doO9hVQjE&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-1567629903816552604?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_XE_Hw5X2VjN36VbeAjVbY5keY8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_XE_Hw5X2VjN36VbeAjVbY5keY8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_XE_Hw5X2VjN36VbeAjVbY5keY8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_XE_Hw5X2VjN36VbeAjVbY5keY8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/JpC7RPByMfo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/1567629903816552604/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=1567629903816552604" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1567629903816552604?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1567629903816552604?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/JpC7RPByMfo/october-is-security-awareness-month.html" title="October is security awareness month!" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/10/october-is-security-awareness-month.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEDSX49eSp7ImA9WxNaFkw.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-4999922862922505168</id><published>2009-08-24T22:41:00.001+04:00</published><updated>2009-11-30T22:51:18.061+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T22:51:18.061+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="background checks" /><title>Background checks and human nature</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_edMpyFux25g/SxQgynlcCjI/AAAAAAAACYQ/YK04YCvFSWE/s1600/background_checks.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 250px; height: 215px;" src="http://1.bp.blogspot.com/_edMpyFux25g/SxQgynlcCjI/AAAAAAAACYQ/YK04YCvFSWE/s320/background_checks.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5409985106370366002" /&gt;&lt;/a&gt;Background checks are an important part of the security process. Background checks are used for:&lt;div&gt;- hiring new employees&lt;/div&gt;&lt;div&gt;- vetting employees for high risk positions&lt;/div&gt;&lt;div&gt;- providing security clearing for government organizations&lt;/div&gt;&lt;div&gt;- providing military clearance&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;However background checks are not performed by automated machines but rather by people. As mentioned many times before people are the weakest link in the security chain. Since people are not always good at discipline, consistency and process.&lt;/div&gt;&lt;div&gt;If we combine these commons flaws further with greed the mixture delivers an unreliable proposition for security. So in background check always "double check" . &lt;a href="http://www.examiner.com/x-13426-CIA-Examiner~y2009m8d18-Laziness-and-greed-behind-faked-CIA-background-checks"&gt;The following article and evolving story highlights the problems of background checks...&lt;/a&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-4999922862922505168?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oexcTslrUUx0qZlqe5Bing6e5jM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oexcTslrUUx0qZlqe5Bing6e5jM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oexcTslrUUx0qZlqe5Bing6e5jM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oexcTslrUUx0qZlqe5Bing6e5jM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/neInmCXKCBQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/4999922862922505168/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=4999922862922505168" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/4999922862922505168?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/4999922862922505168?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/neInmCXKCBQ/background-checks-and-human-nature.html" title="Background checks and human nature" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_edMpyFux25g/SxQgynlcCjI/AAAAAAAACYQ/YK04YCvFSWE/s72-c/background_checks.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/08/background-checks-and-human-nature.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4GQH4yeip7ImA9WxNaFkw.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-8363434824196392713</id><published>2009-07-30T00:00:00.000+04:00</published><updated>2009-12-01T00:02:01.092+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-01T00:02:01.092+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="security awareness" /><title>When I go to UVA Security Awareness</title><content type="html">When I go to UVA is a short video on security awareness...&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/aJZrw68fGl0&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/aJZrw68fGl0&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-8363434824196392713?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/EIrA9TXoXffAwvOVKIdodYNqWAg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EIrA9TXoXffAwvOVKIdodYNqWAg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/EIrA9TXoXffAwvOVKIdodYNqWAg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EIrA9TXoXffAwvOVKIdodYNqWAg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/AoiuAdar1f0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/8363434824196392713/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=8363434824196392713" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/8363434824196392713?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/8363434824196392713?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/AoiuAdar1f0/when-i-go-to-uva-security-awareness.html" title="When I go to UVA Security Awareness" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/07/when-i-go-to-uva-security-awareness.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IGRnwyfSp7ImA9WxNaFkw.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-4128982429134175743</id><published>2009-06-30T22:57:00.000+04:00</published><updated>2009-11-30T23:05:27.295+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T23:05:27.295+03:00</app:edited><title>Hacking expense claims</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_edMpyFux25g/SxQjrzjOB4I/AAAAAAAACYY/KzPhxpoJdFk/s1600/any-store_any-town.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 266px; height: 213px;" src="http://4.bp.blogspot.com/_edMpyFux25g/SxQjrzjOB4I/AAAAAAAACYY/KzPhxpoJdFk/s320/any-store_any-town.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5409988287858083714" /&gt;&lt;/a&gt;Money always provides a motivation for the criminal mind. A psychology study done for common individuals (that means your employee) rates them into three categories:&lt;div&gt;- honest (nothing to worry about but it accounts for only 10-15% or so)&lt;/div&gt;&lt;div&gt;- dishonest (you need to take full measure here, but also it accounts for only 10-15% or so)&lt;/div&gt;&lt;div&gt;- waver (this is everyone else or 60-80%)&lt;/div&gt;&lt;div&gt;We are are apply Vincento Paretto principle also known as 80/20 rule.  &lt;/div&gt;&lt;div&gt;The 80% or the majority you need to put in place the controls to avoid problems. One example could easily be made in expense claims. The internet goes even further by make it easier with sites like:&lt;/div&gt;&lt;div&gt;- &lt;a href="http://www.salesreceiptstore.com/index.html"&gt;the sales receipt store&lt;/a&gt;, will provide you a receipt for any occasion.&lt;/div&gt;&lt;div&gt;So take the time to verify the source of these expense claims it can save your corporation lots of valuable money.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-4128982429134175743?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TQbuVFxVFg9xIEM4jiPuW1mK9Kw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TQbuVFxVFg9xIEM4jiPuW1mK9Kw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TQbuVFxVFg9xIEM4jiPuW1mK9Kw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TQbuVFxVFg9xIEM4jiPuW1mK9Kw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/yDRLt6B2Fjw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/4128982429134175743/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=4128982429134175743" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/4128982429134175743?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/4128982429134175743?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/yDRLt6B2Fjw/hacking-expense-claims.html" title="Hacking expense claims" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_edMpyFux25g/SxQjrzjOB4I/AAAAAAAACYY/KzPhxpoJdFk/s72-c/any-store_any-town.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/06/hacking-expense-claims.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QHSHs7fyp7ImA9WxNaFk0.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-2924270991636179317</id><published>2009-04-30T22:18:00.004+04:00</published><updated>2009-11-30T22:28:59.507+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T22:28:59.507+03:00</app:edited><title>Memory stick best practices for end-users</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_edMpyFux25g/SxQbVX4L8MI/AAAAAAAACYI/MSWyJDjnAUY/s1600/usb-memory-stick.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 140px;" src="http://3.bp.blogspot.com/_edMpyFux25g/SxQbVX4L8MI/AAAAAAAACYI/MSWyJDjnAUY/s320/usb-memory-stick.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5409979106379690178" /&gt;&lt;/a&gt;We are using increasingly powerful portable memory technology the "USB Memory Stick". Originally developed for the cameras and photo world, the memory stick made its transition to the portable word via the USB format.&lt;div&gt;Today the USB memory sticks can carry 8GB or more in a format the can easily be carried. 8GB is more them hard disk capacity of earlier PC or even Mainframes. &lt;/div&gt;&lt;div&gt;So with the extra capacity comes the extra risk of higher amounts of information being disclosed by this high density portable medium.&lt;/div&gt;&lt;div&gt;We normally now recommend the users encrypt the information contained on these USB memory sticks as a "best practice". This same best practice advises that the key or password used to  encrypt the USB should be kept in separate location. &lt;/div&gt;&lt;div&gt;Many users forget easily this simple fact, the consequences can be quite dramatic disclosure of confidential information. &lt;a href="http://news.bbc.co.uk/2/hi/uk_news/england/lancashire/8003757.stm"&gt;See the following article from BBC which highlights this case.&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_edMpyFux25g/SxQat05ZDII/AAAAAAAACYA/5beW-FPFJB8/s1600/usb-memory-stick.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-2924270991636179317?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-Yo-724sRjoLKnfPD4_87q-c93c/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-Yo-724sRjoLKnfPD4_87q-c93c/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-Yo-724sRjoLKnfPD4_87q-c93c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-Yo-724sRjoLKnfPD4_87q-c93c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/6-DzlEMacRY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/2924270991636179317/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=2924270991636179317" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2924270991636179317?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2924270991636179317?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/6-DzlEMacRY/memory-stick-best-practices-for-end.html" title="Memory stick best practices for end-users" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_edMpyFux25g/SxQbVX4L8MI/AAAAAAAACYI/MSWyJDjnAUY/s72-c/usb-memory-stick.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/04/memory-stick-best-practices-for-end.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMGR3g7eip7ImA9WxNaFk0.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-4541692802416016506</id><published>2009-03-31T21:49:00.000+04:00</published><updated>2009-11-30T21:57:06.602+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T21:57:06.602+03:00</app:edited><title>New ways to sniff what you type?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_edMpyFux25g/SxQUXyx9_dI/AAAAAAAACX4/SsSZBljxDq8/s1600/keyboard.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 164px;" src="http://3.bp.blogspot.com/_edMpyFux25g/SxQUXyx9_dI/AAAAAAAACX4/SsSZBljxDq8/s200/keyboard.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5409971451379711442" /&gt;&lt;/a&gt;Ways to capture what you type on a keyboard have always be of interest to both hackers and intelligence agencies. Many approaches have existed for years:&lt;div&gt;- capturing electronic emanations&lt;/div&gt;&lt;div&gt;- using dongle memory devices which attach to keyboard cable&lt;/div&gt;&lt;div&gt;- altered keyboards which record key strokes and get replaced during warranty period with all the valuable information&lt;/div&gt;&lt;div&gt;- keystroke trojans&lt;/div&gt;&lt;div&gt;- etc...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;But technology for sniffing what you type is here. This technology is based on laser listening technology similar to the one which is used today to listen to you talk across walls and windows.&lt;/div&gt;&lt;div&gt;&lt;a href="http://news.zdnet.com/2100-9595_22-280184.html"&gt;The following article from Zdnet provides more details...&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-4541692802416016506?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/27lZ9gKkUUFmAidoLrIDIhp-bwE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/27lZ9gKkUUFmAidoLrIDIhp-bwE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/27lZ9gKkUUFmAidoLrIDIhp-bwE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/27lZ9gKkUUFmAidoLrIDIhp-bwE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/ym1803-TKRw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/4541692802416016506/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=4541692802416016506" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/4541692802416016506?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/4541692802416016506?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/ym1803-TKRw/new-ways-to-sniff-what-you-type.html" title="New ways to sniff what you type?" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_edMpyFux25g/SxQUXyx9_dI/AAAAAAAACX4/SsSZBljxDq8/s72-c/keyboard.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/03/new-ways-to-sniff-what-you-type.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE8HR38_eSp7ImA9WxNaFk0.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-6428000422615211935</id><published>2009-02-28T21:42:00.002+03:00</published><updated>2009-11-30T21:47:16.141+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-30T21:47:16.141+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="skype" /><category scheme="http://www.blogger.com/atom/ns#" term="monitoring" /><title>Monitoring Skype is valuable?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_edMpyFux25g/SxQSRstjN1I/AAAAAAAACXw/hSu-OE-Mfls/s1600/skype.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 200px;" src="http://4.bp.blogspot.com/_edMpyFux25g/SxQSRstjN1I/AAAAAAAACXw/hSu-OE-Mfls/s200/skype.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5409969147648096082" /&gt;&lt;/a&gt;The NSA wants to learn how to do better skype monitoring ("lawful interception"). As we know by now skype is used by:&lt;div&gt;- cyber criminals&lt;/div&gt;&lt;div&gt;- traditional criminals &lt;/div&gt;&lt;div&gt;- terrorists&lt;/div&gt;&lt;div&gt;- sex offenders&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;to escape monitoring and detection.&lt;/div&gt;&lt;div&gt;So the monitoring of skype is of great interest to intelligence agencies such as NSA or others.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.theregister.co.uk/2009/02/12/nsa_offers_billions_for_skype_pwnage/"&gt;More details from the register article...&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-6428000422615211935?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6VgpgAhaXT3HwXMQDfPsIYEaEJw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6VgpgAhaXT3HwXMQDfPsIYEaEJw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6VgpgAhaXT3HwXMQDfPsIYEaEJw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6VgpgAhaXT3HwXMQDfPsIYEaEJw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/z82Li_sOepw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/6428000422615211935/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=6428000422615211935" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/6428000422615211935?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/6428000422615211935?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/z82Li_sOepw/monitoring-skype-is-valuable.html" title="Monitoring Skype is valuable?" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_edMpyFux25g/SxQSRstjN1I/AAAAAAAACXw/hSu-OE-Mfls/s72-c/skype.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/02/monitoring-skype-is-valuable.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UFSH4zeCp7ImA9WxNaEEo.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-1985940872619865692</id><published>2009-01-15T18:54:00.003+03:00</published><updated>2009-11-24T19:13:39.080+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-24T19:13:39.080+03:00</app:edited><title>Can the technology we use introduce risk?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_edMpyFux25g/SwwFVYKlbgI/AAAAAAAACWc/b_7wRyPpmSI/s1600/warcraft.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 195px;" src="http://1.bp.blogspot.com/_edMpyFux25g/SwwFVYKlbgI/AAAAAAAACWc/b_7wRyPpmSI/s200/warcraft.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5407703117387361794" /&gt;&lt;/a&gt;The technology we use today makes our lives easier (sometimes). However this same technology introduces risk:&lt;br /&gt;- Identity theft (impersonating)&lt;br /&gt;- Cyber-war  (facilitating)&lt;br /&gt;- Terrorism (facilitating)&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Some of the technologies we use today have a certain element of risk:&lt;/div&gt;&lt;div&gt;- Linkedin can be used to impersonate you&lt;/div&gt;&lt;div&gt;- Facebook can be use to collect information on you and your friends&lt;/div&gt;&lt;div&gt;- Unpatched windows can be used to propagate botnets, these computer once infected can be use to launch cyber-warfare (see case of Estonia attack)&lt;/div&gt;&lt;div&gt;- Twitter can be use to track you and has been used by Terrorist during the attack in India&lt;/div&gt;&lt;div&gt;- Skype and peer to peer, both these technologies can help bypass legal interception and avoid detection&lt;/div&gt;&lt;div&gt;- Google earth and World of Warcraft has been used by terrorist for planning and training&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;All the technologies we  use today have both a good and bad side. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-1985940872619865692?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NIOcNvFMVC1SG5YoDVQxgwlBT1M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NIOcNvFMVC1SG5YoDVQxgwlBT1M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NIOcNvFMVC1SG5YoDVQxgwlBT1M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NIOcNvFMVC1SG5YoDVQxgwlBT1M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/eB0v8ztXH2A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/1985940872619865692/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=1985940872619865692" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1985940872619865692?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1985940872619865692?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/eB0v8ztXH2A/can-technology-we-use-introduce-risk.html" title="Can the technology we use introduce risk?" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_edMpyFux25g/SwwFVYKlbgI/AAAAAAAACWc/b_7wRyPpmSI/s72-c/warcraft.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2009/01/can-technology-we-use-introduce-risk.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEAQns5fCp7ImA9WxNaEEo.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-2289995827285921445</id><published>2008-12-24T18:27:00.000+03:00</published><updated>2009-11-24T18:30:43.524+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-24T18:30:43.524+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="screen passwords" /><title>Screen Passwords</title><content type="html">The following cartoon from Dilbert introduces the importance of screen passwords in a funny way.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://dilbert.com/strips/comic/2008-12-07/" title="Dilbert.com"&gt;&lt;img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/30000/4000/000/34008/34008.strip.sunday.gif" border="0" alt="Dilbert.com" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-2289995827285921445?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/377PihnlnYpf6ltOcjxGYuQY-aw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/377PihnlnYpf6ltOcjxGYuQY-aw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/377PihnlnYpf6ltOcjxGYuQY-aw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/377PihnlnYpf6ltOcjxGYuQY-aw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/E3vfkHpT3KU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/2289995827285921445/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=2289995827285921445" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2289995827285921445?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2289995827285921445?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/E3vfkHpT3KU/screen-passwords.html" title="Screen Passwords" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/12/screen-passwords.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4NR3w-eCp7ImA9WxNaEEQ.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-3938120680989080990</id><published>2008-07-01T23:33:00.000+04:00</published><updated>2009-11-24T23:36:36.250+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-24T23:36:36.250+03:00</app:edited><title>Difference between traditional crime and Identity Theft</title><content type="html">This short audio clip provide a funny view of Identity Theft. Useful for security awareness programs.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/CS9ptA3Ya9E&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/CS9ptA3Ya9E&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-3938120680989080990?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vBhERslYHPLitpWOFhgGvI-hLr4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vBhERslYHPLitpWOFhgGvI-hLr4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vBhERslYHPLitpWOFhgGvI-hLr4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vBhERslYHPLitpWOFhgGvI-hLr4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/2ldr4QCHJOU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/3938120680989080990/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=3938120680989080990" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/3938120680989080990?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/3938120680989080990?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/2ldr4QCHJOU/difference-between-traditional-crime.html" title="Difference between traditional crime and Identity Theft" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/07/difference-between-traditional-crime.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8HRnszfCp7ImA9WxNaEEo.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-1913234788129223502</id><published>2008-04-01T17:53:00.002+04:00</published><updated>2009-11-24T18:00:37.584+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-24T18:00:37.584+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="warriorsofthenet" /><category scheme="http://www.blogger.com/atom/ns#" term="internet" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="awareness" /><title>What makes the net so different?</title><content type="html">One of the challenges of implementing security awareness campaign is to explain to end users the internet ("net") and its complexity. One always says a picture is worth a thousand words, the following video introduces the "net" in a simple way:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Ve7_4ot-Dzs&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Ve7_4ot-Dzs&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-1913234788129223502?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fqHo4nfbI8LrNABXAMjecmab6k4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fqHo4nfbI8LrNABXAMjecmab6k4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fqHo4nfbI8LrNABXAMjecmab6k4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fqHo4nfbI8LrNABXAMjecmab6k4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/hMsh6qTZcvc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/1913234788129223502/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=1913234788129223502" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1913234788129223502?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1913234788129223502?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/hMsh6qTZcvc/what-makes-net-so-different.html" title="What makes the net so different?" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/04/what-makes-net-so-different.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UHSHw_eip7ImA9WxZQGE8.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-6401104730877608272</id><published>2008-02-24T07:56:00.002+03:00</published><updated>2008-02-24T08:00:39.242+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-24T08:00:39.242+03:00</app:edited><title>Failures of Disk Encryption</title><content type="html">"Security is not a product but a skilled continuous process which requires thought..." Jorge Sebastiao, 1999.&lt;br /&gt;&lt;br /&gt;Even for the best technologies there is always a weak point which must be addressed, in this case Disk Encryption as its weakness. The weakness is that even in memory the keys exist in some readable format, if we can get to it, then it is game over:&lt;br /&gt;&lt;br /&gt;&lt;a style="left: 0px ! important; top: 15px ! important;" title="Click here to block this object with Adblock Plus" class="abp-objtab-016027062752206356 visible ontop" href="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1"&gt;&lt;/a&gt;&lt;a style="left: 0px ! important; top: 15px ! important;" title="Click here to block this object with Adblock Plus" class="abp-objtab-016027062752206356 visible ontop" href="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1"&gt;&lt;/a&gt;&lt;object height="355" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1" type="application/x-shockwave-flash" wmode="transparent" height="355" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-6401104730877608272?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/MMy2-uRjNaOcrBbdBvR0rP5aswo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MMy2-uRjNaOcrBbdBvR0rP5aswo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/MMy2-uRjNaOcrBbdBvR0rP5aswo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MMy2-uRjNaOcrBbdBvR0rP5aswo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/IDDBKWEG_64" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/6401104730877608272/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=6401104730877608272" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/6401104730877608272?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/6401104730877608272?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/IDDBKWEG_64/failures-of-disk-encryption.html" title="Failures of Disk Encryption" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/02/failures-of-disk-encryption.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ABQ3k-fip7ImA9WxZRFko.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-1847810519158251092</id><published>2008-02-10T23:16:00.000+03:00</published><updated>2008-02-10T23:35:52.756+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-10T23:35:52.756+03:00</app:edited><title>Social engineering targets jobseekers</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_edMpyFux25g/R69eZ0lat3I/AAAAAAAAA6Q/JLG9EvTAvAI/s1600-h/jobseeker.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_edMpyFux25g/R69eZ0lat3I/AAAAAAAAA6Q/JLG9EvTAvAI/s200/jobseeker.jpg" alt="" id="BLOGGER_PHOTO_ID_5165451095322572658" border="0" /&gt;&lt;/a&gt;Social engineering for profit see no limits. This time the social engineer aka Hackers are targeting the job seekers by creating a fake web site which is collecting:&lt;br /&gt;- personal data&lt;br /&gt;- CV information&lt;br /&gt;- fees for visa processing (profit motive)&lt;br /&gt;&lt;br /&gt;Please find the links to the original site:&lt;br /&gt;- &lt;a href="http://www.mol.gov.ae/"&gt;Real Ministry of Labor&lt;/a&gt;  http://www.mol.gov.ae/&lt;br /&gt;and the fake site&lt;br /&gt;- &lt;a href="http://www.uaeministryoflabour.tk/"&gt;Fake Ministry of Labor&lt;/a&gt;   http://www.uaeministryoflabour.tk/&lt;br /&gt;&lt;br /&gt;Real site and Fake site are mirror copies of each other&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_edMpyFux25g/R69flklat4I/AAAAAAAAA6Y/dD5bWv3twWA/s1600-h/uaeminlabor.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_edMpyFux25g/R69flklat4I/AAAAAAAAA6Y/dD5bWv3twWA/s400/uaeminlabor.jpg" alt="" id="BLOGGER_PHOTO_ID_5165452396697663362" border="0" /&gt;&lt;/a&gt; as pictured below.&lt;br /&gt;&lt;a href="http://www.itp.net/news/510788-fake-uae-ministry-website-targets-jobseekers"&gt;More details about the story can also be found here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-1847810519158251092?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NkPOO5j0K2r9lOg58TM6zaSL7l4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NkPOO5j0K2r9lOg58TM6zaSL7l4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NkPOO5j0K2r9lOg58TM6zaSL7l4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NkPOO5j0K2r9lOg58TM6zaSL7l4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/CkzXG-NaM7Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/1847810519158251092/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=1847810519158251092" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1847810519158251092?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1847810519158251092?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/CkzXG-NaM7Y/social-engineering-targets-jobseekers.html" title="Social engineering targets jobseekers" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_edMpyFux25g/R69eZ0lat3I/AAAAAAAAA6Q/JLG9EvTAvAI/s72-c/jobseeker.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/02/social-engineering-targets-jobseekers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IFR34-fip7ImA9WxZREkk.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-8112902557409922967</id><published>2008-02-05T22:18:00.000+03:00</published><updated>2008-02-05T22:58:36.056+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-05T22:58:36.056+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="jorge sebastiao" /><category scheme="http://www.blogger.com/atom/ns#" term="comment" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="social networks" /><title>Security Issues with social networks</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_edMpyFux25g/R6i_ci_hM0I/AAAAAAAAA5w/PiFMk1iATiM/s1600-h/social-networks.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_edMpyFux25g/R6i_ci_hM0I/AAAAAAAAA5w/PiFMk1iATiM/s200/social-networks.jpg" alt="" id="BLOGGER_PHOTO_ID_5163587469930738498" border="0" /&gt;&lt;/a&gt;I have been using heavily social networks for the past 3 years, started with linkedin can now reach over 7,000,000 persons online. So the power of the technology is really incredible. Theses are some of the top ones I use:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;linkedin&lt;/li&gt;&lt;li&gt;xing&lt;/li&gt;&lt;li&gt;ecademy&lt;br /&gt;&lt;/li&gt;&lt;li&gt;plaxo&lt;/li&gt;&lt;li&gt;youtube&lt;/li&gt;&lt;li&gt;slideshare&lt;br /&gt;&lt;/li&gt;&lt;li&gt;twitter&lt;/li&gt;&lt;li&gt;mypodcast&lt;/li&gt;&lt;li&gt;lastfm&lt;br /&gt;&lt;/li&gt;&lt;li&gt;myspace&lt;/li&gt;&lt;li&gt;face book&lt;/li&gt;&lt;li&gt;...&lt;/li&gt;&lt;/ul&gt;But these social networks practical experiences are bring in some important questions (which will try to address over this year posts). Some of the main security issues I see are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;propagation of malware (virus, trojans, keyloggers)&lt;/li&gt;&lt;li&gt;defacement of profile, impact in public image&lt;/li&gt;&lt;li&gt;who owns the data? some networks make it easy to get the data in but very difficult out (usage of images to protect contact information)&lt;/li&gt;&lt;li&gt;how to archive and backup this data? who is responsible?&lt;/li&gt;&lt;li&gt;how to delete the data permanently if required?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;predator attacks against minors and kids (parents must learn new ropes)&lt;/li&gt;&lt;li&gt;identity theft, impersonation&lt;br /&gt;&lt;/li&gt;&lt;li&gt;how to maintain so many user IDs (opendID is trying to address this)&lt;/li&gt;&lt;li&gt;how to move data from one site, application to the other (open social is work on this), some users have seen this usage blocked after using automated conversion, migration tools&lt;br /&gt;&lt;/li&gt;&lt;li&gt;how to do investigations, forensics on so many sites to track down criminals effectively&lt;/li&gt;&lt;li&gt;how to separate between business, and personal lives?&lt;/li&gt;&lt;li&gt;effects on corporate information&lt;br /&gt;&lt;/li&gt;&lt;li&gt;leakages&lt;/li&gt;&lt;li&gt;effects on corporate productivity&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;In short network, do business, have fun, but becarefull out-there.&lt;br /&gt;&lt;br /&gt;More details on:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blogs.csoonline.com/social_networking_security_risks"&gt;CSO Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://onguardonline.gov/socialnetworking.html"&gt;Parents Guide&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/news/7739"&gt;At security focus&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.us-cert.gov/cas/tips/ST06-003.html"&gt;USA Cert&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-8112902557409922967?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/IFbUO86g0gKpXOUfof8UNXGGtx0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IFbUO86g0gKpXOUfof8UNXGGtx0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/IFbUO86g0gKpXOUfof8UNXGGtx0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IFbUO86g0gKpXOUfof8UNXGGtx0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/7N8rT4vB5ag" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/8112902557409922967/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=8112902557409922967" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/8112902557409922967?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/8112902557409922967?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/7N8rT4vB5ag/security-issues-with-social-networks.html" title="Security Issues with social networks" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_edMpyFux25g/R6i_ci_hM0I/AAAAAAAAA5w/PiFMk1iATiM/s72-c/social-networks.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/02/security-issues-with-social-networks.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0cDSXo4cSp7ImA9WxZSGEU.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-7143696752776271876</id><published>2008-02-01T20:54:00.000+03:00</published><updated>2008-02-01T21:04:38.439+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-01T21:04:38.439+03:00</app:edited><title>2008 Security Priorities</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_edMpyFux25g/R6NdSC_hMzI/AAAAAAAAA5k/Sh-XZFzFtLY/s1600-h/2008-security-priorities.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 410px; height: 329px;" src="http://3.bp.blogspot.com/_edMpyFux25g/R6NdSC_hMzI/AAAAAAAAA5k/Sh-XZFzFtLY/s400/2008-security-priorities.jpg" alt="" id="BLOGGER_PHOTO_ID_5162072162519036722" border="0" /&gt;&lt;/a&gt;Just finished conducting a poll with the help of Plaxo on security  priorities of 2008. About 9% of the persons requested replied (from a poll size of approximately 2000 persons 183 replied).&lt;br /&gt;&lt;br /&gt;The top 3 areas of focus are therefore:&lt;br /&gt;- Governance and compliance&lt;br /&gt;- Infrastructure security&lt;br /&gt;- Business Continuity and Disaster Recovery (as mentioned by some in the survey comments, the BCP, DRP issue is much bigger then being just part of security, we all agreed on this ...)&lt;br /&gt;&lt;br /&gt;So what are your plans for security for 2008... Be ready as this year will be full  of events.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-7143696752776271876?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Rq_L85x6lRHTF_kSRNIjVIHWEHg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rq_L85x6lRHTF_kSRNIjVIHWEHg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Rq_L85x6lRHTF_kSRNIjVIHWEHg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rq_L85x6lRHTF_kSRNIjVIHWEHg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/xMiYV7PI3co" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/7143696752776271876/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=7143696752776271876" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/7143696752776271876?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/7143696752776271876?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/xMiYV7PI3co/2008-security-priorities.html" title="2008 Security Priorities" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_edMpyFux25g/R6NdSC_hMzI/AAAAAAAAA5k/Sh-XZFzFtLY/s72-c/2008-security-priorities.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/02/2008-security-priorities.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8MQXw4cSp7ImA9WxZSF0w.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-6386484978039709574</id><published>2008-01-30T20:18:00.000+03:00</published><updated>2008-01-30T20:24:40.239+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-01-30T20:24:40.239+03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="esgulf" /><category scheme="http://www.blogger.com/atom/ns#" term="identity theft" /><category scheme="http://www.blogger.com/atom/ns#" term="jorge sebastiao" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="awareness" /><title>Identity Theft Slidecast</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_edMpyFux25g/R6Cxxi_hMyI/AAAAAAAAA5c/Wjf08q69MH4/s1600-h/idtheft.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_edMpyFux25g/R6Cxxi_hMyI/AAAAAAAAA5c/Wjf08q69MH4/s200/idtheft.jpg" alt="" id="BLOGGER_PHOTO_ID_5161320637731517218" border="0" /&gt;&lt;/a&gt;Identity Theft continuous to become an increase threat to security and must be address by using regular awareness sessions with end-users.&lt;br /&gt;The following is an identity theft slidecast and podcast which is simultaneously published on  &lt;a href="http://www.slideshare.net/jorges/identify-theft-v30/"&gt;slideshare (slides and audio)&lt;/a&gt; and &lt;a href="http://esgulf.mypodcast.com/2008/01/Indentity_Theft_security_Awareness_Presentation-76621.html"&gt;mypodcast (audit only) &lt;/a&gt;&lt;br /&gt;...&lt;br /&gt;&lt;div style="width: 425px; text-align: left;" id="__ss_231865"&gt;&lt;object style="margin: 0px;" height="355" width="425"&gt;&lt;param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=identify-theft-v30-1200594491926206-3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=identify-theft-v30-1200594491926206-3" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="355" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;"&gt;&lt;a href="http://www.slideshare.net/?src=embed"&gt;&lt;img src="http://static.slideshare.net/swf/logo_embd.png" style="border: 0px none ; margin-bottom: -5px;" alt="SlideShare" /&gt;&lt;/a&gt; | &lt;a href="http://www.slideshare.net/jorges/identify-theft-v30?src=embed" title="View 'Identify Theft' on SlideShare"&gt;View&lt;/a&gt; | &lt;a href="http://www.slideshare.net/upload?src=embed"&gt;Upload your own&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-6386484978039709574?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/O7dIshkOYs1GxVtvjhmLvfEd4nc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/O7dIshkOYs1GxVtvjhmLvfEd4nc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/O7dIshkOYs1GxVtvjhmLvfEd4nc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/O7dIshkOYs1GxVtvjhmLvfEd4nc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/LogjzvEALfY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/6386484978039709574/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=6386484978039709574" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/6386484978039709574?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/6386484978039709574?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/LogjzvEALfY/identity-theft-slidecast.html" title="Identity Theft Slidecast" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_edMpyFux25g/R6Cxxi_hMyI/AAAAAAAAA5c/Wjf08q69MH4/s72-c/idtheft.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/01/identity-theft-slidecast.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkUFQXg5cCp7ImA9WxZSF00.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-3867156177963916156</id><published>2008-01-29T18:27:00.000+03:00</published><updated>2008-01-30T18:50:10.628+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-01-30T18:50:10.628+03:00</app:edited><title>Are you ready for Cyberwar?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_edMpyFux25g/R6CYyy_hMxI/AAAAAAAAA44/XWud1m0ZqKk/s1600-h/cyber-warriors.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 127px; height: 185px;" src="http://3.bp.blogspot.com/_edMpyFux25g/R6CYyy_hMxI/AAAAAAAAA44/XWud1m0ZqKk/s200/cyber-warriors.jpg" alt="" id="BLOGGER_PHOTO_ID_5161293171415659282" border="0" /&gt;&lt;/a&gt;Last year I wrote about the events of cyberwar between Estonia and Russia. Other ones have happened recently as well such as:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;between USA and China, (more covert activities and experimentation)&lt;/li&gt;&lt;li&gt;between AlQaeda and USA&lt;br /&gt;&lt;/li&gt;&lt;li&gt;between North and South Korea&lt;br /&gt;&lt;/li&gt;&lt;li&gt;between India and Pakistan&lt;/li&gt;&lt;li&gt;....&lt;/li&gt;&lt;/ul&gt;In any cyberwar there are: "cyberwarriors", targets (key infrastructure  such as financial institutions, government, utilities) and collateral damage (potentially your innocent business). So are we ready? Do we understand the dangers? A recent story in CSO magazine highlight the threat level and readiness of given countries as they focus resources for cyberwar.&lt;br /&gt;&lt;table _base_target="_top" border="1"&gt;&lt;tbody _base_target="_top"&gt;&lt;tr&gt; &lt;td&gt;Country&lt;/td&gt; &lt;td&gt;Est Mil Budget&lt;/td&gt; &lt;td&gt;Status&lt;/td&gt; &lt;td&gt;Est Threat&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td&gt;China&lt;/td&gt; &lt;td&gt;$56B&lt;/td&gt; &lt;td&gt;complex&lt;/td&gt; &lt;td&gt;4.78&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td&gt;Russia&lt;/td&gt;&lt;td&gt;$44B&lt;/td&gt;&lt;td&gt;complex&lt;/td&gt;&lt;td&gt;4.39&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td&gt;Iran&lt;/td&gt;&lt;td&gt;$9.7B&lt;/td&gt;&lt;td&gt;advanced&lt;/td&gt;&lt;td&gt;3.79&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td&gt;N Korea&lt;/td&gt; &lt;td&gt;$5.2B&lt;/td&gt; &lt;td&gt;advanced&lt;/td&gt; &lt;td&gt;3.03&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt;&lt;td&gt;Libya&lt;/td&gt;&lt;td&gt;$1.3B&lt;/td&gt;&lt;td&gt;advanced&lt;/td&gt;&lt;td&gt;2.86&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;from this table we notice both China and Russia devoting a substantial military budget and having acquired a complex infrastructure with associated Threat level (ranked from 1 to 5, 5 being highest)&lt;br /&gt;&lt;a href="http://www2.csoonline.com/exclusives/column.html?CID=33496&amp;amp;=nlt_csoupdate"&gt;More details on this story can be found here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-3867156177963916156?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KkKlQG0B-8kxuAZfoKCDXkuaDzs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KkKlQG0B-8kxuAZfoKCDXkuaDzs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KkKlQG0B-8kxuAZfoKCDXkuaDzs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KkKlQG0B-8kxuAZfoKCDXkuaDzs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/a8ENZaEJkwg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/3867156177963916156/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=3867156177963916156" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/3867156177963916156?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/3867156177963916156?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/a8ENZaEJkwg/are-you-ready-for-cyberwar.html" title="Are you ready for Cyberwar?" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_edMpyFux25g/R6CYyy_hMxI/AAAAAAAAA44/XWud1m0ZqKk/s72-c/cyber-warriors.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/01/are-you-ready-for-cyberwar.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMFQH84eCp7ImA9WxZSFUk.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-1649805387687106984</id><published>2008-01-26T02:01:00.000+03:00</published><updated>2008-01-28T20:13:31.130+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-01-28T20:13:31.130+03:00</app:edited><title>UK government mandates encrypted Laptops</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_edMpyFux25g/R54LQC_hMvI/AAAAAAAAA4M/lRHue9DFuEw/s1600-h/Laptopencryption.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_edMpyFux25g/R54LQC_hMvI/AAAAAAAAA4M/lRHue9DFuEw/s200/Laptopencryption.jpg" alt="" id="BLOGGER_PHOTO_ID_5160574593322267378" border="0" /&gt;&lt;/a&gt;In response to the one of the largest disclosures of information in history the UK government responds with policy which mandates the usage of encryption on laptops and media devices when taken away from the offices.&lt;br /&gt;An email was sent to all UK civil servants (government employees) which informs them of the new policy--"prohibts laptops and hard drives containing sensitive data from being taken out of the government buildings unless the devices are encrypted.&lt;br /&gt;More details on this story are contained here:&lt;br /&gt;- &lt;a href="http://www.vnunet.com/vnunet/news/2207901/whitehall-locks-laptops"&gt;Vunet News&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://www.mod.uk/DefenceInternet/DefenceNews/DefencePolicyAndBusiness/BrowneAnnouncesReviewOnModInformationSecurity.htm"&gt;MOD information Security&lt;/a&gt;&lt;br /&gt;This is good news for organization like &lt;a href="http://www.secude.com"&gt;Secude &lt;/a&gt;which offer advanced solutions for &lt;a href="http://www.secude.com/htm/584/en/Products.htm?Produkt=2533"&gt;hard disk encryption and laptop encryption.&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-1649805387687106984?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vpnJHl8Ry0UFdit1rQ3o-2_qQa0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vpnJHl8Ry0UFdit1rQ3o-2_qQa0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vpnJHl8Ry0UFdit1rQ3o-2_qQa0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vpnJHl8Ry0UFdit1rQ3o-2_qQa0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/PFXIYSjgKxc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/1649805387687106984/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=1649805387687106984" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1649805387687106984?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/1649805387687106984?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/PFXIYSjgKxc/uk-government-mandates-encrypted.html" title="UK government mandates encrypted Laptops" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_edMpyFux25g/R54LQC_hMvI/AAAAAAAAA4M/lRHue9DFuEw/s72-c/Laptopencryption.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/01/uk-government-mandates-encrypted.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ABSH8ycSp7ImA9WxZSFU4.&quot;"><id>tag:blogger.com,1999:blog-14940812.post-2469193053429166713</id><published>2008-01-22T19:12:00.001+03:00</published><updated>2008-01-28T20:02:39.199+03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-01-28T20:02:39.199+03:00</app:edited><title>Largest Bank Fraud $ 7 Billion dollars</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_edMpyFux25g/R54Ati_hMtI/AAAAAAAAA38/ccJ6C25o9wM/s1600-h/jeromekerviel.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_edMpyFux25g/R54Ati_hMtI/AAAAAAAAA38/ccJ6C25o9wM/s200/jeromekerviel.jpg" alt="" id="BLOGGER_PHOTO_ID_5160563005500502738" border="0" /&gt;&lt;/a&gt;French bank SOCGEN, Societe General is the victim of the largest bank fraud of the year total amount $7Billion (over €5billion Euros). A junior trader Jerome Kerviel makes trades that cause the bank substantial losses. Jerome is capable of hidding is actions by modifying the information in the Banks computers.&lt;br /&gt;&lt;br /&gt;The trader was able to create fictitious accounts to hide is actions; and support this with falsified documents. In short massive risk, massive losses and total lack of appropriate controls.&lt;br /&gt;&lt;br /&gt;In security there is a simple concept known as dual control; under this control critical system transactions of system information can not be updated by a single individual but requires approval and verification from another party or employee in the organization (these controls are contained in the most basic and simple accounting systems). Why were such controls absent or ignored, I am sure the investigations and postmortem analysis will provide plenty of reading....&lt;br /&gt;D.K. Matai good friend and Chairman of &lt;a href="http://www.mi2g.net/cgi/mi2g/press/240108.php"&gt;Asymmetric Threats also discusses the topic in MI2G press release postings&lt;/a&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.socgen.com"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_edMpyFux25g/R54Duy_hMuI/AAAAAAAAA4E/Jnd9_yR0ugY/s200/socgen-logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5160566325510222562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Some more recent updates on the story are contained here:&lt;br /&gt;- &lt;a href="http://www.reuters.com/article/businessNews/idUSL2816064620080128"&gt;Reuters Time Line&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://www.telegraph.co.uk/money/main.jhtml?xml=/money/2008/01/24/bcnsocgen924.xml"&gt;Telegraph UK&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://www.socgen.com/sg/file/actualiteig/homeSC_3/fraudnote.pdf"&gt;the company explanation&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://www.ft.com/cms/s/0/bd9f55d6-ca4b-11dc-a960-000077b07658.html"&gt;Financial Times&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14940812-2469193053429166713?l=4sec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GIngZyXlHwVbNhHf_1DAJvA3lys/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GIngZyXlHwVbNhHf_1DAJvA3lys/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GIngZyXlHwVbNhHf_1DAJvA3lys/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GIngZyXlHwVbNhHf_1DAJvA3lys/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/blogspot/aTQX/~4/UOxE9gxsGVo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://4sec.blogspot.com/feeds/2469193053429166713/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=14940812&amp;postID=2469193053429166713" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2469193053429166713?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/14940812/posts/default/2469193053429166713?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/blogspot/aTQX/~3/UOxE9gxsGVo/largest-bank-fraud-7-billion-dollars.html" title="Largest Bank Fraud $ 7 Billion dollars" /><author><name>JS</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="22" height="32" src="http://www.esgulf.com/images/jorge_small.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_edMpyFux25g/R54Ati_hMtI/AAAAAAAAA38/ccJ6C25o9wM/s72-c/jeromekerviel.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://4sec.blogspot.com/2008/01/largest-bank-fraud-7-billion-dollars.html</feedburner:origLink></entry></feed>

