<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>John Biasi, CISSP</title>
	
	<link>http://john-biasi.com/wp</link>
	<description>All the security that fits.</description>
	<pubDate>Tue, 22 Jul 2008 16:30:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/john-biasi" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>New Frontiers in Hacking</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/JLK-Vf3-oRo/</link>
		<comments>http://john-biasi.com/wp/2008/03/13/new-frontiers-in-hacking/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 01:30:48 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2008/03/13/new-frontiers-in-hacking/</guid>
		<description>Just when you though it was safe to have a device implanted in your body to deliver electric shocks to your heart, there&amp;#8217;s this:
A Heart Device Is Found Vulnerable to Hacker Attacks [Barnaby J. Feder, NY Times]
It turns out that the risk of someone actually hacking a pacemaker is rather small, since the researchers were [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=New+Frontiers+in+Hacking&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2008%2F03%2F13%2Fnew-frontiers-in-hacking%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p><img src="http://john-biasi.com/wp/wp-content/uploads/2008/03/oakland2008small.jpg" alt="Heart Device Hack" align="right" />Just when you though it was safe to have a device implanted in your body to deliver electric shocks to your heart, there&#8217;s this:</p>
<p><a href="http://www.nytimes.com/2008/03/12/business/12heart-web.html?_r=1&amp;oref=slogin" target="_blank">A Heart Device Is Found Vulnerable to Hacker Attacks</a> [Barnaby J. Feder, NY Times]</p>
<p>It turns out that the risk of someone actually hacking a pacemaker is rather small, since the researchers were testing this on a device that wasn&#8217;t implanted, and they were within 2 inches of the device at the time.</p>
<p>These devices utilize a wireless radio to allow doctors access to monitor and reconfigure them without opening up the patient again.  Normally this is done in the office, with a device placed near the implantation site, so it seems unlikely that someone is going to sit in a local coffee shop and give all the older patrons heart attacks.</p>
<p>In addition to the risk of someone &#8220;tweaking&#8221; a pacemaker&#8217;s settings, there is also the possibility that they would be able to obtain some private medical data from the device, which should raise some additional concerns about patient privacy.</p>
<p>There is some hope, however.  The researchers suggested some enhancements to provide some defensive capabilities to these devices.  These included notification of access attempts, authentication of connections, and key exchange.  Obviously, since these devices have a limited power supply, they are focusing on ways to do this with little or no power coming from the device itself.</p>
<p>The full report can be downloaded <a href="http://www.secure-medicine.org/icd-study/icd-study.pdf" target="_blank">here</a>.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=KBpAUJRu"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=lmAcSrmA"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=zFPJclxo"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=AQ68uUNZ"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=ZvwAXrxG"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=LYaeYYrt"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=kOlin87p"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=llJx0QZx"><img src="http://feeds.feedburner.com/~f/john-biasi?i=llJx0QZx" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=nQAXqY2x"><img src="http://feeds.feedburner.com/~f/john-biasi?i=nQAXqY2x" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=dvyNQslF"><img src="http://feeds.feedburner.com/~f/john-biasi?i=dvyNQslF" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/JLK-Vf3-oRo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2008/03/13/new-frontiers-in-hacking/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2008/03/13/new-frontiers-in-hacking/</feedburner:origLink></item>
		<item>
		<title>I’m officially a CISSP</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/0FmbsFoB3ls/</link>
		<comments>http://john-biasi.com/wp/2007/11/30/im-officially-a-cissp/#comments</comments>
		<pubDate>Fri, 30 Nov 2007 14:42:23 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[Certification]]></category>

		<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/11/30/im-officially-a-cissp/</guid>
		<description>I&amp;#8217;ve been meaning to write a post about passing the CISSP exam, but the time to do so has eluded me, until now.
I received the results of the CISSP exam on October 11th, four days after I took the test in New York City.  Naturally, I was thrilled, and posted as such to the [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=I%26%238217%3Bm+officially+a+CISSP&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F11%2F30%2Fim-officially-a-cissp%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>I&#8217;ve been meaning to write a post about passing the CISSP exam, but the time to do so has eluded me, until now.</p>
<p>I received the results of the CISSP exam on October 11th, <strong>four</strong> days after I took the test in New York City.  Naturally, I was thrilled, and posted as such to the <a title="Security Catalyst Community" href="http://www.securitycatalyst.org/forums/" target="_blank">SCC</a>.  Wasting no time, I had my manager, who is a CISSP (among other certs), fill out the endorsement form.  I promptly faxed the form, along with my resume, to <a href="https://www.isc2.org/cgi-bin/index.cgi" target="_blank">(ISC)2</a>.  And then I waited.</p>
<p>According to the email, it was supposed to take 2-3 weeks for (ISC)2 to process my information and validate that I met the requirements for the certification.  So after 3.5 weeks, with no other communication, I started to get concerned.  After emailing support, I received the following response:</p>
<blockquote><p>We apologize for the delay but our system has not been able to process any certificates for three weeks due to a very large upgrade.  We expect to begin again this week.  We ask that you give two weeks to actually receive your certificate.  If you still do not receive it, please write back.  Thank you for your patience.</p></blockquote>
<p>So when did I receive word that I am officially a CISSP?  November 15th, fully <strong>five weeks</strong> after the news that I passed the exam.  And I didn&#8217;t receive my certificate until over a week later, November 24th.</p>
<p>I suppose it could be worse.  A colleague of mine took the exam in mid-October in Florida, and he just received his exam results <strong>yesterday</strong>.  While waiting five weeks for their verification process was annoying, waiting over four weeks just to get the exam results must be downright <em>painful</em>.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=3CYUL775"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=R6Wm0KHz"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=WSYaPsLS"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=ZHdvJFK7"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=G2H08Qwk"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=j56mzITZ"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=4AiJQwpu"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=toMdfshB"><img src="http://feeds.feedburner.com/~f/john-biasi?i=toMdfshB" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=6z7pkrYJ"><img src="http://feeds.feedburner.com/~f/john-biasi?i=6z7pkrYJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=kXKfX8ON"><img src="http://feeds.feedburner.com/~f/john-biasi?i=kXKfX8ON" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/0FmbsFoB3ls" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/11/30/im-officially-a-cissp/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/11/30/im-officially-a-cissp/</feedburner:origLink></item>
		<item>
		<title>Onward to the CISSP</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/voojQACyT4U/</link>
		<comments>http://john-biasi.com/wp/2007/09/18/onward-to-the-cissp/#comments</comments>
		<pubDate>Tue, 18 Sep 2007 11:22:58 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[Certification]]></category>

		<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/09/18/onward-to-the-cissp/</guid>
		<description>Well, there&amp;#8217;s no turning back now!  I finally scheduled my CISSP exam.
That&amp;#8217;s not to say I can&amp;#8217;t reschedule, but I&amp;#8217;m going to pretend that&amp;#8217;s not an option so I don&amp;#8217;t deviate from my study plan.  When I study for an exam I tend to go to all out, so I&amp;#8217;ll be reading (or [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=Onward+to+the+CISSP&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F09%2F18%2Fonward-to-the-cissp%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p><img src="http://john-biasi.com/wp/wp-content/uploads/2007/09/image003.gif" alt="CISSP" align="right" />Well, there&#8217;s no turning back now!  I finally scheduled my CISSP exam.</p>
<p>That&#8217;s not to say I can&#8217;t reschedule, but I&#8217;m going to pretend that&#8217;s not an option so I don&#8217;t deviate from my study plan.  When I study for an exam I tend to go to all out, so I&#8217;ll be reading (or re-reading in some cases) the Shon Harris All-in-One Exam Guide, the official ISC^2 guide, and the Krutz &amp; Vines CISSP Prep Guide.   And I&#8217;ll be spending many hours running through the practice questions on <a href="http://www.cccure.org/">CCCure.org</a>.</p>
<p>I have been following a number of discussions in the blogosphere and the <a href="http://www.securitycatalyst.org/forums/index.php">SCC</a> regarding the value of the CISSP certification.  While this has been debated by far more experienced security professionals than I can claim to be, I&#8217;ll explain why I am continuing down the CISSP path.</p>
<p>The CISSP certification has been described as &#8220;an inch deep and a mile wide.&#8221;  This is meant to indicate that there is a vast breadth of material covered, but not much of it is explored beyond the basics of that topic area.  This implies that a CISSP is not expected to be an expert on any of the 10 domains of the CBK, but rather has a sufficient level of all-around security knowledge.</p>
<p>I see the CISSP as sort of a minimum requirement for most security professionals.  It&#8217;s not going to impress many people in the field that you have it, but if you don&#8217;t, you&#8217;d better be prepared to demonstrate why you didn&#8217;t need it.</p>
<p>The CISSP is not a Ph.D.  It&#8217;s not even an M.S.  It&#8217;s a certification that demonstrates you were able to survive the somewhat arduous exam and meet the experience requirements.  It&#8217;s likely to get you a pass into the &#8220;good pile&#8221; in an HR resume selection process, and it can be a marketing tool for a consultant to assert their expertise.  It may also give you a bit of a salary increase in your current position.</p>
<p>But let&#8217;s be honest; becoming a CISSP is not the culmination of your career.  Either you are going to continue learning and growing as a security professional, or you are not.  The CISSP shouldn&#8217;t be seen as a high water mark; it&#8217;s more of a checkpoint along the way.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=v0GUHMOW"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=bSjcRUbq"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=jvtKxvC8"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=Mcld4hbr"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=83YuYR7x"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=WTyewQul"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=yGIPmHAl"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=93IHBczO"><img src="http://feeds.feedburner.com/~f/john-biasi?i=93IHBczO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=QmuOi93B"><img src="http://feeds.feedburner.com/~f/john-biasi?i=QmuOi93B" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=ZpE70noH"><img src="http://feeds.feedburner.com/~f/john-biasi?i=ZpE70noH" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/voojQACyT4U" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/09/18/onward-to-the-cissp/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/09/18/onward-to-the-cissp/</feedburner:origLink></item>
		<item>
		<title>Jumping Ship</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/AjKrdj2B-l4/</link>
		<comments>http://john-biasi.com/wp/2007/05/22/jumping-ship/#comments</comments>
		<pubDate>Tue, 22 May 2007 23:47:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Jobs]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/05/22/jumping-ship/</guid>
		<description>Sorry for the long lapse in posting, but I started a new job a few weeks ago, and I&amp;#8217;m still adjusting to the schedule.  I also don&amp;#8217;t know what their blogging policy is, so I&amp;#8217;m going to keep things vague for now about the company.  What I will tell you for now is [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=Jumping+Ship&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F05%2F22%2Fjumping-ship%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>Sorry for the long lapse in posting, but I started a new job a few weeks ago, and I&#8217;m still adjusting to the schedule.  I also don&#8217;t know what their blogging policy is, so I&#8217;m going to keep things vague for now about the company.  What I will tell you for now is that it&#8217;s a much larger company than I have ever worked for, by a factor of about 30.  This is obviously a bit of an adjustment, but I&#8217;m starting to get a handle on the way things work for such a large company.</p>
<p>Why did I change jobs? Don&#8217;t get me wrong, I loved my old job.  I was the main security guru in the place, and I had my hands in every IT-related project that came through.  I enjoyed working there, and the majority of my coworkers were great people.  It came down to some advantages that the new position offered that the old one simply didn&#8217;t:</p>
<p>1. I was &#8220;recruited.&#8221; - Never discount the power of ego.  I hadn&#8217;t posted an updated resume in over 6 months, but this company came looking for me anyway.  It felt good to be sought after, instead of doing the seeking.</p>
<p>2. Location - I had an awful commute at my old job.  On an average day, it would take between 1-1.5 hours to travel in each direction.  Forget about days when it was raining or snowing.</p>
<p>3. Compensation - Not that I was <em>that </em>underpaid or anything, but the new company made an offer right off the bat that was a considerable increase in my salary.</p>
<p>4. Larger company - With a larger company comes a larger and more complex and diverse infrastructure.  While I may have worked on firewalls from vendors such as Cisco and Juniper, I have never had the opportunity to work on a Check Point.</p>
<p>5. Larger team - As I mentioned, I was the main security guy at my last place.  Not that I have a problem with that, but I&#8217;ve only been in the security field for a few years, and I know I still have a lot to learn. This place puts me in a team with a number of highly experienced security professionals.  I may be a little out of my depth at times, but I can learn a lot from the people I&#8217;m working with.</p>
<p>That last reason is probably the biggest reason for making the jump.  I do my best to keep expanding my security knowledge by reading and testing out new tools, but there is something to be said for working with people who have been doing for a lot longer, and who are more than willing to answer any question I can throw at them.</p>
<p>We&#8217;ll see how it goes.  My first couple of projects involve firewall management centralization and network compliance management.  I&#8217;ll post again soon with some details on the products I&#8217;m looking at.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=7dDLpZAO"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=IqqzL3r9"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=x5799EcR"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=oovRbZgo"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=Rn2C3RgA"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=sp74sVAt"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=WthrZYTp"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=3zTEjVZr"><img src="http://feeds.feedburner.com/~f/john-biasi?i=3zTEjVZr" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=WkXTsgtf"><img src="http://feeds.feedburner.com/~f/john-biasi?i=WkXTsgtf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=OHIGS3Jr"><img src="http://feeds.feedburner.com/~f/john-biasi?i=OHIGS3Jr" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/AjKrdj2B-l4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/05/22/jumping-ship/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/05/22/jumping-ship/</feedburner:origLink></item>
		<item>
		<title>Time to dump your cell phone carrier</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/ONDE-QreCLo/</link>
		<comments>http://john-biasi.com/wp/2007/03/20/time-to-dump-your-cell-phone-carrier/#comments</comments>
		<pubDate>Wed, 21 Mar 2007 03:03:02 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/03/20/time-to-dump-your-cell-phone-carrier/</guid>
		<description>I haven&amp;#8217;t had too much use for FreeConference.com, at least not so far.  I only tried it once to get an idea for how it worked, but I never needed to hold a large conference.  After all, I&amp;#8217;m not on the list (at least not yet).  As far as I can tell, it&amp;#8217;s a great [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=Time+to+dump+your+cell+phone+carrier&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F03%2F20%2Ftime-to-dump-your-cell-phone-carrier%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>I haven&#8217;t had too much use for <a href="FreeConference.com">FreeConference.com</a>, at least not so far.  I only tried it once to get an idea for how it worked, but I never needed to hold a large conference.  After all, I&#8217;m not on the <a href="http://www.itsecurity.com/features/top-59-influencers-itsecurity-031407/">list</a> (at least not yet).  As far as I can tell, it&#8217;s a great service that a lot of people find useful.</p>
<p>So why, oh why, do certain cell phone carriers feel the need to block access to this service?  After all, you are paying for the call; shouldn&#8217;t you be able to call who you want?  The answer is, of course, that these carriers would rather force you into paying for their services than let you use their network to access a free service.  Sounds sort of illegal, doesn&#8217;t it?</p>
<p>Here&#8217;s the message from FreeConference.com, with some suggestions:</p>
<blockquote><p><span style="font-size: 0.8em"><strong>Dear FreeConference User:</strong></span></p>
<p><small><strong>AT&amp;T/Cingular, Sprint, and Qwest Are Blocking Your Conference Calling</strong></small></p>
<p><small>As of Friday, March 9, it&#8217;s come to our attention that Cingular Wireless has begun blocking all conference calls made from Cingular handsets to selected conference numbers. If you call our service, you receive a recording that says, &#8220;This call is not allowed from this number. Please dial 611 for customer service&#8221;.</small></p>
<p><small>Earlier this week, Sprint and Qwest joined in this action, blocking cellular and land line calls to these same numbers. This appears to be a coordinated effort to force you to use the paid services they provide, eliminating competition and blocking your right to use the conferencing services that work best for you.</small></p>
<p><small><strong>Don&#8217;t Let AT&amp;T/Cingular, Sprint, or Qwest Take Away Your Right to Use the Conference Service of Your Choice!</strong></small></p>
<p><small>We Need Your Help! Please Take the Actions Below:</small></p>
<p><small>Whether you are one of their customers, or an organizer who is being impacted by these uncompetitive actions, please <a title="http://www.freeconference.com/emctrack.ashx?guid=6dcb2b6b-7fd2-db11-9a4b-000423c97647" href="http://www.freeconference.com/emctrack.ashx?guid=6dcb2b6b-7fd2-db11-9a4b-000423c97647">file a complaint with the FCC</a> or send an email to your <a title="http://www.freeconference.com/emctrack.ashx?guid=73cb2b6b-7fd2-db11-9a4b-000423c97647" href="http://www.freeconference.com/emctrack.ashx?guid=73cb2b6b-7fd2-db11-9a4b-000423c97647">State Attorney General</a> to complain about this monopolistic practice to limit the choices of consumers.</small></p>
<p><small>You can also let these companies know how you feel about their attempt to block competitive services:</small></p>
<ul>
<li><small>Sprint Customers can click <a title="http://www.freeconference.com/emctrack.ashx?guid=72cb2b6b-7fd2-db11-9a4b-000423c97647" href="http://www.freeconference.com/emctrack.ashx?guid=72cb2b6b-7fd2-db11-9a4b-000423c97647">here</a> or dial *2 from their Sprint Phone</small></li>
<li><small>Cingular Customers can click <a title="mailto:michael.balmoris@att.com" href="mailto:michael.balmoris@att.com">here</a> or call 1-888-333-6651</small></li>
<li><small>Qwest Customers can click <a title="http://www.freeconference.com/emctrack.ashx?guid=71cb2b6b-7fd2-db11-9a4b-000423c97647" href="http://www.freeconference.com/emctrack.ashx?guid=71cb2b6b-7fd2-db11-9a4b-000423c97647">here</a> or call 1-800-860-2255</small></li>
</ul>
<p><small>Your FreeConference Team remains steadfastly committed to bringing you simple, convenient and reliable conferencing services at the lowest cost possible. We appreciate your support in this endeavor.</small></p>
<p><small><em>Your FreeConference Team</em></small></p></blockquote>
<p>I found this originally on <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/03/this_is_america.html">SSAATY</a>.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=Mgy4iAxw"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=cyywFaTy"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=xJMDwvIt"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=bg41lFZG"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=O0RdadMa"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=OHs4iyCa"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=I0meq9Ry"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=uAlaBOqu"><img src="http://feeds.feedburner.com/~f/john-biasi?i=uAlaBOqu" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=RC46tID4"><img src="http://feeds.feedburner.com/~f/john-biasi?i=RC46tID4" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=EZ4OKFcT"><img src="http://feeds.feedburner.com/~f/john-biasi?i=EZ4OKFcT" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/ONDE-QreCLo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/03/20/time-to-dump-your-cell-phone-carrier/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/03/20/time-to-dump-your-cell-phone-carrier/</feedburner:origLink></item>
		<item>
		<title>Should we worry more about insiders or outsiders?</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/lc37iGd_epw/</link>
		<comments>http://john-biasi.com/wp/2007/03/19/should-we-worry-more-about-insiders-or-outsiders/#comments</comments>
		<pubDate>Mon, 19 Mar 2007 21:01:20 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/03/19/should-we-worry-more-about-insiders-or-outsiders/</guid>
		<description>I&amp;#8217;ve been having a little bit of a debate with a colleague of mine.  Walking into an environment with only the most basic security measures in place (patch management, AV, moderately restrictive firewall policies), where should you focus your time?  Obviously, the complete picture needs to be dealt with, but would you spend [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=Should+we+worry+more+about+insiders+or+outsiders%3F&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F03%2F19%2Fshould-we-worry-more-about-insiders-or-outsiders%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>I&#8217;ve been having a little bit of a debate with a colleague of mine.  Walking into an environment with only the most basic security measures in place (patch management, AV, moderately restrictive firewall policies), where should you focus your time?  Obviously, the complete picture needs to be dealt with, but would you spend more time hardening against external attacks, or against an insider threat?</p>
<p>I am of the opinion that, once you have the basics in place, you need to focus on the insiders, such as DBAs that have unrestricted access, network admins who use one shared administrative account to administer everything, and users who have local administrative privileges.  Many of the problems you are defending against on the outside are black and white issues - Do I need to disable any services on this web server?  What ports should I allow through this firewall?  What should I log and where should I log it?  And so on.</p>
<p>On the other hand, decisions to restrict access to insiders come up against a lot more resistance, both for business and political reasons.  No one wants to be told they shouldn&#8217;t be trusted with the level of access they have, it&#8217;s an affront.  Also, there are many more complicated situations for internal users.  Maybe restricting write access to USB for all users would be a great security measure, but what about the admins who need to transfer data back and forth?  All these problems have solutions, but the time it takes to resolve them makes it necessary to dedicate a larger portion of your time to these efforts.</p>
<p>Maybe I&#8217;m way off base here.  I&#8217;m not saying external threat mitigation is a cakewalk.  It&#8217;s just that after the basics are taken care of, I think more effort is required to secure things from the internal perspective.  Ok, I&#8217;m ready&#8230;tell me why I&#8217;m wrong.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=kjvSKFHP"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=fzMfNwVu"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=R0DukfJq"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=U2uWIXiK"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=g2paoQCq"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=szrTj0pU"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=9UWQWZLV"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=cexdVi0i"><img src="http://feeds.feedburner.com/~f/john-biasi?i=cexdVi0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=wsh4qX38"><img src="http://feeds.feedburner.com/~f/john-biasi?i=wsh4qX38" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=NFqBKwBv"><img src="http://feeds.feedburner.com/~f/john-biasi?i=NFqBKwBv" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/lc37iGd_epw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/03/19/should-we-worry-more-about-insiders-or-outsiders/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/03/19/should-we-worry-more-about-insiders-or-outsiders/</feedburner:origLink></item>
		<item>
		<title>CompUSA memories</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/IFo-LTqGAGQ/</link>
		<comments>http://john-biasi.com/wp/2007/03/14/compusa-memories/#comments</comments>
		<pubDate>Wed, 14 Mar 2007 11:59:59 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[Jobs]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/03/14/compusa-memories/</guid>
		<description>Reading this post by Ryan Block brought back memories, both good and bad, about my own experiences working at CompUSA.  I would consider CompUSA my first job in &amp;#8220;IT,&amp;#8221; even though the majority of it was so far removed from anything technical it barely qualifies.  However, it was my first real exposure to [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=CompUSA+memories&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F03%2F14%2Fcompusa-memories%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>Reading <a href="http://www.ryanablock.com/archive/2007/03/compusa-closing-store-where-i-had-my-first-job/">this post</a> by Ryan Block brought back memories, both good and bad, about my own experiences working at CompUSA.  I would consider CompUSA my first job in &#8220;IT,&#8221; even though the majority of it was so far removed from anything technical it barely qualifies.  However, it was my first real exposure to people with technical jobs that did not relate to programming.  Prior to this I thought that to be in IT, you had to be a programmer.</p>
<p>While the majority of my time spent at CompUSA could be termed &#8220;retail hell,&#8221; it did give me access to many different types of hardware and software, from many different vendors.  I started in the software department, and vendors came in on a regular basis with freebies in an unsubtle attempt to bribe us into pushing their products over the competition.</p>
<p>Similar to Ryan, I then moved into the Upgrades department, selling the higher-end products that had to be locked away behind the counter.  I was also trying to become a repair tech, and meeting with resistance.  Working in the Upgrades department was somewhat enjoyable, and when it was slow I could go next door to the tech area and check out what they were working on.</p>
<p>Overall, it was good experience, if a bit painful.  Then again, that would be my description of most jobs in retail.  All in all, I&#8217;m not really that broken up over the fact that there will be no more CompUSA stores in my area.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=XZeS7Fjn"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=m7QCSbsK"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=T3dWMkgO"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=GFiqpHrA"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=5ryF7iFb"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=GHEtVBu0"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=JoYPQ4is"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=B0BANGF1"><img src="http://feeds.feedburner.com/~f/john-biasi?i=B0BANGF1" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=iImyXCIT"><img src="http://feeds.feedburner.com/~f/john-biasi?i=iImyXCIT" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=fgTcKfQt"><img src="http://feeds.feedburner.com/~f/john-biasi?i=fgTcKfQt" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/IFo-LTqGAGQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/03/14/compusa-memories/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/03/14/compusa-memories/</feedburner:origLink></item>
		<item>
		<title>Jury Duty</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/4pJ_qqTKCiY/</link>
		<comments>http://john-biasi.com/wp/2007/03/13/jury-duty/#comments</comments>
		<pubDate>Wed, 14 Mar 2007 01:11:15 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/03/13/jury-duty/</guid>
		<description>I had to perform my civic duty recently, and answer a summons for jury duty at my local courthouse.  Not many people are excited by this invitation, and I was no exception.  In fact, I had already used up my one automatic postponement, so I knew I wasn&amp;#8217;t getting out of it.
First impressions: security at [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=Jury+Duty&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F03%2F13%2Fjury-duty%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>I had to perform my civic duty recently, and answer a summons for jury duty at my local courthouse.  Not many people are excited by this invitation, and I was no exception.  In fact, I had already used up my one automatic postponement, so I knew I wasn&#8217;t getting out of it.</p>
<p>First impressions: security at the jury entrance was like going through the airport, with less of a line, and no nonsensical restrictions.  While I was not allowed to bring food or drinks into the facility, I was not forced to throw out a tube of moisturizer in my backpack, for instance.  I assume if I had any weapons or other sharp objects I would have been forced to discard them.  Also, I had to leave my cell phone in the car, as camera phones are a no-no.</p>
<p>While the security at the entrance was tight, I had some concerns.  First, no attempt to check my ID was performed in my entire time at the courthouse.  I had to present my summons, but beyond that, I could have been anyone.  Not that many people are going to crash jury duty, but if someone was motivated to do so, I doubt they would have much difficulty.</p>
<p>Second, the smokers are given their right to light up in a small fenced-in terrace outside the main waiting area.  Good for them, but I question how difficult it would be for someone to pass something to (or from) one of the smokers.</p>
<p>I also have a (minor) complaint.  Why, when there are 3 potential courthouses that the juror pool can be summoned to, do I get stuck with the only one that doesn&#8217;t offer WiFi?  I spent the better part of 6 hours &#8212; don&#8217;t get me started on that one &#8212; waiting to be called into a courtroom, reading old magazines, when I could have been on my laptop getting things done (i.e. posting this complaint earlier).</p>
<p>In the end, I wasn&#8217;t picked for the final jury, and I was thanked for my service and sent home.  While I understand justice is a process, it was unfortunately a lengthy and uneventful process in this case.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=jmgInbdX"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=bFFOQKto"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=k63L3GHC"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=P6KvEEy6"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=NFLHq1QE"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=4QhGbRaF"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=Smb1UmwP"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=MQUWZS40"><img src="http://feeds.feedburner.com/~f/john-biasi?i=MQUWZS40" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=gsXJrY0f"><img src="http://feeds.feedburner.com/~f/john-biasi?i=gsXJrY0f" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=KySxVACP"><img src="http://feeds.feedburner.com/~f/john-biasi?i=KySxVACP" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/4pJ_qqTKCiY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/03/13/jury-duty/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/03/13/jury-duty/</feedburner:origLink></item>
		<item>
		<title>Should Microsoft quit the AV business?</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/xiCf36FxldQ/</link>
		<comments>http://john-biasi.com/wp/2007/03/07/should-microsoft-quit-the-av-business/#comments</comments>
		<pubDate>Wed, 07 Mar 2007 16:57:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/03/07/should-microsoft-quit-the-av-business/</guid>
		<description>An illuminating study was performed by AV-Comparatives, comparing various popular antivirus products.  I haven&amp;#8217;t had the opportunity to test out OneCare, Microsoft&amp;#8217;s antivirus offering, but I assumed they had released a product that was at least comparable to other mainstream antivirus options.  Apparently, I shouldn&amp;#8217;t assume.
ccording to the comparison, Microsoft scored an abysmal [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=Should+Microsoft+quit+the+AV+business%3F&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F03%2F07%2Fshould-microsoft-quit-the-av-business%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>An illuminating study was performed by AV-Comparatives, comparing various popular antivirus products.  I haven&#8217;t had the opportunity to test out OneCare, Microsoft&#8217;s antivirus offering, but I assumed they had released a product that was at least comparable to other mainstream antivirus options.  Apparently, I shouldn&#8217;t assume.</p>
<p>ccording to the comparison, Microsoft scored an abysmal 82.40% total on-demand detection of viruses/malware.  That&#8217;s over 6 percentage points lower than the the next-worst contender (Dr. Web, at 89.27%).  At the other end of the spectrum, Avira PE Premium, G DATA Security AVK, MicroWorld eScan Anti-Virus, F-Secure Anti-Virus, Kapersky Labs Kapersky AV, and AEC TrustPort AV WS were all rated above 97% detection, which AV-Comparatives calls their &#8220;ADVANCED+&#8221; certification level.</p>
<p>Keep in mind, it&#8217;s only a 1.x product from Microsoft, so they may be leaving room for improvement.  But I expected more from Microsoft with all the marketing about their security initiatives.</p>
<p>Here&#8217;s the full results of the test: <a href="http://www.av-comparatives.org/seiten/ergebnisse_2007_02.php">http://www.av-comparatives.org/seiten/ergebnisse_2007_02.php</a></p>
<p>Found via <a href="http://www.pcmag.com/article2/0,1895,2100528,00.asp">PCMag</a>.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=lpax2dNG"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=BC6t71eT"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=p72jIces"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=KF1MJ2kD"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=UD7xyIbH"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=pJg3YwHR"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=DTBWrnEV"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=XSC1AbI9"><img src="http://feeds.feedburner.com/~f/john-biasi?i=XSC1AbI9" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=c6HUv7ZA"><img src="http://feeds.feedburner.com/~f/john-biasi?i=c6HUv7ZA" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=HabjvBBE"><img src="http://feeds.feedburner.com/~f/john-biasi?i=HabjvBBE" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/xiCf36FxldQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/03/07/should-microsoft-quit-the-av-business/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/03/07/should-microsoft-quit-the-av-business/</feedburner:origLink></item>
		<item>
		<title>WordPress Remote Code Execution - Upgrade NOW!</title>
		<link>http://feedproxy.google.com/~r/john-biasi/~3/H4vJxFdSWzI/</link>
		<comments>http://john-biasi.com/wp/2007/03/05/wordpress-remote-code-execution-upgrade-now/#comments</comments>
		<pubDate>Tue, 06 Mar 2007 04:23:12 +0000</pubDate>
		<dc:creator>John</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://john-biasi.com/wp/2007/03/05/wordpress-remote-code-execution-upgrade-now/</guid>
		<description>Over the weekend, there was a notice about a security exploit that was inserted into the install files for WordPress 2.1.1.  Care to guess what version of WordPress this blog was running?  Don&amp;#8217;t worry, I wasn&amp;#8217;t about to volunteer that information until I actually had the upgrade taken care of.  Upgrading WordPress [...]&lt;p&gt;&lt;a href="http://sharethis.com/item?&amp;#038;wp=2.6.1&amp;#38;publisher=0edbbefc-8c65-472c-b325-cfb9a72b4a3a&amp;#38;title=WordPress+Remote+Code+Execution+-+Upgrade+NOW%21&amp;#38;url=http%3A%2F%2Fjohn-biasi.com%2Fwp%2F2007%2F03%2F05%2Fwordpress-remote-code-execution-upgrade-now%2F"&gt;ShareThis&lt;/a&gt;&lt;/p&gt;</description>
			<content:encoded><![CDATA[<p>Over the weekend, there was a notice about a security exploit that was inserted into the install files for WordPress 2.1.1.  Care to guess what version of WordPress this blog was running?  Don&#8217;t worry, I wasn&#8217;t about to volunteer that information until I actually had the upgrade taken care of.  Upgrading WordPress isn&#8217;t an entirely painless experience, but at least it&#8217;s a well-documented process.</p>
<p>If you are running WordPress 2.1.1, and you haven&#8217;t already done so, go to this link immediately, and follow the instructions to upgrade to 2.1.2:</p>
<p><a href="http://wordpress.org/development/2007/03/upgrade-212/"> WordPress 2.1.1 dangerous, Upgrade to 2.1.2</a></p>
<p><strong>Note:</strong> I appear to be having some difficulty creating links, post upgrade.  I&#8217;ll see what I can do to resolve the problem and update this post.</p>
<p><strong>Update:</strong> Problem resolved</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/john-biasi?a=5ZEmSNIl"><img src="http://feeds.feedburner.com/~f/john-biasi?d=41" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=ErMe76ug"><img src="http://feeds.feedburner.com/~f/john-biasi?d=131" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=L6gkbe4y"><img src="http://feeds.feedburner.com/~f/john-biasi?d=367" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=d7qwKXKG"><img src="http://feeds.feedburner.com/~f/john-biasi?d=336" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=SEXHZCBU"><img src="http://feeds.feedburner.com/~f/john-biasi?d=50" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=qnj5w9g0"><img src="http://feeds.feedburner.com/~f/john-biasi?d=232" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=7DBtuAXp"><img src="http://feeds.feedburner.com/~f/john-biasi?d=43" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=xch0LWSV"><img src="http://feeds.feedburner.com/~f/john-biasi?i=xch0LWSV" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=5SyA607m"><img src="http://feeds.feedburner.com/~f/john-biasi?i=5SyA607m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/john-biasi?a=yEXivClY"><img src="http://feeds.feedburner.com/~f/john-biasi?i=yEXivClY" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/john-biasi/~4/H4vJxFdSWzI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://john-biasi.com/wp/2007/03/05/wordpress-remote-code-execution-upgrade-now/feed/</wfw:commentRss>
		<feedburner:origLink>http://john-biasi.com/wp/2007/03/05/wordpress-remote-code-execution-upgrade-now/</feedburner:origLink></item>
	</channel>
</rss>
