<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>NovaInfosec.com</title>
	
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &amp; resources for infosec professionals in NoVA, DC, &amp; MD</description>
	<lastBuildDate>Fri, 25 May 2012 20:04:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/novainfosecportalblog" /><feedburner:info uri="novainfosecportalblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>novainfosecportalblog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Kid Hacking – Learning the Computer</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/lQ78oSghGEw/</link>
		<comments>http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/#comments</comments>
		<pubDate>Fri, 25 May 2012 20:00:14 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Securing Mom]]></category>
		<category><![CDATA[edubuntu]]></category>
		<category><![CDATA[kid]]></category>
		<category><![CDATA[kidz]]></category>
		<category><![CDATA[qimo]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=6513</guid>
		<description><![CDATA[As a follow-up to our recent post on teaching your kids some intro programming, I thought I&#8217;d also put out some notes on introducing the kiddos to computers in general. A while back I put out a call on the NoVAHackers distro list for Linux OSs that kids could learn on. They two most popular recommendations were: Qimo Edubuntu Both of these distros have tons of learning-to-program games as well. The big difference between them is that Qimo was designed for stand-alone computers while Edubuntu was designed for networked computers in a classroom environment. In my experiences with Qimo, there were many exercises focusing on typing, moving the mouse, clicking, and other computer basics. It also included many advanced learning games and even some later programming languages. Although it would freeze up every once in a while, Qimo seemed very stable overall. I was equally impressed with Edubuntu. Unfortunately, I tried to do some updates and it croaked on me for some reason. I could have tried reinstalling but my laziness snuck in and I just stuck with Qimo as it met my basic needs. Additionally, Qimo did seem somewhat better for kids under 6 (pre-school purposes with the youngest) [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Kid+Hacking+%E2%80%93+Learning+the+Computer+http%3A%2F%2Fj.mp%2FL0pyDV" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/&amp;t=Kid+Hacking+%E2%80%93+Learning+the+Computer" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/&amp;title=Kid+Hacking+%E2%80%93+Learning+the+Computer" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2011/10/eskimo.png"><img class="alignright size-full wp-image-6519" title="Eskimo" src="http://www.novainfosecportal.com/wp-content/uploads/2011/10/eskimo.png" alt="Picture of Qimo Logo" width="186" height="143" /></a>As a follow-up to our recent post on <a href="/2012/05/18/kid-hacking-learning-to-program/">teaching your kids some intro programming</a>, I thought I&#8217;d also put out some notes on introducing the kiddos to computers in general. A while back I put out a call on the <a href="/resources/nova-email-lists-networking/#novahackers">NoVAHackers distro list</a> for Linux OSs that kids could learn on. They two most popular recommendations were:</p>
<ul>
<li><a href="http://www.qimo4kids.com/" target="_blank">Qimo</a></li>
<li><a href="https://edubuntu.org/" target="_blank">Edubuntu</a></li>
</ul>
<p>Both of these distros have tons of learning-to-program games as well. The big difference between them is that Qimo was designed for stand-alone computers while Edubuntu was designed for networked computers in a classroom environment.</p>
<p>In my experiences with Qimo, there were many exercises focusing on typing, moving the mouse, clicking, and other computer basics. It also included many advanced learning games and even some later programming languages. Although it would freeze up every once in a while, Qimo seemed very stable overall.</p>
<p>I was equally impressed with Edubuntu. Unfortunately, I tried to do some updates and it croaked on me for some reason. I could have tried reinstalling but my laziness snuck in and I just stuck with Qimo as it met my basic needs. Additionally, Qimo did seem somewhat better for kids under 6 (pre-school purposes with the youngest) and was slightly more kid-friendly in my opinion.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>What other &#8220;kid&#8221; OSs do you use? What are your experiences? Let us know in the comments below. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Kid+Hacking+%E2%80%93+Learning+the+Computer+http%3A%2F%2Fj.mp%2FL0pyDV" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/&amp;t=Kid+Hacking+%E2%80%93+Learning+the+Computer" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/&amp;title=Kid+Hacking+%E2%80%93+Learning+the+Computer" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/lQ78oSghGEw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/25/kid-hacking-learning-the-computer/</feedburner:origLink></item>
		<item>
		<title>Video of the Day – You Down With BGP?</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/Oix9wOBRo20/</link>
		<comments>http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/#comments</comments>
		<pubDate>Fri, 25 May 2012 14:00:31 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=11882</guid>
		<description><![CDATA[Kind of cheesy but does a pretty good job of explaining Border Gateway Protocol to the tunes of some old school Naughty by Nature. It&#8217;s under 5 minutes so it shouldn&#8217;t be too painful. The video was part of the campaign against SOPA, PIPA, and ACTA several months ago. Some of my favorite lines include: You do a trace and then you notice there&#8217;s a routing loop? There&#8217;s no room for adjacencies, there&#8217;s just room to ROUTE IT! If you want to read along during the song (or are brave enough to try to karaoke it), check out there lyrics here. ##### Know of good vids we should feature? Let us know in the comments below. Today&#8217;s post pic is from FurAffinity.net. See ya!]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Video+of+the+Day+%E2%80%93+You+Down+With+BGP%3F+http%3A%2F%2Fj.mp%2FKZCh9S" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/&amp;t=Video+of+the+Day+%E2%80%93+You+Down+With+BGP%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/&amp;title=Video+of+the+Day+%E2%80%93+You+Down+With+BGP%3F" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/opp.jpg"><img class="alignright size-full wp-image-13495" title="Other People's Packets" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/opp.jpg" alt="Album Art of Other People's Packets" width="120" height="120" /></a>Kind of cheesy but does a pretty good job of explaining Border Gateway Protocol to the tunes of some old school Naughty by Nature. It&#8217;s under 5 minutes so it shouldn&#8217;t be too painful. The video was part of the campaign against SOPA, PIPA, and ACTA several months ago. Some of my favorite lines include:</p>
<ul>
<li>You do a trace and then you notice there&#8217;s a routing loop?</li>
<li>There&#8217;s no room for adjacencies, there&#8217;s just room to ROUTE IT!</li>
</ul>
<p>If you want to read along during the song (or are brave enough to try to karaoke it), check out there <a href="http://www.furaffinity.net/view/7456622/" target="_blank">lyrics here</a>.</p>
<p><span style="text-align:center; display: block;"><a href="http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/"><img src="http://img.youtube.com/vi/RT-1DU33xIk/2.jpg" alt="" /></a></span></p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Know of good vids we should feature? Let us know in the comments below. Today&#8217;s post pic is from <a href="http://www.furaffinity.net/view/7456622/" target="_blank">FurAffinity.net</a>. See ya!<br />
</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Video+of+the+Day+%E2%80%93+You+Down+With+BGP%3F+http%3A%2F%2Fj.mp%2FKZCh9S" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/&amp;t=Video+of+the+Day+%E2%80%93+You+Down+With+BGP%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/&amp;title=Video+of+the+Day+%E2%80%93+You+Down+With+BGP%3F" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/Oix9wOBRo20" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/25/video-of-the-day-you-down-with-bgp/</feedburner:origLink></item>
		<item>
		<title>Weekly Rewind – Top Industry News, Kid Hacking, “Infosec” Trademark, &amp; More…</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/K3DkirqZpvQ/</link>
		<comments>http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/#comments</comments>
		<pubDate>Fri, 25 May 2012 03:27:17 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[adwords]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[defcon-kids]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dnschanger]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hackid]]></category>
		<category><![CDATA[moving-target]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[nsa]]></category>
		<category><![CDATA[offensive]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[trademark]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=13476</guid>
		<description><![CDATA[If you missed anything or happened to be offline this past week, we hope you find this post useful as a quick reference. For those readers that may not have noticed, I actually tack on a bit of commentary to some the industry articles &#8211; so check out my italicized/bolded opinions and let me know if you agree in the comments. A la Schneier &#8230; you can also use this rewind post to talk about the security stories in the news that I haven’t covered. Industry Articles A Closer Look into the RSA SecureID Software Token: Widespread use of smart phones by employees to perform work related activities has introduced the idea of using these devices as an authentication token. As an example of such attempts, RSA SecureID software tokens are available for iPhone, Nokia and the Windows platforms. (continued here) (@grecs: Wow, this is a major ding in their soft token market. Come on RSA &#8230; what were you thinking?) Nmap 6 Released: The Nmap Project is pleased to announce the immediate, free availability of the Nmap Security Scanner version 6.00 from http://nmap.org/. It is the product of almost three years of work, 3,924 code commits, and more than [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Weekly+Rewind+%E2%80%93+Top+Industry+News%2C+Kid+Hacking%2C+%E2%80%9CInfosec%E2%80%9D+Trademark%2C+%26+More%E2%80%A6+http%3A%2F%2Fj.mp%2FKw6e3b" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/&amp;t=Weekly+Rewind+%E2%80%93+Top+Industry+News%2C+Kid+Hacking%2C+%E2%80%9CInfosec%E2%80%9D+Trademark%2C+%26+More%E2%80%A6" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/&amp;title=Weekly+Rewind+%E2%80%93+Top+Industry+News%2C+Kid+Hacking%2C+%E2%80%9CInfosec%E2%80%9D+Trademark%2C+%26+More%E2%80%A6" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><img class="alignright size-full wp-image-6180" title="Rewind Button" src="http://www.novainfosecportal.com/wp-content/uploads/2011/09/Button-Rewind-icon.png" alt="Icon of Rewind Button" width="154" height="154" />If you missed anything or happened to be offline this past week, we hope you find this post useful as a quick reference. For those readers that may not have noticed, I actually tack on a bit of commentary to some the industry articles &#8211; so check out my italicized/bolded opinions and let me know if you agree in the comments.</p>
<p>A la Schneier &#8230; you can also use this rewind post to talk about the security stories in the news that I haven’t covered.</p>
<h2>Industry Articles</h2>
<p><strong>A Closer Look into the RSA SecureID Software Token:</strong> Widespread use of smart phones by employees to perform work related activities has introduced the idea of using these devices as an authentication token. As an example of such attempts, RSA SecureID software tokens are available for iPhone, Nokia and the Windows platforms. (<a href="http://www.sensepost.com/blog/7045.html" target="_blank">continued here</a>) <em><strong>(@grecs: Wow, this is a major ding in their soft token market. Come on RSA &#8230; what were you thinking?)</strong></em></p>
<p><strong>Nmap 6 Released:</strong> The Nmap Project is pleased to announce the immediate, free availability of the Nmap Security Scanner version 6.00 from http://nmap.org/. It is the product of almost three years of work, 3,924 code commits, and more than a dozen point releases since the big Nmap 5 release in July 2009. (<a href="http://nmap.org/6/" target="_blank">continued here</a>) <em><strong>(@grecs: Tons of new features and cool things to play with in their first major release in three years.)</strong></em></p>
<p><strong>New White House Cybersecurity Chief Largely an Unknown:</strong> Named late last week to replace Howard Schmidt as the top White House cybersecurity adviser, Michael Daniel is a 17-year veteran of the Office of Management and Budget (OMB) and has been its intelligence branch chief for the past 11 years. (<a href="http://m.csoonline.com/article/706824/new-white-house-cybersecurity-chief-largely-an-unknown?mm_ref=http://www.team-cymru.org/News/" target="_blank">continued here</a>) <em><strong>(@grecs: Makes sense as that intel guys don&#8217;t like to be out in the public too much.)</strong></em></p>
<p><strong>Anatomy of a hack: 6 separate bugs needed to bring down Google browser:</strong> An exploit that fetched a teenage hacker a $60,000 bounty targeted six different security bugs to break out of the security sandbox fortifying Google&#8217;s Chrome browser. The extreme lengths taken in March by a hacker identified only as Pinkie Pie underscore the difficulty of piercing this safety perimeter. (<a href="http://arstechnica.com/security/2012/05/anatomy-of-a-hack-6-separate-bugs-needed-to-bring-down-google-browser/" target="_blank">continued here</a>) <em><strong>(@grecs: Awesome accomplishment by an extremely talented student. This guy is going straight to the pros.)</strong></em></p>
<p><strong>Notifying Users Affected by the DNSChanger Malware:</strong> Starting today we’re undertaking an effort to notify roughly half a million people whose computers or home routers are infected with a well-publicized form of malware known as DNSChanger. After successfully alerting a million users last summer to a different type of malware, &#8230; (<a href="http://googleonlinesecurity.blogspot.com/2012/05/notifying-users-affected-by-dnschanger.html" target="_blank">continued here</a>) <em><strong>(@grecs: Huge mistake to even set these servers up in the first place. Now Google has to step in to hopefully warn enough people of them loosing the interwebs.)</strong></em></p>
<h2>Our Blog Posts</h2>
<p><strong>Video of the Week – How DNS Works:</strong> DNS has progressed a long way from just being a file on your computer that maps domain names to IP addresses. We came across this fairly simple 2:27 minute video that explains the basics of DNS well. (<a href="/2012/05/18/video-of-the-day-how-dns-works/">continued here</a>)</p>
<p><strong>Kid Hacking – Learning to Program:</strong> The successes of several HacKid conferences and the first ever DefCon Kids last year got me thinking about starting to teach my kid a little bit more about computers than he probably learns in school. Programming seemed like the obvious choice to me as that is where I started years ago. Yeah, it was only Basic but at least I learned the concepts. With a little bit of Googling the top choice seemed to be a language called Scratch hosted over at MIT. At this point I didn’t really know much about it so I put a call out to the Twitterverse since I know many of us have elementary-aged kids. (<a href="/2012/05/18/kid-hacking-learning-to-program/">continued here</a>)</p>
<p><strong>&#8220;Infosec&#8221; Trademark Dampens Google&#8217;s Adword Revenue:</strong> Ok … so maybe the title is a little off &#8230; but it did dampen their revenue … at least some. Specifically, they’ve been loosing $10 a day from us. A few weeks ago I decided to try the whole Google AdWords thing out to help spread the word about NovaInfosec.com. I signed up and muddled around trying to understand everything and after a bit of stumbling around I was able to create an ad. It was nothing big as you can see below. So at this point I was pretty happy and next went into generating keywords. This activity took a bit but I came up with around 12 keywords that seemed to fit what I was looking for. It did take a while to come up with those 12 keywords though. (<a href="/2012/05/21/trademark-of-term-infosec/">continued here</a>)</p>
<p><strong>Contemplating the Meaning of Offensive Job Postings:</strong> Huh? First there was the unspoken “O” word. Then it finally started making it’s way into speeches of high-ranking current and former government officials. And now it’s in job posts. Of course a private company actually performing offensive activities would likely be illegal in most cases … although I’m sure there’s a sneaky way around that (e.g., re-terming it as “active defense” or something).” However most likely this person would be serving some government agency in some capacity … so who knows… It’ll be interesting to watch how “offensive” trends in the coming months and years. And with all this press I’m sure NG is getting lots of applications for this position. (<a href="/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/">continued here</a>)</p>
<p><strong>Poll: Would You Give Up Your Facebook Password for a Clearance?:</strong> So last week we did a post on the whole Facebook password turnover thing. Overall legislation is popping up all over the place at the state and federal level preventing employers from asking for such information. Even though somehow this practice crept into practice at companies, clearly almost everyone is against it. A lot of people that I’ve spoken with recently around the DC area were pretty much dead against turning over passwords to an employer. The thing that I think makes DC a little different though is that much of our work involves some type of security investigation. (<a href="/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/">continued here</a>)</p>
<p><strong>NSA Looking to Train Students in Cyber Ops:</strong> The NSA has long run the National Center of Academic Excellence (CAE) program in Information Assurance Education (CAE-IAE) and more recently in Research (CAE-R) however they are reaching into new grounds by formalizing a new Cyber Operations (CAE-Cyber) distinction for colleges and universities. We’ve written about the CAE program before … and although it isn’t the be-all end-all, it’s definitely a good place to start if you are considering where to get your undergrad or graduate degrees. For the new CAE-Cyber program so far the NSA has only designated four schools (highlighted below) as meeting its requirements. (<a href="/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/">continued here</a>)</p>
<p><strong>Is Moving-Target Defense a Security Game Changer?:</strong> I came across this interesting article and audio interview today on research being done on the topic of moving-target defense. Coined in 2008 as a game changing technology in security, I’ve only been recently hearing about this concept and was looking for more details on the topic. This article from GovInfoSecurity.com provided a nice overview and followed with additional details in an 11 minute audio interview with one of the researchers that receive a $1 million grant. The concept is based on the assumption that enterprise networks and systems generally remain static over time. (<a href="/2012/05/23/is-moving-target-defense-a-security-game-changer/">continued here</a>)</p>
<p><strong>Job: Senior Security Consultant in Washington, DC / Virtual:</strong> This challenging position from GuidePoint Security looks to be very flexible and provides great benes however 40% travel might be a little much for some. But if you want to see lots of places and meet lots of people … maybe this is the job for you. The benefits package includes 100% coverage on healthcare (don’t see that too often) with lots of goodies (e.g., MBA/MBP and an iPhone). They seem to be looking for a jack-of-all-trades type security person so I see this as the type of job where if you don’t know it, you better be willing to learn on-the-fly. They also encourage speaking at conferences so that may be a plus for some. The company has been around for a year and is based in Reston, VA. (<a href="/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/">continued here</a>)</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Hope everyone had a wonderful week. Have a great weekend! See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Weekly+Rewind+%E2%80%93+Top+Industry+News%2C+Kid+Hacking%2C+%E2%80%9CInfosec%E2%80%9D+Trademark%2C+%26+More%E2%80%A6+http%3A%2F%2Fj.mp%2FKw6e3b" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/&amp;t=Weekly+Rewind+%E2%80%93+Top+Industry+News%2C+Kid+Hacking%2C+%E2%80%9CInfosec%E2%80%9D+Trademark%2C+%26+More%E2%80%A6" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/&amp;title=Weekly+Rewind+%E2%80%93+Top+Industry+News%2C+Kid+Hacking%2C+%E2%80%9CInfosec%E2%80%9D+Trademark%2C+%26+More%E2%80%A6" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/K3DkirqZpvQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/24/weekly-rewind-%e2%80%93-top-industry-news-kid-hacking-infosec-trademark-more/</feedburner:origLink></item>
		<item>
		<title>Job: Senior Security Consultant in Washington, DC / Virtual</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/jdc9EHb7Jng/</link>
		<comments>http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/#comments</comments>
		<pubDate>Thu, 24 May 2012 20:00:14 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Job Board]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[guidepoint]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[virtual]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=13458</guid>
		<description><![CDATA[This challenging position from GuidePoint Security looks to be very flexible and provides great benes however 40% travel might be a little much for some. But if you want to see lots of places and meet lots of people &#8230; maybe this is the job for you. The benefits package includes 100% coverage on healthcare (don&#8217;t see that too often) with lots of goodies (e.g., MBA/MBP and an iPhone). They seem to be looking for a jack-of-all-trades type security person so I see this as the type of job where if you don&#8217;t know it, you better be willing to learn on-the-fly. They also encourage speaking at conferences so that may be a plus for some. The company has been around for a year and is based in Reston, VA. It might be a chance to get in on the ground floor&#8230; And don&#8217;t forget &#8230; if you organization is interested in posting their career opportunities here, head on over to our Job Board page for all the details. Well anyway &#8230; on to the job post. Title Senior Security Consultant Location Washington, DC / Virtual Company Name GuidePoint Security Job Description Senior Security Consultants at GuidePoint Security are experienced [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Job%3A+Senior+Security+Consultant+in+Washington%2C+DC+%2F+Virtual+http%3A%2F%2Fj.mp%2FKltL65" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/&amp;t=Job%3A+Senior+Security+Consultant+in+Washington%2C+DC+%2F+Virtual" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/&amp;title=Job%3A+Senior+Security+Consultant+in+Washington%2C+DC+%2F+Virtual" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/guidepointlogo.png"><img class="alignright size-full wp-image-13464" title="GuidePoint Security" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/guidepointlogo.png" alt="GuidePoint Security Logo" width="184" height="97" /></a>This challenging position from GuidePoint Security looks to be very flexible and provides great benes however 40% travel might be a little much for some. But if you want to see lots of places and meet lots of people &#8230; maybe this is the job for you. The benefits package includes 100% coverage on healthcare (don&#8217;t see that too often) with lots of goodies (e.g., MBA/MBP and an iPhone). They seem to be looking for a jack-of-all-trades type security person so I see this as the type of job where if you don&#8217;t know it, you better be willing to learn on-the-fly. They also encourage speaking at conferences so that may be a plus for some. The company has been around for a year and is based in Reston, VA. It might be a chance to get in on the ground floor&#8230;</p>
<p>And don&#8217;t forget &#8230; if you organization is interested in posting their career opportunities here, head on over to our <a href="/general/job-board/">Job Board</a> page for all the details. Well anyway &#8230; on to the job post.</p>
<h2>Title</h2>
<p>Senior Security Consultant</p>
<h2>Location</h2>
<p>Washington, DC / Virtual</p>
<h2>Company Name</h2>
<p>GuidePoint Security</p>
<h2>Job Description</h2>
<p>Senior Security Consultants at GuidePoint Security are experienced professionals who are autonomous, experienced, self-driven security fanatics. Our Senior Security Consultants are materially involved in the complete professional services lifecycle, from pre-sales through delivery and have the freedom and control over how engagements are scoped and delivered. Our unique position as both a Value-Added Reseller (VAR) AND a professional services organization also requires our Senior Security Consultants to continually expand their knowledge and experience with the latest cutting-edge information security technologies. This helps satisfy our Senior Security Consultants desire to constantly expand their knowledge and better meet the needs of our clients.</p>
<p>Travel &amp; Office Location</p>
<ul>
<li>Approximately 40% out-of-town travel to client locations is typical for Senior Security Consultants</li>
<li>Senior Security Consultants work from home when not visiting client locations</li>
</ul>
<p>Benefits &amp; Technical Perks</p>
<ul>
<li>Choice of MacBook Air or MacBook Pro</li>
<li>Apple iPhone 4S with mobile hotspot functionality</li>
<li>100% employer-paid medical, dental and vision insurance for employee, with generous employer family contributions</li>
<li>Eligibility for retirement plan after 6 months</li>
<li>Competitive salary dependent on experience</li>
</ul>
<h2>Requirements</h2>
<p>Required</p>
<ul>
<li>Proficiency in Information Security tools such as Nessus, Kismet, Nmap, Burp, Netsparker, WebInspect, AppScan, Qualys, Nexpose, Core Impact, Metasploit and manual techniques to exploit vulnerabilities (both network and application layers)</li>
<li>Proficiency in operating systems including Windows 2003 &amp; 2008 R2, Windows XP and 7, RHES and Ubuntu Linux</li>
<li>Proficiency in manually testing for Application Security specific vulnerabilities such as those included in the OWASP Top 10(SQL Injection, Cross-site Scripting, etc.)</li>
<li>Knowledge of industry standards including ISO27000 series, NIST 800-42 &amp; 800-53 and other industry related security standards</li>
<li>Information Systems architecture and security control design and development experience</li>
<li>Knowledge of Industry Regulations, e.g.,Gramm-Leach-Bliley Act (GLBA), Health Insurance Portability and Accountability Act of 1996 (HIPAA), Payment Card Industry (PCI), Sarbanes-Oxley (SOX)</li>
</ul>
<p>Preferred</p>
<ul>
<li>Experience with application source-code security reviews</li>
<li>Experience with programming languages such as Java, C, C++, C#, Python, Ruby and .NET</li>
<li>Forensic &amp; Incident Response experience</li>
<li>Mobile security experience</li>
<li>PCI DSS Industry experience</li>
<li>Educational &amp; Professional Credentials</li>
<li>Bachelor’s degree in a relevant discipline or equivalent experience</li>
<li>3-5 years of consulting experience in the Information Security industry OR as a technical lead for an internal Information Security program</li>
<li>Professional certifications such as CEH, CPT, CISM, CISSP, GIAC, GSEC and QSA</li>
<li>Conference speaking experience is strongly preferred</li>
</ul>
<h2>About GuidePoint Security</h2>
<p>GuidePoint Security provides customized, innovative and valuable information security solutions that enable commercial and federal organizations to more successfully achieve their security and business goals.</p>
<h2>Follow-Up Contact Information</h2>
<p>For additional information and to apply, head on over to its <a href="http://www.linkedin.com/jobs?viewJob=&amp;jobId=3079344" target="_blank">requisition on LinkedIn</a>.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>You can find more career opportunities over on our <a href="/general/job-board/">Job Board</a>. Head on over there for all the details. Today&#8217;s post image is from the good folks over at <a href="http://www.guidepointsecurity.com/" target="_blank">GuidePointSecurity.com</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Job%3A+Senior+Security+Consultant+in+Washington%2C+DC+%2F+Virtual+http%3A%2F%2Fj.mp%2FKltL65" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/&amp;t=Job%3A+Senior+Security+Consultant+in+Washington%2C+DC+%2F+Virtual" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/&amp;title=Job%3A+Senior+Security+Consultant+in+Washington%2C+DC+%2F+Virtual" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/jdc9EHb7Jng" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/24/job-senior-security-consultant-in-washington-dc-virtual/</feedburner:origLink></item>
		<item>
		<title>Is Moving-Target Defense a Security Game Changer?</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/zQWYKqozH6Y/</link>
		<comments>http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/#comments</comments>
		<pubDate>Thu, 24 May 2012 03:00:32 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[govinfosecurity]]></category>
		<category><![CDATA[moving-target]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=13433</guid>
		<description><![CDATA[I came across this interesting article and audio interview today on research being done on the topic of moving-target defense. Coined in 2008 as a game changing technology in security, I&#8217;ve only been recently hearing about this concept and was looking for more details on the topic. This article from GovInfoSecurity.com provided a nice overview and followed with additional details in an 11 minute audio interview with one of the researchers that receive a $1 million grant. The concept is based on the assumption that enterprise networks and systems generally remain static over time. This gives an attacker ample time to research the environment and layout the most opportune attack. Moving-defense challenges this assumption since the enterprise would constantly change in terms of its configuration of the overall environment. Examples include changing IPs, underlying OSs, listening ports and protocols, etc. An attacker could perform recon and basic scanning for months but then nothing works as expected when it comes time to attack. Enterprises could also use this adaption technique in response to an attack to quickly limit the resources an attacker has access to. And as the researcher noted, the challenge involves keeping the network operational while making all these [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Is+Moving-Target+Defense+a+Security+Game+Changer%3F+http%3A%2F%2Fj.mp%2FJyVTpR" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/&amp;t=Is+Moving-Target+Defense+a+Security+Game+Changer%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/&amp;title=Is+Moving-Target+Defense+a+Security+Game+Changer%3F" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/fencing.jpg"><img class="alignright size-medium wp-image-13441" title="Fencing" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/fencing-300x225.jpg" alt="" width="180" height="135" /></a>I came across this interesting article and audio interview today on research being done on the topic of moving-target defense. Coined in 2008 as a game changing technology in security, I&#8217;ve only been recently hearing about this concept and was looking for more details on the topic. This article from GovInfoSecurity.com provided a nice overview and followed with additional details in an 11 minute audio interview with one of the researchers that receive a $1 million grant.</p>
<p>The concept is based on the assumption that enterprise networks and systems generally remain static over time. This gives an attacker ample time to research the environment and layout the most opportune attack. Moving-defense challenges this assumption since the enterprise would constantly change in terms of its configuration of the overall environment. Examples include changing IPs, underlying OSs, listening ports and protocols, etc. An attacker could perform recon and basic scanning for months but then nothing works as expected when it comes time to attack. Enterprises could also use this adaption technique in response to an attack to quickly limit the resources an attacker has access to. And as the researcher noted, the challenge involves keeping the network operational while making all these changes and ensuring cost-effective management.</p>
<p>Overall moving-target defense looks like an interesting approach and I anticipate the results of their research. I do have my doubts, though, on this being a cost effective security control. To me the resources needed to manage such a vast dynamic environment combined with keeping it operational appears to be too complex and costly. Perhaps this technique could have application in specialized segments (e.g., a DMZ) as part of a defense-in-depth approach.</p>
<p>If you are interested in more details on moving-target defense, the <a href="http://cps-vo.org/group/mtrs/" target="_blank">National Symposium on Moving Target Research</a> is scheduled on June 11 right in our backyard of Annapolis, MD.</p>
<p>via GovInfoSecurity.com</p>
<blockquote><p>Imagine a computer network that can fool intruders into seeing configurations that in reality don&#8217;t exist, making it hard for them to invade the system. That&#8217;s what Scott DeLoach is trying to figure out how to do.</p>
<p>DeLoach, a Kansas State University computer and information sciences professor, and colleague Simon Ou have received a 5-year, $1 million-plus grant from the Air Force Office of Scientific Research to study a type of adaptive cybersecurity called moving-target defense.</p>
<p>In an interview with Information Security Media Group, DeLoach explains a network that employs a moving-target defense would automatically and periodically randomize its configuration through various methods, such as changing the addresses of software applications on the network, switching between instances of the applications and changing the location of critical system data to thwart cyberattackers.</p></blockquote>
<p>Continued <a href="http://www.govinfosecurity.com/interviews/intelligent-defense-against-intruders-i-1565" target="_blank">here</a>.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Do you think this moving-target defense will be game changer? Let us know in the comments below. Today&#8217;s post pic is from <a href="http://www.sportsgamesrules.com/fencing-rules/" target="_blank">SportsGamesRules.com</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Is+Moving-Target+Defense+a+Security+Game+Changer%3F+http%3A%2F%2Fj.mp%2FJyVTpR" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/&amp;t=Is+Moving-Target+Defense+a+Security+Game+Changer%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/&amp;title=Is+Moving-Target+Defense+a+Security+Game+Changer%3F" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/zQWYKqozH6Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/23/is-moving-target-defense-a-security-game-changer/</feedburner:origLink></item>
		<item>
		<title>NSA Looking to Train Students in Cyber Ops</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/bNI6UNzNfQg/</link>
		<comments>http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/#comments</comments>
		<pubDate>Thu, 24 May 2012 01:00:58 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[cae]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[nsa]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=13423</guid>
		<description><![CDATA[The NSA has long run the National Center of Academic Excellence (CAE) program in Information Assurance Education (CAE-IAE) and more recently in Research (CAE-R) however they are reaching into new grounds by formalizing a new Cyber Operations (CAE-Cyber) distinction for colleges and universities. We&#8217;ve written about the CAE program before &#8230; and although it isn&#8217;t the be-all end-all, it&#8217;s definitely a good place to start if you are considering where to get your undergrad or graduate degrees. For the new CAE-Cyber program so far the NSA has only designated four schools (highlighted below) as meeting its requirements. For locals that are interested in attending participating schools, unfortunately it doesn&#8217;t look like any are in the NoVA/DC area. Hopefully, they offer distance learning programs&#8230; via CNet.com The National Security Agency has chosen the first four universities it will accredit to teach cyber ops programs. The universities winning the designation Centers of Academic Excellence in Cyber Operations&#8221; are Dakota State University, the Naval Postgraduate School, Northeastern University, and the University of Tulsa. Twenty universities have applied to partner with the federal agency, which said it started the program with an eye toward building a larger reservoir of professionals to support its work [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=NSA+Looking+to+Train+Students+in+Cyber+Ops+http%3A%2F%2Fj.mp%2FKVrltK" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/&amp;t=NSA+Looking+to+Train+Students+in+Cyber+Ops" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/&amp;title=NSA+Looking+to+Train+Students+in+Cyber+Ops" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2011/05/nsa_logo.gif"><img class="alignright size-full wp-image-5218" title="NSA Logo" src="http://www.novainfosecportal.com/wp-content/uploads/2011/05/nsa_logo.gif" alt="NSA" width="125" height="125" /></a>The NSA has long run the National Center of Academic Excellence (CAE) program in Information Assurance Education (CAE-IAE) and more recently in Research (CAE-R) however they are reaching into new grounds by formalizing a new Cyber Operations (CAE-Cyber) distinction for colleges and universities. We&#8217;ve written about the <a href="/2011/10/07/top-infosec-schools-in-the-metro-dc-area/">CAE program before</a> &#8230; and although it isn&#8217;t the be-all end-all, it&#8217;s definitely a good place to start if you are considering where to get your undergrad or graduate degrees. For the new CAE-Cyber program so far the NSA has only designated four schools (highlighted below) as meeting its requirements. For locals that are interested in attending participating schools, unfortunately it doesn&#8217;t look like any are in the NoVA/DC area. Hopefully, they offer distance learning programs&#8230;</p>
<p>via CNet.com</p>
<p style="padding-left: 30px;">The National Security Agency has chosen the first four universities it will accredit to teach cyber ops programs.</p>
<p style="padding-left: 30px;">The universities winning the designation Centers of Academic Excellence in Cyber Operations&#8221; are <strong>Dakota State University</strong>, the <strong>Naval Postgraduate School</strong>, <strong>Northeastern University</strong>, and the <strong>University of Tulsa</strong>.</p>
<p style="padding-left: 30px;">Twenty universities have applied to partner with the federal agency, which said it started the program with an eye toward building a larger reservoir of professionals to support its work in conducting cyber-intelligence operations against adversaries. The interdisciplinary curriculum will include coursework in computer science, computer engineering, and electrical engineering. Some participants will also be invited to NSA seminars.</p>
<p style="padding-left: 30px;">But this is not the equivalent of spy school. NSA said in a statement that the participating students and faculty members would not participate in U.S. government intelligence activities. Still, government officials have long bemoaned what they see as a pressing need to step up the number &#8212; and talent &#8212; of people it can choose to staff its myriad cyber espionage posts.</p>
<p>Continued <a href="http://news.cnet.com/8301-11386_3-57439464-76/u.s-spy-agency-looking-to-train-students-in-cyber-ops/" target="_blank">here</a>.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>For more information on NSA&#8217;s CAE check out their <a href="http://www.nsa.gov/ia/academic_outreach/nat_cae/" target="_blank">program page</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=NSA+Looking+to+Train+Students+in+Cyber+Ops+http%3A%2F%2Fj.mp%2FKVrltK" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/&amp;t=NSA+Looking+to+Train+Students+in+Cyber+Ops" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/&amp;title=NSA+Looking+to+Train+Students+in+Cyber+Ops" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/bNI6UNzNfQg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/23/nsa-looking-to-train-students-in-cyber-ops/</feedburner:origLink></item>
		<item>
		<title>Poll: Would You Give Up Your Facebook Password for a Clearance?</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/wYASVWZnM_4/</link>
		<comments>http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/#comments</comments>
		<pubDate>Wed, 23 May 2012 03:45:10 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[clearance]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=12713</guid>
		<description><![CDATA[So last week we did a post on the whole Facebook password turnover thing. Overall legislation is popping up all over the place at the state and federal level preventing employers from asking for such information. Even though somehow this practice crept into practice at companies, clearly almost everyone is against it. A lot of people that I&#8217;ve spoken with recently around the DC area were pretty much dead against turning over passwords to an employer. The thing that I think makes DC a little different though is that much of our work involves some type of security investigation. That could be anything from a simple background check all the way up to the highest level of clearances. As in the original case that sparked this whole thing off, Robert Collins was asked for his Facebook password as part of his investigative background to check for gang affiliations. The thing that I haven&#8217;t heard much discussion of yet is whether turning over your passwords is required for any of the common clearance processes out there. According to what I&#8217;ve heard asking for this type of information hasn&#8217;t crept in to the process yet. Many of those that I&#8217;ve chatted with [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Poll%3A+Would+You+Give+Up+Your+Facebook+Password+for+a+Clearance%3F+http%3A%2F%2Fj.mp%2FJw6bqP" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/&amp;t=Poll%3A+Would+You+Give+Up+Your+Facebook+Password+for+a+Clearance%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/&amp;title=Poll%3A+Would+You+Give+Up+Your+Facebook+Password+for+a+Clearance%3F" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/facebook.jpg"><img class="alignright size-medium wp-image-13407" title="Facebook" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/facebook-300x168.jpg" alt="Picture of Facebook" width="210" height="118" /></a>So last week we did a <a href="/2012/05/16/can-asking-for-your-facebook-password-save-the-economy/">post on the whole Facebook password turnover thing</a>. Overall legislation is popping up all over the place at the state and federal level preventing employers from asking for such information. Even though somehow this practice crept into practice at companies, clearly almost everyone is against it.</p>
<p>A lot of people that I&#8217;ve spoken with recently around the DC area were pretty much dead against turning over passwords to an employer. The thing that I think makes DC a little different though is that much of our work involves some type of security investigation. That could be anything from a simple background check all the way up to the highest level of clearances. As in the <a href="http://www.nj.com/news/index.ssf/2012/03/some_employers_are_asking_job.html" target="_blank">original case</a> that sparked this whole thing off, Robert Collins was asked for his Facebook password as part of his investigative background to check for gang affiliations.</p>
<p>The thing that I haven&#8217;t heard much discussion of yet is whether turning over your passwords is required for any of the common clearance processes out there. According to what I&#8217;ve heard asking for this type of information hasn&#8217;t crept in to the process yet. Many of those that I&#8217;ve chatted with were very adamant about turning over their credentials. When I asked if they would cough up the creds if it were required for the clearance process most got pretty quiet.</p>
<p>For many of those around the DC area working for the government (either directly or indirectly), maybe giving up your passwords is only fair in exchange for obtaining a clearance and working on those types of programs. There are perks as well &#8211; job security and higher salaries (~20% more) just to name a few. All this talk leads up to the poll for this week.</p>
Note: There is a poll embedded within this post, please visit the site to participate in this post's poll.
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>If there are other answers I may have missed or opinions you want to mention, please add them to the comments below. And as usual <a href="/contact-us/">let us know</a> if there are other poll questions you’d like to see us ask. Today&#8217;s post pic is from <a href="http://news.blogs.cnn.com/2012/03/23/overheard-on-cnn-com-whats-the-password/" target="_blank">CNN.com</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Poll%3A+Would+You+Give+Up+Your+Facebook+Password+for+a+Clearance%3F+http%3A%2F%2Fj.mp%2FJw6bqP" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/&amp;t=Poll%3A+Would+You+Give+Up+Your+Facebook+Password+for+a+Clearance%3F" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/&amp;title=Poll%3A+Would+You+Give+Up+Your+Facebook+Password+for+a+Clearance%3F" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/wYASVWZnM_4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/22/poll-would-you-give-up-your-facebook-password-for-a-clearance/</feedburner:origLink></item>
		<item>
		<title>Contemplating the Meaning of Offensive Job Postings</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/vJxN478juzA/</link>
		<comments>http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/#comments</comments>
		<pubDate>Wed, 23 May 2012 03:14:27 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[offensive]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[threatpost]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=13391</guid>
		<description><![CDATA[Huh? First there was the unspoken &#8220;O&#8221; word. Then it finally started making it&#8217;s way into speeches of high-ranking current and former government officials. And now it&#8217;s in job posts. Of course a private company actually performing offensive activities would likely be illegal in most cases … although I’m sure there’s a sneaky way around that (e.g., re-terming it as “active defense” or something).&#8221; However most likely this person would be serving some government agency in some capacity &#8230; so who knows&#8230; It&#8217;ll be interesting to watch how &#8220;offensive&#8221; trends in the coming months and years. And with all this press I&#8217;m sure NG is getting lots of applications for this position. via ThreatPost.com (emphasis mine) Defense giant Northrop Grumman is hiring software engineers to help it carry out &#8220;offensive cyberspace operations,&#8221; according to a recent job posting. The job posting, for a &#8220;Cyber Software Engineer 2&#8243; appeared on the Website Clearancejobs.com and described a position on a Northrop R&#38;D project to &#8220;plan, execute and assess an Offensive Cyberspace Operation (OCO) mission&#8221; that would include familiarity with tools like Metasploit and Google Earth and &#8220;integration of capabilities such as command linkages, data flows, situation awareness (SA) and command and control [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Contemplating+the+Meaning+of+Offensive+Job+Postings+http%3A%2F%2Fj.mp%2FKRV8n1" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/&amp;t=Contemplating+the+Meaning+of+Offensive+Job+Postings" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/&amp;title=Contemplating+the+Meaning+of+Offensive+Job+Postings" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/clearancejobs.png"><img class="alignright size-full wp-image-13394" title="Clearance Jobs" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/clearancejobs.png" alt="" width="196" height="91" /></a>Huh? First there was the unspoken &#8220;O&#8221; word. Then it finally started making it&#8217;s way into speeches of high-ranking current and former government officials. And now it&#8217;s in job posts. Of course a private company actually performing offensive activities would likely be illegal in most cases … although I’m sure there’s a sneaky way around that (e.g., re-terming it as “active defense” or something).&#8221; However most likely this person would be serving some government agency in some capacity &#8230; so who knows&#8230; It&#8217;ll be interesting to watch how &#8220;offensive&#8221; trends in the coming months and years. And with all this press I&#8217;m sure NG is getting lots of applications for this position.</p>
<p>via ThreatPost.com (emphasis mine)</p>
<blockquote><p>Defense giant Northrop Grumman is hiring software engineers to help it carry out &#8220;<strong>offensive cyberspace operations</strong>,&#8221; according to a recent job posting.</p>
<p>The job posting, for a &#8220;Cyber Software Engineer 2&#8243; appeared on the Website Clearancejobs.com and described a position on a Northrop R&amp;D project to &#8220;plan, execute and assess an <strong>Offensive Cyberspace Operation (OCO) mission</strong>&#8221; that would include familiarity with tools like Metasploit and Google Earth and &#8220;integration of capabilities such as command linkages, data flows, situation awareness (SA) and command and control (C2) tools.&#8221;</p>
<p>Firms like Northrop have repeatedly been the target of sustained and sophisticated attacks from outside agents. Many of those attackers &#8211; euphemistically described as &#8220;Advanced Persistent Threats&#8221; &#8211; or APTs &#8211; are believed to have links to China and groups working for the People&#8217;s Liberation Army (PLA).</p>
<p>A spokeswoman for Northrop Grumman confirmed the validity of the job posting, but declined to elaborate on what Northrop was referring to with the term &#8220;Offensive Cyberspace Operations.&#8221;</p>
<p>As described, the job appears to be suited to a mid-level software engineer with experience in networking and agile development methodologies using a wide range of software- and Web development platforms, including Java, XML, JMS, PostgreSQL, Javascript and Python. The applicant is also expected to have knowledge of &#8220;&#8216;security research&#8217; tools like Metasploit, WorldWind (and) Google Earth,&#8221; according to the job posting.</p></blockquote>
<p>Continued <a href="https://threatpost.com/en_us/blogs/defense-contractor-northrop-grumman-hiring-offensive-cyber-ops-051812" target="_blank">here</a>.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Check the job post out for yourself <a href="http://www.clearancejobs.com/jobs/1536410/cyber-software-engineer-2" target="_blank">here</a>. Today&#8217;s post pic is from <a href="http://www.clearancejobs.com/jobs/1536410/cyber-software-engineer-2" target="_blank">ClearanceJobs.com</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Contemplating+the+Meaning+of+Offensive+Job+Postings+http%3A%2F%2Fj.mp%2FKRV8n1" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/&amp;t=Contemplating+the+Meaning+of+Offensive+Job+Postings" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/&amp;title=Contemplating+the+Meaning+of+Offensive+Job+Postings" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/vJxN478juzA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/22/contemplating-the-meaning-of-offensive-job-postings/</feedburner:origLink></item>
		<item>
		<title>“Infosec” Trademark Dampens Google’s Adword Revenue</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/XT4rUwznEOY/</link>
		<comments>http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/#comments</comments>
		<pubDate>Tue, 22 May 2012 00:00:04 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[adwords]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[trademark]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=12772</guid>
		<description><![CDATA[Ok &#8230; so maybe the title is a little off &#8230; but it did dampen their revenue &#8230; at least some. Specifically, they&#8217;ve been loosing $10 a day from us. A few weeks ago I decided to try the whole Google AdWords thing out to help spread the word about NovaInfosec.com. I signed up and muddled around trying to understand everything and after a bit of stumbling around I was able to create an ad. It was nothing big as you can see below. So at this point I was pretty happy and next went into generating keywords. This activity took a bit but I came up with around 12 keywords that seemed to fit what I was looking for. It did take a while to come up with those 12 keywords though. I started with around three times that but had to remove many since Google indicated they wouldn&#8217;t generate any traffic. Mmm? I wonder if they really meant to say it wouldn&#8217;t generate revenue for them&#8230; Anyway, I logged out and continued my daily routine, content that I might spread word of the site out to a slightly larger audience. I checked in periodically to see if it [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=%E2%80%9CInfosec%E2%80%9D+Trademark+Dampens+Google%E2%80%99s+Adword+Revenue+http%3A%2F%2Fj.mp%2FJLUTyl" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/&amp;t=%E2%80%9CInfosec%E2%80%9D+Trademark+Dampens+Google%E2%80%99s+Adword+Revenue" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/&amp;title=%E2%80%9CInfosec%E2%80%9D+Trademark+Dampens+Google%E2%80%99s+Adword+Revenue" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/google-trademark-policy.jpg"><img class="alignright size-full wp-image-13276" title="Google Trademark Policy" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/google-trademark-policy.jpg" alt="" width="112" height="112" /></a>Ok &#8230; so maybe the title is a little off &#8230; but it did dampen their revenue &#8230; at least some. Specifically, they&#8217;ve been loosing $10 a day from us. A few weeks ago I decided to try the whole Google AdWords thing out to help spread the word about NovaInfosec.com. I signed up and muddled around trying to understand everything and after a bit of stumbling around I was able to create an ad. It was nothing big as you can see below.</p>
<p style="text-align: center;"><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/adwordad.png"><img class="aligncenter size-medium wp-image-13110" title="NovaInfosec Adword Ad" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/adwordad-300x126.png" alt="Picture of NovaInfosec Adword Ad" width="300" height="126" /></a></p>
<p>So at this point I was pretty happy and next went into generating keywords. This activity took a bit but I came up with around 12 keywords that seemed to fit what I was looking for. It did take a while to come up with those 12 keywords though. I started with around three times that but had to remove many since Google indicated they wouldn&#8217;t generate any traffic. Mmm? I wonder if they really meant to say it wouldn&#8217;t generate revenue for them&#8230; Anyway, I logged out and continued my daily routine, content that I might spread word of the site out to a slightly larger audience.</p>
<p>I checked in periodically to see if it was running but no luck. I expected this wait as Google claimed it could take up to three business days to review and start publishing the ad. After five days I called in, chatted with someone, and they flagged my submission to be reviewed ASAP. After about a day I didn&#8217;t notice anything so I logged back in and was surprise to find that my ad had been disapproved due to a trademark held for the term &#8220;infosec.&#8221; Really?</p>
<p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/adwordrejection.png"><img class="aligncenter size-medium wp-image-13111" title="NovaInfosec Adword Rejection" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/adwordrejection-300x126.png" alt="Picture of NovaInfosec Adword Rejection" width="300" height="126" /></a></p>
<p>I immediately picked up the phone and called Google to see how this obvious error could be resolved. I find it hard to believe that someone could get a trademark on the single word &#8220;infosec.&#8221; One note here &#8230; when paying Google money for using Adwords I found they offer really easy to find contact info. When I called their automated system almost immediately connected to a nice young lady. I think this shows who their customers really are&#8230; Anyway&#8230;</p>
<p>As expected this first-tier person &#8211; we&#8217;ll call her Alice &#8211; really couldn&#8217;t help me out but recommended that I contact the trademark owner, get permission, and have them submit a special form to Google. So while on the phone I headed over to the USPTO website, loaded up and perused their TESS search engine and there didn&#8217;t appeared to be anything relevant.</p>
<p><a href="http://www.novainfosecportal.com/wp-content/uploads/2012/05/trademarksearch.png"><img class="aligncenter size-medium wp-image-13114" title="Trademark Search Results" src="http://www.novainfosecportal.com/wp-content/uploads/2012/05/trademarksearch-300x70.png" alt="Picture of Trademark Search Results" width="300" height="70" /></a></p>
<p>As you can see above, out of the nine results the search only returned two that were listed as active and they were all phrases &#8230; not just a single term &#8220;infosec.&#8221; I was still on the phone with Alice so I mentioned this discovery. Unfortunately, she just went on with her scripted response saying that I would have to contact the owner of the trademark and have them fill out a &#8220;permission&#8221; form to resolve the situation. I politely noted to Alice that I cannot contact the owner since the trademark doesn&#8217;t exist and inquired if she could tell me who the owner was. Alice noted that she didn&#8217;t have access to this information. Not knowing what to do and it being probably near the end of her shift, Alice said that she&#8217;d be sending me an email with the contact info to go investigate further.</p>
<p>Well, we&#8217;ll see where this goes&#8230;</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Do you think the term &#8220;infosec&#8221; should even be trademarkable? Today&#8217;s post pic is from <a href="http://blog.jumpfly.com/public/item/google-adwords-trademark-policy-changes-hooray-0335" target="_blank">JumpFly.com</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=%E2%80%9CInfosec%E2%80%9D+Trademark+Dampens+Google%E2%80%99s+Adword+Revenue+http%3A%2F%2Fj.mp%2FJLUTyl" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/&amp;t=%E2%80%9CInfosec%E2%80%9D+Trademark+Dampens+Google%E2%80%99s+Adword+Revenue" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/&amp;title=%E2%80%9CInfosec%E2%80%9D+Trademark+Dampens+Google%E2%80%99s+Adword+Revenue" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/XT4rUwznEOY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/21/trademark-of-term-infosec/</feedburner:origLink></item>
		<item>
		<title>Where You Want to Be This Week for 05-21-2012</title>
		<link>http://feedproxy.google.com/~r/novainfosecportalblog/~3/xQEuU3WY0Uc/</link>
		<comments>http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/#comments</comments>
		<pubDate>Mon, 21 May 2012 14:00:56 +0000</pubDate>
		<dc:creator>nathiet</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[meetups]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=13203</guid>
		<description><![CDATA[Where do you want to be this week? Now you&#8217;ll always know with our &#8220;Where You Want to Be This Week&#8221; feature, which will tell you about infosec meetups happening in your local area as of Sunday night. If you would like your event listed in our Calendar and in this post, let us know through our Submit Event form or mention it to @grecs on Twitter. Not much is happening this week in terms of meetups. It is a very light week with only one meetup on Tuesday so be sure to check @grecs&#8217;  weekend best bets as we might have something that you might be interested in. With that said, here are your meetups for this week and as well as a preview for next week&#8230; This Week Tuesday (5/22) ISACA NCA Meetup - “Annual Meeting of the Chapter Membership” at Holiday Inn - Rosslyn at Key Bridge from 7:30 AM to 5:20 PM (more info) Next Week And for those who would like to plan ahead, here is a preview of events on our calendar for next week. Wednesday: CapSecDC Meetup Thursday: CharmSec Meetup Remember that Baltimore Node, HacDC, Reverse Space, and Unallocated Space are four local hacker spaces that also hold several [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Where+You+Want+to+Be+This+Week+for+05-21-2012+http%3A%2F%2Fj.mp%2FLaKjeY" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/&amp;t=Where+You+Want+to+Be+This+Week+for+05-21-2012" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/&amp;title=Where+You+Want+to+Be+This+Week+for+05-21-2012" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><p><img class="alignright size-full wp-image-5356" title="Meetup" src="http://www.novainfosecportal.com/wp-content/uploads/2011/05/meetup-logo-300x220.jpg" alt="Picture of Meetup Tag" width="180" height="132" />Where do you want to be this week? Now you&#8217;ll always know with our &#8220;Where You Want to Be This Week&#8221; feature, which will tell you about infosec meetups happening in <span style="font-style: italic;">your</span> local area as of Sunday night. If you would like your event listed in our <a href="/full-calendar/">Calendar</a> and in this post, let us know through our <a href="/events/submit-event/">Submit Event</a> form or mention it to @<a href="http://twitter.com/grecs" target="_blank">grecs</a> on Twitter.</p>
<p>Not much is happening this week in terms of meetups. It is a very light week with only one meetup on Tuesday so be sure to check @<a href="http://twitter.com/#!/grecs" target="_blank">grecs&#8217;</a>  weekend best bets as we might have something that you might be interested in. With that said, here are your meetups for this week and as well as a preview for next week&#8230;</p>
<h2>This Week</h2>
<p><strong>Tuesday (5/22)</strong></p>
<ul>
<li><a href="/events/nova-meetups/#isaca-nca">ISACA NCA Meetup</a> - “Annual Meeting of the Chapter Membership” at<a id="_GPLITA_1" title="Powered by Text-Enhance" href="http://www.novainfosecportal.com/event/isaca-nca-meetup-8/#"><br />
</a>Holiday Inn - Rosslyn at Key Bridge from 7:30 AM to 5:20 PM (<a href="/event/isaca-nca-meetup-8/">more info</a>)</li>
</ul>
<h2>Next Week</h2>
<p>And for those who would like to plan ahead, here is a preview of events on our <a href="/full-calendar/">calendar</a> for next week.</p>
<ul>
<li>Wednesday: CapSecDC Meetup</li>
<li>Thursday: CharmSec Meetup</li>
</ul>
<p>Remember that <a href="/events/nova-meetups/#bnode">Baltimore Node</a>, <a href="/events/nova-meetups/#hacdc">HacDC</a>, <a href="/events/nova-meetups/#reverse">Reverse Space</a>, and <a href="/events/nova-meetups/#unallocated">Unallocated Space</a> are four local hacker spaces that also hold several standard activities each week &#8230; so check them out for more fun stuff to do.</p>
<p>And be sure to subscribe to our <a href="http://feeds.feedburner.com/novainfosecportalblog" target="_blank">RSS feed</a> or follow us on Twitter at @<a href="http://twitter.com/novainfosec" target="_blank">novainfosec</a> and @<a href="http://twitter.com/grecs" target="_blank">grecs</a> to be alerted about any last-minute events or to receive updates on the meetups listed above. Finally, check out our <a href="/full-calendar/">Calendar</a> for a complete list of infosec events in and around NoVA, DC, and MD.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Where+You+Want+to+Be+This+Week+for+05-21-2012+http%3A%2F%2Fj.mp%2FLaKjeY" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/&amp;t=Where+You+Want+to+Be+This+Week+for+05-21-2012" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://reddit.com/submit?url=http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/&amp;title=Where+You+Want+to+Be+This+Week+for+05-21-2012" title="Post to Reddit"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro4.png" alt="Post to Reddit" /></a></p></div><img src="http://feeds.feedburner.com/~r/novainfosecportalblog/~4/xQEuU3WY0Uc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.novainfosecportal.com/2012/05/21/where-you-want-to-be-this-week-for-05-21-2012/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 2.679 seconds. --><!-- Cached page generated by WP-Super-Cache on 2012-05-27 13:24:46 --><!-- Compression = gzip -->

