<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>SECURITY.EXE</title>
	
	<link>http://www.securityexe.com</link>
	<description />
	<lastBuildDate>Mon, 12 Dec 2011 17:08:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary />
	<itunes:author>SECURITY.EXE</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.securityexe.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle />
	<image>
		<title>SECURITY.EXE</title>
		<url>http://www.securityexe.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securityexe.com</link>
	</image>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/securityexe" /><feedburner:info uri="securityexe" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:thumbnail url="http://www.securityexe.com/wp-content/plugins/powerpress/itunes_default.jpg" /><item>
		<title>Boycott C/Net and Download.Com</title>
		<link>http://feedproxy.google.com/~r/securityexe/~3/vSo6Dk6d_HQ/</link>
		<comments>http://www.securityexe.com/?p=359#comments</comments>
		<pubDate>Mon, 12 Dec 2011 17:07:41 +0000</pubDate>
		<dc:creator>alan</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[Cnet]]></category>
		<category><![CDATA[CNET.com]]></category>
		<category><![CDATA[Download.com]]></category>
		<category><![CDATA[HD Moore]]></category>
		<category><![CDATA[InfoWorld]]></category>
		<category><![CDATA[Nmap]]></category>

		<guid isPermaLink="false">http://www.securityexe.com/?p=359</guid>
		<description><![CDATA[There has been a lot written recently about the despicable practice that C/Net&#8217;s Download.com has adopted of wrapping all of the software downloaded via Download.com in wrappers which install 3rd party toolbars and software. It is even more loathsome to include these 3rd party potential security threats when people are downloading security software. But that is exactly [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://www.securityexe.com/wp-content/uploads/2011/12/cnet.jpg"><img class="alignright size-full wp-image-361" title="cnet" src="http://www.securityexe.com/wp-content/uploads/2011/12/cnet.jpg" alt="" width="225" height="225" /></a>There has been a lot written recently about the despicable practice that C/Net&#8217;s <a class="zem_slink" title="Download.com" href="http://download.cnet.com/" rel="homepage">Download.com</a> has adopted of wrapping all of the software downloaded via Download.com in wrappers which install 3rd party toolbars and software. It is even more loathsome to include these 3rd party potential security threats when people are downloading security software. But that is exactly what is happening at Download.com.</p>
<p>Many in the security industry have raised the alarms about this practice. Everyone from <a class="zem_slink" title="HD Moore" href="http://digitaloffense.net/" rel="homepage">HD Moore</a> of <a class="zem_slink" title="Metasploit Project" href="http://www.metasploit.com/" rel="homepage">Metasploit</a> to Fyodor of <a class="zem_slink" title="Nmap" href="http://nmap.org/" rel="homepage">NMap</a> and more. <a href="http://www.infoworld.com/t/anti-spyware/security-pros-slam-cnet-downloadcoms-bundling-181392">InfoWorld</a> and other main stream media outlets have blown the whistle as well.</p>
<p>It has certainly come to the attention of C/Net and they have responded:</p>
<blockquote><p>&#8220;On Wednesday, <a class="zem_slink" title="CNET.com" href="http://www.cnet.com/" rel="homepage">Cnet</a> issued a statement saying it had mistakenly made NMap &#8212; and other open-source software &#8212; part of its program, but planned to continue the bundling of third-party software, with some changes.</p>
<p>&#8220;All third-party offers are clearly identified as such, and there is no requirement for the user to download and install the offer; rather, a user has the option to Accept or Decline,&#8221; Sean Murphy, CBS Interactive&#8217;s vice president and general manager</p></blockquote>
<p>So it was one thing to not know you are making a mistake, it is quite another to know what you are doing is wrong and still do it. If this is going to be the position of C/Net the position of the tech community should be clear. Stop going to C/Net, stop downloading anything from Download.com and if you are a developer don&#8217;t give them permission to list your software.</p>
<p>Until this wrapping of 3rd party software stops, boycott Cnet and Download.com!</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/06/cnet_nmap_toolbar_wrapping_row/">Cnet slammed for wrapping Nmap downloads with cruddy toolbar</a> (go.theregister.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/t/anti-spyware/security-pros-slam-cnet-downloadcoms-bundling-181392&amp;a=66075269&amp;rid=42b9dfff-f660-481b-93ee-ed0783a24454&amp;e=7cf6d01cc752008d956f6d8115a41871">Security pros slam Cnet Download.com&#8217;s bundling</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/12/09/download_nmap_toolbar_row_latest/">Download.com sorry for bundling Nmap with crapware</a> (go.theregister.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.geek.com/articles/geek-pick/nmap-warns-download-com-bundles-malware-with-its-software-2011126/">Nmap warns Download.com bundles malware with its software</a> (geek.com)</li>
<li class="zemanta-article-ul-li"><a href="http://krebsonsecurity.com/2011/12/download-com-bundling-toolbars-trojans/">Download.com Bundling Toolbars, Trojans?</a> (krebsonsecurity.com)</li>
<li class="zemanta-article-ul-li"><a href="https://www.eff.org/deeplinks/2011/12/downloadcom-debacle-what-cnet-needs-do-make-it-right">The Download.com Debacle: What CNET Needs to Do to Make it Right</a> (eff.org)</li>
<li class="zemanta-article-ul-li"><a href="http://download.cnet.com/8301-2007_4-57338809-12/a-note-from-sean-regarding-the-download.com-installer/">A note from Sean regarding the Download.com Installer</a> (download.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://seclists.org/nmap-hackers/2011/5">CNet&#8217;s Download.com now bundling Nmap with malware</a> (seclists.org)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=42b9dfff-f660-481b-93ee-ed0783a24454" alt="Enhanced by Zemanta" /></a></div>
<img src="http://feeds.feedburner.com/~r/securityexe/~4/vSo6Dk6d_HQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.securityexe.com/?feed=rss2&amp;p=359</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.securityexe.com/?p=359</feedburner:origLink></item>
		<item>
		<title>Will CISOs Become CISTOs and CSOs?</title>
		<link>http://feedproxy.google.com/~r/securityexe/~3/jj4k9gMtjG4/</link>
		<comments>http://www.securityexe.com/?p=265#comments</comments>
		<pubDate>Fri, 09 Dec 2011 16:50:23 +0000</pubDate>
		<dc:creator>alan</dc:creator>
				<category><![CDATA[CISO on demand]]></category>
		<category><![CDATA[The CISO Group]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Chief information security officer]]></category>
		<category><![CDATA[Chief security officer]]></category>
		<category><![CDATA[ciso]]></category>
		<category><![CDATA[Consultants]]></category>
		<category><![CDATA[General and Freelance]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Network World]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.securityexe.com/?p=265</guid>
		<description><![CDATA[John Oltsik over on Network World had a good article this week about the changing roles of CISOs.  Reading it I realized he was dead on.  The role of CISO in many organizations is an impossible job.  Those of you in the role probably already know this. The problem is that to perform the CISO [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://www.networkworld.com/community/node/79350">John Oltsik over on Network World </a>had a good article this week about the changing roles of CISOs.  Reading it I realized he was dead on.  The role of CISO in many organizations is an impossible job.  Those of you in the role probably already know this.</p>
<p>The problem is that to perform the CISO role you need a rare combination of skills.  You need the technical chops of a CTO or at the least a seasoned security admin, along with the business sense and feel of a senior level executive/manager.  It is truly a rare individual who has both of these skill sets. Generally, a CISO is stronger in one or the other of these.</p>
<p>As Jon points out though, the job is getting harder, the challengers greater and the risks and rewards higher and more substantial.  Jon&#8217;s solution is that he sees this role breaking into two roles.  One is the CSO who handles the business end of things. He would deal with regulators, the business issues and that kind of thing.</p>
<p>He then sees another role he calls the Chief Information Security Technology Officer.  This is more akin to a CTO, except purely focused on security. He would be the uber-geek security guy who is hip deep in security technology.</p>
<p>Hey that sounds great. Who is not for more attention and resources being given to security?  The problem is that so many companies are just now starting to realize the importance of CISO. It has been a hard battle, asking the organization to now add yet another body to the mix may be more than many are willing to pay.</p>
<p>It seems in security we have to take our victories in small steps.   I don&#8217;t think that 2012 will be the year we move past CISOs.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.btsecurethinking.com/2011/09/what-does-the-future-hold-for-cisos/">What Does the Future Hold for CISOs?</a> (btsecurethinking.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.securosis.com/blog/need-a-ciso-cert-have-200-get-it-while-its-hot">Need a CISO Cert? Have $200? Get it while it&#8217;s hot&#8230;</a> (securosis.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.lumension.com/?p=3842">The New CSO: Cyber Security Officer</a> (lumension.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/241705/security_on_a_shoestring_budget.html">Security on a Shoestring Budget</a> (pcworld.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=e4c11224-90ca-4c0b-aabe-5fdd105f21ca" alt="Enhanced by Zemanta" /></a></div>
<img src="http://feeds.feedburner.com/~r/securityexe/~4/jj4k9gMtjG4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.securityexe.com/?feed=rss2&amp;p=265</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.securityexe.com/?p=265</feedburner:origLink></item>
	<media:credit role="author">SECURITY.EXE</media:credit><media:rating>nonadult</media:rating><media:description type="plain"></media:description></channel>
</rss>
