<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Silver Bullet Security Podcast with Gary McGraw</title>
	
	<link>http://www.cigital.com/silverbullet</link>
	<description>Cigital CTO Gary McGraw discusses software security with security gurus.</description>
	<lastBuildDate>Sat, 18 May 2013 06:48:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<copyright>Copyright (c)2011 Cigital.</copyright>
	<managingEditor>webmaster@cigital.com (Cigital)</managingEditor>
	<webMaster>webmaster@cigital.com (Cigital)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://www.cigital.com/images/silver_bullet_itunes-144x144.png</url>
		<title>Cigital</title>
		<link>http://www.cigital.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle>Co-sponsored by Cigital and IEEE Security &amp; Privacy.</itunes:subtitle>
	<itunes:summary>Co-sponsored by Cigital and IEEE Security &amp; Privacy.</itunes:summary>
	<itunes:keywords>software,security</itunes:keywords>
	
	<itunes:author>Gary McGraw</itunes:author>
	
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.cigital.com/wp-content/themes/cigital_main/img/silver_bullet_promo.png" />
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/silverbulletsecurity" /><feedburner:info uri="silverbulletsecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>Copyright (c)2011 Cigital.</media:copyright><media:thumbnail url="http://www.cigital.com/wp-content/themes/cigital_main/img/silver_bullet_promo.png" /><media:keywords>software,security</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><itunes:owner><itunes:email>webmaster@cigital.com</itunes:email><itunes:name>Gary McGraw</itunes:name></itunes:owner><itunes:category text="Technology" /><item>
		<title>Show 085 – A Discussion with Jim Routh and Scott Matsumoto</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/sR96G4HWtjg/</link>
		<comments>http://www.cigital.com/silver-bullet/show-085/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 16:00:29 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3995</guid>
		<description><![CDATA[The 85th episode of the Silver Bullet Security Podcast is a double whammy. Gary talks mobile security with two guests &#8212;Jim Routh, former global head of application security at JP Morgan Chase (and newly-appointed CSO), and Scott Matusmoto, Principal Consultant and head of the mobile security practice at Cigital. All three discuss the challenges of [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="Jim Routh and Scott Matsumoto" alt="Jim Routh and Scott Matsumoto" src="http://www.cigital.com/wp-content/uploads/2013/05/jrouth-smatsumoto.png" align="right" /></p>
<p>The 85th episode of the Silver Bullet Security Podcast is a double whammy. Gary talks mobile security with two guests  &#8212;Jim Routh, former global head of application security at JP Morgan Chase (and newly-appointed CSO), and Scott Matusmoto, Principal Consultant and head of the mobile security practice at Cigital. All three discuss the challenges of mobile security and how these challenges are exactly the same as and utterly different than software security concerns from across the years. They discuss use of new technologies including accelerometers in enhancing security (or compromising privacy), and the effect that massive phone rooting has on security.  Is mobile security the same old same old or a brand new day? Listen to this podcast and find out for yourself.</p>
<ul>
<li><a href="http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html">Trusted Computing and Computational Liberty</a></li>
<li><a href="http://www.cigital.com/justice-league-blog/2013/04/30/mobile-different-or-same-sht-different-day/">John Steven on Mobile Security</a></li>
<li><a href="http://www.securingjava.com/"><em>Securing Java</em> (dancing pigs and native code risk)</a></li>
<li><a href="http://www.exploitingonlinegames.com/"><em>Exploiting Online Games</em></a></li>
<li><a href="http://searchsecurity.techtarget.com/opinion/McGraws-mobile-app-security-strategy-Three-legs-of-trusted-on-busted">Trusted on Busted</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/sR96G4HWtjg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-085/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3995/0/silverbullet-085.mp3" length="52052096" type="audio/mpeg" />
		<itunes:duration>0:36:01</itunes:duration>
		<itunes:subtitle>
The 85th episode of the Silver Bullet Security Podcast is a double whammy. Gary talks mobile security with two guests  —Jim Routh, former global head of application security at JP Morgan Chase (and newly-appointed CSO), and Scott Matusmoto, P[...]</itunes:subtitle>
		<itunes:summary>
The 85th episode of the Silver Bullet Security Podcast is a double whammy. Gary talks mobile security with two guests  —Jim Routh, former global head of application security at JP Morgan Chase (and newly-appointed CSO), and Scott Matusmoto, Principal Consultant and head of the mobile security practice at Cigital. All three discuss the challenges of mobile security and how these challenges are exactly the same as and utterly different than software security concerns from across the years. They discuss use of new technologies including accelerometers in enhancing security (or compromising privacy), and the effect that massive phone rooting has on security.  Is mobile security the same old same old or a brand new day? Listen to this podcast and find out for yourself.

Trusted Computing and Computational Liberty
John Steven on Mobile Security
Securing Java (dancing pigs and native code risk)
Exploiting Online Games
Trusted on Busted
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3995/0/silverbullet-085.mp3" fileSize="52052096" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-085/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-085</feedburner:origLink></item>
		<item>
		<title>Show 084 – An Interview with Hord Tipton</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/1b6rVXDC61A/</link>
		<comments>http://www.cigital.com/silver-bullet/show-084/#comments</comments>
		<pubDate>Mon, 01 Apr 2013 00:00:58 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3860</guid>
		<description><![CDATA[On the 84th episode of the Silver Bullet Security Podcast, Gary chats with W. Hord Tipton, Executive Director of (ISC)2. Gary and Hord discuss how one gets into science and engineering when growing up in rural Tennessee, what insight being nuclear and chemical engineer gives Hord about modern control systems, whether or not certification can [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="Mark Graff" alt="Mark Graff" src="http://www.cigital.com/wp-content/uploads/2013/03/whtipton-125.png" align="right" /></p>
<p>On the 84th episode of the Silver Bullet Security Podcast, Gary chats with W. Hord Tipton, Executive Director of (ISC)<sup>2</sup>. Gary and Hord discuss how one gets into science and engineering when growing up in rural Tennessee, what insight being nuclear and chemical engineer gives Hord about modern control systems, whether or not certification can help advance software security, and the benefits of teaching software security to kids.</p>
<ul>
<li><a href="https://www.isc2.org/">(ISC)<sup>2</sup></a></li>
<li><a href="https://www.isc2.org/management-team.aspx">(ISC)</sup>2</sup> management team</a></li>
<li><a href="http://www.amazon.com/World-Flat-3-0-History-Twenty-first/dp/0312425074/"><em>The World Is Flat 3.0: A Brief History of the Twenty-first Century</em> by Thomas L. Friedman</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/1b6rVXDC61A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-084/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3860/0/silverbullet-084.mp3" length="54077568" type="audio/mpeg" />
		<itunes:duration>0:37:25</itunes:duration>
		<itunes:subtitle>
On the 84th episode of the Silver Bullet Security Podcast, Gary chats with W. Hord Tipton, Executive Director of (ISC)2. Gary and Hord discuss how one gets into science and engineering when growing up in rural Tennessee, what insight being nuclear [...]</itunes:subtitle>
		<itunes:summary>
On the 84th episode of the Silver Bullet Security Podcast, Gary chats with W. Hord Tipton, Executive Director of (ISC)2. Gary and Hord discuss how one gets into science and engineering when growing up in rural Tennessee, what insight being nuclear and chemical engineer gives Hord about modern control systems, whether or not certification can help advance software security, and the benefits of teaching software security to kids.

(ISC)2
(ISC)2 management team
The World Is Flat 3.0: A Brief History of the Twenty-first Century by Thomas L. Friedman
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3860/0/silverbullet-084.mp3" fileSize="54077568" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-084/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-084</feedburner:origLink></item>
		<item>
		<title>Show 083 – An Interview with Mark Graff</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/ITmaYPAUPxY/</link>
		<comments>http://www.cigital.com/silver-bullet/show-083/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 19:02:51 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3758</guid>
		<description><![CDATA[On the 83rd episode of the Silver Bullet Security Podcast, Gary talks with Mark Graff, CISO at NASDAQ OMX. Gary and Mark discuss what exactly a CISO does all day, how corporate security posture at NASDAQ compares to the security posture at Lawrence Livermore National Laboratory, Enrico Fermi and the piano tuners (the &#8220;Fermi problem&#8221;) [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px" title="Mark Graff" src="http://www.cigital.com/wp-content/uploads/2013/02/mgraff-125.png" alt="Mark Graff" align="right" /></p>
<p>On the 83rd episode of the Silver Bullet Security Podcast, Gary talks with Mark Graff, CISO at NASDAQ OMX. Gary and Mark discuss what exactly a CISO does all day, how corporate security posture at NASDAQ compares to the security posture at Lawrence Livermore National Laboratory, Enrico Fermi and the piano tuners (the &#8220;Fermi problem&#8221;) and how it relates to estimation, and the most surprising cultural difference between the left and right coasts. They close out their conversation with talk about Mark&#8217;s favorite poem from the mid-19th century (and yet it still has a software security connection!).</p>
<ul>
<li><a href="http://www.nasdaqomx.com/">NASDAQ OMX</a></li>
<li><a href="https://www.llnl.gov/">Lawrence Livermore National Laboratory</a></li>
<li><a href="http://www.nasdaqomx.com/digitalAssets/83/83581_testimonyfsccybersecurity06012012.pdf">Congressional testimopny</a> (<a href="http://www.c-spanvideo.org/markgraff">video</a>)</li>
<li><a href="http://www.amazon.com/Secure-Coding-Principles-Mark-Graff/dp/0596002424"><em>Secure Coding: Principles and Practices</em></a></li>
<li><a href="http://bsimm.com">BSIMM</a></li>
<li><a href="http://www.youtube.com/watch?v=m8OXdEC0kpo">Video from LLNL</a></li>
<li><a href="http://en.wikipedia.org/wiki/Fermi_problem">Fermi problem</a></li>
<li><a href="http://www.cigital.com/justice-league-blog/2013/02/14/active-defense-is-irresponsible/">Cyber War and Active Defense</a></li>
<li><a href="http://www.eecs.harvard.edu/~keith/poems/dover.html">Dover Beach</a> (poem)</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/ITmaYPAUPxY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-083/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3758/0/silverbullet-083.mp3" length="53530752" type="audio/mpeg" />
		<itunes:duration>0:37:02</itunes:duration>
		<itunes:subtitle>
On the 83rd episode of the Silver Bullet Security Podcast, Gary talks with Mark Graff, CISO at NASDAQ OMX. Gary and Mark discuss what exactly a CISO does all day, how corporate security posture at NASDAQ compares to the security posture at Lawrence[...]</itunes:subtitle>
		<itunes:summary>
On the 83rd episode of the Silver Bullet Security Podcast, Gary talks with Mark Graff, CISO at NASDAQ OMX. Gary and Mark discuss what exactly a CISO does all day, how corporate security posture at NASDAQ compares to the security posture at Lawrence Livermore National Laboratory, Enrico Fermi and the piano tuners (the “Fermi problem”) and how it relates to estimation, and the most surprising cultural difference between the left and right coasts. They close out their conversation with talk about Mark’s favorite poem from the mid-19th century (and yet it still has a software security connection!).

NASDAQ OMX
Lawrence Livermore National Laboratory
Congressional testimopny (video)
Secure Coding: Principles and Practices
BSIMM
Video from LLNL
Fermi problem
Cyber War and Active Defense
Dover Beach (poem)
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3758/0/silverbullet-083.mp3" fileSize="53530752" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-083/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-083</feedburner:origLink></item>
		<item>
		<title>Show 082 – An Interview with Kevin Fu</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Ck6ykgZ77K4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-082/#comments</comments>
		<pubDate>Fri, 18 Jan 2013 20:40:06 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3657</guid>
		<description><![CDATA[On the 82nd episode of the Silver Bullet Security Podcast, Gary talks with Kevin Fu, Associate Professor in the EECS Department at the University of Michigan. Gary and Kevin discuss finding advisors and picking a grad school, the security implications of embedded medical devices, malware in hospital systems, the consumer trend toward analyzing one&#8217;s own [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px" title="Kevin Fu" src="http://www.cigital.com/wp-content/uploads/2013/01/kfu-125.png" alt="Kevin Fu" align="right" /></p>
<p>On the 82nd episode of the Silver Bullet Security Podcast, Gary talks with Kevin Fu, Associate Professor in the EECS Department at the University of Michigan. Gary and Kevin discuss finding advisors and picking a grad school, the security implications of embedded medical devices, malware in hospital systems, the consumer trend toward analyzing one&#8217;s own health data, and the difficulty of teaching design analysis to other humans. They close out the episode discussing lobster bisque.</p>
<ul>
<li><a href="http://www.eecs.umich.edu/eecs/about/articles/2012/new_CSE_faculty.html">Kevin Fu and Grant Schoenebeck Join the Faculty of CSE @ Michigan</a></li>
<li><a href="http://www.beyster.com/blog/?p=303">The Bob and Betty Beyster Bubbler</a></li>
<li><a href="http://blog.secure-medicine.org/">Medical Device Security Center blog</a></li>
<li><a href="http://www.washingtonpost.com/investigations/health-care-sector-vulnerable-to-hackers-researchers-say/2012/12/25/72933598-3e50-11e2-ae43-cf491b837f7b_story.html">Health-care sector vulnerable to hackers, researchers say</a>, <em>Washington Post</em>.</li>
<li><a href="http://blog.secure-medicine.org/2012/11/false-part-2-fda-does-not-allow.html">FDA Software Patch Poster</a></li>
<li><a href="http://www.thedoctorweighsin.com/hugo-campos-fights-to-get-his-defibrillator-data/">Hugo Campos fights to get his defibrillator data</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Ck6ykgZ77K4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-082/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3657/0/silverbullet-082.mp3" length="39346176" type="audio/mpeg" />
		<itunes:duration>0:27:11</itunes:duration>
		<itunes:subtitle>
On the 82nd episode of the Silver Bullet Security Podcast, Gary talks with Kevin Fu, Associate Professor in the EECS Department at the University of Michigan. Gary and Kevin discuss finding advisors and picking a grad school, the security implicati[...]</itunes:subtitle>
		<itunes:summary>
On the 82nd episode of the Silver Bullet Security Podcast, Gary talks with Kevin Fu, Associate Professor in the EECS Department at the University of Michigan. Gary and Kevin discuss finding advisors and picking a grad school, the security implications of embedded medical devices, malware in hospital systems, the consumer trend toward analyzing one’s own health data, and the difficulty of teaching design analysis to other humans. They close out the episode discussing lobster bisque.

Kevin Fu and Grant Schoenebeck Join the Faculty of CSE @ Michigan
The Bob and Betty Beyster Bubbler
Medical Device Security Center blog
Health-care sector vulnerable to hackers, researchers say, Washington Post.
FDA Software Patch Poster
Hugo Campos fights to get his defibrillator data
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3657/0/silverbullet-082.mp3" fileSize="39346176" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-082/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-082</feedburner:origLink></item>
		<item>
		<title>Show 081 – An Interview with Steve Bellovin</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/bHDfLRLSbTg/</link>
		<comments>http://www.cigital.com/silver-bullet/show-081/#comments</comments>
		<pubDate>Wed, 26 Dec 2012 13:01:48 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3596</guid>
		<description><![CDATA[On the 81st episode of the Silver Bullet Security Podcast, Gary talks with Steve Bellovin, Professor of Computer Science at Columbia University, currently on leave and acting as CTO of the Federal Trade Commission. Gary and Steve discuss how often academic research finds its way into the real world versus research that&#8217;s done in a [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px" title="Steve Bellovin" src="http://www.cigital.com/wp-content/uploads/2012/12/sbellovin-125.png" alt="Steve Bellovin" align="right" /></p>
<p>On the 81st episode of the Silver Bullet Security Podcast, Gary talks with Steve Bellovin, Professor of Computer Science at Columbia University, currently on leave and acting as CTO of the Federal Trade Commission. Gary and Steve discuss how often academic research finds its way into the real world versus research that&#8217;s done in a commercial lab, how code has gotten better overall but how the threat model has changed, whether mobile security is just a repackaging of the same security problem we&#8217;ve been dealing with for years, the state of computer security in the government, the very first days of Usenet and the famed Evil Bit.</p>
<ul>
<li><a href="https://www.cs.columbia.edu/~smb/">Steven M. Bellovin</a></li>
<li><a href="http://www.wilyhacker.com/"><em>Firewalls and Internet Security: Repelling the Wily Hacker</em></a> by William R. Cheswick, Steven M. Bellovin, and Aviel D. Rubin</li>
<li><a href="http://en.wikipedia.org/wiki/Encrypted_key_exchange">Encrypted Key Exchange</a></li>
<li><a href="http://www.cigital.com/papers/download/09-11_Software0511.pdf">Technology Transfer: A Software Security Marketplace Case Study</a> (IEEE  Software, September/October 2011) [PDF]</li>
<li><a href="http://noplasticshowers.com/2012/12/09/tsa-pre-does-not-suck/">TSA Pre</a></li>
<li><a href="http://www.ftc.gov/opa/2010/06/twitter.shtm">Twitter and the FTC</a></li>
<li><a href="http://en.wikipedia.org/wiki/Usenet">Usenet</a></li>
<li><a href="http://www.nndev.org/">nn</a></li>
<li><a href="http://www.ietf.org/rfc/rfc3514.txt">The Evil Bit RFC</a></li>
<li><a href="https://www.cs.columbia.edu/~smb/nsam-160/pal.html">Permissive Action Link</a></li>
<li><a href="https://www.cs.columbia.edu/~smb/frrm.html">Steve drives a train</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/bHDfLRLSbTg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-081/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3596/0/silverbullet-081.mp3" length="48620658" type="audio/mpeg" />
		<itunes:duration>0:33:45</itunes:duration>
		<itunes:subtitle>
On the 81st episode of the Silver Bullet Security Podcast, Gary talks with Steve Bellovin, Professor of Computer Science at Columbia University, currently on leave and acting as CTO of the Federal Trade Commission. Gary and Steve discuss how often [...]</itunes:subtitle>
		<itunes:summary>
On the 81st episode of the Silver Bullet Security Podcast, Gary talks with Steve Bellovin, Professor of Computer Science at Columbia University, currently on leave and acting as CTO of the Federal Trade Commission. Gary and Steve discuss how often academic research finds its way into the real world versus research that’s done in a commercial lab, how code has gotten better overall but how the threat model has changed, whether mobile security is just a repackaging of the same security problem we’ve been dealing with for years, the state of computer security in the government, the very first days of Usenet and the famed Evil Bit.

Steven M. Bellovin
Firewalls and Internet Security: Repelling the Wily Hacker by William R. Cheswick, Steven M. Bellovin, and Aviel D. Rubin
Encrypted Key Exchange
Technology Transfer: A Software Security Marketplace Case Study (IEEE  Software, September/October 2011) [PDF]
TSA Pre
Twitter and the FTC
Usenet
nn
The Evil Bit RFC
Permissive Action Link
Steve drives a train
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3596/0/silverbullet-081.mp3" fileSize="48620658" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-081/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-081</feedburner:origLink></item>
		<item>
		<title>Show 080 – An Interview with Thomas Rid</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/hWKpmfm-RaY/</link>
		<comments>http://www.cigital.com/silver-bullet/show-080/#comments</comments>
		<pubDate>Fri, 30 Nov 2012 17:16:55 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3505</guid>
		<description><![CDATA[On the 80th episode of the Silver Bullet Security Podcast, Gary talks with Thomas Rid, Reader in War Studies at King&#8217;s College London and a non-resident fellow at the Center for Transatlantic Relations in the School for Advanced International Studies, Johns Hopkins University, in Washington, DC. In this episode, Gary and Thomas discuss how Thomas&#8217; [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="Thomas Rid" src="http://www.cigital.com/wp-content/uploads/2012/11/trid-125.png" alt="Thomas Rid" align="right" /></p>
<p>On the 80th episode of the Silver Bullet Security Podcast, Gary talks with Thomas Rid, Reader in War Studies at King&#8217;s College London and a non-resident fellow at the Center for Transatlantic Relations in the School for Advanced International Studies, Johns Hopkins University, in Washington, DC. In this episode, Gary and Thomas discuss how Thomas&#8217; life as a &#8220;wandering academic&#8221; influences his work at the War Studies Department, the inevitably (or otherwise) of cyber-war, attribution, and military dictionaries and the problem of jargon. They close out their chat talking about the Barbican cultural center.</p>
<ul>
<li><a href="http://thomasrid.org/">Thomas Rid</a></li>
<li><a href="http://www.amazon.co.uk/Cyber-War-Will-Take-Place/dp/1849042802/ref=sr_1_9?s=books&#038;ie=UTF8&#038;qid=1349845034&#038;sr=1-9"><em>Cyber War Will Not Take Place</em></a></li>
<li><a href="http://searchsecurity.techtarget.com/news/2240169976/Gary-McGraw-Proactive-defense-prudent-alternative-to-cyberwarfare">Proactive defense prudent alternative to cyberwarfare</a>, SearchSecurity.com.</li>
<li><a href="http://www.barbican.org.uk/">Barbican</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/hWKpmfm-RaY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-080/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3505/0/silverbullet-080.mp3" length="46467200" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>
On the 80th episode of the Silver Bullet Security Podcast, Gary talks with Thomas Rid, Reader in War Studies at King’s College London and a non-resident fellow at the Center for Transatlantic Relations in the School for Advanced International[...]</itunes:subtitle>
		<itunes:summary>
On the 80th episode of the Silver Bullet Security Podcast, Gary talks with Thomas Rid, Reader in War Studies at King’s College London and a non-resident fellow at the Center for Transatlantic Relations in the School for Advanced International Studies, Johns Hopkins University, in Washington, DC. In this episode, Gary and Thomas discuss how Thomas’ life as a “wandering academic” influences his work at the War Studies Department, the inevitably (or otherwise) of cyber-war, attribution, and military dictionaries and the problem of jargon. They close out their chat talking about the Barbican cultural center.

Thomas Rid
Cyber War Will Not Take Place
Proactive defense prudent alternative to cyberwarfare, SearchSecurity.com.
Barbican
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3505/0/silverbullet-080.mp3" fileSize="46467200" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-080/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-080</feedburner:origLink></item>
		<item>
		<title>Show 079 – An Interview with Per-Olof Persson</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/gZDqf5xGGpM/</link>
		<comments>http://www.cigital.com/silver-bullet/show-079/#comments</comments>
		<pubDate>Wed, 24 Oct 2012 20:42:48 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3428</guid>
		<description><![CDATA[On the 79th episode of the Silver Bullet Security Podcast, Gary talks with Per-Olof Persson (a.k.a. Peo), head of Global Software Security Operations at Sony Mobile and Board member of Sony Corporation. Gary and Per-Olof discuss the importance of working different positions within the same company, Sony Mobile&#8217;s software security initiative, the political concerns of [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="Per-Olof Persson" src="http://www.cigital.com/wp-content/uploads/2012/10/ppersson-125.png" alt="Per-Olof Persson" align="right" /></p>
<p>On the 79th episode of the Silver Bullet Security Podcast, Gary talks with Per-Olof Persson (a.k.a. Peo), head of Global Software Security Operations at Sony Mobile and Board member of Sony Corporation. Gary and Per-Olof discuss the importance of working different positions within the same company, Sony Mobile&#8217;s software security initiative, the political concerns of software security, and the cultural challenges of working with international teams. They close out the show with a discussion of American Presidential politics.</p>
<ul>
<li><a href="/silverbullet-files/shows/silverbullet-079-ppersson.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://se.linkedin.com/pub/per-olof-persson/0/974/63">Per-Olof on LinkedIn</a></li>
<li><a href="http://www.sonymobile.com/us/">Sony Mobile</a></li>
<li><a href="http://bsimm.com/">BSIMM4</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/gZDqf5xGGpM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-079/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3428/0/silverbullet-079.mp3" length="40615237" type="audio/mpeg" />
		<itunes:duration>0:27:59</itunes:duration>
		<itunes:subtitle>
On the 79th episode of the Silver Bullet Security Podcast, Gary talks with Per-Olof Persson (a.k.a. Peo), head of Global Software Security Operations at Sony Mobile and Board member of Sony Corporation. Gary and Per-Olof discuss the importance of w[...]</itunes:subtitle>
		<itunes:summary>
On the 79th episode of the Silver Bullet Security Podcast, Gary talks with Per-Olof Persson (a.k.a. Peo), head of Global Software Security Operations at Sony Mobile and Board member of Sony Corporation. Gary and Per-Olof discuss the importance of working different positions within the same company, Sony Mobile’s software security initiative, the political concerns of software security, and the cultural challenges of working with international teams. They close out the show with a discussion of American Presidential politics.

Transcript of this episode [PDF]
Per-Olof on LinkedIn
Sony Mobile
BSIMM4
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3428/0/silverbullet-079.mp3" fileSize="40615237" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-079/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-079</feedburner:origLink></item>
		<item>
		<title>Show 078 – An Interview with Jacob West</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/o46x8Ud_Fiw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-078/#comments</comments>
		<pubDate>Sun, 30 Sep 2012 20:12:38 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3341</guid>
		<description><![CDATA[On the 78th episode of the Silver Bullet Security Podcast, Gary talks with Jacob West, Director, Software Security Research for the Enterprise Security Products division of Hewlett-Packard and newly minted CTO. Gary and Jacob discuss HP&#8217;s acquisition of Fortify, the technical trade-offs that have to be made to allow a tool become widely adopted, BSIMM4, [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="Jacob West" src="http://www.cigital.com/wp-content/uploads/2012/09/jwest-125.png" alt="Jacob West" align="right" /></p>
<p>On the 78th episode of the Silver Bullet Security Podcast, Gary talks with Jacob West, Director, Software Security Research for the Enterprise Security Products division of Hewlett-Packard and newly minted CTO. Gary and Jacob discuss HP&#8217;s acquisition of Fortify, the technical trade-offs that have to be made to allow a tool become widely adopted, BSIMM4, and mobile security. They close out their discussion covering the impossibility of growing good tomatoes in San Francisco.</p>
<ul>
<li><a href="http://bsimm.com/">BSIMM4</a></li>
<li><a href="http://www.forbes.com/sites/andygreenberg/2010/08/18/hps-fortify-buyout-numbers-tell-lucrative-story-for-software-security/">Fortify acquired by HP</a></li>
<li><a href="http://www.cs.berkeley.edu/~daw/mops/">MOPS</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1562220">On using data to drive a scientific model &#8211; Cargo Cult Computer Security</a> (January 28, 2010)</li>
<li><a href="http://bsimm.com/community/">BSIMM Community</a></li>
<li><a href=""http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=pd_bbs_sr_1/104-2577668-4903944?ie=UTF8&#038;s=books&#038;qid=1181852272&#038;sr=8-1">Secure Programming with Static Analysis</a></li>
<li><a href="http://en.wikipedia.org/wiki/Dancing_pigs">Dancing Pigs and Security</a></li>
<li><a href="http://noplasticshowers.com/2012/06/04/dining-out-in-greater-nova/">Jacob and gem&#8217;s foodie adventures</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/o46x8Ud_Fiw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-078/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3341/0/silverbullet-078.mp3" length="44786922" type="audio/mpeg" />
		<itunes:duration>0:30:58</itunes:duration>
		<itunes:subtitle>
On the 78th episode of the Silver Bullet Security Podcast, Gary talks with Jacob West, Director, Software Security Research for the Enterprise Security Products division of Hewlett-Packard and newly minted CTO. Gary and Jacob discuss HP’s acq[...]</itunes:subtitle>
		<itunes:summary>
On the 78th episode of the Silver Bullet Security Podcast, Gary talks with Jacob West, Director, Software Security Research for the Enterprise Security Products division of Hewlett-Packard and newly minted CTO. Gary and Jacob discuss HP’s acquisition of Fortify, the technical trade-offs that have to be made to allow a tool become widely adopted, BSIMM4, and mobile security. They close out their discussion covering the impossibility of growing good tomatoes in San Francisco.

BSIMM4
Fortify acquired by HP
MOPS
On using data to drive a scientific model – Cargo Cult Computer Security (January 28, 2010)
BSIMM Community
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3341/0/silverbullet-078.mp3" fileSize="44786922" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-078/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-078</feedburner:origLink></item>
		<item>
		<title>Show 077 – An Interview with Gary Warzala</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/w5Mw64dKaG8/</link>
		<comments>http://www.cigital.com/silver-bullet/show-077/#comments</comments>
		<pubDate>Tue, 28 Aug 2012 17:05:40 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3252</guid>
		<description><![CDATA[On the 77th episode of the Silver Bullet Security Podcast, Gary talks with Gary Warzala, CISO of Visa International. The Garys discuss what a CISO&#8217;s day-to-day job looks like, how companies can attract and retain good security employees, whether consumers need to understand the difference between software security and security software, and how one can [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="David Evans" src="http://www.cigital.com/wp-content/uploads/2012/08/gwarzala.png" alt="Gary Warzala" align="right" /></p>
<p>On the 77th episode of the Silver Bullet Security Podcast, Gary talks with Gary Warzala, CISO of Visa International. The Garys discuss what a CISO&#8217;s day-to-day job looks like, how companies can attract and retain good security employees, whether consumers need to understand the difference between software security and security software, and how one can measure security and discuss the results with upper management.</p>
<ul>
<li><a href="http://searchsecurity.techtarget.com/opinion/Congress-should-encourage-bug-fixes-reward-secure-systems">Congress should encourage bug fixes, reward secure systems</a></li>
<li><a href="http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf">Verizon 2012 Data Breach Investigations Report</a> [PDF]</li>
<li><a href="http://www.amazon.com/The-Debt-Bomb-Washington-Bankrupting/dp/159555467X"><em>The Debt Bomb</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/w5Mw64dKaG8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-077/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3252/0/silverbullet-077.mp3" length="36085888" type="audio/mpeg" />
		<itunes:duration>0:24:55</itunes:duration>
		<itunes:subtitle>
On the 77th episode of the Silver Bullet Security Podcast, Gary talks with Gary Warzala, CISO of Visa International. The Garys discuss what a CISO’s day-to-day job looks like, how companies can attract and retain good security employees, whet[...]</itunes:subtitle>
		<itunes:summary>
On the 77th episode of the Silver Bullet Security Podcast, Gary talks with Gary Warzala, CISO of Visa International. The Garys discuss what a CISO’s day-to-day job looks like, how companies can attract and retain good security employees, whether consumers need to understand the difference between software security and security software, and how one can measure security and discuss the results with upper management.

Congress should encourage bug fixes, reward secure systems
Verizon 2012 Data Breach Investigations Report [PDF]
The Debt Bomb
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3252/0/silverbullet-077.mp3" fileSize="36085888" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-077/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-077</feedburner:origLink></item>
		<item>
		<title>Show 076 – An Interview with David Evans</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/wuXSGQoESZ4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-076/#comments</comments>
		<pubDate>Fri, 27 Jul 2012 18:10:03 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3198</guid>
		<description><![CDATA[On the 76th episode of the Silver Bullet Security Podcast, Gary chats with David Evans, Associate Professor of Computer Science at the University of Virginia. Gary and Dave discuss the founding of the Interdisciplinary Major in Computer Science (BA) at UVa and why a broad approach to Computer Science and Computer Security is a good [...]]]></description>
				<content:encoded><![CDATA[<p><img style="padding-left: 7px;" title="David Evans" src="http://www.cigital.com/wp-content/uploads/2012/07/devans.png" alt="David Evans" align="right" /></p>
<p>On the 76th episode of the Silver Bullet Security Podcast, Gary chats with David Evans, Associate Professor of Computer Science at the University of Virginia. Gary and Dave discuss the founding of the Interdisciplinary Major in Computer Science (BA) at UVa and why a broad approach to Computer Science and Computer Security is a good idea, why data privacy gets short shrift in the United States, why people think (for no apparent reason) that their mobile devices are secure, groceries, David&#8217;s research on Secure Computation, and the Udacity project. They close out their discussion with a story about David&#8217;s trip to the World Cup in Korea and a choice between GEB and scheme.</p>
<ul>
<li><a href="http://www.cs.virginia.edu/~evans/">David Evans</a></li>
<li><a href="http://www.jeffersonswheel.org/">Jefferson&#8217;s Wheel</a>, David&#8217;s blog</li>
<li><a href="http://www.cs.virginia.edu/ba/">Interdisciplinary Major in Computer Science</a></li>
<li><a href="http://www.udacity.com/">Udacity</a></li>
<li><a href="http://www.researchwithoutwalls.org/">Research Without Walls</a></li>
<li><a href="http://www.amazon.com/G%C3%B6del-Escher-Bach-Eternal-Golden/dp/0465026567/ref=sr_1_1?s=books&#038;ie=UTF8&#038;qid=1343412256&#038;sr=1-1&#038;keywords=GEB">GEB</a></li>
<li><a href="http://en.wikipedia.org/wiki/Scheme_(programming_language)">Scheme</a></li>
<li><a href="http://en.wikipedia.org/wiki/2002_FIFA_World_Cup">World Cup Korea</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/wuXSGQoESZ4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-076/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3198/0/silverbullet-076.mp3" length="47071360" type="audio/mpeg" />
		<itunes:duration>0:32:33</itunes:duration>
		<itunes:subtitle>
On the 76th episode of the Silver Bullet Security Podcast, Gary chats with David Evans, Associate Professor of Computer Science at the University of Virginia. Gary and Dave discuss the founding of the Interdisciplinary Major in Computer Science (BA[...]</itunes:subtitle>
		<itunes:summary>
On the 76th episode of the Silver Bullet Security Podcast, Gary chats with David Evans, Associate Professor of Computer Science at the University of Virginia. Gary and Dave discuss the founding of the Interdisciplinary Major in Computer Science (BA) at UVa and why a broad approach to Computer Science and Computer Security is a good idea, why data privacy gets short shrift in the United States, why people think (for no apparent reason) that their mobile devices are secure, groceries, David’s research on Secure Computation, and the Udacity project. They close out their discussion with a story about David’s trip to the World Cup in Korea and a choice between GEB and scheme.

David Evans
Jefferson’s Wheel, David’s blog
Interdisciplinary Major in Computer Science
Udacity
Research Without Walls
GEB
Scheme
World Cup Korea
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3198/0/silverbullet-076.mp3" fileSize="47071360" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-076/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-076</feedburner:origLink></item>
		<item>
		<title>Show 075 – An Interview with Howard Schmidt</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/RAoZ5XbhD3g/</link>
		<comments>http://www.cigital.com/silver-bullet/show-075/#comments</comments>
		<pubDate>Sat, 30 Jun 2012 17:00:33 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3062</guid>
		<description><![CDATA[On the landmark 75th episode of Silver Bullet, Gary talks with Howard Schmidt, former Cybersecurity Coordinator for the Obama administration. In this episode, Gary and Howard discuss the differences between doing security work in the public and private sectors, the difficulties of establishing cybersecurity in the government (especially when it comes to software security), the [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" src="http://www.cigital.com/wp-content/uploads/2012/06/hschmidt-125.png" alt="" title="Howard Schmidt" width="125" height="125" style="padding-left: 7px;" /></p>
<p>On the landmark 75th episode of Silver Bullet, Gary talks with Howard Schmidt, former Cybersecurity Coordinator for the Obama administration. In this episode, Gary and Howard discuss the differences between doing security work in the public and private sectors, the difficulties of establishing cybersecurity in the government (especially when it comes to software security), the government&#8217;s involvement in cyberespionage, and how the actions of Anonymous and Wikileaks square with the notion of free speech. They close the episode out with talk about Harleys.</p>
<p>This special edition of Silver Bullet was also captured on video. View the video below (for those on feed readers, go to <a href="http://www.cigital.com/silverbullet/show-075/">this episode&#8217;s page</a> for the video):</p>
<p align="center"><iframe width="500" height="281" src="http://www.youtube.com/embed/6FbskX2uUYI?rel=0" frameborder="0"></iframe></p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Howard_Schmidt">Howard Schmidt</a> (Wikipedia)</li>
<li><a href="http://news.cnet.com/8301-1009_3-57436466-83/u.s-cybersecurity-chief-howard-schmidt-retiring/">U.S. cybersecurity chief Howard Schmidt retiring</a></li>
<li><a href="http://www.computerweekly.com/news/2240158763/White-House-cyber-security-coordinator-Howard-Schmidt-joins-Qualys">White House cyber security coordinator Howard Schmidt joins Qualys</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/RAoZ5XbhD3g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-075/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3062/0/silverbullet-075.mp3" length="55378048" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>
On the landmark 75th episode of Silver Bullet, Gary talks with Howard Schmidt, former Cybersecurity Coordinator for the Obama administration. In this episode, Gary and Howard discuss the differences between doing security work in the public and pri[...]</itunes:subtitle>
		<itunes:summary>
On the landmark 75th episode of Silver Bullet, Gary talks with Howard Schmidt, former Cybersecurity Coordinator for the Obama administration. In this episode, Gary and Howard discuss the differences between doing security work in the public and private sectors, the difficulties of establishing cybersecurity in the government (especially when it comes to software security), the government’s involvement in cyberespionage, and how the actions of Anonymous and Wikileaks square with the notion of free speech. They close the episode out with talk about Harleys.
This special edition of Silver Bullet was also captured on video. View the video below (for those on feed readers, go to this episode’s page for the video):


Howard Schmidt (Wikipedia)
U.S. cybersecurity chief Howard Schmidt retiring
White House cyber security coordinator Howard Schmidt joins Qualys
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3062/0/silverbullet-075.mp3" fileSize="55378048" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-075/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-075</feedburner:origLink></item>
		<item>
		<title>Show 074 – An Interview with Bruce Schneier</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/pi6AT5PXI2w/</link>
		<comments>http://www.cigital.com/silver-bullet/show-074/#comments</comments>
		<pubDate>Wed, 30 May 2012 17:54:27 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=3004</guid>
		<description><![CDATA[On the 74th episode of The Silver Bullet Security Podcast, Gary talks for a second time with Bruce Schneier. They revisit Bruce&#8217;s prediction in episode 9 that insight into economics and security would help vendors sell their products more efficiently. In addition, they discuss Bruce&#8217;s new book Liars and Outliers: Enabling the Trust that Society [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" src="http://www.cigital.com/wp-content/uploads/2012/05/bschneier.png" alt="" title="Bruce Schneier" style="padding-left: 7px;" /></p>
<p>On the 74th episode of The Silver Bullet Security Podcast, Gary talks for a second time with Bruce Schneier. They revisit Bruce&#8217;s prediction in episode 9 that insight into economics and security would help vendors sell their products more efficiently. In addition, they discuss Bruce&#8217;s new book <em>Liars and Outliers: Enabling the Trust that Society Needs to Thrive</em>, how far behind the government is in terms of security, cloud computing, and Uncle Milton&#8217;s ant farm.</p>
<ul>
<li><a href="http://www.schneier.com/">Bruce Schneier</a></li>
<li><a href="http://www.schneier.com/book-applied.html"><em>Applied Cryptography</em></a></li>
<li><a href="http://www.schneier.com/book-lo.html"><em>Liars and Outliers</em></a></li>
<li><a href="http://www.cigital.com/silver-bullet/show-009/">Silver Bullet Security Podcast, show 009 (December 2006)</a> &#8211; Gary&#8217;s first chat with Bruce Schneier</li>
<li><a href="http://blogs.msdn.com/b/tzink/archive/2012/05/21/us-cyber-czar-howard-schmidt-resigns.aspx">US cyber czar Howard Schmidt resigns</a>
<li><a href="http://weis2012.econinfosec.org/">Workshop on Economics and Information Security</a></li>
<li><a href="http://www.cigital.com/papers/download/mcgraw-fick-CNAS.pdf" onclick="javascript:_gaq.push(['_trackEvent','download','http://www.cigital.com/papers/download/mcgraw-fick-CNAS.pdf']);">Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security</a> in <a href="http://www.cnas.rsvp1.com/node/6405?mgh=http%3A%2F%2Fwww.cnas.org&#038;mgf=1">AMERICA&#8217;S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II</a>, Center for a New Amercian Security (June 2011).</li>
<li><a href="http://en.wikipedia.org/wiki/Iterated_prisoner%27s_dilemma#The_iterated_prisoner.27s_dilemma">Prisoner&#8217;s Dilemma</a> (Axelrod)</li>
<li><a href="http://unclemilton.com/ant_farm/">Uncle Milton&#8217;s Ant Farm</a></li>
<li><a href="http://www.uglysweaterstore.com/">The Ugly Sweater Store</a></li>
<li><a href="http://www.amazon.com/Vintage-Spirits-Forgotten-Cocktails-Alamagoozlum/dp/1592535615/ref=sr_1_1?s=books&#038;ie=UTF8&#038;qid=1338325646&#038;sr=1-1"><em>Vintage Spirits and Forgotten Cocktails: From the Alamagoozlum to the Zombie 100 Rediscovered Recipes and the Stories Behind Them</em></a> &#8211; Mixology</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/pi6AT5PXI2w" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-074/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3004/0/silverbullet-074.mp3" length="43237504" type="audio/mpeg" />
		<itunes:duration>0:29:54</itunes:duration>
		<itunes:subtitle>
On the 74th episode of The Silver Bullet Security Podcast, Gary talks for a second time with Bruce Schneier. They revisit Bruce’s prediction in episode 9 that insight into economics and security would help vendors sell their products more eff[...]</itunes:subtitle>
		<itunes:summary>
On the 74th episode of The Silver Bullet Security Podcast, Gary talks for a second time with Bruce Schneier. They revisit Bruce’s prediction in episode 9 that insight into economics and security would help vendors sell their products more efficiently. In addition, they discuss Bruce’s new book Liars and Outliers: Enabling the Trust that Society Needs to Thrive, how far behind the government is in terms of security, cloud computing, and Uncle Milton’s ant farm.

Bruce Schneier
Applied Cryptography
Liars and Outliers
Silver Bullet Security Podcast, show 009 (December 2006) – Gary’s first chat with Bruce Schneier
US cyber czar Howard Schmidt resigns
Workshop on Economics and Information Security
Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security in AMERICA’S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).
Prisoner’s Dilemma (Axelrod)
Uncle Milton’s Ant Farm
The Ugly Sweater Store
Vintage Spirits and Forgotten Cocktails: From the Alamagoozlum to the Zombie 100 Rediscovered Recipes and the Stories Behind Them – Mixology
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3004/0/silverbullet-074.mp3" fileSize="43237504" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-074/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-074</feedburner:origLink></item>
		<item>
		<title>Show 073 – An Interview with Robert Vamosi</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/c0oFMCbQi2w/</link>
		<comments>http://www.cigital.com/silver-bullet/show-073/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 13:00:46 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=2906</guid>
		<description><![CDATA[On the 73rd episode of The Silver Bullet Security Podcast, Gary talks with Robert Vamosi, senior analyst with Mocana, freelance security reporter, and author of When Gadgets Betray Us. Gary and Robert discuss whether we&#8217;re doomed to idiocy as a species thanks to gadget dependency, why designers ignore security and privacy issues in gadget design. [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Robert Vamosi" src="/wp-content/uploads/2012/04/rvamosi-125.png" style="padding-left: 7px;" /></p>
<p>On the 73rd episode of The Silver Bullet Security Podcast, Gary talks with Robert Vamosi, senior analyst with Mocana, freelance security reporter, and author of <em>When Gadgets Betray Us</em>. Gary and Robert discuss whether we&#8217;re doomed to idiocy as a species thanks to gadget dependency, why designers ignore security and privacy issues in gadget design.  Finally, Gary and Robert discuss Robert&#8217;s use of the word &#8220;betray.&#8221;</p>
<ul>
<li><a href="http://robertvamosi.com/">Robert Vamosi</a></li>
<li><a href="https://www.mocana.com/vamosi.html">Robert Vamosi (at Mocana)</a></li>
<li><a href="http://whengadgetsbetrayus.com/"><em>When Gadgets Betray Us</em></a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1636983">Gary on Stuxnet</a></li>
<li><a href="http://www.doc88.com/p-94850699414.html">With Or Without You</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/c0oFMCbQi2w" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-073/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/2906/0/silverbullet-073.mp3" length="38475904" type="audio/mpeg" />
		<itunes:duration>0:26:35</itunes:duration>
		<itunes:subtitle>
On the 73rd episode of The Silver Bullet Security Podcast, Gary talks with Robert Vamosi, senior analyst with Mocana, freelance security reporter, and author of When Gadgets Betray Us. Gary and Robert discuss whether we’re doomed to idiocy as[...]</itunes:subtitle>
		<itunes:summary>
On the 73rd episode of The Silver Bullet Security Podcast, Gary talks with Robert Vamosi, senior analyst with Mocana, freelance security reporter, and author of When Gadgets Betray Us. Gary and Robert discuss whether we’re doomed to idiocy as a species thanks to gadget dependency, why designers ignore security and privacy issues in gadget design.  Finally, Gary and Robert discuss Robert’s use of the word “betray.”

Robert Vamosi
Robert Vamosi (at Mocana)
When Gadgets Betray Us
Gary on Stuxnet
With Or Without You
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/2906/0/silverbullet-073.mp3" fileSize="38475904" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-073/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-073</feedburner:origLink></item>
		<item>
		<title>Show 072 – An Interview with Randy Sabett</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/vDH_S3Ekjfk/</link>
		<comments>http://www.cigital.com/silver-bullet/show-072/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 18:32:06 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=2846</guid>
		<description><![CDATA[On the 72nd episode of The Silver Bullet Security Podcast, Gary talks with Randy Sabett, a lawyer with the ZwillGen cyber-law firm in Washington, DC. Gary and Randy discuss Microsoft&#8217;s Zeus Botnet raid, alleged AT&#038;T/NSA wiretapping, whether cyberlaw is full of loopholes, and if security always trades off against privacy and anonymity. They close out [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Randy Sabett" src="/wp-content/uploads/2012/03/rsabett-125.png" style="padding-left: 7px" /></p>
<p>On the 72nd episode of The Silver Bullet Security Podcast, Gary talks with Randy Sabett, a lawyer with the ZwillGen cyber-law firm in Washington, DC. Gary and Randy discuss Microsoft&#8217;s Zeus Botnet raid, alleged AT&#038;T/NSA wiretapping, whether cyberlaw is full of loopholes, and if security always trades off against privacy and anonymity. They close out their discussion discussing the book Randy is currently reading.</p>
<ul>
<li><a href="http://www.zwillgen.com/randy.php">Randy V. Sabett</a></li>
<li><a href="http://blogs.technet.com/b/microsoft_blog/archive/2012/03/25/microsoft-and-financial-services-industry-leaders-target-cybercriminal-operations-from-zeus-botnets.aspx">Microsoft and Financial Services Industry Leaders Target Cybercriminal Operations from Zeus Botnets</a>, The Official Microsoft Blog.</li>
<li><a href="http://www.nytimes.com/2012/03/26/technology/microsoft-raids-tackle-online-crime.html?_r=2&#038;pagewanted=all">Microsoft Raids Tackle Internet Crime</a>, <em>The New York Times</em>.</li>
<li><a href="http://blog.zwillgen.com/2012/02/28/court-upholds-5th-amendment-based-refusal-to-decrypt-hard-drive/">Court Upholds 5th Amendment-based Refusal to Decrypt Hard Drive</a></li>
<li><a href="http://www.cigital.com/papers/download/mcgraw-fick-CNAS.pdf">Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security</a> in AMERICA&#8217;S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).</li>
<li><a href="http://www.amazon.com/Cuckoos-Egg-Clifford-Stoll/dp/0671726889"><em>The Cuckoo&#8217;s Egg</em> by Clifford Stoll</a></li>
<li><a href="http://www.youtube.com/watch?v=aq3wL8ZXjBU">Fram oil filter commercial</a></li>
<li><a href="http://www.washingtonpost.com/business/capitalbusiness/is-time-running-out-on-the-billable-hour/2012/01/10/gIQAKUSU1P_story.html">Is time running out on the billable hour?</a></li>
<li><a href="http://www.singularity.com/"><em>The Singularity is Near</em> by Ray Kurzweil</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/vDH_S3Ekjfk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-072/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/2846/0/silverbullet-072.mp3" length="53426304" type="audio/mpeg" />
		<itunes:duration>0:37:04</itunes:duration>
		<itunes:subtitle>
On the 72nd episode of The Silver Bullet Security Podcast, Gary talks with Randy Sabett, a lawyer with the ZwillGen cyber-law firm in Washington, DC. Gary and Randy discuss Microsoft’s Zeus Botnet raid, alleged AT&amp;T/NSA wiretapping, whet[...]</itunes:subtitle>
		<itunes:summary>
On the 72nd episode of The Silver Bullet Security Podcast, Gary talks with Randy Sabett, a lawyer with the ZwillGen cyber-law firm in Washington, DC. Gary and Randy discuss Microsoft’s Zeus Botnet raid, alleged AT&amp;T/NSA wiretapping, whether cyberlaw is full of loopholes, and if security always trades off against privacy and anonymity. They close out their discussion discussing the book Randy is currently reading.

Randy V. Sabett
Microsoft and Financial Services Industry Leaders Target Cybercriminal Operations from Zeus Botnets, The Official Microsoft Blog.
Microsoft Raids Tackle Internet Crime, The New York Times.
Court Upholds 5th Amendment-based Refusal to Decrypt Hard Drive
Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security in AMERICA’S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).
The Cuckoo’s Egg by Clifford Stoll
Fram oil filter commercial
Is time running out on the billable hour?
The Singularity is Near by Ray Kurzweil
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/2846/0/silverbullet-072.mp3" fileSize="53426304" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-072/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-072</feedburner:origLink></item>
		<item>
		<title>Show 071 – An Interview with Bill Arbaugh</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/JooIseztlUI/</link>
		<comments>http://www.cigital.com/silver-bullet/show-071/#comments</comments>
		<pubDate>Wed, 29 Feb 2012 15:45:18 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=2774</guid>
		<description><![CDATA[On the 71st episode of The Silver Bullet Security Podcast, Gary talks with Bill Arbaugh, Associate Professor of Computer Science at University of Maryland. Gary and Bill discuss how malware has evolved and changed over the last decade and how it&#8217;s affected software security practices, BIOS-based attacks, academia vs. startup, and why the NSA doesn&#8217;t [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Bill Arbaugh" src="/wp-content/uploads/2012/02/barbaugh-12521.png" style="padding-left: 7px" /></p>
<p>On the 71st episode of The Silver Bullet Security Podcast, Gary talks with Bill Arbaugh, Associate Professor of Computer Science at University of Maryland. Gary and Bill discuss how malware has evolved and changed over the last decade and how it&#8217;s affected software security practices, BIOS-based attacks, academia vs. startup, and why the NSA doesn&#8217;t play defense when it comes to cybersecurity.</p>
<ul>
<li><a href="http://www.cs.umd.edu/~waa/UMD/Home.html">Bill Arbaugh @ UMD</a></li>
<li><a href="http://www.microsoft.com/security/portal/komoku/">Microsoft Acquires Komoku</a></li>
<li>Silver Bullet: Ross Anderson, <a href="http://www.cigital.com/silver-bullet/show-013/">show 13</a>, <a href="http://www.cigital.com/silver-bullet/show-070/">show 70</a></li>
<li><a href="http://ictf.cs.ucsb.edu/">International Capture the Flag</a></li>
<li><a href="http://www.cigital.com/papers/download/mcgraw-fick-CNAS.pdf">Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security</a> in AMERICA&#8217;S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/JooIseztlUI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-071/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/2774/0/silverbullet-071.mp3" length="42516608" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>
On the 71st episode of The Silver Bullet Security Podcast, Gary talks with Bill Arbaugh, Associate Professor of Computer Science at University of Maryland. Gary and Bill discuss how malware has evolved and changed over the last decade and how it[...]</itunes:subtitle>
		<itunes:summary>
On the 71st episode of The Silver Bullet Security Podcast, Gary talks with Bill Arbaugh, Associate Professor of Computer Science at University of Maryland. Gary and Bill discuss how malware has evolved and changed over the last decade and how it’s affected software security practices, BIOS-based attacks, academia vs. startup, and why the NSA doesn’t play defense when it comes to cybersecurity.

Bill Arbaugh @ UMD
Microsoft Acquires Komoku
Silver Bullet: Ross Anderson, show 13, show 70
International Capture the Flag
Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security in AMERICA’S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/2774/0/silverbullet-071.mp3" fileSize="42516608" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-071/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-071</feedburner:origLink></item>
		<item>
		<title>Show 070 – An Interview with Ross Anderson</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/drhMgDOPfMM/</link>
		<comments>http://www.cigital.com/silver-bullet/show-070/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 21:05:03 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=2651</guid>
		<description><![CDATA[The 70th episode of The Silver Bullet Security Podcast is our first repeat performance. Gary chats a second time with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering. Ross was a guest on episode 13 of The Silver Bullet Security Podcast and is [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ross Anderson" src="/wp-content/uploads/2012/01/randerson.png" style="padding-left: 7px" /></p>
<p>The 70th episode of The Silver Bullet Security Podcast is our first repeat performance.  Gary chats a second time with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book <em>Security Engineering</em>. Ross was a guest on episode 13 of The Silver Bullet Security Podcast and is our first return guest. Gary and Ross discuss the latest developments in Trusted Computing, the iterated &#8220;Prisoner&#8217;s Dilemma&#8221; as an economic model and its relevance to computer security, information compartmentalization and Wikileaks, time and security, cyberwar versus cybercrime, and Stuxnet.</p>
<ul>
<li><a href="http://www.cigital.com/silver-bullet/show-013/">Silver Bullet Show 013: Ross Anderson</a></li>
<li><a href="/silver-bullet-files/shows/silverbullet-013-randerson.pdf">Transcript of episode 13</a> [PDF]</li>
<li><a href="http://www.ross-anderson.com/">Ross Anderson</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html">Trusted Computing FAQ</a></li>
<li><em>Security Engineering</em> &#8211; Ross&#8217; groundbreaking book <a href="http://www.amazon.com/exec/obidos/ASIN/0471389226/rossandersshomep">in print</a> and <a href="http://www.cl.cam.ac.uk/~rja14/book.html">online</a></li>
<li><a href="http://www.cigital.com/papers/download/mcgraw-fick-CNAS.pdf">Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security</a> in AMERICA&#8217;S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/drhMgDOPfMM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-070/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/2651/0/silverbullet-070.mp3" length="49351625" type="audio/mpeg" />
		<itunes:duration>0:00:01</itunes:duration>
		<itunes:subtitle>
The 70th episode of The Silver Bullet Security Podcast is our first repeat performance.  Gary chats a second time with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Securi[...]</itunes:subtitle>
		<itunes:summary>
The 70th episode of The Silver Bullet Security Podcast is our first repeat performance.  Gary chats a second time with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering. Ross was a guest on episode 13 of The Silver Bullet Security Podcast and is our first return guest. Gary and Ross discuss the latest developments in Trusted Computing, the iterated “Prisoner’s Dilemma” as an economic model and its relevance to computer security, information compartmentalization and Wikileaks, time and security, cyberwar versus cybercrime, and Stuxnet.

Silver Bullet Show 013: Ross Anderson
Transcript of episode 13 [PDF]
Ross Anderson
Trusted Computing FAQ
Security Engineering – Ross’ groundbreaking book in print and online
Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security in AMERICA’S CYBER FUTURE: SECURITY AND PROSPERITY IN THE INFORMATION AGE VOLUMES I AND II, Center for a New Amercian Security (June 2011).
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/2651/0/silverbullet-070.mp3" fileSize="49351625" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-070/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-070</feedburner:origLink></item>
		<item>
		<title>Show 069 – An Interview with Steve Myers</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/5pjQnJL4Xjw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-069/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 15:01:37 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
		
		<guid isPermaLink="false">http://www.cigital.com/?post_type=podcast&amp;p=2493</guid>
		<description><![CDATA[On the 69th episode of The Silver Bullet Security Podcast, Gary talks with Steve Myers, Assistant Professor of Informatics and Computing in the School of Informatics at Indiana University and a member of the Center for Applied Cybersecurity. During this show, Gary and Steve discuss the gap between &#8220;real world&#8221; computer security and &#8220;academic&#8221; computer [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Steve Myers" src="/wp-content/uploads/2011/12/smyers-125.png" style="padding-left: 7px" /></p>
<p>On the 69th episode of The Silver Bullet Security Podcast, Gary talks with Steve Myers, Assistant Professor of Informatics and Computing in the School of Informatics at Indiana University and a member of the Center for Applied Cybersecurity. During this show, Gary and Steve discuss the gap between &#8220;real world&#8221; computer security and &#8220;academic&#8221; computer security, the problem of cryptography, whether it&#8217;s OK to use &#8220;the NASCAR effect&#8221; to draw students into security, and spear phishing.</p>
<ul>
<li><a href="http://www.informatics.indiana.edu/samyers/">Steve Myers</a></li>
<li><a href="http://cacr.iu.edu/">Center for Applied Cybersecurity</a></li>
<li><a href="http://www.cis.syr.edu/~wedu/seed/">The SEED Project</a> (Developing Instructional Laboratories for Computer SEcurity EDucation)</li>
<li><a href="http://www.usenix.org/event/leet11/tech/slides/husted.pdf">Why Mobile to Mobile Malware Won&#8217;t Cause a Storm</a> [PDF], paper for USENIX &#8217;11, with Nathaniel Husted </li>
<li><a href="http://www.cc.gatech.edu/~traynor/">Patrick Traynor</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-020/">Silver Bullet Show 020:­ An Interview with Markus Jakobsson</a></li>
<li><a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-0471782459.html"><em>Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft</em></a>, edited by Steve Myers and Markus Jakobsson</li>
<li><a href="http://www.fbi.gov/news/stories/2009/april/spearphishing_040109">&#8220;Spear phishing&#8221;</a></li>
<li><a href="http://sotw.ca/">Spirit of the West</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/5pjQnJL4Xjw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-069/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/2493/0/silverbullet-069.mp3" length="42492032" type="audio/mpeg" />
		<itunes:duration>0:29:22</itunes:duration>
		<itunes:subtitle>
On the 69th episode of The Silver Bullet Security Podcast, Gary talks with Steve Myers, Assistant Professor of Informatics and Computing in the School of Informatics at Indiana University and a member of the Center for Applied Cybersecurity. During[...]</itunes:subtitle>
		<itunes:summary>
On the 69th episode of The Silver Bullet Security Podcast, Gary talks with Steve Myers, Assistant Professor of Informatics and Computing in the School of Informatics at Indiana University and a member of the Center for Applied Cybersecurity. During this show, Gary and Steve discuss the gap between “real world” computer security and “academic” computer security, the problem of cryptography, whether it’s OK to use “the NASCAR effect” to draw students into security, and spear phishing.

Steve Myers
Center for Applied Cybersecurity
The SEED Project (Developing Instructional Laboratories for Computer SEcurity EDucation)
Why Mobile to Mobile Malware Won’t Cause a Storm [PDF], paper for USENIX ’11, with Nathaniel Husted 
Patrick Traynor
Silver Bullet Show 020:­ An Interview with Markus Jakobsson
Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft, edited by Steve Myers and Markus Jakobsson
“Spear phishing”
Spirit of the West
</itunes:summary>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/2493/0/silverbullet-069.mp3" fileSize="42492032" type="audio/mpeg" /><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-069/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-069</feedburner:origLink></item>
		<item>
		<title>Show 068 – An Interview with John Steven</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/n6S0QF1pD-Y/</link>
		<comments>http://www.cigital.com/silver-bullet/show-068/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 16:50:00 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=97</guid>
		<description><![CDATA[On the 68th episode of The Silver Bullet Security Podcast, Gary is joined in the studio by John Steven, internal CTO at Cigital. Gary and John discuss how software architecture is being pulled by financial services instead of being pushed by technology firms, why architecture risk analysis is so important (and so hard to automate), [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="John Steven" src="/wp-content/uploads/2011/11/jsteven-125.png" style="padding-left: 7px" /></p>
<p>On the 68th episode of The Silver Bullet Security Podcast, Gary is joined in the studio by John Steven, internal CTO at Cigital. Gary and John discuss how software architecture is being pulled by financial services instead of being pushed by technology firms, why architecture risk analysis is so important (and so hard to automate), the bias that developers and security practitioners show towards security features rather than software security Touchpoints, and enterprise use of static analysis tools. They close out the show discussing mixology.</p>
<ul>
<li><a href="http://www.cigital.com/justiceleague/author/jOHN/">John Steven @ Justice League blog</a></li>
<li><a href="https://www.owasp.org/index.php/Virginia">OWASP NoVA</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1680863">Software [In]security: Comparing Apples, Oranges, and Aardvarks (or, All Static Analysis Tools Are Not Created Equal)</a>, InformIT.</li>
<li><a href="http://www.cigital.com/justiceleague/2011/03/29/moving-to-mobile-new-threats/">Moving to Mobile – New Threats</a>, Justice League blog.</li>
<li><a href="http://www.cigital.com/justiceleague/2011/05/11/threat-modeling-vocabulary/">Threat Modeling – Vocabulary</a>, Justice League blog.</li>
<li><a href="http://bsimm.com/">BSIMM</a></li>
<li><a href="http://noplasticshowers.com/2011/04/09/return-to-philly-palomar-philadelphia/">&#8220;The Liberal&#8221;</a></li>
<li><a href="http://prohibitioneracocktails.blogspot.com/2010/07/prohibition-era-cocktails-whiskey-old.html">&#8220;The Old Fashioned&#8221;</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-057/">Silver Bullet: Elinor Mills</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/n6S0QF1pD-Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-068/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/1998/0/silverbullet-068.mp3" length="49463424" type="audio/mpeg" />
		<itunes:duration>0:34:19</itunes:duration>
		<itunes:subtitle>
On the 68th episode of The Silver Bullet Security Podcast, Gary is joined in the studio by John Steven, internal CTO at Cigital. Gary and John discuss how software architecture is being pulled by financial services instead of being pushed by techno[...]</itunes:subtitle>
		<itunes:summary>
On the 68th episode of The Silver Bullet Security Podcast, Gary is joined in the studio by John Steven, internal CTO at Cigital. Gary and John discuss how software architecture is being pulled by financial services instead of being pushed by technology firms, why architecture risk analysis is so important (and so hard to automate), the bias that developers and security practitioners show towards security features rather than software security Touchpoints, and enterprise use of static analysis tools. They close out the show discussing mixology.

John Steven @ Justice League blog
OWASP NoVA
Software [In]security: Comparing Apples, Oranges, and Aardvarks (or, All Static Analysis Tools Are Not Created Equal), InformIT.
Moving to Mobile – New Threats, Justice League blog.
Threat Modeling – Vocabulary, Justice League blog.
BSIMM
“The Liberal”
“The Old Fashioned”
Silver Bullet: Elinor Mills
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/1998/0/silverbullet-068.mp3" fileSize="49463424" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-068/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-068</feedburner:origLink></item>
		<item>
		<title>Show 067 – An Interview with Bill Pugh</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/JX-a5V7aByA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-067/#comments</comments>
		<pubDate>Fri, 28 Oct 2011 17:55:17 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=95</guid>
		<description><![CDATA[On the 67th episode of The Silver Bullet Security Podcast, Gary talks with Bill Pugh, professor at the University of Maryland College Park. Gary and Bill discuss the Marmoset and FindBugs projects, how to teach kids to code and whether coding is an innate ability or is something that can be taught. They also geek [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Bill Pugh" src="/wp-content/uploads/2011/10/bpugh.png" style="padding-left: 7px" /></p>
<p>On the 67th episode of The Silver Bullet Security Podcast, Gary talks with Bill Pugh, professor at the University of Maryland College Park. Gary and Bill discuss the Marmoset and FindBugs projects, how to teach kids to code and whether coding is an innate ability or is something that can be taught.  They also geek out regarding Bill&#8217;s favorite programming languages for coding and teaching about coding. They also discuss the relationship between coding and fire eating.</p>
<ul>
<li><a href="http://www.cs.umd.edu/~pugh/">Bill Pugh</a></li>
<li><a href="http://marmoset.cs.umd.edu/">Marmoset</a></li>
<li><a href="http://dilbert.com/strips/comic/1995-11-13/">Dilbert minivan strip</a></li>
<li><a href="http://findbugs.sourceforge.net/">Find Bugs</a></li>
<li><a href="http://goose.ycp.edu/~dhovemey/">David Hovemeyer</a></li>
<li><a href="http://www.cafepress.com/findbugs.23042006">Find Bugs t-shirt</a></li>
<li><a href="http://www.azulsystems.com/blog/">Cliff Click</a></li>
<li><a href="http://www.cs.umd.edu/class/fall2011/cmsc433/">UMD: Fall 2011 CMSC 433 &#8211; Programming Language Technologies and Paradigms</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/JX-a5V7aByA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-067/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/1608/0/silverbullet-067.mp3" length="58126464" type="audio/mpeg" />
		<itunes:duration>0:40:20</itunes:duration>
		<itunes:subtitle>
On the 67th episode of The Silver Bullet Security Podcast, Gary talks with Bill Pugh, professor at the University of Maryland College Park. Gary and Bill discuss the Marmoset and FindBugs projects, how to teach kids to code and whether coding is an[...]</itunes:subtitle>
		<itunes:summary>
On the 67th episode of The Silver Bullet Security Podcast, Gary talks with Bill Pugh, professor at the University of Maryland College Park. Gary and Bill discuss the Marmoset and FindBugs projects, how to teach kids to code and whether coding is an innate ability or is something that can be taught.  They also geek out regarding Bill’s favorite programming languages for coding and teaching about coding. They also discuss the relationship between coding and fire eating.

Bill Pugh
Marmoset
Dilbert minivan strip
Find Bugs
David Hovemeyer
Find Bugs t-shirt
Cliff Click
UMD: Fall 2011 CMSC 433 – Programming Language Technologies and Paradigms
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/1608/0/silverbullet-067.mp3" fileSize="58126464" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-067/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-067</feedburner:origLink></item>
		<item>
		<title>Show 066 – An Interview with Shari Lawrence Pfleeger</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/oi2qzKbLxO4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-066/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 18:44:32 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=93</guid>
		<description><![CDATA[On the 66th episode of The Silver Bullet Security Podcast, Gary chats with Shari Lawrence Pfleeger, Director of Research for the Institute for Information Infrastructure Protection at Dartmouth College. Gary and Shari discuss the difference between safety-critical software and security-critical software, why measuring software is hard (security notwithstanding), how to speed up tech transfer, and [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Shari Lawrence Pfleeger" src="/wp-content/uploads/2011/09/slpfleeger.png" style="padding-left: 7px" /></p>
<p>On the 66th episode of The Silver Bullet Security Podcast, Gary chats with Shari Lawrence Pfleeger, Director of Research for the Institute for Information Infrastructure Protection at Dartmouth College. Gary and Shari discuss the difference between safety-critical software and security-critical software, why measuring software is hard (security notwithstanding), how to speed up tech transfer, and why there are so few women in computer science.</p>
<ul>
<li><a href="http://shari.pfleeger.com/">Shari Lawrence Pfleeger</a></li>
<li><a href="http://www.amazon.com/Software-Engineering-Theory-Practice-4th/dp/0136061699/ref=ntt_at_ep_dpt_1"><em>Software Engineering: Theory and Practice</em></a>, 4th edition</li>
<li><a href="http://www.washingtonpost.com/lifestyle/style/many-media-types-live-in-the-land-of-twitter-but-most-regular-people-dont/2011/09/01/gIQARfaUdK_story.html">Many media types live in the land of Twitter, but most regular people don’t</a> by Monica Hesse in the <em>Washington Post</em></li>
<li><a href="http://www.youtube.com/watch?v=kAG39jKi0lI">My Blackberry&#8217;s Not Working!</a>, <em>The One Ronnie</em></li>
<li><a href="http://en.wikipedia.org/wiki/The_Hours_(novel)"><em>The Hours</em></a> by Michael Cunningham</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/oi2qzKbLxO4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-066/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/1607/0/silverbullet-066.mp3" length="39577728" type="audio/mpeg" />
		<itunes:duration>0:27:27</itunes:duration>
		<itunes:subtitle>
On the 66th episode of The Silver Bullet Security Podcast, Gary chats with Shari Lawrence Pfleeger, Director of Research for the Institute for Information Infrastructure Protection at Dartmouth College. Gary and Shari discuss the difference between[...]</itunes:subtitle>
		<itunes:summary>
On the 66th episode of The Silver Bullet Security Podcast, Gary chats with Shari Lawrence Pfleeger, Director of Research for the Institute for Information Infrastructure Protection at Dartmouth College. Gary and Shari discuss the difference between safety-critical software and security-critical software, why measuring software is hard (security notwithstanding), how to speed up tech transfer, and why there are so few women in computer science.

Shari Lawrence Pfleeger
Software Engineering: Theory and Practice, 4th edition
Many media types live in the land of Twitter, but most regular people don’t by Monica Hesse in the Washington Post
My Blackberry’s Not Working!, The One Ronnie
The Hours by Michael Cunningham
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/1607/0/silverbullet-066.mp3" fileSize="39577728" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-066/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-066</feedburner:origLink></item>
		<item>
		<title>Show 065 – An Interview with Giovanni Vigna</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Ikspeov4K4k/</link>
		<comments>http://www.cigital.com/silver-bullet/show-065/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 14:49:54 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=91</guid>
		<description><![CDATA[On the 65th episode of The Silver Bullet Security Podcast, Gary is joined by Giovanni Vigna, professor of Computer Science at UC Santa Barbara. They discuss DEFCON&#8217;s classic Capture the Flag contest as well as UCSB&#8217;s international version. They ponder how the notion of &#8220;build security in&#8221; might be integrated into a CTF-type contest. Gary [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Giovanni Vigna" src="/wp-content/uploads/2011/08/gvigna.png" style="padding-left: 7px" /></p>
<p>On the 65th episode of The Silver Bullet Security Podcast, Gary is joined by Giovanni Vigna, professor of Computer Science at UC Santa Barbara. They discuss DEFCON&#8217;s classic Capture the Flag contest as well as UCSB&#8217;s international version.  They ponder how the notion of &#8220;build security in&#8221; might be integrated into a CTF-type contest. Gary and Giovanni also talk about Giovanni&#8217;s favorite course to teach, the challenge of communicating security issues with non-technical people, and the role of blackbox testing in security. They close out the show discussing how to teach a toddler to pick locks.</p>
<ul>
<li><a href="http://www.cs.ucsb.edu/~vigna/">Giovanni at UCSB</a></li>
<li><a href="http://www.defcon.org/html/links/dc-ctf.html">DEFCON Capture the Flag</a></li>
<li><a href="http://ictf.cs.ucsb.edu/">Internatonal Capture the Flag</a></li>
<li><a href="http://www.cigital.com/justiceleague/2011/08/09/building-versus-breaking-a-white-hat-goes-to-blackhat/">Building Versus Breaking: A White Hat goes to Blackhat</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Ikspeov4K4k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-065/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/1606/0/silverbullet-065.mp3" length="44277888" type="audio/mpeg" />
		<itunes:duration>0:30:43</itunes:duration>
		<itunes:subtitle>
On the 65th episode of The Silver Bullet Security Podcast, Gary is joined by Giovanni Vigna, professor of Computer Science at UC Santa Barbara. They discuss DEFCON’s classic Capture the Flag contest as well as UCSB’s international versi[...]</itunes:subtitle>
		<itunes:summary>
On the 65th episode of The Silver Bullet Security Podcast, Gary is joined by Giovanni Vigna, professor of Computer Science at UC Santa Barbara. They discuss DEFCON’s classic Capture the Flag contest as well as UCSB’s international version.  They ponder how the notion of “build security in” might be integrated into a CTF-type contest. Gary and Giovanni also talk about Giovanni’s favorite course to teach, the challenge of communicating security issues with non-technical people, and the role of blackbox testing in security. They close out the show discussing how to teach a toddler to pick locks.

Giovanni at UCSB
DEFCON Capture the Flag
Internatonal Capture the Flag
Building Versus Breaking: A White Hat goes to Blackhat
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/1606/0/silverbullet-065.mp3" fileSize="44277888" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-065/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-065</feedburner:origLink></item>
		<item>
		<title>Show 064 – An Interview with Markus Schumacher</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/IvJGMs_aU7c/</link>
		<comments>http://www.cigital.com/silver-bullet/show-064/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 17:42:21 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=88</guid>
		<description><![CDATA[On the 64th episode of The Silver Bullet Security Podcast, Gary chats with Markus Schumacher, co-founder and CEO of Virtual Forge. Gary and Markus discuss the difference between working for a large corporate and a startup, why Virtual Forge built a code scanning tool for SAP&#8217;s ABAP code, whether security people understand the notion of [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Markus Schumacher" src="/wp-content/uploads/2011/07/mschumacher.png" style="padding-left: 7px" /></p>
<p>On the 64th episode of The Silver Bullet Security Podcast, Gary chats with Markus Schumacher, co-founder and CEO of Virtual Forge. Gary and Markus discuss the difference between working for a large corporate and a startup, why Virtual Forge built a code scanning tool for SAP&#8217;s ABAP code, whether security people understand the notion of security patterns, and Markus&#8217; favorite beverage in Heidelberg.</p>
<ul>
<li><a href="http://virtualforge.com/">Virtual Forge</a></li>
<li><a href="http://www.securitypatterns.org/">Security Patterns</a>, the site</li>
<li><a href="http://www.amazon.com/gp/product/0470858842"><em>Security Patterns</em></a>, the book</li>
<li><a href="http://www.cigital.com/papers/download/09-11_Software0511.pdf">Technology Transfer: A Software Security Marketplace Case Study</a>, (<em>IEEE Software</em>, September/October 2011)</li>
<li><a href="http://www.printmedialounge.de/">Print Media Lounge</a></li>
<li><a href="http://noplasticshowers.com/2011/04/09/return-to-philly-palomar-philadelphia/">Recipe for a Liberal (the drink)</a>
<li><a href="http://www.myspace.com/outofdamage/">Out of Damage</a>, Markus&#8217; band</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/IvJGMs_aU7c" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-064/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/1605/0/silverbullet-064.mp3" length="31412352" type="audio/mpeg" />
		<itunes:duration>0:21:47</itunes:duration>
		<itunes:subtitle>
On the 64th episode of The Silver Bullet Security Podcast, Gary chats with Markus Schumacher, co-founder and CEO of Virtual Forge. Gary and Markus discuss the difference between working for a large corporate and a startup, why Virtual Forge built a[...]</itunes:subtitle>
		<itunes:summary>
On the 64th episode of The Silver Bullet Security Podcast, Gary chats with Markus Schumacher, co-founder and CEO of Virtual Forge. Gary and Markus discuss the difference between working for a large corporate and a startup, why Virtual Forge built a code scanning tool for SAP’s ABAP code, whether security people understand the notion of security patterns, and Markus’ favorite beverage in Heidelberg.

Virtual Forge
Security Patterns, the site
Security Patterns, the book
Technology Transfer: A Software Security Marketplace Case Study, (IEEE Software, September/October 2011)
Print Media Lounge
Recipe for a Liberal (the drink)
Out of Damage, Markus’ band
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/1605/0/silverbullet-064.mp3" fileSize="31412352" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-064/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-064</feedburner:origLink></item>
		<item>
		<title>Show 063 – An Interview with Craig Miller</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Hb8GIKqGNXA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-063/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 14:25:23 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=85</guid>
		<description><![CDATA[On the 63rd episode of The Silver Bullet Security Podcast, Gary talks with Craig Miller, principal at the MAPA Group. Gary and Craig discuss entrepreneurship, the pluses and minuses of working for start-ups and very large corporations, smart grid security, and working with NRECA. They close out the show discussing movies and books. Dr. Craig [...]]]></description>
				<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-358" src="http://www.cigital.com/wp-content/uploads/2011/06/craig-miller.jpg" alt="" width="125" height="125" />On the 63rd episode of The Silver Bullet Security Podcast, Gary talks with Craig Miller, principal at the MAPA Group. Gary and Craig discuss entrepreneurship, the pluses and minuses of working for start-ups and very large corporations, smart grid security, and working with NRECA. They close out the show discussing movies and books.</p>
<ul>
<li><a href="http://www.mapagroup.net/our-team/dr-craig-miller/">Dr. Craig Miller</a></li>
<li><a href="http://www.mapagroup.net/">MAPA Group</a></li>
<li><a href="http://www.saic.com/">SAIC</a></li>
<li><a href="http://en.wikipedia.org/wiki/Smart_grid">Smart grid</a></li>
<li><a href="http://www.nreca.org/">NRECA</a></li>
<li><a href="http://www.nerc.com/">NERC</a></li>
<li><a href="http://en.wikipedia.org/wiki/Continuous_improvement_process">Continuous improvement</a></li>
<li><a href="http://en.wikipedia.org/wiki/On_the_Waterfront"><em>On the Waterfront</em></a></li>
<li><a href="http://www.gutenberg.org/ebooks/2701"><em>Moby Dick</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Hb8GIKqGNXA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-063/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/216/0/silverbullet-063.mp3" length="47413376" type="audio/mpeg" />
		<itunes:duration>0:32:54</itunes:duration>
		<itunes:subtitle>On the 63rd episode of The Silver Bullet Security Podcast, Gary talks with Craig Miller, principal at the MAPA Group. Gary and Craig discuss entrepreneurship, the pluses and minuses of working for start-ups and very large corporations, smart grid se[...]</itunes:subtitle>
		<itunes:summary>On the 63rd episode of The Silver Bullet Security Podcast, Gary talks with Craig Miller, principal at the MAPA Group. Gary and Craig discuss entrepreneurship, the pluses and minuses of working for start-ups and very large corporations, smart grid security, and working with NRECA. They close out the show discussing movies and books.

Dr. Craig Miller
MAPA Group
SAIC
Smart grid
NRECA
NERC
Continuous improvement
On the Waterfront
Moby Dick
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/216/0/silverbullet-063.mp3" fileSize="47413376" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-063/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-063</feedburner:origLink></item>
		<item>
		<title>Show 062 – An Interview with Halvar Flake</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/ioivcQEnya8/</link>
		<comments>http://www.cigital.com/silver-bullet/show-062/#comments</comments>
		<pubDate>Tue, 31 May 2011 15:05:00 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=83</guid>
		<description><![CDATA[On the 62nd episode of The Silver Bullet Security Podcast, Gary chats with Halvar Flake (a.k.a. Thomas Dullien), founder of reverse engineering consultancy, Zynamics, which was recently purchased by Google. Gary and Halvar discuss the acquisition, Zynamics&#8217; product BinDiff, whether the &#8220;bad guys&#8221; are using code understanding tools (including decompilers) better than developers, static versus [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Halvar Flake" src="/wp-content/uploads/2011/05/hflake.png" style="padding-left: 7px" /></p>
<p>On the 62nd episode of The Silver Bullet Security Podcast, Gary chats with Halvar Flake (a.k.a. Thomas Dullien), founder of reverse engineering consultancy, Zynamics, which was recently purchased by Google. Gary and Halvar discuss the acquisition, Zynamics&#8217; product BinDiff, whether the &#8220;bad guys&#8221; are using code understanding tools (including decompilers) better than developers, static versus dynamic analysis, international politics meets computer security, and the growing complexity of malware. They close out with a discussion of music.</p>
<ul>
<li><a href="http://addxorrol.blogspot.com/">ADD / XOR / ROL</a> &#8211; Halvar&#8217;s blog</li>
<li><a href="http://twitter.com/#!/halvarflake">@halvarflake</a></li>
<li><a href="http://www.wired.com/threatlevel/2007/07/german-security/">US Denies Entry</a> (2007)</li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1662328">Cyber Warmongering and Influence Peddling</a> (November 24, 2010)</li>
<li><a href="http://techcrunch.com/2011/03/01/google-buys-security-analytics-startup-zynamics/">Google&#8217;s purchase of Zynamics</a></li>
<li><a href="http://www.zynamics.com/bindiff.html">BinDiff</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-041/">Silver Bullet #41: Fred Schneider</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-046/">Silver Bullet #46: David Rice</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/ioivcQEnya8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-062/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/215/0/silverbullet-062.mp3" length="43913344" type="audio/mpeg" />
		<itunes:duration>0:30:30</itunes:duration>
		<itunes:subtitle>
On the 62nd episode of The Silver Bullet Security Podcast, Gary chats with Halvar Flake (a.k.a. Thomas Dullien), founder of reverse engineering consultancy, Zynamics, which was recently purchased by Google. Gary and Halvar discuss the acquisition, [...]</itunes:subtitle>
		<itunes:summary>
On the 62nd episode of The Silver Bullet Security Podcast, Gary chats with Halvar Flake (a.k.a. Thomas Dullien), founder of reverse engineering consultancy, Zynamics, which was recently purchased by Google. Gary and Halvar discuss the acquisition, Zynamics’ product BinDiff, whether the “bad guys” are using code understanding tools (including decompilers) better than developers, static versus dynamic analysis, international politics meets computer security, and the growing complexity of malware. They close out with a discussion of music.

ADD / XOR / ROL – Halvar’s blog
@halvarflake
US Denies Entry (2007)
Cyber Warmongering and Influence Peddling (November 24, 2010)
Google’s purchase of Zynamics
BinDiff
Silver Bullet #41: Fred Schneider
Silver Bullet #46: David Rice
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/215/0/silverbullet-062.mp3" fileSize="43913344" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-062/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-062</feedburner:origLink></item>
		<item>
		<title>Show 061 – An Interview with Carl Landwehr</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/MkDnlx62hbQ/</link>
		<comments>http://www.cigital.com/silver-bullet/show-061/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 18:50:41 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=82</guid>
		<description><![CDATA[On the 61st episode of The Silver Bullet Security Podcast, Gary talks with Carl Landwehr, Director of Trustworthy Computing at the National Science Foundation and a Senior Research Scientist at the Institute for Systems Research within the University of Maryland. Gary and Carl discuss the most important changes in information security that have developed over [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Carl Landwehr" src="/wp-content/uploads/2011/04/clandwehr.png" style="padding-left: 7px" /></p>
<p>On the 61st episode of The Silver Bullet Security Podcast, Gary talks with Carl Landwehr, Director of Trustworthy Computing at the National Science Foundation and a Senior Research Scientist at the Institute for Systems Research within the University of Maryland. Gary and Carl discuss the most important changes in information security that have developed over the course of Carl&#8217;s career, the academic perspective of the state of commercial computer security, how to balance security and privacy, and the reason behind the leaking of government documents to Wikileaks. They close out the episode discussing books.</p>
<ul>
<li><a href="http://www.isr.umd.edu/faculty/gateways/landwehr.htm">Carl Landwehr</a></li>
<li><a href="http://www.nsf.gov/">National Science Foundation</a></li>
<li><a href="http://www.computer.org/security/"><em>IEEE Security &amp; Privacy Magazine</em></a></li>
<li><a href="http://www.cigital.com/silverbullet/show-046/">Silver Bullet #46: David Rice</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/MkDnlx62hbQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-061/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/214/0/silverbullet-061.mp3" length="39561216" type="audio/mpeg" />
		<itunes:duration>0:27:27</itunes:duration>
		<itunes:subtitle>
On the 61st episode of The Silver Bullet Security Podcast, Gary talks with Carl Landwehr, Director of Trustworthy Computing at the National Science Foundation and a Senior Research Scientist at the Institute for Systems Research within the Universi[...]</itunes:subtitle>
		<itunes:summary>
On the 61st episode of The Silver Bullet Security Podcast, Gary talks with Carl Landwehr, Director of Trustworthy Computing at the National Science Foundation and a Senior Research Scientist at the Institute for Systems Research within the University of Maryland. Gary and Carl discuss the most important changes in information security that have developed over the course of Carl’s career, the academic perspective of the state of commercial computer security, how to balance security and privacy, and the reason behind the leaking of government documents to Wikileaks. They close out the episode discussing books.

Carl Landwehr
National Science Foundation
IEEE Security &amp; Privacy Magazine
Silver Bullet #46: David Rice
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/214/0/silverbullet-061.mp3" fileSize="39561216" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-061/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-061</feedburner:origLink></item>
		<item>
		<title>Show 060 – An Interview with Neil Daswani</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Vfm8E30UhwA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-060/#comments</comments>
		<pubDate>Wed, 30 Mar 2011 15:51:23 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=79</guid>
		<description><![CDATA[On the 5th anniversary, 60th episode of The Silver Bullet Security Podcast, Gary talks with Neil Daswani, CTO and co-founder of Dasient. Gary and Neil discuss Neil&#8217;s previous work at Google and how the &#8220;start-up like&#8221; atmosphere at Google compares with an actual start-up. They also discuss bad ads (aka malvertising), Clickbot.A, the software security [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Neil Daswani" src="/wp-content/uploads/2011/03/ndaswani.png" style="padding-left: 7px" /></p>
<p>On the 5th anniversary, 60th episode of The Silver Bullet Security Podcast, Gary talks with Neil Daswani, CTO and co-founder of Dasient. Gary and Neil discuss Neil&#8217;s previous work at Google and how the &#8220;start-up like&#8221; atmosphere at Google compares with an actual start-up. They also discuss bad ads (aka malvertising), Clickbot.A, the software security related emphasis on testing at Google, and sushi in San Jose.</p>
<ul>
<li><a href="http://www.dasient.com/">Dasient</a></li>
<li><a href="http://www.neildaswani.com/">Neil Daswani</a></li>
<li><a href="http://blog.dasient.com/2011/03/dasient-q4-malware-update-significant.html">Dasient  Q4 2010 Malware Update</a></li>
<li><a href="http://www.darkreading.com/security/application-security/208803630/index.html">Certifiable</a>, McGraw on Software Security Certification for darkreading (May 9, 2007)</li>
<li><a href="http://www.dasient.com/resources/">Dasient Resource Center</a></li>
<li><a href="http://www.usenix.org/events/hotbots07/tech/full_papers/daswani/daswani.pdf">The  Anatomy of Clickbot.A</a> [PDF]</li>
<li><a href="http://scpd.stanford.edu/public/category/courseCategoryCertificateProfile.do?method=load&amp;certificateId=1145836#searchResults">Stanford Advanced Security Certification Program</a></li>
<li><a href="http://tomosushionline.com/">Tomo Sushi</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Vfm8E30UhwA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-060/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/213/0/silverbullet-060.mp3" length="42580096" type="audio/mpeg" />
		<itunes:duration>0:29:32</itunes:duration>
		<itunes:subtitle>
On the 5th anniversary, 60th episode of The Silver Bullet Security Podcast, Gary talks with Neil Daswani, CTO and co-founder of Dasient. Gary and Neil discuss Neil’s previous work at Google and how the “start-up like” atmosphere a[...]</itunes:subtitle>
		<itunes:summary>
On the 5th anniversary, 60th episode of The Silver Bullet Security Podcast, Gary talks with Neil Daswani, CTO and co-founder of Dasient. Gary and Neil discuss Neil’s previous work at Google and how the “start-up like” atmosphere at Google compares with an actual start-up. They also discuss bad ads (aka malvertising), Clickbot.A, the software security related emphasis on testing at Google, and sushi in San Jose.

Dasient
Neil Daswani
Dasient  Q4 2010 Malware Update
Certifiable, McGraw on Software Security Certification for darkreading (May 9, 2007)
Dasient Resource Center
The  Anatomy of Clickbot.A [PDF]
Stanford Advanced Security Certification Program
Tomo Sushi
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/213/0/silverbullet-060.mp3" fileSize="42580096" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-060/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-060</feedburner:origLink></item>
		<item>
		<title>Show 059 – An Interview with Ralph Langner</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/2gV8yP-Tz0E/</link>
		<comments>http://www.cigital.com/silver-bullet/show-059/#comments</comments>
		<pubDate>Fri, 25 Feb 2011 23:00:25 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=77</guid>
		<description><![CDATA[On the bonus-length 59th episode of The Silver Bullet Security Podcast, Gary chats with Ralph Langner, Founder and CEO of Langner Communications. Langer Communications is a German company specializing in control systems security. Ralph was the first to determine that Stuxnet is a directed cybersecurity attack against the kinds of Siemens control systems used to [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ralph Langner" src="/wp-content/uploads/2011/02/rlangner.png" style="padding-left: 7px" /></p>
<p>On the bonus-length 59th episode of The Silver Bullet Security Podcast, Gary chats with Ralph Langner, Founder and CEO of Langner Communications. Langer Communications is a German company specializing in control systems security. Ralph was the first to determine that Stuxnet is a directed cybersecurity attack against the kinds of Siemens control systems used to control nuclear centrifuges in Iran. Gary and Ralph discuss what&#8217;s involved in introducing the concept of cybersecurity to control systems engineers, how anti-virus vendors originally responded to the Stuxnet, as well as plenty of detailed technical info about the worm with an emphasis on its payload.</p>
<ul>
<li><a href="http://www.langner.com/">Langner Communications</a></li>
<li><a href="http://en.wikipedia.org/wiki/Stuxnet">Stuxnet</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1636983">Software [In]security: How to p0wn a Control System with Stuxnet</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1662328">Software [In]security: Cyber Warmongering and Influence Peddling</a></li>
<li><a href="http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html">Israeli Test on Worm Called Crucial in Iran Nuclear Delay</a> (<em>New York Times</em>)</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/2gV8yP-Tz0E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-059/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/212/0/silverbullet-059.mp3" length="60712960" type="audio/mpeg" />
		<itunes:duration>0:42:08</itunes:duration>
		<itunes:subtitle>
On the bonus-length 59th episode of The Silver Bullet Security Podcast, Gary chats with Ralph Langner, Founder and CEO of Langner Communications. Langer Communications is a German company specializing in control systems security. Ralph was the firs[...]</itunes:subtitle>
		<itunes:summary>
On the bonus-length 59th episode of The Silver Bullet Security Podcast, Gary chats with Ralph Langner, Founder and CEO of Langner Communications. Langer Communications is a German company specializing in control systems security. Ralph was the first to determine that Stuxnet is a directed cybersecurity attack against the kinds of Siemens control systems used to control nuclear centrifuges in Iran. Gary and Ralph discuss what’s involved in introducing the concept of cybersecurity to control systems engineers, how anti-virus vendors originally responded to the Stuxnet, as well as plenty of detailed technical info about the worm with an emphasis on its payload.

Langner Communications
Stuxnet
Software [In]security: How to p0wn a Control System with Stuxnet
Software [In]security: Cyber Warmongering and Influence Peddling
Israeli Test on Worm Called Crucial in Iran Nuclear Delay (New York Times)
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/212/0/silverbullet-059.mp3" fileSize="60712960" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-059/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-059</feedburner:origLink></item>
		<item>
		<title>New video: Dr. Gary McGraw chats with Dr. Carl Landwehr</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Gn2N3daJYS8/</link>
		<comments>http://www.cigital.com/silver-bullet/new-video-dr-gary-mcgraw-chats-with-dr-carl-landwehr/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 21:29:14 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=76</guid>
		<description><![CDATA[Silver Bullet is producing a series of short videos featuring members of the IEEE Security &#38; Privacy magazine editorial board. Our first video features outgoing Editor in Chief Carl Landwehr.]]></description>
				<content:encoded><![CDATA[<p>Silver Bullet is producing a series of short videos featuring members of the <em>IEEE Security &amp; Privacy</em> magazine editorial board.  Our first video features outgoing Editor in Chief Carl Landwehr.</p>
<p align="center"><iframe title="YouTube video player" width="500" height="311" src="http://www.youtube.com/embed/uwGwJIB95Pk" frameborder="0" allowfullscreen></iframe></p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Gn2N3daJYS8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/new-video-dr-gary-mcgraw-chats-with-dr-carl-landwehr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.cigital.com/silver-bullet/new-video-dr-gary-mcgraw-chats-with-dr-carl-landwehr/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=new-video-dr-gary-mcgraw-chats-with-dr-carl-landwehr</feedburner:origLink></item>
		<item>
		<title>Show 058 – An Interview with John Savage</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/fzSMyRAsoIM/</link>
		<comments>http://www.cigital.com/silver-bullet/show-058/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 19:32:05 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=74</guid>
		<description><![CDATA[On the 58th episode of The Silver Bullet Security Podcast, Gary talks with John Savage, professor of Computer Science at Brown University and Jefferson Science Fellow for the State Department. Gary and John discuss whether Wikileaks is a terrorist organization, if the use of a cyber-weapon like Stuxnet can be a morally justified act, and [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="John Savage" src="http://www.cigital.com/silverbullet/jsavage-125.png" style="padding-left: 7px" /></p>
<p>On the 58th episode of The Silver Bullet Security Podcast, Gary talks with John Savage, professor of Computer Science at Brown University and Jefferson Science Fellow for the State Department.  Gary and John discuss whether Wikileaks is a terrorist organization, if the use of a cyber-weapon like Stuxnet can be a morally justified act, and the implications of computational nanotechnology on cybersecurity.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-058-jsavage.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cs.brown.edu/~jes/">John Savage at Brown University</a></li>
<li><a href="http://sites.nationalacademies.org/PGA/Jefferson/PGA_052045">Jefferson Science Fellow: Dr. John Savage</a></li>
<li><a href="http://en.wikipedia.org/wiki/International_Telecommunication_Union">International Telecommunication Union</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-049/">Silver Bullet #49: Ivan Arce</a></li>
<li><a href="http://www.amazon.com/Girl-Dragon-Tattoo-Stieg-Larsson/dp/0307269752"><em>The Girl with the Dragon Tattoo</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Homomorphic_encryption">Homomorphic Encryption</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/fzSMyRAsoIM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-058/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/210/0/silverbullet-058.mp3" length="42365056" type="audio/mpeg" />
		<itunes:duration>0:29:23</itunes:duration>
		<itunes:subtitle>
On the 58th episode of The Silver Bullet Security Podcast, Gary talks with John Savage, professor of Computer Science at Brown University and Jefferson Science Fellow for the State Department.  Gary and John discuss whether Wikileaks is a terrorist[...]</itunes:subtitle>
		<itunes:summary>
On the 58th episode of The Silver Bullet Security Podcast, Gary talks with John Savage, professor of Computer Science at Brown University and Jefferson Science Fellow for the State Department.  Gary and John discuss whether Wikileaks is a terrorist organization, if the use of a cyber-weapon like Stuxnet can be a morally justified act, and the implications of computational nanotechnology on cybersecurity.

Transcript of this episode [PDF]
John Savage at Brown University
Jefferson Science Fellow: Dr. John Savage
International Telecommunication Union
Silver Bullet #49: Ivan Arce
The Girl with the Dragon Tattoo
Homomorphic Encryption
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/210/0/silverbullet-058.mp3" fileSize="42365056" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-058/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-058</feedburner:origLink></item>
		<item>
		<title>Show 057 – An Interview with Elinor Mills</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/3y9-bVT8xk4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-057/#comments</comments>
		<pubDate>Thu, 23 Dec 2010 19:10:09 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=71</guid>
		<description><![CDATA[On the 57th Silver Bullet Security Podcast, Gary talks with Elinor Mills, senior writer at CNET&#8217;s news.com. At CNET, Elinor covers Internet technology and security. Gary and Elinor discuss how writing about technology for news organizations has changed over the last 20 years, how technology adoption in Portugal differs from the States, WikiLeaks and the [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Elinor Mills" src="http://www.cigital.com/silverbullet/emills-100.png" style="padding-left: 7px" /></p>
<p>On the 57th Silver Bullet Security Podcast, Gary talks with Elinor Mills, senior writer at CNET&#8217;s news.com. At CNET, Elinor covers Internet technology and security. Gary and Elinor discuss how writing about technology for news organizations has changed over the last 20 years, how technology adoption in Portugal differs from the States, WikiLeaks and the First Amendment, avoiding FUD when covering a breaking news story about security, and Burning Man. They close the episode with a brief discussion of Elinor&#8217;s favorite books.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-057-emills.pdf">Transcript of this episode</a> [pdf]</li>
<li><a href="http://www.cnet.com/profile/elinormills/">Elinor at CNET</a></li>
<li><a href="http://news.cnet.com/insecurity-complex/">Insecurity Complex</a> &#8211; Elinor&#8217;s blog</li>
<li><a href="http://twitter.com/elinormills">Elinor on Twitter</a></li>
<li><a href="http://www.dramainthedesert.com/"><em>Drama in the Desert: Sights and Sounds of Burning Man</em></a> / <a href="http://www.raisedbarnpress.com/">Raised Barn Press</a></li>
<li><a href="http://news.cnet.com/8301-27080_3-20024210-245.html?tag=cnetRiver">Demilitarizing cybersecurity (Q&amp;A)</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1636983">How to p0wn a Control System with Stuxnet</a></li>
<li><a href="http://www.intelius.com/">Intellus</a></li>
<li><a href="http://www.reputationdefender.com/">Reputation Defender</a></li>
<li><a href="http://www.eatinganimals.com/"><em>Eating Animals</em></a></li>
<li><a href="http://www.amazon.com/Corrections-Novel-Jonathan-Franzen/dp/0312421273"><em>The Corrections</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/3y9-bVT8xk4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-057/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/209/0/silverbullet-057.mp3" length="44368000" type="audio/mpeg" />
		<itunes:duration>0:30:47</itunes:duration>
		<itunes:subtitle>
On the 57th Silver Bullet Security Podcast, Gary talks with Elinor Mills, senior writer at CNET’s news.com. At CNET, Elinor covers Internet technology and security. Gary and Elinor discuss how writing about technology for news organizations h[...]</itunes:subtitle>
		<itunes:summary>
On the 57th Silver Bullet Security Podcast, Gary talks with Elinor Mills, senior writer at CNET’s news.com. At CNET, Elinor covers Internet technology and security. Gary and Elinor discuss how writing about technology for news organizations has changed over the last 20 years, how technology adoption in Portugal differs from the States, WikiLeaks and the First Amendment, avoiding FUD when covering a breaking news story about security, and Burning Man. They close the episode with a brief discussion of Elinor’s favorite books.

Transcript of this episode [pdf]
Elinor at CNET
Insecurity Complex – Elinor’s blog
Elinor on Twitter
Drama in the Desert: Sights and Sounds of Burning Man / Raised Barn Press
Demilitarizing cybersecurity (Q&amp;A)
How to p0wn a Control System with Stuxnet
Intellus
Reputation Defender
Eating Animals
The Corrections
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/209/0/silverbullet-057.mp3" fileSize="44368000" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-057/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-057</feedburner:origLink></item>
		<item>
		<title>Show 056 – An Interview with Sammy Migues</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/5MTI_w6L17Q/</link>
		<comments>http://www.cigital.com/silver-bullet/show-056/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 17:32:05 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=70</guid>
		<description><![CDATA[On the 56th Silver Bullet Security Podcast, Gary sits down with Sammy Migues, Principal and Director of Knowledge Management at Cigital. Gary and Sammy discuss how Sammy&#8217;s southern upbringing affects his approach to security, his experience speaking to the National Rural Electric Cooperative Association, the advantages of defensive programming versus &#8220;the bug parade&#8221; and the [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Sammy Migues" src="http://www.cigital.com/silverbullet/smigues-125.png" style="padding-left: 7px" /></p>
<p>On the 56th Silver Bullet Security Podcast, Gary sits down with Sammy Migues, Principal and Director of Knowledge Management at Cigital. Gary and Sammy discuss how Sammy&#8217;s southern upbringing affects his approach to security, his experience speaking to the National Rural Electric Cooperative Association, the advantages of defensive programming versus &#8220;the bug parade&#8221; and the BSIMM. They close the show out discussing bourbon. As a bonus, Sammy may be the first person to ever use the phrase &#8220;flips my bogometer&#8221; on a podcast.</p>
<ul>
<li><a href="http://www.cigital.com/about/team/thoughtleaders/sammy-migues.php">Sammy at Cigital</a></li>
<li><a href="http://www.cigital.com/justiceleague/about/#sammy">Sammy on Justice League</a></li>
<li><a href="http://www.cigital.com/justiceleague/2010/03/24/at-the-nreca-conference/">At the NRECA conference</a> &#8211; Sammy&#8217;s blog post (with video) about his NRECA talk.</li>
<li><a href="http://www.cigital.com/justiceleague/2010/11/12/bsimm-community-conference/">BSIMM Community Conference</a></li>
<li><a href="http://bsimm.com/">BSIMM</a></li>
<li><a href="http://en.wikipedia.org/wiki/Trusted_Computer_System_Evaluation_Criteria"><em>Trusted Computer System Evaluation Criteria</em></a> &#8211; aka &#8220;The Orange Book&#8221;</li>
<li><a href="http://www.greatbourbon.com/antiquecollection.aspx">&#8220;The Antique Collection&#8221; bourbon</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/5MTI_w6L17Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-056/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/208/0/silverbullet-056.mp3" length="38283392" type="audio/mpeg" />
		<itunes:duration>0:26:33</itunes:duration>
		<itunes:subtitle>
On the 56th Silver Bullet Security Podcast, Gary sits down with Sammy Migues, Principal and Director of Knowledge Management at Cigital. Gary and Sammy discuss how Sammy’s southern upbringing affects his approach to security, his experience s[...]</itunes:subtitle>
		<itunes:summary>
On the 56th Silver Bullet Security Podcast, Gary sits down with Sammy Migues, Principal and Director of Knowledge Management at Cigital. Gary and Sammy discuss how Sammy’s southern upbringing affects his approach to security, his experience speaking to the National Rural Electric Cooperative Association, the advantages of defensive programming versus “the bug parade” and the BSIMM. They close the show out discussing bourbon. As a bonus, Sammy may be the first person to ever use the phrase “flips my bogometer” on a podcast.

Sammy at Cigital
Sammy on Justice League
At the NRECA conference – Sammy’s blog post (with video) about his NRECA talk.
BSIMM Community Conference
BSIMM
Trusted Computer System Evaluation Criteria – aka “The Orange Book”
“The Antique Collection” bourbon
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/208/0/silverbullet-056.mp3" fileSize="38283392" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-056/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-056</feedburner:origLink></item>
		<item>
		<title>Show 055 – An Interview with Deborah Frincke</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/AcGtvXVPq34/</link>
		<comments>http://www.cigital.com/silver-bullet/show-055/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 19:03:29 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=69</guid>
		<description><![CDATA[On the 55th Silver Bullet Security Podcast, Gary chats with Deborah Frincke, Chief Scientist, Cybersecurity at Pacific Northwest National Laboratory. Gary and Deb discuss the differences between being a professor and a researcher, whether a professional certification is better than an academic degree, and how a woman&#8217;s reasons for getting into the computer security field [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Deborah Frincke" src="/silver-bullet-files/dfrincke-125.png" style="padding-left: 7px" /></p>
<p>On the 55th Silver Bullet Security Podcast, Gary chats with Deborah Frincke, Chief Scientist, Cybersecurity at Pacific Northwest National Laboratory.  Gary and Deb discuss the differences between being a professor and a researcher, whether a professional certification is better than an academic degree, and how a woman&#8217;s reasons for getting into the computer security field may differ from a man&#8217;s.  They close out the episode by talking flowers.</p>
<ul>
<li><a href="http://www.twitter.com/frincke">Deborah Frincke on Twitter</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1648912">Software [In]security: Technology Transfer</a>, informIT</li>
<li><a href="http://www.pnl.gov/">Pacific Northwest National Labs</a></li>
<li><a href="http://www.uidaho.edu/engr/cs/">University of Idaho Computer Science</a></li>
<li><a href="http://www.uidaho.edu/mrci/csds">University of Idaho Center for Secure &amp; Dependable Systems</a></li>
<li><a href="http://www.nsa.gov/ia/academic_outreach/nat_cae/index.shtml">NSA National Centers of Academic Excellence</a></li>
<li><a href="http://en.wikipedia.org/wiki/Orchidaceae">Orchidaceae</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/AcGtvXVPq34" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-055/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/207/0/silverbullet-055.mp3" length="32100480" type="audio/mpeg" />
		<itunes:duration>0:22:16</itunes:duration>
		<itunes:subtitle>
On the 55th Silver Bullet Security Podcast, Gary chats with Deborah Frincke, Chief Scientist, Cybersecurity at Pacific Northwest National Laboratory.  Gary and Deb discuss the differences between being a professor and a researcher, whether a profes[...]</itunes:subtitle>
		<itunes:summary>
On the 55th Silver Bullet Security Podcast, Gary chats with Deborah Frincke, Chief Scientist, Cybersecurity at Pacific Northwest National Laboratory.  Gary and Deb discuss the differences between being a professor and a researcher, whether a professional certification is better than an academic degree, and how a woman’s reasons for getting into the computer security field may differ from a man’s.  They close out the episode by talking flowers.

Deborah Frincke on Twitter
Software [In]security: Technology Transfer, informIT
Pacific Northwest National Labs
University of Idaho Computer Science
University of Idaho Center for Secure &amp; Dependable Systems
NSA National Centers of Academic Excellence
Orchidaceae
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/207/0/silverbullet-055.mp3" fileSize="32100480" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-055/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-055</feedburner:origLink></item>
		<item>
		<title>Show 054 – An Interview with Marc Donner</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/ZEb36Uq_vQw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-054/#comments</comments>
		<pubDate>Mon, 27 Sep 2010 20:28:37 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=67</guid>
		<description><![CDATA[On the 54th Silver Bullet Security Podcast, Gary talks with Dr. Marc Donner, engineering director for Google Health and Google Finance. Gary and Marc discuss science-fiction books from the last decade, why Americans like to talk about cyberwarfare, and security issues and privacy concerns as related to Google Health initiatives. They finish up their discussion [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Marc Donner" src="http://www.cigital.com/silverbullet/mdonner-125.png" style="padding-left: 7px" /></p>
<p>On the 54th Silver Bullet Security Podcast, Gary talks with Dr. Marc Donner, engineering director for Google Health and Google Finance.  Gary and Marc discuss science-fiction books from the last decade, why Americans like to talk about cyberwarfare, and security issues and privacy concerns as related to Google Health initiatives.  They finish up their discussion by talking about the <a href="http://www.cs.wustl.edu/~cytron/FAQ/Syrup/donner.html">Syrup Wars</a>.</p>
<ul>
<li><a href="http://www.google.com/profiles/marc.donner">Marc Donner</a></li>
<li><a href="http://nygeek.wordpress.com/">hacks from the bleeding edge</a> (Marc&#8217;s blog)</li>
<li><a href="http://csdl2.computer.org/dl/mags/sp/2003/01/j1063.htm">AI Bites Man?</a> (and <a href="http://nygeek.wordpress.com/biblio-tech-writings-on-sf-from-ieee-security-privacy/">the rest of the Biblio Tech archives</a>)</li>
<li><a href="http://www.amazon.com/Iron-Sunrise-Singularity-Charles-Stross/dp/0441012965"><em>Iron Sunrise</em></a>, <a href="http://www.amazon.com/gp/product/0441011799/ref=pd_lpo_k2_dp_sr_1?pf_rd_p=486539851&amp;pf_rd_s=lpo-top-stripe-1&amp;pf_rd_t=201&amp;pf_rd_i=0441012965&amp;pf_rd_m=ATVPDKIKX0DER&amp;pf_rd_r=0W34X7AEEVA9ASFW61FH"><em>Singularity Sky</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/ZEb36Uq_vQw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-054/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/206/0/silverbullet-054.mp3" length="40218752" type="audio/mpeg" />
		<itunes:duration>0:27:54</itunes:duration>
		<itunes:subtitle>
On the 54th Silver Bullet Security Podcast, Gary talks with Dr. Marc Donner, engineering director for Google Health and Google Finance.  Gary and Marc discuss science-fiction books from the last decade, why Americans like to talk about cyberwarfare[...]</itunes:subtitle>
		<itunes:summary>
On the 54th Silver Bullet Security Podcast, Gary talks with Dr. Marc Donner, engineering director for Google Health and Google Finance.  Gary and Marc discuss science-fiction books from the last decade, why Americans like to talk about cyberwarfare, and security issues and privacy concerns as related to Google Health initiatives.  They finish up their discussion by talking about the Syrup Wars.

Marc Donner
hacks from the bleeding edge (Marc’s blog)
AI Bites Man? (and the rest of the Biblio Tech archives)
Iron Sunrise, Singularity Sky
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/206/0/silverbullet-054.mp3" fileSize="40218752" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-054/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-054</feedburner:origLink></item>
		<item>
		<title>Show 053 – An Interview with Richard Bejtlich</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/HlLWxtQvucE/</link>
		<comments>http://www.cigital.com/silver-bullet/show-053/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 20:44:23 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=65</guid>
		<description><![CDATA[On the 53rd episode of The Silver Bullet Security Podcast, Gary interviews Richard Bejtlich, Director of Incident Response for General Electric and Principal Technologist for GE&#8217;s Global Infrastructure Services division. They discuss whether it&#8217;s better to look for known problems or anomalies when performing network security monitoring, how to explain security incidents to &#8220;business guys,&#8221; [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Richard Bejtlich" src="http://www.cigital.com/silverbullet/rbejtlich-125.png" style="padding-left: 7px" /></p>
<p>On the 53rd episode of The Silver Bullet Security Podcast, Gary interviews Richard Bejtlich, Director of Incident Response for General Electric and Principal Technologist for GE&#8217;s Global Infrastructure Services division.  They discuss whether it&#8217;s better to look for known problems or anomalies when performing network security monitoring, how to explain security incidents to &#8220;business guys,&#8221; the notion of “building visibility in,” and the difference between working as an independent consultant in a very small shop and working in a large corporation.</p>
<ul>
<li><a href="http://taosecurity.blogspot.com/">TaoSecurity blog</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-019/">Silver Bullet #19: Mikko Hyppönen</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-041/">Silver Bullet #41: Fred Schneider</a></li>
<li><a href="http://www.vizsec2010.org/speakers">VizSec 2010 keynote</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/HlLWxtQvucE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-053/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/205/0/silverbullet-053.mp3" length="45916288" type="audio/mpeg" />
		<itunes:duration>0:31:51</itunes:duration>
		<itunes:subtitle>
On the 53rd episode of The Silver Bullet Security Podcast, Gary interviews Richard Bejtlich, Director of Incident Response for General Electric and Principal Technologist for GE’s Global Infrastructure Services division.  They discuss whether[...]</itunes:subtitle>
		<itunes:summary>
On the 53rd episode of The Silver Bullet Security Podcast, Gary interviews Richard Bejtlich, Director of Incident Response for General Electric and Principal Technologist for GE’s Global Infrastructure Services division.  They discuss whether it’s better to look for known problems or anomalies when performing network security monitoring, how to explain security incidents to “business guys,” the notion of “building visibility in,” and the difference between working as an independent consultant in a very small shop and working in a large corporation.

TaoSecurity blog
Silver Bullet #19: Mikko Hyppönen
Silver Bullet #41: Fred Schneider
VizSec 2010 keynote
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/205/0/silverbullet-053.mp3" fileSize="45916288" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-053/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-053</feedburner:origLink></item>
		<item>
		<title>Show 052 – An Interview with Paul Kocher</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Xojgpp8NxH4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-052/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 14:18:24 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=63</guid>
		<description><![CDATA[On the 52nd episode of The Silver Bullet Security Podcast, Gary chats with Paul Kocher, President and Chief Scientist of Cryptography Research. Gary and Paul discuss the first system that Paul ever broke, whether engineers and architects need to think like the &#8220;bad guys&#8221; or not, the decision to put content protection on Blu-Ray discs [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Paul Kocher" src="http://www.cigital.com/silverbullet/pkocher-125.png" style="padding-left: 7px" /></p>
<p>On the 52nd episode of The Silver Bullet Security Podcast, Gary chats with Paul Kocher, President and Chief Scientist of Cryptography Research.  Gary and Paul discuss the first system that Paul ever broke, whether engineers and architects need to think like the &#8220;bad guys&#8221; or not, the decision to put content protection on Blu-Ray discs rather than the player, and whether P=NP.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-052-kocher.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cryptography.com/">Cryptography Research</a> (<a href="http://www.cryptography.com/company/profiles/paul-kocher.html">Paul @ Cryptography Research</a>)</li>
<li><a href="http://www.wired.com/threatlevel/2008/02/how-crypto-won/">How Crypto Won the DVD War</a></li>
<li><a href="http://www.rovicorp.com/company/newscenter/pressreleases/1434_7711.htm">Macrovision to Acquire Blu-ray Disc Security Technology from Cryptography Research, Inc.</a> (press release)</li>
<li><a href="http://en.wikipedia.org/wiki/P_versus_NP_problem">P versus NP problem</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Xojgpp8NxH4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-052/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/204/0/silverbullet-052.mp3" length="39264384" type="audio/mpeg" />
		<itunes:duration>0:27:14</itunes:duration>
		<itunes:subtitle>
On the 52nd episode of The Silver Bullet Security Podcast, Gary chats with Paul Kocher, President and Chief Scientist of Cryptography Research.  Gary and Paul discuss the first system that Paul ever broke, whether engineers and architects need to t[...]</itunes:subtitle>
		<itunes:summary>
On the 52nd episode of The Silver Bullet Security Podcast, Gary chats with Paul Kocher, President and Chief Scientist of Cryptography Research.  Gary and Paul discuss the first system that Paul ever broke, whether engineers and architects need to think like the “bad guys” or not, the decision to put content protection on Blu-Ray discs rather than the player, and whether P=NP.

Transcript of this episode [PDF]
Cryptography Research (Paul @ Cryptography Research)
How Crypto Won the DVD War
Macrovision to Acquire Blu-ray Disc Security Technology from Cryptography Research, Inc. (press release)
P versus NP problem
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/204/0/silverbullet-052.mp3" fileSize="39264384" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-052/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-052</feedburner:origLink></item>
		<item>
		<title>Show 051 – An Interview with Anup Ghosh</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/zN9_ValTg0Q/</link>
		<comments>http://www.cigital.com/silver-bullet/show-051/#comments</comments>
		<pubDate>Fri, 25 Jun 2010 17:29:09 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=62</guid>
		<description><![CDATA[On the 51st episode of The Silver Bullet Security Podcast, Gary talks with former co-worker Dr. Anup Ghosh. Anup has authored three books on e-commerce security and over 40 peer-reviewed articles and is founder and chief scientist of Invincea. Gary and Anup discuss the difference between working in a startup and in goverment research, why [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Anup Ghosh" src="http://www.cigital.com/silverbullet/aghosh-125.png" style="padding-left: 7px" /></p>
<p>On the 51st episode of The Silver Bullet Security Podcast, Gary talks with former co-worker Dr. Anup Ghosh.  Anup has authored three books on e-commerce security and over 40 peer-reviewed articles and is founder and chief scientist of Invincea.  Gary and Anup discuss the difference between working in a startup and in goverment research, why antivirus doesn&#8217;t work against the ZeuS botnet and what businesses should do to protect themselves, and the relevance of the desktop in the future of computing.  They close out with a discussion about Anup&#8217;s favorite newspapers and recent books.</p>
<ul>
<li><a href="http://www.invincea.com/">Invincea</a></li>
<li><a href="http://www.amazon.com/gp/search/ref=sr_nr_p_n_feature_browse-b_0?rh=i%3Astripbooks%2Cn%3A%211000%2Cp_27%3AAnup+K.+Ghosh%2Cp_n_feature_browse-bin%3A618083011&amp;bbn=1000&amp;sort=relevancerank&amp;ie=UTF8&amp;qid=1277406212&amp;rnid=618072011">Anup&#8217;s books on Amazon</a></li>
<li><a href="http://www.atp.nist.gov/">Advanced Technology Program</a></li>
<li><a href="http://www.antisource.com/article.php/zeus-botnet-summary">ZeuS botnet summary</a></li>
<li><a href="http://www.invincea.com/wordpress/?p=738">Why Patching Isn’t Enough</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/zN9_ValTg0Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-051/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/203/0/silverbullet-051.mp3" length="47690861" type="audio/mpeg" />
		<itunes:duration>0:33:07</itunes:duration>
		<itunes:subtitle>
On the 51st episode of The Silver Bullet Security Podcast, Gary talks with former co-worker Dr. Anup Ghosh.  Anup has authored three books on e-commerce security and over 40 peer-reviewed articles and is founder and chief scientist of Invincea.  Ga[...]</itunes:subtitle>
		<itunes:summary>
On the 51st episode of The Silver Bullet Security Podcast, Gary talks with former co-worker Dr. Anup Ghosh.  Anup has authored three books on e-commerce security and over 40 peer-reviewed articles and is founder and chief scientist of Invincea.  Gary and Anup discuss the difference between working in a startup and in goverment research, why antivirus doesn’t work against the ZeuS botnet and what businesses should do to protect themselves, and the relevance of the desktop in the future of computing.  They close out with a discussion about Anup’s favorite newspapers and recent books.

Invincea
Anup’s books on Amazon
Advanced Technology Program
ZeuS botnet summary
Why Patching Isn’t Enough
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/203/0/silverbullet-051.mp3" fileSize="47690861" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-051/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-051</feedburner:origLink></item>
		<item>
		<title>Show 050 – An Interview with Richard Clarke</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/TFMIbXf_SQ4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-050/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 19:01:02 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=61</guid>
		<description><![CDATA[On the landmark 50th episode of Silver Bullet, Gary talks with Richard A. Clarke. Richard Clarke is an internationally-recognized expert on security, including homeland security, national security, cyber security, and counterterrorism. Gary and Dick discuss what needs to change in order for the United States to focus more attention on defense against cyber war (as [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.cigital.com/silver-bullet/show-050/rclarke/" rel="attachment wp-att-2903"><img class="alignright  wp-image-2903" title="rclarke" src="http://www.cigital.com/wp-content/uploads/2010/06/rclarke.jpg" alt="" width="112" height="141" /></a>On the landmark 50th episode of Silver Bullet, Gary talks with Richard A. Clarke. Richard Clarke is an internationally-recognized expert on security, including homeland security, national security, cyber security, and counterterrorism. Gary and Dick discuss what needs to change in order for the United States to focus more attention on defense against cyber war (as opposed to offense). They also discuss the importance of software security in preventing cyber crime and cyber war, network scanning as a part of Dick&#8217;s &#8220;Defensive Triad,&#8221; and balancing cybersecurity against individual liberty. We also uncover whether being a guest on Silver Bullet is more stressful than being on <em>The Colbert Report</em>.</p>
<p>This special edition of Silver Bullet was also captured on video. View the video below (for those on feed readers, go to <a href="http://www.cigital.com/silverbullet/show-050/">this episode&#8217;s page</a> for the video):</p>
<div align="center"><iframe src="http://www.youtube.com/embed/videoseries?list=PLE8B0493CB85431CB&amp;hl=en_US" frameborder="0" width="560" height="315"></iframe></div>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-050-rclarke.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.richardaclarke.net/">Richard A. Clarke</a></li>
<li><a><em>Cyber War</em></a></li>
<li><a href="http://www.9-11commission.gov/report/911Report.pdf">9/11 Commission Report</a></li>
<li><a href="http://www.computerworld.com/s/article/9176566/What_if_the_smart_grid_has_stupid_security">What if the smart grid has stupid security?</a></li>
<li>Select TV appearances: <a href="http://www.thedailyshow.com/watch/thu-may-29-2008/richard-clarke">The Daily Show</a> (2008) / <a href="http://www.colbertnation.com/the-colbert-report-videos/80961/january-17-2007/richard-clarke">The Colbert Report</a> (2007) / <a href="http://www.colbertnation.com/the-colbert-report-videos/35756/december-01-2005/richard-clarke">The Colbert Report</a> (2005) / <a href="http://www.cbsnews.com/stories/2004/03/19/60minutes/main607356.shtml">60 Minutes</a> (2004)</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/TFMIbXf_SQ4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-050/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/202/0/silverbullet-050.mp3" length="48566400" type="audio/mpeg" />
		<itunes:duration>0:33:42</itunes:duration>
		<itunes:subtitle>On the landmark 50th episode of Silver Bullet, Gary talks with Richard A. Clarke. Richard Clarke is an internationally-recognized expert on security, including homeland security, national security, cyber security, and counterterrorism. Gary and Dick[...]</itunes:subtitle>
		<itunes:summary>On the landmark 50th episode of Silver Bullet, Gary talks with Richard A. Clarke. Richard Clarke is an internationally-recognized expert on security, including homeland security, national security, cyber security, and counterterrorism. Gary and Dick discuss what needs to change in order for the United States to focus more attention on defense against cyber war (as opposed to offense). They also discuss the importance of software security in preventing cyber crime and cyber war, network scanning as a part of Dick’s “Defensive Triad,” and balancing cybersecurity against individual liberty. We also uncover whether being a guest on Silver Bullet is more stressful than being on The Colbert Report.
This special edition of Silver Bullet was also captured on video. View the video below (for those on feed readers, go to this episode’s page for the video):


Transcript of this episode [PDF]
Richard A. Clarke
Cyber War
9/11 Commission Report
What if the smart grid has stupid security?
Select TV appearances: The Daily Show (2008) / The Colbert Report (2007) / The Colbert Report (2005) / 60 Minutes (2004)
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
		<enclosure url="http://www.cigital.com/silverbullet/videos/silverbullet-050.flv" length="92792089" type="video/x-flv" />
		<enclosure url="http://www.cigital.com/silverbullet/videos/silverbullet-050.flv" length="92792089" type="video/x-flv" />
	<media:content url="http://www.cigital.com/podpress_trac/feed/202/0/silverbullet-050.mp3" fileSize="48566400" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-050/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-050</feedburner:origLink></item>
		<item>
		<title>Show 049 – An Interview with Ivan Arce</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/93q7daaNB0g/</link>
		<comments>http://www.cigital.com/silver-bullet/show-049/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 14:01:32 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=60</guid>
		<description><![CDATA[On the 49th episode of The Silver Bullet Security Podcast, Gary talks with Ivan Arce, co-founder and CTO of Core Security Technologies. Gary and Ivan discuss whether teaching builders to think like attackers is worthwhile, how living in Argentina both helps and hinders a career in computer security, the current state of embedded systems attacks, [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ivan Arce" src="http://www.cigital.com/silverbullet/iarce-125.png" style="padding-left: 7px" /></p>
<p>On the 49th episode of The Silver Bullet Security Podcast, Gary talks with Ivan Arce, co-founder and CTO of Core Security Technologies.  Gary and Ivan discuss whether teaching builders to think like attackers is worthwhile, how living in Argentina both helps and hinders a career in computer security, the current state of embedded systems attacks, and Ivan&#8217;s ongoing disagreement with Microsoft about Virtual PC vulnerabilities. They close things out with a discussion of science fiction books and whether scotch trumps bourbon.</p>
<ul>
<li><a href="http://www.coresecurity.com/">Core Security Technologies</a></li>
<li><a href="http://www.coresecurity.com/content/management-team#ivan">Ivan @ Core Security Technologies</a></li>
<li><a href="http://blogs.csoonline.com/blog/ivan_arce">Attack Points blog</a> (CSO Online)</li>
<li><a href="http://blog.coresecurity.com/?author=16">Ivan on the Core Security Technologies&#8217; blog</a></li>
<li><a href="http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug">Security vulnerability in Microsoft’s Virtual PC</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1588145">Assume Nothing: Is Microsoft Forgetting a Crucial Security Lesson?</a></li>
<li><a href="http://www.jus.uio.no/sisu/accelerando.charles_stross/sisu_manifest.html">SiSU manifest of document filetypes and metadata</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/93q7daaNB0g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-049/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/201/0/silverbullet-049.mp3" length="52990080" type="audio/mpeg" />
		<itunes:duration>0:36:47</itunes:duration>
		<itunes:subtitle>
On the 49th episode of The Silver Bullet Security Podcast, Gary talks with Ivan Arce, co-founder and CTO of Core Security Technologies.  Gary and Ivan discuss whether teaching builders to think like attackers is worthwhile, how living in Argentina [...]</itunes:subtitle>
		<itunes:summary>
On the 49th episode of The Silver Bullet Security Podcast, Gary talks with Ivan Arce, co-founder and CTO of Core Security Technologies.  Gary and Ivan discuss whether teaching builders to think like attackers is worthwhile, how living in Argentina both helps and hinders a career in computer security, the current state of embedded systems attacks, and Ivan’s ongoing disagreement with Microsoft about Virtual PC vulnerabilities. They close things out with a discussion of science fiction books and whether scotch trumps bourbon.

Core Security Technologies
Ivan @ Core Security Technologies
Attack Points blog (CSO Online)
Ivan on the Core Security Technologies’ blog
Security vulnerability in Microsoft’s Virtual PC
Assume Nothing: Is Microsoft Forgetting a Crucial Security Lesson?
SiSU manifest of document filetypes and metadata
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/201/0/silverbullet-049.mp3" fileSize="52990080" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-049/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-049</feedburner:origLink></item>
		<item>
		<title>Show 048 – An Interview with Andrew Jaquith</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/GBBEzJO8RM8/</link>
		<comments>http://www.cigital.com/silver-bullet/show-048/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 15:29:08 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=59</guid>
		<description><![CDATA[On the 48th episode of The Silver Bullet Security Podcast, Gary interviews Andrew Jaquith, senior analyst at Forrester. Gary and Andy discuss how security has become overrun by compliance in the biggest change to corporate security in 15 years, the battle between social networking technology use in the workplace (think Twitter, Facebook, AIM&#8230;) and security, [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Andrew Jaquith" src="http://www.cigital.com/silverbullet/ajaquith-125.png" style="padding-left: 7px" /></p>
<p>On the 48th episode of The Silver Bullet Security Podcast, Gary interviews Andrew Jaquith, senior  analyst at Forrester.  Gary and Andy discuss how security has become overrun by compliance in the biggest change to corporate security in 15 years, the battle between social networking technology use in the workplace (think Twitter, Facebook, AIM&#8230;) and security, security metrics (or lack of such), and Andy&#8217;s latest musical find.</p>
<ul>
<li><a href="http://www.forrester.com/rb/analyst/andrew_jaquith">Andrew Jaquith</a></li>
<li><a href="http://twitter.com/ARJ">Andy on Twitter</a></li>
<li><a href="http://www.forrester.com/go?docid=55857">Data Security Predictions For 2010</a> (December 02, 2009)</li>
<li><a href="http://www.forrester.com/go?docid=55716">Know Your Code: How Static Analysis Tools Make Applications More Secure</a> (November 20, 2009)</li>
<li><a href="http://bsi-mm.com">BSIMM</a></li>
<li><a href="http://en.wikipedia.org/wiki/@stake">@stake</a></li>
<li><a href="http://www.securitymetrics.org/content/Wiki.jsp">Securitymetrics.org</a></li>
<li><a href="http://www.amazon.com/Security-Metrics-Replacing-Uncertainty-Doubt/dp/0321349989"><em>Security Metrics: Replacing Fear, Uncertainty, and Doubt</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/S/MIME">S/MIME</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-026/">Silver Bullet #26: Adam Shostack</a></li>
<li><a href="http://www.youtube.com/watch?v=vV0KmOYfomM">Moby: &#8220;Southside (feat. Gwen Stefani)&#8221;</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/GBBEzJO8RM8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-048/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/200/0/silverbullet-048.mp3" length="43982976" type="audio/mpeg" />
		<itunes:duration>0:30:32</itunes:duration>
		<itunes:subtitle>
On the 48th episode of The Silver Bullet Security Podcast, Gary interviews Andrew Jaquith, senior  analyst at Forrester.  Gary and Andy discuss how security has become overrun by compliance in the biggest change to corporate security in 15 years, t[...]</itunes:subtitle>
		<itunes:summary>
On the 48th episode of The Silver Bullet Security Podcast, Gary interviews Andrew Jaquith, senior  analyst at Forrester.  Gary and Andy discuss how security has become overrun by compliance in the biggest change to corporate security in 15 years, the battle between social networking technology use in the workplace (think Twitter, Facebook, AIM…) and security, security metrics (or lack of such), and Andy’s latest musical find.

Andrew Jaquith
Andy on Twitter
Data Security Predictions For 2010 (December 02, 2009)
Know Your Code: How Static Analysis Tools Make Applications More Secure (November 20, 2009)
BSIMM
@stake
Securitymetrics.org
Security Metrics: Replacing Fear, Uncertainty, and Doubt
S/MIME
Silver Bullet #26: Adam Shostack
Moby: “Southside (feat. Gwen Stefani)”
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/200/0/silverbullet-048.mp3" fileSize="43982976" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-048/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-048</feedburner:origLink></item>
		<item>
		<title>Show 047 – An Interview with Greg Morrisett</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/5wY0uQ9dVEI/</link>
		<comments>http://www.cigital.com/silver-bullet/show-047/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 16:43:13 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=58</guid>
		<description><![CDATA[On the 47th episode of The Silver Bullet Security Podcast, Gary calls in from Leuven, Belgium to chat with childhood friend and security expert Greg Morrisett. Greg is the Allen B. Cutting Professor of Computer Science and Associate Dean for Computer Science and Engineering in the School of Engineering and Applied Sciences at Harvard University. [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Greg Morrisett" src="http://www.cigital.com/silverbullet/gmorrisett-125.png" style="padding-left: 7px" /></p>
<p>On the 47th episode of The Silver Bullet Security Podcast, Gary calls in from Leuven, Belgium to chat with childhood friend and security expert Greg Morrisett.  Greg is the Allen B. Cutting Professor of Computer Science and Associate Dean for Computer Science and Engineering in the School of Engineering and Applied Sciences at Harvard University.  Gary and Greg discuss the relationship between security and programming languages, why the choice of a good programming language (and/or VM) is more important than code review, sensor networks and security, information control, and Gary and Greg&#8217;s most embarrassing moment from adolescence.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-047-gmorrisett.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.eecs.harvard.edu/~greg/">Greg Morrisett</a></li>
<li><a href="http://www.crcs.deas.harvard.edu/">The Center for Research on Computation and Society</a></li>
<li><a href="http://ynot.cs.harvard.edu/">Ynot</a></li>
<li><a href="http://robobees.seas.harvard.edu/">RoboBees</a></li>
<li><a href="http://nobot.cis.upenn.edu/">NoBot</a></li>
<li><a href="http://sos.cse.lehigh.edu/gonative/">GoNative</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/5wY0uQ9dVEI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-047/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/199/0/silverbullet-047.mp3" length="41773184" type="audio/mpeg" />
		<itunes:duration>0:29:00</itunes:duration>
		<itunes:subtitle>
On the 47th episode of The Silver Bullet Security Podcast, Gary calls in from Leuven, Belgium to chat with childhood friend and security expert Greg Morrisett.  Greg is the Allen B. Cutting Professor of Computer Science and Associate Dean for Compu[...]</itunes:subtitle>
		<itunes:summary>
On the 47th episode of The Silver Bullet Security Podcast, Gary calls in from Leuven, Belgium to chat with childhood friend and security expert Greg Morrisett.  Greg is the Allen B. Cutting Professor of Computer Science and Associate Dean for Computer Science and Engineering in the School of Engineering and Applied Sciences at Harvard University.  Gary and Greg discuss the relationship between security and programming languages, why the choice of a good programming language (and/or VM) is more important than code review, sensor networks and security, information control, and Gary and Greg’s most embarrassing moment from adolescence.

Transcript of this episode [PDF]
Greg Morrisett
The Center for Research on Computation and Society
Ynot
RoboBees
NoBot
GoNative
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/199/0/silverbullet-047.mp3" fileSize="41773184" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-047/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-047</feedburner:origLink></item>
		<item>
		<title>Show 046 – An Interview with David Rice</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/MbhqUc0vwHQ/</link>
		<comments>http://www.cigital.com/silver-bullet/show-046/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 16:35:22 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=57</guid>
		<description><![CDATA[On the bonus-length 46th episode of The Silver Bullet Security Podcast, Gary talks with David Rice, Executive Director of the Monterey Group and author of Geekonomics: The Real Cost of Insecure Software. Gary and David discuss David&#8217;s involvement with Infowar at the Naval Postgraduate School and how it impacted his thinking about software, the recent [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="David Rice" src="http://www.cigital.com/silverbullet/drice-125.png" style="padding-left: 7px" /></p>
<p>On the bonus-length 46th episode of The Silver Bullet Security Podcast, Gary talks with David Rice, Executive Director of the Monterey Group and author of <em>Geekonomics: The Real Cost of Insecure Software</em>.  Gary and David discuss David&#8217;s involvement with Infowar at the Naval Postgraduate School and how it impacted his thinking about software, the recent Chinese cyberattack on Google, what incentives exist to create and apply software security best practices, how users may be mistaking marketing for security, and the SANS WhatWorks in Application Security Summit.  They close out by discussing unusual yoga positions.</p>
<ul>
<li><a href="http://www.montereygrp.com/">Monterey Group</a></li>
<li><a href="http://www.geekonomicsbook.com/"><em>Geekonomics: The Real Cost of Insecure Software</em></a> (also: <a href="http://blog.geekonomicsbook.com/">Geekonomics Blog</a>)</li>
<li><a href="http://www.cigital.com/silverbullet/show-041/">Silver Bullet #41 &#8211; Fred Schneider</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-011/">Silver Bullet #11 &#8211; Dorothy Denning</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1338343">Software Security Comes of Age</a> (InformIT) &#8211; on the growth of the software security space</li>
<li><a href="http://www.techcrunch.com/2010/01/12/google-china-attacks/">Google Defends Against Large Scale Chinese Cyber Attack</a></li>
<li><a href="http://www.sans.org/appsec-2010/summit.php">SANS WhatWorks in Application Security Summit 2010</a></li>
<li><a href="http://bsi-mm.com">BSIMM</a></li>
<li><a href="http://hubpages.com/hub/Funny-Yoga">Beached Whale yoga position</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/MbhqUc0vwHQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-046/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/198/0/silverbullet-046.mp3" length="51990656" type="audio/mpeg" />
		<itunes:duration>0:36:06</itunes:duration>
		<itunes:subtitle>
On the bonus-length 46th episode of The Silver Bullet Security Podcast, Gary talks with David Rice, Executive Director of the Monterey Group and author of Geekonomics: The Real Cost of Insecure Software.  Gary and David discuss David’s involv[...]</itunes:subtitle>
		<itunes:summary>
On the bonus-length 46th episode of The Silver Bullet Security Podcast, Gary talks with David Rice, Executive Director of the Monterey Group and author of Geekonomics: The Real Cost of Insecure Software.  Gary and David discuss David’s involvement with Infowar at the Naval Postgraduate School and how it impacted his thinking about software, the recent Chinese cyberattack on Google, what incentives exist to create and apply software security best practices, how users may be mistaking marketing for security, and the SANS WhatWorks in Application Security Summit.  They close out by discussing unusual yoga positions.

Monterey Group
Geekonomics: The Real Cost of Insecure Software (also: Geekonomics Blog)
Silver Bullet #41 – Fred Schneider
Silver Bullet #11 – Dorothy Denning
Software Security Comes of Age (InformIT) – on the growth of the software security space
Google Defends Against Large Scale Chinese Cyber Attack
SANS WhatWorks in Application Security Summit 2010
BSIMM
Beached Whale yoga position
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/198/0/silverbullet-046.mp3" fileSize="51990656" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-046/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-046</feedburner:origLink></item>
		<item>
		<title>Show 045 – An Interview with Lorrie Cranor</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/z3Z0ZQVegII/</link>
		<comments>http://www.cigital.com/silver-bullet/show-045/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 15:33:06 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=56</guid>
		<description><![CDATA[On the 45th episode of The Silver Bullet Security Podcast, Gary chats with Lorrie Cranor, Associate Professor of Computer Science and Engineering and Public Policy at Carnegie Melon University. Gary and Lorrie discuss how everyday people think about privacy and what we can do to get them to care about it, the relationship between trust [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Lorrie Cranor" src="http://www.cigital.com/silverbullet/lcranor-125.png" style="padding-left: 7px" /></p>
<p>On the 45th episode of The Silver Bullet Security Podcast, Gary chats with Lorrie Cranor, Associate Professor of Computer Science and Engineering and Public Policy at Carnegie Melon University.  Gary and Lorrie discuss how everyday people think about privacy and what we can do to get them to care about it, the relationship between trust and privacy, and why the US is lagging behind the EU on privacy-related issues.  They close out the discussion by talking about women in computing.</p>
<ul>
<li><a href="http://lorrie.cranor.org/">Lorrie Cranor</a></li>
<li><a href="http://www.oreilly.com/catalog/securityusability/index.html"><em>Security and Usability: Designing Secure Systems That People Can Use</em></a></li>
<li><a href="http://oreilly.com/catalog/9780596003715/"><em>Web Privacy with P3P</em></a></li>
<li><a href="http://cups.cs.cmu.edu/index.php">CyLab Usable Privacy and Security Laboratory (CUPS)</a></li>
<li><a href="http://cups.cs.cmu.edu/soups/2009/proceedings/a4-kelley.pdf">A &#8220;Nutrition Label&#8221; for Privacy</a></li>
<li><a href="http://bsi-mm.com/europe">BSIMM Europe</a></li>
<li><a href="http://www.youtube.com/watch?v=kLgJYBRzUXY">Google search privacy video</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/z3Z0ZQVegII" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-045/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/197/0/silverbullet-045.mp3" length="38668416" type="audio/mpeg" />
		<itunes:duration>0:26:51</itunes:duration>
		<itunes:subtitle>
On the 45th episode of The Silver Bullet Security Podcast, Gary chats with Lorrie Cranor, Associate Professor of Computer Science and Engineering and Public Policy at Carnegie Melon University.  Gary and Lorrie discuss how everyday people think abo[...]</itunes:subtitle>
		<itunes:summary>
On the 45th episode of The Silver Bullet Security Podcast, Gary chats with Lorrie Cranor, Associate Professor of Computer Science and Engineering and Public Policy at Carnegie Melon University.  Gary and Lorrie discuss how everyday people think about privacy and what we can do to get them to care about it, the relationship between trust and privacy, and why the US is lagging behind the EU on privacy-related issues.  They close out the discussion by talking about women in computing.

Lorrie Cranor
Security and Usability: Designing Secure Systems That People Can Use
Web Privacy with P3P
CyLab Usable Privacy and Security Laboratory (CUPS)
A “Nutrition Label” for Privacy
BSIMM Europe
Google search privacy video
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/197/0/silverbullet-045.mp3" fileSize="38668416" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-045/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-045</feedburner:origLink></item>
		<item>
		<title>Show 044 – An Interview with Steve Kent</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Xg2JWkwUl-E/</link>
		<comments>http://www.cigital.com/silver-bullet/show-044/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 21:55:05 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=55</guid>
		<description><![CDATA[On the 44th episode of The Silver Bullet Security Podcast, Gary talks with Steve Kent, Chief Scientist &#8211; Information Security, for BBN Technologies, a division of Raytheon. Gary and Steve discuss the history of network security, secure transport and base Internet protocols, the role of politics in the adoption of security on the Internet, applied [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Steve Kent" src="http://www.cigital.com/silverbullet/skent-125.png" style="padding-left: 7px" /></p>
<p>On the 44th episode of The Silver Bullet Security Podcast, Gary talks with Steve Kent, Chief Scientist &#8211; Information Security, for BBN Technologies, a division of Raytheon.  Gary and Steve discuss the history of network security, secure transport and base Internet protocols, the role of politics in the adoption of security on the Internet, applied cryptography, and whether security and individual liberty co-exist.  They finish by discussing extremely high end wine.</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2008/08/revealed-the-in/">Internet&#8217;s Biggest Security Hole</a></li>
<li><a href="http://www.ir.bbn.com/sbgp/S-BGP_Clarke_workshop.ppt">Securing the Border Gateway Protocol</a> (PPT)</li>
<li><a href="http://www7.nationalacademies.org/ocga/testimony/IDs_Not_That_Easy.asp">2006: Statement before Congress regarding a nationwide ID system</a></li>
<li><a href="http://bsi-mm.com/europe/">BSIMM Europe</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Xg2JWkwUl-E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-044/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/196/0/silverbullet-044.mp3" length="46776448" type="audio/mpeg" />
		<itunes:duration>0:32:29</itunes:duration>
		<itunes:subtitle>
On the 44th episode of The Silver Bullet Security Podcast, Gary talks with Steve Kent, Chief Scientist – Information Security, for BBN Technologies, a division of Raytheon.  Gary and Steve discuss the history of network security, secure trans[...]</itunes:subtitle>
		<itunes:summary>
On the 44th episode of The Silver Bullet Security Podcast, Gary talks with Steve Kent, Chief Scientist – Information Security, for BBN Technologies, a division of Raytheon.  Gary and Steve discuss the history of network security, secure transport and base Internet protocols, the role of politics in the adoption of security on the Internet, applied cryptography, and whether security and individual liberty co-exist.  They finish by discussing extremely high end wine.

Internet’s Biggest Security Hole
Securing the Border Gateway Protocol (PPT)
2006: Statement before Congress regarding a nationwide ID system
BSIMM Europe

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/196/0/silverbullet-044.mp3" fileSize="46776448" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-044/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-044</feedburner:origLink></item>
		<item>
		<title>Show 043 – An Interview with Christofer Hoff</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/cSwXOtDa6r0/</link>
		<comments>http://www.cigital.com/silver-bullet/show-043/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 21:20:16 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=54</guid>
		<description><![CDATA[On the 43rd episode of The Silver Bullet Security Podcast, Gary chats with Christofer Hoff, Director of Cloud and Virtualization Solutions at Cisco. Hoff is well known for his colorful blog posts and presentations on cloud security and other complex security issues. Suffice it to say, the cloud was a big topic for this issue. [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Christofer Hoff" src="http://www.cigital.com/silverbullet/choff-125.png" style="padding-left: 7px" /></p>
<p>On the 43rd episode of The Silver Bullet Security Podcast, Gary chats with Christofer Hoff, Director of Cloud and Virtualization Solutions at Cisco.  Hoff is well known for his colorful blog posts and presentations on cloud security and other complex security issues.  Suffice it to say, the cloud was a big topic for this issue.  And rum.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-043-choff.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://rationalsurvivability.com/RationalSurvivability/About_The_Hoff.html">Christofer Hoff</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/">Rational Survivability</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/?p=567">The Frogs Who Desired a King: A Virtualization &amp; Cloud Computing Fable</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/?p=1271">Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure</a></li>
<li><a href="http://www.mountgay.com/">Mount Gay Extra Old Rum</a> (Gary&#8217;s favorite)</li>
<li><a href="http://en.wikipedia.org/wiki/Ron_Zacapa_Centenario">Ron Zacapa Centenario Rum</a> (Hoff&#8217;s favorite)</li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/cSwXOtDa6r0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-043/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/195/0/silverbullet-043.mp3" length="45994112" type="audio/mpeg" />
		<itunes:duration>0:31:56</itunes:duration>
		<itunes:subtitle>
On the 43rd episode of The Silver Bullet Security Podcast, Gary chats with Christofer Hoff, Director of Cloud and Virtualization Solutions at Cisco.  Hoff is well known for his colorful blog posts and presentations on cloud security and other compl[...]</itunes:subtitle>
		<itunes:summary>
On the 43rd episode of The Silver Bullet Security Podcast, Gary chats with Christofer Hoff, Director of Cloud and Virtualization Solutions at Cisco.  Hoff is well known for his colorful blog posts and presentations on cloud security and other complex security issues.  Suffice it to say, the cloud was a big topic for this issue.  And rum.

Transcript of this episode [PDF]
Christofer Hoff
Rational Survivability
The Frogs Who Desired a King: A Virtualization &amp; Cloud Computing Fable
Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure
Mount Gay Extra Old Rum (Gary’s favorite)
Ron Zacapa Centenario Rum (Hoff’s favorite)

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/195/0/silverbullet-043.mp3" fileSize="45994112" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-043/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-043</feedburner:origLink></item>
		<item>
		<title>Show 042 – An Interview with Gillian Hayes</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/E-2TXLcKytA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-042/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 18:31:20 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=53</guid>
		<description><![CDATA[On the 42nd episode of The Silver Bullet Security Podcast, Gary chats with Gillian Hayes, Assistant Professor in Informatics at the Bren School of Information and Computer Sciences at UC Irvine. Gary and Gillian discuss how much people really need to know about security going on behind the scenes, how usability affects the health records [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Gillian Hayes" src="http://www.cigital.com/silverbullet/ghayes-125.png" style="padding-left: 7px" /></p>
<p>On the 42nd episode of The Silver Bullet Security Podcast, Gary chats with Gillian Hayes, Assistant Professor in Informatics at the Bren School of Information and Computer Sciences at UC Irvine.  Gary and Gillian discuss how much people really need to know about security going on behind the scenes, how usability affects the health records security, whether or not surveillance changes how 20-somethings act in public (including on the net), and how having more women technologists positively impacts the humanization of technology.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-042-ghayes.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.gillianhayes.com/">Gillian Hayes</a></li>
<li><a href="http://www.star-uci.org/STAR/Welcome.html">Social and technological action research (STAR)</a></li>
<li><a href="http://www.cs.umd.edu/~ben/">Ben Shneiderman</a></li>
<li><a href="http://www.ncwit.org/">National Center for Women and Information Technology</a></li>
<li><a href="http://www.amazon.com/Discovery-Heaven-Harry-Mulisch/dp/0140239375/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1253629779&amp;sr=1-1-spell">The Discovery of Heaven</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/E-2TXLcKytA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-042/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/194/0/silverbullet-042.mp3" length="44429440" type="audio/mpeg" />
		<itunes:duration>0:30:51</itunes:duration>
		<itunes:subtitle>
On the 42nd episode of The Silver Bullet Security Podcast, Gary chats with Gillian Hayes, Assistant Professor in Informatics at the Bren School of Information and Computer Sciences at UC Irvine.  Gary and Gillian discuss how much people really need[...]</itunes:subtitle>
		<itunes:summary>
On the 42nd episode of The Silver Bullet Security Podcast, Gary chats with Gillian Hayes, Assistant Professor in Informatics at the Bren School of Information and Computer Sciences at UC Irvine.  Gary and Gillian discuss how much people really need to know about security going on behind the scenes, how usability affects the health records security, whether or not surveillance changes how 20-somethings act in public (including on the net), and how having more women technologists positively impacts the humanization of technology.

Transcript of this episode [PDF]
Gillian Hayes
Social and technological action research (STAR)
Ben Shneiderman
National Center for Women and Information Technology
The Discovery of Heaven

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/194/0/silverbullet-042.mp3" fileSize="44429440" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-042/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-042</feedburner:origLink></item>
		<item>
		<title>Show 041 – An Interview with Fred Schneider</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/uONCYe42xbw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-041/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 18:10:20 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=52</guid>
		<description><![CDATA[On the 41st episode of The Silver Bullet Security Podcast, Gary talks with Fred Schneider, Samuel B. Eckert Professor of Computer Science at Cornell University and author of Trust in Cyberspace. On the show, Gary and Fred discuss the relationship between security and reliability, diversity as a security mechanism, and the continuum of attack categories [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Fred Schneider" src="http://www.cigital.com/silverbullet/fschneider-125.png" style="padding-left: 7px" /></p>
<p>On the 41st episode of The Silver Bullet Security Podcast, Gary talks with Fred Schneider, Samuel B. Eckert Professor of Computer Science at Cornell University and author of Trust in Cyberspace.  On the show, Gary and Fred discuss the relationship between security and reliability, diversity as a security mechanism, and the continuum of attack categories from configuration problems, to bugs, to flaws, to trust issues. Fred briefly discusses Pointillism at the end of the show.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-041-fschneider.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cs.cornell.edu/fbs/">Fred B. Schneider</a></li>
<li><a href="http://www.cs.cornell.edu/fbs/publications/IEEEspMonoculture.pdf">IEEE Security and Privacy 7, 1 (January/February 2009)</a> [PDF], 14&#8211;17. With Ken Birman.</li>
<li><a href="http://www.nap.edu/openbook.php?record_id=6161">Trust in Cyberspace</a></li>
<li><a href="http://www.webexhibits.org/colorart/jatte.html">Pointillism (Seurat)</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/uONCYe42xbw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-041/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/193/0/silverbullet-041.mp3" length="45879424" type="audio/mpeg" />
		<itunes:duration>0:31:51</itunes:duration>
		<itunes:subtitle>
On the 41st episode of The Silver Bullet Security Podcast, Gary talks with Fred Schneider, Samuel B. Eckert Professor of Computer Science at Cornell University and author of Trust in Cyberspace.  On the show, Gary and Fred discuss the relationship [...]</itunes:subtitle>
		<itunes:summary>
On the 41st episode of The Silver Bullet Security Podcast, Gary talks with Fred Schneider, Samuel B. Eckert Professor of Computer Science at Cornell University and author of Trust in Cyberspace.  On the show, Gary and Fred discuss the relationship between security and reliability, diversity as a security mechanism, and the continuum of attack categories from configuration problems, to bugs, to flaws, to trust issues. Fred briefly discusses Pointillism at the end of the show.

Transcript of this episode [PDF]
Fred B. Schneider
IEEE Security and Privacy 7, 1 (January/February 2009) [PDF], 14–17. With Ken Birman.
Trust in Cyberspace
Pointillism (Seurat)

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/193/0/silverbullet-041.mp3" fileSize="45879424" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-041/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-041</feedburner:origLink></item>
		<item>
		<title>Show 040 – An Interview with Bob Blakley</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/yEV9mitm2HI/</link>
		<comments>http://www.cigital.com/silver-bullet/show-040/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 14:06:47 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=51</guid>
		<description><![CDATA[For the 40th episode of The Silver Bullet Security Podcast, Gary interviews Bob Blakley, VP and research director of The Burton Group&#8217;s Identity and Privacy Strategies. Gary and Bob discuss the importance of liberal arts degrees, the (over) complications of CORBA security, whether computer security requires a complete shift in approach, cybersecurity and governments, and [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Bob Blakley" src="http://www.cigital.com/silverbullet/bblakley-125.png" style="padding-left: 7px" /></p>
<p>For the 40th episode of The Silver Bullet Security Podcast, Gary interviews Bob Blakley, VP and research director of The Burton Group&#8217;s Identity and Privacy Strategies.  Gary and Bob discuss the importance of liberal arts degrees, the (over) complications of CORBA security, whether computer security requires a complete shift in approach, cybersecurity and governments, and the movie <em>Perils in Nude Modeling</em> (really).</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-040-bblakley.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://notabob.blogspot.com/">Ceci n&#8217;est pas un Bob</a> &#8211; Bob&#8217;s blog</li>
<li><a href="http://www.amazon.com/CORBA-Security-Introduction-Addison-Wesley-Technology/dp/0201325659"><em>CORBA Security: An Introduction to Safe Computing with Objects</em></a></li>
<li><a href="http://www.isoc.org/isoc/conferences/ndss/98/blakl_sl.pdf">NDSS&#8217;98 Trust Management Panel: LE NOZZE DI NOMEN</a> [PDF] &#8211; The NDSS &#8220;wedding script&#8221;</li>
<li>&#8220;<a href="http://portal.acm.org/citation.cfm?id=304855">The Emperor&#8217;s Old Armor</a>&#8220;</li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1379758"><a href="http://www.informit.com/articles/article.aspx?p=1379758">Moving U.S. Cybersecurity Beyond Cyberplatitudes</a></li>
<li><a href="http://www.imdb.com/title/tt0432710/"><em>Perils in Nude Modeling</em></a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/yEV9mitm2HI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-040/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	<enclosure url="http://www.isoc.org/isoc/conferences/ndss/98/blakl_sl.pdf" length="18777" type="application/x-pdf" /><media:content url="http://www.isoc.org/isoc/conferences/ndss/98/blakl_sl.pdf" fileSize="18777" type="application/x-pdf" /><itunes:explicit>no</itunes:explicit><itunes:author>Gary McGraw</itunes:author><itunes:summary>Industry Leaders In Application Security &amp; Research</itunes:summary><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-040/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-040</feedburner:origLink></item>
		<item>
		<title>Show 039 – An Interview with Matt Blaze</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/wVAh5mBwqtc/</link>
		<comments>http://www.cigital.com/silver-bullet/show-039/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 21:01:53 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=49</guid>
		<description><![CDATA[For the 39th episode of The Silver Bullet Security Podcast, Gary chats with Matt Blaze, Associate Professor of Computer and Information Science at the University of Pennsylvania. Gary and Matt start the show off discussing the Obama administration&#8217;s &#8220;cyber coordinator&#8221; plan and the large number of cyber plans that are never cyber realized. They also [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Matt Blaze" src="http://www.cigital.com/silverbullet/mblaze-126.png" style="padding-left: 7px" /></p>
<p>For the 39th episode of The Silver Bullet Security Podcast, Gary chats with Matt Blaze, Associate Professor of Computer and Information Science at the University of Pennsylvania.  Gary and Matt start the show off discussing the Obama administration&#8217;s &#8220;cyber coordinator&#8221; plan and the large number of cyber plans that are never cyber realized.  They also discuss key escrow, warrantless wiretapping, the responsibility we have to stay engaged with issues surrounding individual liberty and privacy, and the similarities between physical locks and computer security.  Matt’s musical tastes are also briefly touched on.</p>
<ul>
<li><a href="http://www.crypto.com/">Matt Blaze</a></li>
<li><a href="http://en.wikipedia.org/wiki/Matt_Blaze">Matt Blaze &#8211; Wikipedia</a></li>
<li><a href="http://www.crypto.com/blog/">Matt Blaze&#8217;s Exhaustive Search</a> &#8211; Matt&#8217;s blog</li>
<li><a href="http://www.crypto.com/blog/safecracking_and_science/">Safecracking, Secrecy and Science</a></li>
<li><a href="http://www.crypto.com/papers/mk.pdf">Cryptology and Physical Security: Rights Amplification in Master-Keyed Mechanical Locks</a> &#8211; <em>IEEE Security &amp; Privacy</em>, March/April 2003</li>
<li><a href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1353725,00.html">RSA panel on Surveillance</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-011/">Silver Bullet 11: Dorothy Denning</a></li>
<li><a href="http://en.wikipedia.org/wiki/Trust_management">Trust Management</a></li>
<li><a href="http://www.crypto.com/papers/wiretap.pdf">Signaling Vulnerabilities in Wiretapping Systems</a> &#8211; <em>IEEE Security &amp; Privacy</em>, November/December 2005, by M. Sherr, E. Cronin, S. Clark and M. Blaze.</li>
<li><a href="http://www.everythingthathappens.com/">Eno/Byrne: Everything That Happens Will Happen Today</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/wVAh5mBwqtc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-039/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/191/0/silverbullet-039.mp3" length="46944384" type="audio/mpeg" />
		<itunes:duration>0:32:36</itunes:duration>
		<itunes:subtitle>
For the 39th episode of The Silver Bullet Security Podcast, Gary chats with Matt Blaze, Associate Professor of Computer and Information Science at the University of Pennsylvania.  Gary and Matt start the show off discussing the Obama administration[...]</itunes:subtitle>
		<itunes:summary>
For the 39th episode of The Silver Bullet Security Podcast, Gary chats with Matt Blaze, Associate Professor of Computer and Information Science at the University of Pennsylvania.  Gary and Matt start the show off discussing the Obama administration’s “cyber coordinator” plan and the large number of cyber plans that are never cyber realized.  They also discuss key escrow, warrantless wiretapping, the responsibility we have to stay engaged with issues surrounding individual liberty and privacy, and the similarities between physical locks and computer security.  Matt’s musical tastes are also briefly touched on.

Matt Blaze
Matt Blaze – Wikipedia
Matt Blaze’s Exhaustive Search – Matt’s blog
Safecracking, Secrecy and Science
Cryptology and Physical Security: Rights Amplification in Master-Keyed Mechanical Locks – IEEE Security &amp; Privacy, March/April 2003
RSA panel on Surveillance
Silver Bullet 11: Dorothy Denning
Trust Management
Signaling Vulnerabilities in Wiretapping Systems – IEEE Security &amp; Privacy, November/December 2005, by M. Sherr, E. Cronin, S. Clark and M. Blaze.
Eno/Byrne: Everything That Happens Will Happen Today

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/191/0/silverbullet-039.mp3" fileSize="46944384" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-039/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-039</feedburner:origLink></item>
		<item>
		<title>Show 038 – An Interview with Kay Connelly</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/0iD65_4BD84/</link>
		<comments>http://www.cigital.com/silver-bullet/show-038/#comments</comments>
		<pubDate>Tue, 19 May 2009 21:33:17 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=47</guid>
		<description><![CDATA[For the 38th episode of The Silver Bullet Security Podcast, Gary talks privacy with Kay Connelly, Associate Professor of Computer Science at Indiana University and Senior Associate Director of IU&#8217;s Center for Applied Cybersecurity Research. Gary and Kay discuss why in situ usability study is important, the E.T.H.O.S. living lab (including the &#8220;presence clock&#8221; and [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Kay Connelly" src="http://www.cigital.com/silverbullet/kconnelly-125.png" style="padding-left: 7px" /></p>
<p>For the 38th episode of The Silver Bullet Security Podcast, Gary talks privacy with Kay Connelly, Associate Professor of Computer Science at Indiana University and Senior Associate Director of IU&#8217;s Center for Applied Cybersecurity Research. Gary and Kay discuss why in situ usability study is important, the E.T.H.O.S. living lab (including the &#8220;presence clock&#8221; and the portal monitor), and Kay&#8217;s advice to women interested in pursuing a career in computer science.</p>
<ul>
<li><a href="http://www.cs.indiana.edu/~connelly/">Kay Connelly</a></li>
<li><a href="http://ethos.indiana.edu/?q=blog/3">E.T.H.O.S. &#8211; Ethical Technology in the Homes of Seniors</a></li>
<li><a href="http://www.npr.org/templates/story/story.php?storyId=5201273">Crafting a Smarter, Gentler Cell Phone</a> &#8211; NPR story featuring Kay Connelly</li>
<li><a href="http://www.cs.indiana.edu/surg/Publications/ubicomp07.pdf">Why It’s Worth the Hassle: The Value of In-Situ Studies When Designing Ubicomp</a> [PDF]</li>
<li><a href="http://www.cigital.com/silverbullet/show-007/">Silver Bullet #7: John Stewart</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-015/">Silver Bullet #15: Annie Antón</a></li>
<li><a href="http://www.hhs.gov/ocr/hipaa/">HIPAA</a></li>
<li><a href="http://ethos.indiana.edu/?page_id=103">Ambient (Presence) Clock</a></li>
<li><a href="http://ethos.indiana.edu/?page_id=90">Portal Monitor</a></li>
<li><a href="http://www.amazon.com/Song-You-Novel-Arthur-Phillips/dp/1400066468/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1242410749&amp;sr=1-1"><em>The Song Is You: A Novel</em></a> by Arthur Phillips</li>
<li><a href="http://www.amazon.com/Was-Told-Thered-Be-Cake/dp/159448306X/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1242410724&amp;sr=1-1"><em>I Was Told There&#8217;d Be Cake</em></a> by Sloane Crosley</li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/0iD65_4BD84" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-038/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/190/0/silverbullet-038.mp3" length="36331648" type="audio/mpeg" />
		<itunes:duration>0:25:14</itunes:duration>
		<itunes:subtitle>
For the 38th episode of The Silver Bullet Security Podcast, Gary talks privacy with Kay Connelly, Associate Professor of Computer Science at Indiana University and Senior Associate Director of IU’s Center for Applied Cybersecurity Research. G[...]</itunes:subtitle>
		<itunes:summary>
For the 38th episode of The Silver Bullet Security Podcast, Gary talks privacy with Kay Connelly, Associate Professor of Computer Science at Indiana University and Senior Associate Director of IU’s Center for Applied Cybersecurity Research. Gary and Kay discuss why in situ usability study is important, the E.T.H.O.S. living lab (including the “presence clock” and the portal monitor), and Kay’s advice to women interested in pursuing a career in computer science.

Kay Connelly
E.T.H.O.S. – Ethical Technology in the Homes of Seniors
Crafting a Smarter, Gentler Cell Phone – NPR story featuring Kay Connelly
Why It’s Worth the Hassle: The Value of In-Situ Studies When Designing Ubicomp [PDF]
Silver Bullet #7: John Stewart
Silver Bullet #15: Annie Antón
HIPAA
Ambient (Presence) Clock
Portal Monitor
The Song Is You: A Novel by Arthur Phillips
I Was Told There’d Be Cake by Sloane Crosley

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/190/0/silverbullet-038.mp3" fileSize="36331648" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-038/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-038</feedburner:origLink></item>
		<item>
		<title>Show 037 – An Interview with Virgil Gligor</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/XDvuPBpB1vo/</link>
		<comments>http://www.cigital.com/silver-bullet/show-037/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 18:56:51 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=45</guid>
		<description><![CDATA[On the 37th episode of The Silver Bullet Security Podcast, Gary interviews Virgil Gligor, Professor at Carnegie Mellon University in the Department of Electrical and Computer Engineering and co-director of CyLab. Gary and Virgil discuss how information security has changed over the last 35 years, why software security will be with us forever, and how [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Virgil Gligor" src="http://www.cigital.com/silverbullet/vgligor-120.png" style="padding-left: 7px" /></p>
<p>On the 37th episode of The Silver Bullet Security Podcast, Gary interviews Virgil Gligor, Professor at Carnegie Mellon University in the Department of Electrical and Computer Engineering and co-director of CyLab.  Gary and Virgil discuss how information security has changed over the last 35 years, why software security will be with us forever, and how Virgil&#8217;s childhood in Romania has shaped his views on security.  They close out with a discussion of Virgil&#8217;s breakfast-eating habits.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-037-vgligor.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.ece.cmu.edu/~virgil/">Virgil D. Gligor</a> (@ Carnegie Mellon)</li>
<li><a href="http://www.cylab.cmu.edu/">CyLab</a></li>
<li><a href="http://www.ece.cmu.edu/">Electrical and Computer Engineering at Carnegie Mellon University</a></li>
<li><a href="http://www.amazon.com/Building-Secure-Computer-System-Morrie/dp/0442230222/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1240327785&amp;sr=8-1">Building a Secure Computer System</a></li>
<li><a href="http://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act">Foreign Intelligence Surveillance Act</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1338343">Software Security Comes of Age</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1353725,00.html">RSA panel to discuss surveillance, privacy concerns</li>
<li><a href="http://www.amazon.com/Computer-Security-Science-Matt-Bishop/dp/0201440997"><em>Computer Security: Art and Science</em></a> by Matt Bishop</li>
<li><a href="http://ieeexplore.ieee.org/Xplore/login.jsp?url=http%3A%2F%2Fieeexplore.ieee.org%2Fiel2%2F358%2F3978%2F00151571.pdf%3Farnumber%3D151571&amp;authDecision=-203">Towards a Theory of Penetration-Resistant Systems and its Applications</a> (1991)</li>
<li><a href="http://www2.computer.org/portal/web/csdl/doi/10.1109/SP.1987.10014">A Formal Method for the Identification of Covert Storage Channels in Source Code</a> (1987)</li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/XDvuPBpB1vo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-037/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/189/0/silverbullet-037.mp3" length="39116851" type="audio/mpeg" />
		<itunes:duration>0:27:10</itunes:duration>
		<itunes:subtitle>
On the 37th episode of The Silver Bullet Security Podcast, Gary interviews Virgil Gligor, Professor at Carnegie Mellon University in the Department of Electrical and Computer Engineering and co-director of CyLab.  Gary and Virgil discuss how inform[...]</itunes:subtitle>
		<itunes:summary>
On the 37th episode of The Silver Bullet Security Podcast, Gary interviews Virgil Gligor, Professor at Carnegie Mellon University in the Department of Electrical and Computer Engineering and co-director of CyLab.  Gary and Virgil discuss how information security has changed over the last 35 years, why software security will be with us forever, and how Virgil’s childhood in Romania has shaped his views on security.  They close out with a discussion of Virgil’s breakfast-eating habits.

Transcript of this episode [PDF]
Virgil D. Gligor (@ Carnegie Mellon)
CyLab
Electrical and Computer Engineering at Carnegie Mellon University
Building a Secure Computer System
Foreign Intelligence Surveillance Act
Software Security Comes of Age
RSA panel to discuss surveillance, privacy concerns
Computer Security: Art and Science by Matt Bishop
Towards a Theory of Penetration-Resistant Systems and its Applications (1991)
A Formal Method for the Identification of Covert Storage Channels in Source Code (1987)

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/189/0/silverbullet-037.mp3" fileSize="39116851" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-037/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-037</feedburner:origLink></item>
		<item>
		<title>Show 036 – An Interview with Gary McGraw (by James McGovern)</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/wXS2kAc_B3E/</link>
		<comments>http://www.cigital.com/silver-bullet/show-036/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 20:40:27 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=44</guid>
		<description><![CDATA[We switch things up for this special third anniversary episode of Silver Bullet. This time around, Gary is the victim, being interviewed by James McGovern, Enterprise Architect for The Hartford Financial Services Group, Inc. and OWASP maven. Gary and James discuss the recently released Building Security In Maturity Model, how companies with Software Security Groups [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Gary McGraw" src="http://www.cigital.com/silverbullet/gem-125.png" style="padding-left: 7px" /></p>
<p>We switch things up for this special third anniversary episode of Silver Bullet.  This time around, Gary is the victim, being interviewed by James McGovern, Enterprise Architect for The Hartford Financial Services Group, Inc. and OWASP maven.  Gary and James discuss the recently released Building Security In Maturity Model, how companies with Software Security Groups retain their best and brightest, Microsoft&#8217;s trustworthy computing initiative/SDL program, and what less expensive tools small organizations with only a few developers can use.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-036-gem.pdf">Transcript of this episode</a> [PDF]
<li><a href="http://duckdown.blogspot.com/">Enterprise Architecture: From Incite comes Insight&#8230;</a> &#8211; James McGovern&#8217;s blog</li>
<li><a href="http://www.cigital.com/~gem/">Gary McGraw&#8217;s site</a></li>
<li><a href="http://www.swsec.com/"><em>Software Security: Building Security In</em></a></li>
<li><a href="http://www.bsi-mm.com/">Building Security In Maturity Model (BSIMM)</a></li>
<li><a href="http://duckdown.blogspot.com/2009/02/gartner-releases-paper-on-static.html">Gartner releases paper on Static Analysis</a> &#8211; James&#8217; blog entry on Gartner</li>
<li><a href="http://www.cigital.com/news/index.php?pg=art&amp;artid=155">Cigital&#8217;s John Steven to lead OWASP Northern Virginia Local Chapter</a> (press release)</li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/wXS2kAc_B3E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-036/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/188/0/silverbullet-036.mp3" length="49784960" type="audio/mpeg" />
		<itunes:duration>0:34:34</itunes:duration>
		<itunes:subtitle>
We switch things up for this special third anniversary episode of Silver Bullet.  This time around, Gary is the victim, being interviewed by James McGovern, Enterprise Architect for The Hartford Financial Services Group, Inc. and OWASP maven.  Gary[...]</itunes:subtitle>
		<itunes:summary>
We switch things up for this special third anniversary episode of Silver Bullet.  This time around, Gary is the victim, being interviewed by James McGovern, Enterprise Architect for The Hartford Financial Services Group, Inc. and OWASP maven.  Gary and James discuss the recently released Building Security In Maturity Model, how companies with Software Security Groups retain their best and brightest, Microsoft’s trustworthy computing initiative/SDL program, and what less expensive tools small organizations with only a few developers can use.

Transcript of this episode [PDF]
Enterprise Architecture: From Incite comes Insight… – James McGovern’s blog
Gary McGraw’s site
Software Security: Building Security In
Building Security In Maturity Model (BSIMM)
Gartner releases paper on Static Analysis – James’ blog entry on Gartner
Cigital’s John Steven to lead OWASP Northern Virginia Local Chapter (press release)

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/188/0/silverbullet-036.mp3" fileSize="49784960" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-036/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-036</feedburner:origLink></item>
		<item>
		<title>Show 035 – An Interview with Daniel Suarez</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/mCYRjr9AKkg/</link>
		<comments>http://www.cigital.com/silver-bullet/show-035/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 20:50:17 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=43</guid>
		<description><![CDATA[On the 35th episode of The Silver Bullet Security Podcast, Gary talks with Daniel Suarez, independent consultant and author of Daemon, a new techno-thriller about a gamer that reaches from beyond the grave to declare a war on all of humanity. They talk about Daniel&#8217;s new book and the movie options attached to it, the [...]]]></description>
				<content:encoded><![CDATA[<div style="float: right;text-align: center">
     <img alt="Daniel Suarez" src="http://www.cigital.com/silverbullet/dsuarez-125.png" style="padding-left: 7px" /><br />
     <img alt="Daemon" src="http://www.cigital.com/silverbullet/daemon-125.gif" style="padding-left: 7px;padding-top: 5px" />
</div>
<p>On the 35th episode of The Silver Bullet Security Podcast, Gary talks with Daniel Suarez, independent consultant and author of <em>Daemon</em>, a new techno-thriller about a gamer that reaches from beyond the grave to declare a war on all of humanity.  They talk about Daniel&#8217;s new book and the movie options attached to it, the use of MMORPGs and flash mobs for nefarious means in the form of a distributed emergent attack, the current state of AI, and the follow-up to <em>Daemon</em>, <em>Freedom <sup>TM</sup></em>.</p>
<ul>
<li><a href="http://www.thedaemon.com/"><em>Daemon</em></a></li>
<li><a href="http://www.nbc.com/Last_Call_with_Carson_Daly/video/clips/daniel-suarez/1005261/">Daniel on <em>Last call with Carson Daly</em></a></li>
<li><a href="http://nwn.blogs.com/nwn/2007/08/second-life-and.html">Al-Qaeda in Second Life</a></li>
<li><a href="http://www.amazon.com/Distraction-Bruce-Sterling/dp/0553576399"><em>Distraction</em></a> by Bruce Sterling</li>
<li><a href="http://www.amazon.com/Halting-State-Charles-Stross/dp/0441014984"><em>Halting State</em></a> by Charles Stross</li>
<li><a href="http://fora.tv/2008/08/08/Daniel_Suarez_Daemon_Bot-Mediated_Reality">Bot-Mediated Reality</a> at the Long Now Foundation</li>
<li><a href="http://wiredforwar.pwsinger.com/"><em>Wired for War</em></a> by P.W. Singer</li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/mCYRjr9AKkg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-035/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/187/0/silverbullet-035.mp3" length="36373366" type="audio/mpeg" />
		<itunes:duration>0:25:16</itunes:duration>
		<itunes:subtitle>
     
     

On the 35th episode of The Silver Bullet Security Podcast, Gary talks with Daniel Suarez, independent consultant and author of Daemon, a new techno-thriller about a gamer that reaches from beyond the grave to declare a war on all of hu[...]</itunes:subtitle>
		<itunes:summary>
     
     

On the 35th episode of The Silver Bullet Security Podcast, Gary talks with Daniel Suarez, independent consultant and author of Daemon, a new techno-thriller about a gamer that reaches from beyond the grave to declare a war on all of humanity.  They talk about Daniel’s new book and the movie options attached to it, the use of MMORPGs and flash mobs for nefarious means in the form of a distributed emergent attack, the current state of AI, and the follow-up to Daemon, Freedom TM.

Daemon
Daniel on Last call with Carson Daly
Al-Qaeda in Second Life
Distraction by Bruce Sterling
Halting State by Charles Stross
Bot-Mediated Reality at the Long Now Foundation
Wired for War by P.W. Singer

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/187/0/silverbullet-035.mp3" fileSize="36373366" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-035/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-035</feedburner:origLink></item>
		<item>
		<title>Show 034 – An Interview with Bill Brenner</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/-OkqXFKt8JQ/</link>
		<comments>http://www.cigital.com/silver-bullet/show-034/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 19:05:39 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=42</guid>
		<description><![CDATA[On the 34th episode of The Silver Bullet Security Podcast, Gary interviews Bill Brenner, senior editor at CSO Online and CSO Magazine. Gary and Bill discuss how delivering the security message changes based on the audience (executives versus geeks and CSO’s versus CIO’s), the much-exaggerated death of print media, and balancing headline-grabbing sensationalism with solid [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Bill Brenner" src="http://www.cigital.com/silverbullet/bbrenner-125.png" style="padding-left: 7px" /></p>
<p>On the 34th episode of The Silver Bullet Security Podcast, Gary interviews Bill Brenner, senior editor at CSO Online and <em>CSO Magazine</em>.  Gary and Bill discuss how delivering the security message changes based on the audience (executives versus geeks and CSO’s versus CIO’s), the much-exaggerated death of print media, and balancing headline-grabbing sensationalism with solid security business coverage.  They close out their interview with a discussion of Bill&#8217;s favorite period of history.</p>
<ul>
<li><a href="http://www.csoonline.com/author/380013/Bill+Brenner">Bill Brenner at CSO Online</a></li>
<li><a href="http://www.linkedin.com/in/billbrenner">Bill Brenner on LinkedIn</a></li>
<li><a href="http://www.facebook.com/profile.php?id=1426070157">Bill Brenner on Facebook</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/">Security Wire Weekly</a></li>
<li><a href="http://www.csoonline.com/podcasts">Security Insights Podcast</a></li>
<li><a href="http://1raindrop.typepad.com/">1 Raindrop</a> &#8211; Gunnar Peterson&#8217;s blog.</li>
<li>Silver Bullet interviews with <a href="http://www.cigital.com/silverbullet/show-025/">Jon Swartz, USA Today</a>, <a href="http://www.cigital.com/silverbullet/show-029/">Dennis Fisher, Tech Target</a>, and <a href="http://www.cigital.com/silverbullet/show-032/">Jeremiah Grossman, Whitehat</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/-OkqXFKt8JQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-034/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/186/0/silverbullet-034.mp3" length="40020895" type="audio/mpeg" />
		<itunes:duration>0:27:48</itunes:duration>
		<itunes:subtitle>
On the 34th episode of The Silver Bullet Security Podcast, Gary interviews Bill Brenner, senior editor at CSO Online and CSO Magazine.  Gary and Bill discuss how delivering the security message changes based on the audience (executives versus geeks[...]</itunes:subtitle>
		<itunes:summary>
On the 34th episode of The Silver Bullet Security Podcast, Gary interviews Bill Brenner, senior editor at CSO Online and CSO Magazine.  Gary and Bill discuss how delivering the security message changes based on the audience (executives versus geeks and CSO’s versus CIO’s), the much-exaggerated death of print media, and balancing headline-grabbing sensationalism with solid security business coverage.  They close out their interview with a discussion of Bill’s favorite period of history.

Bill Brenner at CSO Online
Bill Brenner on LinkedIn
Bill Brenner on Facebook
Security Wire Weekly
Security Insights Podcast
1 Raindrop – Gunnar Peterson’s blog.
Silver Bullet interviews with Jon Swartz, USA Today, Dennis Fisher, Tech Target, and Jeremiah Grossman, Whitehat

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/186/0/silverbullet-034.mp3" fileSize="40020895" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-034/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-034</feedburner:origLink></item>
		<item>
		<title>Ad: Reality Check Security Podcast</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/IHX8b38e93s/</link>
		<comments>http://www.cigital.com/silver-bullet/ad-reality-check-security-podcast/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 22:06:08 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=41</guid>
		<description><![CDATA[Note: The Reality Check Podcast is no longer available. We&#8217;re happy to announce the debut of The Reality Check Security Podcast with Gary McGraw: The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners and practical software security. Reality Check’s sister podcast, the Silver Bullet Security Podcast with Gary McGraw, follows a [...]]]></description>
				<content:encoded><![CDATA[<p><strong>Note: The Reality Check Podcast is no longer available.</strong></p>
<p>We&#8217;re happy to announce the debut of <a href="/realitycheck/">The Reality Check Security Podcast with Gary McGraw</a>:</p>
<blockquote><p>The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners and practical software security.   Reality Check’s sister podcast, the <a href="http://www.cigital.com/silverbullet/">Silver Bullet Security Podcast with Gary McGraw</a>, follows a free form interview style tailored highlight the ideas and experience of security gurus.  By contrast, Reality Check is concerned with practical questions centered on running large-scale software security initiatives in the real world.</p>
<p>Reality Check targets experienced leaders working to solve software security problems in large organizations every day.  We use a standard script to guide each conversation with questions about history, methodology, best practice, and measurement.  We plan to interview leaders of mature software security programs and leaders of programs just getting started.</p></blockquote>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/IHX8b38e93s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/ad-reality-check-security-podcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/185/0/Reality%20Check%20Security%20Podcast%20promo%20-%2050%20sec.mp3" length="1218367" type="audio/mpeg" />
		<itunes:duration>0:00:51</itunes:duration>
		<itunes:subtitle>Note: The Reality Check Podcast is no longer available.
We’re happy to announce the debut of The Reality Check Security Podcast with Gary McGraw:
The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners an[...]</itunes:subtitle>
		<itunes:summary>Note: The Reality Check Podcast is no longer available.
We’re happy to announce the debut of The Reality Check Security Podcast with Gary McGraw:
The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners and practical software security.   Reality Check’s sister podcast, the Silver Bullet Security Podcast with Gary McGraw, follows a free form interview style tailored highlight the ideas and experience of security gurus.  By contrast, Reality Check is concerned with practical questions centered on running large-scale software security initiatives in the real world.
Reality Check targets experienced leaders working to solve software security problems in large organizations every day.  We use a standard script to guide each conversation with questions about history, methodology, best practice, and measurement.  We plan to interview leaders of mature software security programs and leaders of programs just getting started.</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/185/0/Reality%20Check%20Security%20Podcast%20promo%20-%2050%20sec.mp3" fileSize="1218367" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/ad-reality-check-security-podcast/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=ad-reality-check-security-podcast</feedburner:origLink></item>
		<item>
		<title>Show 033 – An Interview with Laurie Williams</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/xKjpKBFZm6Q/</link>
		<comments>http://www.cigital.com/silver-bullet/show-033/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 17:41:28 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=40</guid>
		<description><![CDATA[On the 33rd episode of The Silver Bullet Security Podcast, Gary talks with Laurie Williams, Associate Professor of Computer Science at North Carolina State University. Gary and Laurie discuss Laurie&#8217;s nine years at IBM, Agile&#8217;s adoption in the commercial space, XP and software security, and what changes Laurie would make to the standard computer science [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Laurie Williams" src="http://www.cigital.com/silverbullet/lwilliams-125.png" style="padding-left: 7px" /></p>
<p>On the 33rd episode of The Silver Bullet Security Podcast, Gary talks with Laurie Williams, Associate Professor of Computer Science at North Carolina State University.  Gary and Laurie discuss Laurie&#8217;s nine years at IBM, Agile&#8217;s adoption in the commercial space, XP and software security, and what changes Laurie would make to the standard computer science curriculum to better prepare students.</p>
<ul>
<li><a href="http://collaboration.csc.ncsu.edu/laurie/">Laurie Williams</a></li>
<li><a href="http://agile.csc.ncsu.edu/realsearch/">Empirical Software Engineering</a></li>
<li><a href="http://collaboration.csc.ncsu.edu/laurie/Security/ProtectionPoker/">Protection Poker tutorial</a></li>
<li><a href="http://collaboration.csc.ncsu.edu/laurie/Papers/p47-shin.pdf">Is Complexity Really the Enemy of Software Security?</a> [PDF]</li>
<li><a href="http://www.cigital.com/silverbullet/show-026/">Silver Bullet interview with Adam Shostack</a></li>
<li><a href="http://www.learnoutloud.com/Sale-Section/Self-Development/Spirituality/The-Law-of-Attraction/20044"><em>Law of Attraction</em></a> audiobook</li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/xKjpKBFZm6Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-033/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/184/0/silverbullet-033.mp3" length="34050176" type="audio/mpeg" />
		<itunes:duration>0:23:39</itunes:duration>
		<itunes:subtitle>
On the 33rd episode of The Silver Bullet Security Podcast, Gary talks with Laurie Williams, Associate Professor of Computer Science at North Carolina State University.  Gary and Laurie discuss Laurie’s nine years at IBM, Agile’s adoptio[...]</itunes:subtitle>
		<itunes:summary>
On the 33rd episode of The Silver Bullet Security Podcast, Gary talks with Laurie Williams, Associate Professor of Computer Science at North Carolina State University.  Gary and Laurie discuss Laurie’s nine years at IBM, Agile’s adoption in the commercial space, XP and software security, and what changes Laurie would make to the standard computer science curriculum to better prepare students.

Laurie Williams
Empirical Software Engineering
Protection Poker tutorial
Is Complexity Really the Enemy of Software Security? [PDF]
Silver Bullet interview with Adam Shostack
Law of Attraction audiobook

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/184/0/silverbullet-033.mp3" fileSize="34050176" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-033/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-033</feedburner:origLink></item>
		<item>
		<title>Show 032 – An Interview with Jeremiah Grossman</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/mFvuHhGTqFo/</link>
		<comments>http://www.cigital.com/silver-bullet/show-032/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 02:17:49 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=38</guid>
		<description><![CDATA[The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman. Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour. Transcript of this episode [PDF] Jeremiah [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Jeremiah Grossman" src="http://www.cigital.com/silverbullet/jgrossman-125.png" style="padding-left: 7px" /></p>
<p>The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-032-jgrossman.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a></li>
<li><a href="http://jeremiahgrossman.blogspot.com/2008/10/clickjacking-web-pages-can-see-and-hear.html">Clickjacking</a></li>
<li><a href="http://www.webadminblog.com/index.php/2008/09/24/new-0day-browser-exploit-clickjacking-owasp-appsec-nyc-2008/">Adobe 0-day Browser Exploit</a></li>
<li><a href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf">Cross-Site Request Forgeries: Exploitation and Prevention</a> [PDF]</li>
<li><a href="http://www.cs.princeton.edu/sip/pub/spoofing.php3">Web Spoofing: An Internet Con Game</a> by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2007/05/web-application-scan-o-meter.html">Web application scan-o-meter</a></li>
<li><a href="http://1.bp.blogspot.com/_JdybrokZBAk/SO_rUc-ebPI/AAAAAAAABOY/dKbFPJfv1Cs/s1600-h/badgewall.jpg">The &#8220;Wall of Fame&#8221;</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/mFvuHhGTqFo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-032/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/183/0/silverbullet-032.mp3" length="42240718" type="audio/mpeg" />
		<itunes:duration>0:29:20</itunes:duration>
		<itunes:subtitle>
The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can’t b[...]</itunes:subtitle>
		<itunes:summary>
The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can’t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.

Transcript of this episode [PDF]
Jeremiah Grossman
Clickjacking
Adobe 0-day Browser Exploit
Cross-Site Request Forgeries: Exploitation and Prevention [PDF]
Web Spoofing: An Internet Con Game by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach.
Web application scan-o-meter
The “Wall of Fame”

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/183/0/silverbullet-032.mp3" fileSize="42240718" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-032/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-032</feedburner:origLink></item>
		<item>
		<title>Show 031 – An Interview with Matt Bishop</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/uO5mrd1SiDQ/</link>
		<comments>http://www.cigital.com/silver-bullet/show-031/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 18:33:12 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-031/</guid>
		<description><![CDATA[On the 31st episode of The Silver Bullet Security Podcast, Gary talks with Matt Bishop, professor of Computer Science at UC Davis and author of the book Computer Security: Art and Science as well as many peer-reviewed papers. Gary and Matt discuss Matt&#8217;s plan to work security analysis and secure coding into a wider computer [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Matt Bishop" src="http://www.cigital.com/silverbullet/mbishop-125.png" style="padding-left: 7px" /></p>
<p>On the 31st episode of The Silver Bullet Security Podcast, Gary talks with Matt Bishop, professor of Computer Science at UC Davis and author of the book <em>Computer Security: Art and Science</em> as well as many peer-reviewed papers.  Gary and Matt discuss Matt&#8217;s plan to work security analysis and secure coding into a wider computer science cirriculum, Matt&#8217;s early work with Mike Dilger on TOCTOU, whether or not progress is being made in the field of software security, and the role of training in large-scale software security initiatives. Their chat closes with a mention of Matt&#8217;s home menagerie (which does not include any one-legged chickens at this time).</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-031-mbishop.pdf">Transcript of this episode</a></li>
<li><a href="http://nob.cs.ucdavis.edu/bishop/">Matt Bishop</a></li>
<li><a href="http://www.computer.org/security">IEEE <em>Security &amp; Privacy Magazine</em></a></li>
<li><a href="http://nob.cs.ucdavis.edu/book/book-aands/"><em>Computer Security: Art and Science</em></a></li>
<li><a href="http://www.cigital.com/silverbullet/show-011/">Silver Bullet Security Podcast interview with Dorothy Denning</a></li>
<li><a href="http://www.rand.org/pubs/reports/R609-1/R609.1.html">Security Controls for Computer Systems: Report of Defense Science Board Task Force on Computer Security</a> (the &#8220;Ware Report&#8221; referred to in the podcast)</li>
<li><a href="http://www.albany.edu/acc/courses/ia/classics/belllapadula1.pdf">Secure Computer Systems: Mathematical Foundations</a> &#8211; The Bell Lapadula model [PDF]</li>
<li><a href="http://csrc.nist.gov/publications/history/bell76.pdf">Secure Computer System: Unified Exposition and Multics Interpretation</a> [PDF]</li>
<li><a href="http://seclab.cs.ucdavis.edu/papers/HaughBishopNDSS2003.pdf">Testing C Programs for Buffer Overflow Vulnerabilities</a> &#8211; Eric Haugh, Matt Bishop [PDF]</li>
<li><a href="http://www.owasp.org/index.php/File_Access_Race_Condition:_TOCTOU">TOCTOU</a></li>
<li><a href="http://nob.cs.ucdavis.edu/bishop/papers/1996-compsys/">Checking for Race Conditions in File Accesses</a> by Matt Bishop and Michael Dilger</li>
<li><a href="http://www.amazon.com/Song-One-Legged-Chicken/dp/B000V672OK">&#8220;The Song of the One Legged Chicken&#8221;</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/uO5mrd1SiDQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-031/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	<enclosure url="http://www.albany.edu/acc/courses/ia/classics/belllapadula1.pdf" length="192030" type="application/pdf" /><media:content url="http://www.albany.edu/acc/courses/ia/classics/belllapadula1.pdf" fileSize="192030" type="application/pdf" /><itunes:explicit>no</itunes:explicit><itunes:author>Gary McGraw</itunes:author><itunes:summary>Industry Leaders In Application Security &amp; Research</itunes:summary><itunes:keywords>software,security</itunes:keywords><feedburner:origLink>http://www.cigital.com/silver-bullet/show-031/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-031</feedburner:origLink></item>
		<item>
		<title>Show 030 – An Interview with Ken van Wyk</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/5a5GmyljTZc/</link>
		<comments>http://www.cigital.com/silver-bullet/show-030/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 21:23:25 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/</guid>
		<description><![CDATA[On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates. Ken was the first employee of CERT and has been an active member of FIRST. Ken and Gary discuss why the discipline of computer science doesn&#8217;t learn from failure like mechanical engineering does, [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ken van Wyk" src="http://www.cigital.com/silverbullet/kvanwyk-125.png" style="padding-left: 7px" /></p>
<p>On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline of computer science doesn&#8217;t learn from failure like mechanical engineering does, how we&#8217;re making steps backwards in computer security, whether focusing on web applications is a good or bad thing for software security, and Ken&#8217;s recommendation for moderately-priced red wines.</p>
<ul>
<li><a href="http://www.vanwyk.org/ken/">Ken&#8217;s personal page</a></li>
<li><a href="http://www.krvw.com/">KRvW Associates</a></li>
<li><a href="http://www.cert.org/">CERT</a></li>
<li><a href="http://www.first.org/">FIRST</a></li>
<li><a href="http://www.securecoding.org/"><em>Secure Coding</em></a></li>
<li><a href="http://oreilly.com/catalog/9780596001308/"><em>Incident Response</em></a></li>
<li><a href="http://www.securecoding.org/list/">SC-L mailing list</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/07/06/from-the-foreword-to-secure-programming-with-static-analysis/">From the foreword to Secure Programming with Static Analysis</a> &#8211; blog entry with photo of Tacoma Narrows Bridge</li>
<li><a href="http://finance.google.com/finance?chdnp=1&amp;chdd=1&amp;chds=1&amp;chdv=1&amp;chvs=maximized&amp;chdeh=0&amp;chdet=1222200000000&amp;chddm=166345&amp;q=NYSE:TJX&amp;ntsp=0">TJX&#8217;s stock increase since the January 2007 security breach</a></li>
<li><a href="http://www.buildsecurityin.com/">The Addison-Wesley Software Security Series</a></li>
<li><a href="http://www.google.com/search?hl=en&amp;client=opera&amp;rls=en&amp;hs=fdc&amp;sa=X&amp;oi=spell&amp;resnum=0&amp;ct=result&amp;cd=1&amp;q=barbera+d%27asti&amp;spell=1">Barbera D&#8217;Asti wines</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/5a5GmyljTZc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-030/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/181/0/silverbullet-030.mp3" length="31395675" type="audio/mpeg" />
		<itunes:duration>0:21:48</itunes:duration>
		<itunes:subtitle>
On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline o[...]</itunes:subtitle>
		<itunes:summary>
On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline of computer science doesn’t learn from failure like mechanical engineering does, how we’re making steps backwards in computer security, whether focusing on web applications is a good or bad thing for software security, and Ken’s recommendation for moderately-priced red wines.

Ken’s personal page
KRvW Associates
CERT
FIRST
Secure Coding
Incident Response
SC-L mailing list
From the foreword to Secure Programming with Static Analysis – blog entry with photo of Tacoma Narrows Bridge
TJX’s stock increase since the January 2007 security breach
The Addison-Wesley Software Security Series
Barbera D’Asti wines
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/181/0/silverbullet-030.mp3" fileSize="31395675" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-030/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-030</feedburner:origLink></item>
		<item>
		<title>Show 029 – An Interview with Dennis Fisher</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/mj1hC7KvF08/</link>
		<comments>http://www.cigital.com/silver-bullet/show-029/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 15:05:01 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-029-an-interview-with-dennis-fisher/</guid>
		<description><![CDATA[On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget. Dennis helps run SearchSecurity.com and Information Security Magazine. Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Dennis Fisher" src="http://www.cigital.com/silverbullet/dfisher-108.png" style="padding-left: 7px" /></p>
<p>On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and <em>Information Security Magazine</em>.  Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state of software security, and which is harder: being a fry cook at Hardees or working as a PR flack.</p>
<ul>
<li><a href="http://security.blogs.techtarget.com/author/security/">Dennis&#8217; blog</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1239802,00.html">TJX</a></li>
<li><a href="http://music.aol.com/video/dirty-laundry/the-eagles/tag/joe-walsh/1354381">Joe Walsh plays dirty laundry</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1237978">Software Security Grows</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/2008/07/31/the-state-of-software-security">Dennis&#8217; un-named podcast</a></li>
<li><a href="http://www.youtube.com/watch?v=f99PcP0aFNE">Series of Tubes</a></li>
<li><a href="http://www.hardees.com/">Hardees</a></li>
<li><a href="http://www.cs.washington.edu/research/systems/privacy.htm">Nike/iPod</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/mj1hC7KvF08" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-029/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/180/0/silverbullet-029.mp3" length="34313704" type="audio/mpeg" />
		<itunes:duration>0:23:50</itunes:duration>
		<itunes:subtitle>
On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and Information Security Magazine.  Gary and Dennis discuss t[...]</itunes:subtitle>
		<itunes:summary>
On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and Information Security Magazine.  Gary and Dennis discuss the current “BS factor” in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state of software security, and which is harder: being a fry cook at Hardees or working as a PR flack.

Dennis’ blog
TJX
Joe Walsh plays dirty laundry
Software Security Grows
Dennis’ un-named podcast
Series of Tubes
Hardees
Nike/iPod
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/180/0/silverbullet-029.mp3" fileSize="34313704" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-029/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-029</feedburner:origLink></item>
		<item>
		<title>Show 028 – An Interview with Bill Cheswick</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/uRe-iwqrToA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-028/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 19:30:25 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-028/</guid>
		<description><![CDATA[On the 28th episode of The Silver Bullet Security Podcast, Gary interviews Bill Cheswick, a lead member of technical staff at AT&#38;T Research and all around security guru. Bill has been working in computer security for over 35 years. He coined the term &#8220;proxy&#8221; in 1990 with reference to firewalls, and co-authored the book Firewalls [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Bill Cheswick" src="http://www.cigital.com/silverbullet/bcheswick-125.png" style="padding-left: 7px" /></p>
<p>On the 28th episode of <em>The Silver Bullet Security Podcast</em>, Gary interviews Bill Cheswick, a lead member of technical staff at AT&amp;T Research and all around security guru.  Bill has been working in computer security for over 35 years.  He coined the term &#8220;proxy&#8221; in 1990 with reference to firewalls, and co-authored the book <em>Firewalls and Internet Security</em> which was used to train an entire generation of sys admins.  Gary and Bill discuss whether we&#8217;re winning or losing the computer security war, how security threats have evolved from pimply-faced teenagers to organized crime, whether we should move security into &#8220;the cloud,&#8221; and whether re-naming &#8220;Christmas lights&#8221; to &#8220;solstice lights&#8221; would bypass NJ holiday decoration ordinances.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-028-bcheswick.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cheswick.com/ches/">Bill Cheswick</a></li>
<li><a href="http://www.research.att.com/">AT&amp;T Research</a></li>
<li><a href="http://www.lumeta.com/">Lumeta</a></li>
<li><a href="http://www.wilyhacker.com/">FWIS</a></li>
<li>“<a href="http://www.clusit.it/whitepapers/gateway.pdf">The Design of a Secure Internet Gateway</a>” (Usenix 1990, coining of “proxy”)</li>
<li><a href="http://httpd.apache.org/">The Apache web server</a></li>
<li><a href="http://en.wikipedia.org/wiki/Turtles_all_the_way_down">Turtles all the Way Down</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-022/">Ed Amoroso’s Silver Bullet Podcast</a> (use blink test to compare)</li>
<li><a href="http://www.solsticelights.com/">Solstice Lights</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/uRe-iwqrToA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-028/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/179/0/silverbullet-028.mp3" length="34531879" type="audio/mpeg" />
		<itunes:duration>0:23:59</itunes:duration>
		<itunes:subtitle>
On the 28th episode of The Silver Bullet Security Podcast, Gary interviews Bill Cheswick, a lead member of technical staff at AT&amp;T Research and all around security guru.  Bill has been working in computer security for over 35 years.  He coined [...]</itunes:subtitle>
		<itunes:summary>
On the 28th episode of The Silver Bullet Security Podcast, Gary interviews Bill Cheswick, a lead member of technical staff at AT&amp;T Research and all around security guru.  Bill has been working in computer security for over 35 years.  He coined the term “proxy” in 1990 with reference to firewalls, and co-authored the book Firewalls and Internet Security which was used to train an entire generation of sys admins.  Gary and Bill discuss whether we’re winning or losing the computer security war, how security threats have evolved from pimply-faced teenagers to organized crime, whether we should move security into “the cloud,” and whether re-naming “Christmas lights” to “solstice lights” would bypass NJ holiday decoration ordinances.

Transcript of this episode [PDF]
Bill Cheswick
AT&amp;T Research
Lumeta
FWIS
“The Design of a Secure Internet Gateway” (Usenix 1990, coining of “proxy”)
The Apache web server
Turtles all the Way Down
Ed Amoroso’s Silver Bullet Podcast (use blink test to compare)
Solstice Lights

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/179/0/silverbullet-028.mp3" fileSize="34531879" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-028/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-028</feedburner:origLink></item>
		<item>
		<title>Show 027 – An Interview with Gunnar Peterson</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/3pqISyu7-T4/</link>
		<comments>http://www.cigital.com/silver-bullet/show-027/#comments</comments>
		<pubDate>Wed, 18 Jun 2008 13:30:44 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-027/</guid>
		<description><![CDATA[On the 27th episode of The Silver Bullet Security Podcast, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group. Gary and Gunnar begin with the age-old question, &#8220;What is security?&#8221; They go on to discuss how Web 2.0 and SOA security is progressing, the big idea behind &#8220;federated identity,&#8221; whether all [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Gunnar Peterson" src="http://www.cigital.com/silverbullet/gpeterson-123.gif" style="padding-left: 7px" /></p>
<p>On the 27th episode of <em>The Silver Bullet Security Podcast</em>, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group.  Gary and Gunnar begin with the age-old question, &#8220;What is security?&#8221;  They go on to discuss how Web 2.0 and SOA security is progressing, the big idea behind &#8220;federated identity,&#8221; whether all market verticals can follow the software security lead of the financial services industry, and the inherent badness of the color purple.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-027-gpeterson.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.computer.org/portal/pages/security/2008/n2/bsi.xml">Build Security In column from IEEE S&amp;P</a></li>
<li><a href="http://1raindrop.typepad.com/">Gunnar’s Blog</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1217101">informIT (Securing Web 3.0)</a></li>
<li><a href="http://www.securitymetrics.org/content/Wiki.jsp?page=Welcome_blogentry_110308_1">Metricon 3.0</a></li>
<li><a href="http://research.microsoft.com/lampson/69-SecurityRealIEEE/69-SecurityRealIEEE.htm">Butler Lampson on Security</a></li>
<li><a href="http://en.wikipedia.org/wiki/Federated_identity">Federated Identity</a></li>
<li><a href="http://www.pingidentity.com/">Ping Identity</a></li>
<li><a href="http://www.geraldmweinberg.com/Site/Home.html">Gerald Weinberg</a></li>
<li><a href="http://securityblog.verizonbusiness.com/2008/06/13/patching-conundrum/">Verizon Business Security: Patching Conundrum</a></li>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/3pqISyu7-T4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-027/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/178/0/silverbullet-027.mp3" length="40217586" type="audio/mpeg" />
		<itunes:duration>0:27:56</itunes:duration>
		<itunes:subtitle>
On the 27th episode of The Silver Bullet Security Podcast, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group.  Gary and Gunnar begin with the age-old question, “What is security?”  They go on[...]</itunes:subtitle>
		<itunes:summary>
On the 27th episode of The Silver Bullet Security Podcast, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group.  Gary and Gunnar begin with the age-old question, “What is security?”  They go on to discuss how Web 2.0 and SOA security is progressing, the big idea behind “federated identity,” whether all market verticals can follow the software security lead of the financial services industry, and the inherent badness of the color purple.

Transcript of this episode [PDF]
Build Security In column from IEEE S&amp;P
Gunnar’s Blog
informIT (Securing Web 3.0)
Metricon 3.0
Butler Lampson on Security
Federated Identity
Ping Identity
Gerald Weinberg
Verizon Business Security: Patching Conundrum

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/178/0/silverbullet-027.mp3" fileSize="40217586" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-027/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-027</feedburner:origLink></item>
		<item>
		<title>Show 026 – An Interview with Adam Shostack</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/796aiG66fJ8/</link>
		<comments>http://www.cigital.com/silver-bullet/show-026/#comments</comments>
		<pubDate>Thu, 15 May 2008 19:17:01 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-026/</guid>
		<description><![CDATA[The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsoft&#8217;s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective. Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Adam Shostack" src="http://www.cigital.com/silverbullet/ashostack-125.gif" style="padding-left: 7px" /></p>
<p>The 26th episode of <em>The Silver Bullet Security Podcast</em> features Adam Shostack, a security expert on Microsoft&#8217;s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book <em>The New School of Information Security</em>.  They go on to chat about Adam&#8217;s aversion to the term &#8220;best practices,&#8221; the role IEEE Security &amp; Privacy magazine plays in bringing the science of security to a practical level, and whether the biggest problem of the CardSystems breach was the following the letter, rather than the spirit, of PCI.  Also on the agenda, duck-billed platypuses, Kandinski, and books by Pynchon.</p>
<p>(Beginning with this episode, Silver Bullet will be available as a 192k MP3.)</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-026-ashostack.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.emergentchaos.com/">Emergent Chaos blog</a></li>
<li><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787/"><em>The New School of Information Security</em></a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx">Microsoft&#8217;s SDL</a></li>
<li><a href="http://www.cigital.com/justiceleague/category/software-security-touchpoints/">Cigital’s Touchpoints</a></li>
<li><a href="http://www.computer.org/portal/site/security"><em>IEEE Security &amp; Privacy magazine</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Wassily_Kandinsky">Wassily Kandinsky</a></li>
<li><a href="http://money.cnn.com/2005/06/17/news/master_card/index.htm">The CardSystems breach</a> (2005)</li>
<li><a href="http://en.wikipedia.org/wiki/Thomas_Pynchon">Thomas Pynchon</a>
</ul>
<p> </p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/796aiG66fJ8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-026/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/177/0/silverbullet-026.mp3" length="43490207" type="audio/mpeg" />
		<itunes:duration>0:30:12</itunes:duration>
		<itunes:subtitle>
The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsoft’s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got start[...]</itunes:subtitle>
		<itunes:summary>
The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsoft’s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book The New School of Information Security.  They go on to chat about Adam’s aversion to the term “best practices,” the role IEEE Security &amp; Privacy magazine plays in bringing the science of security to a practical level, and whether the biggest problem of the CardSystems breach was the following the letter, rather than the spirit, of PCI.  Also on the agenda, duck-billed platypuses, Kandinski, and books by Pynchon.
(Beginning with this episode, Silver Bullet will be available as a 192k MP3.)

Transcript of this episode [PDF]
Emergent Chaos blog
The New School of Information Security
Microsoft’s SDL
Cigital’s Touchpoints
IEEE Security &amp; Privacy magazine
Wassily Kandinsky
The CardSystems breach (2005)
Thomas Pynchon

 </itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/177/0/silverbullet-026.mp3" fileSize="43490207" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-026/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-026</feedburner:origLink></item>
		<item>
		<title>Show 025 – An Interview with Jon Swartz</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/dIrPwn0xjt0/</link>
		<comments>http://www.cigital.com/silver-bullet/show-025/#comments</comments>
		<pubDate>Fri, 18 Apr 2008 20:58:21 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-025-an-interview-with-jon-swartz/</guid>
		<description><![CDATA[Jon Swartz, USA Today&#8216;s award-winning technology reporter and Pulitzer Prize nominee, is Gary&#8217;s guest on the 25th episode of The Silver Bullet Security Podcast. They discuss Jon&#8217;s new book, Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity and the research that went into [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Jon Swartz" src="http://www.cigital.com/silverbullet/jswartz-125.gif" style="padding-left: 7px" /></p>
<p>Jon Swartz, <em>USA Today</em>&#8216;s award-winning technology reporter and Pulitzer Prize nominee, is Gary&#8217;s guest on the 25th episode of <em>The Silver Bullet Security Podcast</em>.  They discuss Jon&#8217;s new book, <em>Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity</em> and the research that went into writing it.  Gary and Jon also cover how cybercrime is driven by capitalist principals, why the general public&#8217;s attitude is so lax about software security, and how, even though it&#8217;s hard to get an accurate count of identity theft instances, they tend to show a sharp upward trend.  Jon ends the episode by disclosing his secret dream career.</p>
<p>(Apologies for the below-average sound quality on this episode.)</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-025-jswartz.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://zerodaythreat.com/"><em>Zero Day Threat</em></a></li>
<li><a href="http://www.usatoday.com/community/tags/reporter.aspx?id=321">Jon&#8217;s <em>USA Today</em> articles</a></li>
<li>Three recent articles:</li>
<ul>
<li><a href="http://www.usatoday.com/community/utils/idmap/31439036.story">Microsoft still seen with a win</a></li>
<li><a href="http://www.usatoday.com/community/utils/idmap/31438848.story">Online crime&#8217;s impact spreads</a></li>
<li><a href="http://www.usatoday.com/community/utils/idmap/31429572.story">AOL, News Corp. join battle over Yahoo</a></li>
</ul>
<li><a href="http://www.youtube.com/watch?v=-5zxOLZ5jXM"><em>The New Face of Cybercrime</em> trailer</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/dIrPwn0xjt0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-025/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/176/0/silverbullet-025.mp3" length="26697856" type="audio/mpeg" />
		<itunes:duration>0:27:49</itunes:duration>
		<itunes:subtitle>
Jon Swartz, USA Today‘s award-winning technology reporter and Pulitzer Prize nominee, is Gary’s guest on the 25th episode of The Silver Bullet Security Podcast.  They discuss Jon’s new book, Zero Day Threat: The Shocking Truth of [...]</itunes:subtitle>
		<itunes:summary>
Jon Swartz, USA Today‘s award-winning technology reporter and Pulitzer Prize nominee, is Gary’s guest on the 25th episode of The Silver Bullet Security Podcast.  They discuss Jon’s new book, Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity and the research that went into writing it.  Gary and Jon also cover how cybercrime is driven by capitalist principals, why the general public’s attitude is so lax about software security, and how, even though it’s hard to get an accurate count of identity theft instances, they tend to show a sharp upward trend.  Jon ends the episode by disclosing his secret dream career.
(Apologies for the below-average sound quality on this episode.)

Transcript of this episode [PDF]
Zero Day Threat
Jon’s USA Today articles
Three recent articles:

Microsoft still seen with a win
Online crime’s impact spreads
AOL, News Corp. join battle over Yahoo

The New Face of Cybercrime trailer
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/176/0/silverbullet-025.mp3" fileSize="26697856" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-025/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-025</feedburner:origLink></item>
		<item>
		<title>Show 024 – An Interview with Mary Ann Davidson</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/sT2C-0Jt-QU/</link>
		<comments>http://www.cigital.com/silver-bullet/show-024/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 18:26:36 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-024/</guid>
		<description><![CDATA[Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast. Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security. They also talk about how [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Mary Ann Davidson" src="http://www.cigital.com/silverbullet/madavidson-125.gif" /></p>
<p>Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk about how a young CSO-to-be got her first library card.</p>
<ul>
<li><a href="http://blogs.oracle.com/maryanndavidson/">Mary Ann Davidson&#8217;s blog</a></li>
<li><a href="http://wiki.oracle.com/page/Unbreakable+Linux">Unbreakable Linux</a></li>
<li><a href="http://www.amazon.com/Lone-Survivor-Eyewitness-Account-Operation/dp/0316067598"><em>Lone Survivor</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/sT2C-0Jt-QU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-024/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/175/0/silverbullet-024.mp3" length="27605631" type="audio/mpeg" />
		<itunes:duration>0:28:45</itunes:duration>
		<itunes:subtitle>
Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle’s “Unbreakable” campaign, why everyone nee[...]</itunes:subtitle>
		<itunes:summary>
Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle’s “Unbreakable” campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk about how a young CSO-to-be got her first library card.

Mary Ann Davidson’s blog
Unbreakable Linux
Lone Survivor
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/175/0/silverbullet-024.mp3" fileSize="27605631" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-024/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-024</feedburner:origLink></item>
		<item>
		<title>Show 023 – An Interview with Chris Wysopal</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/R0g4im74AHY/</link>
		<comments>http://www.cigital.com/silver-bullet/show-023/#comments</comments>
		<pubDate>Tue, 19 Feb 2008 16:41:13 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-023/</guid>
		<description><![CDATA[On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of The Art of Software Security Testing. Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to work [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Chris Wysopal" src="http://www.cigital.com/silverbullet/cwysopal-125.gif" /></p>
<p>On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of <em>The Art of Software Security Testing</em>.  Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to work for @stake.  Gary and Chris reminisce about L0pht (and the warehouse full of stuff) and discuss the role of security researchers now versus in the mid-late &#8217;90s. They also talk about the current state of the software security market and its continued growth.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Weld_Pond">Chris&#8217; Wikipedia entry</a></li>
<li><a href="http://www.softwaresecuritytesting.com/"><em>The Art of Software Security Testing</em></a></li>
<li><a href="http://www.veracode.com/">Veracode</a></li>
<li><a href="http://www.veracode.com/blog/">Zero in a bit</a> &#8211; Veracode&#8217;s blog</li>
<li><a href="http://en.wikipedia.org/wiki/L0pht">L0pht Heavy Industries</a></li>
<li><a href="http://www.vulnwatch.org/">Vulnwatch</a></li>
<li><a href="http://www.sourceboston.com/">SOURCE: Boston 2008</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/R0g4im74AHY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-023/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/174/0/silverbullet-023.mp3" length="23801984" type="audio/mpeg" />
		<itunes:duration>0:24:48</itunes:duration>
		<itunes:subtitle>
On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of The Art of Software Security Testing.  Chris was one of the seven original members of the L0pht hacker collective (o[...]</itunes:subtitle>
		<itunes:summary>
On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of The Art of Software Security Testing.  Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to work for @stake.  Gary and Chris reminisce about L0pht (and the warehouse full of stuff) and discuss the role of security researchers now versus in the mid-late ’90s. They also talk about the current state of the software security market and its continued growth.

Chris’ Wikipedia entry
The Art of Software Security Testing
Veracode
Zero in a bit – Veracode’s blog
L0pht Heavy Industries
Vulnwatch
SOURCE: Boston 2008
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/174/0/silverbullet-023.mp3" fileSize="23801984" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-023/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-023</feedburner:origLink></item>
		<item>
		<title>Show 022 – An Interview with Ed Amoroso</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/GL7cq_p8X1k/</link>
		<comments>http://www.cigital.com/silver-bullet/show-022/#comments</comments>
		<pubDate>Wed, 23 Jan 2008 21:33:09 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-022/</guid>
		<description><![CDATA[On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&#38;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ed Amaroso" src="http://www.cigital.com/silverbullet/eamoroso-125.gif" /></p>
<p style="margin-top: 5px">On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&amp;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and software correctness/quality vs software security.  They also discuss the Hugh Thompson show now airing on AT&amp;T&#8217;s Tech Channel.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-022-eamoroso.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.silicon-press.com/books/isbn.0-929306-38-4/index.html"><em>Cyber Security</em></a></li>
<li><a href="http://www.amazon.com/Fundamentals-Computer-Security-Technology-Amoroso/dp/0131089293"><em>Fundamentals of Computer Security Technology</em></a></li>
<li><a href="http://www.cigital.com/silverbullet/show-014/">Silver Bullet Interview with Peter Neumann</a></li>
<li><a href="http://www.att.com/techchannel/">AT&amp;T&#8217;s Tech Channel</a></li>
<li><a href="http://techchannel.att.com/site/home/index.cfm?key=7fb7b3944a89e2e9178bb2ce6d83e9d8">Gary on <em>The Hugh Thompson Show</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/GL7cq_p8X1k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-022/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/173/0/silverbullet-022.mp3" length="31119488" type="audio/mpeg" />
		<itunes:duration>0:32:25</itunes:duration>
		<itunes:subtitle>
On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&amp;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting [...]</itunes:subtitle>
		<itunes:summary>
On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&amp;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and software correctness/quality vs software security.  They also discuss the Hugh Thompson show now airing on AT&amp;T’s Tech Channel.

Transcript of this episode [PDF]
Cyber Security
Fundamentals of Computer Security Technology
Silver Bullet Interview with Peter Neumann
AT&amp;T’s Tech Channel
Gary on The Hugh Thompson Show
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/173/0/silverbullet-022.mp3" fileSize="31119488" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-022/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-022</feedburner:origLink></item>
		<item>
		<title>Show 021 – A Panel Discussion with Cigital’s Principals</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/QURvZX5rBb8/</link>
		<comments>http://www.cigital.com/silver-bullet/show-021/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 20:40:32 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-021/</guid>
		<description><![CDATA[For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals. Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant). The group discusses the best ways for large companies to get started with software security and the similarities [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Cigital Logo" src="http://www.cigital.com/silverbullet/cigital-125.gif" /></p>
<p style="margin-top: 5px">For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and the similarities between CLASP, Microsoft&#8217;s SDL, and the Security Touchpoints.  They also ponder how much the security testing burden should fall on QA and whether developing expertise in architectural risk analysis or threat modeling is more helpful.  John Steven also discusses the hole in his dining room, which threat modeling would not have helped to prevent.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-021-cigital.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cigital.com/justiceleague/">Justice League blog</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/11/13/threat-modeling/">Threat Modeling</a> &#8211; a blog entry by John Steven</li>
<li><a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top 10 for 2007</a></li>
<li><a href="http://www.owasp.org/">OWASP</a></li>
<li><a href="http://www.shmoo.com/">The Shmoo Group</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/QURvZX5rBb8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-021/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/172/0/silverbullet-021.mp3" length="22640768" type="audio/mpeg" />
		<itunes:duration>0:23:35</itunes:duration>
		<itunes:subtitle>
For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital’s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pr[...]</itunes:subtitle>
		<itunes:summary>
For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital’s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and the similarities between CLASP, Microsoft’s SDL, and the Security Touchpoints.  They also ponder how much the security testing burden should fall on QA and whether developing expertise in architectural risk analysis or threat modeling is more helpful.  John Steven also discusses the hole in his dining room, which threat modeling would not have helped to prevent.

Transcript of this episode [PDF]
Justice League blog
Threat Modeling – a blog entry by John Steven
OWASP Top 10 for 2007
OWASP
The Shmoo Group
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/172/0/silverbullet-021.mp3" fileSize="22640768" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-021/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-021</feedburner:origLink></item>
		<item>
		<title>Happy Holidays from Silver Bullet</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/eoWlJK3UjVI/</link>
		<comments>http://www.cigital.com/silver-bullet/happy-holidays-from-silver-bullet/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 17:07:55 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/</guid>
		<description />
				<content:encoded><![CDATA[<p align="center"><img src="http://www.cigital.com/wp-content/plugins/flash-video-player/default_video_player.gif" /></p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/eoWlJK3UjVI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/happy-holidays-from-silver-bullet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.cigital.com/silver-bullet/happy-holidays-from-silver-bullet/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=happy-holidays-from-silver-bullet</feedburner:origLink></item>
		<item>
		<title>Show 020 – An Interview with Markus Jakobsson</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/KbERBLEMbnc/</link>
		<comments>http://www.cigital.com/silver-bullet/show-020/#comments</comments>
		<pubDate>Fri, 16 Nov 2007 22:32:45 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-020/</guid>
		<description><![CDATA[For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University. Gary and Markus discuss the difference between academic and corporate research, [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Markus Jakobsson" src="http://www.cigital.com/silverbullet/mjakobsson-125.gif" /></p>
<p style="margin-top: 5px">For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University.  Gary and Markus discuss the difference between academic and corporate research, the idea of &#8220;perfect privacy,&#8221; moving from hardcore cryptography to sociology, how reality is mimicking phishers, and how cartoons can be used to teach security.  In addition, Markus mentions the best place in Southeast Asia to get a haircut.</p>
<ul>
<li><a href="http://www.informatics.indiana.edu/markus/">Markus @ Indiana</a></li>
<li><a href="http://en.wikipedia.org/wiki/Markus_Jakobsson">Markus @ Wikipedia</a> &#8211; he&#8217;s &#8220;orphaned&#8221;!</li>
<li><a href="http://www.ravenwhite.com/">RavenWhite</a></li>
<li><a href="http://www.securitycartoon.com/">SecurityCartoon.com</a></li>
<li><a href="http://www.amazon.com/Crimeware-Symantec-Press-Markus-Jakobsson/dp/0321501950"><em>Crimeware</em><a></li>
<li><a href="http://phishing-and-countermeasures.com/"><em>Phishing and Countermeasures</em></a></li>
<li><a href="http://www.informatics.indiana.edu/markus/documents/security-education.pdf">Using Cartoons to Teach Internet Security</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/KbERBLEMbnc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-020/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/170/0/silverbullet-020.mp3" length="23502848" type="audio/mpeg" />
		<itunes:duration>0:24:29</itunes:duration>
		<itunes:subtitle>
For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecur[...]</itunes:subtitle>
		<itunes:summary>
For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University.  Gary and Markus discuss the difference between academic and corporate research, the idea of “perfect privacy,” moving from hardcore cryptography to sociology, how reality is mimicking phishers, and how cartoons can be used to teach security.  In addition, Markus mentions the best place in Southeast Asia to get a haircut.

Markus @ Indiana
Markus @ Wikipedia – he’s “orphaned”!
RavenWhite
SecurityCartoon.com
Crimeware
Phishing and Countermeasures
Using Cartoons to Teach Internet Security
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/170/0/silverbullet-020.mp3" fileSize="23502848" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-020/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-020</feedburner:origLink></item>
		<item>
		<title>Show 019 – An Interview with Mikko Hyppönen</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/ssXt6qROYxk/</link>
		<comments>http://www.cigital.com/silver-bullet/show-019/#comments</comments>
		<pubDate>Thu, 18 Oct 2007 15:21:38 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-019/</guid>
		<description><![CDATA[For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko&#8217;s [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Mikko Hyppönen" src="http://www.cigital.com/silverbullet/mikko-125.gif" /></p>
<p style="margin-top: 5px">For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko&#8217;s prediction for the appearance of the first mobile botnet.  They also chat about Finnish hip-hop.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-019-mhypponen.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://mikko.hypponen.com/">Mikko Hyppönen</a></li>
<li><a href="http://en.wikipedia.org/wiki/Mikko_Hyppönen">Mikko Hyppönen</a>- Wikipedia</li>
<li><a href="http://www.f-secure.com/">F-Secure</a></li>
<li><a href="http://www.usenix.org/events/sec07/tech/#thurs">Mobile Malware</a> &#8211; Mikko&#8217;s USENIX 2007 talk, both audio and video (scroll down a bit)</li>
<li><a href="http://www.klov.com/game_detail.php?game_id=10505">Xevious</a></li>
<li><a href="http://www.management-consoles.com/">The FSMCs</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/ssXt6qROYxk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-019/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/169/0/silverbullet-019.mp3" length="21301376" type="audio/mpeg" />
		<itunes:duration>0:22:11</itunes:duration>
		<itunes:subtitle>
For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a le[...]</itunes:subtitle>
		<itunes:summary>
For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko’s prediction for the appearance of the first mobile botnet.  They also chat about Finnish hip-hop.

Transcript of this episode [PDF]
Mikko Hyppönen
Mikko Hyppönen- Wikipedia
F-Secure
Mobile Malware – Mikko’s USENIX 2007 talk, both audio and video (scroll down a bit)
Xevious
The FSMCs
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/169/0/silverbullet-019.mp3" fileSize="21301376" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-019/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-019</feedburner:origLink></item>
		<item>
		<title>Show 018 – An Interview with Eugene Spafford</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/B26m-4IbEjA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-018/#comments</comments>
		<pubDate>Tue, 25 Sep 2007 21:04:22 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-018/</guid>
		<description><![CDATA[On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as &#8220;Spaf.&#8221; Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS). On this episode, Gary [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Eugene Spafford" src="http://www.cigital.com/silverbullet/spaf-125.gif" /></p>
<p style="margin-top: 5px">On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as &#8220;Spaf.&#8221;  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS).  On this episode, Gary and Spaf discuss the role of software testing in computer security, commercial certifications and whether they obviate the need for academic training, how Spaf feels about so-called &#8220;ethical hacking,&#8221; and why auditing and compliance is an area of emerging specialization.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-018-spaf.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://spaf.cerias.purdue.edu/">Dr. Eugene Spafford</a></li>
<li><a href="http://www.cerias.purdue.edu/weblogs/author/spaf/">Spaf&#8217;s blog at CERIAS</a></li>
<li><a href="http://en.wikipedia.org/wiki/Gene_Spafford">Gene Spafford</a> &#8211; Wikipedia</li>
<li><a href="http://www.cerias.purdue.edu/">CERIAS</a> &#8211; Center for Education and Research in Information Assurance and Security</li>
<li><a href="http://www.ise.gmu.edu/~ofut/rsrch/mut.html">Mothra</a> &#8211; Mutation testing</li>
<li><a href="http://www.nitrd.gov/pitac/">PITAC</a> &#8211; President&#8217;s Information Technology  Advisory Committee</li>
<li><a href="http://www.cerias.purdue.edu/weblogs/spaf/kudos-opinions-rants/post-120/what-did-you-really-expect/">What did you really expect?</a> &#8211; Spaf&#8217;s post on &#8220;reformed hackers&#8221;</li>
<li><a href="http://wiretap.area.com/Gopher/Library/Techdoc/Virus/inetvir.823">The Internet Worm Program: An Analysis</a></li>
<li><a href="http://spaf.cerias.purdue.edu/~spaf/Yucks/">Yucks Digest</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/B26m-4IbEjA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-018/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/168/0/silverbullet-018.mp3" length="27003008" type="audio/mpeg" />
		<itunes:duration>0:28:08</itunes:duration>
		<itunes:subtitle>
On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as “Spaf.”  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive [...]</itunes:subtitle>
		<itunes:summary>
On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as “Spaf.”  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS).  On this episode, Gary and Spaf discuss the role of software testing in computer security, commercial certifications and whether they obviate the need for academic training, how Spaf feels about so-called “ethical hacking,” and why auditing and compliance is an area of emerging specialization.

Transcript of this episode [PDF]
Dr. Eugene Spafford
Spaf’s blog at CERIAS
Gene Spafford – Wikipedia
CERIAS – Center for Education and Research in Information Assurance and Security
Mothra – Mutation testing
PITAC – President’s Information Technology  Advisory Committee
What did you really expect? – Spaf’s post on “reformed hackers”
The Internet Worm Program: An Analysis
Yucks Digest
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/168/0/silverbullet-018.mp3" fileSize="27003008" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-018/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-018</feedburner:origLink></item>
		<item>
		<title>Show 017 – An Interview with Eric Cole</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/ksPVUX8qRBw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-017/#comments</comments>
		<pubDate>Fri, 24 Aug 2007 20:19:43 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-017/</guid>
		<description><![CDATA[On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor. Eric has written seven books on computer security, including books on steganography and network security. Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), the academic [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Eric Cole" src="http://www.cigital.com/silverbullet/ecole-125.gif" /></p>
<p style="margin-top: 5px">On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), the academic approach to security versus practitioner certification models, and what kinds of training makes for good network security practitioners.  They also discuss the difficulty of certifying software developers.</p>
<ul>
<li><a href="http://www.secure-anchor.com/">Secure Anchor</a></li>
<li><a href="http://www.securityhaven.com/">Security Haven</a></li>
<li><a href="http://digitalcommons.pace.edu/dissertations/AAI3127379/">Stego-marking packets to control information leakage on TCP/IP based networks</a> &#8211; Eric&#8217;s dissertation</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/ksPVUX8qRBw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-017/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/167/0/silverbullet-017.mp3" length="28208320" type="audio/mpeg" />
		<itunes:duration>0:29:23</itunes:duration>
		<itunes:subtitle>
On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to dem[...]</itunes:subtitle>
		<itunes:summary>
On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), the academic approach to security versus practitioner certification models, and what kinds of training makes for good network security practitioners.  They also discuss the difficulty of certifying software developers.

Secure Anchor
Security Haven
Stego-marking packets to control information leakage on TCP/IP based networks – Eric’s dissertation
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/167/0/silverbullet-017.mp3" fileSize="28208320" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-017/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-017</feedburner:origLink></item>
		<item>
		<title>Show 016 – An Interview with Greg Hoglund</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/r3xeZNcHV30/</link>
		<comments>http://www.cigital.com/silver-bullet/show-016/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 22:38:30 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-016/</guid>
		<description><![CDATA[On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of Rootkits: Subverting the Windows Kernel and Exploiting Software. In addition to shameless self-promotion of their new book, Exploiting Online Games, Gary and Greg discuss the natural tendency of [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Greg Hoglund" src="http://www.cigital.com/silverbullet/ghoglund-125.gif" /></p>
<p style="margin-top: 5px">On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of <em>Rootkits: Subverting the Windows Kernel</em> and <em>Exploiting Software</em>.  In addition to shameless self-promotion of their new book, <em>Exploiting Online Games</em>, Gary and Greg discuss the natural tendency of certain types of code to allow exploits, how disclosure is a good thing when it comes to revealing exploits, and the use of rootkits by the &#8220;good guys.&#8221;  Greg also makes us concerned that his 11-year-old daughter may 0wn our box.</p>
<ul>
<li><a href="http://www.rootkit.com/">Rootkit.com</a></li>
<li><a href="http://www.hbgary.com/">HB Gary</a></li>
<li>Greg&#8217;s Blackhat presentation from 2006: <a href="http://www.rootkit.com/vault/hoglund/GregSlidesWoWHack.rar">Hacking World of Warcraft(r): An Exercise in Advanced Rootkit Design</a> [rar, 2.35M]</li>
<li><a href="http://www.exploitingonlinegames.com/">Exploiting Online Games</a></li>
<li><a href="http://www.buildingsecurityin.com/">AWL Software Security Series</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/r3xeZNcHV30" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-016/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/166/0/silverbullet-016.mp3" length="23085184" type="audio/mpeg" />
		<itunes:duration>0:24:03</itunes:duration>
		<itunes:subtitle>
On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of Rootkits: Subverting the Windows Kernel and Exploiting Software.  In addition to shameless s[...]</itunes:subtitle>
		<itunes:summary>
On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of Rootkits: Subverting the Windows Kernel and Exploiting Software.  In addition to shameless self-promotion of their new book, Exploiting Online Games, Gary and Greg discuss the natural tendency of certain types of code to allow exploits, how disclosure is a good thing when it comes to revealing exploits, and the use of rootkits by the “good guys.”  Greg also makes us concerned that his 11-year-old daughter may 0wn our box.

Rootkit.com
HB Gary
Greg’s Blackhat presentation from 2006: Hacking World of Warcraft(r): An Exercise in Advanced Rootkit Design [rar, 2.35M]
Exploiting Online Games
AWL Software Security Series
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/166/0/silverbullet-016.mp3" fileSize="23085184" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-016/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-016</feedburner:origLink></item>
		<item>
		<title>Show 015 – An Interview with Annie Antón</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/TdHGMn2QGcI/</link>
		<comments>http://www.cigital.com/silver-bullet/show-015/#comments</comments>
		<pubDate>Tue, 19 Jun 2007 14:12:30 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-015/</guid>
		<description><![CDATA[On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org. During their discussion, Annie and Gary focus on privacy. They start with an attempt to define what &#8220;privacy&#8221; is in the digital world, moving on to Annie&#8217;s [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Annie Anton" src="http://www.cigital.com/silverbullet/aanton-125.gif" /></p>
<p style="margin-top: 5px">On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary focus on privacy.  They start with an attempt to define what &#8220;privacy&#8221; is in the digital world,  moving on to Annie&#8217;s work with The Privacy Place.  Annie also discusses airlines&#8217; pretty much pitiful privacy policies, the impact that a Google/Doubleclick deal would have on consumer privacy, crazy talk in EULAs, and the book <em>Letters to a Young Catholic</em> (which has nothing to do with privacy).</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-015-aanton.pdf">A partial transcript of the interview in IEEE Security &amp; Privacy</a></li>
<li><a href="http://www4.ncsu.edu/~aianton/">Annie I. Antón</a></li>
<li><a href="http://www.theprivacyplace.org/">The Privacy Place</a></li>
<li><a href="http://www.privacyrights.org/ar/CPResponse.htm">The ChoicePoint Data Security Breach</a></li>
<li><a href="http://www.eppc.org/publications/bookID.50/book_detail.asp"><em>Letters to a Young Catholic</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/TdHGMn2QGcI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-015/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/165/0/silverbullet-015.mp3" length="2147483647" type="audio/mpeg" />
		<itunes:duration>0:25:16</itunes:duration>
		<itunes:subtitle>
On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary fo[...]</itunes:subtitle>
		<itunes:summary>
On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary focus on privacy.  They start with an attempt to define what “privacy” is in the digital world,  moving on to Annie’s work with The Privacy Place.  Annie also discusses airlines’ pretty much pitiful privacy policies, the impact that a Google/Doubleclick deal would have on consumer privacy, crazy talk in EULAs, and the book Letters to a Young Catholic (which has nothing to do with privacy).

A partial transcript of the interview in IEEE Security &amp; Privacy
Annie I. Antón
The Privacy Place
The ChoicePoint Data Security Breach
Letters to a Young Catholic
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/165/0/silverbullet-015.mp3" fileSize="2147483647" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-015/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-015</feedburner:origLink></item>
		<item>
		<title>Show 014 – An Interview with Peter Neumann</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/p1GAzC7YKQU/</link>
		<comments>http://www.cigital.com/silver-bullet/show-014/#comments</comments>
		<pubDate>Tue, 22 May 2007 17:04:03 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-014/</guid>
		<description><![CDATA[The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory. In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics engineering [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Peter Neumann" src="http://www.cigital.com/silverbullet/pneumann-125.gif" /></p>
<p style="margin-top: 5px">The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics engineering (&#8220;nodody writes a line of code without the approving authorities [having] read and understood the specification&#8221;), why DRM is the &#8220;wrong solution to the wrong problem,&#8221; and who was more interesting to meet: Albert Einstein or Norah Jones.</p>
<ul>
<li><a href="http://www.csl.sri.com/users/neumann/">Peter Neumann</a></li>
<li><a href="http://catless.ncl.ac.uk/risks">comp.RISKS</a></li>
<li><a href="http://www.csl.sri.com/users/neumann/neumann-book.html"><em>Computer-Related Risks</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Multics">Multics</a></li>
<li><a href="http://www.multicians.org/fjcc4.html">A General-Purpose File System For Secondary Storage</a> &#8211; Peter&#8217;s 1965 paper on Multics</li>
<li><a href="http://www.multicians.org/">Multics History Project</a></li>
<li><a href="http://www.luntzel.com/bbb/">The Brooklyn Boogaloo Blowout</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/p1GAzC7YKQU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-014/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/164/0/silverbullet-014.mp3" length="20148352" type="audio/mpeg" />
		<itunes:duration>0:20:59</itunes:duration>
		<itunes:subtitle>
The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss th[...]</itunes:subtitle>
		<itunes:summary>
The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics engineering (“nodody writes a line of code without the approving authorities [having] read and understood the specification”), why DRM is the “wrong solution to the wrong problem,” and who was more interesting to meet: Albert Einstein or Norah Jones.

Peter Neumann
comp.RISKS
Computer-Related Risks
Multics
A General-Purpose File System For Secondary Storage – Peter’s 1965 paper on Multics
Multics History Project
The Brooklyn Boogaloo Blowout
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/164/0/silverbullet-014.mp3" fileSize="20148352" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-014/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-014</feedburner:origLink></item>
		<item>
		<title>Show 013 – An Interview with Ross Anderson</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/vq2IymzhB1w/</link>
		<comments>http://www.cigital.com/silver-bullet/show-013/#comments</comments>
		<pubDate>Fri, 13 Apr 2007 20:33:21 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-013/</guid>
		<description><![CDATA[On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering. Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why most systems [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ross Anderson" src="http://www.cigital.com/silver-bullet-files/randerson-125.gif" /></p>
<p style="margin-top: 5px">On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book <em>Security Engineering</em>.   Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why most systems fail, the economic imbalance between engineers/developers and a system&#8217;s users (with respect to who should address security), and why publicly describing attacks is essential to security engineering.  They close out by examining the security implications of wearing a kilt.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-013-randerson.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.ross-anderson.com/">Ross Anderson</a></li>
<li><a href="http://www.lightbluetouchpaper.org/">Light Blue Touchpaper</a> &#8211; A security blog by Cambridge computer scientists.</li>
<li><em>Security Engineering</em> &#8211; Ross&#8217; groundbreaking book <a href="http://www.amazon.com/exec/obidos/ASIN/0471389226/rossandersshomep">in print</a> and <a href="http://www.cl.cam.ac.uk/~rja14/book.html">online</a></li>
<li><a href="http://weis2007.econinfosec.org/">WEIS 2007 &#8211; Sixth Workshop on the Economics of Information Security</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/Papers/rfid-fc07.pdf">RFID and the Middleman</a> [PDF]</li>
<li><a href="http://showcase.netins.net/web/clanande/">The Clan Anderson Society</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/Presentations/busking.jpg">Ross playing the bagpipes</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/vq2IymzhB1w" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-013/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/163/0/silverbullet-013.mp3" length="21927936" type="audio/mpeg" />
		<itunes:duration>0:22:50</itunes:duration>
		<itunes:subtitle>
On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering.   Gary and Ross discuss the [...]</itunes:subtitle>
		<itunes:summary>
On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering.   Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why most systems fail, the economic imbalance between engineers/developers and a system’s users (with respect to who should address security), and why publicly describing attacks is essential to security engineering.  They close out by examining the security implications of wearing a kilt.

Transcript of this episode [PDF]
Ross Anderson
Light Blue Touchpaper – A security blog by Cambridge computer scientists.
Security Engineering – Ross’ groundbreaking book in print and online
WEIS 2007 – Sixth Workshop on the Economics of Information Security
RFID and the Middleman [PDF]
The Clan Anderson Society
Ross playing the bagpipes
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/163/0/silverbullet-013.mp3" fileSize="21927936" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-013/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-013</feedburner:origLink></item>
		<item>
		<title>Show 012 – An Interview with Becky Bace</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Ogw1FbwYJEg/</link>
		<comments>http://www.cigital.com/silver-bullet/show-012/#comments</comments>
		<pubDate>Tue, 13 Mar 2007 21:13:02 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-012/</guid>
		<description><![CDATA[On the 12th episode of The Silver Bullet Security Podcast, Gary talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory. Gary and Becky discuss growing up in [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Becky Bace" src="http://www.cigital.com/silverbullet/bbace-125.gif" /></p>
<p style="margin-top: 5px">On the 12th episode of The Silver Bullet Security Podcast, Gary<br />
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory.  Gary and Becky discuss growing up in rural America, explosives, and Becky&#8217;s Jimmy Hoffa sponsored college funding situation. They also talk about the evolution of security curricula in academia, rampant commercialization of computer security, Becky&#8217;s involvement in tracking down the notorious Kevin Mitnick, vicodin-induced creativity, and eclectic music.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-012-bbace.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci927913,00.html">Who&#8217;s Who in Infosec: Rebecca Bace</a></li>
<li><a href="http://www.tridentcap.com/">Trident Capital</a> &#8211; The VC firm where Becky is an advisor</li>
<li><a href="http://www.thiemeworks.com/write/archives/beckyb2.htm">The IDS Den Mother</a> &#8211; a 2002 interview</li>
<li><a href="http://www.lanl.gov/">Los Alamos National Labs</a></li>
<li><a href="http://www.amazon.com/Intrusion-Detection-Rebecca-Gurley-Bace/dp/1578701856/ref=sr_1_1/104-2577668-4903944?ie=UTF8&amp;s=books&amp;qid=1173812537&amp;sr=8-1"><em>Intrusion Detection</em></a></li>
<li><a href="http://www.amazon.com/Guide-Forensic-Testimony-Presenting-Technical/dp/0201752794/ref=sr_1_2/104-2577668-4903944?ie=UTF8&amp;s=books&amp;qid=1173812537&amp;sr=8-2"><em>A Guide to Forensic Testimony: The Art and Practice of Presenting Testimony As An Expert Technical Witness</em></a> &#8211; Co-authored with Fred Smith</li>
<li><a href="http://www.infosecuritywomen.com/">Executive Women&#8217;s Forum</a></li>
<li><a href="http://www.franksinatra.com/">Frank Sinatra</a></li>
<li><a href="http://www.kinseysicks.com/">The Kinsey Sicks</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Ogw1FbwYJEg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/162/0/silverbullet-012.mp3" length="22704256" type="audio/mpeg" />
		<itunes:duration>0:23:39</itunes:duration>
		<itunes:subtitle>
On the 12th episode of The Silver Bullet Security Podcast, Gary
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, follow[...]</itunes:subtitle>
		<itunes:summary>
On the 12th episode of The Silver Bullet Security Podcast, Gary
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory.  Gary and Becky discuss growing up in rural America, explosives, and Becky’s Jimmy Hoffa sponsored college funding situation. They also talk about the evolution of security curricula in academia, rampant commercialization of computer security, Becky’s involvement in tracking down the notorious Kevin Mitnick, vicodin-induced creativity, and eclectic music.

Transcript of this episode [PDF]
Who’s Who in Infosec: Rebecca Bace
Trident Capital – The VC firm where Becky is an advisor
The IDS Den Mother – a 2002 interview
Los Alamos National Labs
Intrusion Detection
A Guide to Forensic Testimony: The Art and Practice of Presenting Testimony As An Expert Technical Witness – Co-authored with Fred Smith
Executive Women’s Forum
Frank Sinatra
The Kinsey Sicks
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/162/0/silverbullet-012.mp3" fileSize="22704256" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-012/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-012</feedburner:origLink></item>
		<item>
		<title>Show 011 – An Interview with Dorothy Denning</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/twDFcXAPyJ0/</link>
		<comments>http://www.cigital.com/silver-bullet/show-011/#comments</comments>
		<pubDate>Thu, 15 Feb 2007 22:07:35 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-011/</guid>
		<description><![CDATA[On the 11th episode of The Silver Bullet Security Podcast, Gary talks with Dorothy Denning, a professor in the Department of Defense Analysis at the Naval Postgraduate School. Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University. Gary and Dorothy discuss Dorothy&#8217;s involvement in the Clipper Chip controversy (which [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Dorothy Denning" src="http://www.cigital.com/silverbullet/ddenning-125.gif" /></p>
<p style="margin-top: 5px">On the 11th episode of The Silver Bullet Security Podcast, Gary talks with <a href="http://www.nps.navy.mil/ctiw/staff/denning.html">Dorothy Denning</a>, a professor in the <a href="http://www.nps.navy.mil/da/">Department of Defense Analysis</a> at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University.  Gary and Dorothy discuss Dorothy&#8217;s involvement in the Clipper Chip controversy (which earned Dorothy the moniker &#8220;clipper chick&#8221;), the concept of geo-encryption, and a famous 1990 paper she wrote describing a series of interviews with malicious hackers.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-011-ddenning.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://en.wikipedia.org/wiki/Dorothy_E._Denning">Wikipedia: Dorothy Denning</a></li>
<li><a href="http://www.epic.org/crypto/clipper/">Clipper Chip</a> (<a href="http://en.wikipedia.org/wiki/Clipper_chip">More</a>)</li>
<li><a href="http://www.wired.com/wired/archive/4.09/denning_pr.html">Clipper Chick</a> &#8211; a 1996 <em>Wired</em> article about the Clipper Chip controversy.</li>
<li><a href="http://www.cosc.georgetown.edu/~denning/crypto/Future.html">The Future of Cryptography</a></li>
<li><a href="http://www.cs.georgetown.edu/~denning/infosec/Grounding.txt">Location-Based Authentication: Grounding Cyberspace for Better Security</a> &#8211; A 1996 paper by Dorothy Denning and Peter F. MacDoran about geo-encryption.</li>
<li><a href="http://www.sgrm.com/art-7.htm">Concerning Hackers Who Break into Computer Systems</a> &#8211; Dorothy&#8217;s 1990 paper.</li>
<li><a href="http://www.bsim.org">Big Sur Power Walk</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/twDFcXAPyJ0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-011/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/161/0/silverbullet-011.mp3" length="21471242" type="audio/mpeg" />
		<itunes:duration>0:22:22</itunes:duration>
		<itunes:subtitle>
On the 11th episode of The Silver Bullet Security Podcast, Gary talks with Dorothy Denning, a professor in the Department of Defense Analysis at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown Univers[...]</itunes:subtitle>
		<itunes:summary>
On the 11th episode of The Silver Bullet Security Podcast, Gary talks with Dorothy Denning, a professor in the Department of Defense Analysis at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University.  Gary and Dorothy discuss Dorothy’s involvement in the Clipper Chip controversy (which earned Dorothy the moniker “clipper chick”), the concept of geo-encryption, and a famous 1990 paper she wrote describing a series of interviews with malicious hackers.

Transcript of this episode [PDF]
Wikipedia: Dorothy Denning
Clipper Chip (More)
Clipper Chick – a 1996 Wired article about the Clipper Chip controversy.
The Future of Cryptography
Location-Based Authentication: Grounding Cyberspace for Better Security – A 1996 paper by Dorothy Denning and Peter F. MacDoran about geo-encryption.
Concerning Hackers Who Break into Computer Systems – Dorothy’s 1990 paper.
Big Sur Power Walk
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/161/0/silverbullet-011.mp3" fileSize="21471242" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-011/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-011</feedburner:origLink></item>
		<item>
		<title>Show 010 – A Panel Discussion with Fortify Software’s Technical Advisory Board</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/_82XAEnhaWA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-010/#comments</comments>
		<pubDate>Mon, 22 Jan 2007 19:59:59 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-010/</guid>
		<description><![CDATA[The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the Fortify Software Technical Advisory Board, several of whom have been featured on previous episodes. The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using static [...]]]></description>
				<content:encoded><![CDATA[<p align="center"><img alt="Fortify TAB" src="http://www.cigital.com/silverbullet/fortify-tab.jpg" /></p>
<p style="margin-top: 5px">The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the <a href="http://www.fortifysoftware.com/company-partners/tab.jsp">Fortify Software Technical Advisory Board</a>, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using static analysis tools, and software security pedagogy.</p>
<p>Participating members of the Technical Advisory Board include:</p>
<ul>
<li><a href="http://www.cs.umd.edu/~pugh/">Bill Pugh</a>, Professor at University of Maryland, static analysis for finding bugs</li>
<li>Li Gong, GM at Microsoft, MSN in China</li>
<li><a href="http://www.ranum.com/">Marcus Ranum</a>, CSO of Tenable Network Security, security products trainer</li>
<li><a href="http://avirubin.com/">Avi Rubin</a>, Professor at Johns Hopkins, electronic voting security</li>
<li><a href="http://www.cs.cornell.edu/fbs/">Fred Schneider</a>, Professor at Cornell, trustworthy computing</a>
<li><a href="http://www.eecs.harvard.edu/~greg/">Greg Morrisett</a>, Professor at Harvard, dependant type theory</li>
<li><a href="http://nob.cs.ucdavis.edu/~bishop/">Matt Bishop</a>, Professor at UC Davis, computer security</li>
<li><a href="http://www.cs.berkeley.edu/~daw/">Dave Wagner</a>, Professor at Berkeley, software security and electronic voting</li>
</ul>
<p>A complete transcript of this podcast will be available soon from Fortify at <a href="http://www.fortify.com/silverbullet">http://www.fortify.com/silverbullet</a>.</p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/_82XAEnhaWA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/160/0/silverbullet-010.mp3" length="18776359" type="audio/mpeg" />
		<itunes:duration>0:19:34</itunes:duration>
		<itunes:subtitle>
The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the Fortify Software Technical Advisory Board, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can[...]</itunes:subtitle>
		<itunes:summary>
The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the Fortify Software Technical Advisory Board, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using static analysis tools, and software security pedagogy.
Participating members of the Technical Advisory Board include:

Bill Pugh, Professor at University of Maryland, static analysis for finding bugs
Li Gong, GM at Microsoft, MSN in China
Marcus Ranum, CSO of Tenable Network Security, security products trainer
Avi Rubin, Professor at Johns Hopkins, electronic voting security
Fred Schneider, Professor at Cornell, trustworthy computing
Greg Morrisett, Professor at Harvard, dependant type theory
Matt Bishop, Professor at UC Davis, computer security
Dave Wagner, Professor at Berkeley, software security and electronic voting

A complete transcript of this podcast will be available soon from Fortify at http://www.fortify.com/silverbullet.</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/160/0/silverbullet-010.mp3" fileSize="18776359" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-010/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-010</feedburner:origLink></item>
		<item>
		<title>Show 009 – An Interview with Bruce Schneier</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/FPapsq_C_pA/</link>
		<comments>http://www.cigital.com/silver-bullet/show-009/#comments</comments>
		<pubDate>Thu, 14 Dec 2006 11:45:53 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-009/</guid>
		<description><![CDATA[In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier. Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security. He has written eight bestselling books, most recently Beyond Fear: Thinking Sensibly About Security in an Uncertain World and is the editor of the massively [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Bruce Schneier" src="http://www.cigital.com/silverbullet/bschneier-123.jpg" /></p>
<p style="margin-top: 5px">In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security.  He has written eight bestselling books, most recently <em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World</em> and is the editor of the massively popular Cryptogram mailing list.  In this episode, Gary and Bruce discuss the connection between physical security its technological component, the idea of risk management, the intersection of economics and security, and the ideas of &#8220;wholesale surveillance&#8221; and &#8220;security theater.&#8221;  They also discuss patch Tuesday, hack Wednesday, and Microsoft&#8217;s approach to software security.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Bruce_Schneier">Bruce&#8217;s Wikipedia entry</a></li>
<li><a href="http://www.amazon.com/s/104-2577668-4903944?ie=UTF8&amp;index=books&amp;rank=-relevance%2C%2Bavailability%2C-daterank&amp;field-author-exact=Schneier%2C%20Bruce">Bruce&#8217;s books</a></li>
<li><a href="http://pd.startribune.com/sp?aff=3&amp;keywords=schneier">Bruce&#8217;s recent restaurant reviews</a></li>
<li><a href="http://www.counterpane.com/">Counterpane</a></li>
<li><a href="http://crypto-gram.libsyn.com/">Crypto-Gram security podcast</a>
<li><a href="http://www.freedom-to-tinker.com/?p=1052">Property Rights Management</a> &#8211; Ed Felten&#8217;s discussion of PRM, mentioned on the show</li>
<li><a href="http://www.techdirt.com/articles/20051205/2345233.shtml">Copyright Mythbusters: Believe It or Not, Fair Use Exists</a> &#8211; a look at the &#8220;fair use doesn&#8217;t exist&#8221; argument</li>
<li><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/4806948.stm">BBC plans attacked for &#8216;TV tax&#8217;</a> (March 14, 2006)</li>
<li>Bruce&#8217;s suggestion for &#8220;cheap&#8221; wines: <a href="http://www.thewinedoctor.com/regionalguides/loire.shtml">Loire wines</a>, <a href="http://www.beyond.fr/wine/provencewines.html">Provence Wines</a>, <a href="http://www.rhonerangers.org/html/wines.html">Southern Rhone wines</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/FPapsq_C_pA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/159/0/silverbullet-009.mp3" length="23840778" type="audio/mpeg" />
		<itunes:duration>0:24:50</itunes:duration>
		<itunes:subtitle>
In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the “uber-guru” of computer security.  He has written eight bestselling books, most recen[...]</itunes:subtitle>
		<itunes:summary>
In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the “uber-guru” of computer security.  He has written eight bestselling books, most recently Beyond Fear: Thinking Sensibly About Security in an Uncertain World and is the editor of the massively popular Cryptogram mailing list.  In this episode, Gary and Bruce discuss the connection between physical security its technological component, the idea of risk management, the intersection of economics and security, and the ideas of “wholesale surveillance” and “security theater.”  They also discuss patch Tuesday, hack Wednesday, and Microsoft’s approach to software security.

Bruce’s Wikipedia entry
Bruce’s books
Bruce’s recent restaurant reviews
Counterpane
Crypto-Gram security podcast
Property Rights Management – Ed Felten’s discussion of PRM, mentioned on the show
Copyright Mythbusters: Believe It or Not, Fair Use Exists – a look at the “fair use doesn’t exist” argument
BBC plans attacked for ‘TV tax’ (March 14, 2006)
Bruce’s suggestion for “cheap” wines: Loire wines, Provence Wines, Southern Rhone wines
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/159/0/silverbullet-009.mp3" fileSize="23840778" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-009/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-009</feedburner:origLink></item>
		<item>
		<title>Show 008 – An Interview with Brian Chess</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/IrBD4x9mwGI/</link>
		<comments>http://www.cigital.com/silver-bullet/show-008/#comments</comments>
		<pubDate>Fri, 17 Nov 2006 16:35:55 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-008/</guid>
		<description><![CDATA[In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software. Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector. Gary and Brian discuss what commercial developers and academics have to learn from each other, what it&#8217;s [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Brian Chess" src="http://www.cigital.com/silverbullet/bchess-125.jpg" /></p>
<p style="margin-top: 5px">In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary and Brian discuss what commercial developers and academics have to learn from each other, what it&#8217;s like to work for a Kleiner-Perkins startup (KP is the VC firm behind familiar names like Google, Amazon, and Sun), and how mystifying it is that some developers are OK with XSS vulnerabilities in their web applications.</p>
<ul>
<li><a href="http://www.fortifysoftware.com/">Fortify Software</a></li>
<li><a href="http://extra.fortifysoftware.com/blog/">extra</a> &#8211; Fortify&#8217;s software security blog</a></li>
<li>Matt Bishop&#8217;s <a href="http://nob.cs.ucdavis.edu/book/book-aands/index.html"><em>Computer Security: Art and Science</em></a> (mentioned again!)</li>
<li><a href="http://www.kpcb.com/">Kleiner Perkins Caufield &amp; Byers</a></li>
<li><a href="http://www.cigital.com/ssw/">DIMACS Workshop on Software Security</a> with Brian Kernighan</li>
<li><a href="http://sctest.cse.ucsc.edu/chess/">Brian as a wee lad</a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/IrBD4x9mwGI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-008/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/158/0/silverbullet-008.mp3" length="23570442" type="audio/mpeg" />
		<itunes:duration>0:24:33</itunes:duration>
		<itunes:subtitle>
In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary an[...]</itunes:subtitle>
		<itunes:summary>
In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary and Brian discuss what commercial developers and academics have to learn from each other, what it’s like to work for a Kleiner-Perkins startup (KP is the VC firm behind familiar names like Google, Amazon, and Sun), and how mystifying it is that some developers are OK with XSS vulnerabilities in their web applications.

Fortify Software
extra – Fortify’s software security blog
Matt Bishop’s Computer Security: Art and Science (mentioned again!)
Kleiner Perkins Caufield &amp; Byers
DIMACS Workshop on Software Security with Brian Kernighan
Brian as a wee lad
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/158/0/silverbullet-008.mp3" fileSize="23570442" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-008/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-008</feedburner:origLink></item>
		<item>
		<title>Show 007 – An Interview with John Stewart</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/qCbwx2Pm4tE/</link>
		<comments>http://www.cigital.com/silver-bullet/show-007/#comments</comments>
		<pubDate>Wed, 25 Oct 2006 15:00:58 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-007/</guid>
		<description><![CDATA[In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart. Gary and John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse). John and Gary also [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Michael Howard" src="http://www.cigital.com/silverbullet/jstewart-125.jpg" /></p>
<p style="margin-top: 5px">In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse).  John and Gary also revisit Cisco-gate, talk about how John&#8217;s identity was stolen, and determine why John&#8217;s kids don&#8217;t have e-mail addresses.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-007-jstewart.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://newsroom.cisco.com/dlls/tln/exec_team/stewart/perspectives.html">Executive Perspective: John Stewart on Vulnerability Disclosure</a></li>
<li><a href="http://en.wikipedia.org/wiki/CSO">Wikipedia: CSO</a></li>
<li><a href="http://en.wikipedia.org/wiki/Digital_Island">Digital Island</a></li>
<li><a href="http://snowplow.org/tom/worm/worm.html">The What, Why, and How of the 1988 Internet Worm</a> &#8211; a look at the history of the Morris Worm</li>
<li><a href="http://www.wired.com/news/technology/0,1282,68435,00.html">Cisco-gate</a></li>
<li><a href="http://www.csoonline.com/read/030104/idtheft.html">Five Ways to Fight ID Theft</a> &#8211; John talks about finding himself a victim of identity theft; see also: <a href="http://shaunsaxon.com/yamahafz1.html">the motorcycle he was trying to buy when he found out</a></li>
<li><a href="http://www.mykey3000.com/cosmicteams/profiles/gljohn.htm">John Stewart</a>, but not the one Gary interviews (and not the one you&#8217;re thinking of)</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/qCbwx2Pm4tE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-007/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/157/0/silverbullet-007.mp3" length="25985034" type="audio/mpeg" />
		<itunes:duration>0:27:04</itunes:duration>
		<itunes:subtitle>
In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which J[...]</itunes:subtitle>
		<itunes:summary>
In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse).  John and Gary also revisit Cisco-gate, talk about how John’s identity was stolen, and determine why John’s kids don’t have e-mail addresses.

Transcript of this episode [PDF]
Executive Perspective: John Stewart on Vulnerability Disclosure
Wikipedia: CSO
Digital Island
The What, Why, and How of the 1988 Internet Worm – a look at the history of the Morris Worm
Cisco-gate
Five Ways to Fight ID Theft – John talks about finding himself a victim of identity theft; see also: the motorcycle he was trying to buy when he found out
John Stewart, but not the one Gary interviews (and not the one you’re thinking of)
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/157/0/silverbullet-007.mp3" fileSize="25985034" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-007/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-007</feedburner:origLink></item>
		<item>
		<title>Japanese translation of Marcus Ranum interview</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/KZyseSy2HOo/</link>
		<comments>http://www.cigital.com/silver-bullet/japanese-translation-of-marcus-ranum-interview/#comments</comments>
		<pubDate>Wed, 11 Oct 2006 15:34:38 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/</guid>
		<description><![CDATA[Fumio over at LapisNet has translated an excerpt of the Marcus Ranum interview. You can read the Japanese translation here.]]></description>
				<content:encoded><![CDATA[<p>Fumio over at <a href="http://www.lapisnet.co.jp/">LapisNet</a> has translated an excerpt of the <a href="http://www.cigital.com/silverbullet/show-003/">Marcus Ranum interview</a>.  You can read the <a href="http://www.lapisnet.co.jp/jp/info/securitypodcast03.html">Japanese translation here</a>.</p>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/KZyseSy2HOo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/japanese-translation-of-marcus-ranum-interview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.cigital.com/silver-bullet/japanese-translation-of-marcus-ranum-interview/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=japanese-translation-of-marcus-ranum-interview</feedburner:origLink></item>
		<item>
		<title>Show 006 – An Interview with Michael Howard</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/xzi4JNL_O8c/</link>
		<comments>http://www.cigital.com/silver-bullet/show-006/#comments</comments>
		<pubDate>Thu, 28 Sep 2006 20:11:47 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-006/</guid>
		<description><![CDATA[The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft&#8217;s Security Technology Unit. Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security. Michael continues to play a key roll in implementing the [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Michael Howard" src="http://www.cigital.com/silverbullet/mhoward-118.jpg" /></p>
<p style="margin-top: 5px">The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft&#8217;s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security.  Michael continues to play a key roll in implementing the Trustworthy Computing Initiative at Microsoft.  Gary and Michael also discuss the security features of Windows Vista and Michael&#8217;s recommendations for the two most important best practices when developing secure software.  Listen for a startling revelation about Michael&#8217;s choice of a &#8220;desert island book.&#8221;</p>
<ul>
<li><a href="http://blogs.msdn.com/michael_howard/">Michael Howard&#8217;s blog</a></li>
<li><a href="http://www.microsoft.com/mspress/books/5957.asp"><em>Writing Secure Code</em></a> by Michael Howard</li>
<li><a href="http://en.wikipedia.org/wiki/Defense_in_depth">Wikipedia: Defense in Depth</a></li>
<li><a href="http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnsecure/html/sdl.asp">Microsoft&#8217;s Trustworthy Computing Security Development Lifecycle</a></li>
<li><a href="http://nob.cs.ucdavis.edu/book/">Matt Bishop&#8217;s computer security books</a> &#8211; These would go with Michael to a desert island.</li>
<li><a href="http://en.wikipedia.org/wiki/Michael_Howard">Michael Howard</a> &#8211; but not the one Gary interviewed.</li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/xzi4JNL_O8c" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-006/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/155/0/silverbullet-006.mp3" length="24731658" type="audio/mpeg" />
		<itunes:duration>0:25:46</itunes:duration>
		<itunes:subtitle>
The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft’s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the c[...]</itunes:subtitle>
		<itunes:summary>
The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft’s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security.  Michael continues to play a key roll in implementing the Trustworthy Computing Initiative at Microsoft.  Gary and Michael also discuss the security features of Windows Vista and Michael’s recommendations for the two most important best practices when developing secure software.  Listen for a startling revelation about Michael’s choice of a “desert island book.”

Michael Howard’s blog
Writing Secure Code by Michael Howard
Wikipedia: Defense in Depth
Microsoft’s Trustworthy Computing Security Development Lifecycle
Matt Bishop’s computer security books – These would go with Michael to a desert island.
Michael Howard – but not the one Gary interviewed.
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/155/0/silverbullet-006.mp3" fileSize="24731658" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-006/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-006</feedburner:origLink></item>
		<item>
		<title>Show 005 – An Interview with Ed Felten</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/RnGKQMzjZgo/</link>
		<comments>http://www.cigital.com/silver-bullet/show-005/#comments</comments>
		<pubDate>Mon, 28 Aug 2006 18:05:36 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-005/</guid>
		<description><![CDATA[The fifth edition of the Silver Bullet Security Podcast features Ed Felten, Professor of Computer Science and Public Affairs at Princeton University and the Director of the Center for Information Technology Policy. Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship with [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Ed Felten" src="http://www.cigital.com/silverbullet/efelten-125.jpg" /></p>
<p style="margin-top: 5px">The fifth edition of the Silver Bullet Security Podcast features <a href="http://www.cs.princeton.edu/~felten">Ed Felten</a>, Professor of Computer Science and Public Affairs at Princeton University and the Director of the <a href="http://itpolicy.princeton.edu/">Center for Information Technology Policy</a>.  Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship with his former adversaries.  They also talk about how to discuss difficult technology issues with lawmakers and the importance of public policy and the law to computer scientists.  Ed also outlines the challenges of raising a bright 11-year-old.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-005-efelten.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://www.freedom-to-tinker.com/">Freedom to Tinker</a> &#8211; Ed Felten&#8217;s blog</li>
<li><a href="http://www.freedom-to-tinker.com/?p=953">Ed&#8217;s Predictions for 2006</a></li>
<li><a href="http://en.wikipedia.org/wiki/Series_of_tubes">Wikipedia: Series of Tubes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/RnGKQMzjZgo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-005/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/154/0/silverbullet-005.mp3" length="22001674" type="audio/mpeg" />
		<itunes:duration>0:22:55</itunes:duration>
		<itunes:subtitle>
The fifth edition of the Silver Bullet Security Podcast features Ed Felten, Professor of Computer Science and Public Affairs at Princeton University and the Director of the Center for Information Technology Policy.  Gary and Ed take a look at Ed[...]</itunes:subtitle>
		<itunes:summary>
The fifth edition of the Silver Bullet Security Podcast features Ed Felten, Professor of Computer Science and Public Affairs at Princeton University and the Director of the Center for Information Technology Policy.  Gary and Ed take a look at Ed’s predictions for 2006 and how he’s faring so far and then discuss Ed’s relationship with his former adversaries.  They also talk about how to discuss difficult technology issues with lawmakers and the importance of public policy and the law to computer scientists.  Ed also outlines the challenges of raising a bright 11-year-old.

A partial transcript of the interview in IEEE Security &amp; Privacy
Freedom to Tinker – Ed Felten’s blog
Ed’s Predictions for 2006
Wikipedia: Series of Tubes
Subscribe to IEEE Security &amp; Privacy
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/154/0/silverbullet-005.mp3" fileSize="22001674" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-005/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-005</feedburner:origLink></item>
		<item>
		<title>Show 004 – An Interview with Dana Epp</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/DpQRq7GrDDw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-004/#comments</comments>
		<pubDate>Mon, 31 Jul 2006 21:30:23 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-004/</guid>
		<description><![CDATA[In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of Scorpion Software. Dana also runs a popular software security blog and is a jazz trumpeter. On this show, Dana and Gary talk about past programming disasters (&#8220;code lives forever&#8221;), the security implications of systems with ever-increasing [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Dana Epp" src="http://www.cigital.com/silverbullet/depp-125.jpg" /></p>
<p style="margin-top: 5px">In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of <a href="http://www.scorpionsoft.com/">Scorpion Software</a>.  Dana also runs a popular <a href="http://silverstr.ufies.org/blog/">software security blog</a> and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (&#8220;code lives forever&#8221;), the security implications of systems with ever-increasing complexity, suggestions for new developers interested in learning about software security, regulation&#8217;s role in information security, and Miles Davis.</p>
<ul>
<li><a href="http://silverstr.ufies.org/blog/">SilverStr&#8217;s blog</a> &#8211; Dana&#8217;s blog</li>
<li><a href="http://snltranscripts.jt.org/90/90tpat.phtml">It&#8217;s Pat!</a></li>
<li><a href="http://www.rapro.com/">RemoteAccess BBS</a></li>
<li><a href="http://silverstr.ufies.org/blog/archives/000926.html">The 5 Rules of the Regulatory Process</a></li>
<li><a href="http://www.chrisbotti.com/">Chris Botti</a></li>
<li><a href="http://www.securecoding.org/list/">SC-L List</a></li>
<li><a href="http://www.miles-davis.com/brew.html"><em>Bitches Brew</em></a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/DpQRq7GrDDw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-004/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/152/0/silverbullet-004.mp3" length="23488522" type="audio/mpeg" />
		<itunes:duration>0:24:28</itunes:duration>
		<itunes:subtitle>
In the fourth episode of the Silver Bullet Security Podcast, Gary’s guest is Dana Epp, CEO and founder of Scorpion Software.  Dana also runs a popular software security blog and is a jazz trumpeter.  On this show, Dana and Gary talk about pas[...]</itunes:subtitle>
		<itunes:summary>
In the fourth episode of the Silver Bullet Security Podcast, Gary’s guest is Dana Epp, CEO and founder of Scorpion Software.  Dana also runs a popular software security blog and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (“code lives forever”), the security implications of systems with ever-increasing complexity, suggestions for new developers interested in learning about software security, regulation’s role in information security, and Miles Davis.

SilverStr’s blog – Dana’s blog
It’s Pat!
RemoteAccess BBS
The 5 Rules of the Regulatory Process
Chris Botti
SC-L List
Bitches Brew
Subscribe to IEEE Security &amp; Privacy
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/152/0/silverbullet-004.mp3" fileSize="23488522" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-004/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-004</feedburner:origLink></item>
		<item>
		<title>Show 003 – An Interview with Marcus Ranum</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/Cv-ETqqMqzw/</link>
		<comments>http://www.cigital.com/silver-bullet/show-003/#comments</comments>
		<pubDate>Fri, 14 Jul 2006 19:10:27 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-003/</guid>
		<description><![CDATA[In the third episode of the Silver Bullet Security Podcast, Gary talks with Marcus Ranum, who is an acclaimed security guru widely credited with inventing the proxy firewall. Marcus and Gary discuss why Marcus thinks we&#8217;re not making progress in the computer security field, how common sense would help computer security, Richard Feynman, and power [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Marcus J. Ranum" src="http://www.cigital.com/silverbullet/mranum-125.jpg" /></p>
<p style="margin-top: 5px">In the third episode of the Silver Bullet Security Podcast, Gary talks with Marcus Ranum, who is an acclaimed security guru widely credited with inventing the proxy firewall. Marcus and Gary discuss why Marcus thinks we&#8217;re not making progress in the computer security field, how common sense would help computer security, Richard Feynman, and power tools for home repair and improvement.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-003-mranum.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://www.ranum.com/">Ranum.com</a></li>
<li><a href="http://www.ranum.com/security/computer_security/audio/mjr-blackhat-97.mp3">BlackHat Keynote &#8217;97</a> (MP3)</li>
<li><a href="http://www.ranum.com/security/computer_security/editorials/dumb/index.html">The Six Dumbest Ideas in Computer Security</a></li>
<li><a href="http://www.oldwestsnakeoil.com/">Old West Snake Oil</a></li>
<li><a href="http://www.networkworld.com/news/2005/011005widernetpatchtuesday.html">Patch Tuesday</a></li>
<li><a href="http://en.wikipedia.org/wiki/Richard_Feynman">Richard Feynman</a></li>
<li><a href="http://www.toolbarn.com/cgi-bin/bigimage.cgi/DW969K-2/">DeWalt cordless screwdriver</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/Cv-ETqqMqzw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-003/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	<feedburner:origLink>http://www.cigital.com/silver-bullet/show-003/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-003</feedburner:origLink></item>
		<item>
		<title>Show 002 – An Interview with Dan Geer</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/OWPtkMp9jXU/</link>
		<comments>http://www.cigital.com/silver-bullet/show-002/#comments</comments>
		<pubDate>Mon, 12 Jun 2006 17:28:07 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-002/</guid>
		<description><![CDATA[In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at Verdasys. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan&#8217;s paper Cyber Insecurity, his work on Project Athena, [...]]]></description>
				<content:encoded><![CDATA[<p><img align="right" alt="Dan Geer" src="http://www.cigital.com/silverbullet/dgeer-125.jpg" /></p>
<p style="margin-top: 5px">In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at <a href="http://www.verdasys.com/">Verdasys</a>. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan&#8217;s paper Cyber Insecurity, his work on Project Athena, and livestock.</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-002-dgeer.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Dan_Geer">Dan Geer on Wikipedia</a></li>
<li><a href="http://www.ccianet.org/papers/cyberinsecurity.pdf">Cyber Insecurity: The Cost of Monopoly</a> (PDF)</li>
<li><a href="http://en.wikipedia.org/wiki/Project_Athena">Project Athena on Wikipedia</a></li>
<li><a href="http://www2.sims.berkeley.edu/research/projects/how-much-info-2003/">How Much Information 2003</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/OWPtkMp9jXU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-002/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/3/0/silverbullet-002.mp3" length="21510154" type="audio/mpeg" />
		<itunes:duration>0:22:24</itunes:duration>
		<itunes:subtitle>
In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at Verdasys. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a go[...]</itunes:subtitle>
		<itunes:summary>
In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at Verdasys. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan’s paper Cyber Insecurity, his work on Project Athena, and livestock.

A partial transcript of the interview in IEEE Security &amp; Privacy
Dan Geer on Wikipedia
Cyber Insecurity: The Cost of Monopoly (PDF)
Project Athena on Wikipedia
How Much Information 2003
Subscribe to IEEE Security &amp; Privacy
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/3/0/silverbullet-002.mp3" fileSize="21510154" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-002/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-002</feedburner:origLink></item>
		<item>
		<title>Show 001 – An Interview with Avi Rubin</title>
		<link>http://feedproxy.google.com/~r/silverbulletsecurity/~3/GsBHTVbCT_g/</link>
		<comments>http://www.cigital.com/silver-bullet/show-001/#comments</comments>
		<pubDate>Wed, 19 Apr 2006 17:47:13 +0000</pubDate>
		<dc:creator>webmaster@cigital.com (Gary McGraw)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-001/</guid>
		<description><![CDATA[In the debut episode of the Silver Bullet Security Podcast, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University. Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines. Links: A partial transcript of the interview in IEEE Security [...]]]></description>
				<content:encoded><![CDATA[<p><img src="http://www.cigital.com/silverbullet/arubin-125.jpg" alt="Avi Rubin" align="right" /></p>
<p style="margin-top: 5px">In the debut episode of the <em>Silver Bullet Security Podcast</em>, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines.</p>
<p>Links:</p>
<ul>
<li><a href="/silver-bullet-files/shows/silverbullet-001-arubin.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://www.avirubin.com/">Avi&#8217;s site</a></li>
<li><a href="http://www.bravenewballot.org/"><em>Brave New Ballot: The Battle to Safeguard Democracy in the Age of Electronic Voting</em></a>, Avi&#8217;s forthcoming book</li>
<li><a href="http://accurate-voting.org/">ACCURATE</a> &#8211; A Center for Correct, Usable, Reliable, Auditable, and Transparent Elections</li>
<li><a href="http://www.frootloops.com/">Froot Loops</a> and <a href="http://en.wikipedia.org/wiki/Corn_flakes">Corn Flakes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
<img src="http://feeds.feedburner.com/~r/silverbulletsecurity/~4/GsBHTVbCT_g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silver-bullet/show-001/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
			<enclosure url="http://www.cigital.com/podpress_trac/feed/153/0/silverbullet-001.mp3" length="19243018" type="audio/mpeg" />
		<itunes:duration>0:20:03</itunes:duration>
		<itunes:subtitle>
In the debut episode of the Silver Bullet Security Podcast, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he reve[...]</itunes:subtitle>
		<itunes:summary>
In the debut episode of the Silver Bullet Security Podcast, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines.
Links:

A partial transcript of the interview in IEEE Security &amp; Privacy
Avi’s site
Brave New Ballot: The Battle to Safeguard Democracy in the Age of Electronic Voting, Avi’s forthcoming book
ACCURATE – A Center for Correct, Usable, Reliable, Auditable, and Transparent Elections
Froot Loops and Corn Flakes
Subscribe to IEEE Security &amp; Privacy
</itunes:summary>
		<itunes:keywords>Uncategorized</itunes:keywords>
		<itunes:author>webmaster@cigital.com</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	<media:content url="http://www.cigital.com/podpress_trac/feed/153/0/silverbullet-001.mp3" fileSize="19243018" type="audio/mpeg" /><feedburner:origLink>http://www.cigital.com/silver-bullet/show-001/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=show-001</feedburner:origLink></item>
	<media:credit role="author">Gary McGraw</media:credit><media:rating>nonadult</media:rating><media:description type="plain">Co-sponsored by Cigital and IEEE Security &amp; Privacy.</media:description></channel>
</rss>
