<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Josh More's Blog</title>
	
	<link>http://blog.starmind.org</link>
	<description>Thoughts on business, security, and IT. Feed of content on &lt;a href="http://blog.starmind.org:&gt;Josh More's Blog&lt;/a&gt;</description>
	<lastBuildDate>Wed, 28 Apr 2010 01:04:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/starmind-blog" /><feedburner:info uri="starmind-blog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:copyright>Copyright 2007</media:copyright><media:keywords>business,technology,entrepreneurship,literature,partnership,teaming,competition,security</media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Business</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Arts/Literature</media:category><itunes:owner><itunes:email>jmore@starmind.org</itunes:email><itunes:name>Josh More</itunes:name></itunes:owner><itunes:author>Josh More</itunes:author><itunes:explicit>no</itunes:explicit><itunes:keywords>business,technology,entrepreneurship,literature,partnership,teaming,competition,security</itunes:keywords><itunes:subtitle>Fuzzy Business</itunes:subtitle><itunes:summary>Easy-to-understand and entertaining discussions about business themes within the context of children's literature.</itunes:summary><itunes:category text="Business" /><itunes:category text="Technology" /><itunes:category text="Arts"><itunes:category text="Literature" /></itunes:category><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><image><link>http://www.starmind.org</link><url>http://www.starmind.org/star-icon.png</url><title>Josh More - The Starmind</title></image><feedburner:emailServiceId>starmind-blog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/starmind-blog" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://odeo.com/listen/subscribe?feed=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://odeo.com/img/badge-channel-black.gif">Subscribe with ODEO</feedburner:feedFlare><feedburner:feedFlare href="http://www.podnova.com/add.srf?url=http%3A%2F%2Ffeeds.feedburner.com%2Fstarmind-blog" src="http://www.podnova.com/img_chicklet_podnova.gif">Subscribe with Podnova</feedburner:feedFlare><item>
		<title>Firefox Profiles</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/Bi7CIpv0aHs/</link>
		<comments>http://blog.starmind.org/2010/04/27/firefox-profiles/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 01:04:52 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[add ons]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[profiles]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=788</guid>
		<description>I've been absent from this blog for a while.  Other projects are occupying my time.  I hope to return to regular blogging soon... but it may be a bit longer yet. However, one of my projects involved getting a new laptop.  Since getting a new laptop is a good excuse to redo things and do [...]</description>
			<content:encoded><![CDATA[<p>I've been absent from this blog for a while.  Other projects are occupying my time.  I hope to return to regular blogging soon... but it may be a bit longer yet.</p>
<p>However, one of my projects involved getting a new laptop.  Since getting a new laptop is a good excuse to redo things and do them better, I decided to take a closer look at my Firefox profile setup.</p>
<p>I play a lot of roles, ranging from security researcher to consultant.  There are different Firefox configurations that I need for each, but it's a pain to constantly log in to different user accounts.  To make this process simpler, I decided to create four different Firefox profiles, each tuned to a specific set of tasks.  What follows is a description of what I did under Linux.  The same process should apply to other operating systems... but I've not testing them there.  With one exception (noted) all add ons are from <a href="http://addons.mozilla.org">addons.mozilla.org</a>.</p>
<p>Warning, geekery below this line.</p>
<hr />I started with my basic add ons:</p>
<ul>
<li>Adblock Plus to prevent those annoying ads (and ad-based malware infections)</li>
<li>Neo Diggler to give me a quick way to clear the location bar and give me the ability to add custom stuff</li>
<li>No Script to prevent scripts from running.  I did a quick whitelisting of the sites I use a lot (Google, Amazon, Alliance, LinkedIn, etc)</li>
<li>Web of Trust to give me a hint before I click on a link.</li>
<li>Tiny Menu to maximize screen real estate.  (I love me the tiny laptops)</li>
<li>TorButton for quickly accessing The Onion Router (requires installing additional software to utilize)</li>
</ul>
<p>Sadly, LongURL is not supported on the new Firefox yet.</p>
<p>I restarted Firefox to activate everything and configured the plugins the way I like.  I also customized the Nav bar and moved everything up to the Menu bar that TinyMenu made nice and small.  Then I used the View menu to turn off Navigation and Bookmarks.</p>
<p>Then I went into Preferences-&gt;Privacy and set Firefox to "Never remember history" and suggest "Nothing".  I also cleared my history that was created thus far.  In Preferences-&gt;Security, I told it to never remember passwords, block reported attack sites, web forgeries and add ons.  (By not remembering passwords, I render myself less vulnerable to risk from theft of my profile directories, but more vulnerable to keyloggers... it's a good tradeoff to me.)</p>
<p>I then shutdown Firefox and went into ~/.mozilla/firefox.  I did a cp -a of my profile directory to other names (this bit would be different on Windows):</p>
<pre>cd ~/.mozilla/firefox</pre>
<pre>cp -a blahblah.default research</pre>
<pre>cp -a blahblah.default paranoid</pre>
<pre>cp -a blahblah.default webdev</pre>
<p>Then I edited profiles.ini and copied the four top lines of [Profile0] to new blocks of Profiles 1 through 3.  I edited the Name and Path to reflect each of my new profile directories (research, paranoid, webdev).  I edited the Firefox launcher and appended "-ProfileManager --no-remote" to the "run command".  This way, when I click on the little icon, Firefox will prompt me for the profile I want each time I launch it, and it lets me run multiple profiles at once.</p>
<p>I then launched it and selected my "research" profile.</p>
<p>Here, I went back into Preferences-&gt;Privacy and told it to go ahead and remember history and make suggestions (as when I'm researching things, I often forget where I found things and what I searched on.)  Then I installed the following add ons:</p>
<ul>
<li>Add N Edit Cookies for cookie manipulations</li>
<li>HackBar for SQL injection fun</li>
<li>PassiveRecon for exactly what it sounds like</li>
<li>RefControl for mangling HTTP headers</li>
<li>DeeperWeb for those occasional rambling searches.</li>
</ul>
<p>Then I added the following search engines to the dropbox:</p>
<ul>
<li>Offensive Security Exploit Database</li>
<li>Security Focus Vulns Search</li>
<li>Security Wire Search</li>
</ul>
<p>I'll probably add more as I play with it.  I'm still not used to using this feature to search the deep web.  (Wonder if one could be written to access our corporate wiki?)</p>
<p>Then it was time to restart Firefox and activate, set preferences, yada yada yada.</p>
<p>After that, I restarted to access the "paranoid" profile.  I went into Preferences-&gt;Security and turned on ALL warning messages.  It's annoying to use now, but that's partly the point.</p>
<p>I set StartPage to my initial home page, using the "Generate Custom URL" feature on the site.  Since I'm not storing any cookies at all, this is how it has to be done.  I removed all search engines and added IxQuick HTTPS, Startpage HTTPS and Scroogle SSL.   On the AddOn side, I added:</p>
<ul>
<li>Force-TLS to force HTTPS connections (though it really doesn't do all I'd like it to)</li>
<li>Certificate Patrol to track certificate details</li>
<li>Perspectives for a paranoid check against SSL certificate alteration.  This one is linked to from the Mozilla add ons site, but not installable from there.</li>
</ul>
<p>I then disabled the CNNIC SSL certficate (Preferences-&gt;Advanced-&gt;Encryption-&gt;View Certificates-&gt;Authorities, scroll to "CNNIC ROOT" click "Edit" and unselect "This certificate can also identify web sites".)  It's a matter of debate as to whether or not this is necessary... but so long as it's being debated, my paranoid side will be careful.  (The other profiles don't care. :)</p>
<p>Lastly, I installed the Orange Fox theme, which is ugly and garish, but since I wanted a visual reminder that I was in the paranoid profile, it was exactly what I wanted.</p>
<p>After another restart I entered the webdev side.  The fun new add ons here were:</p>
<ul>
<li>Firebug for tracing DOM and CSS issues, which I don't do much anymore, but it's still nice to have.</li>
<li>CodeBurner For Firebug to add reference to Firebug</li>
<li>FlashGot for massive download fun on archive.org</li>
<li>Greasemonkey for fixing stupid sites (and integrating with FlashGot to bypass trivial Javascript-implemented "security" checks)</li>
<li>Live HTTP Headers for watching traffic in real time, when I don't want to launch a real proxy</li>
<li>Web Developer for the same reason as Firebug</li>
</ul>
<p>From here, I am in a position to fire up the profiles as I need them, and am able to work on the web without worrying about my tools being available.</p>

	Tags: <a href="http://blog.starmind.org/tag/add-ons/" title="add ons" rel="tag">add ons</a>, <a href="http://blog.starmind.org/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a href="http://blog.starmind.org/tag/profiles/" title="profiles" rel="tag">profiles</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/" title="Security Sprint – Firefox Profiles (2010/02/03)">Security Sprint – Firefox Profiles</a> (4)</li>
</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Bi7CIpv0aHs:keQAmhelIIE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Bi7CIpv0aHs:keQAmhelIIE:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Bi7CIpv0aHs:keQAmhelIIE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=Bi7CIpv0aHs:keQAmhelIIE:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Bi7CIpv0aHs:keQAmhelIIE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=Bi7CIpv0aHs:keQAmhelIIE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Bi7CIpv0aHs:keQAmhelIIE:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Bi7CIpv0aHs:keQAmhelIIE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=Bi7CIpv0aHs:keQAmhelIIE:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/04/27/firefox-profiles/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/04/27/firefox-profiles/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Security Sprint – Malvertising</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/hACr1Qw_jj4/</link>
		<comments>http://blog.starmind.org/2010/02/17/security-sprint-malvertising/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 14:00:38 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Sprint]]></category>
		<category><![CDATA[adblock]]></category>
		<category><![CDATA[ads]]></category>
		<category><![CDATA[malvertising]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=785</guid>
		<description>We're all busy people. A security sprint should take no more than two hours... which while long for a real sprint, it a mere blink of an eye when compared to the multi-year commitment that is proper security practice. One of the easiest ways for an attacker to get malicious software to a target is [...]</description>
			<content:encoded><![CDATA[<p><em>We're all busy people. A security sprint should take no more than two hours... which while long for a real sprint, it a mere blink of an eye when compared to the multi-year commitment that is proper security practice.</em></p>
<hr />One of the easiest ways for an attacker to get malicious software to a target is to get it running on a popular site.  Newspaper and TV sites are popular targets, and since they fund their operations with web-based advertising, that's where attackers focus.  If they manage to compromise an ad server, then they can get their malicious software right on the popular targets without actually having to compromise the targets themselves.</p>
<p>Sadly, this technique is all too effective against the undefended.</p>
<p>Happily for us, it's easily defended against.</p>
<p>If you run Firefox, you're in the best shape.  There's an Add On called <a href="http://adblockplus.org/en/">Adblock Plus</a>.  Once you install it, you'll be prompted to select a subscription from the list.  (I just pick the top one.)  This list matches most ads and keeps things up to date for you, so if the location of the ad changes, it's still blocked.  So, not only do you not see the annoying ads, but you're also protected against the "malvertisers".</p>
<p>I don't have much direct experience with the non-Firefox browsers, but if you want to use something else, check out <a href="http://adblockie.codeplex.com/">Ad Block IE</a> for IE8, <a href="http://www.ie7pro.com/">IE7Pro</a> for IE7, <a href="http://www.vista4beginners.com/AdBlock-Plus-Filters-Internet-Explorer-8">this technique</a> for combining AdBlock Plus Filters in IE, and <a href="http://www.culater.net/software/PithHelmet/PithHelmet.php">PithHelmet</a> for Safari.</p>
<p>I do have to point out that some developers have gotten clever, and code their applications to make sure that ads are loaded, so if you use this trick, expect things like Facebook games not to work.  But then, <a href="http://www.time.com/time/business/article/0,8599,1935698,00.html?CNN=yes#ixzz0W5ptMKjK">you shouldn't be playing them anyway</a>.</p>

	Tags: <a href="http://blog.starmind.org/tag/adblock/" title="adblock" rel="tag">adblock</a>, <a href="http://blog.starmind.org/tag/ads/" title="ads" rel="tag">ads</a>, <a href="http://blog.starmind.org/tag/malvertising/" title="malvertising" rel="tag">malvertising</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hACr1Qw_jj4:9g3l0ZWeUj4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hACr1Qw_jj4:9g3l0ZWeUj4:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hACr1Qw_jj4:9g3l0ZWeUj4:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=hACr1Qw_jj4:9g3l0ZWeUj4:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hACr1Qw_jj4:9g3l0ZWeUj4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=hACr1Qw_jj4:9g3l0ZWeUj4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hACr1Qw_jj4:9g3l0ZWeUj4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hACr1Qw_jj4:9g3l0ZWeUj4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=hACr1Qw_jj4:9g3l0ZWeUj4:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/17/security-sprint-malvertising/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/17/security-sprint-malvertising/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Security Lessons from Nature – Autotomy</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/tutsTctc8QM/</link>
		<comments>http://blog.starmind.org/2010/02/16/security-lessons-from-nature-autotomy/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 14:00:01 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Natural History]]></category>
		<category><![CDATA[autotomy]]></category>
		<category><![CDATA[honey pot]]></category>
		<category><![CDATA[tarpit]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=773</guid>
		<description>Autotomy is the fancy name that people give to the well-known tendency for certain lizards to throw off their tails to escape predators. The theory, is that the tail will thrash around and distract the predator, thereby giving the lizard a chance to get away. It must be noted that other critters like octopuses, crabs [...]</description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Autotomy">Autotomy</a> is the fancy name that people give to the well-known tendency for certain lizards to throw off their tails to escape predators.  The theory, is that the tail will thrash around and distract the predator, thereby giving the lizard a chance to get away.  It must be noted that other critters like octopuses, crabs and some starfish also do this, as do sea cucumbers.  (Though the sea cucumbers <a href="http://www.seaslugforum.net/factsheet/defauto">eject their internal organs</a> instead.)</p>
<p>So what does this mean in the business/IT world?  Well, the obvious analogy is to distract an incoming attacker by abandoning your resources and letting them go nuts while you relocate your business to Sri Lanka.  However, some might consider this approach somewhat impractical.</p>
<p>However, if we stretch the analogy to the point of breaking (much like a lizard's tail), perhaps it makes sense to build a business strategy around distracting attackers.  There are some technologies that could assist with this.  A <a href="http://en.wikipedia.org/wiki/Honeypot_(computing)">honeypot</a> is often used to trap attacks so that people can learn from them.  This has become even easier now that virtualization has become prevalent.  All you have to do is join <a href="http://www.honeynet.org/project">one</a> <a href="http://www.projecthoneypot.org/">of</a> <a href="http://www.honeyd.org/">many</a> projects and you'll have a nice fake network to distract attackers.</p>
<p>Another technique is <a href="http://en.wikipedia.org/wiki/Tarpitting">tarpitting</a>.  This technology looks at incoming connections, and if they are not approved, it doesn't reject them right away, but instead extends the time before the connection is closed.  Thus, attackers are delayed and, in theory, you gain the time to build a defense.</p>
<p>In practice, of course, you need to actually be watching for the attack and take defensive action.  This technique wouldn't work very well if the lizard dropped it's tail and then stared dumbly as the dog wrestled the tail into submission, ate it, digested it, napped for a bit, woke up, got a bit hungry than then saw a nearby tasty tailless lizard.  So, if you decide to go after this option, you have to remember to "run and hide".  <strong>In other words, keep an eye out for the attacks and be ready to block them.</strong></p>

	Tags: <a href="http://blog.starmind.org/tag/autotomy/" title="autotomy" rel="tag">autotomy</a>, <a href="http://blog.starmind.org/tag/honey-pot/" title="honey pot" rel="tag">honey pot</a>, <a href="http://blog.starmind.org/tag/tarpit/" title="tarpit" rel="tag">tarpit</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.starmind.org/2010/01/26/security-lessons-from-nature-glow-worm-cave/" title="Security Lessons from Nature &#8211; Glow Worm Cave (2010/01/26)">Security Lessons from Nature &#8211; Glow Worm Cave</a> (1)</li>
</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tutsTctc8QM:NkEGs4KMYuY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tutsTctc8QM:NkEGs4KMYuY:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tutsTctc8QM:NkEGs4KMYuY:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=tutsTctc8QM:NkEGs4KMYuY:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tutsTctc8QM:NkEGs4KMYuY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=tutsTctc8QM:NkEGs4KMYuY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tutsTctc8QM:NkEGs4KMYuY:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tutsTctc8QM:NkEGs4KMYuY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=tutsTctc8QM:NkEGs4KMYuY:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/16/security-lessons-from-nature-autotomy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/16/security-lessons-from-nature-autotomy/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Mythic Monday – Hubris</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/9S0UmqUHC1M/</link>
		<comments>http://blog.starmind.org/2010/02/15/mythic-monday-hubris/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 14:00:18 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Mythology]]></category>
		<category><![CDATA[blade]]></category>
		<category><![CDATA[dracula]]></category>
		<category><![CDATA[hubris]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=777</guid>
		<description>I made the mistake the other night of watching Blade Trinity. The movie, as a whole, is irrelevant to this point (and all others, really). However it occurs to me that the evil villain, Dracula (yeah, that's original), suffers from a flaw that is common in many stories. Basically, he is so confident in his [...]</description>
			<content:encoded><![CDATA[<p>I made the mistake the other night of watching <em>Blade Trinity</em>.  The movie, as a whole, is irrelevant to this point (and all others, really).  However it occurs to me that the evil villain, Dracula (yeah, that's original), suffers from a flaw that is common in many stories.  Basically, he is so confident in his skills that he ignores the fact that the hero of story already defeated two movie worths of baddies.</p>
<p>To be fair, other major villains suffer from this same problem: Darth Vader, Lord Voldemort, Lord Sauron... as do heroes: Oedipus, Gilgamesh and Dr. Gregory House.  The problem with them all is that their overconfidence leads directly to their eventual downfall.  Sometimes, it is dramatic and impressive, other times (like this) it just involves a lot of bright shiny pixels that fly every which way until the filmmaker's budget is used up.</p>
<p>The lesson to learn, I think, is that <strong>hubris kills</strong>... often at an appropriately-delayed climactic plot point.  Here in the real world, of course, we tend not to have impressive glorious pixely deaths, which just leaves the problem of supreme overconfidence.</p>
<p>In I.T. Security, this sort of thinking often manifests itself as a general feeling of invulnerability against attack.  This can be due to an existing investment giving a greater feeling of security than actual security.  It can be due to a belief of general supremacy that is undeserved.  Most often, though, it is due to a fundamental misunderstanding of the enemy.</p>
<p>Just as Lord Voldemort couldn't conceive of a bunch of school kids as a threat, and Oedipus allowed himself to think that he had outwitted fate (never, never wise), <strong>if you ignore I.T. threats, you render yourself vulnerable to them</strong> and, through them, invite your inevitable comeuppance.  If you accept your business in all it's flaws, you'll know where to protect yourself.  If you do not, you may well go out in a blaze of shiny glory that is just as logically inexplicable as Dracula's shape-shifting powers in this horrible movie.</p>

	Tags: <a href="http://blog.starmind.org/tag/blade/" title="blade" rel="tag">blade</a>, <a href="http://blog.starmind.org/tag/dracula/" title="dracula" rel="tag">dracula</a>, <a href="http://blog.starmind.org/tag/hubris/" title="hubris" rel="tag">hubris</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=9S0UmqUHC1M:EOmlIfho2cI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=9S0UmqUHC1M:EOmlIfho2cI:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=9S0UmqUHC1M:EOmlIfho2cI:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=9S0UmqUHC1M:EOmlIfho2cI:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=9S0UmqUHC1M:EOmlIfho2cI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=9S0UmqUHC1M:EOmlIfho2cI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=9S0UmqUHC1M:EOmlIfho2cI:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=9S0UmqUHC1M:EOmlIfho2cI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=9S0UmqUHC1M:EOmlIfho2cI:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/15/mythic-monday-hubris/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/15/mythic-monday-hubris/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Should we allow our employees to engage in social networking?</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/S_zDljEMn8A/</link>
		<comments>http://blog.starmind.org/2010/02/12/should-we-allow-our-employees-to-engage-in-social-networking/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 17:14:22 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=771</guid>
		<description>Introduction The question often comes up: Should we allow our employees to engage in social networking? The debate has raged for years, and surprisingly, it is still not settled. In general, the discussion tends to fall down four possible paths: 1) Social media reduces productivity 2) There are a lot of threats that comes from [...]</description>
			<content:encoded><![CDATA[<p><b>Introduction</b></p>
<p>The question often comes up:  Should we allow our employees to engage in social networking?  The debate has raged for years, and surprisingly, it is still not settled.  In general, the discussion tends to fall down four possible paths:</p>
<p>1) Social media reduces productivity<br />
2) There are a lot of threats that comes from social media<br />
3) Social media is a new technology and therefore is scary<br />
4) Employees don't really need social media anyway</p>
<p>So let's take a look at these:</p>
<p><b>1) Productivity</b></p>
<p>Many times the "productivity" topic rages within the security field, which has always surprised me.  Keeping employees productive is the responsibility of the business owner, and while I've often seen it delegated, I've never seen it delegated to either the security people or the admins.  Realistically, this is the responsibility of management or HR.</p>
<p>Even then, it seems that every place has slightly different rules as to what is and is not been permitted.  In some places, it's customary to spend hours each Monday morning talking about the previous weekend's hunting or sporting events.  In others, everyone takes off Friday afternoon and sits around socializing before "closing time" hits.  In still others, there are required breaks every two hours as well as a mandatory lunch.  However, in absolutely none of them is social interaction categorically denied.  The prevailing attitude seems to be that so long as the work gets done, the specifics are irrelevant.</p>
<p>Different people work differently and some need the occasional long social break to limit distraction.  Humans are social beings and there is considerable evidence that socialization is a deep-seated need in our species*.  It seems unlikely that many people could be truly productive without a form of socialization... do the technical means really matter?</p>
<p>Perhaps, instead of banning the technology, it would make more sense to monitor productivity and ensure that any employees that begin to stray are quietly corrected.  This would enable you to take advantage of the benefits that the technology offers without necessarily experiencing a productivity hit.</p>
<p>* This could be a long discussion in of itself, but, fascinating though it may be, would distract from the point</p>
<p><b>2) Threats</b></p>
<p>A considerable amount of malware and no-tech attacks come from social sites.  Twitter is particularly bad, due to the inherent obfuscation used in the TinyURLesque sites (though they're working on it).  However, you can't live a life that is entirely devoid of risks, and in most cases we don't approach risks by banning the technology.  Instead we take a balanced view and assess risks before we take action.  For some reason, many people tend to approach these problems as if it were a game of whack-a-mole, which is a shame.</p>
<p>To draw the over-used analogy to automobiles (a similar technologically-induced societal change), in the rural states, a common threat is deer.  We could address this threat by building fences along each highway (Banning) or by constructing a massive array of detectors, implanting RFID chips in each deer and building weapons-equipped automated flying drones that kill any deer wandering onto the road (Intrusion Prevention).  Instead, we put up little yellow signs that tell people to be careful.  For some reason, we find this a more economical solution, even though it places a slightly higher burden on the drivers to pay attention.</p>
<p>I think that a lot of security professionals avoid the "educate the users" tack because it's traditionally not worked too well.  Of course, a lot of us are also far more comfortable with technology than we are with people, so it is possible that the past failure of education was due to our own failure to educate ourselves on education processes.  Maybe, if we were better at making little yellow signs, many people would manage to avoid the majority of threats.</p>
<p><b>3) New Technology Is Scary</b></p>
<p>I am sorry to say it, but we security professionals tend to say "no" a lot.  I ran into this problem myself recently and used what I call a "shortcut no" -- where I said "no" when I meant "yes we could do that, but I think it would be prohibitively expensive".  However, within the security community, when one person's "shortcut no" is heard as a "true no", we tend to build up an echo chamber effect and think "no one else is permitting this technology, so there must be a reason, so let's just say 'no'".  This, I think, results in the regrettable state of things being banned "for security reasons".</p>
<p>Changes to technologies and processes must be first analyzed and the risks then be explained to management.  At that time, it is their decision.  I have encountered businesses that prefer to believe that regulations such as PCI-DSS, the FTC Red Flag Rules and HIPAA/HITECH do not apply to their business.  In some cases, I have disagreed, but it is, in the end, their decision.  Perhaps the failure was on my part, and I was less than ideally effective in explaining the risks.  However, an alternate perspective is that many experience an unconscious resistance to change.  The impact of new regulations is change, and in many cases, change may be scary.</p>
<p>Of course, fear of change is part of being human.  Luckily, if you know this, you can take steps to address it.  One common approach is to take a social media class.  If you lack the budget for such a thing, you can also spend a day reading about it online.  Good Google terms are <a href="http://www.google.com/search?q=social+media+in+business">social media in business</a>, <a href="http://www.google.com/search?q=twitter+marketing">twitter marketing</a>, <a href="http://www.google.com/search?q=facebook+marketing">facebook marketing</a>, <a href="http://www.google.com/search?q=internet+business+mastery">Internet Business Mastery</a> and <a href="http://www.google.com/search?q=search+engine+optimization">search engine optimization</a>.</p>
<p><b>4) Do They Really Need It?</b></p>
<p>Four years ago I gave a presentation to a group of entrepreneurs about how to leverage technology in a start up.  One question I was asked was "Do I really need a website?"  I was stunned.  I couldn't imagine a new business without one.  Most people I know first check out a business on the web, both for contact information and for reviews.  If a business isn't on the net, it's invisible.  If it's on the net but no one is talking about it, it's probably not worth much.</p>
<p>This is even truer today.  I don't think I've opened a phone book once in the last year.  I've found many great resources through word of mouth via the Internet.  Social media allows me to research a company in minutes.  I can get information faster than ever before on prospective clients, partners and employees.  I can check my thinking against that of others in my field.  I can research threats, responses and technologies without having to do the test implementation myself.  (Though test implementations are still important.)  If it weren't for social media, I would be unable to do my job.</p>
<p>These networked social efficiencies exist pretty much across the board.  Alliance Technologies tends to "run light".  Our marketing, sales, support and administration are staffed at a level far lower than other comparable companies, simply for this reason.  If we didn't have social media, we'd have to double our staff. </p>
<p>Clearly, not all companies are the same.  However, the effectiveness of social media in all aspects of our business leads me to believe that it's generally useful to most businesses.</p>
<p><b>A) We Can't Stop Them Anyway</b></p>
<p>Trying to stop people from socializing is a doomed effort.  You can draft and implement all the polices you want, but if they go contrary to human nature, they will not be followed.  Moreover, if they are burdensome, they will be actively rebelled against.  Do you really want to spend your time protecting against outside attacks while your inside people are working to bypass your web filters, firewalls and IPS systems?  I know that I don't.</p>
<p>Practically speaking, web filtering technology works, but nothing is perfect.  You can block most sites in a category, but there is always a way around it.  You can block gambling sites, but you can't prevent an employee from placing bets via email or SMS on their cell phone.  You can block porn sites, but can't keep someone from bringing a magazine into the office if they really want to.  Generally, you just raise the barrier high enough to say "management would rather you not do this stuff" and people will take the easier path.  Even then, saying "don't gamble" and "don't look at porn" are vastly different messages from "don't talk".  Banning social media is equivalent to banning talking at the water cooler, over the cube walls or in the hallways.  If you try, you'll experience a lot of pushback... and as employee generations shift, the pushback will grow.</p>
<p>Personally, I'd rather focus my efforts towards bringing the employees in line with business goals and then combating actual threats against the business.  To do otherwise is just spinning in circles.</p>
<p><small>(This post originally appeared over at <a href="http://www.alliancetechnologies.net/blog/morej/should-we-allow-our-employees-engage-social-networking">Alliance Technologies</a>)</small></p>

	Tags: <a href="http://blog.starmind.org/tag/policies/" title="policies" rel="tag">policies</a>, <a href="http://blog.starmind.org/tag/social-media/" title="social media" rel="tag">social media</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=S_zDljEMn8A:NN21FjKO5Ro:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=S_zDljEMn8A:NN21FjKO5Ro:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=S_zDljEMn8A:NN21FjKO5Ro:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=S_zDljEMn8A:NN21FjKO5Ro:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=S_zDljEMn8A:NN21FjKO5Ro:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=S_zDljEMn8A:NN21FjKO5Ro:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=S_zDljEMn8A:NN21FjKO5Ro:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=S_zDljEMn8A:NN21FjKO5Ro:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=S_zDljEMn8A:NN21FjKO5Ro:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/12/should-we-allow-our-employees-to-engage-in-social-networking/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/12/should-we-allow-our-employees-to-engage-in-social-networking/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Security Lessons from Nature –</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/tPHZoi-tLU0/</link>
		<comments>http://blog.starmind.org/2010/02/09/security-lessons-from-nature-2/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 14:00:34 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Natural History]]></category>
		<category><![CDATA[portugese man o' war]]></category>
		<category><![CDATA[sea slug]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=764</guid>
		<description>The Blue Glaucus, also known as the sea swallow, blue sea slug and blue ocean slug ('cause one name just isn't cool enough for this sucker) is, as Wikipedia says, a pelagic aeolid nudibranch, a marine opisthobranch gastropod mollusk in the family Glaucidae. Which is fancy sciency way to say it's a slug that lives [...]</description>
			<content:encoded><![CDATA[<p>The <a href="http://en.wikipedia.org/wiki/Glaucus_atlanticus">Blue Glaucus</a>, also known as the sea swallow, blue sea slug and blue ocean slug ('cause one name just isn't cool enough for this sucker) is, as Wikipedia says, a pelagic aeolid nudibranch, a marine opisthobranch gastropod mollusk in the family Glaucidae.  Which is fancy sciency way to say it's a slug that lives in the ocean.  (If you like to geek out on sciency stuff (like me), read <a href="http://en.wikipedia.org/wiki/Nudibranch">this</a>, and <a href="http://en.wikipedia.org/wiki/Opisthobranch">this</a> and <a href="http://en.wikipedia.org/wiki/Pelagic">this</a>.)</p>
<p>What makes this little critter particularly interesting is that it eats Portuguese Man o' Wars (should that be "Men o' War"?).  Not only is it immune to the venom, but it also has the ability to absorb the stinging cells (sciency term: <a href="http://en.wikipedia.org/wiki/Nematocyst">nematocyst</a> (aka cnidocyte, 'cause they're cool too)).  It can then concentrate the cells of all the Portuguese Mens o' Wars it eats and thereby pack a stronger wallop than the original predator.</p>
<p>Business-wise, our friend <strong>Glaucy basically performs a hostile takeover</strong>, absorbs the general features of the acquisee (proteins) and concentrates that which make them unique (nematocysts/cnidocytes).  The lesson here, I think, is to look at what makes others unique and not necessarily one what you have in common.  That's not to say that commonality isn't important... no acquisition is going to work out if you don't share common proteins.  However, a strategic acquisition isn't going to be massively successful unless you can take advantage of and preserve the uniqueness.</p>
<p>The same holds true of employees.  If we hire employees, it is presumably because they have skills that set them above the rest.  (After all, everything else can be automated these days.)  Does it really make sense to push them all towards the same lowest denominator?  Wouldn't it make more sense to give each the tools they need (both technical and cultural) to maximize their success?  By doing such, you have effectively turned them into little stingers that can pack quite a punch.  Then, the trick would be to set them up in teams, so their punch can be concentrated.</p>
<p>Of course, the other lesson to learn from Glaucy is that it's not just a mass of stinging cells.  In order to be a successful organism, it must still move around, hunt and eat.  Thus, priority one is successful operation (not uniformity), and priority two is concentration of attack/defense.  I often find myself falling into the trap of forgetting about operations and trying to promote uniform environments and tool consolidation in the name of security.  After all, that's best practice right?</p>
<p>Wrong.</p>
<p><strong>Best practice is protecting the business.</strong> That means making the business as successful as possible.  I'm afraid that we security practitioners often mistake the process for the result.  Uniformity is a tool to promote control and control is a tool to promote security.  However, as soon as the costs of uniformity and control get in the way of the success of the business, they harm security instead of benefiting it.</p>

	Tags: <a href="http://blog.starmind.org/tag/portugese-man-o-war/" title="portugese man o&#039; war" rel="tag">portugese man o&#039; war</a>, <a href="http://blog.starmind.org/tag/sea-slug/" title="sea slug" rel="tag">sea slug</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tPHZoi-tLU0:E0Q1oQSE5ec:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tPHZoi-tLU0:E0Q1oQSE5ec:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tPHZoi-tLU0:E0Q1oQSE5ec:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=tPHZoi-tLU0:E0Q1oQSE5ec:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tPHZoi-tLU0:E0Q1oQSE5ec:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=tPHZoi-tLU0:E0Q1oQSE5ec:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tPHZoi-tLU0:E0Q1oQSE5ec:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=tPHZoi-tLU0:E0Q1oQSE5ec:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=tPHZoi-tLU0:E0Q1oQSE5ec:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/09/security-lessons-from-nature-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/09/security-lessons-from-nature-2/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Mythic Monday – Bulgarian Scope Creep</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/Aj96SfLV80s/</link>
		<comments>http://blog.starmind.org/2010/02/08/mythic-monday-bulgarian-scope-creep/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 14:00:50 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Mythology]]></category>
		<category><![CDATA[blender]]></category>
		<category><![CDATA[devil]]></category>
		<category><![CDATA[god]]></category>
		<category><![CDATA[scope creep]]></category>
		<category><![CDATA[squash]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=759</guid>
		<description>There is a Bulgarian creation myth where in the beginning, the earth was just a tiny island. Cohabitating on this island were God and the Devil (guess they were more friendly then). One day, perhaps following an Oscar and Felixian roommate dispute, the Devil suggested that God take a nap, planning that whilst the almighty [...]</description>
			<content:encoded><![CDATA[<p>There is a Bulgarian creation myth where in the beginning, the earth was just a tiny island.  Cohabitating on this island were God and the Devil (guess they were more friendly then).  One day, perhaps following an Oscar and Felixian roommate dispute, the Devil suggested that God take a nap, planning that whilst the almighty creator was slumbering, he could be tipped into the ocean.  I guess that, in Bulgaria, one can be omnipotent and omniscient, and still somehow fail to gain their <a href="http://en.wikipedia.org/wiki/Arnold_Rimmer">B.S.C and S.S.C.</a>.</p>
<p>Anyway, as the Devil attempted to push God off the island, the island magically expanded in each direction (it's clear from this story that the Devil wasn't omniscient), so that nary a toe got dampened.  The shoreline simply grew in each direction and, by the time the Devil gave up, the island had expanded to the size of our current Earth.  Which basically means that the state of the Earth today is due entirely to Devil-induced scope creep.</p>
<p>It explains a lot, doesn't it?</p>
<p><strong>Scope creep is a danger in all projects.</strong> It doesn't matter whether you're developing an application, enacting a security program or just shopping for groceries, scope creep can blow both your budget and deadline.  It's tempting when you're working on something to just add a little piece here and there because it will make future work easier.  Unfortunately for the business, integer math insists on <a href="http://en.wikipedia.org/wiki/Summation">summation</a>, and so long as businesses are profit-focused, integer math is going to be important.  From a security perspective, scope creep is additionally dangerous because it complicates things.  Complicated things are harder to secure than simple things.  <strong>The simpler you can keep a project, the better you can understand it, so the easier it is to secure.</strong></p>
<p>Scope creep, of course, is most dangerous when shopping.  A while back, I stopped by the store to pick up some basics (apples, bananas, yogurt, etc), and I noticed that winter squash was on sale... so my scope expanded a little bit and two squash wound up in my cart.  Later, once I got home I realized that I had no idea what to do with them (other than the basic roast squash, which is boring).  After consulting one of my cook books, I discovered that I needed a few more things.  After another shopping trip that involved carrots, celery, onions, garlic and broth, I soon had two soups a simmering.  Regrettably, the last step for each soup involved a blender, and the blender I had was incapable of dealing with the increased complexity of my soups.  It quickly suffered what I must refer to as a catastrophic containment failure which necessitated another trip to the store to get <a href="http://www.osterfusion.com/">a new blender</a>.</p>
<p>All told, my initial scope creep of two impulse-bought squash cost me over a hundred dollars in ingredients and blender replacement, not to mention the ridiculous amount of time wasted in the endeavor.  While I am thankful that I was able to find the blender-related security hole and believe that I have effectively mitigated the risk, life would have been much simpler had I not needed to.</p>
<p>I'm blaming the devil.</p>

	Tags: <a href="http://blog.starmind.org/tag/blender/" title="blender" rel="tag">blender</a>, <a href="http://blog.starmind.org/tag/devil/" title="devil" rel="tag">devil</a>, <a href="http://blog.starmind.org/tag/god/" title="god" rel="tag">god</a>, <a href="http://blog.starmind.org/tag/scope-creep/" title="scope creep" rel="tag">scope creep</a>, <a href="http://blog.starmind.org/tag/squash/" title="squash" rel="tag">squash</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Aj96SfLV80s:yfln7a3Mlg0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Aj96SfLV80s:yfln7a3Mlg0:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Aj96SfLV80s:yfln7a3Mlg0:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=Aj96SfLV80s:yfln7a3Mlg0:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Aj96SfLV80s:yfln7a3Mlg0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=Aj96SfLV80s:yfln7a3Mlg0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Aj96SfLV80s:yfln7a3Mlg0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=Aj96SfLV80s:yfln7a3Mlg0:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=Aj96SfLV80s:yfln7a3Mlg0:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/08/mythic-monday-bulgarian-scope-creep/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/08/mythic-monday-bulgarian-scope-creep/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Advanced Persistent Threat (APT)</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/hbgd4hVgmP8/</link>
		<comments>http://blog.starmind.org/2010/02/05/advanced-persistent-threat-apt/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 14:00:20 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[apt]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=768</guid>
		<description>There has been a great deal of discussion in the security community about APT. The link covers it at a high level, but in a nutshell, it's type of hacking that is distinguished by people who have the time and money to target specific individuals and organizations. Since the number of resources (time and money) [...]</description>
			<content:encoded><![CDATA[<p>There has been a great deal of discussion in the security community about <a href="http://en.wikipedia.org/wiki/Advanced_Persistent_Threat">APT</a>.  The link covers it at a high level, but in a nutshell, it's type of hacking that is distinguished by people who have the time and money to target specific individuals and organizations.  Since the number of resources (time and money) available to the attackers are at a much larger scale than what the defenders can muster, a lot of people are calling this a game changer.</p>
<p>As usual, the battle lines seem drawn along traditional lines, with both sides claiming that the other "doesn't get it".  For a quick read, check out <a href="http://taosecurity.blogspot.com/2010/01/two-dimensional-thinking-and-apt.html">Richard Bejtlich's post</a> and <a href="http://blog.mandiant.com/archives/720">MANDIANT's post</a> and, for a counterpoint, check out <a href="http://1raindrop.typepad.com/1_raindrop/2010/01/i-can-see-atp-from-here.html">Gunnar Peterson's</a>.</p>
<p><strong>Of course, they're both right.  Neither side gets it.</strong> Both are blind.  Those that work enterprise security consulting see APT everywhere... mostly, I suspect, because in the enterprise security space you only call the consultants when it's something particularly troublesome (like APT).  Of course, once you've focused on APT, that's what you get called in on, so the problem probably looks bigger than it is.</p>
<p>In contrast, those of use that don't consult in those spaces don't get those calls, so we don't see it.  We also probably don't have the transparency needed to see such activity if it is going on in our organizations.  So we minimize the threat.</p>
<p>So what do you do about APT?</p>
<p>I suggest that you consider the following checklist:</p>
<ol>
<li>Do you have a firewall?</li>
<li>Does your firewall block outgoing connections?</li>
<li>Do you have local antimalware running on all your endpoints?</li>
<li>Do you have a web filtering solution in place?</li>
<li>Is all access to all systems monitored and audited regularly?</li>
<li>Do you have a process in place to pull all legacy systems off your network?</li>
<li>Do you have a patch management system in place?</li>
<li>Do you have a vulnerability management process in place?</li>
<li>Do you matc all system configurations against hardened templates?</li>
<li>Do you have a data classification policy that applies to all your data?</li>
<li>Are you encrypting your important data?</li>
<li>Do you have a log retention and management infrastructure built?</li>
<li>Are you running an IDS/IPS system?</li>
<li>Do you have third party management systems in place?</li>
<li>Are all of your web applications running in hardened stacks?</li>
<li>Are you using web application firewalls?</li>
<li>Are you using database firewalls?</li>
<li>Do you have regular employee awareness training?</li>
<li>Are complete penetration tests conducted against your organization?</li>
<li>Do you have an Internet data monitoring and scrubbing policy in place?</li>
</ol>
<p>If the answer to <strong>each</strong> question is "yes", then you should worry about APT.  This is not to say that if any of these are "no", you don't have APT going on in your environment.  I'm saying that there's no point pursuing a full on anti-APT strategy until you have the basics in place... and there are a lot of basics.  I'm also not saying that any of these technologies will prevent APT (or any security issues), or that all problems even have technical solutions.  These are just 20 questions that explore what a minimal and sufficient security solution looks like for the average business.</p>
<p>If you don't have a minimal and sufficient security solution in place, it's not that APT isn't a threat or that an unknown enemy isn't out to get you...<strong> it's that you probably have more important things to be working on.</strong></p>

	Tags: <a href="http://blog.starmind.org/tag/apt/" title="apt" rel="tag">apt</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li>No related posts.</li>
	</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hbgd4hVgmP8:IwRTqzCxZV8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hbgd4hVgmP8:IwRTqzCxZV8:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hbgd4hVgmP8:IwRTqzCxZV8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=hbgd4hVgmP8:IwRTqzCxZV8:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hbgd4hVgmP8:IwRTqzCxZV8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=hbgd4hVgmP8:IwRTqzCxZV8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hbgd4hVgmP8:IwRTqzCxZV8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=hbgd4hVgmP8:IwRTqzCxZV8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=hbgd4hVgmP8:IwRTqzCxZV8:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/05/advanced-persistent-threat-apt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/05/advanced-persistent-threat-apt/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Bias Thursday – Déformation professionnelle</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/3cd47ncNaXw/</link>
		<comments>http://blog.starmind.org/2010/02/04/bias-thursday-deformation-professionnelle/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 14:00:42 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Psychology]]></category>
		<category><![CDATA[bias]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=626</guid>
		<description>While I am not a psychologist, a good understanding of psychological issues is an important part of a full security practice. These themed posts are likely to be incomplete, as I am just exploring some ideas and how they might apply to security. Déformation professionnelle (which Google translates as "professional distortion") is the tendency to [...]</description>
			<content:encoded><![CDATA[<p><em>While I am not a psychologist, a good understanding of psychological issues is an important part of a full security practice.  These themed posts are likely to be incomplete, as I am just exploring some ideas and how they might apply to security.</em></p>
<hr />Déformation professionnelle (which Google translates as "professional distortion") is the tendency to consider situations from the perspective of your profession.  The classic example is the joke "when all you have is a hammer, every problem looks like a nail".  What I've noticed, though, is that "profession" seems to apply to business divisions now.  We're all getting extremely specialized, and that seems to create what we can call "a failure to communicate".</p>
<p>Take, for example, the concept of risk.  In the security field, risk is bad and the steps that can be taken to avoid risk seem reasonable.  However, in the business field, risk is viewed in terms of the potential gains that the risk can provide whereas the steps to avoid risk seem likely to cause problems and will therefore impact the bottom line.  Similarly, admins and developers are likely to resist the perceived difficulties in implementing the mitigation strategies.</p>
<p>Again, there are both offensive and defensive capabilities to this bias.  Offensively, simply knowing a target's profession can give you a good chance at predicting their responses.  If you have a planned proposal, you can practice it against others in the same profession and tweak it before you present it to the people that matter.  You can be aware of the context in which they will likely view your ideas and work on expanding their context before you get to the hard stuff.</p>
<p>Defensively, like most biases, you just have to be aware that you will likely view things within the context of your profession.  Thus, if you are having conversations with those outside of your profession, there is a higher likelihood of misunderstanding.  If you find yourself reacting negatively to something someone else says, you should check and see if maybe that reaction is because you are coming at things from different contexts.</p>
<p>As an note to this particular bias, I have occasionally been asked why I blog the way I do.  Other than the fact that the Internet doesn't need yet another voice in the Security echo chamber, I find that forcing myself to consider issues from different contexts (mythological, natural, psychological, etc) allows me to understand the issues at a deeper level.  I don't know if it gives me any advantage over the usual advantages that one gains by taking time to think things through and write them up... but it doesn't seem to be hurting.</p>

	Tags: <a href="http://blog.starmind.org/tag/bias/" title="bias" rel="tag">bias</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.starmind.org/2010/01/28/bias-thursday-pseudocertainty-effect/" title="Bias Thursday &#8211; Pseudocertainty Effect (2010/01/28)">Bias Thursday &#8211; Pseudocertainty Effect</a> (0)</li>
</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=3cd47ncNaXw:NwyhOd0sirk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=3cd47ncNaXw:NwyhOd0sirk:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=3cd47ncNaXw:NwyhOd0sirk:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=3cd47ncNaXw:NwyhOd0sirk:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=3cd47ncNaXw:NwyhOd0sirk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=3cd47ncNaXw:NwyhOd0sirk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=3cd47ncNaXw:NwyhOd0sirk:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=3cd47ncNaXw:NwyhOd0sirk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=3cd47ncNaXw:NwyhOd0sirk:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/04/bias-thursday-deformation-professionnelle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/04/bias-thursday-deformation-professionnelle/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
		<item>
		<title>Security Sprint – Firefox Profiles</title>
		<link>http://feedproxy.google.com/~r/starmind-blog/~3/BbeztTsymLk/</link>
		<comments>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 14:00:43 +0000</pubDate>
		<dc:creator>jmore@starmind.org (Josh More)</dc:creator>
				<category><![CDATA[Sprint]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[profiles]]></category>

		<guid isPermaLink="false">http://blog.starmind.org/?p=624</guid>
		<description>We're all busy people. A security sprint should take no more than two hours... which while long for a real sprint, it a mere blink of an eye when compared to the multi-year commitment that is proper security practice. If you use Firefox as your primary browser, there's a feature that you're probably not taking [...]</description>
			<content:encoded><![CDATA[<p><em>We're all busy people.  A security sprint should take no more than two hours... which while long for a real sprint, it a mere blink of an eye when compared to the multi-year commitment that is proper security practice.</em></p>
<hr />If you use Firefox as your primary browser, there's a feature that you're probably not taking proper advantage of.  Firefox stores your personal data in a profile.  This includes your bookmarks, passwords, cookies and add ons.  The advantage here is that you can tune your Firefox configuration to what you're doing... and somewhat segment your data.</p>
<p>For example, I have my normal browsing profile which includes a bare minimum number of add ons <a href="https://addons.mozilla.org/en-US/firefox/addon/1865">Adblock Plus</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/8636">LongURL Mobile Expander</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/3456">Web of Trust</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/6623">BetterPrivacy</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/2497">Cookie Safe</a> and <a href="https://addons.mozilla.org/en-US/firefox/addon/722">NoScript</a>.  Then, if I am conducting offensive security work, I use a profile that is loaded with some attack tools like <a href="https://addons.mozilla.org/en-US/firefox/addon/7597">SQL Inject Me</a> and <a href="https://addons.mozilla.org/en-US/firefox/addon/7598">XSS Me</a>.  Similarly, when I'm doing web development or troubleshooting, I have a separate profile that loads <a href="https://addons.mozilla.org/en-US/firefox/addon/60">Web Developer</a> and <a href="https://addons.mozilla.org/en-US/firefox/addon/3829">Live HTTP Headers</a>.  This approach keeps my normal use fairly light and allows me to load the extensions that I need when I need them.</p>
<p>In theory, it also keeps my passwords and cookies a bit safer than usual.  It's not as secure as using a completely separate user account or even computer for doing dangerous activities, but it's better than not doing anything at all.</p>
<p>To do build your own profiles, go <a href="http://support.mozilla.com/en-US/kb/Managing+profiles">here</a> and launch the Profile Manager.  Then, when you start Firefox, you will get dialog asking you which profile you wish to run.  From there, it's just a matter of picking which mode you wish to work in and selecting the appropriate profile before you start.</p>

	Tags: <a href="http://blog.starmind.org/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a href="http://blog.starmind.org/tag/profiles/" title="profiles" rel="tag">profiles</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.starmind.org/2010/04/27/firefox-profiles/" title="Firefox Profiles (2010/04/27)">Firefox Profiles</a> (0)</li>
</ul>

<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blog?a=BbeztTsymLk:EU74nHu1YBQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=BbeztTsymLk:EU74nHu1YBQ:63t7Ie-LG7Y"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=63t7Ie-LG7Y" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=BbeztTsymLk:EU74nHu1YBQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=BbeztTsymLk:EU74nHu1YBQ:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=BbeztTsymLk:EU74nHu1YBQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=BbeztTsymLk:EU74nHu1YBQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=BbeztTsymLk:EU74nHu1YBQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/starmind-blog?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/starmind-blog?a=BbeztTsymLk:EU74nHu1YBQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/starmind-blog?i=BbeztTsymLk:EU74nHu1YBQ:gIN9vFwOqvQ" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/?&amp;owa_from=feed&amp;owa_sid=</feedburner:origLink></item>
	<copyright>Copyright 2007</copyright><media:credit role="author">Josh More</media:credit><media:rating>nonadult</media:rating><media:description type="plain">Fuzzy Business</media:description></channel>
</rss>
