<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Network Security Blog &#187; CISSP/ISC2</title>
	<atom:link href="http://www.mckeay.net/category/cisspisc2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Wed, 01 Feb 2012 20:45:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<copyright>2006-2007 </copyright>
	<managingEditor>martin@mckeay.net (Network Security Blog)</managingEditor>
	<webMaster>martin@mckeay.net (Network Security Blog)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo144.jpg</url>
		<title>Network Security Blog</title>
		<link>http://www.mckeay.net</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>Network Security Blog</itunes:author>
	<itunes:owner>
		<itunes:name>Network Security Blog</itunes:name>
		<itunes:email>martin@mckeay.net</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo300.jpg" />
		<item>
		<title>Hoping to affect change at the ISC2</title>
		<link>http://www.mckeay.net/2011/09/13/hoping-to-affect-change-at-the-isc2/</link>
		<comments>http://www.mckeay.net/2011/09/13/hoping-to-affect-change-at-the-isc2/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 03:08:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Simple Security]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2011/09/13/hoping-to-affect-change-at-the-isc2/</guid>
		<description><![CDATA[It might just be a pipe dream to hope that these folks can make any significant change at the ISC2, but the fact that they&#8217;re trying is more than I&#8217;ve ever done.&#160; Which is why I&#8217;m hoping you&#8217;ll throw a little support behind the five people Jack Daniel is highlighting who want to run for [...]]]></description>
			<content:encoded><![CDATA[<p>It might just be a pipe dream to hope that these folks can make any significant change at the ISC2, but the fact that they&#8217;re trying is more than I&#8217;ve ever done.&nbsp; Which is why I&#8217;m hoping you&#8217;ll throw a little support behind the five people <a target="_blank" href="http://blog.uncommonsensesecurity.com/2011/08/isc2-elections-time-again.html">Jack Daniel is highlighting who want to run for the Board</a>.&nbsp; Endorsing them simply puts them on the ballot, it does not mean you have to vote for them, it doesn&#8217;t mean any of them will actually get elected.&nbsp; But it will hopefully send a message that whatever direction the ISC2 is currently headed in, and I certainly don&#8217;t know what direction that is, isn&#8217;t helping the general CISSP at all.</p>
<p>From Jack&#8217;s site:<br />
<blockquote>
<p>Below are the five candidates I am aware of, in alphabetical order:</p>
<ul>
<li>Tadd Axon</li>
<ul>
<li>email: <a href="mailto:isc2bodpetition@tadda.org" target="_blank">isc2bodpetition@tadda.org</a></li>
<li>website: <a title="https://sites.google.com/a/tadda.org/isc2petition/" href="https://sites.google.com/a/tadda.org/isc2petition/">https://sites.google.com/a/tadda.org/isc2petition/</a></li>
</ul>
<li>Seth Hardy</li>
<ul>
<li>email:&nbsp; <a href="mailto:shardy@asymptotic.ca">shardy@asymptotic.ca</a>&nbsp; </li>
<li>website:&nbsp; <a href="http://sethforisc2board.org/">http://sethforisc2board.org</a></li>
</ul>
<li>Javed Ikbal</li>
<ul>
<li>email: <a href="mailto:javed@bodelection.com">javed@bodelection.com</a>&nbsp;</li>
<li>website: <a href="http://bodelection.com/">http://bodelection.com</a></li>
</ul>
<li>Rolf Moulton</li>
<ul>
<li>email:&nbsp; <a href="mailto:rolf.moulton@boardcandidate.com">rolf.moulton@boardcandidate.com</a>&nbsp; </li>
<li>website:&nbsp; <a href="http://www.boardcandidate.com/">http://www.boardcandidate.com</a></li>
</ul>
<li>Wim Remes</li>
<ul>
<li>email: <a href="mailto:wim@remes-it.be">wim@remes-it.be</a>&nbsp; </li>
<li>website:&nbsp; <a href="http://blog.remes-it.be/petition.html">http://blog.remes-it.be/petition.html</a></li>
</ul>
</ul>
</blockquote>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F09%2F13%2Fhoping-to-affect-change-at-the-isc2%2F&amp;title=Hoping+to+affect+change+at+the+ISC2" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2011/09/13/hoping-to-affect-change-at-the-isc2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Support Change at the ISC2</title>
		<link>http://www.mckeay.net/2011/08/25/support-change-at-the-isc2/</link>
		<comments>http://www.mckeay.net/2011/08/25/support-change-at-the-isc2/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 15:01:39 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[CISSP/ISC2]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2011/08/25/support-change-at-the-isc2/</guid>
		<description><![CDATA[I&#8217;ve been a CISSP for close to a decade now.  And in that time, I&#8217;ve never really been happy with the way the ISC2 represents themselves, with the way they promote the the certificate and the way they support the CISSP community.  Basically, it&#8217;s been my opinion that the primary goal of the ISC2 has [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been a CISSP for close to a decade now.  And in that time, I&#8217;ve never really been happy with the way the ISC2 represents themselves, with the way they promote the the certificate and the way they support the CISSP community.  Basically, it&#8217;s been my opinion that the primary goal of the ISC2 has been self-promotion and the gathering of more people who have 5 more letters after their name.  Promoting the community, furthering security, making the world a better place have always seemed like secondary goals at best.  They do perform some good deeds, like the <a href="https://cyberexchange.isc2.org/volunteerIntro.aspx">Safe &amp; Secure Online Program</a>, but even that sometimes comes off as more a PR effort than a real attempt to improve the security of the world overall.  If you&#8217;ve ever read the CISSP mailing list (which you have to be a CISSP to do), you&#8217;ll notice that there&#8217;s been a lot of time spent complaining about the disconnect between everything the Board of the ISC2 does and what the community would really like to see done on our behalf.  My opinions on the leadership is probably part of why the ISC2 labeled a small group of people, including me, as the &#8216;Certified Usual Suspects&#8217;.  I even have the hat to prove it.</p>
<p>I&#8217;ve seen a few attempts at joining the ISC2 Board of Directors over the last few years, but unluckily I&#8217;ve never heard of most of the people who apply.  And to make matters worse, it&#8217;s incredibly difficult to get a seat on the Board unless you&#8217;re endorsed by current members of the Board.  So when I see someone I know of who&#8217;s preparing to take a run at the windmill again, I&#8217;m more than willing to help by putting my support behind them.  This year, <a href="http://blog.remes-it.be/petition.html">Wim Remes is running for the Board</a> and I&#8217;m going to support him and hope other CISSP&#8217;s will consider backing him as well.  I don&#8217;t know him personally, but given the interactions I&#8217;ve had with him on-line and the endorsements he&#8217;s already received from people I trust, I&#8217;m willing to take a chance.</p>
<p>Support Wim Remes by sending an e-mail <strong>from your e-mail address registered with ISC2</strong> mentioning your NAME, EMAIL ADDRESS and CERTIFICATION NUMBER to <a href="http://blog.remes-it.be/mailtowim@remes-it.be">wim@remes-it.be</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2011%2F08%2F25%2Fsupport-change-at-the-isc2%2F&amp;title=Support+Change+at+the+ISC2" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2011/08/25/support-change-at-the-isc2/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Logical fallacies in forums</title>
		<link>http://www.mckeay.net/2010/09/18/logical-fallacies-in-forums/</link>
		<comments>http://www.mckeay.net/2010/09/18/logical-fallacies-in-forums/#comments</comments>
		<pubDate>Sat, 18 Sep 2010 14:12:35 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Simple Security]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2010/09/18/logical-fallacies-in-forums/</guid>
		<description><![CDATA[Maybe it&#8217;s a little egotistical to reprint something you sent to a forum, but I thought I did a pretty good pointing out some of the fallacies I see all to often on forum mailing lists.  I doubt that I&#8217;ll actually influence the people most guilty of these fallacies, but the people who are borderline [...]]]></description>
			<content:encoded><![CDATA[<p>Maybe it&#8217;s a little egotistical to reprint something you sent to a forum, but I thought I did a pretty good pointing out some of the fallacies I see all to often on forum mailing lists.  I doubt that I&#8217;ll actually influence the people most guilty of these fallacies, but the people who are borderline may be salvageable.<br />
&#8212;<br />
Good morning dear colleagues,</p>
<p>I wanted to take a moment to make everyone aware of a very useful site I found several years ago that&#8217;s helpful when getting involved in argumentation of any sort.  It is the Nizkor Project listing of logical fallacies.  I find it helps me a lot to be able to identify and call out specific logical fallacies, at least to myself, and it helps in forming the response to these logical fallacies.  As is often the case in online forums, the person guilty of the fallacies is either unaware of committing the fallacies in the first place or mistakes these fallacies for honest communication.  In either case, conversations with this sort of individual often devolves into appeals to emotion or ad hominem attacks.  I wanted to take some time this morning to point out a few of the fallacies that seem to be more common on this forum:</p>
<p><a href="http://www.nizkor.org/features/fallacies/" target="_blank">http://www.nizkor.org/features/fallacies/</a></p>
<p>First, the ad hominem attack itself:  <a href="http://www.nizkor.org/features/fallacies/ad-hominem.html" target="_blank">http://www.nizkor.org/features/fallacies/ad-hominem.html</a><br />
This is an attack on the person who&#8217;s making the argument rather than the argument itself, aka name calling.  This is also mirrored by the personal attack fallacy (<a href="http://www.nizkor.org/features/fallacies/personal-attack.html" target="_blank">http://www.nizkor.org/features/fallacies/personal-attack.html</a>) where the person claims that any argumentation is a personal attack against them.  This is also related to the appeal to pity, aka &#8216;They&#8217;re picking on me, therefore they must be wrong&#8217; <a href="http://www.nizkor.org/features/fallacies/appeal-to-pity.html" target="_blank">http://www.nizkor.org/features/fallacies/appeal-to-pity.html</a></p>
<p>The second fallacy I often see is the red herring (<a href="http://www.nizkor.org/features/fallacies/red-herring.html" target="_blank">http://www.nizkor.org/features/fallacies/red-herring.html</a>)  The answers that are sent to the forum have little or no relation to<br />
the question that was asked.  This can be an innocent case of missing the point or it can be an example of purposefully leading the conversation away from the subject that was originally brought up.  If you see &#8220;you&#8217;re missing the point&#8221; in a reply, this is often the fallacy that was committed.</p>
<p>Another common fallacy on this forum is the appeal to authority (<a href="http://www.nizkor.org/features/fallacies/appeal-to-authority.html" target="_blank">http://www.nizkor.org/features/fallacies/appeal-to-authority.html</a>)  We&#8217;re all experts of one level or another in this forum, otherwise we should never have been awarded our CISSP&#8217;s in the first place.  However, we sometimes try to falsely extend our authority in one area to cover areas that are tangential to our areas of expertise in was that are not appropriate.  Another example of this is citing vague articles or standards as supporting our cause when they really don&#8217;t have any direct bearing on the argument.  For example, just because Bruce Schneier is a respected author and cryptographer, he could not by any means be considered an expert on securing an Exchange server.  Another part of this fallacy that&#8217;s common is expecting that just because we hold certificates in certain disciplines, that we&#8217;re actually experts in that discipline.  A doctor who graduated at the bottom 5% of his class still graduated after all.</p>
<p>A final fallacy to think on, not because it&#8217;s especially common on the forum, but because it&#8217;s especially common in our lives in general is the appeal to common practice (<a href="http://www.nizkor.org/features/fallacies/appeal-to-common-practice.html" target="_blank">http://www.nizkor.org/features/fallacies/appeal-to-common-practice.html</a>)  Everyone is doing it, so it can&#8217;t be that bad, can it?  This is a fallacy that should be avoided in every aspect of life, not just security.  As parents have been asking their kids for eons, &#8220;If every one of your friends jumped off a cliff, would you jump too?&#8221;.  Everyone has a firewall at the perimeter of their network; does that make a firewall a best practice or does that just mean that it&#8217;s what people are doing because everyone else is doing it?  It may be the best thing to do in your situation, but unless you evaluate it based on your circumstances rather than what others do, you&#8217;ll never know.</p>
<p>I try not to make the mistake of ad hominem attacks, I try to attack a person&#8217;s argument whenever possible.  This is not always possible as the number of fallacies in a response rise and overwhelm any content that may be contained in a response.  Rather than continue down a path of personal attacks and appeals to emotion, I try to bow out of the conversation at that point.  But I&#8217;m not perfect. Next time you send a reply to the list, take a few minutes to check your logic and see if you&#8217;re committing any of these common fallacies.  It will help make your point and increase your standing with your colleagues.  Failure to do so can hurt your standing in the community greatly.</p>
<p>Thank you,</p>
<p>Martin</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F18%2Flogical-fallacies-in-forums%2F&amp;title=Logical+fallacies+in+forums" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2010/09/18/logical-fallacies-in-forums/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Just for fun, part 2</title>
		<link>http://www.mckeay.net/2010/09/09/just-for-fun-part-2/</link>
		<comments>http://www.mckeay.net/2010/09/09/just-for-fun-part-2/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 02:55:53 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Humor]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2010/09/09/just-for-fun-part-2/</guid>
		<description><![CDATA[Here&#8217;s the CISSP Song by Rob Slade.&#160; I&#8217;m not going to try to sing it, but I hope someone does.&#160; And I hope that someone sends me the recording to play on the podcast. Thanks Rob! CISSP Song Lyrics by Rob Slade slade@victoria.tc.ca Sung to the tune of &#8220;The Major General&#8217;s Song,&#8221; from &#8220;Pirates of [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s the CISSP Song by Rob Slade.&nbsp; I&#8217;m not going to try to sing it, but I hope someone does.&nbsp; And I hope that someone sends me the recording to play on the podcast.</p>
<p>Thanks Rob!</p>
<p>CISSP Song<br />
Lyrics by Rob Slade <a href="mailto:slade%40victoria.tc.ca" target="_blank">slade@victoria.tc.ca</a></p>
<p>Sung to the tune of &#8220;The Major General&#8217;s Song,&#8221; from<br />
&#8220;Pirates of Penzance,&#8221; by Gilbert and Sullivan [1]</p>
<p>CISSP (solo):<br />
I am a Certifiable Security Professional<br />
I&#8217;ve countermeasures physical, administrative, technical<br />
I know the ports of TCP and backdoors with malign intent<br />
And survey risk analysis to prove the safeguards wisely spent<br />
I&#8217;m very well acquainted, too, with matters of the blackhat crew<br />
Attendance on the IRC phrack channel makes my colleagues stew<br />
With viruses and zero days I&#8217;m teeming with a lot o&#8217; news,<br />
With many cheerful facts about the weaknesses in Usenet news</p>
<p>CIO Chorus:<br />
With many cheerful facts about the weaknesses in Usenet news (etc.)</p>
<p>CISSP:<br />
I&#8217;m very good at ACLs and mandatory access modes<br />
I know the disassembled names of CPU compare opcodes<br />
In short, in matters physical, administrative, technical<br />
I am the very model of an infosec professional!</p>
<p>Chorus:<br />
In short, in matters physical, administrative, technical<br />
He is the very model of an infosec professional!</p>
<p>CISSP:<br />
I know our mythic history, LaPadula, Biba, and Bell<br />
I know the biometric facts, memorized CERs as well<br />
I understand the lattice, roles, rules, and discretion base<br />
And pseudorandomize my keys to maximize the address space<br />
I&#8217;ve tokens, tickets, one-time passwords, smart cards and a kerberos<br />
And Centralized Remote Authentication to remove the dross<br />
I&#8217;m proof against the DoS, Man-in-the-Middle and brute force attacks<br />
My proprietary off-the-shelf stuff&#8217;s licenced and it never cracks.</p>
<p>Chorus:<br />
His proprietary off-the-shelf&#8217;s all licenced and it never cracks.</p>
<p>CISSP:<br />
My audit logs are analysed, detect intrusions evey time<br />
My legal counsel&#8217;s up to date with all the best computer crime <br />
In short, in matters physical, administrative, technical<br />
I am the very model of an infosec professional!</p>
<p>Chorus:<br />
In short, in matters physical, administrative, technical<br />
He is the very model of an infosec professional!</p>
<p>CISSP:<br />
In fact when I know what is meant by &#8220;data link&#8221; and &#8220;twisted pair&#8221;<br />
When I can tell a fibre optic cable from a trigger hair<br />
When Internet Explorer I no longer use the Web to surf<br />
Or let my users chat on IRC on all my network turf<br />
When I have learnt that firewalls can filter out the packets bad<br />
When I know that the guy with foreign bank accounts might be a cad<br />
In short when I&#8217;ve a wee bit of professional paranoia<br />
You&#8217;ll say a better CISSP has never addressed yuh.</p>
<p>Chorus:<br />
You&#8217;ll say a better CISSP has never addressed yuh.</p>
<p>CISSP:<br />
For my security training, managerial though it may be<br />
Lacks practical direction and real-world applicability<br />
But still, in matters physical, administrative, technical<br />
I am the very model of an infosec professional!</p>
<p>Chorus:<br />
But still, in matters physical, administrative, technical<br />
He is the very model of an infosec professional!</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F09%2F09%2Fjust-for-fun-part-2%2F&amp;title=Just+for+fun%2C+part+2" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2010/09/09/just-for-fun-part-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>RSAC2010:  ISC2</title>
		<link>http://www.mckeay.net/2010/03/08/rsac2010-isc2/</link>
		<comments>http://www.mckeay.net/2010/03/08/rsac2010-isc2/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 14:33:02 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2010/03/08/rsac2010-isc2/</guid>
		<description><![CDATA[I&#8217;ve been a member of the International Information Systems Security Certification Consortium [(ISC)2] for nearly a decade; I passed my CISSP test in November of 2002 and don&#8217;t have to worry much about CPE&#8217;s until at least 2011.&#160; So when I was offered an opportunity to talk to Hord Tipton, Executive Director of the (ISC)2, [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been a member of the <a href="http://www.isc2.org/">International Information Systems Security Certification Consortium [(ISC)2]</a> for nearly a decade; I passed my CISSP test in November of 2002 and don&#8217;t have to worry much about CPE&#8217;s until at least 2011.&nbsp; So when I was offered an opportunity to talk to Hord Tipton, Executive Director of the (ISC)2, I didn&#8217;t hesitate to take them up on the offer.&nbsp; We started off easy, talking about what&#8217;s new at the (ISC)2, and the <a href="http://cyberexchange.isc2.org/volunteerIntro.aspx">Safe &amp; Secure Online Program</a>.&nbsp; Then we moved on to the harder questions, like &#8220;What have you done for me lately?&#8221; and &#8220;What are you doing about people who shouldn&#8217;t be CISSP&#8217;s in the first place?&#8221;&nbsp; The (ISC)2 is never going to make all of us who are certified happy, and that they are taking some steps to address concerns about unqualified practitioners, but it&#8217;d be nice if they were a little more public about it.&nbsp; Oh, and you&#8217;ll hear at the end that the (ISC)2 definitely accepts listening to podcasts for CPE&#8217;s.&nbsp; I forgot to ask about producing them.</p>
<p><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-ISC2.mp3">NSP-RSAC2010-ISC2.mp3</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" alt="" src="http://img.zemanta.com/pixy.gif?x-id=a1b41f2b-e9f9-80fe-a583-f80a3c590c34" /></div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2010%2F03%2F08%2Frsac2010-isc2%2F&amp;title=RSAC2010%3A++ISC2" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2010/03/08/rsac2010-isc2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
			<enclosure url="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-ISC2.mp3" length="12468858" type="audio/mpeg" />
	</item>
		<item>
		<title>You&#8217;ve got to appreciate truth in advertising</title>
		<link>http://www.mckeay.net/2007/07/16/youve-got-to-appreciate-truth-in-advertising/</link>
		<comments>http://www.mckeay.net/2007/07/16/youve-got-to-appreciate-truth-in-advertising/#comments</comments>
		<pubDate>Mon, 16 Jul 2007 16:10:58 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Apple/Mac]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Phishing, scams, etc.]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Simple Security]]></category>
		<category><![CDATA[Site Configuration]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2007/07/16/youve-got-to-appreciate-truth-in-advertising/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>I use Gmail as my central email repository and usually the spam filters they use are pretty good.&nbsp; But lately they&#8217;ve been a little overly aggressive, so I have to comb through to make sure no legitimate email is being caught accidentally.&nbsp; There&#8217;s not a lot that&#8217;s misidentified, but there&#8217;s enough to make it worth the few minutes a day it takes to double-check the spam folder.</p>
<p>I&#8217;ve been amazed at some of the subject lines I see, as well as what I see in the preview of the email.&nbsp; There&#8217;s no way I&#8217;m going to click on any of them to find out what else is in the spam, because it&#8217;s just not worth the risk.&nbsp; But I do have to say that my favorite subject line so far is &#8220;Thanks for contributing to our financial success&#8221;.&nbsp; It&#8217;s honest and straight forward even if it is just an attempt to rip off people around the globe.</p>
<p>On a side note, I used to clean out my spam folder every couple of days, but in March I started letting them accumulate and get deleted automatically when they&#8217;ve aged 30 days.&nbsp; It&#8217;s been interesting watching the number of spams spike and drop.&nbsp; At one point I had gathered nearly 9000 spams in a 30 day period, which works out to an average of 300 spams a day.&nbsp;&nbsp; Personally, that means about 60% of my email is spam, a far lower percentage of spam than most people see.&nbsp; I guess being subscribed to ten or so mailing lists had to have some benefit.</p>
<p>Mine is just a single data point, compared to the millions some anti-spam vendors get to see.&nbsp; But  I like having a personal high water mark to compare to what the vendors are reporting. I&#8217;m not a spam expert, so it&#8217;s interesting to see new spam subjects that companies like&nbsp; <a href="http://www.f-secure.com/weblog/">F-secure</a> report.&nbsp; Anyone else out there keep track of the spam they receive for fun?</p>
<p>Technorati Tags: <a class="performancingtags" href="http://technorati.com/tag/security" rel="tag">security</a>, <a class="performancingtags" href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a class="performancingtags" href="http://technorati.com/tag/McKeay" rel="tag">McKeay</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F16%2Fyouve-got-to-appreciate-truth-in-advertising%2F&amp;title=You%26%238217%3Bve+got+to+appreciate+truth+in+advertising" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2007/07/16/youve-got-to-appreciate-truth-in-advertising/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Using charities to test stolen cards</title>
		<link>http://www.mckeay.net/2007/07/10/using-charities-to-test-stolen-cards/</link>
		<comments>http://www.mckeay.net/2007/07/10/using-charities-to-test-stolen-cards/#comments</comments>
		<pubDate>Tue, 10 Jul 2007 17:51:06 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Apple/Mac]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Phishing, scams, etc.]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Simple Security]]></category>
		<category><![CDATA[Site Configuration]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2007/07/10/using-charities-to-test-stolen-cards/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>This makes sense in a twisted way:&nbsp; <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/07/scammers_make_friends_with_cha.html">scammers are using charities to test stolen credit cards</a>. As the post points out, they&#8217;re using charities because most banks aren&#8217;t going to flag a donation, since it&#8217;s something most people only do on special occasions and it&#8217;s hard to create a behavioral monitoring program that could catch this as being an unusual activity with any accuracy.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2007%2F07%2F10%2Fusing-charities-to-test-stolen-cards%2F&amp;title=Using+charities+to+test+stolen+cards" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2007/07/10/using-charities-to-test-stolen-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The target was material for phishing attacks</title>
		<link>http://www.mckeay.net/2006/09/01/the-target-was-material-for-phishing-attacks/</link>
		<comments>http://www.mckeay.net/2006/09/01/the-target-was-material-for-phishing-attacks/#comments</comments>
		<pubDate>Fri, 01 Sep 2006 21:32:08 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Apple/Mac]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Phishing, scams, etc.]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Simple Security]]></category>
		<category><![CDATA[Site Configuration]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2006/09/01/the-target-was-material-for-phishing-attacks/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>According to the SFGate, the intrusion that AT&amp;T reported earlier this week was not aimed at stealing credit card information, it was <a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2006/09/01/BUGVBKSUIE1.DTL">aimed at providing the raw data to allow the crackers to perform targetted phishing attacks on a massive scale</a>.&nbsp; By seeding an email with information gathered from AT&amp;T&#8217;s database, the phishers can add a level authenticity that makes even some of the most suspicious people on the Internet accept an email as authentic. </p>
<p>This is just one more reason to never respond directly to any request from a merchant or bank that comes to you in the form of an email.&nbsp; As always, if you think an email alert is real, open a browser window and manually type in your bank&#8217;s URL, never click on the link in the email.&nbsp; </p>
<p>Technorati Tags: <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/McKeay" rel="tag">McKeay</a>, <a href="http://technorati.com/tag/AT&amp;T" rel="tag">AT&amp;T</a>, <a href="http://technorati.com/tag/phishing" rel="tag">phishing</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F09%2F01%2Fthe-target-was-material-for-phishing-attacks%2F&amp;title=The+target+was+material+for+phishing+attacks" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2006/09/01/the-target-was-material-for-phishing-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I need some cheap USB thumb drives!</title>
		<link>http://www.mckeay.net/2006/06/09/i-need-some-cheap-usb-thumb-drives/</link>
		<comments>http://www.mckeay.net/2006/06/09/i-need-some-cheap-usb-thumb-drives/#comments</comments>
		<pubDate>Fri, 09 Jun 2006 16:25:31 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Apple/Mac]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Phishing, scams, etc.]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Simple Security]]></category>
		<category><![CDATA[Site Configuration]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2006/06/09/i-need-some-cheap-usb-thumb-drives/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>What an <a href="http://www.darkreading.com/document.asp?doc_id=95556&amp;WT.svl=column1_1">evil, sneaky, underhanded way to social engineer</a> a business!&nbsp; I like it!&nbsp; This company took twenty USB thumb drives, seeded them liberally with malware and pictures, and left them on the ground outside the credit union they were targeting.&nbsp;&nbsp;  People fell for it, and quite frankly I can&#8217;t say I blame them.&nbsp; If I found a thumb drive laying around in the parking lot, I&#8217;d probably plug it into a system to see who it belonged to myself.&nbsp; Or at least I would have before I read this article.&nbsp; </p>
<p>This was done as part of a penatration test, with the full approval of the company that was attacked.&nbsp; But is it really safe for anyone to assume that the any media you find laying around was lost, not placed there on purpose?&nbsp; This really would be a good way to target almost any company you might want to mention.&nbsp; It&#8217;s so much safer to always assume a malicious intent and take the proper precautions than it is to assume innocence.&nbsp; This is why I always get so angry when businesses talk about stolen laptops and the thieves not knowing what they have.&nbsp; You have to assume malicious intent and prove that none exists, not the other way around.</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/USB%20drive" rel="tag">USB drive</a>, <a href="http://technorati.com/tag/social%20engineering" rel="tag">social engineering</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F06%2F09%2Fi-need-some-cheap-usb-thumb-drives%2F&amp;title=I+need+some+cheap+USB+thumb+drives%21" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2006/06/09/i-need-some-cheap-usb-thumb-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quoted for an article on SearchSecurity</title>
		<link>http://www.mckeay.net/2006/05/25/quoted-for-an-article-on-searchsecurity/</link>
		<comments>http://www.mckeay.net/2006/05/25/quoted-for-an-article-on-searchsecurity/#comments</comments>
		<pubDate>Thu, 25 May 2006 17:15:31 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Apple/Mac]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[CISSP/ISC2]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Phishing, scams, etc.]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Simple Security]]></category>
		<category><![CDATA[Site Configuration]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://www.mckeay.net/2006/05/25/quoted-for-an-article-on-searchsecurity/</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p>Comments I made on my <a href="http://www.computerworld.com/blogs/node/2559">ComputerWorld blog</a> were quoted today in an article on <a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1190407,00.html?track=NL-102&amp;ad=551708">SearchSecurity about the Black Frog/Okopipi project.</a>&nbsp; After talking to one or two members of the project, I think I oversimplified the challenges Okopipi will be facing, but I&#8217;m still dubious abou the project.&nbsp; It&#8217;s something that&#8217;s going to have to be handled with great care, and I&#8217;m not sure an open source project is the way to go.&nbsp; Every unsubscribe link is going to have to be verified by a real person, not just a program, and I still see several ways spammers could turn this project to evil.&nbsp; I don&#8217;t think this is reason enough not to at least try, but I don&#8217;t believe I&#8217;ll be participating in a distributed, P2P anti-spam solution any time soon.</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/Okopipi" rel="tag">Okopipi</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2006%2F05%2F25%2Fquoted-for-an-article-on-searchsecurity%2F&amp;title=Quoted+for+an+article+on+SearchSecurity" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.mckeay.net/2006/05/25/quoted-for-an-article-on-searchsecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

