<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Network Security Blog</title><link>http://www.mckeay.net</link><description>The views of one man on security, privacy and anything else that catches his attention</description><language>en</language><image><link>http://www.mckeay.net</link><url>http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo144.jpg</url><title>Network Security Blog</title><width>144</width><height>144</height></image><copyright>©</copyright><managingEditor>martin@mckeay.net</managingEditor><generator>http://wordpress.org/?v=abc</generator><itunes:keywords /><itunes:subtitle>Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.</itunes:subtitle><itunes:summary>Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.</itunes:summary><itunes:author>Martin McKeay</itunes:author><itunes:block>No</itunes:block><itunes:explicit>no</itunes:explicit><itunes:image href="http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo300.jpg" /><media:copyright>©</media:copyright><media:thumbnail url="http://mckeay.net/wp-content/plugins/podpress/images/networksecuritylogo300.jpg" /><media:keywords></media:keywords><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Tech News</media:category><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Technology/Tech News</media:category><itunes:owner><itunes:email>netsecpodcast@mckeay.net</itunes:email><itunes:name>Martin McKeay</itunes:name></itunes:owner><itunes:category text="Technology"><itunes:category text="Tech News" /></itunes:category><itunes:category text="Technology"><itunes:category text="Tech News" /></itunes:category><geo:lat>38.440111</geo:lat><geo:long>-122.745633</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/MartinMckeaysNetworkSecurityBlog" type="application/rss+xml" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item><title>Network Security Podcast, Episode 128</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/457962504/</link><category>Podcast</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 18 Nov 2008 22:19:57 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/18/network-security-podcast-episode-128/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>We&#8217;re joined today by Glenn Fleishman to talk about our own recent past and the recent cracks in the WPA armor.&nbsp; Rich recently got to visit Russia to participate in a talk on Data Leak Prevention, while Martin got his own sit down with DHS Secretary Michael Chertoff.&nbsp; Glenn had a little excitement of his own, with a detailed article on the recently revealed vulnerabilities in WPA using TKIP.&nbsp; It&#8217;s a small vulnerabilty, but both Rich and Glenn suspect it&#8217;s just a precursor to bigger, badder things to come. And somewhere in there, a three year anniversary for the podcast slipped by.</p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-111808-ep128.mp3">Network Security Podcast, Episode 128, November 18, 2008 </a></p>
<p><span style="text-decoration: underline; font-weight: bold;">Show Notes:</span>
<ul>
<li><a href="http://arstechnica.com/articles/paedia/wpa-cracked.ars">Battered but not broken:&nbsp; understanding the WPA crack&nbsp;</a></li>
<li><a href="http://dl.aircrack-ng.org/breakingwepandwpa.pdf">Practical attacks against WEP and WPA&nbsp;</a></li>
</ul>
<p>No time for any music or fancy stuff like that.&nbsp; </p>
<p></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F&amp;title=Network+Security+Podcast%2C+Episode+128" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_hQsN4t6ubSQrIsvFGzY-.iS5Qmc_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/hQsN4t6ubSQrIsvFGzY-.iS5Qmc_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_hQsN4t6ubSQrIsvFGzY-.iS5Qmc_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=hQsN4t6ubSQrIsvFGzY-.iS5Qmc_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F18%2Fnetwork-security-podcast-episode-128%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=8R3MuV"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=8R3MuV" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/457962504" height="1" width="1"/>]]></content:encoded><description>We&amp;#8217;re joined today by Glenn Fleishman to talk about our own recent past and the recent cracks in the WPA armor.&amp;#160; Rich recently got to visit Russia to participate in a talk on Data Leak Prevention, while Martin got his own sit down with DHS Secretary Michael Chertoff.&amp;#160; Glenn had a little excitement of his [...]</description><enclosure url="http://media.libsyn.com/media/mckeay/nsp-111808-ep128.mp3" length="39884392" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/18/network-security-podcast-episode-128/feed/</wfw:commentRss><media:content url="http://media.libsyn.com/media/mckeay/nsp-111808-ep128.mp3" fileSize="39884392" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>Podcast</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2008/11/18/network-security-podcast-episode-128/</feedburner:origLink></item><item><title>Congratulations to April and Jason</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/454509942/</link><category>Blogging</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Sat, 15 Nov 2008 21:00:39 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/15/congratulations-to-april-and-jason/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I spent the last day helping my friends Jason and April get hitched.&nbsp; I think there&#8217;s some work to be done on it, but you can <a href="http://www.apriljason.com/">see some of the video</a> on their site.
<div style="text-align: center;"><a href="http://www.mckeay.net/images/AprilJason316.JPG"><img style="max-width: 800px;" src="http://www.mckeay.net/images/AprilJason316-sm.JPG" /></a></div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F&amp;title=Congratulations+to+April+and+Jason" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_PJIcq4SyKLG6ICD.cEWodubUoDE_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/PJIcq4SyKLG6ICD.cEWodubUoDE_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_PJIcq4SyKLG6ICD.cEWodubUoDE_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=PJIcq4SyKLG6ICD.cEWodubUoDE_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F15%2Fcongratulations-to-april-and-jason%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=FjSV6A"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=FjSV6A" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/454509942" height="1" width="1"/>]]></content:encoded><description>I spent the last day helping my friends Jason and April get hitched.&amp;#160; I think there&amp;#8217;s some work to be done on it, but you can see some of the video on their site.</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/15/congratulations-to-april-and-jason/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/15/congratulations-to-april-and-jason/</feedburner:origLink></item><item><title>Pictures and George Ou’s comments</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/452535868/</link><category>Blogging</category><category>Government</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Thu, 13 Nov 2008 22:47:54 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/13/pictures-and-george-ous-comments/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I just got some pictures from Tuesday that were taken by Secretary Chertoff&#8217;s photographer.&nbsp; If you look at my Mac Book Pro, you&#8217;ll see several stickers rather prominently displayed, but the most obvious one is &#8220;Hack Naked&#8221; from <a href="http://pauldotcom.com">PauldotCom Security Weekly</a>!&nbsp; I really wasn&#8217;t thinking about what I was carrying around, since the bag I was using that day was a Black Hat 2008 bag.&nbsp; I&#8217;m glad they knew enough about me not to be worried about my hacking skills.&nbsp; 
<div style="text-align: center;"><a target="_blank" href="http://www.mckeay.net/images/081111-H-3721C-307-S1%28San%20Diego%20-%20Palo%20Alto%29.jpg"><img style="max-width: 800px;" src="http://www.mckeay.net/images/081111-H-3721C-307-S1%28San%20Diego%20-%20Palo%20Alto%29-sm.JPG" /></a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a target="_blank" href="http://www.mckeay.net/images/081111-H-3721C-309-S1%28San%20Diego%20-%20Palo%20Alto%29.jpg"><img style="max-width: 800px;" src="http://www.mckeay.net/images/081111-H-3721C-309-S1%28San%20Diego%20-%20Palo%20Alto%29-sm.JPG" /></a></div>
<p>George Ou has done a <a href="http://www.formortals.com/Home/tabid/36/EntryID/134/Default.aspx">good job of writing up his experience</a> from Tuesday.&nbsp; George and I have different priorities, so it was good for him to ask questions I wouldn&#8217;t have thought of.&nbsp; We were all impressed by the statistics concerning the no-fly list:&nbsp; there are only approximately 2500 names on the true &#8216;no-fly&#8217; list and another 20,000 on the extra security list.&nbsp; And of those, only 10% are American citizens according to Secretary Chertoff.&nbsp; For such a small list, it sure has created a big stir.</p>
<p>Added:&nbsp; Of course, minutes after I posted this, I found out that Andrew Storms, the guy pictured to the right of me, <a href="http://blog.ncircle.com/blogs/sync/archives/2008/11/meeting_with_michael_chertoff.html">wrote up his own experience</a>.&nbsp; I think between the excellent posts by Andrew and and George, I don&#8217;t need to feel guilty about not having time to write up my own experience.&nbsp; </p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F&amp;title=Pictures+and+George+Ou%26%238217%3Bs+comments" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_zma0BjlhPUWdR1Lv9y9nt6EnrhI_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/zma0BjlhPUWdR1Lv9y9nt6EnrhI_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_zma0BjlhPUWdR1Lv9y9nt6EnrhI_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=zma0BjlhPUWdR1Lv9y9nt6EnrhI_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F13%2Fpictures-and-george-ous-comments%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=p9jAwf"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=p9jAwf" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/452535868" height="1" width="1"/>]]></content:encoded><description>I just got some pictures from Tuesday that were taken by Secretary Chertoff&amp;#8217;s photographer.&amp;#160; If you look at my Mac Book Pro, you&amp;#8217;ll see several stickers rather prominently displayed, but the most obvious one is &amp;#8220;Hack Naked&amp;#8221; from PauldotCom Security Weekly!&amp;#160; I really wasn&amp;#8217;t thinking about what I was carrying around, since the bag I [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/13/pictures-and-george-ous-comments/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/13/pictures-and-george-ous-comments/</feedburner:origLink></item><item><title>Double-check your QSA</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/450869986/</link><category>PCI</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Wed, 12 Nov 2008 10:41:03 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/12/double-check-your-qsa/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I&#8217;m not sure if this is something I&#8217;d missed before, but you can <a href="https://www.pcisecuritystandards.org/qsa_lookup/index.html">look up you&#8217;re Qualified Security Assessor (QSA)</a> and see if they&#8217;re in good standing.&nbsp; All you need is their last name and the name of their company and you can know for certain that they&#8217;re on the up and up and have had their annual training.&nbsp; This is something you should take the five minutes to do to check out the QSA&#8217;s who&#8217;ll be working with you.&nbsp; I don&#8217;t have specific examples, but I&#8217;ve heard rumors that there are some folks out there representing themselves to Level 3 and level 4 merchants as QSA&#8217;s when they&#8217;re not.&nbsp; Take the 5 minutes to verify your assessor, you owe it too yourself.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F&amp;title=Double-check+your+QSA" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_91B8yD7uuXxYCM2FJCD9u18Z7E4_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/91B8yD7uuXxYCM2FJCD9u18Z7E4_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_91B8yD7uuXxYCM2FJCD9u18Z7E4_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=91B8yD7uuXxYCM2FJCD9u18Z7E4_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Fdouble-check-your-qsa%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=7WECa2"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=7WECa2" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/450869986" height="1" width="1"/>]]></content:encoded><description>I&amp;#8217;m not sure if this is something I&amp;#8217;d missed before, but you can look up you&amp;#8217;re Qualified Security Assessor (QSA) and see if they&amp;#8217;re in good standing.&amp;#160; All you need is their last name and the name of their company and you can know for certain that they&amp;#8217;re on the up and up and have [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/12/double-check-your-qsa/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/12/double-check-your-qsa/</feedburner:origLink></item><item><title>Talking to Michael Chertoff</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/450785921/</link><category>Blogging</category><category>Government</category><category>Podcast</category><category>Department of Homeland Security</category><category>DHS</category><category>Michael Chertoff</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Wed, 12 Nov 2008 09:17:10 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/12/talking-to-michael-chertoff/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>I&#8217;m still digesting yesterday&#8217;s talk with DHS Secretary Michael Chertoff.&nbsp; Thanks to Mr. Chertoff and his press folks for inviting me to the event.&nbsp; I never thought I&#8217;d invited to talk to one of the highest level security professionals in the country, it wasn&#8217;t even something I had as a &#8217;some day, possibly&#8217; goal.&nbsp; I don&#8217;t agree with everything Mr. Chertoff said, but I still enjoyed talking to him and learning about his point of view.&nbsp; You can <a href="http://netsecpodcast.com/?p=131">listen to the audio</a> in the latest podcast.</p>
<p>Deborah Gage at SFGate wrote up <a href="http://www.sfgate.com/cgi-bin/blogs/sfgate/detail?blogid=19&amp;entry_id=32533">her impression of the conversation</a>, which captured most of the points of the conversation rather well.&nbsp; I&#8217;m just disappointed she referred to us as &#8216;Silicon Valley bloggers&#8217; instead of mentioning names and blogs.&nbsp; Plus, technically, only George Ou is a Silicon Valley blogger, I&#8217;m over 100 miles away in the North Bay and Andrew Storms isn&#8217;t much closer.&nbsp; Still a good write up.&nbsp; I have to wonder if SFGate.com has something against linking out to bloggers since we&#8217;re sometimes direct competition.&nbsp; </p>
<p>I only took a couple of pictures as I was much more interested in taking part in the conversation and live tweeting it.&nbsp; Luckily Andrew Storms caught a number of <a href="http://www.flickr.com/photos/linecon0/sets/72157608913845084/">good shots of Secretary Chertoff</a>.&nbsp; And the back of my head, definitely not my most photogenic parts.&nbsp; I hope to see Andrew&#8217;s take on the conversation soon.&nbsp; Here are a couple of the photo&#8217;s I took of Mr. Chertoff, Andrew Storms and George Ou.&nbsp; I&#8217;ll post a bit more on the meeting as time allows.&nbsp; Which probably means not today.</p>
<div style="text-align: center;"><a href="http://www.flickr.com/photos/mmckeay/3025228598/"><img style="max-width: 800px;" src="http://farm4.static.flickr.com/3046/3025228598_62d85419f3_m.jpg" /></a>&nbsp;&nbsp; <a href="http://www.flickr.com/photos/mmckeay/3024398503/"><img style="max-width: 800px;" src="http://farm4.static.flickr.com/3048/3024398503_b515049983_m.jpg" /></a></div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F&amp;title=Talking+to+Michael+Chertoff" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_V3rydNFm7DpP63F7AJ.7XgOOM-4_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/V3rydNFm7DpP63F7AJ.7XgOOM-4_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_V3rydNFm7DpP63F7AJ.7XgOOM-4_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=V3rydNFm7DpP63F7AJ.7XgOOM-4_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F12%2Ftalking-to-michael-chertoff%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=MdQ8wn"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=MdQ8wn" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/450785921" height="1" width="1"/>]]></content:encoded><description>I&amp;#8217;m still digesting yesterday&amp;#8217;s talk with DHS Secretary Michael Chertoff.&amp;#160; Thanks to Mr. Chertoff and his press folks for inviting me to the event.&amp;#160; I never thought I&amp;#8217;d invited to talk to one of the highest level security professionals in the country, it wasn&amp;#8217;t even something I had as a &amp;#8217;some day, possibly&amp;#8217; goal.&amp;#160; I [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/12/talking-to-michael-chertoff/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/12/talking-to-michael-chertoff/</feedburner:origLink></item><item><title>Network Security Podcast, Episode 127:  DHS Secretary Michael Chertoff</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/450343389/</link><category>Government</category><category>Podcast</category><category>Chertoff</category><category>Department of Homeland Security</category><category>DHS</category><category>Michael Chertoff</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 11 Nov 2008 23:54:03 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/11/network-security-podcast-episode-127-dhs-secretary-michael-chertoff/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>When I first got an invitation to attend a roundtable discussion with Department of Homeland Security Secretary Michael Chertoff, I thought thought it was a hoax, as did some of the people I asked about it.&nbsp; A little fact checking revealed that it was the real deal, but the meeting was in Washington, DC.&nbsp; Traveling cross country for an hour meeting isn&#8217;t in my budget, so I regretfully passed on the opportunity.&nbsp; Fast forward a month and the invite comes again, but this time it&#8217;s happening at Stanford University.&nbsp; There&#8217;s no way I could pass that by.&nbsp; <a href="http://blog.ncircle.com/">Andrew Storms</a> and <a href="http://www.formortals.com/Default.aspx">George Ou</a> expressed interest in going and Secretary Chertoff&#8217;s Press Secretary, Caroline Dieker, made the arrangements and we were all invited to attend.</p>
<p>I was impressed by Secretary Chertoff; he speaks plainly, with only a little of the evasion I&#8217;d expected from someone in a position like his.&nbsp; I don&#8217;t agree with all his arguments and ideas, but he was very open to discussing them publicly.&nbsp; I almost feel bad that he&#8217;s going to be gone come January.&nbsp; I tried to tweet the whole thing as much as possible, but it&#8217;s easy to get distracted in a situation like this.&nbsp; I captured the entire conversation on my little iRiver 795 and here it is so you can listen for yourself.&nbsp; </p>
<p><a href="http://media.libsyn.com/media/mckeay/nsp-111108-ep127.MP3">Network Security Podcast, Episode 127, November 11, 2008</a> - Blogger Roundtable with DHS Secretary Michael Chertoff</p>
<p>I&#8217;m posting a copy of the live tweets in the comments, along with the replies.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F&amp;title=Network+Security+Podcast%2C+Episode+127%3A++DHS+Secretary+Michael+Chertoff" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_BYiKHeTGdyt0WPvl-u.aGgXNYhc_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/BYiKHeTGdyt0WPvl-u.aGgXNYhc_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_BYiKHeTGdyt0WPvl-u.aGgXNYhc_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=BYiKHeTGdyt0WPvl-u.aGgXNYhc_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fnetwork-security-podcast-episode-127-dhs-secretary-michael-chertoff%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=jaHfjS"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=jaHfjS" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/450343389" height="1" width="1"/>]]></content:encoded><description>When I first got an invitation to attend a roundtable discussion with Department of Homeland Security Secretary Michael Chertoff, I thought thought it was a hoax, as did some of the people I asked about it.&amp;#160; A little fact checking revealed that it was the real deal, but the meeting was in Washington, DC.&amp;#160; Traveling [...]</description><enclosure url="http://media.libsyn.com/media/mckeay/nsp-111108-ep127.MP3" length="52837869" type="audio/mpeg" /><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/11/network-security-podcast-episode-127-dhs-secretary-michael-chertoff/feed/</wfw:commentRss><media:content url="http://media.libsyn.com/media/mckeay/nsp-111108-ep127.MP3" fileSize="52837869" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:author>Martin McKeay</itunes:author><itunes:summary>The views of one man on security, privacy and anything else that catches his attention</itunes:summary><itunes:keywords>Government, Podcast, Chertoff, Department of Homeland Security, DHS, Michael Chertoff</itunes:keywords><feedburner:origLink>http://www.mckeay.net/2008/11/11/network-security-podcast-episode-127-dhs-secretary-michael-chertoff/</feedburner:origLink></item><item><title>All the stuff I don’t have time to blog about</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/449619471/</link><category>General</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Tue, 11 Nov 2008 09:06:40 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/11/all-the-stuff-i-dont-have-time-to-blog-about/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>We&#8217;re all busy and the more stories I accumulate in my browser, the less time it seems I have to do anything with them.&nbsp; So in order to clear out some of the open tabs, here&#8217;s some of the stories I&#8217;ve been reading lately:
<ul>
<li><a href="http://phx.corporate-ir.net/phoenix.zhtml?c=69641&amp;p=irol-newsArticle&amp;ID=1223389&amp;highlight=">Express Scritps warns of potential large data breach tied to threat</a> - Extortion, plan and simple.&nbsp;&nbsp;</li>
<li><a href="http://dmiessler.com/blog/a-crazy-idea-regarding-the-obama-administration-and-security">A Crazy idea regarding the Obama administration and security</a> - If you&#8217;re abut change, lets make some that might have impact</li>
<li><a href="http://www.ft.com/cms/s/0/2931c542-ac35-11dd-bf71-000077b07658.html">Chinese hack into White House Network</a> - No wonder the WH staff can&#8217;t manage to keep any email for judges to review</li>
<li><a href="http://www.pcworld.com/article/153533/">Wanted:&nbsp; New Antispam tactics</a> - Aren&#8217;t the one&#8217;s we&#8217;re using working?</li>
<li><a href="http://news.bbc.co.uk/2/hi/technology/7719281.stm">Study shows how spammers cash in</a> - Making money on one fool in 12.5 million</li>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/11/i-can-haz-tcg-if-map-support-in-your-security-product-please.html">I can haz TCG IF-MAP support in your security product, please..</a>. - Where&#8217;s my secret acronym decoder ring when I need it?</li>
<li><a href="http://www.eff.org/deeplinks/2008/11/privacy-agenda">A privacy agenda for the new administration</a> - Hey, maybe the next Prez will be okay with me having some privacy</li>
<li><a href="http://blog.decurity.com/index.php/dec_template/more/dhs_blog_round_table/">DHS Blog Round table</a> - Rocky came up with some of the best<a href="http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/"> questions for DHS Secretary Chertoff</a>.</li>
<li><a href="http://ehsanakhgari.org/blog/2008-11-04/dont-leave-trace-private-browsing-firefox">Don&#8217;t leave a trace:&nbsp; Private browsing in Firefox&nbsp;</a></li>
<li><a href="http://techdulla.wordpress.com/2008/11/11/bonehead-moves/">Bonehead moves</a> - I&#8217;ve never done anything like this, honest.&nbsp; I&#8217;ll share my bonehead story later this week.</li>
<li><a href="http://www.andrewhay.ca/archives/418">The Security Chef&#8217;s &#8216;Better Bird Turkey&#8217;</a> - Ask a question on twitter and you get answers.&nbsp; Funny how that works.&nbsp; Grilled turkey for Thanksgiving!</li>
</ul>
<p>Is that enough?&nbsp; I think so. </p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F&amp;title=All+the+stuff+I+don%26%238217%3Bt+have+time+to+blog+about" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_scQfbukRkIAIMrGB14.2m6w4.iU_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/scQfbukRkIAIMrGB14.2m6w4.iU_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_scQfbukRkIAIMrGB14.2m6w4.iU_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=scQfbukRkIAIMrGB14.2m6w4.iU_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F11%2Fall-the-stuff-i-dont-have-time-to-blog-about%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=8nyiZm"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=8nyiZm" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/449619471" height="1" width="1"/>]]></content:encoded><description>We&amp;#8217;re all busy and the more stories I accumulate in my browser, the less time it seems I have to do anything with them.&amp;#160; So in order to clear out some of the open tabs, here&amp;#8217;s some of the stories I&amp;#8217;ve been reading lately:

Express Scritps warns of potential large data breach tied to threat - [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/11/all-the-stuff-i-dont-have-time-to-blog-about/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/11/all-the-stuff-i-dont-have-time-to-blog-about/</feedburner:origLink></item><item><title>What would you ask the Department of Homeland Security Secretary?</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/449055028/</link><category>Blogging</category><category>Government</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Mon, 10 Nov 2008 20:39:09 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Michael Chertoff, the Secretary of the Department of Homeland Security, will be here in California tomorrow.&nbsp; He&#8217;s hosting a blogger roundtable on Cybersecurity and I&#8217;m one of an unknown number of security bloggers who&#8217;ll be attending the event and talking to Mr. Chertoff face to face.&nbsp; Quite frankly I was surprised that the Department of Homeland Security was even aware of blogs, let alone willing to step out of Washington to talk to us in person.&nbsp; I probably shouldn&#8217;t be, since the <a href="http://www.tsa.gov/blog/">TSA has had a blog</a> for months now, even if I rarely agree with what they post there and never take it at face value.</p>
<p>Mr. Chertoff is on his way out due to the change in leadership our country is going through, but he&#8217;s held a highly political and thankless job for some time now.&nbsp; He has a unique view of the security of not only our nation, but every nation in the world.&nbsp; So what would you ask the man who&#8217;s been responsible for &#8216;homeland security&#8217;?&nbsp; What do you want to know about how we&#8217;re doing security at the highest levels?&nbsp; What burning questions about the TSA and your shoes are eating away at you?&nbsp; If it was you going to talk to Mr. Chertoff tomorrow, what&#8217;s the one question you&#8217;ld ask?</p>
<p>I have a number of my own questions, but I know that you can come up with even better.&nbsp; Leave a comment on this post with the question you&#8217;d ask.&nbsp; Keep it short and concise, make it topical to cybersecurity.&nbsp; I won&#8217;t be asking any &#8216;attack&#8217; questions, but I&#8217;m perfectly willing to ask some of the hard questions.&nbsp; Personally, I want to know what it&#8217;s like to be placed in charge of Homeland Security without any real power to affect change?&nbsp; Except that most security managers already know what that&#8217;s like.</p>
<p>We&#8217;re allowed to bring cameras and audio equipment, but no video.&nbsp; Most of my equipment is for close up interviews, but I&#8217;ll do the best I can with what I have.&nbsp; I&#8217;m just hoping the Secret Service doesn&#8217;t decide that some of my equipment isn&#8217;t acceptable.&nbsp; Or decide that I&#8217;m a security risk at the last minute.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F&amp;title=What+would+you+ask+the+Department+of+Homeland+Security+Secretary%3F" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_H7F.sRHy2p1jZ6Z0jxr-IVCKmxM_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/H7F.sRHy2p1jZ6Z0jxr-IVCKmxM_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_H7F.sRHy2p1jZ6Z0jxr-IVCKmxM_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=H7F.sRHy2p1jZ6Z0jxr-IVCKmxM_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fwhat-would-you-ask-the-department-of-homeland-security-secretary%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=VE3TFs"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=VE3TFs" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/449055028" height="1" width="1"/>]]></content:encoded><description>Michael Chertoff, the Secretary of the Department of Homeland Security, will be here in California tomorrow.&amp;#160; He&amp;#8217;s hosting a blogger roundtable on Cybersecurity and I&amp;#8217;m one of an unknown number of security bloggers who&amp;#8217;ll be attending the event and talking to Mr. Chertoff face to face.&amp;#160; Quite frankly I was surprised that the Department of [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/</feedburner:origLink></item><item><title>IT Horror Stories</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/448473631/</link><category>General</category><category>Humor</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Mon, 10 Nov 2008 08:56:41 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/10/it-horror-stories/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Congratulations to Jason, the winner of the free pass to CSI.&nbsp; Here&#8217;s his story about how a minor change to a script almost caused a major disaster.&nbsp; I have my own war story about scripts I&#8217;ll share later this week.&nbsp; Here&#8217;s a hint:&nbsp; Always make sure you&#8217;re in the proper directory when running your scripts.<br />
<blockquote>
<p>This happened when I was first learning to admin UNIX boxes. Another<br />
SysAdmin and I were working on a shell script to lowercase the file<br />
names of 30-40 million image files. They were on an NFS mount that was<br />
used by several servers. These images were part of detail listings of a<br />
relatively busy web site and we were right in the middle of the day. </p>
<p>Now that the background of the mess are fully explained, the story<br />
gets going. We went through several revisions and were testing against<br />
a directory on a desktop system. Nothing destructive happened during<br />
testing and we were getting fairly comfortable with the “safety” of the<br />
script. </p>
<p>We finally thought we had a working script, so we moved it to the<br />
prod server. Then we noticed a “minor” change that needed to be made on<br />
it. We made the change then decided that since this was a such a small,<br />
little tweak we could run it on the live NFS mount without any further<br />
testing. Fire in the hole!</p>
<p>The script took off and we watched it run. All was well. Then my<br />
phone rang from the NOC. A panicked operator was on the phone saying,<br />
“Hey what’s happening with listing images from xyz.com? They are all<br />
coming up as 404s!” I killed the script while thinking some thing like<br />
“oh crap, oh crap, oh crap!” Sure enough the script had wiped out about<br />
50% of the images. Amazing how fast a shell script can delete when it<br />
goes haywire. </p>
<p>We pointed the web servers to a backup copy of the images, then<br />
started to recover to the production mount. The backup was a couple<br />
days old, so our image processing guys had to re-upload the missing<br />
work. I was lucky that the online backup was there. I had taken it for<br />
reasons unrelated to this event. The next day I got to explain to the<br />
CIO what had happened.</p>
<p>The moral of the story was backup first and test your script until<br />
it is golden before going live. Then test it again and again and again.<br />
Make sure you are doing at the proper time, then go to production. We<br />
didn’t have change control, so I’d add get all the approvals now too.<br />
Cover your butt.</p>
<p>It was a good lesson.  I’ve never done anything like that again in the last 7 years.</p>
</blockquote>
<p></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F&amp;title=IT+Horror+Stories" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_gwl9fr1c0zC46IQy4FBuzKr80uo_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/gwl9fr1c0zC46IQy4FBuzKr80uo_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_gwl9fr1c0zC46IQy4FBuzKr80uo_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=gwl9fr1c0zC46IQy4FBuzKr80uo_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F10%2Fit-horror-stories%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=IcnJSs"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=IcnJSs" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/448473631" height="1" width="1"/>]]></content:encoded><description>Congratulations to Jason, the winner of the free pass to CSI.&amp;#160; Here&amp;#8217;s his story about how a minor change to a script almost caused a major disaster.&amp;#160; I have my own war story about scripts I&amp;#8217;ll share later this week.&amp;#160; Here&amp;#8217;s a hint:&amp;#160; Always make sure you&amp;#8217;re in the proper directory when running your scripts.

This [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/10/it-horror-stories/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/10/it-horror-stories/</feedburner:origLink></item><item><title>Nessus Beta plugin for PCI compliance</title><link>http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~3/444596794/</link><category>PCI</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">netsecpodcast@mckeay.net (Martin McKeay)</dc:creator><pubDate>Thu, 06 Nov 2008 11:40:03 -0600</pubDate><guid isPermaLink="false">http://www.mckeay.net/2008/11/06/nessus-beta-plugin-for-pci-compliance/</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>If you&#8217;re already using Nessus and you need an internal scanning engine for PCI compliance, then you need to be checking out the <a href="http://blog.tenablesecurity.com/2008/10/pci-dss-plugins.html">three new PCI-DSS plugins that the folks over at Tenable have created</a>.&nbsp; These are still beta and should not be treated as proof of compliance yet, but they&#8217;ll still give you a very good idea of what your current status is.&nbsp; They&#8217;re lookin for your feedback, so play with the plugins a little and let them know what you&#8217;re experience is like.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F&amp;title=Nessus+Beta+plugin+for+PCI+compliance" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>
<p><map name="google_ad_map_lgKcTJw7yNsIKocxVQt1lU33lFU_"><area shape="rect" href="http://imageads.googleadservices.com/pagead/imgclick/lgKcTJw7yNsIKocxVQt1lU33lFU_?pos=0" coords="1,2,367,28"/><area shape="rect" href="http://services.google.com/feedback/abg" coords="384,10,453,23"/></map><img usemap="#google_ad_map_lgKcTJw7yNsIKocxVQt1lU33lFU_" border="0" src="http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&client=ca-martin@mckeay.net&output=png&cuid=lgKcTJw7yNsIKocxVQt1lU33lFU_&url=http%3A%2F%2Fwww.mckeay.net%2F2008%2F11%2F06%2Fnessus-beta-plugin-for-pci-compliance%2F"/></p>
<p><a href="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?a=zT9tyt"><img src="http://feeds.feedburner.com/~a/MartinMckeaysNetworkSecurityBlog?i=zT9tyt" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/MartinMckeaysNetworkSecurityBlog/~4/444596794" height="1" width="1"/>]]></content:encoded><description>If you&amp;#8217;re already using Nessus and you need an internal scanning engine for PCI compliance, then you need to be checking out the three new PCI-DSS plugins that the folks over at Tenable have created.&amp;#160; These are still beta and should not be treated as proof of compliance yet, but they&amp;#8217;ll still give you a [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.mckeay.net/2008/11/06/nessus-beta-plugin-for-pci-compliance/feed/</wfw:commentRss><feedburner:origLink>http://www.mckeay.net/2008/11/06/nessus-beta-plugin-for-pci-compliance/</feedburner:origLink></item><media:credit role="author">Martin McKeay</media:credit><media:rating>nonadult</media:rating><media:description type="plain">Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.</media:description></channel></rss>
