<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title></title>
	<atom:link href="http://www.secsocial.com/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.secsocial.com/blog</link>
	<description></description>
	<lastBuildDate>Fri, 23 Jul 2010 20:41:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Security Summer-Camp &#8211; Part 1: The Talks</title>
		<link>http://www.secsocial.com/blog/?p=429</link>
		<comments>http://www.secsocial.com/blog/?p=429#comments</comments>
		<pubDate>Fri, 23 Jul 2010 20:31:16 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Black Hat / Defcon]]></category>
		<category><![CDATA[SecurityBSides]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[Security BSides]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=429</guid>
		<description><![CDATA[Planning on attending the mother-load of conferences next week in Las Vegas? Are you a first-timer, or generally have trouble planning where to go and what to do? Here is a good list for you, this will take you from Wednesday when Black Hat and Security BSides Las Vegas begin until Sunday of DefCon Closing [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.blackhat.com/html/bh-us-10"><img class="alignleft size-medium wp-image-433" title="blackhat_ger" src="http://www.secsocial.com/blog/wp-content/uploads/2010/07/blackhat_ger-300x105.jpg" alt="" width="300" height="105" /></a><a href="http://www.defcon.org/html/defcon-18"><img class="alignleft size-medium wp-image-432" title="dc-18-logo-wide" src="http://www.secsocial.com/blog/wp-content/uploads/2010/07/dc-18-logo-wide-300x110.png" alt="" width="300" height="110" /></a></p>
<p style="text-align: center;">
<p style="text-align: center;">
<p style="text-align: center;"><a href="http://www.securitybsides.com/BSidesLasVegas"><img class="size-medium wp-image-431 aligncenter" title="securitybsides_logo" src="http://www.secsocial.com/blog/wp-content/uploads/2010/07/securitybsides_logo-300x300.jpg" alt="" width="180" height="180" /></a></p>
<p><span style="color: #ffffff;"><em>Planning on attending the mother-load of conferences next week in Las Vegas? Are you a first-timer, or generally have trouble planning where to go and what to do? Here is a good list for you, this will take you from Wednesday when Black Hat and Security BSides Las Vegas begin until Sunday of DefCon Closing Ceremonies.</em></span></p>
<h2>SecBarbie’s talk picks of the week:</h2>
<h3><span style="color: #ff0000;"><a href="http://www.blackhat.com/html/bh-us-10"><img class="aligncenter" title="Black Hat 2010" src="http://www.securityuniversity.net/Assets/Images/Current_Images/events-blackhat-usa-2010.jpg" alt="" width="200" height="150" /></a>Black Hat</span></h3>
<p><strong><span style="color: #993300;">Wednesday 1:45pm &#8211; 3pm </span></strong></p>
<p><strong><em>Augustus 1 &amp; 2</em></strong></p>
<p><span style="color: #ffffff;">Barnaby Jack &#8211; Jackpotting Automated Teller Machines Redux!</span></p>
<p><strong><span style="color: #993300;">Wednesday 3:15pm &#8211; 4:30pm</span></strong></p>
<p><strong><em>Roman</em></strong></p>
<p><span style="color: #ffffff;">Dan Kaminsky &#8211; Black Ops Of Fundamental Defense: Web Edition</span></p>
<p><strong><span style="color: #993300;">Wednesday 4:45pm &#8211; 6pm </span></strong></p>
<p><strong><em>Augustus 5 &amp; 6</em></strong></p>
<p><span style="color: #ffffff;">Fyodor &#8211; Mastering the Nmap Scripting Engine</span></p>
<p><strong><em>Milano 5 &#8211; 8</em></strong></p>
<p><span style="color: #ffffff;">Alex Hutton / Allison Miller &#8211; Ushering in the Post-GRC World: Applied Threat Modeling</span></p>
<p><strong><span style="color: #993300;">Thursday 10am &#8211; 11am </span></strong></p>
<p><strong><em>Augustus 3 &amp; 4</em></strong></p>
<p><span style="color: #ffffff;">Chris Hoff &#8211; Cloudinomicon: Idepotent Infrastructure, Survivable Systems &amp; Bringing 				  Sexy Back to Information Centricity</span></p>
<p><strong><span style="color: #993300;">Thursday 11:15am &#8211; 12:30pm </span></strong></p>
<p><strong><em>Roman</em></strong></p>
<p><span style="color: #ffffff;">Cesar Cerrudo &#8211; Token Kidnapping’s Revenge</span></p>
<p><strong><em>Forum 25</em></strong></p>
<p><span style="color: #ffffff;">Lee Kushner, Mike Murray   -  Your Career = Your Business</span></p>
<p><strong><em>Milano 5 &#8211; 8</em></strong></p>
<p><span style="color: #ffffff;">Tiffany Rad	- The DMCA &amp; ACTA vs. Academic &amp; Professional Research: How Misuse 		  of this Intellectual Property Legislation Chills Research, Disclosure and 		  Innovation</span></p>
<p><strong><span style="color: #993300;">Thursday 3:15pm &#8211; 4:30pm </span></strong></p>
<p><strong><em>Milano 1 &#8211; 4</em></strong></p>
<p><span style="color: #ffffff;">Samy Kamkar	- How I met your girlfriend</span></p>
<p>Wednesday also has the <strong><em><span style="color: #ffffff;">Cloud Security Alliance Summit</span> </em></strong>with some pretty amazing, insightful, and wicked cool folks such as:</p>
<p>Chris Hoff	  &#8211;   Cloudersize Keynote</p>
<p>Josh Pennell   &#8211;   Hacking the Hypervisor 2010</p>
<p>Steve Riley	  &#8211;   Security and compliance in the Amazon cloud</p>
<p style="text-align: center;"><a href="http://www.securitybsides.com/BSidesLasVegas"><img class="size-medium wp-image-431 aligncenter" title="securitybsides_logo" src="http://www.secsocial.com/blog/wp-content/uploads/2010/07/securitybsides_logo-300x300.jpg" alt="" width="180" height="180" /></a></p>
<p><strong><span style="color: #00ff00;">Security BSides &#8211; Las Vegas 2010</span></strong></p>
<p>I can’t even begin to pick the Security BSides talks (special mention to the InfoSec Mentor Panel that I’ll be on Wednesday at 6pm) as I would whole-heartedly endorse all of them. Bravo to the talk selection guys! So, here is the BSides Schedule:</p>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top"></td>
<td valign="top"><strong>TRACK 1</strong></p>
<p><strong>On The Keys</strong></td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"><strong>TRACK 2</strong></p>
<p><strong>AFK</strong></td>
<td valign="top"></td>
</tr>
<tr>
<td valign="top"><strong>7/28/2010</strong></td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"><strong> </strong></td>
<td valign="top"></td>
</tr>
<tr>
<td valign="top">10:00 AM</td>
<td valign="top"><strong>David Rook</strong></td>
<td valign="top"><a href="http://www.securityninja.co.uk/more-information-about-my-securitybsides-presentation">Injecting Simplicity not SQL</a></td>
<td valign="top"></td>
<td valign="top"><strong>Daniel Molina </strong></td>
<td valign="top">Top 10 Things IT is Doing to Enable CyberCrime</td>
</tr>
<tr>
<td valign="top">11:00 AM</td>
<td valign="top"><strong>Ryan Linn </strong></td>
<td valign="top">Multi-Player MetaSploit</td>
<td valign="top"></td>
<td valign="top"><strong>Will Gragido </strong></td>
<td valign="top">Through the rabbit hole: An Expose of Darknets and the Onion Routed Underground</td>
</tr>
<tr>
<td valign="top">12:00 PM</td>
<td valign="top"><strong>Christopher E. Pogue </strong></td>
<td valign="top">Sniper Forensics</td>
<td valign="top"></td>
<td valign="top"><strong>Gene Kim </strong></td>
<td valign="top">Mobilizing the PCI Resistance: Lessons Learned From Fighting Prior Wars (SOX-404)</td>
</tr>
<tr>
<td valign="top">01:00 PM</td>
<td valign="top"><strong>Chris Lytle,</strong></p>
<p><strong>Leigh Hollowell </strong></td>
<td valign="top">CCDC</td>
<td valign="top"></td>
<td valign="top"><strong>Andrew Hay,</strong></p>
<p><strong>Chris Nickerson </strong></td>
<td valign="top">Building Bridges -  Forcing Hackers and Business to Hug it Out</td>
</tr>
<tr>
<td valign="top">02:00 PM</td>
<td valign="top"><strong>Sean-Paul Correll,</strong></p>
<p><strong>Luis Corrons </strong></td>
<td valign="top">Catch That Butterfly: Stopping Mariposa in its Tracks and Revealing a Growing Underground Network of Amateur Hackers</td>
<td valign="top"></td>
<td valign="top"><strong>Vik Phatak</strong></td>
<td valign="top">ExploitHub: Arming the Pen Testers to Plug the Holes</td>
</tr>
<tr>
<td valign="top">03:00 PM</td>
<td valign="top"><strong>Dave Kennedy (Rel1K)</strong></td>
<td valign="top">SET 0.6 release with special PHUKD Key</td>
<td valign="top"></td>
<td valign="top"><strong>Paul Judge, David Maynor </strong></td>
<td valign="top">The Dark side of Twitter, Measuring and Analyzing Malicious Activity on Twitter</td>
</tr>
<tr>
<td valign="top">04:00 PM</td>
<td valign="top"><strong>frank^2</strong></td>
<td valign="top">Fuck Tools, Do It yourself Jerk</td>
<td valign="top"></td>
<td valign="top"><strong>Grecs</strong></td>
<td valign="top">Infosec Communities for Career Success: Understanding, Participating, and Cooking One Up</td>
</tr>
<tr>
<td valign="top">05:00 PM</td>
<td valign="top"><strong>Jabra</strong></td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"><strong>Joseph Sokoly</strong></td>
<td valign="top">Infosec Young and Restless</td>
</tr>
<tr>
<td valign="top">06:00 PM</td>
<td valign="top"><strong> Jim MacLeod</strong></td>
<td valign="top">Stupid IP Tables Tricks</td>
<td valign="top"></td>
<td valign="top"><strong>INFOSEC Mentoring, Mentee-ing Panel</strong></td>
<td valign="top"></td>
</tr>
<tr>
<td valign="top">7/29/2010</td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"></td>
<td valign="top"></td>
</tr>
<tr>
<td valign="top">10:00 AM</td>
<td valign="top"><strong>Jimmy Shah </strong></td>
<td valign="top">Mobile Hackery</td>
<td valign="top"></td>
<td valign="top"><strong>Josh Corman, Dennis Fisher, HD Moore, Jack Daniel</strong></td>
<td valign="top">InfoSec Speed Debates</td>
</tr>
<tr>
<td valign="top">11:00 AM</td>
<td valign="top"><strong>Egyp7 </strong></td>
<td valign="top">Beyond r57</td>
<td valign="top"></td>
<td valign="top"><strong>Chris Sumner </strong></td>
<td valign="top">Social Network Special Ops</td>
</tr>
<tr>
<td valign="top">12:00 PM</td>
<td valign="top"><strong>HDM</strong></td>
<td valign="top">Fun with VxWorks</td>
<td valign="top"></td>
<td valign="top"><strong>Frank Breedijk, Ian Southam</strong></td>
<td valign="top">The road to hell is paved with best practices</td>
</tr>
<tr>
<td valign="top">01:00 PM</td>
<td valign="top"><strong>Davi Ottenheimer </strong></td>
<td valign="top">Keypad Bypass Hacks</td>
<td valign="top"></td>
<td valign="top"><strong>Bruce Potter </strong></td>
<td valign="top">How to Make Network Diagrams that Don&#8217;t Suck</td>
</tr>
<tr>
<td valign="top">02:00 PM</td>
<td valign="top"><strong>Zach Lanier</strong></td>
<td valign="top">It Melts In Your Hand: An Overview of Security (Failures) In Mobile Applications</td>
<td valign="top"></td>
<td valign="top"><strong>Eric Smith</strong></td>
<td valign="top">Roman Profiles : The 6 Mistakes of</td>
</tr>
<tr>
<td valign="top">03:00 PM</td>
<td valign="top"><strong>Ray Kelly </strong></td>
<td valign="top">A mechanics view of SQL injection</td>
<td valign="top"></td>
<td valign="top"><strong>ValSmith</strong></td>
<td valign="top">Social Engineering the CFP Process</td>
</tr>
<tr>
<td valign="top">04:00 PM</td>
<td valign="top"><strong>Moxie Marlinspike</strong></td>
<td valign="top">How technology killed my heroes, and why they will never be born again</td>
<td valign="top"></td>
<td valign="top"><strong>Chris Roberts</strong></td>
<td valign="top">Planes, Trains and Automobiles: (OK, Cars and Buses)</td>
</tr>
<tr>
<td valign="top">05:00 PM</td>
<td valign="top"><strong>Jason Ross </strong></td>
<td valign="top">Who Owns the Internet? AKA: Where did all that cyberspace go?</td>
<td valign="top"></td>
<td valign="top"><strong>Andre Gironda </strong></td>
<td valign="top">App Assessments Reloaded</td>
</tr>
</tbody>
</table>
<p style="text-align: center;"><a href="http://www.defcon.org/html/defcon-18/dc-18-schedule.html"><img class="aligncenter size-medium wp-image-432" title="dc-18-logo-wide" src="http://www.secsocial.com/blog/wp-content/uploads/2010/07/dc-18-logo-wide-300x110.png" alt="" width="300" height="110" /></a></p>
<h2><span style="color: #0000ff;">DefCon 18</span></h2>
<p><strong><span style="color: #3366ff;">Friday 1pm &#8211; 2pm </span></strong></p>
<p><strong>Track 4</strong></p>
<p>Dennis Brown	- How Hackers Won the Zombie Apocalypse</p>
<p><strong><span style="color: #3366ff;">Friday 2pm &#8211; 3pm </span></strong></p>
<p><strong>Track 3</strong></p>
<p>Jim Rennie, Eric Rachner	- Search &amp; Seizure &amp; Golfballs</p>
<p><strong><span style="color: #3366ff;">Friday 3pm &#8211; 3:30pm </span></strong></p>
<p><strong>Track 5</strong></p>
<p>Righter Kunkel 	- Air Traffic Control Insecurity 2.0</p>
<p><strong> </strong></p>
<p><strong><span style="color: #3366ff;">Friday 4pm &#8211; 5pm </span></strong></p>
<p><strong>Track 4</strong></p>
<p>Tottenkoph	- An Introduction to Virtual Graffiti</p>
<p><strong><span style="color: #3366ff;">Friday 5pm &#8211; 6pm </span></strong></p>
<p><strong>Track 2</strong></p>
<p>Sumit Siddharth	- Hacking Oracle from Web Apps</p>
<p><strong><span style="color: #3366ff;">Friday 6pm &#8211; 6:20pm </span></strong></p>
<p><strong>Track 5</strong></p>
<p>Marisa Fagan	- Be A MENTOR!</p>
<p><strong><span style="color: #3366ff;">Friday 9pm &#8211; ???pm </span></strong></p>
<p><strong>Track 1</strong></p>
<p>Hacker Jeopardy!!!!!!!      &#8211; Bring Booze!</p>
<p><strong><span style="color: #3366ff;">Saturday 10am &#8211; 11am</span></strong></p>
<p><strong>Track 2</strong></p>
<p>Jeremy Brown 	- Exploiting SCADA Systems</p>
<p><strong><span style="color: #3366ff;">Saturday 10am &#8211; 11am</span></strong></p>
<p><strong>Track 4</strong></p>
<p>Chris Paget 	- Extreme-range RFID Tracking</p>
<p><strong><span style="color: #3366ff;">Saturday 11am &#8211; 12pm</span></strong></p>
<p><strong>Track 4</strong></p>
<p>Barnaby Jack &#8211; Jackpotting Automated Teller Machines Redux!</p>
<p><strong><span style="color: #3366ff;">Saturday 12pm &#8211; 1pm</span></strong></p>
<p><strong>Track 1</strong></p>
<p>Nicholas Percoco, Christian Papathanasiou &#8211; “This is not the Droid you’re looking for..”</p>
<p><strong><span style="color: #3366ff;">Saturday 1pm &#8211; 2pm</span></strong></p>
<p><strong>Track 1</strong></p>
<p>frank^2		- Trolling Reverse-Engineers with Math: Ness&#8230;. It Hurts&#8230;</p>
<p><strong><span style="color: #3366ff;">Saturday 3pm &#8211; 4pm</span></strong></p>
<p><strong>Track 2</strong></p>
<p>James Arlen		- SCADA and ICS for Security Experts: How to avoid Cyberduchery</p>
<p><strong><span style="color: #3366ff;">Saturday 3pm &#8211; 4pm</span></strong></p>
<p><strong>Track 5</strong></p>
<p>Garry Pejski		- My Life as a Spyware Developer</p>
<p><strong> </strong></p>
<p><strong><span style="color: #3366ff;">Saturday 4pm &#8211; 5pm</span></strong></p>
<p><strong>Track 4</strong></p>
<p>Jayson Street	- Deceiving the Heavens to Cross the Sea: Using the 26 			stratagems for Social Engineering</p>
<p><strong> </strong></p>
<p><strong><span style="color: #3366ff;">Saturday 5pm &#8211; 6pm</span></strong></p>
<p><strong>Track 4</strong></p>
<p>Leigh Honeywell, follower	- Physical Computing, Virtual Security: Adding the Arduino 				Microcontroller Development Environment to your security 				toolbox</p>
<p><strong><span style="color: #3366ff;">Saturday 7pm &#8211; 9pm</span></strong></p>
<p><strong>Track 5</strong></p>
<p>DefCon Security Jam III: Now in 3D?</p>
<p><strong><span style="color: #3366ff;">Saturday 10pm &#8211; ??pm</span></strong></p>
<p><strong>Track 4</strong></p>
<p>10,000 Cent Pyramid</p>
<p><strong><span style="color: #3366ff;">Sunday 10am &#8211; 11am</span></strong></p>
<p><strong>Track 4</strong></p>
<p>Mike Bailey		- Web Services we just don’t need</p>
<p><strong><span style="color: #3366ff;">Sunday 11am -  12pm</span></strong></p>
<p><strong>Track 2</strong></p>
<p>Valsmith, Colin Ames, Anthony Lai 	- Balancing the Pwn Trade Deficit</p>
<p><strong><span style="color: #3366ff;">Sunday 1pm -  2pm</span></strong></p>
<p><strong>Track 5</strong></p>
<p>mc.fly, rvd, vyrus, no maam	- ChaosVPN for Playing CTFs</p>
<p><strong><span style="color: #3366ff;">Sunday 2pm -  3pm</span></strong></p>
<p><strong>Track 3</strong></p>
<p>David Smith, Samuel Petreski	- A new approach to forensic methodology 					- !!BUSTED!! Case Studies</p>
<p><strong><span style="color: #3366ff;">Sunday 4pm -  5pm</span></strong></p>
<p><strong>Track 1</strong></p>
<p>The Suggmeister			- Social Networking Special Ops: Extending Data 					Visualization Tools for Faster Pwnage</p>
<p><strong> </strong></p>
<p><strong><span style="color: #3366ff;">Sunday 5pm -  6pm</span></strong></p>
<p><strong>Track 1</strong></p>
<p>Justin Morehouse, Tony Flick	- Getting Social with the Smart Grid</p>
<p><strong><span style="color: #3366ff;">Sunday 6pm </span></strong></p>
<p><strong>CLOSING CEREMONIES!!!!! </strong></p>
<p><span style="color: #993300;"><em><strong>Please reclaim all lost livers here!</strong></em></span></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p>If you are NOT going to be in the melt-your-face-off land of Las Vegas next week, you can follow all of the action and some of the parties via my live-conference feed on twitter <a href="http://www.twitter.com/iobarbie">@IOBarbie</a> !</p>
<p style="text-align: center;"><a href="http://www.twitter.com/IOBarbie"><img class="aligncenter size-medium wp-image-441" title="IOBarbie" src="http://www.secsocial.com/blog/wp-content/uploads/2010/07/IOBarbie-300x291.jpg" alt="" width="180" height="175" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=429</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inside the heart of a QSA</title>
		<link>http://www.secsocial.com/blog/?p=417</link>
		<comments>http://www.secsocial.com/blog/?p=417#comments</comments>
		<pubDate>Thu, 27 May 2010 16:14:00 +0000</pubDate>
		<dc:creator>diami03</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[QSA]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=417</guid>
		<description><![CDATA[What a special day, I am happy to share a guest-blog from one of my favorite assessor&#8217;s and dear friend Michelle Klinger (@Diami03 on Twitter). She has agreed to add content on Security Sociability from her perspective as a PCI-DSS QSA and information security professional. -SecBarbie Inside the heart of a QSA by @Diami03 One [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #800000;">What a special day, I am happy to share a guest-blog from one of my favorite assessor&#8217;s and dear friend Michelle Klinger (@Diami03 on Twitter). She has agreed to add content on Security Sociability from her perspective as a PCI-DSS QSA and information security professional.</span></em></p>
<p><em><span style="color: #800000;">-SecBarbie</span></em></p>
<h2>Inside the heart of a QSA</h2>
<h3>by @Diami03</h3>
<p><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/05/PCI-Heart-Logo.gif"><img class="alignright size-thumbnail wp-image-425" title="PCI-Heart-Logo" src="http://www.secsocial.com/blog/wp-content/uploads/2010/05/PCI-Heart-Logo-150x150.gif" alt="" width="150" height="150" /></a>One of my true passions as an assessor is when clients actually thank me at the end of an engagement for identifying their weaknesses and then the periodic communications thereafter when they seek my security know-how as they evaluate new initiatives.</p>
<p>For those who do not know who I am, I am a disillusioned, frustrated, confused security professional. Oh, so we have met?! What’s making me feel hopeless, you ask? I must have forgotten to mention I’m a security professional that is also a QSA. Makes sense now, doesn’t it?</p>
<p>I’ve been recently feeling a crisis of info sec faith.  For those of you who follow me on Twitter (@diami03), you may have noticed my ire at performing PCI assessments on the rise.  To get some perspective, understand I am a security assessor by heart.  I enjoy meeting clients who are truly interested in securing their environment, helping them identify security gaps, and then brainstorming about remediation solutions.  I had been performing security assessments for the past 5 years using various security industry standards for guidance, my favorite being ISO27002. In those 5 years, the rates of compliance based assessments, most notably PCI, were on the rise but I was able to satisfy my information security fix with those clients who just wanted to understand their environment and to secure it.</p>
<p>Sadly, those days are long gone. Now I’m left with a checklist and a list of clients a mile long who are waiting in line to be branded as PCI compliant.  Gone are the clients whose sole concern was for all of the information they housed. No longer am I able to assist clients understand their environment and help steer them down the path of information security righteousness.  No, those days are long gone. Now I’m told to mind my business.  If I make a security recommendation based on an observation, and I am unable to point to a PCI requirement mandating it, then I’ve committed an act of blasphemy.</p>
<p>Fine, with all that said, what’s my point? I’m not really sure I have one, other than to exorcise these feelings of impotence and publicly restate my commitment to security and not just a checklist babe.  I also thought I might shed some light on the internal battle some QSAs are feeling which you might not be aware of.   Although many of you have a negative view of QSA assessors, which I blame the PCI QSA process for, understand that there are a few of us silently screaming but unable to be heard. This is my silent cry!</p>
<p>I get it, not everyone is happy in their jobs.  As was made clear in the 2009 Dark Reading article, “<a href="http://www.darkreading.com/security/management/showArticle.jhtml?articleID=218600434">One in Two Security Pros Unhappy in Their Job</a>” we are not all 100% satisfied in our current positions, and “that IT security pros feel they could be doing more.”  For now I’ll continue doing PCI assessments because, quite frankly, I like the idea of being able to pay my mortgage every month. I would like to make one thing clear however, that I do not plan on just sitting back and letting the problems fester, but am attempting to raise awareness by giving talks, writing blog posts, and sharing my frustrations and suggestions for change with the industry.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=417</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Is your social media message in-tune?</title>
		<link>http://www.secsocial.com/blog/?p=400</link>
		<comments>http://www.secsocial.com/blog/?p=400#comments</comments>
		<pubDate>Wed, 10 Mar 2010 14:41:18 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Branding]]></category>
		<category><![CDATA[Mike Murray]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=400</guid>
		<description><![CDATA[After attending the talk given by Mike Murray at RSA Conference in San Francisco last week on “Tweeting for Dollars: UsingSocial Media to Enhance your Career in Security” I found myself even more intrigued by some people’s message in the social media spectrum. One of the major points that Mike made during his talk was [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-401 alignleft" title="TweetDollar" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/images-1.jpeg" alt="" width="91" height="103" /></p>
<p>After attending the talk given by <a href="http://twitter.com/mmurray">Mike Murray</a> at RSA Conference in San Francisco last week on “Tweeting for Dollars: UsingSocial Media to Enhance your Career in Security” I found myself even more intrigued by some people’s message in the social media spectrum. One of the major points that Mike made during his talk was that not only do organizations need to have a social media strategy, but each person who is engaging in social media should think about theirs as well. Regardless of any intent, each person in social media has a brand. It is our responsibility to ensure that this brand is reflective of what we desire it to be. Some brands are easier to spot then others, but what is your brand saying about you?</p>
<p>The best question that someone asked in the presentation was that of a gentleman ‘screwing up’ his twitter account. By his definition of screwing up, it meant that he wasn’t focused on tweeting about his career only, he was tweeting about everything and talking to people. This wasn’t a screw up at all, this gentleman was having a conversation, he was doing social media right! The humanity of social media is what makes it so attractive to readers. People have been using the internet for years to read press releases, and some even use RSS feeds on a daily basis to keep up on those news articles. They don’t need Twitter or Facebook to keep up on that, Social Media let’s us all know that every celebrity, industry pundit, and random people you met at a convention all have something else going on outside of their career, or hobby that they are known for.</p>
<p><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/branding_iron.jpg"><img class="size-thumbnail wp-image-402 alignright" title="branding_iron" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/branding_iron-150x150.jpg" alt="" width="120" height="120" /></a>As an organization, it is also very important to decide on how the corporate brand is going to be reflected by the employees. Compose a social media policy stating if employees are allowed to share corporate information, or if that is going to be left only to be executed by the corporate social media accounts and team. If employees are allowed to share certain corporate data, it is very important to identify and classify what information is never to be shared in the social media space. The organization is also responsible to educate the employees of these policies to ensure a clear, unified message.</p>
<p><img class="alignleft" title="Retweet" src="http://scoopdog.files.wordpress.com/2009/11/tweet-retweet.jpg" alt="" width="113" height="76" />So how would a person or an organization drive their brand while engaging their audience? Have a conversation! Read whatyour followers are doing, and engage them. Sure, throw out important information that is self-serving as well (ie. Blog Post announcement, PR release links, etc.), but also retweet and share other contributors information. Know who you audience is, and get to know them!</p>
<p style="text-align: center;">Sharing is caring!</p>
<p style="text-align: center;"><img class="aligncenter" title="Share Bear" src="http://i-love-cartoons.com/snags/clipart/Care-Bears/Care-Bear-Share.jpg" alt="" width="134" height="164" /></p>
<p style="text-align: center;">
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=400</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecurityBSidesSF: Evolution, not just education!</title>
		<link>http://www.secsocial.com/blog/?p=359</link>
		<comments>http://www.secsocial.com/blog/?p=359#comments</comments>
		<pubDate>Wed, 10 Mar 2010 03:40:49 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[SecurityBSides]]></category>
		<category><![CDATA[Sociability]]></category>
		<category><![CDATA[Women in Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Andrew Hay]]></category>
		<category><![CDATA[Jack Daniels]]></category>
		<category><![CDATA[Parisoma]]></category>
		<category><![CDATA[SecurityBSidesSF]]></category>
		<category><![CDATA[Vendors]]></category>
		<category><![CDATA[Vissago]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=359</guid>
		<description><![CDATA[SecurityBSides in San Francisco on March 2nd and 3rd held at Parisoma was an experience that those in attendance will not soon forget. This is not for the reasons of Andrew Hay&#8217;s opening slide with his pink dress, but for a community of security professionals sharing and collaborating in a fresh new way from the vendor is [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-medium wp-image-360 alignright" title="Andrew in Dress" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.08.24-PM-300x225.png" alt="" width="240" height="180" /></p>
<p><a href="http://www.securitybsides.com/">SecurityBSides in San Francisco</a> on March 2nd and 3rd held at <a href="http://www.parisoma.com/">Parisoma</a> was an experience that those in attendance will not soon forget. This is not for the reasons of <a href="http://www.andrewhay.ca/" target="_blank">Andrew Hay&#8217;s</a> opening slide with his pink dress, but for a community of security professionals sharing and collaborating in a fresh new way from the vendor is king conference that was across town. What makes this conference so very different is the interaction at a granular level that the attendees can have with the speakers and sponsors. Not only are the actual talks much more interactive, but the sponsors who are in attendance can actually interface with the attendees and understand their needs as well as have the opportunity to convey their message in a conversation, not an expo-floor 5 minute pitch.</p>
<p>Some of the talks that were covered over the 2 days of the event are listed <a href="http://www.securitybsides.com/BSidesSanFrancisco" target="_blank">here</a>.</p>
<p>Media coverage of SecurityBSides <a href="http://www.securitybsides.com/Media">here</a>.</p>
<p><em>Thank you to the vendors &amp; volunteers that made this event possible!</em></p>
<h3>Upcoming SecurityBSides Events:</h3>
<p>March 13, 2010 - <a href="http://www.securitybsides.com/BSidesAustin">BSidesAustin &#8211; &#8220;Keep Security Weird&#8221;</a> &#8211; Coinciding with <a href="http://sxsw.com/interactive" target="_blank">SxSW Interactive</a></p>
<p><a href="http://sxsw.com/interactive" target="_blank"></a>April 24-25, 2010 - <a href="http://www.securitybsides.com/BSidesBoston">BSidesBoston</a> &#8211; weekend after <a href="http://www.sourceconference.com/index.php/source-boston-2009">SOURCE Boston</a>.</p>
<p>July 29-30, 2010 - <a href="http://www.securitybsides.com/BSidesLasVegas">BSidesLasVegas</a> &#8211; coinciding with Black Hat / Defcon</p>
<p>Here are some highlights from SecurityBSides San Francisco acquired using the ancient art of screen capture from the Flickr streams of <a href="http://www.flickr.com/photos/jack_daniel/sets/72157623420979405/">Jack Daniel</a> and <a href="http://www.flickr.com/photos/vissago/sets/72157623548516772/">Vissago</a>.</p>
<h3><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.09.42-PM.png"><img class="alignleft size-medium wp-image-371" title="Security Women &lt;3 each other" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.09.42-PM-300x192.png" alt="" width="180" height="115" /></a><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.14.00-PM.png"></a></h3>
<p><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.14.00-PM.png"><img class="alignleft size-medium wp-image-377" title="SDLC Marisa" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.14.00-PM-273x300.png" alt="" width="164" height="180" /></a></p>
<p><img class="size-thumbnail wp-image-380 alignleft" title="BSidesCrew" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.16.25-PM-150x150.png" alt="" width="150" height="150" /><span style="font-weight: normal; font-size: 13px;"><img class="size-thumbnail wp-image-379 alignleft" title="PCI Panel" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.14.58-PM-150x150.png" alt="" width="150" height="150" /></span></p>
<h3><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.16.42-PM.png"><img class="alignleft size-medium wp-image-381" title="ST JJ and EJ" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.16.42-PM-286x300.png" alt="" width="229" height="240" /></a><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.11.37-PM.png"><img class="alignnone size-medium wp-image-375" title="GenderPanel" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.11.37-PM-300x195.png" alt="" width="300" height="195" /></a> <a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.10.12-PM.png"><img class="size-thumbnail wp-image-372 alignleft" title="FrankBSides" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.10.12-PM-150x150.png" alt="" width="150" height="150" /></a><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.12.16-PM.png"><img class="size-medium wp-image-376 alignleft" title="HDMoore" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.12.16-PM-300x283.png" alt="" width="300" height="283" /></a></h3>
<p><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.10.39-PM.png"><img class="size-medium wp-image-373 alignleft" title="Stacy" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.10.39-PM-189x300.png" alt="" width="189" height="300" /></a></p>
<h3><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.16.56-PM.png"><img class="size-medium wp-image-382 alignleft" title="Taco Truck" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.16.56-PM-300x231.png" alt="" width="300" height="231" /></a></h3>
<h3><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.17.46-PM.png"><img class="alignleft size-medium wp-image-383" title="JackD" src="http://www.secsocial.com/blog/wp-content/uploads/2010/03/Screen-shot-2010-03-09-at-9.17.46-PM-204x300.png" alt="" width="204" height="300" /></a></h3>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=359</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My ode to Rapid7</title>
		<link>http://www.secsocial.com/blog/?p=336</link>
		<comments>http://www.secsocial.com/blog/?p=336#comments</comments>
		<pubDate>Wed, 17 Feb 2010 20:30:23 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Sociability]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[FAILBarbie]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=336</guid>
		<description><![CDATA[&#60;Fade IN:&#62; A few weeks back, I was sitting in my office in the middle of a meeting with one of my Directors and my phone rings. It came through as one of our trunk lines, so I knew it was a transfer form the receptionist, I was in a good mood, so I answered [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.rapid7.com"><img class="aligncenter size-medium wp-image-337" title="rapid7" src="http://www.secsocial.com/blog/wp-content/uploads/2010/02/rapid7-300x38.jpg" alt="" width="300" height="38" /></a></p>
<p><strong>&lt;Fade IN:&gt;</strong></p>
<p><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/02/large_better-off-ted-upfront.jpg"><img class="alignleft size-medium wp-image-338" title="large_better-off-ted-upfront" src="http://www.secsocial.com/blog/wp-content/uploads/2010/02/large_better-off-ted-upfront-300x198.jpg" alt="" width="300" height="198" /></a>A few weeks back, I was sitting in my office in the middle of a meeting with one of my Directors and my phone rings. It came through as one of our trunk lines, so I knew it was a transfer form the receptionist, I was in a good mood, so I answered it. Low and behold it was my first call from a Rapid7 Sales representative (First that I actually answered that is). Knowing that Rapid7 recently acquired Metasploit, I gave the gentleman a listen. He talked up the RSA party, HD Moore, and the products that Rapid7 is currently marketing compared to some of the competitors. All in all, it was a perfectly fine conversation and I did walk away with some value add. My only critique was that it was pretty long, and I’m pretty busy to spend that much time talking about a product that we aren’t yet seeking a new vendor for.</p>
<p><strong>&lt;Announcers Voice:&gt; Later the same day</strong></p>
<p>I receive another call from a Rapid7 sales representative who had no idea that I had just spoken with a gentleman earlier! I might have been a little curt on the phone, but please refer back to the fact that I am actually extremely busy, and had already invested 40 minutes on the phone with the previous representative.</p>
<p>Later the same day I asked my twitterverse for information about Rapid7 products, because I trust my colleagues who have used them more then I could EVER trust a demo. Thanks to the great social community of Security Twits I gathered a great deal of information. Additionally, I learned from someone close to internal Rapid7 that Rapid7 follows all the <a href="http://search.twitter.com/search?q=rapid7">Rapid7 mentions on twitter.</a>.. what fun would a day be without throwing a #Rapid7 after some tweets?</p>
<p><strong>&lt;evil-grin&gt;</strong></p>
<p>In all seriousness, Rapid7 is doing some very positive things for the industry in regards to sponsorship of the <a href="http://twitter.com/securitytwits/people">SecurityTwits</a> event at <a href="http://www.sourceconference.com">SourceBoston</a>, employing some <a href="http://www.linkedin.com/companies/rapid7">AMAZING researchers</a>, and advancing the <a href="http://www.metasploit.com">MetaSploit project</a> with commercial funding!</p>
<p>Rapid7, please work on a sales team lesson in positive versus negative social media networking. Here are my examples of Rapid7 Negative Social Media Marketing:</p>
<p><strong><span style="color: #ffff00;">LinkedIN</span></strong></p>
<ul>
<li>Requests to professionals who they have never met or never worked with:</li>
</ul>
<blockquote><p>TwitterNames Ommited: “ Anybody know what&#8217;s the bright idea with <strong>Rapid7</strong>&#8216;s sales team suddenly trying to join people&#8217;s networks on linkedin??”</p>
<p>“ Ok <a href="http://twitter.com/Rapid7">@<strong>Rapid7</strong></a>, your salespeople’s newfound relentless addition of my linkedin have grown irritating &amp; bothersome. Please DIAF.&lt;- Ah :&#8221;</p></blockquote>
<ul>
<li>The February 16th slew of LinkedIN Spam from &#8220;Business Developers&#8221; that most of my colleagues received. Not cool!</li>
</ul>
<p><strong><span style="color: #ffff00;">Twitter</span></strong><span style="color: #ffff00;">:</span></p>
<ul>
<li>Rapid7 twitter feed is just a Press Release reel, there is no interaction with the community, same can be said for the Facebook page!</li>
</ul>
<h3>Notable mention:</h3>
<p>Having the “JR” account reps monitor twitter for Rapid7 mentions &#8212; Boiler Room meets Rapid7!</p>
<p style="text-align: center;"><img class="size-medium wp-image-339 aligncenter" title="boiler-room" src="http://www.secsocial.com/blog/wp-content/uploads/2010/02/boiler-room-300x190.jpg" alt="" width="300" height="190" /></p>
<h1 style="text-align: center;"><span style="color: #ffffff;">+</span></h1>
<p><span style="color: #ffffff;"><br />
</span></p>
<p style="text-align: center;"><img class="size-medium wp-image-340    aligncenter" title="6820_144976844616_144972014616_2292573_7155267_n" src="http://www.secsocial.com/blog/wp-content/uploads/2010/02/6820_144976844616_144972014616_2292573_7155267_n-300x199.jpg" alt="" width="300" height="199" /></p>
<p><span style="font-size: xx-large;"><strong><br />
</strong></span></p>
<h3>The RSA Party!</h3>
<p>I’m sure everyone is thrilled that Rapid7 is hosting a party at RSA. But again, this is another marketing fail. They might not want to use the acronym “VIP” as it generally doesn’t mean invite everyone in the world, post it on twitter, then brag about having 1,000+ people at the party.</p>
<p>In case you didn’t RSVP&#8230; you can do so here <a href="http://www.rapid7.com/forms/rsarsvp.jsp">http://www.rapid7.com/forms/rsarsvp.jsp</a></p>
<p>Come on Rapid7, you can do better then this!</p>
<p>I’m sure you are a great organization, it sure looks as if your employees have fun working there, but I have to say that Rapid7 Sales and Marketing gets the *first ever* Official SecBarbie FAILBarbie award of the month for doing bad all by themselves!</p>
<p><a href="http://www.secsocial.com/blog/wp-content/uploads/2010/02/images.jpeg"><img class="aligncenter size-full wp-image-347" title="images" src="http://www.secsocial.com/blog/wp-content/uploads/2010/02/images.jpeg" alt="" width="129" height="97" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=336</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Security B-Sides San Francisco &#8211; Preview</title>
		<link>http://www.secsocial.com/blog/?p=312</link>
		<comments>http://www.secsocial.com/blog/?p=312#comments</comments>
		<pubDate>Thu, 11 Feb 2010 17:19:16 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Women in Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Gender]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[SecurityBSides]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=312</guid>
		<description><![CDATA[If you have been living under a rock somewhere and somehow haven&#8217;t heard about this revolution known as SecurityBsides, well, perk up folks! With SecurityBSides San Francisco being the second large-scale un-conferences that compliments a large corporate conference, the proposed talks are already shaping up to be something so very special to our industry! This [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="-webkit-user-select: none;" src="http://api.ning.com/files/cXEGRcSFMjLhm7ydtCGLPzVMESPp1fmYMcvTWYbMMZAik*N1fpOCnVmAvYU0vhe8lnN97i1Dpr3Y8j*bBYeuPs*okTRW-Z1Z/bsides_logo_onwhite.jpg" alt="" width="180" height="180" /></p>
<p>If you have been living under a rock somewhere and somehow haven&#8217;t heard about this revolution known as <a href="http://www.securitybsides.com" target="_blank">SecurityBsides</a>, well, perk up folks! With SecurityBSides San Francisco being the second large-scale un-conferences that compliments a large corporate conference, the proposed talks are already shaping up to be something so very special to our industry! This is an un-conference that is completely powered by the people, so if you haven&#8217;t yet <a href="http://www.securitybsides.com/BSidesSanFranciscoTalks" target="_blank">voted for the talks</a> that you would like to hear, do it or don&#8217;t complain!</p>
<p>Here is my short-list of talks that I think are going to be wonderful</p>
<blockquote><address><span style="color: #ffff99;">*Some are not yet picked to present, so if you agree, vote often!</span></address>
<address></address>
</blockquote>
<h4>The Great Compliance Debate: No Child Left Behind or The Polio Vaccine</h4>
<blockquote><p><strong><span style="color: #ffffff;">Panel Discussion: <a href=" http://www.the451group.com">Joshua Corma</a>n</span><span style="color: #ffffff;"> , <a href="http://blog.uncommonsensesecurity.com/">Jack Daniel</a> (@jack_daniel) </span><span style="color: #ffffff;">, <a href="http://www.chuvakin.org/">Anton Chuvakin</a> (@anton_chuvakin) </span><span style="color: #ffffff;">, <a href="http://www.csoandy.com/">Andy Ellis</a> (@CSOAndy)</span><span style="color: #ffffff;">, a surprise guest</span></strong></p></blockquote>
<h4>How to Design and Develop Your Own Security Event</h4>
<blockquote><p><strong><span style="color: #ffffff;"><a href="http://www.sourceconference.com">Stacy Thayer, Ph.D</a>. </span><a href="http://twitter.com/stacythayer"><span style="color: #000000;"><span style="text-decoration: none;"><span style="color: #ffffff;">@stacythayer</span></span></span></a></strong></p></blockquote>
<h4>My Life on the Infosec D-List</h4>
<blockquote><p><strong><span style="color: #ffffff;"><a href="http://www.andrewhay.ca">Andrew Hay</a></span></strong></p></blockquote>
<h4>Hacking the Sales Cycle</h4>
<blockquote><p><strong><span style="color: #ffffff;"><a href=" http://shpantzer.blogspot.com">Gal Shpantzer</a></span></strong></p></blockquote>
<h4>Being Inbred Isn&#8217;t Just a Problem for Hillbillies.  Groupthink and the InfoSec Industry</h4>
<blockquote><p><strong><span style="color: #ffffff;"><a href="http://www.nsslabs.com">Vikram Phatak</a></span></strong></p></blockquote>
<h4>Risk Management &#8211; Time to blow it up and start over?</h4>
<blockquote><p><strong><span style="color: #ffffff;"><a href="http://www.newschoolsecurity.com">Alex Hutton</a></span></strong></p></blockquote>
<p>What kind of self-serving person would I be if I didn&#8217;t put a shameless plug in for the Gender Panel: Unicorns, Clubhouses, and Ruffled Feathers: Women in Security:</p>
<p>Rounding out the panelist this year will be:</p>
<blockquote><p><span style="color: #ffff99;">Jennifer Jabbusch &#8211; CISO of </span><a onmousedown="return clk(this.href,'','','res','1','','0CAcQFjAA')" href="http://www.cadincweb.com/"><span style="color: #ffff99;">Carolina Advanced Digital, </span><em><span style="color: #ffff99;">Inc</span></em><span style="color: #ffff99;">.</span></a></p>
<p><span style="color: #ffff99;">Andrew Hay &#8211; 2008 &#8220;Security Thought Leader&#8221; award winner by SANS Institute / </span><a href="www.andrewhay.ca" target="_blank"><span style="color: #ffff99;">Security Blogger </span></a><span style="color: #ffff99;">/ InfoSec Professional</span></p>
<p><span style="color: #ffff99;">Lisa Lorenzin &#8211; Crazy smart solutions architect for an organization that I&#8217;m not sure if she&#8217;s listing (you have google, figure it out yourself)</span></p>
<p><span style="color: #ffff99;">Gurdeep Kaur &#8211; Author of controversial SANS Reading Room Paper “</span><a href="http://www.sans.org/reading_room/whitepapers/leadership/rss/women_in_it_security_project_management_33209" target="_blank"><span style="color: #ffff99;">Women in IT Security Project Management”</span></a></p>
<p><span style="color: #ffff99;">Michelle Klinger &#8211; Full time QSA, defender of all things saucy and womanly.</span></p></blockquote>
<address></address>
<address></address>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=312</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Shnow-pocolypse 2010! (A mini-journal)</title>
		<link>http://www.secsocial.com/blog/?p=305</link>
		<comments>http://www.secsocial.com/blog/?p=305#comments</comments>
		<pubDate>Sat, 06 Feb 2010 07:31:46 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Sociability]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Misc.]]></category>
		<category><![CDATA[Shmoocon]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=305</guid>
		<description><![CDATA[To quote the weather channel &#8220;The storm may reach the top 3 of all-time in the Washington, D.C., area and may rival the record of 28&#8243; from the &#8220;Knickerbocker&#8221; storm of 1922.&#8221; I am taking a little break in the festivities to let you all know that it has officially snowed pretty hard at ShmooCon [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-308 aligncenter" title="ShmooCon-inv" src="http://www.secsocial.com/blog/wp-content/uploads/2010/02/ShmooCon-inv.gif" alt="" width="120" height="120" /></p>
<p>To quote the weather channel</p>
<blockquote><p>&#8220;The storm may reach the top 3 of all-time in the Washington, D.C., area and may rival the record of 28&#8243; from the</p>
<p>&#8220;Knickerbocker&#8221; storm of 1922.&#8221;</p></blockquote>
<p>I am taking a little break in the festivities to let you all know that it has officially snowed pretty hard at ShmooCon VI. My flight has been canceled for Sunday, so with any luck at all I will be arriving back in Chicago (aka, the land that can handle 6&#8243;&lt; of snow) sometime early next week.<br />
With that, I have to say that the spirits of all the con goers is absolutely amazing! Trash-bag sleds are being used as well as certain individuals who have snowboards and snowshoes. The content of the event has started out with a bang, and the actual tracks tomorrow look exceptionally promising!</p>
<p>Thank you to @quine &#8216;s employer for hosting the<a href="http://security-twits.com/"> Securitytwits</a> meet-up this afternoon, it was VERY enjoyable! <a href="http://www.syngress.com/">Syngress</a> held a very nice happy-hour meet-up, and the <a href="http://www.dc949.org/">DC949</a> party was absolutely killer! Festivities are still commencing as I type, but sometimes one must just call it an evening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=305</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unicorns, Clubhouses, and Ruffled Feathers: Women in Security &#8212; A few good people needed &#8212;</title>
		<link>http://www.secsocial.com/blog/?p=295</link>
		<comments>http://www.secsocial.com/blog/?p=295#comments</comments>
		<pubDate>Fri, 29 Jan 2010 21:56:00 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Women in Security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Gender]]></category>
		<category><![CDATA[Security Industry]]></category>
		<category><![CDATA[SecurityBSidesSF]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=295</guid>
		<description><![CDATA[Notice I said people, not women. If you are interested in speaking on a panel at SecurityBSidesSF about Gender (Unicorns, Clubhouses, and Ruffled Feathers: Women in Security) and how it is impacting our industry by sharing diverse stories that have shaped your career, and tips for how as an industry we can improve, please contact me! [...]]]></description>
			<content:encoded><![CDATA[<p><img id="ipfG0ckOfW8WWWSpM:" class="alignleft" style="border: 1px solid; vertical-align: bottom;" src="http://t0.gstatic.com/images?q=tbn:G0ckOfW8WWWSpM:http://api.ning.com/files/cXEGRcSFMjLhm7ydtCGLPzVMESPp1fmYMcvTWYbMMZAik*N1fpOCnVmAvYU0vhe8lnN97i1Dpr3Y8j*bBYeuPs*okTRW-Z1Z/bsides_logo_onwhite.jpg" alt="" width="130" height="130" /></p>
<p>Notice I said people, not women.</p>
<p>If you are interested in speaking on a panel at <a href="http://www.securitybsides.org/BSidesSanFranciscoTalks">SecurityBSidesSF</a> about Gender (Unicorns, Clubhouses, and Ruffled Feathers: Women in Security) and how it is impacting our industry by sharing diverse stories that have shaped your career, and tips for how as an industry we can improve, please contact me!</p>
<p><a href="http://www.linkedin.com/in/gurdeepkaur">Gurdeep Kaur</a> who wrote the paper on “<a href="http://www.sans.org/reading_room/whitepapers/leadership/rss/women_in_it_security_project_management_33209" target="_blank">Women in IT Security Project Management” </a> has agreed to sit on the panel to discuss her findings and her experience that prompted the research. Also <a href="http://www.securityuncorked.com">Jennifer Jabbusch</a> will be speaking again as she did on the original panel at <a href="http://www.securitybsides.com/BSidesLasVegas01">SeucrityBSidesLV</a>.</p>
<p><img id="ipfDHMq0GMG7a2pCM:" class="alignright" style="border: 1px solid; vertical-align: bottom;" src="http://t2.gstatic.com/images?q=tbn:DHMq0GMG7a2pCM:http://inpop.com/mediakit/_superchick/superchick_megaphone_logo_hi.jpg" alt="" width="104" height="150" /></p>
<p>I am looking for 3 more panelist to make up a 5 person panel.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=295</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Really SANS? &#8211; “Women in IT Security Project Management”  &#8212; Part II</title>
		<link>http://www.secsocial.com/blog/?p=291</link>
		<comments>http://www.secsocial.com/blog/?p=291#comments</comments>
		<pubDate>Mon, 25 Jan 2010 14:23:35 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Women in Security]]></category>
		<category><![CDATA[Gender]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=291</guid>
		<description><![CDATA[Thank you all for the response, but I want to clarify two points that I&#8217;m not sure I communicated well in the original post. First of all, I want to give SANS a big kudos for actually posting a piece that is gender based, this was a risk, and I’m glad they took it. Many [...]]]></description>
			<content:encoded><![CDATA[<p>Thank you all for the response, but I want to clarify two points that I&#8217;m not sure I communicated well in<a href="http://www.secsocial.com/blog/?p=260"> the original post</a>.<img class="alignright" title="Girl Code" src="http://www.ini.cmu.edu/ini_files/news_images/2009/ewf09.jpg" alt="" width="200" height="200" /></p>
<p>First of all, I want to give <a href="http://sans.org/">SANS</a> a big kudos for actually posting a piece that is gender based, this was a risk, and I’m glad they took it. Many more organizations would benefit from helping broaden the horizons of gender awareness in the technical fields. Conferences have been very apprehensive in accepting a round-table panel composed of industry professionals (not marketing women) to discuss the state of the industry in regards to gender. Currently, the panel is being held at <a href="http://www.securitybsides.com/">SecurityBsides</a> events and there will be some perspective European conferences this year that are opening up to the conversation. There are also many women that do not feel comfortable speaking out or helping other women gain entry to the field, this is a definite gender issue, but one we need to address on a different plane, and more in another post.</p>
<p>The second point in the original post was that of the review itself, the content of the research for the paper itself was fine, where I felt there was a deficiency was when it took a turn away from fair representation. Perhaps the advisor could have proofed the paper and suggested some edits to keep it broad enough as to not be easily identified as personal rhetoric, thus reinforcing the research points. I am fortunate enough that the author of the piece HAS agreed to speak on the Gender panel at BSidesSF that will occur during the week of the RSA Conference in San Francisco.</p>
<p>Again, for any women that may be reading this, here is a list of some great sites on the internet that discuss current gender issues.</p>
<p><a href="http://geekfeminism.wikia.com/wiki/Geek_Feminism_Wiki">The Geek Feminism Wiki </a></p>
<p><a href="http://www.ewf-usa.com/">Executive Women&#8217;s Forum </a></p>
<p>Signed,</p>
<address><span style="color: #ff99cc;"> The unconventional gender supporter &#8211; Erin</span></address>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=291</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I need a sysadmin for my Facebook!</title>
		<link>http://www.secsocial.com/blog/?p=274</link>
		<comments>http://www.secsocial.com/blog/?p=274#comments</comments>
		<pubDate>Wed, 20 Jan 2010 21:53:05 +0000</pubDate>
		<dc:creator>SecBarbie</dc:creator>
				<category><![CDATA[Sociability]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.secsocial.com/blog/?p=274</guid>
		<description><![CDATA[Facebook is so lovely, you can learn about what your friends who you don’t have time to keep up with are doing, look at their pictures, watch some of their videos and generally cyber-stalk them with their permission. Opps, we call that ‘being social’ not stalking now. In the last few years people have really enhanced the art of the me-me using social networks such as Facebook under the guise of “maintaining transparency”. This does beg the question, how much is too much?]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Facebook" src="http://www.wvu.edu/~mcnair/facebookLogo.jpg" alt="" width="221" height="83" /></p>
<h4><span style="color: #ff00ff;">- A Facebook Privacy Memoir Part I</span></h4>
<p>Facebook is so lovely, you can learn about what your friends who you don’t have time to keep up with are doing, look at their pictures, watch some of their videos and generally cyber-stalk them with their permission. Opps, we call that ‘being social’ not stalking now. In the last few years people have really enhanced the art of the me-me using social networks such as Facebook under the guise of “maintaining transparency”. This does beg the question, how much is too much?</p>
<p><img class="alignright" title="Facebook Privacy" src="http://cdn.mashable.com/wp-content/uploads/2009/04/privacy-page1.png" alt="" width="357" height="359" /></p>
<p>In the last year Facebook has come a long way when it comes to the privacy settings, and nearly everyone is hiding something from the general population so we do have a start for some security.  If you want to be ubber technical about it, you can use friend lists and play with your privacy settings to create different views for each segment of your life, but who has time for this? Just like any system, add more complex controls and the users who should be using them the most will not.</p>
<p>I have used firewall graphical interfaces that are less complicated then the Facebook privacy settings. This is mostly due to the privacy settings for Facebook are not all in one place. There are the Privacy settings in the drop down, but then you have to customize your photo privacy settings in a whole different screen. Now add in the option to great groups for your contact and manage the settings by those groups as well. All of the technical minded people might think this is a piece of cake, but my aunt who isn’t that technical, can barely handle navigating from one profile to the next much less the privacy settings! Yet, she has no problem posting pictures, tagging me on the pictures, and sharing them with her friends.</p>
<p>As a Christopher Burgess wrote in his <a href="http://blogs.cisco.com/security/comments/security_who_is_responsible/" target="_blank">Cisco Security Blog about ‘Security &#8211; Who is Responsible’</a></p>
<blockquote><p><span style="color: #99ccff;">“ When we wish to use an automobile, we are required to go through a number of steps even before we get the vehicle rolling.  During the drive, we adhere to the rules of the road (drive on the appropriate side, use our signals, stop at red-lights, go when green, etc.).  When the engine light illuminates, the brakes start to screech, or the steering pulls too far left, we take note and either perform the required maintenance or we take it to the garage shop for service. We correct. The mechanic isn’t sitting in the backseat providing telemetry surrounding your vehicle’s operation, and unless my grandmother is in your backseat, you’re probably not being told how to steer, accelerate or brake.  You are responsible.  All of these actions are the responsibility of the operator—the user.  You, the user, will decide “How do I maintain my vehicle and operate it?”  When you violate motor vehicle laws (and are caught), what occurs?  You receive a ticket and tickets carry consequences.  In the US the consequences might include a monetary fine, points on your license and, for some, a mandatory trip to court.  With choices and actions come consequences.</span></p>
<p><span style="color: #99ccff;">In the online world, we have the same basic responsibilities for security as a driver has in the physical world for safety.”</span></p></blockquote>
<p>The unfortunate fact is that there is no education on the do’s and don’t of social media for people such as my aunt, nor would millions of high school students who are competing for the largest friend list and posting every little moment of their life even listen it it was! So here are my two tips for Facebook and a link to Cracked’s 10 Commandments of Facebook.</p>
<p><strong> </strong></p>
<ol>
<h2><strong>Don’t friend ANYONE you don’t know, and deny friend request if you don’t know them!</strong></h2>
</ol>
<p><strong> </strong></p>
<p>Don’t friend anyone you don’t know if you post anything to your Facebook that you wouldn’t post on a pubic or work bulletin board! You don’t really know who is on the other side of the profile.</p>
<p>If you don’t know the person, deny the friend request promptly! Unfortunately there is a bug in Facebook right now that allows people who request you as a friend to see your live feed while the friend request is pending. As of right now, there is not a privacy setting on the live feed. This is bound to change soon, but it is good measure to always deny friend request until you know that person.</p>
<ol>
<h2><strong>Unless part of your job is using Facebook, don’t update your Facebook from work!</strong></h2>
</ol>
<p><strong> </strong></p>
<p>You don’t know who is really on the other side of your ‘Friends’, so unless part of your job is social media, don’t update your Facebook status from work. Wait for lunch, or after work. This is ESPECIALLY important if your organization doesn’t allow access to Facebook.</p>
<h3 style="text-align: center;"><a href="http://www.cracked.com/blog/the-10-commandments-of-facebook/">The 10 Commandments of Facebook</a></h3>
<p>Until next time&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.secsocial.com/blog/?feed=rss2&amp;p=274</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
