<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title>Sync</title>
      <link>http://blog.ncircle.com/blogs/sync/</link>
      <description></description>
      <language>en</language>
      <copyright>Copyright 2010</copyright>
      <lastBuildDate>Thu, 25 Feb 2010 08:26:58 -0800</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>RSA Conference Twitter Badge Mod</title>
         <description>&lt;p&gt;Again this year, the folks at the nCircle booth will be providing customized RSA badge mods with your twitter handle.&lt;br /&gt;
&lt;img alt=&quot;twitter_badge_small.jpg&quot; src=&quot;http://blog.ncircle.com/blogs/sync/twitter_badge_small.jpg&quot; width=&quot;200&quot; height=&quot;66&quot; border=&quot;1&quot; /&gt;&lt;/p&gt;

&lt;p&gt;We've made things really simple to request your own:&lt;/p&gt;

&lt;p&gt;Follow &lt;a href=&quot;http://twitter.com/ncircletweets&quot;&gt;@ncircletweets&lt;/a&gt;&lt;br /&gt;
Send us a DM that you'd like one for yourself.&lt;br /&gt;
Come by the booth (#1023) at RSA for pickup.&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2010/02/rsa_conference_twitter_badge_m.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2010/02/rsa_conference_twitter_badge_m.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">RSA2010</category>
        
        
         <pubDate>Thu, 25 Feb 2010 08:26:58 -0800</pubDate>
      </item>
            <item>
         <title>nCircle Announces Patch Priority Index</title>
         <description>&lt;p&gt;Each time a vendor releases patches; I always answer the same questions about prioritization.  Which new patch is the most important?  How is enterprise IT going to be tackling this new work?&lt;/p&gt;

&lt;p&gt;At nCircle, we know from customers and other publicly available sources that most companies need at least 60 days to complete a patch deployment cycle.  Every day a new deluge of patches are released.  Every group of new patches kicks off a new cycle of patch management steps. Each patch must be evaluated, prioritized and scheduled.  Information security managers are continually juggling decisions regarding risk, prioritization and resource allocation and the variables change every time a vendor releases a new set of patches&lt;/p&gt;

&lt;p&gt;Today, nCircle announced the Patch Priority Index, a monthly ranking of the top 10 highest risk vulnerabilities from key vendors such as Microsoft and Adobe that adjusts to reflect how vulnerability's risk changes over time. The Patch Priority Index (PPI) helps prioritize risk reduction decisions by evaluating new patches within the context of the bigger security picture and acknowledges that all patches may not be deployed before the next group of patches are released. &lt;br /&gt;
  &lt;br /&gt;
The idea for this index grew out of community discussions with customers, partners and vendors.  Our Patch Priority Index is a free and publicly available service that nCircle is providing as a service to the information security community.  &lt;/p&gt;

&lt;p&gt;We hope that the service will provide a repeatable, consistent and complimentary metric that IT security teams can use to effectively prioritize the most critical vulnerabilities.&lt;/p&gt;

&lt;p&gt;Patch Priority Index rankings are based on key elements of nCircle's Risk Score and includes a critical time component that is unique among scoring systems. This time component prioritizes new patches within the context of all patches previously released by a vendor within the preceding twelve months. &lt;/p&gt;

&lt;p&gt;Patch Priority Index debuts for Microsoft vulnerabilities in March and other key &lt;br /&gt;
vendors will follow. &lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.ncircle.com/index.php?s=Patch-Priority-Index&quot;&gt;The most recent Patch Priority Index may be found here&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.ncircle.com/index.php?s=resources_whiteform&amp;whitepaper=nCircle- Vulnerability-Scoring-System&quot;&gt;For information on the nCircle risk score algorithm, please check out our &lt;br /&gt;
whitepaper&lt;/a&gt;&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2010/02/ncircle_announces_patch_priori.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2010/02/ncircle_announces_patch_priori.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">In The News</category>
        
        
         <pubDate>Tue, 23 Feb 2010 09:09:02 -0800</pubDate>
      </item>
            <item>
         <title>How does a consumer report PCI non-compliance?</title>
         <description>&lt;p&gt;This past Saturday my son and I were having a &quot;boys day&quot;.  My wife was out having &lt;br /&gt;
fun all day and the boys were left to be boys.  Dinnertime rolled around and we were &lt;br /&gt;
having too much fun playing LEGO India Jones to even consider making food. So I &lt;br /&gt;
treated him to a stereotypical boys dinner - video games and pizza.  This was when &lt;br /&gt;
the fun turned into fear.&lt;/p&gt;

&lt;p&gt;Moments after ordering pizza online from our favorite local pizzeria, the phone &lt;br /&gt;
rang.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Caller:&lt;/strong&gt; &quot;This is Joe from the local pizza place, calling to confirm your order&quot;.&lt;br /&gt;
The order and delivery location was confirmed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Caller:&lt;/strong&gt; &quot;And how do want to pay for this?&quot;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me:&lt;/strong&gt; &quot;Um, well I just entered all my credit card info into your website like I usually &lt;br /&gt;
do&quot;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Caller:&lt;/strong&gt; &quot;oh&quot;.  A moment of pause. &quot;Oh I see your credit card info now in the email.&quot;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me, with a definite tone of anger:&lt;/strong&gt; &quot;My credit card was sent to you in email?!&quot;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Caller:&lt;/strong&gt; &quot;um, I'll get that pizza delivered ASAP.&quot;&lt;br /&gt;
Click&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
The pizza delivery guy arrived.  As it turns out it was the owner delivering the pizza.  &lt;br /&gt;
He explained to me that he had recently bought the local franchise and had no idea &lt;br /&gt;
that the online orders were emailed to him along with all the customer information.  &lt;br /&gt;
As an attempt at a good-hearted gesture, he gave me some free breadsticks along &lt;br /&gt;
with the printed email containing my entire credit card and address information.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
I was now bent out of shape.  Five minutes of Google searches turned up no methods &lt;br /&gt;
for a consumer to report this obvious PCI non-compliance.  Asking friends on &lt;br /&gt;
Twitter and Facebook ended up with equally non-specific information. Some friends &lt;br /&gt;
offered up email addresses of people at Visa, others stated quite assuredly that a &lt;br /&gt;
consumer has no means to turn in violators.  Realize of course that nCircle (my &lt;br /&gt;
employer) is a certified PCI scan vendor and my online friends are all very much &lt;br /&gt;
entrenched in information security.  That is to say that you would think someone &lt;br /&gt;
like me could ask around and quickly find a way to report this merchant to the PCI &lt;br /&gt;
council for review.&lt;/p&gt;

&lt;p&gt;The next step was to call my bank and issue a fraud alert.  The bank customer &lt;br /&gt;
support person took my information, listened well and followed her procedural &lt;br /&gt;
steps exactly as instructed.  All my information was confirmed, past orders were confirmed &lt;br /&gt;
and a new card was issued.  I requested directions on how to report this merchant &lt;br /&gt;
for obvious non-compliance.  Furthermore, I felt the merchant was in violation of a &lt;br /&gt;
number of laws by printing out my entire credit card number.  The bank customer &lt;br /&gt;
support person offered the number of the Better Business Bureau.  &lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Think about this.  The PCI standards council has worked hard to ensure compliance &lt;br /&gt;
of all their merchants.  An entire industry has sprung up around the PCI Data &lt;br /&gt;
Security Standards.  Yet, the standard provideds no means for consumers to flag &lt;br /&gt;
merchants for non-compliance.  Even the issuing bank seems to have no means to do &lt;br /&gt;
so.&lt;/p&gt;

&lt;p&gt;Aside from naming names here in my public soap box, how are consumers suppose &lt;br /&gt;
to help due their part to ensure security and privacy of the credit card industry?&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2010/02/how_does_a_consumer_report_pci.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2010/02/how_does_a_consumer_report_pci.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security Industry</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">compliance</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">PCI</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">standards</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">VISA</category>
        
         <pubDate>Mon, 22 Feb 2010 10:25:28 -0800</pubDate>
      </item>
            <item>
         <title>BofA Website Outage - A Giant PR Mistake</title>
         <description>&lt;p&gt;For a lot of Americans, today is both a payday and the last business day to pay those bills online due this month.  So it goes without saying that many people have noticed that Bank of America's website has been unavailable for most of the day.&lt;/p&gt;

&lt;p&gt;A quick search on twitter shows many Americans complaining about the site being down.  Yet, so far only a few news organizations are covering the outage.  The only official word from the company has come from its twitter account ( http://twitter.com/BofA_help ).  Apparently, they feel that the outage is only affecting a few people by issuing a statement, &quot; We are aware some customers are experiencing access issues. Our tech team is working to resolve as soon as possible.&quot;  Those news organizations covering the outage all report no word back from the company.&lt;/p&gt;

&lt;p&gt;Meanwhile, speculation is on the rise that the company is in the midst of a cyber attack.  This is turning into a giant PR mistake by Bank Of America.  For a company that took billions of federal assistance, this would also seem like something our new Cyber Czar should be looking into.  We must not forget that at the very least, one tenet of information security is availability.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2010/01/bofa_website_outage_a_giant_pr.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2010/01/bofa_website_outage_a_giant_pr.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">In The News</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">bank of america</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">bofa</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">mistake</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">nCircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">outage</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">PR</category>
        
         <pubDate>Fri, 29 Jan 2010 14:17:02 -0800</pubDate>
      </item>
            <item>
         <title>Is Google to blame for the IE 0-Day Hype?</title>
         <description>&lt;p&gt;The sudden hypersensitivity regarding a new Microsoft IE 0-day, traces its roots to this weeks Google's overhyped breach.  On Tuesday, Google went public with an admission of its own compromise.  This was no ordinary breach, but one of global proportions that claimed they and 20+ other companies were all victims of state sponsored cyber thiefdom.  Everyone suddenly became aware of China's cyber terror potential.  &lt;/p&gt;

&lt;p&gt;Queue the Beethoven.&lt;/p&gt;

&lt;p&gt;While most everyone assumed the public Adobe PDF flaw was the attack vector, we should have more correctly assumed not one but many attack vectors were at play.  Come Friday, in an unexpected turn of events, Microsoft was taking the brunt of the blame in a newly announced IE vulnerability.  Microsoft is getting a bum deal here and has much of it to blame on Google's overhype.&lt;/p&gt;

&lt;p&gt;What if we replayed this week's events with a different set of goggles? &lt;/p&gt;

&lt;p&gt;Suppose that Google had not raised its own compromise to the level of state sponsored cyber terror, while threatening its own retaliation by ceasing censorship of search data.  Furthermore, Google didn't need to announce that some 20+ other companies were also victims.  At this point, the other companies have very little reason not to come forward.  They can safely join the ranks of the others affected and cleanly play the victim role of being attacked by a state sponsored cyber terror.  Yet, very few have come forward despite all having been notified.&lt;/p&gt;

&lt;p&gt;It would seem to me this was an obvious calculated overhype. The event provided the perfect set of excuses for Google to combat Chinese censorship while giving them an alternative reason to pull out of China.  It's a win-win for Google - fight Chinese censorship, support Chinese human rights activists and cleanly exit a failing business venture.&lt;/p&gt;

&lt;p&gt;With any good attention diversionary plan an unexpected victim arises. &lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
Take the facts of the IE vulnerability independent of all external events.  What we have today is a bug in all versions of Internet Explorer, but so far only weaponized for IE version 6 on Windows XP.  As usual, DEP and ASLR are providing significant mitigation with IE8, Vista and Windows7.  The net of these findings is that today's attacks are only successful on Windows XP with IE6.  Jonathan Ness of the MSRC engineering team spelled out these important &lt;a href=&quot;http://blogs.technet.com/srd/archive/2010/01/15/assessing-risk-of-ie-0day-vulnerability.aspx&quot;&gt;facts in a blog post Friday evening&lt;/a&gt;.  In an ordinary humdrum month, the vulnerability would be worrisome, but not epic.&lt;/p&gt;

&lt;p&gt;Zero day attacks happen every day.  Even the most secure organizations get compromised.  Everyone is a target, everyone will be a victim.  Take a few deep breaths.&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2010/01/is_google_to_blame_for_the_ie.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2010/01/is_google_to_blame_for_the_ie.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security Industry</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">0day</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">china</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">google</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ie</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">internet explorer</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Microsoft</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">vulnerability</category>
        
         <pubDate>Sat, 16 Jan 2010 18:05:03 -0800</pubDate>
      </item>
            <item>
         <title>Twitter is down, twitter is down! I don&apos;t know what to do.</title>
         <description>&lt;p&gt;On this momentous occasion of a twitter outage apparently caused by a &lt;a href=&quot;http://status.twitter.com/&quot;&gt;big DDoS attack&lt;/a&gt;, let us celebrate by naming 5 things we used to do before twitter.&lt;/p&gt;

&lt;p&gt;1.	Work more&lt;br /&gt;
2.	Email the person directly&lt;br /&gt;
3.	Pick up the phone&lt;br /&gt;
4.	Make a decision by yourself &lt;br /&gt;
5.	Watch the evening news and not find it old news&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/08/twitter_is_down_twitter_is_dow.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/08/twitter_is_down_twitter_is_dow.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">In The News</category>
        
        
         <pubDate>Thu, 06 Aug 2009 08:53:41 -0800</pubDate>
      </item>
            <item>
         <title>How to react when big leaguers get hacked</title>
         <description>&lt;p&gt;An old boss told me once, &quot;You play in the big leagues, and you will eventually fall like a big leaguer.&quot;   The fact is many people have their computer security compromised daily, and this is also true for many corporations.  But how are we supposed to react when the &quot;big leaguers&quot; in our industry fall victim too?&lt;/p&gt;

&lt;p&gt;Over the last week some of the security industry's heavy hitters were victims of widely publicized security breaches.  Dan Kaminksy, Matasano Security and Kevin Mitnick all had their websites breached.  Some events were little more than defacements; in Dan's case some of his personal information was publicized.  We, the BlackHat attendees, are the ones entrusted by individuals, large corporations and government entities to protect networks against precisely these types of attacks.   What do high profiles breaches like these mean for our reputations and for our industry?&lt;/p&gt;

&lt;p&gt;The truth is that data breaches are so common that most of us aren't even alarmed anymore. Privacyrights.org tracks the millions of private records that are compromised each year.  The Conficker worm was said to have compromised millions of computers.  We have become so used to reading about these stories and shrugging our mental shoulders that some people say our industry has become laize faire.   We work towards compliance; we fight for budget and reducing our risk metrics.  But are we really living and breathing what we preach?&lt;/p&gt;

&lt;p&gt;This is not to say that Kaminksy, Matasano or Mitnick aren't intelligent, creative thought leaders who honestly work hard each and every day.  It does mean that even the best of us are vulnerable to the same threats as everyone else.  It also means that every company, even the ones we work so diligently to protect, is susceptible to some sort of data breach. No one is beyond the law of statistics.&lt;/p&gt;

&lt;p&gt;So what does it really mean when even the security gurus at Blackhat get breached?  It means there is always room to improve, and it means that there is no such thing as complete security, no matter how much money you spend or how smart you are.&lt;/p&gt;

&lt;p&gt;This sobering reality is a reminder to us all about the value of vigilance. It's also a reminder that every breach offers a lesson. Dan Kaminksy handled this very public data breach by congratulating his attackers and offering them two of his grandma's famous cookies. &lt;/p&gt;

&lt;p&gt;Dan will definitely step us his security, will you?&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/08/how_to_react_when_big_leaguers.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/08/how_to_react_when_big_leaguers.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security Industry</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">hacked</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Kaminsky</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Matasano</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Mitnick</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
        
         <pubDate>Mon, 03 Aug 2009 13:25:40 -0800</pubDate>
      </item>
            <item>
         <title>Apple Needs to Get Serious About iPhone Security</title>
         <description>&lt;p&gt;Two years ago I took some hard hits from my peers for calling the iPhone &quot;a security nightmare&quot;.  Two years later, I can't find a single person who doesn't agree that the iPhone is the number one mobile target of security researchers.  Fast forward to today -- is the iPhone still a security nightmare or have those problems been relegated to annoyance status?&lt;/p&gt;

&lt;p&gt;Last night at one of the BlackHat evening events, I went out of my way to personally thank Charlie Miller for his creative and diligent work finding new and ever more alarming bugs in the iPhone.  Charlie needs very few introductions these days due to the notoriety driven by his iPhone security hole discoveries and his history at the Pwn2Own contest.   But Charlie is not alone when it comes to iPhone security research.  Apple security updates for the iPhone OS now recognize a rapidly expanding list of bug reporters. &lt;/p&gt;

&lt;p&gt;The iPhone is now on its' third full OS version and Apple has added many new enterprise and security related features.  In spite of Apple's attempts to keep the iPhone a closed system,  more known about its inner workings than any other mobile platform (except possibly the open source development of Android).  iPhone popularity  isn't limited to consumers, it is a favorite with security researchers.&lt;/p&gt;

&lt;p&gt;One security maxim says that risk increases in proportion to the target landscape.  If this is true then, the iPhone represents a significant security risks simply because of its market penetration.  The same thing can be leveled at Microsoft Windows.  It's easy to say that because the iPhone is getting the high level of security attention it represents the greater threat than other popular mobile platforms such as Windows Mobile or Blackberry. This kind of thinking is short sighted.&lt;/p&gt;

&lt;p&gt;The reason why the iPhone continues to represent a significant threat to the enterprise is not because of its operating system design or the dozens of security bugs it contains.  The iPhone risk continues to escalate because of the way Apple prioritizes and operationalizes security.  Apple continues to prioritize usability and features ahead of security.  Apple just recently added on board data encryption to the new 3GS model.  Only days later after its release iPhone encryption was shown to be easily subverted.  And enterprise security teams operating with limited resources still don't have a centralized management console for pushing out updates, and the updates themselves are released on Apple's timing with no advance clues as to timing or content.  Enterprises that allow iPhones on their networks must live without vendor-supplied intelligence routinely provided by other vendors.&lt;/p&gt;

&lt;p&gt;Today'the iPhone might not qualify as a security nightmare but it's still a pain in the side both IT security and operational teams.   We would like very much to support and deliver the best tools to our users, and that includes the iPhone.  The problem is that Apple's enterprise management tools just don't measure up to what is available from Microsoft and Blackberry.  And even when we get in a bind with security issues from other vendors, at least they communicate and lend us a hand with detailed information and risk mitigation steps.  It's time for Apple to get serious about security if they want to grow in the enterprise.  &lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/08/apple_needs_to_get_serious_abo.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/08/apple_needs_to_get_serious_abo.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security Industry</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">apple</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">iphone</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">mac</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
        
         <pubDate>Mon, 03 Aug 2009 13:19:54 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Responds To Criticisms About Its SDLC</title>
         <description>&lt;p&gt;Adobe had a turbulent start this year and in response to cries from it's disgruntled users, Adobe security has announced several strategic moves.  &lt;a href=&quot;http://blogs.adobe.com/asset/2009/05/adobe_reader_and_acrobat_secur.html&quot;&gt;This blog post from Adobe&lt;/a&gt; describes the three much-needed things Adobe will be doing to improve security for their popular Reader and Acrobat products. &lt;/p&gt;

&lt;p&gt;First, Adobe's existing secure product development standards will now also be used against their existing/legacy code base.  Second, Adobe now promises quicker and more in-depth security incident response mechanisms.  Finally, Adobe will be moving to a regular patch release cycle.&lt;/p&gt;

&lt;p&gt;The three initiatives essentially mirror what we have come to know and appreciate about Microsoft's security processes.  About a decade ago, hit by bad press and poor industry reputation, Microsoft embarked on a similar but grander vision.  The result of that effort is that today Microsoft is the leader when it comes to managing the enterprise security development lifecycle.&lt;/p&gt;

&lt;p&gt;These initiatives are a great start for Adobe to begin rehabilitating their image.  These initiatives go a long way, but they are still missing a few important components.  &lt;/p&gt;

&lt;p&gt;First, Adobe needs to learn how to reign in the bug finders.  Both critical security incidents with Adobe so far in 2009 have involved situations where proof-of-concept code was made public before Adobe could repair the bug.  Letting bug exploits out into the wild set Adobe back on their heels and left IT security groups in a reactionary mode trying to cover their security assets without much help from Adobe &lt;/p&gt;

&lt;p&gt;Second, enterprise IT shops could benefit greatly from centralized tools that allow for product policy changes.  If Adobe published means and methods to disable product functionality using active directory group policies, then IT would be in a better position to respond and implement policy-setting changes.  &lt;/p&gt;

&lt;p&gt;Finally, JavaScript bugs riddled Adobe products in 2008 and in 2009.  It would behoove them to consider disabling JavaScript by default.&lt;/p&gt;

&lt;p&gt;The long string of critical bugs in Adobe products has disappointed me, among many others.  The bugs, coupled with poor company communications and difficult to deploy mitigation steps have made the last six months ever more trying in our security team.  Going forward there will be 2 key metrics of Adobe's successful implementation of their new security program.  First will the obvious - fewer security holes.  The second indicator will be when Adobe has successfully convinced the bug finders to disclose holes to them instead of publishing them online. &lt;/p&gt;

&lt;p&gt;The bottom line is that the changes announced today by Adobe are welcome and we all hope that Adobe sees immediate improvement across their install base. &lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/05/adobe_responds_to_criticisms_a.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/05/adobe_responds_to_criticisms_a.html</guid>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">adobe</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">pdf</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">reader</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">risk</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">SDLC</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
        
         <pubDate>Wed, 20 May 2009 14:45:40 -0800</pubDate>
      </item>
            <item>
         <title>FBI Citizens&apos; Academy, Week 5</title>
         <description>&lt;p&gt;Week 5 of the FBI Citizens' Academy was mostly dedicated to counterterrorism.&lt;/p&gt;

&lt;p&gt;First we received an overview of the counterterrorism program from the local assistant special agent in charge for the counterterrorism group.  The number 1 priority of the FBI is to protect the United States from a terrorist attack.  This includes protecting US interests and citizens both locally and located abroad.  We learned about the joint terrorism task force (JTTF) that makes up federal, state and local law enforcement personnel.  The JTTF acts as an integrated investigative force to combat domestic and internal terrorism.  Here in the Bay Area we also have a northern California regional intelligence center, also referred to as a fusion center.  After the overview, speakers led the class thru 2 separate case studies.  The first of domestic terrorism related to individuals harming local university professors that worked in areas where animal tested is involved.  The second case study demonstrated a case of international terrorism.  In this second case, a local bay area resident was found supporting terrorists on foreign soil by monetary means.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
The evening ended with a quick discussion of InfraGard.  InfraGard is a partnership between the FBI and the private sector for information sharing and analysis.  The partnership works towards preventing hostile acts against the United States.&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/05/fbi_citizens_academy_week_5.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/05/fbi_citizens_academy_week_5.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">FBI Citizens Academy</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">Academy</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Citizens</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">counterterrorism</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">FBI</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">JTTF</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
        
         <pubDate>Wed, 20 May 2009 09:11:49 -0800</pubDate>
      </item>
            <item>
         <title>Why Common Risk Scores Matter</title>
         <description>&lt;p&gt;The date is May 12th 2009 and you are a mild mannered IT manager anticipating a single bulletin from Microsoft and a possible update from Adobe.  The team has their assignments; their computers are locked and loaded. The team is ready to execute on the planned patch release mechanisms.  &lt;/p&gt;

&lt;p&gt;At 10AM Pacific Microsoft releases their patch on time.  The single bulletin is the anticipated bug fix for the PowerPoint vulnerability.  Some members of the team are a bit agitated by the high CVE count and the lack of updates for the OSX Office platform.  You are able to quickly refocus the team and move forward.  Hours later, rumors hit that not only did Adobe publish their fix, but also Apple released a new revision of their operating system.  &lt;/p&gt;

&lt;p&gt;In fact both of these things happen and OSX 10.5.7 includes fixes for 67 vulnerabilities.  Together the Apple, Adobe and Microsoft patches account for 83 CVE fixes.  Now the team is seriously disheartened.  Your job is to draw the group together, review the unexpected workload and set priorities.  Did I mention that because of the economy, your team is now smaller, but doing just as much, if not more work. &lt;/p&gt;

&lt;p&gt;Microsoft produces their risk categorization.  Adobe employs yet another risk methodology and Apple  also defines bugs in their own way.  The lack of any common metric across the three vendors in combination with the additional calculus needed to accommodate your internal risk equations equals uncertain resource drain. &lt;/p&gt;

&lt;p&gt;On any normal Microsoft patch Tuesday, most enterprises IT teams have their risk calculators in hand and resources at the ready.  Some teams split up the duties between client and server vulnerabilities.  Others take the highest risk first no matter where the bug lies.  Either way, the security team adapts in order to deal with the Microsoft specific criticality ratings and their exploitability index.  &lt;/p&gt;

&lt;p&gt;The same thing ensues on an Oracle CPU day.  And even when smaller vendors like Adobe release bug fixes, most enterprises know how to massage the vendor specific risk data into their own risk profile equations.  This data manipulation is  a completely avoidable step.&lt;/p&gt;

&lt;p&gt;CVSS (Common Vulnerability Scoring System) version 2 was finalized two years ago. Even before that, CVSS v1 was in play for a number of years.  While everyone recognizes that there are some shortcomings with the standard, it is nonetheless a common means to reliably communicate information about risk.  It enables vendors to consistently distribute quantifiable information to enterprises who then use this data in their own decision-making engines.  &lt;/p&gt;

&lt;p&gt;So with this industry wide tool readily available, why is it that today enterprise IT must differentiate and discriminate the various meanings of the word 'critical' from multiple vendors?&lt;/p&gt;

&lt;p&gt;On a day like May 12th 2009, enterprise IT had a whole range of decision making to perform.  Which bugs were most important for my enterprise?  Where do the greatest risks lie and which patches should be tested and delivered first?  Do you tackle the low hanging fruit or the higher risk and possibly more cumbersome patches first?  &lt;/p&gt;

&lt;p&gt;These decisions are made countless times every year as vendors release patches.  Unfortunately for those in the trenches, too many valuable resources are consumed with just trying to normalize the vendor datasets.  If all vendors across the board delivered data with standard metrics, then at least enterprise IT would be in a better position to handle the inevitable changes smoothly and with minimal disruption.&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/05/why_common_risk_scores_matter.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/05/why_common_risk_scores_matter.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security Industry</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">adobe</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">apple</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">cvss</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Microsoft</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">patch</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">risk</category>
        
         <pubDate>Thu, 14 May 2009 08:47:49 -0800</pubDate>
      </item>
            <item>
         <title>May Patch Tuesday - Fear Not the 14 CVEs</title>
         <description>&lt;p&gt;Why couldn't Microsoft have kept things easy this month?  Last week Microsoft's advanced notification information spelled out a single bulletin for PowerPoint.  Given the single outstanding publicly known vulnerability in Microsoft's products, May patch Tuesday certainly looked like it would be an easy one.  Alas, we did receive a single bulletin today, but with it came 14 CVEs and a note of more to come.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Don't get caught up in the details &lt;/strong&gt; &lt;/p&gt;

&lt;p&gt;First thing to take away is that newer Microsoft Office products carry on signs of being more secure.  Office 2007, with its new office file format, continues to present lower risk levels. Even in the face of zero day bugs like those of Excel in February and now PowerPoint, Office 2007 was noticeably less affected.  Now with the PowerPoint 4 format being totally retired, managers have more ammo than ever to go obtain budget for upgrades.&lt;/p&gt;

&lt;p&gt;The second important piece not to overlook is that more patches for today's bugs are due out soon.  Microsoft recognized that these bugs also affect the Mac Office products, but don't have patches available yet.  Releasing patches for only piece of their product line and leaving the Mac users out in the cold is unlike Microsoft.  However, given that current exploit samples were less functional on the Mac and given the market share dichotomy between Office Mac and Windows, the split release cycle is understandable.&lt;/p&gt;

&lt;p&gt;The third piece of today's puzzle is that after you look over the mass of CVEs patched; don't forget that one of them is the known zero day bug that was described in KB969136.  This means that Micrsoft not only patched the known zero day bug as promised, but also went much further at delivering a more secure Office product lineup.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/05/may_patch_tuesday_fear_not_the.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/05/may_patch_tuesday_fear_not_the.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security Industry</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">information security</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Microsoft</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">MS09-017</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">patch</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">patch tuesday</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">risk</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
        
         <pubDate>Tue, 12 May 2009 11:22:06 -0800</pubDate>
      </item>
            <item>
         <title>FBI Citizens&apos; Academy, Week 4</title>
         <description>&lt;p&gt;Week 4 of the FBI Citizens' Academy: Violent Crimes, White Collar Crimes and Civil Rights Crimes.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
The mission of the FBI violent crimes program is to:&lt;br /&gt;
* Effectively address those violent crimes that pose significant risk to citizens of the US.&lt;br /&gt;
* Reduce incidents of crimes against children.&lt;br /&gt;
* Address other major violent crimes to include Indian Country, transportation and other special jurisdiction crimes.&lt;/p&gt;

&lt;p&gt;Common crimes include bank robbery, kidnapping, and extortion. The presenter referred to the &lt;a href=&quot;http://www.fbi.gov/ucr/ucr.htm&quot;&gt;uniformed crime report (UCR)&lt;/a&gt; for anyone wanting the most up to date crime statistics.  He did, however, highlight some interesting statistics.  According to the 2006 UCR, there are only 2.4 sworn law officers per very 1,000 inhabitants in the US.  Further, according to a number of news outlets, nearly 1 in every 100 adults is behind bars.&lt;/p&gt;

&lt;p&gt;The presenter turned our attention to criminal gang activity nationally and locally.  According to Morgan and Quinto press, in 2007 the most dangerous cities included Oakland at number 4 and Richmond  in9th place.   Gangs, as the presenter taught us, fulfill social needs  for their members.  Whether it is the mimicking of an extended family, creating social or ethnic bonds, the gangs provide members with an identity that is represented by their clothing, hand signs, graffiti and tattoos.&lt;/p&gt;

&lt;p&gt;White-collar crime efforts fall into 2 areas of the national FBI priority list - #4 combat public corruption at all levels and #7 combat major white collar crime.  Crimes that typically fall under the white-collar division include public corruption, corporate or securities fraud and health care fraud.  Of these crimes, the most up and coming are financial fraud including mortgage fraud and Ponzi schemes.  The FBI investigates public corruption cases and provides check and balances in the criminal justice system because agents typically have fewer local and political ties.&lt;/p&gt;

&lt;p&gt;The final topic for the evening was civil rights.  The FBI is the primary federal agency responsible for investigating all allegations of civil rights violations.  Selected crimes involving civil rights allegations include: hate crimes, color of law, human trafficking and freedom of access to clinic entrances act.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/04/fbi_citizens_academy_week_4.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/04/fbi_citizens_academy_week_4.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">FBI Citizens Academy</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">Academy</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">Citizens</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">FBI</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
        
         <pubDate>Wed, 29 Apr 2009 15:34:46 -0800</pubDate>
      </item>
            <item>
         <title>RSA 2009 Recap</title>
         <description>&lt;p&gt;Hard to believe, but RSA 2009 was just last week.  I found it to be a very successful show and now it's my turn to recap.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Themes&lt;/strong&gt;&lt;br /&gt;
Every year the marketing team tasks me with finding themes at the show.  In no particular order, the top themes between the talks and the booths were: virtualization, cyberwar/cybersecurity, and compliance/policy/regulation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Attendance&lt;/strong&gt;&lt;br /&gt;
During the first part of the week, &lt;a href=&quot;http://blog.ncircle.com/blogs/sync/archives/2009/04/rsa_opens_show_me_the_people.html&quot;&gt;I had noted that the attendance appeared to be dramatically lower than usual&lt;/a&gt;.  To my surprise, as the week progressed, the attendance appeared to be on par with prior years.  In fact, a member of the RSA conference PR team emailed me to say that the unofficial count for 2009 is less than 15% off of prior years.  Considering current news of financial cutbacks, a drop in less than 15% would appear to be pretty good.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best Event&lt;/strong&gt;&lt;br /&gt;
Without a doubt, the security bloggers meet up on Wednesday evening was the week's highlight.  This was a great chance to chat candidly with bloggers, press and friends.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One Thing I Learned&lt;/strong&gt;&lt;br /&gt;
&lt;a href=&quot;http://blog.ncircle.com/blogs/sync/archives/2009/04/rsa_virtualization_security_pa.html&quot;&gt;The Virtualization Security Panel&lt;/a&gt; opened up slew of new thoughts for me.  Hopefully, I'll have some time to both implement my ideas at work and share them in a blog post.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Special Thanks&lt;/strong&gt;&lt;br /&gt;
Special thanks to a number of journalists who let me share some time with them: George Hulme, Dennis Fisher and Ryan Naraine&lt;/p&gt;

&lt;p&gt;All my &lt;a href=&quot;http://blog.ncircle.com/blogs/sync/archives/rsa_2009/&quot;&gt;blog posts from RSA 2009.&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/04/rsa_2009_recap.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/04/rsa_2009_recap.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">RSA 2009</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">ncircle</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">risk</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">rsa</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">rsa 2009</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">rsacon</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
        
         <pubDate>Tue, 28 Apr 2009 13:43:50 -0800</pubDate>
      </item>
            <item>
         <title>RSA Virtualization Security Panel Review</title>
         <description>&lt;p&gt;Putting Simon Crosby and Chris Hoff on the same panel to discuss virtualization security is a recipe for a good lively discussion.  At the end of the panel, the audience was not disappointed.  In addition to Crosby and Hoff, the panel also included Michael Berman of Catbird and Stephen Herrod of VMware.&lt;/p&gt;

&lt;p&gt;The discussion started with some hi jinx by Crosby and Hoff.  Crosby handed out gifts to the panelists that included a broken toy sword and a ball and chain.  Hoff gave out cigars, one notably much smaller for his nemesis, Mr. Crosby.  Despite Chris Hoff's sometimes-flamboyant style, he initially came out mild mannered and on an even keel.  His moderate, centrist and thoughtful approach lasted throughout the discussion.  Conversely, Simon Crosby of Citrix and huge proponent of Xen spent most of his time trying to put VMWare into a corner.  Crosby touted Xen as the most secure hypervisor system because of its open nature and its continuous real life testing because of it's use as the foundation of  Amazon's EC2 offering.&lt;br /&gt;
 &lt;br /&gt;
Despite the moderator's attempts to encourage the panel to discuss real world security implications of virtualization, the topics kept going back to the implementation and security of VMware products like vShield.  In the final moments of the session, the panelists did finally provide a few recommendations worthy of implementing today.  One of these nuggets was that insight included most of the security basics necessary for all systems, virtualized or not.  Examples of these basics included using configuration guidelines, creating operational plans that include security and risk considerations and building architectures that consider the security implications of the entire virtualization life cycle.&lt;/p&gt;

&lt;p&gt;Overall, the virtualizations security panel was entertaining and insightful.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</description>
         <link>http://blog.ncircle.com/blogs/sync/archives/2009/04/rsa_virtualization_security_pa.html</link>
         <guid>http://blog.ncircle.com/blogs/sync/archives/2009/04/rsa_virtualization_security_pa.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">RSA 2009</category>
        
                  <category domain="http://www.sixapart.com/ns/types#tag">andrew storms</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">risk</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">rsa</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">rsacon</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">security</category>
                  <category domain="http://www.sixapart.com/ns/types#tag">virtualization</category>
        
         <pubDate>Thu, 23 Apr 2009 15:31:50 -0800</pubDate>
      </item>
      
   </channel>
</rss>
