<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>The Lens</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/" />
   <link rel="self" type="application/atom+xml" href="http://blog.ncircle.com/blogs/the-lens/atom.xml" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens/4</id>
   <updated>2008-06-10T20:59:49Z</updated>
   
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 3.35</generator>

<entry>
   <title>iPhone 2.0 is Less Secure</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/06/iphone_20_is_less_secure.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.479</id>
   
   <published>2008-06-10T20:13:31Z</published>
   <updated>2008-06-10T20:59:49Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
There&apos;s nothing quite as effective for illustrating a point than a top n list. Here are the top 4 reasons that the new iPhone is less secure than the previous version. 4. The Price How could the price make the...
   </content>
</entry>
<entry>
   <title>A Virtual Advantage</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/05/a_virtual_advantage.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.478</id>
   
   <published>2008-05-28T17:24:25Z</published>
   <updated>2008-05-28T17:43:12Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
First, the article. Second, the salient quote so that you don&apos;t really have to read said article: &quot;If you are getting any benefit from Microsoft&apos;s software, you need to have a license, whether that benefit is for physical machines or...
   </content>
</entry>
<entry>
   <title>Secure360 Conference</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/05/secure360_conference.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.476</id>
   
   <published>2008-05-12T17:00:46Z</published>
   <updated>2008-05-12T17:19:17Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
I&apos;m headed to the Secure360 Conference in St. Paul tomorrow and Wednesday. Despite the name, it doesn&apos;t have anything in particular to do with IP360 or nCircle. I attended this show last year and it was pretty valuable if you&apos;re...
   </content>
</entry>
<entry>
   <title>It&apos;s Not Always About You</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/04/its_not_always_about_you_1.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.463</id>
   
   <published>2008-04-02T14:07:32Z</published>
   <updated>2008-04-02T15:00:40Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
Earlier this week, someone asked me this question: &quot;What should the PCI Council be working on next to protect card holder data?&quot; I thought about this for a while, and decided that the only honest answer is nothing. I will...
   </content>
</entry>
<entry>
   <title>But I Egress...</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/03/but_i_egress.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.462</id>
   
   <published>2008-03-31T12:20:50Z</published>
   <updated>2008-03-31T12:31:18Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
We&apos;re often so focused on who is getting into our infrastructure that we forget about who or what might be getting out. It&apos;s a natural tendency, of course, given the focus that InfoSec has traditionally had, and given that we...
   </content>
</entry>
<entry>
   <title>It&apos;s not about technology</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/03/its_not_about_technology_1.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.459</id>
   
   <published>2008-03-17T13:46:14Z</published>
   <updated>2008-03-18T15:32:45Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
Sometimes we all need a reminder of the obvious. This article from Infoworld reminded me of something I&apos;d learned a while back and recently forgotten: Information Security is not about technology. &quot;Ultimately, the most significant point of disconnect between security...
   </content>
</entry>
<entry>
   <title>MDI DSS: The Next Regulatory Front?</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2008/03/mdi_dss_the_next_regulatory_fr.html" />
   <id>tag:blog.ncircle.com,2008:/blogs/the-lens//4.458</id>
   
   <published>2008-03-12T20:29:17Z</published>
   <updated>2008-03-12T20:46:34Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
It&apos;s a wonderful thing that a doctor can wirelessly reprogram a pacemaker for a patient to deliver better care. It seems quite odd to me, however, that no one thought to protect the connection with authentication and encryption. That being...
   </content>
</entry>
<entry>
   <title>Old Skool is Still Cool</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/07/old_skool_is_still_cool.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.430</id>
   
   <published>2007-07-23T16:27:40Z</published>
   <updated>2007-07-24T11:56:48Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
If you ever find yourself wondering if simple directory traversal vulnerabilities are still relevant in this day and age, go read about Fox News. It&apos;s unfortunate that we don&apos;t know, and probably won&apos;t know, how long this condition was present....
   </content>
</entry>
<entry>
   <title>The End Of The World (As We Know It)</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/05/the_end_of_the_world_as_we_kno.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.416</id>
   
   <published>2007-05-24T13:46:26Z</published>
   <updated>2007-05-24T15:07:10Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
On Tuesday I heard Marcus Ranum talk at the Secure360 show in St. Paul. His general premise, which I won&apos;t enumerate fully, was that market consolidation, increase in legislation, and the general lack of relationship between actual attacks and information...
   </content>
</entry>
<entry>
   <title>Headline Entertainment</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/05/headline_entertainment.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.414</id>
   
   <published>2007-05-16T19:11:49Z</published>
   <updated>2007-05-16T19:14:37Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
As I was paging through my RSS reader, I came across a pair of headlines that made me chuckle sitting next to each other: IBM, Symantec Tackle Compliance IBM loses tapes with employee personal info If you don&apos;t actually go...
   </content>
</entry>
<entry>
   <title>The Law of PCI</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/05/the_law_of_pci.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.412</id>
   
   <published>2007-05-15T16:43:35Z</published>
   <updated>2007-05-15T17:03:34Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
Texas has passed a bill that makes PCI compliance a law. You can check out the text of the legislation here. The bill allows a financial institution to &apos;bring an action&apos; against a business if they are in violation of...
   </content>
</entry>
<entry>
   <title>PCI: Is Compliance Really the Goal?</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/04/pci_is_compliance_really_the_g.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.403</id>
   
   <published>2007-04-23T14:40:11Z</published>
   <updated>2007-04-23T14:52:23Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
In reading this article from Dark Reading, which quotes a recent RSA survey about PCI compliance, I&apos;m struck by what seems like a missing component. The basic gist of the survey results is that while more than 50% of merchants...
   </content>
</entry>
<entry>
   <title>Bad Habits or Good Marketing</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/03/bad_habits_or_good_marketing.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.385</id>
   
   <published>2007-03-26T11:22:54Z</published>
   <updated>2007-03-26T11:41:36Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
Flixster wants you to give them access to your email accounts so that they can invite everyone from your address book to join Flixster. They do this by asking you to provide them with the password for those accounts. Read...
   </content>
</entry>
<entry>
   <title>PCI Confusion: What is Compliant?</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/03/pci_confusion_what_is_complian_1.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.384</id>
   
   <published>2007-03-23T20:16:55Z</published>
   <updated>2007-03-23T20:44:01Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
As you may have noted, nCircle recently introduced our Certified PCI Scan Service, which means that we achieved certification as an Approved Scanning Vendor from the PCI Security Standards Council. One of the requirements of PCI is that we score...
   </content>
</entry>
<entry>
   <title>Is Brand Damage a Myth?</title>
   <link rel="alternate" type="text/html" href="http://blog.ncircle.com/blogs/the-lens/archives/2007/03/is_brand_damage_a_myth.html" />
   <id>tag:blog.ncircle.com,2007:/blogs/the-lens//4.381</id>
   
   <published>2007-03-21T11:35:06Z</published>
   <updated>2007-03-21T17:57:55Z</updated>
   

   <author>
      <name>Tim Erlin</name>
      <uri>http://blog.ncircle.com/the-lens</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blog.ncircle.com/blogs/the-lens/">
Yesterday I saw a presentation from a sales rep of PointSec at a local ISSA meeting. Aside from the fact that it was, I suspect, largely a straight copy of their standard sales deck, there were a few interesting points,...
   </content>
</entry>

</feed>
