<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; General</title>
	<atom:link href="http://www.dlstrom.com/category/general/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 20 Dec 2011 17:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The &#8220;Compliance Equals Security&#8221; Trap</title>
		<link>http://www.dlstrom.com/2011/12/20/the-compliance-equals-security-trap/</link>
		<comments>http://www.dlstrom.com/2011/12/20/the-compliance-equals-security-trap/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 17:00:00 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=536</guid>
		<description><![CDATA[I was recently engaged to help remediate some exposures found during the preparation for PCI DSS compliance reporting. They had run an external vulnerability scan with Nessus so that they could find exposures and fix them before the &#8220;official&#8221; scan was run. Several vulnerabilities were found that would have caused the organization to fail their [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/12/20/the-compliance-equals-security-trap/" data-text="The &#8220;Compliance Equals Security&#8221; Trap" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/12/20/the-compliance-equals-security-trap/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>I was recently engaged to help remediate some exposures found during the preparation for PCI DSS compliance reporting. They had run an external vulnerability scan with Nessus so that they could find exposures and fix them before the &#8220;official&#8221; scan was run.</p>
<p>Several vulnerabilities were found that would have caused the organization to fail their external vulnerability scan. Many of the vulnerabilities were due to an open port on the server. Several cross-site scripting vulnerabilities were found. Sample code from one of the installed applications was publicly accessible.</p>
<p>As we were working through these issues, a common theme came up.</p>
<p style="text-align: center;"><strong>How do we fix Issue X so that we pass the scan?</strong></p>
<p>Now think about that a minute… Approaching the vulnerabilities with this attitude is kind of like fixing a flat tire with <a href="http://www.fixaflat.com/">Fix-A-Flat</a>. It may work, but you should still have the tire looked at by a professional.</p>
<p>Here&#8217;s a specific example from the vulnerability scan. Port 8080 was publicly available on the web server. Several vulnerabilities were found on 8080. It was suggested that we just block 8080 at the firewall. Sure that would work to keep the problems from being found in the external vulnerability scan. But is that the right fix? No.</p>
<p>The right fix was to harden the server by shutting down any unneeded services <em>and</em> to block an unneeded ports on the firewall <em>and</em> uninstall the sample code from the server <em>and</em> institute change control on servers and firewalls <em>and</em> …&#8230;</p>
<p>My final recommendation? Take steps to think beyond compliance requirements. Checkboxes and automated scans are helpful, but nothing replaces good analysis and testing. Meeting compliance requirements is a good starting point, but don&#8217;t omit really knowing the risks your organization faces.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/12/20/the-compliance-equals-security-trap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; Sept 4, 2011</title>
		<link>http://www.dlstrom.com/2011/09/04/what-ive-been-reading-sept-4-2011/</link>
		<comments>http://www.dlstrom.com/2011/09/04/what-ive-been-reading-sept-4-2011/#comments</comments>
		<pubDate>Sun, 04 Sep 2011 18:00:58 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=511</guid>
		<description><![CDATA[Some days are more interesting than others. Monday, August 29, 2011 Interestingly, I found nothing of real interest on the Internet today! Let&#8217;s see if Tuesday is any better&#8230; Tuesday, August 30, 2011 More research on global warming. I doubt Al Gore supports it. &#8211; Sun Causes Climate Change Shock According to Al Gore, climate [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/09/04/what-ive-been-reading-sept-4-2011/" data-text="What I&#8217;ve Been Reading &#8211; Sept 4, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/09/04/what-ive-been-reading-sept-4-2011/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Some days are more interesting than others.</p>
<p><strong>Monday, August 29, 2011</strong></p>
<p>Interestingly, I found nothing of real interest on the Internet today! Let&#8217;s see if Tuesday is any better&#8230;</p>
<p><strong>Tuesday, August 30, 2011</strong></p>
<p>More research on global warming. I doubt Al Gore supports it. &#8211; <a href="http://blogs.telegraph.co.uk/news/jamesdelingpole/100102296/sun-causes-climate-change-shock/">Sun Causes Climate Change Shock </a></p>
<p>According to Al Gore, climate change skeptics are racist. That&#8217;s an interesting leap of logic. &#8211; <a href="http://www.investors.com/NewsAndAnalysis/Article/583159/201108291855/Perry-Vs-Gore.htm">Perry Vs. Gore</a></p>
<p><strong>Wednesday, August 31, 2011</strong></p>
<p>Leaders should be willing to communicate, even when it is not required. This looks like a lesson that Cook has learned from Jobs. &#8211; <a href="http://www.cultofmac.com/like-steve-jobs-apple-ceo-tim-cook-also-responds-to-his-email/111374">Like Steve Jobs, Apple CEO Tim Cook Also Responds to His Email</a></p>
<p>APOD &#8211; <a href="http://apod.nasa.gov/apod/ap110831.html">Roll Cloud Over Wisconsin </a> &#8211; We had one of these pass through Manhattan a year ago. My youngest son took a picture of it. View it <a href="http://lifeinrileycounty.com/2010/09/picture-of-the-week-september-30-2010/">here</a>.</p>
<p>Determining the root cause can be difficult. Read this &#8211; <a href="http://informationsecurityhq.com/how-to-perform-a-root-cause-analysis/">How to perform a root cause analysis?</a></p>
<p><strong>Thursday, September 1, 2011</strong></p>
<p>This looks like Keynesian economics to me &#8211; <a href="http://www.gocomics.com/nonsequitur/2011/09/01">Non Sequitur for 9/1/11</a></p>
<p>The best quote from this article, &#8220;The way children are grouped, which now occurs by their &#8220;date of manufacture,&#8221; no longer makes sense.&#8221; &#8211; <a href="http://www.lethbridgeherald.com/local-news/schools-need-help-in-raising-todays-children-says-education-advocate-83111.html">Schools need help in raising today&#8217;s children, says education advocate</a></p>
<p>Pretty cool pictures of lightning <a href="http://www.digital-photography-school.com/15-spectacular-lightning-images">here</a></p>
<p>Small businesses have a problem. They often have no money to implement appropriate security controls. They should read <a href="http://twitter.com/#!/russelleubanks/status/109206116260519936">this tweet</a> from Russell Eubanks</p>
<p><strong>Friday, September 2, 2011</strong></p>
<p>I&#8217;ve always wondered about the Magic Eraser. Now I know&#8230; &#8211; <a href="http://home.howstuffworks.com/magic-eraser1.htm">How do magic erasers get rid of stains? </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/09/04/what-ive-been-reading-sept-4-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; August 28, 2011</title>
		<link>http://www.dlstrom.com/2011/08/28/what-ive-been-reading-august-28-2011/</link>
		<comments>http://www.dlstrom.com/2011/08/28/what-ive-been-reading-august-28-2011/#comments</comments>
		<pubDate>Sun, 28 Aug 2011 18:00:54 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=493</guid>
		<description><![CDATA[&#8217;tis the beginning of the new school year. My mind is on things like&#8230; Doing more with less Maximizing results while maintaining effort Reasonable protection So, here are the links of the week. Monday, August 22, 2011 Since my youngest is starting college today, this is of interest &#8211; Back to School: 15 Essential iOS [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/08/28/what-ive-been-reading-august-28-2011/" data-text="What I&#8217;ve Been Reading &#8211; August 28, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/08/28/what-ive-been-reading-august-28-2011/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>&#8217;tis the beginning of the new school year. My mind is on things like&#8230;</p>
<ul>
Doing more with less<br />
Maximizing results while maintaining effort<br />
Reasonable protection
</ul>
<p>So, here are the links of the week.</p>
<p><strong>Monday, August 22, 2011</strong></p>
<p>Since my youngest is starting college today, this is of interest &#8211; <a href="http://mashable.com/2011/08/17/iphone-apps-students/">Back to School: 15 Essential iOS Apps for Students</a></p>
<p><strong>Tuesday, August 23, 2011</strong></p>
<p>I really hope this is true. Maybe it would help Verizon lower their prices! &#8211; <a href="http://mashable.com/2011/08/23/sprint-to-get-iphone-5/">Sprint To Sell the iPhone 5 [REPORT]</a></p>
<p>Trying to achieve privacy and security in an open wireless network. Looks like some promising research &#8211; <a href="http://www.darkreading.com/authentication/167901072/security/news/231500516/baking-security-into-open-wifi-networks.html">Baking Security Into Open WiFi Networks</a></p>
<p><strong>Wednesday, August 24, 2011</strong></p>
<p>If you don&#8217;t have the time to do your own research (and very few of us do), there are many sources to help guide us in network security. Just one source is the NSA. Take a look at this guide that was referenced recently in a <a href="http://www.sans.org/newsletters/#newsbites">SANS NewsBites</a> newsletter. &#8211; <a href="http://www.nsa.gov/ia/_files/factsheets/Best_Practices_Datasheets.pdf">Best Practices for Keeping Your Home Network Secure</a></p>
<p>With winter coming, I&#8217;m hoping that someone I know will get one of these &#8211; <a href="http://www.etsy.com/listing/69898584/knit-vulcan-hat">Knit Vulcan Hat</a></p>
<p>This is not good for the reputation of being secure by default &#8211; <a href="http://www.h-online.com/security/news/item/Mac-OS-X-Lion-fails-to-check-passwords-when-authenticating-via-LDAP-1328704.html">Mac OS X Lion fails to check passwords when authenticating via LDAP</a></p>
<p>Have you read <a href="http://www.amazon.com/Edge-Disaster-Rebulding-Resilient-ebook/dp/B000OI0FSK/ref=dp_kinw_strp_1?ie=UTF8&#038;m=AG56TWVU5XWC2">The Edge of Disaster</a> by Stephen Flynn? Yesterday&#8217;s earthquake reminds me of examples from Flynn &#8211; <a href="http://www.csoonline.com/article/688492/aging-east-coast-infrastructure-a-concern-after-quake">Aging East Coast Infrastructure a Concern After Quake</a></p>
<p><strong>Thursday, August 25, 2011</strong></p>
<p>As they say in Star Trek Land, all good things&#8230; &#8211; <a href="http://daily.inc.com/2011/08/24/steve-jobs-apple-ceo-steps-down/">Steve Jobs, Apple CEO, steps down</a></p>
<p>Universities seem to be a ripe environment for personal information to be lost. It&#8217;s interesting that an individual in the article blames Google for changing the way they find servers and documents. I think the real question should ask why are the universities not doing a better job of protecting the personal information of the students and staff, and why are they not aging information out of their systems. &#8211; <a href="http://www.huffingtonpost.com/2011/08/24/yale-social-security-numbers-google-hacking_n_935400.html">Yale Social Security Numbers Exposed In Latest Case Of &#8216;Google Hacking&#8217; </a></p>
<p>If you use Facebook, you need to read this <a href="https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf">Guide to Facebook Security</a>.</p>
<p>I would be glad to take your contributions toward the purchase of the <a href="http://www.logos.com/product/9653/nelson-bible-reference-bundle">Nelson Bible Reference Bundle</a> from <a href="http://www.logos.com">Logos</a>.</p>
<p><strong>Friday, August 26, 2011</strong></p>
<p>Khan Academy looks to provide a series of academic videos. It is heavy on math and science. Take a look and see if it could help your student. &#8211; <a href="http://www.khanacademy.org/">Khan Academy</a></p>
<p>Along the educational lines, I came across this article talking about Skype&#8217;s initiatives to connect teachers. Examples are given. If you are an educator, you should evaluate this to see if there might be application for you. &#8211; <a href="http://mashable.com/2011/03/30/skype-in-the-classroom/">Skype Launches a Dedicated Network for Teachers</a></p>
<p>You&#8217;ve got to read this &#8211; <a href="http://online.wsj.com/article/SB10001424053111903596904576516412073445854.html">Keynesian Economics vs. Regular Economics</a>. If you get blocked by the WSJ paywall, then google &#8220;Keynesian Economics vs. Regular Economics&#8221; and find the cached copy from Google. Either way, it really helps understand what is driving the Obama administration.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/08/28/what-ive-been-reading-august-28-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; August 14, 2011</title>
		<link>http://www.dlstrom.com/2011/08/14/what-ive-been-reading-august-14-2011/</link>
		<comments>http://www.dlstrom.com/2011/08/14/what-ive-been-reading-august-14-2011/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 18:00:45 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=462</guid>
		<description><![CDATA[Here&#8217;s this week&#8217;s list o&#8217; links that I found interesting&#8230; Monday, August 8, 2011 This has some very serious implications &#8211; Black Hat hacker details lethal wireless attack on insulin pumps This is on my to-do list of things to watch &#8211; Off Topic: Creating Metasploit Exploit Modules Step By Step (Tutorial!) Every system and/or [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/08/14/what-ive-been-reading-august-14-2011/" data-text="What I&#8217;ve Been Reading &#8211; August 14, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/08/14/what-ive-been-reading-august-14-2011/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Here&#8217;s this week&#8217;s list o&#8217; links that I found interesting&#8230;</p>
<p><strong>Monday, August 8, 2011</strong></p>
<p>This has some very serious implications &#8211; <a href="http://www.extremetech.com/extreme/92054-black-hat-hacker-details-wireless-attack-on-insulin-pumps">Black Hat hacker details lethal wireless attack on insulin pumps</a></p>
<p>This is on my to-do list of things to watch &#8211; <a href="http://it-audit.sans.org/blog/2010/01/04/off-topic-creating-metasploit-exploit-modules-step-by-step-tutorial/">Off Topic: Creating Metasploit Exploit Modules Step By Step (Tutorial!)</a></p>
<p>Every system and/or network administrator should become familiar with these tools &#8211; <a href="http://www.cio.com/article/686847/15_Incredibly_Useful_and_Free_Microsoft_Tools_for_IT_Pros">15 Incredibly Useful (and Free) Microsoft Tools for IT Pros</a></p>
<p>Not long ago I wrote about <a href="http://www.dlstrom.com/2011/07/27/you-want-a-tablet-but-android-or-ios/">choosing an Android or iOS tablet</a>. Here is an article discussing low-cost options &#8211; <a href="http://www.computerworld.com/s/article/9218967/What_300_or_less_buys_in_a_tablet">What $300 or less buys in a tablet</a></p>
<p><strong>Tuesday, August 9, 2011</strong></p>
<p>I&#8217;ve found the <a href="http://windowssecrets.com/">Windows Secrets</a> newsletter useful for several years. You probably will, too. They have a free edition and a paid edition.</p>
<p>Wow. This is sobering and awe-inspiring. You&#8217;ve got to take the time to work your way through each installment as it is published. &#8211; <a href="http://www.theatlantic.com/infocus/ww2.html">World War II in Photos</a></p>
<p>From Dave Hoelzer&#8230; <a href="http://it-audit.sans.org/blog/2009/01/20/you-might-be-compliant-but-are-you-secure">You Might Be Compliant&#8230; But Are You Secure??</a>. This isn&#8217;t a new post, but it is still relevant. I&#8217;ve been thinking about this very thing as I work through the PCI DSS.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/08/14/what-ive-been-reading-august-14-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; August 7, 2011</title>
		<link>http://www.dlstrom.com/2011/08/07/what-ive-been-reading-august-7-2011/</link>
		<comments>http://www.dlstrom.com/2011/08/07/what-ive-been-reading-august-7-2011/#comments</comments>
		<pubDate>Sun, 07 Aug 2011 18:00:05 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=448</guid>
		<description><![CDATA[Here are some things I&#8217;ve found interesting this past week&#8230; Monday, August 1, 2011 10 things I learnt from Daily Shooting &#8211; http://shoottokyo.com/daily-shooting/ I thought I had a great idea, then I found that someone else is already aggregating government contract opportunities. This is but one place I found &#8211; State &#038; Local Government and [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/08/07/what-ive-been-reading-august-7-2011/" data-text="What I&#8217;ve Been Reading &#8211; August 7, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/08/07/what-ive-been-reading-august-7-2011/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Here are some things I&#8217;ve found interesting this past week&#8230;</p>
<p><strong>Monday, August 1, 2011</strong></p>
<p><em>10 things I learnt from Daily Shooting</em> &#8211; <a href="http://shoottokyo.com/daily-shooting/">http://shoottokyo.com/daily-shooting/</a></p>
<p>I thought I had a great idea, then I found that someone else is already aggregating government contract opportunities. This is but one place I found &#8211; <em>State &#038; Local Government and Contract Opportunities</em> &#8211; <a href="http://www.govcb.com/">http://www.govcb.com/</a></p>
<p>Some people do find them valuable. &#8211; <em>Do Facebook Ads Bring Customers?</em> &#8211; <a href="http://www.inc.com/howard-greenstein/do-facebook-ads-bring-customers.html">http://www.inc.com/howard-greenstein/do-facebook-ads-bring-customers.html</a></p>
<p>I bought an external drive that was listed at USB 3.0 and compatible with USB 2.0. The first thing I noticed was a difference in the cable. So I headed to Wikipedia &#8211; <a href="http://en.wikipedia.org/wiki/USB_3.0">http://en.wikipedia.org/wiki/USB_3.0</a></p>
<p><strong>Tuesday, August 2, 2011</strong></p>
<p>Years ago, I had a friend who was always providing strange facts. Seems like that friend has been replaced by the Internet. &#8211; <em>What lives Inside Your Navel?</em> &#8211; <a href="http://news.discovery.com/human/belly-button-organisms-110801.html">http://news.discovery.com/human/belly-button-organisms-110801.html</a></p>
<p>From the Freakonomics folks&#8230; &#8211; <em>What Does Your Web Browser Say About Your I.Q.? (Hint: I.E. Users Won’t Like the Answer)</em> &#8211; <a href="http://www.freakonomics.com/2011/08/02/what-does-your-web-browser-say-about-your-i-q-hint-i-e-users-wont-like-the-answer/">http://www.freakonomics.com/2011/08/02/what-does-your-web-browser-say-about-your-i-q-hint-i-e-users-wont-like-the-answer/</a></p>
<p>This is pretty interesting &#8211; <em>Getting Bin Laden</em> &#8211; <a href="http://www.newyorker.com/reporting/2011/08/08/110808fa_fact_schmidle">http://www.newyorker.com/reporting/2011/08/08/110808fa_fact_schmidle</a></p>
<p>I enjoy reading what David Pogue writes. &#8211; <em>The Perils of Copy Protection</em> &#8211; <a href="http://www.scientificamerican.com/article.cfm?id=the-perils-of-copy-protection">http://www.scientificamerican.com/article.cfm?id=the-perils-of-copy-protection</a></p>
<p><strong>Wednesday, August 3, 2011</strong></p>
<p>What if he had succeeded? &#8211; <a href="http://hosted.ap.org/dynamic/stories/E/EU_SWEDEN_NUCLEAR?SITE=AP&#038;SECTION=HOME&#038;TEMPLATE=DEFAULT&#038;CTIME=2011-08-03-11-33-45">Swedish man caught trying to split atoms at home</a></p>
<p><strong>Thursday, August 4, 2011</strong></p>
<p>Some days I just feel old. Dilbert doesn&#8217;t help. &#8211; <a href="http://dilbert.com/strips/comic/2011-08-03/">http://dilbert.com/strips/comic/2011-08-03/</a></p>
<p>I don&#8217;t agree with some of this, but it is worthy of thought &#8211; <a href="http://erratasec.blogspot.com/2011/08/white-hats-are-not-on-same-of-law-but.html">White-hats are on the side of law, but not order</a></p>
<p>I&#8217;ve been using BackTrack 4 and a separate install for Nessus. Nessus is installed in BackTrack 5. Here&#8217;s how to begin using it. &#8211; <a href="http://blog.tenablesecurity.com/2011/07/enabling-nessus-on-backtrack-5-the-official-guide.html">Enabling Nessus on BackTrack 5 &#8211; The Official Guide</a></p>
<p>This is almost enough to make me subscribe to GigaOM Pro just so I can read more information &#8211; <a href="http://gigaom.com/cleantech/a-sneak-peek-into-googles-servers-energy-efficiency/">A sneak peek into Google’s servers and energy efficiency</a></p>
<p><strong>Friday, August 5, 2011</strong></p>
<p>Some folks I know can relate to this &#8211; <a href="http://aprogrammerslife.info/2011/08/03/are-you-a-programmer/">Are You a Programmer?</a></p>
<p>This is pretty cool &#8211; <a href="http://sports.yahoo.com/nfl/blog/shutdown_corner/post/Steelers-coach-sells-Mercedes-to-team-cafeteria-?urn=nfl-wp4503">Steelers coach sells Mercedes to team cafeteria worker for $20</a></p>
<p>We, too, have seen an increase in the cost of detection and recovery following an incident &#8211; <a href="http://www.infosecurity-magazine.com/view/19905/the-cost-of-cyber-attacks-is-up-56-study-reveals/">The cost of cyber attacks is up 56%, study reveals</a></p>
<p>Many people claim creativity. How many of these characteristics do you possess? &#8211; <a href="https://plus.google.com/112726038360301567381/posts/9WBjjeQUCh6">9 Attitudes of Highly Creative People</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/08/07/what-ive-been-reading-august-7-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; July 31, 2011</title>
		<link>http://www.dlstrom.com/2011/07/31/what-ive-been-reading-july-31-2011-2/</link>
		<comments>http://www.dlstrom.com/2011/07/31/what-ive-been-reading-july-31-2011-2/#comments</comments>
		<pubDate>Sun, 31 Jul 2011 18:00:21 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=431</guid>
		<description><![CDATA[Things I found interesting this past week&#8230; Monday, July 25, 2011 Now, if only Washington could resolve the debt ceiling and budget cuts issues&#8230; &#8211; Agreement in place; players will vote once document is done &#8211; http://www.nfl.com/news/story/09000d5d820f4c7f/article/with-agreement-in-place-players-will-vote-once-document-is-completed This is one reason why I choose to use a Mac &#8211; McDonalds Wi-Fi Guide Once again, those [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/07/31/what-ive-been-reading-july-31-2011-2/" data-text="What I&#8217;ve Been Reading &#8211; July 31, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/07/31/what-ive-been-reading-july-31-2011-2/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Things I found interesting this past week&#8230;</p>
<p><strong>Monday, July 25, 2011</strong></p>
<p>Now, if only Washington could resolve the debt ceiling and budget cuts issues&#8230; &#8211; <em>Agreement in place; players will vote once document is done</em> &#8211; <a href="http://www.nfl.com/news/story/09000d5d820f4c7f/article/with-agreement-in-place-players-will-vote-once-document-is-completed">http://www.nfl.com/news/story/09000d5d820f4c7f/article/with-agreement-in-place-players-will-vote-once-document-is-completed</a></p>
<p>This is one reason why I choose to use a Mac &#8211; <a href="http://s3.amazonaws.com/twitpic/photos/full/354952917.jpg?AWSAccessKeyId=AKIAJF3XCCKACR3QDMOA&#038;Expires=1311610210&#038;Signature=nG7JSsmlCcRY6OR55zTv%2Bb1QdD4%3D">McDonalds Wi-Fi Guide</a></p>
<p>Once again, those British newspapers tell us what we already know. I would have almost expected this in <a href="http://www.theonion.com">The Onion</a> &#8211; <em>Monday mornings so depressing you won&#8217;t crack a smile until 11.16am</em> &#8211; <a href="http://www.telegraph.co.uk/news/newstopics/howaboutthat/8658968/Monday-mornings-so-depressing-you-wont-crack-a-smile-until-11.16am.html">http://www.telegraph.co.uk/news/newstopics/howaboutthat/8658968/Monday-mornings-so-depressing-you-wont-crack-a-smile-until-11.16am.html</a></p>
<p>Here&#8217;s another list of mistakes we make in information security &#8211; <em>The 5 biggest IT security mistakes</em> &#8211; <a href="http://www.networkworld.com/news/2011/072511-security-mistakes.html">http://www.networkworld.com/news/2011/072511-security-mistakes.html</a></p>
<p><strong>Tuesday, July 26, 2011</strong></p>
<p>By correlating information from disparate sources, you can infer much. This article shows that it is not just Google, Twitter and FaceBook that have private information about us, but the credit card companies do also. Seems like the privacy horse left the barn sometime in the 1980s&#8230; &#8211; <em>Amex knows what you do not</em> &#8211; <a href="http://www.stephencolman.com.au/blog/2011/07/14/amex-knows-what-you-do-not/">http://www.stephencolman.com.au/blog/2011/07/14/amex-knows-what-you-do-not/</a></p>
<p>We&#8217;re hurting, but someone else is hurting worse. That always makes it better, right? &#8211; <em>Apple COO Says iPads Are Hurting Mac SalesBut, he adds, they&#8217;re hurting Windows even more</em> &#8211; <a href="http://technology.inc.com/2011/07/26/apple-coo-says-ipads-are-hurting-mac-sales/">http://technology.inc.com/2011/07/26/apple-coo-says-ipads-are-hurting-mac-sales/</a></p>
<p><strong>Wednesday, July 27, 2011</strong></p>
<p>Years ago, an old friend give me advice similar to #10 &#8211; <em>10 Public Speaking Tips For Introverts</em> &#8211; <a href="http://www.psychologytoday.com/blog/quiet-the-power-introverts/201107/10-public-speaking-tips-introverts">http://www.psychologytoday.com/blog/quiet-the-power-introverts/201107/10-public-speaking-tips-introverts</a></p>
<p>Another interesting perspective for my job-seeking friends &#8211; <em>A Simple Strategy for Acing a Job Interview</em> &#8211; <a href="http://blogs.cio.com/careers/16404/simple-strategy-acing-job-interview">http://blogs.cio.com/careers/16404/simple-strategy-acing-job-interview</a></p>
<p><strong>Thursday, July 28, 2011</strong></p>
<p>And now for some good news from Arlan at Farm Futures &#8211; <a href="http://twitter.com/#!/ArlanFF101/status/96569600552091648">Unemployment claims drop</a></p>
<p>This would seem &#8211; <em>Restaurant Breach Leads to Fraud</em> &#8211; <a href="http://www.bankinfosecurity.com/articles.php?art_id=3899">http://www.bankinfosecurity.com/articles.php?art_id=3899</a></p>
<p>Google+ is forcing Facebook to advance in many ways. This is new &#8211; <em>Facebook for Business</em> &#8211; <a href="https://www.facebook.com/business">https://www.facebook.com/business</a></p>
<p>I enjoy the photography tips and ideas from Kent Weakley. This one is especially important for the non-professional photographer who primarily uses the lens that came with the camera body &#8211; <em>5 Ways to Max Out Your Kit Lens</em> &#8211; <a href="http://kentweakley.com/blog/5-ways-max-out-kit-lens/">http://kentweakley.com/blog/5-ways-max-out-kit-lens/<br />
</a></p>
<p>BibleReader on iOS is one of the most used applications I have on my iPad2. I learned some things from these videos &#8211; <em>BibleReader 5 Video Tutorials &#038; Reviews</em> &#8211; <a href="http://olivetree.com/learningcenter/br5/">http://olivetree.com/learningcenter/br5/</a></p>
<p><strong>Friday, July 28, 2011</strong></p>
<p>Brian Krebs has some good advice here &#8211; <em>Is Your Voicemail Wide Open?</em> &#8211; <a href="http://krebsonsecurity.com/2011/07/is-your-voicemail-wide-open/">http://krebsonsecurity.com/2011/07/is-your-voicemail-wide-open/</a></p>
<p>It feels good to reminisce a little about the Good Old Days &#8211; <em>MS-DOS Turns 30: PCMag&#8217;s Original Interview With Bill Gates</em> &#8211; <a href="http://www.pcmag.com/article2/0,2817,2389282,00.asp">http://www.pcmag.com/article2/0,2817,2389282,00.asp</a></p>
<p>No surprise here &#8211; Most organizations do not follow security best practices, survey finds &#8211; <a href="http://www.infosecurity-us.com/view/19737/most-organizations-do-not-follow-security-best-practices-survey-finds/">http://www.infosecurity-us.com/view/19737/most-organizations-do-not-follow-security-best-practices-survey-finds/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/07/31/what-ive-been-reading-july-31-2011-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You want a tablet, but Android or iOS?</title>
		<link>http://www.dlstrom.com/2011/07/27/you-want-a-tablet-but-android-or-ios/</link>
		<comments>http://www.dlstrom.com/2011/07/27/you-want-a-tablet-but-android-or-ios/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 18:00:56 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Tablet]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=401</guid>
		<description><![CDATA[It&#8217;s July and folks are starting to think about Christmas?? That must be the case, because I&#8217;ve had two people in the last week ask me what tablet they should buy their spouse for Christmas. My standard answer is &#8230; It depends Let me make it clear that I try to remain relatively agnostic when [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/07/27/you-want-a-tablet-but-android-or-ios/" data-text="You want a tablet, but Android or iOS?" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/07/27/you-want-a-tablet-but-android-or-ios/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>It&#8217;s July and folks are starting to think about Christmas?? That must be the case, because I&#8217;ve had two people in the last week ask me what tablet they should buy their spouse for Christmas. My standard answer is &#8230;</p>
<p style="text-align: center;">It depends</p>
<p style="text-align: left;">Let me make it clear that I try to remain relatively agnostic when answering that question. You see, I currently run an Android cell phone, use an iPad2, have a 2006 model MacBook, and am writing this post on a Windows 7 desktop computer. I have used Windows Mobile cell phones and an iPhone 3. I have virtual machines running a variety of Linux distributions.</p>
<p style="text-align: left;">To put it mildly, I have some personal preferences, but mostly care about using a product that works.</p>
<p style="text-align: left;">When talking to most people, I avoid any discussion of the technical and marketing merits of one product over another. Sure, we could discuss the encryption found on iOS. Or, we could discuss the malicious apps that have found their way into the Android Market. Or, we could talk about more developers writing for Android (or, iOS depending on which industry pundit you read). Or we could discuss the merits (or problems) of the protections used by Apple before they let an app be included in the App Store. Or, we could get into a deep philosophical discussion of whether iOS is closed or open and whether Android is any different.</p>
<p style="text-align: left;">Most people simply care about 2 things &#8211; <strong>cost</strong> and <strong>usability</strong>.</p>
<p style="text-align: left;"><strong>Cost</strong> is really a non-issue when considering the choice for a tablet. If someone really wants a low-end tablet, they can get a Nook and flash cyanogenmod onto it. That makes a remarkably usable tablet for around $250. The difficulty I see with recommending this option is that most consumers simply lack the technical know-how to successfully do this. Another low-cost option is one of the Android tablets with a resistive screen. These are generally under-powered, and the entire user-experience is painful. They just do not meet expectations.</p>
<p style="text-align: left;">To achieve the expectations that almost everyone has, you need to be prepared to spend $500+ for a useful tablet. The low-end WiFi-only tablets for both Android and iOS/iPad2 start there. A recent circular from Best Buy shows the Toshiba Thrive for $479. That is only $20 less than the comparably equipped 16GB iPad2. The way I see it, cost is a non-issue when making a decision.</p>
<p style="text-align: left;">So, if cost is not a significant differentiator, then how about the <strong>user experience</strong>? Here&#8217;s what I tell inquirers&#8230;</p>
<ul>
<li>They are both similar with how applications are started. You press the application icon and the application starts in the foreground.</li>
<li>Both are multi-tasking. To see running applications on iOS, you double-press the only button on the front of the unit. To see running apps on Android, you long-press the Home button. With both you can quickly go to another running application. Note that there are some folks who will argue that one or the other is better with multi-tasking. I don&#8217;t know a single non-technical consumer who really cares!</li>
<li>Both have a way to download more apps onto the device. Both processes work well. There are similar apps for both platforms.</li>
<li>Both devices can be used quite effectively.</li>
</ul>
<p>But, there are some differences&#8230;</p>
<ul>
<li>If Flash websites are important to them, then they should look to the Android platform. iOS does not support Flash. In my experience this is becoming less and less of an issue for most people.</li>
<li>iOS devices (iPad and iPhone) currently require a connection to iTunes running either Mac OS X or Windows in order to set up the device. This will no longer be an issue once iOS 5 is released later this year. But for now Android is the only one that is truly stand-alone.</li>
<li>It seems to me that the iOS interface is simpler and more understandable for the non-technical user. Android makes use of pop-up menus throughout, and iOS generally does not.</li>
<li>Deleting an application from iOS is simpler than deleting from Android. On iOS you simply long-press an app and it starts jiggling with a red X. Press the red X and the application is gone. On Android, you have to press the <strong>Menu</strong> button on the home screen, then choose <strong>Settings</strong>. After that, select <strong>Applications</strong> and then <strong>Manage Applications</strong>. Select the application you want to delete and then choose <strong>Uninstall</strong>. It&#8217;s a pretty cumbersome and non-user friendly process.</li>
<li>iOS versions are released regularly to all iPad/iPhone/iTouch devices as a result of the hardware coming from the same manufacturer. New Android units can be found with Android v2.2. Others have v2.3. Most tablets are now selling with v3. But, it is up to the device manufacturer to ensure that the lasted Android software is available for specific hardware.</li>
<li>All iOS devices look and feel the same. Many Android hardware manufacturers are customizing the Android experience rather than using stock Android. It becomes confusing for the consumer to have to understand the various versions.</li>
</ul>
<p>I find it interesting that almost everyone I know that is a hard-core Microsofty is also a hard-core Android fan.</p>
<p>So in the end I tell people that unless Flash support is a Killer App for them, they probably would be satisfied with either one.</p>
<p>And, then they always ask me my preference. I tell them that I bought my wife an iPad and she has not been disappointed.</p>
<p>Have fun!</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/07/27/you-want-a-tablet-but-android-or-ios/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; July 24, 2011</title>
		<link>http://www.dlstrom.com/2011/07/24/what-ive-been-reading-july-24-2011/</link>
		<comments>http://www.dlstrom.com/2011/07/24/what-ive-been-reading-july-24-2011/#comments</comments>
		<pubDate>Sun, 24 Jul 2011 18:00:30 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=384</guid>
		<description><![CDATA[Here are the stories I found interesting this past week. Monday, July 18, 2011 If you are still trying to figure out what to do with your iPad, read this &#8211; Top 5 Business Uses for the iPad &#8211; http://www.openforum.com/articles/top-5-business-uses-for-the-ipad Tuesday, July 19, 2011 I can honestly say that I&#8217;ve never, ever thought about this [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/07/24/what-ive-been-reading-july-24-2011/" data-text="What I&#8217;ve Been Reading &#8211; July 24, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/07/24/what-ive-been-reading-july-24-2011/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Here are the stories I found interesting this past week.</p>
<p><strong>Monday, July 18, 2011</strong></p>
<p>If you are still trying to figure out what to do with your iPad, read this &#8211; <em>Top 5 Business Uses for the iPad</em> &#8211; <a href="http://www.openforum.com/articles/top-5-business-uses-for-the-ipad">http://www.openforum.com/articles/top-5-business-uses-for-the-ipad</a></p>
<p><strong>Tuesday, July 19, 2011</strong></p>
<p>I can honestly say that I&#8217;ve never, ever thought about this &#8211; <em>How to avoid being eaten by lions</em> &#8211; <a href="http://bbcearth.posterous.com/how-to-avoid-being-eaten-by-lions#">http://bbcearth.posterous.com/how-to-avoid-being-eaten-by-lions#</a></p>
<p>Let&#8217;s see if there is any relationship between this and being eaten by lions &#8211; <em>The Contagious Smell of Fear In Information Security</em> &#8211; <a href="http://blog.zeltser.com/post/7787134857/smell-of-fear-in-infosec">http://blog.zeltser.com/post/7787134857/smell-of-fear-in-infosec</a></p>
<p>This obviously takes a great amount of work and attention to detail. I love the statement &#8220;Effective remediation means, identifying the &#8220;right&#8221; programs to patch, Stefan Frei, research analyst director of Secunia, told SCMagazineUS.com on Thursday.&#8221; &#8211; <em>Report says firms must rethink patching strategy</em> &#8211; <a href="http://www.scmagazineus.com/report-says-firms-must-rethink-patching-strategy/article/207478/">http://www.scmagazineus.com/report-says-firms-must-rethink-patching-strategy/article/207478/</a></p>
<p><strong>Wednesday, July 20, 2011</strong></p>
<p>I&#8217;m trying Real Hard not to make a cynical comment about this &#8211; <em>Bill Gates To Reinvent The Toilet</em> &#8211; <a href="http://mashable.com/2011/07/19/bill-gates-reinvent-toilet/">http://mashable.com/2011/07/19/bill-gates-reinvent-toilet/</a></p>
<p>Another example of small actions having a much larger impact &#8211; <em>Scientist: Tae Bo workout sent skyscraper shaking</em> &#8211; <a href="http://news.blogs.cnn.com/2011/07/19/scientist-tae-bo-workout-sent-skyscraper-shaking/">http://news.blogs.cnn.com/2011/07/19/scientist-tae-bo-workout-sent-skyscraper-shaking/</a></p>
<p>But they don&#8217;t really say Why? &#8211; <em>Apple iOS still rules, but Windows 7 Phone edges Android in user satisfaction</em> &#8211; <a href="http://www.networkworld.com/news/2011/071811-smartphone-preferences.html">http://www.networkworld.com/news/2011/071811-smartphone-preferences.html</a></p>
<p><strong>Thursday, July 21, 2011</strong></p>
<p>It is important to be aware and observant &#8211; <em>How to Avoid Being a Victim of ATM Skimming</em> &#8211; <a href="http://www.walletpop.com/2011/07/18/how-to-avoid-being-a-victim-of-atm-skimming/">http://www.walletpop.com/2011/07/18/how-to-avoid-being-a-victim-of-atm-skimming/</a></p>
<p>I enjoy reading David Pogue. Here&#8217;s his take on OS X Lion &#8211; <em>Upgrading to Lion Means Embracing the iPad</em> &#8211; <a href="http://www.nytimes.com/2011/07/21/technology/personaltech/the-usual-apple-upgrade-big-steps-forward-a-stumble-backward-state-of-the-art.html">http://www.nytimes.com/2011/07/21/technology/personaltech/the-usual-apple-upgrade-big-steps-forward-a-stumble-backward-state-of-the-art.html</a></p>
<p>Have you always wondered why there are so many standards in electronics, etc? &#8211; <em>How Standards Proliferate</em> &#8211; <a href="http://xkcd.com/927/">http://xkcd.com/927/</a></p>
<p><strong>Friday, July 22, 2011</strong></p>
<p>The space shuttle program starts and ends with Star Trek &#8211; Shuttle Era Ends – <em>Atlantis Welcomed Home To Star Trek Voyager Theme</em> &#8211; <a href="http://trekmovie.com/2011/07/21/shuttle-era-ends-atlantis-welcomed-home-with-star-trek-voyager-theme/">http://trekmovie.com/2011/07/21/shuttle-era-ends-atlantis-welcomed-home-with-star-trek-voyager-theme/</a></p>
<p>Do you suppose this dude has <a href="http://en.wikipedia.org/wiki/Little_man_syndrome">Little Man Syndrome</a>? &#8211; <em>Man Etches Name in Sand, Visible from Space</em> &#8211; <a href="http://news.discovery.com/space/big-pic-hamad-abu-dhabi-space-graffiti-110721.html">http://news.discovery.com/space/big-pic-hamad-abu-dhabi-space-graffiti-110721.html</a></p>
<p>For the job seekers &#8211; <em>Hacker hunters: Join the cyber security job boom</em> &#8211; <a href="http://tech.fortune.cnn.com/2011/07/22/hacker-hunters-join-the-cyber-security-job-boom/">http://tech.fortune.cnn.com/2011/07/22/hacker-hunters-join-the-cyber-security-job-boom/</a></p>
<p>&#8230; and those job seekers need to understand this &#8211; <em>The business-security disconnect that won&#8217;t die</em> &#8211; <a href="http://www.csoonline.com/article/686591/the-business-security-disconnect-that-won-t-die">http://www.csoonline.com/article/686591/the-business-security-disconnect-that-won-t-die</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/07/24/what-ive-been-reading-july-24-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The StillSecure PCI Calculator</title>
		<link>http://www.dlstrom.com/2011/07/19/the-stillsecure-pci-calculator/</link>
		<comments>http://www.dlstrom.com/2011/07/19/the-stillsecure-pci-calculator/#comments</comments>
		<pubDate>Wed, 20 Jul 2011 01:00:51 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=387</guid>
		<description><![CDATA[Last week I came across the PCI Calculator from StillSecure. I&#8217;ve since downloaded it and spent a bit of time with it. What are my impressions? I was expecting some sort of tool to help me with tracking and maintaining PCI compliance. I obviously read the StillSecure description and created a fictional meaning in my [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/07/19/the-stillsecure-pci-calculator/" data-text="The StillSecure PCI Calculator" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/07/19/the-stillsecure-pci-calculator/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Last week I came across the <a href="http://www.stillsecure.com/pcicomplete/calculator.php">PCI Calculator</a> from StillSecure. I&#8217;ve since downloaded it and spent a bit of time with it.</p>
<p>What are my impressions?</p>
<p>I was expecting some sort of tool to help me with tracking and maintaining PCI compliance. I obviously read the StillSecure description and created a fictional meaning in my own mind!</p>
<p>What I did get from StillSecure is a tool that is useful in helping to create budgets for the PCI compliance testing. It allows for using Gartner benchmarks for estimating costs for level 1-4 merchants by contracting the StillSecure PCI Complete service.</p>
<p>While I am not currently looking for a service to do PCI work, it is interesting to see the estimated savings. This is an option that I need to remember for the future.</p>
<p>As far as I know, I don&#8217;t know anyone at StillSecure, nor do I have any vested interest in the company. But should the time come when I need help with PCI compliance, the numbers in the PCI Calculator would make me want to include them in the RFP list. I guess that&#8217;s what a sales tool is supposed to do.</p>
<p>Keep yourself safe!<br />
-Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/07/19/the-stillsecure-pci-calculator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What I&#8217;ve Been Reading &#8211; July 15, 2011</title>
		<link>http://www.dlstrom.com/2011/07/18/what-ive-been-reading-july-15-2011/</link>
		<comments>http://www.dlstrom.com/2011/07/18/what-ive-been-reading-july-15-2011/#comments</comments>
		<pubDate>Mon, 18 Jul 2011 13:04:59 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=381</guid>
		<description><![CDATA[(I had some computer problems, so this is getting put up a couple of days late.) Here are some interesting links from the past couple of weeks&#8230; Tuesday, July 5, 2011 This is a welcome change in attitude &#8211; Apple to allow license-free virtualization with OS X Lion &#8211; http://www.engadget.com/2011/07/04/apple-to-allow-license-free-virtualization-with-os-x-lion-devel/ This is an interesting project [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/07/18/what-ive-been-reading-july-15-2011/" data-text="What I&#8217;ve Been Reading &#8211; July 15, 2011" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/07/18/what-ive-been-reading-july-15-2011/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>(I had some computer problems, so this is getting put up a couple of days late.)</p>
<p>Here are some interesting links from the past couple of weeks&#8230;</p>
<p><strong>Tuesday, July 5, 2011</strong><br />
This is a welcome change in attitude &#8211; Apple to allow license-free virtualization with OS X Lion &#8211; <a href="http://www.engadget.com/2011/07/04/apple-to-allow-license-free-virtualization-with-os-x-lion-devel/">http://www.engadget.com/2011/07/04/apple-to-allow-license-free-virtualization-with-os-x-lion-devel/</a></p>
<p>This is an interesting project &#8211; A month of sunrises over Chicago &#8211; <a href="http://vimeo.com/25999231">http://vimeo.com/25999231</a></p>
<p><strong>Wednesday, July 6, 2011</strong><br />
I found this analysis interesting &#8211; This Is The Connected States of America &#8211; <a href="http://www.good.is/post/this-is-the-connected-states-of-america/">http://www.good.is/post/this-is-the-connected-states-of-america/</a></p>
<p>I’m not really surprised to see this &#8211; Atlanta cheating scandal renews school reform debate &#8211; <a href="http://www.cbsnews.com/stories/2011/07/05/eveningnews/main20077025.shtml?tag=cbsnewsLeadStoriesAreaMain;cbsnewsLeadStoriesHeadlines">http://www.cbsnews.com/stories/2011/07/05/eveningnews/main20077025.shtml?tag=cbsnewsLeadStoriesAreaMain;cbsnewsLeadStoriesHeadlines</a></p>
<p>Although I’m not a fanboy of Facebook, this seems like a natural progression &#8211; Call Your Friends Right From Facebook &#8211; <a href="http://blog.facebook.com/blog.php?post=10150223135777131">http://blog.facebook.com/blog.php?post=10150223135777131</a></p>
<p><strong>Thursday, July 7, 2011</strong><br />
It takes work to make your web application security &#8211; Protecting your web apps from the tyrrany of evil with OWASP &#8211; <a href="http://www.troyhunt.com/2011/07/protecting-your-web-apps-from-tyranny.html">http://www.troyhunt.com/2011/07/protecting-your-web-apps-from-tyranny.html</a></p>
<p>Inc. has some good basic information on communication &#8211; How to Communicate in a Crisis &#8211; <a href="http://www.inc.com/guides/how-to-communicate-in-a-crisis.html">http://www.inc.com/guides/how-to-communicate-in-a-crisis.html</a></p>
<p>We’re told to do patches. But what if we can’t? &#8211; “There’s a Patch for that” (or maybe not) &#8211; <a href="http://isc.sans.org/diary.html?storyid=11170">http://isc.sans.org/diary.html?storyid=11170</a></p>
<p>Sometimes you have to pay for customers &#8211; Microsoft gives $250K to University of Nebraska to Use Office 365 &#8211; <a href="http://venturebeat.com/2011/07/05/microsoft-gives-250k-to-university-of-nebraska-to-use-office-365/">http://venturebeat.com/2011/07/05/microsoft-gives-250k-to-university-of-nebraska-to-use-office-365/</a></p>
<p><strong>Friday, July 8, 2011</strong><br />
The Droid 3 from Motorola looks like a sweet phone &#8211; <a href="http://www.verizonwireless.com/b2c/store/controller?item=phoneFirst&amp;action=viewPhoneDetail&amp;selectedPhoneId=5676&amp;deviceCategoryId=1">http://www.verizonwireless.com/b2c/store/controller?item=phoneFirst&amp;action=viewPhoneDetail&amp;selectedPhoneId=5676&amp;deviceCategoryId=1</a></p>
<p>I’ll be downloading this &#8211; PCI Calculator from StillSecure &#8211; <a href="http://www.stillsecure.com/pcicomplete/calculator.php">http://www.stillsecure.com/pcicomplete/calculator.php</a></p>
<p>First the Pope, and now the President &#8211; Obama tweets for first time &#8211; <a href="http://holykaw.alltop.com/obama-tweets-for-first-time">http://holykaw.alltop.com/obama-tweets-for-first-time</a></p>
<p>This reminds me of <a href="http://en.wikipedia.org/wiki/Death_By_Powerpoint">Death By PowerPoint</a> &#8211; Three Powerpoint slides to avoid &#8211; <a href="http://scotteblin.typepad.com/blog/2011/07/three-signs-that-your-slide-deck-stinks.html">http://scotteblin.typepad.com/blog/2011/07/three-signs-that-your-slide-deck-stinks.html</a></p>
<p>Printer produces personalized 3D chocolate &#8211; <a href="http://www.bbc.co.uk/news/technology-14030720">http://www.bbc.co.uk/news/technology-14030720</a></p>
<p><strong>Tuesday, July 12, 2011</strong><br />
For all my job seeking friends &#8211; 99 interview tips that will actually work &#8211; <a href="http://passivepanda.com/interview-tips">http://passivepanda.com/interview-tips</a></p>
<p>How many can you count in this picture? &#8211; The Perseus cluster of galaxies &#8211; <a href="http://apod.nasa.gov/apod/ap110712.html">http://apod.nasa.gov/apod/ap110712.html</a></p>
<p>I wonder how many industries have significant issues with employee theft, and what other solutions have been found &#8211; Pizza Hut saves dough with biometrics &#8211; <a href="http://planetbiometrics.com/article-details/i/708/">http://planetbiometrics.com/article-details/i/708/</a></p>
<p>I’ve got mixed feelings about this &#8211; Light bulb ban draws fire &#8211; <a href="http://money.cnn.com/2011/07/11/news/economy/light_bulb_ban">http://money.cnn.com/2011/07/11/news/economy/light_bulb_ban</a>/index.htm?iid=HP_LN</p>
<p>Get ready for &#8216;Manhattanhenge’ on July 13 &#8211; <a href="http://news.discovery.com/space/get-ready-for-manhattanhenge-july-13-110712.html">http://news.discovery.com/space/get-ready-for-manhattanhenge-july-13-110712.html</a></p>
<p>One Neptunian Year! &#8211; Hubble’s Neptune Anniversary Pictures &#8211; <a href="http://www.nasa.gov/mission_pages/hubble/science/neptune-circuit.html">http://www.nasa.gov/mission_pages/hubble/science/neptune-circuit.html</a></p>
<p><strong>Wednesday, July 13, 2011</strong><br />
U.S., Russia Make Cyber Security Pact &#8211; <a href="http://www.itbusinessedge.com/cm/community/news/gt/blog/us-russia-make-cyber-security-pact/?cs=47806">http://www.itbusinessedge.com/cm/community/news/gt/blog/us-russia-make-cyber-security-pact/?cs=47806</a></p>
<p><strong>Thursday, July 14, 2011</strong><br />
Pentagon Discloses Largest-Ever Cyber Theft &#8211; <a href="http://www.foxnews.com/politics/2011/07/14/pentagon-discloses-largest-ever-cyber-theft/">http://www.foxnews.com/politics/2011/07/14/pentagon-discloses-largest-ever-cyber-theft/</a></p>
<p><strong>Friday, July 15, 2011</strong><br />
Metasploit is the Hot Thing right now &#8211; Metasploit Payloads Explained &#8211; <a href="https://infosecisland.com/blogview/14893-Metasploit-Payloads-Explained-Part-1.html and https://www.infosecisland.com/blogview/14894-Metasploit-Payloads-Explained-Part-1-Continued.html">https://infosecisland.com/blogview/14893-Metasploit-Payloads-Explained-Part-1.html and https://www.infosecisland.com/blogview/14894-Metasploit-Payloads-Explained-Part-1-Continued.html</a></p>
<p>Another information security framework that I need to take a look at &#8211; OWASP Mantra &#8211; <a href="http://www.getmantra.com/">http://www.getmantra.com/</a></p>
<p>You should actively protect your identity. One way is to monitor your credit reports. The government passed a law in 2004 that requires the big three to provide an annual free report. &#8211; Free Annual Credit Report Law &#8211; <a href="http://idtheftcenter.blogspot.com/2011/03/federal-annual-free-credit-report-law.html">http://idtheftcenter.blogspot.com/2011/03/federal-annual-free-credit-report-law.html</a></p>
<p>Another example of 3D printing &#8211; 3D Printer &#8211; <a href="http://www.youtube.com/watch?v=ZboxMsSz5Aw">http://www.youtube.com/watch?v=ZboxMsSz5Aw</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/07/18/what-ive-been-reading-july-15-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

