<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec</title>
	<atom:link href="http://www.dlstrom.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 27 Jul 2010 13:26:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>19-1 Loss Is Not A Good Thing</title>
		<link>http://www.dlstrom.com/2010/07/27/19-1-loss-is-not-a-good-thing/</link>
		<comments>http://www.dlstrom.com/2010/07/27/19-1-loss-is-not-a-good-thing/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 13:26:01 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=334</guid>
		<description><![CDATA[Last night the Kansas City Royals lost a baseball game to the Minnesota Twins by a score of 19 to 1. That tied the worst loss in the teams history. Wow! I grew up listening to the Royals on the radio almost every night. Those were the days when the Royals were almost always in [...]]]></description>
			<content:encoded><![CDATA[<p>Last night the <a href="http://kansascity.royals.mlb.com/index.jsp?c_id=kc">Kansas City Royals</a> lost a baseball game to the <a href="http://minnesota.twins.mlb.com/index.jsp?c_id=min">Minnesota Twins</a> by a score of 19 to 1. That tied the worst loss in the teams history. Wow!</p>
<p>I grew up listening to the Royals on the radio almost every night. Those were the days when the Royals were almost always in contention for the top spot in their division, led by players with names like Otis, Rojas, White, Brett, Mayberry, Busby, and many others. That does not seem to be the case now&#8230;</p>
<p>I keep wondering how this can happen? Last night it came down to pitching and hitting. The Twins kept hitting everything that the Royals threw, and the Royals didn&#8217;t. Someone on the Twins roster hit his very first major league home run &#8211; and it was a grand slam! (not good) The inability of the Royals over the past 20 years to regain their former status comes down to execution by players and management.</p>
<p>Now, let&#8217;s take a leap over to the information security things that I normally write about.</p>
<p>Last night&#8217;s loss illustrates an important point that we all should remember. Unless we are <a href="http://www.dlstrom.com/2010/07/23/must-be-diligent-always/">diligent</a>, it is easy to allow gaps to appear in what we are doing to protect our networks and important information.</p>
<p>Just as there was a huge gap last night between what the Royals didn&#8217;t do and what the Twin did do, so there is often a big gap in our protection measures. We get busy doing stuff, and allow little holes to appear.</p>
<p>This easily happens regardless of industry. There are federal regulations and industry guidelines to help us do the right thing. But if we don&#8217;t regularly evaluate what we are practicing, then gaps appear.</p>
<ul>
<li>How long has it been since you have reviewed your firewall configuration?</li>
<li>How about reviewing your logs for suspicious activity?</li>
<li>When was the last time that your policies were reviewed? Do they still fit your organization?</li>
<li>Is your patch management plan being followed?</li>
<li>Are you doing vulnerability assessment? How about pen testing?</li>
<li>How do you ensure that your software developers are baking good security practices into their code?</li>
</ul>
<p>Thought should be given to these, and many more, questions about your security practices. The Bad Guys are constantly looking for gaps in your coverage.</p>
<p>Don&#8217;t let yourself develop gaps that are too big and costly to overcome. Don&#8217;t have a game like the Royals did last night.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/07/27/19-1-loss-is-not-a-good-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Must. Be. Diligent. Always.</title>
		<link>http://www.dlstrom.com/2010/07/23/must-be-diligent-always/</link>
		<comments>http://www.dlstrom.com/2010/07/23/must-be-diligent-always/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:00:01 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Data Leakage]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=332</guid>
		<description><![CDATA[I checked my email yesterday morning and was greeted with these three headlines: Employee at Maryland state agency posts client information online Sensitive database compromised at Buena Vista University Hospital: files with personal, medical data on 800,000 gone Whether a state agency, hospital or university, the issues are the same. Confidential information must remain confidential [...]]]></description>
			<content:encoded><![CDATA[<p>I checked my email yesterday morning and was greeted with these three headlines:</p>
<p><a href="http://www.scmagazineus.com/employee-at-maryland-state-agency-posts-client-information-online/article/174993/?DCMP=EMC-SCUS_Newswire">Employee at Maryland state agency posts client information online</a></p>
<p><a href="http://www.scmagazineus.com/sensitive-database-compromised-at-buena-vista-university/article/174988/?DCMP=EMC-SCUS_Newswire">Sensitive database compromised at Buena Vista University</a></p>
<p><a href="http://www.scmagazineus.com/hospital-files-with-personal-medical-data-on-800000-gone/article/174970/?DCMP=EMC-SCUS_Newswire">Hospital: files with personal, medical data on 800,000 gone</a></p>
<p>Whether a state agency, hospital or university, the issues are the same. Confidential information <strong>must</strong> remain confidential and there <strong>must</strong> be practices in place to maintain this confidentiality.</p>
<p>This is true for the small business, also.</p>
<p>I have heard many small business owners state that &#8220;no one would care about them&#8221;. This may have been correct in the past, but it is certainly no longer the case.</p>
<p>Policy statements, and enforcement of that policy, can be a significant deterrent to events such as are depicted in the above links.</p>
<p>Think about this: Who is in charge of updating the business website? Is only authorized information put on the Internet? Who is the one responsible for authorization?</p>
<p>Sometimes a file may accidentally get put on a web server. The contents of the web server should be a part of the regular audits.</p>
<p>Regardless of policy, breach and data loss events are usually a result of someone not being diligent.</p>
<p>I sure not would want to be the one responsible for any of these data loss events.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/07/23/must-be-diligent-always/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec Tip: Check Your Router Configuration!</title>
		<link>http://www.dlstrom.com/2010/07/22/infosec-tip-check-your-router-configuration/</link>
		<comments>http://www.dlstrom.com/2010/07/22/infosec-tip-check-your-router-configuration/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 14:01:01 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Home InfoSec]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=330</guid>
		<description><![CDATA[Most folks will not understand (or even care about) the details of the recently reported DNS rebind vulnerability. But this problem affects many of the low-end cable and DSL routers that are used in homes and small businesses. Even more alarming is that a tool to exploit this vulnerability is to be released at Black [...]]]></description>
			<content:encoded><![CDATA[<p>Most folks will not understand (or even care about) the details of the recently <a href="http://darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=225900016&amp;subSection=Vulnerabilities+and+threats">reported DNS rebind vulnerability</a>. But this problem affects many of the low-end cable and DSL routers that are used in homes and small businesses.</p>
<p>Even more alarming is that a tool to exploit this vulnerability is to be released at <a href="https://www.blackhat.com/">Black Hat 2010</a> in just a few days.</p>
<p>What can you do to protect yourself from this exploit?</p>
<ol>
<li>Change the administrative passwords on your routers. All of your routers come with a well-known default administrative password. You should connect to the router and make sure that you are not using the default. You should also use a complex password.</li>
<li>Disallow remote administration of the device. Many routers allow administrative access from the Internet. This should be allowed only in rare and well-defined situations. Although this is not directly related to the DNS rebind problems, you should still verify this setting.</li>
<li>Upgrade the firmware to the latest version available from the manufacturer. Most manufacturers put out updates to the firmware that is running on their routers. If you are not running the latest version of the firmware for the router, go get it from the manufacturer&#8217;s website and do the upgrade. This will protect you from other attacks.</li>
<li>If you are using wireless, be sure to use WPA2 to protect your wireless connections. I hope you are not using WEP. Using WPA2 is much better. (A technical explanation is beyond the scope of this post.)</li>
</ol>
<p>These steps will minimize the attack surface on your devices.</p>
<p>Good luck!</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/07/22/infosec-tip-check-your-router-configuration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Youth Safety on a Living Internet</title>
		<link>http://www.dlstrom.com/2010/06/28/youth-safety-on-a-living-internet/</link>
		<comments>http://www.dlstrom.com/2010/06/28/youth-safety-on-a-living-internet/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 14:05:47 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[K-12 Education]]></category>
		<category><![CDATA[NTIA]]></category>
		<category><![CDATA[OSTWG]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=324</guid>
		<description><![CDATA[Earlier in the month, the Online Safety and Technology Working Group within the NTIA submitted their report entitled Youth Safety on a Living Internet, along with their recommendations to the Dept of Commerce and members of the House and Senate. Here is a summary of the objectives of the report which is take directly from [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier in the month, the <a href="http://www.ntia.doc.gov/advisory/onlinesafety/">Online Safety and Technology Working Group</a> within the NTIA submitted their report entitled <a href="http://www.ntia.doc.gov/reports/2010/OSTWG_Final_Report_060410.pdf">Youth Safety on a Living Internet</a>, along with their recommendations to the Dept of Commerce and members of the House and Senate.</p>
<p>Here is a summary of the objectives of the report which is take directly from the introductory comments&#8230;</p>
<blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">On behalf of the Online Safety and Technology Working Group (OSTWG), we are pleased to transmit this report to you. As mandated, we reviewed and evaluated:</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">1.<span style="white-space: pre;"> </span>The status of industry efforts to promote online safety through educational efforts, parental control technology, blocking and filtering software, age-appropriate labels for content or other technologies or initiatives designed to promote a safe online environment for children;</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">2.<span style="white-space: pre;"> </span>The status of industry efforts to promote online safety among providers of electronic communications services and remote computing services by reporting apparent child pornography, including any obstacles to such reporting;</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">3.<span style="white-space: pre;"> </span>The practices of electronic communications service providers and remote computing service providers related to record retention in connection with crimes against children; and</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">4.<span style="white-space: pre;"> </span>The development of technologies to help parents shield their children from inappropriate material on the Internet.</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"> </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;">The report contains recommendations in each of the above categories, as well some general recommendations. We believe these recommendations will further advance our collective goal to provide a safer online experience to our children.﻿</p>
</blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; color: #1a1a18;"><span style="color: #000000;"><span style="font-size: medium;"><span style="color: #1a1a18;"><br /></span></span></span></p>
<p>This is an important document. If you have children, know children or are involved with kids at church or school you should take the time to read this report.</p>
<p>- Dan</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/06/28/youth-safety-on-a-living-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thoughts on integrity inspired by LIGATT</title>
		<link>http://www.dlstrom.com/2010/06/23/thoughts-on-integrity-inspired-by-ligatt/</link>
		<comments>http://www.dlstrom.com/2010/06/23/thoughts-on-integrity-inspired-by-ligatt/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 13:32:32 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[LIGATT]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=322</guid>
		<description><![CDATA[A lot of buzz has been generated recently as a result of charges and allegations against LIGATT Security and Gregory Evans. A recent article from The Register lists the major complaints. I don&#8217;t have any first-hand experience with or knowledge of LIGATT or Gregory Evans. However I find this whole discussion interesting, and it raises a [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of buzz has been generated recently as a result of charges and allegations against <a href="http://www.ligattsecurity.com/">LIGATT Security</a> and Gregory Evans. A recent article from <a href="http://www.theregister.co.uk/2010/06/22/worlds_no_1_hacker/">The Register</a> lists the major complaints.</p>
<p>I don&#8217;t have any first-hand experience with or knowledge of LIGATT or Gregory Evans. However I find this whole discussion interesting, and it raises a question for me.</p>
<p>What role does integrity play in the personal and professional life of an information security professional?</p>
<p>One of my professors at <a href="http://www.dts.edu/">Dallas Theological Seminary</a> once defined integrity as &#8220;doing what&#8217;s right even though no one is watching.&#8221; That has worked well for me.</p>
<p>I see these components of integrity at play in the LIGATT situation:</p>
<ul>
<li>
<p><strong>Permission</strong> &#8211; Evans is accused of plagiarism in a recent book. Multiple authors claim that he used their material without permission. A significant part of integrity, then is using other people&#8217;s work only with their express permission. It doesn&#8217;t matter if that work is written, or just ideas. You can&#8217;t take what you know is the work of someone else and use it with the claim that it is yours.</p>
</li>
<li>
<p><strong>Honesty</strong> &#8211; Evans is also accused of falsifying or mis-representing his time in prison and his relationship with Kevin Mitnick. If someone cannot be trusted to tell the truth about their life, then how can you count on them to honestly present facts and finding from their work. Many times we are put in positions where we have access to confidential information. We must be honest in all of our dealings.</p>
</li>
<li><strong>Disclosure</strong> &#8211; The temptation exists to withhold certain information, at times, in an effort to bolster a certain position. Negotiations with vendors or unions often rely on this ploy. Sometimes, we are tempted to withhold information from the boss, because the full disclosure might make us look bad. There may sometimes be legitimate reasons for not disclosing all information. Make sure that the reasons for this are legitimate, and not simply to make yourself look good.</li>
</ul>
<p>Like I said at the start, I don&#8217;t know Gregory Evans, nor do I have any experience with LIGATT. But, we all can learn some lessons from the recent flurry.</p>
<p>Let&#8217;s do our jobs with integrity, ok?</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/06/23/thoughts-on-integrity-inspired-by-ligatt/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Usability vs Security</title>
		<link>http://www.dlstrom.com/2010/06/01/usability-vs-security/</link>
		<comments>http://www.dlstrom.com/2010/06/01/usability-vs-security/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 06:00:00 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[InfoSec Function]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=319</guid>
		<description><![CDATA[We can&#8217;t let employees use an Android phone. It&#8217;s not enterprise-ready! A Mac? We don&#8217;t use those. Flash drives are not allowed here! We have all heard arguments like that. For as long as I&#8217;ve been active with information security, there has been tension between non-InfoSec folks and technology users. Users perspective &#8211; The tools [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>We can&#8217;t let employees use an Android phone. It&#8217;s not enterprise-ready!</strong></p>
<p style="text-align: center;"><strong>A Mac? We don&#8217;t use those.</strong></p>
<p style="text-align: center;"><strong>Flash drives are not allowed here!</strong></p>
<p>We have all heard arguments like that.</p>
<p>For as long as I&#8217;ve been active with information security, there has been tension between non-InfoSec folks and technology users.</p>
<p>Users perspective &#8211; The tools and devices that the company provides just are not good enough. I use a &lt;some device&gt; at home and it really would help me at my job. In fact, I&#8217;ve already started using it for some work activities&#8230;</p>
<p>InfoSec perspective &#8211; The consumer device may be Really Cool, but we haven&#8217;t done a security assessment on it yet. Can the data on it be encrypted? What about a remote wipe of the data? We&#8217;re not going to allow that on our corporate network&#8230;</p>
<p>And so the tension goes on and on and on.</p>
<p>What ever happened to technology being an enabler?</p>
<p>So, what role does Information Security play?</p>
<ul>
<li>Don&#8217;t allow unwanted traffic on the network.</li>
<li>Don&#8217;t allow unauthorized software on the workstation.</li>
<li>Don&#8217;t allow access to certain data.</li>
<li>Don&#8217;t allow unapproved devices.</li>
</ul>
<p>That&#8217;s all pretty negative, isn&#8217;t it? Here are some random thoughts about what we should be doing&#8230;</p>
<ul>
<li>Don&#8217;t forget that business exists for a reason. Our job is to help protect that business, not always to be like Nancy Reagan and &#8220;just say NO&#8221;.</li>
<li>Encourage personal responsibility to protect the business. It is the job of everyone.</li>
<li>Find out what the real deficiency is that the user is trying to remediate with the consumer device and address that real need.</li>
<li>Remember that there are legitimate times to take a stand and refuse to allow certain devices to be used in the company.</li>
<li>Regulation, such as PCI/DSS, SOX, GLBA, etc, exist to provide guidelines. Many businesses can be surprisingly flexible, even when these regulations must be followed.</li>
<li>But, don&#8217;t be afraid to do the necessary work to perform the risk analysis of the device, and maybe change policy or practice if the risk is at an acceptable level.</li>
<li>Finally, an attitude of working together can go a long way in helping the user to understand the issues surrounding their favorite consumer device.</li>
</ul>
<p>That&#8217;s about it for my thoughts this week. Until next time&#8230;</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/06/01/usability-vs-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Privacy Policy (again)</title>
		<link>http://www.dlstrom.com/2010/05/26/facebook-privacy-policy-again/</link>
		<comments>http://www.dlstrom.com/2010/05/26/facebook-privacy-policy-again/#comments</comments>
		<pubDate>Wed, 26 May 2010 18:54:19 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[FaceBook]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=315</guid>
		<description><![CDATA[According to cnnfn.com, simplification is coming to Facebook privacy configurations. The article starts out with this&#8230; By Ben Rooney, staff reporterMay 25, 2010: 6:25 PM ET NEW YORK (CNNMoney.com) &#8212; Facebook confirmed Tuesday that it will simplify its privacy settings, in a move aimed at quelling growing concerns over how much user information is exposed [...]]]></description>
			<content:encoded><![CDATA[<p>According to cnnfn.com, simplification is coming to Facebook privacy configurations. The <a href="http://money.cnn.com/2010/05/25/technology/facebook_privacy_settings/index.htm">article</a> starts out with this&#8230;</p>
<blockquote>
<p><span class="storybyline">By Ben Rooney, staff reporter</span><span class="storytimestamp">May 25, 2010: 6:25 PM ET</span><!--startclickprintexclude--><!--endclickprintexclude--><!-- CONTENT --></p>
<p>NEW YORK  (CNNMoney.com) &#8212; Facebook confirmed Tuesday that it will simplify its  privacy settings, in a move aimed at quelling growing concerns over how  much user information is exposed online.</p>
<p>&#8220;I can confirm that our  new, simpler user controls will begin rolling out tomorrow (Wednesday). I  can&#8217;t say more yet,&#8221; Andrew Noyes, a Facebook spokesman, said in a  statement.﻿</p>
<p> </p>
</blockquote>
<p>You can read the rest of the article to see what is being said.</p>
<p>Of course, Facebook has been talking about privacy settings for a long time. So has the press, pundits and bloggers. Not that I&#8217;m skeptical, or anything, but time will tell as to whether Facebook is truly making any useful changes.</p>
<p>While you are waiting for Facebook to make things simple, head on over to <a href="http://www.reclaimprivacy.org/">http://www.reclaimprivacy.org/</a> and use their scanner to help you identify and understand your current settings. The tool will also make some recommendations for you.</p>
<p>Was that a black helicopter that I just saw flying overhead?</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/05/26/facebook-privacy-policy-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>He&#8217;s Dead, Jim&#8230;</title>
		<link>http://www.dlstrom.com/2010/05/24/hes-dead-jim/</link>
		<comments>http://www.dlstrom.com/2010/05/24/hes-dead-jim/#comments</comments>
		<pubDate>Mon, 24 May 2010 15:28:40 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[FlashDrive]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=313</guid>
		<description><![CDATA[Pay attention, everyone - You should never have the only copy of your important files be stored on your flash drive. It will die (or be lost or be stolen). If this is the case, you may be completely out of luck. I had a friend give me a flash drive this past weekend. The [...]]]></description>
			<content:encoded><![CDATA[<p>Pay attention, everyone -</p>
<p>You should never have the only copy of your important files be stored on your flash drive. It will die (or be lost or be stolen). If this is the case, you may be completely out of luck.</p>
<p>I had a friend give me a flash drive this past weekend. The flash drive is not recognized by any computer. Where there normally is a light that comes on when plugged in, now there is no longer a light.</p>
<p>If the problem is more that just a poor USB connector, then it will be pretty costly to recover the data, if it is possible at all&#8230; Usually the cost will outweigh the benefit of recovered files.</p>
<p>So, use the flash drive only as a working and portable storage device. Make sure they are encrypted. Copy the files back to your computer if they are important. That way they will be a part of  your normal backups. (You do have a backup system, right?)</p>
<p>If you don&#8217;t have a backup system in place, consider using something like LockYourData (<a href="http://www.lockyourdata.com/">www.lockyourdata.com</a>). It allows  you to manage both online and local backups as well as keeping multiple generations of files.</p>
<p>The last thing you want to hear is the words of Dr. McCoy as he looks up and says, &#8220;He&#8217;s dead, Jim.&#8221;</p>
<p> </p>
<p><object width="445" height="364"><param name="movie" value="http://www.youtube.com/v/qJQwHwP0ojI&#038;hl=en_US&#038;fs=1&#038;border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/qJQwHwP0ojI&#038;hl=en_US&#038;fs=1&#038;border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="445" height="364"></embed></object></p>
<p> </p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/05/24/hes-dead-jim/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another Report on Microsoft Security Essentials (MSE)</title>
		<link>http://www.dlstrom.com/2010/05/06/another-report-on-microsoft-security-essentials-mse/</link>
		<comments>http://www.dlstrom.com/2010/05/06/another-report-on-microsoft-security-essentials-mse/#comments</comments>
		<pubDate>Thu, 06 May 2010 14:31:37 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Home InfoSec]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=309</guid>
		<description><![CDATA[Fred Langa with Windows Secrets has written about his experiences with Microsoft Security Essentials (MSE) running on Windows 7. http://windowssecrets.com/2010/05/06/01-The-120-day-Microsoft-security-suite-test-drive Important points&#8230; Use firewall, filters (in browsers &#38; email), and anti-malware. Products from Microsoft are finally easy-to-use for normal users. MSE can be configured to be very unobtrusive. MSE will frustrate advanced users, or those [...]]]></description>
			<content:encoded><![CDATA[<p>Fred Langa with Windows Secrets has written about his experiences with Microsoft Security Essentials (MSE) running on Windows 7.</p>
<p><a href="http://windowssecrets.com/2010/05/06/01-The-120-day-Microsoft-security-suite-test-drive">http://windowssecrets.com/2010/05/06/01-The-120-day-Microsoft-security-suite-test-drive</a></p>
<p>Important points&#8230;</p>
<ul>
<li>Use firewall, filters (in browsers &amp; email), and anti-malware.</li>
<li>Products from Microsoft are finally easy-to-use for normal users.</li>
<li>MSE can be configured to be very unobtrusive.</li>
<li>MSE will frustrate advanced users, or those who need more complex customization.</li>
</ul>
<p>Personally, I&#8217;ve had MSE running on a virtual machine that I use every day, and have been pleased. It is lightweight in it&#8217;s use of system resources.</p>
<p>It seems that for most home users who are running Windows 7, there is no need to purchase a security suite.</p>
<p>- Dan</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/05/06/another-report-on-microsoft-security-essentials-mse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Privacy Policy</title>
		<link>http://www.dlstrom.com/2010/05/04/facebook-privacy-policy/</link>
		<comments>http://www.dlstrom.com/2010/05/04/facebook-privacy-policy/#comments</comments>
		<pubDate>Tue, 04 May 2010 13:48:07 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[FaceBook]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=307</guid>
		<description><![CDATA[Facebook&#8217;s Eroding Privacy Policy: A Timeline You really need to take a look at this article. It shows how Facebook has slowly and steadily made your privacy disappear. You should carefully consider how this impacts you. - Dan]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.eff.org/deeplinks/2010/04/facebook-timeline">Facebook&#8217;s Eroding Privacy Policy: A Timeline</a></p>
<p>You really need to take a look at this article. It shows how Facebook has slowly and steadily made your privacy disappear.</p>
<p>You should carefully consider how this impacts you.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/05/04/facebook-privacy-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
