<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Data Security Podcast</title>
	<atom:link href="http://datasecurityblog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://datasecurityblog.wordpress.com</link>
	<description>News about Data Security, The Law, and The Digital Underworld - - - DataSecurityPodcast.com and DataSecurityBlog.com</description>
	<lastBuildDate>Mon, 07 Dec 2009 19:32:15 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='datasecurityblog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/addad890ac2c66ac7b9582358927dfaf?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Data Security Podcast</title>
		<link>http://datasecurityblog.wordpress.com</link>
	</image>
			<item>
		<title>Data Security Podcast Episode 84, Dec 7 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/12/07/data-security-podcast-episode-84-dec-7-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/12/07/data-security-podcast-episode-84-dec-7-2009/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 19:23:16 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1459</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Is there is a Russian connection to the &#8220;Climategate&#8221; attack?

* &#8216;Take Back Your Privacy&#8217; &#8212; A new nation-wide effort ramps up
* Our take on this week’s news.
–&#62; Stream This Week’s Show with our Built-In Flash Player:

–&#62; Scroll down [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1459&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Is there is a Russian connection to the &#8220;Climategate&#8221; attack?<strong><br />
</strong></p>
<p>* &#8216;Take Back Your Privacy&#8217; &#8212; A new nation-wide effort ramps up</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fdataclonelabs.com%2Fsecurity_talkworkshop%2Fdatasecpodcast_84.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 84</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 84 of the Data Security Podcast</strong></p>
<p>* Samantha has a conversation with Leslie Harris, president and CEO of The Center for Democracy and Technology. They are a D.C. group launching a consumer privacy campaign.  They want to educate consumers, pressure businesses, and push for a new law. <a title="Take Bake Your Privacy" href="http://www.cdt.org/takebackyourprivacy" target="_blank">Read more</a> at the &#8220;Take Back Our Privacy&#8221; area of their site.</p>
<p>* Tales From The Dark Web:  What, if any connection is there between Russian and the &#8220;Climategate&#8221; attack? Read more in the <a title="Climategate" href="http://www.dailymail.co.uk/news/article-1233562/Emails-rocked-climate-change-campaign-leaked-Siberian-closed-city-university-built-KGB.html" target="_blank">The UK Daily Mail story</a>. And, Adobe to release <a title="Adobe Patches" href="http://www.adobe.com/support/security/bulletins/apsb09-19.html" target="_blank">critical security patches</a> tomorrow .</p>
<p>* From Our Take on The News: <a title="Sting" href="http://www.wbtv.com/Global/story.asp?S=11623288" target="_blank"><span style="font-size:small;">SC police academy IT chief nabbed in Web sting</span></a>;  <a title="LimeWire" href="http://cbs13.com/local/limewire.child.porn.2.1346842.html" target="_blank"><span style="font-size:small;">&#8216;Accidental&#8217; Download Sending Man To Prison</span></a>.</p>
<p>* From Our Take on The News:  Department of Defense misses its own deadline for removing social security numbers from military ID cards.  <a title="Stars and Stripes" href="http://www.stripes.com/article.asp?section=104&amp;article=66444" target="_blank">Read about it at Stars and Stripes</a>.</p>
<p>* From Our Take on The News: Sprint received 8 million requests from Law Enforcement for GPS location data.  EFF is on the case, but this story has a fascinating origin… and an almost instantaneous rebuttal from Sprint.  (Which doesn’t deny the 8 million figure, but attempts to give it some context… The company is, of course, a regulated industry stuck in the middle, between the demands of its customers and the demands of congress, law enforcement and FTC… ). <a title="EFF" href="http://www.eff.org/deeplinks/2009/12/surveillance-shocker-sprint-received-8-million-law" target="_blank">Read more at EFF</a>.</p>
<p>* From Our Take on The News: <span style="font-size:small;">The economics of security advice; a very interesting MSFT research paper, and a related SANS posting. Read more at <a title="SANS" href="http://isc.sans.org/diary.html?storyid=7696" target="_blank">The SANS Internet Storm Center</a>.</span></p>
<p><span style="font-size:x-small;">* </span>The Wrap:  Many More Government Records Compromised in 2009 than Year Ago, Report Claims. <a title="Databreaches.net" href="http://www.databreaches.net/?p=8691" target="_blank">Read more at databreaches.net</a> .</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1459/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1459/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1459/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1459/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1459/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1459/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1459/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1459/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1459/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1459/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1459&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/12/07/data-security-podcast-episode-84-dec-7-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://dataclonelabs.com/security_talkworkshop/datasecpodcast_84.mp3" length="28056451" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://dataclonelabs.com/security_talkworkshop/datasecpodcast_84.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://dataclonelabs.com/security_talkworkshop/datasecpodcast_84.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 83, Nov 30 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/29/data-security-podcast-episode-83-nov-29-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/29/data-security-podcast-episode-83-nov-29-2009/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 06:01:04 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Insider Threats]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Las Vegas Metro Police]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[Zues Banking Trojan]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1436</guid>
		<description><![CDATA[


30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* New highly damaging attack plays on the very fear of being attacked

* Stopping insider attacks with the right internal controls
* Our take on this week’s news.
–&#62; Stream This Week’s Show with our Built-In Flash Player:

–&#62; Scroll down to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1436&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div>
<div>
<div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* New highly damaging attack plays on the very fear of being attacked<strong><br />
</strong></p>
<p>* Stopping insider attacks with the right internal controls</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_83.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 83</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 83 of the Data Security Podcast</strong></p>
<p>* Ira has a conversation with Cheryl Traverse President/ Chief Executive Officer with <a title="Xceedium.com" href="http://www.xceedium.com/en/" target="_blank">Xceedium</a>, a company that provides centralized, secure IT operations management.  Ira and Cheryl talk about the controls that protect against insider threats, and help put organizations in compliance with data security and privacy mandates.</p>
<p>* Tales From The Dark Web:  Bank attacks hides in &#8217;software update&#8217; links. This attack combines the fear of not properly patching with attacks that empty business bank accounts. Hat tip to the story in <a title="Bank attacks hide in software update links" href="http://darkreading.com/security/attacks/showArticle.jhtml?articleID=221901213" target="_blank">Darkreading.com</a> .</p>
<p>* From Out Take on The News: Reuters news story on the <a title="Cyber breaches are a closely kept secret" href="http://www.reuters.com/article/ousivMolt/idUSTRE5AN4YH20091124" target="_blank">under-reporting of cyber attacks</a>.</p>
<div class="wp-caption alignright" style="width: 260px"><img title="What Happens In Vegas...Goes Where??" src="http://cache.vegas.com/attractions/on_the_strip/images/welcomesign.jpg" alt="" width="250" height="188" /><p class="wp-caption-text">What Happens In Vegas...Goes Where??</p></div>
</div>
<p>* From Our Take on The News: Las Vegas Metro Police admits to large databreach of background check data.  Hat tip to excellent work by <a title="Metro Data Breach" href="http://www.lasvegassun.com/news/2009/nov/28/metro-admits-release-data/" target="_blank">The Las Vegas Sun newspaper</a>.</p>
<p>*  From The Wrap: We comment on the news that the <a title="Ikee Worm Writer" href="http://www.sophos.com/blogs/gc/g/2009/11/26/ikee-worm-author-job-iphone-app-firm/" target="_blank">Ikee worm author gets job at iPhone app firm</a>, as posted by Graham Cluley.</p>
</div>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1436/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1436&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/29/data-security-podcast-episode-83-nov-29-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_83.mp3" length="26764957" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://cache.vegas.com/attractions/on_the_strip/images/welcomesign.jpg" medium="image">
			<media:title type="html">What Happens In Vegas...Goes Where??</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_83.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_83.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 82, Nov 24 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/23/data-security-podcast-episode-82-nov-24-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/23/data-security-podcast-episode-82-nov-24-2009/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 06:31:20 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[eMail Security]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[Adobe Flash]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Surveillance cameras]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1420</guid>
		<description><![CDATA[

30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* FBI Report: Latest target for the cybercriminal? Law Firms and PR Firms

* Adobe Speaks: special segment with their senior security officers
* Our take on this week’s news.
–&#62; Stream This Week’s Show with our Built-In Flash Player:

–&#62; Scroll down [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1420&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div>
<div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* FBI Report: Latest target for the cybercriminal? Law Firms and PR Firms<strong><br />
</strong></p>
<p>* Adobe Speaks: special segment with their senior security officers</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_82.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 82</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 82 of the Data Security Podcast</strong></p>
<p><img class="alignleft" title="Adobe Flash" src="http://www.adobe.com/devnet/images/160x160/logo_flashplayer.jpg" alt="Adobe Flash Logo" width="160" height="160" />* Ira has a conversation with two security officers at Adobe Systems about the allegations made by web security researcher Mike Bailey of unpatchable &#8220;Same Origin Flaws&#8221; in Adobe Flash.  Brad Arkin, Director of Product Security and Privacy, and Peleus Uhley, Senior Security Researcher give their take on Mike Bailey&#8217;s claims. Here are the links mentioned in the segment:</p>
<p style="padding-left:30px;">
<div style="padding-left:30px;">- Adobe Flash Player <a title="Flash White Paper" href="http://www.adobe.com/devnet/flashplayer/articles/flash_player10_security_wp.html" target="_blank">security white paper</a></div>
<p style="padding-left:30px;">- Browser Security Handbook, Part 2—Information on the <a title="Security Handbook" href="http://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy" target="_blank">Same-Origin Policy</a>.</p>
<p style="padding-left:30px;">-  <a title="Adobe Flash article" href="http://www.adobe.com/devnet/flashplayer/articles/secure_swf_apps.html" target="_blank"> Peleus Uhley’s article</a> on creating more secure Flash applications / “Understanding that SWFs are Code”</p>
<p>* Tales From The Dark Web: FBI WARNING: <a title="FBI Warning" href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221900096" target="_blank">U.S. LAW FIRMS AND PUBLIC RELATIONS FIRMS</a>.  That link is a copy of the <a title="FBI Warning" href="http://www.fbi.gov/cyberinvest/escams.htm" target="_blank">FBI posting</a>. The FBI does not contain a permanent link, so it may become hard to find as new stories are posted above this law firm alert.</p>
<p>* From Our Take on The News:  <a title="UMC Records Leak" href="http://www.lasvegassun.com/news/2009/nov/21/fbi-looking-umc-records-leak/" target="_blank">FBI looking at UMC records leak: Agent says ‘multiple federal laws’ might have been violated</a>. Hat tip to the Las Vegas Sun newspaper for the investigative reporting on this story.</p>
<p>* From Our Take on The News:  <a title="Symantec SQL Attack" href="http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/" target="_blank">Symantec exposed passwords, serials numbers;  SQL Injection, full database access</a>, from Romanian security researcher, Unu. Apologies for mis-spelling Unu&#8217;s name on the show.<a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank"><img class="    alignright" title="Microsoft Internet Explorer 6 Icon" src="http://blogs.zdnet.com/security/images/internet_explorer.png" alt="" width="70" height="74" /></a></p>
<p>*  From The Wrap:  Read the SANS Internet Storm Center&#8217;s reports on <a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">IE</a><a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">6 </a><a title="IE Zero-Day" href="http://isc.sans.org/diary.html?storyid=7624" target="_blank">and IE7 web browser 0-Day Flaw</a>, and <a title="SANS" href="http://isc.sans.org/diary.html?storyid=7633" target="_blank">an Update</a>. No patch available (yet?), but Microsoft has some mitigation suggestions, linked through the Update.</p>
</div>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1420/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1420/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1420/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1420/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1420/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1420/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1420/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1420/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1420/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1420/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1420&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/23/data-security-podcast-episode-82-nov-24-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_82.mp3" length="21311530" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.adobe.com/devnet/images/160x160/logo_flashplayer.jpg" medium="image">
			<media:title type="html">Adobe Flash</media:title>
		</media:content>

		<media:content url="http://blogs.zdnet.com/security/images/internet_explorer.png" medium="image">
			<media:title type="html">Microsoft Internet Explorer 6 Icon</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_82.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_82.mp3" />
		</media:content>
	</item>
		<item>
		<title>Program Note &#8211; Data Security Podcast 82</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/22/program-note-data-security-podcast-82/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/22/program-note-data-security-podcast-82/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 04:35:02 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1413</guid>
		<description><![CDATA[Episode 82 of the Data Security Podcast is scheduled to post Monday over night/Tuesday early morning, Greenwich Mean Time.  In the meantime listen to Ira Victor&#8217;s two-part infosec special interviews on fighting web drive-by downloads. We posted a two part special edition last Thursday and Friday, Episode #80 and #81.
      [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1413&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Episode 82 of the Data Security Podcast is scheduled to post Monday over night/Tuesday early morning, Greenwich Mean Time.  In the meantime listen to Ira Victor&#8217;s two-part infosec special interviews on fighting web drive-by downloads. We posted a two part special edition last Thursday and Friday, Episode #80 and #81.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1413/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1413/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1413/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1413/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1413/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1413/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1413/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1413/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1413/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1413/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1413&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/22/program-note-data-security-podcast-82/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 81, Nov 20 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/20/data-security-podcast-episode-81-nov-20-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/20/data-security-podcast-episode-81-nov-20-2009/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 16:20:56 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[Exclusive]]></category>
		<category><![CDATA[Interview Only Edition]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[endpoints]]></category>
		<category><![CDATA[InZero Systems]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1405</guid>
		<description><![CDATA[


EXCLUSIVE &#8211; For Friday November 20th, we depart from our regular format for those with an advanced understanding of information security technologies. 
This is part two of two special editions featuring technical conversations with newsmakers on new counter measures to fight web drive-by downloads. Part two features Louis Hughes, Chairman and CEO of InZero Systems; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1405&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="post-1393">
<div>
<div>
<h3>EXCLUSIVE &#8211; For Friday November 20th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. </strong></h3>
<h3><strong>This is part two of two special editions featuring technical conversations with newsmakers on new counter measures to fight web drive-by downloads. Part two features</strong> Louis Hughes, Chairman and CEO of InZero Systems; and Yura Socolov, Director, IT Security of InZero Systems. InZero Systems has created a new hardware sandbox approach to this vexing security issue.</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 82.  Episode 82 is scheduled to post Sunday night /Monday morning, November 23rd, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 81:  InfoSec Conversation with InZero Systems on countering web drive-by downloads with a new hardware sandbox.</p>
<p>–&gt; Stream This Special Episode with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_81.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 81</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 81 of the Data Security Podcast</strong></p>
<p>Ira has an extended, technical conversation with Louis Hughes, Chairman and CEO of InZero Systems; and Yura Socolov, Director, IT security of InZero Systems. <a title="InZero" href="http://www.inzerosystems.com" target="_blank">InZero Systems</a> has an interested approach to fighting web drive-by downloads.</p>
</div>
</div>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1405/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1405/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1405/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1405/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1405/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1405/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1405/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1405/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1405/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1405/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1405&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/20/data-security-podcast-episode-81-nov-20-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_81.mp3" length="23296104" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_81.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_81.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 80, Nov 19 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/19/data-security-podcast-episode-80-nov-19-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/19/data-security-podcast-episode-80-nov-19-2009/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 14:23:31 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Interview Only Edition]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[endpoints]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[web application security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1393</guid>
		<description><![CDATA[For Thursday November 19th, and Friday November 20th, we depart from our regular format for those with an advanced understanding of information security technologies. 
These two special editions feature technical conversations with newsmakers on new counter measures to fight web drive-by downloads. Part one (this episode) features Pedro Bustamante, Senior Security Researcher with PandaSecurity. Part [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1393&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3>For Thursday November 19th, and Friday November 20th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. </strong></h3>
<h3><strong>These two special editions feature technical conversations with newsmakers on new counter measures to fight web drive-by downloads. Part one (this episode) features</strong> Pedro Bustamante, Senior Security Researcher with PandaSecurity. Part two will post tomorrow, with an EXCLUSIVE interview with the creators of a new hardware sandbox approach to this vexing security issue.</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 82.  Episode 82 is scheduled to post Sunday night /Monday morning, November 23rd, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 80:  InfoSec Conversation with Pedro Bustamante on countering web drive-by downloads.</p>
<p>–&gt; Stream This Special Episode with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_80.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 80</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 80 of the Data Security Podcast</strong></p>
<p>Ira has an extended, technical conversation with Pedro Bustamante, Senior Security Researcher with PandaSecurity.  Ira and Pedro will discuss web drive-by downloads. Here is <a title="Panda" href="http://cloudprotection.pandasecurity.com/" target="_blank">the link that Pedro mentions</a> in the segment.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1393/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1393/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1393/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1393&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/19/data-security-podcast-episode-80-nov-19-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_80.mp3" length="10941962" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_80.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_80.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 79, Nov 16 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 18:02:05 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[DefCon]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[EFF]]></category>
		<category><![CDATA[Google Books]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[two factor]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1378</guid>
		<description><![CDATA[
30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* The odds of unknowingly logging onto an &#8216;evil twin&#8217; of your online banking site is increasing due to new broadband hazards.

* A revised Google Book Settlement was submitted to the courts . It doesn’t address privacy at all.
* [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1378&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* The odds of unknowingly logging onto an &#8216;evil twin&#8217; of your online banking site is increasing due to new broadband hazards.<strong><br />
</strong></p>
<p>* A revised Google Book Settlement was submitted to the courts . It doesn’t address privacy at all.</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_79.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 79</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 79 of the Data Security Podcast</strong></p>
<p>* Program note about this week&#8217;s Conversation:  Ira will have an extended, technical conversation with Pedro Bustamante, Senior Security Researcher with PandaSecurity.  Ira and Pedro will discuss web drive-by downloads and other security issues in a special interview segment that will appear in a separate posting later this week. You can listen to the segment by streaming on this site, on iTunes, or other RSS feeds you use to listen to the Data Security Podcast.</p>
<p>* Tales From The Dark Web: What if you typed in your bank&#8217;s web address, but unknown to you, you were taken to an evil twin of your bank, controlled by cyber criminals? Well, the odds of that happening is increasing, due to Domain Name System (DNS)  issues in a significant number of broadband modems and routers.  Many other attacks can use these DNS flaws. Hat tip to the <a title="DNS Problems" href="http://www.pcworld.com/businesscenter/article/182168/dns_problem_linked_to_ddos_attacks_gets_worse.html" target="_blank">coverage</a> by Robert McMillan of the IDG News Service.</p>
<p>* From Our Take on The News:  Airport security in Saint Louis hassled one guy for half an hour, because he was carrying $4,700 in a cash box, which he placed on the x-ray conveyor belt and subjected to TSA scrutiny, as is required for all carry-on cargo.  The money was connected with his (legal) job with <a title="Campaign for Liberty" href="http://www.campaignforliberty.com/blog.php?view=14907" target="_blank">Campaign for Liberty</a>. The guy <a title="Steven Bierfeldt" href="http://contrarian.ca/tag/steven-bierfeldt/" target="_blank">recorded the abusive inquisition</a> on his iPhone.  The ACLU sued the TSA.  Now the airport security rules have changed. Read the coverage in <a title="Airport rules changed after Ron Paul aide detained" href="http://www.washingtontimes.com/news/2009/nov/11/rules-changed-after-paul-aide-detained-at-airport/" target="_blank">The Washington Times</a>.</p>
<p>* From Our Take on The News:  A flaw in Adobe Flash has a huge impact on web usage, especially those businesses that use Google Gmail/Google Apps/PHP Discussions, and sites the scores of sites that allow the upload of information to the site.  Mike Bailey, an expert on web application security, has an excellent infosec write up at the <a title="Foreground Security" href="http://www.foregroundsecurity.com/MyBlog/flash-origin-policy-issues.html" target="_blank">Foreground Security blog</a>.  Faster read in <a title="Flash Flaw" href="http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers" target="_blank">Computerworld</a>.</p>
<p>*  From The Wrap:  Revised Google Book Settlement was submitted to the court late Friday night. It doesn’t address privacy at all, even after EFF and other parties submitted a legal brief outlining legitimate fears that Google can track, and is likely to share individual book search information with law enforcement and anyone else who issues a subpoena. Google will retain book-search details, right down to page number and how long you lingered there, for every book you search.  <a title="Google Books" href="http://www.washingtontimes.com/news/2009/nov/11/rules-changed-after-paul-aide-detained-at-airport/" target="_blank">Read this account of the revised settlement</a>.</p>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1378/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1378&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/16/data-security-podcast-episode-79-nov-17-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_79.mp3" length="25107017" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_79.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_79.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 78, Nov 09 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 05:40:21 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Conference Coverage]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Report Security Flaws]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[60 Minutes]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[mobile phone security]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Power Grid]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Surveillance cameras]]></category>
		<category><![CDATA[web application security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1356</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Why are web drive-by downloads proliferating like cockroaches?

* Sixty Minutes just covered a data security story. We rate the coverage.
* Our take on this week’s news.
–&#62; Stream This Week’s Show with our Built-In Flash Player:

–&#62; Scroll down to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1356&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Why are web drive-by downloads proliferating like cockroaches?<strong><br />
</strong></p>
<p>* Sixty Minutes just covered a data security story. We rate the coverage.</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_78.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 78</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 78 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks with Georg Hess, CEO and Co-Founder, <a title="Art of Defence" href="http://www.artofdefence.com/en" target="_blank">Art of D<span style="font-size:small;">efence</span></a>, about network scans versus web application scans. <a title="OWASP AppSec DC 2009" href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" target="_blank">OWASP AppSec DC 2009</a> takes place this week,  November 10-13th, in Washington, DC. The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Their mission is to make application security visible,  so that people and organizations can make informed decisions about true application security risks.</p>
<p style="text-align:center;"><a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009"><img class=" aligncenter" title="OWASP Conf 2009 Wash DC" src="http://www.owasp.org/images/9/92/Dc09.png" alt="OWASP Conf 2009 Wash DC" width="468" height="60" /></a></p>
<p>* Tales From The Dark Web:  Our take on the 60 Minutes segment Sabotaging The System:  Could hackers get into the computer systems that run crucial elements of the world&#8217;s infrastructure, such as the power grids, water works or even a nation&#8217;s military arsenal?  Be sure to <a title="60 Minutes" href="http://www.cbsnews.com/video/watch/?id=5578986n&amp;tag=api" target="_blank">watch this video segment</a> with the highest level non-technical boss in your organization. Also, make sure you, and your non-technical boss watch the &#8220;Web Extras&#8221; from this segment.  One of the stunning parts of the segment was the claim that private companies are more vulnerable because the companies only care about profit. Unlike government networks, which are more secure (uh?).  If that was the case, how can that be squared against the portion of the segment that revealed that the Feds lost 12TB of data from the DOD, DOE, DOC and possible NASA, in 2007? Where was the profit motive that stopped good security in those organizations? Security expert Robert Graham explores this, and other issues, in this posting: <a title="Brazil Grid Attacks?" href="http://erratasec.blogspot.com/2009/11/brazil-outage-not-caused-by-hackers.html" target="_blank">Brazil outage NOT caused by hackers</a>.</p>
<p>* From Our Take on The News:  New open-source voting technology – the developer is looking for jurisdictions to try it for free.  <a title="http://www.wired.com/threatlevel/2009/11/scantegrity" href="http://www.wired.com/threatlevel/2009/11/scantegrity" target="_blank">Read the Wired account</a>.</p>
<p>* From Our Take on The News:  A technical overview of the <a title="SSL flaw report" href="http://www.leviathansecurity.com/pdf/Renegotiating_TLS.pdf" target="_blank">newly discovered SSL vulnerabilities</a> and possible mitigation. Ben Laurie has excellent, technical <a title="SSL flaw blogs" href="http://www.links.org/?p=789" target="_blank">blog postings</a> about the SSL protocol flaw.</p>
<p>* From Our Take on The News:  Voters hate traffic surveillance cameras &#8212; proven in three U. S. cities in last week’s elections. (<a title="Washington Post" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/11/04/AR2009110404747.html" target="_blank">As if we still need proof</a>.) Great coverage of <a title="StopBigBrotherMD.org" href="http://www.stopbigbrothermd.org" target="_blank">traffic surveillance and related matters</a> in Maryland. (But the topic is universal).</p>
<p>* From The Wrap:  First iPhone worm found, <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank">details at F-Secure</a>.  A <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/cydia.htm" target="_blank">how-to for changing the SSH default password</a> in your jailbroken iPhone; one uses a computer connected to your iPhone to change the SSH settings.  Note: If you are not using a jailbroken iPhone, you don&#8217;t need to make changes to be protected from this particular attack.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1356/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1356&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_78.mp3" length="21038184" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.owasp.org/images/9/92/Dc09.png" medium="image">
			<media:title type="html">OWASP Conf 2009 Wash DC</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_78.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_78.mp3" />
		</media:content>
	</item>
		<item>
		<title>Special Security Geek Edition: Interview with Marsh Ray, Discoverer of SSL Flaw</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 04:41:57 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Exclusive]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[Marsh Ray]]></category>
		<category><![CDATA[PhoneFactor]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1335</guid>
		<description><![CDATA[For Thursday November 5th, we depart from our regular format for those with an advanced understanding of information security technologies. This episode is a one-topic special edition, providing coverage of a major man-in-the-middle flaw discovered in the SSL protocol (see, we told you it was for security geeks).
We will return to our regular format of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1335&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3>For Thursday November 5th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. This episode is a one-topic special edition, </strong>providing coverage of a major man-in-the-middle flaw discovered in the SSL protocol (see, we told you it was for security geeks).</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 78.  Episode 78 is scheduled to post Sunday night /Monday morning, November 8th, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 77:  Conversation with Marsh Ray, discoverer of the new SSL flaw</p>
<p>–&gt; Stream This Special Episode Show with our Built-In Flash Player:<span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_77.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 77</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 77 of the Data Security Podcast</strong></p>
<p>Breaking news with an extended interview with Marsh Ray,  Senior Software Developer and Engineer with multi-factor security company <a title="Phone Factor" href="http://www.Phonefactor.com" target="_blank">PhoneFactor</a>.</p>
<div class="wp-caption alignleft" style="width: 195px"><img title="SSL Lock" src="http://www.deskdrivers.com/images/ssl-lock-icon.jpg" alt="SSL lock engaged, but is the connection secure?" width="185" height="113" /><p class="wp-caption-text">SSL lock engaged, but is the connection secure?</p></div>
<p>Marsh Ray discovered a major security flaw in the SSL protocol.   SSL is the most widely used encryption protocol on the internet.</p>
<p>Marsh Ray keeps a blog at <a title="Extendedsubset Blog" href="http://extendedsubset.com/" target="_blank">extendedsubset.com</a>.  He works for PhoneFactor, where you can read more about this <a title="PhoneFactor/SSL hazard" href="http://www.phonefactor.com/sslgap/" target="_blank">vulnerability in SSL</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1335/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1335&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_77.mp3" length="17311033" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.deskdrivers.com/images/ssl-lock-icon.jpg" medium="image">
			<media:title type="html">SSL Lock</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_77.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_77.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 76, Nov 02 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 02:14:38 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[EFF]]></category>
		<category><![CDATA[FCC]]></category>
		<category><![CDATA[Google Book Search]]></category>
		<category><![CDATA[Law Abiding Citizen]]></category>
		<category><![CDATA[Online Bingo]]></category>
		<category><![CDATA[Online Gaming]]></category>
		<category><![CDATA[Online Poker]]></category>
		<category><![CDATA[Online Sportsbook]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[World Series]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1318</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Placing an online bet for the World Series? Employees of online betting sites might be selling customer data online. 

* Google Book Search: What data is Google storing about readers of online books?
* Our take on this week’s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1318&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Placing an online bet for the World Series? Employees of online betting sites might be selling customer data online. <strong><br />
</strong></p>
<p>* Google Book Search: What data is Google storing about readers of online books?</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_76.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 76</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 76 of the Data Security Podcast</strong></p>
<p>* Conversation:  Samantha talks with Rebecca Jeschke  of the <a title="EFF" href="http://www.eff.org" target="_blank">Electronic Frontier Foundation</a> (EFF). There are lots of privacy objections  to the Google book search settlement… EFF is leading the way on the privacy  objections. <a title="EFF" href="http://www.eff.org/press/archives/2009/09/08" target="_blank">Read about it here.</a> And <a title="EFF Legal Filing" href="http://www.eff.org/files/filenode/authorsguild_v_google/File%20Stamped%20Brf.pdf" target="_blank">here’s the legal document</a> filed by EFF… the  settlement hearing has been indefinitely postponed.</p>
<p>* Tales From The Dark Web:  Are online casinos leaking information about their customers? Hard to say, as we saw the original web posting about this is only available in the Google Cache. Here is <a title="TightPoker" href="http://shar.es/axiGT" target="_blank">a story from TightPoker.com</a> about the original posting. That story lists the original site at AustralianGambling.au, but the URL should be AustralianGambling.com.au .</p>
<p>* From Our Take on The News:  <a title="Metadata Case" href="http://arstechnica.com/tech-policy/news/2009/10/lobbyists-beware-arizona-rules-metadata-is-public-record.ars" target="_blank">Lobbyists beware: judge rules metadata is public record</a>. This story also talks about the Google metadata leak.</p>
<p>* From Our Take on The News: A MUST READ &#8211; Samantha writes at the <a title="Reasonable Reporter" href="http://reasonablereporter.wordpress.com/2009/10/29/social-engineering-high-tech-crimes-require-low-tech-legwork/" target="_blank">ReasonableReporter.com about social engineering</a> and how the technique is used in real life, and in the new movie Law Abiding Citizen:</p>
<p><span style="text-align:center; display: block;"><a href="http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/"><img src="http://img.youtube.com/vi/yFTlG-gxPAA/2.jpg" alt="" /></a></span></p>
<p>* Wrap: Ira talked about the launch of <a title="Digital Forensics Magazine" href="http://tr.im/DQRA" target="_blank">Digital Forensics Magazine</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1318/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1318&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_76.mp3" length="14651392" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/yFTlG-gxPAA/2.jpg" medium="image" />

		<media:content url="http://security.talkworkshop.com/datasecpodcast_76.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_76.mp3" />
		</media:content>
	</item>
	</channel>
</rss>