<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Data Security Podcast</title>
	<atom:link href="http://datasecurityblog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://datasecurityblog.wordpress.com</link>
	<description>News about Data Security, The Law, and The Digital Underworld - - - DataSecurityPodcast.com and DataSecurityBlog.com</description>
	<lastBuildDate>Fri, 13 Nov 2009 15:23:38 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='datasecurityblog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/addad890ac2c66ac7b9582358927dfaf?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Data Security Podcast</title>
		<link>http://datasecurityblog.wordpress.com</link>
	</image>
			<item>
		<title>Data Security Podcast Episode 78, Nov 09 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 05:40:21 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Conference Coverage]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Report Security Flaws]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[60 Minutes]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[mobile phone security]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Power Grid]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Surveillance cameras]]></category>
		<category><![CDATA[web application security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1356</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Why are web drive-by downloads proliferating like cockroaches?

* Sixty Minutes just covered a data security story. We rate the coverage.
* Our take on this week’s news.
–&#62; Stream This Week’s Show with our Built-In Flash Player:

–&#62; Scroll down to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1356&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Why are web drive-by downloads proliferating like cockroaches?<strong><br />
</strong></p>
<p>* Sixty Minutes just covered a data security story. We rate the coverage.</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_78.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 78</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 78 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks with Georg Hess, CEO and Co-Founder, <a title="Art of Defence" href="http://www.artofdefence.com/en" target="_blank">Art of D<span style="font-size:small;">efence</span></a>, about network scans versus web application scans. <a title="OWASP AppSec DC 2009" href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" target="_blank">OWASP AppSec DC 2009</a> takes place this week,  November 10-13th, in Washington, DC. The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Their mission is to make application security visible,  so that people and organizations can make informed decisions about true application security risks.</p>
<p style="text-align:center;"><a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009"><img class=" aligncenter" title="OWASP Conf 2009 Wash DC" src="http://www.owasp.org/images/9/92/Dc09.png" alt="OWASP Conf 2009 Wash DC" width="468" height="60" /></a></p>
<p>* Tales From The Dark Web:  Our take on the 60 Minutes segment Sabotaging The System:  Could hackers get into the computer systems that run crucial elements of the world&#8217;s infrastructure, such as the power grids, water works or even a nation&#8217;s military arsenal?  Be sure to <a title="60 Minutes" href="http://www.cbsnews.com/video/watch/?id=5578986n&amp;tag=api" target="_blank">watch this video segment</a> with the highest level non-technical boss in your organization. Also, make sure you, and your non-technical boss watch the &#8220;Web Extras&#8221; from this segment.  One of the stunning parts of the segment was the claim that private companies are more vulnerable because the companies only care about profit. Unlike government networks, which are more secure (uh?).  If that was the case, how can that be squared against the portion of the segment that revealed that the Feds lost 12TB of data from the DOD, DOE, DOC and possible NASA, in 2007? Where was the profit motive that stopped good security in those organizations? Security expert Robert Graham explores this, and other issues, in this posting: <a title="Brazil Grid Attacks?" href="http://erratasec.blogspot.com/2009/11/brazil-outage-not-caused-by-hackers.html" target="_blank">Brazil outage NOT caused by hackers</a>.</p>
<p>* From Our Take on The News:  New open-source voting technology – the developer is looking for jurisdictions to try it for free.  <a title="http://www.wired.com/threatlevel/2009/11/scantegrity" href="http://www.wired.com/threatlevel/2009/11/scantegrity" target="_blank">Read the Wired account</a>.</p>
<p>* From Our Take on The News:  A technical overview of the <a title="SSL flaw report" href="http://www.leviathansecurity.com/pdf/Renegotiating_TLS.pdf" target="_blank">newly discovered SSL vulnerabilities</a> and possible mitigation. Ben Laurie has excellent, technical <a title="SSL flaw blogs" href="http://www.links.org/?p=789" target="_blank">blog postings</a> about the SSL protocol flaw.</p>
<p>* From Our Take on The News:  Voters hate traffic surveillance cameras &#8212; proven in three U. S. cities in last week’s elections. (<a title="Washington Post" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/11/04/AR2009110404747.html" target="_blank">As if we still need proof</a>.) Great coverage of <a title="StopBigBrotherMD.org" href="http://www.stopbigbrothermd.org" target="_blank">traffic surveillance and related matters</a> in Maryland. (But the topic is universal).</p>
<p>* From The Wrap:  First iPhone worm found, <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank">details at F-Secure</a>.  A <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/cydia.htm" target="_blank">how-to for changing the SSH default password</a> in your jailbroken iPhone; one uses a computer connected to your iPhone to change the SSH settings.  Note: If you are not using a jailbroken iPhone, you don&#8217;t need to make changes to be protected from this particular attack.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1356/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1356/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1356/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1356&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_78.mp3" length="21038184" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.owasp.org/images/9/92/Dc09.png" medium="image">
			<media:title type="html">OWASP Conf 2009 Wash DC</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_78.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_78.mp3" />
		</media:content>
	</item>
		<item>
		<title>Special Security Geek Edition: Interview with Marsh Ray, Discoverer of SSL Flaw</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 04:41:57 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Exclusive]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[Marsh Ray]]></category>
		<category><![CDATA[PhoneFactor]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1335</guid>
		<description><![CDATA[For Thursday November 5th, we depart from our regular format for those with an advanced understanding of information security technologies. This episode is a one-topic special edition, providing coverage of a major man-in-the-middle flaw discovered in the SSL protocol (see, we told you it was for security geeks).
We will return to our regular format of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1335&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3>For Thursday November 5th, we depart from our regular format for those with an advanced understanding of information security technologies<strong>. This episode is a one-topic special edition, </strong>providing coverage of a major man-in-the-middle flaw discovered in the SSL protocol (see, we told you it was for security geeks).</h3>
<h3><strong>We will return to our regular format of the latest news on <strong>data security, privacy, and the law </strong>with Episode 78.  Episode 78 is scheduled to post Sunday night /Monday morning, November 8th, 2009 at ~12.01am Greenwich Mean Time. That is our regularly scheduled show posting time.<br />
</strong></h3>
<p>On Episode 77:  Conversation with Marsh Ray, discoverer of the new SSL flaw</p>
<p>–&gt; Stream This Special Episode Show with our Built-In Flash Player:<span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_77.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 77</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version forFREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 77 of the Data Security Podcast</strong></p>
<p>Breaking news with an extended interview with Marsh Ray,  Senior Software Developer and Engineer with multi-factor security company <a title="Phone Factor" href="http://www.Phonefactor.com" target="_blank">PhoneFactor</a>.</p>
<div class="wp-caption alignleft" style="width: 195px"><img title="SSL Lock" src="http://www.deskdrivers.com/images/ssl-lock-icon.jpg" alt="SSL lock engaged, but is the connection secure?" width="185" height="113" /><p class="wp-caption-text">SSL lock engaged, but is the connection secure?</p></div>
<p>Marsh Ray discovered a major security flaw in the SSL protocol.   SSL is the most widely used encryption protocol on the internet.</p>
<p>Marsh Ray keeps a blog at <a title="Extendedsubset Blog" href="http://extendedsubset.com/" target="_blank">extendedsubset.com</a>.  He works for PhoneFactor, where you can read more about this <a title="PhoneFactor/SSL hazard" href="http://www.phonefactor.com/sslgap/" target="_blank">vulnerability in SSL</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1335/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1335&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/05/special-edition-interview-with-marsh-ray-discoverer-of-ssl-flaw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_77.mp3" length="17311033" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.deskdrivers.com/images/ssl-lock-icon.jpg" medium="image">
			<media:title type="html">SSL Lock</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_77.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_77.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 76, Nov 02 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 02:14:38 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[EFF]]></category>
		<category><![CDATA[FCC]]></category>
		<category><![CDATA[Google Book Search]]></category>
		<category><![CDATA[Law Abiding Citizen]]></category>
		<category><![CDATA[Online Bingo]]></category>
		<category><![CDATA[Online Gaming]]></category>
		<category><![CDATA[Online Poker]]></category>
		<category><![CDATA[Online Sportsbook]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[World Series]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1318</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Placing an online bet for the World Series? Employees of online betting sites might be selling customer data online. 

* Google Book Search: What data is Google storing about readers of online books?
* Our take on this week’s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1318&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Placing an online bet for the World Series? Employees of online betting sites might be selling customer data online. <strong><br />
</strong></p>
<p>* Google Book Search: What data is Google storing about readers of online books?</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_76.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 76</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 76 of the Data Security Podcast</strong></p>
<p>* Conversation:  Samantha talks with Rebecca Jeschke  of the <a title="EFF" href="http://www.eff.org" target="_blank">Electronic Frontier Foundation</a> (EFF). There are lots of privacy objections  to the Google book search settlement… EFF is leading the way on the privacy  objections. <a title="EFF" href="http://www.eff.org/press/archives/2009/09/08" target="_blank">Read about it here.</a> And <a title="EFF Legal Filing" href="http://www.eff.org/files/filenode/authorsguild_v_google/File%20Stamped%20Brf.pdf" target="_blank">here’s the legal document</a> filed by EFF… the  settlement hearing has been indefinitely postponed.</p>
<p>* Tales From The Dark Web:  Are online casinos leaking information about their customers? Hard to say, as we saw the original web posting about this is only available in the Google Cache. Here is <a title="TightPoker" href="http://shar.es/axiGT" target="_blank">a story from TightPoker.com</a> about the original posting. That story lists the original site at AustralianGambling.au, but the URL should be AustralianGambling.com.au .</p>
<p>* From Our Take on The News:  <a title="Metadata Case" href="http://arstechnica.com/tech-policy/news/2009/10/lobbyists-beware-arizona-rules-metadata-is-public-record.ars" target="_blank">Lobbyists beware: judge rules metadata is public record</a>. This story also talks about the Google metadata leak.</p>
<p>* From Our Take on The News: A MUST READ &#8211; Samantha writes at the <a title="Reasonable Reporter" href="http://reasonablereporter.wordpress.com/2009/10/29/social-engineering-high-tech-crimes-require-low-tech-legwork/" target="_blank">ReasonableReporter.com about social engineering</a> and how the technique is used in real life, and in the new movie Law Abiding Citizen:</p>
<p><span style="text-align:center; display: block;"><a href="http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/"><img src="http://img.youtube.com/vi/yFTlG-gxPAA/2.jpg" alt="" /></a></span></p>
<p>* Wrap: Ira talked about the launch of <a title="Digital Forensics Magazine" href="http://tr.im/DQRA" target="_blank">Digital Forensics Magazine</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1318/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1318&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/11/01/data-security-podcast-episode-76-nov-92-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_76.mp3" length="14651392" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/yFTlG-gxPAA/2.jpg" medium="image" />

		<media:content url="http://security.talkworkshop.com/datasecpodcast_76.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_76.mp3" />
		</media:content>
	</item>
		<item>
		<title>Obama: $3.4B Toward &#8216;Smart&#8217; Power Grid &#8211; What About Smart Security and Privacy for The Grid?</title>
		<link>http://datasecurityblog.wordpress.com/2009/10/27/obama-3-4b-toward-smart-power-grid-what-about-smart-security-and-privacy-for-the-grid/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/10/27/obama-3-4b-toward-smart-power-grid-what-about-smart-security-and-privacy-for-the-grid/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 13:05:42 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[Smart Grid]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1311</guid>
		<description><![CDATA[President Obama is annoucing $3.4b in stimulus monies for the &#8220;Smart&#8221; Power Grid today (see story here).
But, here is part of the story that is not getting much, if any, coverage: What are the security and privacy issues in deploying the Smart Grid and Smart Meters?
While I am not an expert on energy, I am [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1311&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>President Obama is annoucing $3.4b in stimulus monies for the &#8220;Smart&#8221; Power Grid today (see story <a title="Smart Grid" href="http://www.foxnews.com/politics/2009/10/27/obama-putting-b-smart-power-g rid/?test=latestnews" target="_blank">here</a>).</p>
<p>But, here is part of the story that is not getting much, if any, coverage: What are the security and privacy issues in deploying the Smart Grid and Smart Meters?</p>
<p>While I am not an expert on energy, I am knowledgable on the data security and privacy issues on this topic. This is an issue that could literally impact every citizen and business in the US, and impact the very foundation of the economy.</p>
<p>There are advanced technologies that could truly help secure the delivery of power. There are rules that can be put into place to help protect privacy. But, these items do not appear to be on the agenda today, and get little attention in day-to-day coverage.</p>
<p>Early deployments of the Smart Grid and Smart Meters have not made security and privacy a priority, much beyond lip service.</p>
<p>There will be some very negative outcomes for this program if  security and privacy are not truly &#8220;baked in&#8221; at the beginning of this next wave of deployments.</p>
<p>Written By: Ira Victor, GIAC G17799 GCFA GPCI GSEC   ISACA CGEIT</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1311/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1311&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/10/27/obama-3-4b-toward-smart-power-grid-what-about-smart-security-and-privacy-for-the-grid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 75, Oct 25 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/10/25/data-security-podcast-episode-75-oct-25-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/10/25/data-security-podcast-episode-75-oct-25-2009/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 04:44:05 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Exclusive]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Report Security Flaws]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[mobile phone security]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Surveillance cameras]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[web application security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1295</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Everyone loves retail gift cards&#8230;they are quick and easy for consumers, and for web application &#8220;hackers.&#8221; 

* Some Time Warner cable internet users are vulnerable to serious attacks &#8212; when will Time Warner release a fix?
* Our take [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1295&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Everyone loves retail gift cards&#8230;they are quick and easy for consumers, and for web application &#8220;hackers.&#8221; <strong><br />
</strong></p>
<p>* Some Time Warner cable internet users are vulnerable to serious attacks &#8212; when will Time Warner release a fix?</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_75.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 75</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 75 of the Data Security Podcast</strong></p>
<div class="wp-caption alignright" style="width: 183px"><img class="  " title="Time Warner-supplied SMC cable modems: Open for Exploit?" src="http://www.smc-broadband.com/product_files/8014WN-RESthumb.jpg" alt="Time Warner-supplied SMC cable modem: open for exploit?" width="173" height="92" /><p class="wp-caption-text">Time Warner-supplied SMC cable modems: Open for Exploit?</p></div>
<p>* Conversation:  Ira talks with David Chen of Pip.io with an update on the critical vulnerabilities he discovered in a batch of Time Warner cable modems (made by SMC). TW now acknowledges the flaw, and they have made statements elsewhere that a fix is being deployed.  David Chen tells us that as of this past weekend the vulnerabilities remain.  Both David Chen and The Data Security Podcast have attempted to get an update on a fix. Time Warner cable has not replied to written requests from David Chen, or from this program.  David Chen is blogging with recommendation on how he thinks Time Warner Cable could mitigate these flaws&#8230; see  <a title="David Chen's Blog" href="http://chenosaurus.com/2009/10/26/time-warner-security-hole-still-wide-open/" target="_blank">his latest blog here</a>.<a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"> </a></p>
<p>* Tales From The Dark Web: Retail gift cards are potentially vulnerable to attacks. One that jumps out: web application attacks. <a title="Gift card report" href="http://research.corsaire.com/whitepapers/091021-attacking-magstripe-gift-cards.pdf" target="_blank">Read the entire report by Corsaire</a>.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News: Jurors are using smartphone from the jury box and the deliberation room – <a title="The Christian Science Monitor " href="http://www.csmonitor.com/2009/1021/p02s26-usju.html" target="_blank">potentially putting trial outcomes into jeopardy</a>.</p>
<p>* From Our Take on The News: <a title="Tresury Strategies" href="http://www.treasurystrategies.com/resources/pressReleases/TSIBankWillFail.pdf" target="_blank">Treasury Strategies Sees Possible Bank Failures Due to Fraud Losses</a></p>
<p>* The Kicker: <span style="color:#000000;"><a title="Long Island Teen" href="http://www.newsday.com/long-island/teen-s-video-snags-surprise-locker-thief-suspect-1.1542434" target="_blank">Long Island Teen Uses Hidden Video to Catch a Thief</a><br />
</span></p>
<div id="_mcePaste" style="overflow:hidden;position:absolute;left:-10000px;top:1054px;width:1px;height:1px;"><strong><span style="font-family:Verdana,Arial,Helvetica,sans-serif;color:#330066;font-size:small;">Modern Bank Robbers Could Shutter As Many As 10 Financial Institutions</span></strong></div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1295/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1295/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1295/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1295/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1295/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1295/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1295/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1295/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1295/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1295/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1295&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/10/25/data-security-podcast-episode-75-oct-25-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_75.mp3" length="23032790" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.smc-broadband.com/product_files/8014WN-RESthumb.jpg" medium="image">
			<media:title type="html">Time Warner-supplied SMC cable modems: Open for Exploit?</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_75.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_75.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 74, Oct 18 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/10/19/data-security-podcast-episode-74-oct-18-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/10/19/data-security-podcast-episode-74-oct-18-2009/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 17:24:53 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Rogueware]]></category>
		<category><![CDATA[Total Security]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[USB security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1276</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Now the bad guys are holding computer files for ransom if you don&#8217;t buy their phony anti-virus software. We have a workaround. 

* Midyear elections are coming up, and the last thing the campaigns seem to think about [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1276&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Now the bad guys are holding computer files for ransom if you don&#8217;t buy their phony anti-virus software. We have a workaround. <strong><br />
</strong></p>
<p>* Midyear elections are coming up, and the last thing the campaigns seem to think about is data security.</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:<br />
<span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_74.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 74</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 74 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks with Gretchen Hellman, VP of Marketing for <a title="Election 2010 data security" href="http://www.vormetric.com/" target="_blank">Vormetric</a> about information security, the security issues with the new GOP web site, and election campaign security.<a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"> </a></p>
<p>* Tales From The Dark Web:  Watch the video by PandaSecurity that demonstrates a damaging new fake anti-virus that denies access to files and applications on victim systems unless a ransom is paid. The link below takes you to a video of the attack, and we have posted the keys to defeat the current variant of lock out.  If you work in IT/InfoSec please write an email to users with a warning, include the keys to unlock the software, and have the end user re-image their hard drive.</p>
<div class="wp-caption aligncenter" style="width: 250px"><a href="http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx"><img title="Rogueware with new Ransomware Technology" src="http://farm3.static.flickr.com/2642/3993133972_af6917dbf6_m.jpg" alt="Rogueware with new Ransomware Technology" width="240" height="69" /></a><p class="wp-caption-text">Rogueware with new Ransomware Technology</p></div>
<p><a href="http://vimeo.com/6949998">Click here to view the Rogueware with new Ransomware Technology™</a> video. The video comes to us from <a href="http://vimeo.com/pandasecurity">Panda Security</a>.  Take note that the malware icon disappears from the computer, and when it does, the attack is in place.  If you have a system that is infected with this attack, Panda has cracked the malware and has provided a list of working keys, which give access to the current variants of the TotalSecurity2009 attack:</p>
<p>WNDS-TGN15-RFF29-AASDJ-ASD65<br />
WNDS-U94KO-LF4G4-1V8S1-2CRFE<br />
WNDS-6W954-FX65B-41VDF-8G4JI<br />
WNDS-G84H6-S854F-79ZA8-W4ERS<br />
WNDS-TTUYJ-7UO54-G561H-J1D6F<br />
WNDS-A1SDF-6AS4D-RF5RE-79G84<br />
WNDS-A1SDF-RY4E8-7U98D-F1GB2<br />
WNDS-5SRTS-AEHUF-YA54S-D6F35<br />
WNDS-P9685-4H41A-DSW3A-2R64T<br />
WNDS-2AE32-1VFC2-B6894-G67YU<br />
WNDS-4TS8R-D6F5D-4JH8T-U4JK5<br />
WNDS-FGS5D-649RG-4S53D-412SF<br />
WNDS-452S3-ER00F-TSE35-S8FSD<br />
WNDS-SERFH-2642S-F04SD-64FG1<br />
WNDS-F40SA-1ER5H-4FG5D-F8412<br />
WNDS-5D1V2-XB0D5-JT1TY-97DS3<br />
WNDS-4BGY2-JY4KO-IT98Y-7HJ43<br />
WNDS-G8FB6-1V87S-DRT1S-63SRG<br />
WNDS-HFVDR-9844O-U54DA-5TBSC<br />
WNDS-89OF7-7324R-5SAD4-TG68U<br />
WNDS-JUYH3-24GHJ-HGKSH-FKLSD</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Danger Will Robinson! Danger! Additional insiders have stepped forward to shed more light into Microsoft&#8217;s troubled acquisition of Danger, its beleaguered Pink Project, and what has become one of <a title="Danger Story on AppleInsider" href="http://www.appleinsider.com/articles/09/10/12/microsofts_sidekick_pink_problems_blamed_on_dogfooding_and_sabotage.html" target="_blank">the most high profile Information Technology disasters</a> in recent memory.  <strong> </strong></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1276/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1276&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/10/19/data-security-podcast-episode-74-oct-18-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_74.mp3" length="25718784" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://farm3.static.flickr.com/2642/3993133972_af6917dbf6_m.jpg" medium="image">
			<media:title type="html">Rogueware with new Ransomware Technology</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_74.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_74.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 73, Oct 11 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 04:57:36 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Conference Coverage]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[eMail Security]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[DefCon]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[endpoints]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[mobile phone security]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[two factor]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1261</guid>
		<description><![CDATA[
30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Major patching in store this week, due in part to flaws revealed this summer in Las Vegas? 

* A fresh look at a Zeus banking attack counter-measure
* Our take on this week’s news.
–&#62; Stream This Week’s Show with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1261&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Major patching in store this week, due in part to flaws revealed this summer in Las Vegas? <strong><br />
</strong></p>
<p>* A fresh look at a Zeus banking attack counter-measure</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_73.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 73</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 73 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira takes a new look at a counter-measure for the latest wave of Zeus banking attacks in his conversation with Steven Dispensa, CTO of <a title="PhoneTrust" href="http://www.phonefactor.com/" target="_blank">PhoneFactor</a>. <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"><br />
</a></p>
<p>* Tales From The Dark Web: It&#8217;s like clockwork&#8230;two months after security events BlackHat and Defcon every summer in Las Vegas, we see a surge in patches for attacks that were highlighted at these events.  Microsoft Security Bulletin Advance <a title="Patch Tuesday" href="http://www.microsoft.com/technet/security/Bulletin/MS09-oct.mspx" target="_blank">Notification for October 13th 2009.</a> Security Advisory for <a title="Adobe Patches" href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank">Adobe Reader and Acrobat</a> for October 13th 2009, including the CVE number.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Danger Will Robinson! Danger!  Update on <a title="Sidekick Data Loss" href="http://forums.t-mobile.com/tmbl/?category.id=Sidekick" target="_blank">Danger&#8217;s Sidekick Massive Data Loss</a>.  Read the <a title="Sidekick Data Loss FAQ" href="http://forums.t-mobile.com/tmbl/board/message?board.id=Sidekick2&amp;thread.id=6095" target="_blank">FAQ</a> for tips on trying to salvage your data.</p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  Computer Network <a title="Denial of Service Denial" href="http://www.sciencedaily.com/releases/2009/09/090930141541.htm" target="_blank">Denial Of Service Denial</a></p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News: Twitter shuts down legit security researcher, Mikko Hypponen.  Reports from <a title="Mikkoh Blog 1" href="http://www.f-secure.com/weblog/archives/00001786.html" target="_blank">his blog here</a>, and <a title="Mikkoh Blog 2" href="http://www.f-secure.com/weblog/archives/00001789.html" target="_blank">an update here</a>.</p>
<p style="text-align:center;">
<div class="wp-caption aligncenter" style="width: 503px"><a href="http://www.f-secure.com/weblog/archives/00001786.html"><img class="  " title="Twitter Shuts Legit Down Security Researchers Account" src="http://www.f-secure.com/weblog/archives/twitter_suspended4.png" alt="Twitter Shuts Legit Down Security Researchers Account" width="493" height="244" /></a><p class="wp-caption-text">Twitter Shuts Legit Down Security Researcher&#39;s Account</p></div>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1261/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1261&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/10/11/data-security-podcast-episode-73-oct-11-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_73.mp3" length="27596278" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://www.f-secure.com/weblog/archives/twitter_suspended4.png" medium="image">
			<media:title type="html">Twitter Shuts Legit Down Security Researchers Account</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_73.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_73.mp3" />
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 72, Oct 04 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/10/04/data-security-podcast-episode-72-oct-04-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/10/04/data-security-podcast-episode-72-oct-04-2009/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 02:54:12 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Conference Coverage]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[Polymorphic Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[TSA]]></category>
		<category><![CDATA[Zues Banking Trojan]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1247</guid>
		<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten)
On this week’s program:
* Polymorphic malware &#8211; every time it attacks it has a new signature.

* The balance on your bank account looks find, too bad all your money&#8217;s gone.
* Our take on this week’s news.
–&#62; Stream This Week’s Show with our [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1247&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Polymorphic malware &#8211; every time it attacks it has a new signature.<strong><br />
</strong></p>
<p>* The balance on your bank account looks find, too bad all your money&#8217;s gone.</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_72.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 72</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 72 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks about a dangerous new twist to the banking attacks Yuval Ben-Izhak the CTO of security company Finjan. Here is the link to the <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank">Finjan Report on the new Zeus bank Trojan</a> mentioned in the segment.<a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank"><br />
</a></p>
<p>* Tales From The Dark Web: Polymorphic malware &#8211; every time it attacks it has a different signature.  That means you anti-virus won&#8217;t recognize it.  Ira talked about the presentation at ISACA Security and Risk Conference by Stuart Staniford, the Chief Scientist at <a title="FireEye" href="http://www.fireeye.com" target="_blank">FireEye</a>.  Read the related <a title="APWK" href="http://www.antiphishing.org/reports/apwg_report_h1_2009.pdf" target="_blank">Anti-Phishing Working Group paper</a> on the topic.</p>
<p>* From Our Take on The News:  <span style="color:#000000;">From Wired.com &#8211; <a title="Wired.com" href="http://www.wired.com/threatlevel/2009/10/probe-targets-archives-handling-of-data-on-70-million-vets" target="_blank">Probe Targets Archives’ Handling of Data on 70 Million Vets</a></span></p>
<p><span style="color:#000000;font-size:x-small;">* </span>From Our Take on The News:  <a title="TSA" href="http://www.tsa.gov/what_we_do/layers/secureflight/index.shtm" target="_blank">Secure Flight Program</a> by the TSA. EPIC (The Electronic Privacy Information Center)  follows the surveillance and profiling of airline passengers. Their most recent post on the TSA “Secure Flight” program was in 2007, when the organization recommended that “secure flight should be grounded” due to privacy concerns. The program is now being expanded to require airline passengers to provide their date of birth when they purchase an airline ticket.  See: <span style="font-family:Arial;"><a title="EPIC" href="http://epic.org/privacy/airtravel/secureflight.html" target="_blank">http://epic.org/privacy/airtravel/secureflight.html</a></span></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1247/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1247/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1247/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1247&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/10/04/data-security-podcast-episode-72-oct-04-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_72.mp3" length="27739951" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_72.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_72.mp3" />
		</media:content>
	</item>
		<item>
		<title>BREAKING NEWS &#8211; New Twist to Zeus Bank Trojan; Well-Known Penetration Tester at ISACA Conference Calls Revelation &#8220;Disastrous&#8221;</title>
		<link>http://datasecurityblog.wordpress.com/2009/09/30/breaking-news-new-twist-to-zeus-bank-trojan-well-known-penetration-tester-at-isaca-conference-calls-revelation-disasterous/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/09/30/breaking-news-new-twist-to-zeus-bank-trojan-well-known-penetration-tester-at-isaca-conference-calls-revelation-disasterous/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 08:00:29 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Annoucements]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Conference Coverage]]></category>
		<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Exclusive]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[web application security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1208</guid>
		<description><![CDATA[Reporting from the ISACA Security and Risk Management Conference in Las Vegas, we have breaking security news this morning.
Organized cyber criminals have added a new damaging element to an already viscous cyber attack. Yuval Ben-Itzhak, CTO of Finjan spoke by phone with the Data Security Podcast about a frightening new twist to the surge of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1208&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Reporting from the <a title="ISACA Las Vegas" href="http://www.isaca.org/Template.cfm?Section=ISRMC1&amp;Template=/ContentManagement/ContentDisplay.cfm&amp;ContentID=45178" target="_blank">ISACA Security and Risk Management Conference</a> in Las Vegas, we have breaking security news this morning.</p>
<p>Organized cyber criminals have added a new damaging element to an already viscous cyber attack. Yuval Ben-Itzhak, CTO of Finjan spoke by phone with the Data Security Podcast about a frightening new twist to the surge of bank account stealing Trojan attacks.</p>
<p>First some background:  This news program, and other media outlets, have been reporting in the last few months about a wave of bank account Trojans that have been stealing money from small and medium sized businesses, and local governments. Theses well organized cyber criminals have been combining web drive-by attacks, with unauthorized electronic funds transfers. The cyber criminals then use innocent money mules to launder the money.  The mules are typically lured into popular “make cash at home” schemes.</p>
<p>A construction company in Maine lost $588,000 from a recent attack, and they are now suing their bank.  It’s important to note that while consumers generally have 60 days to “unwind” an unauthorized electronic funds transfer, businesses accounts are only protected if the bank is alerted within 48 hours of an unauthorized transfer.  On The Data Security Podcast earlier this week, we interviewed the lawyer representing the construction company that suffered the $588,000 loss, see link below.</p>
<p>The Data Security Podcast can now report a dangerous new element to these attacks.  Ben-Izthak tells the Data Security Podcast that Finjin security researchers have seen the cyber criminals actually alter the “account view” online screens that a victim sees. Of course the altered screen views do not show suspicious transactions. This means that a business will probably lose the chance to catch unauthorized transactions within the 48 hour window.</p>
<p>Here’s the process &#8211; The business uses a computer(s) to do online business banking, and uses that same computer  to do web activities, email, and other standard business internet tasks. The attackers use those normal internet activities to plant a version of Zeus banking Trojan onto the business computer systems. These attacks are designed to by-pass most firewalls and many popular anti-virus programs.</p>
<p>The Trojan captures log-in info, challenge question/answers, and account numbers, right from the business computer systems…all the info the criminals need to conduct unauthorized electronic funds transfers.</p>
<p>Here’s the new twist: The attackers are now altering the web screens that display business account information. The bank’s computers are not altered, but rather the business customer’s view of their own accounts, as seen from their own computers.  This is known in security-speak as an integrity attack: when authorized persons are unable to trust the accuracy of their own information</p>
<p>Ira Victor, Co-Host of The Data Security Podcast, is covering the ISACA Las Vegas Conference and had an exclusive sit-down interview with well-known data security researcher and penetration testing expert &#8216;Famous Peter Woods&#8217; (as he is known), about this new attack.  Peter Woods is the COO of <a title="First Base" href="http://Firstbase.co.uk" target="_blank">First Base</a>, a security company in the UK.  Mr. Woods is also  a keynote speaker at the conference.</p>
<p>Peter Woods characterized this new variation of the Zeus bank Trojan &#8220;as a disaster.&#8221;  Mr. Woods recommended that business engage is a serious round of new user awareness training. When we asked Mr. Woods about technical counter-measures the banks could undertake, he questioned the willingness of many banks to invest in counter-measures that would truly be effective against these types of attacks. He thought that many banks would be more likely to add new legal disclosures in an attempt to indemnify themselves from financial loss.</p>
<p>Indeed, some banks are now putting new warnings on their web sites that encourage customers to &#8220;update anti-virus&#8221; and to &#8220;update system-patches.&#8221; Other speakers at the ISACA conference in Las Vegas generally agree that while that those measures are good for stopping certain attacks, they are mostly insufficient to thwart these newer types of attacks.</p>
<p>In <a title="Data Security Podcast 71" href="http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/" target="_blank">Data Security Podcast Episode 71</a>, Samantha Stone has an eye-opening interview with the attorney of the Maine construction company that lost $588,000 in a cyber attack, and is suing their bank. The cause of action? The plaintiff claims the bank breached it fiduciary duty when it failed to protect against the loss of the $588,000.  We suspect that a  variant of  the Zeus banking Trojan attack was used to steal the money.</p>
<p>Be sure to listen to subscribe to our RSS feed and listen Data Security Podcast Episode 72. When that show posts, it will include our interview with Yuval Ben-Yitzhak of Finjan. Here is the link to the <a title="Zeus Trojan" href="http://security.talkworkshop.com/show_notes/Finjan_Zeus_Trojan_Update_Sept_2009.pdf" target="_blank">Finjan Report on the new Zeus bank Trojan</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1208/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1208&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/09/30/breaking-news-new-twist-to-zeus-bank-trojan-well-known-penetration-tester-at-isaca-conference-calls-revelation-disasterous/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Security Podcast Episode 71, Sep 28 2009</title>
		<link>http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/</link>
		<comments>http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/#comments</comments>
		<pubDate>Sun, 27 Sep 2009 23:39:54 +0000</pubDate>
		<dc:creator>datasecurityblog</dc:creator>
				<category><![CDATA[Court Cases]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[criminal forensics]]></category>
		<category><![CDATA[darkweb]]></category>
		<category><![CDATA[ediscovery]]></category>
		<category><![CDATA[web server security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[bank trojan]]></category>
		<category><![CDATA[Drive-by download]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Surveillance cameras]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://datasecurityblog.wordpress.com/?p=1190</guid>
		<description><![CDATA[
30 minutes every week on data security, privacy, and the law…..(plus or minus five)
On this week’s program:
* $4k per day scamming fake Viagra? That&#8217;s just the tip of the iceberg.

* Business bank accounts are the targets of attacks, businesses are responding with lawsuits against banks.
* Our take on this week’s news.
–&#62; Stream This Week’s Show [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1190&subd=datasecurityblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div>
<h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus five)</strong></h3>
<p>On this week’s program:</p>
<p>* $4k per day scamming fake Viagra? That&#8217;s just the tip of the iceberg.<strong><br />
</strong></p>
<p>* Business bank accounts are the targets of attacks, businesses are responding with lawsuits against banks.</p>
<p>* Our take on this week’s news.</p>
<p>–&gt; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_71.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p><span style="text-align:left;display:block;"> </span></p>
<p>–&gt; Scroll down to see links and show notes for this week’s show</p>
<p>–&gt; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 71</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&gt;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&gt;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&amp;task=view&amp;id=101&amp;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 71 of the Data Security Podcast</strong></p>
<p>* Conversation: Samantha talks with attorney Dan Mitchell, of Bernstein Shur. His business client was the victim of one of the bank account attacks, resulting in a cash loss of over $500,000. His client is suing the bank. Coverage in <a title="Computerworld" href="http://www.computerworld.com/s/article/9138467/Construction_firm_sues_after_588_000_online_theft?source=rss_security" target="_blank">Computerworld</a>.</p>
<p>* Tales From The Dark Web: Pharma scams earn $4k per day for members of the Dark Wek.  Read that and a LOT more in Dimitry Samosseiko of SophosLabs<a title="Dmitry Samoseiko's Paper" href="http://www.sophos.com/sophos/docs/eng/marketing_material/samosseiko-vb2009-paper.pdf" target="_blank"> paper he presented to the Virus Bulletin Conference</a> in Geneva Switzerland. That event wrapped up last Friday.</p>
<p>* From Our Take on The News:  <a title="Twitter Attacks" href="http://lastwatchdog.com/waves-twitter-attacks-errode-trustworthiness-tweets/" target="_blank">Waves of Twitter attacks erode trustworthiness of Tweets</a>.</p>
<div class="wp-caption aligncenter" style="width: 310px"><a href="http://lastwatchdog.com/waves-twitter-attacks-errode-trustworthiness-tweets/"><img title="How much should you trust Tweets?" src="http://lastwatchdog.com/wp/wp-content/uploads/twitter_spam.gif" alt="How much should you trust Tweets?" width="300" height="225" /></a><p class="wp-caption-text">How much should you trust Tweets?</p></div>
<p>* From Our Take on The News:  How much of your business data should you trust to web mail?</p>
<p>* From Our Take on The News:  <a title="Cameras keep track of all cars..." href="http://seattletimes.nwsource.com/html/localnews/2009873854_medina16m.html" target="_blank">Cameras keep track of all cars entering Medina Washington.</a></p>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/datasecurityblog.wordpress.com/1190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/datasecurityblog.wordpress.com/1190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/datasecurityblog.wordpress.com/1190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/datasecurityblog.wordpress.com/1190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/datasecurityblog.wordpress.com/1190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/datasecurityblog.wordpress.com/1190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/datasecurityblog.wordpress.com/1190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/datasecurityblog.wordpress.com/1190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/datasecurityblog.wordpress.com/1190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/datasecurityblog.wordpress.com/1190/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=datasecurityblog.wordpress.com&blog=4168461&post=1190&subd=datasecurityblog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://datasecurityblog.wordpress.com/2009/09/27/data-security-podcast-episode-71-sep-28-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://security.talkworkshop.com/datasecpodcast_71.mp3" length="16039936" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/585251cb6aaff159911b0a650465f33d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">datasecurityblog</media:title>
		</media:content>

		<media:content url="http://lastwatchdog.com/wp/wp-content/uploads/twitter_spam.gif" medium="image">
			<media:title type="html">How much should you trust Tweets?</media:title>
		</media:content>

		<media:content url="http://security.talkworkshop.com/datasecpodcast_71.mp3" medium="audio">
			<media:player url="http://datasecurityblog.wordpress.com/wp-content/plugins/audio-player/player.swf?soundFile=http://security.talkworkshop.com/datasecpodcast_71.mp3" />
		</media:content>
	</item>
	</channel>
</rss>