<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Security</title>
	<atom:link href="http://episteme.ca/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://episteme.ca</link>
	<description></description>
	<lastBuildDate>Thu, 26 Jan 2012 20:50:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Suppressing Dissent</title>
		<link>http://episteme.ca/2010/07/21/suppressing-dissent/</link>
		<comments>http://episteme.ca/2010/07/21/suppressing-dissent/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 01:43:46 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[byron sonne]]></category>
		<category><![CDATA[canada]]></category>
		<category><![CDATA[dissent]]></category>
		<category><![CDATA[free byron]]></category>
		<category><![CDATA[overreaction]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[stupidity]]></category>
		<category><![CDATA[supression]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=767</guid>
		<description><![CDATA[I once heard it said (and I can&#8217;t find the quote) that a society&#8217;s level of freedom isn&#8217;t determined by how it treats its normal citizens &#8211; it&#8217;s determined by how it treats those who dissent and don&#8217;t adhere to society&#8217;s norms. Nowhere do I find this more evident than in the Byron case. Look, [...]]]></description>
			<content:encoded><![CDATA[<p>I once heard it said (and I can&#8217;t find the quote) that a society&#8217;s level of freedom isn&#8217;t determined by how it treats its normal citizens &#8211; it&#8217;s determined by how it treats those who dissent and don&#8217;t adhere to society&#8217;s norms.</p>
<p>Nowhere do I find this more evident than in the <a href="http://www.freebyron.com">Byron</a> case. </p>
<p>Look, let&#8217;s be blunt: from everything we know about what Byron was doing, it was kind of stupid.  He was acting as an agitator to the G20 security establishment.  He wasn&#8217;t being particularly subtle.  He was <i>trying</i> to stir up a response, and he did.</p>
<p>I think it&#8217;s clear that he&#8217;s guilty of mischief.  He&#8217;s certainly an agent provocateur (<a href="http://en.wikipedia.org/wiki/Agent_provocateur">def:  &#8220;a person or group that seeks to discredit or harm another by provoking them to commit a wrong or rash action.&#8221;</a>)</p>
<p><a href="http://www.nowtoronto.com/guides/g20/2010/story.cfm?content=175989">Joshua Errett over at NOW Toronto</a> described it best:</p>
<p>&#8220;<i>What Sonne was actually trying to do is expose security inadequacies of the G20, as is the role of the hacker. His intent was never to harm, and any crimes he allegedly committed were entirely victimless.</p>
<p>That the justice system can’t see the deep shades of difference between Sonne detailing security lapses and petty vandalism is an outright shame. And, in some ways, discrimination. If Sonne had been a cowardly Blac Blocker, bail would have already been set. There certainly seems a different set of rules for hacking.</i>&#8221;</p>
<p>With <a href="http://www.thestar.com/news/gta/crime/article/837834--computer-expert-remains-jailed-in-g20-case">the ruling yesterday that Byron will remain in jail until his trial</a> and be unable to have any contact with his wife during that time (unless in the presence of lawyers), there&#8217;s little question that he got the &#8220;rash action&#8221;.</p>
<p>And it&#8217;s clear that Canadian society has made its statement on how it intends to deal with dissent &#8211; zero tolerance.  </p>
<p>In contrast to Byron&#8217;s crimes, <a href="http://www.thestar.com/news/canada/article/673235">those who steal $30-$50 million</a>, <a href="http://www.thestar.com/news/gta/crime/article/836055--life-sentence-for-killer-of-caring-young-woman">dangerous offenders</a>, <a href="http://www.torontosun.com/news/torontoandgta/2010/07/20/14773816.html">those who kill while drinking and driving</a> and <a href="http://cnews.canoe.ca/CNEWS/Crime/2009/12/15/12158456-sun.html">crack dealers</a> all go free on bail.</p>
<p>This is one of the more disturbing issues with the case &#8211; not that Byron wasn&#8217;t guilty of being annoying, but that the treatment he is receiving at the hands of the justice system in Canada is far more harsh than those who commit far more significant crimes that leave people hurt, dead or destitute. </p>
<p><a href="http://www.freebyron.com">Free Byron.</a></p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/byron+sonne' rel='tag' target='_self'>byron sonne</a>, <a class='technorati-link' href='http://technorati.com/tag/canada' rel='tag' target='_self'>canada</a>, <a class='technorati-link' href='http://technorati.com/tag/dissent' rel='tag' target='_self'>dissent</a>, <a class='technorati-link' href='http://technorati.com/tag/free+byron' rel='tag' target='_self'>free byron</a>, <a class='technorati-link' href='http://technorati.com/tag/overreaction' rel='tag' target='_self'>overreaction</a>, <a class='technorati-link' href='http://technorati.com/tag/politics' rel='tag' target='_self'>politics</a>, <a class='technorati-link' href='http://technorati.com/tag/stupidity' rel='tag' target='_self'>stupidity</a>, <a class='technorati-link' href='http://technorati.com/tag/supression' rel='tag' target='_self'>supression</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2010/07/21/suppressing-dissent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Byron (and influence through the media)</title>
		<link>http://episteme.ca/2010/06/23/byron-and-influence-through-the-media/</link>
		<comments>http://episteme.ca/2010/06/23/byron-and-influence-through-the-media/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 21:14:17 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[arrest]]></category>
		<category><![CDATA[byron sonne]]></category>
		<category><![CDATA[inappropriate pictures]]></category>
		<category><![CDATA[influence]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=740</guid>
		<description><![CDATA[If you&#8217;re following the Toronto news today, one of the main stories out there is about a former team member of mine, Byron Sonne. The news coverage (CNN, Yahoo) paints Byron to be one step this side of Timothy McVeigh&#8230; explosives, threatening police, etc. And that doesn&#8217;t even mention that the picture that they&#8217;re using [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re following the Toronto news today, one of the main stories out there is about a former team member of mine, Byron Sonne.  The news coverage (<a href="http://news.blogs.cnn.com/2010/06/23/man-threatening-g-20-arrested-for-explosive-device/">CNN</a>, <a href="http://ca.news.yahoo.com/s/capress/100623/national/g20_arrest_1">Yahoo</a>) paints Byron to be one step this side of Timothy McVeigh&#8230; explosives, threatening police, etc.</p>
<p><img class="alignright" src="http://beta.images.theglobeandmail.com/archive/00720/ByronSonne_72068_720684gm-a.jpg" alt="" width="252" height="168" /> And that doesn&#8217;t even mention that the picture that they&#8217;re using makes him look that way.  (As an aside: in my 11th grade journalism class, we spent a lot of time talking about how pictures frame the news story that you&#8217;re reading.  Before you ever even start the <a href="http://www.theglobeandmail.com/news/world/g8-g20/news/man-charged-in-connection-with-summit/article1614068/">Globe and Mail</a> coverage of this story, you&#8217;re greeted with a blurry, grainy picture of Byron looking like he&#8217;s about to blow up a building.   Regardless of whether the facts  support the charge, our minds are primed with all of the times that we&#8217;ve seen a terrifying looking psychopath looking very similarly to this picture&#8230; and we read the story with that bent.)</p>
<p>Unfortunately, the reality seems a little less glamorous.  If you read <a href="http://www.twitter.com/torontogoat">Byron&#8217;s Twitter account</a>, you&#8217;ll find that Byron was being little more than the opinionated activist that he is. <a href="http://www.thestar.com/news/gta/article/827287--was-arrested-man-planning-to-monitor-police?bn=1">&#8220;An agent provocateur&#8221;</a>, as someone told The Star. He talked about investigating the fences and <a href="http://www.youtube.com/torontogoat">posted video of the fences</a>.  He talked about how the cameras were being set up in locations that were likely to be used by activists.  And he was pointing out that the amount of money spent on &#8220;security&#8221; for this conference was a little out of range.</p>
<p>One of the things that Byron has been most pilloried for in the news was the talk he gave a few months back on radio surveillance (a decent account can be found <a href="http://www.thestar.com/news/gta/article/827287--was-arrested-man-planning-to-monitor-police?bn=1">here</a>).</p>
<p>Amazingly, Byron even <a href="http://twitter.com/torontogoat/status/16319480945">posted the slides to that supposedly &#8220;provocative&#8221; talk on his Twitter feed</a>.  (I&#8217;ve put the same slides <a href="http://episteme.ca/wp-content/uploads/2010/06/RF-CounterSurveillance.pdf">here</a> for the BitTorrent challenged).  Read them&#8230; there&#8217;s nothing in there that suggests anything but a security professional talking about insecure radio transmission.</p>
<p><img class="size-medium wp-image-742 alignleft" title="byron" src="http://episteme.ca/wp-content/uploads/2010/06/byron-300x225.jpg" alt="" width="300" height="225" /> Let&#8217;s give a different picture of the guy that used to work for me.  Byron&#8217;s a very smart and well-rounded engineer.  While he wasn&#8217;t the top producer on the team, he was someone who I valued a great deal from a management perspective.  He was vocal and would push others to come to the table with their best (even when he wasn&#8217;t up to their level).  He was the member of the team most willing to call out others in a meeting.  It wasn&#8217;t just internal&#8230; he was even willing to <a href="http://web.archive.org/web/20061004221752/http://blog.ncircle.com/archives/2005/11/vendors_please.htm">call out a vendor in a blog post</a>.  (Note that since I wrote this, nCircle took <a href="http://blog.ncircle.com/archives/2005/11/vendors_please_fix_your_crappy.html"">the orginal post down</a>)</p>
<p>Above all, Byron Sonne was always an ethical person and someone who I trusted a great deal.   And I agree with the assessment that <a href="http://jessehirsh.com/">Jesse Hirsh</a> made in <a href="http://www.thestar.com/news/gta/article/827287--was-arrested-man-planning-to-monitor-police?bn=1">an interview with The Toronto Star</a>:</p>
<p><em>“I suspect that this may just be a stunt and perhaps a stunt that got out of hand,” Hirsh said.</em></p>
<p>Regardless, it&#8217;s a shock to me that this would lead to an arrest and incarceration.  None of the posts made threats or suggested potential for harm.  His talk is innocuous.  And this all looks like a very large over-reaction from a police service that felt somewhat embarrassed that someone was publicly calling them out on their failure to encrypt their communications and poor placement of security cameras.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/arrest' rel='tag' target='_self'>arrest</a>, <a class='technorati-link' href='http://technorati.com/tag/byron+sonne' rel='tag' target='_self'>byron sonne</a>, <a class='technorati-link' href='http://technorati.com/tag/inappropriate+pictures' rel='tag' target='_self'>inappropriate pictures</a>, <a class='technorati-link' href='http://technorati.com/tag/influence' rel='tag' target='_self'>influence</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2010/06/23/byron-and-influence-through-the-media/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Influence and Failing Kindergarten</title>
		<link>http://episteme.ca/2010/05/18/influence-and-failing-kindergarten/</link>
		<comments>http://episteme.ca/2010/05/18/influence-and-failing-kindergarten/#comments</comments>
		<pubDate>Tue, 18 May 2010 16:12:01 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=738</guid>
		<description><![CDATA[Had a great chat with my friend Drawk Kwast recently that he recorded for his list of users (which was an honor given the people he usually interviews). As expected, we rambled all over the map and talked about a million different topics around influence, living an adventurous and successful life, and always being willing [...]]]></description>
			<content:encoded><![CDATA[<p>Had <a href="http://www.drawkkwast.com/affiliate/idevaffiliate.php?id=1002&#038;url=1">a great chat with my friend Drawk Kwast</a> recently that he recorded for his list of users (which was an honor given the people he usually interviews).  As expected, we rambled all over the map and talked about a million different topics around influence, living an adventurous and successful life, and always being willing to have fun and do the things that most people won&#8217;t do.</p>
<p>The thought that stuck out to both of us during the chat was the idea that we&#8217;d fail kindergarten if we were subjected to another year &#8211; that the things that has made each of us successful to this point would have caused utter failure in the current school system.  We both have a nearly chronic inability to follow the rules, stay in single-file lines, refrain from asking &#8220;why?&#8221; about a million times too often and ensure that we always make the sky blue when we color.  </p>
<p>As Drawk said: &#8220;<i>we&#8217;d in the corner eating the paste.</i>&#8221;</p>
<p>I realized later that I should have corrected him&#8230; so I will now&#8230; &#8220;<i>we&#8217;d be in the corner figuring out how to take the paste, turn it in to some crazy 5-star dish involving liquid nitrogen and debating about how to market a nationwide line of &#8220;frozen paste&#8221; shops.</i>&#8220;.  </p>
<p>It&#8217;s a trait that a lot of my friends seem to share.  </p>
<p><a href="http://www.drawkkwast.com/affiliate/idevaffiliate.php?id=1002&#038;url=1">The MP3</a> is worth a listen &#8211; Drawk had some great stories on there and I talked about random stuff that some people might find interesting.</p>
<p>(Aside: if you haven&#8217;t picked up Drawk&#8217;s &#8220;<a href="http://www.drawkkwast.com/1002-2-3-16.html" target="_blank">Domination Basics</a>&#8221; ebook, you need to &#8211; it&#8217;s free and one of the better reads of the last year.  The last person who I convinced to read it immediately sent me the message that &#8220;OMG! Drawk Kwast is the UberMan!!!!&#8221;.  All I can say is that you should read it yourself and find out what all the exclamation points are all about.)</p>

<!-- start wp-tags-to-technorati 1.02 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2010/05/18/influence-and-failing-kindergarten/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Return-to-Barry-White Human Exploitation</title>
		<link>http://episteme.ca/2009/11/04/return-to-barry-white-human-exploitation/</link>
		<comments>http://episteme.ca/2009/11/04/return-to-barry-white-human-exploitation/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 23:37:41 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://episteme.ca/2009/11/04/return-to-barry-white-human-exploitation/</guid>
		<description><![CDATA[Spent a weekend in early October hanging out with Tom and Kim at their rapport and anchoring bootcamp.&#160; And I was talking in email with my friend Cris Neckar afterward where we were talking about the large number of pre-existing anchors that exist within someone’s already vast consciousness. Cris’s comment was that using pre-existing material [...]]]></description>
			<content:encoded><![CDATA[<p>Spent a weekend in early October hanging out with <a href="http://www.essential-skills.com">Tom and Kim</a> at their rapport and anchoring bootcamp.&#160; And I was talking in email with <a href="http://labs.neohapsis.com/">my friend Cris Neckar</a> afterward where we were talking about the large number of pre-existing anchors that exist within someone’s already vast consciousness.</p>
<p>Cris’s comment was that using pre-existing material for anchors is “sort of like exploiting around DEP” – basically, the idea of a &quot;Return-to-libc” exploit.&#160; You have pre-existing functions that perform the task that you’re hoping to do.</p>
<p>This reminded me of something that <a href="http://www.twitter.com/tomvizzini">Tom</a> did to me during the weekend.&#160; Tom walked up to me this weekend and said: </p>
<p>&quot;<em>So, you&#8217;re a hypnotist right?&#160; You&#8217;ve been in trance before, you know what that feels like, don’t you?</em>&quot; And, as soon as I think about it (which I have to do to understand his question), he achors it.</p>
<p>Tom then proceeded to spend the rest of the weekend enjoying firing off the trance anchor at opportune times.</p>
<p>So, in our email conversation, Cris and I were talking about some good elicitations to anchor that many people would already have:</p>
<p>“<em>Hey&#8230; remember that scene from Say Anything where John Cusack was standing outside with the boom-box on his head?&#160; How romantic was that?&#160; What was the most romantic movie scene you remember&#8230; one that just made your heart melt?</em>&quot; </p>
<p>Or: &quot;<i>As you wish</i>&quot; (for anyone who has seen the Princess Bride). </p>
<p>Or: &quot;<em>What’s the song that gets you most in the mood?</em>”</p>
<p>In other words, the &quot;Return-to-Barry-White&quot; exploit.&#160; </p>
<p><em><font size="1">Note: I’m well aware that this isn’t at all new.&#160; Neither’s ret2libc, really.&#160; But it’s a great example that hopefully drives some new ideas and new thinking.</font></em></p>

<!-- start wp-tags-to-technorati 1.02 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/11/04/return-to-barry-white-human-exploitation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recap: The Hope Symposium</title>
		<link>http://episteme.ca/2009/09/23/recap-the-hope-symposium/</link>
		<comments>http://episteme.ca/2009/09/23/recap-the-hope-symposium/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 20:23:55 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://episteme.ca/2009/09/23/recap-the-hope-symposium/</guid>
		<description><![CDATA[This past weekend, I had the privilege of speaking at&#160; The Hope Symposium.&#160; It was a small conference put on by my friends over at NLP Canada. I was actually lucky enough to speak twice at the conference – I was the opening speaker and the final speaker before Chris and Linda closed out the [...]]]></description>
			<content:encoded><![CDATA[<p>This past weekend, I had the privilege of speaking at&#160; <a href="http://www.relaxedandready.ca">The Hope Symposium</a>.&#160; It was a small conference put on by my friends over at <a href="http://nlpcanada.com">NLP Canada</a>.</p>
<p>I was actually lucky enough to speak twice at the conference – I was the opening speaker and the final speaker before Chris and Linda closed out the conference.</p>
<p>More (including video of my talks) in the coming days, but for now, just a picture of me, Chris <a href="http://rapidsuccesscoach.com">Ron Verreggen of RapidSuccessCoach.com</a>.</p>
<p><a href="http://episteme.ca/wp-content/uploads/2009/09/ChrisMikeRon.jpg"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="ChrisMikeRon" border="0" alt="ChrisMikeRon" src="http://episteme.ca/wp-content/uploads/2009/09/ChrisMikeRon_thumb.jpg" width="644" height="432" /></a></p>

<!-- start wp-tags-to-technorati 1.02 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/09/23/recap-the-hope-symposium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Greed as a prime motivator</title>
		<link>http://episteme.ca/2009/07/22/greed-as-a-prime-motivator/</link>
		<comments>http://episteme.ca/2009/07/22/greed-as-a-prime-motivator/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 01:09:29 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[con artist]]></category>
		<category><![CDATA[con man]]></category>
		<category><![CDATA[security awareness]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=604</guid>
		<description><![CDATA[I found this article the other day about the teen in Great Britain who managed to completely dupe a bunch of airline executives in believing that he was a millionaire who was looking to buy into their company and expand it. The key to the attack is that greed was the prime motivator in the [...]]]></description>
			<content:encoded><![CDATA[<p>I found this article the other day about the teen in Great Britain who managed to completely dupe a bunch of airline executives in believing that he was a millionaire who was looking to buy into their company and expand it. The key to the attack is that greed was the prime motivator in the attack.  From <a href="href="http://chattahbox.com/curiosity/2009/07/20/teenager-with-autism-fools-airline-into-thinking-he-is-tycoon/">the article</a>:</p>
<p>&#8220;<i>When asked how he had managed to fool them, one of the airline execs in Jersey stated:</p>
<p>“If they were real then there would have been opportunities for us to expand our business and that’s not the sort of thing we are going to ignore.”</i>&#8221;</p>
<p>That quote is the key to it all &#8211; we can all learn something from this executive. The problem is that the higher ups in this company were willing to throw caution to the wind when granted a potential for monetary gain. Of course they’d love to expand their company, but at the cost of ignoring security and inviting the con-artist into their inner sanctum?</p>
<p>The question is would this executive also be answering a phishing email like the one I got from Jassay Goran in the Solomon Islands that promised me I’d get $8.5 million if I followed a few simple steps? People involved in social engineering are often extremely bright, inventive and ingratiating &#8211; as I have said repeatedly in talks, social engineering is primarily a <i>crime of the imagination</i>. Note that in his explanation and defense of his actions, the executive used the phrase, “if they were real,” as the pretext for his action. Anytime someone does that, they’re taking a big chance with that little word “if.”</p>
<p>I’ll comment more on this article and overall story in a later blog. I think there’s something to be learned from a fact that’s recently been reported about this 17-year old—he has Autism. Also, this story really makes me reconsider the whole topic of user education. More thoughts after the pre-Blackhat rush settles a tad.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/con+artist' rel='tag' target='_self'>con artist</a>, <a class='technorati-link' href='http://technorati.com/tag/con+man' rel='tag' target='_self'>con man</a>, <a class='technorati-link' href='http://technorati.com/tag/security+awareness' rel='tag' target='_self'>security awareness</a>, <a class='technorati-link' href='http://technorati.com/tag/social+engineering' rel='tag' target='_self'>social engineering</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/07/22/greed-as-a-prime-motivator/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Constraints and The Bandwidth Problem</title>
		<link>http://episteme.ca/2009/07/17/does-secure-inside-mean-secure-outside-too/</link>
		<comments>http://episteme.ca/2009/07/17/does-secure-inside-mean-secure-outside-too/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 22:51:15 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Fiber Optics]]></category>
		<category><![CDATA[Internet security]]></category>
		<category><![CDATA[security awareness]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=596</guid>
		<description><![CDATA[I got in a conversation last week about the upcoming bandwidth crisis in the core. I&#8217;ve managed to forget about those issues more and more over the past few months. I’ve spent a lot of time thinking about vulnerability research and social engineering lately at the expense of a lot of other security thinking. But [...]]]></description>
			<content:encoded><![CDATA[<p>I got in a conversation last week about the upcoming bandwidth crisis in the core.  I&#8217;ve managed to forget about those issues more and more over the past few months.  I’ve spent a lot of time thinking about vulnerability research and social engineering lately at the expense of a lot of other security thinking. But that conversation and <a href="http://www.dailymail.co.uk/home/moslive/article-1196775/Web-trouble-The-hidden-cables-Cornish-beach-feeding-worlds-internet.html">this article</a> brought my thinking back to the infrastructure side of security.  From the article:</p>
<p>“The super-high-speed cable is now hidden under six feet of Cornish beach-which is just as well, because if it were discovered and damaged, the entire web in Britain could turn to treacle. Warren Pole reports on the fragile network of ocean cabling that keeps the modern world turning, the madcap economics of internet supply-and why it will run out of space by 2014 unless scientists think of something&#8230; fast.”</p>
<p>While we&#8217;re pushing bandwidth at the final mile (I&#8217;m able to get 25Mbps down, and that&#8217;s not even on FIOS), we&#8217;re going to run in to significant snags at the key chokepoints &#8211; the core internet infrastructure and the transoceanic cables. </p>
<p>According to <a href="http://www.dailymail.co.uk/home/moslive/article-1196775/Web-trouble-The-hidden-cables-Cornish-beach-feeding-worlds-internet.html">the article</a>, there are nine cables joining the US and England that have a capacity over 39Tbps.  </p>
<p>When I started in security in the 90s, we spent a lot of time talking about infrastructure and the core.  Then, we &#8220;solved&#8221; a lot of the bandwidth problems in the late 90s and got ahead of the game.</p>
<p>And now we&#8217;re deploying video across the net.  I watched UFC 100 the other night through Yahoo.  All of my TV is via iTunes/AppleTV.</p>
<p>We&#8217;re not prepared for users like me.  And that doesn&#8217;t even consider the idea of wholesale IPTV.  No question &#8211; the idea of trying to lay cable to solve this problem is going to be difficult to keep up with.  These cable links, which can be seen simultaneously as being tenuous and formidable, retro and high tech and innovative and shortsighted, are a model for the often unpredicted but possibly anticipated challenges that keep us in business.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Fiber+Optics' rel='tag' target='_self'>Fiber Optics</a>, <a class='technorati-link' href='http://technorati.com/tag/Internet+security' rel='tag' target='_self'>Internet security</a>, <a class='technorati-link' href='http://technorati.com/tag/Security' rel='tag' target='_self'>Security</a>, <a class='technorati-link' href='http://technorati.com/tag/security+awareness' rel='tag' target='_self'>security awareness</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/07/17/does-secure-inside-mean-secure-outside-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Networking and Security</title>
		<link>http://episteme.ca/2009/07/13/social-networking-and-security/</link>
		<comments>http://episteme.ca/2009/07/13/social-networking-and-security/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 22:50:44 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=593</guid>
		<description><![CDATA[Lately, I&#8217;ve been thinking more and more about social networking. I was reading a recent article by Eric Ogren on this issue at Searchsecurity.com. The article said: &#8220;According to a recent Websense Inc. survey, the decision has already been made by the business units with 86% of IT respondents reporting pressure to allow more social [...]]]></description>
			<content:encoded><![CDATA[<p>Lately, I&#8217;ve been thinking more and more about social networking.    I was reading a <a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1360757,00.html">recent article by Eric Ogren on this issue at Searchsecurity.com</a>.  The article said:</p>
<p>&#8220;<i>According to a recent Websense Inc. survey, the decision has already been made by the business units with 86% of IT respondents reporting pressure to allow more social networking in the business. The message resonates loud and clear to security: Resistance to advances in technology is futile; find secure ways that business can move forward.</i>&#8221;</p>
<p>It seems obvious that the more social networking we do, the more vulnerable we make ourselves to breeches in security. Viruses can spread quickly, data can be compromised and entire systems can be severely hampered.</p>
<p>The fact is Facebook offers a variety of ways for those in the same company to interact and for various organizations to create networks &#8211; there&#8217;s business value there.  Not to mention that <a href="http://www.twitter.com">Twitter</a>, <a href="http://www.linkedin.com">LinkedIn</a>, <a href="http://www.myspace.com">MySpace</a> and other such sites, although all different, have the power to bridge a global communications gap. Both Facebook and Twitter have become popular with professionals between the ages of 25 and 35.</p>
<p>It’s evident to me that it’s virtually impossible to stop this trend towards incorporating and integrating social networking sites into the IT networks of companies. With pressure on businesses to allow the use of such sites comes the need for controls, common sense and regulations.  While I&#8217;m a huge fan of incorporating social networking in to business, there&#8217;s definitely an important control issue here.  Here are a few questions I encourage anyone to consider before using a social networking site in tandem with his/her business.</p>
<p><i><b>Why are you deciding to incorporate a social networking site?</b></i><br />
There’s no doubt that such sites make communication easier. That’s a given. But you have to determine the reason for this expanded communication and how much control is needed. You’ll need to develop protocols for using the site within your company and other protocols in utilizing the site when dealing with vendors, clients and the general public.</p>
<p><i><b>Which features will your employees be able to access and which will your business utilize in its public profile?</b></i><br />
Each social networking site offers a range of choices to its users. As an example, if you elect to go with Facebook, a range of choices await you as to how much information is public, which tools are made available and how participants can interact. Are Wall postings appropriate, should Status updates be allowed and which groups, if any, will be established? These questions and others are appropriate for the manner in which the network is used within the company and amongst the general public, clients and vendors.</p>
<p><b><i>What controls will you put around the use of the technology?</b></i><br />
Once you decide to incorporate a social networking site, you’ll need to develop a sound security plan and a method for checking on how individuals are using the site. Opening your business up to a site such as Facebook makes it more vulnerable to hackers, phising schemes and other security concerns. Once you open up your organization to an outside entity greater security precautions and more vigilance will be needed. Beyond just technical controls, also consider the need for policies and procedures &#8211; develop written policies, specific guidelines and a clear vision of the exact reasons for using such a site to guard against misuse, miscommunication and compromises in security. It’s the first step in helping to ensure a smooth transition by your company into the world of social networking.</p>
<p>Anybody who knows me knows that I&#8217;m a huge fan of social networking (evidence <a href="http://www.twitter.com/mmurray">Twitter</a>, <a href="http://www.linkedin.com/in/mikemurray">LinkedIn</a>, <a href="http://www.facebook.com/michael.l.murray">Facebook</a>) &#8211; as such, I welcome the fact that social networking sites are not only here to stay, but that they will continue to expand and evolve. That means that the security and business communities as a whole must also evolve and develop. </p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/facebook' rel='tag' target='_self'>facebook</a>, <a class='technorati-link' href='http://technorati.com/tag/linkedin' rel='tag' target='_self'>linkedin</a>, <a class='technorati-link' href='http://technorati.com/tag/Security' rel='tag' target='_self'>Security</a>, <a class='technorati-link' href='http://technorati.com/tag/social+networking' rel='tag' target='_self'>social networking</a>, <a class='technorati-link' href='http://technorati.com/tag/twitter' rel='tag' target='_self'>twitter</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/07/13/social-networking-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NLP is not Science</title>
		<link>http://episteme.ca/2009/04/16/nlp-is-not-science/</link>
		<comments>http://episteme.ca/2009/04/16/nlp-is-not-science/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 02:10:51 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=585</guid>
		<description><![CDATA[One of the people whose work I have enjoyed of late is Gadi Evron. I find that he and I approach problems and random things very similarly (although he blogs his results far, far more frequently than I do&#8230; mine just get saved up for classes, webinars and articles). So, Gadi posted recently about his [...]]]></description>
			<content:encoded><![CDATA[<p>One of the people whose work I have enjoyed of late is <a href="http://gevron.livejournal.com/">Gadi Evron</a>. I find that he and I approach problems and random things very similarly (although he blogs his results far, far more frequently than I do&#8230; mine just get saved up for <a href="http://chicagocon.com/2009s/semasterclass.html">classes</a>, <a href="http://www.ethicalhacker.net/content/view/242/2/">webinars</a> and <a href="http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/board,72.0/">articles</a>).</p>
<p>So, <a href="http://gevron.livejournal.com/17290.html">Gadi posted recently about his disappointment with NLP</a>.  It&#8217;s not the first time I&#8217;ve heard these arguments, and they all come down to a single, fundamental misunderstanding:</p>
<p>What we commonly call &#8220;NLP&#8221; is not science.  Nor is it even scientific.</p>
<p>Most of this confusion comes out of the distinct issue that <a href="http://www.johngrinder.com/">John Grinder</a> called out in his book <a href="http://www.amazon.com/Whispering-Wind-Carmen-Bostic-Clair/dp/0971722307/episteme-20">Whispering In the Wind</a>.  The thing that was originally &#8220;NLP&#8221; was a project that attempted to model successful people, notice the patterns of language and behavior, and replicate them.  (This, Grinder refers to as &#8220;NLP<sub>modelling</sub>&#8220;).   </p>
<p>NLP<sub>modelling</sub> was not scientific, but at least its principles were sound.  Grinder and Bandler went and sat in the room with three strong therapists and learned to &#8220;act like&#8221; those therapists.  They kept doing so until they were able to replicate the behavior.  And then they continued to do so until they gained conscious ability to explain <i>how</i> they replicated the behavior.</p>
<p>While none of this was science, at least there was a principle behind it.</p>
<p>Where it all went to H-E-double-hockey-sticks is when they wrote down what they did and tried to explain how they replicated that behavior.    This was a fool&#8217;s errand in some ways&#8230; there are grave epistemological concerns here &#8211; it&#8217;s beyond difficult to take your own behavior, translate it into conscious understanding and then try to convey it to others in language.  It&#8217;s the same reason that great baseball players aren&#8217;t often good coaches &#8211; when you&#8217;re really good at something, it can often be difficult to teach others.   Grinder once noted that when <a href="http://en.wikipedia.org/wiki/Gregory_Bateson">Bateson</a> reviewed their work, his comment was: &#8220;Shoddy Epistemology.&#8221;  Bateson was accurate, and this is where things started to get wonky.</p>
<p>This is because NLP<sub>modelling</sub>  is not what most people call &#8220;NLP&#8221;.  When referring to NLP, most people are referring to the things that were written down &#8211; the hypothesis explanations that were posed by <a href="http://www.johngrinder.com/">Grinder</a> , <a href="http://www.richardbandler.com/">Bandler</a> and their colleagues/followers (e.g. <a href="http://www.nlpu.com/robbio.htm">Dilts</a>, <a href="http://www.steveandreas.com/">the Andreas&#8217;</a>, etc.) to explain how they replicated behavior.  These are what Grinder calls &#8220;NLP<sub>application</sub>&#8220;).  </p>
<p>Unfortunately, because of the epistemological concerns, NLP<sub>application</sub> is about as scientific as me trying to predict the weather by sticking a wet finger in the air.  Because we can hypothesize just about anything.  I can observe how certain people act, and then make up any random example of why it must be true. For example, I could tell you that people are a certain way because of the position of the moon and the stars when they were born.  <a href="http://www.astrology.com/">How crazy would that be?  </a></p>
<p><b>So, if NLP isn&#8217;t science, what are we to do?</b></p>
<p>Most people want to throw the baby out with the bath water.  I&#8217;m a big fan of the original project &#8211; let&#8217;s look at people who get a particular result, and figure out how they do it.</p>
<p>But if you want to make it science, then turn around and figure out <b>how</b> it works.</p>
<p>Anyone who has looked at NLP has seen the following chart:</p>
<p><img src="http://completelymental.net/eyes.gif">  (Borrowed from http://completelymental.net/ )</p>
<p>The thing is, anybody who has tried to study whether it works finds that it doesn&#8217;t.  Yet, many NLP people swear that there&#8217;s some efficacy in watching people&#8217;s eye patterns and using them to discern how people are thinking.</p>
<p>I was lucky enough to study NLP with <a href="http://www.nlpcanada.com/">Linda Ferguson and Chris Keeler at NLP Canada</a>, and they get it.  Linda was the first to point out to me that what Grinder &#038; Bandler probably noticed (unconsciously) was the same set of patterns that <a href="http://www.paulekman.com/">Paul Ekman</a> has noticed &#8211; we express many feelings and emotions in very small and quick ways with the musculature around our eyes.</p>
<p>So, while eye accessing cues don&#8217;t work, we find that paying close attention to that region of the face leads us to a detailed understanding of someone&#8217;s emotional state.</p>
<p>This is what happens when you approach a project without solid epistemology &#8211; you end up with many of the right behaviors, but the wrong reasons behind them.  </p>
<p>And, sometimes, you end up with a whole pile of dogma and &#8220;true believers&#8221;.  But that&#8217;s the subject of a different rant.  </p>
<p>Until then, realize: NLP is not science.  There is some useful background to take the tools and attempt to use them, and, even better, combine them with other, more useful science to figure out how to tie it together.</p>
<p>(As a shameless plug, I&#8217;m the one taking the lead on much of the &#8220;NLP-like&#8221; content at the <a href="http://www.chicagocon.com/2009s/semasterclass.html">SE Master Class</a>.  I say &#8220;NLP-like&#8221;, because it won&#8217;t be based on either NLP<sub>application</sub> or NLP<sub>modelling</sub>.  But anyone with an NLP background will find similarities on the things that really work in the real world, without much of the NLP and hypnosis dogma that goes around.)</p>

<!-- start wp-tags-to-technorati 1.02 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/04/16/nlp-is-not-science/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Six Sigma and App Security</title>
		<link>http://episteme.ca/2009/03/20/six-sigma-and-app-security/</link>
		<comments>http://episteme.ca/2009/03/20/six-sigma-and-app-security/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 16:56:14 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=580</guid>
		<description><![CDATA[From a note that Hoff tweeted, I ended up reading Jeremiah&#8217;s awesome new post in which he asked the following question: &#8220;How do you achieve quick wins in Web Application Security, rooted in software, with measurable results that CIOs would appreciate? &#8221; I started a thread on twitter with my answer, but that&#8217;s not the [...]]]></description>
			<content:encoded><![CDATA[<p>From a note that <a href="http://www.rationalsurvivability.com">Hoff</a> tweeted, I ended up reading <a href="http://jeremiahgrossman.blogspot.com/2009/03/quick-wins-and-web-application-security.html">Jeremiah&#8217;s awesome new post</a> in which he asked the following question:</p>
<p>&#8220;<i>How do you achieve quick wins in Web Application Security, rooted in software, with measurable results that CIOs would appreciate? </i>&#8221;</p>
<p>I started a thread on twitter with my answer, but that&#8217;s not the format for reasoned discourse and detailed thinking.  So, I decided to write about my thoughts a little more in detail here.</p>
<p>The answer is simple:  <b><i>You don&#8217;t.</b></i></p>
<p>Jeremiah laid out most of the reasons in his post, but it comes down to one thing: an SDL improvement effort is a multi-faceted, process-based set of changes that lead to a long-term process that creates security through up-front consideration, not through solving one-off tactical issues.</p>
<p>In that way, the effort that Jeremiah lays out is exactly the same as that faced by the Quality proponents and <a href="http://en.wikipedia.org/wiki/W._Edwards_Deming">Deming</a> followers in the 80s.  Everyone &#8220;knew&#8221; that quality was important, but nobody could ever justify the up-front costs of redesigning an entire process to create that kind of quality.  </p>
<p>In short, there were no short-term wins.</p>
<p>Yet, today, almost every large corporation has implemented some form of Six Sigma/Lean/TQM program at some point.  </p>
<p>The point I was making on <a href="http://www.twitter.com/mmurray">twitter</a> was that, if there&#8217;s a model to follow to find the way to make application security palatable to the C-suite, it&#8217;s the adoption model of Six Sigma.</p>
<p>I see three key points to the adoption of quality as a movement.</p>
<p><strong>Business Pain without a forseeable end</strong><br />
The main driver behind the quality movements of the late 80s and early 90s was the pain that most organizations were feeling.  The economic recovery of the 80s lead to a strong competitive environment, with extra pain coming from overseas competition.  In the case of the auto industry, it was Japan.  For other orgs, the pain came from other offshore and domestic competitors.   And as the economy slowed in the late 80s/early 90s recession, many of these organizations looked for a sustainable competitive advantage to give them an opportunity to survive when others in their space couldn&#8217;t.</p>
<p>The economy is leading us to a similar state today.  Businesses are looking for an advantage as the economy turns down.  (Note that I don&#8217;t believe that application security leads to a sustainable competitive advantage in the same way that Lean and 6S do.  I&#8217;m just making a parallel between the conditions).</p>
<p><strong>Examples of Success</strong><br />
The most important factor in the adoption of quality processes was the very public example of success put forward by Honeywell, Motorola and GE.  From <a href="http://en.wikipedia.org/wiki/Six_Sigma#Historical_overview">Wikipedia</a>:</p>
<p>&#8220;<i>Other early adopters of Six Sigma who achieved well-publicized success include Honeywell (previously known as AlliedSignal) and General Electric, where the method was introduced by Jack Welch.[8] By the late 1990s, about two-thirds of the Fortune 500 organizations had begun Six Sigma initiatives with the aim of reducing costs and improving quality.</i>&#8221;</p>
<p>Because these organizations put forward incredibly public accounts of their success, it was easy for other C-level executives to embrace the potential of the initiatives.  While every leader wants to believe that they&#8217;re an individual, the top levels of business are very much a CYA culture &#8211; only the success of one&#8217;s peers allows one to take the risk.</p>
<p>This lead to&#8230;</p>
<p><strong>Quality is Free</strong><br />
As these successes built, documentation started to build the belief in this type of program.  This eventually lead to the mantra that &#8220;Quality is Free&#8221; &#8211; the idea that a successfully implemented quality program pays for itself in the long-term, regardless of the short-term cost/pain associated with the implementation.</p>
<p>My point to  <a href="http://jeremiahgrossman.blogspot.com/2009/03/quick-wins-and-web-application-security.html">Jeremiah</a> is that the Application Security community is living without the latter two of these points &#8211; we have no examples (save perhaps Microsoft) that show that a consistent focus on process-oriented security is successful.  And we have no data that backs up the long-term cost benefit of the initiative.</p>
<p>In a situation where the task requires long-term process reorientation, short term wins aren&#8217;t possible. We need to follow the model of the adoption of Six Sigma:  We need to court those forward-thinking, Jack Welch-type CIOs who are willing to make this happen, and then have them make their successes public.  </p>
<p>Only then will we see a widespread adoption of security-focused SDL reengineering initiatives.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/03/20/six-sigma-and-app-security/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Modern Social Engineering</title>
		<link>http://episteme.ca/2009/03/17/modern-social-engineering/</link>
		<comments>http://episteme.ca/2009/03/17/modern-social-engineering/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 20:59:25 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[chicagocon]]></category>
		<category><![CDATA[Chris Nickerson]]></category>
		<category><![CDATA[influence]]></category>
		<category><![CDATA[SE Master Class]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=577</guid>
		<description><![CDATA[I&#8217;ve spent a lot of my time lately working on projects related to social engineering. Writing articles, prepping class material, and just generally having conversations and brushing up on my skills. For those that don&#8217;t already know, Chris Nickerson and I are doing a full five-day class on Social Engineering at ChicagoCon in May, and [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve spent a lot of my time lately working on projects related to social engineering.  Writing articles, prepping class material, and just generally having conversations and brushing up on my skills.  For those that don&#8217;t already know, <a href="http://www.laresconsulting.com">Chris Nickerson</a> and I are doing a <a href="http://chicagocon.com/2009s/semasterclass.html">full five-day class on Social Engineering at ChicagoCon</a> in May, and there&#8217;s much to prep for.  </p>
<p>In preparation, and to give people a brief taste, Chris and I did a webinar last week.  <a href="http://www.ethicalhacker.net/content/view/242/2/">Check out the video for the webinar over at EH.net</a></p>
<p>Also, since Chris leaked it already (when someone SE&#8217;d him on <a href="http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,3616.0/">EH.net</a>), I&#8217;ll post a small snippet of one afternoon of course outline here:</p>
<p><i>Determining Tests<br />
•         Types of testing<br />
o   Direction of attacks<br />
o   External<br />
?  Electronic<br />
•         Phishing<br />
•         Client-side / browser side exploitation<br />
•   Metasploit<br />
•   Core<br />
•   By hand</p>
<p>•         Malicious attachments<br />
?  Person to Person<br />
•         Phone<br />
•         Written<br />
•         Social Networks/IM<br />
•         Public Manipulation<br />
o   Internal<br />
?  Person to Person<br />
•         Gaining access to physical credentials<br />
•         Solicitation<br />
•         Direct interaction<br />
•         Creating spies / information leak sources<br />
o   Methods (al mamalik,qulaam, kgb,cia,others)<br />
o   Trading information<br />
•         Becoming an employee<br />
?  Electronic<br />
•         CD/Key drops<br />
•         Authentication bypass<br />
•         Key /perimeter bypass<br />
•         Falsification of credentials<br />
•         RFID/ HID copying </i></p>
<p>Check out the <a href="http://www.ethicalhacker.net/content/view/242/2/">webinar</a>, and hopefully you sign up for the <a href="http://chicagocon.com/2009s/semasterclass.html">class</a>.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/chicagocon' rel='tag' target='_self'>chicagocon</a>, <a class='technorati-link' href='http://technorati.com/tag/Chris+Nickerson' rel='tag' target='_self'>Chris Nickerson</a>, <a class='technorati-link' href='http://technorati.com/tag/influence' rel='tag' target='_self'>influence</a>, <a class='technorati-link' href='http://technorati.com/tag/SE+Master+Class' rel='tag' target='_self'>SE Master Class</a>, <a class='technorati-link' href='http://technorati.com/tag/Security' rel='tag' target='_self'>Security</a>, <a class='technorati-link' href='http://technorati.com/tag/social+engineering' rel='tag' target='_self'>social engineering</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2009/03/17/modern-social-engineering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting Information Security Training Right</title>
		<link>http://episteme.ca/2008/12/17/getting-information-security-training-right/</link>
		<comments>http://episteme.ca/2008/12/17/getting-information-security-training-right/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 23:06:44 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CEH]]></category>
		<category><![CDATA[ethical hacker]]></category>
		<category><![CDATA[ethical hacking]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec training]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[penetration test training]]></category>
		<category><![CDATA[security certification]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=568</guid>
		<description><![CDATA[Anybody who has talked to me in the past few years knows that one of the things that I&#8217;m most passionate about is evolving one&#8217;s career. Whether it&#8217;s the work I do with career coaching, my talks and research with Lee Kushner on infosec careers, or just my blog posts here, it&#8217;s a favorite topic [...]]]></description>
			<content:encoded><![CDATA[<p>Anybody who has talked to me in the past few years knows that one of the things that I&#8217;m most passionate about is evolving one&#8217;s career.  Whether it&#8217;s the work I do with <a href="http://www.connectedcareer.com">career coaching</a>, my talks and research with <a href="http://www.ljkushner.com">Lee Kushner</a> on <a href="http://www.infosecleaders.com">infosec careers</a>, or just my blog posts here, it&#8217;s a favorite topic of mine.</p>
<p>The topic of certifications go hand in hand with career management &#8211; in fact, when Lee and I talk, one of our slides lists &#8220;What certification should I get?&#8221; as our &#8220;<i>least favorite question</i>&#8220;.  Because we get it every time we talk to anybody.</p>
<p>One of the other things I&#8217;ve been doing of late is teaching classes to help people become more effective penetration testers.  Penetration testing is where I started my career, and I really enjoy helping people learn those skills and develop that part of their capabilities.  So, for the first few months after I left Neohapsis, I was working with one of the more well-known training organizations, and I expected to be able to make a difference. </p>
<p>Unfortunately, my expectations were underwhelmed.  Where the organization promised &#8220;deluxe acommodations&#8221; for their students, we were booked at the Quality Inn.  Where they promised &#8220;cutting-edge techniques&#8221;, they got information and exercises that were 5 years old.  </p>
<p>Anybody who has worked with me knows I&#8217;m a bit of a stickler for doing right by my clients.  And this wasn&#8217;t right.   And I was frustrated because, despite my emails to the leadership of the organization, I was seeing no improvement.</p>
<p>So, I was sharing this frustration with my associates over at <a href="http://www.foregroundsecurity.com">Foreground Security</a> (who also run <a href="http://www.thehackeracademy.com">The Hacker Academy</a>.  And they agreed with me.   But they did it one better: they challenged me.  <a href="http://foregroundsecurity.com/index.php?section=21">Dave and Aaron</a> said:</p>
<p>&#8220;Can you do better?&#8221;</p>
<p>When I told them I could, they threw down the gauntlet.  </p>
<p>&#8220;Give it a shot.  What would it need?&#8221;</p>
<p>After a few conversations, we came up with a few different things.  First and foremost, the curriculum needs to be up to date.   No more teaching stuff that is five years old and calling it &#8220;state of the art&#8221;.   Exercises should be consistent with what <a href="http://www.foregroundsecurity.com">Foreground&#8217;s</a> team of pen-testers are seeing on real engagements on a daily basis.   If tools/exploits/techniques stop being relevant, then we teach their replacements.  </p>
<p>Second: the curriculum needs to be <i>KEPT</i> up to date.  And so do the students. And the students need access to a quarterly update of all the things that are new.  No more of the &#8220;get &#8216;em out the door&#8221; way of doing things &#8211; let&#8217;s ensure that every student who goes through this class is given access to continuing information that will let them stay current.</p>
<p>Third: Let&#8217;s give them real facilities with solid, repeatable technology and processes.  And it shouldn&#8217;t matter whether they take a class from us in Orlando, DC, San Francisco or Switzerland, the experience should be the same.</p>
<p>And, finally: Instructors should be trained to give the same material in the same way each time.   </p>
<p>In short, we&#8217;ll run it like a business.  And we&#8217;ll treat our students the way that they deserve to be treated.</p>
<p>Well, Dave and Aaron liked that so much that they told me to go for it.  And they <a href="http://www.prweb.com/releases/2008/12/prweb1759624.htm">put out a press release about it</a>.   Our first class with the new curriculum I&#8217;m designing is going to be in mid-January, in Orlando.  Because, really&#8230; who wants to be anywhere but Florida in January?</p>
<p><a href="mailto:mmurray@episteme.ca">Email me</a> if you have questions.  Or email <a href="mailto:aaron@thehackeracademy.com">Aaron Cohen</a> to find out the logistics, price, signup, etc. </p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/CEH' rel='tag' target='_self'>CEH</a>, <a class='technorati-link' href='http://technorati.com/tag/ethical+hacker' rel='tag' target='_self'>ethical hacker</a>, <a class='technorati-link' href='http://technorati.com/tag/ethical+hacking' rel='tag' target='_self'>ethical hacking</a>, <a class='technorati-link' href='http://technorati.com/tag/information+security' rel='tag' target='_self'>information security</a>, <a class='technorati-link' href='http://technorati.com/tag/infosec+training' rel='tag' target='_self'>infosec training</a>, <a class='technorati-link' href='http://technorati.com/tag/penetration+test' rel='tag' target='_self'>penetration test</a>, <a class='technorati-link' href='http://technorati.com/tag/penetration+test+training' rel='tag' target='_self'>penetration test training</a>, <a class='technorati-link' href='http://technorati.com/tag/Security' rel='tag' target='_self'>Security</a>, <a class='technorati-link' href='http://technorati.com/tag/security+certification' rel='tag' target='_self'>security certification</a>, <a class='technorati-link' href='http://technorati.com/tag/training' rel='tag' target='_self'>training</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/12/17/getting-information-security-training-right/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The Importance of Turnover</title>
		<link>http://episteme.ca/2008/12/08/the-importance-of-turnover/</link>
		<comments>http://episteme.ca/2008/12/08/the-importance-of-turnover/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 19:08:52 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bill belichick]]></category>
		<category><![CDATA[new england patriots]]></category>
		<category><![CDATA[patriots]]></category>
		<category><![CDATA[tom brady]]></category>
		<category><![CDATA[turnover]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=563</guid>
		<description><![CDATA[We in North America love our sports metaphors. I was reminded of that recently when I was speaking with the president of a successful and relatively forward-thinking security company, and he was telling me about his management philosophy. &#8220;I want the people on my team to stick around. I mean, look at the New England [...]]]></description>
			<content:encoded><![CDATA[<p>We in North America love our sports metaphors.  I was reminded of that recently when I was speaking with the president of a successful and relatively forward-thinking security company, and he was telling me about his management philosophy.</p>
<p>&#8220;<i><b>I want the people on my team to stick around.  I mean, look at the New England Patriots &#8211; you think they build a dynasty with huge amounts of turnover?  Nope &#8211; they kept the core of that team intact over the years.</i></b>&#8221;</p>
<p>Well, I personally don&#8217;t agree with his stance.  I have always believed that teams that stay together for too long lose the freshness and innovativeness that is required for success in these times.  I heard a great quote (attributed to <a href="http://www.tompeters.com">Tom Peters</a>) recently:</p>
<p>&#8220;If the rate of change outside your organization is greater than the rate of change inside your organization, then the end is near.&#8221;</p>
<p>Brilliant.  And true (in my experience).</p>
<p>But not in the opinion of my colleague.  Nor, in the opinion of the New England Patriots, apparently.</p>
<p>But I&#8217;m a football fan as well, and something about that didn&#8217;t smell right.</p>
<p>So, I put together <a href="http://spreadsheets.google.com/pub?key=pYod0vMQbGvzk9du7ofR5bg&#038;gid=7">some research on the matter</a>.  And it showed exactly what I&#8217;d expect &#8211; the New England Patriots are a dynasty not because they keep their core together, but because <b>they have built a system that manages turnover</b>.</p>
<p>To summarize the research: from 2003-2008, the Patriots had approximately 33% turnover among staff and players &#8211; that is, the entire team could be expected to be replaced EVERY 3 YEARS.  Yet they remained competitive during that time.</p>
<p>In fact, only 13 players TOTAL (3 offensive, 5 defensive, and 5 coaches) were on the team for all five of those years.  (And they&#8217;re hardly &#8220;core&#8221;, unless one considers the long snapper and the running backs coach &#8220;core&#8221;).  The two most important of those are Tom Brady and Bill Belichick, and even Brady&#8217;s importance has been minimized this year, given the play of Matt Cassel in the same system.</p>
<p>More importantly, when you look at the coaches, the turnover has all been where it would be presumed to be most important: at the top.  The team has used 3 offensive coordinators and 3 defensive coordinators in those 5 years &#8211; in product development terms, that&#8217;s like switching VPs of Marketing and Engineering 3 times in 5 years.</p>
<p>So, I assert that the New England Patriots make my point: the reason that a company (or a football team) is successful isn&#8217;t its ability to avoid turnover, but its ability to create (esp. talent development and knowledge capture) systems and (most importantly) a culture that minimizes the impact of turnover.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/bill+belichick' rel='tag' target='_self'>bill belichick</a>, <a class='technorati-link' href='http://technorati.com/tag/Business' rel='tag' target='_self'>Business</a>, <a class='technorati-link' href='http://technorati.com/tag/Management' rel='tag' target='_self'>Management</a>, <a class='technorati-link' href='http://technorati.com/tag/new+england+patriots' rel='tag' target='_self'>new england patriots</a>, <a class='technorati-link' href='http://technorati.com/tag/patriots' rel='tag' target='_self'>patriots</a>, <a class='technorati-link' href='http://technorati.com/tag/tom+brady' rel='tag' target='_self'>tom brady</a>, <a class='technorati-link' href='http://technorati.com/tag/turnover' rel='tag' target='_self'>turnover</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/12/08/the-importance-of-turnover/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Coming Soon: Security People on Video</title>
		<link>http://episteme.ca/2008/12/04/coming-soon-security-people-on-video/</link>
		<comments>http://episteme.ca/2008/12/04/coming-soon-security-people-on-video/#comments</comments>
		<pubDate>Fri, 05 Dec 2008 01:28:18 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[demos on demand]]></category>
		<category><![CDATA[demos on demand for security]]></category>
		<category><![CDATA[it harvest]]></category>
		<category><![CDATA[michael santarcangelo]]></category>
		<category><![CDATA[richard steinnon]]></category>
		<category><![CDATA[security catalyst]]></category>
		<category><![CDATA[security video]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=558</guid>
		<description><![CDATA[Because what we all need is to see more of that, right? Seriously, though &#8211; I&#8217;m working with a cool new project and I wanted to share a bit of a preview. The site is called Demos on Demand for Security. It&#8217;s sort of like a Revision3 for Security, and has brought aboard some pretty [...]]]></description>
			<content:encoded><![CDATA[<p>Because what we all need is to see more of that, right?</p>
<p>Seriously, though &#8211; I&#8217;m working with a cool new project and I wanted to share a bit of a preview.  The site is called <a href="http://www.demosondemand.com/dod_security/001/page/dods_demo_2.html">Demos on Demand for Security</a>.  It&#8217;s sort of like a <a href="http://revision3.com">Revision3</a> for Security, and has brought aboard some pretty cool people as hosts.  I&#8217;m not going to share all the names, but it should be obvious from the <a href="http://www.demosondemand.com/clients/dod_security/002/page/videos.htm">sample videos</a> that <a href="http://www.it-harvest.com">Richard Steinnon</a> is going to be one of the hosts.   (If you&#8217;re interested in being a host or a guest, feel free to <a href="mailto:mmurray@episteme.ca">email me</a></p>
<p>I&#8217;m also excited to announce that I&#8217;ll be doing a regular (at least a couple times per month) show with my favorite person in the industry to debate with &#8211; the always fun and lively <a href="http://www.securitycatalyst.com">Michael Santarcangelo</a>.  Sort of a Hannity and Combs of security, so to speak.  With hard-hitting (but entirely &#8220;fair and balanced&#8221;) interviews of the people in the security industry.  </p>
<p>The first episode of that show should be up in the next few weeks, so keep watching both here, and at the  <a href="http://www.demosondemand.com/clients/dod_security/002/page/videos.htm">DoDS site</a> for updates.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/demos+on+demand' rel='tag' target='_self'>demos on demand</a>, <a class='technorati-link' href='http://technorati.com/tag/demos+on+demand+for+security' rel='tag' target='_self'>demos on demand for security</a>, <a class='technorati-link' href='http://technorati.com/tag/it+harvest' rel='tag' target='_self'>it harvest</a>, <a class='technorati-link' href='http://technorati.com/tag/michael+santarcangelo' rel='tag' target='_self'>michael santarcangelo</a>, <a class='technorati-link' href='http://technorati.com/tag/richard+steinnon' rel='tag' target='_self'>richard steinnon</a>, <a class='technorati-link' href='http://technorati.com/tag/Security' rel='tag' target='_self'>Security</a>, <a class='technorati-link' href='http://technorati.com/tag/security+catalyst' rel='tag' target='_self'>security catalyst</a>, <a class='technorati-link' href='http://technorati.com/tag/security+video' rel='tag' target='_self'>security video</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/12/04/coming-soon-security-people-on-video/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Working hard</title>
		<link>http://episteme.ca/2008/12/01/working-hard/</link>
		<comments>http://episteme.ca/2008/12/01/working-hard/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 17:16:47 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[arizona cardinals]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[derek brooks]]></category>
		<category><![CDATA[hard work]]></category>
		<category><![CDATA[nfl]]></category>
		<category><![CDATA[peter king]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=554</guid>
		<description><![CDATA[Over the years, I have become a big fan of football &#8211; less because of what goes on during the games as what happens behind the scenes. One need only look at the life of a professional football player or coach to understand the difference between the work ethic of someone who is a moderate [...]]]></description>
			<content:encoded><![CDATA[<p>Over the years, I have become a big fan of football &#8211; less because of what goes on during the games as what happens behind the scenes.  One need only look at the life of a professional football player or coach to understand the difference between the work ethic of someone who is a moderate success, and someone who ascends to the ultimate top of his/her field.</p>
<p>This has been a fantastic week for that curiosity on my part.  First, there&#8217;s a great article in Sports Illustrated about the preparation that Derek Brooks makes <b>every week</b>.  The article is reprinted <a href="http://www.nflgridirongab.com/2008/11/25/check-out-peter-kings-recent-si-article-on-derrick-brooks/">here</a>.  Relevant quote: </p>
<p>&#8220;<i>It may be surprising that a 10-time Pro Bowl linebacker would study players who are still three or four years from making it to the NFL. But even now, the day before he faced the Vikings, the 35-year-old Brooks settled into his den again to watch Florida quarterback Tim Tebow and running back Percy Harvin in the Gators’ rout of South Carolina. “Some people relax or get recharged by going to Europe or going to the beach,” Brooks said. “For me it’s studying young kids. The one edge I feel no one will ever have over me is the mental edge of knowing players.”</i></p>
<p>This is a guy who is a veteran and future Hall of Famer.  Anybody care to guess what got him there?</p>
<p>Even more interesting is this week&#8217;s version <a href="http://sportsillustrated.cnn.com/2008/writers/peter_king/11/30/week13/2.html">Peter King&#8217;s &#8220;Monday Morning QB&#8221; column</a> &#8211; King breaks down the week that the Arizona Cardinals just had and exactly what the schedule was: </p>
<p>&#8220;<i>From 8 p.m. to midnight, the coaches met to finish the gameplan, working on red-zone, goal-line and nickel plays. Most coaches were at the facility for 17 hours, minimum, on Monday.</i>&#8221;</p>
<p>The work required to be successful at the level of NFL players should be instructive as to what it takes to be at that level in any career or job.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/arizona+cardinals' rel='tag' target='_self'>arizona cardinals</a>, <a class='technorati-link' href='http://technorati.com/tag/career' rel='tag' target='_self'>career</a>, <a class='technorati-link' href='http://technorati.com/tag/derek+brooks' rel='tag' target='_self'>derek brooks</a>, <a class='technorati-link' href='http://technorati.com/tag/hard+work' rel='tag' target='_self'>hard work</a>, <a class='technorati-link' href='http://technorati.com/tag/nfl' rel='tag' target='_self'>nfl</a>, <a class='technorati-link' href='http://technorati.com/tag/peter+king' rel='tag' target='_self'>peter king</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/12/01/working-hard/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Branding Exercise</title>
		<link>http://episteme.ca/2008/10/29/a-branding-exercise/</link>
		<comments>http://episteme.ca/2008/10/29/a-branding-exercise/#comments</comments>
		<pubDate>Wed, 29 Oct 2008 17:25:28 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[brand you]]></category>
		<category><![CDATA[branding]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[Career Skills]]></category>
		<category><![CDATA[personal branding]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=327</guid>
		<description><![CDATA[I talk about it all the time: the most important thing that you must do for your career is branding your name. Your &#8220;Personal Brand&#8221; IS your career. I happened upon an interesting thought exercise for branding when talking with Melina the other day. We were talking about her business, and I asked the following [...]]]></description>
			<content:encoded><![CDATA[<p>I talk about it all the time: the most important thing that you must do for your career is branding your name.  Your &#8220;Personal Brand&#8221; IS your career.</p>
<p>I happened upon an interesting thought exercise for branding when talking with <a href="http://www.melinamurray.com">Melina</a> the other day.  We were talking about her business, and I asked the following question:</p>
<p>&#8220;<i>What problem do you want your clients to have when they think of your name?</i>&#8221;</p>
<p>That&#8217;s an incredibly powerful way to conceive of branding.  It speaks to all elements of what a brand is &#8211; what you&#8217;re an expert on, what you&#8217;re known for, and how you help your clients on a daily basis.</p>
<p>This is true whether you&#8217;re branding a business or developing your personal brand.  Change it around for personal branding: </p>
<p><i>What problems do you want your boss/peers/colleagues to have when they think about calling you?</i></p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/brand+you' rel='tag' target='_self'>brand you</a>, <a class='technorati-link' href='http://technorati.com/tag/branding' rel='tag' target='_self'>branding</a>, <a class='technorati-link' href='http://technorati.com/tag/career' rel='tag' target='_self'>career</a>, <a class='technorati-link' href='http://technorati.com/tag/Career+Skills' rel='tag' target='_self'>Career Skills</a>, <a class='technorati-link' href='http://technorati.com/tag/personal+branding' rel='tag' target='_self'>personal branding</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/10/29/a-branding-exercise/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Job Searches and Career Management</title>
		<link>http://episteme.ca/2008/10/27/job-searches-and-career-management/</link>
		<comments>http://episteme.ca/2008/10/27/job-searches-and-career-management/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 19:24:18 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[career management]]></category>
		<category><![CDATA[Career Skills]]></category>
		<category><![CDATA[jason alba]]></category>
		<category><![CDATA[jibberjobber]]></category>
		<category><![CDATA[job search]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=496</guid>
		<description><![CDATA[Over at his blog today, Jason Alba posted a bunch of comparisons of Job Search and Career Management, all in the form: Job Search is to _____ as Career Management is to _____ I figured I&#8217;d post some additional ones: Job search is to accident as career management is to plan. Job search is to [...]]]></description>
			<content:encoded><![CDATA[<p>Over at his blog today, <a href="http://www.jibberjobber.com/blog/2008/10/27/job-search-is-to-_____-as-career-management-is-to-_____/">Jason Alba posted a bunch of comparisons of Job Search and Career Management</a>, all in the form: </p>
<p><b>Job Search is to _____ as Career Management is to _____</b></p>
<p>I figured I&#8217;d post some additional ones:</p>
<p><i>Job search is to <b>accident</b> as career management is to <b>plan</b>.</i></p>
<p><i>Job search is to <b>workout</b> as career management is to <b>training</b>.</i></p>
<p><i>Job search is to <b>dating</b> as career management is to <b>marriage</b>.</i></p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/career' rel='tag' target='_self'>career</a>, <a class='technorati-link' href='http://technorati.com/tag/career+management' rel='tag' target='_self'>career management</a>, <a class='technorati-link' href='http://technorati.com/tag/Career+Skills' rel='tag' target='_self'>Career Skills</a>, <a class='technorati-link' href='http://technorati.com/tag/jason+alba' rel='tag' target='_self'>jason alba</a>, <a class='technorati-link' href='http://technorati.com/tag/jibberjobber' rel='tag' target='_self'>jibberjobber</a>, <a class='technorati-link' href='http://technorati.com/tag/job+search' rel='tag' target='_self'>job search</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/10/27/job-searches-and-career-management/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Seth Godin on Choosing A Job</title>
		<link>http://episteme.ca/2008/10/27/seth-godin-on-choosing-a-job/</link>
		<comments>http://episteme.ca/2008/10/27/seth-godin-on-choosing-a-job/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 19:13:51 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[Career Skills]]></category>
		<category><![CDATA[forget the parachute]]></category>
		<category><![CDATA[seth godin]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=494</guid>
		<description><![CDATA[Seth wrote a post recently on the importance of where you work and its effect on your career. In the post, he said: &#8220;And yet, there are plenty of books about getting a job, but no books I know of about choosing a job.&#8221;&#8221; That&#8217;s exactly why I wrote Forget the Parachute, Let Me Fly [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://sethgodin.typepad.com/seths_blog/2008/10/be-careful-of-w.html">Seth wrote a post recently</a> on the importance of where you work and its effect on your career.  In the post, he said:</p>
<p>&#8220;<i>And yet, there are plenty of books about getting a job, but no books I know of about choosing a job.&#8221;</i>&#8221;</p>
<p>That&#8217;s exactly why I wrote <a href="http://www.forgettheparachute.com">Forget the Parachute, Let Me Fly the Plane</a> last year.  One of the most frustrating experiences I&#8217;ve gone through while coaching people on their careers is to have them accept jobs without doing the background research on the company.</p>
<p>So, I wrote a book about how to get a job that actually works for you. </p>
<p>You know, I was going to write an entire post on this&#8230; but I said it best on pg. 74 of <a href="http://www.forgettheparachute.com">Forget the Parachute</a>:</p>
<hr />
<b>“But, what about Monster?  What about Craigslist?”.</b>   That damn inner skeptic again.   <b>“Shouldn’t I just type in the name of my job on the internet and apply to anybody who has it?” </b></p>
<p><font color="purple"><b>No.   We’re going to align you with companies first. Then, you’re going to go get the job from them.  Because you’re already like them and they’re like you: if we align right, it’ll be like you already have the job.  They just don’t know it yet. </b></font></p>
<p><b>“But&#8230;”,</b>  I can hear your inner skeptic saying.  <b>“That’s not how I learned it.“ </b></p>
<p>Of course it’s not.  Because what you learned is what everyone else does.  And it’s why I had the opportunity to quote the statistic earlier that 3 in every 4 people around you is looking for a new job right now.  </p>
<p><b>If you do what you’ve always done, you’ll get what you’ve always got. </b></p>
<hr />
<p>Then, you do a few exercises that help you to research and find companies that fit with who you are and what you&#8217;re truly looking for.</p>
<p>Seth has it right in his new post: where you work matters.  A lot.  So spend the time figuring out whether the companies you&#8217;re looking at align with who you are and where you want to go.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/career' rel='tag' target='_self'>career</a>, <a class='technorati-link' href='http://technorati.com/tag/Career+Skills' rel='tag' target='_self'>Career Skills</a>, <a class='technorati-link' href='http://technorati.com/tag/forget+the+parachute' rel='tag' target='_self'>forget the parachute</a>, <a class='technorati-link' href='http://technorati.com/tag/seth+godin' rel='tag' target='_self'>seth godin</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/10/27/seth-godin-on-choosing-a-job/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ChicagoCon &#8211; Recession-proofing Your Career</title>
		<link>http://episteme.ca/2008/10/24/chicagocon-recession-proofing-your-career/</link>
		<comments>http://episteme.ca/2008/10/24/chicagocon-recession-proofing-your-career/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 16:08:34 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[breakout session]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[chicagocon]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[information security career]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=469</guid>
		<description><![CDATA[So, as I mentioned in this post, I&#8217;ll be doing a breakout session next weekend at ChicagoCon. The description on the conference website is: &#8220;Information security is one of the most difficult industries to navigate a career in. The industry is new, and the skills are ever-changing. The nature of the industry is that the [...]]]></description>
			<content:encoded><![CDATA[<p>So, as I mentioned in <a href="http://episteme.ca/2008/10/21/the-best-con-you-dont-know-about/">this post</a>, I&#8217;ll be doing a breakout session next weekend at <a href="http://www.chicagocon.com">ChicagoCon</a>.  The description on the conference website is:</p>
<p>&#8220;<i>Information security is one of the most difficult industries to navigate a career in. The industry is new, and the skills are ever-changing. The nature of the industry is that the biggest threats are always in the newest technologies, which means that if you&#8217;re not actively running, you&#8217;re falling behind. Not to mention that there&#8217;s no industry standard for certification, for knowledge, or even for what &#8220;security&#8221; actually is. It&#8217;s confusing at the best of times.</p>
<p>And this isn&#8217;t the best of times.</p>
<p>As the industry gets more complex and the economy tightens, a solid career plan and the skills to pull off that plan are going to become ever more important. Industry veteran and respected career speaker and coach Mike Murray will work with the attendees of ChicagoCon to discuss the fundamental skills needed, and put the audience of this breakout session through exercises that will help clarify that plan, and move forward toward their ultimate career goals.</i>&#8221;</p>
<p>But I wanted to provide some deeper information for those who might be interested or want to know more.</p>
<p>We&#8217;re going to talk about:</p>
<ul>
<li>Uncovering Opportunities &#8211; Finding a job in troubled times</li>
<li>Life Jackets &#8211; Keeping your head above water until you&#8217;ve found that job</li>
<li>The Art of Indispensibility &#8211; Making it harder for your company to let go of you</li>
<li>Preparing for the Worst &#8211; Ensuring that you&#8217;re ready to go even before you get laid off</li>
</ul>
<p>We&#8217;ll also talk about real situations that members of the the audience are having, and I&#8217;ll be working with people in the class one-on-one to help them prepare themselves for whatever is going to happen next in their careers.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/breakout+session' rel='tag' target='_self'>breakout session</a>, <a class='technorati-link' href='http://technorati.com/tag/career' rel='tag' target='_self'>career</a>, <a class='technorati-link' href='http://technorati.com/tag/chicagocon' rel='tag' target='_self'>chicagocon</a>, <a class='technorati-link' href='http://technorati.com/tag/conference' rel='tag' target='_self'>conference</a>, <a class='technorati-link' href='http://technorati.com/tag/information+security+career' rel='tag' target='_self'>information security career</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/10/24/chicagocon-recession-proofing-your-career/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The Dumbest Prediction I&#8217;ve Heard in a While</title>
		<link>http://episteme.ca/2008/10/23/the-dumbest-prediction-ive-heard-in-a-while/</link>
		<comments>http://episteme.ca/2008/10/23/the-dumbest-prediction-ive-heard-in-a-while/#comments</comments>
		<pubDate>Thu, 23 Oct 2008 20:55:54 +0000</pubDate>
		<dc:creator>mmurray</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[focus]]></category>

		<guid isPermaLink="false">http://episteme.ca/?p=492</guid>
		<description><![CDATA[I was reading Hoff&#8217;s recent post on virtualization, and I found myself needing to write a bit of a rant. I don&#8217;t usually have much to say about what Hoff writes about, because virtualization isn&#8217;t an area that I spend any time on. But in Hoff&#8217;s critique of Tarry Singh&#8217;s latest post, there was something [...]]]></description>
			<content:encoded><![CDATA[<p>I was reading <a href="http://rationalsecurity.typepad.com/blog/2008/10/attack-of-the-virtualization-hacker-hyperbole.html">Hoff&#8217;s recent post on virtualization</a>, and I found myself needing to write a bit of a rant.  I don&#8217;t usually have much to say about what Hoff writes about, because virtualization isn&#8217;t an area that I spend any time on.  But in Hoff&#8217;s critique of <a href="http://tarrysingh.blogspot.com/2008/10/good-news-hackers-focus-on.html">Tarry Singh&#8217;s latest post</a>, there was something that blew my mind.</p>
<p><a href="http://tarrysingh.blogspot.com/2008/10/good-news-hackers-focus-on.html">Tarry asserts in his post</a> that one of the good things about hackers spending time finding vulnerabilities is that (and I quote):</p>
<p>&#8220;<i>Security and Compliance will be core focus of all organizations (as regulators will come knocking at your doorsteps)</i>&#8221;</p>
<p>Umm&#8230; I hate to say it, but that ain&#8217;t ever gonna happen.  No matter how many regulators show up on someone&#8217;s doorstep, that counts as one of the least well-thought-out predictions I&#8217;ve ever heard.</p>
<p>Simply put:
<ul>
<li>McDonald&#8217;s core focus will always be on making hamburgers.</li>
<li>Nike&#8217;s core focus will always be on making shoes/clothing for athletes.</li>
<li>Ford&#8217;s core focus will always be on making cars.</li>
</ul>
<p>If those organizations ever make &#8220;Security and Compliance&#8221; their core focus, they won&#8217;t have businesses anymore.</p>
<p>While we may think that security is important, the day that it surpasses the core focus of any business (that isn&#8217;t in the security and compliance business) is the day that that business has taken their eye off the ball.  By definition.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Business' rel='tag' target='_self'>Business</a>, <a class='technorati-link' href='http://technorati.com/tag/compliance' rel='tag' target='_self'>compliance</a>, <a class='technorati-link' href='http://technorati.com/tag/focus' rel='tag' target='_self'>focus</a>, <a class='technorati-link' href='http://technorati.com/tag/Security' rel='tag' target='_self'>Security</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://episteme.ca/2008/10/23/the-dumbest-prediction-ive-heard-in-a-while/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

