<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
					xmlns:content="http://purl.org/rss/1.0/modules/content/"
					xmlns:wfw="http://wellformedweb.org/CommentAPI/"
				  >
<channel>
<title>Dark Reading - CS Island Weblog</title>
<link>http://darkreading.com</link>
<description><![CDATA[]]></description>
<item>
<title>The SpiderLabs Report</title>
<link>http://www.darkreading.com/blog/229200067/the-spiderlabs-report.html</link>
<pubDate>Sat, 29 Jan 2011 03:14:00 -0500</pubDate>
<description><![CDATA[A look at the Trustwave Cyber Crime report]]></description>
<category></category>
</item>
<item>
<title>Anonymity And Nonversations</title>
<link>http://www.darkreading.com/blog/229000358/anonymity-and-nonversations.html</link>
<pubDate>Sun, 09 Jan 2011 01:14:00 -0500</pubDate>
<description><![CDATA[There are lots of lessons for the security industry in the Wikileaks case, including learning how to talk past each other.]]></description>
<category></category>
</item>
<item>
<title>There's A Recipe For That</title>
<link>http://www.darkreading.com/blog/227700795/there-s-a-recipe-for-that.html</link>
<pubDate>Tue, 15 Jun 2010 07:09:14 -0400</pubDate>
<description><![CDATA[Back in the dark ages when I was a programmer, I became horribly fascinated with a tool called make. It was a tool for dealing with the complexities of, well, making finished executable code.]]></description>
<category></category>
</item>
<item>
<title>Facebook: Screw You, Privacy Hugger</title>
<link>http://www.darkreading.com/blog/227700806/facebook-screw-you-privacy-hugger.html</link>
<pubDate>Tue, 01 Jun 2010 08:27:24 -0400</pubDate>
<description><![CDATA[As you know, Facebook recently overhauled its privacy controls -- or, well, overhauled the user interface to them. Upshot: Get over the privacy thing. But is that really what we want?]]></description>
<category></category>
</item>
<item>
<title>Lessons From The Volcano</title>
<link>http://www.darkreading.com/blog/227700560/lessons-from-the-volcano.html</link>
<pubDate>Mon, 17 May 2010 10:44:44 -0400</pubDate>
<description><![CDATA[I had a chance to fly rather close to Iceland's Eyjafjallajokull volcano last week. On a flight back from Frankfurt, the pilot somehow got permission to divert from the scheduled flight path as we crossed Iceland to give us a closer look of the volcano.]]></description>
<category></category>
</item>
<item>
<title>The Idiot Threat</title>
<link>http://www.darkreading.com/blog/227700854/the-idiot-threat.html</link>
<pubDate>Thu, 06 May 2010 13:55:33 -0400</pubDate>
<description><![CDATA[It's been interesting to see how the failed bombing in New York's Times Square has been sifted for "lessons."]]></description>
<category></category>
</item>
<item>
<title>Will Cyber Shockwave Make Some Waves?</title>
<link>http://www.darkreading.com/blog/227700759/will-cyber-shockwave-make-some-waves.html</link>
<pubDate>Wed, 17 Feb 2010 17:11:11 -0500</pubDate>
<description><![CDATA[With March Madness coming up, I recently spent the morning in some rather distinguished company simulating the effect of a March Madness smartphone app that turned out (within the confines of the simulation) to be malware.]]></description>
<category></category>
</item>
<item>
<title>New Flaws Pry Lid Off Cloud Frameworks</title>
<link>http://www.darkreading.com/blog/227700915/new-flaws-pry-lid-off-cloud-frameworks.html</link>
<pubDate>Fri, 05 Feb 2010 07:21:05 -0500</pubDate>
<description><![CDATA[A new set of vulnerabilities came to light this week at Black Hat DC, and its appearance provides a good look at our bleak "next-gen" security future.]]></description>
<category></category>
</item>
<item>
<title>In Support of Poor Ol' Windows Vista</title>
<link>http://www.darkreading.com/blog/227700770/in-support-of-poor-ol-windows-vista.html</link>
<pubDate>Tue, 13 Oct 2009 12:49:36 -0400</pubDate>
<description><![CDATA[We just released the October issue of the CSI <i>Alert</i> to CSI members, and this month we focus on Windows 7. This issue is, in some ways, a follow-up to last year's issue, "The Fate of the Secure OS," in which I said some nice things about Windows Vista, and advised it would be imprudent to completely ignore Windows Vista -- eyes-closed, fingers-in-ears, chanting I'm-not-listening-I'm-not-listening.]]></description>
<category></category>
</item>
<item>
<title>How Much Would You Pay To Never Have To Store PII?</title>
<link>http://www.darkreading.com/blog/227700982/how-much-would-you-pay-to-never-have-to-store-pii.html</link>
<pubDate>Wed, 02 Sep 2009 07:09:48 -0400</pubDate>
<description><![CDATA[Imagine a world in which you can do all manner of smooth, rich, user-friendly online commerce with mighty security. You can have complete faith in the validity of customers' login credentials and payment data (thereby reducing fraud costs, for starters). You can protect users' privacy...and never need to worry about securely storing -- or even seeing -- customers' credit card data or other legally protected personally identifiable information. Wait 12 to 18 months, and you might just have that.]]></description>
<category></category>
</item>
<item>
<title>Who Are These Followers And Followees of the Twitter Botnet?</title>
<link>http://www.darkreading.com/blog/227700674/who-are-these-followers-and-followees-of-the-twitter-botnet.html</link>
<pubDate>Mon, 17 Aug 2009 07:01:43 -0400</pubDate>
<description><![CDATA[Social networks really do bring people together, don't they? Old friends. Long-lost relatives. Bots and bot-herders. Warms the heart.]]></description>
<category></category>
</item>
<item>
<title>Black Hat, Day One: Rationalizing And Reinforcing  My Pessimistic World View</title>
<link>http://www.darkreading.com/blog/227700491/black-hat-day-one-rationalizing-and-reinforcing-my-pessimistic-world-view.html</link>
<pubDate>Thu, 30 Jul 2009 08:26:20 -0400</pubDate>
<description><![CDATA[When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.]]></description>
<category></category>
</item>
<item>
<title>UPDATE: BlackHat, Kinda: 'Real' Black Hats Hack Security Experts</title>
<link>http://www.darkreading.com/blog/227700598/update-blackhat-kinda-real-black-hats-hack-security-experts.html</link>
<pubDate>Wed, 29 Jul 2009 08:23:20 -0400</pubDate>
<description><![CDATA[The rumor here is that the attacks did indeed happen, but the significance of it is actually quite small--not worth paying attention to, since attention is clearly what the attackers are seeking. More info to come...

BlackHat, Kinda: Yesterday a hacking group released details (<a href="http://sh0dan.org/zf05.txt">http://r00tsecurity.org/files/zf05.txt</a>) of a number of successful attacks they conducted, apparently with the principal purpose of embarrassing some of the security industry's most well-known experts. The group claims that they collected about 75,000 passwords, including those of a few security experts speaking at the BlackHat Briefings today and tomorrow.

"Welcome one and all to the real Black Hat Briefings," reads the site. "Live from the underground, coming right at you free of charge."]]></description>
<category></category>
</item>
<item>
<title>Kantara Initiative: Another Effort To Get Identity 2.0 Out Of The Gate</title>
<link>http://www.darkreading.com/blog/227700533/kantara-initiative-another-effort-to-get-identity-2-0-out-of-the-gate.html</link>
<pubDate>Mon, 06 Jul 2009 13:09:50 -0400</pubDate>
<description><![CDATA[We've been saying for a while now that better identity management -- more so than secure Web app coding or even more secure browsers -- could fuel a quantum leap in Web security. The "Identity 2.0" community can be credited with wonderful research and truly significant advancements in identity management technology. In many ways, we're poised for an identity revolution. However, the efforts have been hampered by a lack of public awareness, a lack of interoperable standards, usability concerns, and a fundamental chicken/egg problem.]]></description>
<category></category>
</item>
<item>
<title>EU Group: Social Networks, Thirty-Party App Developers Subject To EU Privacy Laws</title>
<link>http://www.darkreading.com/blog/227700990/eu-group-social-networks-thirty-party-app-developers-subject-to-eu-privacy-laws.html</link>
<pubDate>Thu, 25 Jun 2009 09:57:55 -0400</pubDate>
<description><![CDATA[I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.]]></description>
<category></category>
</item>
<item>
<title>Ruminating on CSI SX</title>
<link>http://www.darkreading.com/blog/227700658/ruminating-on-csi-sx.html</link>
<pubDate>Wed, 20 May 2009 13:11:09 -0400</pubDate>
<description><![CDATA[Citizens of the Information Security Nation, to you I say <i>Classify and inventory your data and assets!</i>

Tedium? Odium? Delirium? Yes, probably all three. But worth the trouble.]]></description>
<category></category>
</item>
<item>
<title>Tippett To Discuss Verizon Breach Report</title>
<link>http://www.darkreading.com/blog/227700714/tippett-to-discuss-verizon-breach-report.html</link>
<pubDate>Thu, 14 May 2009 08:47:35 -0400</pubDate>
<description><![CDATA[Dr. Peter Tippett, vice president of research and intelligence for Verizon Business Security Solutions, will discuss the results of the company's "2009 Verizon Business Data Breach Investigations Report" (DBIR) at CSI SX: Security Exchange, taking place May 17-21 in Las Vegas.]]></description>
<category></category>
</item>
<item>
<title>SIEM Case Study: Israeli E-Government ISP</title>
<link>http://www.darkreading.com/blog/227700948/siem-case-study-israeli-e-government-isp.html</link>
<pubDate>Tue, 12 May 2009 12:04:35 -0400</pubDate>
<description><![CDATA[Want a case study on <a href="http://www.artofeurope.com/shakespeare/sha8.htm" target="new">the slings and arrows of outrageous</a> SIEM implementation? Sure you do. (Really. You do. Trust me on this one.)]]></description>
<category></category>
</item>
<item>
<title>A Cloud Might Save You Money...But What If The Cloud Goes Broke?</title>
<link>http://www.darkreading.com/blog/227700563/a-cloud-might-save-you-money-but-what-if-the-cloud-goes-broke.html</link>
<pubDate>Wed, 25 Mar 2009 08:29:11 -0400</pubDate>
<description><![CDATA[I've been <a href="http://gocsiblog.com/?p=517" target="new">talking quite a bit</a> about whether or not (not) users of cloud services can prove compliance with security, privacy, and e-discovery laws.  Now a story from <a href="http://www.theregister.co.uk/2009/03/25/security_cloud/" target="new">The Register</a> has me thinking about yet another issue -- the inescapable question of a service provider's financial stability.]]></description>
<category></category>
</item>
<item>
<title>BBC Responds To Legality Issues Of Recent Tech Show</title>
<link>http://www.darkreading.com/blog/227700613/bbc-responds-to-legality-issues-of-recent-tech-show.html</link>
<pubDate>Thu, 19 Mar 2009 09:20:39 -0400</pubDate>
<description><![CDATA[<a href="http://gocsiblog.com/?p=775" target="new">Yesterday</a> Nick Reynolds of the BBC directed me, as well as many other writers, to the BBC's official response to allegations that its technology show, <em>Click</em>, violated the U.K.'s Computer Misuse Act when it purchased and used a botnet as part of an investigative report into cybercrime.]]></description>
<category></category>
</item>
<item>
<title>BBC Botnet Experiment IS Illegal, No Matter What They Say</title>
<link>http://www.darkreading.com/blog/227700661/bbc-botnet-experiment-is-illegal-no-matter-what-they-say.html</link>
<pubDate>Tue, 17 Mar 2009 11:05:21 -0400</pubDate>
<description><![CDATA[Saturday, <a href="http://news.bbc.co.uk/2/hi/programmes/click_online/default.stm" target="new">"Click"</a>--"the BBC's flagship technology programme"--broadcast <a href="http://news.bbc.co.uk/2/hi/programmes/click_online/7938201.stm">an investigative report</a> on cybercrime. The exciting thing about this particular program is that they purchased and used a botnet as part of their investigation. The creators of the program are under the impression that their experiment was perfectly legal, because they had no criminal intent. 

They are mistaken.]]></description>
<category></category>
</item>
<item>
<title>See How I Suffer For My Science?</title>
<link>http://www.darkreading.com/blog/227700530/see-how-i-suffer-for-my-science.html</link>
<pubDate>Thu, 12 Mar 2009 07:21:40 -0400</pubDate>
<description><![CDATA[Today I saw two fraudulent charges on my bank account, and a few weeks ago I accidentally wiped off all of the data from my BlackBerry.

Why?

Because I love too much.]]></description>
<category></category>
</item>
<item>
<title>Peter Parker's Uncle Ben Would Not Approve</title>
<link>http://www.darkreading.com/blog/227700692/peter-parker-s-uncle-ben-would-not-approve.html</link>
<pubDate>Tue, 03 Mar 2009 09:03:35 -0500</pubDate>
<description><![CDATA[Note to Web browsers: With great power comes great responsibility.]]></description>
<category></category>
</item>
<item>
<title>Could Slimmer OSes Lead To Better Mobile Device Security?</title>
<link>http://www.darkreading.com/blog/227700515/could-slimmer-oses-lead-to-better-mobile-device-security.html</link>
<pubDate>Tue, 10 Feb 2009 13:15:24 -0500</pubDate>
<description><![CDATA[Maybe I'm stretching a bit, but let's say that operating system developers slimmed down their standard OSes enough so that eventually they'd be skinny enough to have a career in fashion and, more important, run on mobile devices. And, if so, would this be a good thing for mobile device security?]]></description>
<category></category>
</item>
<item>
<title>Can You Vote for Me Now? Estonia First Country to Cast Cell Phone Votes</title>
<link>http://www.darkreading.com/blog/227700866/can-you-vote-for-me-now-estonia-first-country-to-cast-cell-phone-votes.html</link>
<pubDate>Tue, 16 Dec 2008 10:51:53 -0500</pubDate>
<description><![CDATA[The Estonian Parliament has passed a law that will allow citizens to vote via cell phone by 2011. In the past, Estonians were able to cast their votes over the Internet, which apparently worked seamlessly despite security concerns. (See Sara Peters' coverage of e-voting in Estonia in the November 2005 <em>Alert</em>, <a href="http://www.gocsi.com/membersonly/showArticle.jhtml?articleID=172901878&catID=18523&_requestid=144577" target="new">Academic Group Publishes Criticisms of e-Voting</a>; membership required.)]]></description>
<category></category>
</item>
</channel>
</rss>
