<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title>Branden Williams&apos; Security Convergence Blog</title>
      <link>http://blogs.verisign.com/securityconvergence/</link>
      <description>Security In-Depth: Information, Physical, Criminal, and Critical Infrastructure
</description>
      <language>en</language>
      <copyright>Copyright 2008</copyright>
      <lastBuildDate>Mon, 21 Jul 2008 09:29:44 -0700</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/?v=3.2</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>Confused about DLP?</title>
         <description><![CDATA[<p>Don't worry, you are not alone.  A partnership of several companies <a href="http://www.reuters.com/article/pressRelease/idUS97399+21-Jul-2008+MW20080721">released DLP In Depth today</a>, a website that is set off to unravel the mystery of Digital Loss Prevention (DLP).  DLP technologies have been around for some time, but last year we saw a <a href="http://www.youtube.com/watch?v=iPelkGNjY5c">fury of activity</a> in that market as RSA picked up Tablus, and Symantec picked up Vontu.  </p>

<p>At VeriSign, we regularly recommend using DLP products as part of your <a href="http://www.youtube.com/watch?v=WSz3QSM4mCM">security strategy</a>.  Knowing where your data lives is the first step to being able to secure it.</p>

<p>So if you are looking for more info on DLP, go check out <a href="http://www.dlpindepth.org">www.dlpindepth.org</a>!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/confused_about_dlp.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/confused_about_dlp.php</guid>
         <category>Headlines</category>
         <pubDate>Mon, 21 Jul 2008 09:29:44 -0700</pubDate>
      </item>
            <item>
         <title>Thanks to the EUCI!</title>
         <description><![CDATA[<p>Thanks to everyone at EUCI and their great hospitality in Vail.  I'm looking forward to <a href="http://www.youtube.com/watch?v=36tBS6dXo-U">working with some of you</a> soon!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/thanks_to_the_euci.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/thanks_to_the_euci.php</guid>
         <category>PCI</category>
         <pubDate>Thu, 17 Jul 2008 18:40:46 -0700</pubDate>
      </item>
            <item>
         <title>Are you in Vail for the EUCI Conference?</title>
         <description><![CDATA[<p>If so, <a href="mailto:TheSecurityBlog@gmail.com">drop me a line</a>!   I'm leaving the home base here in a few hours to head there for the conference.  I will be discussing personally identifiable information and why it is important to secure.  </p>

<p>After I speak, I'll be <a href="http://feeds.gawker.com/~r/gizmodo/full/~3/326603992/fun-times-with-hands+free-driving">high-tailing it</a> to Denver International to catch a return flight home.  Hope to see you there!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/are_you_in_vail_for_the_euci_c.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/are_you_in_vail_for_the_euci_c.php</guid>
         <category>Administration</category>
         <pubDate>Wed, 16 Jul 2008 11:16:00 -0700</pubDate>
      </item>
            <item>
         <title>Looking for a career as a QSA?</title>
         <description><![CDATA[<p>Well look no further!  Come join VeriSign's Premier Global PCI Consulting practice!!  If you are a current QSA in good standing, take a look at the job listings below.  If you are a security professional that wants to get into PCI related work, we can train you!  </p>

<p><a href="https://careers.verisign.com/irec/jobsearch/search.faces">Click here</a> and enter keywords "qualified security assessor" to learn more!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/looking_for_a_career_as_a_qsa.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/looking_for_a_career_as_a_qsa.php</guid>
         <category>Administration</category>
         <pubDate>Thu, 10 Jul 2008 19:28:58 -0700</pubDate>
      </item>
            <item>
         <title>Herding Cats, July 2008 is out!</title>
         <description><![CDATA[<p>Before you click on the link to read the article, I should warn you.  Things got a little silly with this one.  I even had to edit a cleverly-placed word as my editor threw up a little when he hit publish on this one.  </p>

<p><a href="http://www.buzzfeed.com/peggy/im-not-here-to-make-friends">SILLY</a>.</p>

<p>Anyway... I hope you enjoy the July edition of Herding Cats entitled, <a href="https://www.issa.org/Library/Journals/2008/July/Williams-The%20Forward%20Looking%20Future.pdf">The Forward Looking Future</a>!</p>

<p>Oh, and it looks like Twitter lost me.  I'm there, but you can't see my updates.  *shrug*</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/herding_cats_july_2008_is_out.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/herding_cats_july_2008_is_out.php</guid>
         <category>Headlines</category>
         <pubDate>Wed, 09 Jul 2008 12:46:48 -0700</pubDate>
      </item>
            <item>
         <title>Mind the Storefront!</title>
         <description><![CDATA[<p>Dave Taylor has another guest post on <a href="http://StoreFrontBackTalk.com">StoreFrontBackTalk</a>, this one alluding to a <a href="http://storefrontbacktalk.com/story/062608taylorpci">lack of audit resources to mind the storefront</a> (like <a href="http://video.google.com/videoplay?docid=-8147594025026276025">Minding the Gap</a>!).  </p>

<p>Store front security continues to be an issue for retailers even outside of PCI.  Take physical security for example.  Realize that a major retailer's data center tends to be a hardened facility that is not easily accessed (with the exception of a few notable ones that are for another post).  There are <a href="http://www.youtube.com/watch?v=ul-F4jatz_g">security guards</a>, badged access, and sometimes even man traps.  Now visit that same retailer's store front.  You might find accessible Ethernet jacks, or worse, a system room door that is unlocked or left wide open.  Walk into there with an official ID and you might just jack in to that same VLAN or security level as if you jumped through all the hoops at the data center!</p>

<p>The point that Dave makes is the same one I'll make here.  There are two things that will greatly mitigate the risks associated with weak physical security in the stores.  <br />
<ol><br />
<li>Remove all card data from the store (How about most of it?  Or just unencrypted data?)<br />
<li>Deploy end-to-end encryption from the POS Terminal to the data center.<br />
</ol><br />
Companies that treat their store networks as trusted are <a href="http://www.youtube.com/watch?v=wIjZ8NpgDTU">fooling</a> themselves.  Those networks are either already hacked, or could easily be hacked (even if you ignored the obvious insider threat!).  End to end encryption is a best practice for PCI (and in my opinion, it should stay that way for now), but it is definitely an example of layered security on top of compliance that will greatly increase a company's resistance to a breach.</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/mind_the_storefront.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/mind_the_storefront.php</guid>
         <category>Headlines</category>
         <pubDate>Sun, 06 Jul 2008 16:18:14 -0700</pubDate>
      </item>
            <item>
         <title>Enjoy the Holiday!</title>
         <description><![CDATA[<p>It's time to celebrate American Independence!  I'll be taking a holiday for a few days, but will return next week.  I will have a post hit on Monday though, so keep your eyes <a href="http://www.metacafe.com/w/1097676 ">peeled</a> (ouch?)!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/enjoy_the_holiday.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/enjoy_the_holiday.php</guid>
         <category>Administration</category>
         <pubDate>Wed, 02 Jul 2008 05:42:14 -0700</pubDate>
      </item>
            <item>
         <title>PCI Requirement 6.6 in the news!</title>
         <description><![CDATA[<p>The deadline has passed, do you know where your <del>children</del> web application firewalls are?  If you scratched your head and then saw a shiny object fly by to steal your attention, you are not alone.  Information Security Magazine <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1319360,00.html">interviewed me for an article</a> on this topic.  Go check it out!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/07/pci_requirement_66_in_the_news.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/07/pci_requirement_66_in_the_news.php</guid>
         <category>Headlines</category>
         <pubDate>Tue, 01 Jul 2008 12:13:41 -0700</pubDate>
      </item>
            <item>
         <title>Not all QSAs are created equal!</title>
         <description><![CDATA[<p>The PCI landscape is pretty <a href="http://www.youtube.com/watch?v=2T5_0AGdFic">scary</a> out there.  If you are a merchant or service provider that is looking for assistance, there is a long line of companies that are ready to help.  What should you expect from your QSA?  What should your assessment look like to get the best results?</p>

<p>VeriSign reviewed our findings from our customers and wrote a white paper entitled, "<a href="http://www.computerworld.com/action/whitepapers.do?command=viewWhitePaperDetail&contentId=9103838">Not All QSAs Are Created Equal: What You Should Know Before You Buy</a>" that talk about what you should expect.  This paper is a FREE download!  Go check it out!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/not_all_qsas_are_created_equal.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/not_all_qsas_are_created_equal.php</guid>
         <category>PCI</category>
         <pubDate>Sun, 29 Jun 2008 12:11:47 -0700</pubDate>
      </item>
            <item>
         <title>Breach got you down?</title>
         <description><![CDATA[<p>Well, it has happened again.  I received a rather menacing looking note in the mail today.  You know, one of those heavy stock sealed letters that has the <a href="http://www.youtube.com/watch?v=6-38SfQQZqQ">perforated</a> edges?  Yeah.  That kind.</p>

<p>Inside it looks like my information is on a lost tape from a bank.  The funny thing is, I don't remember banking with this institution... ever.  I have a feeling that one of the brokerage firms I use (or used) was backed by this institution, but nevertheless, I thought of an interesting type of phishing attack that I bet would work.  When I looked through this notice, it did appear to have a corresponding breach on <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm">PrivacyRights.org</a>.  I have already placed my fraud alerts, so I should be good.  </p>

<p>But what if it didn't?  If I were to target specific individuals (i.e., <a href="http://www.microsoft.com/protect/yourself/phishing/spear.mspx">spear phishing</a>) and tell them that their information was compromised from a large bank and provided a number for them to call for <a href="http://www.metacafe.com/w/234602 ">more info</a>, would they readily give me enough information to steal their identity?  I think people have started to be wary about clicking on things or giving out information over email, but what about through the mail?  Sure it won't have the same reach that electronic attacks will, but how much more lucrative could the loot get?</p>

<p>My thoughts are that it would work remarkably well against those individuals who don't have lawyers reading their mail, and especially some of the elderly population.</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/breach_got_you_down_1.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/breach_got_you_down_1.php</guid>
         <category>Enterprise Security</category>
         <pubDate>Fri, 27 Jun 2008 08:49:41 -0700</pubDate>
      </item>
            <item>
         <title>PIN Security finally catching up?</title>
         <description><![CDATA[<p>Wired reports that a Citibank hack may be responsible for a recent <a href="http://blog.wired.com/27bstroke6/2008/06/citibank-atm-se.html">ATM crime spree</a>.  <em>Edit: <a href="http://blog.wired.com/27bstroke6/2008/06/fbi-arrests-six.html">Looks like some arrests have been made</a>! </em> I've discussed issues around hacking <a href="http://blogs.verisign.com/securityconvergence/2008/04/tee_hee_eee_pee_cee.php">ATMs</a> and challenges with <a href="http://blogs.verisign.com/securityconvergence/2007/12/automatic_fuel_dispensers_skim.php">skimming</a> in the past, but this one appeared to be pretty lucrative.  While bank networks are not impenetrable, attacking endpoints is becoming much easier and more lucrative.  </p>

<p>Anyone remember the old days when you had to make sure the ATM you were going to use <a href="http://www.collisiondetection.net/mt/archives/2005/03/_next_time_you.html">was real</a>?  Speaking of that... Ladies, you should beware of <a href="http://www.prankplace.com/atm.htm">this</a>.</p>

<p>Something of interest to me... As a consumer, do you check your bank statement with all of your receipts?  Would you know if money started disappearing from your account in $10-$30 increments?  Does the state of your personal financial situation dictate your attention to your bank account?  I may be a dying breed, but I have been known to spend twenty minutes <a href="http://www.youtube.com/watch?v=TJiOjiMbvko">poring</a> over a bank statement to figure out where I missed a dime.</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/pin_security_finally_catching.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/pin_security_finally_catching.php</guid>
         <category>Enterprise Security</category>
         <pubDate>Wed, 25 Jun 2008 07:51:49 -0700</pubDate>
      </item>
            <item>
         <title>Listen to my PCI Podcast!</title>
         <description><![CDATA[<p>About a month ago an <a href="http://www.truveo.com/Beer-Bottle-Symphony-Orchestra/id/3653130681">audio guy</a> showed up to my house and pinned a tiny microphone to my shirt for a podcast on PCI.  It is a joint podcast with John Pescatore of Gartner.  The theme is on managing PCI Compliance.</p>

<p><a href="http://www.itbriefingcenter.com/programs/gartner_635_podcast_verisign.html">Go check it out</a>!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/listen_to_my_pci_podcast.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/listen_to_my_pci_podcast.php</guid>
         <category>PCI</category>
         <pubDate>Fri, 20 Jun 2008 07:46:48 -0700</pubDate>
      </item>
            <item>
         <title>Where oh where has my little blogger gone?</title>
         <description><![CDATA[<p>I haven't written, called, emailed, faxed, or even sent you guys anything via carrier pidgeon.  For that, I grovel at your feet and request my <a href="http://video.google.com/videoplay?docid=4709095204479401952">penance</a> (tee hee, I love the occasional translation error, especially when it reminds me of the <a href="http://www.youtube.com/watch?v=2Lwf3G5eiwo">most beautiful thing</a> I have ever seen).  What have I been up to?</p>

<p>Last week was fun.  Boston & Cincinnati in two days.  Was great seeing many of you out there!  Especially when a coworker and I started eating at the <a href="http://www.youtube.com/watch?v=_O1ogV5kRxc">wrong party</a>!  This week, so far, I have met with the Visa CISP and Incident Response teams over two days, and I am headed home to fly out to Atlanta for a couple of customer meetings.  If you are in town, drop me a line!</p>

<p>Some PCI News for you...</p>

<p>The PCI Security Standards Council has announced their <a href="https://www.pcisecuritystandards.org/pdfs/06-16-08.pdf">community meetings</a> for 2008.  We will be there!  They have also announced training dates for PA-DSS assessors.</p>

<p>I'm off to DFW!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/where_oh_where_has_my_little_b.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/where_oh_where_has_my_little_b.php</guid>
         <category>Administration</category>
         <pubDate>Mon, 16 Jun 2008 18:41:46 -0700</pubDate>
      </item>
            <item>
         <title>Are you in Cincinnati?</title>
         <description><![CDATA[<p>If so, shoot me an email!  I will be there for the 5th 3rd Customer event tomorrow (if I can ever get out of Boston!).</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/are_you_in_cincinnati.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/are_you_in_cincinnati.php</guid>
         <category>Administration</category>
         <pubDate>Mon, 09 Jun 2008 19:38:04 -0700</pubDate>
      </item>
            <item>
         <title>June Edition of Herding Cats</title>
         <description><![CDATA[<p>The ISSA has posted the electronic version of the journal, so if you are itching to read what is coming to you via the post, go check it out!  My column this month is titled "<a href="https://www.issa.org/Library/Journals/2008/June/Williams-Dont%20Get%20Cyber-Jacked.pdf">Don't Get Cyberjacked!</a>"</p>

<p>It may be the first time that the phrase "This ain't your daddy's security incident" and the word "<a href="http://www.expertvillage.com/video/14471_stripping-sander.htm">stripper</a>" appear on the same page (or ever) in that fantastic publication.  Go <a href="http://www.youtube.com/watch?v=eBGIQ7ZuuiU">check it</a> out!</p>]]></description>
         <link>http://blogs.verisign.com/securityconvergence/2008/06/june_edition_of_herding_cats.php</link>
         <guid>http://blogs.verisign.com/securityconvergence/2008/06/june_edition_of_herding_cats.php</guid>
         <category>Enterprise Security</category>
         <pubDate>Thu, 05 Jun 2008 08:03:34 -0700</pubDate>
      </item>
      
   </channel>
</rss>
