<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Security Hype</title>
	<link>http://www.securityhype.com/blog</link>
	<description>Security clarity. One listener at a time.</description>
	<pubDate>Sun, 06 Apr 2008 15:37:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Bill Burns and Bob Lord </copyright>
		<managingEditor>admin@securityhype.com (Bill Burns and Bob Lord)</managingEditor>
		<webMaster>admin@securityhype.com(Bill Burns and Bob Lord)</webMaster>
		<category>information computer security</category>
		<ttl>1440</ttl>
		<itunes:keywords>computer security, information security, technology, SSL, encryption, cryptography</itunes:keywords>
		<itunes:subtitle>Security Clarity. One listener at a time. Bill and Bob are computer security veterans with over 30 years of experience between them. In this podcast they share their experience and knowledge with other technically-minded security professionals. Each po...</itunes:subtitle>
		<itunes:summary>Security clarity. One listener at a time.</itunes:summary>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:category text="Technology">
  <itunes:category text="Software How-To"/>
</itunes:category>
<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Bill Burns and Bob Lord</itunes:name>
			<itunes:email>admin@securityhype.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:image href="http://www.securityhype.com/blog/wp-content/images/SecurityHype_logo-large.gif" />
		<image>
			<url>http://www.securityhype.com/blog/wp-content/images/SecurityHype_logo-small.gif</url>
			<title>Security Hype</title>
			<link>http://www.securityhype.com/blog</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Security Hype 8.3-Security In the News - Voicemail line 1-866-527-6606</title>
		<link>http://www.securityhype.com/blog/archives/38</link>
		<comments>http://www.securityhype.com/blog/archives/38#comments</comments>
		<pubDate>Sun, 06 Apr 2008 15:37:19 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/38</guid>
		<description><![CDATA[In this episode, Bill and Bob debunk recent articles on computer security.   

Gambling site brought to its knees by &#8216;unstoppable&#8217; botnet -http://software.silicon.com/security/0,39024655,39170296,00.htm?r=11
Computer Users Expect More Mac Attacks -http://www.informationweek.com/security/showArticle.jhtml?articleID=206504189
Cyberthieves go phishing to rob banks -http://www.cnn.com/2008/TECH/02/12/cyber.thieves/index.html?eref=rss_topstories
State of the Malware Nation - http://blog.johnath.com/index.php/2008/02/26/state-of-the-malware-nation/

See you at RSA 2008. And special thanks to Lee Anne for helping us out with this episode! If you [...]]]></description>
			<content:encoded><![CDATA[<p>In this episode, Bill and Bob debunk recent articles on computer security.   
<ul>
<li>Gambling site brought to its knees by &#8216;unstoppable&#8217; botnet -<a href="http://software.silicon.com/security/0,39024655,39170296,00.htm?r=11">http://software.silicon.com/security/0,39024655,39170296,00.htm?r=11</a></li>
<li>Computer Users Expect More Mac Attacks -<a href="http://www.informationweek.com/security/showArticle.jhtml?articleID=206504189">http://www.informationweek.com/security/showArticle.jhtml?articleID=206504189</a></li>
<li>Cyberthieves go phishing to rob banks -<a href="http://www.cnn.com/2008/TECH/02/12/cyber.thieves/index.html?eref=rss_topstories">http://www.cnn.com/2008/TECH/02/12/cyber.thieves/index.html?eref=rss_topstories</a></li>
<li>State of the Malware Nation - <a href="http://blog.johnath.com/index.php/2008/02/26/state-of-the-malware-nation/">http://blog.johnath.com/index.php/2008/02/26/state-of-the-malware-nation/</a></li>
</ul>
<p>See you at RSA 2008. And special thanks to Lee Anne for helping us out with this episode! If you have comments or suggestions for the show, share them by calling 1-866-527-6606 or emailing us at <a href="mailto:comments@securityhype.com">comments@securityhype.com</a>.   </p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/38/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/38/0/Security_Hype_8.3-Security_In_the_News_-_Voicemail_line_1-866-527-6606.m4a" length="11346696" type="audio/x-m4a"/>
<itunes:duration>14:50</itunes:duration>
		<itunes:subtitle>In this episode, Bill and Bobnbsp;debunk recent articles on computer security. nbsp;nbsp;	Gambling site brought to its knees by 'unstoppable' botnet -http://software.silicon.com/security/0,39024655,39170296,00.htm?r=11	Computer Users Expect More Mac ...</itunes:subtitle>
		<itunes:summary>In this episode, Bill and Bobnbsp;debunk recent articles on computer security. nbsp;nbsp;	Gambling site brought to its knees by 'unstoppable' botnet -http://software.silicon.com/security/0,39024655,39170296,00.htm?r=11	Computer Users Expect More Mac Attacks -http://www.informationweek.com/security/showArticle.jhtml?articleID=206504189	Cyberthieves go phishing to rob banks -http://www.cnn.com/2008/TECH/02/12/cyber.thieves/index.html?eref=rss_topstories	State of the Malware Nation -nbsp;http://blog.johnath.com/index.php/2008/02/26/state-of-the-malware-nation/See you at RSA 2008.nbsp;And special thanks to Lee Anne for helping us out with this episode!nbsp;If you have comments or suggestions for the show, share them by calling 1-866-527-6606 or emailing us atnbsp;comments@securityhype.com.nbsp;nbsp;nbsp;</itunes:summary>
		<itunes:keywords>general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 8.2-Industry Predictions for 2008 - Voicemail line 1-866-527-6606</title>
		<link>http://www.securityhype.com/blog/archives/37</link>
		<comments>http://www.securityhype.com/blog/archives/37#comments</comments>
		<pubDate>Wed, 27 Feb 2008 00:00:57 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/37</guid>
		<description><![CDATA[Bill and Bob discuss what other people think are the information security trends for 2008.
Paul Kocher&#8217;s theory is that you don&#8217;t &#8220;win&#8221; at security, the best you can hope for is to be able to keep playing: a &#8220;stalemate&#8221; mentality versus a &#8220;checkmate&#8221; mentality. That&#8217;s a great theory, but Bill&#8217;s trying to figure out how [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob discuss what other people think are the information security trends for 2008.</p>
<p>Paul Kocher&#8217;s theory is that you don&#8217;t &#8220;win&#8221; at security, the best you can hope for is to be able to keep playing: a &#8220;stalemate&#8221; mentality versus a &#8220;checkmate&#8221; mentality. That&#8217;s a great theory, but Bill&#8217;s trying to figure out how we declare &#8220;success&#8221; in the computer and information security space. For instance, by what measure can we declare that we&#8217;ve done a better job in 2007 than in 2006?</p>
<p>What do YOU think will rock the security world in 2008?</p>
<p>Links discussed or referenced in the show:</p>
<ul>
<li>Data breach statistics: The number of records stolen per second has increased from 1.7 to 5.1 between 2006 and 2007: http://etiolated.org/statistics</li>
<li>A good statistical writeup:  <a href="http://www.privacyrights.org/ar/DataBreaches2006-Analysis.htm">http://www.privacyrights.org/ar/DataBreaches2006-Analysis.htm</a></li>
<li>Data breaches are on the decline (what does THAT mean?): <a href="http://etiolated.org/">http://etiolated.org/</a></li>
<li><a href="http://www.networkworld.com/news/2007/111307-top-security-menace-2008.html">Symantec 2008 predictions</a>:
<ul>
<li>Decentralized bot nets {Bill: that&#8217;s already been done!}</li>
<li>popular websites spreading malware; especially social network sites</li>
<li>Mobile phones (move to where the users are)</li>
<li>Virtual worlds (Did 2nd life already jump the shark?)</li>
<li>Election/political hacks, phishing, DoS {Check out the security cartoon interview from episode 7.10}</li>
</ul>
</li>
<li><a href="http://www.freedom-to-tinker.com/?p=1245">Ed Felten</a>:
<ul>
<li>From the site&#8217;s comments: A new kind of botnet will come into existence (or at least, be discovered), without a visible control channel. It will be designed to be autonomous and evolve slowly. Stealthy, many variants will remain below the radar of bot hunters. {Bill: doesn&#8217;t that already exist?}</li>
<li>A Facebook application will cause a big privacy to-do.</li>
<li>{Bill: I think a ad-related version of this will happen.}</li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/37/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/37/0/Security_Hype_8.2-Other_Peoples_Predictions_for_2008_-_Voicemail_line_1-866-527-6606.m4a" length="15567788" type="audio/x-m4a"/>
<itunes:duration>22:00</itunes:duration>
		<itunes:subtitle>Bill and Bob discuss what other people think are the information security trends for 2008.

Paul Kocher's theory is that you don't "win" at security, the ...</itunes:subtitle>
		<itunes:summary>Bill and Bob discuss what other people think are the information security trends for 2008.

Paul Kocher's theory is that you don't "win" at security, the best you can hope for is to be able to keep playing: a "stalemate" mentality versus a "checkmate" mentality. That's a great theory, but Bill's trying to figure out how we declare "success" in the computer and information security space. For instance, by what measure can we declare that we've done a better job in 2007 than in 2006?

What do YOU think will rock the security world in 2008?

Links discussed or referenced in the show:

	Data breach statistics: The number of records stolen per second has increased from 1.7 to 5.1 between 2006 and 2007: http://etiolated.org/statistics
	A good statistical writeup:nbsp; http://www.privacyrights.org/ar/DataBreaches2006-Analysis.htm
	Data breaches are on the decline (what does THAT mean?): http://etiolated.org/
	Symantec 2008 predictions:

	Decentralized bot nets {Bill: that's already been done!}
	popular websites spreading malware; especially social network sites
	Mobile phones (move to where the users are)
	Virtual worlds (Did 2nd life already jump the shark?)
	Election/political hacks, phishing, DoS {Check out the security cartoon interview from episode 7.10}


	Ed Felten:

	From the site's comments: A new kind of botnet will come into existence (or at least, be discovered), without a visible control channel. It will be designed to be autonomous and evolve slowly. Stealthy, many variants will remain below the radar of bot hunters. {Bill: doesn't that already exist?}
	A Facebook application will cause a big privacy to-do.
	{Bill: I think a ad-related version of this will happen.}


</itunes:summary>
		<itunes:keywords>general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 8.1-Our Predictions for 2008 - Voicemail line 1-866-527-6606</title>
		<link>http://www.securityhype.com/blog/archives/36</link>
		<comments>http://www.securityhype.com/blog/archives/36#comments</comments>
		<pubDate>Thu, 07 Feb 2008 06:22:44 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/36</guid>
		<description><![CDATA[Show Notes for 8.1:

Shout-outs to:

Thank you to the mysterious and powerful Bill @ Apple for technical assistance
Thank you to Wil Becker (http://ironwil.net/blog/) for adding us to his blogroll  - THANKS!


Bob&#8217;s sarcastic predictions:

Microsoft will claim that Vista will be the most secure OS EVAR!
Virtualization will prove to be a new shiny toy for malware authors. [...]]]></description>
			<content:encoded><![CDATA[<p>Show Notes for 8.1:</p>
<ol>
<li>Shout-outs to:
<ol>
<li>Thank you to the mysterious and powerful Bill @ Apple for technical assistance</li>
<li>Thank you to Wil Becker (<a href="http://ironwil.net/blog/">http://ironwil.net/blog/</a>) for adding us to his blogroll  - THANKS!</li>
</ol>
</li>
<li>Bob&#8217;s sarcastic predictions:
<ol>
<li>Microsoft will claim that Vista will be the most secure OS EVAR!</li>
<li>Virtualization will prove to be a new shiny toy for malware authors. Or at least someone will demonstrate something cool to the press.</li>
<li>Reasonably sane people will start taking themselves &#8220;off the grid&#8221;. Social networking sites will continue to leak private information, and the benefits of social nets will be lower than the costs for some people.</li>
<li>Sarbanes and Oxley will win the Nobel Peace Prize.</li>
<li>2008 will be the year of PKI!</li>
</ol>
</li>
<li>Bill&#8217;s predictions:
<ol>
<li>People will become desensitized to <a href="http://en.wikipedia.org/wiki/Personally_identifiable_information">PII</a> breaches, news overage will wane, people will get blasé about it</li>
<li>Macs OS X will see its first really solid malware attack that will be a wake-up call to Mac users to finally check (enable!, for Tiger) their firewalls and install AV scanning software. Free = <a href="http://www.clamxav.com/">ClamXav</a>
<ol>
<li>Will it force Leopard upgrades? If hackers are smart, their attack will be Leopard compatible.</li>
</ol>
</li>
<li><a href="http://news.netcraft.com/archives/2008/01/03/phishing_kits_take_advantage_of_novice_fraudsters.html">Overly</a> <a href="http://news.netcraft.com/archives/2008/01/22/mrbrain_stealing_phish_from_fraudsters.html">greedy</a>, warring botnet factions will fight each other and briefly take out parts of the Internet in collateral damage
<ol>
<li>site:phishing toolkits with backdoors</li>
</ol>
</li>
<li>IPv6 will start to gain traction and we&#8217;ll start seeing IPv6 hacks (finally), which is probably an inevitable phase for any technology to become ubiquitous.</li>
<li>The corp security industry (cutbacks, less to spend) will be focused on maintaining compliance, moving away from &#8220;risk management&#8221; and &#8220;ROI&#8221;. Watch for more marketing messages in that vain.</li>
<li>No massive attack on cell phone networks or SCADA. (And would we ever find out?)</li>
<li>Malware served via ads, serve up malware (related to legit web site defacement)
<ol>
<li>Ad distribution  become decentralized, democratized, less trustworthy</li>
</ol>
</li>
</ol>
</li>
</ol>
<p>Have predictions of your own?  Post them below or call the studio voice mail line!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/36/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/36/0/Security_Hype_8.1-Our_2008_Predictions_-_Voicemail_line_1-866-527-6606.m4a" length="9243892" type="audio/x-m4a"/>
<itunes:duration>12:22</itunes:duration>
		<itunes:subtitle>Show Notes for 8.1:

	Shout-outs to:

	Thank you to the mysterious and powerful Bill @ Apple for technical assistance
	Thank you to Wil Becker (http://ironwil.net/blog/) for adding us ...</itunes:subtitle>
		<itunes:summary>Show Notes for 8.1:

	Shout-outs to:

	Thank you to the mysterious and powerful Bill @ Apple for technical assistance
	Thank you to Wil Becker (http://ironwil.net/blog/) for adding us to his blogroll  - THANKS!


	Bob's sarcastic predictions:

	Microsoft will claim that Vista will be the most secure OS EVAR!
	Virtualization will prove to be a new shiny toy for malware authors. Or at least someone will demonstrate something cool to the press.
	Reasonably sane people will start taking themselves "off the grid". Social networking sites will continue to leak private information, and the benefits of social nets will be lower than the costs for some people.
	Sarbanes and Oxley will win the Nobel Peace Prize.
	2008 will be the year of PKI!


	Bill's predictions:

	People will become desensitized to PII breaches, news overage will wane, people will get blaseacute; about it
	Macs OS X will see its first really solid malware attack that will be a wake-up call to Mac users to finally check (enable!, for Tiger) their firewalls and install AV scanning software. Free = ClamXav

	Will it force Leopard upgrades? If hackers are smart, their attack will be Leopard compatible.


	Overly greedy, warring botnet factions will fight each other and briefly take out parts of the Internet in collateral damage

	site:phishing toolkits with backdoors


	IPv6 will start to gain traction and we'll start seeing IPv6 hacks (finally), which is probably an inevitable phase for any technology to become ubiquitous.
	The corp security industry (cutbacks, less to spend) will be focused on maintaining compliance, moving away from "risk management" and "ROI". Watch for more marketing messages in that vain.
	No massive attack on cell phone networks or SCADA. (And would we ever find out?)
	Malware served via ads, serve up malware (related to legit web site defacement)

	Ad distribution  become decentralized, democratized, less trustworthy





Have predictions of your own?  Post them below or call the studio voice mail line!</itunes:summary>
		<itunes:keywords>podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.12-Vista UAC a year later, MiTM attacks at the office, Crypto Key Size Recommendations, Macs under attack - Voicemail line 1-866-527-6606</title>
		<link>http://www.securityhype.com/blog/archives/31</link>
		<comments>http://www.securityhype.com/blog/archives/31#comments</comments>
		<pubDate>Mon, 03 Dec 2007 05:00:18 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[S/MIME]]></category>

		<category><![CDATA[SSL]]></category>

		<category><![CDATA[encryption]]></category>

		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/31</guid>
		<description><![CDATA[How paranoid are you? keylength.com
What RSA keysizes are you using at your company? What is your guidance? Are you sticking with RSA or moving to ECC?
Macs are under attack (include link to new trojan house): http://machinist.salon.com/blog/2007/11/02/mac_trojan/
eweek article link
full disclosure versus responsible disclosure (link to resp. disclosure RFC)
mac versus windows updates: Windows does a better job [...]]]></description>
			<content:encoded><![CDATA[<p>How paranoid are you? keylength.com</p>
<p>What RSA keysizes are you using at your company? What is your guidance? Are you sticking with RSA or moving to ECC?<br />
Macs are under attack (include link to new trojan house): http://machinist.salon.com/blog/2007/11/02/mac_trojan/</p>
<p>eweek article link</p>
<p>full disclosure versus responsible disclosure (link to resp. disclosure RFC)</p>
<p>mac versus windows updates: Windows does a better job because it auto installs, does it auto reboot? Macs will go weeks/months with patches pending and won&#8217;t auto reboot. Does Leopard fix this? Do you actually need to *reboot*</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/31/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/31/0/Security_Hype_7.12-Vista_UAC_a_year_later_MiTM_attacks_at_the_office_Crypto_Key_Size_Recommendations_Macs_under_attack_Voicemail_line_1-866-527-6606.m4a" length="29448889" type="audio/x-m4a"/>
<itunes:duration>29:55</itunes:duration>
		<itunes:subtitle>How paranoid are you? keylength.com

What RSA keysizes are you using at your company? What is your guidance? Are you sticking with RSA or moving to ...</itunes:subtitle>
		<itunes:summary>How paranoid are you? keylength.com

What RSA keysizes are you using at your company? What is your guidance? Are you sticking with RSA or moving to ECC?
Macs are under attack (include link to new trojan house): http://machinist.salon.com/blog/2007/11/02/mac_trojan/

eweek article link

full disclosure versus responsible disclosure (link to resp. disclosure RFC)

mac versus windows updates: Windows does a better job because it auto installs, does it auto reboot? Macs will go weeks/months with patches pending and won't auto reboot. Does Leopard fix this? Do you actually need to *reboot*</itunes:summary>
		<itunes:keywords>S/MIME,,SSL,,encryption,,general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.11-Listener feedback, how do you tell if your network is being monitered, and new security in FireFox 3 - Voicemail line 1-866-527-6606.</title>
		<link>http://www.securityhype.com/blog/archives/33</link>
		<comments>http://www.securityhype.com/blog/archives/33#comments</comments>
		<pubDate>Fri, 02 Nov 2007 15:48:47 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[SSL]]></category>

		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/33</guid>
		<description><![CDATA[Bill and Bob address listener feedback on SiteKey and the security distinction between signature versus encryption. Bill&#8217;s Paypal securitykey arrived, and he reviews the activation process and tries it out for few days. Despite the fact that it won&#8217;t protect against phishing attacks, find out why he ended up deactivating it on his ebay account [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob address listener feedback on SiteKey and the security distinction between signature versus encryption. Bill&#8217;s Paypal securitykey arrived, and he reviews the activation process and tries it out for few days. Despite the fact that it won&#8217;t protect against phishing attacks, find out why he ended up deactivating it on his ebay account afterall.</p>
<p>Bob&#8217;s worried about his Internet security when staying at a hotel. How can <strong>you</strong> be certain that no one&#8217;s snooping on your traffic? Do you have any suggestions? Bob&#8217;s also wondering how can you tell if his employer is monitoring his personal traffic while at work? A question for the listeners: Does your company&#8217;s VPN enforce split tunneling or not? We&#8217;ll cover the results in an upcoming episode.</p>
<p>Finally, here about upcoming changes to FireFox 3&#8217;s security libraries. New crypto routines and security UI in FireFox!?!</p>
<p>What do you want us to cover in upcoming episodes? Send your show suggestions and feedback to comments@SecurityHype.com. And if you like this show (and even if you don&#8217;t), we&#8217;d be honored if you would submit a review in iTunes.</p>
<p>Thank you for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/33/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/33/0/Security_Hype_7.11-Listener_feedback_how_do_you_tell_if_your_network_is_being_monitered_and_new_security_in_FireFox_3_-_Voicemail_line_1-866-527-6606.m4a" length="37836412" type="audio/x-m4a"/>
<itunes:duration>38:49</itunes:duration>
		<itunes:subtitle>Bill and Bob address listener feedback on SiteKey and the security distinction between signature versus encryption. Bill's Paypal securitykey arrived, and he reviews the activation ...</itunes:subtitle>
		<itunes:summary>Bill and Bob address listener feedback on SiteKey and the security distinction between signature versus encryption. Bill's Paypal securitykey arrived, and he reviews the activation process and tries it out for few days. Despite the fact that it won't protect against phishing attacks, find out why he ended up deactivating it on his ebay account afterall.

Bob's worried about his Internet security when staying at a hotel. How can you be certain that no one's snooping on your traffic? Do you have any suggestions? Bob's also wondering how can you tell if his employer is monitoring his personal traffic while at work? A question for the listeners: Does your company's VPN enforce split tunneling or not? We'll cover the results in an upcoming episode.

Finally, here about upcoming changes to FireFox 3's security libraries. New crypto routines and security UI in FireFox!?!

What do you want us to cover in upcoming episodes? Send your show suggestions and feedback to comments@SecurityHype.com. And if you like this show (and even if you don't), we'd be honored if you would submit a review in iTunes.

Thank you for listening!</itunes:summary>
		<itunes:keywords>SSL,,general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.10-SecurityCartoon.com - Voicemail line 1-866-527-6606</title>
		<link>http://www.securityhype.com/blog/archives/32</link>
		<comments>http://www.securityhype.com/blog/archives/32#comments</comments>
		<pubDate>Mon, 15 Oct 2007 04:57:25 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/32</guid>
		<description><![CDATA[Bill and Bob interview Dr. Markus Jakobsson and Dr. Sukamol Srikwan, creators of SecurityCartoon.com. It&#8217;s not your ordinary comic strip: Over a year of research when into this innovative and friendly information security educational methodology. Learn the background on this effective security countermeasure and why everyone &#8212; especially information security professionals &#8212; need to pay [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob interview Dr. Markus Jakobsson and Dr. Sukamol Srikwan, creators of <a href="http://www.SecurityCartoon.com" target="_blank">SecurityCartoon.com</a>. It&#8217;s not your ordinary comic strip: Over a year of research when into this innovative and friendly information security educational methodology. Learn the background on this effective security countermeasure and why everyone &#8212; especially information security professionals &#8212; need to pay attention to this teaching method.</p>
<p>Please send your feedback and other show ideas to comments@SecurityHype.com or call our toll-free voice mail line at 1-866-527-6606</p>
<p>Thanks for listening!</p>
<p>Other links mentioned in this episode:</p>
<ul>
<li><strong><a href="http://www.informatics.indiana.edu/markus/" target="_blank">Markus Jakobsson</a>: Associate Professor of <a href="http://www.informatics.indiana.edu/">Informatics</a></strong> and <strong><a href="http://www.informatics.indiana.edu/markus/Yes.htm">Associate Associate Professor</a> of <a href="http://www.cogs.indiana.edu/">Cognitive Science</a></strong></li>
<li><a href="http://www.informatics.indiana.edu/sjakobss/" target="_blank">Sukamol Srikwan Jakobsson</a>:  Research Associate / Staff Scientist; The Center for Genomics and Bioinformatics</li>
<li>October is <a href="http://www.staysafeonline.info/" target="_blank">National Cyber Security Awareness Month </a>- learn how to stay safe on the Internet!</li>
<li><a href="http://www.informatics.indiana.edu/markus/papers/phishing_jakobsson.pdf%20http://www.informatics.indiana.edu/markus/papers/phishing_jakobsson.pdf" target="_blank">Messin&#8217; with Texas, Deriving Mother&#8217;s Maiden Names Using Public Records</a></li>
<li>Cartoon showing <a href="http://www.securitycartoon.com/index.php?comic=20070619&amp;tag=phishing&amp;last=">phishing and URL obfuscation</a></li>
<li><a href="http://www.SecurityCartoon.info">www.SecurityCartoon.info</a> - Whitepaper and study behind the cartoon.</li>
</ul>
<p>Cartoons embedded in this podcast were reproduced with permission. Please visit <a href="http://www.securitycartoon.com/">www.SecurityCartoon.com</a> for more material.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/32/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/32/0/Security_Hype_7.10-SecurityCartoon.com_-_Voicemail_line_1-866-527-6606.m4a" length="31788942" type="audio/x-m4a"/>
<itunes:duration>32:00</itunes:duration>
		<itunes:subtitle>Bill and Bob interview Dr. Markus Jakobsson and Dr. Sukamol Srikwan, creators of SecurityCartoon.com. It's not your ordinary comic strip: Over a year of research ...</itunes:subtitle>
		<itunes:summary>Bill and Bob interview Dr. Markus Jakobsson and Dr. Sukamol Srikwan, creators of SecurityCartoon.com. It's not your ordinary comic strip: Over a year of research when into this innovative and friendly information security educational methodology. Learn the background on this effective security countermeasure and why everyone -- especially information security professionals -- need to pay attention to this teaching method.

Please send your feedback and other show ideas to comments@SecurityHype.com or call our toll-free voice mail line at 1-866-527-6606

Thanks for listening!

Other links mentioned in this episode:

	Markus Jakobsson: Associate Professor of Informatics and Associate Associate Professor of Cognitive Science
	Sukamol Srikwan Jakobsson:  Research Associate / Staff Scientist; The Center for Genomics and Bioinformatics
	October is National Cyber Security Awareness Month - learn how to stay safe on the Internet!
	Messin' with Texas, Deriving Mother's Maiden Names Using Public Records
	Cartoon showing phishing and URL obfuscation
	www.SecurityCartoon.info - Whitepaper and study behind the cartoon.

Cartoons embedded in this podcast were reproduced with permission. Please visit www.SecurityCartoon.com for more material.</itunes:summary>
		<itunes:keywords>general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.9-How Netscape tried to keep ahead of the hackers. Voicemail line 1-866-527-6606.</title>
		<link>http://www.securityhype.com/blog/archives/30</link>
		<comments>http://www.securityhype.com/blog/archives/30#comments</comments>
		<pubDate>Sun, 16 Sep 2007 05:42:54 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[SSL]]></category>

		<category><![CDATA[encryption]]></category>

		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/30</guid>
		<description><![CDATA[Bill and Bob invite Bob Relyea back to reminisce on Netscape&#8217;s early challenges to keep &#8220;strong crypto&#8221; out of the hands on &#8220;non US Domestic&#8221; persons, as declared by US Export Restrictions laws. The race was one! You&#8217;ll hear what Netscape crypto engineers did to try to stay ahead of the hackers, and the level [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob invite Bob Relyea back to reminisce on Netscape&#8217;s early challenges to keep &#8220;strong crypto&#8221; out of the hands on &#8220;non US Domestic&#8221; persons, as declared by US Export Restrictions laws. The race was one! You&#8217;ll hear what Netscape crypto engineers did to try to stay ahead of the hackers, and the level of effort the hackers used to circumvent them.  This is the classic &#8220;cat and mouse&#8221; game. Check out the old <a href="http://www.fortify.net/">Fortify</a> effort, which has been frozen circa 2000 when Netscape released version 4.73 that included 128-bit crypto to everyone.</p>
<p>Paul Kocher did a great job at explaining the real challenge faced by security developers: Why companies want to make this a &#8220;Stalemate&#8221; problem instead of a &#8220;Checkmate&#8221; one. (<a href="http://www.cryptography.com/resources/whitepapers/SPDC2004.pdf">PDF</a> Link)</p>
<p>Send your show suggestions and feedback to <a href="mailto:comments@SecurityHype.com?Subject=Security%20Hype%20show%20comments">comments@SecurityHype.com</a> or call the studio line at 1-866-527-6606.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/30/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/30/0/Security_Hype_7.9-How_Netscape_tried_to_keep_ahead_of_the_hackers.m4a" length="10502045" type="audio/x-m4a"/>
<itunes:duration>10:37</itunes:duration>
		<itunes:subtitle>Bill and Bob invite Bob Relyea back to reminisce on Netscape's early challenges to keep "strong crypto" out of the hands on "non US Domestic" ...</itunes:subtitle>
		<itunes:summary>Bill and Bob invite Bob Relyea back to reminisce on Netscape's early challenges to keep "strong crypto" out of the hands on "non US Domestic" persons, as declared by US Export Restrictions laws. The race was one! You'll hear what Netscape crypto engineers did to try to stay ahead of the hackers, and the level of effort the hackers used to circumvent them.nbsp; This is the classic "cat and mouse" game. Check out the old Fortify effort, which has been frozen circa 2000 when Netscape released version 4.73 that included 128-bit crypto to everyone.

Paul Kocher did a great job at explaining the real challenge faced by security developers: Why companies want to make this a "Stalemate" problem instead of a "Checkmate" one. (PDF Link)

Send your show suggestions and feedback to comments@SecurityHype.com or call the studio line at 1-866-527-6606.</itunes:summary>
		<itunes:keywords>SSL,,encryption,,general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.8-Bob Relyea AACS Part 2: Practical implications of key compromises. Voicemail line 1-866-527-6606</title>
		<link>http://www.securityhype.com/blog/archives/29</link>
		<comments>http://www.securityhype.com/blog/archives/29#comments</comments>
		<pubDate>Thu, 06 Sep 2007 07:05:21 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[encryption]]></category>

		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/29</guid>
		<description><![CDATA[Bill and Bob wrap up their interview with Bob Relyea who describes the practical implications to the AACS key compromise.
Bill recounts the story of the satellite pirates who were locked out by DirecTV in the middle of the Superbowl, sometimes called “Black Sunday”.  DirecTV had been slowly downloading a pirate detection and lockout routine, [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob wrap up their interview with Bob Relyea who describes the practical implications to the AACS key compromise.</p>
<p>Bill recounts the story of the satellite pirates who were locked out by DirecTV in the middle of the Superbowl, sometimes called “Black Sunday”.  DirecTV had been slowly downloading a pirate detection and lockout routine, byte by byte, over the course of a few weeks.  When activated, this routine disabled the hacked cards.  So anti-pirate measures can be quite affective, at least in the short term.</p>
<p>We ask Bob Relyea a number of questions about the AACS crack, and whether or not it&#8217;s a big deal.  Is AACS really better than the old CSS system?  We explore the issue of using well-known crypto standards, and if the content protection people learned from their CSS mistakes. We also talk about what steps we might see the studios take.</p>
<p>Here&#8217;s a good Wired article: http://blog.wired.com/gadgets/2007/02/the_new_hddvdbl.html</p>
<p>There are loads of other sites on the web.  Search for “09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0” or “09 F9 key”.</p>
<p>Send your show suggestions and feedback to <a href="mailto:comments@SecurityHype.com?Subject=Security%20Hype%20show%20comments">comments@SecurityHype.com</a> or call the studio line at 1-866-527-6606.</p>
<p>Thank you for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/29/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/29/0/Security_Hype_7.8-Bob_Relyea_AACS_Part_2._Practical_implications_of_key_compromises.m4a" length="15800508" type="audio/x-m4a"/>
<itunes:duration>16:00</itunes:duration>
		<itunes:subtitle>Bill and Bob wrap up their interview with Bob Relyea who describes the practical implications to the AACS key compromise.

Bill recounts the story of the ...</itunes:subtitle>
		<itunes:summary>Bill and Bob wrap up their interview with Bob Relyea who describes the practical implications to the AACS key compromise.

Bill recounts the story of the satellite pirates who were locked out by DirecTV in the middle of the Superbowl, sometimes called ldquo;Black Sundayrdquo;.  DirecTV had been slowly downloading a pirate detection and lockout routine, byte by byte, over the course of a few weeks.  When activated, this routine disabled the hacked cards.  So anti-pirate measures can be quite affective, at least in the short term.

We ask Bob Relyea a number of questions about the AACS crack, and whether or not it's a big deal.  Is AACS really better than the old CSS system?  We explore the issue of using well-known crypto standards, and if the content protection people learned from their CSS mistakes. We also talk about what steps we might see the studios take.

Here's a good Wired article: http://blog.wired.com/gadgets/2007/02/the_new_hddvdbl.html

There are loads of other sites on the web.  Search for ldquo;09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0rdquo; or ldquo;09 F9 keyrdquo;.

Send your show suggestions and feedback to comments@SecurityHype.com or call the studio line at 1-866-527-6606.

Thank you for listening!
</itunes:summary>
		<itunes:keywords>encryption,,general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.7-RSA Key hack revisited, AACS in depth with Bob Relyea</title>
		<link>http://www.securityhype.com/blog/archives/27</link>
		<comments>http://www.securityhype.com/blog/archives/27#comments</comments>
		<pubDate>Mon, 16 Jul 2007 04:00:39 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/27</guid>
		<description><![CDATA[Bob Relyea, a PKI and cryptographic engineer, joins Bill and Bob to discuss the recent RSA and AACS key compromises in depth.
In the news, we&#8217;ve been reading about how researchers have been able to factor a very large number which is 307 digits long.  Bob Relyea helps us understand if these results help spell [...]]]></description>
			<content:encoded><![CDATA[<p>Bob Relyea, a PKI and cryptographic engineer, joins Bill and Bob to discuss the recent RSA and AACS key compromises in depth.</p>
<p>In the news, we&#8217;ve been reading about how <a href="http://www.schneier.com/blog/archives/2007/05/307digit_number.html">researchers have been able to factor a very large number</a> which is 307 digits long.  Bob Relyea helps us understand if these results help spell doom for 1024-bit RSA or if it&#8217;s a non-event. Are there implications for Diffie-Hellman and DSA as well?</p>
<p>We&#8217;ve also been reading about AACS, a new DVD content protection scheme aimed at preventing piracy of the new high-definition DVDs.  One of the AACS keys was found and posted on the web, including on <a href="http://www.digg.com">Digg</a>. Digg management removed the key, triggering a user revolt at Digg.  A <a href="http://www.boingboing.net/2007/05/02/digg_users_revolt_ov.html">summary posted on BoingBoing</a> nicely describes the event and Digg&#8217;s decision to side with its users, risking legal action by the DVD industry.</p>
<p>Bob Relyea helps us understand what AACS really is, how it works, and how it attempts to address the security flaws the previous standard. Bob will help us understand whether or not a key compromise like the one highlighted on Digg represents a real problem for the motion picture industry.</p>
<p>If you like the show, please go to iTunes and <a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=214914297">add your reviews</a> to our podcast. If you have suggestions for show topics or have comments on this episode please send your feedback to <a href="mailto:comments@SecurityHype.com">comments@SecurityHype.com</a></p>
<p>Thanks for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/27/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/27/0/Security_Hype_7.7-RSA_Key_Compromise_and_AACS_key_management_details.m4a" length="1" type="audio/x-m4a"/>
<itunes:duration>00:01:01</itunes:duration>
		<itunes:subtitle>Bob Relyea, a PKI and cryptographic engineer, joins Bill and Bob to discuss the recent RSA and AACS key compromises in depth.

In the news, we've ...</itunes:subtitle>
		<itunes:summary>Bob Relyea, a PKI and cryptographic engineer, joins Bill and Bob to discuss the recent RSA and AACS key compromises in depth.

In the news, we've been reading about how researchers have been able to factor a very large number which is 307 digits long.  Bob Relyea helps us understand if these results help spell doom for 1024-bit RSA or if it's a non-event. Are there implications for Diffie-Hellman and DSA as well?

We've also been reading about AACS, a new DVD content protection scheme aimed at preventing piracy of the new high-definition DVDs.  One of the AACS keys was found and posted on the web, including on Digg. Digg management removed the key, triggering a user revolt at Digg.  A summary posted on BoingBoing nicely describes the event and Digg's decision to side with its users, risking legal action by the DVD industry.

Bob Relyea helps us understand what AACS really is, how it works, and how it attempts to address the security flaws the previous standard. Bob will help us understand whether or not a key compromise like the one highlighted on Digg represents a real problem for the motion picture industry.

If you like the show, please go to iTunes and add your reviews to our podcast. If you have suggestions for show topics or have comments on this episode please send your feedback to comments@SecurityHype.com

Thanks for listening!</itunes:summary>
		<itunes:keywords>general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.6-SiteKey (not) broken and Mozilla&#8217;s radical Security UI idea</title>
		<link>http://www.securityhype.com/blog/archives/26</link>
		<comments>http://www.securityhype.com/blog/archives/26#comments</comments>
		<pubDate>Thu, 21 Jun 2007 17:00:58 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[S/MIME]]></category>

		<category><![CDATA[SSL]]></category>

		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/26</guid>
		<description><![CDATA[Bill and Bob peel back the hype on &#8220;SiteKey is broken!&#8221; claims and find that it&#8217;s working as designed. SiteKey isn&#8217;t broken, but computer security user interface design IS broken. User&#8217;s don&#8217;t know how to evaluate when computer systems are behaving securely, and are struggling to stay safe on the Internet.
New MIT &#38; Harvard research [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob peel back the hype on &#8220;SiteKey is broken!&#8221; claims and find that it&#8217;s working as designed. SiteKey isn&#8217;t broken, but computer security user interface design IS broken. User&#8217;s don&#8217;t know how to evaluate when computer systems are behaving securely, and are struggling to stay safe on the Internet.</p>
<p><a href="http://usablesecurity.org/emperor/">New MIT &amp; Harvard research</a> indicates that people don&#8217;t know that the ABSENCE of security information on a banking website means &#8220;danger&#8221;. More evidence that security usability - particularly with web browsers - is in a sad state.</p>
<p><a href="http://www.microsoft.com/windows/products/winfamily/ie/ev/default.mspx">Microsoft&#8217;s support</a> for EV SSL certificates has several new UI changes in the IE browser in  an attempt to help people make security determinations. The Mozilla Foundation is considering taking a radically different approach. Jonathan Nightingale believes that SSL web connections is not about encryption, it&#8217;s about identity of the website you&#8217;re connecting to.  <a href="http://blog.johnath.com/index.php/2007/06/04/will-firefox-have-a-green-bar/">Is the Lock Icon going away!?!</a> Will this actually work and protect users on the Internet? Does this make sense? Send us your thoughts to <a href="mailto:comments@SecurityHype.com?Subject=Mozilla%27s%20new%20SSL%20UI%20proposal">comments@SecurityHype.com</a>. We&#8217;ll try to get Jonathan on the show.<a href="mailto:comments@SecurityHype.com?Subject=Mozilla%27s%20new%20SSL%20UI%20proposal"><br />
</a></p>
<p>DiscoverCard&#8217;s fraud detection process is being exploited by hackers through &#8220;<a href="http://www.businessweek.com/technology/content/jul2006/tc20060710_811021.htm">phone phishing</a>&#8221; attacks. We tried to explain this to the DiscoverCard operator and they just didn&#8217;t understand the attack vector. Credit card companies spend millions of dollars printing and issuing credit cards to people, why would they use a different phone number for their customers to call and report fraud? They should be encouraging customers to use a simple, verifiable, and secure process.</p>
<p>What other silly security processes have you run across?</p>
<p>If you like the show, please go to iTunes and <a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=214914297">add your reviews</a> to our podcast. If you have suggestions for show topics or have comments on this episode please send your feedback to <a href="mailto:comments@SecurityHype.com">comments@SecurityHype.com</a></p>
<p>Thanks for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/26/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/26/0/Security_Hype_7.6-SiteKey_not_broken_and_Mozillas_radical_Security_UI_idea.m4a" length="1" type="audio/x-m4a"/>
<itunes:duration>30:03</itunes:duration>
		<itunes:subtitle>Bill and Bob peel back the hype on "SiteKey is broken!" claims and find that it's working as designed. SiteKey isn't broken, but computer security ...</itunes:subtitle>
		<itunes:summary>Bill and Bob peel back the hype on "SiteKey is broken!" claims and find that it's working as designed. SiteKey isn't broken, but computer security user interface design IS broken. User's don't know how to evaluate when computer systems are behaving securely, and are struggling to stay safe on the Internet.

New MIT #38; Harvard research indicates that people don't know that the ABSENCE of security information on a banking website means "danger". More evidence that security usability - particularly with web browsers - is in a sad state.

Microsoft's support for EV SSL certificates has several new UI changes in the IE browser in  an attempt to help people make security determinations. The Mozilla Foundation is considering taking a radically different approach. Jonathan Nightingale believes that SSL web connections is not about encryption, it's about identity of the website you're connecting to.  Is the Lock Icon going away!?! Will this actually work and protect users on the Internet? Does this make sense? Send us your thoughts to comments@SecurityHype.com. We'll try to get Jonathan on the show.


DiscoverCard's fraud detection process is being exploited by hackers through "phone phishing" attacks. We tried to explain this to the DiscoverCard operator and they just didn't understand the attack vector. Credit card companies spend millions of dollars printing and issuing credit cards to people, why would they use a different phone number for their customers to call and report fraud? They should be encouraging customers to use a simple, verifiable, and secure process.

What other silly security processes have you run across?

If you like the show, please go to iTunes and add your reviews to our podcast. If you have suggestions for show topics or have comments on this episode please send your feedback to comments@SecurityHype.com

Thanks for listening!</itunes:summary>
		<itunes:keywords>S/MIME,,SSL,,general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.5-CreditCard Skimming, Setting up Secure Email</title>
		<link>http://www.securityhype.com/blog/archives/24</link>
		<comments>http://www.securityhype.com/blog/archives/24#comments</comments>
		<pubDate>Fri, 01 Jun 2007 02:50:45 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[S/MIME]]></category>

		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/24</guid>
		<description><![CDATA[Bill and Bob discuss credit card skimming, how is this risk different than exposing your CC number over the Internet? In this episode you&#8217;ll learn how to secure your email using FireFox and Thunderbird. You&#8217;re using 2048-bit RSA keys, right? And you&#8217;re backing up your digital certificates and private keys too, yes? Once you get [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob discuss credit card skimming, how is this risk different than exposing your CC number over the Internet? In this episode you&#8217;ll learn how to secure your email using <a href="http://www.mozilla.com/firefox/">FireFox</a> and <a href="http://www.mozilla.com/thunderbird/">Thunderbird</a>. You&#8217;re using 2048-bit RSA keys, right? And you&#8217;re backing up your digital certificates and private keys too, yes? Once you get your certificate, send us an encrypted email using our certificate!</p>
<p>Alternative instructions: <a href="http://office.microsoft.com/en-us/outlook/HP012305371033.aspx">Outlook</a> and <a href="http://www.joar.com/certificates/">Apple Mail</a>.</p>
<p>Did you know that if you aren&#8217;t digitally signing AND encrypting your email, the message isn&#8217;t truly secure?  Bob discusses this subtle but important distinction. If this doesn&#8217;t make sense, let us know and we&#8217;ll cover this in more depth.</p>
<p>Free S/MIME certificates are available from <a href="http://www.comodo.com/products/certificate_services/email_certificate.html">Comodo</a> (Windows only) and <a href="http://www.thawte.com/secure-email/personal-email-certificates/index.html">Thawte</a>. Remember that with Thawte you have to &#8220;join&#8221; their system.</p>
<p>If you&#8217;re enjoying our podcast, we&#8217;d appreciate hearing more feedback from you and seeing your reviews at iTunes. If you have comments, suggestions or know where Bob, Alice, Eve and Mallory are please contact us at <a href="mailto:comments@SecurityHype.com">comments@SecurityHype.com</a>.</p>
<p>Thank you for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/24/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/24/0/Security_Hype_7.5-Skimming_and_Configuring_secure_email.m4a" length="1" type="audio/x-m4a"/>
<itunes:duration>00:01:01</itunes:duration>
		<itunes:subtitle>Bill and Bob discuss credit card skimming, how is this risk different than exposing your CC number over the Internet? In this episode you'll learn ...</itunes:subtitle>
		<itunes:summary>Bill and Bob discuss credit card skimming, how is this risk different than exposing your CC number over the Internet? In this episode you'll learn how to secure your email using FireFox and Thunderbird. You're using 2048-bit RSA keys, right? And you're backing up your digital certificates and private keys too, yes? Once you get your certificate, send us an encrypted email using our certificate!

Alternative instructions: Outlook and Apple Mail.

Did you know that if you aren't digitally signing AND encrypting your email, the message isn't truly secure?  Bob discusses this subtle but important distinction. If this doesn't make sense, let us know and we'll cover this in more depth.

Free S/MIME certificates are available from Comodo (Windows only) and Thawte. Remember that with Thawte you have to "join" their system.

If you're enjoying our podcast, we'd appreciate hearing more feedback from you and seeing your reviews at iTunes. If you have comments, suggestions or know where Bob, Alice, Eve and Mallory are please contact us at comments@SecurityHype.com.

Thank you for listening!</itunes:summary>
		<itunes:keywords>S/MIME,,general,security,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.4-OCSP, CRL, and Vista&#8217;s new SSL tricks</title>
		<link>http://www.securityhype.com/blog/archives/23</link>
		<comments>http://www.securityhype.com/blog/archives/23#comments</comments>
		<pubDate>Wed, 02 May 2007 03:50:03 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[SSL]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/23</guid>
		<description><![CDATA[Bill and Bob catch up on listener feedback, then delve into more details about digital certificates.  Certificates and private keys may become compromised before they expire.  CRL and OCSP are two methods that applications and systems can verify the status of digital certificates.  Microsoft Vista, for the first time, now performs certificate [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob catch up on listener feedback, then delve into more details about digital certificates.  Certificates and private keys may become compromised before they expire.  CRL and OCSP are two methods that applications and systems can verify the status of digital certificates.  Microsoft Vista, for the first time, now performs certificate revocation status checking by default.  This is a good thing and we hope other systems and applications follow their lead.</p>
<p>Do you use CRLs, OCSP, or something else in your PKI? How did you decide which protocol to support, if any?  We&#8217;d love to know.  Have you encountered any OCSP-related errors in Vista?  We have, and we&#8217;ll talk about them in upcoming episodes.</p>
<p>If you&#8217;d like to join the conversation, send your feedback to comments@SecurityHype.com.  Thank you for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/23/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/23/0/Security_Hype_7.4-OCSP_CRL_and_Vista.m4a" length="1" type="audio/x-m4a"/>
<itunes:duration>00:01:01</itunes:duration>
		<itunes:subtitle>Bill and Bob catch up on listener feedback, then delve into more details about digital certificates.  Certificates and private keys may become compromised before ...</itunes:subtitle>
		<itunes:summary>Bill and Bob catch up on listener feedback, then delve into more details about digital certificates.  Certificates and private keys may become compromised before they expire.  CRL and OCSP are two methods that applications and systems can verify the status of digital certificates.  Microsoft Vista, for the first time, now performs certificate revocation status checking by default.  This is a good thing and we hope other systems and applications follow their lead.

Do you use CRLs, OCSP, or something else in your PKI? How did you decide which protocol to support, if any?  We'd love to know.  Have you encountered any OCSP-related errors in Vista?  We have, and we'll talk about them in upcoming episodes.

If you'd like to join the conversation, send your feedback to comments@SecurityHype.com.  Thank you for listening!</itunes:summary>
		<itunes:keywords>SSL,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.3-RSA 2007 Conference Roundup, Vendor Smackdown</title>
		<link>http://www.securityhype.com/blog/archives/18</link>
		<comments>http://www.securityhype.com/blog/archives/18#comments</comments>
		<pubDate>Sun, 04 Mar 2007 21:49:43 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[general security]]></category>

		<category><![CDATA[podcast]]></category>

		<category><![CDATA[product review]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/18</guid>
		<description><![CDATA[Bob and Bill discuss their impressions of the RSA 2007 Security Conference. It seems to be getting less &#8220;technical&#8221; and more &#8220;business focused&#8221;, but Bill was underwhelmed. Bob notices that all the good security company names are taken. What were your thoughts of the conference, did you find it as helpful as previous years?In the [...]]]></description>
			<content:encoded><![CDATA[<p>Bob and Bill discuss their impressions of the RSA 2007 Security Conference. It seems to be getting less &#8220;technical&#8221; and more &#8220;business focused&#8221;, but Bill was underwhelmed. Bob notices that all the good security company names are taken. What were your thoughts of the conference, did you find it as helpful as previous years?In the new &#8220;Vendor Smackdown&#8221; section, Bill tries to figure out what problem PC Magazine&#8217;s &#8220;CoverUp&#8221; program was designed to solve.  Do you use it and find it useful? Tell us if we&#8217;re missing something.</p>
<p>Send your smackdown nominees, suggestions, or feedback to <a href="mailto:Comments@SecurityHype.com">Comments@SecurityHype.com</a></p>
<p>Links referenced in this episode:</p>
<ul>
<li><a href="http://www.google.com/url?sa=t&amp;ct=res&amp;cd=2&amp;url=http%3A%2F%2Fwww.rsaconference.com%2F2007%2FUS%2F&amp;ei=MQ7tRePqL43egwPy-vj7CQ&amp;usg=__FiScgJjU13RHKQLG7XQ5V4azUac=&amp;sig2=tZSdb1mSRl0DKbg8q6tlfA">RSA Security Conference 2007</a></li>
<li><a href="http://www.pcmag.com/article2/0,1895,2086261,00.asp?kc=PCPC10701DTX3C0001163">PC Magazine&#8217;s CoverUp</a></li>
</ul>
<p>And thanks for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/18/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/18/0/Security_Hype_7.3-RSA2007_recap_and_Vendor_Smackdown.m4a" length="15712248" type="audio/x-m4a"/>
<itunes:duration>18:30</itunes:duration>
		<itunes:subtitle>Bob and Bill discuss their impressions of the RSA 2007 Security Conference. It seems to be getting less "technical" and more "business focused", but Bill ...</itunes:subtitle>
		<itunes:summary>Bob and Bill discuss their impressions of the RSA 2007 Security Conference. It seems to be getting less "technical" and more "business focused", but Bill was underwhelmed. Bob notices that all the good security company names are taken. What were your thoughts of the conference, did you find it as helpful as previous years?In the new "Vendor Smackdown" section, Bill tries to figure out what problem PC Magazine's "CoverUp" program was designed to solve.  Do you use it and find it useful? Tell us if we're missing something.

Send your smackdown nominees, suggestions, or feedback to Comments@SecurityHype.com

Links referenced in this episode:

	RSA Security Conference 2007
	PC Magazine's CoverUp

And thanks for listening!</itunes:summary>
		<itunes:keywords>general,security,,podcast,,product,review</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.2-How banks encourage fraud, ways to reduce getting phished, first S/MIME discussion</title>
		<link>http://www.securityhype.com/blog/archives/16</link>
		<comments>http://www.securityhype.com/blog/archives/16#comments</comments>
		<pubDate>Wed, 28 Feb 2007 08:11:23 +0000</pubDate>
		<dc:creator>bob</dc:creator>
		
		<category><![CDATA[SSL]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/16</guid>
		<description><![CDATA[Many banks encourage phishing through their use of inconsistent user interfaces and the improper use of SSL, both putting their customers&#8217; credentials at risk.  Financial institutions invent their own email security schemes that are readily copied by hackers and provide no real security.  Bill and Bob describe several examples of how bad web [...]]]></description>
			<content:encoded><![CDATA[<p>Many banks encourage phishing through their use of inconsistent user interfaces and the improper use of SSL, both putting their customers&#8217; credentials at risk.  Financial institutions invent their own email security schemes that are readily copied by hackers and provide no real security.  Bill and Bob describe several examples of how bad web and email security practices confuse their customers and weaken the total online security experience.  They also provide some suggestions based on solid security practices.</p>
<p>Think SSL is too expensive to deploy?  That&#8217;s 20th century thinking!  Bob&#8217;s team has lab test statistics to refute that old myth: http://boblord.livejournal.com/1538.html</p>
<p>Links referenced in this email:</p>
<ol>
<li>ETrade &#8220;Secure&#8221; Email which dilutes the security lock icon’s value <a href="http://www.securityhype.com/blog/wp-content/uploads/2007/02/etrade-email.jpg" title="ETrade Secure Email:Diluting the lock icon’s value." rel="lightbox"><img src="http://www.securityhype.com/blog/wp-content/uploads/2007/02/etrade-email.thumbnail.jpg" alt="ETrade Secure Email:Diluting the lock icon’s value." /></a></li>
<li><a href="http://news.netcraft.com/archives/2005/12/28/more_than_450_phishing_attacks_used_ssl_in_2005.html">NetCraft Phishing Link</a></li>
<li><a href="http://survey.netcraft.com/surveys/analysis/https/2005/Jun/">NetCraft Surveys</a></li>
<li><a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1169557,00.html?track=sy160">Yahoo! endangers, confuses uses instead of using SSL to begin with</a></li>
<li><a href="http://computerworld.co.nz/news.nsf/UNID/FCC8B6B48B24CDF2CC2570020018FF73?OpenDocument&amp;pub=Computerworld">SSL security warnings don&#8217;t stop users from getting hacked</a></li>
<li><a href="http://knaddison.com/technology/sb-ssl-google-com-security-domain-name-mismatch">Google&#8217;s SSL warnings don&#8217;t stop users either</a></li>
<li><a href="http://www.millersmiles.co.uk/report/2531">Fake Chase phishing email #1</a></li>
<li><a href="http://www.millersmiles.co.uk/report/2388">Fake Chase phishing email #2</a></li>
</ol>
<p>Thank you for listening!  Please send your comments, suggestions, and feedback to <a href="mailto:comments@SecurityHype.com">comments@SecurityHype.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/16/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/16/0/Security_Hype_7.2-Banks_encourage_phishing.m4a" length="19935218" type="audio/x-m4a"/>
<itunes:duration>39:42</itunes:duration>
		<itunes:subtitle>Many banks encourage phishing through their use of inconsistent user interfaces and the improper use of SSL, both putting their customers' credentials at risk.  ...</itunes:subtitle>
		<itunes:summary>Many banks encourage phishing through their use of inconsistent user interfaces and the improper use of SSL, both putting their customers' credentials at risk.  Financial institutions invent their own email security schemes that are readily copied by hackers and provide no real security.  Bill and Bob describe several examples of how bad web and email security practices confuse their customers and weaken the total online security experience.  They also provide some suggestions based on solid security practices.

Think SSL is too expensive to deploy?  That's 20th century thinking!  Bob's team has lab test statistics to refute that old myth: http://boblord.livejournal.com/1538.html

Links referenced in this email:

	ETrade "Secure" Email which dilutes the security lock iconrsquo;s value 
	NetCraft Phishing Link
	NetCraft Surveys
	Yahoo! endangers, confuses uses instead of using SSL to begin with
	SSL security warnings don't stop users from getting hacked
	Google's SSL warnings don't stop users either
	Fake Chase phishing email #1
	Fake Chase phishing email #2

Thank you for listening!  Please send your comments, suggestions, and feedback to comments@SecurityHype.com.</itunes:summary>
		<itunes:keywords>SSL,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Security Hype 7.1-SSL and phishable PayPal tokens</title>
		<link>http://www.securityhype.com/blog/archives/13</link>
		<comments>http://www.securityhype.com/blog/archives/13#comments</comments>
		<pubDate>Sun, 04 Feb 2007 23:13:11 +0000</pubDate>
		<dc:creator>bill</dc:creator>
		
		<category><![CDATA[SSL]]></category>

		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://www.securityhype.com/blog/archives/13</guid>
		<description><![CDATA[Bill and Bob discuss misinformation about SSL represented in the February issue of Popular Mechanics and from BEA technical documents.  We also discuss why hackers aren&#8217;t concerned by PayPal&#8217;s announcement to issue One Time Password (OTP) tokens to protect their members: the hackers already know how to defeat them.
(Technical glitch: the 8-second gap in [...]]]></description>
			<content:encoded><![CDATA[<p>Bill and Bob discuss misinformation about SSL represented in the February issue of Popular Mechanics and from BEA technical documents.  We also discuss why hackers aren&#8217;t concerned by PayPal&#8217;s announcement to issue One Time Password (OTP) tokens to protect their members: the hackers already know how to defeat them.</p>
<p>(Technical glitch: the 8-second gap in the beginning of the audio will be fixed by our next episode.)</p>
<p>Please send your comments, suggestions, and feedback to <a href="mailto:comments@SecurityHype.com">comments@SecurityHype.com</a>.  And thank you for listening!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityhype.com/blog/archives/13/feed</wfw:commentRss>
			<enclosure url="http://www.securityhype.com/blog/podpress_trac/feed/13/0/Security_Hype_7.1-SSL_and_hackable_PayPal_tokens.m4a" length="3948155" type="audio/x-m4a"/>
<itunes:duration>15:39</itunes:duration>
		<itunes:subtitle>Bill and Bob discuss misinformation about SSL represented in the February issue of Popular Mechanics and from BEA technical documents.  We also discuss why ...</itunes:subtitle>
		<itunes:summary>Bill and Bob discuss misinformation about SSL represented in the February issue of Popular Mechanics and from BEA technical documents.  We also discuss why hackers aren't concerned by PayPal's announcement to issue One Time Password (OTP) tokens to protect their members: the hackers already know how to defeat them.

(Technical glitch: the 8-second gap in the beginning of the audio will be fixed by our next episode.)

Please send your comments, suggestions, and feedback to comments@SecurityHype.com.  And thank you for listening!</itunes:summary>
		<itunes:keywords>SSL,,podcast</itunes:keywords>
		<itunes:author>Bill Burns and Bob Lord</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
	</channel>
</rss>
