<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>firstinitiallastname</title>
	
	<link>http://www.filn.net/blog</link>
	<description>putting the 'er' in Internet</description>
	<lastBuildDate>Wed, 09 Dec 2009 19:20:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Firstinitiallastname" /><feedburner:info uri="firstinitiallastname" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Security Through Obscurity and the TSA</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/cYllChMTMfA/</link>
		<comments>http://www.filn.net/blog/2009/12/09/security-through-obscurity-and-the-tsa/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 19:20:03 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/2009/12/09/security-through-obscurity-and-the-tsa/</guid>
		<description><![CDATA[My post, just not here.]]></description>
			<content:encoded><![CDATA[<p>My <a href="http://blog.ncircle.com/blogs/the-lens/archives/2009/12/security_through_obscurity_and.html">post,</a> just not here. </p>

<p><a href="http://feedads.g.doubleclick.net/~a/Xk2h8Y9mg6WN8N0HhxEzTsb723I/0/da"><img src="http://feedads.g.doubleclick.net/~a/Xk2h8Y9mg6WN8N0HhxEzTsb723I/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Xk2h8Y9mg6WN8N0HhxEzTsb723I/1/da"><img src="http://feedads.g.doubleclick.net/~a/Xk2h8Y9mg6WN8N0HhxEzTsb723I/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/cYllChMTMfA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/12/09/security-through-obscurity-and-the-tsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/12/09/security-through-obscurity-and-the-tsa/</feedburner:origLink></item>
		<item>
		<title>Vulnerability Management Panel Featuring…</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/xz_gOOGxsNs/</link>
		<comments>http://www.filn.net/blog/2009/07/27/vulnerability-management-panel-featuring/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 14:12:27 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/?p=63</guid>
		<description><![CDATA[&#8230;me, Ron Gula, Sheldon Malm, and Bob Greenbaum. You can listen to the recording here.]]></description>
			<content:encoded><![CDATA[<p>&#8230;me, Ron Gula, Sheldon Malm, and Bob Greenbaum. You can listen to the recording <a href="https://whitehatworldevents.webex.com/ec0605l/eventcenter/recording/recordAction.do;jsessionid=XT5FKt0QH0x4J15ccxCp3zvhxpJypDw10QmwTQh8LXZZ76sfmyg2!-746833459?theAction=poprecord&#038;actname=%2Feventcenter%2Fframe%2Fg.do&#038;apiname=lsr.php&#038;renewticket=0&#038;renewticket=0&#038;actappname=ec0605l&#038;entappname=url0107l&#038;needFilter=false&#038;&#038;isurlact=true&#038;entactname=%2FnbrRecordingURL.do&#038;rID=1468317&#038;rKey=28bf66efb2be1c6a&#038;recordID=1468317&#038;rnd=2336112525&#038;siteurl=whitehatworldevents&#038;SP=EC&#038;AT=pb&#038;format=short">here</a>. </p>

<p><a href="http://feedads.g.doubleclick.net/~a/CdEM84UUynTl_eo_-wc5gzBXI7A/0/da"><img src="http://feedads.g.doubleclick.net/~a/CdEM84UUynTl_eo_-wc5gzBXI7A/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/CdEM84UUynTl_eo_-wc5gzBXI7A/1/da"><img src="http://feedads.g.doubleclick.net/~a/CdEM84UUynTl_eo_-wc5gzBXI7A/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/xz_gOOGxsNs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/07/27/vulnerability-management-panel-featuring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/07/27/vulnerability-management-panel-featuring/</feedburner:origLink></item>
		<item>
		<title>Will Code for Food</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/TsA7AhCxxao/</link>
		<comments>http://www.filn.net/blog/2009/06/23/will-code-for-food/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 20:55:27 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/?p=60</guid>
		<description><![CDATA[Here&#8217;s a slideshow of the worst US cities for IT workers. Here&#8217;s the list of them: 1. Detroit, MI 2. Bentonville, AK 3. Cleveland, OH 4. Syracuse, NY 5. Boston, MA and San Francisco, CA 6. Any town in Alaska 7. Orlando, FL You can compare that to the 10 cities with the best IT [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a <a href="http://www.cio.com/article/495555/The_Worst_U.S._Cities_to_Work_in_IT">slideshow </a>of the worst US cities for IT workers. Here&#8217;s the list of them:</p>
<p>1. Detroit, MI<br />
2. Bentonville, AK<br />
3. Cleveland, OH<br />
4. Syracuse, NY<br />
5. Boston, MA and San Francisco, CA<br />
6. Any town in Alaska<br />
7. Orlando, FL</p>
<p>You can compare that to the 10 cities with the <a href="http://www.cio.com/article/493282/Where_the_IT_Jobs_Are_American_Cities">best </a>IT job prospects:</p>
<p>1. Atlanta, GA<br />
2. Boston. MA<br />
3. Chicago, IL<br />
4. Dallas, TX<br />
5. Los Angeles, CA<br />
6. New York/New Jersey<br />
7. Philadelphia, PA<br />
8. Seattle, WA<br />
9. Silicon Valley, CA<br />
10. Washington D.C/Baltimore</p>
<p>Poor Boston seems a bit schizophrenic. Of course, one could argue that &#8220;Silicon Valley&#8221; and &#8220;San Francisco&#8221; are too close to each other to be counted differently. I mean, what percentage of IT workers employed in SF actually live within city limits? To be fair, &#8216;where the jobs are/aren&#8217;t&#8217; is a different metric from &#8216;best/worst.&#8217; You could have a high number of jobs, but still end up in the &#8216;worst&#8217; group if the external environment is bad. </p>

<p><a href="http://feedads.g.doubleclick.net/~a/RVUFfaj4aysIdhqBzKgHTx4Nn1o/0/da"><img src="http://feedads.g.doubleclick.net/~a/RVUFfaj4aysIdhqBzKgHTx4Nn1o/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/RVUFfaj4aysIdhqBzKgHTx4Nn1o/1/da"><img src="http://feedads.g.doubleclick.net/~a/RVUFfaj4aysIdhqBzKgHTx4Nn1o/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/TsA7AhCxxao" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/06/23/will-code-for-food/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/06/23/will-code-for-food/</feedburner:origLink></item>
		<item>
		<title>Easy</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/RH3OKUtmIg0/</link>
		<comments>http://www.filn.net/blog/2009/06/22/easy/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 13:29:13 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/?p=55</guid>
		<description><![CDATA[There are a lot of businesses that make it hard for their customers to actually buy something. They organize their stores in confusing ways, open and close at odd hours or on odd days, and institute policies that *seem* good for the company or shop, but really only serve to make it harder for customers [...]]]></description>
			<content:encoded><![CDATA[<p>There are a lot of businesses that make it hard for their customers to actually buy something. They organize their stores in confusing ways, open and close at odd hours or on odd days, and institute policies that *seem* good for the company or shop, but really only serve to make it harder for customers to buy. Return policies are the best examples. Many companies institute policies that are restrictive about how and when you may return merchandise you don&#8217;t want. Operations like <a href="http://www.zappos.com">Zappos </a>and <a href="http://www.nordstrom.com">Nordstrom </a>take the opposite approach. It&#8217;s hard to argue that one way or the other is the right way to run a business. Both are successful, and when talking about return policies, there&#8217;s probably a right balance. </p>
<p>There are other ways, however, to ensure that your product is easy to buy. I walked by this shop called <a href="http://www.gatheronfrance.com/">Gather</a> (warning, auto-music on link) yesterday and it had this sign in the window.</p>
<p><img src="http://www.filn.net/blog/wp-content/uploads/2009/06/2009-06-21-16.33.22-300x225.jpg" alt="2009-06-21 16.33.22" title="2009-06-21 16.33.22" width="300" height="225" class="aligncenter size-medium wp-image-56" /></p>
<p>Caribou, as you can probably guess or already know, is a cafe. Gather is located right next to Caribou. There are a lot of shops that post signs saying &#8220;no food or drink,&#8221; which is really saying that if you are eating or drinking, they don&#8217;t want your business. Gather could have posted nothing, implying that drinks are ok. This sign, however, simply suggests that once you have your half-caff, extra strong, skim, no-whip mocha, you might just enjoy drinking it in their shop instead of sitting in Caribou. </p>

<p><a href="http://feedads.g.doubleclick.net/~a/C_eBZeuDRmGjCh1iGN5yeZhXgMY/0/da"><img src="http://feedads.g.doubleclick.net/~a/C_eBZeuDRmGjCh1iGN5yeZhXgMY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/C_eBZeuDRmGjCh1iGN5yeZhXgMY/1/da"><img src="http://feedads.g.doubleclick.net/~a/C_eBZeuDRmGjCh1iGN5yeZhXgMY/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/RH3OKUtmIg0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/06/22/easy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/06/22/easy/</feedburner:origLink></item>
		<item>
		<title>Finally Help That’s Helpful</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/aqP80WIFutU/</link>
		<comments>http://www.filn.net/blog/2009/06/16/finally-help-thats-helpful/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 16:53:52 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Random]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/2009/06/16/finally-help-thats-helpful/</guid>
		<description><![CDATA[I have a strong dislike for automated help systems that fail almost completely to actually help you. So I was really pleased to find that Whirlpool is actually quite helpful with my refrigerator. I heard a dripping sound from the fridge, checked out and found that it was indeed dripping and filling a pan underneath. [...]]]></description>
			<content:encoded><![CDATA[<p>I have a strong dislike for automated help systems that fail almost completely to actually help you. So I was really pleased to find that <a href="http://www.whirlpool.com">Whirlpool </a>is actually quite helpful with my refrigerator. I heard a dripping sound from the fridge, checked out and found that it was indeed dripping and filling a pan underneath. I went to Whirlpool&#8217;s website, put in that I have a refrigerator, the type and &#8216;dripping water.&#8217; The second search result was &#8220;A <span class="highlight">water</span> <span class="highlight">dripping</span> sound may be heard as <span class="highlight">water</span> runs into the drain pan during the defrost cycle,&#8221; and it comes with an mp3 of the sound so I can identify if it&#8217;s the same sound I&#8217;m hearing. Nice.&nbsp;</p>

<p><a href="http://feedads.g.doubleclick.net/~a/ICP8pBtGhrCpQ79PhuViDrJ0H1I/0/da"><img src="http://feedads.g.doubleclick.net/~a/ICP8pBtGhrCpQ79PhuViDrJ0H1I/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/ICP8pBtGhrCpQ79PhuViDrJ0H1I/1/da"><img src="http://feedads.g.doubleclick.net/~a/ICP8pBtGhrCpQ79PhuViDrJ0H1I/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/aqP80WIFutU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/06/16/finally-help-thats-helpful/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/06/16/finally-help-thats-helpful/</feedburner:origLink></item>
		<item>
		<title>Web App Vuln Stats</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/Wpn531Tr4X0/</link>
		<comments>http://www.filn.net/blog/2009/06/16/web-app-vuln-stats/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 14:21:00 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/2009/06/16/web-app-vuln-stats/</guid>
		<description><![CDATA[Some stats about Web Application vulnerabilities from White Hat Security. Around 30 percent of Websites are likely to contain content spoofing bugs 18 percent, insufficient authorization 17 percent, SQL injection 14 percent, predictable resource location 11 percent, session fixation 11 percent, cross-site request forgery (CSRF) 10 percent, insufficient authentication 9 percent, HTTP response-splitting flaws To [...]]]></description>
			<content:encoded><![CDATA[<p>Some <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=217500479&amp;cid=RSSfeed">stats </a>about Web Application vulnerabilities from White Hat Security. <span class="smalltext"></p>
<p>Around 30 percent of Websites are likely to contain content spoofing bugs<br />
18 percent, insufficient authorization<br />
17 percent, SQL injection<br />
14 percent, predictable resource location<br />
11 percent, session fixation<br />
11 percent, cross-site request forgery (CSRF)<br />
10 percent, insufficient authentication<br />
9 percent, HTTP response-splitting flaws</p>
<p>To be fair and accurate, of course, these statistics apply to the sample group of White Hat Security customers, not the entire Internet. <br />
</span></p>

<p><a href="http://feedads.g.doubleclick.net/~a/iXq8GxMFZTo8I7Os7peNEBVjol4/0/da"><img src="http://feedads.g.doubleclick.net/~a/iXq8GxMFZTo8I7Os7peNEBVjol4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/iXq8GxMFZTo8I7Os7peNEBVjol4/1/da"><img src="http://feedads.g.doubleclick.net/~a/iXq8GxMFZTo8I7Os7peNEBVjol4/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/Wpn531Tr4X0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/06/16/web-app-vuln-stats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/06/16/web-app-vuln-stats/</feedburner:origLink></item>
		<item>
		<title>The Segway Problem</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/Q9mvwcNElr4/</link>
		<comments>http://www.filn.net/blog/2009/06/14/the-segway-problem/#comments</comments>
		<pubDate>Sun, 14 Jun 2009 17:57:03 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/?p=48</guid>
		<description><![CDATA[The Segway was a revolutionary feat of engineering. It&#8217;s called &#8220;dynamic stabilization&#8221; and allows the Segway to run on two wheels without falling over or causing the rider to tumble off. When it came out, people were interested. The problem with Segway is that the thing that makes it unique, the feature that&#8217;s hard to [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.segway.com/">Segway </a>was a revolutionary feat of engineering. It&#8217;s called &#8220;dynamic stabilization&#8221; and allows the Segway to run on two wheels without falling over or causing the rider to tumble off. When it came out, people were interested. </p>
<p>The problem with Segway is that the thing that makes it unique, the feature that&#8217;s hard to replicate, isn&#8217;t actually that important to the market. See, you can deliver a personal mobility machine suitable for almost everything the Segway does without &#8216;dynamic stabilization&#8217; technology. Just add a third wheel. </p>
<div id="attachment_50" class="wp-caption alignleft" style="width: 644px"><a href="http://www.dailymail.co.uk/news/article-1192581/Police-unveil-new-twist-old-idea--bobby-motorised-tricycle.html"><img src="http://www.filn.net/blog/wp-content/uploads/2009/06/article-1192581-0550C03F000005DC-243_634x837.jpg" alt="Not a Segway" title="article-1192581-0550C03F000005DC-243_634x837" width="634" height="837" class="size-full wp-image-50" /></a><p class="wp-caption-text">Not a Segway</p></div>

<p><a href="http://feedads.g.doubleclick.net/~a/ecaJ_MvtV1p6KV51hz7eidcw0Ug/0/da"><img src="http://feedads.g.doubleclick.net/~a/ecaJ_MvtV1p6KV51hz7eidcw0Ug/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/ecaJ_MvtV1p6KV51hz7eidcw0Ug/1/da"><img src="http://feedads.g.doubleclick.net/~a/ecaJ_MvtV1p6KV51hz7eidcw0Ug/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/Q9mvwcNElr4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/06/14/the-segway-problem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/06/14/the-segway-problem/</feedburner:origLink></item>
		<item>
		<title>Questions to Ask Yourself</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/WfO9AtssAxU/</link>
		<comments>http://www.filn.net/blog/2009/06/12/questions-to-ask-yourself/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 17:14:21 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/?p=45</guid>
		<description><![CDATA[Ok, it&#8217;s really only one question: Why am I here? The link is to a short blog post that&#8217;s worth reading if your day generally involves attending meetings.]]></description>
			<content:encoded><![CDATA[<p>Ok, it&#8217;s really only one question: <a href="http://sethgodin.typepad.com/seths_blog/2009/06/why-am-i-here.html">Why am I here?</a></p>
<p>The link is to a short blog post that&#8217;s worth reading if your day generally involves attending meetings.  </p>

<p><a href="http://feedads.g.doubleclick.net/~a/IXigP92bmk9RsDpTDdxaKFLHCSc/0/da"><img src="http://feedads.g.doubleclick.net/~a/IXigP92bmk9RsDpTDdxaKFLHCSc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/IXigP92bmk9RsDpTDdxaKFLHCSc/1/da"><img src="http://feedads.g.doubleclick.net/~a/IXigP92bmk9RsDpTDdxaKFLHCSc/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/WfO9AtssAxU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/06/12/questions-to-ask-yourself/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/06/12/questions-to-ask-yourself/</feedburner:origLink></item>
		<item>
		<title>PCI FAQ featuring me at Practi…</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/d40t4Posgo8/</link>
		<comments>http://www.filn.net/blog/2009/03/26/pci-faq-featuring-me-at-practi/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 18:28:43 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[tweet]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/2009/03/26/pci-faq-featuring-me-at-practi/</guid>
		<description><![CDATA[PCI FAQ featuring me at Practical eCommerce: http://tinyurl.com/dcsevk]]></description>
			<content:encoded><![CDATA[<p>PCI FAQ featuring me at Practical eCommerce: <a href="http://tinyurl.com/dcsevk" rel="nofollow">http://tinyurl.com/dcsevk</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/s3bH3TbQWtJhV649knjr9WTIRzM/0/da"><img src="http://feedads.g.doubleclick.net/~a/s3bH3TbQWtJhV649knjr9WTIRzM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/s3bH3TbQWtJhV649knjr9WTIRzM/1/da"><img src="http://feedads.g.doubleclick.net/~a/s3bH3TbQWtJhV649knjr9WTIRzM/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/d40t4Posgo8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/03/26/pci-faq-featuring-me-at-practi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/03/26/pci-faq-featuring-me-at-practi/</feedburner:origLink></item>
		<item>
		<title>There Is No Perimeter</title>
		<link>http://feedproxy.google.com/~r/Firstinitiallastname/~3/qRjQhpKPVSw/</link>
		<comments>http://www.filn.net/blog/2009/03/19/there-is-no-perimeter/#comments</comments>
		<pubDate>Thu, 19 Mar 2009 13:56:42 +0000</pubDate>
		<dc:creator>Tim Erlin</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ATMs]]></category>

		<guid isPermaLink="false">http://www.filn.net/blog/?p=39</guid>
		<description><![CDATA[Ok, so ATMs are computing devices and ergo they&#8217;re vulnerable to attack. Why is this attack interesting? Why is it worth a post? Well, let&#8217;s start here: &#8220;This is not something the average hacker on the street would have access to,&#8221; he adds. &#8220;They need physical access to the ATM &#8212; they need to have [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_38" class="wp-caption alignleft" style="width: 458px"><img class="size-full wp-image-38" title="blue-screen-of-death-atm" src="http://www.filn.net/blog/wp-content/uploads/2009/03/blue-screen-of-death-atm.jpg" alt="General Protection Fault indeed." width="448" height="336" /><p class="wp-caption-text">General Protection Fault indeed.</p></div>
<p>Ok, so ATMs are computing devices and ergo they&#8217;re vulnerable to attack. Why is this <a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=215901034">attack</a> interesting? Why is it worth a post? Well, let&#8217;s start here:</p>
<p>&#8220;This is not something the average hacker on the street would have access to,&#8221; he adds. &#8220;They need physical access to the ATM &#8212; they need to have someone on the inside or involved with the manufacture of these devices to gain access and install the software. &#8221;</p>
<p>Even the outsider attacks are insider attacks. You know, with the technological advancements in virtualization, I can&#8217;t help wondering if the attackers didn&#8217;t just develop against a virtual machine. Heck, I can&#8217;t imagine that Diebold doesn&#8217;t have a way to virtualize their own ATMs for development and testing. So, conclusion #1: just because you are an &#8216;appliance&#8217; doesn&#8217;t mean you can&#8217;t be copied and hacked.</p>
<p>&#8220;<span class="smalltext">The Trojan collected PINs and the so-called Track 2 encrypted data stored on magnetic stripes on ATM cards, he says, which allowed the attackers to clone real ATM cards. They would then insert their own specially crafted card into the Trojan-infected ATM machine to gain access, and the machine would then spit out the stolen information via the machine&#8217;s printer.&#8221;</span></p>
<p><span class="smalltext">So they went to the trouble of hacking ATMs, but the only method they developed of delivering the data was for someone to walk up to the ATM and print out the info that&#8217;s been collected? Seems to me that if they&#8217;re skilled enough to pull off this hack, then they&#8217;re skilled enough to find a way to bulk deliver the data. Of course, sometimes low-tech is the most successful route, but it wouldn&#8217;t surprise me if this wasn&#8217;t a proof of concept or if this ATM malware doesn&#8217;t have a longer life in some unexpected way.<br />
</span></p>

<p><a href="http://feedads.g.doubleclick.net/~a/sr-CfU92Zv9hw8M3NNNsOQpQO4U/0/da"><img src="http://feedads.g.doubleclick.net/~a/sr-CfU92Zv9hw8M3NNNsOQpQO4U/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/sr-CfU92Zv9hw8M3NNNsOQpQO4U/1/da"><img src="http://feedads.g.doubleclick.net/~a/sr-CfU92Zv9hw8M3NNNsOQpQO4U/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Firstinitiallastname/~4/qRjQhpKPVSw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.filn.net/blog/2009/03/19/there-is-no-perimeter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.filn.net/blog/2009/03/19/there-is-no-perimeter/</feedburner:origLink></item>
	</channel>
</rss>
