<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Frames And Bits - The Andrew Storms Blog</title>
    
    
    <link rel="alternate" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/" />
    <id>tag:typepad.com,2003:weblog-1816608</id>
    <updated>2009-05-03T16:49:40-07:00</updated>
    <subtitle>Observations of Andrew Storms</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/FramesAndBits-TheAndrewStormsBlog" /><feedburner:info uri="framesandbits-theandrewstormsblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://hubbub.api.typepad.com/" /><entry>
        <title>Weekend Frame - Moon Over The Valley</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/DfkjRkmRaT8/weekend-frame-moon-over-the-valley.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/05/weekend-frame-moon-over-the-valley.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-66327097</id>
        <published>2009-05-03T16:49:40-07:00</published>
        <updated>2009-05-03T16:50:38-07:00</updated>
        <summary>Camera: Nikon D70s Exposure: 0.001 sec (1/1600) Aperture: f/5.6 Focal Length: 48 mm Exposure: 0.00 ISO Speed: 400</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Photography" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="photography" />
        <category scheme="http://sixapart.com/ns/types#tag" term="yosemite" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><br /><p /><div style="text-align: center;"><a href="http://www.flickr.com/photos/linecon0/3492717380/" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="display: inline;"><img alt="Yosemite_moon" border="0" class="at-xid-6a0111684254e2970c0115706a8d5f970b image-full " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c0115706a8d5f970b-800wi" title="Yosemite_moon" /></a></div><p> </p><br /><p><br /><span style="font-size: 12px; font-family: Verdana;"><strong>Camera:</strong>
						<strong><a href="http://www.flickr.com/cameras/nikon/d70s/">Nikon D70s</a></strong>
<br />					
					
						<strong>Exposure:</strong>
						<strong>0.001 sec (1/1600)</strong>
					
					
						<strong><br />Aperture:</strong>
						<strong>f/5.6</strong>
<br />					
					
						<strong>Focal Length:</strong>
						<strong>48 mm</strong>
					
					
						<strong><br />Exposure:</strong>
						<strong>0.00</strong>
					
					
						<strong><br />ISO Speed:</strong>
						400</span></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/DfkjRkmRaT8" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/05/weekend-frame-moon-over-the-valley.html</feedburner:origLink></entry>
    <entry>
        <title>Security Bloggers Meetup</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/mNbAN3RQnzw/security-bloggers-meetup.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/04/security-bloggers-meetup.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-65987477</id>
        <published>2009-04-24T13:09:53-07:00</published>
        <updated>2009-04-24T13:09:53-07:00</updated>
        <summary>Congratulations to the winners of the Social Security Awards at the Security Bloggers Meetup. The winners are: PaulDotCom won the Best Podcast Award SANS Internet Storm Center took the best technical blog award TaoSecurity for the best non technical blog...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="rsacon" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p><br />Congratulations to the winners of the Social Security Awards at the Security Bloggers Meetup.  The winners are:</p><ul>
<li><a href="http://pauldotcom.com/">PaulDotCom</a> won the Best Podcast Award</li>
<li><a href="http://isc.sans.org/">SANS Internet Storm Center</a> took the best technical blog award</li>
<li><a href="http://taosecurity.blogspot.com/">TaoSecurity</a> for the best non technical blog</li>
<li><a href="http://sunbeltblog.blogspot.com/">Sunbelt Security</a> for the best corporate blog</li>
<li><a href="http://securityincite.com/">Security Incite</a> won the most entertaining blog</li>
</ul>
<p>Huge thanks to <a href="http://securosis.com/" target="_blank">Rich Mogul</a>, <a href="http://www.mckeay.net/" target="_blank">Martin McKeay</a>, <a href="http://blogs.zdnet.com/feeds/" target="_blank">Jennifer Leggio</a>, Sonya Caprio, <a href="http://www.stillsecureafteralltheseyears.com/" target="_blank">Alan Shimel</a> and Jeanne Friedman for putting in many hours to make the event happen.</p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/mNbAN3RQnzw" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/04/security-bloggers-meetup.html</feedburner:origLink></entry>
    <entry>
        <title>Recent Press</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/ytT9kkzLGBo/recent-press.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/04/recent-press.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-65698531</id>
        <published>2009-04-20T06:00:00-07:00</published>
        <updated>2009-04-20T06:00:00-07:00</updated>
        <summary>A sampling of my recent press coverage. Cloud Implementation, Part 1: Planning for Success CRM Buyer - ‎Apr 3, 2009‎ Grid spyware: Deregulation bites us again ZDNet - ‎Apr 8, 2009‎ Microsoft patches serious Excel zero-day, Windows flaws SearchSecurity.com -...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Andrew Storms" />
        <category scheme="http://sixapart.com/ns/types#tag" term="information security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="news" />
        <category scheme="http://sixapart.com/ns/types#tag" term="press" />
        <category scheme="http://sixapart.com/ns/types#tag" term="risk" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p><img src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01053717122b970b-pi" /><br />A sampling of my recent press coverage.</p>


<p><span style="font-size: 16px; font-family: Verdana;"><a class="usg-AFQjCNH8RkcyL1a0fBQvlz1gxfIO6qrk6A sig2-Bn_7XasE-AomcwZZ1u2alA" href="http://www.crmbuyer.com/story/Cloud-Implementation-Part-1-Planning-for-Success-66718.html" target="_self">Cloud Implementation, Part 1: Planning for Success</a>
<br />
<span class="source">CRM Buyer</span> - <span class="date">‎Apr 3, 2009‎</span>
<br /><br /><a class="usg-AFQjCNFjGzcPCZ9ttP4ovE_RYIJrlhCC-w sig2-47SEAmyGH4IHqO69nrkNsA" href="http://government.zdnet.com/?p=4580" target="_self">Grid spyware: Deregulation bites us again</a>
<br />
<span class="source">ZDNet</span> - <span class="date">‎Apr 8, 2009‎</span>
<br /><br /><a class="usg-AFQjCNGIdurYjdGZAGfhJSUB2jDogJHYMQ sig2-yn3eob8w69-AUhmPNNiuww" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1353765,00.html" target="_self">Microsoft patches serious Excel zero-day, Windows flaws</a>

SearchSecurity.com - ‎Apr 14, 2009</span></p>
<p><span style="font-size: 16px; font-family: Verdana;"><a class="usg-AFQjCNHXBfR34AuuxwUB8gt8PCX9_gcIVQ sig2-iaP0ap72mFvHJog9dlmdFQ" href="http://www.arnnet.com.au/article/299289/microsoft_patches_insane_number_bugs" target="_self">Microsoft patches 'insane' number of bugs</a>

<span class="source"><br />ARNnet</span> - <span class="date">‎Apr 14, 2009‎</span></span></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/ytT9kkzLGBo" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/04/recent-press.html</feedburner:origLink></entry>
    <entry>
        <title>Weekend Frame - Round and Round</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/AiJtukWvfMo/weekend-frame-round-and-round.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/04/weekend-frame-round-and-round.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-65698403</id>
        <published>2009-04-18T19:32:57-07:00</published>
        <updated>2009-04-18T19:34:05-07:00</updated>
        <summary>Round and round we go. Should be a good week at RSA.</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Photography" />
        
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>Round and round we go. Should be a good week at RSA.</p><div style="text-align: center;"><span style="text-decoration: underline;"><a href="http://www.flickr.com/photos/linecon0/3446657216/" style="display: inline;"><img alt="Round" border="0" class="at-xid-6a0111684254e2970c01156f338922970c image-full " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01156f338922970c-800wi" style="border: 4px solid black;" title="Round" /></a> </span> <br /><br /></div><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/AiJtukWvfMo" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/04/weekend-frame-round-and-round.html</feedburner:origLink></entry>
    <entry>
        <title>Debunking Mobile Malware Spread Due to Marketshare Conditions</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/7wIKuu9-3_4/debunking-mobile-malware-spread-due-to-marketshare-conditions.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/04/debunking-mobile-malware-spread-due-to-marketshare-conditions.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-65230869</id>
        <published>2009-04-08T10:14:08-07:00</published>
        <updated>2009-04-08T10:12:50-07:00</updated>
        <summary>The looming mobile malware threat of the past decade has yet to materialize. The reason for its lack of fruition, according to scientists, is due to geography and the lack of a dominant market shareholder. However well done the math,...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="blackberry" />
        <category scheme="http://sixapart.com/ns/types#tag" term="geography" />
        <category scheme="http://sixapart.com/ns/types#tag" term="iphone" />
        <category scheme="http://sixapart.com/ns/types#tag" term="malware" />
        <category scheme="http://sixapart.com/ns/types#tag" term="mobile" />
        <category scheme="http://sixapart.com/ns/types#tag" term="smartphone" />
        <category scheme="http://sixapart.com/ns/types#tag" term="spread" />
        <category scheme="http://sixapart.com/ns/types#tag" term="virus" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.flickr.com/photos/linecon0/663757037/" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="float: right;"><img alt="AppleStore" border="0" class="at-xid-6a0111684254e2970c011570093fbc970b " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c011570093fbc970b-320pi" style="border: 3px solid black; margin: 4px;" title="AppleStore" /></a>
 The looming mobile malware threat of the past decade has yet to materialize.  The reason for its lack of fruition, according to scientists, is due to geography and the lack of a dominant market shareholder.  However well done the math, the scientific study is flawed nonetheless.  <a href="http://www.barabasilab.com/pubs/CCNR-ALB_Publications/200904-02_ScienceExpr-PhoneViruses/200904-02_ScienceExpr-PhoneViruses" target="_blank">“Understanding the Spreading Patterns of Mobile Phone Viruses” a new paper by 4 scientists</a> fails take into account modern malware trends and operational knowledge of security vendors like those of antivirus companies.</p><p>Mitigation and countermeasures to risk is a common parlay for business decisions.  In this study, the scientists declare that antivirus vendors will have ample time to deliver antivirus protections due to the slow speed of Bluetooth viruses.  Unfortunately, the paper fails to take into account the business operations of antivirus vendors.  AV vendors also perform their own risk analysis in order to determine priority for signature writers.  Slower moving viruses or any virus with less perceived risk will go second to high-risk threats.  In addition, the way vendors become aware of threats are typically in two methods – customer reports and Internet monitoring systems.  To best of my knowledge, AV vendors aren’t walking the streets in major metro areas with smartphone in hand scooping up Bluetooth traffic in hopes of finding a virus.  More than likely, by the time an AV vendor got wind of a Bluetooth virus, it will already have been spreading for days or perhaps weeks.  </p><p><br />The work declares that market share, <em>m</em>, can be declared as a free parameter simply because malware only works on the operating system for which it was designed.</p><p style="font-size: 11px; font-family: Verdana; margin-left: 80px;"><em>"A cell phone virus can infect only the phones with the operating system (OS) it was designed for (2, 3), making the market share m of an OS an important free parameter in our study."</em></p><p><br />The accuracy of this statement is correct, but fails to take into account current trends of malware.  A virus is typically written for a specific architecture and operating system. It cannot magically morph into a self-aware entity, which can now infect every operating system.  By somehow implying such silliness as a method to declare <em>m</em> as a free floating and utmost important variable is itself flawed.  Nonetheless, the more important trend failed to be recognized is that malware more often targets applications and not operating systems.  The truth of the matter is that most breaches in the last 5 years attack applications, not operating systems.  Recent to 2009 are the Adobe vulnerabilities that affected Windows, Mac and Unix systems.  Browsers, the ubiquitous tool of the computer today, are cross platform affected.  Firefox, for example, commonly requires updates to both Mac and Windows.  Apple, which produces personal computer software and one of the most popular smart phones, also commonly finds itself updating software for vulnerabilities on Windows, Mac and the iPhone.  So much of the study relies on market share to be a variable; unfortunately, market share is such a small piece of reality.</p><p><br />The paper does acknowledge that MMS based viruses can spread much quicker than Bluetooth, but again places a strong foundation on operating specific threats. No creativity is imposed to suppose that a crafty virus writer could implant payloads for multiple operating systems.  Or why couldn’t the virus be written in architecture neutral language such as Java that compiles to byte code?  Nearly every smartphone on the market today supports Java.  If the paper is found to be correct in this regards, then simply writing a Java based virus will turn the math completely upside down.</p><p>To further argue against this paper, we cannot overlook the fact that these devices are now equipped with Wifi, can hold up a VPN back to the corporate office and have wired USB connections.  Any slow spreading downplay of the Bluetooth connection are immediately surpassed by the distance and speed of wifi.  The potential adjacency spread of malware given the devices numerous connection types easily outpaces and diminishes any compensating declinations due to single operating system virus supposition.</p><p>We have to thank these scientists for their hard work and excellent study.  However, I must disagree with their conclusions that market share and geography alone are reasons enough why we haven’t yet seen the major mobile virus outbreak soon to come.</p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/7wIKuu9-3_4" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/04/debunking-mobile-malware-spread-due-to-marketshare-conditions.html</feedburner:origLink></entry>
    <entry>
        <title>Weekend Frame - Homebrew</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/kKrlzB8jhsY/weekend-frame-homebrew.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/04/weekend-frame-homebrew.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-65058275</id>
        <published>2009-04-04T06:00:00-07:00</published>
        <updated>2009-04-04T06:00:00-07:00</updated>
        <summary>A work buddy made this nice beer.</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Photography" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="beer" />
        <category scheme="http://sixapart.com/ns/types#tag" term="photography" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>A work buddy made this nice beer.</p><p><br /><a href="http://www.flickr.com/photos/linecon0/3393398853/" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="display: inline;"><img alt="Beer" border="0" class="at-xid-6a0111684254e2970c01156fd2c2a3970b " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01156fd2c2a3970b-500pi" title="Beer" /></a>
 </p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/kKrlzB8jhsY" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/04/weekend-frame-homebrew.html</feedburner:origLink></entry>
    <entry>
        <title>Recent Press Coverage</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/1RtxMT4JXO4/recent-press-coverage.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/04/recent-press-coverage.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-65058115</id>
        <published>2009-04-03T15:50:55-07:00</published>
        <updated>2009-04-03T15:50:55-07:00</updated>
        <summary>A recap of selected articles where I was quoted in recent days. Bill to centralize cybersecurity ZDNet - ‎Apr 1, 2009‎ Hackers Mistimed Conficker, But Threat Lingers NewsFactor Network - ‎Apr 2, 2009‎ Cloud Implementation, Part 1: Planning for Success...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Andrew Storms" />
        <category scheme="http://sixapart.com/ns/types#tag" term="cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="conficker" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ncircle" />
        <category scheme="http://sixapart.com/ns/types#tag" term="pr" />
        <category scheme="http://sixapart.com/ns/types#tag" term="press" />
        <category scheme="http://sixapart.com/ns/types#tag" term="zdnet" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p><img src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01053717122b970b-pi" />

</p><p>A recap of selected articles where I was quoted in recent days.</p><p><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNHAVPJhL27r4SvQFhbEgrhGCc4SZA sig2-c9hTaWyvg4phgsK4Wrc_WA" href="http://government.zdnet.com/?p=4532" target="_self">Bill to centralize cybersecurity</a>

</span>
</p><div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">ZDNet</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Apr 1, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNE7hVd8OUCpiNWUBjyjApPIBbV2dQ sig2-N2LXJ7mKzAZHQ8NzhMZSxQ" href="http://www.newsfactor.com/news/Mistimed-Conficker-Is-Still-a-Threat/story.xhtml?story_id=0020002HDU5S" target="_self">Hackers Mistimed Conficker, But Threat Lingers</a>

</span>
<div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">NewsFactor Network</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Apr 2, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNH8RkcyL1a0fBQvlz1gxfIO6qrk6A sig2-4lKz0MXnc1UXlCpNzuSavQ" href="http://www.crmbuyer.com/story/Cloud-Implementation-Part-1-Planning-for-Success-66718.html" target="_self">Cloud Implementation, Part 1: Planning for Success</a>

<br /></span>
<span style="font-size: 12px; font-family: Verdana;">CRM Buyer</span> <br /><br /><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNGa_jIxTWmpS-IohLvHSNR41C6-Vw sig2-CGtzdn2HAjIgw6U_7-bdbA" href="http://www.networkworld.com/news/2009/040309-attackers-exploit-critical-powerpoint.html" target="_self">Attackers exploit critical powerpoint vulnerability</a>
<br />
</span>
<span style="font-size: 12px; font-family: Verdana;">NetworkWorld.com</span><br /></div><br /></div><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/1RtxMT4JXO4" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/04/recent-press-coverage.html</feedburner:origLink></entry>
    <entry>
        <title>Weekend Frame  - Prickly Bits</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/Bu3ocvQ9yVo/weekend-frame-prickly-bits.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/weekend-frame-prickly-bits.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64765071</id>
        <published>2009-03-27T20:01:31-07:00</published>
        <updated>2009-03-27T20:01:31-07:00</updated>
        <summary>Sometimes the scariest things are the ones out in plain view. Last week of the quarter is just around the corner. Careful what you reach for, it might bite back. Camera: Nikon D70s Exposure: 0.017 sec (1/60) Aperture: f/5.0 Focal...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Photography" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="cacti" />
        <category scheme="http://sixapart.com/ns/types#tag" term="cactus" />
        <category scheme="http://sixapart.com/ns/types#tag" term="photography" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p><br />Sometimes the scariest things are the ones out in plain view.</p><div style="text-align: center;"><a href="http://www.flickr.com/photos/linecon0/3388296519/" style="display: inline;"><img alt="Prickly" border="0" class="at-xid-6a0111684254e2970c01156e7aa7e6970c " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01156e7aa7e6970c-500pi" title="Prickly" /></a>
 <br /></div><br /><br /><p><br />Last week of the quarter is just around the corner.  <br />Careful what you reach for, it might bite back.</p><p /><p /><p><span style="font-size: 11px; font-family: Verdana;"><strong>Camera:</strong>
						<strong><a href="http://www.flickr.com/cameras/nikon/d70s/">Nikon D70s</a></strong>
					
					
						<strong><br />Exposure:</strong>
						<strong>0.017 sec (1/60)</strong>
					
					
						<strong><br />Aperture:</strong>
						<strong>f/5.0</strong>
					
					
						<strong><br />Focal Length:</strong>
						<strong>55 mm</strong>
<br />					
					
						<strong>Exposure:</strong>
						<strong>0.00</strong>
					
					
						<strong><br />ISO Speed:</strong>
						400
<br />					
					
						<strong>Exposure Bias:</strong>
						0 EV<br /><strong>Flash:</strong>
						No Flash</span></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/Bu3ocvQ9yVo" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/weekend-frame-prickly-bits.html</feedburner:origLink></entry>
    <entry>
        <title>Doing Business With Heartland; Regaining The Trust</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/qzkkNyZsRhc/doing-business-with-heartland-regaining-the-trust.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/doing-business-with-heartland-regaining-the-trust.html" thr:count="1" thr:updated="2009-03-25T17:14:15-07:00" />
        <id>tag:typepad.com,2003:post-64635449</id>
        <published>2009-03-25T15:36:30-07:00</published>
        <updated>2009-03-25T15:36:30-07:00</updated>
        <summary>According to a computerworld article and a statement by Heartland, competitors of the now PCI-delisted payment processor are using the breach as means to lure their customers. Competitors are apparently suggesting that doing business with Heartland will result in fines...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="breach" />
        <category scheme="http://sixapart.com/ns/types#tag" term="business" />
        <category scheme="http://sixapart.com/ns/types#tag" term="credit" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Gartner" />
        <category scheme="http://sixapart.com/ns/types#tag" term="heartland" />
        <category scheme="http://sixapart.com/ns/types#tag" term="information" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI" />
        <category scheme="http://sixapart.com/ns/types#tag" term="risk" />
        <category scheme="http://sixapart.com/ns/types#tag" term="security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>According to a <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9130480&amp;source=rss_topic17" target="_blank">computerworld article</a> and a <a href="http://www.2008breach.com/" target="_blank">statement by Heartland</a>, competitors of the now PCI-delisted payment processor are using the breach as means to lure their customers.  Competitors are apparently suggesting that doing business with Heartland will result in fines from Visa.  That part is not true.  Visa has publicly stated that no fines will be levied against Heartland’s customers.    However, would you continue to trust Heartland, its auditor and the PCI compliance standard to do their jobs in protecting your information?</p><p>Without casting doubt on Heartland, this is a case where past performances may be sings of future returns.  Heartland continues to stay on message that they will be re-certified by May.  It’s also unclear if Trustwave, their prior PCI auditor, will be the ones re-certifying them.  The biggest question of all: when will they come entirely clean with their incident findings and how can they regain our trust?</p><p>In any economy it’s a natural force of doing business to use your competitor’s weaknesses against them.  Despite assurances from Visa and Gartner, you can bet that Heartland’s customers are thinking seriously about switching processors.  If I had any say into what goes on at Heartland, I’d suggest a few moves to help regain customer confidence:</p><ol>
<li>Use a new PCI auditor this time around.  Why use just one, how about two entirely different and independent audit firms.  Not to say that TrustWave didn’t do their job, but take all doubts off the table immediately.</li>
<li>Invest in an automated compliance and audit system.  Being compliant once a year is not compliant at all.  This is particularly the case if you consider the mass volumes of transactions at Heartland – 100 million a month.  Compliance is much like a new car.  Once you drive it off the lot, it depreciates at a rapid rate.  For most computer assets, once they go into production, they will naturally migrate out of compliance.</li>
<li>Provide an honest and complete incident report to the public.  Let the public and the customers decide how the incident was handled and who is best to handle the next breach.  Breaches happen all the time.  What separates the field is 1) how well the company strategically positioned their assets against a breach and 2) how well the breach was handled and 3) how the company moves forward based on what was learned from the breach.</li>
</ol>
<p><br />In the end, lets all hope that this breach will be a learning event for Heartland and all businesses.</p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/qzkkNyZsRhc" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/doing-business-with-heartland-regaining-the-trust.html</feedburner:origLink></entry>
    <entry>
        <title>Weekend Frame - Squares</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/wadHe8CA6Ks/weekend-frame-squares.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/weekend-frame-squares.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64465579</id>
        <published>2009-03-22T08:26:34-07:00</published>
        <updated>2009-03-22T08:27:33-07:00</updated>
        <summary>Sometimes all your corners look squared up. Upon second look, things are not as they seem. Speaking of recursion, on Friday night I attended the LongNow talk with Daniel Everett. "The Pirahã, a remote Amazonian tribe with little outside contact,...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Photography" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="photography" />
        <category scheme="http://sixapart.com/ns/types#tag" term="picture" />
        <category scheme="http://sixapart.com/ns/types#tag" term="recursion" />
        <category scheme="http://sixapart.com/ns/types#tag" term="square" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><div style="text-align: center;"><a href="http://www.flickr.com/photos/linecon0/3345154983/" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="Squares" border="0" class="at-xid-6a0111684254e2970c01156f34ccaa970b " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01156f34ccaa970b-320pi" style="border: 4px solid black; margin: 2px;" title="Squares" /></a></div><p>
 </p><p><br />Sometimes all your corners look squared up.  Upon second look, things are not as they seem.</p><p>Speaking of recursion, on Friday night I attended the <a href="http://longnow.org/">LongNow talk with Daniel Everett.</a> "The Pirahã, a remote Amazonian tribe with little outside contact, have
attracted the attention of mainstream media, scientists, zen buddhists,
professors of religion, mathematicians, philosophers and others because
of their unusual confluence of values, language, and culture."  </p><p /><p>Part of the synopsis by Stewart Brand:</p>



<div style="margin-left: 40px;"><span style="font-size: 12px; font-family: Verdana;">"The Pirahã tribe in the heart of the Amazon numbers only 360,
spread in small groups over 300 miles.  An exceptionally cheerful
people, they live with a focus on immediacy, empiricism, and physical
rigor that has shaped their unique language, claims linguist Daniel
Everett.</span><br /><span style="font-size: 12px; font-family: Verdana;">The Pirahã language has no numbers or concept of counting (only
terms for "relatively small" and "relatively large"); no
kinship terms beyond immediate children and parents; no "left" and
"right" (only "upriver" and "downriver"); no named
distinction of past and future (only near time and far time); no
creation stories or myths; and---most important for linguists---no
recursion.</span><br /><span style="font-size: 12px; font-family: Verdana;">A recursive sentence like "The boy who was fishing owned the
dog" does not occur in the Pirahã language.  They would say,
"The boy was fishing" and "The boy owned the dog."  The
eminent linguist Noam Chomsky has declared that recursion is an
essential part of human language and is innate.  Chomsky's
former student Everett says that the Pirahã language proves
otherwise.  The resultant controversy is profound."</span></div><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/wadHe8CA6Ks" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/weekend-frame-squares.html</feedburner:origLink></entry>
    <entry>
        <title>Another Twitter Breakin? Guy Kawasaki's Twitter Stream Looks Unusual</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/ftSr2sY4pV8/another-twitter-breakin-guy-kawasakis-twitter-stream-looks-unusual.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/another-twitter-breakin-guy-kawasakis-twitter-stream-looks-unusual.html" thr:count="1" thr:updated="2009-03-24T13:05:40-07:00" />
        <id>tag:typepad.com,2003:post-64382695</id>
        <published>2009-03-19T16:12:05-07:00</published>
        <updated>2009-03-19T20:10:07-07:00</updated>
        <summary>For most of today, Twitter seemed to have been sporting the "Fail Whale" of over capacity. However, more interesting was the Guy Kawasaki twitter stream. At about 3pm Pacific, users starting seeing some strange tweets. "How am I in gk's...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="breach" />
        <category scheme="http://sixapart.com/ns/types#tag" term="fail" />
        <category scheme="http://sixapart.com/ns/types#tag" term="guy kawaski" />
        <category scheme="http://sixapart.com/ns/types#tag" term="security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="twitter" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>For most of today, Twitter seemed to have been sporting the "Fail Whale" of over capacity.  However, more interesting was the <a href="http://twitter.com/guykawasaki" target="_blank">Guy Kawasaki twitter stream</a>.  At about 3pm Pacific, users starting seeing some strange tweets.</p><p><a href="http://framesandbits.typepad.com/.a/6a0111684254e2970c011169095fc9970c-popup" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="float: right;"><img alt="Picture 1" class="at-xid-6a0111684254e2970c011169095fc9970c " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c011169095fc9970c-120wi" style="border: 1px solid black; margin: 0px 0px 5px 5px;" title="Picture 1" /></a>
 </p><p>"How am I in gk's account?"<br />"<span class="status-body"><span class="entry-content">I am the all powerful guykawasaki coming to you live via adjix"<br />"</span></span><span class="status-body"><span class="entry-content">wtg @<a href="http://twitter.com/sswayze">sswayze</a> ! you're right #friedchicken is the biz. shouts to @<a href="http://twitter.com/kfc_col">kfc_col</a> , @<a href="http://twitter.com/knownhuman">knownhuman</a>, @<a href="http://twitter.com/froggie775">froggie775</a> and the rest of the #friedchicken crew."<br />"</span></span><span class="status-body"><span class="entry-content"><a href="http://adjix.com/hhk5" rel="nofollow" target="_blank">http://adjix.com/hhk5</a> 

Ad: Free $25 Starbucks Card! <a href="http://is.gd/nK6d" rel="nofollow" target="_blank">http://is.gd/nK6d</a>"<br />"</span></span><span class="status-body"><span class="entry-content">now that I have
your attention, it would be super if you could help us all trend
#friedchicken it's time has come friedchicken.alltop.com"</span></span><br /><span class="status-body"><span class="entry-content"><br />By all regards, something unplanned happened or is happening.  Clicking one of those short URLs takes you to a blog posting by Mack Collier.  Mr Collier even received a comment on his posting, "</span></span>Have you hacked into Guy Kawasaki's Twitter account? If not you,
somebody who likes you has - multiple links to this post today ??"</p><p><span class="status-body"><span class="entry-content">A look at
Guy's twitter page confirmed that the suspicious tweets were from a different twitter
client called "Adjix" whereas his normal tweets historically come from
TweetDeck.<br /><br />Twitter already has a shady history of security issues including an <a href="http://blog.wired.com/27bstroke6/2009/01/professed-twitt.html" target="_blank">administrator account breach back in January</a>.  We will have to wait and see what happens.  Until then, most users are just enjoying the Fail Whale.</span></span>    <span class="status-body"><span class="entry-content" /></span></p><p><strong>UPDATE:</strong></p><p><a href="http://gawker.com/5176022/twitter-hack-briefly-renders-self+promoters-tweets-comprehensible" target="_blank"><a href="http://gawker.com/5176022/twitter-hack-briefly-renders-self+promoters-tweets-comprehensible" target="_blank">According to gawker.com</a>, his account was indeed "hacked" after Kawaski accidentally broadcasted his twitter credentials at Adjix:</a></p><p style="font-size: 12px; font-family: Verdana; margin-left: 40px;">Yes, he told me, when I reached him at an airport, his account had
been hacked, but it was probably his fault. "I was using a new service
called Adjix, and I did something too fast," he told me. "I can't
explain it." Sort of like Twitter.</p>
<p style="font-size: 12px; font-family: Verdana; margin-left: 40px;">Kawasaki then suggested I speculate that he faked the hacking to get
more attention. He added that he loved the hacker's tweets about fried
chicken, and would gladly add it as a topic to his website Alltop.com.
See? Everything on Twitter ends up being about self-promotion.</p>
<p style="font-size: 12px; font-family: Verdana; margin-left: 40px;"><strong />Adjix president Joe Moreno, in an email,
said that Kawasaki mistakenly broadcast his login credentials over the
service, allowing a hacker to take control of his account.</p><p> </p><p><span class="status-body"><span class="entry-content"><em><span style="font-size: 11px; font-family: Verdana;">Original Post: </span></em></span></span><em><span style="font-size: 11px; font-family: Verdana;"><span class="post-footers">March 19, 2009 at 04:12 PM</span></span></em></p><p><em><span style="font-size: 11px; font-family: Verdana;"><span class="post-footers">Edit: March 19, 2009 at 8:00 PM fix a few ty<span style="font-size: 10px; font-family: Verdana;">pos</span></span></span><span style="font-size: 10px; font-family: Verdana;">.  Add info from Gawker.com</span></em><br /><span class="status-body"><span class="entry-content" /></span></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/ftSr2sY4pV8" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/another-twitter-breakin-guy-kawasakis-twitter-stream-looks-unusual.html</feedburner:origLink></entry>
    <entry>
        <title>iPhone OS 3, amazingly boring</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/1At8Q_GkEPg/iphone-os-3-amazingly-boring.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/iphone-os-3-amazingly-boring.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64294365</id>
        <published>2009-03-17T21:00:05-07:00</published>
        <updated>2009-03-17T20:57:27-07:00</updated>
        <summary>Wake me up when the iPhone OS version 3 demo-thing is done. What happens when you release the most disruptive hand held technology? Well, you have to continue to outdo yourself time and time again. Apple’s preview today was a...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Andrew Storms" />
        <category scheme="http://sixapart.com/ns/types#tag" term="apple" />
        <category scheme="http://sixapart.com/ns/types#tag" term="iphone" />
        <category scheme="http://sixapart.com/ns/types#tag" term="risk" />
        <category scheme="http://sixapart.com/ns/types#tag" term="security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>Wake me up when the iPhone OS version 3 demo-thing is done.  What happens when you release the most disruptive hand held technology?  Well, you have to continue to outdo yourself time and time again.  Apple’s preview today was a snooze.  Lets review the biggest new features.</p><p><a href="http://www.flickr.com/photos/linecon0/664650858/" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="float: right;"><img alt="AppleStore" border="0" class="at-xid-6a0111684254e2970c01127973983a28a4 " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01127973983a28a4-320pi" style="border: 3px solid black;" title="AppleStore" /></a>
 <strong>Pushed content</strong><br />This is actually as a result of the iPhone’s inability to run background apps.  Ever notice that when you exit Safari and to go read email, that the website doesn’t keep loading in the background?  Or how IM clients are web based and must be in the foreground.  Apple says that "pushed content" will fix that and provide a new medium for developers.</p><p><strong>In-app purchases</strong><br />You can now purchase content or add-ons from within an application.  Great idea.  "The first one is free."</p><p><strong>P2P blue tooth</strong><br />Great feature in a gaming device, a bit worrisome in an enterprise-level mobile platform.  Just what we need is yet another network-aware vector for attack.  Lets hope they did this one securely.  I can just imagine a new bread of blue tooth sniper rifles at DefCon.</p><p><strong>Copy and Paste</strong><br />Seriously enough, I have to believe that this one did take a while due to security concerns.  With attacks like ClickJacking and untrusted web content, who knows what kind of data is going to be selected and copied into a clipboard.  More than likely, that clipboard is part of the  underlying "off limits" operating system.  This could be new interesting attack vector.  Though, you would think that a feature that goes back to at least the 1980's would be more standard by now.<br /><strong><br />Whats Missing</strong></p><ul>
<li>The platform still lacks enterprise-class policy compliance tools.  The current method for sending out configuration settings is cumbersome and prone to circumvention.</li>
<li>Centralized accounting and auditing are not anywhere to be found.  Want to know how many SMS texts a user sent or who they called or what software is installed?  Accountability tools are missing. </li>
<li>Data on the device is still not encrypted.  This alone will disqualify the device for many enterprises.</li>
<li>What about the historical iPhone attacks that just utilized known bugs in open source software running on the device?  No word today if iPhone OS 3 will be kept up to date any faster to thwart these attacks.</li>
</ul><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/1At8Q_GkEPg" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/iphone-os-3-amazingly-boring.html</feedburner:origLink></entry>
    <entry>
        <title>Recent Press Coverage</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/iU0QAFS01fs/recent-press-coverage.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/recent-press-coverage.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64066283</id>
        <published>2009-03-13T16:10:00-07:00</published>
        <updated>2009-03-13T16:10:00-07:00</updated>
        <summary>A recap of selected articles where I was quoted in recent days. Adobe issues critical PDF reader patch GCN.com - ‎Mar 12, 2009‎ Windows Patch Aimed at Picture-File Vulnerability Sci-Tech Today - ‎Mar 11, 2009‎ Adobe issues fix for zero-day...</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Andrew Storms" />
        <category scheme="http://sixapart.com/ns/types#tag" term="press" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p><img src="http://framesandbits.typepad.com/.a/6a0111684254e2970c01053717122b970b-pi" /><br />A recap of selected articles where I was quoted in recent days.</p><p><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNFzxZPLpq3XT9kgNkorj1tqvt4Ctw sig2-tJvZRO8C_asJu6ZDyS_ifA" href="http://gcn.com/articles/2009/03/12/adobe-patch.aspx" target="_self">Adobe issues critical PDF reader patch</a>
</span>
</p><div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">GCN.com</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Mar 12, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNE2eQ2Css-MUvdJBFyxyNuorn8l-Q sig2-JAYL2DwmXJBeO8o5RIayUA" href="http://www.sci-tech-today.com/news/Patch-Aimed-at-Picture-File-Danger/story.xhtml?story_id=023002KGFT64" target="_self">Windows Patch Aimed at Picture-File Vulnerability</a>
</span>
<div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">Sci-Tech Today</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Mar 11, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNHEoiJan4hZfCP0YLDIKNgzD5XLPQ sig2-JAXprTv0Dm8CEw2768wNOw" href="http://www.zdnetasia.com/news/security/0,39044215,62052085,00.htm" target="_self">Adobe issues fix for zero-day Reader vulnerability</a>
</span>
<div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">ZDNet Asia</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Mar 10, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNEIIavxD1_Gqas4PeWmo_AgOuQnrA sig2-RgJbDJ-58pDnzG_iL-2WXQ" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1350496,00.html" target="_self">Adobe issues patch to block zero-day flaw</a>
</span>
<div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">SearchSecurity.com</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Mar 10, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNE8XYCIDpW9FOn_iUuMgpcOf0XU-Q sig2-8aC2aGBxNtQMnxrIw81weg" href="http://www.scmagazineus.com/Microsoft-patches-for-GDI-DNS-vulnerabilities/article/128579/" target="_self">Microsoft patches for GDI, DNS vulnerabilities</a>
</span>
<div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">SC Magazine US</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Mar 10, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNHJhqFm-Cchk3gBYxchRPS_9rVVZA sig2-oy-mF21a2O55Dvhx_g7yZg" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9129342&amp;intsrc=news_ts_head" target="_self">Microsoft patches 'evil' Windows kernel bug</a>
</span>
<div class="sub-title"><span style="font-size: 12px; font-family: Verdana;">Computerworld</span><span style="font-size: 12px; font-family: Verdana;"> - </span><span style="font-size: 12px; font-family: Verdana;">‎Mar 10, 2009‎<br /><br /></span><span style="font-size: 12px; font-family: Verdana;"><a class="usg-AFQjCNEBJKJP_TrxsBEQq7mm0GUh2McE4g sig2-wEsOEML4z3w2uBhCeaVnnQ" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1350454,00.html" target="_self">Microsoft patches critical Windows kernel flaw</a>
<br /></span>
<span style="font-size: 12px; font-family: Verdana;"><span class="source">SearchSecurity.com</span> - <span class="date">‎Mar 10, 2009‎</span></span><br /></div><br /></div><br /></div><br /></div><br /></div><br /></div><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/iU0QAFS01fs" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/recent-press-coverage.html</feedburner:origLink></entry>
    <entry>
        <title>Adobe Releases Patch on MS Patch Tuesday</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/E59hUweJ59A/adobe-releases-patch-on-ms-patch-tuesday.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/adobe-releases-patch-on-ms-patch-tuesday.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63904315</id>
        <published>2009-03-10T15:12:50-07:00</published>
        <updated>2009-03-10T15:12:50-07:00</updated>
        <summary>As if IT security teams didn't have enough to worry about today, Adobe released a patch for their high profile zero day vulnerability in Adobe reader and Acrobat. Patches for versions 7 and 8 of their software aren't available yet....</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Information Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="0day" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Adobe" />
        <category scheme="http://sixapart.com/ns/types#tag" term="patch" />
        <category scheme="http://sixapart.com/ns/types#tag" term="risk" />
        <category scheme="http://sixapart.com/ns/types#tag" term="security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="update" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>As if IT security teams didn't have enough to worry about today, Adobe released a patch for their high profile zero day vulnerability in Adobe reader and Acrobat.  Patches for versions 7 and 8 of their software aren't available yet.</p><p>The story on this exploit started on Feb. 19th when <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219%20%29" target="_blank">ShadowServer</a><span style="font-family: Verdana;"> posted information on a "0-date on the loose"</span> and referenced a Symantec AV update from February 12th, indicating that the attack had already been in the wild.</p><p>Adding to today's confusion, <a href="http://www.us-cert.gov/current/index.html#adobe_reader_and_acrobat_vulnerability" target="_blank">US-CERT is now recognizing new attack vectors for the Adobe JBIG2 vulnerability</a>.<br />
<br />Throughout this entire process Adobe <a href="http://framesandbits.typepad.com/frames_and_bits/2009/02/adobe-might-be-listening.html">has been slow to communicate and provide</a><br /><span style="font-family: Verdana;">useful information for security managers</span>.  Even with the onslaught of  critical press and jabs from the security community, Adobe was late to acknowledge the vulnerability and later yet in releasing remediation steps.</p><p>Initially they promised a patch by March 11th, so most security teams have been holding their breath and sitting with white knuckles over the last few weeks while the bug received more attention.</p><p>Other teams started migration to the alternative, FoxIt.  In a moment of irony, <a href="http://www.foxitsoftware.com/pdf/reader/security.htm" target="_blank">FoxIt was </a><br /><span style="font-family: Verdana;">also found to be vulnerable to same bug.</span></p><p>I joked just this morning that all I needed to ruin my day was for Adobe to release their patch.</p><p>Having the patch early is a huge benefit, but releasing it on the same day as Microsoft's planned March patch spells disaster for enterprise resource planning, and it still leaves Adobe with a black eye for lack of communication.</p><p /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/E59hUweJ59A" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/adobe-releases-patch-on-ms-patch-tuesday.html</feedburner:origLink></entry>
    <entry>
        <title>Weekend Frame - Yosemite</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/FramesAndBits-TheAndrewStormsBlog/~3/n-U0fSnrIwU/weekend-frame-yosemite.html" />
        <link rel="replies" type="text/html" href="http://framesandbits.typepad.com/frames_and_bits/2009/03/weekend-frame-yosemite.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63815799</id>
        <published>2009-03-08T20:33:06-07:00</published>
        <updated>2009-03-08T20:33:06-07:00</updated>
        <summary>Just got back from Yosemite. Here is a frame from my blackberry camera. This week is going to be busy. Monday: Internal security training Tuesday: Microsoft reboot Wednesday: Expected Adobe reader patch for the 0day issue.</summary>
        <author>
            <name>Andrew Storms</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Photography" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Adobe" />
        <category scheme="http://sixapart.com/ns/types#tag" term="microsoft" />
        <category scheme="http://sixapart.com/ns/types#tag" term="picture" />
        <category scheme="http://sixapart.com/ns/types#tag" term="yosemite" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://framesandbits.typepad.com/frames_and_bits/"><div xmlns="http://www.w3.org/1999/xhtml"><p>Just got back from Yosemite.  Here is a frame from my blackberry camera.</p><p><br /><a href="http://www.flickr.com/photos/linecon0/3333752355/" style="display: inline;"><img alt="Valley_sunset" border="0" class="at-xid-6a0111684254e2970c011168cd0851970c image-full " src="http://framesandbits.typepad.com/.a/6a0111684254e2970c011168cd0851970c-800wi" style="border: 4px solid black;" title="Valley_sunset" /></a>
 </p><br /><p><br />This week is going to be busy.<br />Monday: Internal security training<br />Tuesday: Microsoft reboot<br />Wednesday: <a href="http://framesandbits.typepad.com/frames_and_bits/2009/02/adobe-might-be-listening.html">Expected Adobe reader patch for the 0day issue.</a></p><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/FramesAndBits-TheAndrewStormsBlog/~4/n-U0fSnrIwU" height="1" width="1" /></div></content>



    <feedburner:origLink>http://framesandbits.typepad.com/frames_and_bits/2009/03/weekend-frame-yosemite.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 -->

