<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Part Time Security Guy</title>
	<atom:link href="http://parttimesecurityguy.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://parttimesecurityguy.wordpress.com</link>
	<description>Learning Secure Development And The Tribulations On Spreading The Word</description>
	<lastBuildDate>Wed, 27 Apr 2011 13:25:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='parttimesecurityguy.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Part Time Security Guy</title>
		<link>http://parttimesecurityguy.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://parttimesecurityguy.wordpress.com/osd.xml" title="Part Time Security Guy" />
	<atom:link rel='hub' href='http://parttimesecurityguy.wordpress.com/?pushpress=hub'/>
		<item>
		<title>How Much Security Do You Expect For Free</title>
		<link>http://parttimesecurityguy.wordpress.com/2011/04/27/how-much-security-do-you-expect-for-free/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2011/04/27/how-much-security-do-you-expect-for-free/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 13:19:59 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Gaming]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[PSN]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://parttimesecurityguy.wordpress.com/2011/04/27/how-much-security-do-you-expect-for-free/</guid>
		<description><![CDATA[http://www.bbc.co.uk/news/technology-13192359 There is a parallel with our industry, which I will get to eventually. Some of you may be aware that the Playstation network, which is Sony&#8217;s answer to Xbox Live in that it is a free multiplayer gaming service and media provider (unlike Xbox Live online play requires a subscription). So given that Sony [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=25&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.bbc.co.uk/news/technology-13192359">http://www.bbc.co.uk/news/technology-13192359</a></p>
<p>There is a parallel with our industry, which I will get to eventually. Some of you may be aware that the Playstation network, which is Sony&#8217;s answer to Xbox Live in that it is a free multiplayer gaming service and media provider (unlike Xbox Live online play requires a subscription). So given that Sony are not paid to support the service, and upgrade/development costs are funded by Sony themselves. Until the incident occurred what incentive did they have to ensure the security of the system and the data that it held.</p>
<p>This is the same issue facing control system users and vendors. Control system users will nearly always prioritise features over security. Also the vendor will not directly be impacted by any breach of a control system(our networks just fine thankyouverymuch). So where is the vendors incentive, and where is the users incentive. Apart from Stuxnet there is little real hard and fast incident metrics that can be used to determine any ROI on security. And you can even argue that Stuxnet was a targeted attack that did not impact a large majority of the control systems in the world.</p>
<p>So what&#8217;s the next step, vendors to keep providing &#8220;security for free&#8221; For the vendors to make a concerted effort to shore up their software, or for the customers to realise that control system security is an issue that we all share?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=25&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2011/04/27/how-much-security-do-you-expect-for-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>Turning the world Amish one presentation at a time</title>
		<link>http://parttimesecurityguy.wordpress.com/2010/03/05/turning-the-world-amish-one-presentation-at-a-time/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2010/03/05/turning-the-world-amish-one-presentation-at-a-time/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 10:31:00 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Presenting]]></category>
		<category><![CDATA[Smart Grid]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/2010/03/05/turning-the-world-amish-one-presentation-at-a-time/</guid>
		<description><![CDATA[This presentation was shown to the OWASP Scotland chapter… seemed to go down well, I certainly enjoyed it, even if I had heard the jokes before.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=24&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://prezi.com/9vofnzgzqxwe/the-industrial-owners-manual/">presentation</a> was shown to the OWASP Scotland chapter… seemed to go down well, I certainly enjoyed it, even if I had heard the jokes before.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=24&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2010/03/05/turning-the-world-amish-one-presentation-at-a-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>Sony Experience in Applying the Microsoft SDL</title>
		<link>http://parttimesecurityguy.wordpress.com/2010/03/02/sony-experience-in-applying-the-microsoft-sdl/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2010/03/02/sony-experience-in-applying-the-microsoft-sdl/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 11:51:00 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Process]]></category>
		<category><![CDATA[SDL]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/2010/03/02/sony-experience-in-applying-the-microsoft-sdl/</guid>
		<description><![CDATA[The following link is a case study in applying Microsoft Secure Development Lifecycle to a Sony development centre over an 18 month, 3 phase project. The goals of the project were: 1) Ensure that the development centre produced high quality applications meeting or exceeding industry standards for quality and security 2) Enable the development team [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=22&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The following <a href="http://www.securityinnovation.com/pdf/sony-si-sdl-case-study.pdf">link</a> is a case study in applying Microsoft Secure Development Lifecycle to a Sony development centre over an 18 month, 3 phase project.</p>
<p>The goals of the project were:</p>
<p>1) Ensure that the development centre produced high quality applications meeting or exceeding industry standards for quality and security</p>
<p>2) Enable the development team to become more self-reliant on its own security expertise within the 18 months</p>
<p>At the conclusion of the project teh development team had moved themselves up to the Standardised level, and already including some advanced and dynamic activities.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=22&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2010/03/02/sony-experience-in-applying-the-microsoft-sdl/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>Award Winning News Title</title>
		<link>http://parttimesecurityguy.wordpress.com/2009/03/22/award-winning-news-title/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2009/03/22/award-winning-news-title/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 12:00:59 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Smart Grid]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/2009/03/22/award-winning-news-title/</guid>
		<description><![CDATA[Winning the award for stating the bleeding obvious that is: http://edition.cnn.com/2009/TECH/03/20/smartgrid.vulnerability/ Don’t panic I’m hoping that this is not a one off and I get back into posting again<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=19&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Winning the award for stating the bleeding obvious that is:<br />
<a href="http://edition.cnn.com/2009/TECH/03/20/smartgrid.vulnerability/">http://edition.cnn.com/2009/TECH/03/20/smartgrid.vulnerability/</a></p>
<p>Don’t panic I’m hoping that this is not a one off and I get back into posting again</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=19&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2009/03/22/award-winning-news-title/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>Training, training and more training</title>
		<link>http://parttimesecurityguy.wordpress.com/2008/05/21/training-training-and-more-training/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2008/05/21/training-training-and-more-training/#comments</comments>
		<pubDate>Wed, 21 May 2008 20:48:52 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Training]]></category>
		<category><![CDATA[Presenting]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/?p=18</guid>
		<description><![CDATA[Well last weeks training went well, both sessions got a fair crowd, and sensible questions were asked, so it&#8217;s a step in the right direction. As per usual, nerves got the better of me for the first presentation and I rattled through the slides at a rate of knots. The second one went much smoother. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=18&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well last weeks training went well, both sessions got a fair crowd, and sensible questions were asked, so it&#8217;s a step in the right direction.  </p>
<p>As per usual, nerves got the better of me for the first presentation and I rattled through the slides at a rate of knots.  The second one went much smoother. </p>
<p>It was interesting to guage peoples reactions during and after the sessions, one of the common points that came out was that they had not really thought of coding securely and how a simple crash could be so much more.</p>
<p>So having presented an overview of the new coding standards, we have sent them out to, hopefully, be read and understood, failing that I&#8217;m working on a more details training session that should bring people up to speed.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/parttimesecurityguy.wordpress.com/18/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/parttimesecurityguy.wordpress.com/18/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=18&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2008/05/21/training-training-and-more-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>This Weeks Link</title>
		<link>http://parttimesecurityguy.wordpress.com/2008/05/21/this-weeks-link/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2008/05/21/this-weeks-link/#comments</comments>
		<pubDate>Wed, 21 May 2008 20:34:11 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/?p=17</guid>
		<description><![CDATA[Only the one thing caught my eye this week: Oracles asking for secure training at uni<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=17&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Only the one thing caught my eye this week:</p>
<ul>
<li><a href="http://www.dwheeler.com/blog/2008/05/15/">Oracles asking for secure training at uni</a></li>
</ul>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/parttimesecurityguy.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/parttimesecurityguy.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=17&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2008/05/21/this-weeks-link/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>This Weeks Links</title>
		<link>http://parttimesecurityguy.wordpress.com/2008/05/11/this-weeks-links/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2008/05/11/this-weeks-links/#comments</comments>
		<pubDate>Sun, 11 May 2008 21:08:58 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/?p=16</guid>
		<description><![CDATA[More things that have caught my eye Static code analysis failures Spot the overflow a torrent of trojans made simple Poking holes in databases for fun and profit measuring secure<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=16&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>More things that have caught my eye</p>
<ul>
<li><a href="http://portal.spidynamics.com/blogs/rafal/archive/2008/05/06/Static-Code-Analysis-Failures.aspx">Static code analysis failures</a></li>
<li><a href="http://www.digitalbond.com/index.php/2008/05/02/spot-the-overflow/">Spot the overflow</a></li>
<li><a href="http://www.0x000000.com/?i=564">a torrent of trojans made simple</a></li>
<li><a href="http://www.darkreading.com/document.asp?doc_id=153291&amp;f_src=darkreading_sitedefault">Poking holes in databases for fun and profit</a></li>
<li><a href="http://blogs.msdn.com/sdl/archive/2008/05/08/how-secure-is-secure.aspx">measuring secure</a></li>
</ul>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/parttimesecurityguy.wordpress.com/16/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/parttimesecurityguy.wordpress.com/16/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=16&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2008/05/11/this-weeks-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>Enjoy this, it&#8217;s the only training you&#8217;re getting</title>
		<link>http://parttimesecurityguy.wordpress.com/2008/05/10/enjoy-this-its-the-only-training-youre-getting/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2008/05/10/enjoy-this-its-the-only-training-youre-getting/#comments</comments>
		<pubDate>Sat, 10 May 2008 15:39:18 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/?p=15</guid>
		<description><![CDATA[And unfortunately (for me) I&#8217;ll be the one doing the training. Having spent the last couple of months producing our secure coding guidelines, it is now time to roll it out to all the developers. So I&#8217;ve become a powerpoint wiz again and put some slide together, going through the main points of the guidelines. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=15&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>And unfortunately (for me) I&#8217;ll be the one doing the training.  Having spent the last couple of months producing our secure coding guidelines, it is now time to roll it out to all the developers.</p>
<p>So I&#8217;ve become a powerpoint wiz again and put some slide together, going through the main points of the guidelines.  To ensure buy in (I hope) I&#8217;ve tried to emphasize the quality aspects of secure coding, in that a securely written program will be a high quality one.</p>
<p>You may get people saying &#8220;this secure coding malarky, just a load of shit isn&#8217;t it&#8221;, it&#8217;s harder to say the same about quality coding because then you shouldn`t be developing code in the first place if you do not care about quality.</p>
<p>The other aspect of this is, given that there is little in the way of &#8220;secure&#8221; thinking, why focus on coding guidelines first.  Well for a number of reasons, firstly I&#8217;m a developer it is what I understand, secondly one of my many &#8216;hats&#8217; is that I am the ISO department rep for software development, so I already manage the coding guidelines, so fitting another one in is quite straightforward.</p>
<p>Finally a number of studies, both open source and from the likes of Microsoft show that over 50% of all security vulnerabilities are caused by software bugs rather that design defects.</p>
<p>As I am &#8220;part time&#8221; there is only so much I can do, so why not tackle the low hanging fruit, with potentially quite a big benefit.</p>
<p>As it happens we have thought a little about requirements and design, but nothing formal, but what we have will be mentioned as we have invited our architects (design) and business analysts (requirements) to the training.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/parttimesecurityguy.wordpress.com/15/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/parttimesecurityguy.wordpress.com/15/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=15&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2008/05/10/enjoy-this-its-the-only-training-youre-getting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>This Weeks Linkage</title>
		<link>http://parttimesecurityguy.wordpress.com/2008/05/04/this-weeks-linkage/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2008/05/04/this-weeks-linkage/#comments</comments>
		<pubDate>Sun, 04 May 2008 12:24:20 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[Compiler]]></category>
		<category><![CDATA[Reverse engineering]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/?p=14</guid>
		<description><![CDATA[Things that have caught my eye this week: reverse engineering firmware All my hard work writing coding guidelines scuppered by the compiler<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=14&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Things that have caught my eye this week:</p>
<ul>
<li><a href="http://www.matasano.com/log/1047/toast-spells-tsaot-in-reverse/">reverse engineering firmware</a></li>
<li><a href="http://lwn.net/Articles/278137/">All my hard work writing coding guidelines scuppered by the compiler</a></li>
</ul>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/parttimesecurityguy.wordpress.com/14/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/parttimesecurityguy.wordpress.com/14/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=14&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2008/05/04/this-weeks-linkage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
		<item>
		<title>Scoring vulnerabilities</title>
		<link>http://parttimesecurityguy.wordpress.com/2008/05/02/scoring-vulnerabilities/</link>
		<comments>http://parttimesecurityguy.wordpress.com/2008/05/02/scoring-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 May 2008 22:42:50 +0000</pubDate>
		<dc:creator>cc</dc:creator>
				<category><![CDATA[Process]]></category>
		<category><![CDATA[DREAD]]></category>
		<category><![CDATA[STRIDE]]></category>

		<guid isPermaLink="false">http://parttimesecurityguy.wordpress.com/?p=13</guid>
		<description><![CDATA[As we are only really starting out thinking about security, one of the things that we are looking at is how to determin the severity and priority or reported vulnerabilities. We have a process for dealing with existing bugs, but given that the bug review team has no experience in review security issues, so something [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=13&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As we are only really starting out thinking about security, one of the things that we are looking at is how to determin the severity and priority or reported vulnerabilities.</p>
<p>We have a process for dealing with existing bugs, but given that the bug review team has no experience in review security issues, so something a little more thorough that a finger in the air is needed.</p>
<p>I had done some poking around our software and had logged about half a dozen issues and the security team decided that we should start to score them.  We looked around and decided to focus on the Microsoft <a href="http://blogs.msdn.com/sdl/archive/2007/09/11/stride-chart.aspx" target="_top">STRIDE</a> and <a href="http://blogs.msdn.com/david_leblanc/archive/2007/08/13/dreadful.aspx" target="_top">DREAD</a> models to describe and categorise them.</p>
<p>So 4 of us sat down and individually scored, them and realised that whilst we scored them differently, we picked the same ones as our highest priority.</p>
<p>What we learned as part of the process, is we had to determine what a Damage of 1 or 5 meant to our software.  So we went through and added examples of what a 5 damage meant compared to a 1 or a 3.  We also noted factors that would affect the score.  for example discoverability was simplistically scored and the level of knowledge required, so that if joe bloggs could find it, then it scored 5.  but this could be impacted by the time needed to discover something.</p>
<p>There was discussion about the point of view of the attacker.  It was simpler to assume that the damage, reproducability and affected users should assume that the vulnerability was about to be exploited.</p>
<p>Exploitability and discoverability dealt with the difficulty in getting to that stage in the first place.</p>
<p>With all that slowly getting in place, we now have the basis for a reliable scoring method that should help us prioritise our fixes when vulnerabilities are reported.  Now we have to work on the rest of the process.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/parttimesecurityguy.wordpress.com/13/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/parttimesecurityguy.wordpress.com/13/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/parttimesecurityguy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/parttimesecurityguy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/parttimesecurityguy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/parttimesecurityguy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/parttimesecurityguy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/parttimesecurityguy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/parttimesecurityguy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/parttimesecurityguy.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=parttimesecurityguy.wordpress.com&amp;blog=3563544&amp;post=13&amp;subd=parttimesecurityguy&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://parttimesecurityguy.wordpress.com/2008/05/02/scoring-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c646705e259ef203b3554eb9c7247cb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cc</media:title>
		</media:content>
	</item>
	</channel>
</rss>
