http://www.rsa.com/blog/rssfeed.aspx Speaking of Security, the RSA Blog and Podcast http://www.rsa.com/blog/ Speaking of Security is the RSA Blog and Podcast. It features a group of experts in identity management, encryption, privacy, policy, and enterprise security standards. Security http://www.rsa/blog/images/small_blog_logo.gif http://www.rsa.com/blog/ 144 36 Speaking of Security A Podcast for Security Professionals A weekly look at RSA's – and the industry's – issues-of-the-moment. RSA, The Security Division of EMC en-us no RSA, The Security Division of EMC podcast@rsa.com Copyright 2005 - 2008 RSA Security Inc. Big Steps Toward Managing Security and Compliance for Virtual Infrastructureblog@rsa.com (Steve Schlarman)http://www.rsa.com/blog/blog_entry.aspx?id=1704Wed, 01 Sep 2010 00:00:00 GMTblog@rsa.com (Steve Schlarman)http://www.rsa.com/blog/blog_entry.aspx?id=1704This week, the industry celebrates one of the most influential and explosive technologies influencing the world of information systems: Virtualization. At <a href="http://www.vmworld.com/community/conferences/2010/" target="_blank">VMWorld 2010</a>, the focus on virtualization across the enterprise and cloud computing highlights some of the most interesting and impactful technologies that our industry is utilizing. We have had...Speaking of Security Podcast #197blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1703Wed, 01 Sep 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1703<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1703">Click to Download/Listen</a> <br> <br> This week's Speaking of Security podcast features an interesting discussion with Ira Winkler, a well-known expert on internet security and information-related crime investigation. <br><br>The Cloud has a Silver Liningblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1702Mon, 30 Aug 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1702Talking with customers every day, I hear constant concerns about lack of visibility into (and control over) security and compliance in the virtual infrastructure, lack of guidance and orchestration tools and the high cost and difficulty of meeting audits and achieving compliance.Popularity of automated stores in the black market increase as source code is traded in "kits"blog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1701Thu, 26 Aug 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1701In my<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1695" target="_blank"> last post</a>, I discussed the trend of automated credit card stores proliferating in the fraudster underground. In addition to the reasons I listed...Speaking of Security Podcast #196blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1699Wed, 18 Aug 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1699<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1699">Click to Download/Listen</a> <br> <br> This week's Speaking of Security podcast discusses the upcoming RSA Archer eGRC Road Show. We also debut the Speaking of Security Newswire, featuring the latest security and technology headlines. <br><br>Only You Can Prevent (Internet) Forest Fires: driving online safety and security homeblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1700Wed, 18 Aug 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1700There's an important Messaging Convention around <a href="http://www.staysafeonline.org/blog/online-safety-personal-priority-americans" target="_blank">online consumer safety and security</a> that wrapped up this month, put on by the <a href="http://www.staysafeonline.org" target="_blank">National Cyber Security Alliance</a> (NCSA), <a href="http://www.antiphishing.org/" target="_blank">Anti-Phishing Working Group</a> (APWG) and member organizations including RSA around communicating the central role of people in protecting themselves and, frankly...Nation States and Mobile Devices: It's Time to Listenblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1698Fri, 13 Aug 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1698The motivations, instincts and needs of Nation States, regardless of rhetoric, are largely the same for <a href="http://en.wikipedia.org/wiki/Akkadia" target="_blank">Akkadia</a>, <a href="http://en.wikipedia.org/wiki/Sumer" target="_blank">Sumeria</a>, <a href="http://en.wikipedia.org/wiki/Roman_Empire" target="_blank">Rome</a> and ancient <a href="http://en.wikipedia.org/wiki/Judea" target="_blank">Judea</a> as they are for the modern <a href="http://en.wikipedia.org/wiki/USA" target="_blank">USA</a>, <a href="http://en.wikipedia.org/wiki/China" target="_blank">China</a> or <a href="http://en.wikipedia.org/wiki/Europe" target="_blank">European</a> state. The theaters in which nations can act and the tools and trade-offs among tactics are very different, and this has come to light recently with some activity and demands around features and requests for mobile endpoints. Payment Security Insight from the Verizon 2010 Data Breach Investigations Reportblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1697Fri, 13 Aug 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1697This week, Verizon released their <a href="http://www.verizonbusiness.com/resources/reports/rp_2010-DBIR-combined-reports_en_xg.pdf" target="_blank">2010 Data Breach Investigations Report</a>. The report is a treasure trove of statistics that illuminate all facets of what&rsquo;s happening in recent compromises. I wanted to focus on the insight around the current state of payment card data breaches, which continue to make up a majority of the breaches (54%) that Verizon&rsquo;s RISK team investigates and writes about.Speaking of Security Podcast #195blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1696Wed, 11 Aug 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1696<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1696">Click to Download/Listen</a> <br> <br> The dog days of summer mean a chance to reflect on some hot industry topics with Sam Curry, Chief Technologist for RSA. <br><br>Automated Credit Card Stores and the Business of Trading in the Fraud Undergroundblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1695Wed, 11 Aug 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1695Innovation and evolution are two words that are not hard to find in blog posts and news articles about fraud. It seems that almost every day security researchers uncover new features and improvements in fraudsters&rsquo; tools and infrastructure. Many of these innovations stem from the availability of new services in the underground.A choice of wordsblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1693Fri, 06 Aug 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1693Language is important. It is the manner in which we communicate intent and meaning to each other. Thus our choice of words is important, because words have specific meanings. That is an obvious statement, but one that is frequently forgotten. All too often, we use...Speaking of Security Podcast #194blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1692Wed, 04 Aug 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1692<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1692">Click to Download/Listen</a> <br> <br /> RSA Conference Europe is fast approaching. This week's Speaking of Security podcast checks in on what to expect at this year's event. <br><br>The Wave of Coolblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1691Wed, 04 Aug 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1691What do the <a href="http://en.wikipedia.org/wiki/IPad" target="_blank">iPad</a>, <a href="http://en.wikipedia.org/wiki/Cabbage_Patch_Kids" target="_blank">Cabbage</a> Patches, <a href="http://en.wikipedia.org/wiki/Converse_Shoes" target="_blank">Converse</a> and <a href="http://en.wikipedia.org/wiki/The_Matrix" target="_blank">The Matrix</a> have in common? Well, to answer that we need to look at drivers for a moment, and I don't mean machine drivers and technology&hellip;I mean people drivers. Let's look at their urges, needs and wants.Social Trojaningblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1689Wed, 28 Jul 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1689I went to my favorite fraud underground forum, bought my favorite Trojan kit (I like Zeus), and then I looked through the Build-a-Trojan checklist for next steps.Fraudsters enjoy a summer holidayblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1688Tue, 27 Jul 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1688It&rsquo;s now <a href="http://www.astrobio.net/pressrelease/3459/summer-on-triton" target="_blank">summer</a> on Triton. <br> <br> Don&rsquo;t pack your holiday gear though; the average temperature on Neptune&rsquo;s major moon, which is about 30 times further from the sun than Earth, is...Looking at Visa's Tokenization Best Practicesblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1687Fri, 23 Jul 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1687Last week, Visa issued their initial guidance on <a href="http://usa.visa.com/download/merchants/tokenization_best_practices.pdf" target="_blank">tokenization</a> best practices. Overall, I think Visa presented a good start for the industry. Several <a href="http://securosis.com/blog/comments-on-visas-tokenization-best-practices/" target="_blank">other</a> <a href="http://www.akamai.com/html/misc/security_blog.html" target="_blank">bloggers</a> seem to agree. However, I do have a bone or two to pick with what they propose.Revolutionary Fever: Humanity will win the battle, and Liberty will have a network*blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1686Thu, 22 Jul 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1686The pace of life continues to accelerate and become more-and-more distracting, and today RSA announced the <a href="http://www.rsa.com/node.aspx?id=3001" target="_blank">latest SBIC report</a> and new research results from IDG Research Services. The <a href="http://www.rsa.com/node.aspx?id=3001" target="_blank">IDG data</a> and SBIC report on the clash, the conflict really, between technologies in our lives bleeding into...Cybercriminals Now Using Public Social Networks to Give Command and Control Orders to Banking Trojansblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1684Mon, 19 Jul 2010 00:00:00 GMTblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1684While malware updating via public resources is nothing new in itself, the RSA FraudAction Research Lab recently witnessed this hosting method being used to operate a <em>banking</em> Trojan; specifically a variant of...Call it What You Want: But it is Still the Black Marketblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1683Thu, 15 Jul 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1683Unless you accidentally wandered here while searching for the Road Safety Authority, you&rsquo;ve most likely been introduced with the &ldquo;fraudster underground&rdquo; or &ldquo;<a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=10414" target="_blank">underground economy</a>.&rdquo; A lot has been written about the criminal bowels of the Internet, either in...Helping the merchantblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1679Tue, 13 Jul 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1679I recently found myself in a conversation with the head of operations for a large, multinational retailer and we were discussing PCI. I made an observation that goes something like this...Paul the Octopus - He's done it again!blog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1681Tue, 13 Jul 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1681You&rsquo;ve got to love <a href="http://www.telegraph.co.uk/sport/football/world-cup-2010/7884509/World-Cup-final-100-per-cent-for-Paul-the-psychic-octopus.html">Paul the Octopus</a>. To those of you living across the pond and not following football (soccer) news, that&rsquo;s the cute octopus-turned-oracle that managed to predict each and every game Germany played in the World Cup, and foresaw that Spain would beat the Netherlands in the finals."You're gonna need a bigger boat"blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1678Tue, 13 Jul 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1678Have you ever felt like Sheriff Brody in the movie 'Jaws' when he finally saw the shark they were hunting and realized that it was a 25' 3-ton great white? If you've ever talked to someone in the IT security business right after they've experienced a major data breach what you'll generally hear them say is something to the effect of...Speaking of Security Podcast #193blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1680Tue, 13 Jul 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1680<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1680">Click to Download/Listen</a> <br> <br /> A discussion on the current cyber security legislative landscape direct from Washington, DC on this week's Speaking of Security podcast. <br><br>The Root Cause of Advanced Persistent Threatsblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1682Tue, 13 Jul 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1682The term &quot;<a href="http://en.wikipedia.org/wiki/Advanced_Persistent_Threat" target="_blank">Advanced Persistent Threat</a>&quot; (or APT) has been around for a long time in the non-computer world and for a decent amount of time in the computer world behind closed doors; but as I watch the use of certain words and phrases, APT is on the ascendancy.PCI Doesn't Take Vacationsblog@rsa.com (Branden Williams)http://www.rsa.com/blog/blog_entry.aspx?id=1675Fri, 09 Jul 2010 00:00:00 GMTblog@rsa.com (Branden Williams)http://www.rsa.com/blog/blog_entry.aspx?id=1675I was lucky enough to spend some quality time away from the tubes last week, and while I am not part of a rogue PCI enforcement militia, I do tend to observe how organizations tackle security and compliance issues. For the first time, I found a rather unique disclaimer that was mere feet away from the Point of Interaction. It shocked me so much, I snapped a picture to make sure I got the wording correct. It plainly stated...Physical to Virtual Disaster Recovery Planning: Considerations for the Cloudblog@rsa.com (Steve Suther)http://www.rsa.com/blog/blog_entry.aspx?id=1677Thu, 08 Jul 2010 00:00:00 GMTblog@rsa.com (Steve Suther)http://www.rsa.com/blog/blog_entry.aspx?id=1677How's your disaster recovery planning these days? <br><br> If you&rsquo;re reading this, it&rsquo;s pretty safe to assume that either you or someone in your organization is &ldquo;tuned in&rdquo; enough to have well documented DR plans that enable your company's business operations to continue...VLANs and Segmentationblog@rsa.com (Branden Williams)http://www.rsa.com/blog/blog_entry.aspx?id=1674Thu, 08 Jul 2010 00:00:00 GMTblog@rsa.com (Branden Williams)http://www.rsa.com/blog/blog_entry.aspx?id=1674I was following an email trail from a few colleagues and it dawned on me that I had not written about the use of VLANs with respect to PCI in this blog. If you purchased <a href="https://www.brandenwilliams.com/media/" target="_blank">Anton &amp; my book</a>, you can get...The "Should" Rule of Cloud Computingblog@rsa.com (Branden Williams)http://www.rsa.com/blog/blog_entry.aspx?id=1673Tue, 06 Jul 2010 00:00:00 GMTblog@rsa.com (Branden Williams)http://www.rsa.com/blog/blog_entry.aspx?id=1673I&rsquo;ve been asked over the last few months quite a bit about virtualization and cloud computing. Virtualization is something most people understand, but cloud computing baffles many professionals because there is often not a clear nomenclature used to describe products and services in the space<a href="https://www.brandenwilliams.com/blog/2010/06/24/the-should-rule-of-cloud-computing/#footnote_0_1958" title="I just saw an ad for a &ldquo;Dynamic Cloud Server.&rdquo; For real." target="_blank"><sup>1</sup></a>.Governance: The Big Problemblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1676Tue, 06 Jul 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1676I alluded to this a few weeks ago in <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1664" target="_blank">Xanadu</a>, but I got to thinking about the subject and realized it deserves a little more exploration and discussion. I mentioned an almost mythical &quot;hunter-gatherer&quot; society and the potential to...Card Checking is Still a Booming Businessblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1671Fri, 02 Jul 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1671For those who commit it, fraud is similar to a game of chess. You can&rsquo;t reach a check-mate if you haven&rsquo;t aligned all your pieces appropriately before making your big move. If you&rsquo;re trying to defraud a bank through the online channel, you first need...Are You a GRC Saboteur?blog@rsa.com (Steve Schlarman)http://www.rsa.com/blog/blog_entry.aspx?id=1672Thu, 01 Jul 2010 00:00:00 GMTblog@rsa.com (Steve Schlarman)http://www.rsa.com/blog/blog_entry.aspx?id=1672We all have our own little secret hobbies that we use to escape from the craziness of our everyday life. Spend any time with someone, and most likely you will learn about their pets, their thimble collection, their penchant for...Tokens and Standardsblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1670Wed, 30 Jun 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1670In <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1657" target="_blank">my last post</a>, I discussed the interesting situation that the PCI council finds itself in, where they are in the process of providing guidance on use of a technology...Speaking of Security Podcast #192blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1668Mon, 28 Jun 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1668<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1668">Click to Download/Listen</a> <br> <br /> David Kirkpatrick, author of the new book, "<em>The Facebook Effect: The Inside Story of the Company that is Connecting the World</em>" is the guest on a special edition of the Speaking of Security podcast. <br><br>Not Another Agent!blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1669Mon, 28 Jun 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1669One of the most important principles in the security industry, and something that we are embracing wholeheartedly at RSA is to <em>build in</em> security rather than <em>bolt on</em> agents, protocols and capabilities as an afterthought. A good example of this is the <a href="http://www.rsa.com/press_release.aspx?id=10992" target="_blank">recently announced relationship</a> between...Good Times in Fraudland: Part IIblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1667Thu, 24 Jun 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1667In my <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1643" target="_blank">first</a> of three entries summarizing 2009 online fraud trends, I suggested that there had never been a better time to be a cybercriminal, and talked about the high grade Trojans currently available to fraudsters. But to use a modern warfare analogy...Xanadu: the new landscape of the payment card industryblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1664Tue, 22 Jun 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1664<u>Sea change</u>, <u>paradigm shift</u> and <u>disruptive technologies</u> are all phrases used to describe things that revolutionize society or part of society. They are often marked by...Speaking of Security Podcast #191blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1662Tue, 22 Jun 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1662<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1662">Click to Download/Listen</a> <br> <br /> A new Security Brief produced by RSA explains how advanced security technologies and emerging outsourced services can relieve merchants of the growing burden of storing electronic payment card information. Hear more on the Speaking of Security podcast. <br><br>And your total is...blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1665Mon, 21 Jun 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1665Twice in the last 2 months I've been privileged to present a session on security considerations for cloud computing at different industry events. In both instances there were plenty of questions and lots of detailed follow-up discussions. I got to sit down with...Surprising surge of Phishing on nationwide banksblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1666Mon, 21 Jun 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1666In the last couple of months the RSA Anti Fraud Command Center witnessed a dramatic surge of Phishing on nationwide US banks. <br> <br> Ever since the good old days of the initial Phishing attacks in 2003-2004, the share of national banks &ndash; those that span across the entire US &ndash; has been declining, as the major banks implemented effective remedies against Phishing and the public became more aware of attacks where the fraudster posed as a major national bank. The heat moved to smaller targets: regional banks and small credit unions. What is the Air Speed Velocity of an Unladen Swallow?blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1663Fri, 18 Jun 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1663I've previously written about asking the right questions, and I've had discussions about that issue with several customers. Originally I focused on asking about risk vs. compliance, with compliance being just another risk factor..."Red Flags" Compliance Deadline Extended...Again! blog@rsa.com (Steve Suther)http://www.rsa.com/blog/blog_entry.aspx?id=1661Fri, 18 Jun 2010 00:00:00 GMTblog@rsa.com (Steve Suther)http://www.rsa.com/blog/blog_entry.aspx?id=1661On May 28, 2010, <a href="http://www.ftc.gov/opa/2010/05/redflags.shtm" target="_blank">the FTC announced</a> that it would again delay enforcement of the Identity Theft Red Flags Rule that was enacted as part of the Fair and Accurate Credit Transactions Act of 2003 (FACTA).Universal Man-In-The-Middle: Next Generation Phishing Was Already Hereblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1660Thu, 17 Jun 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1660Over the years, phishing attacks have changed and evolved. Around 2005, it was popular to add a Javascript code to the simple HTML pages that took advantage of a vulnerability in the browser. This allowed the fraudsters to spoof the URL of the phishing attack so it would appear as...Computing as a Public Utility: Closer than Everblog@rsa.com (Nirav Mehta)http://www.rsa.com/blog/blog_entry.aspx?id=1659Fri, 11 Jun 2010 00:00:00 GMTblog@rsa.com (Nirav Mehta)http://www.rsa.com/blog/blog_entry.aspx?id=1659There is no question cloud/utility computing has arrived and is here to stay. But, something is afoot that deserves special attention. On May 6, the Federal Communications Commission (FCC) of the United States announced a plan to...Making the Cloud Privateblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1658Fri, 11 Jun 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1658I did an interview with the guys from Wikibon (Mike Versace and David Vellante), and I wanted to sum it up in a nice written blog. Then I realized that there's so much in this one that it speaks for itself. So if you want to know what I look and sound like, and want to learn about Security and the Cloud, check out this interview! <a href="http://wikibon.org/blog/what-makes-private-cloud-private/" target="_blank">http://wikibon.org/blog/what-makes-private-cloud-private/</a> Playing Catch-upblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1657Fri, 11 Jun 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1657The rise of point-to-point (or sometimes called end-to-end) encryption and tokenization has led to an interesting condition in the marketplace &ndash; the regulatory and standards bodies playing catch-up. This isn&rsquo;t to say that technology adoption hasn&rsquo;t predated a standard before.Speaking of Security Podcast #190blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1656Wed, 09 Jun 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1656<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1656">Click to Download/Listen</a> <br> <br /> Hear how a successful online jeweler is protecting customer transactions on this week's Speaking of Security podcast. <br><br>Fraudsters Still Earn a Paycheck from Traditional Methods: From Phishing Kits to Cashblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1654Thu, 03 Jun 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1654Every fraud operation consists of two main stages. In the first stage, fraudsters use various tools and sources to obtain records of stolen identities, while in the second &ldquo;cash out&rdquo; stage, they turn those records into cold hard cash.42blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1655Thu, 03 Jun 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1655Those of you that are Hitchhiker fans will recognize the meaning of 42 - it's the Answer to Life, the Universe and Everything. And for the non-fans out there, you may be asking 'What's the question?'; well, that's the problem - you can't know both the question and the answer in the same universe...Speaking of Security Podcast #189blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1652Wed, 02 Jun 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1652<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1652">Click to Download/Listen</a> <br> <br /> What is a Man-in-the-Browser attack and how can enterprises combat them? Hear more on this week's Speaking of Security podcast. <br><br>Preventing Fire Salesblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1653Wed, 02 Jun 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1653Recently a colleague of mine (thanks, Heidi!) reminded me that a major milestone in the evolution of the NERC standards was fast approaching. By July 12, 2010, all of the Critical Infrastructure Protection (CIP) requirements defined as part of the NERC standard transition from a required status of 'Compliant' (C) to 'Auditably Compliant' (AC). Log Management: Catalyst for Vital Functionsblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1651Wed, 02 Jun 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1651First, there was <strong><u>SEM</u></strong>: Security Event Management. SEM was about sitting on masses of data. I remember once meeting someone who worked with early IDS technologies (before Gartner pronounced the death of IDS), and I met an admin who could...Speaking of Security Podcast #188blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1650Wed, 26 May 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1650<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1650">Click to Download/Listen</a> <br> <br /> Hear how one of the top credit unions in the US has deployed the RSA enVision SIEM platform to help analyze internal processes and drive greater business value, on this week's Speaking of Security podcast. <br><br>Wall of Yellow...?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1649Fri, 21 May 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1649<p>Symantec is on an acquisition spree. </p> <p>There. I said it.</p> <p>We can check the box for having many of the right dancers, but how is the choreography coming? How much can Symantec &ldquo;focus on&rdquo; at once? These are the real questions for me.</BSIMM2 - A Very Useful Reference for Software Security Practitionersblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1648Thu, 20 May 2010 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1648On May 12th, Gary McGraw and his teams from Cigital and Fortify Software released version 2 of the <a href="http://bsimm2.com/" target="_blank">Building Security in Maturity Model (BSIMM)</a>. It triples the size of the software security practices analyzed by the study to a total of 30. EMC was part of the nine...Utilities are Coming of Age...has your industry?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1647Thu, 20 May 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1647I had a conversation with a utility recently in the United States that is rushing to roll out SmartMeters as part of their spending of the government stimulus package. I had one of those conversations again...Phishing Persists - and Persistence Pays Parasites*blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1645Tue, 18 May 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1645<p>Phishing persists.</p> I was shocked to see that <a href="http://en.wikipedia.org/wiki/Cory_Doctorow">Cory Doctorow</a>, a really technical author and blogger, was in fact phished recently and wrote about it this <a href="http://www.locusmag.com/" target="_blank">Locus</a> article <a href="http://www.locusmag.com/Perspectives/2010/05/cory-doctorow-persistence-pays-parasites/" target="_blank">Persistence Pays Parasites</a>Combined Arms and Defense in Depth against MITX (aka MITM)blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1646Tue, 18 May 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1646<a href="http://en.wikipedia.org/wiki/Defense_in_depth_%28computing%29" target="_blank">Defense-in-depth</a> is the only sane answer in a world where threat is presented by an intelligent opponent in a persistent and sustained manner. Eventually, as I pointed out in <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1472" target="_blank">Nothing Can Come of Nothing</a>, the bad guys will find a way...Online Security is Like Football - You Need a Defensive Front Lineblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1644Tue, 18 May 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1644A <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1637" target="_blank">recent blog</a> by my colleague, Seth Geftic, discussed the inability of security education to prevent fraud. The issue of security education has always been a complex one. Until an empirical study comes along that...Good Times in Fraudland: Part Iblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1643Tue, 18 May 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1643Thirty years from now if I&rsquo;ll ever look back and read my old blogs, I&rsquo;m sure I&rsquo;ll agree with what my current self is about to state: There was never a better time to be a cybercriminal than in good old 2009.How many Fortune 500 Companies Compromised? Answer Insideblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1640Fri, 14 May 2010 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1640In the last few weeks I&rsquo;ve been talking to some of the corporations hit by the infamous Operation Aurora; the attack that triggered the <a href="http://www.finextra.com/community/fullblog.aspx?id=3720" target="_blank">Google-China virtual war</a>. <br> <br> The CISOs of these companies are facing a daunting task. These incidents reached board-level attention, and left many questions unanswered. How good are the traditional defense mechanisms?Journeys (or stripping away what we don't need and bringing only "CIA" to the cloud with us)blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1642Fri, 14 May 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1642Here it is: a security guy saying it's not about security. I am a security guy, so here goes&hellip; <br><br> <strong>It's not about security.</strong> <br><br> Wow&hellip;that didn't hurt as much as I thought it would!The Real Cost of a Pizza - and a Social Security Numberblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1641Thu, 13 May 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1641A good friend of mine who lives in New York engaged me in a conversation about identity theft recently where he said, &ldquo;I don&rsquo;t care if they steal my credit card information. For that, I&rsquo;m covered. What I am worried about is my Social Security number. If that ever gets stolen &ndash; I&rsquo;d be in serious trouble!&rdquo;Speaking of Security Podcast #187blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1639Wed, 12 May 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1639<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1639">Click to Download/Listen</a> <br> <br /> RSA continues to expand its Speaking of Security blog team. Meet one of our newest bloggers on this week's Speaking of Security podcast. <br><br>Would the Real Cost of PCI Please Stand Up?blog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1638Fri, 07 May 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1638This week at <a href="http://www.nacsonline.com/NACSTech/Pages/default.aspx" target="_blank">NACStech</a>, I spoke with several people from a large retail chain - people who are hip-deep in the PCI compliance efforts within their organization. So as we were talking, one senior person made the comment that, &ldquo;PCI compliance only costs us around $30,000 a year&rdquo;.The Security Education Gapblog@rsa.com (Seth Geftic)http://www.rsa.com/blog/blog_entry.aspx?id=1637Fri, 07 May 2010 00:00:00 GMTblog@rsa.com (Seth Geftic)http://www.rsa.com/blog/blog_entry.aspx?id=1637One of the best parts of my jobs is getting to present on <a href="http://www.rsa.com/node.aspx?id=1331" target="_blank">online threats</a>. I get to speak at conferences, on webinars and in front of customers about the dangers that we all face when we are on the Internet due to the sophistication of cybercriminals. After giving these presentations, no matter who is in the audience, I always get someone that asks, &ldquo;What about education&hellip;does it work?&rdquo; These days, I&rsquo;m not convinced it does.Birds of a Feather...blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1636Thu, 06 May 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1636Brian Krebs has a great piece on the Mariposa (Spanish for butterfly) botnet that is really worth reading. I won't spoil it, but essentially it is about two criminals trying to get a job with Panda Security. There are some interesting take aways here, but what struck me most is...Speaking of Security Podcast #186blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1635Wed, 05 May 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1635<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1635">Click to Download/Listen</a> <br> <br /> Cyberklix is a leader in the field of Log Management and Security Event Management. Hear about some of its current business challenges on this week's Speaking of Security podcast. <br><br>Trumpet Your (Security) Achievements Loudly!blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1633Wed, 28 Apr 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1633The Lockheed Martin Cyber Security Alliance today announced a critical survey and data related to US government adoption of cloud services. Most importantly, it issued a related white paper on "Awareness, Trust, and Security to Shape Cloud Adoption" that address full-on the perception (as opposed to the realities) of the cloud with respect to the government. Speaking of Security Podcast #185blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1634Wed, 28 Apr 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1634<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1634">Click to Download/Listen</a> <br> <br /> New research commissioned by RSA reveals that despite known online threats, young adults seem to be choosing convenience over security when it comes to their online activity. We discuss on this week's Speaking of Security podcast. <br><br>Innovating for Profits Fraudster Styleblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1631Tue, 27 Apr 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1631It would come as no surprise to anyone that every fraudster attempts to maximize his profits, and there are several ways to do so. First, a fraudster could increase the amount of credentials he obtains, either by using more sophisticated tools or by simply using existing tools more often.Security by Obscurity Never Works...blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1632Tue, 27 Apr 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1632Every now and then something comes up that is, strangely, humorous. Having seen the Haiti exploits (see post on <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1575" target="_blank">Non Illegitimi Carborundum</a>) and the cease-fire opportunism (see <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1416" target="_blank">Cease Fire</a> post), I scratched my head and wondered&hellip;so where are the Eyjafjallaj&ouml;kull hoaxes? Silver bulletsblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1630Mon, 26 Apr 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1630In my last post, I talked about performing encryption in hardware vs. software, and why RSA and First Data made the business decisions that we did for our payment security solution, TransArmor. Since then, I have heard from...Putting Dogma in Front of Karmablog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1629Fri, 23 Apr 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1629For those of you who were around in security then, you are probably chuckling. For those who weren't: the Furby was a toy that could "learn." Unfortunately, it was feared that it could learn too much...and that if it were in a work environment, or worse in a classified or sensitive area, that it might be a foreign spy or a cute-looking insider.Never Give An Order You Know Won't Be Obeyed*blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1628Thu, 22 Apr 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1628The dust has settled...the worst has blown over; but what an article and what a response! Kudos to Mark Pothier at the Boston Globe for his "Please do Not Change Your Password" article that stirred up our industry like a bee's nest kicked over by a bear covered in honey!Speaking of Security Podcast #184blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1625Tue, 20 Apr 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1625<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1625">Click to Download/Listen</a> <br> <br /> Learn about RSA CyberCrime Intelligence, a new service designed to better understand the risks of malware to the enterprise on this Speaking of Security podcast. <br><br>STOP! Don't Post That! What happens on Spring Break is about to be posted to your Mom and your next 4 bosses!blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1627Tue, 20 Apr 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1627How much of what Gen Y is going through is unique to this generation and how much of it is the standard process of growing up and maturing with the added leavening of technology thrown into the mix? I remember as a Gen X-er...Avoiding Castles in the Swamp, Part 4blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1626Fri, 16 Apr 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1626In this on-going series on Security Operations, I've discussed basic foundational requirements including goals, roles and responsibilities, monitoring plans, etc. There's one final area that I'd like to cover...A Cybercrime Self-Confessionblog@rsa.com (Sean Brady)http://www.rsa.com/blog/blog_entry.aspx?id=1624Thu, 15 Apr 2010 00:00:00 GMTblog@rsa.com (Sean Brady)http://www.rsa.com/blog/blog_entry.aspx?id=1624Yes, I am one of those Users. I am one of those Users that I spend a significant part of my job working to educate customers and the industry about. You see, as part of my job, I am issued a laptop by EMC, the parent company of RSA. I am in fact working from that laptop right now. It should also be noted...Speaking of Security Podcast #183blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1623Wed, 14 Apr 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1623<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1623">Click to Download/Listen</a> <br> <br /> KPMG provides audit, tax and advisory services as part of a global network spanning over 140 countries. Hear about their commitment to security on this week's Speaking of Security podcast. <br><br>Avoiding Castles in the Swamp, Part 3blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1622Wed, 14 Apr 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1622In this blog series, I have been exploring some of the foundational requirements necessary for effectively implementing an advanced Security Operations function within an organization. We've looked at the basic...Avoiding Castles in the Swamp, Part 2blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1621Mon, 12 Apr 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1621In my last entry, I started discussing some of the foundational requirements necessary to implement a successful Security Operations (SecOps) program. I'd like to drill down a bit more into some of the most critical ones, and, ironically...Software- vs. Hardware-based Encryption in the POSblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1620Fri, 09 Apr 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1620A few years ago, I saw a video on the Internet about &lsquo;lock bumping&rsquo; and &lsquo;bump keys&rsquo;. For those that don&rsquo;t know, lock bumping is a frightening technique...Avoiding Castles in the Swamp, Part 1blog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1619Thu, 08 Apr 2010 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1619Here's a quote from Monty Python's, &quot; The Holy Grail,&quot; &nbsp;that frequently comes to mind when I discuss Security Operations with customers...Speaking of Security Podcast #182blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1618Tue, 06 Apr 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1618<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1618">Click to Download/Listen</a> <br> <br /> RSA is hiring to fill key positions in its global product organization. Learn more about the 90 Hires in 90 Days program on this week's Speaking of Security podcast. <br><br>Matching the Last Four Keeps the Bad Guys Awayblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1616Tue, 06 Apr 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1616Have you ever bought something at the store with your debit or credit card and the clerk hands you the card back without checking to make sure the signature matches? Or better yet...To Each According To His Needs*blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1617Mon, 05 Apr 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1617Please forgive my using a slogan popularized by <a href="http://en.wikipedia.org/wiki/From_each_according_to_his_ability,_to_each_according_to_his_need" target="_blank">Karl Marx</a>, but it seemed appropriate in this context: Forrester just published a fascinating paper on the <u><a href="http://www.rsa.com/CorporateSecrets" target="_blank">Value of Corporate Secrets</a></u>.The Security Alphabet: a primer for April learningblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1615Tue, 30 Mar 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1615I was watching some children's television with my 4 year old nephew this weekend (after playing with a rubber-band powered glider I bought for him in Asia in the yard &ndash; we had nice weather this weekend), and I thought...Why protecting payment card data is different &ndash; and the unique opportunities it createsblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1614Fri, 26 Mar 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1614In the years I have been focusing on data security (as opposed to general &lsquo;information security&rsquo;), I have spoken to hundreds of companies about the types of data they find valuable. Invariably...Speaking of Security Podcast #181blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1613Tue, 23 Mar 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1613<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1613">Click to Download/Listen</a> <br> <br /> The 2010 Archer GRC Summit, the premiere networking event for governance, risk and compliance programs is fast approaching. Hear all about it on this week's Speaking of Security podcast. <br><br>The Connection between Age and Credit Card Fraud &ndash; and Can the EMV Standard Solve the Problem?blog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1612Fri, 19 Mar 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1612In my<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1603" target="_blank"> last post</a>, I discussed how fraudsters take advantage of the fact that some financial institutions still are not authenticating the CVV on credit cards. This is allowing fraudsters to...AS-Troyak Exposes a Large Cybercrime Infrastructureblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1610Wed, 17 Mar 2010 00:00:00 GMTblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1610Last week, RSA and other security professionals noticed a sudden <a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline/#more-1672" target="_blank">halt in the activity</a> of an upstream Internet connectivity provider named &ldquo;AS-Troyak&rdquo;, thus causing...Speaking of Security Podcast #180blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1611Tue, 16 Mar 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1611<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1611">Click to Download/Listen</a> <br> <br /> RSA has announced enhancements to its RSA&reg; Data Loss Prevention (DLP) Suite. Hear about them on this week's Speaking of Security podcast. <br><br>The Case for Supply Chain Integrityblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1609Mon, 15 Mar 2010 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1609A couple of recent incidents are shedding some light on the complexity of ensuring software code integrity throughout the supply chain.A Touch of Realityblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1608Mon, 15 Mar 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1608After my <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1604" target="_blank">Aliens v. Code Breaking</a> blog, I came across something by Tom St. Denis (a fellow Canadian who published TomLib and wrote...Is tokenization important in a Chip & PIN world?blog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1607Fri, 12 Mar 2010 00:00:00 GMTblog@rsa.com (Robert McMillon)http://www.rsa.com/blog/blog_entry.aspx?id=1607One of the questions I get asked frequently is <a href="/blog/blog_entry.aspx?id=1595" target="_blank">how tokenization works</a> in countries that use EMV, commonly known as &lsquo;Chip &amp; PIN&rsquo;. The dialogue usually...Speaking of Security Podcast #179blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1606Thu, 11 Mar 2010 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1606<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1606">Click to Download/Listen</a> <br> <br /> Colleges and universities in the US are now the latest target for phishing attacks. This week's Speaking of Security podcast discusses this new trend. <br><br>Are you smarter than a PC?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1605Wed, 10 Mar 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1605<p>A lot of hacking is playing with other people, you know, getting them to do strange things.<BR> -Steve Wozniak</p> <p>The unexamined life is not worth living<br> -Socrates, Sec 38.</p> <p>My girlfriend Kathleen (who incidentally wants to start a food review blog with me since we've eaten at some amazing places recently)...The CVV Loophole of Credit Card Fraud is Closed for Businessblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1603Tue, 09 Mar 2010 00:00:00 GMTblog@rsa.com (Idan Aharoni)http://www.rsa.com/blog/blog_entry.aspx?id=1603One of the things I like to do when interviewing job candidates is to ask them questions about the world of fraud. I don&rsquo;t expect them to prove that they&rsquo;re certified fraudsters when they come in, but it can flesh out many paradigms that the candidates may already have. For example...Aliens v. Code Breakingblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1604Tue, 09 Mar 2010 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1604Last week, Andrea Pellegrini, Valeria Bertacco and Todd Austin published <a href="http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf" target="_blank">&quot;Fault Based Attack of RSA Authentication&quot;</a> (I'll call it FBARA here for ease of reference) as I was boarding a plane to return from...Videos from RSA Conference 2010blog@rsa.com (Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1602Thu, 04 Mar 2010 00:00:00 GMTblog@rsa.com (Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1602See what people are saying about this year's RSA Conference.