<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for SecMusings</title>
	<atom:link href="http://shermansolutionsllc.com/secmusings/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://shermansolutionsllc.com/secmusings</link>
	<description>Andy's Reflections on Technology and Security</description>
	<lastBuildDate>Mon, 20 Jul 2009 01:53:01 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Conficker &#8220;doomsday&#8221; passes without incident by andy</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/24/comment-page-1#comment-1506</link>
		<dc:creator>andy</dc:creator>
		<pubDate>Mon, 20 Jul 2009 01:53:01 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=24#comment-1506</guid>
		<description>Yes, but this is July, and the post was from April...</description>
		<content:encoded><![CDATA[<p>Yes, but this is July, and the post was from April&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Conficker &#8220;doomsday&#8221; passes without incident by Vinoth</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/24/comment-page-1#comment-1505</link>
		<dc:creator>Vinoth</dc:creator>
		<pubDate>Sun, 19 Jul 2009 15:16:17 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=24#comment-1505</guid>
		<description>Actually NMAP have a feature to detect conficker infected PC</description>
		<content:encoded><![CDATA[<p>Actually NMAP have a feature to detect conficker infected PC</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated Lockouts: Just Say No! by tom</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/5/comment-page-1#comment-322</link>
		<dc:creator>tom</dc:creator>
		<pubDate>Mon, 25 Aug 2008 13:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=5#comment-322</guid>
		<description>er - that should have been COMPLIANCE (not APPLIANCE)</description>
		<content:encoded><![CDATA[<p>er &#8211; that should have been COMPLIANCE (not APPLIANCE)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated Lockouts: Just Say No! by tom</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/5/comment-page-1#comment-321</link>
		<dc:creator>tom</dc:creator>
		<pubDate>Mon, 25 Aug 2008 13:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=5#comment-321</guid>
		<description>But most managers implementing security policies have not the slightest interest in making their systems &quot;secure&quot; whatever that might mean in their environment.

Their main concern is to earn brownie points by reporting to their managers that they have achieved whatever level of appliance is deemed necessary.

-- Security is not an add-on</description>
		<content:encoded><![CDATA[<p>But most managers implementing security policies have not the slightest interest in making their systems &#8220;secure&#8221; whatever that might mean in their environment.</p>
<p>Their main concern is to earn brownie points by reporting to their managers that they have achieved whatever level of appliance is deemed necessary.</p>
<p>&#8211; Security is not an add-on</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Independence Day by yathrib</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/10/comment-page-1#comment-65</link>
		<dc:creator>yathrib</dc:creator>
		<pubDate>Fri, 11 Jul 2008 14:58:12 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=10#comment-65</guid>
		<description>Here in Brooklyn there seemed to be a constant NYPD presence in the streets which resulted in very few (illegal) fireworks display.  Of course, that&#039;s always the part I remember from when I was a kid!

Looks like we&#039;ll be checking out the &quot;approved&quot; displays at the local minor league stadiums in the coming weeks.</description>
		<content:encoded><![CDATA[<p>Here in Brooklyn there seemed to be a constant NYPD presence in the streets which resulted in very few (illegal) fireworks display.  Of course, that&#8217;s always the part I remember from when I was a kid!</p>
<p>Looks like we&#8217;ll be checking out the &#8220;approved&#8221; displays at the local minor league stadiums in the coming weeks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Unconventional Wisdom by andy</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/3/comment-page-1#comment-14</link>
		<dc:creator>andy</dc:creator>
		<pubDate>Mon, 30 Jun 2008 14:08:15 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=3#comment-14</guid>
		<description>I missed that one.  I&#039;d love to hear more about it.</description>
		<content:encoded><![CDATA[<p>I missed that one.  I&#8217;d love to hear more about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Unconventional Wisdom by yathrib</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/3/comment-page-1#comment-13</link>
		<dc:creator>yathrib</dc:creator>
		<pubDate>Sun, 29 Jun 2008 10:57:18 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=3#comment-13</guid>
		<description>Oh yes, I would love to know where many of these &quot;sounds like security, but it&#039;s not&quot; policies come from.

Auditors often suggest policies which engineers should know better than to accept.

I don&#039;t know if you recall the furor a few years ago about &quot;MarketScore&quot; (now called comScore) amongst .edus, but that was a good example of auditor-driven policies (firewalling off MarketScore&#039;s servers) which weren&#039;t the best solution.</description>
		<content:encoded><![CDATA[<p>Oh yes, I would love to know where many of these &#8220;sounds like security, but it&#8217;s not&#8221; policies come from.</p>
<p>Auditors often suggest policies which engineers should know better than to accept.</p>
<p>I don&#8217;t know if you recall the furor a few years ago about &#8220;MarketScore&#8221; (now called comScore) amongst .edus, but that was a good example of auditor-driven policies (firewalling off MarketScore&#8217;s servers) which weren&#8217;t the best solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated Lockouts: Just Say No! by yathrib</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/5/comment-page-1#comment-12</link>
		<dc:creator>yathrib</dc:creator>
		<pubDate>Sun, 29 Jun 2008 10:52:06 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=5#comment-12</guid>
		<description>Funny, we cover this very point in an introductory security class I teach.  Most of the students in that class picked up that 3-strike lockouts just gave the attacker a trivial DoS capability.

Back-off timers seem to be a nice solution: a human interactively logging in will realize they&#039;re making a mistake if after three tries it takes them a minute to get another prompt.</description>
		<content:encoded><![CDATA[<p>Funny, we cover this very point in an introductory security class I teach.  Most of the students in that class picked up that 3-strike lockouts just gave the attacker a trivial DoS capability.</p>
<p>Back-off timers seem to be a nice solution: a human interactively logging in will realize they&#8217;re making a mistake if after three tries it takes them a minute to get another prompt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated Lockouts: Just Say No! by Steve Ruegnitz</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/5/comment-page-1#comment-9</link>
		<dc:creator>Steve Ruegnitz</dc:creator>
		<pubDate>Fri, 20 Jun 2008 20:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=5#comment-9</guid>
		<description>Andy

Sad but true that at this point it has gone beyond conventional wisdom to lock out after three attempts, it has joined the ranks of generic audit checklists.  This will make well meaning, but not well skilled audit teams simply look for a binary answer of &quot;yes we do lock out or no we don&#039;t&quot; with little to no understanding of the implications.

I fear this policy will be with us long after any utility to it (if there ever was any utility in the first place) is gone.</description>
		<content:encoded><![CDATA[<p>Andy</p>
<p>Sad but true that at this point it has gone beyond conventional wisdom to lock out after three attempts, it has joined the ranks of generic audit checklists.  This will make well meaning, but not well skilled audit teams simply look for a binary answer of &#8220;yes we do lock out or no we don&#8217;t&#8221; with little to no understanding of the implications.</p>
<p>I fear this policy will be with us long after any utility to it (if there ever was any utility in the first place) is gone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated Lockouts: Just Say No! by Kevin Riggins</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/5/comment-page-1#comment-8</link>
		<dc:creator>Kevin Riggins</dc:creator>
		<pubDate>Fri, 20 Jun 2008 15:24:35 +0000</pubDate>
		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=5#comment-8</guid>
		<description>Andy,

Really enjoyed the post.  Good stuff.  As you and the other commenters have pointed out, password lockouts are another fine example of &quot;It Depends.&quot;  Having the business folks chime in on issues like this is vitally important as you allude to with your example of stock traders not being able to work because of lockouts.  

On a bit of a side note, what a great way to attack the brand of a company that relies on their people being able to access systems real-time. 

Keep up the good work.

Kevin</description>
		<content:encoded><![CDATA[<p>Andy,</p>
<p>Really enjoyed the post.  Good stuff.  As you and the other commenters have pointed out, password lockouts are another fine example of &#8220;It Depends.&#8221;  Having the business folks chime in on issues like this is vitally important as you allude to with your example of stock traders not being able to work because of lockouts.  </p>
<p>On a bit of a side note, what a great way to attack the brand of a company that relies on their people being able to access systems real-time. </p>
<p>Keep up the good work.</p>
<p>Kevin</p>
]]></content:encoded>
	</item>
</channel>
</rss>
