<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Internet SecuritT Group</title>
	<atom:link href="http://www.securitt.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitt.com</link>
	<description>Internet Security Consultant Services of West Virginia</description>
	<lastBuildDate>Sun, 05 Feb 2012 06:45:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Strong network security in the cloud</title>
		<link>http://www.securitt.com/strong-network-security-in-the-cloud</link>
		<comments>http://www.securitt.com/strong-network-security-in-the-cloud#comments</comments>
		<pubDate>Sun, 05 Feb 2012 06:45:29 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strong]]></category>

		<guid isPermaLink="false">http://www.securitt.com/strong-network-security-in-the-cloud</guid>
		<description><![CDATA[CloudPassage unveiled Halo NetSec, an automated solution that provides advanced network access control for servers running in public clouds including Rackspace and Amazon EC2. Cloud computing ha&#8230; View full post on Help Net Security &#8211; News]]></description>
			<content:encoded><![CDATA[<p>CloudPassage unveiled Halo NetSec, an automated solution that provides advanced network access control for servers running in public clouds including Rackspace and Amazon EC2.</p>
<p> Cloud computing ha&#8230;</p>
<p>View full post on <a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/0fzXh4T1KT4/secworld.php">Help Net Security &#8211; News</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/strong-network-security-in-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity Legislation Components, (Sun, Feb 5th)</title>
		<link>http://www.securitt.com/cybersecurity-legislation-components-sun-feb-5th</link>
		<comments>http://www.securitt.com/cybersecurity-legislation-components-sun-feb-5th#comments</comments>
		<pubDate>Sun, 05 Feb 2012 05:06:36 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Components]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[legislation]]></category>

		<guid isPermaLink="false">http://www.securitt.com/cybersecurity-legislation-components-sun-feb-5th</guid>
		<description><![CDATA[As many of us have seen in the media recently, the United States and other world governments are deeply entrenched in discussions over proposed cybersecurity legislation. There are many different flavors of legislation currently being discussed by governments across the globe, of which I dont intend to cover here. In the US it appears the [...]]]></description>
			<content:encoded><![CDATA[<p>As many of us have seen in the media recently, the United States and other world governments are deeply entrenched in discussions over proposed cybersecurity legislation. There are many different flavors of legislation currently being discussed by governments across the globe, of which I dont intend to cover here. In the US it appears the government has finally started to address cybersecurity issues that have been discussed in this forum for years. One piece of the legislation currently being discussed is a proposal sponsored by Rep. Dan Lungren (R-Calif.) is House Resolution 3674 &#8211; the Promoting and Enhancing Cybersecurity and Information Sharing Enhancement Act of 2011 or PrECISE. The thrust of the bill is to amend the current Homeland Security Act of 2002 which will give additional authority to the USGovernment in the national cybersecurity effort.</p>
<p>
I want to highlight some of the ideas being presented in this bill and how they are going to be a huge win for the cyber security community. These are just a few of the items being discussed, but these will pay huge dividends in the security effort.</p>
<p>The coordination and sharing of information between the civilian and government agencies is one of the topics some of the bills being considered address, and is a critical component in the cybersecurity effort. As it is written in PrECISE SEC. 2. Sec.226 (2) foster the development, in conjunction with other governmental entities and the private sector, of essential information security technologies and capabilities for protecting Federal systems and critical infrastructure information systems, including comprehensive protective capabilities and other technological solutions. Organizations that have previously developed implementation strategies for information systems have a leg up on organizations that have not. The Black Hat community has excelled at this type of sharing, and has been an excellent vehicle for their efforts. They are not impeded by corporate policy, federal guidelines, or other governing regulations. </p>
<p>The silos of information that exist in the enterprise today have also led to silos of security information. The production, collection, and correlation of that information is often difficult because different vendor technologies, implemented at different stages, lead to disparate systems. PrECISE SEC. 2, Sec 226 Para. (3) states the need to acquire, integrate, and facilitate the adoption of new cybersecurity technologies and practices in a technologically and vendor-neutral manner to keep pace with emerging terrorist and other cybersecurity threats. There are many great minds and methods to approach this, and the solution will not be easy. It is a critical solution that needs to be addressed.</p>
<p>User awareness and education is critical for every aspect of information security. With the increase of reliance on technology throughout, the importance of user education increases accordingly. PrECISE SEC. 2, Sec 226 Para.(6) states  and</p>
<p>-(C) training opportunities to support the development of an effective national cybersecurity workforce and educational paths to cybersecurity professions<br />
User education and awareness training, coupled with the information sharing efforts mentioned in Para. (2) will go a long way towards improving the overall security of the information and systems we use every day.</p>
<p>
I am excited to see the governments taking cybersecurity seriously, and hope the politicians can produce something that is useable and applicable to the world today. The implementation of some of the ideas discussed in this bill will be a huge undertaking, and needs to be done.As a society we have moved beyond the point where cybersecurity is merely desirable by the people who rely on technology. it is a fundamental need, and in some instances, desperately.<br />
Tony Carothers<br />
tony d0t carothers at g_mail</p>
<p> (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.</p>
<p>View full post on <a href="http://isc.sans.edu/diary.html?storyid=12535&#038;rss">      SANS Internet Storm Center, InfoCON: green</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/cybersecurity-legislation-components-sun-feb-5th/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Satellite phones lift skirt, flash cipher secrets at boffins</title>
		<link>http://www.securitt.com/satellite-phones-lift-skirt-flash-cipher-secrets-at-boffins</link>
		<comments>http://www.securitt.com/satellite-phones-lift-skirt-flash-cipher-secrets-at-boffins#comments</comments>
		<pubDate>Sun, 05 Feb 2012 02:07:45 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[boffins]]></category>
		<category><![CDATA[Cipher]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[lift]]></category>
		<category><![CDATA[phones]]></category>
		<category><![CDATA[satellite]]></category>
		<category><![CDATA[Secrets]]></category>
		<category><![CDATA[skirt]]></category>

		<guid isPermaLink="false">http://www.securitt.com/satellite-phones-lift-skirt-flash-cipher-secrets-at-boffins</guid>
		<description><![CDATA[Security though obscurity fails yet again Researchers at the Ruhr-University Bochum have managed to extract the secret encryption algorithmns used by satellite phones, and discovered that it&#8217;s a lot less secure than one might hope.… View full post on The Register &#8211; Security]]></description>
			<content:encoded><![CDATA[<h4>Security though obscurity fails yet again</h4>
<p>Researchers at the Ruhr-University Bochum have managed to extract the secret encryption algorithmns used by satellite phones, and discovered that it&#8217;s a lot less secure than one might hope.…</p>
<p>View full post on <a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/03/satellite_phone_hack/">The Register &#8211; Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/satellite-phones-lift-skirt-flash-cipher-secrets-at-boffins/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multi-factor authentication for mobile users</title>
		<link>http://www.securitt.com/multi-factor-authentication-for-mobile-users</link>
		<comments>http://www.securitt.com/multi-factor-authentication-for-mobile-users#comments</comments>
		<pubDate>Sun, 05 Feb 2012 00:45:15 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Multifactor]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://www.securitt.com/multi-factor-authentication-for-mobile-users</guid>
		<description><![CDATA[DigitalPersona announced the newest version of DigitalPersona Pro Enterprise has support for a variety of new authentication credentials. With the software, organizations can now mix and match differe&#8230; View full post on Help Net Security &#8211; News]]></description>
			<content:encoded><![CDATA[<p>DigitalPersona announced the newest version of DigitalPersona Pro Enterprise has support for a variety of new authentication credentials. With the software, organizations can now mix and match differe&#8230;</p>
<p>View full post on <a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/9UraqClo18A/secworld.php">Help Net Security &#8211; News</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/multi-factor-authentication-for-mobile-users/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac OS X Lion 10.7.3 released</title>
		<link>http://www.securitt.com/mac-os-x-lion-10-7-3-released</link>
		<comments>http://www.securitt.com/mac-os-x-lion-10-7-3-released#comments</comments>
		<pubDate>Sat, 04 Feb 2012 18:48:40 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[10.7.3]]></category>
		<category><![CDATA[Lion]]></category>
		<category><![CDATA[released]]></category>

		<guid isPermaLink="false">http://www.securitt.com/mac-os-x-lion-10-7-3-released</guid>
		<description><![CDATA[The 10.7.3 update is recommended for all OS X Lion users and includes general operating system fixes that improve the stability, compatibility, and security of your Mac. The OS X Lion 10.7.3 Upda&#8230; View full post on Help Net Security &#8211; News]]></description>
			<content:encoded><![CDATA[<p>The 10.7.3 update is recommended for all OS X Lion users and includes general operating system fixes that improve the stability, compatibility, and security of your Mac.</p>
<p> The OS X Lion 10.7.3 Upda&#8230;</p>
<p>View full post on <a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/jCWFeDoL5JU/secworld.php">Help Net Security &#8211; News</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/mac-os-x-lion-10-7-3-released/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Government website passwords published by Anonymous</title>
		<link>http://www.securitt.com/government-website-passwords-published-by-anonymous</link>
		<comments>http://www.securitt.com/government-website-passwords-published-by-anonymous#comments</comments>
		<pubDate>Sat, 04 Feb 2012 18:45:23 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[published]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.securitt.com/government-website-passwords-published-by-anonymous</guid>
		<description><![CDATA[As the moment when the new legislation for defending the rights of copyright holders regarding online sharing will be discussed is coming near, the Irish politician pushing it and the government itsel&#8230; View full post on Help Net Security &#8211; News]]></description>
			<content:encoded><![CDATA[<p>As the moment when the new legislation for defending the rights of copyright holders regarding online sharing will be discussed is coming near, the Irish politician pushing it and the government itsel&#8230;</p>
<p>View full post on <a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/UPmpmtlz1us/secworld.php">Help Net Security &#8211; News</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/government-website-passwords-published-by-anonymous/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple FileVault cracked in under an hour by forensics biz</title>
		<link>http://www.securitt.com/apple-filevault-cracked-in-under-an-hour-by-forensics-biz</link>
		<comments>http://www.securitt.com/apple-filevault-cracked-in-under-an-hour-by-forensics-biz#comments</comments>
		<pubDate>Sat, 04 Feb 2012 16:10:31 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[cracked]]></category>
		<category><![CDATA[FileVault]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hour]]></category>
		<category><![CDATA[under]]></category>

		<guid isPermaLink="false">http://www.securitt.com/apple-filevault-cracked-in-under-an-hour-by-forensics-biz</guid>
		<description><![CDATA[Passware scratches Lion&#8217;s belly, penetrates fruity disk Apple&#8217;s FileVault disk encryption can be circumvented in less than an hour, according to a computer forensics firm.… View full post on The Register &#8211; Security]]></description>
			<content:encoded><![CDATA[<h4>Passware scratches Lion&#8217;s belly, penetrates fruity disk</h4>
<p>Apple&#8217;s FileVault disk encryption can be circumvented in less than an hour, according to a computer forensics firm.…</p>
<p>View full post on <a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/03/apple_disc_crypto_broken/">The Register &#8211; Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/apple-filevault-cracked-in-under-an-hour-by-forensics-biz/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous hackers leak Scotland Yard-FBI conference call</title>
		<link>http://www.securitt.com/anonymous-hackers-leak-scotland-yard-fbi-conference-call</link>
		<comments>http://www.securitt.com/anonymous-hackers-leak-scotland-yard-fbi-conference-call#comments</comments>
		<pubDate>Sat, 04 Feb 2012 16:07:56 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Call]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[leak]]></category>
		<category><![CDATA[Scotland]]></category>
		<category><![CDATA[YardFBI]]></category>

		<guid isPermaLink="false">http://www.securitt.com/anonymous-hackers-leak-scotland-yard-fbi-conference-call</guid>
		<description><![CDATA[Were you talking about us? Members of Anonymous have released an intercept of a conference call between investigators at the FBI and Scotland Yard during which operations against hacktivist group were discussed.… View full post on The Register &#8211; Security]]></description>
			<content:encoded><![CDATA[<h4>Were you talking about us?</h4>
<p>Members of Anonymous have released an intercept of a conference call between investigators at the FBI and Scotland Yard during which operations against hacktivist group were discussed.…</p>
<p>View full post on <a href="http://go.theregister.com/feed/www.theregister.co.uk/2012/02/03/anonymous_leaks_fbi_conference_call/">The Register &#8211; Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/anonymous-hackers-leak-scotland-yard-fbi-conference-call/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sophos 2012 Security Threat Report, (Fri, Feb 3rd)</title>
		<link>http://www.securitt.com/sophos-2012-security-threat-report-fri-feb-3rd</link>
		<comments>http://www.securitt.com/sophos-2012-security-threat-report-fri-feb-3rd#comments</comments>
		<pubDate>Sat, 04 Feb 2012 13:05:38 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Threat]]></category>

		<guid isPermaLink="false">http://www.securitt.com/sophos-2012-security-threat-report-fri-feb-3rd</guid>
		<description><![CDATA[Last week Sophos released it 2012 Security Threat Report which highlighted some key finding from 2011: - Smartphones and tablets causing significant security challenges - Major data breaches and targeted attacks on high-profile companies and agencies - Hacktivism &#8211; A shift from hacking for money to hacking as a form of protest or to prove [...]]]></description>
			<content:encoded><![CDATA[<p>Last week Sophos released it 2012 Security Threat Report which highlighted some key finding from 2011:<br />
- Smartphones and tablets causing significant security challenges</p>
<p>- Major data breaches and targeted attacks on high-profile companies and agencies</p>
<p>- Hacktivism &#8211; A shift from hacking for money to hacking as a form of protest or to prove a point</p>
<p>- Conficker worm is still the most commonly encountered pieces of malicious software seen is Sophos customers</p>
<p>- Fake antivirus software is still the most common type of malware but in second half of the year appears to be on the decline</p>
<p>- Spearphishing attacks on the rise<br />
Despite all this, some successes On March 16, 2011 a coordinated effort known as Operation b107 between Microsoft, FireEye, U.S. federal law enforcement agents and the University of Washington knocked Rustock offline. [1] The entire report available here.<br />
Handler Mark published a diary on some of the things to take in consideration When your service provider has a breach. [3]<br />
[1] http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-07.aspx</p>
<p>[2] http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report/html-01.aspx</p>
<p>[3] https://isc.sans.edu/diary.html?storyid=10651</p>
<p>[4] http://www.sophos.com/medialibrary/PDFs/other/SophosSecurityThreatReport2012.pdf<br />
Data breach diaries reported by ISC in 2011:<br />
[1] WordPress.com https://isc.sans.edu/diary.html?storyid=10729</p>
<p>[2] RSA Breach https://isc.sans.edu/diary.html?storyid=10609</p>
<p>[3] Lockheed Marting https://isc.sans.edu/diary.html?storyid=10939</p>
<p>[4] Sega Pass https://isc.sans.edu/diary.html?storyid=11065</p>
<p>[5] SonyPictures https://isc.sans.edu/diary.html?storyid=10996</p>
<p>[6] DigiNotar SSL Breach (result = bankruptcy) https://isc.sans.edu/diary.html?storyid=11479</p>
<p>[7] GlobalSign https://isc.sans.edu/diary.html?storyid=12205</p>
<p>[8] Stratfor Global Intelligence https://isc.sans.edu/diary.html?storyid=12271<br />
&#8212;&#8212;&#8212;&#8211;<br />
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu</p>
<p> (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.</p>
<p>View full post on <a href="http://isc.sans.edu/diary.html?storyid=12526&#038;rss">      SANS Internet Storm Center, InfoCON: green</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/sophos-2012-security-threat-report-fri-feb-3rd/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VeriSign hack: Reactions from the security community</title>
		<link>http://www.securitt.com/verisign-hack-reactions-from-the-security-community</link>
		<comments>http://www.securitt.com/verisign-hack-reactions-from-the-security-community#comments</comments>
		<pubDate>Sat, 04 Feb 2012 12:46:13 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[COMMUNITY]]></category>
		<category><![CDATA[from]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Reactions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[VeriSign]]></category>

		<guid isPermaLink="false">http://www.securitt.com/verisign-hack-reactions-from-the-security-community</guid>
		<description><![CDATA[VeriSign admitted it was hacked in 2010 and cannot identify what data was stolen. Below are comments on the situation that Help Net Security received from industry veterans. Jon Callas, CTO for E&#8230; View full post on Help Net Security &#8211; News]]></description>
			<content:encoded><![CDATA[<p>VeriSign admitted it was hacked in 2010 and cannot identify what data was stolen. Below are comments on the situation that Help Net Security received from industry veterans.</p>
<p> Jon Callas, CTO for E&#8230;</p>
<p>View full post on <a href="http://feedproxy.google.com/~r/HelpNetSecurity/~3/Z6QWGuy5G7g/secworld.php">Help Net Security &#8211; News</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitt.com/verisign-hack-reactions-from-the-security-community/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

