<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-5124364383139248505.post6083618435467493727..comments</id><updated>2011-10-10T02:29:14.251-06:00</updated><category term='insecurity'/><category term='browser exploit'/><category term='education'/><category term='security testing'/><category term='breach'/><category term='social engineering'/><category term='protect'/><category term='client side'/><category term='security'/><category term='assess'/><category term='War'/><category term='brittish'/><category term='hacking'/><category term='eartland'/><category term='audit'/><category term='life'/><category term='phishing'/><category term='data loss'/><category term='first post'/><category term='pentesting'/><category term='security industry'/><category term='infosec'/><category term='tactics'/><category term='credit card'/><category term='anon'/><category term='lulz'/><category term='training'/><title type='text'>Comments on LARES BLOG: Confessions of a SecAddict</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.laresblog.com/feeds/6083618435467493727/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html'/><author><name>Nickerson</name><uri>http://www.blogger.com/profile/05101697766242051577</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_RrfMe_nc1PI/SaNMhzvTN0I/AAAAAAAAAAY/SsRqgVwWEz0/S220/12943_009.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-6866920810150246386</id><published>2011-10-10T02:29:14.251-06:00</published><updated>2011-10-10T02:29:14.251-06:00</updated><title type='text'>The Registration plate shall bear nine characters,...</title><content type='html'>The Registration plate shall bear nine characters, laser branded into the reflective sheeting and would act as a permanent &lt;br /&gt;&lt;br /&gt;consecutive identification number. The hot stamping film shall bear a verification inscription.&lt;br /&gt;&lt;br /&gt;&lt;a href="www.celex.co.in/hrps.php" rel="nofollow"&gt;hsrp&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/6866920810150246386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/6866920810150246386'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1318235354251#c6866920810150246386' title=''/><author><name>business hub</name><uri>http://www.blogger.com/profile/06540779737682881976</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-346484196'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-7270270974496701984</id><published>2011-09-19T11:41:59.147-06:00</published><updated>2011-09-19T11:41:59.147-06:00</updated><title type='text'>I am sorry, but am I the only one who finds the wh...</title><content type='html'>I am sorry, but am I the only one who finds the white text on the black background difficult to read?!! The article seems interesting and I see many a ppl have read and commented..but somehow I couldnt look at it for long... :(</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/7270270974496701984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/7270270974496701984'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1316454119147#c7270270974496701984' title=''/><author><name>Aniket</name><uri>http://theitaxis.wordpress.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1484141389'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-3448306807087859197</id><published>2010-04-06T19:40:17.328-06:00</published><updated>2010-04-06T19:40:17.328-06:00</updated><title type='text'>Moon. So True. This is why I consider proper testi...</title><content type='html'>Moon. So True. This is why I consider proper testing much like an intervention. Even proper education or training in an org can do this. Because as you said, they usually need some type of &amp;quot;force&amp;quot; to get them started.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/3448306807087859197'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/3448306807087859197'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270604417328#c3448306807087859197' title=''/><author><name>christopher</name><uri>http://www.blogger.com/profile/14748853066031748495</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1475139531'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-497017864276790702</id><published>2010-04-06T12:35:14.811-06:00</published><updated>2010-04-06T12:35:14.811-06:00</updated><title type='text'>Great points!  But noone who is addicted goes to r...</title><content type='html'>Great points!  But noone who is addicted goes to rehab unless they are forced to by circumstances…  hitting rock bottom or some &amp;quot;intervention&amp;quot;…  In the case of business, &amp;quot;rock bottom&amp;quot; could be a breach (resulting in substantial direct or indirect costs to the company) and intervention could be a Board member who understands business risks in terms of more than just credit, market or regulatory risks and factors in the IT security &amp;amp; business continuity, etc and the privacy components of risk management and pushes for better governance.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/497017864276790702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/497017864276790702'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270578914811#c497017864276790702' title=''/><author><name>Moonraker069</name><uri>http://moonraker069.pip.verisignlabs.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1247412440'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-4339310757711528050</id><published>2010-04-06T08:53:50.113-06:00</published><updated>2010-04-06T08:53:50.113-06:00</updated><title type='text'>First of all, I just want to say the opening lines...</title><content type='html'>First of all, I just want to say the opening lines attributed to Delchi are pure genius and I say they resonate with me, especially the last line which ultimately says, &amp;quot;Be happy despite not getting what we want every time.&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;I think there are a ton of layers we could go through when talking about things like &amp;quot;learned helplessness&amp;quot; and powerlessness in regards to corporate or even individual security, and how it may relate to our own well-being in the face of not getting the security we know an entity needs. Likewise to the internal employees who have an ear towards being more secure.&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;I get what jbrashars is saying about letting a few lumps get through to make a point in learning. I feel like until corporations feel a few lumps, the best they do is throw their IT ops into detox (assessment), pop some pills (appliances), and limit their view to only what they want to deal with (scope). But like you&amp;#39;ve said, that&amp;#39;s not getting at the root of the issues, which is attitude/perception/happiness/human minds.&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;Steps #2 and #3 could be a great approach for a corporate entity to start turning their initiatives over to security experts who can help them!&lt;br /&gt;&lt;br /&gt;--LonerVamp</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/4339310757711528050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/4339310757711528050'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270565630113#c4339310757711528050' title=''/><author><name>L</name><uri>http://www.blogger.com/profile/10949152012822050629</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1997736329'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-8190263375104442420</id><published>2010-04-05T12:36:05.644-06:00</published><updated>2010-04-05T12:36:05.644-06:00</updated><title type='text'>Thank you.

PS Also liked the Vodka metaphor.</title><content type='html'>Thank you.&lt;br /&gt;&lt;br /&gt;PS Also liked the Vodka metaphor.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/8190263375104442420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/8190263375104442420'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270492565644#c8190263375104442420' title=''/><author><name>Владимир Стыран</name><uri>http://www.blogger.com/profile/12271406187339769088</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10284374856633951375'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_qASWdX8owQc/S69snlumOfI/AAAAAAAAEiU/Zwa_rk97mk0/S220/%D0%92%D0%BE%D0%B2%D0%B0%D0%BD%D0%A7%D0%91.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-54016008'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-6119843902960236116</id><published>2010-04-05T12:26:13.581-06:00</published><updated>2010-04-05T12:26:13.581-06:00</updated><title type='text'>Awe, fuck. I missed the red text at the top before...</title><content type='html'>Awe, fuck. I missed the red text at the top before I posted, with your serenity prayer. Well, I guess it&amp;#39;s suicide again for me.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/6119843902960236116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/6119843902960236116'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270491973581#c6119843902960236116' title=''/><author><name>jbrashars</name><uri>http://openid.aol.com/jbrashars</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1625313790'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-5268768016954207018</id><published>2010-04-05T12:15:27.299-06:00</published><updated>2010-04-05T12:15:27.299-06:00</updated><title type='text'>Loved the  “Well, we will consider you recovered i...</title><content type='html'>Loved the  “Well, we will consider you recovered if you don’t drink Vodka any more. All of the other alcohol isn’t IN SCOPE”  quote!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/5268768016954207018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/5268768016954207018'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270491327299#c5268768016954207018' title=''/><author><name>Dr Anton Chuvakin</name><uri>http://www.blogger.com/profile/12740087457147758558</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='21' src='http://www.chuvakin.com/official-3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1730644029'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-4361824970550608013</id><published>2010-04-05T12:04:49.335-06:00</published><updated>2010-04-05T12:04:49.335-06:00</updated><title type='text'>Chris,
I&amp;#39;m digging it. Although I can&amp;#39;t he...</title><content type='html'>Chris,&lt;br /&gt;I&amp;#39;m digging it. Although I can&amp;#39;t help but wonder if the 12 steps are more for the tester/auditor/savvy employee, or for the company themselves? As the boundaries of the internet melt away and people plug more and more of their lives online, the need for security goes up exponentially but the budget rarely moves in an upward direction. Too often, security is treated as a costly measure and not a cost saving measure, and thus so much of it is reactive. &amp;quot;Shit, we got pwned and gigs of cardholder data is on our twitter feed. Guess we better call ACME Sec. But ask if there&amp;#39;s a coupon.&amp;quot;   Any why SHOULD they care? Jesus, look at the financial sector. One of the biggest economic fuck ups of our lives and the banks get bailed out on our dime. Where is the incentive? &lt;br /&gt;&lt;br /&gt;Being an InfoSecPro is a lot like being a parent. You can talk until you&amp;#39;re blue in the face about not grabbing onto the scalding hot pot handle, because you&amp;#39;re GOING to get burned, or don&amp;#39;t ride your big wheel down the stairs or we have to go to the hospital. But unless the kids (or companies) take a few lumps and learn WHY you have to be careful, from scars, the lesson is never truly absorbed. &lt;br /&gt;&lt;br /&gt;As both an InfoSecPro and the father of a toddler, I am learning that my job is to make sure the kid/company lives long enough to learn and to reach maturity. Sometimes that lesson is expensive, but if we&amp;#39;ve done our job, it&amp;#39;s not fatal or permanently disfiguring. &lt;br /&gt;&lt;br /&gt;But knowing that isn&amp;#39;t enough to make it any easier, or less frustrating. That doesn&amp;#39;t mean I don&amp;#39;t stomp and scream whenever I see my kid put himself in harm&amp;#39;s way. I don&amp;#39;t know that I&amp;#39;ll ever be able to stop doing that. I guess part of the process is knowing when to let someone get owned a little bit, so that they learn to listen, and when to put your foot down and say &amp;quot;If you don&amp;#39;t listen to him THIS time, you might not get to hear me say anything next time.&amp;quot; &lt;br /&gt;&lt;br /&gt;I think it&amp;#39;s important to take your 12 step approach; I also think a helpful supplement to your program is the InfoSec Serenity Prayer:&lt;br /&gt;&lt;br /&gt;$deity grant me the serenity to accept the policies I cannot change;&lt;br /&gt;the courage to change the things I can;&lt;br /&gt;and the wisdom to know the difference.&lt;br /&gt;&lt;br /&gt;Living one assessment at a time&lt;br /&gt;Enjoying one hack at a time&lt;br /&gt;Accepting hardships as the pathway to security;&lt;br /&gt;Taking this sinful circle jerk&lt;br /&gt;As it is, not as I would have it.&lt;br /&gt;Trusting that getting popped and leaked all over twitter will make things right if we surrender to FUD&lt;br /&gt;That I may be reasonably happy in this industry&lt;br /&gt;and supremely happy with my job&lt;br /&gt;Forever and in retirement.&lt;br /&gt;Amen.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/4361824970550608013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/4361824970550608013'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270490689335#c4361824970550608013' title=''/><author><name>jbrashars</name><uri>http://openid.aol.com/jbrashars</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1625313790'/></entry><entry><id>tag:blogger.com,1999:blog-5124364383139248505.post-2386624309301944556</id><published>2010-04-05T11:49:52.002-06:00</published><updated>2010-04-05T11:49:52.002-06:00</updated><title type='text'>Very inspirational!</title><content type='html'>Very inspirational!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/2386624309301944556'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5124364383139248505/6083618435467493727/comments/default/2386624309301944556'/><link rel='alternate' type='text/html' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html?showComment=1270489792002#c2386624309301944556' title=''/><author><name>Joh Man X</name><uri>http://www.blogger.com/profile/07548666855526410544</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_h6VdC3vJFmw/S7oijI7ehgI/AAAAAAAAAHQ/fJuQn08xuGw/S220/johmanx_sq_banner_small.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.laresblog.com/2010/04/confessions-of-secaddict.html' ref='tag:blogger.com,1999:blog-5124364383139248505.post-6083618435467493727' source='http://www.blogger.com/feeds/5124364383139248505/posts/default/6083618435467493727' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1704107296'/></entry></feed>
