<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The InfoSec Blog</title>
	
	<link>http://infosecblog.antonaylward.com</link>
	<description>System Integrity: Without Integrity you don't have Security</description>
	<pubDate>Fri, 14 Nov 2008 15:54:16 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SystemIntegrity" type="application/rss+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
		<title>Going Rogue</title>
		<link>http://infosecblog.antonaylward.com/2008/11/11/going-rogue/</link>
		<comments>http://infosecblog.antonaylward.com/2008/11/11/going-rogue/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 16:02:24 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Crime]]></category>

		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Risk]]></category>

		<category><![CDATA[Allied Irish Bank]]></category>

		<category><![CDATA[Business]]></category>

		<category><![CDATA[Canadian Imperial Bank of Commerce]]></category>

		<category><![CDATA[CIBC]]></category>

		<category><![CDATA[fraud]]></category>

		<category><![CDATA[John Rusnak]]></category>

		<category><![CDATA[Morgan Stanley]]></category>

		<category><![CDATA[Nick Leason]]></category>

		<category><![CDATA[Toshihide Iguchi]]></category>

		<category><![CDATA[United Kingdom]]></category>

		<category><![CDATA[WorldCom]]></category>

		<category><![CDATA[Yasuo Hamanaka]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=192</guid>
		<description><![CDATA[In this article at TechRepublic, Tom Olzak tries to address the issue of insider threat by talking about why your employees might &#8216;go rogue&#8217;.   I think he completely misses the point by discussing the motivation for spies and convicted traitors.  This is a different class of people from toss that commit financial fraud [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/11/11/going-rogue/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Internet addiction defined</title>
		<link>http://infosecblog.antonaylward.com/2008/11/10/internet-addiction-defined/</link>
		<comments>http://infosecblog.antonaylward.com/2008/11/10/internet-addiction-defined/#comments</comments>
		<pubDate>Mon, 10 Nov 2008 14:52:10 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Politics &amp; Economics]]></category>

		<category><![CDATA[Social]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=182</guid>
		<description><![CDATA[
http://www.engadget.com/2008/11/10/internet-addiction-defined-in-china-entire-engadget-staff-now-o/
Is a &#8220;dependency&#8221; the same as an &#8220;addiction&#8220;?
Many businesses and business processes, to say nothing of Government, are now _dependent_ on the Internet.  Its a key part of our economy, not just our lifestyle.  The world could possibly give up cell-phones but I doubt it could give up the &#8216;Net and continue without [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/11/10/internet-addiction-defined/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cyber-terrorism will be punishable by death</title>
		<link>http://infosecblog.antonaylward.com/2008/11/10/cyber-terrorism-will-be-punishable-by-death/</link>
		<comments>http://infosecblog.antonaylward.com/2008/11/10/cyber-terrorism-will-be-punishable-by-death/#comments</comments>
		<pubDate>Mon, 10 Nov 2008 12:53:39 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Crime]]></category>

		<category><![CDATA[Politics &amp; Economics]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Terrorism]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=179</guid>
		<description><![CDATA[http://www.dailytimes.com.pk/default.asp?page=2008\117\story_7-11-2008_pg1_8
Only in Pakistan?  Shame!
The penalty is limited to an offence that ‘causes death of any person’,
according to the ordinance that will be considered effective from
September 29.
And, thinking of the &#8220;for want of a nail&#8221; poem, how indirect does this causality have to be?  OK, I can see zapping someone&#8217;s pacemaker, but how about [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/11/10/cyber-terrorism-will-be-punishable-by-death/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Words</title>
		<link>http://infosecblog.antonaylward.com/2008/10/20/new-words/</link>
		<comments>http://infosecblog.antonaylward.com/2008/10/20/new-words/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 14:14:54 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Humour]]></category>

		<category><![CDATA[British English]]></category>

		<category><![CDATA[Language]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=174</guid>
		<description><![CDATA[
A non-native English speaker I was in correspondence with thanked me for helping expand his vocabulary.
It occurs to me that understanding English grammar and the use of prefixes and suffixes cn also help expnad your vocabulary.  Here are some words not often found IN dictionaries. (Of course this is British English spelling,  American English [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/10/20/new-words/feed/</wfw:commentRss>
		</item>
		<item>
		<title>All I Need To Know About Project Management I Learnt From My Cats</title>
		<link>http://infosecblog.antonaylward.com/2008/08/22/all-i-need-to-know-about-project-management-i-learnt-from-my-cats/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/22/all-i-need-to-know-about-project-management-i-learnt-from-my-cats/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 14:29:24 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Human Factors]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=159</guid>
		<description><![CDATA[
The most interesting, creative, fun and innovative people don&#8217;t run
with the pack.
You&#8217;re a leader because your team believes you are worth following,
not because you are appointed leader.
You don&#8217;t lead by giving orders, you lead by motivation.
Don&#8217;t expect to generate consensus easily, and be very suspicious when it occurs other than spontaneously.
&#8216;Who&#8217;s to blame&#8217; is the [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/22/all-i-need-to-know-about-project-management-i-learnt-from-my-cats/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Are Mission Statements High Entropy?</title>
		<link>http://infosecblog.antonaylward.com/2008/08/22/are-mission-statements-high-entropy/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/22/are-mission-statements-high-entropy/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 14:08:35 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Social]]></category>

		<category><![CDATA[Baroque Cycle]]></category>

		<category><![CDATA[Cryptonomicon]]></category>

		<category><![CDATA[English language]]></category>

		<category><![CDATA[Neal Stephenson]]></category>

		<category><![CDATA[Racter]]></category>

		<category><![CDATA[Snowcrash]]></category>

		<category><![CDATA[Talk radio]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=158</guid>
		<description><![CDATA[My friend and fellow security droid Gary Hinson asked why so many corporate mission statements end up being utter gibberish, with more meanings than bits.
Hmm.
A &#8216;bit&#8217; being, according to /usr/share/units.dat, a measure of entropy.
No Gary, I think that corporate mission statements, like political party policies, are high entropy. and with a high negative correlation with [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/22/are-mission-statements-high-entropy/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Billion and Billions.</title>
		<link>http://infosecblog.antonaylward.com/2008/08/22/billion-and-billions/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/22/billion-and-billions/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 14:00:24 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Crime]]></category>

		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Social]]></category>

		<category><![CDATA[Confidence trick]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=154</guid>
		<description><![CDATA[No, not a Google its a Sagan!
I&#8217;m sure that like me you get mails that read something like
From:Mr.John Lewis
Phone No: 44-702 409 9061
This is to inform you that your funds of US$15 Million
has been approved for immediate delivery to you.
For the purpose of clarification,you are advised to
reconfirm your Full Names,Direct Telephone
Numbers,Physical Address with Zip Code [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/22/billion-and-billions/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A sign of the times</title>
		<link>http://infosecblog.antonaylward.com/2008/08/22/a-sign-of-the-times/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/22/a-sign-of-the-times/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 13:48:18 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Social]]></category>

		<category><![CDATA[Standards]]></category>

		<category><![CDATA[(ISC)²]]></category>

		<category><![CDATA[Certified Information Systems Security Professional]]></category>

		<category><![CDATA[Information security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=153</guid>
		<description><![CDATA[It seems that many people in HR don&#8217;t realise that the interview is a two-way street.  Not only are they trying to find out if the candidate is suitable, but the candidate wants to know about the position, the firm, the job and the people he will be working with.  The most sucessful [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/22/a-sign-of-the-times/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Why would anyone choose Linux when they already have Windows?</title>
		<link>http://infosecblog.antonaylward.com/2008/08/20/why-would-anyone-choose-linux-when-they-already-have-windows/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/20/why-would-anyone-choose-linux-when-they-already-have-windows/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 12:39:41 +0000</pubDate>
		<dc:creator>antonaylward</dc:creator>
		
		<category><![CDATA[Incoming]]></category>

		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Mark Shuttleworth]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[WordPerfect]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=147</guid>
		<description><![CDATA[http://blogs.techrepublic.com.com/window-on-windows/?p=760&#38;tag=nl.e101
I could go through a litany of complaints I have about Linux. I could
complain about the confusing number of distributions. I could complain
about the propensity of Linux proponents to cause unnecessary confusion
by abbreviating or using acronyms for Linux-only functions. I could
complain about the silly confusing names they give applications.
How come Linux gets berated for this?
There&#8217;s [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/20/why-would-anyone-choose-linux-when-they-already-have-windows/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Passwords Suck!</title>
		<link>http://infosecblog.antonaylward.com/2008/08/14/passwords-suck/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/14/passwords-suck/#comments</comments>
		<pubDate>Thu, 14 Aug 2008 13:32:31 +0000</pubDate>
		<dc:creator>antonaylward</dc:creator>
		
		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Rants and Raves]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Client]]></category>

		<category><![CDATA[Gene Spafford]]></category>

		<category><![CDATA[IPhone]]></category>

		<category><![CDATA[Passphrase]]></category>

		<category><![CDATA[Password]]></category>

		<category><![CDATA[Password strength]]></category>

		<category><![CDATA[Rick Smith]]></category>

		<category><![CDATA[Secure Shell]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=145</guid>
		<description><![CDATA[http://techbuddha.wordpress.com/2008/08/13/passwords-suck/
Indeed they do.
Its beginning to look like the point I&#8217;ve been trying to make for years, here and with clients, is finally getting some notice.  That the sad real truth is that passwords are security theatre.  They  provide the
illusion that you&#8217;re securing something.
For those new here, I&#8217;ve long recommended Rick Smith&#8217;s excellent [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/14/passwords-suck/feed/</wfw:commentRss>
		</item>
		<item>
		<title>‘Fakeproof’ e-passport</title>
		<link>http://infosecblog.antonaylward.com/2008/08/08/fakeproof-e-passport/</link>
		<comments>http://infosecblog.antonaylward.com/2008/08/08/fakeproof-e-passport/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 11:29:44 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Law]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Fingerprint]]></category>

		<category><![CDATA[Passport]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=136</guid>
		<description><![CDATA[
My collegue Sami O. Koskinen said &#8220;I always felt like the new biometric passport is just a show&#8221; and I have to agree with him.  He also has reservations about  the idea of building a national fingerprint database covering all citizen, and I would think visitors to a country.  He points out [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/08/08/fakeproof-e-passport/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Why San Francisco’s network admin went rogue</title>
		<link>http://infosecblog.antonaylward.com/2008/07/19/why-san-franciscos-network-admin-went-rogue/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/19/why-san-franciscos-network-admin-went-rogue/#comments</comments>
		<pubDate>Sat, 19 Jul 2008 11:07:59 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Crime]]></category>

		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Social]]></category>

		<category><![CDATA[Terry Childs]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=123</guid>
		<description><![CDATA[http://www.infoworld.com/archives/emailPrint.jsp?R=printThis&#38;A=/article/08/07/18/30FE-sf-network-lockout_1.html
To an auditor or anyone with security training this screams of a security risk.
One critical guy who has no backup. private and sole knowledge of the system, never takes vacations. arrogant and protective of his knowledge.
Its a classical case of what should be avoided.  There are no management controls in place.  He could [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/19/why-san-franciscos-network-admin-went-rogue/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Business Logic Flaws</title>
		<link>http://infosecblog.antonaylward.com/2008/07/18/business-logic-flaws/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/18/business-logic-flaws/#comments</comments>
		<pubDate>Sat, 19 Jul 2008 02:52:44 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Risk]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Social]]></category>

		<category><![CDATA[Standards]]></category>

		<category><![CDATA[Electronic mailing list]]></category>

		<category><![CDATA[FMEA]]></category>

		<category><![CDATA[owasp]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/2008/07/18/business-logic-flaws/</guid>
		<description><![CDATA[Toronto - OWASP
This month&#8217;s meeting was about layer 7 errors in web applications.  Trey Ford was a fast spoken Texan and gave some good examples.
The common thread, as I saw it, was that no amount of pen testing, no amount of risk analysis would have uncovered these flaws.  What they had in common [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/18/business-logic-flaws/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Best spam *ever* …</title>
		<link>http://infosecblog.antonaylward.com/2008/07/18/best-spam-ever/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/18/best-spam-ever/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 23:27:59 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Humour]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=115</guid>
		<description><![CDATA[Maybe I&#8217;m just punchy from dealing with too much real spam, but I found this hilarious.
Introducing&#8211;Penis Reduction Pills!
Shipped to you, not in the stereotypical plain brown wrapper, but in a
large box proudly labeled on all six sides.  Because you wouldn&#8217;t be
ordering them if you didn&#8217;t need them, right?  Just leave the bottle
around the [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/18/best-spam-ever/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Don’t print this out!  Its too long</title>
		<link>http://infosecblog.antonaylward.com/2008/07/18/dont-print-this-out/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/18/dont-print-this-out/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 12:40:03 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Risk]]></category>

		<category><![CDATA[Business Continuity Planning]]></category>

		<category><![CDATA[FMEA]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=110</guid>
		<description><![CDATA[BSI Germany have an extensive list of threats.
Comprehensive?  Well, pretty good.
The kind of thing that could keep a client&#8217;s IT staff occupied for weeks.   If they had hard copy to annotate and work with.
However it is bottom-up as opposed to top down, dealing with details (aka threats) rather than FMEA - failure [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/18/dont-print-this-out/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Not Microsoft’s fault?</title>
		<link>http://infosecblog.antonaylward.com/2008/07/17/not-microsofts-fault/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/17/not-microsofts-fault/#comments</comments>
		<pubDate>Thu, 17 Jul 2008 22:13:17 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Disk partitioning]]></category>

		<category><![CDATA[Encryption]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/?p=106</guid>
		<description><![CDATA[Data can leak from partially encrypted disks
&#8220;Information is spilling out from the encrypted region into the unencrypted region&#8221;
Help me here.  Why would you have an only partially encrypted drive?  Yes, that&#8217;s easy to set up with Linux where you have many partitions.  In fact failing to encrypt swap is a classical mistake.
But [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/17/not-microsofts-fault/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Motive isn’t necessary to convict</title>
		<link>http://infosecblog.antonaylward.com/2008/07/15/isnt-necessary-to-convic/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/15/isnt-necessary-to-convic/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 15:10:32 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Crime]]></category>

		<category><![CDATA[Law]]></category>

		<category><![CDATA[Social]]></category>

		<category><![CDATA[Alan Dershowitz]]></category>

		<category><![CDATA[motive]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/2008/07/15/isnt-necessary-to-convic/</guid>
		<description><![CDATA[http://government.zdnet.com/?p=3874
There&#8217;s an old joke about a man brought before the court for breaking and entering, not because he was caught in the commission of a crime but because he was found in possession of housebreaking tools - crowbars, glass-cutter and so forth.
When found guilty by the judge he said &#8220;well you better convict me for [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/15/isnt-necessary-to-convic/feed/</wfw:commentRss>
		</item>
		<item>
		<title>On Spies and inside knowledge</title>
		<link>http://infosecblog.antonaylward.com/2008/07/15/on-spies-and-inside-knowledge/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/15/on-spies-and-inside-knowledge/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 13:55:22 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Risk]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/2008/07/15/on-spies-and-inside-knowledge/</guid>
		<description><![CDATA[My friend and mentor, Donn Parker, observes:  
Build your security assuming that the enemy knows as much about
your security and what you are doing as you do.

The lesson of history, InfoSec, industry, literature, warfare and politics tells us this is so.
Chapter 13 of Sun Tzu&#8217;s great work, &#8220;On the use of Spies&#8220;, advises:
What enables [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/15/on-spies-and-inside-knowledge/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How magic might finally fix your computer -</title>
		<link>http://infosecblog.antonaylward.com/2008/07/10/how-magic-might-finally-fix-your-computer/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/10/how-magic-might-finally-fix-your-computer/#comments</comments>
		<pubDate>Thu, 10 Jul 2008 12:33:12 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Human Factors]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/2008/07/10/how-magic-might-finally-fix-your-computer/</guid>
		<description><![CDATA[http://redtape.msnbc.com/2008/07/cambridge-mass.html#posts
Charlatans don&#8217;t bother creating detailed schemes for deception. They
just have a feel for what fools people.
Its not about technology&#8230;
Bad guys have better people skills
Criminals usually don&#8217;t bother learning all the ins and out of the
technology they exploit &#8212; they simply learn enough to be dangerous. But
they spend endless hours understanding the people they plan to [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/10/how-magic-might-finally-fix-your-computer/feed/</wfw:commentRss>
		</item>
		<item>
		<title>When did you last update your browser?</title>
		<link>http://infosecblog.antonaylward.com/2008/07/03/when-did-you-last-update-your-browser/</link>
		<comments>http://infosecblog.antonaylward.com/2008/07/03/when-did-you-last-update-your-browser/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 12:57:48 +0000</pubDate>
		<dc:creator>Anton Aylward</dc:creator>
		
		<category><![CDATA[Failures]]></category>

		<category><![CDATA[Risk]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecblog.antonaylward.com/2008/07/03/when-did-you-last-update-your-browser/</guid>
		<description><![CDATA[http://www.theregister.co.uk/2008/07/03/browser_insecurity_survey/
I gather than flaws browsers account for a lot of attacks, arising from malware and spyware that gets &#8217;snuck in&#8217; by various methods such as XSS.
Lets be realistic, though; the browser isn&#8217;t the only avenue by which a user&#8217;s workstation can be infected - I&#8217;ll leave servers out of this for the moment.  Updating [...]]]></description>
		<wfw:commentRss>http://infosecblog.antonaylward.com/2008/07/03/when-did-you-last-update-your-browser/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
