<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityCurve</title>
	<atom:link href="http://www.securitycurve.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitycurve.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 22:22:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Post Virtualization Security</title>
		<link>http://www.securitycurve.com/wordpress/archives/5140?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=5140</link>
		<comments>http://www.securitycurve.com/wordpress/archives/5140#comments</comments>
		<pubDate>Tue, 24 Jan 2012 13:44:20 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Cloud security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=5140</guid>
		<description><![CDATA[As the second law of thermodynamics tells us, all things trend toward chaos and this is no less true with a virtual environment. Sprawl can have a real security impact, and it takes discipline and planning to control sprawl &#8212; discipline and planning that won&#8217;t occur without someone from the security team actively monitoring the [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><blockquote><p>As the second law of thermodynamics tells us, all things trend toward chaos and this is no less true with a virtual environment. Sprawl can have a real security impact, and it takes discipline and planning to control sprawl &#8212; discipline and planning that won&#8217;t occur without someone from the security team actively monitoring the problem and formulating strategies for how to address the issue.</p>
<p>VVirtualization has been one of the most rapidly and widely adopted technologies in recent memory. It&#8217;s huge, and it&#8217;s here to stay.</p>
<p>And as security professionals know, setting up a virtual environment securely isn&#8217;t easy. Significant effort goes into tasks like evaluating off-premise service providers, ensuring regulatory compliance, and standing up technical controls like monitoring and encryption. But in the excitement to stand up the new environment and get security to an acceptable &#8220;target state,&#8221; organizations sometimes don&#8217;t address security hygiene long-term. In other words, security is in high gear while the environment spins up, but it doesn&#8217;t lay the groundwork for what happens once things are chugging along.</p></blockquote>
<p>Read the rest of Ed&#8217;s article over at <a href="http://www.ecommercetimes.com/story/74250.html" target="_blank">E-Commerce Times</a>.</p>
<div class="shr-publisher-5140"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5140' data-shr_title='Post+Virtualization+Security'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5140' data-shr_title='Post+Virtualization+Security'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/5140/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using HIPAA To Advance Your Security Initiative</title>
		<link>http://www.securitycurve.com/wordpress/archives/5133?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=using-hipaa-to-advance-your-security-initiative</link>
		<comments>http://www.securitycurve.com/wordpress/archives/5133#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:06:12 +0000</pubDate>
		<dc:creator>Diana</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[SC in the news]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=5133</guid>
		<description><![CDATA[[Excerpted from "Security Via HIPAA Compliance," a new report By Diana Kelley and Ed Moyle, posted on Dark Reading's Compliance Tech Center.] Healthcare compliance requirements can be a driver to improve your organization&#8217;s overall security. Here&#8217;s how: If your security organization is in the healthcare space, you inevitably are wrestling with the Healthcare Information Portability [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><em>[Excerpted from "Security Via HIPAA Compliance," a new report By Diana Kelley and Ed Moyle, posted on Dark Reading's Compliance Tech Center.]</em></p>
<p>Healthcare compliance requirements can be a driver to improve your organization&#8217;s overall security. Here&#8217;s how:    </p>
<blockquote><p>
If your security organization is in the healthcare space, you inevitably are wrestling with the Healthcare Information Portability and Accountability Act (HIPAA). HIPAA compliance is one of the biggest challenges healthcare IT organizations face &#8212; but it also could be an opportunity to advance your security agenda.</p>
<p>For security professionals to leverage compliance investment and activities for broader benefit, they must understand what’s driving current compliance investment.</p>
<p>First, it bears saying that the standards outlined in the HIPAA Security Rule are designed to address broad swaths of industry—from small clinics and physician offices to the largest institutional care providers and insurance companies. Because of this, the high-level security control objectives outlined in the Security Rule (standards) as well as the supporting controls are extremely broad and lacking in technical specificity.</p>
<p>How can security organizations make use of compliance activities?</p></blockquote>
<p>Check out the rest of the excerpt at <a href="http://www.darkreading.com/compliance/167901112/security/security-management/232400364/using-hipaa-to-advance-your-security-initiative.html" target="_blank">Dark Reading</a> or download the entire report at the <a href="http://www.darkreading.com/tech-center/10/Compliance.html" target="_blank">DR Compliance Tech Center</a>. </p>
<div class="shr-publisher-5133"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5133' data-shr_title='Using+HIPAA+To+Advance+Your+Security+Initiative'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F5133' data-shr_title='Using+HIPAA+To+Advance+Your+Security+Initiative'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/5133/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thoughts on free security tools to assist in cloud migration via the Savvis blog</title>
		<link>http://www.securitycurve.com/wordpress/archives/4970?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=thoughts-on-free-security-tools-to-assist-in-cloud-migration-via-the-savvis-blog</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4970#comments</comments>
		<pubDate>Wed, 21 Dec 2011 18:12:57 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[SC in the news]]></category>
		<category><![CDATA[Savvis]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4970</guid>
		<description><![CDATA[So I have a few humble thoughts about free security tools over on the Savvis Blog that you as a cloud customer can use to fill in gaps that sometimes occur during a transition to a cloud environment.  I won&#8217;t reproduce the content here, but wanted to pass along the link. You can check it [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/Cloud.jpg" rel="lightbox[4970]"><img class="alignright size-full wp-image-4974" title="Cloud" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/Cloud.jpg" alt="" width="100" height="80" /></a></p>
<p>So I have a few humble thoughts about free security tools over on the <a href="http://blog.savvis.net/" target="_blank">Savvis Blog</a> that you as a cloud customer can use to fill in gaps that sometimes occur during a transition to a cloud environment.  I won&#8217;t reproduce the content here, but wanted to pass along the link.</p>
<p>You can check it out on the Savvis blog at <a href="http://blog.savvis.com/2011/12/5-free-cloud-security-tools.html" target="_blank">this link</a>.  It&#8217;s entitled, &#8220;<em>5 free security tools every cloud user should know about</em>&#8220;.</p>
<p>Image source: savvis.com</p>
<div class="shr-publisher-4970"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4970' data-shr_title='Thoughts+on+free+security+tools+to+assist+in+cloud+migration+via+the+Savvis+blog'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4970' data-shr_title='Thoughts+on+free+security+tools+to+assist+in+cloud+migration+via+the+Savvis+blog'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4970/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chrome &#8220;most secure&#8221;?  Depends on your frame of reference&#8230;</title>
		<link>http://www.securitycurve.com/wordpress/archives/4966?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=chrome-most-secure-depends-on-your-frame-of-reference</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4966#comments</comments>
		<pubDate>Tue, 20 Dec 2011 15:20:29 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Accuvant]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Chrome]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4966</guid>
		<description><![CDATA[In interesting research news, there&#8217;s a paper out from Accuvant that attempts to compare the relative security merits of the &#8220;big three&#8221; browsers: Chrome, FireFox and Internet Exploder Explorer.  It&#8217;s an interesting read, so I suggest checking it out. Now, I admit that I was skeptical when I first started reading it.  Not only can [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/Chrome-1st-birthday-cake.png" rel="lightbox[4966]"><img class="alignright size-medium wp-image-4967" title="Chrome-1st-birthday-cake" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/Chrome-1st-birthday-cake-300x207.png" alt="" width="300" height="207" /></a></p>
<p>In interesting research news, there&#8217;s a <a href="http://www.zdnet.com/blog/security/new-study-claims-that-chrome-is-the-most-secure-browser/9839" target="_blank">paper out from Accuvant</a> that attempts to compare the relative security merits of the &#8220;big three&#8221; browsers: Chrome, FireFox and Internet <del datetime="2011-12-19T21:51:00+00:00">Exploder </del>Explorer.  It&#8217;s an interesting read, so I suggest <a href="http://www.accuvant.com/sites/default/files/images/webbrowserresearch_v1_0.pdf" target="_blank">checking it out</a>.</p>
<p>Now, I admit that I was skeptical when I first started reading it.  Not only can the &#8220;which product is more secure&#8221; evaluations be a little spurious, but this particular report is also actually sponsored by Google, so&#8230; well&#8230; you can see how one might wonder about that&#8230;  At least without a deeper dive.</p>
<p>However, after reading it in more depth, I think they&#8217;ve done a reasonable job in impartially analyzing the question in their scope.  In other words in analyzing the &#8220;software security&#8221; side of the argument &#8211; put another way, the resistance of the product to attack via coding or software architecture vulnerability.  Note that&#8217;s not the same as security features &#8212; or security of the product overall.  Security features are another matter entirely.  But I think it&#8217;s useful to bring it up because the industry press coverage doesn&#8217;t really seem to be discriminating between the two.  And they really are different questions.</p>
<p>As an example of what I mean by this, consider the SSL/TLS implementation of the various browsers.  This isn&#8217;t in the scope of the Accuvant analysis (since it doesn&#8217;t directly relate to attack resilience)&#8230; but it would be relevant, I&#8217;d think, to the broader &#8220;which is more secure&#8221; question.  Like, I&#8217;ve griped in the past about the fact that <a href="http://www.securitycurve.com/wordpress/archives/3723" target="_blank">until recently Chrome supported SSL 2.0</a> by default (seems like a major no-no in my humble opinion) and the fact that FireFox is the only one of the big three to have OCSP checking enabled by default (again, haven&#8217;t looked at these settings in a while so maybe this is a moving target in light of the <a href="http://www.securitycurve.com/wordpress/archives/4626" target="_blank">certifipocolypse </a>a while back).  These aspects of &#8220;brows<strong>ing</strong> security&#8221; (note how that&#8217;s  different from &#8220;brows<strong>er</strong> security&#8221; &#8211; at least as evaluated through resistance to software-directed attack) would have been a &#8220;score one&#8221; for FireFox in my estimation.</p>
<p>But again&#8230; not in the scope of their analysis.</p>
<p>So the point is: I&#8217;m impressed with the fact that they&#8217;ve tried to come up with an actual methodology to evaluate the security of the underlying codebase.  And I&#8217;m also interested in their conclusion.  Although I&#8217;d recommend sticking close to their actual research vs. how the industry press seems to be spinning it.</p>
<p>Image source: itsalltech.com</p>
<div class="shr-publisher-4966"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4966' data-shr_title='Chrome+%22most+secure%22%3F++Depends+on+your+frame+of+reference...'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4966' data-shr_title='Chrome+%22most+secure%22%3F++Depends+on+your+frame+of+reference...'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4966/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CA Baseline Guidance&#8230; skeptical.</title>
		<link>http://www.securitycurve.com/wordpress/archives/4962?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ca-baseline-guidance-skeptical</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4962#comments</comments>
		<pubDate>Fri, 16 Dec 2011 19:44:39 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[X.509]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4962</guid>
		<description><![CDATA[In light of continued shenanigans in the CA community, apparently the CA/Browser forum has put out some guidelines for certificates that are going to be trusted by default in various browsers. The document is here if you want to check it out. I get it why the CA&#8217;s want this.  It&#8217;s important that people believe they&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/My_Authoritah_by_wareagle884.jpg" rel="lightbox[4962]"><img class="alignright size-medium wp-image-4963" title="My_Authoritah_by_wareagle884" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/My_Authoritah_by_wareagle884-300x229.jpg" alt="" width="300" height="229" /></a></p>
<p>In light of <a href="http://searchsecurity.techtarget.com/news/2240112681/GlobalSign-hack-update-Certificate-authority-finds-no-rogue-certs" target="_blank">continued shenanigans in the CA community</a>, apparently the <a href="http://news.hitb.org/content/industry-group-creates-guidelines-issuing-ssl-certs" target="_blank">CA/Browser forum has put out some guidelines</a> for certificates that are going to be trusted by default in various browsers.</p>
<p>The <a href="http://www.cabforum.org/Baseline_Requirements_V1.pdf" target="_blank">document is here</a> if you want to check it out.</p>
<p>I get it why the CA&#8217;s want this.  It&#8217;s important that people believe they&#8217;re taking action.  It&#8217;s an entry-heavy, low-maintenance business.  Meaning, you invest a lot in the beginning and milk it over a long period of time.  But yet, there&#8217;s no reason why CA&#8217;s <em>have to</em> exist.  The exist right now because of inertia; because it&#8217;s easier to go with the status quo than it is to change the way the process works.</p>
<p>There&#8217;s no<em> technical reason</em> why another approach couldn&#8217;t work equally well or better (it does for PGP).  Ripping down the underpinnings now is a perfectly viable option &#8211; and one CA&#8217;s <span style="text-decoration: underline;">really</span> don&#8217;t want.  Because changing it would choke the revenue stream of the long-time players and would mean that newer players may not even recoup their outlay.</p>
<p>But yet&#8230; the guidelines.  First, it&#8217;s a <em>voluntary</em> industry association.  Their only enforcement authority is in getting the browser folks to require an audit that conforms to this.  From the <a href="http://www.cabforum.org/Announcement-Baseline_Requirements.pdf" target="_blank">press release</a>:</p>
<blockquote><p>Following adoption of Version 1.0 of the Baseline Requirements, the CA/Browser Forum will request that all browser and relying party application software developers incorporate the Baseline Requirements into their accreditation and approval schemes as requirements for all applicants who request that a selfsigned root certificate be embedded as a trust anchor in their software.  The CAB Forum also intends that the ETSI ESI Committee and AICPA/CICA Task Force on the WebTrust Program for CAs will coordinate revisions to their respective audit standards such that the Baseline Requirements will become auditable requirements starting in June 2011.</p></blockquote>
<p>Yes, yes.  I&#8217;m sure everybody with a browser or utility SSL implementation are going to immediately comply&#8230; And as to what it addresses?  Not enough.  On the plus side, they realize this:</p>
<blockquote><p>CA and browser members of the CAB Forum acknowledge that the current version lacks provisions in some key areas, and they anticipate working in the coming months to overcome these deficiencies.</p></blockquote>
<p>That&#8217;s an understatement &#8211; like a &#8220;hurricanes might bring humidity&#8221; kind of understatement.  But at least they get it that it&#8217;s missing stuff.</p>
<p>All in all, I have mixed feelings.  I&#8217;m not the kind of guy who&#8217;s into changing stuff just because&#8230; but there really are some serious flaws in both the technical and business sides of the CA infrastructure that foster low assurance.  And this document doesn&#8217;t change any of those things.  The financial incentive for CA&#8217;s to have poor security (to drive price competition) is still there &#8211; it arguably just raises the bar a little bit.  Now, the financial incentive (assuming browser folks require this) is to be <em>just </em>close enough to compliance to minimize costs.  I.e., to stay as close to&#8221;not compliant&#8221; as their auditors will let them.  I&#8217;m not sure that&#8217;s going to solve the problem.</p>
<p>I&#8217;ll wait to see what future revisions have in store, but in the meantime I&#8217;m skeptical.</p>
<p>Image Source: freerepublic.com</p>
<div class="shr-publisher-4962"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4962' data-shr_title='CA+Baseline+Guidance...+skeptical.'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4962' data-shr_title='CA+Baseline+Guidance...+skeptical.'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4962/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chatting with an auditor about credit unions</title>
		<link>http://www.securitycurve.com/wordpress/archives/4956?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=chatting-with-an-auditor-about-credit-unions</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4956#comments</comments>
		<pubDate>Thu, 15 Dec 2011 01:21:47 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Credit Unions]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4956</guid>
		<description><![CDATA[So if you recall, I received an inquiry the other day to take a bit further my post where I was quacking about credit unions. As a refresher, the gist of that discussion was that I found it to be somewhat lame that credit unions were complaining about how they have stringent technical controls whereas [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/251a10f960a51034a15e7af4a29f7e99.jpg" rel="lightbox[4956]"><img class="alignright size-medium wp-image-4957" title="251a10f960a51034a15e7af4a29f7e99" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/251a10f960a51034a15e7af4a29f7e99-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>So if you recall, I received an inquiry the other day to take a bit further my post <a href="http://www.securitycurve.com/wordpress/archives/4918" target="_blank">where I was quacking about credit unions</a>.</p>
<p>As a refresher, the gist of that discussion was that I found it to be somewhat lame that credit unions were complaining about how they have stringent technical controls whereas merchants don&#8217;t. My meta-point was that merchants (at least for card-based payments) have some very stringent (i.e. technically prescriptive) security controls by virtue of PCI compliance.  Credit unions, on the other hand, by virtue of their regulatory context, have more &#8220;interpretive latitude&#8221; in how technical security controls get implemented.  Meaning, they should try on PCI compliance before calling out merchants (especially the big ones) for having it soft.</p>
<p>To get some additional context on this point, I reached out to a former colleague who&#8217;s now an auditor for credit unions and community banks.  I&#8217;ll keep his name off the record &#8211; not because he asked me to necessarily, but because he asked that I not identify his employer&#8230; and anybody with a browser and a linkedin account can look at my background, guess who he might be, and determine his place of employment.  So let&#8217;s just call him &#8220;Papa&#8221; &#8211; for &#8220;Papa Smurf&#8221;, his nickname when we worked together.  Anyway, mega-thanks to him for going through this with me.</p>
<p>Anyway, below is the record of the discussion I had with him.  I&#8217;ll pull out some of the material that I think highlights or negates my point from earlier in a subsequent post (since we really got into detail and covered a lot of ground in our discussion):</p>
<p><strong>Can you briefly describe the type of work that you do with credit unions?</strong></p>
<p>Typically under contract, what we do is a full-scope risk assessment.  Under the current regulations, a credit union, unlike a bank, does not have to have an IT audit.  They are instead required to have an “IT risk assessment”.  This risk assessment looks at approximately 27 control objectives that come out of COBIT.  The objective is the same as an audit &#8211; the difference is that during a risk assessment, you don’t collect work papers and the client is responsible to complete specific areas of a risk assessment themselves.</p>
<p>We have credit unions that request an IT audit over and above a risk assessment.  Audit is basically a “black &amp; white” evaluation exercise (you either “have it” or you don’t – you meet the bar or you do not); An IT Audit is based on COBIT, a methodology from ISACA (Information Systems Audit and Control Association) to evaluate the controls  and how they comply with the FFIEC IT Audit guidelines.  A risk assessment on the other hand is based on the National Institute of Standards and Technology’s (NIST) Special Publication 800-30 and follows the guidance provided in the FFIEC Information Security Booklet to evaluate the risks and safeguards in place to support the bank or credit unions Information Security Program.</p>
<p><strong>How many banks and credit unions would you say you’ve worked with in the past two years?</strong></p>
<p>Probably around 24.  About one per month.</p>
<p><strong>What specifically is required of a bank or credit union with respect to security controls?  What standards do they need to adhere to?  </strong></p>
<p>Credit unions are regulated by the NCUA (National Credit Union Association).  The difference is that credit unions are non-profit.  Regulatory-wise, there’s no difference between a credit union and a bank and from a financial aspect, they both provide services to customers/members and the business community such as loans (car, mortgages), savings, checking, etc.  The FFIEC is the inter-agency chartered to provide guidance to all banking institutions.  FFIEC includes OCC, FRB, Federal Deposit, and the NCUA.  It also used to provide governance to OTS, but that’s gone because there are very few thrifts ( savings and loans &#8211; think: “It’s a Wonderful Life”).</p>
<p>In terms of our risk assessments, we take into account items from COBIT as well as guidance from PCAOB in addition to industry best practices.  We use  best practices because they change faster due to technology and procedure than the guidance from the FFIEC and elsewhere.  The fact that it is not FFIEC guidance, doesn’t mean it’s not useful for these organization to consider.  For example, we sometimes use the PCI DSS as a best practice guideline for what these organizations should look to from a best practices standpoint.  The DSS has straightforward questions looking for straightforward responses.</p>
<p><strong>What’s the role of the FFIEC examiner handbook?  How much teeth do those controls have?  How do those rules compare to PCI DSS? </strong></p>
<p>FFIEC guidance is high level in terms of technical content.  While it is called ‘guidance’ they are standards and the banks and credit unions must comply with the guidance. They are examined using the FFIEC as the source document for compliance.  PCI is not a regulatory requirement – it is private enterprise (Visa, MC, Amex) that established specific rules that a card issuer/merchant must follow.  That doesn’t mean that nothing goes wrong – all you need to do is look at the  TJ Max and Hannaford incidents.  Under PCI, card issuers/merchants  are required to comply to the requirements and have an annual PCI audit done by persons certified directly by PCI. More than that, I am not sure – nothing in the PCI documentation indicates you will lose your right to be a card merchant but there must be some ramifications.</p>
<p><strong>What happens when a credit union doesn’t comply? </strong></p>
<p>When a credit union is being examined by the NCU, assuming a  full-scope exam, it would include all areas of IT including BCP/DR, handling of member (customer) information, data at rest/in transit, user (employee) access controls, and LAN/WAN networking.  .  However, in the past few years, my take has been that they are focusing more attention on the financial  side rather than IT.  So when it comes to IT – the credit union gets a pass because areas were not examined but that doesn’t mean when we do an audit or risk assessment we will let it pass – we cannot because of the COBIT, NIST, FFIEC, and other guidance factors.</p>
<p>FFIEC guidance – even though it’s guidance – is required for these organizations to meet it.  Incident response for example, is a requirement.  But there’s some interpretive latitude relative to the degree or depth of that plan.</p>
<p><strong>Is there any “wiggle room” when an organization can’t meet the guidance? </strong></p>
<p>The rule of thumb I use relative to Incident Response is a clause in the FFIEC guidance that speaks to “size and complexity”.  A smaller credit union might not have the same level of technical expertise, IT staffing, or funds to purchase something like enCase (the forensic product) to do investigations; they might not have the money to support it, to train users, licensing fees, etc. – you have to measure their response plan and ability to support it based on what makes sense for an organization their size.</p>
<p>However, BCP/DR for example, requires a  recovery and a continuity plan.  They have to have a plan in place.  On the other hand, there is no regulatory requirement for a bank to have a generator.  When I got into this line of work, I thought there was because it makes sense.  However, there isn’t.  When you have a power outage in an area, you’re not opening your doors.  There’s guidance and then there’s a flaw in the guidance.  There are some that do, but many banks and credit unions do not.</p>
<p><strong>What’s the role of GLBA?</strong></p>
<p>GLBA says that customer information (name, ssn, etc.) otherwise referred to as non-public personal information and it must be protected.  This is information that is not commonly found such as in a telephone bill, a telephone book, or a car rental agreement.  The primary objective of an information security risk assessment is to identify, evaluate, and prioritize threats to information assets and vulnerabilities in the control environment.  The risk assessment represents the foundation of the Information Security Program and is an ongoing process that highlights needed program enhancements.</p>
<p>This entire process requires the bank/credit union to have appropriate policy and procedures in place to provide guidance to all employees on how to handle and control customer (member) information.</p>
<p>Not having formal policy, but having documented procedures isn’t great, but it is a start.  The Board of Directors are expected to develop, or have developed for the bank/credit union, policies that they, the BOD are required to review, and approve and have implemented.  If they don’t, they cannot protect the information properly and I would write it up  a high or medium priority in a risk assessment I’m doing.</p>
<p>Protection of all media (optical, magnetic, or paper) at rest (sitting in a cabinet or database) or in transit (sent from main office to backupsite, etc.) has to be protected as well.  It must be secured such that only persons who need access to it, do.  This is commonly referred to as the rule of least privilege.   I did one audit for example where regulatory required documentation was stored in one central room and a number of individuals had access.  They stored non-perishable foods, holiday decorations, etc. in the same room.  That was an issue.  The paper materials should be in a secured location – either in a secured desk, locked room, cabinet, etc.</p>
<p>&nbsp;</p>
<div class="shr-publisher-4956"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4956' data-shr_title='Chatting+with+an+auditor+about+credit+unions+'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4956' data-shr_title='Chatting+with+an+auditor+about+credit+unions+'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4956/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-Commerce Times: An InfoSec Holiday Survival Guide</title>
		<link>http://www.securitycurve.com/wordpress/archives/4953?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=e-commerce-times-an-infosec-holiday-survival-guide</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4953#comments</comments>
		<pubDate>Thu, 15 Dec 2011 00:25:13 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[SC in the news]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4953</guid>
		<description><![CDATA[This month for eCommerce Times, I outline a few strategies for planning ahead of time for security resource dropoff during the holidays: The end of the year is one of the riskiest times for information security. Attack levels rise right at the time IT staff attendance typically takes a dip. Adjusting to this critical period [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/security.jpg" rel="lightbox[4953]"><img class="alignright size-full wp-image-4954" title="security" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/security.jpg" alt="" width="172" height="124" /></a></p>
<p>This month for eCommerce Times, I outline a few strategies for planning ahead of time for security resource dropoff during the holidays:</p>
<blockquote><p>The end of the year is one of the riskiest times for information security. Attack levels rise right at the time IT staff attendance typically takes a dip. Adjusting to this critical period isn&#8217;t easy, but collecting the right information now can help you take a better course of action when this season rolls around next year.</p></blockquote>
<p>If it sounds interesting to you, check out the full article <a href="http://www.ecommercetimes.com/story/73962.html" target="_blank">here</a>.</p>
<div class="shr-publisher-4953"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4953' data-shr_title='E-Commerce+Times%3A+An+InfoSec+Holiday+Survival+Guide'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4953' data-shr_title='E-Commerce+Times%3A+An+InfoSec+Holiday+Survival+Guide'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4953/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Wallet, cardholder data, and the edge of PCI?</title>
		<link>http://www.securitycurve.com/wordpress/archives/4949?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-wallet-cardholder-data-and-the-edge-of-pcis-regulatory-map</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4949#comments</comments>
		<pubDate>Wed, 14 Dec 2011 01:56:09 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Payments]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4949</guid>
		<description><![CDATA[So today we have some excellent coverage via the always-interesting Mocana DeviceLine blog (have I blog-rolled them enough do you think?) covering a technical deep-dive on Google Wallet from ViaForensics.  An interesting read. According to their inquiry of how Google Wallet works, they&#8217;ve determined that there&#8217;s some scary data stored cleartext on the phone, including: Card [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/iObject___Edgeworth_by_GyakutenPhoenix.jpg" rel="lightbox[4949]"><img class="alignright size-medium wp-image-4950" title="iObject___Edgeworth_by_GyakutenPhoenix" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/iObject___Edgeworth_by_GyakutenPhoenix-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>So today we have some <a href="https://mocana.com/blog/2011/12/13/google-wallet-app-stores-unencrypted-data/" target="_blank">excellent coverage via the always-interesting Mocana DeviceLine blog</a> (have I blog-rolled them enough do you think?) covering a <a href="http://viaforensics.com/mobile-security/forensics-security-analysis-google-wallet.html" target="_blank">technical deep-dive on Google Wallet</a> from ViaForensics.  An interesting read.</p>
<p>According to their inquiry of how Google Wallet works, they&#8217;ve determined that there&#8217;s some scary data stored cleartext on the phone, including:</p>
<ul>
<li>Card type and last 4</li>
<li>Card holder name</li>
<li>Current balance</li>
<li>Available to spend</li>
<li>Statement balance</li>
<li>Payment due date</li>
<li>Citi contact number</li>
</ul>
<p>Well, that&#8217;s interesting. Folks might object to this kind of data being stored in cleartext within Google Wallet (I sure do), but I&#8217;d like to point out that the problem isn&#8217;t so much Google Wallet (although, guys&#8230; really?  Statement Balance?  Really?)  but instead the fact that mobile devices are blurring the lines between what&#8217;s a payment application vs. what&#8217;s not.</p>
<p>You see, right now, shy of actually storing the whole credit card number, there&#8217;s not really much guidance on what is or is not acceptable here from a protection standpoint.  Technically, Google Wallet falls into what the <a href="https://www.pcisecuritystandards.org/documents/pa-dss_mobile_apps-faqs.pdf" target="_blank">standards council has defined</a> as a &#8220;Category 3 Payment Acceptance Application.&#8221;  What is a Category 3 mobile payment acceptance application, you ask? Per the council:</p>
<blockquote><p>Payment application operates on any consumer electronic handheld device (e.g., smart phone, tablet, or PDA) that is not solely dedicated to payment acceptance for transaction processing.</p></blockquote>
<p>Sounds like Google Wallet, amirite?  So how do you validate such an application?  For example say Google wants to do the right thing and have someone review their app to avoid these kinds of shenanigans&#8230; to ensure that the security of the application is consistent with the defined requirements of PCI?  Short answer: you can&#8217;t.  Longer answer &#8212;  from the council:</p>
<blockquote><p>The PCI SSC recommends that mobile payment acceptance applications that fit into Category 3—and are thus not eligible for PA-DSS validation at this time but are intended for use in the cardholder data environment—are developed using PA-DSS as a baseline for protection of payment card data and in support of PCI DSS compliance.</p></blockquote>
<p>OK, so you can&#8217;t validate it.  They recommend that you maybe skim through the PA-DSS to check out how to protect cardholder data from an application standpoint, but it&#8217;s discretionary&#8230; So you can&#8217;t validate to PA-DSS.  Unfortunate.  So what is the oversight for these apps? Who&#8217;s responsible?  From the same document:</p>
<blockquote><p>Applications used for payment-initiation—for example, those downloaded by consumers onto their mobile phones and used for consumers’ personal shopping—are seen as similar to the payment card in a consumer’s wallet. The Council’s purview does not currently extend to, nor is PA-DSS applicable to, consumer-facing mobile payment initiation applications.</p></blockquote>
<p>And there you have it.  My reading of this is that &#8212; at least currently &#8212; the expectation that we should have for security of &#8220;consumer-facing mobile payment initiation applications&#8221; is the goose-egg.  In other words, Google didn&#8217;t cross a regulatory boundary.  One might argue that there <em>should be</em> a regulatory boundary here&#8230; but if there is, I can&#8217;t find it.</p>
<p>Anybody disagree?  Would love to hear from a PA-QSA on this.</p>
<p>Image source: gyakutenphoenix.deviantart.com</p>
<div class="shr-publisher-4949"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4949' data-shr_title='Google+Wallet%2C+cardholder+data%2C+and+the+edge+of+PCI%3F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4949' data-shr_title='Google+Wallet%2C+cardholder+data%2C+and+the+edge+of+PCI%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4949/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Was two-factor broken?  I beg to differ</title>
		<link>http://www.securitycurve.com/wordpress/archives/4942?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=was-two-factor-broken-i-beg-to-differ</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4942#comments</comments>
		<pubDate>Tue, 13 Dec 2011 01:03:13 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Two-factor]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4942</guid>
		<description><![CDATA[So the other day I came across this article that proudly pronounced &#8220;fraudsters defeat two-factor&#8221; as well as an extremely lucid response via the WikID blog.  It&#8217;s worth reading the original article for folks implementing phone-based OOB two-factor authentication (since it highlights an interesting misuse-case) and it&#8217;s also worth reading the excellent follow-on piece that puts [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/Broken_heart_by_OanimeOluverO.png" rel="lightbox[4942]"><img class="alignright size-medium wp-image-4943" title="Broken_heart_by_OanimeOluverO" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/12/Broken_heart_by_OanimeOluverO-300x211.png" alt="" width="300" height="211" /></a></p>
<p>So the other day I came across this article that proudly pronounced <a href="http://www.net-security.org/secworld.php?id=12060" target="_blank">&#8220;fraudsters defeat two-factor&#8221;</a> as well as an extremely lucid response via the <a href="http://www.wikidsystems.com/WiKIDBlog/fraudsters-defeat-poor-risk-management-not-two-factor-authentication" target="_blank">WikID blog</a>.  It&#8217;s worth reading the original article for folks implementing phone-based OOB two-factor authentication (since it highlights an interesting misuse-case) and it&#8217;s also worth reading the excellent follow-on piece that puts it in perspective.</p>
<p>Anyway, I won&#8217;t belabor this point other than to point out that the WikID folks are right on the money, but for those folks who follow the two-factor market space and who missed this discussion, I thought it was worth calling attention to.</p>
<p>Image source: coolchaser.com</p>
<div class="shr-publisher-4942"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4942' data-shr_title='Was+two-factor+broken%3F++I+beg+to+differ'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4942' data-shr_title='Was+two-factor+broken%3F++I+beg+to+differ'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4942/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Administrivia: Comment foolishness at critical mass.  Moving to Disqus</title>
		<link>http://www.securitycurve.com/wordpress/archives/4883?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=administrivia-comment-foolishness-at-critical-mass-moving-to-disqus</link>
		<comments>http://www.securitycurve.com/wordpress/archives/4883#comments</comments>
		<pubDate>Wed, 07 Dec 2011 13:07:16 +0000</pubDate>
		<dc:creator>Ed</dc:creator>
				<category><![CDATA[Administrative]]></category>

		<guid isPermaLink="false">http://www.securitycurve.com/wordpress/?p=4883</guid>
		<description><![CDATA[Apologies to individuals who have tried to comment the past few days but have found themselves unable to. Bad news is that once again, WordPress unexpectedly reset the comment settings without a peep (leaving me in the dark until people started complaining about it.)  Good news is that this instance of that foolishness brought the situation to [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p><a href="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/11/Skryim-Trailer-Analysis-11-Troll.jpg" rel="lightbox[4883]"><img class="alignright size-medium wp-image-4884" title="Skryim-Trailer-Analysis-11-Troll" src="http://www.securitycurve.com/wordpress/wp-content/uploads/2011/11/Skryim-Trailer-Analysis-11-Troll-300x169.jpg" alt="" width="300" height="169" /></a></p>
<p>Apologies to individuals who have tried to comment the past few days but have found themselves unable to.</p>
<p>Bad news is that<strong> once again</strong>, WordPress unexpectedly reset the comment settings without a peep (leaving me in the dark until people started complaining about it.)  Good news is that this instance of that foolishness brought the situation to a head, giving me the motivation to move comments over to Disqus.  So there you have it: new comments, at Disqus.</p>
<p>Please to enjoy.</p>
<p>Image note: From the Skyrim trailer<a href="http://www.maximumpc.com/article/features/skyrim_trailer_analyzed_shot--shot" target="_blank"> shot-by-shot analysis</a> over at MaximumPC.  Get it?  Because&#8230; like it&#8217;s a troll&#8230; and, you know, comments&#8230; oh, never mind.</p>
<div class="shr-publisher-4883"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4883' data-shr_title='Administrivia%3A+Comment+foolishness+at+critical+mass.++Moving+to+Disqus'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.securitycurve.com%2Fwordpress%2Farchives%2F4883' data-shr_title='Administrivia%3A+Comment+foolishness+at+critical+mass.++Moving+to+Disqus'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.securitycurve.com/wordpress/archives/4883/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

