<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; mubix</title>
	<atom:link href="http://www.novainfosecportal.com/tag/mubix/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Mon, 06 Sep 2010 02:37:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New NoVA Group &#8211; NoVA Hackers Association</title>
		<link>http://www.novainfosecportal.com/2009/11/01/new-nova-group-nova-hackers-association/</link>
		<comments>http://www.novainfosecportal.com/2009/11/01/new-nova-group-nova-hackers-association/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 00:00:12 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[meetup]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[nova-dc-luncheon]]></category>
		<category><![CDATA[novahackers]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=2597</guid>
		<description><![CDATA[Well maybe not a totally new group &#8230; but one that @mubix and @carnal0wnage finally brought live. It looks like the site itself was created over on Blogger in April of 2008. But just just as we thought the site was going to wither away,  our fearless NoVA leaders  recently   started [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2604" title="novahackers" src="http://www.novainfosecportal.com/wp-content/uploads/2009/11/novahackers.png" alt="novahackers" width="72" height="72" />Well maybe not a totally new group &#8230; but one that <a href="http://twitter.com/mubix">@mubix</a> and <a href="http://twitter.com/carnal0wnage">@carnal0wnage</a> finally brought live. It looks like the site itself was created over on Blogger in April of 2008. But just just as we thought the site was going to wither away,  our fearless NoVA leaders  recently   started kicking each other into shape &#8230; and about 2 weeks ago seemed to have morphed the NoVA/DC Luncheon into this new association and created a <a href="http://groups.google.com/group/novahackers">related Google Group</a>.</p>
<p>Not much has happened on the <a href="http://novahackers.blogspot.com/">their Blogger site</a> yet but the discussion on Google immediately took off with over 400 posts and 64 members as I write this. Since this group is in the &#8220;forming&#8221; phase, most of the discussion is all about how this association is going to work, everyone doing introductions, and of course ShmooCon tickets. Currently, it looks like they are going to try to hold two events each month. One will be the traditional luncheon that @mubix has been organizing for the past year. The second event may be a more formal evening meetup with presentations and all.</p>
<p>Joining seems to be pretty similar to the <a href="http://en.wikipedia.org/wiki/Freemasonry">Freemasons</a>. You have to be invited by a current member or a current member has to invite you. Additionally, there seems to be a requirement to be active. @mubix and crew will be skimming membership every few months and deleting lurkers. I think these two controls will go a long way to helping stem the prevalence of spam. But please remember that they are still in the development stages of putting this thing together so the &#8220;rules&#8221; may  change over time.</p>
<p>You can find out more information on the NoVA Hackers Association on our <a href="/events/nova-meetups/#novahackers">NoVA Meetups</a> page. Also keep up to date and help morph this group into what it will be by visiting them over at their <a href="http://groups.google.com/group/novahackers">Google Group</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/11/01/new-nova-group-nova-hackers-association/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/08/17/top-3-nova-infosec-blog-posts-of-the-week-21/</link>
		<comments>http://www.novainfosecportal.com/2009/08/17/top-3-nova-infosec-blog-posts-of-the-week-21/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 15:00:44 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[geminisecurity]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[NoVA Bloggers]]></category>
		<category><![CDATA[richard-bejtlich]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security-career-advice]]></category>
		<category><![CDATA[security-careers]]></category>
		<category><![CDATA[voting-machine-security]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1951</guid>
		<description><![CDATA[While we love security news sites as much as the next person, we really love hearing from people in the local security community. That&#8217;s why we started our &#8220;Top 3 NoVA Infosec Blog Posts of the Week&#8221; feature; it lets us highlight the best of local security bloggers, and gives you the opportunity to read awesome security [...]]]></description>
			<content:encoded><![CDATA[<p>While we love security news sites as much as the next person, we really love hearing from people in the <a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">local security community</a>. That&#8217;s why we started our &#8220;Top 3 NoVA Infosec Blog Posts of the Week&#8221; feature; it lets us highlight the best of local security bloggers, and gives you the opportunity to read awesome security material produced by members of the local community.</p>
<p>If you&#8217;re a local security blogger that would like to be considered for this feature, please feel free to <a href="http://www.novainfosecportal.com/contact-us/">shoot us an email</a> or send us a tweet <a href="http://www.twitter.com/grecs">@grecs</a>. We also have a handy <a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">list</a> of local bloggers, so be sure to contact us if you aren&#8217;t already on the list!</p>
<p><strong>#3 &#8211; Election Woes</strong>: Just when you thought the election headache was over, <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> proves you wrong. Because while the election itself might be over, the controversy over voting machines is just beginning. In their post &#8220;AVC Advantage Attack,&#8221; @geminisecurity points out the fact that you can learn to hack a voting machine for around $20, and it&#8217;s a fairly simple task. That&#8217;s right: We are voting on machines that are not only easy to hack, but aren&#8217;t even regulated! Something tells us that George Washington is rolling over in his grave. Be sure to check out the full post <a href="http://securitymusings.com/article/1401/avc-advantage-attack">here</a>. </p>
<p><strong>#2 &#8211; Simple Security</strong>: We&#8217;ll be honest; this post got our attention before we even read it. With a title like &#8220;Simplicity is Security,&#8221; how could it not? Taking an interesting look at security by examining the use (or lack thereof) of debit and credit cards in Japan, <a href="http://www.twitter.com/mubix">@mubix</a> makes some excellent points about how our desire to jump on every technological advance that comes along is making it harder to have good security. After talking about how people in Japan usually don&#8217;t have credit cards, debit cards, or do any of their banking online, @mubix poses the following question to his readers: &#8220;Should we continue down the path of “MORE SECURITY” or should we deviate a bit for simpler, possibly non-technical practices?&#8221; While we can&#8217;t say that we totally agree with the route of non-technical practices, we do believe that there is a happy medium. To answer the question for yourself, why not check out the <a href="http://www.room362.com/archives/621-simplicity-is-security.html">full post</a>?<span id="more-1951"></span></p>
<p><strong>#1 &#8211; Careers in Security</strong>: With the current economy being what it is, career advice had become rather popular as of late. Richard Bejtlich of TaoSecurity jumped on the career advice train this week in his post &#8220;Thoughts on Security Careers.&#8221; Quoting a number of different posts that deal with popular career trends and career advice for security professionals, Bejtlich gives his own insight, tips, and tricks. Even if you&#8217;re not interested in leaving your current job for another, <a href="http://taosecurity.blogspot.com/2009/08/thoughts-on-security-careers.html">this post</a> is a must-read.</p>
<p>Well, that&#8217;s all for this week. Be sure to check back next week for more great reads from security professionals in your community.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/08/17/top-3-nova-infosec-blog-posts-of-the-week-21/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/08/10/top-3-nova-infosec-blog-posts-of-the-week-20/</link>
		<comments>http://www.novainfosecportal.com/2009/08/10/top-3-nova-infosec-blog-posts-of-the-week-20/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 18:00:58 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[gemini-security]]></category>
		<category><![CDATA[grecs]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[NoVA Bloggers]]></category>
		<category><![CDATA[richard-bejtlich]]></category>
		<category><![CDATA[rybolov]]></category>
		<category><![CDATA[sandboxie]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[taosecuirty]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1905</guid>
		<description><![CDATA[It&#8217;s that time of the week again when we bring you the best of local security blogs. But before we get to that, we thought we&#8217;d share our tweet of the week along with a #totw that deserves honorable mention to get your afternoon started with a few laughs.
Our official #totw was a RT by [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s that time of the week again when we bring you the best of <a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">local security blogs</a>. But before we get to that, we thought we&#8217;d share our tweet of the week along with a #totw that deserves honorable mention to get your afternoon started with a few laughs.</p>
<p>Our official #totw was a RT by <a href="http://www.twitter.com/mubix">@mubix</a>:</p>
<blockquote><p><span class="status-body"><a onclick="pageTracker._trackPageview('/exit/to/grecs');" href="http://twitter.com/grecs" target="_blank">grecs</a> <span id="msgtxt3104264498" class="msgtxt en">RT <a onclick="pageTracker._trackPageview('/exit/to/mubix')" href="http://twitter.com/mubix" target="_blank">@mubix</a> RT <a onclick="pageTracker._trackPageview('/exit/to/secureideas')" href="http://twitter.com/secureideas" target="_blank">@secureideas</a>: &#8220;When pen tester tells U they luv something, get it off yr network.&#8221; <a onclick="pageTracker._trackPageview('/exit/to/agent0x0')" href="http://twitter.com/agent0x0" target="_blank">@agent0&#215;0</a>: &#8220;I luv Sharepoint.&#8221; <a title="#defcon" href="http://twitter.com/search?q=%23defcon">#defcon</a> <a title="#totw" href="http://twitter.com/search?q=%23totw"><strong>#totw</strong></a></span></span></p></blockquote>
<p><span class="status-body"><span class="msgtxt en">Honorable mention belongs to this tweet by </span></span><span class="status-body"><span id="msgtxt3134284588" class="msgtxt en"><a onclick="pageTracker._trackPageview('/exit/to/technogeezer')" href="http://twitter.com/technogeezer" target="_blank">@technogeezer</a></span></span> because it&#8217;s so true!</p>
<blockquote><p><span class="status-body"><a onclick="pageTracker._trackPageview('/exit/to/grecs');" href="http://twitter.com/grecs" target="_blank">grecs</a> <span id="msgtxt3134284588" class="msgtxt en">LOL.. RT: <a onclick="pageTracker._trackPageview('/exit/to/technogeezer')" href="http://twitter.com/technogeezer" target="_blank">@technogeezer</a>: Someone here at CSC now refers to physical meetings as getting together in &#8216;meatspace&#8217; <a title="#totw" href="http://twitter.com/search?q=%23totw"><strong>#totw</strong></a></span></span></p></blockquote>
<p><span class="status-body"><span class="msgtxt en">Now, on to the posts!</span></span></p>
<p><strong>#3 &#8211; Lessons From the Sandbox</strong>: If you are  looking for great technical posts, <a href="http://www.twitter.com/geminisecurity">@geminisecurity</a> should be your first stop. Their latest post, &#8220;Protect Your Computer By Running Applications in Sandboxie&#8221; talks about the Windows utility Sandboxie—a program that allows you to run &#8220;applications in an isolated environment on your computer so you can protect yourself from malware, surf the web, and maintain your registry without affecting your host system.&#8221; They also note that &#8220;Sandboxie is a good alternative to setting up a virtual machine, especially if you just want to run a quick test or two without having to wait for an entire operating system to boot up.&#8221; Be sure to read the post and learn more about Sandboxie <a href="http://securitymusings.com/article/1379/protect-your-computer-by-running-applications-in-sandboxie">here</a>. <span id="more-1905"></span></p>
<p><strong>#2 &#8211; The Bureaucracy Is Down</strong>: In his post &#8220;Blast From the Past,&#8221; TaoSecurity&#8217;s Richard <span>Bejtlich uses an example from his own life that illustrates the sometimes ridiculous nature of tasks given by large organizations. In Bejtlich&#8217;s case, it was the Air Force that had given him and his co-workers what seemed to be an impossible mission: </span>Centralize Air Force email within the course of a few months. Needless to say, such a feat was impossible in such a small amount of time. But now, nearly 11 years later, Bejtlich says that it is finally happening; that Air Force email will be starting the centralization process at<em> </em>Keesler Air Force Base, Miss. But as he says at the end of his post, &#8220;[s]o, about 11 years after being told to accomplish the same task, the effort will be done! I think there are lessons here for anyone with a similarly large, bureaucratic, turf-centric, distributed, decentralized, global organization.&#8221; Be sure to read the full post <a href="http://taosecurity.blogspot.com/2009/08/blast-from-past.html">here</a>.</p>
<p><span class="status-body"><span class="msgtxt en"><strong>#1 &#8211; Help Isn&#8217;t Coming</strong>: Leave it to <a href="http://www.twitter.com/rybolov">@</a></span></span><a href="http://www.twitter.com/rybolov">rybolov</a> to hit the nail on the head when it comes to the Cybersecurity Coordinator position and why, even after two months, it <em>still</em> hasn&#8217;t been filled. In his post &#8220;Help Wanted,&#8221; he poses the following question: &#8220;So let me give you a hypothetical job: You have to give up your high-paying private-sector job to be a Government employee. You have tons of responsibility. You have no real authority. You have no dedicated budget. You have no staffers. The job has had half a dozen people filling it in the last 7 years. The job has been open longer than it’s been staffed over the past 7 years.&#8221; Does that sound like a job that any of you would want? Didn&#8217;t think so. By being blunt (unlike government officials), @rybolov makes excellent points as to why the Cybersecurity Coordinator position is still empty, and will likely remain that way unless something changes. Be sure to read his full post <a href="http://www.guerilla-ciso.com/archives/1259">here</a>.</p>
<p>Well, that&#8217;s all for this week. Be sure to follow us <a href="http://www.twitter.com/grecs">@grecs</a> for more great posts throughout the week!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/08/10/top-3-nova-infosec-blog-posts-of-the-week-20/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/07/20/top-3-nova-infosec-blog-posts-of-the-week-17/</link>
		<comments>http://www.novainfosecportal.com/2009/07/20/top-3-nova-infosec-blog-posts-of-the-week-17/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 14:00:20 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[local-bloggers]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[richard-bejtlich]]></category>
		<category><![CDATA[rybolov]]></category>
		<category><![CDATA[scap]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sexism-in-security]]></category>
		<category><![CDATA[white-hat]]></category>
		<category><![CDATA[white-hat-budget]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1824</guid>
		<description><![CDATA[If ever there was a week of controversial posts, it would be this one. While the posts we usually cover follow trends and topics without coloring outside the lines too much, this week you can expect to read some thought-provoking posts about sexism in information security, what white hat could do with a million bucks [...]]]></description>
			<content:encoded><![CDATA[<p>If ever there was a week of controversial posts, it would be this one. While the posts we usually cover follow trends and topics without coloring outside the lines too much, this week you can expect to read some thought-provoking posts about sexism in information security, what white hat could do with a million bucks (far less than black hat, by the way), and the way that Federated Management should be run.</p>
<p>In other words, the perfect reading material to go with your morning coffee.</p>
<p>Now, on to the posts!</p>
<p><strong>#3 &#8211; Plan for BSOFH Happiness</strong>: Half sarcasm, half advice, <a href="http://www.twitter.com/rybolov">@rybolov&#8217;s</a> post &#8220;Federated Vulnerability Management&#8221; gives the nitty-gritty on government patch and vulnerability management. After talking about what&#8217;s wrong with government patches and vulnerability management, he recommends using SCAP to &#8216;fix&#8217; the mess. While the post is a little longer than usual, it&#8217;s definitely <a href="http://www.guerilla-ciso.com/archives/1197">worth the read</a>. <span id="more-1824"></span></p>
<p><strong>#2 &#8211; Sexism, Religion, and Hackers</strong>: This is a topic that isn&#8217;t discussed enough. While DojoSec&#8217;s Marcus J. Carey did a v-blog post about sexism in the security field a little over <a href="http://www.novainfosecportal.com/2009/05/03/grecs-weekly-infosec-ramblings-for-2009-05-03/#sexism-in-security">two months ago</a>, there hasn&#8217;t been much discussion about it since. That&#8217;s why it was refreshing to see <a href="http://www.twitter.com/mubix">@mubix</a> respond to a post by <a href="http://www.twitter.com/shazzzam">@shazzzam</a> and others about females in information security. Let&#8217;s be honest: it&#8217;s not fair, and there is a bias. But as @mubix points out, &#8220;[s]exism, and for that matter, any “-ism” is flawed on both sides.&#8221; This is a highly controversial post, but one that should be read. You can read the full post <a href="http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html">here</a>.</p>
<p><strong>#1 &#8211; White Hat for a Million</strong>: After his post &#8220;<a href="http://www.novainfosecportal.com/2009/06/29/top-3-nova-infosec-blog-posts-of-the-week-14/">Black Hat Budgeting</a>&#8221; got a fair amount of response last month, author and speaker Richard Bejtlich decided to revisit the million dollar security question this month by figuring out what white hat security could do with a million dollars compared to what black hat could do. The results? Not exactly pretty. As Bejtlich says at the end of his post, &#8220;I am much less comfortable building out this team, compared to the Black Hat Budgeting exercise. There are way too many variables involved in defending any enterprise.&#8221; With roughly $850,000 spent on staff, there&#8217;s only $150,000 left for technology. How does Bejtlich break it all down? Read the <a href="http://taosecurity.blogspot.com/2009/07/white-hat-budgeting.html">full post</a> to find out.</p>
<p>Well, that’s all for this week. Be sure to follow me <a href="http://www.twitter.com/grecs">@grecs</a> during the week for more great posts from local bloggers.</p>
<p style="text-align: center;">o o o o o</p>
<p style="text-align: center;"><em>Know a blog that should be considered for our &#8220;Top 3 NoVA Infosec Blog Posts of the Week&#8221; feature? If so, <a href="http://www.twitter.com/grecs">send us a tweet</a> with a link to the blog and the request for us to check it out.<br />
</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/07/20/top-3-nova-infosec-blog-posts-of-the-week-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 3 NoVA Infosec Blog Posts of the Week</title>
		<link>http://www.novainfosecportal.com/2009/06/01/top-3-nova-infosec-blog-posts-of-the-week-10/</link>
		<comments>http://www.novainfosecportal.com/2009/06/01/top-3-nova-infosec-blog-posts-of-the-week-10/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 14:00:45 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Blogs/Podcasts]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[gemini-security]]></category>
		<category><![CDATA[information-security-blogs]]></category>
		<category><![CDATA[infosec-bloggers]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[NoVA Bloggers]]></category>
		<category><![CDATA[obama]]></category>
		<category><![CDATA[president-obama]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[richard-bejtlich]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[taosecurity]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1614</guid>
		<description><![CDATA[This week we are featuring a new NoVA Blogger, @geminisecurity. Please take a moment to check out their Twitter feed and welcome them to the local infosec community.
While he doesn’t have a post featured this week, we would also like to introduce local NoVA blogger @bobgourley. Please take a moment to visit his Twitter feed [...]]]></description>
			<content:encoded><![CDATA[<p>This week we are featuring a new NoVA Blogger, <span style="color: #3366ff;"><a href="http://twitter.com/geminisecurity">@geminisecurity</a></span>. Please take a moment to check out their <span style="color: #3366ff;"><a href="http://twitter.com/geminisecurity">Twitter feed</a></span> and welcome them to the local infosec community.</p>
<p>While he doesn’t have a post featured this week, we would also like to introduce local NoVA blogger <span style="color: #3366ff;"><a href="http://twitter.com/bobgourley">@bobgourley</a></span>. Please take a moment to visit his <span style="color: #3366ff;"><a href="http://twitter.com/bobgourley">Twitter feed</a></span> or his <span style="color: #3366ff;"><span style="color: #3366ff;"><a href="http://ctovision.com/">blog</a></span> </span>and welcome him to the local infosec community.</p>
<p>Now, to the posts!</p>
<p><strong>#3 &#8211; The Mystery of SSL</strong>: The post “How does SSL work anyway?” post published by <span style="color: #3366ff;"><a href="http://twitter.com/geminisecurity">@geminisecurity</a></span> this week was not only useful, but witty. Likening SSL to a handshake—“[i]t’s like the secret handshake you used in grade school to get into your clubhouse”—@geminisecurity had some useful tips and tricks about Server Authentication, Client Authentication, References, and other SSL protocols. You can check out the full post <span style="color: #3366ff;"><a href="http://securitymusings.com/article/1095/how-does-ssl-work-anyway">here</a></span>.<span id="more-1614"></span></p>
<p><strong>#2 &#8211; Resources Galore</strong>: It seems that <span style="color: #3366ff;"><a href="http://www.twitter.com/mubix">@mubix</a></span> is the man to talk to if you’re looking for great <span style="color: #3366ff;"><a href="http://www.novainfosecportal.com/resources/nova-email-lists-networking/">security resources</a></span>. Posting what he described as “Getting your fill of Security,” this week, @mubix is now keeping a running list of security <span style="color: #3366ff;"><a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">podcasts</a></span>, security <span style="color: #3366ff;"><a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">bloggers</a></span>, security-related <span style="color: #3366ff;"><a href="http://www.novainfosecportal.com/resources/nova-email-lists-networking/novainfosec-twits/">Twitter accounts</a></span>, and sites that you’re free to hack. You can check out the list <span style="color: #3366ff;"><a href="http://www.room362.com/archives/569-getting-your-fill-of-security.html">here</a></span>. You can also check out our <a href="http://www.novainfosecportal.com/resources/nova-email-lists-networking/">list</a> of security resources for additional information.</p>
<p><strong>#1 &#8211; 60 Day Surprise</strong>: After President Obama gave his remarks on Cyber Security earlier in the week, <span style="color: #3366ff;"><a href="http://www.bejtlich.net/">Richard Bejtlich</a></span> wasted no time before blogging his own thoughts about the President’s controversial speech. While we read a lot of tweets and <span style="color: #3366ff;"><a href="http://www.novainfosecportal.com/resources/infosec-blogs-podcasts/">blog posts</a></span> this week that dealt with Obama’s ultimate stance on Cyber Security, we felt that Bejtlich’s was by far the best. Not only did he provide an intelligent commentary about what President Obama said, he also created an ‘imaginary’ speech of “what I would have liked to have heard [from President Obama].” This is a must-read post for anyone in the field, as the President’s stance on Cyber Security will affect all of us in some way. You can read the full post <span style="color: #3366ff;"><a href="http://taosecurity.blogspot.com/2009/05/president-obamas-real-speech-on-cyber.html">here</a></span>.</p>
<p>Well, that&#8217;s all for this week. As always, we&#8217;d love to know if there are any other NoVA bloggers out there would would like to be considered for our &#8220;Top NoVA Infosec Blog Posts of the Week&#8221; feature. If so, leave a comment below or send us a tweet <span style="color: #3366ff;"><a href="http://www.twitter.com/grecs">@grecs</a></span>.</p>
<p style="text-align: center;">o o o o o</p>
<p style="text-align: center;"><em>How <a href="http://www.amazon.com/gp/product/B00155184G?ie=UTF8&amp;tag=grecomconsult-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=B00155184G">Ironclad</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=grecomconsult-20&amp;l=as2&amp;o=1&amp;a=B00155184G" border="0" alt="" width="1" height="1" /> is your information? </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/06/01/top-3-nova-infosec-blog-posts-of-the-week-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reminder: NoVA/DC Luncheon is Tomorrow, 05-21</title>
		<link>http://www.novainfosecportal.com/2009/05/20/reminder-novadc-luncheon-is-tomorrow-05-21/</link>
		<comments>http://www.novainfosecportal.com/2009/05/20/reminder-novadc-luncheon-is-tomorrow-05-21/#comments</comments>
		<pubDate>Wed, 20 May 2009 14:30:35 +0000</pubDate>
		<dc:creator>paques</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[meetups]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[nova-dc-luncheon]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1546</guid>
		<description><![CDATA[Just a quick reminder that the NoVA/DC Luncheon hosted by @mubix is tomorrow, May 21st. For more information about the NoVA/DC Luncheon, see its description in our Infosec Meetups section.
View our Calendar for a list of similar infosec events in and around the NoVA area. See our original post for more information about this meetup. 
o     o     o     o     o
Was [...]]]></description>
			<content:encoded><![CDATA[<p>Just a quick reminder that the <a href="http://www.novainfosecportal.com/events/nova-meetups/#novadcluncheon">NoVA/DC Luncheon</a> hosted by <a href="http://www.twitter.com/mubix">@mubix</a> is tomorrow, May 21st. For more information about the NoVA/DC Luncheon, see its <a href="http://www.novainfosecportal.com/events/nova-meetups/#novadcluncheon">description</a> in our Infosec Meetups section.</p>
<p>View our <a href="http://www.novainfosecportal.com/events/full-calendar/">Calendar</a> for a list of similar infosec events in and around the NoVA area. See our <a href="http://www.novainfosecportal.com/2009/05/14/novadc-luncheon-meetup-thursday-05-21/">original post</a> for more information about this meetup. <span id="more-1546"></span></p>
<p style="text-align: center;">o     o     o     o     o</p>
<p class="MsoNormal" style="text-align: center;"><em>Was this post helpful? If so, consider passing it along to a friend or becoming a <a href="http://www.novainfosecportal.com/general/help-us-help-you/">subscriber</a></em><em> of our site. Or, you can always do both—we won’t complain.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/05/20/reminder-novadc-luncheon-is-tomorrow-05-21/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NoVA/DC Luncheon Meetup Thursday, 05-21</title>
		<link>http://www.novainfosecportal.com/2009/05/14/novadc-luncheon-meetup-thursday-05-21/</link>
		<comments>http://www.novainfosecportal.com/2009/05/14/novadc-luncheon-meetup-thursday-05-21/#comments</comments>
		<pubDate>Thu, 14 May 2009 15:30:11 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[meetup]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[nova-dc-luncheon]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security-professionals]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1505</guid>
		<description><![CDATA[Just wanted to let everyone know that the NoVA/DC Luncheon Meetup hosted by @mubix will be happening on Thursday, May 21st.
An informal meetup of security professionals in the NoVA/DC area, this is a great chance to take a longer lunch and get to know some local professionals that you may not have had the chance to [...]]]></description>
			<content:encoded><![CDATA[<p>Just wanted to let everyone know that the <a href="http://www.novainfosecportal.com/events/nova-meetups/#novadcluncheon">NoVA/DC Luncheon Meetup</a> hosted by <a href="http://www.twitter.com/mubix">@mubix</a> will be happening on Thursday, May 21st.</p>
<p>An informal meetup of security professionals in the NoVA/DC area, this is a great chance to take a longer lunch and get to know some local professionals that you may not have had the chance to meet before. </p>
<p>You can view additional details about this meetup below.<span id="more-1505"></span></p>
<ul>
<li><strong>Who: </strong><a href="http://www.twitter.com/mubix">@mubix</a> and whoever else shows up</li>
<li><strong>What:</strong> NoVA/DC Luncheon Meetup</li>
<li><strong>When:</strong> 05-21, around lunchtime</li>
<li><strong>Where:</strong> Rossyln, VA (be sure to <a href="mailto:mubix@hak5.org">contact</a> mubix for full meetup details)</li>
</ul>
<p style="text-align: center;">o     o     o     o     o</p>
<p style="text-align: center;"><em>Do you have your </em><a href="http://www.novainfosecportal.com/general/help-us-help-you/"><em>summer reading</em></a><em> yet?</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/05/14/novadc-luncheon-meetup-thursday-05-21/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DojoSec Infosec Meetup Event &#8211; Thursday, 04-02: Career Advice and Adobe Acrobat</title>
		<link>http://www.novainfosecportal.com/2009/03/31/dojosec-infosec-meetup-event-thursday-04-02-career-advice-and-adobe-acrobat/</link>
		<comments>http://www.novainfosecportal.com/2009/03/31/dojosec-infosec-meetup-event-thursday-04-02-career-advice-and-adobe-acrobat/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 22:46:07 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[dojosec-sourcefire]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[matt-watchinski]]></category>
		<category><![CDATA[meetups]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[rob-fuller]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1284</guid>
		<description><![CDATA[They had us at “Holy Hot Tuna.”
That’s the title (or part of it, anyways) of Matt Watchinski’s talk at the upcoming DojoSec meetup this Thursday, April 2nd. As much as we’d like you to guess what the rest of the title is (there would be some interesting answers, we’re sure), we’ll be a good sport [...]]]></description>
			<content:encoded><![CDATA[<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">They had us at “Holy Hot Tuna.”</p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">That’s the title (or part of it, anyways) of Matt Watchinski’s talk at the upcoming <a href="http://www.novainfosecportal.com/events/nova-meetups/#dojosec"><span style="color: #b85b5a;">DojoSec</span></a> meetup this Thursday, April 2nd. As much as we’d like you to guess what the rest of the title is (there would be some interesting answers, we’re sure), we’ll be a good sport and just tell you.</p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">The full title is “1 Byte, 5 Minutes, Holy Hot Tuna,” which is related (but mostly unrelated) to what Watchinski will be discussing: The recent flaw in Adobe Acrobat and Acrobat Reader. </p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">Watchinski will discuss the entire process behind discovering the flaw, including how he gathered intelligence through exploitation, mitigation, and vulnerability disclosure. He’ll also discuss why the VRT decided to release a third-party patch and why the flaw caused a mini media circus.</p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">Watchinski’s fellow speaker, Rob Fuller (known as Mubix to many of you) also went the way of a creative title for his talk, giving a presentation entitled<span id="more-1284"></span>: “From Couch to Career in 80 Hours.” The thing we love most about his title? The fact that he didn’t promise to work miracles in 1 hour. 80 hours sounds about right for what Fuller is hoping his audience will want to accomplish.</p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">In Fuller’s crash course about what the DojoSec site describes as “hacking your career,” Fuller wants to give his audience tips that will help them take them to the next level professionally. While a lot of Fuller’s talk will appeal to the hacker part of security professionals (cyber-stalking potential employers, anyone?), Fuller will also cover practical issues that are often overlooked, such as how to accept an offer letter.</p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">Sound like something you might want to attend? The great news is that now you can ‘attend’ the meetup virtually as well as in person. The DojoSec meetup will be streaming live via their <a href="http://www.ustream.tv/dojosec">Ustream</a> channel.</p>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">If you’d like additional information about this meetup, look no further then below. </p>
<ul style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">
<li><strong>Who:</strong> Rob Fuller (<a href="http://twitter.com/mubix">Mubix</a>), <a href="http://www.room362.com/">Room362.com</a> and Matt Watchinski, <a href="http://www.sourcefire.com/">Sourcefire</a> </li>
<li><strong>What:</strong> &#8220;From Couch to Career in 80 hours&#8221; by Fuller and &#8220;1 Byte, 5 Minutes, Holy Hot Tuna&#8221; by Watchinski</li>
<li><strong>When:</strong> 04-02, 6:00-9:30 PM EST</li>
<li><strong>Where:</strong> <a href="http://www.capitol-college.edu/">Capitol College</a> (<a href="http://maps.google.com/maps?f=d&amp;source=s_d&amp;saddr=&amp;daddr=11301+Springfield+Road,+Laurel,+Maryland+20708&amp;hl=en&amp;geocode=&amp;mra=ls&amp;sll=37.0625,-95.677068&amp;sspn=40.681389,92.8125&amp;ie=UTF8&amp;z=16">11301 Springfield Road, Laurel, Maryland 20708</a>)</li>
</ul>
<p style="BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; CURSOR: text; BORDER-BOTTOM: #ffffff 1px solid">For more information on DojoSec, see its <a href="http://www.novainfosecportal.com/events/nova-meetups/#dojosec">description</a> in our <a href="http://www.novainfosecportal.com/events/nova-meetups/">NoVA Meetups</a> section. View our <a href="http://www.novainfosecportal.com/events/full-calendar/">Calendar</a> for a complete list of infosec events in and around the NoVA area. Here is a link to more information about the <a title="DojoSec meetup" href="http://www.dojosec.com/?p=76" target="_blank">DojoSec meetup</a>.</p>
<p style="text-align: center;">###</p>
<p style="text-align: center;"><em>Was this post helpful? If so, consider passing it along to a friend or becoming a </em><a href="http://www.novainfosecportal.com/general/help-us-help-you/"><span style="color: #b85b5a;"><em>subscriber</em></span></a><em> of our site. Or, you can always do both—we won’t complain.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/03/31/dojosec-infosec-meetup-event-thursday-04-02-career-advice-and-adobe-acrobat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
