<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; privacy</title>
	<atom:link href="http://www.novainfosecportal.com/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Tue, 27 Jul 2010 15:00:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cookie Use &#8230; How Agencies Should Set Example for Broader Industry</title>
		<link>http://www.novainfosecportal.com/2010/06/29/cookie-use-how-agencies-should-set-example-for-broader-industry/</link>
		<comments>http://www.novainfosecportal.com/2010/06/29/cookie-use-how-agencies-should-set-example-for-broader-industry/#comments</comments>
		<pubDate>Tue, 29 Jun 2010 15:30:26 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[omb]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3848</guid>
		<description><![CDATA[I came across an article yesterday discussing the Office of Management and Budget&#8217;s (OMB) recent guidance allowing the government to use &#8220;persistent cookies.&#8221; For over a decade they have not been able to use such technologies to track user website visits. The new guidance, M-10-22, permits the use of &#8220;web measurement and customization technologies, including [...]]]></description>
			<content:encoded><![CDATA[<p>I came across an <a href="http://www.govinfosecurity.com/articles.php?art_id=2700">article</a> yesterday discussing the Office of Management and Budget&#8217;s (OMB) recent guidance allowing the government to use &#8220;persistent cookies.&#8221; For over a decade they have not been able to use such technologies to track user website visits. The new guidance, M-10-22, permits the use of &#8220;web measurement and customization technologies, including cookies &#8211; small pieces of browser software that track and authenticate web viewing activities by users.&#8221;</p>
<p>One of the more interesting points I noticed in the article is the decision to leave the choice of using an &#8220;opt-in&#8221; versus an &#8220;opt-out&#8221; model up to the individual agencies. I wish OMB would have set an example here and made a cross-the-board statement that users <strong>MUST</strong> opt-in. Instead they danced around the subject and passed the decision onto the individual agencies for better or for worse.</p>
<p>I know as a website operator how &#8220;neat&#8221; these statistics can be however the most important stats (e.g., total hits or page views) can often be collected without the use of tracking cookies or similar techniques. We are all tired of commercial companies taking advantage these technologies at the expense of our privacy. Each of the individual agencies need to take a stand and choose the &#8220;opt-in&#8221; model as a small step in showing the commercial world how it should be done.</p>
<p>I know this opinion may not be popular in some circles &#8230; but in the end, it&#8217;s just the right thing to do!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/06/29/cookie-use-how-agencies-should-set-example-for-broader-industry/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PrivacyCampDC Infosec Conference Event &#8211; Saturday, 06-20</title>
		<link>http://www.novainfosecportal.com/2009/06/16/privacycampdc-infosec-conference-event-saturday-06-20/</link>
		<comments>http://www.novainfosecportal.com/2009/06/16/privacycampdc-infosec-conference-event-saturday-06-20/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 15:00:27 +0000</pubDate>
		<dc:creator>paques</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[governmental-policy]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacycampdc]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1687</guid>
		<description><![CDATA[There&#8217;s been quite a bit of buzz surrounding this year&#8217;s PrivacyCampDC, and it&#8217;s easy to see why. Described as &#8220;an unconference about [p]rivacy with a particular focus on electronic privacy and Government Policy,&#8221; the goal of PrivacyCampDC is to &#8220;connect researchers, developers, practitioners, citizens and other enthusiasts for a day of intense collaboration and knowledge [...]]]></description>
			<content:encoded><![CDATA[<p style="border: 1px solid #ffffff; cursor: text;">There&#8217;s been quite a bit of buzz surrounding this year&#8217;s <a title="PrivacyCampDC" href="../events/infosec-conferences/#pcdc">PrivacyCampDC</a>, and it&#8217;s easy to see why. Described as &#8220;an unconference about [p]rivacy with a particular focus on electronic privacy and Government Policy,&#8221; the goal of PrivacyCampDC is to &#8220;connect researchers, developers, practitioners, citizens and other enthusiasts for a day of intense collaboration and knowledge sharing.&#8221;</p>
<p style="border: 1px solid #ffffff; cursor: text;">And lets be honest: the world &#8216;camp&#8217; just sounds so much more interesting than &#8216;conference,&#8217; doesn&#8217;t it?</p>
<p style="border: 1px solid #ffffff; cursor: text;">We&#8217;re really excited to see how this event plays out, so if you end up attending, please <a title="drop us a line" href="../contact-us/">drop us a line</a> about how it went. Also be sure to check out the helpful information below. <span id="more-1687"></span></p>
<p style="border: 1px solid #ffffff; cursor: text;"><!--more--></p>
<ul style="border: 1px solid #ffffff; cursor: text;">
<li><strong>Who:</strong> PrivacyCampDC</li>
<li><strong>What:</strong> &#8220;[A]n unconference about [p]rivacy with a particular focus on electronic privacy and Government Policy.&#8221;</li>
<li><strong>When:</strong> 06-20 &#8211; 06-20-2009</li>
<li><strong>Where:</strong> <a title="Center for American Progress Action Fund" href="http://www.americanprogressaction.org/">Center for American Progress Action Fund</a> (<a title="1333 H Street, NW - Washington, DC 20005" href="http://maps.google.com/maps?f=d&amp;source=s_d&amp;saddr=&amp;daddr=1333+H+Street,+NW+-+Washington,+DC+20005&amp;hl=en&amp;geocode=&amp;mra=ls&amp;sll=37.579413,-95.712891&amp;sspn=47.42872,88.242187&amp;ie=UTF8&amp;z=16">1333 H Street, NW &#8211; Washington, DC 20005</a>)</li>
</ul>
<p style="border: 1px solid #ffffff; cursor: text;">For more information on PrivacyCampDC, see its <a href="../events/infosec-conferences/#pcdc">description</a> in our I<a href="../events/infosec-conferences/">nfosec Conferences</a> section. View our <a title="Calendar" href="../events/full-calendar/">Calendar</a> for a list of similar infosec events in and around the NoVA area. See the PrivacyCampDC <a title="registration page" href="http://privacycampdc09-fbevent.eventbrite.com/" target="_blank">registration page</a> for more information.</p>
<p style="border: 1px solid #ffffff; cursor: text; text-align: center;">o o o o o</p>
<p style="border: 1px solid #ffffff; cursor: text; text-align: center;"><em>If you attend this event, why not write about it for NovaInfosecPortal? <a href="http://www.novainfosecportal.com/contact-us/">Contact us</a> if you&#8217;re interested. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/06/16/privacycampdc-infosec-conference-event-saturday-06-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2009 – Friday Schedule Update</title>
		<link>http://www.novainfosecportal.com/2009/02/04/shmoocon-2009-%e2%80%93-friday-schedule-update/</link>
		<comments>http://www.novainfosecportal.com/2009/02/04/shmoocon-2009-%e2%80%93-friday-schedule-update/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 03:07:25 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalk]]></category>
		<category><![CDATA[friday]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[keynote]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[podcaster meetup]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[reminder]]></category>
		<category><![CDATA[schedule]]></category>
		<category><![CDATA[shmooball]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=1002</guid>
		<description><![CDATA[While I already updated my “ShmooCon 2009 Guide – Friday Recommendations,” post, I wanted to make sure that everyone was aware of the schedule changes for this Friday at ShmooCon.
According to Podcasters Meetup, the live show, book signing, and FireTalks on Friday will be happening later than originally planned.
Setup will now start at 7:30pm, with the [...]]]></description>
			<content:encoded><![CDATA[<p>While I already updated my “<a href="http://www.novainfosecportal.com/2009/02/02/shmoocon-2009-guide-friday-recommendations/">ShmooCon 2009 Guide – Friday Recommendations</a>,” post, I wanted to make sure that everyone was aware of the schedule changes for this Friday at ShmooCon.</p>
<p>According to <a href="http://www.podcastersmeetup.com/">Podcasters Meetup</a>, the live show, book signing, and FireTalks on Friday will be happening later than originally planned.</p>
<p>Setup will now start at 7:30pm, with the live show taking place from 8:00-9:00. The book signing will take place during the FireTalks, which start at 9:00.</p>
<p>There will also be a HacDC party that starts at 10:00pm, so be sure to visit the <a href="http://wiki.hacdc.org/index.php?title=Shmoocon_Party">HacDC wiki</a> if you’re interested in learning more.</p>
<p>You can get more updates at the Podcasters Meetup Twitter feed, <a href="http://twitter.com/podcastmeetup">@podcastmeetup</a>.</p>
<p style="text-align: center;">###</p>
<p style="text-align: center;"><em>Was this post helpful? If so, consider passing it along to a friend or becoming a </em><a href="http://www.novainfosecportal.com/general/help-us-help-you/"><span style="color: #b85b5a;"><em>subscriber</em></span></a><em> of our site. Or, you can always do both—we won’t complain.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/02/04/shmoocon-2009-%e2%80%93-friday-schedule-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2009 Guide – Friday Recommendations</title>
		<link>http://www.novainfosecportal.com/2009/02/02/shmoocon-2009-guide-friday-recommendations/</link>
		<comments>http://www.novainfosecportal.com/2009/02/02/shmoocon-2009-guide-friday-recommendations/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 00:34:58 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalk]]></category>
		<category><![CDATA[friday]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[keynote]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[podcaster meetup]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[reminder]]></category>
		<category><![CDATA[shmooball]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=991</guid>
		<description><![CDATA[In my last two posts (“Up to this Point” and “General Advice”) I looked at the events leading up to this week and general advice for getting the most out of the conference. In this post I’m going to look at some of the different talks and activities going on Friday.
 As part of this discussion [...]]]></description>
			<content:encoded><![CDATA[<p>In my last two posts (“<a href="http://www.novainfosecportal.com/2009/01/29/shmoocon-2009-guide-%e2%80%93-up-to-this-point/">Up to this Point</a>” and “<a href="http://www.novainfosecportal.com/2009/02/01/shmoocon-2009-guide-%e2%80%93-general-advice/">General Advice</a>”) I looked at the events leading up to this week and general advice for getting the most out of the conference. In this post I’m going to look at some of the different talks and activities going on Friday.</p>
<p> As part of this discussion I’ll be giving my recommended activities. Keep in mind that these choices are based on my likes and dislikes. I’d advise reviewing the full list of activities yourself just to make sure you don’t miss anything that’s important to you.</p>
<p>Before I talk about Friday evening, I do want to take a minute to mention the plan for a Security Twits lunch meetup at 12:00pm at Harry&#8217;s Pub in the Marriott. If you plan on attending, RSVP at securitytwits{0&#215;40}n0where.org. If you&#8217;d like more information, you can visit <a href="http://twitter.com/securitytwits ">@securitytwits</a> to see the original tweet.</p>
<p>And now, onto the evening portion of ShmooCon.</p>
<p>In typical ShmooCon fashion, Friday evening is dedicated to the “One Track Mind” talks. Of the “One Track Mind” sessions, three look particularly interesting to me. Being a fan of PaulDotCom and Larry’s imaginative hardware hacking exploits, how could I pass up “<a href="http://www.shmoocon.org/presentations-all.html#shmooball">Building the 2008 and 2009 ShmooBall Launchers</a>” by Larry Pesce and David Lauer at 4:30? Both <a href="http://securityjustice.com/archives/48">SecurityJustice</a> and <a href="http://securid.wordpress.com/2009/01/05/shmoocon-paper-accepted/">Securi-D’s</a> Weblog preview what they’ll be discussing.</p>
<p>Following those session, the “<a href="http://www.shmoocon.org/presentations-all.html#srizbi">The Day Spam Stopped (The Srizbi Botnet Takedown)</a>” talk by Julia Wolf at 5:00 seems like a nice post-mortem of a complex topic that I’m always looking to learn more about. In theory I understand how botnets work, but I’m continually looking for more details of them in action. And seeing a practical application of botnets—which this talk will provide—really drills those theories in.</p>
<p>The final “One Track Mind” session I hope to see is “<a href="http://www.shmoocon.org/presentations-all.html#watcher">Watching the Watcher: The Prevalence of Third-Party Web Tracking</a>” by Brent Chapman, Tera Corbari, and Matt Devers at 6:30. Being a mildly paranoid person (which is probably why I migrated into the infosec field), I am always interested in learning more about who and what is profiling me<span id="more-991"></span> through increasingly complex information gathering techniques. Plus, the advanced tracking mechanisms that many of these organizations use are simply facinating. Learning their techniques would at least help me disrupt their profile building activities. That’s my hope, anyways.</p>
<p>To finish out Friday night’s official activities, I’ll be going to hear what Matt Blaze has to say in his <a href="http://www.shmoocon.org/presentations-all.html#keynote">keynote</a> talk. Speaking of Blaze&#8217;s talk in particular, one thing that has always bothered me ever so slightly at ShmooCon is that there’s no overview of the keynote. We always get nice bios but nothing concrete on the exact topic. Based on Matt’s background, it’ll probably involve the intersection of security and public policy in some way. Does anyone else have any ideas on his topic? Or did I just miss a major announcement somewhere?</p>
<p>According to <a href="Matt’s Wikipedia article">Matt’s Wikipedia article</a>, it looks like he’s been involved in some interesting things. He is credited with developing the forerunner of IPSec in ‘93, circumventing the wiretapping capabilities of the Clipper chip in ‘94, and rediscovering a vulnerability in “master key” security in physical locks in ’03. (It’s technically a “rediscovery” because it was an open secret among locksmiths). He also coined the term “trust management,” which means to “refer to the policy system which decides whether a particular entity should be permitted to carry out a particular action.” Currently, Matt is an Associate Professor of Computer and Information Science at the University of Pennsylvania.</p>
<p>Next come several unofficial ShmooCon Friday night events that you may want to take part in. There is some overlap with the official talks but you may want to check out the <a href="http://www.podcastersmeetup.com/?p=66">Podcaster’s Meetup</a>. Setup begins at 7:30, with the live show starting at 8:00. Podcasters taking part include Hak5, PaulDotCom, CyberSpeak, Sucurabit, Security Justice, SploitCase, Unpersons, Phone Losers of America, and SMBMinute. After the recording, there will be some time for getting your books signed if you’re interested.</p>
<p>The FireTalks then start at 9:00. For those of you who don’t know, the FireTalk sessions include several 10 to 15 minute talks by those who have something interesting to say, but didn’t get accepted by ShmooCon or didn’t submit their proposed talk in time.</p>
<p>If you’d like more information, you can view the <a href="http://www.podcastersmeetup.com/?p=66">Podcaster’s Meetup</a> post about the FireTalks, which I’ve pasted part of below.</p>
<p>&#8220;Have a talk that didn’t get accepted? Want the chance to share a project that you are working on? Think of FireTalks as a verbal blog post.</p>
<p> The human experience is built on the ability to tell and learn from stories. At SchmooCon 2009, “FireTalks” is a supportive environment in which to either share insights or learn from others. Whether polishing a presentation (story) for conferences, meetings or training, FireTalks are the way to share, learn and improve.</p>
<p> The inaugural FireTalks take place Friday night — following the Podcasters Meetup. Talks are limited to 10-15 minutes with four (4) scheduled talks and four (4) open slots. Open slots will be filled on a first come, first serve basis.</p>
<p> Saturday night will be more relaxed. Come join us and present, listen and learn.&#8221;</p>
<p>Both the Podcaster’s Meeting and the FireTalks will take place somewhere around the press room. I guess we’ll have to figure out the location once we get there. As I mentioned in the “General Advice” post, be sure to check Twitter for constant updates about the conference.</p>
<p>Afterward the FireTalks are over, continue the fun with some networking at a local spot. Or if you&#8217;re interested, CharmSec is having a meetup after the keynote. Be sure to check it out if you can. You can view <a href="http://twitter.com/charmsec/statuses/1176642602">@charmsec</a> for additional details. You may also want to follow <a href="http://twitter.com/podcastmeetup">@podcastmeetup</a> on Twitter to get any last minute updates.</p>
<p>If there’s anything I’ve missed, please feel free to let me know by leaving a comment below.  Praise and criticism (and by that, I mean <span style="text-decoration: underline;">constructive feedback</span>) is always appreciated. Additionally, has anyone figured out what the keynote topic is or where the post Podcaster’s Meetup/FireTalks “local spot” is going to be?</p>
<p>In my next post, I’ll be discussing Saturday’s activities with some recommended talks and other events. Choosing which sessions to attend will definitely be a lot harder given the wide range of options.</p>
<p style="TEXT-ALIGN: center">###</p>
<p style="TEXT-ALIGN: center"><em>Was this post helpful? If so, consider passing it along to a friend or becoming a <a href="http://www.novainfosecportal.com/general/help-us-help-you/">subscriber</a> of our site. Or, you can always do both—we won’t complain.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/02/02/shmoocon-2009-guide-friday-recommendations/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
