<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security &#187; Crime</title>
	<atom:link href="http://www.halbheer.info/security/category/cybercrime/crime/feed" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.info/security</link>
	<description>I am the Worldwide Chief Security Advisor for Microsoft and would like to discuss Information Security</description>
	<lastBuildDate>Thu, 09 Sep 2010 12:29:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>What it takes to shut down a botnet</title>
		<link>http://www.halbheer.info/security/2010/09/02/what-it-takes-to-shut-down-a-botnet</link>
		<comments>http://www.halbheer.info/security/2010/09/02/what-it-takes-to-shut-down-a-botnet#comments</comments>
		<pubDate>Thu, 02 Sep 2010 12:57:51 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Botnet]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/09/02/what-it-takes-to-shut-down-a-botnet</guid>
		<description><![CDATA[It hits the press from time to time that somebody was successful taking down a botnet. We had some success as well with the Waledac Botnet Takedown. There is actually a good article on What it takes to shut down &#8230; <a href="http://www.halbheer.info/security/2010/09/02/what-it-takes-to-shut-down-a-botnet">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/03/20/results-of-operation-b49-botnet-takedown' rel='bookmark' title='Permanent Link: Results of Operation b49 (Botnet Takedown)'>Results of Operation b49 (Botnet Takedown)</a></li>
<li><a href='http://www.halbheer.info/security/2008/12/07/is-there-a-botnet-building-on-ms08-067-exploits' rel='bookmark' title='Permanent Link: Is there a Botnet building on MS08-067 exploits?'>Is there a Botnet building on MS08-067 exploits?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/how-a-botnet-looks-like' rel='bookmark' title='Permanent Link: How a Botnet looks like'>How a Botnet looks like</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F09%252F02%252Fwhat-it-takes-to-shut-down-a-botnet%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2Fc5l5gO%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22What%20it%20takes%20to%20shut%20down%20a%20botnet%22%20%7D);"></div>
<p>It hits the press from time to time that somebody was successful taking down a botnet. We had some success as well with the <a href="http://clubhouse.microsoft.com/Public/Post/d4666a88-8d90-4d6c-9311-07e9452eebdb" target="_blank">Waledac Botnet Takedown</a>.</p>
<p>There is actually a good article on <a href="http://www.infoworld.com/t/anti-spam/what-it-takes-shut-down-botnet-903" target="_blank">What it takes to shut down a botnet</a>. When I was doing some bing-search on the botnet takedowns, I found good work from Microsoft research as well: Your botnet is my botnet: <a href="http://academic.research.microsoft.com/Paper/4852217.aspx" target="_blank">analysis of a botnet takeover</a>.</p>
<p>It is not only about taking down the botnet, it is about going after the criminals and making sure it does not recover.</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/03/20/results-of-operation-b49-botnet-takedown' rel='bookmark' title='Permanent Link: Results of Operation b49 (Botnet Takedown)'>Results of Operation b49 (Botnet Takedown)</a></li>
<li><a href='http://www.halbheer.info/security/2008/12/07/is-there-a-botnet-building-on-ms08-067-exploits' rel='bookmark' title='Permanent Link: Is there a Botnet building on MS08-067 exploits?'>Is there a Botnet building on MS08-067 exploits?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/how-a-botnet-looks-like' rel='bookmark' title='Permanent Link: How a Botnet looks like'>How a Botnet looks like</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/09/02/what-it-takes-to-shut-down-a-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are We Losing the Fight Against Cybercrime?</title>
		<link>http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime</link>
		<comments>http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime#comments</comments>
		<pubDate>Tue, 17 Aug 2010 12:04:30 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Collaboration]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime</guid>
		<description><![CDATA[It is an interesting and difficult question. What can we do to really be able to stay on top? Or shall we give up? Well, clearly, I do not think so. I read this article today, which really made me &#8230; <a href="http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/24/sans-commits-1-million-to-fight-cybercrime-in-developing-countries' rel='bookmark' title='Permanent Link: SANS Commits $1 Million to Fight Cybercrime in Developing Countries'>SANS Commits $1 Million to Fight Cybercrime in Developing Countries</a></li>
<li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
<li><a href='http://www.halbheer.info/security/2010/02/09/use-music-to-fight-cybercrime-maga-no-need-pay' rel='bookmark' title='Permanent Link: Use Music to Fight Cybercrime: &#8216;Maga No Need Pay&#8217;'>Use Music to Fight Cybercrime: &#8216;Maga No Need Pay&#8217;</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F08%252F17%252Fare-we-losing-the-fight-against-cybercrime%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FbK2gnc%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Are%20We%20Losing%20the%20Fight%20Against%20Cybercrime%3F%22%20%7D);"></div>
<p>It is an interesting and difficult question. What can we do to really be able to stay on top? Or shall we give up? Well, clearly, I do not think so.</p>
<p>I read this article today, which really made me think: <a href="http://www.pcworld.com/article/203287/black_hats_are_winning_symantec_says.html" target="_blank">Black Hats are Winning, Symantec Says</a> – wow! A fairly clear statement. We lost (at least according to Symantec). And the solution is – you guess – new technology:</p>
<blockquote><p>&#8220;Technology that does not rely on capturing and analysing a threat in order to protect against it, like Symantec&#8217;s Reputation-Based Security, is indeed becoming imperative. Other methods that are also playing a key role in combating today&#8217;s most pervasive threats are heuristic, behavioural and intrusion prevention technologies.&#8221;</p></blockquote>
<p>So, I agree that new ways are need but really in enhancing today’s technology? Sure, we have to make sure we keep up with what is going on, but is it a technology problem, which can be solved by the next generation of any security product?</p>
<p>Remember that, a few years ago, we launched Trustworthy Computing in order to change the way we, Microsoft, internally think but we always said that this is an industry initiative. After a while, we realized that this was not enough and we came up with a model we call <a href="http://www.microsoft.com/endtoendtrust" target="_blank">End to End Trust</a>. The reason we did that was fairly simple: We did the SD3+C (Security by Design, Secure by Default, Secure in Deployment and Communication), we introduced the Security Development Lifecycle, and we worked on specific threat mitigation (actually, this is what Symantec seems to refer to). But unless the underlying architecture does fundamentally change, we (the industry) will not be able to change the rules and always run behind the criminals.</p>
<p>So, the ecosystem needs the trusted stack and a sound identity system which allows for strong identities and for minimal disclosure at the same time – without risking the freedom of speech.</p>
<p>All this is not new, the technologies are available. The problem is, that this is not a Microsoft challenge – it is an industry problem and the ecosystem has to buy in. We are doing a lot of groundwork there but as long as we are looking for medication to cure the symptoms and are not ready to look for the big bold changes, we will definitely lose. However, clearly we need to work on the medication in the meantime as well.</p>
<p>And then, let’s think about what this means for the Cloud… but this is something for another post…</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/24/sans-commits-1-million-to-fight-cybercrime-in-developing-countries' rel='bookmark' title='Permanent Link: SANS Commits $1 Million to Fight Cybercrime in Developing Countries'>SANS Commits $1 Million to Fight Cybercrime in Developing Countries</a></li>
<li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
<li><a href='http://www.halbheer.info/security/2010/02/09/use-music-to-fight-cybercrime-maga-no-need-pay' rel='bookmark' title='Permanent Link: Use Music to Fight Cybercrime: &#8216;Maga No Need Pay&#8217;'>Use Music to Fight Cybercrime: &#8216;Maga No Need Pay&#8217;</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Future of Cybercrime</title>
		<link>http://www.halbheer.info/security/2010/08/11/the-future-of-cybercrime</link>
		<comments>http://www.halbheer.info/security/2010/08/11/the-future-of-cybercrime#comments</comments>
		<pubDate>Wed, 11 Aug 2010 15:46:08 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Fun]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/08/11/the-future-of-cybercrime</guid>
		<description><![CDATA[If you do not know this blog, it is definitely worth looking at it from time to time: Paleo-Future. There I found a prediction on cybercrime dated 1981: It describes the impact of computers in the “future” – say today. &#8230; <a href="http://www.halbheer.info/security/2010/08/11/the-future-of-cybercrime">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/08/07/success-against-cybercrime' rel='bookmark' title='Permanent Link: Success against Cybercrime'>Success against Cybercrime</a></li>
<li><a href='http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime' rel='bookmark' title='Permanent Link: Are We Losing the Fight Against Cybercrime?'>Are We Losing the Fight Against Cybercrime?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/24/sans-commits-1-million-to-fight-cybercrime-in-developing-countries' rel='bookmark' title='Permanent Link: SANS Commits $1 Million to Fight Cybercrime in Developing Countries'>SANS Commits $1 Million to Fight Cybercrime in Developing Countries</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F08%252F11%252Fthe-future-of-cybercrime%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22The%20Future%20of%20Cybercrime%22%20%7D);"></div>
<p>If you do not know this blog, it is definitely worth looking at it from time to time: <a href="http://www.paleofuture.com/" target="_blank">Paleo-Future</a>.</p>
<p>There I found a prediction on cybercrime dated 1981:</p>
<p><a href="http://www.paleofuture.com/storage/1981%20computer%20criminals%20paleofuture.jpg" target="_blank"><img src="http://www.paleofuture.com/storage/1981%20computer%20criminals%20paleofuture.jpg" width="500" height="500"></a></p>
<p>It describes the impact of computers in the “future” – say today. If you click on the picture, you can see the original. </p>
<p>There is a good quote in there:</p>
<p><em>However, it is very difficult to carry out a successful robbery by computer. Many computers have secret codes to prevent anyone but their owners from operating them. As computers are used more and more, it is likely that computer crime will become increasingly difficult to carry out.</em></p>
<p><img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.halbheer.info/security/wp-content/uploads/2010/08/wlEmoticonsmile.png"> &#8211; the original post can be found here: <a href="http://www.paleofuture.com/blog/2009/3/23/computer-criminals-of-the-future-1981.html">Computer Criminals of the Future (1981)</a></p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/08/07/success-against-cybercrime' rel='bookmark' title='Permanent Link: Success against Cybercrime'>Success against Cybercrime</a></li>
<li><a href='http://www.halbheer.info/security/2010/08/17/are-we-losing-the-fight-against-cybercrime' rel='bookmark' title='Permanent Link: Are We Losing the Fight Against Cybercrime?'>Are We Losing the Fight Against Cybercrime?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/24/sans-commits-1-million-to-fight-cybercrime-in-developing-countries' rel='bookmark' title='Permanent Link: SANS Commits $1 Million to Fight Cybercrime in Developing Countries'>SANS Commits $1 Million to Fight Cybercrime in Developing Countries</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/08/11/the-future-of-cybercrime/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Success against Cybercrime</title>
		<link>http://www.halbheer.info/security/2010/08/07/success-against-cybercrime</link>
		<comments>http://www.halbheer.info/security/2010/08/07/success-against-cybercrime#comments</comments>
		<pubDate>Sat, 07 Aug 2010 19:21:38 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/08/07/success-against-cybercrime</guid>
		<description><![CDATA[I just read this article E-crime unit arrests suspected phishing gang, which shows that we are making progress in fighting cybercrime. Very good news Roger Related posts:Council of Europe &#8211; Octopus Conference (Cooperation against Cybercrime) &#8211; Key Messages Council of &#8230; <a href="http://www.halbheer.info/security/2010/08/07/success-against-cybercrime">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/03/26/council-of-europe-octopus-conference-cooperation-against-cybercrime-key-messages' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) &ndash; Key Messages'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) &ndash; Key Messages</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/24/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-2' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/24/council-of-europe-we-need-one-cybercrime-convention' rel='bookmark' title='Permanent Link: Council of Europe: We need ONE Cybercrime Convention'>Council of Europe: We need ONE Cybercrime Convention</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F08%252F07%252Fsuccess-against-cybercrime%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Success%20against%20Cybercrime%22%20%7D);"></div>
<p>I just read this article <a href="http://www.zdnet.co.uk/news/security-threats/2010/08/05/e-crime-unit-arrests-suspected-phishing-gang-40089746/" target="_blank">E-crime unit arrests suspected phishing gang</a>, which shows that we are making progress in fighting cybercrime. Very good news</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/03/26/council-of-europe-octopus-conference-cooperation-against-cybercrime-key-messages' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) &ndash; Key Messages'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) &ndash; Key Messages</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/24/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-2' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/24/council-of-europe-we-need-one-cybercrime-convention' rel='bookmark' title='Permanent Link: Council of Europe: We need ONE Cybercrime Convention'>Council of Europe: We need ONE Cybercrime Convention</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/08/07/success-against-cybercrime/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</title>
		<link>http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885</link>
		<comments>http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885#comments</comments>
		<pubDate>Fri, 02 Jul 2010 11:25:20 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885</guid>
		<description><![CDATA[I blogged about the vulnerability which was publically disclosed by a researcher working for Google earlier this month. In the meantime the attacks started to increase. I think that it would be important for you to look at what is &#8230; <a href="http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete' rel='bookmark' title='Permanent Link: Vulnerability Disclosure to Compete?'>Vulnerability Disclosure to Compete?</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/18/end-of-support-for-windows-2000-and-windows-xp-sp2' rel='bookmark' title='Permanent Link: End of Support for Windows 2000 and Windows XP SP2'>End of Support for Windows 2000 and Windows XP SP2</a></li>
<li><a href='http://www.halbheer.info/security/2008/11/26/attacks-on-ms08-067' rel='bookmark' title='Permanent Link: Attacks on MS08-067'>Attacks on MS08-067</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F07%252F02%252Fattacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Attacks%20on%20the%20Windows%20Help%20and%20Support%20Center%20Vulnerability%20%28CVE-2010-1885%29%22%20%7D);"></div>
<p>I blogged about the vulnerability which was publically disclosed by a researcher working for Google <a href="http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete" target="_blank">earlier this month</a>. In the meantime the attacks started to increase. I think that it would be important for you to look at what is going on. There is a good blog post by our malware protection center: <a href="http://blogs.technet.com/b/mmpc/archive/2010/06/30/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885.aspx" target="_blank">Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete' rel='bookmark' title='Permanent Link: Vulnerability Disclosure to Compete?'>Vulnerability Disclosure to Compete?</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/18/end-of-support-for-windows-2000-and-windows-xp-sp2' rel='bookmark' title='Permanent Link: End of Support for Windows 2000 and Windows XP SP2'>End of Support for Windows 2000 and Windows XP SP2</a></li>
<li><a href='http://www.halbheer.info/security/2008/11/26/attacks-on-ms08-067' rel='bookmark' title='Permanent Link: Attacks on MS08-067'>Attacks on MS08-067</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is a Copy Machine Your Biggest Security Risk?</title>
		<link>http://www.halbheer.info/security/2010/06/26/is-a-copier-your-biggest-security-risk</link>
		<comments>http://www.halbheer.info/security/2010/06/26/is-a-copier-your-biggest-security-risk#comments</comments>
		<pubDate>Sat, 26 Jun 2010 07:59:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Trends]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/06/26/is-a-copier-your-biggest-security-risk</guid>
		<description><![CDATA[Probably not. However, it indefinitely is a security risk. We are talking about this since a looooooong time as such copiers are sold since 2002. I just recently heard that the criminals are looking into this heavily and now it &#8230; <a href="http://www.halbheer.info/security/2010/06/26/is-a-copier-your-biggest-security-risk">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/08/10/assessing-the-risk-of-the-august-security-updates' rel='bookmark' title='Permanent Link: Assessing the risk of the August security updates'>Assessing the risk of the August security updates</a></li>
<li><a href='http://www.halbheer.info/security/2008/11/05/lottery-scams-one-of-the-biggest-threat-to-end-users' rel='bookmark' title='Permanent Link: Lottery Scams &#8211; One of the Biggest Threat to End Users'>Lottery Scams &#8211; One of the Biggest Threat to End Users</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/more-of-a-third-of-software-is-stolen' rel='bookmark' title='Permanent Link: More of a third of software is stolen'>More of a third of software is stolen</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F26%252Fis-a-copier-your-biggest-security-risk%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Is%20a%20Copy%20Machine%20Your%20Biggest%20Security%20Risk%3F%22%20%7D);"></div>
<p>Probably not. However, it indefinitely is a security risk. We are talking about this since a looooooong time as such copiers are sold since 2002. I just recently heard that the criminals are looking into this heavily and now it is even discussed publically on BCS News: <a href="http://www.cbsnews.com/video/watch/?id=6412572n" target="_blank">Copy Machines, a Security Risk?</a></p>
<p>Actually a really good video.</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/08/10/assessing-the-risk-of-the-august-security-updates' rel='bookmark' title='Permanent Link: Assessing the risk of the August security updates'>Assessing the risk of the August security updates</a></li>
<li><a href='http://www.halbheer.info/security/2008/11/05/lottery-scams-one-of-the-biggest-threat-to-end-users' rel='bookmark' title='Permanent Link: Lottery Scams &#8211; One of the Biggest Threat to End Users'>Lottery Scams &#8211; One of the Biggest Threat to End Users</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/more-of-a-third-of-software-is-stolen' rel='bookmark' title='Permanent Link: More of a third of software is stolen'>More of a third of software is stolen</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/26/is-a-copier-your-biggest-security-risk/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Notebook searches at a country border</title>
		<link>http://www.halbheer.info/security/2010/06/14/notebook-searches-at-a-country-border</link>
		<comments>http://www.halbheer.info/security/2010/06/14/notebook-searches-at-a-country-border#comments</comments>
		<pubDate>Mon, 14 Jun 2010 11:08:24 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Policies]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1555</guid>
		<description><![CDATA[I guess you still know the discussions a while ago where it was made public that notebooks can be searched without suspicion when you cross the border to the US. Actually the truth is, that this can happen everywhere as &#8230; <a href="http://www.halbheer.info/security/2010/06/14/notebook-searches-at-a-country-border">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/20/schneier-on-us-customs-notebook-searches-do-not-follow-the-rules' rel='bookmark' title='Permanent Link: Schneier on US Customs Notebook Searches: Do not follow the rules'>Schneier on US Customs Notebook Searches: Do not follow the rules</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud' rel='bookmark' title='Permanent Link: Legal Challenges of International Business and the Cloud'>Legal Challenges of International Business and the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F14%252Fnotebook-searches-at-a-country-border%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Notebook%20searches%20at%20a%20country%20border%22%20%7D);"></div>
<p>I guess you still know the discussions a while ago where it was made public that notebooks can be searched without suspicion when you cross the border to the US. Actually the truth is, that this can happen everywhere as far as I understand. To be clear: I am not a lawyer, I am an engineer. However, when I discussed this with a lawyer, he explained to me that anything I carry with me when I cross a border can be searched – something we got used to, no? The notebook is just part of the “anything” in the statement above.</p>
<p>So, the nervousness is really about the customs officer keeping a notebook and getting access to the data, which is scary but again, is this any different to carrying paper across the border – except for the sheer volume but basically if you carry confidential documents across any country’s border the customs officer can search you and have a look at your paper.</p>
<p>So far so good but it seems that some customs officers took their time when they actually wanted to search a notebook – a few months until an year.  They simply kept it. Now a court in the US ruled that this is illegal: <a href="http://news.cnet.com/8301-13578_3-20007315-38.html" target="_blank">Judge limits DHS laptop border searches</a></p>
<p>So, while the search at entry is still acceptable due to the points I made above, the confiscation of a computer for a longer period of time seems to be illegal. Will be interesting to see how this will develop.</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/20/schneier-on-us-customs-notebook-searches-do-not-follow-the-rules' rel='bookmark' title='Permanent Link: Schneier on US Customs Notebook Searches: Do not follow the rules'>Schneier on US Customs Notebook Searches: Do not follow the rules</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud' rel='bookmark' title='Permanent Link: Legal Challenges of International Business and the Cloud'>Legal Challenges of International Business and the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/14/notebook-searches-at-a-country-border/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Should the Government be able to enforce security updates?</title>
		<link>http://www.halbheer.info/security/2010/06/13/should-the-government-be-able-to-enforce-security-updates</link>
		<comments>http://www.halbheer.info/security/2010/06/13/should-the-government-be-able-to-enforce-security-updates#comments</comments>
		<pubDate>Sun, 13 Jun 2010 08:59:05 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Terrorism]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[International]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1552</guid>
		<description><![CDATA[This is actually an interesting question. A lot of governments enforce rules and regulations on how you have to run your car, how often you have to check it, in which condition you have to keep your tires etc. The &#8230; <a href="http://www.halbheer.info/security/2010/06/13/should-the-government-be-able-to-enforce-security-updates">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/16/the-importance-of-international-collaborationeven-in-exercises' rel='bookmark' title='Permanent Link: The Importance of International Collaboration&ndash;Even in Exercises'>The Importance of International Collaboration&ndash;Even in Exercises</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/21/analysis-of-the-estonian-attacks' rel='bookmark' title='Permanent Link: Analysis of the Estonian Attacks'>Analysis of the Estonian Attacks</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F13%252Fshould-the-government-be-able-to-enforce-security-updates%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Should%20the%20Government%20be%20able%20to%20enforce%20security%20updates%3F%22%20%7D);"></div>
<p>This is actually an interesting question. A lot of governments enforce rules and regulations on how you have to run your car, how often you have to check it, in which condition you have to keep your tires etc. The same is true for a lot of other devices we are using.</p>
<p>Now, it seems that the US just passed <a href="http://www.nextgov.com/nextgov/ng_20100610_9392.php?oref=topstory" target="_blank">a bill to give the president the power to order companies to deploy security updates or block a certain type of traffic</a>. I understand where this is coming from: You need some level of authority if your critical infrastructure is under attack. Here, a lot of governments rely on the collaboration of the different players. The US seems to go one step further. Honestly, I am not completely sure whether I like it or not. It has a lot of pros and cons.</p>
<p>What is your view?</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/16/the-importance-of-international-collaborationeven-in-exercises' rel='bookmark' title='Permanent Link: The Importance of International Collaboration&ndash;Even in Exercises'>The Importance of International Collaboration&ndash;Even in Exercises</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/21/analysis-of-the-estonian-attacks' rel='bookmark' title='Permanent Link: Analysis of the Estonian Attacks'>Analysis of the Estonian Attacks</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/13/should-the-government-be-able-to-enforce-security-updates/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Disclosure to Compete?</title>
		<link>http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete</link>
		<comments>http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete#comments</comments>
		<pubDate>Fri, 11 Jun 2010 07:36:54 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Competition]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1547</guid>
		<description><![CDATA[As you know (I stress that fairly often ), I am Swiss. The reason why I am stressing this today is that I want to give you an example on security from the Swiss market: The banks here on place &#8230; <a href="http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities' rel='bookmark' title='Permanent Link: How to Deal With Vulnerabilities'>How to Deal With Vulnerabilities</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885' rel='bookmark' title='Permanent Link: Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)'>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/selling-vulnerabilities-and-ethics' rel='bookmark' title='Permanent Link: Selling Vulnerabilities and Ethics'>Selling Vulnerabilities and Ethics</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F11%252Fvulnerability-disclosure-to-compete%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Vulnerability%20Disclosure%20to%20Compete%3F%22%20%7D);"></div>
<p>As you know (I stress that fairly often <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> ), I am Swiss. The reason why I am stressing this today is that I want to give you an example on security from the Swiss market: The banks here on place compete with each other – obviously. However, I have never seen the banks competing on security. They never use for example new authentication schemes in eBanking to compete. There is nothing like “our eBank is more secure than our competitor&#8217;s” or “have you seen, our competitor was just successfully phished”. The reason for that is fairly simple: The whole banking system will lose as trust will erode in the ecosystem as such if they start to blame each other and this is not to the advantage of all the banks.</p>
<p>Why do I tell you this? Well, as you know, we at Microsoft are promoting responsible disclosure of vulnerabilities since years. We do not buy vulnerabilities and if we find vulnerabilities in third party products, we let the vendor know and help them to fix the issue. This is to protect the ecosystem, to protect our customers as public, irresponsible disclosure puts all our joint customers at risk.</p>
<p>By the way, on a side-note I want to make sure you have seen the advisory we release yesterday on a <em>Vulnerability in Windows Help and Support Center Could Allow Remote Code Execution</em> as it might be important for you to understand the workarounds. The history of this vulnerability can be found here: <a href="/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx" target="_blank">Windows Help Vulnerability Disclosure</a>. I just want to quote the blog post: <em>This issue was reported to us on June 5<sup>th</sup>, 2010 by a Google security researcher and then made public less than four days later, on June 9<sup>th</sup>, 2010.  Public disclosure of the details of this vulnerability and how to exploit it, without giving us time to resolve the issue for our potentially affected customers, makes broad attacks more likely and puts customers at risk</em></p>
<p>…</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities' rel='bookmark' title='Permanent Link: How to Deal With Vulnerabilities'>How to Deal With Vulnerabilities</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885' rel='bookmark' title='Permanent Link: Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)'>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/selling-vulnerabilities-and-ethics' rel='bookmark' title='Permanent Link: Selling Vulnerabilities and Ethics'>Selling Vulnerabilities and Ethics</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Open Source and Hackers</title>
		<link>http://www.halbheer.info/security/2010/06/09/open-source-and-hackers</link>
		<comments>http://www.halbheer.info/security/2010/06/09/open-source-and-hackers#comments</comments>
		<pubDate>Wed, 09 Jun 2010 11:45:32 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Behavior]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[OpenSource]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1543</guid>
		<description><![CDATA[The debate is probably as old as the Open Source software development model: Which one is more secure: Open Source or shared source as we at Microsoft run it? I know that we could now enter a religious debate about &#8230; <a href="http://www.halbheer.info/security/2010/06/09/open-source-and-hackers">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/20/the-debate-on-security-metrics' rel='bookmark' title='Permanent Link: The Debate on Security Metrics'>The Debate on Security Metrics</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/08/1541' rel='bookmark' title='Permanent Link: We Need Solid and Strong Transparent Processes for the Cloud'>We Need Solid and Strong Transparent Processes for the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/08/24/the-importance-of-application-security' rel='bookmark' title='Permanent Link: The Importance of Application Security'>The Importance of Application Security</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F09%252Fopen-source-and-hackers%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Open%20Source%20and%20Hackers%22%20%7D);"></div>
<p>The debate is probably as old as the Open Source software development model: Which one is more secure: Open Source or shared source as we at Microsoft run it? I know that we could now enter a religious debate about that, which I do not want to as I do not really believe in the value of such debate.</p>
<p>However, it is always interesting to see who is looking how at this debate. Does it help security if everyone can see the code or does it help the attackers? We have a program which we call <a href="http://www.microsoft.com/resources/sharedsource/gsp.mspx" target="_blank">Government Security Program</a>, giving governments under certain circumstances (e.g. protection of intellectual property) access to our source. Sometimes we have the debate with government officials whether having access to the code could allow an attacking government to get an advantage in the area or cyberwar or cyber espionage. Looking at that debate, OpenSource would even be worse as it means access for everybody.</p>
<p>Now, I just read this article: <a href="http://www.technologyreview.com/computing/25480/?a=f" target="_blank">Open-Source Could Mean an Open Door for Hackers</a>. It is about a paper looking at data from Intrusion Detection Systems and their finding is that <em>flaws in open-source software tend to be attacked more quickly and more often than vulnerabilities in closed-source software. </em>An interesting statement in the light that we know that there are more vulns in OpenSource software than in shared source and fairly often it is because of the lack of processes enforced to engineer security into the product from the beginning.</p>
<p>Another thing which is important to me is <em>&#8220;As defenders get out their patches, the attackers have more incentive to move on to a different exploit,&#8221; Ransbotham </em>[the author of the paper] <em>says. </em>In other words, having a strong incident response (besides the engineering process) is at least as important.</p>
<p>This should be something the industry adopts. We made our engineering process called <a href="http://www.microsoft.com/security/sdl/default.aspx" target="_blank">Security Development Lifecycle</a> public and I think our incident response is wide known as well as being a best practice. So, something people should finally come to adopt</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/20/the-debate-on-security-metrics' rel='bookmark' title='Permanent Link: The Debate on Security Metrics'>The Debate on Security Metrics</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/08/1541' rel='bookmark' title='Permanent Link: We Need Solid and Strong Transparent Processes for the Cloud'>We Need Solid and Strong Transparent Processes for the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/08/24/the-importance-of-application-security' rel='bookmark' title='Permanent Link: The Importance of Application Security'>The Importance of Application Security</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/09/open-source-and-hackers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
