<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4482521283458453577.post7099374738219727944..comments</id><updated>2008-12-18T09:09:47.852-08:00</updated><category term='SCCM'/><category term='AES'/><category term='the force'/><category term='jedi'/><category term='risk management'/><category term='passwords'/><category term='nbnsspoof'/><category term='youngling'/><category term='diversion'/><category term='updates'/><category term='externality'/><category term='bullshit'/><category term='help'/><category term='Outlook Web Access'/><category term='OS X'/><category term='gnome'/><category term='quality assurance'/><category term='encryption'/><category term='backtrack'/><category term='risk modeling'/><category term='auditing'/><category term='nbnspoof'/><category term='sith'/><category term='metrics'/><category term='python'/><category term='rails'/><category term='contact'/><category term='pointsec'/><category term='DMCA'/><category term='script'/><category term='dark side'/><category term='data loss prevention'/><category term='lockpicking'/><category term='fde'/><category term='NPV'/><category term='Application Layer Firewall'/><category term='New School'/><category term='lightsaber'/><category term='Form 0'/><category term='snort'/><category term='black fist'/><category term='monte carlo'/><category term='linux'/><category term='Book Review'/><category term='change management'/><category term='incident response'/><category term='openbsd'/><category term='PCI'/><category term='VMWare'/><category term='form III'/><category term='relayd'/><category term='security'/><category term='information'/><category term='novell'/><category term='awkward'/><category term='padawan'/><category term='policies'/><category term='video tutorial'/><category term='jar jar binks'/><category term='forensics'/><category term='TrustedSource'/><category term='mind trick'/><category term='form II'/><category term='phishing'/><category term='copyright'/><category term='economics'/><category term='antivirus'/><category term='blogger'/><category term='unix'/><category term='mac'/><category term='R72'/><category term='event logs'/><category term='Deadly Whisper'/><category term='Sidewinder'/><category term='Ubuntu'/><category term='project management'/><category term='statistics'/><category term='google'/><title type='text'>Comments on Black Fist Security: Does it seem like people with more education are h...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.blackfistsecurity.com/feeds/7099374738219727944/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html'/><author><name>kevin thompson</name><uri>https://profiles.google.com/107682921975811187169</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-njbZ3e90-4I/AAAAAAAAAAI/AAAAAAAAAP8/tYdzjKjLpUg/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-8906575126221190659</id><published>2008-12-18T09:09:00.000-08:00</published><updated>2008-12-18T09:09:00.000-08:00</updated><title type='text'>Being a university faculty myself, let me provide ...</title><content type='html'>Being a university faculty myself, let me provide my perspective on the subject of faculty being harder to educate and on the need for improved security education/awareness.&lt;BR/&gt;&lt;BR/&gt;First of all, faculty members who have tenure (myself included) can be quite stubborn and may as you put it "thick-headed."  Some of that may come from an attitude of "if it ain't broke, don't fix it" stemming from years of administration-backed changes that seem to have little positive impact on the primary mission of the university, i.e. teaching.&lt;BR/&gt;&lt;BR/&gt;However, I suspect that there's a deeper mechanism at work here, namely that the very  "thought leaders" and "lifelong learners" that you have identified focus the subject of their lifelong learning so narrowly as to become unable to absorb new concepts, ideas, or worse change their way of thinking.&lt;BR/&gt;&lt;BR/&gt;On a concept like information security in which technology and practices need to adapt to the changes in the threat environment, I find that many of my faculty colleagues are thinking more like dinosaurs rather than "thought leaders." Most security professionals would agree that what worked yesterday (or last month, or last year, or 10 years ago) may not work tomorrow. Yet, many faculty continue to act and think as if what they've come to know and experience in the near or distant past will continue to hold true.&lt;BR/&gt;&lt;BR/&gt;On the subject of the phishing emails, the simple act of questioning the validity of an email message, or a message received via more traditional means, goes contrary to the environment of trust and sharing that adorns academia. Faculty may, by the very nature of their training and conditioning, be more susceptible to phishing than the average user.&lt;BR/&gt;&lt;BR/&gt;Finally, you are absolutely correct in wanting to ensure better security for ALL the machines within your domain, faculty and lab machines included. I am a firm believer in the validity of the configuration standards that you mention for all publicly visible servers. If a faculty (or staff) doesn't know what TCP, SMTP, or DNS are, then they should not be administering the server, at least not on their own. I see a need for cooperation here, where IT services and others can agree to share the administration of these servers in order to provide a valuable service (the reason that the server is up in the first place) with reasonable security and patching processes (to make security managers happy and keep hackers at bay).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default/8906575126221190659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default/8906575126221190659'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html?showComment=1229620140000#c8906575126221190659' title=''/><author><name>DrInfoSec</name><uri>http://www.blogger.com/profile/04203172703592313484</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-7099374738219727944' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/7099374738219727944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1749483130'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-2181671368422141964</id><published>2008-12-08T07:54:00.000-08:00</published><updated>2008-12-08T07:54:00.000-08:00</updated><title type='text'>Indeed, this is not an isolated phenomenon</title><content type='html'>Indeed, this is not an isolated phenomenon</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default/2181671368422141964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default/2181671368422141964'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html?showComment=1228751640000#c2181671368422141964' title=''/><author><name>Matt and Brandy</name><uri>http://www.blogger.com/profile/17729544036391954258</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-7099374738219727944' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/7099374738219727944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1427026435'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-7669112185017911996</id><published>2008-12-06T16:07:00.000-08:00</published><updated>2008-12-06T16:07:00.000-08:00</updated><title type='text'>I'm not surprised, but unfortunately I have no bet...</title><content type='html'>I'm not surprised, but unfortunately I have no better insight into this, other than to confirm that it's not just your university.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default/7669112185017911996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/7099374738219727944/comments/default/7669112185017911996'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html?showComment=1228608420000#c7669112185017911996' title=''/><author><name>Michael Janke ' or 1=1 --</name><uri>http://www.blogger.com/profile/00357905802460949707</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04760442407271622658'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://bp2.blogger.com/_MzTxs5YYjdk/SAJvvQ0hryI/AAAAAAAAAQ0/lqiaj2S3ONc/S220/mJanke.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2008/12/does-it-seem-like-people-with-more.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-7099374738219727944' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/7099374738219727944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566504464'/></entry></feed>
