<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title>Michal Sobiegraj | Security Consultant and Evangelist</title>
      <link>http://sobiegraj.com/blog/</link>
      <description></description>
      <language>en</language>
      <copyright>Copyright 2008</copyright>
      <lastBuildDate>Sun, 28 Sep 2008 16:11:42 +0100</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>Why is security awareness important</title>
         <description><![CDATA[<p>Since you are reading this, you probably think security is oh-so important. Well, here is a funny surprise: turns out most people out there actually think that living their lives, doing their business and running their errands  is way more important.</p>

<p>And some of them actually have an idea <a href="http://sethgodin.typepad.com/seths_blog/2008/09/random-travel-t.html">how to make things better</a>. Worth taking into account when your business relies on people buying your security solutions or services. It seems like the very least you should do is to make sure your users and customers understand how THEY benefit from the introduced security measures and why the inconveniences they introduce are absolutely necessary for them to work. And better make sure they really are necessary.<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/09/why_is_security_awareness_impo_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/09/why_is_security_awareness_impo_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Marketing security</category>
        
        
         <pubDate>Sun, 28 Sep 2008 16:11:42 +0100</pubDate>
      </item>
            <item>
         <title>Cartoons</title>
         <description><![CDATA[<div style='float: left;padding-right: 10px;'><a href="http://www.flickr.com/photos/brandcamp/2240150178/in/set-72157603843758644/"><img src="http://farm3.static.flickr.com/2028/2240150178_e6264a7f40_m.jpg" style="width: 240px; height: 185px;" /></a></div>

<p>Last week <a href="http://skydeckcartoons.com/">Tom Fishburne’s</a> <a href="http://stores.lulu.com/tomfishburne">This One Time at Brand Camp</a> (his latest cartoon book) got to me finally and I’m here to report to you that it’s been a wonderful read! The cartoons generally talk about marketing. I’m not a marketing pro or anything, you probably know this, so I think I am a pretty good test for Tom’s toons and their amusingness to a layperson. And I have to say, they passed the test surprisingly well. Even better, I learned quite a bit while laughing out loud. Can you wish for more?</p>

<p>One of the best cartoons from the book (in my opinion of curse) is the one on the left (click it to enlarge).</p>

<p>Brilliant! Not even a word and the message is crystal clear. Makes you nod and go “Right. That’s how it is.” Just brilliant!</p>

<p>Great job Tom! Please keep it going :-)<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/09/cartoons.html</link>
         <guid>http://sobiegraj.com/blog/2008/09/cartoons.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Miscellaneous</category>
        
        
         <pubDate>Tue, 23 Sep 2008 14:46:10 +0100</pubDate>
      </item>
            <item>
         <title>Usable data encryption for mobile devices</title>
         <description><![CDATA[<p>It comes to be more and more tempting to store and process important business docs on our mobiles/smart-phones as the devices keep growing bigger, mightier and more usable. Together with the time saving benefits we get from being able to do the work while on the go, there is also a still growing danger of our precious information being stolen together with the device and used by a thief for whatever evil purpose they intend it to use.</p>

<p>And face it, you wouldn’t work on a report or an email while in a cab or a plane if it wasn’t an essential and really urgent thing to do. So, I guess we can safely assume that the data you have on the device may be worth a lot for someone who knows this and that about your business.</p>

<p>So, what options do we have here? Not getting much into technical details, let’s just try to figure out what could work for someone who most importantly wants to do their job without their phone driving them nuts and secondly wants the solution to provide a reasonable level of security to the precious data in it. It’s quite obvious that we need to encrypt, but how? Again, technical details aside, let’s just focus on user-device interaction.</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/09/usable_data_encryption_for_mob_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/09/usable_data_encryption_for_mob_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security</category>
        
        
         <pubDate>Fri, 19 Sep 2008 15:52:36 +0100</pubDate>
      </item>
            <item>
         <title>ISSA meetings in Wrocław back after summer (Sep 23, 2008)</title>
         <description><![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/issa-logo-small.png' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='110' width='200'/></div>

<p>[UPDATE: If you are planning to come to the meeting, we will need your name in order for security to let you into the building. So, please send us an email with a subject "[ISSA] Potwierdzenie udziału w spotkaniu - Wroclaw 2008-09-23" to wroclaw at issa.org.pl</p>

<p>Be sure to actually include your name!]</p>

<p><br />
I’m happy to invite you to this month’s ISSA meeting on September 23. We'll be talking about security policies and, more on the technical side, about DNS cache poisoning.</p>

<p>When: September 23, 6:30 PM</p>

<p>Where: <a href="http://maps.google.com/maps?f=q&hl=pl&geocode=&q=pl.+Grunwaldzki+25,+Wroc%C5%82aw+&ie=UTF8&ll=51.114246,17.061253&spn=0.011261,0.026479&z=15&iwloc=cent">Credit Suisse, Grunwaldzki Center building B, fourth floor, Grunwaldzki Square 25, Wrocław</a></p>

<p>Agenda:<br />
1. Welcome after summer - Michał Sobiegraj<br />
2. Development and Deployment of Security Policies - Radek Michalski<br />
3. DNS Cache Poisoning (recent update) - Jarek Sajko</p>

<p>We plan to end the official part of the meeting around 8:30.</p>

<p>See you!<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/09/issa_meetings_in_wroclaw_back_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/09/issa_meetings_in_wroclaw_back_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
        
        
         <pubDate>Sun, 14 Sep 2008 14:48:07 +0100</pubDate>
      </item>
            <item>
         <title>New biz-cards</title>
         <description><![CDATA[<div style='float: right'><a href="http://flickr.com/photos/sobiegraj/2850040617/"><img src='http://farm4.static.flickr.com/3157/2850040617_9249b5c9f0_m.jpg' alt='Biz-cards' style='margin: 10px 5px 10px 10px;border: 1px solid #aaa;' height='180' width='250'/></a></div>

<p>As some say (me included), it’s nice to give people something of value just the moment you first meet. It binds. And what is of more value than an insightful point delivered in a funny way? Plus it doesn’t cost you much and has potential to change the world (a wee bit, but still).</p>

<p>So why not add some value to the usual biz-card exchange? Say, in form of couple of valuable words on the back side of a card? And I bet you can also make it fun to read. In order to boost up the fun factor I used couple of doodles by <a href="http://www.gapingvoid.com/">Hugh MacLeod</a>.</p>

<p>If you want to print each card with a unique picture on the back, <a href="http://www.moo.com/">moo.com</a> is the place.<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/09/new_bizcards_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/09/new_bizcards_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Miscellaneous</category>
        
        
         <pubDate>Fri, 12 Sep 2008 14:26:06 +0100</pubDate>
      </item>
            <item>
         <title>IT Risk management in Wrocław once again (July 23.)</title>
         <description><![CDATA[<p>Since the meeting didn’t work out the last time due to some unexpected circumstances, please let me invite you to the event again. The agenda stays the same.</p>

<p><strong>When</strong>: July 23, 6PM</p>

<p><strong>Where</strong>: Credit Suisse, <a href="http://maps.google.com/maps?f=q&hl=pl&geocode=&q=poland,+wroc%C5%82aw,+szewska+5&sll=37.0625,-95.677068&sspn=60.635244,108.457031&ie=UTF8&ll=51.109989,17.033958&spn=0.011936,0.026479&z=15&iwloc=addr">Kameleon building at Szewska st.</a>, 1st. floor</p>

<p>See you at the meeting!<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/07/it_risk_management_in_wroclaw.html</link>
         <guid>http://sobiegraj.com/blog/2008/07/it_risk_management_in_wroclaw.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
        
        
         <pubDate>Wed, 09 Jul 2008 17:02:12 +0100</pubDate>
      </item>
            <item>
         <title>IT Risk management in Wrocław on July 3.</title>
         <description><![CDATA[<p>I haven't posted in ages! I've even managed to forget the MT backend script name (not to mention I've lost my bookmarks somewhere down the road). But I'm back! Unfortunately I'm still busy as... well... as someone very busy, so I'll keep it short this time.</p>

<p>To the point: if you're from Wrocław area or if you happen to be around on July 3, be sure to come to the ISSA Polska meeting in Wrocław. We plan the meeting to be real fun this time. We'll be having a guest from Credit Suisse IT Risk dept. giving a talk. We also plan to discuss latest incidents in Poland.</p>

<p>When: July 3, 6PM</p>

<p>Where: Credit Suisse, <a href=" http://maps.google.com/maps?f=q&hl=pl&geocode=&q=poland,+wroc%C5%82aw,+szewska+5&sll=37.0625,-95.677068&sspn=60.635244,108.457031&ie=UTF8&ll=51.109989,17.033958&spn=0.011936,0.026479&z=15">Kameleon building at Szewska st.</a>, 1st. floor</p>

<p>See you there!</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/06/it_risk_management_in_wroclaw_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/06/it_risk_management_in_wroclaw_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
        
        
         <pubDate>Sat, 28 Jun 2008 14:43:59 +0100</pubDate>
      </item>
            <item>
         <title>A piece of phishing email</title>
         <description><![CDATA[<p>Not that long ago I got this:</p>

<p><img style='margin: 10px 5px 10px 10px;' src="http://sobiegraj.com/gfx/visa.jpg" width="400" height="400" alt="VISA phishing email" /></p>

<p>When was the last time you got a phishing email? Not that long ago, I bet. Me too. There is nothing unusual in it, nowadays we get so much of it that we simply get used to it and usually just silently delete or ignore it (if spam filters don’t do it for us).</p>

<p>So, why am I talking about this? Well, because of a funny coincidence. Or maybe it wasn’t that much of a coincidence… Here is the story.</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/05/a_piece_of_phishing_email_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/05/a_piece_of_phishing_email_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security</category>
        
        
         <pubDate>Tue, 06 May 2008 16:25:04 +0100</pubDate>
      </item>
            <item>
         <title>Fifth ISSA meeting in Wroclaw (May 19, 2008)</title>
         <description><![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/ISSA-Polska.jpg' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='60' width='200'/></div>

<p>We're gonna do it for the fifth time already! Whooohoo! :)</p>

<p>This time the main theme will be Intrusion Detection Systems and Web Application Firewalls. Also a discussion panel is planned so that we all could shout at each other and throw blunt objects in each other’s general directions.<br />
Here is the agenda:</p>

<p>1.	A warm welcome (myself)<br />
2.	Intrusion Detection Systems (Wojtek Wirkijowski)<br />
3.	Web Application Firewalls (Edward Weinert)<br />
4.	Discussion Panel (Andrzej Piotr Kleśnicki)</p>

<p>And as always, there is a prize to be won.</p>

<p>See you at the meeting!<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/05/fifth_issa_meeting_in_wroclaw_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/05/fifth_issa_meeting_in_wroclaw_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
        
        
         <pubDate>Tue, 06 May 2008 13:14:15 +0100</pubDate>
      </item>
            <item>
         <title>A funny thing with Thunderbird</title>
         <description><![CDATA[<p>I’m using Thunderbird as my email client on a daily basis. Not that long ago I’ve been trying to send a PDF document, that I previously got from the Web, as an email attachment. To my surprise the normal drag’n’drop and send routine didn’t do it. A short glance at the filename made it obvious &mdash; the percent-encoded forward slashes (<tt>%2F</tt>) in the filename got in the way.</p>

<p>As probably most of you guys, I’m not spending my day fuzzing stuff, but, probably as most of you again, I’m bumping over a software glitch from time to time. Sometimes, when I’m in the mood, I’m poking the hole to see what happens. </p>

<p>And I was in the mood that day.</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/04/a_funny_thing_with_thunderbird.html</link>
         <guid>http://sobiegraj.com/blog/2008/04/a_funny_thing_with_thunderbird.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security</category>
        
        
         <pubDate>Wed, 30 Apr 2008 10:48:22 +0100</pubDate>
      </item>
            <item>
         <title>After ISSA Wroclaw meeting #4</title>
         <description><![CDATA[<div style='float: right'><a href="http://www.flickr.com/photos/sobiegraj/2410918613/" title="ISSA Wrocław"><img style='margin: 10px 5px 10px 10px;' src="http://farm4.static.flickr.com/3242/2410918613_3ccd984815_m.jpg" width="240" height="180" alt="ISSA Wrocław" /></a></div>

<p>It's been hands-on and it's been fun! :) Huge thanks goes to Edi Weinert and Tadeusz Kowalczyk who put all this together and made the whole thing possible. And of course thanks to you all! I hope you enjoyed the workshop and we'd really love to hear your comments on what we could do better next time.</p>

<p>Hope to see you next time! And in the meantime, be sure to click at the photo for more geeky shots.</p>

<p>Thank you all once again!</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/04/after_issa_wroclaw_meeting_4_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/04/after_issa_wroclaw_meeting_4_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
                  <category domain="http://www.sixapart.com/ns/types#category">Security</category>
        
        
         <pubDate>Mon, 14 Apr 2008 02:18:59 +0100</pubDate>
      </item>
            <item>
         <title>After the 3rd ISSA meeting in Wroclaw</title>
         <description><![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/ISSA-Polska.jpg' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='60' width='200'/></div>

<p>Thank you! Thanks to all of you who made it to the meeting despite the fact that we have changed the location twice. And my apologies to all of you, who didn’t. We will do our best to make sure it doesn’t happen anymore.</p>

<p>Despite all the trouble, the meeting was fun. We totally run out of schedule due to discussions that broke out during the first talk. Oh, and the cookies were awesome! Not to mention the coffee.</p>

<p>We have one piece of slides this time, so, for all of you who would like to go through the presentation again and for others that didn’t make it to the meeting, here it is.</p>

<div style="width:425px;text-align:left" id="__ss_304964"><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=issa-incident-responce-1205409194816616-3"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=issa-incident-responce-1205409194816616-3" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object></div>

<p>Thanks again and see you next month!<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/03/after_the_3rd_issa_meeting_in_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/03/after_the_3rd_issa_meeting_in_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
        
        
         <pubDate>Thu, 13 Mar 2008 14:34:27 +0100</pubDate>
      </item>
            <item>
         <title>Third ISSA meeting in Wroclaw (Mar 11, 2008)</title>
         <description><![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/ISSA-Polska.jpg' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='60' width='200'/></div>

<p>Let me invite you to another <a href="http://www.issa.org.pl/">ISSA</a> meeting in Wroclaw. It’s the third meeting already and this time we’ll be discussing <em>Computer Forensics</em> and <em>Incident Response</em>. We’ll be having a discussion panel as the last time and we’ll let you guys win some prizes in a <a href="http://groups.google.com/group/issa-polska-wroclaw/browse_thread/thread/c180c74ba33423c7">competition</a>.</p>

<p>All that and even more on <strong>Mar 11, 2008</strong> at <strong>6pm</strong>.</p>

<p>Where? <strike>At BZ WBK Wroclaw HQ, <strong>Rynek 9/11</strong> (second door if you look from the pl. Solny direction).</strike> At Politechnika Wroclawska, Janiszewskiego 11/17, building C3, room 118 (enter either through building C-1 or C-5).</p>

<p>An important note: you need to register for the meeting before Feb 4, 2008, 9pm at the latest. In order to register, please use the following <a href="mailto:wroclaw@issa.org.pl?subject=[ISSA] Potwierdzenie udziału w spotkaniu 2008-03-11">link</a>.</p>

<p><strong>UPDATE: This time we meet  at Politechnika Wroclawska, Janiszewskiego 11/17, building C3, room 118 (enter either through building C-1 or C-5).</strong><br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/03/third_issa_meeting_in_wroclaw.html</link>
         <guid>http://sobiegraj.com/blog/2008/03/third_issa_meeting_in_wroclaw.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">ISSA</category>
        
        
         <pubDate>Mon, 03 Mar 2008 14:25:53 +0100</pubDate>
      </item>
            <item>
         <title>Automatische Antwort</title>
         <description><![CDATA[<p>What do you think happens when some spamming bots pick up your email address and start using it as a source address when throwing discounted Viagra and almost-like-the-real-thing watch replicas crap at people in unbelievable amounts?</p>

<p>Tons, and I mean TONS, of "undeliverable message" bounces together with quite a lot of my favourites – out of office notes. When you think about it, quite a lot of information is being thrown at you in such messages. Here are some sanitised examples (all in German, as my email address sells on a German market, apparently).<br />
</p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/02/automatische_antwort_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/02/automatische_antwort_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Security</category>
        
        
         <pubDate>Mon, 25 Feb 2008 13:40:11 +0100</pubDate>
      </item>
            <item>
         <title>Xploit #1</title>
         <description><![CDATA[<p>For all of you guys around here in Poland, another opportunity to deepen your acquaintance with information security just appeared. The first issue of <a href="http://www.Xploit.pl/">Xploit</a> have just hit the shelves.</p>

<div style='float: right'><img src='http://sobiegraj.com/gfx/xploit1.jpg' alt='Xploit 1/2008' style='padding: 2px;margin: 10px 5px 10px 10px; border: 1px solid #aaa' height='250' width='179'/></div>

<p>What’s in it?<ul><li>A remote DoS on Vista,</li><li>A tale of a deadly <a href="http://code.google.com/android/">Android</a>,</li><li>A short story of hacking PSP,</li><li>Everything you ever wanted to know about hosting, but were afraid to ask,</li><li>Challenges of risk analysis,</li><li>Securing SQL Server 2005,</li><li>Polish law and hacking,</li><li>TPM in GNU/Linux,</li><li>and much, much more.</li></ul>All in Polish with a conventional live CD included.</p>

<p>I had a pleasure to share some thoughts on risk analysis in this issue, so be it only for that I really encourage you to visit your newsagent and give this fine new magazine a try. </p>]]>
         </description>
         <link>http://sobiegraj.com/blog/2008/02/xploit_1_1.html</link>
         <guid>http://sobiegraj.com/blog/2008/02/xploit_1_1.html</guid>
                  <category domain="http://www.sixapart.com/ns/types#category">Review</category>
                  <category domain="http://www.sixapart.com/ns/types#category">Security</category>
        
        
         <pubDate>Tue, 19 Feb 2008 12:28:34 +0100</pubDate>
      </item>
      
   </channel>
</rss>

