<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Uncorked</title>
	<atom:link href="http://securityuncorked.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securityuncorked.com</link>
	<description>JJ's Complete Unofficial Guide to InfoSec</description>
	<lastBuildDate>Tue, 09 Apr 2013 01:19:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Speaking on Consumerization and Security at SecureWorld Charlotte</title>
		<link>http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/</link>
		<comments>http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/#comments</comments>
		<pubDate>Tue, 09 Apr 2013 00:57:42 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1727</guid>
		<description><![CDATA[ShareHi folks! This week, I&#8217;ll be presenting The Mobile Edge: Consumerization and Security at the SecureWorld Charlotte event. Due to other scheule commitments Thursday, I&#8217;ll only be at the event Wednesday, April 10th. I asked for the Early Bird Session at 8:30, so I can tackle the task of waking you up. &#160; The Mobile [...]]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/" data-text="Speaking on Consumerization and Security at SecureWorld Charlotte"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F04%2Fconsumerization-secureworld-charlotte%2F&amp;linkname=Speaking%20on%20Consumerization%20and%20Security%20at%20SecureWorld%20Charlotte" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/','Speaking%20on%20Consumerization%20and%20Security%20at%20SecureWorld%20Charlotte')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F04%2Fconsumerization-secureworld-charlotte%2F&amp;title=Speaking%20on%20Consumerization%20and%20Security%20at%20SecureWorld%20Charlotte" id="wpa2a_6">Share</a></p><p>Hi folks!</p>
<p>This week, I&#8217;ll be presenting <em>The Mobile Edge: Consumerization and Security</em> at the <a href="http://secureworldexpo.com/event/index.php/2013-charlotte-home" target="_blank">SecureWorld Charlotte </a>event. Due to other scheule commitments Thursday, I&#8217;ll only be at the event Wednesday, April 10th. I asked for the Early Bird Session at 8:30, so I can tackle the task of waking you up.<span id="more-1727"></span><br />
<img class="size-full wp-image-1728 alignnone" title="SecureWorld-Expo" src="http://securityuncorked.com/wordpress/wp-content/uploads/2013/04/SecureWorld-Expo.jpg" alt="" width="128" height="91" /></p>
<p>&nbsp;</p>
<blockquote><p><strong>The Mobile Edge: Consumerization and Security</strong><br />
Wednesday, April 10th<br />
8:30am &#8211; 9:15am<br />
A dive in to maintaining security as consumer-grade mobile products enter the enterprise. Join this discussion and dialogue on BYOD, the consumerization of IT, and how to appropriately apply policy and technology to security the enterprise. This session is guided with best practices, common practices, emerging trends and technologies, and tips for evaluating and selecting solutions that will make you successful. We’ll also cultivate ideas for corporate policy and technical enforcement as part of an overall strategy for BYOD and consumerization.<br />
 </p></blockquote>
<ul>
<li>SecureWorld Charlotte Event<br />
<a href="http://secureworldexpo.com/event/index.php/2013-charlotte-home">http://secureworldexpo.com/event/index.php/2013-charlotte-home</a></li>
<li>The Mobile Edge &#8211; Session Details<br />
<a href="http://secureworldexpo.com/event/index.php/the-mobile-edge-consumerization-and-security-jennifer-minella">http://secureworldexpo.com/event/index.php/the-mobile-edge-consumerization-and-security-jennifer-minella</a></li>
</ul>
<p># # #</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/" data-text="Speaking on Consumerization and Security at SecureWorld Charlotte"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F04%2Fconsumerization-secureworld-charlotte%2F&amp;linkname=Speaking%20on%20Consumerization%20and%20Security%20at%20SecureWorld%20Charlotte" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/','Speaking%20on%20Consumerization%20and%20Security%20at%20SecureWorld%20Charlotte')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F04%2Fconsumerization-secureworld-charlotte%2F&amp;title=Speaking%20on%20Consumerization%20and%20Security%20at%20SecureWorld%20Charlotte" id="wpa2a_8">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2013/04/consumerization-secureworld-charlotte/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where to find JJ at RSA 2013 &#8211; NAC, certs, SBN and more</title>
		<link>http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/</link>
		<comments>http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/#comments</comments>
		<pubDate>Tue, 19 Feb 2013 21:00:24 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[NAC & 802.1X]]></category>
		<category><![CDATA[(ISC)2]]></category>
		<category><![CDATA[Certifications]]></category>
		<category><![CDATA[nac]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[RSA 2013]]></category>
		<category><![CDATA[SBN]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1713</guid>
		<description><![CDATA[Each year I like to share some of my where-abouts with you, and invite you to come say hello or join me in a session, discussion, debate or even a party. This year, I'm involved with two RSA sessions and some extra-curricular activities with organizations like TCG.]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/" data-text="Where to find JJ at RSA 2013 &#8211; NAC, certs, SBN and more"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fwhere-to-find-me-at-rsa-2013%2F&amp;linkname=Where%20to%20find%20JJ%20at%20RSA%202013%20%E2%80%93%20NAC%2C%20certs%2C%20SBN%20and%20more" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/','Where%20to%20find%20JJ%20at%20RSA%202013%20&#8211;%20NAC,%20certs,%20SBN%20and%20more')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fwhere-to-find-me-at-rsa-2013%2F&amp;title=Where%20to%20find%20JJ%20at%20RSA%202013%20%E2%80%93%20NAC%2C%20certs%2C%20SBN%20and%20more" id="wpa2a_10">Share</a></p><p>Each year I like to share some of my where-abouts with you, and invite you to come say hello or join me in a session, discussion, debate or even a party. This year, I&#8217;m involved with two RSA sessions and some extra-curricular activities with organizations like TCG. Here&#8217;s the scoop!<span id="more-1713"></span></p>
<ul>
<li><strong>Monday, February 25, 2:50-3:50 PM in Room 302</strong><br />
<strong><a title="RSA session details" href="https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=1920&amp;tclass=popup" target="_blank">PROF-M03 &#8211; Information Security Certifications: Do They Still Provide Industry Value?</a></strong></li>
</ul>
<p style="padding-left: 60px;">Moderator(s): <span style="text-decoration: underline;">Thomas Stamulis</span> &#8211; Regional Director, Verizon<br />
Panelist(s): <span style="text-decoration: underline;">Richard Moore</span> &#8211; Vice President, Sr. IS Manager, RBS Citizens<br />
<span style="text-decoration: underline;">Andrew Ellis</span> &#8211; CSO, Akamai Technologies<br />
<span style="text-decoration: underline;">Hord Tipton</span> &#8211; Executive Director, (ISC)2<br />
<span style="text-decoration: underline;">Jennifer Jabbusch-Minella</span> &#8211; CISO, CAD, Inc.</p>
<p style="padding-left: 60px;">Information security certifications have been around for more than two decades, and hundreds of thousands of professionals have attained them. As the industry matures, many academic institutions now offer bachelor and advanced information security degrees. Should the infosec community continue to support these certifications or should we encourage a more traditional academic approach?</p>
<p style="padding-left: 60px;"><strong>My notes</strong>: Join what is sure to be a bang-up session as we discuss the ins and outs of infosec certifications in 2013 and beyond. Hear from Richard, who has a degree in information security and a plethora of acronyms after his name, and enjoy the rebuttal by Andy, a highly successful CSO who continues his success and initiatives without the overhead of industry certifications. As someone who has been a contributing author of the official (ISC)2 CISSP Courseware, and other certifications, I have my own feelings about the virtues and values of our alphabet soup. (ISC)2 Director Hord Tipton is guaranteed to liven the conversation, and with Tom moderating, who knows what will happen.</p>
<ul>
<li><strong> Thursday, February 28, 1:00- 2:00 PM in Room 111<br />
<a title="RSA session details" href="https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=3786&amp;tclass=popup" target="_blank">P2P2-R35 &#8211; Endpoint Integrity and Access Control / NAC is Back; Making it Work</a></strong></li>
</ul>
<p style="padding-left: 60px;">Facilitator(s): <span style="text-decoration: underline;">Jennifer Jabbusch-Minella</span> &#8211; CISO, CAD, Inc.</p>
<p style="padding-left: 60px;">While current solutions have proven difficult to implement in the real world, the need for access control and network security continues to grow. Join this Peer 2 Peer session for a lively discussion of real world case studies, an exploration of technical roadblocks and a dive into vendor-specific solutions. Participants will be given a copy of the host’s proprietary Universal NAC Evaluation Framework document to reference and evaluate various technologies and solutions at a technical level.</p>
<p style="padding-left: 60px;"><strong>My notes</strong>: This is a Peer-2-Peer session, and these are absolutely among my favorite formats at RSA. P2Ps are a chance to connect and share ideas with your peers. I&#8217;ll lead the conversation, get the discussion sparked and lend my experience when needed. Every year I&#8217;ve hosted a NAC session, it has been FULL. These P2Ps are limited to the FIRST 20 PEOPLE in line, so if you really want a seat, get there early. Last time the session was full before I even made it to the room, 18 minutes prior to the start time.</p>
<p><strong> Other sessions, events and places to find me:</strong></p>
<ul>
<li><strong>Monday, 10:00AM &#8211; 2:00PM in South Room 301</strong><br />
TCG Seminar: Trusted Computing &#8211; Billions of Secure Endpoints in 10 Years</li>
<li><strong><strong>Monday, 4:30-7:00PM at St Regis</strong><br />
</strong>5th Annual Security Sociability RSA Happy Hour</li>
<li><strong>Wednesday, 5:00-8:00PM at private location</strong><br />
Security Bloggers Meetup and awards</li>
<li><strong>Wednesday, 8PM  at unknown location</strong><br />
Barracuda &#8211; Blind Tiger Party</li>
<li><strong>Thursday, 5:30- 6:50PM in North Room 134</strong><br />
Flash Talks Powered by PechaKucha</li>
<li><strong>Various, Expo Floor</strong><br />
Other times, I&#8217;ll be on the Expo Floor, talking to vendors</li>
<li>Find parties by following @RSAparties on twitter</li>
</ul>
<p><strong>More resources for RSA:</strong></p>
<ul>
<li><a title="9 Tips to Find the Best Sessions and Speakers at RSA" href="http://securityuncorked.com/2012/02/9-tips-find-best-sessions-speakers-rsa/" target="_blank">9 Tips to Find the Best Sessions and Speakers at RSA</a></li>
</ul>
<p># # #</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/" data-text="Where to find JJ at RSA 2013 &#8211; NAC, certs, SBN and more"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fwhere-to-find-me-at-rsa-2013%2F&amp;linkname=Where%20to%20find%20JJ%20at%20RSA%202013%20%E2%80%93%20NAC%2C%20certs%2C%20SBN%20and%20more" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/','Where%20to%20find%20JJ%20at%20RSA%202013%20&#8211;%20NAC,%20certs,%20SBN%20and%20more')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fwhere-to-find-me-at-rsa-2013%2F&amp;title=Where%20to%20find%20JJ%20at%20RSA%202013%20%E2%80%93%20NAC%2C%20certs%2C%20SBN%20and%20more" id="wpa2a_12">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2013/02/where-to-find-me-at-rsa-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The great Nothing at Security Uncorked</title>
		<link>http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/</link>
		<comments>http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/#comments</comments>
		<pubDate>Tue, 19 Feb 2013 20:24:38 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Random-izations]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1715</guid>
		<description><![CDATA[ShareI hesitate to post here today. I&#8217;m looking at my recent blogging history and I&#8217;m saddened. It&#8217;s as though The great Nothing has come and devoured this digital land of mine. I didn&#8217;t fall off the face of the Earth though, and the Nothing hasn&#8217;t completely taken ownership this spot. I&#8217;ve been writing, as usual [...]]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/" data-text="The great Nothing at Security Uncorked"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fthe-great-nothing-at-security-uncorked%2F&amp;linkname=The%20great%20Nothing%20at%20Security%20Uncorked" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/','The%20great%20Nothing%20at%20Security%20Uncorked')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fthe-great-nothing-at-security-uncorked%2F&amp;title=The%20great%20Nothing%20at%20Security%20Uncorked" id="wpa2a_18">Share</a></p><p>I hesitate to post here today. I&#8217;m looking at my recent blogging history and I&#8217;m saddened. It&#8217;s as though<a title="The Neverending Story" href="http://www.imdb.com/title/tt0088323" target="_blank"> The great Nothing </a>has come and devoured this digital land of mine.<img class="alignright  wp-image-1717" title="image_neverendingstory-empress1" src="http://securityuncorked.com/wordpress/wp-content/uploads/2013/02/image_neverendingstory-empress1.png" alt="" width="206" height="156" /></p>
<p>I didn&#8217;t fall off the face of the Earth though, and the Nothing hasn&#8217;t completely taken ownership this spot. I&#8217;ve been writing, as usual for other media outlets and analyst groups. Some of that content is publicly available and I have failed you, my readers, in linking those posts here.</p>
<p>And so, my sad eyes look now upon a single grain of sand; the sole remaining piece of my digital home, seemingly consumed by The Nothing. As I imagine this blog restored to its full potential, with more content, education and hilarity, I see a glimmer of hope and a landscape manifesting in front of me.</p>
<blockquote><p>&#8220;We can&#8217;t wait for a snail. Can I carry you?&#8221;<br />
&#8220;Don&#8217;t worry, it&#8217;s a racing snail!&#8221;<br />
&#8220;Oh but, but, we can&#8217;t even wait for a racing snail.&#8221;<br />
&#8220;Tally ho!&#8221;<br />
&#8220;Hey, it really is a racing snail!&#8221;</p></blockquote>
<p><strong>Upcoming:</strong></p>
<ul>
<li>Where to find me at RSA this year</li>
<li>RSA sessions for NAC and endpoint security, wireless and trends</li>
<li>What I&#8217;ve been up to</li>
<li>More on wireless and wireless security</li>
<li>Updated NAC white papers and vendor comparison</li>
</ul>
<p><img class="alignleft  wp-image-1718" title="image_neverendingstory-sand1" src="http://securityuncorked.com/wordpress/wp-content/uploads/2013/02/image_neverendingstory-sand1.png" alt="" width="221" height="146" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p># # #</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/" data-text="The great Nothing at Security Uncorked"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fthe-great-nothing-at-security-uncorked%2F&amp;linkname=The%20great%20Nothing%20at%20Security%20Uncorked" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/','The%20great%20Nothing%20at%20Security%20Uncorked')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2013%2F02%2Fthe-great-nothing-at-security-uncorked%2F&amp;title=The%20great%20Nothing%20at%20Security%20Uncorked" id="wpa2a_20">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2013/02/the-great-nothing-at-security-uncorked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is LinkedIn lying about their new password salting?</title>
		<link>http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/</link>
		<comments>http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 20:17:47 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Industry Insider]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[password leak]]></category>
		<category><![CDATA[salt]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1701</guid>
		<description><![CDATA[Wow, we're a skeptical and paranoid bunch, aren't we? I can't blame the numerous security professionals that are making claims that LinkedIn is likely lying about their new password salting for added security. If you're not a cryptography junkie, it may not make sense. I've been running things by several cryptography specialists and our security research friends as a sanity check too, but some of these claims are getting out of hand. Is LinkedIn lying about implemented salts to secure user passwords?
]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/" data-text="Is LinkedIn lying about their new password salting?"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fis-linkedin-lying-about-their-new-password-salting%2F&amp;linkname=Is%20LinkedIn%20lying%20about%20their%20new%20password%20salting%3F" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/','Is%20LinkedIn%20lying%20about%20their%20new%20password%20salting?')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fis-linkedin-lying-about-their-new-password-salting%2F&amp;title=Is%20LinkedIn%20lying%20about%20their%20new%20password%20salting%3F" id="wpa2a_22">Share</a></p><p>Wow, we&#8217;re a skeptical and paranoid bunch, aren&#8217;t we? I can&#8217;t blame the numerous security professionals that are making claims that LinkedIn is likely lying about their new password salting for added security. If you&#8217;re not a cryptography junkie, it may not make sense. I&#8217;ve been running things by several cryptography specialists and our security research friends as a sanity check too, but some of these claims are getting out of hand.</p>
<p><strong>Is LinkedIn lying about implemented salts to secure user passwords?<span id="more-1701"></span></strong></p>
<p>Probably not. As I noted in <a title="Correcting colleagues on LinkedIn salting and hashing details" href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/" target="_blank">this post, correcting some of my colleagues</a>, what <a href="http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised/" target="_blank">LinkedIn claims they have done </a>is possible, reasonable and the most secure and simple recourse to retroactively apply the added security of salting to already-stored passwords. I intend to write a short piece on salting and hashing, but haven&#8217;t gotten around to it. If there&#8217;s an explanation (with graphics) you&#8217;ve read and liked, feel free to link it here in the comments.</p>
<p><strong>Here’s the argument from some skeptical friends,</strong> “You have to add the salt with the original password, so either LinkedIn is lying, or they are storing the original password in plaintext (a big no-no).”</p>
<p><strong>Here’s my response, and why that’s not correct</strong>. Normally, yes, the salt would be applied to the original password, to create a salted, hash output. However, there are more ways to skin a crypto cat, and LinkedIn has probably done something slightly different.</p>
<p><strong>So, what is LinkedIn doing? </strong>I, and my fellow security professionals, feel pretty sure they’ve taken the original password hashes, added the salt to that, and re-hashed with SHA-1.</p>
<p>For an example of what this looks like, and a simple demo of how easy or hard they are to crack, see my post on <a title="How to crack your own LinkedIn password hash" href="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/" target="_blank">How to crack your LinkedIn password hash</a>.</p>
<p>I don&#8217;t work at LinkedIn, and I don&#8217;t consult for them, so this post is a bit of technical speculation based on a little common sense. Read this and think it through before you accuse LinkedIn of lying, or assume they&#8217;re not doing whatever&#8217;s in their power to add security. If you&#8217;re still skeptical, feel free to share your questions or stories here. I invite all my colleagues to respond in kind and provide additional info too.</p>
<p># # #</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/" data-text="Is LinkedIn lying about their new password salting?"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fis-linkedin-lying-about-their-new-password-salting%2F&amp;linkname=Is%20LinkedIn%20lying%20about%20their%20new%20password%20salting%3F" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/','Is%20LinkedIn%20lying%20about%20their%20new%20password%20salting?')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fis-linkedin-lying-about-their-new-password-salting%2F&amp;title=Is%20LinkedIn%20lying%20about%20their%20new%20password%20salting%3F" id="wpa2a_24">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to crack your own LinkedIn password hash</title>
		<link>http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/</link>
		<comments>http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 20:16:42 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Industry Insider]]></category>
		<category><![CDATA[crack your own password]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[password hashes]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1703</guid>
		<description><![CDATA[Several people have asked what it means to crack a password hash, and others have asked for an even simpler explanation of what a hash is. In brief, a hash is a one-way cryptographic function. In security circles, it's not really considered to be encryption, in the technical sense, but it is a function of cryptography. When we hash something, we take a value, it can be any length of letters, numbers, text and we perform a function on it that spits out a fixed-length value. With the LinkedIn passwords, they use a hash algorithm called SHA-1. SHA-1 always gives us an output of exactly 160 bits. You'll see a specific example set below.]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/" data-text="How to crack your own LinkedIn password hash"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fhow-to-crack-your-own-linkedin-password-hash%2F&amp;linkname=How%20to%20crack%20your%20own%20LinkedIn%20password%20hash" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/','How%20to%20crack%20your%20own%20LinkedIn%20password%20hash')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fhow-to-crack-your-own-linkedin-password-hash%2F&amp;title=How%20to%20crack%20your%20own%20LinkedIn%20password%20hash" id="wpa2a_26">Share</a></p><p><strong>Several people have asked what it means to crack a password hash, and others have asked for an even simpler explanation of what a hash is.</strong></p>
<p><strong>In brief, a hash is a one-way cryptographic function</strong>. In security circles, it&#8217;s not really considered to be encryption, in the technical sense, but it is a function of cryptography. When we hash something, we take a value, it can be any length of letters, numbers, text and we perform a function on it that spits out a fixed-length value. With the LinkedIn passwords, they use a hash algorithm called SHA-1. SHA-1 always gives us an output of exactly 160 bits. You&#8217;ll see a specific example set below.<span id="more-1703"></span></p>
<p>It’s this method that <strong>LinkedIn, and other sites, use to store passwords</strong>. User passwords should never be stored in plaintext. Hashed passwords (with a salt, described later) are an accepted common practice for storing user passwords. Note that some security professionals will argue that passwords should be stored using password encryption, instead of these hashes. For more on that, read <a href="http://krebsonsecurity.com/2012/06/how-companies-can-beef-up-password-security" target="_blank">comments by Thomas Ptacek on Brian Krebs’ blog</a>. For more on what LinkedIn changed, see<a title="Is LinkedIn lying about their new password salting?" href="http://securityuncorked.com/2012/06/is-linkedin-lying-about-their-new-password-salting/" target="_blank"> &#8220;Is LinkedIn lying about their new password salting?&#8221;</a></p>
<p>The idea of a hash is that it’s one-way. Every time you put in a value, you get the same output, but you can’t take the output, perform a reverse function, and arrive at the original value. That means, as in our example below, if we enter “fluffyrocks” and hash it, we’ll always get the exact same hash value. But, there’s not a way to take the hash value and directly figure out the original text is “fluffyrocks”. When a site validates your password, it’s taking the hashed value of what you enter, and comparing that to what’s stored in its database. If you entered “fluffyrocks” the hash output should enter what’s stored. If you enter anything but that, the hash won’t match and you won’t be authenticated. Even the smallest change in the original text produces a drastically different hash.</p>
<p><strong>Now, this one-way function doesn’t mean that you can’t crack a hash</strong>. It’s just cracked using different methods than a two-way encryption algorithm. With hashes, attacks are brute-force using dictionary attacks and/or rainbow tables. Meaning, something analyzes pre-computed hash values. When a match of hash values is found, an attacker can see what in the cracking dictionary produced the same hash. That’s how these hashed passwords are compromised.</p>
<p><strong>The most common practice when storing passwords as hashes, is to use what’s called a salt</strong>. A salt adds some entropy to the mix by introducing additional bits that will be hashed along with the password. Salt strings vary in length and are applied before or after the password in the hash algorithm. Each password in a database should have a unique salt. This won’t completely prevent the password hashes from being compromised, but it makes the task a lot more daunting and processor- and time-intensive. To crack a list of salted hashed passwords, an attacker must factor both dictionaries for the original password and the salt values.</p>
<p><strong>So, how hard is it to crack unsalted passwords, such as those leaked in the LinkedIn breach?</strong> Here’s an example and fun hands-on activity for you to try.</p>
<p> <strong>An example:</strong></p>
<ol>
<li><strong>Your plaintext password</strong> (not stored by LinkedIn)<br />
= fluffyrocks</li>
<li><strong>LinkedIn’s unsalted SHA-1 hash stored</strong>, function (sha1($pass))<br />
= (sha1(fluffyrocks))<br />
= 4d39d3da4fe662e3a4a6a006e450612b55123416</li>
<li><strong>Normal password salting with SHA-1 hash</strong>, salted with abcdef0123 (sha1($salt.$pass))<br />
= (sha1(abcdef0123.fluffyrocks))<br />
= 861867bdaadfc4b0ece92ba4eefa1d6f570ab019</li>
<li><strong>LinkedIn’s salted double-hashed</strong>, now stored  (sha1($salt.sha1($pass)))<br />
= (sha1(abcdef0123.sha1(fluffyrocks)))<br />
= 4ed11b5260f33f3ac2b1bafb7b322f795c087f6b</li>
</ol>
<p> <strong>Try it yourself:</strong></p>
<p><strong>1. First, find out the hash value of a password or string.</strong><br />
You can find the SHA-1 hash of a password or phrase on several sites, try <a href="http://www.xorbin.com/tools/sha1-hash-calculator">http://www.xorbin.com/tools/sha1-hash-calculator</a> or <a href="http://www.tech-faq.com/sha-1-generator">http://www.tech-faq.com/sha-1-generator</a> , or Google “SHA-1 generator”.</p>
<p><strong>2. Then use a SHA-1 cracker online.</strong><br />
In my example below, I used <a href="http://www.crackstation.net/">www.CrackStation.net</a> to test out the ease of cracking. Google for SHA-1 crackers for more options.</p>
<p> Note the links provided are for unsalted hashes. There are tools readily available designed to crack salted hashes also. This is why I’ve noted earlier that salting the password before storing it doesn’t prevent it from being cracked, it just adds some protection.</p>
<p> Here in the screenshot from Crack Station below, I’ve entered 3 values:</p>
<ol>
<li>SHA1- hash of the unsalted password</li>
<li>SHA1- hash of a salted password</li>
<li>SHA1- hash of a salted of the original password hash* (What LinkedIn is doing now, read more here)</li>
</ol>
<p>Voila!</p>
<p><strong>You can see the unsalted hash was cracked immediately</strong> and returned my plaintext password of “fluffyrocks”. As expected, the two salted hashes were not cracked with this tool. This is why more than 50% of the LinkedIn hashes were cracked, and the original plaintext found so quickly. Had the passwords been salted, it would have slowed the process, but not prevented it.</p>
<p> <a href="http://securityuncorked.com/wordpress/wp-content/uploads/2012/06/linkedin-crackstation-fluffyrocks.png"><img class="wp-image-1705 alignnone" title="linkedin-crackstation-fluffyrocks" src="http://securityuncorked.com/wordpress/wp-content/uploads/2012/06/linkedin-crackstation-fluffyrocks.png" alt="" width="804" height="431" /></a></p>
<p>&nbsp;</p>
<p># # #</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/" data-text="How to crack your own LinkedIn password hash"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fhow-to-crack-your-own-linkedin-password-hash%2F&amp;linkname=How%20to%20crack%20your%20own%20LinkedIn%20password%20hash" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/','How%20to%20crack%20your%20own%20LinkedIn%20password%20hash')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fhow-to-crack-your-own-linkedin-password-hash%2F&amp;title=How%20to%20crack%20your%20own%20LinkedIn%20password%20hash" id="wpa2a_28">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Three reasons you care about the LinkedIn breach</title>
		<link>http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/</link>
		<comments>http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 01:26:18 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Industry Insider]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[leak]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1674</guid>
		<description><![CDATA[Overheard in conversations, both in person and online, are comments "I don't care about LinkedIn, I don't need to change my password" and "they're just hashes, only a few passwords were posted." To those of you with this attitude, I think you’re missing the bigger picture.]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/" data-text="Three reasons you care about the LinkedIn breach"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fthree-reasons-you-care-about-the-linkedin-breach%2F&amp;linkname=Three%20reasons%20you%20care%20about%20the%20LinkedIn%20breach" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/','Three%20reasons%20you%20care%20about%20the%20LinkedIn%20breach')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fthree-reasons-you-care-about-the-linkedin-breach%2F&amp;title=Three%20reasons%20you%20care%20about%20the%20LinkedIn%20breach" id="wpa2a_30">Share</a></p><p>I&#8217;ve been reading the flurry of posts, blogs, tweets and offhanded comments regarding <a title="LinkedIn Blog" href="http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised/" target="_blank">LinkedIn&#8217;s recent data breach</a>. I&#8217;m calling it a data breach here, not a password hash breach, because at this point, I don&#8217;t think anyone knows the extent of damage, or the full breadth of what data may have been taken.</p>
<p>Overheard in conversations, both in person and online, are comments &#8220;I don&#8217;t care about LinkedIn, I don&#8217;t need to change my password&#8221; and &#8220;they&#8217;re just hashes, only a few passwords were posted.&#8221; To those of you with this attitude, I think you’re missing the bigger picture.<span id="more-1674"></span></p>
<p>I&#8217;d like to clear up a few things and share three reasons I think you’ll care about this LinkedIn breach.</p>
<h2><strong>Before we jump in, I’ll share my opinion about this breach in general.</strong></h2>
<p>I think quite a bit of what LinkedIn has shared is ambiguous, at best. I&#8217;m okay with that for now, because I think their involvement with law enforcement agencies and the fact they&#8217;re still in the discovery stage, prevents them from sharing much. They don&#8217;t know everything yet, and what they may know, is probably not in their best interest to share.</p>
<p>As security professionals, we can certainly find cause to criticize LinkedIn for how they&#8217;ve handled this, but I&#8217;ll leave that to others. I&#8217;m sure there&#8217;s a copious amount of critical articles out there. For now, I think they&#8217;re doing an acceptable (but not exceptional) job.</p>
<p><a href="http://blog.linkedin.com/2012/06/09/an-update-on-taking-steps-to-protect-our-members/" target="_blank">LinkedIn has locked the accounts and sent notifications </a>to some of the affected users. Strangely, we can’t seem to establish any pattern in the notifications, and the verbiage LinkedIn has used in describing what it deems vulnerable is very vague.</p>
<blockquote>
<h4><strong><span style="color: #000000;">Even if you didn’t receive the “Dear user” letter, some of your online accounts may be at risk.</span></strong></h4>
</blockquote>
<h2><strong>Three reasons you care about the breach.</strong></h2>
<p>For those of you that don’t think a breach of your LinkedIn password matters, here’s why you should care.</p>
<h3>1. Someone may have full access to your account.</h3>
<p>We don’t know if the thieves stole additional data or not. It’s perfectly possible they have the full list of email addresses to go along with the password hashes. It&#8217;s also extremely likely they have more than the 6.5 million hashes they have released so far.</p>
<h3>2. Even in hash form, your password is vulnerable.</h3>
<p>Hashes of passwords are vulnerable and unsalted hashes (what was leaked from LinkedIn) are extremely vulnerable. See more on this below. <a href="http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised" target="_blank">LinkedIn has posted</a>  that its database now uses salted and hashed passwords. It appears this measure to increase password confidentiality was implemented prior to the notification of the breach, but after the breach itself. Meaning, the passwords are much more secured now, and as long as they are new passwords, or weren’t captured in the leak, they’re pretty safe now.</p>
<p>A<strong> NOTE </strong>on correcting colleagues on LinkedIn salting and hashes. I’d like to note there are some articles out there with <span style="color: #000000;"><a title="Correcting colleagues on LinkedIn salting and hashing details" href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/" target="_blank">misinformation as to the salting and hashing methods.</a></span></p>
<h3>3. That password is a key to another door.</h3>
<p>About 75% of users re-use passwords across multiple sites. Read the <a href="http://www.pcworld.com/article/188763/too_many_people_reuse_logins_study_finds.html" target="_blank">article here </a>or the <a href="http://www.trusteer.com/sites/default/files/cross-logins-advisory.pdf" target="_blank">original findings (PDF). </a>  Meaning, if someone did steal the email addresses along with the hashes, they can very easily find other sites, or doors to which your password will be the key.</p>
<p>If you&#8217;re not sure what to do next, read my recommendation for dealing with the breach at <span style="color: #ff0000;"><a title="LinkedIn: Don’t just change your password, do this" href="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/" target="_blank">LinkedIn: Don&#8217;t just change your password, do this.</a></span></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/" data-text="Three reasons you care about the LinkedIn breach"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fthree-reasons-you-care-about-the-linkedin-breach%2F&amp;linkname=Three%20reasons%20you%20care%20about%20the%20LinkedIn%20breach" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/','Three%20reasons%20you%20care%20about%20the%20LinkedIn%20breach')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fthree-reasons-you-care-about-the-linkedin-breach%2F&amp;title=Three%20reasons%20you%20care%20about%20the%20LinkedIn%20breach" id="wpa2a_32">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LinkedIn: Don&#8217;t just change your password, do this</title>
		<link>http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/</link>
		<comments>http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 01:24:31 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Industry Insider]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[password hash]]></category>
		<category><![CDATA[password recommendation]]></category>
		<category><![CDATA[secure passwords]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1672</guid>
		<description><![CDATA[I disagree with a lot of the sites that have made the simple recommendation to change your LinkedIn password. LinkedIn added the recommendations that users change passwords at other sites, change passwords often, and use greater complexity (more combinations of numbers, letters, characters and capitals). I’m going to go one step further and be very specific in my recommendations.]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/" data-text="LinkedIn: Don&#8217;t just change your password, do this"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Flinkedin-dont-just-change-your-password-do-this%2F&amp;linkname=LinkedIn%3A%20Don%E2%80%99t%20just%20change%20your%20password%2C%20do%20this" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/','LinkedIn:%20Don&#8217;t%20just%20change%20your%20password,%20do%20this')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Flinkedin-dont-just-change-your-password-do-this%2F&amp;title=LinkedIn%3A%20Don%E2%80%99t%20just%20change%20your%20password%2C%20do%20this" id="wpa2a_34">Share</a></p><p><strong>Don’t just change your password, do this</strong></p>
<p>I disagree with a lot of the sites that have made the simple recommendation to change your LinkedIn password. <a href="http://blog.linkedin.com/2012/06/09/an-update-on-taking-steps-to-protect-our-members/" target="_blank">LinkedIn added the recommendations </a>that users change passwords at other sites, change passwords often, and use greater complexity (more combinations of numbers, letters, characters and capitals). I’m going to go one step further and be very specific in my recommendations.<span id="more-1672"></span></p>
<ul>
<li><span style="text-decoration: underline;">Change your LinkedIn password to something new and <strong>unique</strong></span>. Make sure this password is not one you currently use, or will use on another site. This is to be known as your LinkedIn password and nothing else. If hackers still have access to the LinkedIn servers, this will prevent them capturing another shared password.</li>
<li><span style="text-decoration: underline;">Change the passwords on any and all sites or resources that shared your previous LinkedIn password</span>. Make them complex and unique. If you have trouble remembering passwords, use a web-based tool like Last Pass (one example of many available). If you used that password inside your work environment anywhere, notify your administrators and have the password(s) changed immediately.</li>
<li><span style="text-decoration: underline;">Backup your LinkedIn connections</span>. There’s an export feature on the site. Just in case your account is compromised further later, you’ll at least have that. Rebuilding the network is the most time-consuming task.</li>
<li><span style="text-decoration: underline;">Lock your credit reporting accounts</span>. If you fear other accounts may have been compromised, and someone may have access to your personal information, you may want to contact your credit reporting agencies and ask them to lock inquiries on your accounts. This will prevent anyone from opening new fake credit or banking accounts in your name. This is for those of you that are paranoid or have a lot to lose.</li>
</ul>
<p>See related links for more on the LinkedIn breach.</p>
<ul>
<li><a title="Correcting colleagues on LinkedIn salting and hashing details" href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/" target="_blank">Correcting colleagues on LinkedIn salting and hashing details</a></li>
<li><a href="http://securityuncorked.com/2012/06/three-reasons-you-care-about-the-linkedin-breach" target="_blank">Three reasons you care about the LinkedIn breach</a></li>
</ul>
<p># # #</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/" data-text="LinkedIn: Don&#8217;t just change your password, do this"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Flinkedin-dont-just-change-your-password-do-this%2F&amp;linkname=LinkedIn%3A%20Don%E2%80%99t%20just%20change%20your%20password%2C%20do%20this" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/','LinkedIn:%20Don&#8217;t%20just%20change%20your%20password,%20do%20this')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Flinkedin-dont-just-change-your-password-do-this%2F&amp;title=LinkedIn%3A%20Don%E2%80%99t%20just%20change%20your%20password%2C%20do%20this" id="wpa2a_36">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/06/linkedin-dont-just-change-your-password-do-this/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Correcting colleagues on LinkedIn salting and hashing details</title>
		<link>http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/</link>
		<comments>http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 01:17:48 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Industry Insider]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[salt]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1679</guid>
		<description><![CDATA[I’d like to note there are some articles out there with misinformation as to the salting and hashing methods and abilities of LinkedIn to retroactively fix the issue of unsalted passwords. In one particular article at Computer World  a reference was cited as saying LinkedIn could not have implemented the salting feature with the already-created database of hashes, and that salting could only be implemented with the original password, when a user created or changed a password. 
]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/" data-text="Correcting colleagues on LinkedIn salting and hashing details"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fcorrecting-colleagues-linkedin-salting-hashing%2F&amp;linkname=Correcting%20colleagues%20on%20LinkedIn%20salting%20and%20hashing%20details" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/','Correcting%20colleagues%20on%20LinkedIn%20salting%20and%20hashing%20details')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fcorrecting-colleagues-linkedin-salting-hashing%2F&amp;title=Correcting%20colleagues%20on%20LinkedIn%20salting%20and%20hashing%20details" id="wpa2a_38">Share</a></p><p>I’d like to note there are some articles out there with misinformation as to the salting and hashing methods and abilities of LinkedIn to retroactively fix the issue of unsalted passwords.</p>
<p>In one particular <a href="http://www.computerworld.com/s/article/9227869/Hackers_crack_more_than_60_of_breached_LinkedIn_passwords?taxonomyId=82&amp;pageNumber=1" target="_blank">article at Computer World </a> a reference was cited as saying LinkedIn could not have implemented the <a href="http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised/" target="_blank">salting feature with the already-created database of hashes</a>, and that salting could only be implemented with the original password, when a user created or changed a password.<span id="more-1679"></span></p>
<p>This is not accurate, LinkedIn can (and I’m sure they have) applied a second iteration of the hash algorithm with the newly-added salt. Cryptography professionals and security researchers alike will agree this is acceptable, and actually more secure than simply salting the original password. In this particular case, I’m sure the iteration was added as a necessity (since they don’t have the original passwords) and not out of an added security consideration.</p>
<p>Soon, I&#8217;ll provide more on what salting and hashing is, but for now I wanted to make sure and set this straight. <a href="http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised/" target="_blank">What LinkedIn has claimed it did </a>is reasonable, possible and what we&#8217;d expect them to do.</p>
<p><strong>Update</strong>: More on salting and hashing basics, with an example and steps to crack your own password now at <a title="How to crack your own LinkedIn password hash" href="http://securityuncorked.com/2012/06/how-to-crack-your-own-linkedin-password-hash/">&#8220;How to crack your own LinkedIn password hash.&#8221;</a></p>
<p># # #</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/" data-text="Correcting colleagues on LinkedIn salting and hashing details"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fcorrecting-colleagues-linkedin-salting-hashing%2F&amp;linkname=Correcting%20colleagues%20on%20LinkedIn%20salting%20and%20hashing%20details" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/','Correcting%20colleagues%20on%20LinkedIn%20salting%20and%20hashing%20details')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F06%2Fcorrecting-colleagues-linkedin-salting-hashing%2F&amp;title=Correcting%20colleagues%20on%20LinkedIn%20salting%20and%20hashing%20details" id="wpa2a_40">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/06/correcting-colleagues-linkedin-salting-hashing/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Help Bail JJ Out of Jail &#8211; MDA</title>
		<link>http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/</link>
		<comments>http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/#comments</comments>
		<pubDate>Sat, 24 Mar 2012 16:25:12 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Random-izations]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1665</guid>
		<description><![CDATA[ShareHelp Bail JJ Out of Jail!  They&#8217;re coming to take me away&#8230; Not to the funny farm; they&#8217;re locking me up for good! I&#8217;m proud to tell you that I&#8217;m going &#8220;behind bars&#8221; to help in the fight against muscle disease. I&#8217;m joining other community leaders to help raise critical funds for MDA, and I [...]]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/" data-text="Help Bail JJ Out of Jail &#8211; MDA"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fhelp-bail-jj-out-of-jail-mda%2F&amp;linkname=Help%20Bail%20JJ%20Out%20of%20Jail%20%E2%80%93%20MDA" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/','Help%20Bail%20JJ%20Out%20of%20Jail%20&#8211;%20MDA')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fhelp-bail-jj-out-of-jail-mda%2F&amp;title=Help%20Bail%20JJ%20Out%20of%20Jail%20%E2%80%93%20MDA" id="wpa2a_46">Share</a></p><h2>Help Bail JJ Out of Jail! </h2>
<div>
<div>
<p>They&#8217;re coming to take me away&#8230; Not to the funny farm; they&#8217;re locking me up for good!</p>
</div>
</div>
<div>
<p>I&#8217;m proud to tell you that I&#8217;m going &#8220;behind bars&#8221; to help in the fight against muscle disease. I&#8217;m joining other community leaders to help raise critical funds for MDA, and I need your help to reach my bail!</p>
<p>As many of my friends already know, in 1999 we lost my Grandmother, Virginia Jabbusch, to her fight with ALS, more commonly known as Lou Gehrig&#8217;s disease. Read more at <a href="http://www.als-mda.org/disease/als.html">http://www.als-mda.org/disease/als.html</a>. Anyone who&#8217;s gone through that can tell you it is undoubtedly one of the most painful and difficult things to experience.</p>
<p><a href="http://www2.mda.org/goto/jj"><img class="alignright size-full wp-image-1666" title="logo-mda-lockup-2012" src="http://securityuncorked.com/wordpress/wp-content/uploads/2012/03/logo-mda-lockup-2012.jpg" alt="" width="240" height="149" /></a>One day, in my lifetime, I hope to see a cure for ALS and other muscular diseases. For today, what I want to do is help raise money for MDA to help families living with MDA. Among other things, this 2012 Lock-Up will help send kids to MDA Summer Camp.</p>
<p>ANY amount helps, no matter how small. I say this because, I fear my getting locked up will be a little bit like the Ransom of Red Chief, and I&#8217;m going to need all the help I can get! There are at least 3 people paying money to keep me IN jail.</p>
<ul>
<li><a title="JJ's MDA Lockup page" href="http://www2.mda.org/goto/jj" target="_blank">JJ&#8217;s Lockup Page</a></li>
<li><a href="http://www2.mda.org/site/Donation2?df_id=1617&amp;FR_ID=2252&amp;PROXY_ID=1190089&amp;1617.donation=form1&amp;PROXY_TYPE=20" target="_blank">Make a bail donation</a></li>
</ul>
<p># # #</p>
</div>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/" data-text="Help Bail JJ Out of Jail &#8211; MDA"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fhelp-bail-jj-out-of-jail-mda%2F&amp;linkname=Help%20Bail%20JJ%20Out%20of%20Jail%20%E2%80%93%20MDA" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/','Help%20Bail%20JJ%20Out%20of%20Jail%20&#8211;%20MDA')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fhelp-bail-jj-out-of-jail-mda%2F&amp;title=Help%20Bail%20JJ%20Out%20of%20Jail%20%E2%80%93%20MDA" id="wpa2a_48">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/03/help-bail-jj-out-of-jail-mda/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join me for the online P2P chat on BYOD this Thursday (RSA Conference Online)</title>
		<link>http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/</link>
		<comments>http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 15:11:01 +0000</pubDate>
		<dc:creator>jj</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[BYOX]]></category>
		<category><![CDATA[RSA 2012]]></category>

		<guid isPermaLink="false">http://securityuncorked.com/?p=1659</guid>
		<description><![CDATA[This Thursday, March 15th, I'll be hosting the RSA Conference Online Peer2Peer chat session on BYOD, "Doubts, Dread and Decisions: Dealing with BYOD in the Enterprise". The live P2P session at RSA was full 15 minutes before we started! If you missed that session, or couldn't attend RSA, this is your opportunity to participate with your peers. Registration is free and open to the public.]]></description>
			<content:encoded><![CDATA[<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/" data-text="Join me for the online P2P chat on BYOD this Thursday (RSA Conference Online)"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fjoin-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online%2F&amp;linkname=Join%20me%20for%20the%20online%20P2P%20chat%20on%20BYOD%20this%20Thursday%20%28RSA%20Conference%20Online%29" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/','Join%20me%20for%20the%20online%20P2P%20chat%20on%20BYOD%20this%20Thursday%20(RSA%20Conference%20Online)')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fjoin-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online%2F&amp;title=Join%20me%20for%20the%20online%20P2P%20chat%20on%20BYOD%20this%20Thursday%20%28RSA%20Conference%20Online%29" id="wpa2a_50">Share</a></p><p>This Thursday, March 15th, I&#8217;ll be hosting the RSA Conference Online Peer2Peer chat session on BYOD, &#8220;Doubts, Dread and Decisions: Dealing with BYOD in the Enterprise&#8221;. The live P2P session at RSA was full 15 minutes before we started! If you missed that session, or couldn&#8217;t attend RSA, this is your opportunity to participate with your peers. Registration is free and open to the public.</p>
<p><span id="more-1659"></span></p>
<p>RSA Conference Online, Peer2Peer<br />
Thursday, March 15, 2012<br />
8:00-8:30am <span style="text-decoration: underline;">Pacific</span> | 11:00-11:30am <span style="text-decoration: underline;">Eastern</span><br />
<strong>Doubts, Dread and Decisions: Dealing with BYOD in the Enterprise</strong><br />
Moderated by Jennifer Jabbusch Minella, Chief Information Security Officer, Infrastructure Security Specialist, CAD, Inc.</p>
<p>To participate, just register for free at <a href="http://www.rsaconference.com/events/online.htm">http://www.rsaconference.com/events/online.htm</a>. Please check your login access PRIOR to the event. I&#8217;ve had a few issues logging in when I originally set up my account.</p>
<p>To view the full RSA Conference Online schedule, visit <a href="http://www.rsaconference.com/events/2012/usa/rsac-online.htm">http://www.rsaconference.com/events/2012/usa/rsac-online.htm</a>.</p>
<p>I look forward to seeing you online Thursday!</p>
<p># # #</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="horizontal" data-url="http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/" data-text="Join me for the online P2P chat on BYOD this Thursday (RSA Conference Online)"></a><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/"></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fjoin-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online%2F&amp;linkname=Join%20me%20for%20the%20online%20P2P%20chat%20on%20BYOD%20this%20Thursday%20%28RSA%20Conference%20Online%29" title="Email" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:if(document.all){window.external.AddFavorite('http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/','Join%20me%20for%20the%20online%20P2P%20chat%20on%20BYOD%20this%20Thursday%20(RSA%20Conference%20Online)')}else{var%20b=a2a_config.localize.BookmarkInstructions%20||%20'Press%20Ctrl+D%20to%20bookmark%20this%20page';alert(a2a_config.localize.BookmarkInstructions)}" title="Bookmark/Favorites" rel="nofollow" target="_blank"><img src="http://securityuncorked.com/wordpress/wp-content/plugins/add-to-any/icons/bookmark.png" width="16" height="16" alt="Bookmark/Favorites"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fsecurityuncorked.com%2F2012%2F03%2Fjoin-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online%2F&amp;title=Join%20me%20for%20the%20online%20P2P%20chat%20on%20BYOD%20this%20Thursday%20%28RSA%20Conference%20Online%29" id="wpa2a_52">Share</a></p>]]></content:encoded>
			<wfw:commentRss>http://securityuncorked.com/2012/03/join-me-for-the-online-p2p-chat-on-byod-this-thursday-rsa-conference-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
