<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: How to Be a Security Idiot</title>
	<link>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Tue, 14 Oct 2008 10:49:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: a random reader</title>
		<link>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/#comment-1390</link>
		<dc:creator>a random reader</dc:creator>
		<pubDate>Sat, 28 Jul 2007 09:40:23 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/#comment-1390</guid>
		<description>Nice slides and all, people need education and all, but maybe the title should read: "How to Be a Windows Security Idiot" or "How to be an Idiot with the Operating System Designed for Idiots" or something.</description>
		<content:encoded><![CDATA[<p>Nice slides and all, people need education and all, but maybe the title should read: &#8220;How to Be a Windows Security Idiot&#8221; or &#8220;How to be an Idiot with the Operating System Designed for Idiots&#8221; or something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dannyl</title>
		<link>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/#comment-510</link>
		<dc:creator>dannyl</dc:creator>
		<pubDate>Fri, 04 May 2007 13:28:28 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/#comment-510</guid>
		<description>Here is my humble contribution to stupid security practices - but with a slant for the "Corporate IT guys"

1. Leave Default permissions on all systems
2. Outsource your process of knowing what's good. Instead of taking the time to list the 30 or so legitimate things you need to do, pay $29.95/year to someone else who has a checklist and will scan your web site once/week
3. Penetrate and patch - Let me put it to you in different terms: if "Penetrate and Patch" was effective, we would have run out of security bugs in Internet Explorer by now.
4. Hacking is cool - (No Virginia - good engineering is better)
5. Educating users on IT security is good. No....a little knowledge can be dangerous - I would say some simple guidelines like "Always delete mail from people or subjects you don't know" is probably the most effective security training you can do

6. Action is Better Than Inaction - YOH - let's clean up all those old log directories with a rm -rf /var

Danny</description>
		<content:encoded><![CDATA[<p>Here is my humble contribution to stupid security practices - but with a slant for the &#8220;Corporate IT guys&#8221;</p>
<p>1. Leave Default permissions on all systems<br />
2. Outsource your process of knowing what&#8217;s good. Instead of taking the time to list the 30 or so legitimate things you need to do, pay $29.95/year to someone else who has a checklist and will scan your web site once/week<br />
3. Penetrate and patch - Let me put it to you in different terms: if &#8220;Penetrate and Patch&#8221; was effective, we would have run out of security bugs in Internet Explorer by now.<br />
4. Hacking is cool - (No Virginia - good engineering is better)<br />
5. Educating users on IT security is good. No&#8230;.a little knowledge can be dangerous - I would say some simple guidelines like &#8220;Always delete mail from people or subjects you don&#8217;t know&#8221; is probably the most effective security training you can do</p>
<p>6. Action is Better Than Inaction - YOH - let&#8217;s clean up all those old log directories with a rm -rf /var</p>
<p>Danny</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ezgranny420</title>
		<link>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/#comment-503</link>
		<dc:creator>ezgranny420</dc:creator>
		<pubDate>Thu, 03 May 2007 17:04:14 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/05/02/how-to-be-a-security-idiot/#comment-503</guid>
		<description>HAHAHAHA, brilliant additions!</description>
		<content:encoded><![CDATA[<p>HAHAHAHA, brilliant additions!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.158 seconds -->
