<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Blogging Without a Safety Net &#187; Security</title>
	<atom:link href="http://mr-purpleduck.me.uk/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://mr-purpleduck.me.uk</link>
	<description>Photography, Security and a little bit of every day life</description>
	<lastBuildDate>Sat, 12 Nov 2011 21:21:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='mr-purpleduck.me.uk' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Blogging Without a Safety Net &#187; Security</title>
		<link>http://mr-purpleduck.me.uk</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://mr-purpleduck.me.uk/osd.xml" title="Blogging Without a Safety Net" />
	<atom:link rel='hub' href='http://mr-purpleduck.me.uk/?pushpress=hub'/>
		<item>
		<title>Correct system time is a security issue</title>
		<link>http://mr-purpleduck.me.uk/2007/09/30/correct-system-time-is-a-security-issue/</link>
		<comments>http://mr-purpleduck.me.uk/2007/09/30/correct-system-time-is-a-security-issue/#comments</comments>
		<pubDate>Sun, 30 Sep 2007 14:05:40 +0000</pubDate>
		<dc:creator>mrpurpleduck</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://mrpurpleduck.wordpress.com/2007/09/30/correct-system-time-is-a-security-issue/</guid>
		<description><![CDATA[There&#8217;s a story that hit Slashdot today about Debian (see bug #433869) not using the security.debian.org system to send out an update to the timezone data for a change in New Zealand daylight savings time. The update in question is &#8230; <a href="http://mr-purpleduck.me.uk/2007/09/30/correct-system-time-is-a-security-issue/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mr-purpleduck.me.uk&amp;blog=1241487&amp;post=54&amp;subd=mrpurpleduck&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a <a href="http://linux.slashdot.org/article.pl?sid=07/09/30/1117241&amp;from=rss">story</a> that hit <a href="http://slashdot.org/">Slashdot</a> today about <a href="http://www.debian.org/">Debian</a> (see bug <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433869">#433869</a>) not using the <em>security.debian.org</em> system to send out an update to the timezone data for a change in New Zealand daylight savings time.</p>
<p>The update in question is not a security fix, however having the correct time on a system is very important for security. Without the correct local time across all of your different systems (and thus having the correct timestamp on log messages) you will not be able to collate messages between different systems (e.g. routers, firewalls, other unix/linux systems) during an incident. This has already been released by <a href="http://support.microsoft.com/kb/933360/">Microsoft</a>, <a href="http://rhn.redhat.com/errata/RHEA-2007-0689.html">Red Hat</a> and, I expect, other vendors.</p>
<p>To me this seems just to be another reason that an commercial company should not run Debian GNU/Linux as you&#8217;re at the whims of a bunch of volunteers who are unlikely to understand the security concerns of your business (e.g. PCI/DSS or Sarbanes-Oxley). However it&#8217;s still a good OS if you&#8217;re running a personal system or if you can have a team of Debian sysadmins/developers at your call to backport important package changes.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mrpurpleduck.wordpress.com/54/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mrpurpleduck.wordpress.com/54/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mrpurpleduck.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mrpurpleduck.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mrpurpleduck.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mrpurpleduck.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mrpurpleduck.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mrpurpleduck.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mrpurpleduck.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mrpurpleduck.wordpress.com/54/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mr-purpleduck.me.uk&amp;blog=1241487&amp;post=54&amp;subd=mrpurpleduck&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://mr-purpleduck.me.uk/2007/09/30/correct-system-time-is-a-security-issue/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/784f08567206e748eb5e9d375e5c02af?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jjm</media:title>
		</media:content>
	</item>
		<item>
		<title>Security training a liability?</title>
		<link>http://mr-purpleduck.me.uk/2007/05/10/security-training-a-liability/</link>
		<comments>http://mr-purpleduck.me.uk/2007/05/10/security-training-a-liability/#comments</comments>
		<pubDate>Thu, 10 May 2007 20:40:01 +0000</pubDate>
		<dc:creator>mrpurpleduck</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mrpurpleduck.wordpress.com/2007/05/10/security-training-a-liability/</guid>
		<description><![CDATA[Following seeing a link a a book called The No Asshole Rule: Building a Civilized Workplace and Surviving One That Isn&#8217;t on Cutaway&#8217;s blog (Security Ripcord) I just had to order it from the US. Not really sure how I &#8230; <a href="http://mr-purpleduck.me.uk/2007/05/10/security-training-a-liability/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mr-purpleduck.me.uk&amp;blog=1241487&amp;post=35&amp;subd=mrpurpleduck&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Following seeing a link a a book called <a href="http://www.amazon.com/Asshole-Rule-Civilized-Workplace-Surviving/dp/0446526568">The No Asshole Rule: Building a Civilized Workplace and Surviving One That Isn&#8217;t</a> on Cutaway&#8217;s blog (<a href="http://www.cutawaysecurity.com/">Security Ripcord</a>) I just had to order it from the US.</p>
<p>Not really sure how I managed to find <a href="http://www.cutawaysecurity.com/blog/archives/77">this blog post</a> this evening given that it&#8217;s from January, anyway it&#8217;s a rant on security training being a liability. Given the views I&#8217;ve seen on training over the years I&#8217;m not surprised on that one.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mrpurpleduck.wordpress.com/35/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mrpurpleduck.wordpress.com/35/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mrpurpleduck.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mrpurpleduck.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mrpurpleduck.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mrpurpleduck.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mrpurpleduck.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mrpurpleduck.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mrpurpleduck.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mrpurpleduck.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mr-purpleduck.me.uk&amp;blog=1241487&amp;post=35&amp;subd=mrpurpleduck&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://mr-purpleduck.me.uk/2007/05/10/security-training-a-liability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/784f08567206e748eb5e9d375e5c02af?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jjm</media:title>
		</media:content>
	</item>
	</channel>
</rss>
