<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>The Silver Bullet Security Podcast</title>
	<atom:link href="http://www.cigital.com/silverbullet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/silverbullet</link>
	<description>In-depth conversations with leading security gurus, hosted by Gary McGraw, sponsored by IEEE Security &#38; Privacy Magazine.</description>
	<lastBuildDate>Thu, 04 Mar 2010 20:01:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.4" -->
		<copyright>2006-2009 </copyright>
		<managingEditor>webmaster@cigital.com (The Silver Bullet Security Podcast)</managingEditor>
		<webMaster>webmaster@cigital.com (The Silver Bullet Security Podcast)</webMaster>
		<category>posts</category>
		<ttl>1440</ttl>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
		<itunes:author>The Silver Bullet Security Podcast</itunes:author>
		<itunes:category text="Society &amp; Culture"/>
		<itunes:owner>
			<itunes:name>The Silver Bullet Security Podcast</itunes:name>
			<itunes:email>webmaster@cigital.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://www.cigital.com/silverbullet/logo-sbsp-sm.jpg" />
		<image>
			<url>http://www.cigital.com/silverbullet/logo-sbsp-sm.jpg</url>
			<title>The Silver Bullet Security Podcast</title>
			<link>http://www.cigital.com/silverbullet</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Show 047 &#8211; An Interview with Greg Morrisett</title>
		<link>http://www.cigital.com/silverbullet/show-047/</link>
		<comments>http://www.cigital.com/silverbullet/show-047/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 16:43:13 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=58</guid>
		<description><![CDATA[
On the 47th episode of The Silver Bullet Security Podcast, Gary calls in from Leuven, Belgium to chat with childhood friend and security expert Greg Morrisett.  Greg is the Allen B. Cutting Professor of Computer Science and Associate Dean for Computer Science and Engineering in the School of Engineering and Applied Sciences at Harvard [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Greg Morrisett" title="Greg Morrisett" src="http://www.cigital.com/silverbullet/gmorrisett-125.png" style="padding-left: 7px;" /></p>
<p>On the 47th episode of The Silver Bullet Security Podcast, Gary calls in from Leuven, Belgium to chat with childhood friend and security expert Greg Morrisett.  Greg is the Allen B. Cutting Professor of Computer Science and Associate Dean for Computer Science and Engineering in the School of Engineering and Applied Sciences at Harvard University.  Gary and Greg discuss the relationship between security and programming languages, why the choice of a good programming language (and/or VM) is more important than code review, sensor networks and security, information control, and Gary and Greg&#8217;s most embarrassing moment from adolescence.</p>
<ul>
<li><a href="http://www.eecs.harvard.edu/~greg/">Greg Morrisett</a></li>
<li><a href="http://www.crcs.deas.harvard.edu/">The Center for Research on Computation and Society</a></li>
<li><a href="http://ynot.cs.harvard.edu/">Ynot</a></li>
<li><a href="http://robobees.seas.harvard.edu/">RoboBees</a></li>
<li><a href="http://nobot.cis.upenn.edu/">NoBot</a></li>
<li><a href="http://sos.cse.lehigh.edu/gonative/">GoNative</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-047/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/58/0/silverbullet-047.mp3" length="41773184" type="audio/mpeg"/>
<itunes:duration>29:00</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 046 &#8211; An Interview with David Rice</title>
		<link>http://www.cigital.com/silverbullet/show-046/</link>
		<comments>http://www.cigital.com/silverbullet/show-046/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 16:35:22 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=57</guid>
		<description><![CDATA[
On the bonus-length 46th episode of The Silver Bullet Security Podcast, Gary talks with David Rice, Executive Director of the Monterey Group and author of Geekonomics: The Real Cost of Insecure Software.  Gary and David discuss David&#8217;s involvement with Infowar at the Naval Postgraduate School and how it impacted his thinking about software, the [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="David Rice" title="David Rice" src="http://www.cigital.com/silverbullet/drice-125.png" style="padding-left: 7px;" /></p>
<p>On the bonus-length 46th episode of The Silver Bullet Security Podcast, Gary talks with David Rice, Executive Director of the Monterey Group and author of <em>Geekonomics: The Real Cost of Insecure Software</em>.  Gary and David discuss David&#8217;s involvement with Infowar at the Naval Postgraduate School and how it impacted his thinking about software, the recent Chinese cyberattack on Google, what incentives exist to create and apply software security best practices, how users may be mistaking marketing for security, and the SANS WhatWorks in Application Security Summit.  They close out by discussing unusual yoga positions.</p>
<ul>
<li><a href="http://www.montereygrp.com/">Monterey Group</a></li>
<li><a href="http://www.geekonomicsbook.com/"><em>Geekonomics: The Real Cost of Insecure Software</em></a> (also: <a href="http://blog.geekonomicsbook.com/">Geekonomics Blog</a>)</li>
<li><a href="http://www.cigital.com/silverbullet/show-041/">Silver Bullet #41 &#8211; Fred Schneider</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-011/">Silver Bullet #11 &#8211; Dorothy Denning</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1338343">Software Security Comes of Age</a> (InformIT) &#8211; on the growth of the software security space</li>
<li><a href="http://www.techcrunch.com/2010/01/12/google-china-attacks/">Google Defends Against Large Scale Chinese Cyber Attack</a></li>
<li><a href="http://www.sans.org/appsec-2010/summit.php">SANS WhatWorks in Application Security Summit 2010</a></li>
<li><a href="http://bsi-mm.com">BSIMM</a></li>
<li><a href="http://hubpages.com/hub/Funny-Yoga">Beached Whale yoga position</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-046/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/57/0/silverbullet-046.mp3" length="51990656" type="audio/mpeg"/>
<itunes:duration>36:06</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 045 &#8211; An Interview with Lorrie Cranor</title>
		<link>http://www.cigital.com/silverbullet/show-045/</link>
		<comments>http://www.cigital.com/silverbullet/show-045/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 15:33:06 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=56</guid>
		<description><![CDATA[
On the 45th episode of The Silver Bullet Security Podcast, Gary chats with Lorrie Cranor, Associate Professor of Computer Science and Engineering and Public Policy at Carnegie Melon University.  Gary and Lorrie discuss how everyday people think about privacy and what we can do to get them to care about it, the relationship between [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Lorrie Cranor" title="Lorrie Cranor" src="http://www.cigital.com/silverbullet/lcranor-125.png" style="padding-left: 7px;" /></p>
<p>On the 45th episode of The Silver Bullet Security Podcast, Gary chats with Lorrie Cranor, Associate Professor of Computer Science and Engineering and Public Policy at Carnegie Melon University.  Gary and Lorrie discuss how everyday people think about privacy and what we can do to get them to care about it, the relationship between trust and privacy, and why the US is lagging behind the EU on privacy-related issues.  They close out the discussion by talking about women in computing.</p>
<ul>
<li><a href="http://lorrie.cranor.org/">Lorrie Cranor</a></li>
<li><a href="http://www.oreilly.com/catalog/securityusability/index.html"><em>Security and Usability: Designing Secure Systems That People Can Use</em></a></li>
<li><a href="http://oreilly.com/catalog/9780596003715/"><em>Web Privacy with P3P</em></a></li>
<li><a href="http://cups.cs.cmu.edu/index.php">CyLab Usable Privacy and Security Laboratory (CUPS)</a></li>
<li><a href="http://cups.cs.cmu.edu/soups/2009/proceedings/a4-kelley.pdf">A &#8220;Nutrition Label&#8221; for Privacy</a></li>
<li><a href="http://bsi-mm.com/europe">BSIMM Europe</a></li>
<li><a href="http://www.youtube.com/watch?v=kLgJYBRzUXY">Google search privacy video</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-045/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/56/0/silverbullet-045.mp3" length="38668416" type="audio/mpeg"/>
<itunes:duration>26:51</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 044 &#8211; An Interview with Steve Kent</title>
		<link>http://www.cigital.com/silverbullet/show-044/</link>
		<comments>http://www.cigital.com/silverbullet/show-044/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 21:55:05 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=55</guid>
		<description><![CDATA[On the 44th episode of The Silver Bullet Security Podcast, Gary talks with Steve Kent, Chief Scientist &#8211; Information Security, for BBN Technologies, a division of Raytheon.  Gary and Steve discuss the history of network security, secure transport and base Internet protocols, the role of politics in the adoption of security on the Internet, [...]]]></description>
			<content:encoded><![CDATA[<p>On the 44th episode of The Silver Bullet Security Podcast, Gary talks with Steve Kent, Chief Scientist &#8211; Information Security, for BBN Technologies, a division of Raytheon.  Gary and Steve discuss the history of network security, secure transport and base Internet protocols, the role of politics in the adoption of security on the Internet, applied cryptography, and whether security and individual liberty co-exist.  They finish by discussing extremely high end wine.</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2008/08/revealed-the-in/">Internet&#8217;s Biggest Security Hole</a></li>
<li><a href="http://www.ir.bbn.com/sbgp/S-BGP_Clarke_workshop.ppt">Securing the Border Gateway Protocol</a> (PPT)</li>
<li><a href="http://www7.nationalacademies.org/ocga/testimony/IDs_Not_That_Easy.asp">2006: Statement before Congress regarding a nationwide ID system</a></li>
<li><a href="http://bsi-mm.com/europe/">BSIMM Europe</a></li>
</ul>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-044/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/55/0/silverbullet-044.mp3" length="46776448" type="audio/mpeg"/>
<itunes:duration>32:29</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 043 &#8211; An Interview with Christofer Hoff</title>
		<link>http://www.cigital.com/silverbullet/show-043/</link>
		<comments>http://www.cigital.com/silverbullet/show-043/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 21:20:16 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=54</guid>
		<description><![CDATA[
On the 43rd episode of The Silver Bullet Security Podcast, Gary chats with Christofer Hoff, Director of Cloud and Virtualization Solutions at Cisco.  Hoff is well known for his colorful blog posts and presentations on cloud security and other complex security issues.  Suffice it to say, the cloud was a big topic for [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Christofer Hoff" title="Christofer Hoff" src="http://www.cigital.com/silverbullet/choff-125.png" style="padding-left: 7px;" /></p>
<p>On the 43rd episode of The Silver Bullet Security Podcast, Gary chats with Christofer Hoff, Director of Cloud and Virtualization Solutions at Cisco.  Hoff is well known for his colorful blog posts and presentations on cloud security and other complex security issues.  Suffice it to say, the cloud was a big topic for this issue.  And rum.</p>
<ul>
<li><a href="http://rationalsurvivability.com/RationalSurvivability/About_The_Hoff.html">Christofer Hoff</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/">Rational Survivability</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/?p=567">The Frogs Who Desired a King: A Virtualization &#038; Cloud Computing Fable</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/?p=1271">Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure</a></li>
<li><a href="http://www.mountgay.com/">Mount Gay Extra Old Rum</a> (Gary&#8217;s favorite)</li>
<li><a href="http://en.wikipedia.org/wiki/Ron_Zacapa_Centenario">Ron Zacapa Centenario Rum</a> (Hoff&#8217;s favorite)</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-043/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/54/0/silverbullet-043.mp3" length="45994112" type="audio/mpeg"/>
<itunes:duration>31:56</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 042 &#8211; An Interview with Gillian Hayes</title>
		<link>http://www.cigital.com/silverbullet/show-042/</link>
		<comments>http://www.cigital.com/silverbullet/show-042/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 18:31:20 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=53</guid>
		<description><![CDATA[
On the 42nd episode of The Silver Bullet Security Podcast, Gary chats with Gillian Hayes, Assistant Professor in Informatics at the Bren School of Information and Computer Sciences at UC Irvine.  Gary and Gillian discuss how much people really need to know about security going on behind the scenes, how usability affects the health [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Gillian Hayes" title="Gillian Hayes" src="http://www.cigital.com/silverbullet/ghayes-125.png" style="padding-left: 7px;" /></p>
<p>On the 42nd episode of The Silver Bullet Security Podcast, Gary chats with Gillian Hayes, Assistant Professor in Informatics at the Bren School of Information and Computer Sciences at UC Irvine.  Gary and Gillian discuss how much people really need to know about security going on behind the scenes, how usability affects the health records security, whether or not surveillance changes how 20-somethings act in public (including on the net), and how having more women technologists positively impacts the humanization of technology.</p>
<ul>
<li><a href="http://www.gillianhayes.com/">Gillian Hayes</a></li>
<li><a href="http://www.star-uci.org/STAR/Welcome.html">Social and technological action research (STAR)</a></li>
<li><a href="http://www.cs.umd.edu/~ben/">Ben Shneiderman</a></li>
<li><a href="http://www.ncwit.org/">National Center for Women and Information Technology</a></li>
<li><a href="http://www.amazon.com/Discovery-Heaven-Harry-Mulisch/dp/0140239375/ref=sr_1_1?ie=UTF8&#038;s=books&#038;qid=1253629779&#038;sr=1-1-spell">The Discovery of Heaven</a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-042/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/53/0/silverbullet-042.mp3" length="44429440" type="audio/mpeg"/>
<itunes:duration>30:51</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 041 &#8211; An Interview with Fred Schneider</title>
		<link>http://www.cigital.com/silverbullet/show-041/</link>
		<comments>http://www.cigital.com/silverbullet/show-041/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 18:10:20 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=52</guid>
		<description><![CDATA[
On the 41st episode of The Silver Bullet Security Podcast, Gary talks with Fred Schneider, Samuel B. Eckert Professor of Computer Science at Cornell University and author of Trust in Cyberspace.  On the show, Gary and Fred discuss the relationship between security and reliability, diversity as a security mechanism, and the continuum of attack [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Fred Schneider" title="Fred Schneider" src="http://www.cigital.com/silverbullet/fschneider-125.png" style="padding-left: 7px;" /></p>
<p>On the 41st episode of The Silver Bullet Security Podcast, Gary talks with Fred Schneider, Samuel B. Eckert Professor of Computer Science at Cornell University and author of Trust in Cyberspace.  On the show, Gary and Fred discuss the relationship between security and reliability, diversity as a security mechanism, and the continuum of attack categories from configuration problems, to bugs, to flaws, to trust issues. Fred briefly discusses Pointillism at the end of the show.</p>
<ul>
<li><a href="http://www.cs.cornell.edu/fbs/">Fred B. Schneider</a></li>
<li><a href="http://www.cs.cornell.edu/fbs/publications/IEEEspMonoculture.pdf">IEEE Security and Privacy 7, 1 (January/February 2009)</a> [PDF], 14&#8211;17. With Ken Birman.</li>
<li><a href="http://www.nap.edu/openbook.php?record_id=6161">Trust in Cyberspace</a></li>
<li><a href="http://www.webexhibits.org/colorart/jatte.html">Pointillism (Seurat)</a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-041/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/52/0/silverbullet-041.mp3" length="45879424" type="audio/mpeg"/>
<itunes:duration>31:51</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 040 &#8211; An Interview with Bob Blakley</title>
		<link>http://www.cigital.com/silverbullet/show-040/</link>
		<comments>http://www.cigital.com/silverbullet/show-040/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 14:06:47 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=51</guid>
		<description><![CDATA[
For the 40th episode of The Silver Bullet Security Podcast, Gary interviews Bob Blakley, VP and research director of The Burton Group&#8217;s Identity and Privacy Strategies.  Gary and Bob discuss the importance of liberal arts degrees, the (over) complications of CORBA security, whether computer security requires a complete shift in approach, cybersecurity and governments, [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Bob Blakley" title="Bob Blakley" src="http://www.cigital.com/silverbullet/bblakley-125.png" style="padding-left: 7px;" /></p>
<p>For the 40th episode of The Silver Bullet Security Podcast, Gary interviews Bob Blakley, VP and research director of The Burton Group&#8217;s Identity and Privacy Strategies.  Gary and Bob discuss the importance of liberal arts degrees, the (over) complications of CORBA security, whether computer security requires a complete shift in approach, cybersecurity and governments, and the movie <em>Perils in Nude Modeling</em> (really).</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-040-bblakley.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://notabob.blogspot.com/">Ceci n&#8217;est pas un Bob</a> &#8211; Bob&#8217;s blog</li>
<li><a href="http://www.amazon.com/CORBA-Security-Introduction-Addison-Wesley-Technology/dp/0201325659"><em>CORBA Security: An Introduction to Safe Computing with Objects</em></a></li>
<li><a href="http://www.isoc.org/isoc/conferences/ndss/98/blakl_sl.pdf">NDSS&#8217;98 Trust Management Panel: LE NOZZE DI NOMEN</a> [PDF] &#8211; The NDSS &#8220;wedding script&#8221;</li>
<li>&#8220;<a href="http://portal.acm.org/citation.cfm?id=304855">The Emperor&#8217;s Old Armor</a>&#8220;</li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1379758"><a href="http://www.informit.com/articles/article.aspx?p=1379758">Moving U.S. Cybersecurity Beyond Cyberplatitudes</a></li>
<li><a href="http://www.imdb.com/title/tt0432710/"><em>Perils in Nude Modeling</em></a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-040/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/51/0/silverbullet-040.mp3" length="37165184" type="audio/mpeg"/>
<itunes:duration>25:48</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 039 &#8211; An Interview with Matt Blaze</title>
		<link>http://www.cigital.com/silverbullet/show-039/</link>
		<comments>http://www.cigital.com/silverbullet/show-039/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 21:01:53 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=49</guid>
		<description><![CDATA[
For the 39th episode of The Silver Bullet Security Podcast, Gary chats with Matt Blaze, Associate Professor of Computer and Information Science at the University of Pennsylvania.  Gary and Matt start the show off discussing the Obama administration&#8217;s &#8220;cyber coordinator&#8221; plan and the large number of cyber plans that are never cyber realized.  [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Matt Blaze" title="Matt Blaze" src="http://www.cigital.com/silverbullet/mblaze-126.png" style="padding-left: 7px;" /></p>
<p>For the 39th episode of The Silver Bullet Security Podcast, Gary chats with Matt Blaze, Associate Professor of Computer and Information Science at the University of Pennsylvania.  Gary and Matt start the show off discussing the Obama administration&#8217;s &#8220;cyber coordinator&#8221; plan and the large number of cyber plans that are never cyber realized.  They also discuss key escrow, warrantless wiretapping, the responsibility we have to stay engaged with issues surrounding individual liberty and privacy, and the similarities between physical locks and computer security.  Matt’s musical tastes are also briefly touched on.</p>
<ul>
<li><a href="http://www.crypto.com/">Matt Blaze</a></li>
<li><a href="http://en.wikipedia.org/wiki/Matt_Blaze">Matt Blaze &#8211; Wikipedia</a></li>
<li><a href="http://www.crypto.com/blog/">Matt Blaze&#8217;s Exhaustive Search</a> &#8211; Matt&#8217;s blog</li>
<li><a href="http://www.crypto.com/blog/safecracking_and_science/">Safecracking, Secrecy and Science</a></li>
<li><a href="http://www.crypto.com/papers/mk.pdf">Cryptology and Physical Security: Rights Amplification in Master-Keyed Mechanical Locks</a> &#8211; <em>IEEE Security &#038; Privacy</em>, March/April 2003</li>
<li><a href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1353725,00.html">RSA panel on Surveillance</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-011/">Silver Bullet 11: Dorothy Denning</a></li>
<li><a href="http://en.wikipedia.org/wiki/Trust_management">Trust Management</a></li>
<li><a href="http://www.crypto.com/papers/wiretap.pdf">Signaling Vulnerabilities in Wiretapping Systems</a> &#8211; <em>IEEE Security &#038; Privacy</em>, November/December 2005, by M. Sherr, E. Cronin, S. Clark and M. Blaze.</li>
<li><a href="http://www.everythingthathappens.com/">Eno/Byrne: Everything That Happens Will Happen Today</a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-039/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/49/0/silverbullet-039.mp3" length="46944384" type="audio/mpeg"/>
<itunes:duration>32:36</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 038 &#8211; An Interview with Kay Connelly</title>
		<link>http://www.cigital.com/silverbullet/show-038/</link>
		<comments>http://www.cigital.com/silverbullet/show-038/#comments</comments>
		<pubDate>Tue, 19 May 2009 21:33:17 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=47</guid>
		<description><![CDATA[
For the 38th episode of The Silver Bullet Security Podcast, Gary talks privacy with Kay Connelly, Associate Professor of Computer Science at Indiana University and Senior Associate Director of IU&#8217;s Center for Applied Cybersecurity Research. Gary and Kay discuss why in situ usability study is important, the E.T.H.O.S. living lab (including the &#8220;presence clock&#8221; and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Kay Connelly" title="Kay Connelly" src="http://www.cigital.com/silverbullet/kconnelly-125.png" style="padding-left: 7px;" /></p>
<p>For the 38th episode of The Silver Bullet Security Podcast, Gary talks privacy with Kay Connelly, Associate Professor of Computer Science at Indiana University and Senior Associate Director of IU&#8217;s Center for Applied Cybersecurity Research. Gary and Kay discuss why in situ usability study is important, the E.T.H.O.S. living lab (including the &#8220;presence clock&#8221; and the portal monitor), and Kay&#8217;s advice to women interested in pursuing a career in computer science.</p>
<ul>
<li><a href="http://www.cs.indiana.edu/~connelly/">Kay Connelly</a></li>
<li><a href="http://ethos.indiana.edu/?q=blog/3">E.T.H.O.S. &#8211; Ethical Technology in the Homes of Seniors</a></li>
<li><a href="http://www.npr.org/templates/story/story.php?storyId=5201273">Crafting a Smarter, Gentler Cell Phone</a> &#8211; NPR story featuring Kay Connelly</li>
<li><a href="http://www.cs.indiana.edu/surg/Publications/ubicomp07.pdf">Why It’s Worth the Hassle: The Value of In-Situ Studies When Designing Ubicomp</a> [PDF]</li>
<li><a href="http://www.cigital.com/silverbullet/show-007/">Silver Bullet #7: John Stewart</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-015/">Silver Bullet #15: Annie Antón</a></li>
<li><a href="http://www.hhs.gov/ocr/hipaa/">HIPAA</a></li>
<li><a href="http://ethos.indiana.edu/?page_id=103">Ambient (Presence) Clock</a></li>
<li><a href="http://ethos.indiana.edu/?page_id=90">Portal Monitor</a></li>
<li><a href="http://www.amazon.com/Song-You-Novel-Arthur-Phillips/dp/1400066468/ref=sr_1_1?ie=UTF8&#038;s=books&#038;qid=1242410749&#038;sr=1-1"><em>The Song Is You: A Novel</em></a> by Arthur Phillips</li>
<li><a href="http://www.amazon.com/Was-Told-Thered-Be-Cake/dp/159448306X/ref=sr_1_1?ie=UTF8&#038;s=books&#038;qid=1242410724&#038;sr=1-1"><em>I Was Told There&#8217;d Be Cake</em></a> by Sloane Crosley</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-038/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/47/0/silverbullet-038.mp3" length="36331648" type="audio/mpeg"/>
<itunes:duration>25:14</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 037 &#8211; An Interview with Virgil Gligor</title>
		<link>http://www.cigital.com/silverbullet/show-037/</link>
		<comments>http://www.cigital.com/silverbullet/show-037/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 18:56:51 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=45</guid>
		<description><![CDATA[
On the 37th episode of The Silver Bullet Security Podcast, Gary interviews Virgil Gligor, Professor at Carnegie Mellon University in the Department of Electrical and Computer Engineering and co-director of CyLab.  Gary and Virgil discuss how information security has changed over the last 35 years, why software security will be with us forever, and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Virgil Gligor" title="Virgil Gligor" src="http://www.cigital.com/silverbullet/vgligor-120.png" style="padding-left: 7px;" /></p>
<p>On the 37th episode of The Silver Bullet Security Podcast, Gary interviews Virgil Gligor, Professor at Carnegie Mellon University in the Department of Electrical and Computer Engineering and co-director of CyLab.  Gary and Virgil discuss how information security has changed over the last 35 years, why software security will be with us forever, and how Virgil&#8217;s childhood in Romania has shaped his views on security.  They close out with a discussion of Virgil&#8217;s breakfast-eating habits.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-037-vgligor.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.ece.cmu.edu/~virgil/">Virgil D. Gligor</a> (@ Carnegie Mellon)</li>
<li><a href="http://www.cylab.cmu.edu/">CyLab</a></li>
<li><a href="http://www.ece.cmu.edu/">Electrical and Computer Engineering at Carnegie Mellon University</a></li>
<li><a href="http://www.amazon.com/Building-Secure-Computer-System-Morrie/dp/0442230222/ref=sr_1_1?ie=UTF8&#038;s=books&#038;qid=1240327785&#038;sr=8-1">Building a Secure Computer System</a></li>
<li><a href="http://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act">Foreign Intelligence Surveillance Act</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1338343">Software Security Comes of Age</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1353725,00.html">RSA panel to discuss surveillance, privacy concerns</li>
<li><a href="http://www.amazon.com/Computer-Security-Science-Matt-Bishop/dp/0201440997"><em>Computer Security: Art and Science</em></a> by Matt Bishop</li>
<li><a href="http://ieeexplore.ieee.org/Xplore/login.jsp?url=http%3A%2F%2Fieeexplore.ieee.org%2Fiel2%2F358%2F3978%2F00151571.pdf%3Farnumber%3D151571&#038;authDecision=-203">Towards a Theory of Penetration-Resistant Systems and its Applications</a> (1991)</li>
<li><a href="http://www2.computer.org/portal/web/csdl/doi/10.1109/SP.1987.10014">A Formal Method for the Identification of Covert Storage Channels in Source Code</a> (1987)</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-037/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/45/0/silverbullet-037.mp3" length="39116851" type="audio/mpeg"/>
<itunes:duration>27:10</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 036 &#8211; An Interview with Gary McGraw (by James McGovern)</title>
		<link>http://www.cigital.com/silverbullet/show-036/</link>
		<comments>http://www.cigital.com/silverbullet/show-036/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 20:40:27 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=44</guid>
		<description><![CDATA[
We switch things up for this special third anniversary episode of Silver Bullet.  This time around, Gary is the victim, being interviewed by James McGovern, Enterprise Architect for The Hartford Financial Services Group, Inc. and OWASP maven.  Gary and James discuss the recently released Building Security In Maturity Model, how companies with Software [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Gary McGraw" title="Gary McGraw" src="http://www.cigital.com/silverbullet/gem-125.png" style="padding-left: 7px;" /></p>
<p>We switch things up for this special third anniversary episode of Silver Bullet.  This time around, Gary is the victim, being interviewed by James McGovern, Enterprise Architect for The Hartford Financial Services Group, Inc. and OWASP maven.  Gary and James discuss the recently released Building Security In Maturity Model, how companies with Software Security Groups retain their best and brightest, Microsoft&#8217;s trustworthy computing initiative/SDL program, and what less expensive tools small organizations with only a few developers can use.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-036-gem.pdf">Transcript of this episode</a> [PDF]
<li><a href="http://duckdown.blogspot.com/">Enterprise Architecture: From Incite comes Insight&#8230;</a> &#8211; James McGovern&#8217;s blog</li>
<li><a href="http://www.cigital.com/~gem/">Gary McGraw&#8217;s site</a></li>
<li><a href="http://www.swsec.com/"><em>Software Security: Building Security In</em></a></li>
<li><a href="http://www.bsi-mm.com/">Building Security In Maturity Model (BSIMM)</a></li>
<li><a href="http://duckdown.blogspot.com/2009/02/gartner-releases-paper-on-static.html">Gartner releases paper on Static Analysis</a> &#8211; James&#8217; blog entry on Gartner</li>
<li><a href="http://www.cigital.com/news/index.php?pg=art&#038;artid=155">Cigital&#8217;s John Steven to lead OWASP Northern Virginia Local Chapter</a> (press release)</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-036/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/44/0/silverbullet-036.mp3" length="49784960" type="audio/mpeg"/>
<itunes:duration>34:34</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 035 &#8211; An Interview with Daniel Suarez</title>
		<link>http://www.cigital.com/silverbullet/show-035/</link>
		<comments>http://www.cigital.com/silverbullet/show-035/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 20:50:17 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=43</guid>
		<description><![CDATA[
     
     

On the 35th episode of The Silver Bullet Security Podcast, Gary talks with Daniel Suarez, independent consultant and author of Daemon, a new techno-thriller about a gamer that reaches from beyond the grave to declare a war on all of humanity.  They talk about [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; text-align: center;">
     <img alt="Daniel Suarez" title="Daniel Suarez" src="http://www.cigital.com/silverbullet/dsuarez-125.png" style="padding-left: 7px;" /><br />
     <img alt="Daemon" title="Daemon" src="http://www.cigital.com/silverbullet/daemon-125.gif" style="padding-left: 7px; padding-top: 5px;" />
</div>
<p>On the 35th episode of The Silver Bullet Security Podcast, Gary talks with Daniel Suarez, independent consultant and author of <em>Daemon</em>, a new techno-thriller about a gamer that reaches from beyond the grave to declare a war on all of humanity.  They talk about Daniel&#8217;s new book and the movie options attached to it, the use of MMORPGs and flash mobs for nefarious means in the form of a distributed emergent attack, the current state of AI, and the follow-up to <em>Daemon</em>, <em>Freedom <sup>TM</sup></em>.</p>
<ul>
<li><a href="http://www.thedaemon.com/"><em>Daemon</em></a></li>
<li><a href="http://www.nbc.com/Last_Call_with_Carson_Daly/video/clips/daniel-suarez/1005261/">Daniel on <em>Last call with Carson Daly</em></a></li>
<li><a href="http://nwn.blogs.com/nwn/2007/08/second-life-and.html">Al-Qaeda in Second Life</a></li>
<li><a href="http://www.amazon.com/Distraction-Bruce-Sterling/dp/0553576399"><em>Distraction</em></a> by Bruce Sterling</li>
<li><a href="http://www.amazon.com/Halting-State-Charles-Stross/dp/0441014984"><em>Halting State</em></a> by Charles Stross</li>
<li><a href="http://fora.tv/2008/08/08/Daniel_Suarez_Daemon_Bot-Mediated_Reality">Bot-Mediated Reality</a> at the Long Now Foundation</li>
<li><a href="http://wiredforwar.pwsinger.com/"><em>Wired for War</em></a> by P.W. Singer</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-035/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/43/0/silverbullet-035.mp3" length="36373366" type="audio/mpeg"/>
<itunes:duration>25:16</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 034 &#8211; An Interview with Bill Brenner</title>
		<link>http://www.cigital.com/silverbullet/show-034/</link>
		<comments>http://www.cigital.com/silverbullet/show-034/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 19:05:39 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=42</guid>
		<description><![CDATA[
On the 34th episode of The Silver Bullet Security Podcast, Gary interviews Bill Brenner, senior editor at CSO Online and CSO Magazine.  Gary and Bill discuss how delivering the security message changes based on the audience (executives versus geeks and CSO’s versus CIO’s), the much-exaggerated death of print media, and balancing headline-grabbing sensationalism with [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Bill Brenner" title="Bill Brenner" src="http://www.cigital.com/silverbullet/bbrenner-125.png" style="padding-left: 7px;" /></p>
<p>On the 34th episode of The Silver Bullet Security Podcast, Gary interviews Bill Brenner, senior editor at CSO Online and <em>CSO Magazine</em>.  Gary and Bill discuss how delivering the security message changes based on the audience (executives versus geeks and CSO’s versus CIO’s), the much-exaggerated death of print media, and balancing headline-grabbing sensationalism with solid security business coverage.  They close out their interview with a discussion of Bill&#8217;s favorite period of history.</p>
<ul>
<li><a href="http://www.csoonline.com/author/380013/Bill+Brenner">Bill Brenner at CSO Online</a></li>
<li><a href="http://www.linkedin.com/in/billbrenner">Bill Brenner on LinkedIn</a></li>
<li><a href="http://www.facebook.com/profile.php?id=1426070157">Bill Brenner on Facebook</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/">Security Wire Weekly</a></li>
<li><a href="http://www.csoonline.com/podcasts">Security Insights Podcast</a></li>
<li><a href="http://1raindrop.typepad.com/">1 Raindrop</a> &#8211; Gunnar Peterson&#8217;s blog.</li>
<li>Silver Bullet interviews with <a href="http://www.cigital.com/silverbullet/show-025/">Jon Swartz, USA Today</a>, <a href="http://www.cigital.com/silverbullet/show-029/">Dennis Fisher, Tech Target</a>, and <a href="http://www.cigital.com/silverbullet/show-032/">Jeremiah Grossman, Whitehat</a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-034/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/42/0/silverbullet-034.mp3" length="40020895" type="audio/mpeg"/>
<itunes:duration>27:48</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Ad: Reality Check Security Podcast</title>
		<link>http://www.cigital.com/silverbullet/ad-reality-check-security-podcast/</link>
		<comments>http://www.cigital.com/silverbullet/ad-reality-check-security-podcast/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 22:06:08 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=41</guid>
		<description><![CDATA[We&#8217;re happy to announce the debut of The Reality Check Security Podcast with Gary McGraw:
The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners and practical software security.   Reality Check’s sister podcast, the Silver Bullet Security Podcast with Gary McGraw, follows a free form interview style tailored highlight the ideas [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re happy to announce the debut of <a href="/realitycheck/">The Reality Check Security Podcast with Gary McGraw</a>:</p>
<blockquote><p>The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners and practical software security.   Reality Check’s sister podcast, the <a href="http://www.cigital.com/silverbullet/">Silver Bullet Security Podcast with Gary McGraw</a>, follows a free form interview style tailored highlight the ideas and experience of security gurus.  By contrast, Reality Check is concerned with practical questions centered on running large-scale software security initiatives in the real world.</p>
<p>Reality Check targets experienced leaders working to solve software security problems in large organizations every day.  We use a standard script to guide each conversation with questions about history, methodology, best practice, and measurement.  We plan to interview leaders of mature software security programs and leaders of programs just getting started.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/ad-reality-check-security-podcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/41/0/Reality%20Check%20Security%20Podcast%20promo%20-%2050%20sec.mp3" length="1218367" type="audio/mpeg"/>
<itunes:duration>0:51</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 033 &#8211; An Interview with Laurie Williams</title>
		<link>http://www.cigital.com/silverbullet/show-033/</link>
		<comments>http://www.cigital.com/silverbullet/show-033/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 17:41:28 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=40</guid>
		<description><![CDATA[
On the 33rd episode of The Silver Bullet Security Podcast, Gary talks with Laurie Williams, Associate Professor of Computer Science at North Carolina State University.  Gary and Laurie discuss Laurie&#8217;s nine years at IBM, Agile&#8217;s adoption in the commercial space, XP and software security, and what changes Laurie would make to the standard computer [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Laurie Williams" title="Laurie Williams" src="http://www.cigital.com/silverbullet/lwilliams-125.png" style="padding-left: 7px;" /></p>
<p>On the 33rd episode of The Silver Bullet Security Podcast, Gary talks with Laurie Williams, Associate Professor of Computer Science at North Carolina State University.  Gary and Laurie discuss Laurie&#8217;s nine years at IBM, Agile&#8217;s adoption in the commercial space, XP and software security, and what changes Laurie would make to the standard computer science curriculum to better prepare students.</p>
<ul>
<li><a href="http://collaboration.csc.ncsu.edu/laurie/">Laurie Williams</a></li>
<li><a href="http://agile.csc.ncsu.edu/realsearch/">Empirical Software Engineering</a></li>
<li><a href="http://collaboration.csc.ncsu.edu/laurie/Security/ProtectionPoker/">Protection Poker tutorial</a></li>
<li><a href="http://collaboration.csc.ncsu.edu/laurie/Papers/p47-shin.pdf">Is Complexity Really the Enemy of Software Security?</a> [PDF]</li>
<li><a href="http://www.cigital.com/silverbullet/show-026/">Silver Bullet interview with Adam Shostack</a></li>
<li><a href="http://www.learnoutloud.com/Sale-Section/Self-Development/Spirituality/The-Law-of-Attraction/20044"><em>Law of Attraction</em></a> audiobook</li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-033/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/40/0/silverbullet-033.mp3" length="34050176" type="audio/mpeg"/>
<itunes:duration>23:39</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 032 &#8211; An Interview with Jeremiah Grossman</title>
		<link>http://www.cigital.com/silverbullet/show-032/</link>
		<comments>http://www.cigital.com/silverbullet/show-032/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 02:17:49 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/?p=38</guid>
		<description><![CDATA[
The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.

Transcript of this episode [PDF]
Jeremiah Grossman
Clickjacking
Adobe [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Jeremiah Grossman" title="Jeremiah Grossman" src="http://www.cigital.com/silverbullet/jgrossman-125.png" style="padding-left: 7px;" /></p>
<p>The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-032-jgrossman.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a></li>
<li><a href="http://jeremiahgrossman.blogspot.com/2008/10/clickjacking-web-pages-can-see-and-hear.html">Clickjacking</a></li>
<li><a href="http://www.webadminblog.com/index.php/2008/09/24/new-0day-browser-exploit-clickjacking-owasp-appsec-nyc-2008/">Adobe 0-day Browser Exploit</a></li>
<li><a href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf">Cross-Site Request Forgeries: Exploitation and Prevention</a> [PDF]</li>
<li><a href="http://www.cs.princeton.edu/sip/pub/spoofing.php3">Web Spoofing: An Internet Con Game</a> by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2007/05/web-application-scan-o-meter.html">Web application scan-o-meter</a></li>
<li><a href="http://1.bp.blogspot.com/_JdybrokZBAk/SO_rUc-ebPI/AAAAAAAABOY/dKbFPJfv1Cs/s1600-h/badgewall.jpg">The &#8220;Wall of Fame&#8221;</a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-032/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/38/0/silverbullet-032.mp3" length="42240718" type="audio/mpeg"/>
<itunes:duration>29:20</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 031 &#8211; An Interview with Matt Bishop</title>
		<link>http://www.cigital.com/silverbullet/show-031/</link>
		<comments>http://www.cigital.com/silverbullet/show-031/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 18:33:12 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-031/</guid>
		<description><![CDATA[
On the 31st episode of The Silver Bullet Security Podcast, Gary talks with Matt Bishop, professor of Computer Science at UC Davis and author of the book Computer Security: Art and Science as well as many peer-reviewed papers.  Gary and Matt discuss Matt&#8217;s plan to work security analysis and secure coding into a wider [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Matt Bishop" title="Matt Bishop" src="http://www.cigital.com/silverbullet/mbishop-125.png" style="padding-left: 7px;" /></p>
<p>On the 31st episode of The Silver Bullet Security Podcast, Gary talks with Matt Bishop, professor of Computer Science at UC Davis and author of the book <em>Computer Security: Art and Science</em> as well as many peer-reviewed papers.  Gary and Matt discuss Matt&#8217;s plan to work security analysis and secure coding into a wider computer science cirriculum, Matt&#8217;s early work with Mike Dilger on TOCTOU, whether or not progress is being made in the field of software security, and the role of training in large-scale software security initiatives. Their chat closes with a mention of Matt&#8217;s home menagerie (which does not include any one-legged chickens at this time).</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-031-mbishop.pdf">Transcript of this episode</a></li>
<li><a href="http://nob.cs.ucdavis.edu/bishop/">Matt Bishop</a></li>
<li><a href="http://www.computer.org/security">IEEE <em>Security &#038; Privacy Magazine</em></a></li>
<li><a href="http://nob.cs.ucdavis.edu/book/book-aands/"><em>Computer Security: Art and Science</em></a></li>
<li><a href="http://www.cigital.com/silverbullet/show-011/">Silver Bullet Security Podcast interview with Dorothy Denning</a></li>
<li><a href="http://www.rand.org/pubs/reports/R609-1/R609.1.html">Security Controls for Computer Systems: Report of Defense Science Board Task Force on Computer Security</a> (the &#8220;Ware Report&#8221; referred to in the podcast)</li>
<li><a href="http://www.albany.edu/acc/courses/ia/classics/belllapadula1.pdf">Secure Computer Systems: Mathematical Foundations</a> &#8211; The Bell Lapadula model [PDF]</li>
<li><a href="http://csrc.nist.gov/publications/history/bell76.pdf">Secure Computer System: Unified Exposition and Multics Interpretation</a> [PDF]</li>
<li><a href="http://seclab.cs.ucdavis.edu/papers/HaughBishopNDSS2003.pdf">Testing C Programs for Buffer Overflow Vulnerabilities</a> &#8211; Eric Haugh, Matt Bishop [PDF]</li>
<li><a href="http://www.owasp.org/index.php/File_Access_Race_Condition:_TOCTOU">TOCTOU</a></li>
<li><a href="http://nob.cs.ucdavis.edu/bishop/papers/1996-compsys/">Checking for Race Conditions in File Accesses</a> by Matt Bishop and Michael Dilger</li>
<li><a href="http://www.amazon.com/Song-One-Legged-Chicken/dp/B000V672OK">&#8220;The Song of the One Legged Chicken&#8221;</a></li>
</ul>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-031/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/36/0/silverbullet-031.mp3" length="35151294" type="audio/mpeg"/>
<itunes:duration>24:24</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 030 &#8211; An Interview with Ken van Wyk</title>
		<link>http://www.cigital.com/silverbullet/show-030/</link>
		<comments>http://www.cigital.com/silverbullet/show-030/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 21:23:25 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-030/</guid>
		<description><![CDATA[
On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline of computer science doesn&#8217;t learn from failure like mechanical [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ken van Wyk" title="Ken van Wyk" src="http://www.cigital.com/silverbullet/kvanwyk-125.png" style="padding-left: 7px;" /></p>
<p>On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline of computer science doesn&#8217;t learn from failure like mechanical engineering does, how we&#8217;re making steps backwards in computer security, whether focusing on web applications is a good or bad thing for software security, and Ken&#8217;s recommendation for moderately-priced red wines.</p>
<ul>
<li><a href="http://www.vanwyk.org/ken/">Ken&#8217;s personal page</a></li>
<li><a href="http://www.krvw.com/">KRvW Associates</a></li>
<li><a href="http://www.cert.org/">CERT</a></li>
<li><a href="http://www.first.org/">FIRST</a></li>
<li><a href="http://www.securecoding.org/"><em>Secure Coding</em></a></li>
<li><a href="http://oreilly.com/catalog/9780596001308/"><em>Incident Response</em></a></li>
<li><a href="http://www.securecoding.org/list/">SC-L mailing list</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/07/06/from-the-foreword-to-secure-programming-with-static-analysis/">From the foreword to Secure Programming with Static Analysis</a> &#8211; blog entry with photo of Tacoma Narrows Bridge</li>
<li><a href="http://finance.google.com/finance?chdnp=1&#038;chdd=1&#038;chds=1&#038;chdv=1&#038;chvs=maximized&#038;chdeh=0&#038;chdet=1222200000000&#038;chddm=166345&#038;q=NYSE:TJX&#038;ntsp=0">TJX&#8217;s stock increase since the January 2007 security breach</a></li>
<li><a href="http://www.buildsecurityin.com/">The Addison-Wesley Software Security Series</a></li>
<li><a href="http://www.google.com/search?hl=en&#038;client=opera&#038;rls=en&#038;hs=fdc&#038;sa=X&#038;oi=spell&#038;resnum=0&#038;ct=result&#038;cd=1&#038;q=barbera+d%27asti&#038;spell=1">Barbera D&#8217;Asti wines</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-030/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/35/0/silverbullet-030.mp3" length="31395675" type="audio/mpeg"/>
<itunes:duration>21:48</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 029 &#8211; An Interview with Dennis Fisher</title>
		<link>http://www.cigital.com/silverbullet/show-029/</link>
		<comments>http://www.cigital.com/silverbullet/show-029/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 15:05:01 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-029-an-interview-with-dennis-fisher/</guid>
		<description><![CDATA[
On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and Information Security Magazine.  Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dennis Fisher" title="Dennis Fisher" src="http://www.cigital.com/silverbullet/dfisher-108.png" style="padding-left: 7px;" /></p>
<p>On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and <em>Information Security Magazine</em>.  Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state of software security, and which is harder: being a fry cook at Hardees or working as a PR flack.</p>
<ul>
<li><a href="http://security.blogs.techtarget.com/author/security/">Dennis&#8217; blog</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1239802,00.html">TJX</a></li>
<li><a href="http://music.aol.com/video/dirty-laundry/the-eagles/tag/joe-walsh/1354381">Joe Walsh plays dirty laundry</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1237978">Software Security Grows</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/2008/07/31/the-state-of-software-security">Dennis&#8217; un-named podcast</a></li>
<li><a href="http://www.youtube.com/watch?v=f99PcP0aFNE">Series of Tubes</a></li>
<li><a href="http://www.hardees.com/">Hardees</a></li>
<li><a href="http://www.cs.washington.edu/research/systems/privacy.htm">Nike/iPod</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-029/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/34/0/silverbullet-029.mp3" length="34313704" type="audio/mpeg"/>
<itunes:duration>23:50</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 028 &#8211; An Interview with Bill Cheswick</title>
		<link>http://www.cigital.com/silverbullet/show-028/</link>
		<comments>http://www.cigital.com/silverbullet/show-028/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 19:30:25 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-028/</guid>
		<description><![CDATA[
On the 28th episode of The Silver Bullet Security Podcast, Gary interviews Bill Cheswick, a lead member of technical staff at AT&#038;T Research and all around security guru.  Bill has been working in computer security for over 35 years.  He coined the term &#8220;proxy&#8221; in 1990 with reference to firewalls, and co-authored the [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Bill Cheswick" title="Bill Cheswick" src="http://www.cigital.com/silverbullet/bcheswick-125.png" style="padding-left: 7px;" /></p>
<p>On the 28th episode of <em>The Silver Bullet Security Podcast</em>, Gary interviews Bill Cheswick, a lead member of technical staff at AT&#038;T Research and all around security guru.  Bill has been working in computer security for over 35 years.  He coined the term &#8220;proxy&#8221; in 1990 with reference to firewalls, and co-authored the book <em>Firewalls and Internet Security</em> which was used to train an entire generation of sys admins.  Gary and Bill discuss whether we&#8217;re winning or losing the computer security war, how security threats have evolved from pimply-faced teenagers to organized crime, whether we should move security into &#8220;the cloud,&#8221; and whether re-naming &#8220;Christmas lights&#8221; to &#8220;solstice lights&#8221; would bypass NJ holiday decoration ordinances.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-028-bcheswick.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cheswick.com/ches/">Bill Cheswick</a></li>
<li><a href="http://www.research.att.com/">AT&#038;T Research</a></li>
<li><a href="http://www.lumeta.com/">Lumeta</a></li>
<li><a href="http://www.wilyhacker.com/">FWIS</a></li>
<li>“<a href="http://www.clusit.it/whitepapers/gateway.pdf">The Design of a Secure Internet Gateway</a>” (Usenix 1990, coining of “proxy”)</li>
<li><a href="http://httpd.apache.org/">The Apache web server</a></li>
<li><a href="http://en.wikipedia.org/wiki/Turtles_all_the_way_down">Turtles all the Way Down</a></li>
<li><a href="http://www.cigital.com/silverbullet/show-022/">Ed Amoroso’s Silver Bullet Podcast</a> (use blink test to compare)</li>
<li><a href="http://www.solsticelights.com/">Solstice Lights</a></li>
</ul>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-028/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/33/0/silverbullet-028.mp3" length="34531879" type="audio/mpeg"/>
<itunes:duration>23:59</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 027 &#8211; An Interview with Gunnar Peterson</title>
		<link>http://www.cigital.com/silverbullet/show-027/</link>
		<comments>http://www.cigital.com/silverbullet/show-027/#comments</comments>
		<pubDate>Wed, 18 Jun 2008 13:30:44 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-027/</guid>
		<description><![CDATA[
On the 27th episode of The Silver Bullet Security Podcast, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group.  Gary and Gunnar begin with the age-old question, &#8220;What is security?&#8221;  They go on to discuss how Web 2.0 and SOA security is progressing, the big idea behind &#8220;federated identity,&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Gunnar Peterson" title="Gunnar Peterson" src="http://www.cigital.com/silverbullet/gpeterson-123.gif" style="padding-left: 7px;" /></p>
<p>On the 27th episode of <em>The Silver Bullet Security Podcast</em>, Gary interviews software security expert Gunnar Peterson, a Managing Principal at Arctec Group.  Gary and Gunnar begin with the age-old question, &#8220;What is security?&#8221;  They go on to discuss how Web 2.0 and SOA security is progressing, the big idea behind &#8220;federated identity,&#8221; whether all market verticals can follow the software security lead of the financial services industry, and the inherent badness of the color purple.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-027-gpeterson.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.computer.org/portal/pages/security/2008/n2/bsi.xml">Build Security In column from IEEE S&#038;P</a></li>
<li><a href="http://1raindrop.typepad.com/">Gunnar’s Blog</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1217101">informIT (Securing Web 3.0)</a></li>
<li><a href="http://www.securitymetrics.org/content/Wiki.jsp?page=Welcome_blogentry_110308_1">Metricon 3.0</a></li>
<li><a href="http://research.microsoft.com/lampson/69-SecurityRealIEEE/69-SecurityRealIEEE.htm">Butler Lampson on Security</a></li>
<li><a href="http://en.wikipedia.org/wiki/Federated_identity">Federated Identity</a></li>
<li><a href="http://www.pingidentity.com/">Ping Identity</a></li>
<li><a href="http://www.geraldmweinberg.com/Site/Home.html">Gerald Weinberg</a></li>
<li><a href="http://securityblog.verizonbusiness.com/2008/06/13/patching-conundrum/">Verizon Business Security: Patching Conundrum</a></li>
</ul>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-027/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/32/0/silverbullet-027.mp3" length="40217586" type="audio/mpeg"/>
<itunes:duration>27:56</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 026 &#8211; An Interview with Adam Shostack</title>
		<link>http://www.cigital.com/silverbullet/show-026/</link>
		<comments>http://www.cigital.com/silverbullet/show-026/#comments</comments>
		<pubDate>Thu, 15 May 2008 19:17:01 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-026/</guid>
		<description><![CDATA[
The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsoft&#8217;s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Adam Shostack" title="Adam Shostack" src="http://www.cigital.com/silverbullet/ashostack-125.gif" style="padding-left: 7px;" /></p>
<p>The 26th episode of <em>The Silver Bullet Security Podcast</em> features Adam Shostack, a security expert on Microsoft&#8217;s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book <em>The New School of Information Security</em>.  They go on to chat about Adam&#8217;s aversion to the term &#8220;best practices,&#8221; the role IEEE Security &#038; Privacy magazine plays in bringing the science of security to a practical level, and whether the biggest problem of the CardSystems breach was the following the letter, rather than the spirit, of PCI.  Also on the agenda, duck-billed platypuses, Kandinski, and books by Pynchon.</p>
<p>(Beginning with this episode, Silver Bullet will be available as a 192k MP3.)</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-026-ashostack.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.emergentchaos.com/">Emergent Chaos blog</a></li>
<li><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787/"><em>The New School of Information Security</em></a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx">Microsoft&#8217;s SDL</a></li>
<li><a href="http://www.cigital.com/justiceleague/category/software-security-touchpoints/">Cigital’s Touchpoints</a></li>
<li><a href="http://www.computer.org/portal/site/security"><em>IEEE Security &#038; Privacy magazine</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Wassily_Kandinsky">Wassily Kandinsky</a></li>
<li><a href="http://money.cnn.com/2005/06/17/news/master_card/index.htm">The CardSystems breach</a> (2005)</li>
<li><a href="http://en.wikipedia.org/wiki/Thomas_Pynchon">Thomas Pynchon</a>
</ul>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-026/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/31/0/silverbullet-026.mp3" length="43490207" type="audio/mpeg"/>
<itunes:duration>30:12</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 025 &#8211; An Interview with Jon Swartz</title>
		<link>http://www.cigital.com/silverbullet/show-025/</link>
		<comments>http://www.cigital.com/silverbullet/show-025/#comments</comments>
		<pubDate>Fri, 18 Apr 2008 20:58:21 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-025-an-interview-with-jon-swartz/</guid>
		<description><![CDATA[
Jon Swartz, USA Today&#8217;s award-winning technology reporter and Pulitzer Prize nominee, is Gary&#8217;s guest on the 25th episode of The Silver Bullet Security Podcast.  They discuss Jon&#8217;s new book, Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity and the research that went [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Jon Swartz" title="Jon Swartz" src="http://www.cigital.com/silverbullet/jswartz-125.gif" style="padding-left: 7px;" /></p>
<p>Jon Swartz, <em>USA Today</em>&#8217;s award-winning technology reporter and Pulitzer Prize nominee, is Gary&#8217;s guest on the 25th episode of <em>The Silver Bullet Security Podcast</em>.  They discuss Jon&#8217;s new book, <em>Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity</em> and the research that went into writing it.  Gary and Jon also cover how cybercrime is driven by capitalist principals, why the general public&#8217;s attitude is so lax about software security, and how, even though it&#8217;s hard to get an accurate count of identity theft instances, they tend to show a sharp upward trend.  Jon ends the episode by disclosing his secret dream career.</p>
<p>(Apologies for the below-average sound quality on this episode.)</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-025-jswartz.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://zerodaythreat.com/"><em>Zero Day Threat</em></a></li>
<li><a href="http://www.usatoday.com/community/tags/reporter.aspx?id=321">Jon&#8217;s <em>USA Today</em> articles</a></li>
<li>Three recent articles:</li>
<ul>
<li><a href="http://www.usatoday.com/community/utils/idmap/31439036.story">Microsoft still seen with a win</a></li>
<li><a href="http://www.usatoday.com/community/utils/idmap/31438848.story">Online crime&#8217;s impact spreads</a></li>
<li><a href="http://www.usatoday.com/community/utils/idmap/31429572.story">AOL, News Corp. join battle over Yahoo</a></li>
</ul>
<li><a href="http://www.youtube.com/watch?v=-5zxOLZ5jXM"><em>The New Face of Cybercrime</em> trailer</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-025/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/30/0/silverbullet-025.mp3" length="26697856" type="audio/mpeg"/>
<itunes:duration>27:49</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 024 &#8211; An Interview with Mary Ann Davidson</title>
		<link>http://www.cigital.com/silverbullet/show-024/</link>
		<comments>http://www.cigital.com/silverbullet/show-024/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 18:26:36 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-024/</guid>
		<description><![CDATA[
Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Mary Ann Davidson" title="Mary Ann Davidson" src="http://www.cigital.com/silverbullet/madavidson-125.gif" /></p>
<p>Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk about how a young CSO-to-be got her first library card.</p>
<ul>
<li><a href="http://blogs.oracle.com/maryanndavidson/">Mary Ann Davidson&#8217;s blog</a></li>
<li><a href="http://wiki.oracle.com/page/Unbreakable+Linux">Unbreakable Linux</a></li>
<li><a href="http://www.amazon.com/Lone-Survivor-Eyewitness-Account-Operation/dp/0316067598"><em>Lone Survivor</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-024/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/29/0/silverbullet-024.mp3" length="27605631" type="audio/mpeg"/>
<itunes:duration>28:45</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 023 &#8211; An Interview with Chris Wysopal</title>
		<link>http://www.cigital.com/silverbullet/show-023/</link>
		<comments>http://www.cigital.com/silverbullet/show-023/#comments</comments>
		<pubDate>Tue, 19 Feb 2008 16:41:13 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-023/</guid>
		<description><![CDATA[
On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of The Art of Software Security Testing.  Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Chris Wysopal" title="Chris Wysopal" src="http://www.cigital.com/silverbullet/cwysopal-125.gif" /></p>
<p>On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of <em>The Art of Software Security Testing</em>.  Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to work for @stake.  Gary and Chris reminisce about L0pht (and the warehouse full of stuff) and discuss the role of security researchers now versus in the mid-late &#8217;90s. They also talk about the current state of the software security market and its continued growth.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Weld_Pond">Chris&#8217; Wikipedia entry</a></li>
<li><a href="http://www.softwaresecuritytesting.com/"><em>The Art of Software Security Testing</em></a></li>
<li><a href="http://www.veracode.com/">Veracode</a></li>
<li><a href="http://www.veracode.com/blog/">Zero in a bit</a> &#8211; Veracode&#8217;s blog</li>
<li><a href="http://en.wikipedia.org/wiki/L0pht">L0pht Heavy Industries</a></li>
<li><a href="http://www.vulnwatch.org/">Vulnwatch</a></li>
<li><a href="http://www.sourceboston.com/">SOURCE: Boston 2008</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-023/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/28/0/silverbullet-023.mp3" length="23801984" type="audio/mpeg"/>
<itunes:duration>24:48</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 022 &#8211; An Interview with Ed Amoroso</title>
		<link>http://www.cigital.com/silverbullet/show-022/</link>
		<comments>http://www.cigital.com/silverbullet/show-022/#comments</comments>
		<pubDate>Wed, 23 Jan 2008 21:33:09 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-022/</guid>
		<description><![CDATA[
On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&#038;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ed Amaroso" title="Ed Amoroso" src="http://www.cigital.com/silverbullet/eamoroso-125.gif" /></p>
<p style="margin-top: 5px">On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&#038;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and software correctness/quality vs software security.  They also discuss the Hugh Thompson show now airing on AT&#038;T&#8217;s Tech Channel.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-022-eamoroso.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.silicon-press.com/books/isbn.0-929306-38-4/index.html"><em>Cyber Security</em></a></li>
<li><a href="http://www.amazon.com/Fundamentals-Computer-Security-Technology-Amoroso/dp/0131089293"><em>Fundamentals of Computer Security Technology</em></a></li>
<li><a href="http://www.cigital.com/silverbullet/show-014/">Silver Bullet Interview with Peter Neumann</a></li>
<li><a href="http://www.att.com/techchannel/">AT&#038;T&#8217;s Tech Channel</a></li>
<li><a href="http://techchannel.att.com/site/home/index.cfm?key=7fb7b3944a89e2e9178bb2ce6d83e9d8">Gary on <em>The Hugh Thompson Show</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-022/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/27/0/silverbullet-022.mp3" length="31119488" type="audio/mpeg"/>
<itunes:duration>32:25</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 021 &#8211; A Panel Discussion with Cigital&#8217;s Principals</title>
		<link>http://www.cigital.com/silverbullet/show-021/</link>
		<comments>http://www.cigital.com/silverbullet/show-021/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 20:40:32 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-021/</guid>
		<description><![CDATA[
For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Cigital Logo" title="Cigital Logo" src="http://www.cigital.com/silverbullet/cigital-125.gif" /></p>
<p style="margin-top: 5px">For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and the similarities between CLASP, Microsoft&#8217;s SDL, and the Security Touchpoints.  They also ponder how much the security testing burden should fall on QA and whether developing expertise in architectural risk analysis or threat modeling is more helpful.  John Steven also discusses the hole in his dining room, which threat modeling would not have helped to prevent.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-021-cigital.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cigital.com/justiceleague/">Justice League blog</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/11/13/threat-modeling/">Threat Modeling</a> &#8211; a blog entry by John Steven</li>
<li><a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top 10 for 2007</a></li>
<li><a href="http://www.owasp.org/">OWASP</a></li>
<li><a href="http://www.shmoo.com/">The Shmoo Group</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-021/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/26/0/silverbullet-021.mp3" length="22640768" type="audio/mpeg"/>
<itunes:duration>23:35</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Happy Holidays from Silver Bullet</title>
		<link>http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/</link>
		<comments>http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 17:07:55 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/</guid>
		<description><![CDATA[

Get the Flash Player to see this player.

var s0 = new SWFObject("http://www.cigital.com/silverbullet/wp-content/plugins/flash-video-player/flvplayer.swf","n0","320","240","7");
s0.addParam("allowfullscreen","true");
s0.addParam("allowscriptaccess","always");
s0.addVariable("javascriptid","n0");
s0.addVariable("width","320");
s0.addVariable("height","240");
s0.addVariable("autoscroll","true");
s0.addVariable("largecontrols","false");
s0.addVariable("logo","http://www.cigital.com/silverbullet");
s0.addVariable("overstretch","true");
s0.addVariable("showdigits","true");
s0.addVariable("showdownload","false");
s0.addVariable("showeq","false");
s0.addVariable("showicons","true");
s0.addVariable("showvolume","true");
s0.addVariable("thumbsinplaylist","false");
s0.addVariable("autostart","false");
s0.addVariable("bufferlength","3");
s0.addVariable("repeat","false");
s0.addVariable("rotatetime","5");
s0.addVariable("smoothing","true");
s0.addVariable("volume","80");
s0.addVariable("enablejs","true");
s0.addVariable("linkfromdisplay","false");
s0.addVariable("t","autodetect");
s0.addVariable("useaudio","false");
s0.addVariable("usecaptions","false");
s0.addVariable("usefullscreen","true");
s0.addVariable("usekeys","false");
s0.addVariable("file","http://www.cigital.com/silverbullet/videos/silverbulletmerryxmas.flv");
s0.write("video0");


]]></description>
			<content:encoded><![CDATA[<p align="center">
<span id="video1" class="flashvideo">
<a href="http://www.macromedia.com/go/getflashplayer">Get the Flash Player</a> to see this player.</span>
<script type="text/javascript">
var s1 = new SWFObject("http://www.cigital.com/silverbullet/wp-content/plugins/flash-video-player/flvplayer.swf","n1","320","240","7");
s1.addParam("allowfullscreen","true");
s1.addParam("allowscriptaccess","always");
s1.addVariable("javascriptid","n1");
s1.addVariable("width","320");
s1.addVariable("height","240");
s1.addVariable("autoscroll","true");
s1.addVariable("largecontrols","false");
s1.addVariable("logo","http://www.cigital.com/silverbullet");
s1.addVariable("overstretch","true");
s1.addVariable("showdigits","true");
s1.addVariable("showdownload","false");
s1.addVariable("showeq","false");
s1.addVariable("showicons","true");
s1.addVariable("showvolume","true");
s1.addVariable("thumbsinplaylist","false");
s1.addVariable("autostart","false");
s1.addVariable("bufferlength","3");
s1.addVariable("repeat","false");
s1.addVariable("rotatetime","5");
s1.addVariable("smoothing","true");
s1.addVariable("volume","80");
s1.addVariable("enablejs","true");
s1.addVariable("linkfromdisplay","false");
s1.addVariable("t","autodetect");
s1.addVariable("useaudio","false");
s1.addVariable("usecaptions","false");
s1.addVariable("usefullscreen","true");
s1.addVariable("usekeys","false");
s1.addVariable("file","http://www.cigital.com/silverbullet/videos/silverbulletmerryxmas.flv");
s1.write("video1");
</script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Show 020 &#8211; An Interview with Markus Jakobsson</title>
		<link>http://www.cigital.com/silverbullet/show-020/</link>
		<comments>http://www.cigital.com/silverbullet/show-020/#comments</comments>
		<pubDate>Fri, 16 Nov 2007 22:32:45 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-020/</guid>
		<description><![CDATA[
For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University.  Gary and Markus discuss the difference between academic and corporate [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Markus Jakobsson" title="Markus Jakobsson" src="http://www.cigital.com/silverbullet/mjakobsson-125.gif" /></p>
<p style="margin-top: 5px">For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University.  Gary and Markus discuss the difference between academic and corporate research, the idea of &#8220;perfect privacy,&#8221; moving from hardcore cryptography to sociology, how reality is mimicking phishers, and how cartoons can be used to teach security.  In addition, Markus mentions the best place in Southeast Asia to get a haircut.</p>
<ul>
<li><a href="http://www.informatics.indiana.edu/markus/">Markus @ Indiana</a></li>
<li><a href="http://en.wikipedia.org/wiki/Markus_Jakobsson">Markus @ Wikipedia</a> &#8211; he&#8217;s &#8220;orphaned&#8221;!</li>
<li><a href="http://www.ravenwhite.com/">RavenWhite</a></li>
<li><a href="http://www.securitycartoon.com/">SecurityCartoon.com</a></li>
<li><a href="http://www.amazon.com/Crimeware-Symantec-Press-Markus-Jakobsson/dp/0321501950"><em>Crimeware</em><a></li>
<li><a href="http://phishing-and-countermeasures.com/"><em>Phishing and Countermeasures</em></a></li>
<li><a href="http://www.informatics.indiana.edu/markus/documents/security-education.pdf">Using Cartoons to Teach Internet Security</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-020/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/24/0/silverbullet-020.mp3" length="23502848" type="audio/mpeg"/>
<itunes:duration>24:29</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 019 &#8211; An Interview with Mikko Hyppönen</title>
		<link>http://www.cigital.com/silverbullet/show-019/</link>
		<comments>http://www.cigital.com/silverbullet/show-019/#comments</comments>
		<pubDate>Thu, 18 Oct 2007 15:21:38 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-019/</guid>
		<description><![CDATA[
For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Mikko Hyppönen" title="Mikko Hyppönen" src="http://www.cigital.com/silverbullet/mikko-125.gif" /></p>
<p style="margin-top: 5px">For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko&#8217;s prediction for the appearance of the first mobile botnet.  They also chat about Finnish hip-hop.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-019-mhypponen.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://mikko.hypponen.com/">Mikko Hyppönen</a></li>
<li><a href="http://en.wikipedia.org/wiki/Mikko_Hyppönen">Mikko Hyppönen</a>- Wikipedia</li>
<li><a href="http://www.f-secure.com/">F-Secure</a></li>
<li><a href="http://www.usenix.org/events/sec07/tech/#thurs">Mobile Malware</a> &#8211; Mikko&#8217;s USENIX 2007 talk, both audio and video (scroll down a bit)</li>
<li><a href="http://www.klov.com/game_detail.php?game_id=10505">Xevious</a></li>
<li><a href="http://www.management-consoles.com/">The FSMCs</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-019/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/23/0/silverbullet-019.mp3" length="21301376" type="audio/mpeg"/>
<itunes:duration>22:11</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 018 &#8211; An Interview with Eugene Spafford</title>
		<link>http://www.cigital.com/silverbullet/show-018/</link>
		<comments>http://www.cigital.com/silverbullet/show-018/#comments</comments>
		<pubDate>Tue, 25 Sep 2007 21:04:22 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-018/</guid>
		<description><![CDATA[
On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as &#8220;Spaf.&#8221;  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS).  On this [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Eugene Spafford" title="Eugene Spafford" src="http://www.cigital.com/silverbullet/spaf-125.gif" /></p>
<p style="margin-top: 5px">On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as &#8220;Spaf.&#8221;  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS).  On this episode, Gary and Spaf discuss the role of software testing in computer security, commercial certifications and whether they obviate the need for academic training, how Spaf feels about so-called &#8220;ethical hacking,&#8221; and why auditing and compliance is an area of emerging specialization.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-018-spaf.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://spaf.cerias.purdue.edu/">Dr. Eugene Spafford</a></li>
<li><a href="http://www.cerias.purdue.edu/weblogs/author/spaf/">Spaf&#8217;s blog at CERIAS</a></li>
<li><a href="http://en.wikipedia.org/wiki/Gene_Spafford">Gene Spafford</a> &#8211; Wikipedia</li>
<li><a href="http://www.cerias.purdue.edu/">CERIAS</a> &#8211; Center for Education and Research in Information Assurance and Security</li>
<li><a href="http://www.ise.gmu.edu/~ofut/rsrch/mut.html">Mothra</a> &#8211; Mutation testing</li>
<li><a href="http://www.nitrd.gov/pitac/">PITAC</a> &#8211; President&#8217;s Information Technology  Advisory Committee</li>
<li><a href="http://www.cerias.purdue.edu/weblogs/spaf/kudos-opinions-rants/post-120/what-did-you-really-expect/">What did you really expect?</a> &#8211; Spaf&#8217;s post on &#8220;reformed hackers&#8221;</li>
<li><a href="http://wiretap.area.com/Gopher/Library/Techdoc/Virus/inetvir.823">The Internet Worm Program: An Analysis</a></li>
<li><a href="http://spaf.cerias.purdue.edu/~spaf/Yucks/">Yucks Digest</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-018/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/22/0/silverbullet-018.mp3" length="27003008" type="audio/mpeg"/>
<itunes:duration>28:08</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 017 &#8211; An Interview with Eric Cole</title>
		<link>http://www.cigital.com/silverbullet/show-017/</link>
		<comments>http://www.cigital.com/silverbullet/show-017/#comments</comments>
		<pubDate>Fri, 24 Aug 2007 20:19:43 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-017/</guid>
		<description><![CDATA[
On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Eric Cole" title="Eric Cole" src="http://www.cigital.com/silverbullet/ecole-125.gif" /></p>
<p style="margin-top: 5px">On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), the academic approach to security versus practitioner certification models, and what kinds of training makes for good network security practitioners.  They also discuss the difficulty of certifying software developers.</p>
<ul>
<li><a href="http://www.secure-anchor.com/">Secure Anchor</a></li>
<li><a href="http://www.securityhaven.com/">Security Haven</a></li>
<li><a href="http://digitalcommons.pace.edu/dissertations/AAI3127379/">Stego-marking packets to control information leakage on TCP/IP based networks</a> &#8211; Eric&#8217;s dissertation</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-017/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/21/0/silverbullet-017.mp3" length="28208320" type="audio/mpeg"/>
<itunes:duration>29:23</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 016 &#8211; An Interview with Greg Hoglund</title>
		<link>http://www.cigital.com/silverbullet/show-016/</link>
		<comments>http://www.cigital.com/silverbullet/show-016/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 22:38:30 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-016/</guid>
		<description><![CDATA[
On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of Rootkits: Subverting the Windows Kernel and Exploiting Software.  In addition to shameless self-promotion of their new book, Exploiting Online Games, Gary and Greg discuss the natural tendency [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Greg Hoglund" title="Greg Hoglund" src="http://www.cigital.com/silverbullet/ghoglund-125.gif" /></p>
<p style="margin-top: 5px">On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of <em>Rootkits: Subverting the Windows Kernel</em> and <em>Exploiting Software</em>.  In addition to shameless self-promotion of their new book, <em>Exploiting Online Games</em>, Gary and Greg discuss the natural tendency of certain types of code to allow exploits, how disclosure is a good thing when it comes to revealing exploits, and the use of rootkits by the &#8220;good guys.&#8221;  Greg also makes us concerned that his 11-year-old daughter may 0wn our box.</p>
<ul>
<li><a href="http://www.rootkit.com/">Rootkit.com</a></li>
<li><a href="http://www.hbgary.com/">HB Gary</a></li>
<li>Greg&#8217;s Blackhat presentation from 2006: <a href="http://www.rootkit.com/vault/hoglund/GregSlidesWoWHack.rar">Hacking World of Warcraft(r): An Exercise in Advanced Rootkit Design</a> [rar, 2.35M]</li>
<li><a href="http://www.exploitingonlinegames.com/">Exploiting Online Games</a></li>
<li><a href="http://www.buildingsecurityin.com/">AWL Software Security Series</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-016/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/20/0/silverbullet-016.mp3" length="23085184" type="audio/mpeg"/>
<itunes:duration>24:03</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 015 &#8211; An Interview with Annie Antón</title>
		<link>http://www.cigital.com/silverbullet/show-015/</link>
		<comments>http://www.cigital.com/silverbullet/show-015/#comments</comments>
		<pubDate>Tue, 19 Jun 2007 14:12:30 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-015/</guid>
		<description><![CDATA[
On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary focus on privacy.  They start with an attempt to define what &#8220;privacy&#8221; is in the digital world,  [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Annie Anton" title="Annie Anton" src="http://www.cigital.com/silverbullet/aanton-125.gif" /></p>
<p style="margin-top: 5px">On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary focus on privacy.  They start with an attempt to define what &#8220;privacy&#8221; is in the digital world,  moving on to Annie&#8217;s work with The Privacy Place.  Annie also discusses airlines&#8217; pretty much pitiful privacy policies, the impact that a Google/Doubleclick deal would have on consumer privacy, crazy talk in EULAs, and the book <em>Letters to a Young Catholic</em> (which has nothing to do with privacy).</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-015-aanton.pdf">A partial transcript of the interview in IEEE Security &#038; Privacy</a></li>
<li><a href="http://www4.ncsu.edu/~aianton/">Annie I. Antón</a></li>
<li><a href="http://www.theprivacyplace.org/">The Privacy Place</a></li>
<li><a href="http://www.privacyrights.org/ar/CPResponse.htm">The ChoicePoint Data Security Breach</a></li>
<li><a href="http://www.eppc.org/publications/bookID.50/book_detail.asp"><em>Letters to a Young Catholic</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-015/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/19/0/silverbullet-015.mp3" length="2147483647" type="audio/mpeg"/>
<itunes:duration>25:16</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 014 &#8211; An Interview with Peter Neumann</title>
		<link>http://www.cigital.com/silverbullet/show-014/</link>
		<comments>http://www.cigital.com/silverbullet/show-014/#comments</comments>
		<pubDate>Tue, 22 May 2007 17:04:03 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-014/</guid>
		<description><![CDATA[
The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Peter Neumann" title="Peter Neumann" src="http://www.cigital.com/silverbullet/pneumann-125.gif" /></p>
<p style="margin-top: 5px">The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics engineering (&#8220;nodody writes a line of code without the approving authorities [having] read and understood the specification&#8221;), why DRM is the &#8220;wrong solution to the wrong problem,&#8221; and who was more interesting to meet: Albert Einstein or Norah Jones.</p>
<ul>
<li><a href="http://www.csl.sri.com/users/neumann/">Peter Neumann</a></li>
<li><a href="http://catless.ncl.ac.uk/risks">comp.RISKS</a></li>
<li><a href="http://www.csl.sri.com/users/neumann/neumann-book.html"><em>Computer-Related Risks</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Multics">Multics</a></li>
<li><a href="http://www.multicians.org/fjcc4.html">A General-Purpose File System For Secondary Storage</a> &#8211; Peter&#8217;s 1965 paper on Multics</li>
<li><a href="http://www.multicians.org/">Multics History Project</a></li>
<li><a href="http://www.luntzel.com/bbb/">The Brooklyn Boogaloo Blowout</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-014/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/18/0/silverbullet-014.mp3" length="20148352" type="audio/mpeg"/>
<itunes:duration>20:59</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 013 &#8211; An Interview with Ross Anderson</title>
		<link>http://www.cigital.com/silverbullet/show-013/</link>
		<comments>http://www.cigital.com/silverbullet/show-013/#comments</comments>
		<pubDate>Fri, 13 Apr 2007 20:33:21 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-013/</guid>
		<description><![CDATA[
On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering.   Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ross Anderson" title="Ross Anderson" src="http://www.cigital.com/silverbullet/randerson-125.gif" /></p>
<p style="margin-top: 5px">On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book <em>Security Engineering</em>.   Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why most systems fail, the economic imbalance between engineers/developers and a system&#8217;s users (with respect to who should address security), and why publicly describing attacks is essential to security engineering.  They close out by examining the security implications of wearing a kilt.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-013-randerson.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.ross-anderson.com/">Ross Anderson</a></li>
<li><a href="http://www.lightbluetouchpaper.org/">Light Blue Touchpaper</a> &#8211; A security blog by Cambridge computer scientists.</li>
<li><em>Security Engineering</em> &#8211; Ross&#8217; groundbreaking book <a href="http://www.amazon.com/exec/obidos/ASIN/0471389226/rossandersshomep">in print</a> and <a href="http://www.cl.cam.ac.uk/~rja14/book.html">online</a></li>
<li><a href="http://weis2007.econinfosec.org/">WEIS 2007 &#8211; Sixth Workshop on the Economics of Information Security</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/Papers/rfid-fc07.pdf">RFID and the Middleman</a> [PDF]</li>
<li><a href="http://showcase.netins.net/web/clanande/">The Clan Anderson Society</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/Presentations/busking.jpg">Ross playing the bagpipes</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-013/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/17/0/silverbullet-013.mp3" length="21927936" type="audio/mpeg"/>
<itunes:duration>22:50</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 012 &#8211; An Interview with Becky Bace</title>
		<link>http://www.cigital.com/silverbullet/show-012/</link>
		<comments>http://www.cigital.com/silverbullet/show-012/#comments</comments>
		<pubDate>Tue, 13 Mar 2007 21:13:02 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-012/</guid>
		<description><![CDATA[
On the 12th episode of The Silver Bullet Security Podcast, Gary
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory.  Gary and Becky discuss growing up in [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Becky Bace" title="Becky Bace" src="http://www.cigital.com/silverbullet/bbace-125.gif" /></p>
<p style="margin-top: 5px">On the 12th episode of The Silver Bullet Security Podcast, Gary<br />
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory.  Gary and Becky discuss growing up in rural America, explosives, and Becky&#8217;s Jimmy Hoffa sponsored college funding situation. They also talk about the evolution of security curricula in academia, rampant commercialization of computer security, Becky&#8217;s involvement in tracking down the notorious Kevin Mitnick, vicodin-induced creativity, and eclectic music.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-012-bbace.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci927913,00.html">Who&#8217;s Who in Infosec: Rebecca Bace</a></li>
<li><a href="http://www.tridentcap.com/">Trident Capital</a> &#8211; The VC firm where Becky is an advisor</li>
<li><a href="http://www.thiemeworks.com/write/archives/beckyb2.htm">The IDS Den Mother</a> &#8211; a 2002 interview</li>
<li><a href="http://www.lanl.gov/">Los Alamos National Labs</a></li>
<li><a href="http://www.amazon.com/Intrusion-Detection-Rebecca-Gurley-Bace/dp/1578701856/ref=sr_1_1/104-2577668-4903944?ie=UTF8&#038;s=books&#038;qid=1173812537&#038;sr=8-1"><em>Intrusion Detection</em></a></li>
<li><a href="http://www.amazon.com/Guide-Forensic-Testimony-Presenting-Technical/dp/0201752794/ref=sr_1_2/104-2577668-4903944?ie=UTF8&#038;s=books&#038;qid=1173812537&#038;sr=8-2"><em>A Guide to Forensic Testimony: The Art and Practice of Presenting Testimony As An Expert Technical Witness</em></a> &#8211; Co-authored with Fred Smith</li>
<li><a href="http://www.infosecuritywomen.com/">Executive Women&#8217;s Forum</a></li>
<li><a href="http://www.franksinatra.com/">Frank Sinatra</a></li>
<li><a href="http://www.kinseysicks.com/">The Kinsey Sicks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/16/0/silverbullet-012.mp3" length="22704256" type="audio/mpeg"/>
<itunes:duration>23:39</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 011 &#8211; An Interview with Dorothy Denning</title>
		<link>http://www.cigital.com/silverbullet/show-011/</link>
		<comments>http://www.cigital.com/silverbullet/show-011/#comments</comments>
		<pubDate>Thu, 15 Feb 2007 22:07:35 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-011/</guid>
		<description><![CDATA[
On the 11th episode of The Silver Bullet Security Podcast, Gary talks with Dorothy Denning, a professor in the Department of Defense Analysis at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University.  Gary and Dorothy discuss Dorothy&#8217;s involvement in the Clipper Chip [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dorothy Denning" title="Dorothy Denning" src="http://www.cigital.com/silverbullet/ddenning-125.gif" /></p>
<p style="margin-top: 5px">On the 11th episode of The Silver Bullet Security Podcast, Gary talks with <a href="http://www.nps.navy.mil/ctiw/staff/denning.html">Dorothy Denning</a>, a professor in the <a href="http://www.nps.navy.mil/da/">Department of Defense Analysis</a> at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University.  Gary and Dorothy discuss Dorothy&#8217;s involvement in the Clipper Chip controversy (which earned Dorothy the moniker &#8220;clipper chick&#8221;), the concept of geo-encryption, and a famous 1990 paper she wrote describing a series of interviews with malicious hackers.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-011-ddenning.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://en.wikipedia.org/wiki/Dorothy_E._Denning">Wikipedia: Dorothy Denning</a></li>
<li><a href="http://www.epic.org/crypto/clipper/">Clipper Chip</a> (<a href="http://en.wikipedia.org/wiki/Clipper_chip">More</a>)</li>
<li><a href="http://www.wired.com/wired/archive/4.09/denning_pr.html">Clipper Chick</a> &#8211; a 1996 <em>Wired</em> article about the Clipper Chip controversy.</li>
<li><a href="http://www.cosc.georgetown.edu/~denning/crypto/Future.html">The Future of Cryptography</a></li>
<li><a href="http://www.cs.georgetown.edu/~denning/infosec/Grounding.txt">Location-Based Authentication: Grounding Cyberspace for Better Security</a> &#8211; A 1996 paper by Dorothy Denning and Peter F. MacDoran about geo-encryption.</li>
<li><a href="http://www.sgrm.com/art-7.htm">Concerning Hackers Who Break into Computer Systems</a> &#8211; Dorothy&#8217;s 1990 paper.</li>
<li><a href="http://www.bsim.org">Big Sur Power Walk</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-011/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/15/0/silverbullet-011.mp3" length="21471242" type="audio/mpeg"/>
<itunes:duration>22:22</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 010 &#8211; A Panel Discussion with Fortify Software&#8217;s Technical Advisory Board</title>
		<link>http://www.cigital.com/silverbullet/show-010/</link>
		<comments>http://www.cigital.com/silverbullet/show-010/#comments</comments>
		<pubDate>Mon, 22 Jan 2007 19:59:59 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-010/</guid>
		<description><![CDATA[
The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the Fortify Software Technical Advisory Board, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><img alt="Fortify TAB" src="http://www.cigital.com/silverbullet/fortify-tab.jpg" /></p>
<p style="margin-top: 5px">The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the <a href="http://www.fortifysoftware.com/company-partners/tab.jsp">Fortify Software Technical Advisory Board</a>, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using static analysis tools, and software security pedagogy.</p>
<p>Participating members of the Technical Advisory Board include:</p>
<ul>
<li><a href="http://www.cs.umd.edu/~pugh/">Bill Pugh</a>, Professor at University of Maryland, static analysis for finding bugs</li>
<li>Li Gong, GM at Microsoft, MSN in China</li>
<li><a href="http://www.ranum.com/">Marcus Ranum</a>, CSO of Tenable Network Security, security products trainer</li>
<li><a href="http://avirubin.com/">Avi Rubin</a>, Professor at Johns Hopkins, electronic voting security</li>
<li><a href="http://www.cs.cornell.edu/fbs/">Fred Schneider</a>, Professor at Cornell, trustworthy computing</a>
<li><a href="http://www.eecs.harvard.edu/~greg/">Greg Morrisett</a>, Professor at Harvard, dependant type theory</li>
<li><a href="http://nob.cs.ucdavis.edu/~bishop/">Matt Bishop</a>, Professor at UC Davis, computer security</li>
<li><a href="http://www.cs.berkeley.edu/~daw/">Dave Wagner</a>, Professor at Berkeley, software security and electronic voting</li>
</ul>
<p>A complete transcript of this podcast will be available soon from Fortify at <a href="http://www.fortify.com/silverbullet">http://www.fortify.com/silverbullet</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/14/0/silverbullet-010.mp3" length="18776359" type="audio/mpeg"/>
<itunes:duration>19:34</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 009 &#8211; An Interview with Bruce Schneier</title>
		<link>http://www.cigital.com/silverbullet/show-009/</link>
		<comments>http://www.cigital.com/silverbullet/show-009/#comments</comments>
		<pubDate>Thu, 14 Dec 2006 11:45:53 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-009/</guid>
		<description><![CDATA[
In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security.  He has written eight bestselling books, most recently Beyond Fear: Thinking Sensibly About Security in an Uncertain World and is the editor of [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Bruce Schneier" title="Bruce Schneier" src="http://www.cigital.com/silverbullet/bschneier-123.jpg" /></p>
<p style="margin-top: 5px">In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security.  He has written eight bestselling books, most recently <em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World</em> and is the editor of the massively popular Cryptogram mailing list.  In this episode, Gary and Bruce discuss the connection between physical security its technological component, the idea of risk management, the intersection of economics and security, and the ideas of &#8220;wholesale surveillance&#8221; and &#8220;security theater.&#8221;  They also discuss patch Tuesday, hack Wednesday, and Microsoft&#8217;s approach to software security.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Bruce_Schneier">Bruce&#8217;s Wikipedia entry</a></li>
<li><a href="http://www.amazon.com/s/104-2577668-4903944?ie=UTF8&#038;index=books&#038;rank=-relevance%2C%2Bavailability%2C-daterank&#038;field-author-exact=Schneier%2C%20Bruce">Bruce&#8217;s books</a></li>
<li><a href="http://pd.startribune.com/sp?aff=3&#038;keywords=schneier">Bruce&#8217;s recent restaurant reviews</a></li>
<li><a href="http://www.counterpane.com/">Counterpane</a></li>
<li><a href="http://crypto-gram.libsyn.com/">Crypto-Gram security podcast</a>
<li><a href="http://www.freedom-to-tinker.com/?p=1052">Property Rights Management</a> &#8211; Ed Felten&#8217;s discussion of PRM, mentioned on the show</li>
<li><a href="http://www.techdirt.com/articles/20051205/2345233.shtml">Copyright Mythbusters: Believe It or Not, Fair Use Exists</a> &#8211; a look at the &#8220;fair use doesn&#8217;t exist&#8221; argument</li>
<li><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/4806948.stm">BBC plans attacked for &#8216;TV tax&#8217;</a> (March 14, 2006)</li>
<li>Bruce&#8217;s suggestion for &#8220;cheap&#8221; wines: <a href="http://www.thewinedoctor.com/regionalguides/loire.shtml">Loire wines</a>, <a href="http://www.beyond.fr/wine/provencewines.html">Provence Wines</a>, <a href="http://www.rhonerangers.org/html/wines.html">Southern Rhone wines</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/13/0/silverbullet-009.mp3" length="23840778" type="audio/mpeg"/>
<itunes:duration>24:50</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 008 &#8211; An Interview with Brian Chess</title>
		<link>http://www.cigital.com/silverbullet/show-008/</link>
		<comments>http://www.cigital.com/silverbullet/show-008/#comments</comments>
		<pubDate>Fri, 17 Nov 2006 16:35:55 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-008/</guid>
		<description><![CDATA[
In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary and Brian discuss what commercial developers and academics have to learn from each other, [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Brian Chess" title="Brian Chess" src="http://www.cigital.com/silverbullet/bchess-125.jpg" /></p>
<p style="margin-top: 5px">In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary and Brian discuss what commercial developers and academics have to learn from each other, what it&#8217;s like to work for a Kleiner-Perkins startup (KP is the VC firm behind familiar names like Google, Amazon, and Sun), and how mystifying it is that some developers are OK with XSS vulnerabilities in their web applications.</p>
<ul>
<li><a href="http://www.fortifysoftware.com/">Fortify Software</a></li>
<li><a href="http://extra.fortifysoftware.com/blog/">extra</a> &#8211; Fortify&#8217;s software security blog</a></li>
<li>Matt Bishop&#8217;s <a href="http://nob.cs.ucdavis.edu/book/book-aands/index.html"><em>Computer Security: Art and Science</em></a> (mentioned again!)</li>
<li><a href="http://www.kpcb.com/">Kleiner Perkins Caufield &amp; Byers</a></li>
<li><a href="http://www.cigital.com/ssw/">DIMACS Workshop on Software Security</a> with Brian Kernighan</li>
<li><a href="http://sctest.cse.ucsc.edu/chess/">Brian as a wee lad</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-008/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/12/0/silverbullet-008.mp3" length="23570442" type="audio/mpeg"/>
<itunes:duration>24:33</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 007 &#8211; An Interview with John Stewart</title>
		<link>http://www.cigital.com/silverbullet/show-007/</link>
		<comments>http://www.cigital.com/silverbullet/show-007/#comments</comments>
		<pubDate>Wed, 25 Oct 2006 15:00:58 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-007/</guid>
		<description><![CDATA[
In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse).  John [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Michael Howard" title="John Stewart" src="http://www.cigital.com/silverbullet/jstewart-125.jpg" /></p>
<p style="margin-top: 5px">In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse).  John and Gary also revisit Cisco-gate, talk about how John&#8217;s identity was stolen, and determine why John&#8217;s kids don&#8217;t have e-mail addresses.</p>
<ul>
<li><a href="/silverbullet/shows/silverbullet-007-jstewart.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://newsroom.cisco.com/dlls/tln/exec_team/stewart/perspectives.html">Executive Perspective: John Stewart on Vulnerability Disclosure</a></li>
<li><a href="http://en.wikipedia.org/wiki/CSO">Wikipedia: CSO</a></li>
<li><a href="http://en.wikipedia.org/wiki/Digital_Island">Digital Island</a></li>
<li><a href="http://snowplow.org/tom/worm/worm.html">The What, Why, and How of the 1988 Internet Worm</a> &#8211; a look at the history of the Morris Worm</li>
<li><a href="http://www.wired.com/news/technology/0,1282,68435,00.html">Cisco-gate</a></li>
<li><a href="http://www.csoonline.com/read/030104/idtheft.html">Five Ways to Fight ID Theft</a> &#8211; John talks about finding himself a victim of identity theft; see also: <a href="http://shaunsaxon.com/yamahafz1.html">the motorcycle he was trying to buy when he found out</a></li>
<li><a href="http://www.mykey3000.com/cosmicteams/profiles/gljohn.htm">John Stewart</a>, but not the one Gary interviews (and not the one you&#8217;re thinking of)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-007/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/11/0/silverbullet-007.mp3" length="25985034" type="audio/mpeg"/>
<itunes:duration>27:04</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Japanese translation of Marcus Ranum interview</title>
		<link>http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/</link>
		<comments>http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/#comments</comments>
		<pubDate>Wed, 11 Oct 2006 15:34:38 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/</guid>
		<description><![CDATA[Fumio over at LapisNet has translated an excerpt of the Marcus Ranum interview.  You can read the Japanese translation here.
]]></description>
			<content:encoded><![CDATA[<p>Fumio over at <a href="http://www.lapisnet.co.jp/">LapisNet</a> has translated an excerpt of the <a href="http://www.cigital.com/silverbullet/show-003/">Marcus Ranum interview</a>.  You can read the <a href="http://www.lapisnet.co.jp/jp/info/securitypodcast03.html">Japanese translation here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Show 006 &#8211; An Interview with Michael Howard</title>
		<link>http://www.cigital.com/silverbullet/show-006/</link>
		<comments>http://www.cigital.com/silverbullet/show-006/#comments</comments>
		<pubDate>Thu, 28 Sep 2006 20:11:47 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-006/</guid>
		<description><![CDATA[
The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft&#8217;s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security.  Michael continues to play a key roll in [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Michael Howard" title="Michael Howard" src="http://www.cigital.com/silverbullet/mhoward-118.jpg" /></p>
<p style="margin-top: 5px">The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft&#8217;s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security.  Michael continues to play a key roll in implementing the Trustworthy Computing Initiative at Microsoft.  Gary and Michael also discuss the security features of Windows Vista and Michael&#8217;s recommendations for the two most important best practices when developing secure software.  Listen for a startling revelation about Michael&#8217;s choice of a &#8220;desert island book.&#8221;</p>
<ul>
<li><a href="http://blogs.msdn.com/michael_howard/">Michael Howard&#8217;s blog</a></li>
<li><a href="http://www.microsoft.com/mspress/books/5957.asp"><em>Writing Secure Code</em></a> by Michael Howard</li>
<li><a href="http://en.wikipedia.org/wiki/Defense_in_depth">Wikipedia: Defense in Depth</a></li>
<li><a  href="http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnsecure/html/sdl.asp">Microsoft&#8217;s Trustworthy Computing Security Development Lifecycle</a></li>
<li><a href="http://nob.cs.ucdavis.edu/book/">Matt Bishop&#8217;s computer security books</a> &#8211; These would go with Michael to a desert island.</li>
<li><a href="http://en.wikipedia.org/wiki/Michael_Howard">Michael Howard</a> &#8211; but not the one Gary interviewed.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-006/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/9/0/silverbullet-006.mp3" length="24731658" type="audio/mpeg"/>
<itunes:duration>25:46</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 005 &#8211; An Interview with Ed Felten</title>
		<link>http://www.cigital.com/silverbullet/show-005/</link>
		<comments>http://www.cigital.com/silverbullet/show-005/#comments</comments>
		<pubDate>Mon, 28 Aug 2006 18:05:36 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-005/</guid>
		<description><![CDATA[
The fifth edition of the Silver Bullet Security Podcast features Ed Felten, Professor of Computer Science and Public Affairs at Princeton University and the Director of the Center for Information Technology Policy.  Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ed Felten" title="Ed Felten" src="http://www.cigital.com/silverbullet/efelten-125.jpg" /></p>
<p style="margin-top: 5px">The fifth edition of the Silver Bullet Security Podcast features <a href="http://www.cs.princeton.edu/~felten">Ed Felten</a>, Professor of Computer Science and Public Affairs at Princeton University and the Director of the <a href="http://itpolicy.princeton.edu/">Center for Information Technology Policy</a>.  Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship with his former adversaries.  They also talk about how to discuss difficult technology issues with lawmakers and the importance of public policy and the law to computer scientists.  Ed also outlines the challenges of raising a bright 11-year-old.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-005-efelten.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://www.freedom-to-tinker.com/">Freedom to Tinker</a> &#8211; Ed Felten&#8217;s blog</li>
<li><a href="http://www.freedom-to-tinker.com/?p=953">Ed&#8217;s Predictions for 2006</a></li>
<li><a href="http://en.wikipedia.org/wiki/Series_of_tubes">Wikipedia: Series of Tubes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-005/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/8/0/silverbullet-005.mp3" length="22001674" type="audio/mpeg"/>
<itunes:duration>22:55</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 004 &#8211; An Interview with Dana Epp</title>
		<link>http://www.cigital.com/silverbullet/show-004/</link>
		<comments>http://www.cigital.com/silverbullet/show-004/#comments</comments>
		<pubDate>Mon, 31 Jul 2006 21:30:23 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-004/</guid>
		<description><![CDATA[
In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of Scorpion Software.  Dana also runs a popular software security blog and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (&#8220;code lives forever&#8221;), the security implications of systems [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dana Epp" title="Dana Epp" src="http://www.cigital.com/silverbullet/depp-125.jpg" /></p>
<p style="margin-top: 5px">In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of <a href="http://www.scorpionsoft.com/">Scorpion Software</a>.  Dana also runs a popular <a href="http://silverstr.ufies.org/blog/">software security blog</a> and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (&#8220;code lives forever&#8221;), the security implications of systems with ever-increasing complexity, suggestions for new developers interested in learning about software security, regulation&#8217;s role in information security, and Miles Davis.</p>
<ul>
<li><a href="http://silverstr.ufies.org/blog/">SilverStr&#8217;s blog</a> &#8211; Dana&#8217;s blog</li>
<li><a href="http://snltranscripts.jt.org/90/90tpat.phtml">It&#8217;s Pat!</a></li>
<li><a href="http://www.rapro.com/">RemoteAccess BBS</a></li>
<li><a href="http://silverstr.ufies.org/blog/archives/000926.html">The 5 Rules of the Regulatory Process</a></li>
<li><a href="http://www.chrisbotti.com/">Chris Botti</a></li>
<li><a href="http://www.securecoding.org/list/">SC-L List</a></li>
<li><a href="http://www.miles-davis.com/brew.html"><em>Bitches Brew</em></a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-004/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/6/0/silverbullet-004.mp3" length="23488522" type="audio/mpeg"/>
<itunes:duration>24:28</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 003 &#8211; An Interview with Marcus Ranum</title>
		<link>http://www.cigital.com/silverbullet/show-003/</link>
		<comments>http://www.cigital.com/silverbullet/show-003/#comments</comments>
		<pubDate>Fri, 14 Jul 2006 19:10:27 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-003/</guid>
		<description><![CDATA[
In the third episode of the Silver Bullet Security Podcast, Gary talks with Marcus Ranum, who is an acclaimed security guru widely credited with inventing the proxy firewall. Marcus and Gary discuss why Marcus thinks we&#8217;re not making progress in the computer security field, how common sense would help computer security, Richard Feynman, and power [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Marcus J. Ranum" title="Marcus J. Ranum" src="http://www.cigital.com/silverbullet/mranum-125.jpg" /></p>
<p style="margin-top: 5px">In the third episode of the Silver Bullet Security Podcast, Gary talks with Marcus Ranum, who is an acclaimed security guru widely credited with inventing the proxy firewall. Marcus and Gary discuss why Marcus thinks we&#8217;re not making progress in the computer security field, how common sense would help computer security, Richard Feynman, and power tools for home repair and improvement.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-003-mranum.pdf">A partial transcript of the interview in <em>IEEE Security &#038; Privacy</em></a></li>
<li><a href="http://www.ranum.com/">Ranum.com</a></li>
<li><a href="http://www.ranum.com/security/computer_security/audio/mjr-blackhat-97.mp3">BlackHat Keynote &#8216;97</a> (MP3)</li>
<li><a href="http://www.ranum.com/security/computer_security/editorials/dumb/index.html">The Six Dumbest Ideas in Computer Security</a></li>
<li><a href="http://www.oldwestsnakeoil.com/">Old West Snake Oil</a></li>
<li><a href="http://www.networkworld.com/news/2005/011005widernetpatchtuesday.html">Patch Tuesday</a></li>
<li><a href="http://en.wikipedia.org/wiki/Richard_Feynman">Richard Feynman</a></li>
<li><a href="http://www.toolbarn.com/cgi-bin/bigimage.cgi/DW969K-2/">DeWalt cordless screwdriver</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-003/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<!-- Media File exists for this post, but its not enabled for this feed -->
	</item>
		<item>
		<title>Show 002 &#8211; An Interview with Dan Geer</title>
		<link>http://www.cigital.com/silverbullet/show-002/</link>
		<comments>http://www.cigital.com/silverbullet/show-002/#comments</comments>
		<pubDate>Mon, 12 Jun 2006 17:28:07 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-002/</guid>
		<description><![CDATA[
In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at Verdasys. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan&#8217;s paper Cyber Insecurity, his work on Project Athena, [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dan Geer" title="Dan Geer" src="http://www.cigital.com/silverbullet/dgeer-125.jpg" /></p>
<p style="margin-top: 5px">In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at <a href="http://www.verdasys.com/">Verdasys</a>. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan&#8217;s paper Cyber Insecurity, his work on Project Athena, and livestock.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-002-dgeer.pdf">A partial transcript of the interview in <em>IEEE Security &#038; Privacy</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Dan_Geer">Dan Geer on Wikipedia</a></li>
<li><a href="http://www.ccianet.org/papers/cyberinsecurity.pdf">Cyber Insecurity: The Cost of Monopoly</a> (PDF)</li>
<li><a href="http://en.wikipedia.org/wiki/Project_Athena">Project Athena on Wikipedia</a></li>
<li><a href="http://www2.sims.berkeley.edu/research/projects/how-much-info-2003/">How Much Information 2003</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &#038; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-002/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/3/0/silverbullet-002.mp3" length="21510154" type="audio/mpeg"/>
<itunes:duration>22:24</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
		<item>
		<title>Show 001 &#8211; An Interview with Avi Rubin</title>
		<link>http://www.cigital.com/silverbullet/show-001/</link>
		<comments>http://www.cigital.com/silverbullet/show-001/#comments</comments>
		<pubDate>Wed, 19 Apr 2006 17:47:13 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
				<category><![CDATA[Shows]]></category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-001/</guid>
		<description><![CDATA[
In the debut episode of the Silver Bullet Security Podcast, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines.
Links:

A partial transcript of the interview in IEEE Security [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.cigital.com/silverbullet/arubin-125.jpg" alt="Avi Rubin" title="Avi Rubin" align="right" /></p>
<p style="margin-top: 5px">In the debut episode of the <em>Silver Bullet Security Podcast</em>, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines.</p>
<p>Links:</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-001-arubin.pdf">A partial transcript of the interview in <em>IEEE Security &#038; Privacy</em></a></li>
<li><a href="http://www.avirubin.com/">Avi&#8217;s site</a></li>
<li><a href="http://www.bravenewballot.org/"><em>Brave New Ballot: The Battle to Safeguard Democracy in the Age of Electronic Voting</em></a>, Avi&#8217;s forthcoming book</li>
<li><a href="http://accurate-voting.org/">ACCURATE</a> &#8211; A Center for Correct, Usable, Reliable, Auditable, and Transparent Elections</li>
<li><a href="http://www.frootloops.com/">Froot Loops</a> and <a href="http://en.wikipedia.org/wiki/Corn_flakes">Corn Flakes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &#038; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-001/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<enclosure url="http://www.cigital.com/silverbullet/podpress_trac/feed/7/0/silverbullet-001.mp3" length="19243018" type="audio/mpeg"/>
<itunes:duration>20:03</itunes:duration>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:subtitle></itunes:subtitle>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:summary></itunes:summary>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:keywords></itunes:keywords>
<br />
<b>Warning</b>:  htmlentities() expects at most 3 parameters, 4 given in <b>/srv/www/cigital.com/silverbullet/wp-content/plugins/podpress/podpress_feed_functions.php</b> on line <b>31</b><br />
		<itunes:author></itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>No</itunes:block>
	</item>
	</channel>
</rss>
