<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.11" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>The Silver Bullet Security Podcast</title>
	<link>http://www.cigital.com/silverbullet</link>
	<description>In-depth conversations with leading security gurus, hosted by Gary McGraw, sponsored by IEEE Security &#038; Privacy Magazine.</description>
	<pubDate>Fri, 18 Apr 2008 21:18:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.11</generator>
	<language>en</language>
			<item>
		<title>Show 025 - An Interview with Jon Swartz</title>
		<link>http://www.cigital.com/silverbullet/show-025/</link>
		<comments>http://www.cigital.com/silverbullet/show-025/#comments</comments>
		<pubDate>Fri, 18 Apr 2008 20:58:21 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-025-an-interview-with-jon-swartz/</guid>
		<description><![CDATA[
Jon Swartz, USA Today&#8217;s award-winning technology reporter and Pulitzer Prize nominee, is Gary&#8217;s guest on the 25th episode of The Silver Bullet Security Podcast.  They discuss Jon&#8217;s new book, Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity and the research that went [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Jon Swartz" title="Jon Swartz" src="http://www.cigital.com/silverbullet/jswartz-125.gif" style="padding-left: 7px;" /></p>
<p>Jon Swartz, <em>USA Today</em>&#8217;s award-winning technology reporter and Pulitzer Prize nominee, is Gary&#8217;s guest on the 25th episode of <em>The Silver Bullet Security Podcast</em>.  They discuss Jon&#8217;s new book, <em>Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity</em> and the research that went into writing it.  Gary and Jon also cover how cybercrime is driven by capitalist principals, why the general public&#8217;s attitude is so lax about software security, and how, even though it&#8217;s hard to get an accurate count of identity theft instances, they tend to show a sharp upward trend.  Jon ends the episode by disclosing his secret dream career.</p>
<p>(Apologies for the below-average sound quality on this episode.)</p>
<ul>
<li><a href="http://zerodaythreat.com/"><em>Zero Day Threat</em></a></li>
<li><a href="http://www.usatoday.com/community/tags/reporter.aspx?id=321">Jon&#8217;s <em>USA Today</em> articles</a></li>
<li>Three recent articles:</li>
<ul>
<li><a href="http://www.usatoday.com/community/utils/idmap/31439036.story">Microsoft still seen with a win</a></li>
<li><a href="http://www.usatoday.com/community/utils/idmap/31438848.story">Online crime&#8217;s impact spreads</a></li>
<li><a href="http://www.usatoday.com/community/utils/idmap/31429572.story">AOL, News Corp. join battle over Yahoo</a></li>
</ul>
<li><a href="http://www.youtube.com/watch?v=-5zxOLZ5jXM"><em>The New Face of Cybercrime</em> trailer</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-025/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 024 - An Interview with Mary Ann Davidson</title>
		<link>http://www.cigital.com/silverbullet/show-024/</link>
		<comments>http://www.cigital.com/silverbullet/show-024/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 18:26:36 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-024/</guid>
		<description><![CDATA[
Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Mary Ann Davidson" title="Mary Ann Davidson" src="http://www.cigital.com/silverbullet/madavidson-125.gif" /></p>
<p>Oracle Chief Security Officer Mary Ann Davidson is the guest on the 24th episode of The Silver Bullet Security Podcast.  Gary and Mary Ann discuss how an MBA helps in the CSO role, Oracle&#8217;s &#8220;Unbreakable&#8221; campaign, why everyone needs training in secure coding, and how military history informs computer security.  They also talk about how a young CSO-to-be got her first library card.</p>
<ul>
<li><a href="http://blogs.oracle.com/maryanndavidson/">Mary Ann Davidson&#8217;s blog</a></li>
<li><a href="http://wiki.oracle.com/page/Unbreakable+Linux">Unbreakable Linux</a></li>
<li><a href="http://www.amazon.com/Lone-Survivor-Eyewitness-Account-Operation/dp/0316067598"><em>Lone Survivor</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-024/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 023 - An Interview with Chris Wysopal</title>
		<link>http://www.cigital.com/silverbullet/show-023/</link>
		<comments>http://www.cigital.com/silverbullet/show-023/#comments</comments>
		<pubDate>Tue, 19 Feb 2008 16:41:13 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-023/</guid>
		<description><![CDATA[
On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of The Art of Software Security Testing.  Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Chris Wysopal" title="Chris Wysopal" src="http://www.cigital.com/silverbullet/cwysopal-125.gif" /></p>
<p>On the 23rd episode of The Silver Bullet Security Podcast, Gary talks with Chris Wysopal, founder and CTO of Veracode and author of <em>The Art of Software Security Testing</em>.  Chris was one of the seven original members of the L0pht hacker collective (operating under the hacker handle Weld Pond) and later went on to work for @stake.  Gary and Chris reminisce about L0pht (and the warehouse full of stuff) and discuss the role of security researchers now versus in the mid-late &#8217;90s. They also talk about the current state of the software security market and its continued growth.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Weld_Pond">Chris&#8217; Wikipedia entry</a></li>
<li><a href="http://www.softwaresecuritytesting.com/"><em>The Art of Software Security Testing</em></a></li>
<li><a href="http://www.veracode.com/">Veracode</a></li>
<li><a href="http://www.veracode.com/blog/">Zero in a bit</a> - Veracode&#8217;s blog</li>
<li><a href="http://en.wikipedia.org/wiki/L0pht">L0pht Heavy Industries</a></li>
<li><a href="http://www.vulnwatch.org/">Vulnwatch</a></li>
<li><a href="http://www.sourceboston.com/">SOURCE: Boston 2008</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-023/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 022 - An Interview with Ed Amoroso</title>
		<link>http://www.cigital.com/silverbullet/show-022/</link>
		<comments>http://www.cigital.com/silverbullet/show-022/#comments</comments>
		<pubDate>Wed, 23 Jan 2008 21:33:09 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-022/</guid>
		<description><![CDATA[
On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&#038;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ed Amaroso" title="Ed Amoroso" src="http://www.cigital.com/silverbullet/eamoroso-125.gif" /></p>
<p style="margin-top: 5px">On the 22nd episode of The Silver Bullet Security Podcast, Gary interviews Ed Amoroso, Chief Information Security Officer of AT&#038;T. They discuss how Peter Neumann influenced Ed, the difference between bugs and flaws and whether bugs are getting too much attention, the propensity for confusion around how security actually works, privacy, security, and monitoring, and software correctness/quality vs software security.  They also discuss the Hugh Thompson show now airing on AT&#038;T&#8217;s Tech Channel.</p>
<ul>
<li><a href="http://www.silicon-press.com/books/isbn.0-929306-38-4/index.html"><em>Cyber Security</em></a></li>
<li><a href="http://www.amazon.com/Fundamentals-Computer-Security-Technology-Amoroso/dp/0131089293"><em>Fundamentals of Computer Security Technology</em></a></li>
<li><a href="http://www.cigital.com/silverbullet/show-014/">Silver Bullet Interview with Peter Neumann</a></li>
<li><a href="http://www.att.com/techchannel/">AT&#038;T&#8217;s Tech Channel</a></li>
<li><a href="http://techchannel.att.com/site/home/index.cfm?key=7fb7b3944a89e2e9178bb2ce6d83e9d8">Gary on <em>The Hugh Thompson Show</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-022/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 021 - A Panel Discussion with Cigital&#8217;s Principals</title>
		<link>http://www.cigital.com/silverbullet/show-021/</link>
		<comments>http://www.cigital.com/silverbullet/show-021/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 20:40:32 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-021/</guid>
		<description><![CDATA[
For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Cigital Logo" title="Cigital Logo" src="http://www.cigital.com/silverbullet/cigital-125.gif" /></p>
<p style="margin-top: 5px">For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and the similarities between CLASP, Microsoft&#8217;s SDL, and the Security Touchpoints.  They also ponder how much the security testing burden should fall on QA and whether developing expertise in architectural risk analysis or threat modeling is more helpful.  John Steven also discusses the hole in his dining room, which threat modeling would not have helped to prevent.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-021-cigital.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cigital.com/justiceleague/">Justice League blog</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/11/13/threat-modeling/">Threat Modeling</a> - a blog entry by John Steven</li>
<li><a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top 10 for 2007</a></li>
<li><a href="http://www.owasp.org/">OWASP</a></li>
<li><a href="http://www.shmoo.com/">The Shmoo Group</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-021/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Happy Holidays from Silver Bullet</title>
		<link>http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/</link>
		<comments>http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 17:07:55 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Site news</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/</guid>
		<description><![CDATA[

Get the Flash Player to see this player.

var s0 = new SWFObject("http://www.cigital.com/silverbullet/wp-content/plugins/flash-video-player/flvplayer.swf","n0","320","240","7");
s0.addParam("allowfullscreen","true");
s0.addParam("allowscriptaccess","always");
s0.addVariable("javascriptid","n0");
s0.addVariable("width","320");
s0.addVariable("height","240");
s0.addVariable("autoscroll","true");
s0.addVariable("largecontrols","false");
s0.addVariable("logo","http://www.cigital.com/silverbullet");
s0.addVariable("overstretch","true");
s0.addVariable("showdigits","true");
s0.addVariable("showdownload","false");
s0.addVariable("showeq","false");
s0.addVariable("showicons","true");
s0.addVariable("showvolume","true");
s0.addVariable("thumbsinplaylist","false");
s0.addVariable("autostart","false");
s0.addVariable("bufferlength","3");
s0.addVariable("repeat","false");
s0.addVariable("rotatetime","5");
s0.addVariable("smoothing","true");
s0.addVariable("volume","80");
s0.addVariable("enablejs","true");
s0.addVariable("linkfromdisplay","false");
s0.addVariable("t","autodetect");
s0.addVariable("useaudio","false");
s0.addVariable("usecaptions","false");
s0.addVariable("usefullscreen","true");
s0.addVariable("usekeys","false");
s0.addVariable("file","http://www.cigital.com/silverbullet/videos/silverbulletmerryxmas.flv");
s0.write("video0");


]]></description>
			<content:encoded><![CDATA[<p align="center">
<span id="video1" class="flashvideo">
<a href="http://www.macromedia.com/go/getflashplayer">Get the Flash Player</a> to see this player.</span>
<script type="text/javascript">
var s1 = new SWFObject("http://www.cigital.com/silverbullet/wp-content/plugins/flash-video-player/flvplayer.swf","n1","320","240","7");
s1.addParam("allowfullscreen","true");
s1.addParam("allowscriptaccess","always");
s1.addVariable("javascriptid","n1");
s1.addVariable("width","320");
s1.addVariable("height","240");
s1.addVariable("autoscroll","true");
s1.addVariable("largecontrols","false");
s1.addVariable("logo","http://www.cigital.com/silverbullet");
s1.addVariable("overstretch","true");
s1.addVariable("showdigits","true");
s1.addVariable("showdownload","false");
s1.addVariable("showeq","false");
s1.addVariable("showicons","true");
s1.addVariable("showvolume","true");
s1.addVariable("thumbsinplaylist","false");
s1.addVariable("autostart","false");
s1.addVariable("bufferlength","3");
s1.addVariable("repeat","false");
s1.addVariable("rotatetime","5");
s1.addVariable("smoothing","true");
s1.addVariable("volume","80");
s1.addVariable("enablejs","true");
s1.addVariable("linkfromdisplay","false");
s1.addVariable("t","autodetect");
s1.addVariable("useaudio","false");
s1.addVariable("usecaptions","false");
s1.addVariable("usefullscreen","true");
s1.addVariable("usekeys","false");
s1.addVariable("file","http://www.cigital.com/silverbullet/videos/silverbulletmerryxmas.flv");
s1.write("video1");
</script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/happy-holidays-from-silver-bullet/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 020 - An Interview with Markus Jakobsson</title>
		<link>http://www.cigital.com/silverbullet/show-020/</link>
		<comments>http://www.cigital.com/silverbullet/show-020/#comments</comments>
		<pubDate>Fri, 16 Nov 2007 22:32:45 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-020/</guid>
		<description><![CDATA[
For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University.  Gary and Markus discuss the difference between academic and corporate [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Markus Jakobsson" title="Markus Jakobsson" src="http://www.cigital.com/silverbullet/mjakobsson-125.gif" /></p>
<p style="margin-top: 5px">For the landmark 20th episode of The Silver Bullet Security Podcast, Gary interviews Markus Jakobsson, soon to be a reseacher at PARC after a stint as an Associate Professor of Informatics and associate director of the Center for Applied Cybersecurity Research at Indiana University.  Gary and Markus discuss the difference between academic and corporate research, the idea of &#8220;perfect privacy,&#8221; moving from hardcore cryptography to sociology, how reality is mimicking phishers, and how cartoons can be used to teach security.  In addition, Markus mentions the best place in Southeast Asia to get a haircut.</p>
<ul>
<li><a href="http://www.informatics.indiana.edu/markus/">Markus @ Indiana</a></li>
<li><a href="http://en.wikipedia.org/wiki/Markus_Jakobsson">Markus @ Wikipedia</a> - he&#8217;s &#8220;orphaned&#8221;!</li>
<li><a href="http://www.ravenwhite.com/">RavenWhite</a></li>
<li><a href="http://www.securitycartoon.com/">SecurityCartoon.com</a></li>
<li><a href="http://www.amazon.com/Crimeware-Symantec-Press-Markus-Jakobsson/dp/0321501950"><em>Crimeware</em><a></li>
<li><a href="http://phishing-and-countermeasures.com/"><em>Phishing and Countermeasures</em></a></li>
<li><a href="http://www.informatics.indiana.edu/markus/documents/security-education.pdf">Using Cartoons to Teach Internet Security</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-020/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 019 - An Interview with Mikko Hyppönen</title>
		<link>http://www.cigital.com/silverbullet/show-019/</link>
		<comments>http://www.cigital.com/silverbullet/show-019/#comments</comments>
		<pubDate>Thu, 18 Oct 2007 15:21:38 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-019/</guid>
		<description><![CDATA[
For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Mikko Hyppönen" title="Mikko Hyppönen" src="http://www.cigital.com/silverbullet/mikko-125.gif" /></p>
<p style="margin-top: 5px">For the 19th episode of The Silver Bullet Security Podcast, Gary interviews Mikko Hyppönen, Chief Research Officer at F-Secure. During this show, Gary and Mikko discuss Helsinki and Finnish pronunciation, whether mobile viruses are all hype or a legitimate threat, if the iPhone as a closed system is good or bad for security, and Mikko&#8217;s prediction for the appearance of the first mobile botnet.  They also chat about Finnish hip-hop.</p>
<ul>
<li><a href="http://mikko.hypponen.com/">Mikko Hyppönen</a></li>
<li><a href="http://en.wikipedia.org/wiki/Mikko_Hyppönen">Mikko Hyppönen</a>- Wikipedia</li>
<li><a href="http://www.f-secure.com/">F-Secure</a></li>
<li><a href="http://www.usenix.org/events/sec07/tech/#thurs">Mobile Malware</a> - Mikko&#8217;s USENIX 2007 talk, both audio and video (scroll down a bit)</li>
<li><a href="http://www.klov.com/game_detail.php?game_id=10505">Xevious</a></li>
<li><a href="http://www.management-consoles.com/">The FSMCs</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-019/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 018 - An Interview with Eugene Spafford</title>
		<link>http://www.cigital.com/silverbullet/show-018/</link>
		<comments>http://www.cigital.com/silverbullet/show-018/#comments</comments>
		<pubDate>Tue, 25 Sep 2007 21:04:22 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-018/</guid>
		<description><![CDATA[
On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as &#8220;Spaf.&#8221;  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS).  On this [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Eugene Spafford" title="Eugene Spafford" src="http://www.cigital.com/silverbullet/spaf-125.gif" /></p>
<p style="margin-top: 5px">On the 18th episode of The Silver Bullet Security Podcast, Gary talks with Dr. Eugene Spafford, better known as &#8220;Spaf.&#8221;  Spaf is a professor of computer science and Electrical and Computer Engineering at Purdue University and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS).  On this episode, Gary and Spaf discuss the role of software testing in computer security, commercial certifications and whether they obviate the need for academic training, how Spaf feels about so-called &#8220;ethical hacking,&#8221; and why auditing and compliance is an area of emerging specialization.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-018-spaf.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://spaf.cerias.purdue.edu/">Dr. Eugene Spafford</a></li>
<li><a href="http://www.cerias.purdue.edu/weblogs/author/spaf/">Spaf&#8217;s blog at CERIAS</a></li>
<li><a href="http://en.wikipedia.org/wiki/Gene_Spafford">Gene Spafford</a> - Wikipedia</li>
<li><a href="http://www.cerias.purdue.edu/">CERIAS</a> - Center for Education and Research in Information Assurance and Security</li>
<li><a href="http://www.ise.gmu.edu/~ofut/rsrch/mut.html">Mothra</a> - Mutation testing</li>
<li><a href="http://www.nitrd.gov/pitac/">PITAC</a> - President&#8217;s Information Technology  Advisory Committee</li>
<li><a href="http://www.cerias.purdue.edu/weblogs/spaf/kudos-opinions-rants/post-120/what-did-you-really-expect/">What did you really expect?</a> - Spaf&#8217;s post on &#8220;reformed hackers&#8221;</li>
<li><a href="http://wiretap.area.com/Gopher/Library/Techdoc/Virus/inetvir.823">The Internet Worm Program: An Analysis</a></li>
<li><a href="http://spaf.cerias.purdue.edu/~spaf/Yucks/">Yucks Digest</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-018/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 017 - An Interview with Eric Cole</title>
		<link>http://www.cigital.com/silverbullet/show-017/</link>
		<comments>http://www.cigital.com/silverbullet/show-017/#comments</comments>
		<pubDate>Fri, 24 Aug 2007 20:19:43 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-017/</guid>
		<description><![CDATA[
On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Eric Cole" title="Eric Cole" src="http://www.cigital.com/silverbullet/ecole-125.gif" /></p>
<p style="margin-top: 5px">On the 17th episode of The Silver Bullet Security Podcast, Gary talks with Eric Cole, CEO of Secure Anchor.  Eric has written seven books on computer security, including books on steganography and network security.  Gary and Eric discuss how to demostrate security ROI in different types of organizations (ranging from government to corporate), the academic approach to security versus practitioner certification models, and what kinds of training makes for good network security practitioners.  They also discuss the difficulty of certifying software developers.</p>
<ul>
<li><a href="http://www.secure-anchor.com/">Secure Anchor</a></li>
<li><a href="http://www.securityhaven.com/">Security Haven</a></li>
<li><a href="http://digitalcommons.pace.edu/dissertations/AAI3127379/">Stego-marking packets to control information leakage on TCP/IP based networks</a> - Eric&#8217;s dissertation</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-017/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 016 - An Interview with Greg Hoglund</title>
		<link>http://www.cigital.com/silverbullet/show-016/</link>
		<comments>http://www.cigital.com/silverbullet/show-016/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 22:38:30 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-016/</guid>
		<description><![CDATA[
On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of Rootkits: Subverting the Windows Kernel and Exploiting Software.  In addition to shameless self-promotion of their new book, Exploiting Online Games, Gary and Greg discuss the natural tendency [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Greg Hoglund" title="Greg Hoglund" src="http://www.cigital.com/silverbullet/ghoglund-125.gif" /></p>
<p style="margin-top: 5px">On the 16th episode of The Silver Bullet Security Podcast, Gary talks with Greg Hoglund, who runs the popular rootkit.com, CEO of HB Gary, and co-author of <em>Rootkits: Subverting the Windows Kernel</em> and <em>Exploiting Software</em>.  In addition to shameless self-promotion of their new book, <em>Exploiting Online Games</em>, Gary and Greg discuss the natural tendency of certain types of code to allow exploits, how disclosure is a good thing when it comes to revealing exploits, and the use of rootkits by the &#8220;good guys.&#8221;  Greg also makes us concerned that his 11-year-old daughter may 0wn our box.</p>
<ul>
<li><a href="http://www.rootkit.com/">Rootkit.com</a></li>
<li><a href="http://www.hbgary.com/">HB Gary</a></li>
<li>Greg&#8217;s Blackhat presentation from 2006: <a href="http://www.rootkit.com/vault/hoglund/GregSlidesWoWHack.rar">Hacking World of Warcraft(r): An Exercise in Advanced Rootkit Design</a> [rar, 2.35M]</li>
<li><a href="http://www.exploitingonlinegames.com/">Exploiting Online Games</a></li>
<li><a href="http://www.buildingsecurityin.com/">AWL Software Security Series</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-016/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 015 - An Interview with Annie Antón</title>
		<link>http://www.cigital.com/silverbullet/show-015/</link>
		<comments>http://www.cigital.com/silverbullet/show-015/#comments</comments>
		<pubDate>Tue, 19 Jun 2007 14:12:30 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-015/</guid>
		<description><![CDATA[
On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary focus on privacy.  They start with an attempt to define what &#8220;privacy&#8221; is in the digital world,  [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Annie Anton" title="Annie Anton" src="http://www.cigital.com/silverbullet/aanton-125.gif" /></p>
<p style="margin-top: 5px">On the 15th episode of The Silver Bullet Security Podcast, Gary interviews Annie Antón, Associate Professor of Software Engineering at North Carolina State University and director of theprivacyplace.org.   During their discussion, Annie and Gary focus on privacy.  They start with an attempt to define what &#8220;privacy&#8221; is in the digital world,  moving on to Annie&#8217;s work with The Privacy Place.  Annie also discusses airlines&#8217; pretty much pitiful privacy policies, the impact that a Google/Doubleclick deal would have on consumer privacy, crazy talk in EULAs, and the book <em>Letters to a Young Catholic</em> (which has nothing to do with privacy).</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-015-aanton.pdf">A partial transcript of the interview in IEEE Security &#038; Privacy</a></li>
<li><a href="http://www4.ncsu.edu/~aianton/">Annie I. Antón</a></li>
<li><a href="http://www.theprivacyplace.org/">The Privacy Place</a></li>
<li><a href="http://www.privacyrights.org/ar/CPResponse.htm">The ChoicePoint Data Security Breach</a></li>
<li><a href="http://www.eppc.org/publications/bookID.50/book_detail.asp"><em>Letters to a Young Catholic</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-015/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 014 - An Interview with Peter Neumann</title>
		<link>http://www.cigital.com/silverbullet/show-014/</link>
		<comments>http://www.cigital.com/silverbullet/show-014/#comments</comments>
		<pubDate>Tue, 22 May 2007 17:04:03 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-014/</guid>
		<description><![CDATA[
The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Peter Neumann" title="Peter Neumann" src="http://www.cigital.com/silverbullet/pneumann-125.gif" /></p>
<p style="margin-top: 5px">The 14th episode of The Silver Bullet Security Podcast features Peter Neumann, designer of the Multics OS file system, moderator of comp.RISKS, and Principal Scientist at the SRI Computer Science Laboratory.  In this show, Gary and Peter discuss the most important changes in computer security since the 1960s, the discipline involved in early Multics engineering (&#8221;nodody writes a line of code without the approving authorities [having] read and understood the specification&#8221;), why DRM is the &#8220;wrong solution to the wrong problem,&#8221; and who was more interesting to meet: Albert Einstein or Norah Jones.</p>
<ul>
<li><a href="http://www.csl.sri.com/users/neumann/">Peter Neumann</a></li>
<li><a href="http://catless.ncl.ac.uk/risks">comp.RISKS</a></li>
<li><a href="http://www.csl.sri.com/users/neumann/neumann-book.html"><em>Computer-Related Risks</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Multics">Multics</a></li>
<li><a href="http://www.multicians.org/fjcc4.html">A General-Purpose File System For Secondary Storage</a> - Peter&#8217;s 1965 paper on Multics</li>
<li><a href="http://www.multicians.org/">Multics History Project</a></li>
<li><a href="http://www.luntzel.com/bbb/">The Brooklyn Boogaloo Blowout</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-014/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 013 - An Interview with Ross Anderson</title>
		<link>http://www.cigital.com/silverbullet/show-013/</link>
		<comments>http://www.cigital.com/silverbullet/show-013/#comments</comments>
		<pubDate>Fri, 13 Apr 2007 20:33:21 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-013/</guid>
		<description><![CDATA[
On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book Security Engineering.   Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ross Anderson" title="Ross Anderson" src="http://www.cigital.com/silverbullet/randerson-125.gif" /></p>
<p style="margin-top: 5px">On the 13th episode of The Silver Bullet Security Podcast, Gary chats with Ross Anderson, Professor of Security Engineering at the Computer Laboratory at Cambridge University and author of the book <em>Security Engineering</em>.   Gary and Ross discuss the effect of posting his excellent book on the net for free, the simple reasons why most systems fail, the economic imbalance between engineers/developers and a system&#8217;s users (with respect to who should address security), and why publicly describing attacks is essential to security engineering.  They close out by examining the security implications of wearing a kilt.</p>
<ul>
<li><a href="http://www.ross-anderson.com/">Ross Anderson</a></li>
<li><a href="http://www.lightbluetouchpaper.org/">Light Blue Touchpaper</a> - A security blog by Cambridge computer scientists.</li>
<li><em>Security Engineering</em> - Ross&#8217; groundbreaking book <a href="http://www.amazon.com/exec/obidos/ASIN/0471389226/rossandersshomep">in print</a> and <a href="http://www.cl.cam.ac.uk/~rja14/book.html">online</a></li>
<li><a href="http://weis2007.econinfosec.org/">WEIS 2007 - Sixth Workshop on the Economics of Information Security</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/Papers/rfid-fc07.pdf">RFID and the Middleman</a> [PDF]</li>
<li><a href="http://showcase.netins.net/web/clanande/">The Clan Anderson Society</a></li>
<li><a href="http://www.cl.cam.ac.uk/~rja14/Presentations/busking.jpg">Ross playing the bagpipes</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-013/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 012 - An Interview with Becky Bace</title>
		<link>http://www.cigital.com/silverbullet/show-012/</link>
		<comments>http://www.cigital.com/silverbullet/show-012/#comments</comments>
		<pubDate>Tue, 13 Mar 2007 21:13:02 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-012/</guid>
		<description><![CDATA[
On the 12th episode of The Silver Bullet Security Podcast, Gary
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory.  Gary and Becky discuss growing up in [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Becky Bace" title="Becky Bace" src="http://www.cigital.com/silverbullet/bbace-125.gif" /></p>
<p style="margin-top: 5px">On the 12th episode of The Silver Bullet Security Podcast, Gary<br />
talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory.  Gary and Becky discuss growing up in rural America, explosives, and Becky&#8217;s Jimmy Hoffa sponsored college funding situation. They also talk about the evolution of security curricula in academia, rampant commercialization of computer security, Becky&#8217;s involvement in tracking down the notorious Kevin Mitnick, vicodin-induced creativity, and eclectic music.</p>
<ul>
<li><a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci927913,00.html">Who&#8217;s Who in Infosec: Rebecca Bace</a></li>
<li><a href="http://www.tridentcap.com/">Trident Capital</a> - The VC firm where Becky is an advisor</li>
<li><a href="http://www.thiemeworks.com/write/archives/beckyb2.htm">The IDS Den Mother</a> - a 2002 interview</li>
<li><a href="http://www.lanl.gov/">Los Alamos National Labs</a></li>
<li><a href="http://www.amazon.com/Intrusion-Detection-Rebecca-Gurley-Bace/dp/1578701856/ref=sr_1_1/104-2577668-4903944?ie=UTF8&#038;s=books&#038;qid=1173812537&#038;sr=8-1"><em>Intrusion Detection</em></a></li>
<li><a href="http://www.amazon.com/Guide-Forensic-Testimony-Presenting-Technical/dp/0201752794/ref=sr_1_2/104-2577668-4903944?ie=UTF8&#038;s=books&#038;qid=1173812537&#038;sr=8-2"><em>A Guide to Forensic Testimony: The Art and Practice of Presenting Testimony As An Expert Technical Witness</em></a> - Co-authored with Fred Smith</li>
<li><a href="http://www.infosecuritywomen.com/">Executive Women&#8217;s Forum</a></li>
<li><a href="http://www.franksinatra.com/">Frank Sinatra</a></li>
<li><a href="http://www.kinseysicks.com/">The Kinsey Sicks</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-012/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 011 - An Interview with Dorothy Denning</title>
		<link>http://www.cigital.com/silverbullet/show-011/</link>
		<comments>http://www.cigital.com/silverbullet/show-011/#comments</comments>
		<pubDate>Thu, 15 Feb 2007 22:07:35 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-011/</guid>
		<description><![CDATA[
On the 11th episode of The Silver Bullet Security Podcast, Gary talks with Dorothy Denning, a professor in the Department of Defense Analysis at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University.  Gary and Dorothy discuss Dorothy&#8217;s involvement in the Clipper Chip [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dorothy Denning" title="Dorothy Denning" src="http://www.cigital.com/silverbullet/ddenning-125.gif" /></p>
<p style="margin-top: 5px">On the 11th episode of The Silver Bullet Security Podcast, Gary talks with <a href="http://www.nps.navy.mil/ctiw/staff/denning.html">Dorothy Denning</a>, a professor in the <a href="http://www.nps.navy.mil/da/">Department of Defense Analysis</a> at the Naval Postgraduate School.  Previously, Dorothy was a distinguished professor at Georgetown University and a professor at Purdue University.  Gary and Dorothy discuss Dorothy&#8217;s involvement in the Clipper Chip controversy (which earned Dorothy the moniker &#8220;clipper chick&#8221;), the concept of geo-encryption, and a famous 1990 paper she wrote describing a series of interviews with malicious hackers.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Dorothy_E._Denning">Wikipedia: Dorothy Denning</a></li>
<li><a href="http://www.epic.org/crypto/clipper/">Clipper Chip</a> (<a href="http://en.wikipedia.org/wiki/Clipper_chip">More</a>)</li>
<li><a href="http://www.wired.com/wired/archive/4.09/denning_pr.html">Clipper Chick</a> - a 1996 <em>Wired</em> article about the Clipper Chip controversy.</li>
<li><a href="http://www.cosc.georgetown.edu/~denning/crypto/Future.html">The Future of Cryptography</a></li>
<li><a href="http://www.cs.georgetown.edu/~denning/infosec/Grounding.txt">Location-Based Authentication: Grounding Cyberspace for Better Security</a> - A 1996 paper by Dorothy Denning and Peter F. MacDoran about geo-encryption.</li>
<li><a href="http://www.sgrm.com/art-7.htm">Concerning Hackers Who Break into Computer Systems</a> - Dorothy&#8217;s 1990 paper.</li>
<li><a href="http://www.bsim.org">Big Sur Power Walk</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-011/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 010 - A Panel Discussion with Fortify Software&#8217;s Technical Advisory Board</title>
		<link>http://www.cigital.com/silverbullet/show-010/</link>
		<comments>http://www.cigital.com/silverbullet/show-010/#comments</comments>
		<pubDate>Mon, 22 Jan 2007 19:59:59 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-010/</guid>
		<description><![CDATA[
The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the Fortify Software Technical Advisory Board, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using [...]]]></description>
			<content:encoded><![CDATA[<p align="center"><img alt="Fortify TAB" src="http://www.cigital.com/silverbullet/fortify-tab.jpg" /></p>
<p style="margin-top: 5px">The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the <a href="http://www.fortifysoftware.com/company-partners/tab.jsp">Fortify Software Technical Advisory Board</a>, several of whom have been featured on previous episodes.  The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using static analysis tools, and software security pedagogy.</p>
<p>Participating members of the Technical Advisory Board include:</p>
<ul>
<li><a href="http://www.cs.umd.edu/~pugh/">Bill Pugh</a>, Professor at University of Maryland, static analysis for finding bugs</li>
<li>Li Gong, GM at Microsoft, MSN in China</li>
<li><a href="http://www.ranum.com/">Marcus Ranum</a>, CSO of Tenable Network Security, security products trainer</li>
<li><a href="http://avirubin.com/">Avi Rubin</a>, Professor at Johns Hopkins, electronic voting security</li>
<li><a href="http://www.cs.cornell.edu/fbs/">Fred Schneider</a>, Professor at Cornell, trustworthy computing</a>
<li><a href="http://www.eecs.harvard.edu/~greg/">Greg Morrisett</a>, Professor at Harvard, dependant type theory</li>
<li><a href="http://nob.cs.ucdavis.edu/~bishop/">Matt Bishop</a>, Professor at UC Davis, computer security</li>
<li><a href="http://www.cs.berkeley.edu/~daw/">Dave Wagner</a>, Professor at Berkeley, software security and electronic voting</li>
</ul>
<p>A complete transcript of this podcast will be available soon from Fortify at <a href="http://www.fortify.com/silverbullet">http://www.fortify.com/silverbullet</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-010/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 009 - An Interview with Bruce Schneier</title>
		<link>http://www.cigital.com/silverbullet/show-009/</link>
		<comments>http://www.cigital.com/silverbullet/show-009/#comments</comments>
		<pubDate>Thu, 14 Dec 2006 11:45:53 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-009/</guid>
		<description><![CDATA[
In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security.  He has written eight bestselling books, most recently Beyond Fear: Thinking Sensibly About Security in an Uncertain World and is the editor of [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Bruce Schneier" title="Bruce Schneier" src="http://www.cigital.com/silverbullet/bschneier-123.jpg" /></p>
<p style="margin-top: 5px">In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security.  He has written eight bestselling books, most recently <em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World</em> and is the editor of the massively popular Cryptogram mailing list.  In this episode, Gary and Bruce discuss the connection between physical security its technological component, the idea of risk management, the intersection of economics and security, and the ideas of &#8220;wholesale surveillance&#8221; and &#8220;security theater.&#8221;  They also discuss patch Tuesday, hack Wednesday, and Microsoft&#8217;s approach to software security.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Bruce_Schneier">Bruce&#8217;s Wikipedia entry</a></li>
<li><a href="http://www.amazon.com/s/104-2577668-4903944?ie=UTF8&#038;index=books&#038;rank=-relevance%2C%2Bavailability%2C-daterank&#038;field-author-exact=Schneier%2C%20Bruce">Bruce&#8217;s books</a></li>
<li><a href="http://pd.startribune.com/sp?aff=3&#038;keywords=schneier">Bruce&#8217;s recent restaurant reviews</a></li>
<li><a href="http://www.counterpane.com/">Counterpane</a></li>
<li><a href="http://crypto-gram.libsyn.com/">Crypto-Gram security podcast</a>
<li><a href="http://www.freedom-to-tinker.com/?p=1052">Property Rights Management</a> - Ed Felten&#8217;s discussion of PRM, mentioned on the show</li>
<li><a href="http://www.techdirt.com/articles/20051205/2345233.shtml">Copyright Mythbusters: Believe It or Not, Fair Use Exists</a> - a look at the &#8220;fair use doesn&#8217;t exist&#8221; argument</li>
<li><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/4806948.stm">BBC plans attacked for &#8216;TV tax&#8217;</a> (March 14, 2006)</li>
<li>Bruce&#8217;s suggestion for &#8220;cheap&#8221; wines: <a href="http://www.thewinedoctor.com/regionalguides/loire.shtml">Loire wines</a>, <a href="http://www.beyond.fr/wine/provencewines.html">Provence Wines</a>, <a href="http://www.rhonerangers.org/html/wines.html">Southern Rhone wines</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-009/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 008 - An Interview with Brian Chess</title>
		<link>http://www.cigital.com/silverbullet/show-008/</link>
		<comments>http://www.cigital.com/silverbullet/show-008/#comments</comments>
		<pubDate>Fri, 17 Nov 2006 16:35:55 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-008/</guid>
		<description><![CDATA[
In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary and Brian discuss what commercial developers and academics have to learn from each other, [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Brian Chess" title="Brian Chess" src="http://www.cigital.com/silverbullet/bchess-125.jpg" /></p>
<p style="margin-top: 5px">In the eighth episode of The Silver Bullet Podcast, Gary talks with Brian Chess, co-founder and chief scientist of Fortify Software.  Brian completed his computer science Ph.D. at UC Santa Cruz after several years in the commercial sector.  Gary and Brian discuss what commercial developers and academics have to learn from each other, what it&#8217;s like to work for a Kleiner-Perkins startup (KP is the VC firm behind familiar names like Google, Amazon, and Sun), and how mystifying it is that some developers are OK with XSS vulnerabilities in their web applications.</p>
<ul>
<li><a href="http://www.fortifysoftware.com/">Fortify Software</a></li>
<li><a href="http://extra.fortifysoftware.com/blog/">extra</a> - Fortify&#8217;s software security blog</a></li>
<li>Matt Bishop&#8217;s <a href="http://nob.cs.ucdavis.edu/book/book-aands/index.html"><em>Computer Security: Art and Science</em></a> (mentioned again!)</li>
<li><a href="http://www.kpcb.com/">Kleiner Perkins Caufield &amp; Byers</a></li>
<li><a href="http://www.cigital.com/ssw/">DIMACS Workshop on Software Security</a> with Brian Kernighan</li>
<li><a href="http://sctest.cse.ucsc.edu/chess/">Brian as a wee lad</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-008/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 007 - An Interview with John Stewart</title>
		<link>http://www.cigital.com/silverbullet/show-007/</link>
		<comments>http://www.cigital.com/silverbullet/show-007/#comments</comments>
		<pubDate>Wed, 25 Oct 2006 15:00:58 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-007/</guid>
		<description><![CDATA[
In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse).  John [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Michael Howard" title="John Stewart" src="http://www.cigital.com/silverbullet/jstewart-125.jpg" /></p>
<p style="margin-top: 5px">In the seventh episode of The Silver Bullet Podcast, Gary interviews Cisco Chief Security Officer John Stewart.  Gary and  John discuss what CSOs do all day, how John got started in computer security, and the infamous Morris Worm from 1988 (which John was deeply involved in while a student at Syracuse).  John and Gary also revisit Cisco-gate, talk about how John&#8217;s identity was stolen, and determine why John&#8217;s kids don&#8217;t have e-mail addresses.</p>
<ul>
<li><a href="http://newsroom.cisco.com/dlls/tln/exec_team/stewart/perspectives.html">Executive Perspective: John Stewart on Vulnerability Disclosure</a></li>
<li><a href="http://en.wikipedia.org/wiki/CSO">Wikipedia: CSO</a></li>
<li><a href="http://en.wikipedia.org/wiki/Digital_Island">Digital Island</a></li>
<li><a href="http://snowplow.org/tom/worm/worm.html">The What, Why, and How of the 1988 Internet Worm</a> - a look at the history of the Morris Worm</li>
<li><a href="http://www.wired.com/news/technology/0,1282,68435,00.html">Cisco-gate</a></li>
<li><a href="http://www.csoonline.com/read/030104/idtheft.html">Five Ways to Fight ID Theft</a> - John talks about finding himself a victim of identity theft; see also: <a href="http://shaunsaxon.com/yamahafz1.html">the motorcycle he was trying to buy when he found out</a></li>
<li><a href="http://www.mykey3000.com/cosmicteams/profiles/gljohn.htm">John Stewart</a>, but not the one Gary interviews (and not the one you&#8217;re thinking of)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-007/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Japanese translation of Marcus Ranum interview</title>
		<link>http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/</link>
		<comments>http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/#comments</comments>
		<pubDate>Wed, 11 Oct 2006 15:34:38 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Site news</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/</guid>
		<description><![CDATA[Fumio over at LapisNet has translated an excerpt of the Marcus Ranum interview.  You can read the Japanese translation here.
]]></description>
			<content:encoded><![CDATA[<p>Fumio over at <a href="http://www.lapisnet.co.jp/">LapisNet</a> has translated an excerpt of the <a href="http://www.cigital.com/silverbullet/show-003/">Marcus Ranum interview</a>.  You can read the <a href="http://www.lapisnet.co.jp/jp/info/securitypodcast03.html">Japanese translation here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/japanese-translation-of-marcus-ranum-interview/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 006 - An Interview with Michael Howard</title>
		<link>http://www.cigital.com/silverbullet/show-006/</link>
		<comments>http://www.cigital.com/silverbullet/show-006/#comments</comments>
		<pubDate>Thu, 28 Sep 2006 20:11:47 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-006/</guid>
		<description><![CDATA[
The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft&#8217;s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security.  Michael continues to play a key roll in [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Michael Howard" title="Michael Howard" src="http://www.cigital.com/silverbullet/mhoward-118.jpg" /></p>
<p style="margin-top: 5px">The sixth episode of the show features an interview with Michael Howard, the Senior Security Program Manager of Microsoft&#8217;s Security Technology Unit.  Michael has been at Microsoft since 1992 and discusses what it has been like watching the company come to grips with software security.  Michael continues to play a key roll in implementing the Trustworthy Computing Initiative at Microsoft.  Gary and Michael also discuss the security features of Windows Vista and Michael&#8217;s recommendations for the two most important best practices when developing secure software.  Listen for a startling revelation about Michael&#8217;s choice of a &#8220;desert island book.&#8221;</p>
<ul>
<li><a href="http://blogs.msdn.com/michael_howard/">Michael Howard&#8217;s blog</a></li>
<li><a href="http://www.microsoft.com/mspress/books/5957.asp"><em>Writing Secure Code</em></a> by Michael Howard</li>
<li><a href="http://en.wikipedia.org/wiki/Defense_in_depth">Wikipedia: Defense in Depth</a></li>
<li><a  href="http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnsecure/html/sdl.asp">Microsoft&#8217;s Trustworthy Computing Security Development Lifecycle</a></li>
<li><a href="http://nob.cs.ucdavis.edu/book/">Matt Bishop&#8217;s computer security books</a> - These would go with Michael to a desert island.</li>
<li><a href="http://en.wikipedia.org/wiki/Michael_Howard">Michael Howard</a> - but not the one Gary interviewed.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-006/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 005 - An Interview with Ed Felten</title>
		<link>http://www.cigital.com/silverbullet/show-005/</link>
		<comments>http://www.cigital.com/silverbullet/show-005/#comments</comments>
		<pubDate>Mon, 28 Aug 2006 18:05:36 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-005/</guid>
		<description><![CDATA[
The fifth edition of the Silver Bullet Security Podcast features Ed Felten, Professor of Computer Science and Public Affairs at Princeton University and the Director of the Center for Information Technology Policy.  Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Ed Felten" title="Ed Felten" src="http://www.cigital.com/silverbullet/efelten-125.jpg" /></p>
<p style="margin-top: 5px">The fifth edition of the Silver Bullet Security Podcast features <a href="http://www.cs.princeton.edu/~felten">Ed Felten</a>, Professor of Computer Science and Public Affairs at Princeton University and the Director of the <a href="http://itpolicy.princeton.edu/">Center for Information Technology Policy</a>.  Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship with his former adversaries.  They also talk about how to discuss difficult technology issues with lawmakers and the importance of public policy and the law to computer scientists.  Ed also outlines the challenges of raising a bright 11-year-old.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-005-efelten.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://www.freedom-to-tinker.com/">Freedom to Tinker</a> - Ed Felten&#8217;s blog</li>
<li><a href="http://www.freedom-to-tinker.com/?p=953">Ed&#8217;s Predictions for 2006</a></li>
<li><a href="http://en.wikipedia.org/wiki/Series_of_tubes">Wikipedia: Series of Tubes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-005/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 004 - An Interview with Dana Epp</title>
		<link>http://www.cigital.com/silverbullet/show-004/</link>
		<comments>http://www.cigital.com/silverbullet/show-004/#comments</comments>
		<pubDate>Mon, 31 Jul 2006 21:30:23 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-004/</guid>
		<description><![CDATA[
In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of Scorpion Software.  Dana also runs a popular software security blog and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (&#8221;code lives forever&#8221;), the security implications of systems [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dana Epp" title="Dana Epp" src="http://www.cigital.com/silverbullet/depp-125.jpg" /></p>
<p style="margin-top: 5px">In the fourth episode of the Silver Bullet Security Podcast, Gary&#8217;s guest is Dana Epp, CEO and founder of <a href="http://www.scorpionsoft.com/">Scorpion Software</a>.  Dana also runs a popular <a href="http://silverstr.ufies.org/blog/">software security blog</a> and is a jazz trumpeter.  On this show, Dana and Gary talk about past programming disasters (&#8221;code lives forever&#8221;), the security implications of systems with ever-increasing complexity, suggestions for new developers interested in learning about software security, regulation&#8217;s role in information security, and Miles Davis.</p>
<ul>
<li><a href="http://silverstr.ufies.org/blog/">SilverStr&#8217;s blog</a> - Dana&#8217;s blog</li>
<li><a href="http://snltranscripts.jt.org/90/90tpat.phtml">It&#8217;s Pat!</a></li>
<li><a href="http://www.rapro.com/">RemoteAccess BBS</a></li>
<li><a href="http://silverstr.ufies.org/blog/archives/000926.html">The 5 Rules of the Regulatory Process</a></li>
<li><a href="http://www.chrisbotti.com/">Chris Botti</a></li>
<li><a href="http://www.securecoding.org/list/">SC-L List</a></li>
<li><a href="http://www.miles-davis.com/brew.html"><em>Bitches Brew</em></a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-004/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 003 - An Interview with Marcus Ranum</title>
		<link>http://www.cigital.com/silverbullet/show-003/</link>
		<comments>http://www.cigital.com/silverbullet/show-003/#comments</comments>
		<pubDate>Fri, 14 Jul 2006 19:10:27 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-003/</guid>
		<description><![CDATA[
In the third episode of the Silver Bullet Security Podcast, Gary talks with Marcus Ranum, who is an acclaimed security guru widely credited with inventing the proxy firewall. Marcus and Gary discuss why Marcus thinks we&#8217;re not making progress in the computer security field, how common sense would help computer security, Richard Feynman, and power [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Marcus J. Ranum" title="Marcus J. Ranum" src="http://www.cigital.com/silverbullet/mranum-125.jpg" /></p>
<p style="margin-top: 5px">In the third episode of the Silver Bullet Security Podcast, Gary talks with Marcus Ranum, who is an acclaimed security guru widely credited with inventing the proxy firewall. Marcus and Gary discuss why Marcus thinks we&#8217;re not making progress in the computer security field, how common sense would help computer security, Richard Feynman, and power tools for home repair and improvement.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-003-mranum.pdf">A partial transcript of the interview in <em>IEEE Security &#038; Privacy</em></a></li>
<li><a href="http://www.ranum.com/">Ranum.com</a></li>
<li><a href="http://www.ranum.com/security/computer_security/audio/mjr-blackhat-97.mp3">BlackHat Keynote &#8216;97</a> (MP3)</li>
<li><a href="http://www.ranum.com/security/computer_security/editorials/dumb/index.html">The Six Dumbest Ideas in Computer Security</a></li>
<li><a href="http://www.oldwestsnakeoil.com/">Old West Snake Oil</a></li>
<li><a href="http://www.networkworld.com/news/2005/011005widernetpatchtuesday.html">Patch Tuesday</a></li>
<li><a href="http://en.wikipedia.org/wiki/Richard_Feynman">Richard Feynman</a></li>
<li><a href="http://www.toolbarn.com/cgi-bin/bigimage.cgi/DW969K-2/">DeWalt cordless screwdriver</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-003/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 002 - An Interview with Dan Geer</title>
		<link>http://www.cigital.com/silverbullet/show-002/</link>
		<comments>http://www.cigital.com/silverbullet/show-002/#comments</comments>
		<pubDate>Mon, 12 Jun 2006 17:28:07 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-002/</guid>
		<description><![CDATA[
In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at Verdasys. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan&#8217;s paper Cyber Insecurity, his work on Project Athena, [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="Dan Geer" title="Dan Geer" src="http://www.cigital.com/silverbullet/dgeer-125.jpg" /></p>
<p style="margin-top: 5px">In this episode of the Silver Bullet Security Podcast, Gary chats with Dan Geer, Chief Scientist at <a href="http://www.verdasys.com/">Verdasys</a>. Dan has a Ph.D. in biostatistics from Harvard. He and Gary discuss the need to understand both technology and business in order to be a good security practitioner, Dan&#8217;s paper Cyber Insecurity, his work on Project Athena, and livestock.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-002-dgeer.pdf">A partial transcript of the interview in <em>IEEE Security &#038; Privacy</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Dan_Geer">Dan Geer on Wikipedia</a></li>
<li><a href="http://www.ccianet.org/papers/cyberinsecurity.pdf">Cyber Insecurity: The Cost of Monopoly</a> (PDF)</li>
<li><a href="http://en.wikipedia.org/wiki/Project_Athena">Project Athena on Wikipedia</a></li>
<li><a href="http://www2.sims.berkeley.edu/research/projects/how-much-info-2003/">How Much Information 2003</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &#038; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-002/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Show 001 - An Interview with Avi Rubin</title>
		<link>http://www.cigital.com/silverbullet/show-001/</link>
		<comments>http://www.cigital.com/silverbullet/show-001/#comments</comments>
		<pubDate>Wed, 19 Apr 2006 17:47:13 +0000</pubDate>
		<dc:creator>rmacmich</dc:creator>
		
		<category>Shows</category>

		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-001/</guid>
		<description><![CDATA[
In the debut episode of the Silver Bullet Security Podcast, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines.
Links:

A partial transcript of the interview in IEEE Security [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.cigital.com/silverbullet/arubin-125.jpg" alt="Avi Rubin" title="Avi Rubin" align="right" /></p>
<p style="margin-top: 5px">In the debut episode of the <em>Silver Bullet Security Podcast</em>, Gary talks with Avi Rubin, professor of computer science and technical director of the information security institute at Johns Hopkins University.   Avi made headlines in 2003 when he revealed glitches in Diebold electronic voting machines.</p>
<p>Links:</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-001-arubin.pdf">A partial transcript of the interview in <em>IEEE Security &#038; Privacy</em></a></li>
<li><a href="http://www.avirubin.com/">Avi&#8217;s site</a></li>
<li><a href="http://www.bravenewballot.org/"><em>Brave New Ballot: The Battle to Safeguard Democracy in the Age of Electronic Voting</em></a>, Avi&#8217;s forthcoming book</li>
<li><a href="http://accurate-voting.org/">ACCURATE</a> - A Center for Correct, Usable, Reliable, Auditable, and Transparent Elections</li>
<li><a href="http://www.frootloops.com/">Froot Loops</a> and <a href="http://en.wikipedia.org/wiki/Corn_flakes">Corn Flakes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &#038; Privacy</em></a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/silverbullet/show-001/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
