<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Pie</title>
	<atom:link href="http://securitypie.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitypie.com</link>
	<description>The ramblings of three security curmudgeons</description>
	<lastBuildDate>Wed, 17 Feb 2010 04:13:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Word games for (Californian) children</title>
		<link>http://securitypie.com/word-games-for-californian-children/</link>
		<comments>http://securitypie.com/word-games-for-californian-children/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 04:13:15 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=753</guid>
		<description><![CDATA[Can you tell which of the following is a name for Marijuana (5), which is a name of a rollercoaster (6), and which is both (5)?
1. Tennessee Twister
2. Déjà vu
3. Cincinnati Cyclone
4. Afterburn
5. Pineapple Express
6. California Screaming
7. Brain Teaser
8. Blazing Fury
9. Flashback
10. Humbolt Scorcher
11. Great White
12. Hypersonic XLC
13. Hyperponic XLC
14. Invertigo
15. Woodstock&#8217;s Express
16. Bug Out
By [...]]]></description>
			<content:encoded><![CDATA[<p>Can you tell which of the following is a name for Marijuana (5), which is a name of a rollercoaster (6), and which is both (5)?</p>
<p>1. Tennessee Twister<br />
2. Déjà vu<br />
3. Cincinnati Cyclone<br />
4. Afterburn<br />
5. Pineapple Express<br />
6. California Screaming<br />
7. Brain Teaser<br />
8. Blazing Fury<br />
9. Flashback<br />
10. Humbolt Scorcher<br />
11. Great White<br />
12. Hypersonic XLC<br />
13. Hyperponic XLC<br />
14. Invertigo<br />
15. Woodstock&#8217;s Express<br />
16. Bug Out</p>
<p>By Lockie Hunter. Answers at McSweeney&#8217;s (http://www.mcsweeneys.net/links/lists/4hunter.html).</p>
<p>/al</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/word-games-for-californian-children/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beam me up Scotty</title>
		<link>http://securitypie.com/beam-me-up-scotty/</link>
		<comments>http://securitypie.com/beam-me-up-scotty/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 06:35:56 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Travel]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=751</guid>
		<description><![CDATA[Through my career I have learned that in order to be successful, people need to work together and interact with other people.
When it comes to “business”, we’re connecting (doing business) with people we trust and respect. I believe that in order to create a trust and some sort of a bond (the actual type vary) [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 347px"><img title="Beam Me Up" src="http://media-cdn.tripadvisor.com/media/photo-s/01/1d/73/f9/beam-me-up-scotty.jpg" alt="Beam Me Up" width="337" height="450" /><p class="wp-caption-text">Beam Me Up</p></div>
<p>Through my career I have learned that in order to be successful, people need to work together and interact with other people.</p>
<p>When it comes to “business”, we’re connecting (doing business) with people we trust and respect. I believe that in order to create a trust and some sort of a bond (the actual type vary) eye contact and handshake should be made – in other words, we need to travel.</p>
<p>Remote sensing technologies and “passing the ball” methods are useful to maintain a relationship but they could never be a substitute for creating it.  In other words, we need to meet our customers, partners, suppliers, vendors (and family) in order to create and maintain a successful relationship.</p>
<p>Spending most of the 24 hours in airplanes and airports the other day, I can only ask for one thing: please make it simple to travel.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/beam-me-up-scotty/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why???</title>
		<link>http://securitypie.com/why/</link>
		<comments>http://securitypie.com/why/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 20:14:28 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=746</guid>
		<description><![CDATA[Why do we work so hard to protect user data and privacy when it seems users are very happy to place their credit card info online and broadcast their shopping? The concept of blippy.com was shocking to me. It still is. Do users understand that all this information is amassed and can be used at [...]]]></description>
			<content:encoded><![CDATA[<p>Why do we work so hard to protect user data and privacy when it seems users are very happy to place their credit card info online and broadcast their shopping? The concept of blippy.com was shocking to me. It still is. Do users understand that all this information is amassed and can be used at any time by anyone?</p>
<p>What makes blippy trustworthy of access to a bank account? Are they audited? Are they PCI compliant? They are not even public and (unlike TJX) have nothing to lose by compromising the security of the users data&#8230;</p>
<p><a href="http://securitypie.com/wp-content/uploads/2010/02/blippy.png"><img src="http://securitypie.com/wp-content/uploads/2010/02/blippy-300x174.png" alt="" title="blippy" width="300" height="174" class="aligncenter size-medium wp-image-747" /></a></p>
<p>Yesterday, while analyzing business processes at a DLP account, we ran across a user that sent their entire password list in an unencrypted CSV format. Access to bank accounts, investment accounts, healthcare, Web 2.0 sites, etc.</p>
<p>Perhaps privacy, by 2020, will be replaced by identity insurance&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/why/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Luxury blinks</title>
		<link>http://securitypie.com/luxury-blinks/</link>
		<comments>http://securitypie.com/luxury-blinks/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 18:28:41 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[First Class]]></category>
		<category><![CDATA[Food]]></category>
		<category><![CDATA[general]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[thoughts]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=744</guid>
		<description><![CDATA[The wine industry (as we are told) is in crisis. At a recent conference (Vino2010 in New York) a group of panelists discussed the future of luxury wine (see the excellent read at http://www.vinography.com/archives/2010/02/the_future_of_luxury_wine.html). I, for one, am happy. Prices are falling. Not neccessarily for the uber wines, but very decidedly for anything else. I [...]]]></description>
			<content:encoded><![CDATA[<p>The wine industry (as we are told) is in crisis. At a recent conference (Vino2010 in New York) a group of panelists discussed the future of luxury wine (see the excellent read at http://www.vinography.com/archives/2010/02/the_future_of_luxury_wine.html). I, for one, am happy. Prices are falling. Not neccessarily for the uber wines, but very decidedly for anything else. I can walk into wine shops and pick up decent wines that in 2006 were asking for very unreasonable prices.</p>
<p>It is a buyers market, and picking the wrong wine is no longer a very costly mistake. It literally take me back to the 90&#8217;s, right before (and perhaps as) the asian and US markets conspired to jack up the prices of wines. Now that both the Asians and Americans lost their funding sources, they stopped paying exorbitantly for wine.</p>
<p>This is so good. The bubble has funded extensive knowhow in wines. How to extract as blockbuster a wine as possible from newly planted berries: and make a killing in the process. So there are many great wines out there. And they have no buyers, so some great ones sell for 30c on the dollar. Their future prospect is questionable: They may fold, they may redo their business model, who knows. But for now, run out and get them! </p>
<p>Now I do have to watch the calories, though&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/luxury-blinks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are We There Yet?</title>
		<link>http://securitypie.com/are-we-there-yet/</link>
		<comments>http://securitypie.com/are-we-there-yet/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 23:59:48 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[theory]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=740</guid>
		<description><![CDATA[RSA Conference, the biggest security event of the year will take place next month.
IMO now is a good time to review how we are doing as an industry, fulfilling our destination (that is, securing).
On Jone 2003, Gartner declared that IDS are dead and &#8220;recommends that enterprises redirect the money they would have spent on IDS toward defense [...]]]></description>
			<content:encoded><![CDATA[<p>RSA Conference, the biggest security event of the year will take place next month.</p>
<p>IMO now is a good time to review how we are doing as an industry, fulfilling our destination (that is, securing).</p>
<p>On Jone 2003, Gartner declared that IDS are dead and &#8220;recommends that enterprises redirect the money they would have spent on IDS toward defense applications such as those offered by thought-leading firewall vendors that offer both network-level and application-level firewall capabilities in an integrated product.&#8221;</p>
<p>6.5  years later, are we there yet?</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/are-we-there-yet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;High End&#8221; Security</title>
		<link>http://securitypie.com/high-end-security/</link>
		<comments>http://securitypie.com/high-end-security/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 19:11:46 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=730</guid>
		<description><![CDATA[So I periodically dabble with my hifi setup. I rearrange stuff, I recalibrate my reference levels at the sitting positions using an inexpensive sound pressure level meter, and measure the distances using a cool laser distance meter.
I ignore my acoustics engineer self (that left in place by 10 years of SONAR system engineering) that is [...]]]></description>
			<content:encoded><![CDATA[<p>So I periodically dabble with my hifi setup. I rearrange stuff, I recalibrate my reference levels at the sitting positions using an inexpensive sound pressure level meter, and measure the distances using a cool laser distance meter.</p>
<p>I ignore my acoustics engineer self (that left in place by 10 years of SONAR system engineering) that is screaming (Edvard Munch style) at the banality of my exercise. </p>
<p><a href="http://securitypie.com/wp-content/uploads/2010/01/RS-SPL-Meter.jpg"><img src="http://securitypie.com/wp-content/uploads/2010/01/RS-SPL-Meter.jpg" alt="" title="RS SPL Meter" width="255" height="275" class="aligncenter size-full wp-image-732" /></a></p>
<p>My engineer self does have a point: My SPL meter, for example, is a cheapo Radio Shack SPL meter. It measure signal in decibels. But a decibel is a ratio between two numbers: a reference figure, and a measured value. For example, a good measurement would be 12 dB re 1 uPa @ 1m which mould mean that my signal was 12 decidel relative to a pressure wave of 1 micro Pascal (pressure) as measure 1 meter from the source. My practical self dismissed my engineer self by saying &#8220;it is all relative anyway, so the exact parameter of the measurement is not important&#8221;; to which my engineer self scoffs with a resounding &#8220;idiot! <em>If you don&#8217;t understand what you are measuring then anything that you measure is suspect. For example, your rear speakers naturally have a different freq response than your front speakers. Hence if you try to balance them using the SPL meter, and you don&#8217;t *really* understand how it sums the SPL throughout the frequency range, you might get inconsistent results. This will also be true due to difference in the vertical response of the sepakers vis-a-vis your sitting position</em>&#8220;. Now once in a while my engineer self nearly gets a sure footing and I trend precipitously close to acquiring a Bruel &#038; Kjaer measurement system so I can start measuring with aplomb. I usually luck out by ending up reading some article I find somewhere instead of paying the requisite megabucks for B&#038;K Uber Gerate.</p>
<div id="attachment_733" class="wp-caption aligncenter" style="width: 181px"><a href="http://securitypie.com/wp-content/uploads/2010/01/BRUELKJAER_2230-SYSTEM.jpg"><img src="http://securitypie.com/wp-content/uploads/2010/01/BRUELKJAER_2230-SYSTEM-171x300.jpg" alt="" title="BRUEL&amp;KJAER_2230-SYSTEM" width="171" height="300" class="size-medium wp-image-733" /></a><p class="wp-caption-text">Bruel &#038; Kjaer 2230</p></div>
<p>So here is a question: Most of us know that there is a hifi market denoted as &#8220;Audiophile&#8221;. There is also a market called &#8220;professional audio&#8221;. There are very few brands that cater to both (I can only think of Dynaudio, Bryston, JBL, ADAM Audio, PMC, JM labs and a few others) and many of the products are so labelled (pro audio vs. home audio). Now audio is audio &#8211; why is there such a distinct seperation between the two markets?</p>
<div id="attachment_735" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2010/01/HM3_BLK.jpg"><img src="http://securitypie.com/wp-content/uploads/2010/01/HM3_BLK-300x176.jpg" alt="" title="HM3_BLK" width="300" height="176" class="size-medium wp-image-735" /></a><p class="wp-caption-text">Is this home audio or pro? ADAM HM3 in Black</p></div>
<div id="attachment_736" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2010/01/P33A.jpg"><img src="http://securitypie.com/wp-content/uploads/2010/01/P33A-300x157.jpg" alt="" title="P33A" width="300" height="157" class="size-medium wp-image-736" /></a><p class="wp-caption-text">Is this for Home of Pro use? P33A (Hint: room acoustics controls and the technical designation of near/midfield monitor should make the intended audience clear)</p></div>
<p>Here are my opinions:<br />
1. It isn&#8217;t looks (so called Wife Acceptance Factor &#8211; WAF) &#8211; Some home audio stuff is as horrid looking as the most functional of pro audio devices. And some pro audio stuff is drop dead gorgeous.<br />
2. It isn&#8217;t pricing &#8211; Some pro audio stuff is as expensive as audiophile stuff. Even though it is easier to justify the really upper end stuff for home use (the justification is based on expendable income, just like an ultra high-end stovetop for people who only cook steaks, more than any value statement) &#8211; it isn&#8217;t really necessary for a recording studio.<br />
3. Objective vs. Subjective sensibilities &#8211; By far the biggest differentiator &#8211; Audiophile makers differentiate themselves by ratings, by reviews, and mostly by subjective assessments. Audio professionals look for objective assessments (impossible to do, but possible to try to achieve). In fact many Audiophiles disregard objective assessments (like measurements) as secondary to subjective assessments (like listening to their favorite CDs). Meanwhile pros (like audio designers) measure first, and then validate the measurement with listening tests (to ensure they haven&#8217;t a &#8220;lemon&#8221;).<br />
<em>Note: The audio engineering market is exceptionally mature. So I have to accept the fact that both approaches have their merit. <strong>Audiophiles indeed have to rationalize their choices </strong>- and subjective assessments are the most optimal way to rationalize a choice, especially when there is no concensus on &#8220;state-of-the-art&#8221;. Meanwhile, <strong>audio pros have to make rational choices</strong> &#8211; for example, unlike an Audiophile, they must have a perfectly flat frequency response otherwise their recordings will be equalized to compensate and tend to sound &#8220;off&#8221; on other equipment. This might be interpreted by their customers as a quality deficiency resulting in fewer, lower paying projects. <strong>So both approaches are the correct approaches for their market segments</strong>.</em></p>
<p>What has this got to do with security? Well, security is just like any other market. It has the customers that rationalize their decision, and it has customers that make rational decisions. Now here is the funny fact-of-life: customers in the latter group tend to be assured with their decision and can defend it reasonably well, while customers in the former group tend to hem-and-haw and sort themselves into religious-like user camps. Just like the Audiophiles who flock to like-minded rationalization groups (like the sound-of-wire vs. all wires are identical camp, the Single Ended Triode vs. push-pull camp, the record player vs. CD or BD camps, the solid state vs. vacuum tube camps etc.).</p>
<p>The rational thinking &#8220;objective&#8221; group (typically early adopters) work like entrepeneurs: They identify a problem, create a list of parameters for their problem, and search for solutions. The decision rationalizing &#8220;subjective&#8221; group works in other ways, for example by stating top-level decision criteria inconsistent with the problem scenarios.</p>
<p>As an example, to compensate for their inability to achieve a sensible technical decision &#8211; or even a sensible description of the problem they are trying to solve &#8211; they will choose on other parameters &#8211; like integration with other products &#8211; whether those integrations make sense or not &#8211; or based on analyst opinion, or past relationships, or a reference list, or even past lust (or current bedroom relationship). </p>
<p>This is the &#8220;high end&#8221; model based on perception of applicability vs. measured applicability to the problem. Security folk are especially prone to this style of analysis since their role is multi disciplinary. The DLP market is becoming the best example of how this multi disciplinary responsibility serves to undermine the decision process eventually resulting in an alarming number of failed projects. For example, assume a security person who came from networking. Their background is reviewing logs, identifying the patterns of malware and they have a keen understanding of exploits. Being the best on their team, they are invited to participate in a DLP project selection committee. What, within their experience, allows them to understand the nature of risk due to information exposure? Not much&#8230; For the majority of technical security experts, the meaning of risk (and methodologies to assess and minimize risk) is obtuse. What is worse, risk is the sort of variable that everyone thinks they know and very few actually do. Even banking risk departments, who are supposed to be the leaders in risk class assessments, proved that they had no clue a year or so ago when they piled high risk products into lower risk bundles &#8211; just ask any jet airliner designer how wrong that assumption is.<br />
Similarly, consider a CISO. Predominantly a business title, how is a CISO to assess the technical capabilities and applicability to the network of a DLP solution? A good CISO is ill equipped to provide a concrete technical answer to the question of technical suitability.<br />
Add to this equation the fact that business folk and technical folk might as well speak a different language alltogether, and you are left with dire prospects for your selection committee.</p>
<p>This is where the analogy between the Audio Market and the Security Markets ends. An amplifier is an amplifier. It might amplify differently. But all amplifiers, and especially at the high-end side of the market, do a reasonable job of amplification. Almost all pro models are identical. That is the safety of a mature market. But the security market, by its nature, will never mature. Hackers and thieves will ensure that whatever we purchase today will be outdated quickly (as quickly as they can write the scripts to make it outdated). The results of the emotional decisions, in an immature market can be disaster. Remember the sods who bought the original early day $15-25k hi-def plasma displays only to have them become obsolete within 2 years due to the emergence of copy protection (HDCP)? </p>
<p>So 2 years later and the committee finally realize that while they really needed an equivalent of a pickup truck they had mistakingly acquired a dragster. It couldn&#8217;t pull the weight of the problem, it was hard to control and it tended to periodically veer off into the ditch. They hired a team of 100 to rebuild the engine every Tuesday and Thursdays. And you needed a semi-trailer to haul the damn thing around.</p>
<p>But at least they purchased &#8220;high end&#8221;. Colorful, shiney, heavy and what a guilt trip (as well as sometimes career limiting). As one CISO put it to me, it is &#8220;the cost of a maturing security organization&#8221;. </p>
<p>Back to my speakers. Radio Shack SPL meter useless in calibrating sub level (due to inconsistencies in frequency reponse). Damn it. Perhaps it is time for a B&#038;K measurement station? Gotta love those Danes for their perfect measurement stuff. $5k &#8211; Eh? Nah. ETF 5 and a somewhat calibrated Behringer mic (50$) is all I really need.</p>
<p>Happy measuring!         </p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/high-end-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ipodus Giganticus</title>
		<link>http://securitypie.com/ipodus-giganticus/</link>
		<comments>http://securitypie.com/ipodus-giganticus/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 02:07:32 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=728</guid>
		<description><![CDATA[While Sharon is busy waddling knee-deep through Phy (layer 1) terminology, another hardware/lifestyle company has released its gigantic equivalent of their iPod product, named iPad. 
Somehow the glitter of lower tech color LCD screens has been noisier than Sharon&#8217;s uber technology switches. Go figure.
]]></description>
			<content:encoded><![CDATA[<p>While Sharon is busy waddling knee-deep through Phy (layer 1) terminology, another hardware/lifestyle company has released its gigantic equivalent of their iPod product, named iPad. </p>
<p>Somehow the glitter of lower tech color LCD screens has been noisier than Sharon&#8217;s uber technology switches. Go figure.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/ipodus-giganticus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Alphabet Soup</title>
		<link>http://securitypie.com/new-alphabet-soup/</link>
		<comments>http://securitypie.com/new-alphabet-soup/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 01:31:52 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Food]]></category>
		<category><![CDATA[soup]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=723</guid>
		<description><![CDATA[In a high-tech job (but also any other job) change requires to learn the new lingo. Like Obama, I like the change. I consider this fun (and I WILL change the world)&#8230;
While I&#8217;m waiting for Assaf to create the next-gen soup, here is the partial list of abbreviations and their meaning I have to learn. In [...]]]></description>
			<content:encoded><![CDATA[<p>In a high-tech job (but also any other job) change requires to learn the new lingo. Like <a href="http://www.telegraph.co.uk/news/worldnews/northamerica/usa/barackobama/3219308/Barack-Obama-vows-to-change-the-world.html" target="_blank">Obama</a>, I like the change. I consider this fun (and <a href="http://news.yahoo.com/s/politico/20100120/pl_politico/31703" target="_blank">I WILL change the world)</a>&#8230;</p>
<p>While I&#8217;m waiting for Assaf to create the next-gen soup, here is the partial list of abbreviations and their meaning I have to learn. In some cases, it takes me 20+ years in time&#8230;</p>
<p><a href="http://securitypie.com/wp-content/uploads/2010/01/success-alphabet-soup.jpg"><img class="alignleft size-full wp-image-724" title="Eat this alphabet soup to get  success " src="http://securitypie.com/wp-content/uploads/2010/01/success-alphabet-soup.jpg" alt="Eat this alphabet soup to get  success " width="229" height="233" /></a></p>
<ul>
<li><strong>AUI</strong> : Attachment Unit Interface, originally connected to a MAU</li>
<li><strong>MAU</strong> : Medium Attachment Unit, like a 10Base-2 transceiver.</li>
<li><strong>XAUI </strong>: A 10G AUI, the X is the Roman numeral for 10; Data path is 4×3.125Gbps Lanes</li>
<li><strong>XLAUI</strong> : A 40G AUI, XL being the Roman numeral for 40; Data path is 4×10.3.125Gbps Lanes</li>
<li><strong>CAUI</strong>: A 100G AUI, C (you guessed it) being the Roman numeral for 100; Data path is 10×10.3125Gbps Lanes</li>
<li><strong>MII </strong>: Medium Independent Interface, 4bit wide data path.</li>
<li><strong>RMII</strong> : Reduced MII, the MII but with less signals!</li>
<li><strong>SMII</strong> : Serial MII, the data path is reduced to one bit.</li>
<li><strong>GMII</strong> : Gigabit MII, 8bit wide data path.</li>
<li><strong>RGMII</strong> : Reduced Gigabit MII.</li>
<li><strong>SGMII</strong> :  Serial Gigabit MII.</li>
<li><strong>XGMII</strong> : 10G MII (this time the G made it in).</li>
<li><strong>XGXS</strong> : XGMII eXtender Sublayer.</li>
<li><strong>XLGMII</strong> : 40G MII.</li>
<li><strong>CGMII</strong> : 100G MII.</li>
<li><strong>MAC</strong> : Media Access Controller.</li>
<li><strong>PLS</strong> : Physical Layer Signaling; for 10Mbps only, implemented the Manchester encoding.</li>
<li><strong>RS</strong> : Reconciliation Sublayer.</li>
<li><strong>PCS</strong> : Physical Coding Sublayer; e.g. 8B/10B.</li>
<li><strong>MLD</strong> : Multi Lane Distribution</li>
<li><strong>PMA</strong> :  Physical Medium Attachment.</li>
<li><strong>PMD</strong> : Physical Medium Dependant.</li>
<li><strong>IPG</strong> : Inter Packet Gap; Code words sent between valid Ethernet Frames.</li>
</ul>
<p><a href="http://www.broadcom.com/press/glossary.php" target="_blank">See also the Broadcom glossary of terms. </a></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/new-alphabet-soup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google: Do What You Say</title>
		<link>http://securitypie.com/do-what-you-say/</link>
		<comments>http://securitypie.com/do-what-you-say/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 07:51:32 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Data protection]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=711</guid>
		<description><![CDATA[First, let me start stating that this is NOT a security issue with Google, even though it might be presented this way.
Unless you were hiding in a cave in the past hours you know that Google is taking some serious steps to protect its customers (you, me, all of us) after it was attacked one [...]]]></description>
			<content:encoded><![CDATA[<p>First, let me start stating that this is NOT a security issue with Google, even though it might be presented this way.</p>
<p>Unless you were hiding in a cave in the past hours you know that Google is taking some serious steps to protect its customers (you, me, all of us) after it was attacked one more time (see  &#8221;<a href="http://government.zdnet.com/?p=6837" target="_blank">Google on the defensive, vulnerable; China risks international and U.S. response</a>&#8220;). Among other things, &#8220;<a href="http://www.prnewswire.com/news-releases/google-finally-improves-security-of-gmail-connections-as-consumer-watchdog-urged-81375657.html" target="_blank">Google Finally Improves Security of Gmail Connections as Consumer Watchdog Urged</a>&#8221; which is great:</p>
<blockquote>
<div id="_mcePaste">Consumer Watchdog said Google should use encryption for connections to all its Internet-based services, not just Gmail.The new security measures would not have prevented the sort of cyber attack that targeted Google from China. It does increase security to prevent third parties from snooping as information moves from a computer over a network to Google&#8217;s servers. Google has offered SSL encryption using the https protocol as an option since 2008</div>
</blockquote>
<p>But if you look on the  the screenshot you can see that NOT all the traffic is encrypted&#8230; While this might be OK for static pages, who knows what other pages are not protected with SSL? Why can&#8217;t you turn it on for the entire site? It will add more credibility and assurance&#8230;</p>
<div id="attachment_713" class="wp-caption aligncenter" style="width: 662px"><a href="http://securitypie.com/wp-content/uploads/2010/01/HTTPS-by-default-not-so-sure1.tiff"><img class="size-full wp-image-713  " title="HTTPS by default - not so sure" src="http://securitypie.com/wp-content/uploads/2010/01/HTTPS-by-default-not-so-sure1.tiff" alt="" width="652" height="171" /></a><p class="wp-caption-text">HTTPS by default - not so sure</p></div>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/do-what-you-say/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>To Know</title>
		<link>http://securitypie.com/to-know/</link>
		<comments>http://securitypie.com/to-know/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 17:40:39 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=707</guid>
		<description><![CDATA[Victor Stampfer knows something about cooking. At the end of his long book he lists this knowledge clearly and articulately:
Cellulose hydrolysis above 120C
Cooking vegetables to hydrolysis pectin and starch > 85C
Pectin Hydrolysis 85C
Cooking vegetables to hydrolysis (starch only) 85C >    > 80C
Starch solubilization and hydrolysis 80C
Myofibrilar proteins and myoglobin alteration (loss of [...]]]></description>
			<content:encoded><![CDATA[<p>Victor Stampfer knows something about cooking. At the end of his long book he lists this knowledge clearly and articulately:</p>
<p>Cellulose hydrolysis above 120C<br />
Cooking vegetables to hydrolysis pectin and starch > 85C<br />
Pectin Hydrolysis 85C<br />
Cooking vegetables to hydrolysis (starch only) 85C >    > 80C<br />
Starch solubilization and hydrolysis 80C<br />
Myofibrilar proteins and myoglobin alteration (loss of waterholding capacity; color is definitely altered) 68C<br />
Cooking of &#8211;<br />
     &#8211; braized, sauteed, steamed or boiled meats<br />
     &#8211; roasted white meat<br />
     &#8211; fish<br />
Sarcoplasmic protein alteration (modification of the perception of color) 62C<br />
Cooking of &#8211;<br />
     &#8211; just cooked fish < 62C<br />
     - red, roasted or grilled meats <62C<br />
             - rare 56-58C<br />
             - medium rare 58-60C<br />
             - medium well 60-62C<br />
             - well done > 62C<br />
Beginning the destruction of vegetative forms of bacteria 52C (careful of spores!)<br />
Bacterial growth, spore germination < 52C </p>
<p>It is really all you need to know to cook some of the best meals of your life. </p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/to-know/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
