<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tales of Ordinary Madness &#187; Me and My Big Ideas</title>
	<atom:link href="http://chris.teodorski.com/category/me-and-my-big-ideas/feed/" rel="self" type="application/rss+xml" />
	<link>http://chris.teodorski.com</link>
	<description>Chris' Tales of Ordinary Madness</description>
	<lastBuildDate>Fri, 16 Jul 2010 17:36:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Narcissistic Vulnerability Pimp</title>
		<link>http://chris.teodorski.com/2010/04/narcissistic-vulnerability-pimp/</link>
		<comments>http://chris.teodorski.com/2010/04/narcissistic-vulnerability-pimp/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 02:21:44 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=260</guid>
		<description><![CDATA[I have always held Verizon’s Business Security division in rather high regard, primarily because over the last several years I’ve found their Data Breech Investigations report a useful and very telling document.  I’m often in the situation in my career of explaining the “real” threat that X poses.  This document has always provided [...]]]></description>
			<content:encoded><![CDATA[<p>I have always held Verizon’s Business Security division in rather high regard, primarily because over the last several years I’ve found their Data Breech Investigations report a useful and very telling document.  I’m often in the situation in my career of explaining the “real” threat that X poses.  This document has always provided something for me to point at and say here is why you, Mr. BusinessMan need to care about securing your enterprise.  Having Verizon’s name tied to it gave it some additional weight.</p>
<p>However, this morning I read the article entitled “<a href="http://securityblog.verizonbusiness.com/2010/04/22/redefining-security-researcher/#more-757">Redefining Security Researcher” by Wade Baker</a>.  In this blog posting the author suggests that the InfoSec community suffers from the “ridiculous yet long-standing inability to distinguish the good guys from the bad guys”.  I have several issues with Wade’s terminology and his logic.  </p>
<p>First, as Wade suggests the headlines do often read “Security Researcher Breaks This” and “Security Researcher Exposes That”.   However, the author of the article or his/her editor picks that headline not the “Security Researcher”.   Just like the television reporter gets to decide if the term “World’s Number One Hacker” appears underneath Gregory D. Evans when he mugs for CNN.  We in the industry have only limited influence over the terminology used.  A perfect example of this is death of the term “cracker” and the changing of the word “hacker” to be synonymous with criminal.   </p>
<p>Also, let’s not forget that even the Narcissistic Vulnerability Pimp is doing research.  It’s not like they have some secret vulnerability hole where they can pull vulnerabilities from.  While you might object to their methods of disclosure, that doesn’t mean that their efforts are due anything less than being called a “Security Researcher”.    They are in fact researching security issues.</p>
<p>Finally, as Wade points out in his later comments on the post, several analogies do fall flat when used to further explain disclosure.  Admittedly no analogy is destined to be a perfect fit; however I do feel that I’ve found an analogy that works well enough – Bullet-Proof vests.  Imagine someone discovered that a certain brand of 9mm ammunition could easily pierce a standard bullet proof vest.  They contact the manufacturer and inform them that the vest fails to stop this particular brand of bullet.  The manufacturer says “we don’t believe that to be a real issue”.    How should this be handled?  Hundreds perhaps thousands of vests with this vulnerability are deployed in military, police, and civilian circles.  If the bad guys get wind of this, you can be sure this brand of bullet will become the round of choice.  I think the only responsible thing to do is go public with this information.  This allows each person to make an educated decision when they put on a vest – like wearing some additional layer of protection.  Hopefully the public outrage will force the vendor to look into the problem and fix the issue.   </p>
<p>Vulnerability disclosure is a touchy subject and will always be a balancing act between being responsible and doing what is best to protect the consumer, allowing the consumer to make an educated decision about what software provides the level of security and functionality necessary to get the job done.</p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2010/04/narcissistic-vulnerability-pimp/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Mr. Deity Episode 4: Mr. Deity and the Messages</title>
		<link>http://chris.teodorski.com/2009/09/mr-deity-episode-4-mr-deity-and-the-messages/</link>
		<comments>http://chris.teodorski.com/2009/09/mr-deity-episode-4-mr-deity-and-the-messages/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 01:26:18 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Atheism]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=242</guid>
		<description><![CDATA[
These are too damn funny.  No idea why I&#8217;m just discovering these guys now&#8230;
]]></description>
			<content:encoded><![CDATA[<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/UaZDcS-rMf4&#038;hl=en&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/UaZDcS-rMf4&#038;hl=en&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object></p>
<p>These are too damn funny.  No idea why I&#8217;m just discovering these guys now&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/09/mr-deity-episode-4-mr-deity-and-the-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My lil&#8217; peanut</title>
		<link>http://chris.teodorski.com/2009/08/my-lil-peanut/</link>
		<comments>http://chris.teodorski.com/2009/08/my-lil-peanut/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 02:02:39 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=239</guid>
		<description><![CDATA[Here he/she is &#8212; the first public viewing of our new little peanut.  I think he/she has my eyes.

]]></description>
			<content:encoded><![CDATA[<p>Here he/she is &#8212; the first public viewing of our new little peanut.  I think he/she has my eyes.</p>
<p><img src="http://chris.teodorski.com/images/peanut.jpg" alt="lil peanut" /></p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/08/my-lil-peanut/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Building my security lab</title>
		<link>http://chris.teodorski.com/2009/05/building-my-security-lab/</link>
		<comments>http://chris.teodorski.com/2009/05/building-my-security-lab/#comments</comments>
		<pubDate>Wed, 20 May 2009 01:09:53 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=228</guid>
		<description><![CDATA[So I&#8217;ve been slowly (that is VERY slowly) re-arranging my office to make some additional room for some additional computers.  My goal is to create a security lab that will allow me in my spare time to work on my web assessment/penetration skills.  My intention was to utilize either VMWare or Sun&#8217;s Virtual [...]]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;ve been slowly (that is VERY slowly) re-arranging my office to make some additional room for some additional computers.  My goal is to create a security lab that will allow me in my spare time to work on my web assessment/penetration skills.  My intention was to utilize either VMWare or Sun&#8217;s Virtual Box to give me some additional flexibility and hopefully keep my electric bill somewhere below the GDP of Micronesia (which in case you are wondering is about 232 million USD).  Well while poking around today, I found this great article that covers Virtual Appliances, with a specific focus on those that would be of interest to the security professional.  Now many of these would have nothing to do with my web application penetration testing, but they are still some pretty neat appliances.  It&#8217;s worth a read:<br />
<a href="http://www.tssci-security.com/archives/2009/03/18/virtual-appliances-for-the-security-professional/"><br />
Virtual appliances for the security professional</a></p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/05/building-my-security-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why do you believe in god?</title>
		<link>http://chris.teodorski.com/2009/05/why-do-you-believe-in-god/</link>
		<comments>http://chris.teodorski.com/2009/05/why-do-you-believe-in-god/#comments</comments>
		<pubDate>Tue, 19 May 2009 02:09:01 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Atheism]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=218</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><a href="http://chris.teodorski.com/wp-content/uploads/2009/05/17417233.gif"><img src="http://chris.teodorski.com/wp-content/uploads/2009/05/17417233-212x300.gif" alt="17417233" title="17417233" width="212" height="300" class="alignnone size-medium wp-image-225" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/05/why-do-you-believe-in-god/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wait, you want me to believe the National Organization for Marriage is just a bunch of bigots?</title>
		<link>http://chris.teodorski.com/2009/04/wait-you-want-me-to-believe-the-national-organization-for-marriage-is-just-a-bunch-of-bigots/</link>
		<comments>http://chris.teodorski.com/2009/04/wait-you-want-me-to-believe-the-national-organization-for-marriage-is-just-a-bunch-of-bigots/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 01:17:17 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=194</guid>
		<description><![CDATA[
Okay, when you put it that way, I guess they just might be.  Great job Redditors!
http://blog.reddit.com/2009/04/redditors-receive-homo-heros-honor-for.html
]]></description>
			<content:encoded><![CDATA[<p><object width="425" height="349"><param name="movie" value="http://www.youtube.com/v/ZC4B4LknF90&#038;border=1&#038;color1=0x6699&#038;color2=0x54abd6&#038;hl=en&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/ZC4B4LknF90&#038;border=1&#038;color1=0x6699&#038;color2=0x54abd6&#038;hl=en&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="349"></embed></object></p>
<p>Okay, when you put it that way, I guess they just might be.  Great job Redditors!</p>
<p><a href="http://blog.reddit.com/2009/04/redditors-receive-homo-heros-honor-for.html">http://blog.reddit.com/2009/04/redditors-receive-homo-heros-honor-for.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/04/wait-you-want-me-to-believe-the-national-organization-for-marriage-is-just-a-bunch-of-bigots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Would Jesus NOT Do?</title>
		<link>http://chris.teodorski.com/2009/04/what-would-jesus-not-do/</link>
		<comments>http://chris.teodorski.com/2009/04/what-would-jesus-not-do/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 00:23:14 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Atheism]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=191</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><object width="445" height="364"><param name="movie" value="http://www.youtube.com/v/zOfjkl-3SNE&#038;hl=en&#038;fs=1&#038;rel=0&#038;border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/zOfjkl-3SNE&#038;hl=en&#038;fs=1&#038;rel=0&#038;border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="445" height="364"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/04/what-would-jesus-not-do/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I want a debaptism certificate</title>
		<link>http://chris.teodorski.com/2009/04/i-want-a-debaptism-certificate/</link>
		<comments>http://chris.teodorski.com/2009/04/i-want-a-debaptism-certificate/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 00:50:35 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Atheism]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=188</guid>
		<description><![CDATA[I knew I missed something when I was in the UK.  I missed an opportunity to purchase a Certificate of Debaptism from the National Secular Society.
Debaptism Certificate
]]></description>
			<content:encoded><![CDATA[<p>I knew I missed something when I was in the UK.  I missed an opportunity to purchase a Certificate of Debaptism from the National Secular Society.</p>
<p><a href="http://www.secularism.org.uk/shop.html?category=merchandise%2F940">Debaptism Certificate</a></p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/04/i-want-a-debaptism-certificate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why must you be so mean?</title>
		<link>http://chris.teodorski.com/2009/04/why-must-you-be-so-mean/</link>
		<comments>http://chris.teodorski.com/2009/04/why-must-you-be-so-mean/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 00:19:25 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Atheism]]></category>
		<category><![CDATA[Friends]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=183</guid>
		<description><![CDATA[My good friend Sunil asked me the other day why I was so harsh on religion.  If I remember the timing correctly he was responding primarliy to the &#8220;Crazy vs Religious&#8221; cartoon I posted below.  Sam Harris summed it up for me very well in the video below, but I&#8217;d like to paraphrase. [...]]]></description>
			<content:encoded><![CDATA[<p>My good friend Sunil asked me the other day why I was so harsh on religion.  If I remember the timing correctly he was responding primarliy to the &#8220;Crazy vs Religious&#8221; cartoon I posted below.  Sam Harris summed it up for me very well in the video below, but I&#8217;d like to paraphrase.  If I came to you and insisted that there was inside of me a giant invisible machine powered by invisible winged monkeys that generated the very energy that kept all of life going, you would dismiss me a crazy person.  This is a totally rational response to what I have claimed.  Unless I can provide some shred of evidence, I should be dismissed as a kook.  However, religion is given a pass when it comes to rational thought.  Challenge religion to produce any evidence of its claims and suddenly you are guilty of oppression and religious intolerance.  Claiming that a man walked on water, or rose from the dead, or flew off into the sky on a winged horse, or parted the sea is no less crazy than my winged monkeys whodrive the giant love engine.  As I&#8217;ve said before, how can we as an rational animal be expected to advance, when we insist on bringing the boogey man from the past along with us.  </p>
<p>As long as religion continues to attempt to change laws or prevent archaic laws from being changed (like preventing two consenting adults from legally marrying), I will speak harshly of religion.   As long as religion keeps attmepting to prevent birth control from being taught in schools or preventing condoms from being distributed to a contintent whose population is being decimated by AIDs, I will continue to speak harshly of religion.</p>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/04/why-must-you-be-so-mean/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chris &#8220;hearts&#8221; Sam Harris</title>
		<link>http://chris.teodorski.com/2009/04/chris-hearts-sam-harris/</link>
		<comments>http://chris.teodorski.com/2009/04/chris-hearts-sam-harris/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 22:35:55 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Atheism]]></category>
		<category><![CDATA[Me and My Big Ideas]]></category>

		<guid isPermaLink="false">http://chris.teodorski.com/?p=179</guid>
		<description><![CDATA[Hugh Hewitt vs Sam HarrisUploaded by apologetics
]]></description>
			<content:encoded><![CDATA[<div><object width="480" height="381"><param name="movie" value="http://www.dailymotion.com/swf/x5afgu_hugh-hewitt-vs-sam-harris_tech&#038;related=1"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.dailymotion.com/swf/x5afgu_hugh-hewitt-vs-sam-harris_tech&#038;related=1" type="application/x-shockwave-flash" width="480" height="381" allowFullScreen="true" allowScriptAccess="always"></embed></object><br /><b><a href="http://www.dailymotion.com/video/x5afgu_hugh-hewitt-vs-sam-harris_tech">Hugh Hewitt vs Sam Harris</a></b><br /><i>Uploaded by <a href="http://www.dailymotion.com/apologetics">apologetics</a></i></div>
]]></content:encoded>
			<wfw:commentRss>http://chris.teodorski.com/2009/04/chris-hearts-sam-harris/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
