<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Vmyths</title>
	<atom:link href="http://Vmyths.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://Vmyths.com</link>
	<description>Truth about computer security hysteria</description>
	<lastBuildDate>Thu, 03 Feb 2011 05:36:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>Comment on Does &#8220;Gulf War printer virus&#8221; hoax have roots in a WWII sailor&#8217;s tale? by Stuxnet, cyberwar, cybersabotage, blah&#8230; &#124; ESET ThreatBlog</title>
		<link>http://Vmyths.com/2010/11/28/wwii/comment-page-1/#comment-516</link>
		<dc:creator>Stuxnet, cyberwar, cybersabotage, blah&#8230; &#124; ESET ThreatBlog</dc:creator>
		<pubDate>Thu, 03 Feb 2011 05:36:21 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=744#comment-516</guid>
		<description>[...] irrelevant thought: why, I wonder, do all the Stuxnet conspiracy theories keep reminding me of the Iraqui printer virus story? Is it all the &#8220;nudge, wink, I know something you don&#8217;t know&#8221; commentary [...]</description>
		<content:encoded><![CDATA[<p>[...] irrelevant thought: why, I wonder, do all the Stuxnet conspiracy theories keep reminding me of the Iraqui printer virus story? Is it all the &#8220;nudge, wink, I know something you don&#8217;t know&#8221; commentary [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SANS &#8220;Threat Level&#8221; remains green over Stuxnet hysteria by xfmrhsd</title>
		<link>http://Vmyths.com/2010/09/27/sans/comment-page-1/#comment-514</link>
		<dc:creator>xfmrhsd</dc:creator>
		<pubDate>Thu, 18 Nov 2010 05:35:10 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=1224#comment-514</guid>
		<description>Must hurt to be right, hope the link works;
http://my.earthlink.net/article/tec?guid=20101117/1cf800db-87e7-42a6-bf3c-a34c22aa737e
Here it comes.</description>
		<content:encoded><![CDATA[<p>Must hurt to be right, hope the link works;<br />
<a href="http://my.earthlink.net/article/tec?guid=20101117/1cf800db-87e7-42a6-bf3c-a34c22aa737e" rel="nofollow">http://my.earthlink.net/article/tec?guid=20101117/1cf800db-87e7-42a6-bf3c-a34c22aa737e</a><br />
Here it comes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Stuxnet worm smells like overhype by xfmrhsd</title>
		<link>http://Vmyths.com/2010/09/24/stuxnet/comment-page-1/#comment-512</link>
		<dc:creator>xfmrhsd</dc:creator>
		<pubDate>Mon, 27 Sep 2010 02:31:17 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=1098#comment-512</guid>
		<description>Was a quiet decade as far as virus hype goes, looked like the old days with the Symantec banner on CBS Evening News today, took over 10 years for it to come back. Duke Nukem forever comes out Feb 2011, any connections conspiracy theorists? Or could this be simply a cycle in virus hype as happened before (Benefiting AV companies) concurrent with simply a company capitalizing on a long awaited release just after a major financial upheaval. In either case we out here stand to benefit from the entertainment. Good AV software (Not Symantec by the way! I use a free down loadable copy from a good company) and a hardware firewall makes all this just entertainment for us. Game on AV industry! Hype on gaming industry! Wait! reverse that, or maybe not , does this apply to both? In any case I will be playing DNF when it comes out...and no thumbdrives will be allowed on military bases forever.</description>
		<content:encoded><![CDATA[<p>Was a quiet decade as far as virus hype goes, looked like the old days with the Symantec banner on CBS Evening News today, took over 10 years for it to come back. Duke Nukem forever comes out Feb 2011, any connections conspiracy theorists? Or could this be simply a cycle in virus hype as happened before (Benefiting AV companies) concurrent with simply a company capitalizing on a long awaited release just after a major financial upheaval. In either case we out here stand to benefit from the entertainment. Good AV software (Not Symantec by the way! I use a free down loadable copy from a good company) and a hardware firewall makes all this just entertainment for us. Game on AV industry! Hype on gaming industry! Wait! reverse that, or maybe not , does this apply to both? In any case I will be playing DNF when it comes out&#8230;and no thumbdrives will be allowed on military bases forever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Gov&#8217;t hype surrounds &#8221;Operation Buckshot Yankee&#8221; by Rob Rosenberger</title>
		<link>http://Vmyths.com/2010/08/26/oby/comment-page-1/#comment-511</link>
		<dc:creator>Rob Rosenberger</dc:creator>
		<pubDate>Sun, 05 Sep 2010 19:48:43 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=925#comment-511</guid>
		<description>Further reading:
&lt;ol&gt;
&lt;li&gt;&lt;cite&gt;SecurityWeek&lt;/cite&gt;: &lt;a target=press href=&quot;http://www.securityweek.com/defense-departments-cyberwar-credibility-gap&quot; rel=&quot;nofollow&quot;&gt;Defense Department’s Cyberwar Credibility Gap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Wired.com&lt;/cite&gt; Danger room: &lt;a target=press href=&quot;http://www.wired.com/dangerroom/2010/08/insiders-doubt-2008-pentagon-hack-was-foreign-spy-attack/&quot; rel=&quot;nofollow&quot;&gt;Insiders Doubt 2008 Pentagon Hack Was Foreign Spy Attack&lt;/a&gt;&lt;/li&gt; 
&lt;/ol&gt;</description>
		<content:encoded><![CDATA[<p>Further reading:</p>
<ol>
<li><cite>SecurityWeek</cite>: <a target=press href="http://www.securityweek.com/defense-departments-cyberwar-credibility-gap" rel="nofollow">Defense Department’s Cyberwar Credibility Gap</a></li>
<li><cite>Wired.com</cite> Danger room: <a target=press href="http://www.wired.com/dangerroom/2010/08/insiders-doubt-2008-pentagon-hack-was-foreign-spy-attack/" rel="nofollow">Insiders Doubt 2008 Pentagon Hack Was Foreign Spy Attack</a></li>
</ol>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Today&#8217;s DEPSECDEF plagiarized his predecessor&#8217;s &#8221;wake-up call&#8221; by Rob Rosenberger</title>
		<link>http://Vmyths.com/2010/08/27/oby-2/comment-page-1/#comment-510</link>
		<dc:creator>Rob Rosenberger</dc:creator>
		<pubDate>Sun, 05 Sep 2010 19:48:15 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=942#comment-510</guid>
		<description>Further reading:
&lt;ol&gt;
&lt;li&gt;&lt;cite&gt;SecurityWeek&lt;/cite&gt;: &lt;a target=press href=&quot;http://www.securityweek.com/defense-departments-cyberwar-credibility-gap&quot; rel=&quot;nofollow&quot;&gt;Defense Department’s Cyberwar Credibility Gap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Wired.com&lt;/cite&gt; Danger room: &lt;a target=press href=&quot;http://www.wired.com/dangerroom/2010/08/insiders-doubt-2008-pentagon-hack-was-foreign-spy-attack/&quot; rel=&quot;nofollow&quot;&gt;Insiders Doubt 2008 Pentagon Hack Was Foreign Spy Attack&lt;/a&gt;&lt;/li&gt; 
&lt;/ol&gt;</description>
		<content:encoded><![CDATA[<p>Further reading:</p>
<ol>
<li><cite>SecurityWeek</cite>: <a target=press href="http://www.securityweek.com/defense-departments-cyberwar-credibility-gap" rel="nofollow">Defense Department’s Cyberwar Credibility Gap</a></li>
<li><cite>Wired.com</cite> Danger room: <a target=press href="http://www.wired.com/dangerroom/2010/08/insiders-doubt-2008-pentagon-hack-was-foreign-spy-attack/" rel="nofollow">Insiders Doubt 2008 Pentagon Hack Was Foreign Spy Attack</a></li>
</ol>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virus experts play &#8220;king of the hill&#8221; on Twitter by Rob Rosenberger</title>
		<link>http://Vmyths.com/2010/08/30/twitter-3/comment-page-1/#comment-509</link>
		<dc:creator>Rob Rosenberger</dc:creator>
		<pubDate>Tue, 31 Aug 2010 02:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=1022#comment-509</guid>
		<description>Graham Cluley &lt;em&gt;gets&lt;/em&gt; the humor in my columns.  He &lt;a target=twitter href=&quot;https://twitter.com/gcluley&quot; rel=&quot;nofollow&quot;&gt;replied via Twitter&lt;/a&gt;: &quot;Glad to have provided some inspiration! cheers!&quot;  He probably knows I played leapfrog with him to reach my real target: @PCVirusNews.</description>
		<content:encoded><![CDATA[<p>Graham Cluley <em>gets</em> the humor in my columns.  He <a target=twitter href="https://twitter.com/gcluley" rel="nofollow">replied via Twitter</a>: &#8220;Glad to have provided some inspiration! cheers!&#8221;  He probably knows I played leapfrog with him to reach my real target: @PCVirusNews.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Gov&#8217;t hype surrounds &#8221;Operation Buckshot Yankee&#8221; by Gsparky</title>
		<link>http://Vmyths.com/2010/08/26/oby/comment-page-1/#comment-507</link>
		<dc:creator>Gsparky</dc:creator>
		<pubDate>Fri, 27 Aug 2010 01:49:30 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=925#comment-507</guid>
		<description>Yeah, baby!  Now *THAT&#039;S* what I&#039;m talking about!</description>
		<content:encoded><![CDATA[<p>Yeah, baby!  Now *THAT&#8217;S* what I&#8217;m talking about!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Obama (!) spouts an urban legend in his cybersecurity speech by Rob Rosenberger</title>
		<link>http://Vmyths.com/2009/05/29/obama/comment-page-1/#comment-504</link>
		<dc:creator>Rob Rosenberger</dc:creator>
		<pubDate>Tue, 22 Sep 2009 01:09:03 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=656#comment-504</guid>
		<description>::My question, though, is how much do you
::think cyber-terrorism/security affects
::and costs the United States annually?

Great question, Charley!  Before I answer it, let me stress that while the &quot;inside experts&quot; claim they DO know the true scope of your question ... I insist they DON&#039;T know the true scope.  Extraordinary claims require extraordinary evidence, which we lack.  The inside experts tell the public they can&#039;t divulge the truth because Osama bin Laden will use the knowledge to destroy the United States.  Everything the public does know, overwhelmingly points to hyperbole and hysteria.  So the skeptics say &quot;stop crying wolf&quot; and the inside experts say &quot;we&#039;re Cassandras, you just wait and see.&quot;

So.  How much does it cost?  Skeptical expert Bruce Schneier describes the cost as a &quot;terrorism tax,&quot; similar to the Cold War tax although much more directly extracted from every American&#039;s pocketbook.

I myself engage in hyperbole when I say &quot;I honestly believe the cyber-terror tax exceeds its return on investment.&quot;  Why, then, would I let the inside experts turn on me to demand &quot;what evidence supports your belief&quot;?  Because I can then respond &quot;well, you&#039;re the only one here who can give our audience the evidence they need to disbelieve me.  But you won&#039;t cough up any evidence for scrutiny, will you?&quot;

Still, it doesn&#039;t answer your question.  So let&#039;s make a (somewhat invalid) comparison.  &quot;Rob, did we spend too much on the Y2K hysteria?&quot;  The answer is &quot;businessmen spent the right amount, but if they spent it in fear, then they spent the right amount for the wrong reason.&quot;  A college-level logic course will teach you that, given a chocie, you&#039;d rather spend the wrong amount for the right reason, than spend the right amount for the wrong reason.  Terrorism of any sort is simply a matter of risk; the money you spend to mitigate it (repeat &quot;mitigate&quot;) is essentially an insurance bet.  (Professional poker players understand this logic as the &quot;expected value of a hand.&quot;  Pros would rather lose a hand for the right reason than win a hand for the wrong reason.)

So, the answer to your question.  The computer security industrial complex doesn&#039;t mitigate cyber-terror in a logical manner.  We&#039;re spending money &quot;wrong,&quot; and that&#039;s not right.

::Should we be paying more attention to it,
::not necessarily through fear mongering,
::but rather through indepth and accurate
::analysis and understanding?

Yes.  And I think the government should do it.  Sadly, their research remains highly overclassified even by the government&#039;s own admission.

But it&#039;s even worse than most experts realize, and we can expose it with a simple observation.  We know the U.S. military analyzes the attacks it gets each day -- knowledge that remains completely out of reach to airmen &amp; soldiers who would use the info to defend their home networks.  It&#039;s valid to assume major intelligence agencies both friendly (e.g. Israel) and hostile (e.g. North Korea) target the home networks of career officers &amp; sergeants who habitually take FOUO and (yes!) classified info home to work on it after duty hours.  Military analysis would at least yield a realtime blackhole list, yet the knowledge goes to waste on home networks where it would prove particularly useful.

I forget who once said &quot;analysis that cannot be obtained is analysis that does not exist.&quot;  The military&#039;s (public) release of a realtime blackhole list would do wonders in the realm of information protection.  But they don&#039;t release it ... so it doesn&#039;t exist for those who could benefit from it.

Crud.  Did I just say &quot;we do analysis wrong&quot;?

...Did I answer both of your questions, Charley?</description>
		<content:encoded><![CDATA[<p>::My question, though, is how much do you<br />
::think cyber-terrorism/security affects<br />
::and costs the United States annually?</p>
<p>Great question, Charley!  Before I answer it, let me stress that while the &#8220;inside experts&#8221; claim they DO know the true scope of your question &#8230; I insist they DON&#8217;T know the true scope.  Extraordinary claims require extraordinary evidence, which we lack.  The inside experts tell the public they can&#8217;t divulge the truth because Osama bin Laden will use the knowledge to destroy the United States.  Everything the public does know, overwhelmingly points to hyperbole and hysteria.  So the skeptics say &#8220;stop crying wolf&#8221; and the inside experts say &#8220;we&#8217;re Cassandras, you just wait and see.&#8221;</p>
<p>So.  How much does it cost?  Skeptical expert Bruce Schneier describes the cost as a &#8220;terrorism tax,&#8221; similar to the Cold War tax although much more directly extracted from every American&#8217;s pocketbook.</p>
<p>I myself engage in hyperbole when I say &#8220;I honestly believe the cyber-terror tax exceeds its return on investment.&#8221;  Why, then, would I let the inside experts turn on me to demand &#8220;what evidence supports your belief&#8221;?  Because I can then respond &#8220;well, you&#8217;re the only one here who can give our audience the evidence they need to disbelieve me.  But you won&#8217;t cough up any evidence for scrutiny, will you?&#8221;</p>
<p>Still, it doesn&#8217;t answer your question.  So let&#8217;s make a (somewhat invalid) comparison.  &#8220;Rob, did we spend too much on the Y2K hysteria?&#8221;  The answer is &#8220;businessmen spent the right amount, but if they spent it in fear, then they spent the right amount for the wrong reason.&#8221;  A college-level logic course will teach you that, given a chocie, you&#8217;d rather spend the wrong amount for the right reason, than spend the right amount for the wrong reason.  Terrorism of any sort is simply a matter of risk; the money you spend to mitigate it (repeat &#8220;mitigate&#8221;) is essentially an insurance bet.  (Professional poker players understand this logic as the &#8220;expected value of a hand.&#8221;  Pros would rather lose a hand for the right reason than win a hand for the wrong reason.)</p>
<p>So, the answer to your question.  The computer security industrial complex doesn&#8217;t mitigate cyber-terror in a logical manner.  We&#8217;re spending money &#8220;wrong,&#8221; and that&#8217;s not right.</p>
<p>::Should we be paying more attention to it,<br />
::not necessarily through fear mongering,<br />
::but rather through indepth and accurate<br />
::analysis and understanding?</p>
<p>Yes.  And I think the government should do it.  Sadly, their research remains highly overclassified even by the government&#8217;s own admission.</p>
<p>But it&#8217;s even worse than most experts realize, and we can expose it with a simple observation.  We know the U.S. military analyzes the attacks it gets each day &#8212; knowledge that remains completely out of reach to airmen &#038; soldiers who would use the info to defend their home networks.  It&#8217;s valid to assume major intelligence agencies both friendly (e.g. Israel) and hostile (e.g. North Korea) target the home networks of career officers &#038; sergeants who habitually take FOUO and (yes!) classified info home to work on it after duty hours.  Military analysis would at least yield a realtime blackhole list, yet the knowledge goes to waste on home networks where it would prove particularly useful.</p>
<p>I forget who once said &#8220;analysis that cannot be obtained is analysis that does not exist.&#8221;  The military&#8217;s (public) release of a realtime blackhole list would do wonders in the realm of information protection.  But they don&#8217;t release it &#8230; so it doesn&#8217;t exist for those who could benefit from it.</p>
<p>Crud.  Did I just say &#8220;we do analysis wrong&#8221;?</p>
<p>&#8230;Did I answer both of your questions, Charley?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Obama (!) spouts an urban legend in his cybersecurity speech by Charley Brown</title>
		<link>http://Vmyths.com/2009/05/29/obama/comment-page-1/#comment-502</link>
		<dc:creator>Charley Brown</dc:creator>
		<pubDate>Sat, 19 Sep 2009 15:11:01 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=656#comment-502</guid>
		<description>I probably should have read part one before parts 2 and 3 of this article, but I do have a question. You mentioned in part 2 that government intelligence officials have lacked data and appropriate computations regarding the prevalence and cost of cyber-terrorism and cyber-security. Obama, Clinton and past Presidents have used faulty intelligence information to push agendas. My question, though, is how much do you think cyber-terrorism/security affects and costs the United States annually? Should we be paying more attention to it, not necessarily through fear mongering, but rather through indepth and accurate analysis and understanding? Perhaps it is the fear mongering, but I do feel that as we progress further into a global, digital environment, there is a need for cyber-security. Do I agree with Obama and his numbers on this issue? Not at all, I feel as if its a tactic to push agenda rather than really focusing on what should be done about it. I&#039;m just curious to see how you feel about the core of the issue beyond Obama&#039;s blunder.

-Charley Brown

&lt;a href=&quot;http://www.welivethis.com/newsfeed/2009/09/13/audio-engineering-schools/&quot; rel=&quot;nofollow&quot;&gt;Audio Engineering Schools&lt;/a&gt;

&lt;a href=&quot;http://www.welivethis.com/newsfeed/category/hiphop-music/&quot; rel=&quot;nofollow&quot;&gt;Latest Hip Hop Music&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>I probably should have read part one before parts 2 and 3 of this article, but I do have a question. You mentioned in part 2 that government intelligence officials have lacked data and appropriate computations regarding the prevalence and cost of cyber-terrorism and cyber-security. Obama, Clinton and past Presidents have used faulty intelligence information to push agendas. My question, though, is how much do you think cyber-terrorism/security affects and costs the United States annually? Should we be paying more attention to it, not necessarily through fear mongering, but rather through indepth and accurate analysis and understanding? Perhaps it is the fear mongering, but I do feel that as we progress further into a global, digital environment, there is a need for cyber-security. Do I agree with Obama and his numbers on this issue? Not at all, I feel as if its a tactic to push agenda rather than really focusing on what should be done about it. I&#8217;m just curious to see how you feel about the core of the issue beyond Obama&#8217;s blunder.</p>
<p>-Charley Brown</p>
<p><a href="http://www.welivethis.com/newsfeed/2009/09/13/audio-engineering-schools/" rel="nofollow">Audio Engineering Schools</a></p>
<p><a href="http://www.welivethis.com/newsfeed/category/hiphop-music/" rel="nofollow">Latest Hip Hop Music</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Obama part 2: where did his &#8220;$1 trillion&#8221; guesstimate come from? by Charley Brown</title>
		<link>http://Vmyths.com/2009/05/29/obama-2/comment-page-1/#comment-501</link>
		<dc:creator>Charley Brown</dc:creator>
		<pubDate>Sat, 19 Sep 2009 14:45:41 +0000</pubDate>
		<guid isPermaLink="false">http://Vmyths.com/?p=697#comment-501</guid>
		<description>Although I am an Obama supporter, I can&#039;t help but say that I&#039;m not surprised. It seems as if the intelligence officials of each and every one of our past few presidents conjure up ridiculous numbers when trying to push their specific agenda. I had hoped Obama would be different, but I guess hope gets you no where.

It is really sad that after 10-15 years, our top government intelligence officials have FAILED when it comes to compiling and understand cyber-security data. One would think the government could reach out to the most intelligent cyber-security experts to compile data that can help them better understand cyber-threats and the security measures that can be take at the least expense to the public. I&#039;m not holding my breath.

-Charley Brown

&lt;a href=&quot;http://www.welivethis.com/newsfeed/2009/09/13/audio-engineering-schools/&quot; rel=&quot;nofollow&quot;&gt;Audio Engineering Schools&lt;/a&gt;

&lt;a href=&quot;http://www.welivethis.com/newsfeed/category/hiphop-music/&quot; rel=&quot;nofollow&quot;&gt;Latest Hip Hop Music&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Although I am an Obama supporter, I can&#8217;t help but say that I&#8217;m not surprised. It seems as if the intelligence officials of each and every one of our past few presidents conjure up ridiculous numbers when trying to push their specific agenda. I had hoped Obama would be different, but I guess hope gets you no where.</p>
<p>It is really sad that after 10-15 years, our top government intelligence officials have FAILED when it comes to compiling and understand cyber-security data. One would think the government could reach out to the most intelligent cyber-security experts to compile data that can help them better understand cyber-threats and the security measures that can be take at the least expense to the public. I&#8217;m not holding my breath.</p>
<p>-Charley Brown</p>
<p><a href="http://www.welivethis.com/newsfeed/2009/09/13/audio-engineering-schools/" rel="nofollow">Audio Engineering Schools</a></p>
<p><a href="http://www.welivethis.com/newsfeed/category/hiphop-music/" rel="nofollow">Latest Hip Hop Music</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
