<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.11.81 (http://www.squarespace.com/) on Thu, 16 Feb 2012 02:08:55 GMT--><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:rss="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:cc="http://web.resource.org/cc/"><rss:channel rdf:about="http://jimmyblake.com/blog/"><rss:title>Blog</rss:title><rss:link>http://jimmyblake.com/blog/</rss:link><rss:description></rss:description><dc:language>en-GB</dc:language><dc:date>2012-02-16T02:08:55Z</dc:date><admin:generatorAgent rdf:resource="http://www.squarespace.com/">Squarespace Site Server v5.11.81 (http://www.squarespace.com/)</admin:generatorAgent><rss:items><rdf:Seq><rdf:li rdf:resource="http://jimmyblake.com/blog/2012/2/15/my-interview-about-b-sides-london-and-the-venue-for-2012.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/11/16/vote-wim-remes-for-isc2-board.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/7/14/issa-cisos-den.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/4/28/ubuntu-1104-natty-narwhal-released.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/4/24/it-security-vendor-presentations-for-dummies.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/4/24/iphonetracker-visualise-iphone-geolocation-data.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/4/22/security-ymca-b-sides-london-closing-session.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/4/20/b-sides-london-presentation-cloud-computing-due-diligence-wt.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/3/12/talk-security-b-sides-london-20-april-2011.html"/><rdf:li rdf:resource="http://jimmyblake.com/blog/2011/1/17/fosdem-2011.html"/></rdf:Seq></rss:items></rss:channel><rss:item rdf:about="http://jimmyblake.com/blog/2012/2/15/my-interview-about-b-sides-london-and-the-venue-for-2012.html"><rss:title>My interview about B-Sides London and the venue for 2012</rss:title><rss:link>http://jimmyblake.com/blog/2012/2/15/my-interview-about-b-sides-london-and-the-venue-for-2012.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2012-02-15T14:08:48Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p><iframe width="560" height="315" src="http://www.youtube.com/embed/VdxwuXqDa-s" frameborder="0" allowfullscreen></iframe></p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/11/16/vote-wim-remes-for-isc2-board.html"><rss:title>Vote Wim Remes for ISC(2) Board</rss:title><rss:link>http://jimmyblake.com/blog/2011/11/16/vote-wim-remes-for-isc2-board.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-11-16T06:49:56Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>if you hold a CISSP certification please take the time to read Wim Remes' manifesto for change. I fully support his proposed changes, and I encourage everyone to vote for him in the elections that start today.
<p>&nbsp;</p>
<p><a href="http://t.co/wrfRunPI">Vote for Wim on the ISC(2) site here</a>;
<p>&nbsp;</p>
<p>For convenience I've enclosed details from Wim's site below:
<p>&nbsp;</p>
<p>"On August 19th I received the yearly e-mail from (ISC)2 where they informed me of their yearly board elections that will take place as from November 16th.
<p>&nbsp;</p>
<p>While I respect everyone currently slated for the ballot, I always cringe a little when I look back of yet another year where the divide between what I consider the infosec community of which I am a vocal participant and the institution ISC2 has become. I could spend another year on the sideline watching the gap grow bigger OR I can try and BE the change that A LOT of my online and real life friends are waiting for.
<p>&nbsp;</p>
<p>This is my official petition page to have my name added to the election ballot on November 16th.
<p>&nbsp;</p>
<p>If I&rsquo;m to become a member of the (ISC)2 Board of Directors I will strive to do the following in the three years that I will be given the opportunity to be the change you are all looking for:
<p>&nbsp;</p>
<p>
<p>
<p>
<p>
<p>
<p>
<ul>
<li>A closer collaboration with the information security community at large. This means recognition of what is currently considered to be an outlawish community but what I consider as a treasure trove of knowledge and capability that remains untapped. Either because we are afraid of what we don&rsquo;t understand or because hackers are still suffering from a bad image. Not in my book!</li>
<li>A review of the certification requirements for the flagship (ISC)2 certification, the CISSP, in order to bring it back to the level it once was on. Ideally with the incorporation of more in-depth requirements on a technical level, requirements in soft skills and, possibly, the addition of a written paper requirement that would show the knowledge the candidate has acquired during the learning process. This last requirement would feedback into the community becoming a valuable resource for security professionals globally.</li>
<li>I am from Europe. I still feel that many of the subject covered by (ISC)2 and other organizations are focused on the US. My goal is to widen the efforts to a global approach that brings communities from different continents together instead of seperating them further. While there is a different in laws, culture, etc. across continents, I firmly belief that we have more in common and there needs to be a better collaboration<br />in order to address the security challenges we have coming at us.</li>
<li>With my work on the&nbsp;<a href="http://www.pentest-standard.org">Penetration Testing Execution Standard (PTES)</a>, <a href="http://www.infosecmentors.com">Infosec Mentors</a>, <a href="http://www.brucon.org">Brucon</a>, <a href="http://www.eurotrashsecurity.eu">Eurotrash Security Podcast</a> and other global initiatives I want to encourage the members of (ISC)2 tobecome a part of the community that I consider so valuable.&nbsp;</li>
</ul>
<p>
<p>
<p><strong>About Me</strong>
<p>&nbsp;
<p>This is not about me but apparently I need some kind of bio. I am Wim Remes (CISSP ), working in IT for 14 years now and passionate about security for over 10 of those. I have not graduated from any posh university but who cares right? I&rsquo;m currently working for a Big4 company in Belgium as a Security Consultant. I will add extra information to my bid page as soon as possible.<br />In the mean time, please take the time to send me that e-mail and spread the link to this page as wide and as deep as possible. I need 500 signatures to my petition before September 19th. If you want passion on the (ISC)2 Board of Directors, you know what to do!</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>
</p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/7/14/issa-cisos-den.html"><rss:title>ISSA CISO's Den</rss:title><rss:link>http://jimmyblake.com/blog/2011/7/14/issa-cisos-den.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-07-14T11:19:05Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>I attended the CISO's Den event today on HMS President on the River Thames, organised by the London Information Systems Security Association (ISSA) Chapter.</p><p>The event was excellent, despite me having the unique experience of being slightly seasick while watching vendor pitches (normally vendor presentations, on their own, make me feel sick).  HMS President originally put to sea in 1917, way before air conditioning.  Having 100s of CISOs in suits in a big tin box in a very hot day </p><p>The presentations were limited to 10 minutes, which really separated the men from the boys.  </p><p>A couple of presentations stood out for me: Wave's empassioned  plea for us to use the Trusted Platform Module functionality built into many of our systems - "its there already, just try it"; and Sophos' very concise view of commoditisation of IT and productisation of malware.   Other presentations included Web-application security, discovery of I appropriately shared documents, an MSSP and vulnerability assessment,</p><p>Splunk laid into the SIEM space saying relational databases and normalisation limits the usefulness.  Not sure I agree that there is validity in a  Log Management vs. SIEM argument, they are both needed but each perform different function.  It's all well and good saying dump everything in a unstructured repository, but normalisation and correlation are required to stop your SOC drowning under the sheer volume of events.</p><p>The Tripwire Sales Engineer's presentation was then quite bitchy about Splunk, quoting their relative positions on the Gartner quadrant and saying knowing that an event has happened is pointless without knowing what has changed (impact).</p><p>Ironically both Tripware and Splunk were trying to prove credibility, not by the amount of enterprise customers they each have, but rather around the amount of commodity systems they're logging - car park barriers, ticket machines, etc.</p><p>Another classic line of the day was the MSSP saying "all our analysts are CISSP and GCIH certified, if you don't know what that means, it means they know what they're talking about" - this made me spit my drink out over my shirt.</p><p><br /></p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/4/28/ubuntu-1104-natty-narwhal-released.html"><rss:title>Ubuntu 11.04 Natty Narwhal Released</rss:title><rss:link>http://jimmyblake.com/blog/2011/4/28/ubuntu-1104-natty-narwhal-released.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-04-28T15:15:50Z</dc:date><dc:subject>BackTrack Linux Open Source Ubuntu</dc:subject><content:encoded><![CDATA[<p>Today sees the release of Ubuntu's latest version of their linux distribution, 11.04 codenamed Natty Narwhal. &nbsp;Until Canonical head-huncho Mark Shuttleworth <a href="http://www.markshuttleworth.com/archives/478">announced the codename of this release last August</a>, I had been blissfully unaware of what a narwhal was, it seems it is a type of arctic whale.</p>
<p>I had used 11.04 in both Alpha 1, although 'use' in this context is a very loose term as it was an alpha release, and Beta 2. &nbsp;Beta 2 only came out recently and didn't seem&nbsp;quite baked so I am curious as to how stable and finished the release is.</p>
<p>I don't normally drop new Ubuntu releases onto my production boxes as they normally break a lot of the security tools I use (the upcoming release of BackTrack 5 is based on Ubuntu 10.04, which is now a year old), so I'll be sticking with 10.10 for a while on those machines. &nbsp;I have, however, got it running over a virtual machine on my main MacBook Pro and I am going to try and work out which tools will run on it and which won't.</p>
<p>What I am really looking forward to is BackTrack 5 <a href="http://www.backtrack-linux.org/backtrack/backtrack-5-release-tool-suggestions/">whose release is only a couple of weeks away</a>. &nbsp;They will now be supporting both 32-bit and 64-bit and have changed the menu layout to follow the testing methodologies of OSSTMM and PTES.</p>
<p>Ubuntu 11.04 can be downloaded from the <a href="http://www.ubuntu.com/download">Ubuntu Downloads Page</a>.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/4/24/it-security-vendor-presentations-for-dummies.html"><rss:title>IT Security Vendor Presentations for Dummies</rss:title><rss:link>http://jimmyblake.com/blog/2011/4/24/it-security-vendor-presentations-for-dummies.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-04-24T21:22:22Z</dc:date><dc:subject>Amusing Infosec humour presentation skills</dc:subject><content:encoded><![CDATA[I found this highly amusing tongue-in-cheek look at IT security vendor's presentations:

<div class="prezi-player"><style type="text/css" media="screen">.prezi-player { width: 400px; } .prezi-player-links { text-align: center; }</style><object id="prezi_2dor-emhawja" name="prezi_2dor-emhawja" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="400" height="400"><param name="movie" value="http://prezi.com/bin/preziloader.swf"/><param name="allowfullscreen" value="true"/><param name="allowscriptaccess" value="always"/><param name="bgcolor" value="#ffffff"/><param name="flashvars" value="prezi_id=2dor-emhawja&amp;lock_to_path=0&amp;color=ffffff&amp;autoplay=no&amp;autohide_ctrls=0"/><embed id="preziEmbed_2dor-emhawja" name="preziEmbed_2dor-emhawja" src="http://prezi.com/bin/preziloader.swf" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="400" bgcolor="#ffffff" flashvars="prezi_id=2dor-emhawja&amp;lock_to_path=0&amp;color=ffffff&amp;autoplay=no&amp;autohide_ctrls=0"></embed></object><div class="prezi-player-links"><p><a title="" href="http://prezi.com/2dor-emhawja/itsec-vendor-presentation-for-dummies/">ITSEC vendor presentation for dummies</a> on <a href="http://prezi.com">Prezi</a></p></div></div>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/4/24/iphonetracker-visualise-iphone-geolocation-data.html"><rss:title>iPhoneTracker: Visualise iPhone Geolocation Data</rss:title><rss:link>http://jimmyblake.com/blog/2011/4/24/iphonetracker-visualise-iphone-geolocation-data.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-04-24T07:43:51Z</dc:date><dc:subject>Infosec Privacy geolocation iOS iPad iPhone</dc:subject><content:encoded><![CDATA[<p>There have been several stories in the tech and mainstream press over the past couple of weeks about the fact that the iPhone and iPad records historical geolocation data. &nbsp;</p>
<p>I initially put down the story to the usual hysteria of the press and their Schadenfreude desire&nbsp;to pursue any story that reflects the iPhone in a bad light. &nbsp;Then I came across the <a href="http://petewarden.github.com/iPhoneTracker/">iPhoneTracker application from Peter Warden and Alasdair Allan</a>. &nbsp;This application takes a copy of the raw geolocation data file, which is backed up to your Mac the first time you sync every day and then plots the locations within the given timeframe on an Open Street Maps map.</p>
<p>Here is my resulting map - note the large blobs in Belgium and the Netherlands ;)</p>
<p><span class="full-image-block ssNonEditable"><span><img src="http://jimmyblake.com/storage/iPhoneTracker.png?__SQUARESPACE_CACHEVERSION=1303631872132" alt="" /></span></span></p>
<p>I'm pleased to say that I seem to have covered more of the UK that a lot of journos, but seeing my movements for the past year plotted out is actually quite scary.</p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/4/22/security-ymca-b-sides-london-closing-session.html"><rss:title>Security YMCA: B-Sides London Closing Session</rss:title><rss:link>http://jimmyblake.com/blog/2011/4/22/security-ymca-b-sides-london-closing-session.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-04-22T11:55:20Z</dc:date><dc:subject>Infosec Security B-Sides London YMCA camp</dc:subject><content:encoded><![CDATA[The rockstars of information security closed out our first Security B-Sides London with an informative session on the need to eliminate silos between security and developers, oh and then they dressed as gay icons and sang...<P><BR>

<iframe title="YouTube video player" width="480" height="390" src="http://www.youtube.com/embed/fvRs1Uw9hkY" frameborder="0" allowfullscreen></iframe><P><BR>

<B>Thanks to the B-Sides Village People:</B><P>
<UL>
<LI>TheSuggmeister (<a href="http://twitter.com/#!/TheSuggmeister">@TheSuggmeister</a>)</LI>
<LI>Frank Breedijk (<a href="http://twitter.com/#!/seccubus">@seccubus</a>)</LI>
<LI>Arron "finux" Finnon (<a href="http://twitter.com/#!/f1nux">@f1nux</a>)</LI>
<LI>Chris John Riley (<a href="http://twitter.com/#!/ChrisJohnRiley">@ChrisJohnRiley</a>)</LI>
<LI>Matt Summers (<a href="http://twitter.com/#!/dive_monkey">@dive_monkey</a>)</LI>
<LI>Tom Mackenzie (<a href="http://twitter.com/#!/tmacuk">@tmacuk</a>) provides backing vocals at one stage too</LI>
</UL>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/4/20/b-sides-london-presentation-cloud-computing-due-diligence-wt.html"><rss:title>B-Sides London Presentation: Cloud Computing Due Diligence WTF</rss:title><rss:link>http://jimmyblake.com/blog/2011/4/20/b-sides-london-presentation-cloud-computing-due-diligence-wt.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-04-20T10:53:53Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>The first UK London B-Sides is going stunningly well and&nbsp;I've just finished my presentation.</p>
<p><A HREF="http://jimmyblake.squarespace.com/storage/Cloud%20%20Conputing%20Due%20Diligence%20WTF%202.pdf" />Download my presentation</A></p>
<p>&nbsp;</p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/3/12/talk-security-b-sides-london-20-april-2011.html"><rss:title>Talk @ Security B-Sides London 20 April 2011</rss:title><rss:link>http://jimmyblake.com/blog/2011/3/12/talk-security-b-sides-london-20-april-2011.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-03-12T08:18:35Z</dc:date><dc:subject>Cloud Computing Infosec</dc:subject><content:encoded><![CDATA[<p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://jimmyblake.com/blog/2011/1/17/fosdem-2011.html"><rss:title>FOSDEM 2011</rss:title><rss:link>http://jimmyblake.com/blog/2011/1/17/fosdem-2011.html</rss:link><dc:creator>Jimmy Blake</dc:creator><dc:date>2011-01-17T11:10:52Z</dc:date><dc:subject>Geek Culture Infosec Open Source</dc:subject><content:encoded><![CDATA[<p></p>]]></content:encoded></rss:item></rdf:RDF>
