<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for ShackF00</title>
	<atom:link href="http://daveshackleford.com/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://daveshackleford.com</link>
	<description>Musings on Security &#38; Other Stuff</description>
	<lastBuildDate>Thu, 16 Feb 2012 20:11:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>Comment on The Cloud&#8217;s Low-Rent District by Jason Graf</title>
		<link>http://daveshackleford.com/?p=774&#038;cpage=1#comment-3064</link>
		<dc:creator>Jason Graf</dc:creator>
		<pubDate>Thu, 16 Feb 2012 20:11:45 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=774#comment-3064</guid>
		<description>Great comments and like the analogy to the work of Tim Ferriss. As you stated so many of these CSP&#039;s start out very small and work themselves into big business. Hard to think so far ahead when you are just trying to make your rent payment and pay your employees. The risks are however very large, and anything that will encourage/motivate companies to spend some of their time and money is good. It does seem as humans and organizations that we tend to be mostly motivated by the cost of something or potential loss of business. Thanks for taking the time to put this into words.</description>
		<content:encoded><![CDATA[<p>Great comments and like the analogy to the work of Tim Ferriss. As you stated so many of these CSP&#8217;s start out very small and work themselves into big business. Hard to think so far ahead when you are just trying to make your rent payment and pay your employees. The risks are however very large, and anything that will encourage/motivate companies to spend some of their time and money is good. It does seem as humans and organizations that we tend to be mostly motivated by the cost of something or potential loss of business. Thanks for taking the time to put this into words.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Infosec: Where&#8217;s our &#8220;Long Tail&#8221;? by Lucas Samaras</title>
		<link>http://daveshackleford.com/?p=754&#038;cpage=1#comment-3049</link>
		<dc:creator>Lucas Samaras</dc:creator>
		<pubDate>Mon, 06 Feb 2012 18:22:52 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=754#comment-3049</guid>
		<description>The innovators are definitely out there, they just get dwarfed by all the noise and forgotten after they get acquired.  I&#039;m looking forward to those small booths with quirky launches like xoware, which is in the Exhibitors&#039; listing but doesn&#039;t even have a website up yet. Here&#039;s their description, let&#039;s hope their busy innovating (ahem, b/c they&#039;re definitely not marketing):

&quot;x.o.ware is building an exoskeleton for your network, which allows you to securely access it or the Internet anywhere. &quot;

Here&#039;s a quick summary of the Top Ten Finalists from the Innovation Sandbox:
http://www.marketwatch.com/story/top-10-finalists-announced-for-the-most-innovative-company-at-rsar-conference-2012-contest-2012-01-05</description>
		<content:encoded><![CDATA[<p>The innovators are definitely out there, they just get dwarfed by all the noise and forgotten after they get acquired.  I&#8217;m looking forward to those small booths with quirky launches like xoware, which is in the Exhibitors&#8217; listing but doesn&#8217;t even have a website up yet. Here&#8217;s their description, let&#8217;s hope their busy innovating (ahem, b/c they&#8217;re definitely not marketing):</p>
<p>&#8220;x.o.ware is building an exoskeleton for your network, which allows you to securely access it or the Internet anywhere. &#8221;</p>
<p>Here&#8217;s a quick summary of the Top Ten Finalists from the Innovation Sandbox:<br />
<a href="http://www.marketwatch.com/story/top-10-finalists-announced-for-the-most-innovative-company-at-rsar-conference-2012-contest-2012-01-05" rel="nofollow">http://www.marketwatch.com/story/top-10-finalists-announced-for-the-most-innovative-company-at-rsar-conference-2012-contest-2012-01-05</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by Does Offensive Security Really Exist? &#124; 安全业界观察</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2872</link>
		<dc:creator>Does Offensive Security Really Exist? &#124; 安全业界观察</dc:creator>
		<pubDate>Tue, 15 Nov 2011 22:26:47 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2872</guid>
		<description>[...] had some great commentary and discussion on my last post, “Doom, Gloom, and Infosec“. Jericho rightly pointed out the ever-popular Charlatans page at Attrition. This, could , most [...]</description>
		<content:encoded><![CDATA[<p>[...] had some great commentary and discussion on my last post, “Doom, Gloom, and Infosec“. Jericho rightly pointed out the ever-popular Charlatans page at Attrition. This, could , most [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by Open Tabs 11/11/11 &#124; 安全业界观察</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2861</link>
		<dc:creator>Open Tabs 11/11/11 &#124; 安全业界观察</dc:creator>
		<pubDate>Fri, 11 Nov 2011 16:07:34 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2861</guid>
		<description>[...] Doom, gloom and infosec – Of course our career field isn’t all feces and stench, but it’s not roses and cake either.   [...]</description>
		<content:encoded><![CDATA[<p>[...] Doom, gloom and infosec – Of course our career field isn’t all feces and stench, but it’s not roses and cake either.   [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by Network Security Blog &#187; Open Tabs 11/11/11</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2860</link>
		<dc:creator>Network Security Blog &#187; Open Tabs 11/11/11</dc:creator>
		<pubDate>Fri, 11 Nov 2011 14:04:05 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2860</guid>
		<description>[...] Doom, gloom and infosec &#8211; Of course our career field isn&#8217;t all feces and stench, but it&#8217;s not roses and cake either.&#160;&#160; [...]</description>
		<content:encoded><![CDATA[<p>[...] Doom, gloom and infosec &#8211; Of course our career field isn&#8217;t all feces and stench, but it&#8217;s not roses and cake either.&nbsp;&nbsp; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by Davienthemoose</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2858</link>
		<dc:creator>Davienthemoose</dc:creator>
		<pubDate>Fri, 11 Nov 2011 04:05:46 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2858</guid>
		<description>I think saying &quot;people don&#039;t listen&quot; is an oversimplification.

It&#039;s not that people don&#039;t listen; it&#039;s that many orgs say &quot;Go make us secure!&quot; an then say &quot;Don&#039;t do that!&quot; to most, if not all of the things that infosec pros know will fullfill that goal. And it&#039;s not a difference of communication or a misalignment of priority; it&#039;s a fundamental difference in culture between infosec pros and those who pay for infosec pros. Infosec pros want to do the right thing; everyone else wants to do whatever they want and have all those inconvenient requirements just leave them alone.

The burnout comes from knowing what is wrong, feeling responsible for it, and being told not to do anything about it (but say you are).

Defense does suck. We spend more time fighting with our own side to get the right tools, the right training, the right policies, the right backing, an the right people to have a chance at fighting &quot;the bad guys&quot; than we do actually doing the job we were hired to do.</description>
		<content:encoded><![CDATA[<p>I think saying &#8220;people don&#8217;t listen&#8221; is an oversimplification.</p>
<p>It&#8217;s not that people don&#8217;t listen; it&#8217;s that many orgs say &#8220;Go make us secure!&#8221; an then say &#8220;Don&#8217;t do that!&#8221; to most, if not all of the things that infosec pros know will fullfill that goal. And it&#8217;s not a difference of communication or a misalignment of priority; it&#8217;s a fundamental difference in culture between infosec pros and those who pay for infosec pros. Infosec pros want to do the right thing; everyone else wants to do whatever they want and have all those inconvenient requirements just leave them alone.</p>
<p>The burnout comes from knowing what is wrong, feeling responsible for it, and being told not to do anything about it (but say you are).</p>
<p>Defense does suck. We spend more time fighting with our own side to get the right tools, the right training, the right policies, the right backing, an the right people to have a chance at fighting &#8220;the bad guys&#8221; than we do actually doing the job we were hired to do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by Episode 519 &#8211; Infosec Whiners, Rogue Risk Manager, Steve Was Right, Comcast’s Native IPv6 and 5 iOS Tips &#124; InfoSec Daily</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2857</link>
		<dc:creator>Episode 519 &#8211; Infosec Whiners, Rogue Risk Manager, Steve Was Right, Comcast’s Native IPv6 and 5 iOS Tips &#124; InfoSec Daily</dc:creator>
		<pubDate>Fri, 11 Nov 2011 01:51:40 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2857</guid>
		<description>[...] Source:http://daveshackleford.com/?p=689 [...]</description>
		<content:encoded><![CDATA[<p>[...] Source:<a href="http://daveshackleford.com/?p=689" rel="nofollow">http://daveshackleford.com/?p=689</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by @451wendy</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2856</link>
		<dc:creator>@451wendy</dc:creator>
		<pubDate>Thu, 10 Nov 2011 15:33:13 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2856</guid>
		<description>Your assertion that &quot;infosec is not a calling&quot; is going to prompt a lot of discussion, I think. :-)

Those folks whose self-identity is based on rescuing or saving others are going to internalize infosec; they can&#039;t help it.  And because of all the roadblocks you mention, they&#039;ll find a never-ending supply of windmills, but will very rarely be able to rest on victories.  Maybe it&#039;s that combination that leads to stress and unhappiness.

For that matter, if you have a need to &quot;win&quot; and you can&#039;t win at infosec, then at least you can &quot;win&quot; over your fellow infosec practitioners.  Which explains a lot of the rest of the debates. ;-)</description>
		<content:encoded><![CDATA[<p>Your assertion that &#8220;infosec is not a calling&#8221; is going to prompt a lot of discussion, I think. <img src='http://daveshackleford.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Those folks whose self-identity is based on rescuing or saving others are going to internalize infosec; they can&#8217;t help it.  And because of all the roadblocks you mention, they&#8217;ll find a never-ending supply of windmills, but will very rarely be able to rest on victories.  Maybe it&#8217;s that combination that leads to stress and unhappiness.</p>
<p>For that matter, if you have a need to &#8220;win&#8221; and you can&#8217;t win at infosec, then at least you can &#8220;win&#8221; over your fellow infosec practitioners.  Which explains a lot of the rest of the debates. <img src='http://daveshackleford.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by jericho</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2855</link>
		<dc:creator>jericho</dc:creator>
		<pubDate>Thu, 10 Nov 2011 09:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2855</guid>
		<description>attrition.org/errata would be a great reason &#039;infosec sucks&#039; and would surely explain burnout for attrition staff.</description>
		<content:encoded><![CDATA[<p>attrition.org/errata would be a great reason &#8216;infosec sucks&#8217; and would surely explain burnout for attrition staff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Doom, Gloom, and Infosec by J4vv4D</title>
		<link>http://daveshackleford.com/?p=689&#038;cpage=1#comment-2853</link>
		<dc:creator>J4vv4D</dc:creator>
		<pubDate>Wed, 09 Nov 2011 15:59:37 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=689#comment-2853</guid>
		<description>Spot on Dave... now this is what I&#039;m talking about.

You&#039;re absolutely right. We&#039;ve got so many great things going for us in the industry. You can choose to delve into the depths of technology, coding, exploits or go for a wider risk path. There are also so many great people to meet, network with and learn from. Which is probably why there are so many rocking conferences around. We have people who are genuinely excited and passionate about their chosen field of work... and that alone is worth a smile a day :)</description>
		<content:encoded><![CDATA[<p>Spot on Dave&#8230; now this is what I&#8217;m talking about.</p>
<p>You&#8217;re absolutely right. We&#8217;ve got so many great things going for us in the industry. You can choose to delve into the depths of technology, coding, exploits or go for a wider risk path. There are also so many great people to meet, network with and learn from. Which is probably why there are so many rocking conferences around. We have people who are genuinely excited and passionate about their chosen field of work&#8230; and that alone is worth a smile a day <img src='http://daveshackleford.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

