<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>ICMPECHO &#187; 2008 &#187; April</title>
	<atom:link href="http://www.icmpecho.com/2008/04/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.icmpecho.com</link>
	<description>More than your usual type 8's</description>
	<pubDate>Thu, 20 Nov 2008 00:53:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<item>
		<title>Semi-good news</title>
		<link>http://www.icmpecho.com/2008/04/03/semi-good-news/</link>
		<comments>http://www.icmpecho.com/2008/04/03/semi-good-news/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 00:26:12 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[vista]]></category>

		<category><![CDATA[end-of-life]]></category>

		<category><![CDATA[EOL]]></category>

		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=36</guid>
		<description><![CDATA[Microsoft has let the expiration date on Windows XP slip a little further, but unfortunately only for OEM&#8217;s on cheap/weak computers.
More at The Register.
My feeling is that Microsoft is slipping in a lot of areas right now and alternatives are being examined where there is possibility to do so.
Vista is/was probably a big mistake, and [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has let the expiration date on Windows XP slip a little further, but unfortunately only for OEM&#8217;s on cheap/weak computers.</p>
<p>More at <a href="http://www.theregister.co.uk/2008/04/03/microsoft_extends_xp_shelf_date_for_ulcpcs/">The Register</a>.</p>
<p>My feeling is that Microsoft is slipping in <a href="http://www.pcworld.com/businesscenter/article/143903/is_microsoft_losing_credibility.html">a lot of areas right now</a> and <a href="http://www.macobserver.com/article/2007/03/07.7.shtml">alternatives are being examined where there is possibility to do so</a>.</p>
<p>Vista is/was probably a big mistake, and key features are being turned off in a lot of larger environments for the sake of compatibility with older applications. </p>
<p>The problems companies are facing with this operating system is not very far from what they would be facing if switching to an open source solution as many components need to be rewritten in whole.</p>
<p>The world is changing and there are alternatives to resource-hogging and expensive software. You wanna stay in the game? <strong>Then get with it.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/04/03/semi-good-news/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WP 2.5 - cleanest admin interface so far&#8230;</title>
		<link>http://www.icmpecho.com/2008/04/01/wp-25-cleanest-admin-interface-so-far/</link>
		<comments>http://www.icmpecho.com/2008/04/01/wp-25-cleanest-admin-interface-so-far/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 00:25:16 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[misc]]></category>

		<category><![CDATA[2.5]]></category>

		<category><![CDATA[upgrade]]></category>

		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=35</guid>
		<description><![CDATA[Was lagging 3 days on my Wordpress upgrade and just upgraded.
Credits to WP for the new clean admin interface. Very easy to get used to.
G&#8217;night!
]]></description>
			<content:encoded><![CDATA[<p>Was lagging 3 days on my <a href="http://www.wordpress.org">Wordpress</a> upgrade and just upgraded.</p>
<p>Credits to <a href="http://www.wordpress.org">WP</a> for the new clean admin interface. Very easy to get used to.</p>
<p>G&#8217;night!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/04/01/wp-25-cleanest-admin-interface-so-far/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The most disregarded aspect of AV testing,</title>
		<link>http://www.icmpecho.com/2008/04/01/the-most-disregarded-aspect-of-av-testing/</link>
		<comments>http://www.icmpecho.com/2008/04/01/the-most-disregarded-aspect-of-av-testing/#comments</comments>
		<pubDate>Tue, 01 Apr 2008 23:59:50 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[networking]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[work]]></category>

		<category><![CDATA[anti-malware]]></category>

		<category><![CDATA[anti-virus]]></category>

		<category><![CDATA[management suites]]></category>

		<category><![CDATA[protection]]></category>

		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/2008/04/01/the-most-disregarded-aspect-of-av-testing/</guid>
		<description><![CDATA[is without doubt the hands-on management aspects of the whole suites.
Every month I read news, blogs and press releases from both vendors and independents on detection effectiveness. Sometimes these news are about the accuracy of the vendors signatures, sometimes about the files the sig&#8217;s missed, sometimes it&#8217;s about the vendors brand new and shining behavioural [...]]]></description>
			<content:encoded><![CDATA[<p>is without doubt the hands-on <strong>management aspects of the whole suites</strong>.</p>
<p><strong>Every month I read news, blogs and press releases</strong> from both vendors and independents on detection effectiveness. Sometimes these news are about the accuracy of the vendors signatures, sometimes about the files the sig&#8217;s missed, sometimes it&#8217;s about the vendors brand new and shining behavioural analysis engines. But it is almost never about the technical management features of the products. What eventually makes the news in this aspect is either the new administration consoles that pop up every two to three years or if something fail in a spectacular fashion.</p>
<p>That kind of information is not really as newsworthy as a remedy to the latest threat, but one thing is for sure and that is that it doesn&#8217;t matter how good the detection ratios are if the client protections remain <strong>unmanaged, defunct or unlicensed</strong>.</p>
<p><strong>Most of the time this is not a problem in larger networks</strong> where the appropriate funds and technical resources has been allocated, but if reviewing smaller companies or organizations (<500, sometimes larger) without dedicated security management you will often find problems. </p>
<p>The problems range from client communication malfunctions to management servers dropping dead for no particular reason. Often, these issues requires human interaction to resolve and this in turn increases the IT-services overhead. Sometimes this happens with our (Panda Security's) solutions and sometimes some other vendors (I consult for another company in the PCM Group and meet a lot of different environments).</p>
<p><strong>I&#8217;m not saying this is the AV vendors fault,</strong> as it often turns out to be erroneous customer configurations and/or secondary system malfunctions (thank you Microsoft for your most excellent AD/DHCP/DNS solutions, thank you). </p>
<p><strong>My point is that these problems, from a software point of view, should be a calculable risk.</strong></p>
<p><strong>People</strong> will make mistakes. <strong>People</strong> will be incompetent. <strong>People</strong> will be lazy. <strong>People</strong> will &#8220;install and forget&#8221;. <strong>People</strong> will be <strong>People</strong>. And we should be better at understanding and counteracting these factors.</p>
<p><strong>The latest versions</strong> of Panda AdminSecure has some of this in functions that repair failing client protections automatically, but it surely is not enough. <strong>People should not be able to</strong> set permissions or deactivate polices that might be a danger to the protection functioning without some serious alarm bells going off. <strong>People should not be able to</strong> setup firewall policies that cripple the communication required and by that degrading the level of protection without the central management consoles showing large red flashing screens. If something is done by a Microsoft patch which might or do disrupt the correct functioning of any server components, <strong>the management tools should be able to tell the administrators this in a reliable fashion.</strong></p>
<p><strong>Surely</strong> there are those that think that this is complete bullshit and have the <em>&#8220;if they&#8217;re morons and fail, plz let them burn&#8221;</em> attitude. <strong>These people are ignorant</strong> of the overall picture and do not understand the underlying problem.</p>
<p>If there were no unprotected (not installed or malfunctioning protection) clients, there is a much smaller market for &#8220;corporate&#8221; malware creation. One effect of this is less money for the bad guys. Less money for the bad guys means they have less money to spend on maintaining developing new malware.</p>
<p>And of course, <strong>Less malware development => good for all</strong>.</p>
<p>In conclusion, </p>
<p><strong>Security systems is all about reliability. How come AV&#8217;s are lagging on this particular point?</strong> </p>
<p>Users and less experienced technicians are unpredictable, but how hard can it be? We have built engines that can detect hostile code based on behavior, why not do the same to the admins <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/04/01/the-most-disregarded-aspect-of-av-testing/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
