<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aten Labs &#187; hire</title>
	<atom:link href="http://atenlabs.com/blog/tag/hire/feed/" rel="self" type="application/rss+xml" />
	<link>http://atenlabs.com/blog</link>
	<description>San Diego&#039;s Premier IT Security Consultancy</description>
	<lastBuildDate>Wed, 29 Feb 2012 19:14:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Making Security Research Relevant</title>
		<link>http://atenlabs.com/blog/making-security-research-relevant/</link>
		<comments>http://atenlabs.com/blog/making-security-research-relevant/#comments</comments>
		<pubDate>Tue, 20 Jan 2009 01:50:07 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[and]]></category>
		<category><![CDATA[be safer]]></category>
		<category><![CDATA[consulting]]></category>
		<category><![CDATA[diego]]></category>
		<category><![CDATA[for]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hire]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infrastucture]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[us]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=32</guid>
		<description><![CDATA[I&#8217;m very very open and transparent about security, technology and what I do. I&#8217;ve written documentation so thorough that my clients have ended the contracts stating &#8220;we dont need you anymore &#8211; with these docs we can do the work ourselves&#8221; &#8211; in the grander scheme of things thats awesome. I love it when clients [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m very very open and transparent about security, technology and what I do. I&#8217;ve written documentation so thorough that my clients have ended the contracts stating &#8220;we dont need you anymore &#8211; with these docs we can do the work ourselves&#8221; &#8211; in the grander scheme of things thats awesome. I love it when clients learn from me and it makes me feel really good about what I do &#8211; especially if it sticks the first time &#8211; but it certainly is prohibitive towards me paying my rent.</p>
<p>I&#8217;ve been very vocal in the last year about what I do &#8211; to the point it manifests itself as talks I give during BarCamp (LA and San Diego), and Refresh San Diego which is held at Qualcomm. Here is my most recent talk</p>
<p><center><object width="400" height="300"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2847947&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=2847947&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"></embed></object><br /><a href="http://vimeo.com/">Security 102, part 1</a> from <a href="http://vimeo.com/viss">Dan Tentler</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p><object width="400" height="300"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2879833&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=2879833&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"></embed></object><br /><a href="http://vimeo.com/">Security102, part 2</a> from <a href="http://vimeo.com/viss">Dan Tentler</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p>Video courtesy of <a href="http://twitter.com/northlight">@northlight</a></center><br />
<span id="more-32"></span><br />
Additionally, here is a talk that I&#8217;ve been doing at BarCamp San Diego that approaches security from a people perspective &#8211; meaning: If you can&#8217;t hack the systems, hack its operators. This story describes how people are willing to give away information to a<a href="http://blogs.wsj.com/biztech/2008/04/16/security-is-no-match-for-chocolate-and-good-looking-women/?mod=WSJBlog"> pretty girl who hands out chocoloate</a>. Heres my Talk:</p>
<p><center><object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="437" height="370" id="viddler"><param name="movie" value="http://www.viddler.com/player/3e908112/" /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="wmode" value="transparent"/><embed src="http://www.viddler.com/player/3e908112/" width="437" height="370" type="application/x-shockwave-flash" allowScriptAccess="always" allowFullScreen="true" wmode="transparent" name="viddler" ></embed></object><br />
Videos couresty of <a href="http://twitter.com/northlight">@northlight</a><br />
</center></p>
<p>I&#8217;ve decided that it&#8217;s in everyone&#8217;s best interests to at least have a dialog about security. That being said I&#8217;m now offering free consultations! To my amazement I&#8217;ve even had a few people turn down FREE HOURS from me. For the first time in quite a while I was literally without words.</p>
<p>I thought it best at that point to illustrate exactly what I mean by security. </p>
<ul>
<li><a href="http://twitpic.com/14u50">This</a> is a screenshot of the last ten days of SQL injection exploits posted to <a href="http://milw0rm.com">milw0rm.com</a>. This is *ONLY* SQL injections, not any other vulnerabilities (for everyone that thinks using magic_quotes_gpc is safe, <a href="http://search.twitter.com/search?max_id=1131544205&#038;page=2&#038;q=magic_quotes_gpc">think again</a> (and <a href="http://twitter.com/Viss/statuses/1077256407">again</a> and <a href="http://twitter.com/DjYXA/statuses/1050507177">again</a>)</li>
<li><a href="http://www.securityfocus.com/vista">Securityfocus</a>, which is a major vendor for security information has its own section JUST for Microsoft Vista.</li>
<li><a href="http://twitpic.com/kjgx">ONE command</a> line will give you a command shell on a vulnerable windows machine. That leads to installing malware, stealing passwords, reading emails &#8211; the whole nine yards &#8211; just like theyre sitting AT your computer, or on your server.</li>
<li><a href="http://twitpic.com/104fo">Using WEP for wireless security is a joke</a>. If you don&#8217;t use WPA you may as well not bother encrypting. That also leads to people sniffing your information out of the air &#8211; passwords, credentials, AIM/Yahoo conversations &#8211; everything.</li>
<li>The web2.0 community is just <a href="http://twitpic.com/rqzy">making things worse</a> by being willfully ignorant</li>
</ul>
<p>The point I&#8217;m trying to get across is that security isn&#8217;t just installing a virus scanner and an adware scanner and making sure your system is free of viruses. Code is developed every day that <a href="http://www.google.com/search?num=100&#038;hl=en&#038;lr=&#038;ie=ISO-8859-1&#038;q=%22supplied+argument+is+not+a+valid+MySQL+result+resource%22">exposes crucial information to the world, which is then indexed by google</a>. Security isn&#8217;t just about viruses, its about making your private information stay private &#8211; in all cases. Error messages that leak information such as filenames, database names, database tables, usernames etc just help attackers gain further entry into systems.</p>
<p>I do more than just security work &#8211; I&#8217;m a full-fledged Systems Architect with over ten years of experience in the field. Once you build a large scale enterprise environment, it has to be secured, right?<br />
Every once in a while during conversations at meetups I tell people that I&#8217;m a Security Researcher and a Systems Architect and they end up asking me later &#8220;so what do you actually DO?&#8221;. So heres a short list:</p>
<ul>
<li>Information Tecnhnology(IT) and Information Security(InfoSec) consulting: working directly with sales, marketing and PR departments to coach bloggers, twitter users and writers on what terminology to use, what new technology is out there, what is safe, what isn&#8217;t safe, figures and reports on the latest attacks, bot nets, viruses and other threats influencing the world</li>
<li>MSSQL and MySQL database administration, design, tuning, and security</li>
<li>Designing networks: switches, routers, firewalls, intrusion detection, backups, redundancy</li>
<li>Workflow Management: Setting up HRIS systems, ticketing systems, automating things like installations, software deployments, antivirus and other workstation maintenance procedures, creating a documentation repository using mediawiki</li>
<li>Emerging Technologies: Staying abreast of all new versions of software and hardware available, defining when and what to upgrade, planning upgrades, defining when and how to scale, choosing the right hardware and software for the job, identifying when to decommission old equipment or software and how execute it</li>
<li>Security: Staying abreast of all current and anticipated versions of software frameworks, firmwares, networking and phone equipment, defining what software and appliances need to be secured and or upgraded, defining what network resources get deployed where in the clients landscape and subequently documenting everything along the way</li>
</ul>
<p>There is no environment alien to me, no operating system I do not have experience with, no development/scripting language I have no experience with and there is no limit to what can be done with the proper resources.</p>
<p>The Rates for hours at AtenLabs are fiercely competitive and in our wake we leave nothing but courage, confidence, and smiling clients.</p>
<p>If you&#8217;re even thinking about contacting us for us for a free consultation &#8211; stop thinking and contact us.</p>
<p><center><a href="mailto:dan@atenlabs.com">info@atenlabs.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/making-security-research-relevant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

