<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-14277984</id><updated>2009-11-15T11:54:36.413-02:00</updated><title type='text'>Gbitten</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default?start-index=26&amp;max-results=25'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>265</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-14277984.post-1140566458974937006</id><published>2009-10-24T05:13:00.020-02:00</published><updated>2009-10-26T22:51:07.312-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'>WGA: um abuso com o consumidor e um absurdo para a segurança</title><content type='html'>Tentei instalar uma &lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=pt-br&amp;FamilyID=06739ca6-7368-4acb-bb67-7e8146071a29"&gt;atualização de segurança&lt;/a&gt; hoje. Mas a Microsoft não me permite fazer o download da atualização sem que o Windows Genuine Advantage (WGA) esteja instalado. O &lt;a href="http://www.microsoft.com/genuine/downloads/FAQ.aspx?displaylang=pt-br#ID0EMEAC"&gt;FAQ do WGA&lt;/a&gt; diz o seguinte:
&lt;blockquote&gt;&lt;span style="font-weight:bold;"&gt;P:&lt;/span&gt; As atualizações de segurança exigem validação?&lt;BR&gt;
&lt;span style="font-weight:bold;"&gt;R:&lt;/span&gt; As atualizações de segurança não fazem parte do WGA ou do OGA. Você pode instalar atualizações de segurança com o recurso Atualizações Automáticas do Windows &lt;span style="font-weight:bold;"&gt;ou baixá-las do Centro de Download&lt;/span&gt;.&lt;/blockquote&gt;
Mentira! Não há como abaixar a atualização que apontei acima. Em resumo, sempre me recusei a instalar o WGA simplesmente por que ele não me agrega nenhum benefício. Agora, a Microsoft me nega a possibilidade de realizar uma atualização de segurança importante. Me sinto ultrajado.&lt;br&gt;&lt;br&gt;
Em tempo, meu Windows não é pirata, eu pagei à Microsoft por ele.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-1140566458974937006?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/1140566458974937006/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=1140566458974937006&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/1140566458974937006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/1140566458974937006'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2009/10/wga-e-um-abuso-com-o-consumidor-e-um.html' title='WGA: um abuso com o consumidor e um absurdo para a segurança'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-6223399927022215191</id><published>2009-10-12T18:26:00.013-03:00</published><updated>2009-10-12T21:04:18.090-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Controle'/><category scheme='http://www.blogger.com/atom/ns#' term='Backup'/><title type='text'>Um backupzinho vez em quando é bom</title><content type='html'>Nesta nota, a T-Mobile e a Microsoft praticamente não deixam esperança de recuperação dos dados dos clientes no serviço T-Mobile Sidekick. É impressionante como as organizações continuam a não implementar, ou implementam de forma deficiente, controles para mitigação de riscos básicos porem de grande impacto. Neste caso específico, aparentemente faltou &lt;a href="http://blogs.computerworld.com/14893/microsoft_kills_the_sidekick_the_first_smart_phone_is_dead"&gt;gestão de mudança&lt;/a&gt; e &lt;a href="http://www.engadget.com/2009/10/11/sidekick-failure-rumors-point-fingers-at-outsourcing-lack-of-ba/"&gt;backup&lt;/a&gt;.
&lt;blockquote&gt;&lt;span style="font-weight:bold;"&gt;DEAR&lt;/span&gt; valued T-Mobile Sidekick customers:&lt;br&gt;&lt;br&gt;

T-Mobile and the Sidekick data services provider, Danger, a subsidiary of Microsoft, are reaching out to express our apologies regarding the recent Sidekick data service disruption. We appreciate your patience as Microsoft/Danger continues to work on maintaining platform stability, and restoring all services for our Sidekick customers.&lt;br&gt;&lt;br&gt;

Regrettably, based on Microsoft/Danger’s latest recovery assessment of their systems, we must now inform you that &lt;span style="font-weight:bold;"&gt;personal information stored on your device – such as contacts, calendar entries, to-do lists or photos – that is no longer on your Sidekick almost certainly has been lost&lt;/span&gt; as a result of a server failure at Microsoft/Danger. That said, our teams continue to work around-the-clock in hopes of discovering some way to recover this information. However, the likelihood of a successful outcome is extremely low. As such, we wanted to share this news with you and offer some tips and suggestions to help you rebuild your personal content. You can find these tips at the T-Mobile Sidekick Forums (http://www.t-mobile.com/sidekick ). We encourage you to visit the Forums on a regular basis to access the latest updates as well as FAQs regarding this service disruption.&lt;br&gt;&lt;br&gt;

In addition, we plan to communicate with you on Monday (Oct. 12) the status of the remaining issues caused by the service disruption, including the data recovery efforts and the Download Catalog restoration which we are continuing to resolve. We also will communicate any additional tips or suggestions that may help in restoring your content.&lt;br&gt;&lt;br&gt;

We recognize the magnitude of this inconvenience. Our primary efforts have been focused on restoring our customers’ personal content. We also are considering additional measures for those of you who have lost your content to help reinforce how valuable you are as a T-Mobile customer.&lt;br&gt;&lt;br&gt;

We continue to advise customers to NOT reset their device by removing the battery or letting their battery drain completely, as any personal content that currently resides on your device will be lost.&lt;br&gt;&lt;br&gt;

Once again, T-Mobile and Microsoft/Danger regret any and all inconvenience this matter has caused.&lt;/blockquote&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.sidekick.com/"&gt;http://www.sidekick.com/&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-6223399927022215191?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/6223399927022215191/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=6223399927022215191&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6223399927022215191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6223399927022215191'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2009/10/um-backupzinho-vez-em-quando-e-bom.html' title='Um backupzinho vez em quando é bom'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-4478300683504890894</id><published>2009-09-09T23:36:00.003-03:00</published><updated>2009-10-12T11:26:19.358-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>Por que não se pensou nisso antes?</title><content type='html'>&lt;ul style="FONT-WEIGHT: bold"&gt;&lt;li&gt;&lt;a href="https://developer.mozilla.org/devnews/index.php/2009/09/04/helping-users-keep-plugins-updated/"&gt;Helping users keep plugins updated&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-4478300683504890894?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/4478300683504890894/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=4478300683504890894&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/4478300683504890894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/4478300683504890894'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2009/09/por-que-nao-se-pensou-nisso-antes.html' title='Por que não se pensou nisso antes?'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-8854367501446221113</id><published>2009-08-05T15:55:00.000-03:00</published><updated>2009-08-05T15:57:09.845-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Direito'/><title type='text'>Declaração de quitação anual de débitos</title><content type='html'>&lt;a href="http://www.planalto.gov.br/ccivil_03/_Ato2007-2010/2009/Lei/L12007.htm"&gt;Esta é uma lei (muito) boa.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-8854367501446221113?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/8854367501446221113/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=8854367501446221113&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/8854367501446221113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/8854367501446221113'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2009/08/declaracao-de-quitacao-anual-de-debitos.html' title='Declaração de quitação anual de débitos'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-8650456240559310537</id><published>2009-07-16T08:34:00.000-03:00</published><updated>2009-07-16T08:35:47.436-03:00</updated><title type='text'>Fora Sarney!</title><content type='html'>&lt;a href="http://twitter.com/forasarney"&gt;http://twitter.com/forasarney&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-8650456240559310537?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/8650456240559310537/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=8650456240559310537&amp;isPopup=true' title='1 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/8650456240559310537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/8650456240559310537'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2009/07/fora-sarney.html' title='Fora Sarney!'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-5598087110824366228</id><published>2009-06-23T16:22:00.007-03:00</published><updated>2009-06-24T08:22:09.527-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Em casa de ferreiro ...</title><content type='html'>O pessoal da Microsoft precisa aprender a usar o corretor ortográfico (o grifo é meu):
&lt;blockquote&gt;Voo 447, Crimes Hediondos e Engenharia Social 3.0&lt;br&gt;&lt;br&gt;

Há algum tempo bloquei sobre o fenômeno Conficker e fiz uma comparação com o worm Morris, evento de mais de 20 anos de idade e o quanto aprendemos (ou não aprendemos) desde então.&lt;br&gt;&lt;br&gt;

Com a recente tragédia no voo 447, começaram a "chover" emails falsos de toda a sorte, com iscas do tipo "fotos exclusivas do acidente", "sobreviventes encontrados" entre muitos outros. Um chamariz perfeito para usuários menos treinados ou mais curiosos.&lt;br&gt;&lt;br&gt;

Rios de dinheiro tem sido gastos com ferramentas e novas &lt;span style="font-weight: bold;"&gt;tecnicas&lt;/span&gt; de proteção contra esse tipo de ameaça, mas &lt;span style="font-weight: bold;"&gt;sera&lt;/span&gt; que estamos escolhendo os campos de batalha corretos?&lt;br&gt;&lt;br&gt;

Aprendemos cada vez mais o papel do usuário nesse tipo de incidente, mas aparentemente não aprendemos o suficiente para cuidar dos usuários.&lt;br&gt;&lt;br&gt;

No acidente aéreo ocorrido no Brasil no ano passado quando duas aeronaves colidiram no ar, até mesmo fotos falsas (provenientes de uma &lt;span style="font-weight: bold;"&gt;serie&lt;/span&gt; de TV onde ocorre um acidente logo no primeiro episódio) para chamar a atenção de usuários incautos.&lt;br&gt;&lt;br&gt;

Essas não exatamente novas, mas certamente bem criativas formas de se utilizar engenharia social requerem cuidados ligados a conscientização e constante esforço junto aos usuários. &lt;span style="font-weight: bold;"&gt;Antivirus&lt;/span&gt; de forma isolada não são suficientes (embora uma verificação ortográfica integrada pudesse ser uma boa idéia - Muitos desses emails são maravilhas da engenharia social mas ataques violentos a &lt;span style="font-weight: bold;"&gt;lingua&lt;/span&gt; portuguesa). "Vazou OS &lt;span style="font-weight: bold;"&gt;videos&lt;/span&gt; do Desastre" é um bom exemplo disso. A &lt;span style="font-weight: bold;"&gt;construcao&lt;/span&gt; desses emails ainda é bem arcaica, mas com o uso de logotipos e imagens surrupiadas de sites de &lt;span style="font-weight: bold;"&gt;noticias&lt;/span&gt; e outros &lt;span style="font-weight: bold;"&gt;artificios&lt;/span&gt; como links falsos (como no exemplo onde o email sugere que o link é da FAB mas na verdade aponta para um site que hospeda o código malicioso)&lt;br&gt;&lt;br&gt;

Vale a pena conscientizar os usuários sobre esses "fenômenos" e manter máquinas atualizadas e processos bem definidos para monitorar mudanças de configuração, aderência a políticas de segurança corporativas entre outras medidas importantes. Crimes hediondos recentes, tragédias que circulam a mídia: A temática central muda, mas a engenharia social só se aperfeiçoa. QUando surge uma nova manchete, golpistas certamente usaram esse artifício para melhorar os resultados de sua "pesca".&lt;br&gt;&lt;br&gt;

A cada incidente temos que aprender não apenas as questões técnicas envolvidas mas &lt;span style="font-weight: bold;"&gt;tambem&lt;/span&gt; como nossos usuários reagem para que os mecanismos de defesa possam aprender com cada experiência.&lt;br&gt;&lt;br&gt;

Aylton Souza&lt;/blockquote&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size:78%;"&gt;&lt;a href="http://blogs.technet.com/risco/archive/2009/06/23/voo-447-crimes-hediondos-e-engenharia-social-3-0.aspx"&gt;http://blogs.technet.com/risco/archive/2009/06/23/voo-447-crimes-hediondos-e-engenharia-social-3-0.aspx&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-5598087110824366228?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/5598087110824366228/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=5598087110824366228&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5598087110824366228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5598087110824366228'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2009/06/em-casa-de-ferreiro.html' title='Em casa de ferreiro ...'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-3485207719216232676</id><published>2008-12-04T22:03:00.003-02:00</published><updated>2008-12-04T22:08:22.959-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Um artigo para a geração Você S.A.</title><content type='html'>&lt;ul&gt;&lt;li&gt;&lt;a href="http://wagnerelias.com/2008/12/04/coisas-que-me-irritam-e-espero-que-mudem/"&gt;Coisas que me irritam e espero que mudem&lt;/a&gt; (by Wagner Elias)&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-3485207719216232676?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/3485207719216232676/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=3485207719216232676&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3485207719216232676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3485207719216232676'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/12/um-artigo-para-gerao-voc-sa.html' title='Um artigo para a geração Você S.A.'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-5510073996528366941</id><published>2008-11-23T12:11:00.003-02:00</published><updated>2008-11-23T12:39:51.727-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Evento'/><title type='text'>Calendário de eventos</title><content type='html'>Ronaldo Vasconcellos, o criador de algumas das principais &lt;a href="http://lists.securityguys.com.br/"&gt;listas de segurança brasileiras&lt;/a&gt;, mantém este calendário de eventos de segurança.&lt;ul&gt;&lt;li&gt;&lt;a href="http://securityguys.com.br/calendar/"&gt;Computer Security and Hacker Conferences&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-5510073996528366941?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/5510073996528366941/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=5510073996528366941&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5510073996528366941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5510073996528366941'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/11/calendrio-de-eventos.html' title='Calendário de eventos'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-6922265882012993316</id><published>2008-11-15T09:44:00.008-02:00</published><updated>2008-11-22T11:41:19.131-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SOx'/><title type='text'>Sarbanes-Oxley e o mito da retenção de logs</title><content type='html'>&lt;p&gt;Existe uma grande confusão em &lt;a href="http://esj.com/security/article.aspx?EditorialsID=965"&gt;diversas&lt;/a&gt; &lt;a href="http://www.sans.org/resources/security_plus/data_retention_ew.php"&gt;páginas&lt;/a&gt; na &lt;a href="http://msmvps.com/blogs/harrywaldron/archive/2005/03/23/39391.aspx"&gt;web&lt;/a&gt; que afirmam que a Sarbanes-Oxley determina 7 anos para retenção de logs. Isto é comum na Internet, as pessoas fazem copy &amp;amp; paste de outras páginas, não verificam as fontes originais e, no final, algo que é uma inverdade passa a ter credibilidade pois muitos repetem esta informação.&lt;/p&gt;&lt;p&gt;Ocorre que a U.S. Securities and Exchange Commission definiu o seguinte em uma das suas &lt;a href="http://www.sec.gov/rules/final/33-8180.htm"&gt;regulamentações&lt;/a&gt;:&lt;/p&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;WE &lt;/span&gt;are adopting rules requiring accounting firms to retain for seven years certain records relevant to their audits and reviews of issuers' financial statements. Records to be retained include an accounting firm's workpapers and certain other documents that contain conclusions, opinions, analyses, or financial data related to the audit or review.&lt;/blockquote&gt;&lt;p&gt;Como pode-se verificar no texto a cima, a Sarbanes-Oxley &lt;span style="font-weight: bold;"&gt;não &lt;/span&gt;expecifica qual deve ser o período de retenção de logs, mas sim, determina que as empresas de auditoria guardem por 7 anos os registros das auditorias realizadas.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-6922265882012993316?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/6922265882012993316/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=6922265882012993316&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6922265882012993316'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6922265882012993316'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/11/sarbanes-oxley-e-o-mito-da-reteno-de.html' title='Sarbanes-Oxley e o mito da retenção de logs'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-2237171978245824097</id><published>2008-09-30T22:36:00.004-03:00</published><updated>2008-09-30T22:43:43.628-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gestão de segurança'/><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Segurança vs. Inovação</title><content type='html'>Quando segurança é visto como um obstáculo para inovação, algo está errado.&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;THE &lt;/span&gt;study, done by research firm IDC on behalf of RSA Security, shows that the majority of senior managers believe IT security risk is the largest single obstacle to innovation in their businesses right now. Much of this stems from the belief that security personnel are inclined to simply say no to whatever request they receive from a line of business executive and that even if they do agree to help with a given initiative, the turnaround time will be too long to be of any use, the research shows.&lt;/blockquote&gt;&lt;div style="text-align: right;"&gt;&lt;a style="font-weight: bold;" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1332838,00.html?track=sy160"&gt;IT security not valued at many firms, study finds&lt;/a&gt; by Dennis Fisher&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-2237171978245824097?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/2237171978245824097/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=2237171978245824097&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/2237171978245824097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/2237171978245824097'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/segurana-vs-inovao.html' title='Segurança vs. Inovação'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-526256457061236490</id><published>2008-09-30T05:46:00.005-03:00</published><updated>2008-09-30T05:58:36.538-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Controle'/><category scheme='http://www.blogger.com/atom/ns#' term='Gestão de segurança'/><category scheme='http://www.blogger.com/atom/ns#' term='Log'/><title type='text'>Apresentação sobre gerenciamento de log</title><content type='html'>&lt;ul&gt;&lt;li&gt;&lt;a style="font-weight: bold;" href="http://chuvakin.blogspot.com/2008/09/fun-presentation-from-recent-issa-e.html" title="Logs = Accountability"&gt;Logs = Accountability&lt;/a&gt; by Dr Anton Chuvakin&lt;/li&gt;&lt;/ul&gt;&lt;div style="width: 425px; text-align: left;" id="__ss_620729"&gt;&lt;object style="margin: 0px;" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=isc2logsaccountabilityjul2008rel-1222464889669894-9&amp;amp;rel=0&amp;amp;stripped_title=logs-accountability-presentation"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=isc2logsaccountabilityjul2008rel-1222464889669894-9&amp;amp;rel=0&amp;amp;stripped_title=logs-accountability-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-526256457061236490?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/526256457061236490/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=526256457061236490&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/526256457061236490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/526256457061236490'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/apresentao-sobre-gerenciamento-de-log.html' title='Apresentação sobre gerenciamento de log'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-4574513295798612546</id><published>2008-09-29T07:46:00.007-03:00</published><updated>2008-09-29T08:02:56.791-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ROI'/><category scheme='http://www.blogger.com/atom/ns#' term='Gestão de segurança'/><category scheme='http://www.blogger.com/atom/ns#' term='Métrica'/><category scheme='http://www.blogger.com/atom/ns#' term='Economia'/><title type='text'>Métricas econômicas e financeiras de segurança</title><content type='html'>&lt;p&gt;&lt;a style="font-weight: bold;" href="http://www1.inf.tu-dresden.de/%7Erb21/publications/BN2008_Economic_Security_Metrics.pdf"&gt;Este paper&lt;/a&gt; de Rainer Böhme e Thomas Nowey é realmente bom. A sua primeira parte resume muito habilidosamente os principais métodos de decisão financeira para investimentos em segurança da informação, tais como ALE (Annual Loss Expectancy), algumas variações de ROSI (Return on Security Investment) e NVP (Net Present Value). Além disso, ele analisa algumas da deficiências destes métodos.&lt;/p&gt;&lt;p&gt;A segunda parte descreve algumas métricas de segurança baseadas em mecanismos de mercado. É um assunto muito interessante que merece mais da minha atenção no futuro. A propósito, este paper é originalmente um capítulo do livro “&lt;a href="http://www.springer.com/computer/programming/book/978-3-540-68946-1"&gt;LNCS 4909 Dependability Metrics&lt;/a&gt;”.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-4574513295798612546?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/4574513295798612546/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=4574513295798612546&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/4574513295798612546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/4574513295798612546'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/mtricas-econmicas-e-financeiras-de.html' title='Métricas econômicas e financeiras de segurança'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-5903771327026792284</id><published>2008-09-22T08:27:00.005-03:00</published><updated>2008-09-22T08:36:15.364-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Segurança por corretude, isolamento ou obscuridade</title><content type='html'>&lt;p&gt;Como frequentemente ocorre, Joanna Rutkowska postou algumas idéias interessantes:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;IF&lt;/span&gt; we looked at the computer systems and how they try to provide security, I think we could categorize those attempts into three broad categories:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Security by Correctness&lt;/li&gt;&lt;li&gt;Security by Isolation&lt;/li&gt;&lt;li&gt;Security by Obscurity&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;Mais &lt;a href="http://theinvisiblethings.blogspot.com/2008/09/three-approaches-to-computer-security.html"&gt;aqui&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-5903771327026792284?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/5903771327026792284/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=5903771327026792284&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5903771327026792284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5903771327026792284'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/segurana-por-corretude-isolamento-ou.html' title='Segurança por corretude, isolamento ou obscuridade'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-7046085099398249939</id><published>2008-09-17T21:59:00.005-03:00</published><updated>2008-09-18T08:36:58.099-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Links'/><title type='text'>Teste de software e risco quantitativo</title><content type='html'>&lt;h3&gt;Blogs sobre teste de software&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blogs.msdn.com/james_whittaker/"&gt;JW on Test&lt;/a&gt;&lt;/li&gt;
   &lt;li&gt;&lt;a href="http://testingexperience.blogspot.com/"&gt;Testing, TCL and Other Stuff&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Artigo sobre risco quantitativo (o título já diz tudo)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/"&gt;The Fallacy of Complete and Accurate Risk Quantification&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-7046085099398249939?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/7046085099398249939/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=7046085099398249939&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/7046085099398249939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/7046085099398249939'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/links.html' title='Teste de software e risco quantitativo'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-3067401761878557087</id><published>2008-09-15T23:23:00.003-03:00</published><updated>2008-09-15T23:33:01.586-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gestão de segurança'/><category scheme='http://www.blogger.com/atom/ns#' term='Economia'/><title type='text'>Novos caminhos para gestão de segurança</title><content type='html'>&lt;span xmlns=""&gt;&lt;p&gt;Segurança da informação tem duas grandes vertentes: uma tecnológica e outra de gestão. A primeira vertente avança com grande velocidade a ponto de ser difícil de acompanhar. Já a segunda, não apresenta nada de verdadeiramente novo a um bom tempo.
&lt;/p&gt;&lt;p&gt;Basicamente o que vemos hoje é gestão baseada em conformidade, em risco ou em ambos. Modelos de gestão por conformidade são fundamentados em ditas melhores práticas do mercado, porem sofrem por não conseguirem apresentar o valor real que estas práticas trazem a organização.
&lt;/p&gt;&lt;p&gt;Modelos de gestão por risco também têm suas limitações. Os que trabalham com riscos qualitativos, trazem a dificuldade de associação do risco identificado com a realidade percebida pela organização, pois o risco identificado depende fundamentalmente do ponto de vista de quem o identificou. Por sua vez, realizar o cálculo de risco quantitativo em segurança da informação uma tarefa extremamente árdua e muitas vezes inviável quando se busca um resultado útil e honesto para a gestão.
&lt;/p&gt;&lt;p&gt;Será que estamos fadados a estas opções? Acredito que não. Existem alguns &lt;a href="http://english.gustavobittencourt.com/2008/09/economics-of-information-security-links.html"&gt;estudos&lt;/a&gt; relacionados à teoria econômica (macro e micro) aplicada à segurança da informação. As forças de mercado estão cada vez mais fáceis de serem identificadas nas questões envolvendo segurança da informação. O próximo passo me parece óbvio, por que não utilizar os modelos de gestão econômica para gestão de segurança da informação?&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-3067401761878557087?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/3067401761878557087/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=3067401761878557087&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3067401761878557087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3067401761878557087'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/novos-caminhos-para-gesto-de-segurana.html' title='Novos caminhos para gestão de segurança'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-6159809869038212922</id><published>2008-09-09T20:19:00.006-03:00</published><updated>2008-09-16T22:12:01.991-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Evento'/><title type='text'>YSTS 2.0</title><content type='html'>Em novembro vai haver a segunda edição do &lt;a href="http://www.ysts.org/"&gt;You Sh0t The Sheriff&lt;/a&gt;. A primeira edição deste evento foi excelente. Para quem quiser submeter um paper, segue o &lt;a href="http://www.ysts.org/cfp20.html"&gt;enlace&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-6159809869038212922?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/6159809869038212922/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=6159809869038212922&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6159809869038212922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6159809869038212922'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/ysts-20.html' title='YSTS 2.0'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-3408807390049412758</id><published>2008-09-08T22:16:00.004-03:00</published><updated>2008-09-08T22:26:26.744-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ROI'/><title type='text'>ROI em segurança é ...</title><content type='html'>... como o modelo OSI, só existe na teoria.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-3408807390049412758?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/3408807390049412758/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=3408807390049412758&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3408807390049412758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3408807390049412758'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/roi-em-segurana.html' title='ROI em segurança é ...'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-8170510586975442756</id><published>2008-09-03T20:27:00.000-03:00</published><updated>2008-09-03T20:32:37.919-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fun'/><title type='text'>Best Practices</title><content type='html'>&lt;a href="http://dilbert.com/strips/comic/2008-09-03/" title="Dilbert.com"&gt;&lt;img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/20000/2000/200/23259/23259.strip.gif" border="0" alt="Dilbert.com" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-8170510586975442756?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/8170510586975442756/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=8170510586975442756&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/8170510586975442756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/8170510586975442756'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/09/best-practices.html' title='Best Practices'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-6089328006390652219</id><published>2008-06-03T21:22:00.002-03:00</published><updated>2008-08-25T12:57:42.960-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Artigo sobre desenvolvimento seguro</title><content type='html'>&lt;p&gt;&lt;a style="font-weight: bold;" href="http://msdn.microsoft.com/pt-br/library/cc627254.aspx"&gt;Dicas que todo desenvolvedor deve saber sobre Segurança no Desenvolvimento de Software&lt;/a&gt;&lt;/p&gt;By Weber Ress&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-6089328006390652219?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/6089328006390652219/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=6089328006390652219&amp;isPopup=true' title='1 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6089328006390652219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/6089328006390652219'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/06/artigo-sobre-desenvolvimento-seguro.html' title='Artigo sobre desenvolvimento seguro'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-1351737290918049487</id><published>2008-03-12T22:44:00.004-03:00</published><updated>2008-03-12T23:44:59.994-03:00</updated><title type='text'>Testando o novo Netvibes</title><content type='html'>Ginger, o novo portal do Netvibes tem um recurso interessante de compartilhar uma página inicial customizada com qualquer um. Veja abaixo:
&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.netvibes.com/gbitten"&gt;&lt;span style="font-weight: bold;"&gt;http://www.netvibes.com/gbitten&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-1351737290918049487?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/1351737290918049487/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=1351737290918049487&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/1351737290918049487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/1351737290918049487'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/03/testando-o-novo-netvibes.html' title='Testando o novo Netvibes'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-3681306941852071204</id><published>2008-03-05T21:24:00.002-03:00</published><updated>2008-03-05T21:33:11.856-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Processo'/><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>BPM e Segurança</title><content type='html'>A tempos que planejo escrever sobre a relação entre BPM (Business Process Management) e Segurança da Informação. Como ainda não venci minha própria inércia, ao menos aponto para este bom artigo de Mark Curphey sobre o mesmo tema. Afinal, andam dizendo por aí que segurança é processo.
&lt;ul&gt;&lt;li&gt;&lt;a href="http://securitybuddha.com/2008/02/28/tenets-of-effective-bpm/"&gt;&lt;span style="font-weight: bold;"&gt;Tenets of Effective BPM&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-3681306941852071204?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/3681306941852071204/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=3681306941852071204&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3681306941852071204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/3681306941852071204'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/03/bpm-e-segurana.html' title='BPM e Segurança'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-5357618853871766191</id><published>2008-03-04T21:55:00.007-03:00</published><updated>2008-03-04T22:15:23.509-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Futebol'/><title type='text'>Zico</title><content type='html'>&lt;div id="imagem" style="float: right; width: 425px;"&gt;&lt;object height="355" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/c9g5dl7IO2o"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.youtube.com/v/c9g5dl7IO2o" type="application/x-shockwave-flash" wmode="transparent" height="355" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;Ídolo eu nunca tive, a não ser esse cara, não apenas como jogador, mas principalmente como exemplo de humanidade, dignidade e respeito de uma figura pública que não se vê mais hoje em dia. Esse vídeo ilustra bem isso, bons tempos.&lt;BR CLEAR=both&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-5357618853871766191?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/5357618853871766191/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=5357618853871766191&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5357618853871766191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5357618853871766191'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/03/zico.html' title='Zico'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-1070966015444759896</id><published>2008-02-28T22:44:00.006-03:00</published><updated>2008-02-28T22:50:03.346-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fun'/><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Anticlimax</title><content type='html'>Apesar da torcida contra, não passou de um furto comum. Que baita anticlimax.
&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.estadao.com.br/economia/not_eco132142,0.htm"&gt;&lt;span style="font-weight: bold;"&gt;Presos no furto da Petrobras não sabiam de dados sigilosos&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-1070966015444759896?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/1070966015444759896/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=1070966015444759896&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/1070966015444759896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/1070966015444759896'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/02/anticlimax.html' title='Anticlimax'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-7712143499363694357</id><published>2008-02-26T19:41:00.006-03:00</published><updated>2008-02-26T19:47:55.443-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Artigo'/><title type='text'>Artigo sobre como enfrentar uma auditoria</title><content type='html'>Resumindo minha impressão sobre o artigo do Eduardo Camargo Neves: "&lt;span style="font-weight: bold;"&gt;ab uno disce omnes&lt;/span&gt;".&lt;ul&gt;&lt;li&gt;&lt;a href="http://camargoneves.com/?p=120"&gt;&lt;span style="font-weight: bold;"&gt;Guia Básico de Sobrevivência para uma Auditoria de Sistemas – Parte 2 de 2&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-7712143499363694357?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/7712143499363694357/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=7712143499363694357&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/7712143499363694357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/7712143499363694357'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/02/artigo-sobre-como-enfrentar-uma.html' title='Artigo sobre como enfrentar uma auditoria'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14277984.post-5553074277978005280</id><published>2008-02-21T01:34:00.017-03:00</published><updated>2008-02-23T23:25:59.567-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viagem'/><title type='text'>Softwares precisam ser vulneráveis</title><content type='html'>&lt;p&gt;Hoje, estava a ouvir o excelente podcast "&lt;a style="font-weight: bold;" href="http://www.naopod.com.br/"&gt;i sh0t the sheriff&lt;/a&gt;", quando um assunto abordado Luiz Eduardo, Nelson Murilo e Willian Caprino me chamou a atenção. A conversa, se não me engano, era sobre IDS e como este tipo de controle pode ser ineficiente. Em determinado momento da discussão, foi colocado que a culpa é dos desenvolvedores e arquitetos de software que produzem sistemas vulneráveis, a ponto de sugerir que sistemas operacionais são vulneráveis a vírus, bots e trojans por causa de deficiências em suas arquiteturas.&lt;/p&gt;&lt;p&gt;Nesta questão é que minha opinião diverge. Softwares não são vulneráveis apenas por preguiça ou incompetência dos desenvolvedores, muitas vezes, estes mesmos softwares necessitam ser vulneráveis para serem viáveis. É justamente o caso dos sistemas operacionais em relação a vírus, bots e trojans, onde não há solução fácil. Trusted Computing, que por exemplo promete alguma efetividade contra esses tipos de malware, é uma tecnologia cara e pouquíssimo disseminada.&lt;/p&gt;&lt;p&gt;Fazendo uma analogia, não vejo ninguém reclamando dos projetistas automobilísticos por causa da vulnerabilidade dos pneus, onde um prego pode até mesmo causar a morte de um ser humano. A solução para esta vulnerabilidade é simples, um pneu maciço, porem é anti-econômica para a maioria dos casos. O mesmo ocorreu com os protocolos da família TCP/IP, muito mais vulneráveis em sua arquitetura do que os protocolos OSI, porem muito mais viáveis economicamente. E se dependêssemos apenas da família OSI, tenho convicção de que hoje não haveria internet.&lt;/p&gt;&lt;p&gt;Da mesma forma que desenvolvedores e analistas de sistemas precisam rever seus conceitos no processo de desenvolvimento de softwares, os profissionais de segurança precisam aceitar a existência de vulnerabilidades, elas são intrínsecas a qualquer ambiente. Tentar eliminá-las por completo quase sempre torna os produtos caros demais, pesados demais e difíceis demais de manusear.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14277984-5553074277978005280?l=www.gustavobittencourt.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.gustavobittencourt.com/feeds/5553074277978005280/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=14277984&amp;postID=5553074277978005280&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5553074277978005280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14277984/posts/default/5553074277978005280'/><link rel='alternate' type='text/html' href='http://www.gustavobittencourt.com/2008/02/softwares-precisam-ser-vulnerveis.html' title='Softwares precisam ser vulneráveis'/><author><name>Gustavo Araujo Bittencourt</name><uri>http://www.blogger.com/profile/03445897744346622932</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='17542377459202273568'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>