<?xml version="1.0" encoding="iso-8859-1"?>
<!-- generator="FeedCreator 1.7.2c" -->
<rss version="2.0">
    <channel>
        <title>NoShut.com</title>
        <description>Alans Thoughts</description>
        <link>http://www.noshut.com/</link>
        <lastBuildDate>Tue, 30 Mar 2010 04:00:17 +0100</lastBuildDate>
        <generator>FeedCreator 1.7.2c</generator>
        <language>us-en</language>
        <copyright>Copyright 2010, Alan Caruth</copyright>
        <managingEditor>r.andom@noshut.com</managingEditor>
        <webMaster>r.andom@noshut.com</webMaster>
        <docs>http://blogs.law.harvard.edu/tech/rss</docs>
        <item>
            <title>Allergy Shots - 1 Year and 3 Months In (Or: Alan's subjective view of Allergy Shots So Far)</title>
            <link>http://www.noshut.com/?eid=725</link>
            <description>&lt;b&gt;Two years ago I took a risk and had Lasik done. The results were spectacular...&lt;/b&gt;&lt;br&gt;
So, when Tanya (my fiance) and I thought about moving in together there was something that had to be contemplated: I had allergies/asthma and could spend only a few hours in any environment with dogs or cats during any given week. Tanya is a major dog person. Our options could be summarized as: Figure out how to stop Alan from reacting, or get rid of the dogs. The latter was not a happy thing to contemplate, so it was time to see if I could do anything.&lt;br&gt;&lt;br&gt;
&lt;b&gt;I started doing research and discovered a body experiment I could partake in with a couple of potential outcomes:&lt;/b&gt;&lt;br&gt;
	1.	Spend months of your life sitting in doctors offices over 2-5 years with nothing to show for it other than a damaged wallet.&lt;br&gt;
	2.	Spend months of your life in a doctors office over 2-5 years with some allergy resistance.. and still damaged wallet.&lt;br&gt;
	3.	Spend months of your life in a doctors office over 2-5 years and be cured of your targeted allergies.. and yes, still a damaged wallet.&lt;br&gt;&lt;br&gt;
After having Lasik done, allergy shots and the potential of changing how your body reacts to allergens seemed like a very worthwhile experiment. My asthma has always caused issues and allergies are something I’ve always fought using antihistamines and the like. The concept of getting rid of my allergies was awesome, and like getting rid of glasses/contacts, is a quality of life improvement worth some risk (if I must rate it - in my case more worthwhile than the Lasik - since glasses didn’t limit me from doing things, but my allergies and asthma did).&lt;br&gt;&lt;br&gt;
&lt;b&gt;If you are not familiar with allergy shots the basic concept is this:&lt;/b&gt;
You are injected on a regular basis (twice a week, then once a week, and now every other week in my case) with what you are allergic to, in doses that are gradually ramped up over time. The hope is that eventually your body stops reacting to the allergens due to them being ever-present in your blood stream. By soaking your system over time with higher and higher doses your system is conditioned to tolerate the higher level, which in a perfect scenario your immune system starts ignoring completely. In effect you are moving the baseline up for your tolerance to a particular allergen, eventually to the point where your body doesn’t react at all.&lt;br&gt;&lt;br&gt;
As for drugs, you are probably going to stay on them for quite awhile. Even allergy shots are not perfect, and the doc made it clear up front that if anything my drug dosages and types would probably increase for the first few years as they tried to control my allergies/asthma while working toward immunity, which they did.&lt;br&gt;&lt;br&gt;
The process is supposed to take 2-5 years although many places recommend staying on “booster” shots. Based around my reading many people quit the shots and years later are still fine from what I’ve read. Mileage may vary. I haven’t made it that far yet, so I can’t testify to the result in my case.&lt;br&gt;&lt;br&gt;
One mistake I made in relation to this blog entry (and wasn’t contemplating at the time) was I didn’t start documenting the Allergy shots until now, which is well after my initial impressions have worn off, so these observation are a bit late and probably a bit skewed....&lt;br&gt;&lt;br&gt;
&lt;b&gt;Things to know about the Allergy Shot experience:&lt;/b&gt;&lt;br&gt;
	1.	Getting started is not cheap - I’ve maxed out my insurance out of pocket the last two years, and will probably continue for at least a few more years. First there are doctor exams, then there are allergy tests (both scratch and blood tests in my case), then there are follow-up appointments, drugs to control your allergies/asthma and the ongoing costs of the shots, which are about $35 every other week for me at this time. My out of pocket cost so far has been at least $4,000 between all components since I showed up for my first exam. Side Note: Thanks to my &lt;a href=http://www.gci.com&gt;employer&lt;/a&gt; for providing great insurance and being a awesome employer for many years.&lt;br&gt;&lt;br&gt;
	2.	Allergy shots require commitment. Commitment to see doctors every 3-6 months to grade your progress/adjust medications and 2-5 years of your life of allergy shots themselves - then there is the biggest commitment - time sitting around..&lt;br&gt;&lt;br&gt;
	3.	Time sitting around - You show up at your docs office, wait for your shot (5-20 minutes typical in my case), then after the shot (takes 5-10 minutes or so to get), you must stick around the doctor’s office for half an hour to make sure you don’t suffer any major effects or go into anaphylactic shock. This means on you are burning close to a hour of time minus travel each time you go in for shots. On a positive note, my doc office has Wifi so that you can bring along your computer and use the Internet or work while waiting.&lt;br&gt;&lt;br&gt;
	4.	Additional Notes on Time - If you miss a few shots (no two month europe trips in the first few years), they back your dose down and ramp back up, in addition if you have a major reaction, that can also delay your progress. One other schedule impacting item is when moving to new vials of allergen you must ramp-up again over a period of 3 weeks, which means every 2-3 months having to revert to a once-a-week schedule (at least on my current dosage/visit timing).&lt;br&gt;&lt;br&gt;
&lt;b&gt;So how are the shots?&lt;/b&gt;&lt;br&gt;
Due to my allergy set (shrubs, trees, grasses, mice, dogs and cats if I remember correctly), they give me two shots each time. One in the back of each arm. The shots are using pediatric needles, so it’s a VERY small prick, most of the time no bleeding, or if so only one or two drops. During the initial ramp-up I had much arm soreness. At a certain point the soreness and swelling reduced, but now that I’m at maximum dosage every shot is followed by arm swelling and minor pain for a few days. It is nothing major, but is a bit of a distraction.&lt;br&gt;&lt;br&gt;
&lt;b&gt;What are the results like after a year+?&lt;/b&gt;&lt;br&gt;
A Drug Disclaimer: The antihistamines I’m on haven’t changed much - I’m on the same basic stuff I have been since a few years before the shots, which is a Claritin or Zyrtec generic. In addition I’m on some other drugs/steroids to keep my allergies under control. The asthma meds I’m on have changed dramatically. I’m now on two types of inhaled medicine to control my asthma, one being a emergency inhaler, which I’ve been on for many years and the other being a daily use control inhaler. In October 2009 I started exercising every other day, which I’m happy to say is still occurring. When I started exercising my asthma stepped up so they had to adjust my dosage of my daily inhaler, but my asthma is now is a very good place.&amp;nbsp;&amp;nbsp;Feel free to contact me for additional gory details :^).&lt;br&gt;&lt;br&gt;
&lt;b&gt;So Really - what is it like after a year now that there has been a mega disclaimer?&lt;/b&gt;&lt;br&gt;
Huge Improvement. Probably best indicated by example (keep in mind, this is shots + medicine modification):&lt;br&gt;&lt;br&gt;
&lt;b&gt;Before Shots&lt;/b&gt; - Emergency Asthma Inhaler + Daily Antihistamine: 2 Hours around dogs and I would have 3-5 days of asthma flare-ups and congestion for at least 8-10 hours, if not a full day. Petting the dogs would result in itchy skin in only a few minutes, heaven forbid I rub my eyes without washing my hands, they will be irritated all day. Visiting anyone’s house with pets and less than perfect house maintenance (LTPHM from here out) or significant airflow would cause reactions in 15-30 minutes, which depending on the situation could cause me to have issues for several days. Inhaler sometimes needed before exercise and before bed.&lt;br&gt;&lt;br&gt;
&lt;b&gt;6ish months&lt;/b&gt; - Emergency/Long Term Asthma Meds + Increased Allergy Med Regiment + Shots: I could sit in a room with the dogs for 1-2 hours a few nights in a row, but then had to spend very limited time around them for a few days to let my asthma/allergies calm down. Petting the dogs still resulted in a fairly quick reaction. Most of the time I don’t need my emergency inhaler unless I’ve pushed my luck too much recently with the dogs. LTPHM environments would cause reactions in a few hours, followed by minor annoyance over the next several days such as needing a inhaler that night, and a OTC decongestant to help clean out my system. Not as bad as before. Inhaler still needed sometimes before bed, and often during exercise.&lt;br&gt;&lt;br&gt;
&lt;b&gt;1 Year&lt;/b&gt; - Increased Exercise for a few months, no other adjustments: Asthma started kicking up significantly both at night, sometimes during day and before bed after increased exercise. During a doc visit they doubled my daily inhaler dosage. Within a week or two my asthma issues dramatically reduced. I was able to sit with the dogs almost every night without any major issues sharing the same airspace with the dogs above and beyond the exercise issues.&lt;br&gt;&lt;br&gt;
&lt;b&gt;1 Year 3 Months&lt;/b&gt; - No additional adjustments: I can spend significant time around the dogs without reaction as long as there is no direct contact. If I sit with them (dog on lap) for more than 5-10 minutes at a time I can still force a allergic reaction, or if I touch on them and don’t wash my hands within 5-10 minutes. I can inhabit the same airspace (same room) with them daily for several hours without any issues. Exercise doesn’t normally require a emergency inhaler, and the vast majority of the time I don’t need to utilize additional decongestants or inhaler before bed.
&lt;br&gt;&lt;br&gt;&lt;b&gt;Summary:&lt;/b&gt; Over the last Year my allergies and asthma have improved dramatically. We are not only keeping our two small dogs, we are eyeballing a puppy to be a partner for our younger dog, which a year ago was not even a option. I can still force allergic reactions, but they are no where near as severe as they were, and now living with the dogs is mostly pleasure rather than mostly avoidance and coping. Even better, now I don’t have to think before I visit a new place, such as homes with large dogs or LTPHM - which ever since I was a little kid was always a major consideration. Big quality of life boost.&amp;nbsp;&amp;nbsp;At this time I’m thinking the results are 50% drug adjustments and 50% shots, but I’m already feeling MUCH better about my ability to manage my allergies and asthma. We’ll see how the future turns out.</description>
            <pubDate>Tue, 30 Mar 2010 11:34:37 +0100</pubDate>
        </item>
        <item>
            <title>Intent</title>
            <link>http://www.noshut.com/?eid=724</link>
            <description>In both my personal and work life over the years I’ve had a theory about communication - that theory has been that you need to deliver on the intent of the person asking for something, not the specific thing they are asking for. 
&lt;br /&gt;&lt;br /&gt;
Example: When your mom said “Clean the floor in your room” when you were a kid - did that really mean clean stuff off the floor, or clean the room? Would she be happy if you piled everything on the bed, or perhaps shoved it into the closet (guilty :^))? No. That is because the intent of her message is different from what she asked for. What she really wanted was for you to clean your room, and taking her literally could backfire.
&lt;br /&gt;&lt;br /&gt;
This same concept applies in business and personal communications. How many times have you asked for something, or been asked for something, then when you deliver the goods the other person isn’t satisfied? It was the concept, the goal, the intent they were seeking, along with all things that go with it - a certain amount of comprehensiveness, ownership, and quality that was not directly spoken to, but was very important to the end product and their satisfaction level with the result. Sometimes it takes effort, and if you are overworked or stressed sometimes delivering anything more than the specific request seems like a pain, but will result in a better product.
&lt;br /&gt;&lt;br /&gt;
So that’s my thought of the day. Understanding and communicating intent and goal, not just the specific deliverables requested when generating, or requesting something will make both parties much more satisfied in the end, even if it means doing a bit more work.</description>
            <pubDate>Wed, 17 Mar 2010 06:51:25 +0100</pubDate>
        </item>
        <item>
            <title>Three+ Things I learned at SANS 2010 - Info Recon - Sunday Edition</title>
            <link>http://www.noshut.com/?eid=723</link>
            <description>On Sunday I attended SEC550, Information Reconnaissance: Competitive Intelligence &amp; Online Privacy. It is a one day class taught by &lt;a href=http://blog.layeredsec.com/&gt;Bryce Galbraith&lt;/a&gt;. He was clear that it’s early in it’s development, but it’s already packed full of great information and tools - much more than I will cover here. If you took the time to do a deep-dive on info recon it could easily be a multi-day class.&lt;br&gt;&lt;br&gt;
Here are a few items I took away from the class:&lt;br&gt;
	1.	The explosion of social networks and personal/corporate information being moved online in the last ten years has taken the hunt for information about people and companies to a completely different place. It’s no longer about finding out where a website is hosted, what OS it runs, where someone lives or what a company is using for their accounting software - You can now gather large amounts of real information about people or organizations, dig deep through legal, public sources and correlate information people share freely with deep web and other resources to infer a complete picture.&lt;br&gt;&lt;br&gt;
	2.	Take copious notes when doing information recon. A tidbit of data you didn’t think was worth much could correlate with other data later to finish the puzzle.&lt;br&gt;&lt;br&gt;
	3.	The Deep Web is now a ocean of information. There are great gateway sites you can use to find different resources, including (the class had MANY sites and tools, here are a few highlighted): &lt;a href=http://www.blackbookonline.info/&gt;Black Book Online&lt;/a&gt;, &lt;a href=http://www.pipl.com&gt;Pipl&lt;/a&gt;, &lt;a href=http://www.searchsystems.net/&gt;Searchsystems.net&lt;/a&gt;, &lt;a href=http://www.einvestigator.com/&gt;EInvestigator&lt;/a&gt;&lt;br&gt;&lt;br&gt;
	4.	Google is still the premier search tool to find out tidbits of information about people, companies, etc. but there are many other search tools, which may locate other info. A reference for Google Hacking: &lt;a href=http://www.googleguide.com/&gt;Google Guide&lt;/a&gt;, A list of Search Engines over on Wikipedia:&amp;nbsp;&amp;nbsp;&lt;a href=http://en.wikipedia.org/wiki/List_of_search_engines&gt;List of Search Engines&lt;/a&gt;&lt;br&gt;&lt;br&gt;
	5.	It’s important to keep your ethics/legal brain engaged when doing recon; you can slip into a zone of gray easily, and perhaps threaten the validity of your findings or risk breaking the law.&lt;br&gt;&lt;br&gt;
	6.	Ex or Current Employee Resumes on the Internet can provide a wealth of freely available information on corporations.&lt;br&gt;&lt;br&gt;
	7.	If you are interested in all those data breaches you don’t hear about, there is a maintained database on the web with the highlights: &lt;a href=http://datalossdb.org/&gt;DatalossDB&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
	8.	Social engineering is still in heavy use and cannot be discounted, either by it’s use as a tool, or it’s threat to your organization.&lt;br&gt;&lt;br&gt;
This course is packed with info, there is so much that it would be a big challenge to cover all the topics, if you are really interested it’s definitely a course worth attending.
&lt;br /&gt;&lt;br /&gt;
&lt;a href=http://www.noshut.com/?eid=717&gt;Link to my 3+ Things Learned List&lt;/a&gt; series for the Legal class taught by Ben Wright.&lt;br&gt;
&lt;a href=http://www.noshut.com&gt;Main Blog&lt;/a&gt;</description>
            <pubDate>Tue, 16 Mar 2010 06:54:48 +0100</pubDate>
        </item>
        <item>
            <title>Three+ Things I learned at SANS 2010 - Friday Edition (a bit late :^))</title>
            <link>http://www.noshut.com/?eid=722</link>
            <description>	1.	Case law may act as a example, but should not be used as a guarantee of result - each case is judged separately and often by different courts with different focus and understanding of the material, and although prior case law is a influence, it’s not a guarantee of result.&lt;br&gt;&lt;br&gt;
	2.	By looking at cases between similar nations (e.g. english speaking, 1st world nations with similar government structures) you might be able to derive information about how another nation’s courts might interpret a new situation.&lt;br&gt;&lt;br&gt;
	3.	Information gathered from questionable sources might be admitted in court - such as information gathered through activities that may themselves be illegal, such information gathered by a vigilante.&lt;br&gt;&lt;br&gt;
	4.	Scienter and Self-Help are important concepts in our legal system - acting with scienter is to act knowing that you are committing a wrongdoing. &lt;a href=http://en.wikipedia.org/wiki/Scienter&gt;Wikipedia&lt;/a&gt; has a bit on this topic. Self-Help is acting on your own behalf without engaging law enforcement, &lt;a href=http://en.wikipedia.org/wiki/Self-help_%28law%29&gt;Wikipedia&lt;/a&gt; also has a blurb on this concept.&lt;br&gt;&lt;br&gt;
	5.	Computer forensics work often requires licenses so it is important to understand the requirements in your state if you are to perform forensics work as a professional.&lt;br&gt;&lt;br&gt;
	6.	Being aware of international and state law boundaries/compliance is important when gathering evidence and attempting to pursue a situation, especially on the Internet since it crosses so many legal jurisdictions and there might be multiple overlapping law enforcement agencies. &lt;br&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com/?eid=717&gt;Monday Edition&lt;/a&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com&gt;Main Blog&lt;/a&gt;</description>
            <pubDate>Sun, 14 Mar 2010 20:15:36 +0100</pubDate>
        </item>
        <item>
            <title>Things I learned at SANS 2010 - Thursday Edition</title>
            <link>http://www.noshut.com/?eid=721</link>
            <description>1.	Every reaction to a situation can influence others to think of your organization as “good” or “bad”. Being open, transparent and taking responsibility quickly comes off much better than shutting down, seeming closed and acting slowly. Your organization needs to assure that at the end of the day people have a positive view of you, even if it means fessing up to major mistakes or wrongdoing.&lt;br&gt;&lt;br&gt;
	2.	Don’t tamper with a pre-existing records, especially logs and the like - rather than edit a pre-existing record, create a new one referencing the old one and the corrections you have. By doing it that way if the records are ever questioned it will not appear that they were tampered with.&lt;br&gt;&lt;br&gt;
	3.	Many civil actions and investigations (read: no jail time) can become criminal easily (read: jail time) if there is any evidence of fraud, tampering or misrepresentation. &lt;br&gt;&lt;br&gt;
	4.	Modern Auditors have a responsibility not only to validate things are correct and in order, but to also look for suspicious activity and ask questions which will help them locate fraud.&lt;br&gt;&lt;br&gt;
Plus over the last few days I’ve added a couple of new books to my to-read list: The Naked Corporation and Geekonomics.&lt;br&gt;&lt;br&gt;
One other thing I should mention is our class is taught by &lt;a href=http://legal-beagle.typepad.com/security&gt;Ben Wright&lt;/a&gt;, who is a awesome instructor. It’s rare that you get a instructor who is as energetic and communicating as well on day four as he is on day one.&lt;br&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com/?eid=722&gt;Friday Edition&lt;/a&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com&gt;Main Blog&lt;/a&gt;</description>
            <pubDate>Fri, 12 Mar 2010 12:43:46 +0100</pubDate>
        </item>
        <item>
            <title>Three Things I learned at SANS 2010 - Wednesday Edition</title>
            <link>http://www.noshut.com/?eid=720</link>
            <description>	1.	Breaching a contract in America is a economic situation, not a ethical or criminal one. The goal is to make the vendor or customer whole. It can have fall-out, and damage company reputation, but it is not a “go directly to jail” situation.&lt;br&gt;&lt;br&gt;
	2.	Force Majeure clauses are not a 100% protection. If you have a primary system and it fails with no backup you may still be liable if the system that failed was critical, and it was well within your control to have a backup. In the same situation, if you have a backup system, and both the primary and backup system fail, that may fall under Force Majeure since you made reasonable effort to make sure the system didn’t go offline. In other words when something falls under Force Majeure you can’t just throw up your hands and wait for it to fix itself.&lt;br&gt;&lt;br&gt;
	3.	The definition of Best Effort between the Legal and IT Realm are two different things - in Legal definition it is more than just “reasonable effort”, whereas in IT it is often “the minimum effort necessary”.&lt;br /&gt;&lt;br /&gt;
&lt;a href=http://www.noshut.com/?eid=721&gt;Thursday Edition&lt;/a&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com&gt;Main Blog&lt;/a&gt;</description>
            <pubDate>Thu, 11 Mar 2010 18:46:45 +0100</pubDate>
        </item>
        <item>
            <title>Lasik - 1 Year and 4ish Months In</title>
            <link>http://www.noshut.com/?eid=719</link>
            <description>After going through the vast majority of this winter there are only a few additional thoughts I have on the lasik experience:&lt;br&gt;&lt;br&gt;
1. When my eyes get tired, they are tired. It’s time to shut them for a bit, otherwise I’m blinking for the rest of the evening and they feel slightly irritated.&lt;br&gt;&lt;br&gt;
2. I still get dry eye occasionally, which rarely (never?) happened before Lasik, but it’s a pretty minor experience. A bit of rest, or hanging out in a slightly humid environment fixes them up pretty quick. One other trick I can use in emergencies is to put a eye drop or two in each eye and close them for five minutes or so, that usually gets them back on track. The one time when the dryness of my eyes is more apparent than others is when driving with the A/C on - airflow on my face without enough humidity will suck the moisture right out of them. It’s quickly remedied by turning off the A/C for a few moments in most cases.&lt;br&gt;&lt;br&gt;
That’s about it. The vast majority of the time I don’t think about my vision or have any issues with it. Still have 20/20 or better and am very satisfied with the experience. &lt;br&gt;&lt;br&gt;
In interest of full disclosure I’ll state that my near-sight vision is a bit worse than it was a few years back, but I started to notice that a bit before the Lasik. That particular issue is a side effect of age, not eye surgery :^). I just need to stop opting for the highest resolution possible in the smallest screen size when buying computer monitors, for day to day reading and non-monitor activities my vision is still great.&lt;br&gt;&lt;br&gt;
Rating of Lasik so far: Absolutely worth it.&lt;br&gt;&lt;br&gt;
For those of you who want a second opinion, there was a article on Lasik in Consumer Reports at some point in the last several months. Here is a link to a tidbit about it: &lt;a href=http://www.consumerreports.org/health/healthy-living/beauty-personal-care/lasik-eye-surgery/overview/lasik-ov.htm&gt;Consumer Reports&lt;/a&gt;</description>
            <pubDate>Wed, 10 Mar 2010 11:44:57 +0100</pubDate>
        </item>
        <item>
            <title>Three+ Things I learned at SANS 2010 Today - Tuesday Edition</title>
            <link>http://www.noshut.com/?eid=718</link>
            <description>	1.	Everything said when you are functioning in a legal context must be accurate. Period. Exaggerations or any false statements, even made thinking they are correct at the time can bite you later. Research and understand what you are talking about before commenting.&lt;br&gt;&lt;br&gt;
	2.	The Legal team needs to have a solid relationship and good communication practices with the IT group. Courts are relying more and more on the lawyer being able to speak intelligently about the organization’s capabilities to do things like recover documentation and what specific information would be needed to find the right data.&lt;br&gt;&lt;br&gt;
	3.	Your policies (exampled via data retention policies) must be modeled with all applicable laws and industry rules in mind - not just a single one, or a group of laws/rules/guidelines your specific industry is required to follow. By strictly complying to or fixating on one set of rules you could be breaking others or ignoring common sense. Remember the big picture.&lt;br&gt;&lt;br&gt;
	4.	Identification and Signatures are two different things and should not be confused. Signatures are “a symbol adopted with intent”, meaning that even items you might not think of as a signature (such as a email from your account to another person - or your name typed at the bottom of a message) might be considered legally binding depending on circumstance and intent.&lt;br&gt;&lt;br&gt;
	5.	When talking about Terms and Conditions - make sure everyone knows yours, and repeat them as often as you must in order to keep them known.&lt;br&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com/?eid=720&gt;Wednesday Edition&lt;/a&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com&gt;Main Blog&lt;/a&gt;</description>
            <pubDate>Wed, 10 Mar 2010 11:10:54 +0100</pubDate>
        </item>
        <item>
            <title>Three+ Things I learned at SANS 2010 Today</title>
            <link>http://www.noshut.com/?eid=717</link>
            <description>Three+ things I learned at SANS 2010 (Legal Track) today:&lt;br&gt;
	1.	Appropriately vague or tentative language is not a bad thing in security policies. What is the risk of writing a “must” into a policy, not delivering on the promise, then having to testify about your lack of enforcement in court or answer to it in a public forum? &lt;br&gt;&lt;br&gt;
	2.	Any effort to provide due care is better than no effort at all (e.g. having a security policy vs. not having one due to lack of enforcement concerns). Negligence when common sense states that there was a easy solution is bad - especially to a judge or jury.&lt;br&gt;&lt;br&gt;
	3.	Disclaimers, Terms of Service, and things like login banners should be used whenever possible. Words are cheap, and can save your ass. The key concept is to seek consent so that you can handle privacy concerns.&lt;br&gt;&lt;br&gt;
	4.	Handling a legal issue in the wrong way can turn into a PR nightmare. Decisions to take legal action should be ran through a PR filter to make sure it won’t stink when your opponents take their argument to the Internet.&lt;br&gt;&lt;br&gt;
Great class so far, loving the material and providing new perspectives.&lt;br&gt;
&lt;br /&gt;
&lt;a href=http://www.noshut.com/?eid=718&gt;Tuesday Edition&lt;/a&gt;&lt;br&gt;
&lt;a href=http://www.noshut.com&gt;Main Blog&lt;/a&gt;</description>
            <pubDate>Tue, 09 Mar 2010 11:24:29 +0100</pubDate>
        </item>
        <item>
            <title>Free iTunes Apps</title>
            <link>http://www.noshut.com/?eid=716</link>
            <description>Being the Thanksgiving/Black Friday I took a look for the currently discounted to free iTunes apps (apps that are discounted to zero, but didn't appear to be apps that just bounce up from paid to free all the time).&lt;br&gt;
&lt;br&gt;
Here is the list I created tonight:&lt;br&gt;
&lt;br&gt;
Current Free Apps:&lt;br&gt;
Sip-N-Store&lt;br&gt;
doubledrop&lt;br&gt;
Lucha Libre Matchup&lt;br&gt;
iSoroban&lt;br&gt;
Creepytown&lt;br&gt;
Perdiemcalc&lt;br&gt;
TweetL&lt;br&gt;
Squeezer&lt;br&gt;
Super Shock Football&lt;br&gt;
Burning Man 2008&lt;br&gt;
Indian Snacks (veg)&lt;br&gt;
Arcade Hockey&lt;br&gt;
Flit&lt;br&gt;
FAce It!&lt;br&gt;
Vocaform&lt;br&gt;
Wash Tub Bass&lt;br&gt;
Galleryify!&lt;br&gt;
Formalogy&lt;br&gt;
Recipes with Conversions&lt;br&gt;
Bug Eat Grass&lt;br&gt;
UpNext 3D Cities&lt;br&gt;
Ink&lt;br&gt;
Christmas Fun Bells&lt;br&gt;
Easy Sale Price Pro&lt;br&gt;
Scare my Puppy - Dog Whistle&lt;br&gt;
Dweebs&lt;br&gt;
Flashlights&lt;br&gt;
iCrossFingers&lt;br&gt;
Blutalk - Bluetooth chat app&lt;br&gt;
Snow Queen - comic book&lt;br&gt;
Post - Twitter app&lt;br&gt;
Pocket Paradise -- soundscape creator&lt;br&gt;
Urinals: The Game&lt;br&gt;
Hot Dog Down a Hallway&lt;br&gt;
FlickTunes&lt;br&gt;
AAA Watch&lt;br&gt;
Baby Animals - A encyclopedia game&lt;br&gt;
Pudge&lt;br&gt;
Color Converter&lt;br&gt;
iChing 2go&lt;br&gt;
An Android's Odyssey&lt;br&gt;
Tides of War&lt;br&gt;
Rocket Bird&lt;br&gt;
Coffee Order&lt;br&gt;
Bubble Trouble&lt;br&gt;
GoParking&lt;br&gt;
DronEze&lt;br&gt;
DodgeDot&lt;br&gt;
Mood Mouse -- Remote control computer App&lt;br&gt;
CA Sales Control&lt;br&gt;
Escape I&lt;br&gt;
Bugs Bubble&lt;br&gt;
Besieged&lt;br&gt;
&lt;br /&gt;&lt;br /&gt;</description>
            <pubDate>Fri, 27 Nov 2009 11:37:42 +0100</pubDate>
        </item>
    </channel>
</rss>
