<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
	<channel>
<title>KRvW Associates Anouncements</title><link>http://www.KRvW.com/index.html</link><description>What&#x27;s happening at KRvW</description><dc:language>en</dc:language><dc:creator>Ken@KRvW.com</dc:creator><dc:rights>Copyright 2008-2009 KRvW Associates&#x2c; LLC</dc:rights><dc:date>2010-08-12T09:23:40-04:00</dc:date><admin:generatorAgent rdf:resource="http://www.realmacsoftware.com/" />
<admin:errorReportsTo rdf:resource="mailto:Ken@KRvW.com" /><sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>
<lastBuildDate>Thu, 12 Aug 2010 09:26:05 -0400</lastBuildDate><item><title>Column: Opinion: Making apps safe is hard</title><dc:creator>Ken@KRvW.com</dc:creator><category>None</category><dc:date>2010-08-12T09:23:40-04:00</dc:date><link>http://www.KRvW.com/events_log/files/02ce78a1508c867a854d250091a19af4-25.php#unique-entry-id-25</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/02ce78a1508c867a854d250091a19af4-25.php#unique-entry-id-25</guid><content:encoded><![CDATA[<span style="font:12px Arial, Verdana, Helvetica, sans-serif; ">In this month&rsquo;s </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com" rel="external">Computerworld</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> column, </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/s/article/9180579/Making_apps_safe_is_hard_work?taxonomyId=17" rel="external">Ken delves into the difficulties</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> faced by companies that run app stores. It turns out that vetting apps for security criteria is a really tough problem to solve, and one that&rsquo;s not likely to happen to any great degree on any of the popular app stores today.<br /></span>]]></content:encoded></item><item><title>Column: Opinion: Maybe users aren&#x27;t so funny after all</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2010-03-16T17:41:33-04:00</dc:date><link>http://www.KRvW.com/events_log/files/952423b348b704dee11034ddfdb26e1e-24.php#unique-entry-id-24</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/952423b348b704dee11034ddfdb26e1e-24.php#unique-entry-id-24</guid><content:encoded><![CDATA[<span style="font:12px Arial, Verdana, Helvetica, sans-serif; ">This month in  </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com" rel="external">Computerworld</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; ">, Ken continues to delve into examples of how the security community has failed the everyday computer user.  Click </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/s/article/9171458/Opinion_Maybe_users_aren_t_so_funny_after_all?taxonomyId=17&pageNumber=1" rel="external">here</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> to read more on user base misconceptions regarding e-mail and Web site safety.</span>]]></content:encoded></item><item><title>Column: Opinion: Alice&#x27;s adventures in cyberland</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2010-02-18T18:59:44-05:00</dc:date><link>http://www.KRvW.com/events_log/files/1ded2874ab387eaef149e562709566c0-23.php#unique-entry-id-23</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/1ded2874ab387eaef149e562709566c0-23.php#unique-entry-id-23</guid><content:encoded><![CDATA[<span style="font:12px Arial, Verdana, Helvetica, sans-serif; ">In Ken&rsquo;s February </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com" rel="external">Computer world</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> column, he uses a personal experience to point out how computer security has failed the everyday consumer.  Click </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/s/article/9157198/Opinion_Alice_s_adventures_in_cyberland?taxonomyId=17&pageNumber=1" rel="external">here</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> to read how this experience further supports his argument for an app store for all users. </span>]]></content:encoded></item><item><title>Column: IT&#x27;s 5 big security mistakes</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2010-01-18T16:13:27-05:00</dc:date><link>http://www.KRvW.com/events_log/files/30fb523e0317a491a16e48b9cc417a23-22.php#unique-entry-id-22</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/30fb523e0317a491a16e48b9cc417a23-22.php#unique-entry-id-22</guid><content:encoded><![CDATA[<span style="font:12px Arial, Verdana, Helvetica, sans-serif; ">Happy New Year!  Ever resolve not to repeat mistakes?  In January's </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/" rel="external">Computerworld</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> column, Ken discusses </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/s/article/9144300/Opinion_IT_s_5_big_security_mistakes" rel="external">IT's 5 big security mistakes</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> that industry never seems to learn from.  </span>]]></content:encoded></item><item><title>Column: An app store for all?</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2010-01-18T15:54:49-05:00</dc:date><link>http://www.KRvW.com/events_log/files/7ed966e5f1a7eef62edb8b72e2245b87-21.php#unique-entry-id-21</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/7ed966e5f1a7eef62edb8b72e2245b87-21.php#unique-entry-id-21</guid><content:encoded><![CDATA[<span style="font:12px Arial, Verdana, Helvetica, sans-serif; ">Are you an app store fanatic? Click </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/s/article/9142552/Opinion_An_app_store_for_all_?taxonomyId=17&pageNumber=1" rel="external">here</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> for Ken's December </span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "><a href="http://www.computerworld.com/" rel="external">Computerworld</a></span><span style="font:12px Arial, Verdana, Helvetica, sans-serif; "> column, where he provides his opinion on the app store model for desktop computers.</span>]]></content:encoded></item><item><title>KRvW Associates&#x2c; LLC announces a new training partner</title><dc:creator>Ken@KRvW.com</dc:creator><category>Announcements</category><dc:date>2009-11-13T15:40:06-05:00</dc:date><link>http://www.KRvW.com/events_log/files/83760d820727175bc85673f144e079a0-20.php#unique-entry-id-20</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/83760d820727175bc85673f144e079a0-20.php#unique-entry-id-20</guid><content:encoded><![CDATA[KRvW Associates, LLC is pleased to announce a partnership with the <a href="http://www.saltbushgroup.com/" rel="external">Saltbush Group</a>.  Following recent training for the <a href="http://www.deewr.gov.au/Pages/default.aspx" rel="external">Department of Education, Employment and Workplace Relations (DEEWR)</a>, Ken received the following kind words from one of the students in the class:<br /><br />"Ken van Wyk runs an up-to-date comprehensive course that I would highly recommend it to anyone in this area.<br /><br />He presents with years of experience and stories, in a friendly, down-to-earth fashion, adjusting his presentation style to the audience.  In the course, he presents a balanced approach and explains the cost-benefits of mitigation controls.  He never gets carried away and reminds us of the real goal, which is to serve busines.  He doesn't try to push any particular vender, technology or system.  Nor does he try to sell you any of his books but he will be glad to sign them if you do.<br /><br />I learnt a lot and really enjoyed the course. Thanks Ken!"<br /><span style="font:12px Cambria; "><br /></span>]]></content:encoded></item><item><title>Column: Opinion: Can the SSL vulnerability hurt you?</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-11-13T15:22:29-05:00</dc:date><link>http://www.KRvW.com/events_log/files/5df29ececc51fbaff3c4061f8d35ec3a-19.php#unique-entry-id-19</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/5df29ececc51fbaff3c4061f8d35ec3a-19.php#unique-entry-id-19</guid><content:encoded><![CDATA[Ken's column in November's issue of <a href="http://www.computerworld.com" rel="external">Computerworld</a> is now available.  This month Ken offers his opinion on whether the latest SSL vulnerability can hurt you.  Click <a href="http://www.computerworld.com/s/article/9140741/Opinion_Can_the_SSL_vulnerability_hurt_you_?taxonomyId=17" rel="external">here</a> to read his column.<span style="font:12px Cambria; "><br /></span>]]></content:encoded></item><item><title>Column: Why application-layer defenses belong in the applications</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-10-12T12:56:14-04:00</dc:date><link>http://www.KRvW.com/events_log/files/fdbd4fd0d22dd6ea62190919244a14a1-18.php#unique-entry-id-18</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/fdbd4fd0d22dd6ea62190919244a14a1-18.php#unique-entry-id-18</guid><content:encoded><![CDATA[In this month's <a href="http://www.computerworld.com" rel="external">Computerworld</a>, Ken's column discusses why application-layer defenses belong in the applications. Click <a href="http://www.computerworld.com/s/article/9139244/Opinion_Why_application_layer_defenses_belong_in_the_applications?taxonomyId=17&pageNumber=2" rel="external">here</a> to read his column.]]></content:encoded></item><item><title>New Q4 speaking engagement added</title><dc:creator>Ken@KRvW.com</dc:creator><category>Events</category><dc:date>2009-09-09T16:53:06-04:00</dc:date><link>http://www.KRvW.com/events_log/files/8bbe4c2dda7842f2314c749d2b08a8f3-17.php#unique-entry-id-17</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/8bbe4c2dda7842f2314c749d2b08a8f3-17.php#unique-entry-id-17</guid><content:encoded><![CDATA[Ken will be presenting at the <a href="http://www.clcert.cl" rel="external">CLCERT</a> / <a href="http://www.first.org" rel="external">FIRST</a> <a href="http://www.first.org/events/colloquia/oct2009/" rel="external">Technical Colloquium</a> and <a href="http://www.clcert.cl/tc2009/sobre.php" rel="external">Security Workshop</a> in Santiago, Chile, on 20-23 October 2009.  (NOTE: The Security Workshop is open to the public, but the FIRST Technical Colloquium is only open to FIRST member organizations.)<br /><br />Contact us directly for further information.<br />]]></content:encoded></item><item><title>Column: No more excuses for SQL injection</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-09-03T11:34:59-04:00</dc:date><link>http://www.KRvW.com/events_log/files/d42b88d37b390869c77d02f9dc4a85de-16.php#unique-entry-id-16</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/d42b88d37b390869c77d02f9dc4a85de-16.php#unique-entry-id-16</guid><content:encoded><![CDATA[Ken has a new monthly column, in <a href="http://www.computerworld.com" rel="external">Computerworld</a>.  <a href="http://www.computerworld.com/s/article/9136223/Opinion_Irresponsibility_runs_amok_at_Black_Hat_Defcon" rel="external">Last month&rsquo;s column</a> discussed vulnerability disclosure, and <a href="http://www.computerworld.com/s/article/9137478/Opinion_No_more_excuses_for_SQL_injection_attacks" rel="external">this month</a> he takes on SQL Injection attacks and how easy they are to prevent.<br /><br />]]></content:encoded></item><item><title>Fall 2009 Speaking Calendar</title><dc:creator>Ken@KRvW.com</dc:creator><category>Events</category><dc:date>2009-08-21T08:12:51-04:00</dc:date><link>http://www.KRvW.com/events_log/files/c7b76eb9d966e26342dc69f308e52146-15.php#unique-entry-id-15</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/c7b76eb9d966e26342dc69f308e52146-15.php#unique-entry-id-15</guid><content:encoded><![CDATA[We&rsquo;ve added a few public speaking engagements on the Fall 2009 calendar.  Please come out and see us at the following events:<br /><br /><ul class="disc"><li><em>21-25 September</em>: <strong>Advanced Incident Handling</strong>, Carnegie Mellon University.  Ken and Rick are co-instructing for the Software Engineering Institute, delivering their Advanced Incident Handling class at SEI&rsquo;s Arlington, Virginia USA facility.  <a href="http://www.sei.cmu.edu/products/courses/cert/csih-advanced.html" rel="external">Details can be found here.</a></li><li><em>28-30 October</em>: <strong>IDS/IPS: Intrusion Detection In-Depth</strong>.  Ken will be delivering this 3-day, in-depth, hands-on workshop in Rome, Italy for Technology Transfer.  <a href="http://www.technologytransfer.eu/event/477/IDS/IPS_Intrusion_Detection_and_Prevention_in_depth.html" rel="external">Details can be found here.</a></li><li><em>2-4 November</em>: <strong>Building Secure Web Applications in Java EE</strong>.  Ken will be delivering this hands-on workshop in Rome, Italy for Technology Transfer.  <a href="http://www.technologytransfer.eu/event/928/SECURE_CODING_Building_Secure_Web_Applications_in_Java/J2EE.html" rel="external">Details can be found here.</a></li><li><em>10-13 November</em>: <strong>The Essential Role of Infosec in Secure Software Development</strong>.  Ken will be presenting this 1-hour technical session at OWASP DC in Washington, DC, USA.  <a href="http://www.owasp.org/index.php/AppSecDC_Schedule_09" rel="external">Details can be found here.</a></li></ul><br />For any questions about these events or workshops/sessions, please contact us.<br /><br />]]></content:encoded></item><item><title>Added 1-day dev module to class</title><dc:creator>Ken@KRvW.com</dc:creator><category>Announcements</category><dc:date>2009-07-21T18:13:50-04:00</dc:date><link>http://www.KRvW.com/events_log/files/0dbf42190381306cf8372932cae2476a-14.php#unique-entry-id-14</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/0dbf42190381306cf8372932cae2476a-14.php#unique-entry-id-14</guid><content:encoded><![CDATA[Good news.  We&rsquo;ve added a 1-day optional addition to our 3-day web application security class.  <br /><br />This optional day includes 3 in-depth coding labs for software developers to fine tune their Java EE skills.  The labs include patching existing Java EE code to make it resilient to cross-site scripting (XSS) and SQL injection flaws, as well as adding various role-based access control code to some existing web servlets.<br /><br />Additionally, in this 1-day add-on, students will get hands-on exposure to a commercial static code analysis tool by analyzing some existing open source Java software.<br /><br />See our <a href="../training/training.html" rel="self" title="Training">course descriptions</a> for more details, or contact us directly.<br /><br />]]></content:encoded></item><item><title>Speaking at Infocon</title><dc:creator>Ken@KRvW.com</dc:creator><category>Events</category><dc:date>2009-03-10T00:13:25-04:00</dc:date><link>http://www.KRvW.com/events_log/files/e385b54e460c3fcef1860c31dbe61af0-13.php#unique-entry-id-13</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/e385b54e460c3fcef1860c31dbe61af0-13.php#unique-entry-id-13</guid><content:encoded><![CDATA[Another addition to our Q1-Q2 speaking engagements, Rick Forno will be moderating a panel on US CyberSecurity at Infowarcon in April.  See <a href="http://www.infowarcon.com/content.asp?contenttype=Agenda">InfowarCon Online</a> for details.<br />]]></content:encoded></item><item><title>OWASP podcast features KRvW</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-02-27T10:50:56-05:00</dc:date><link>http://www.KRvW.com/events_log/files/cc245b73def6870253e8cd9e2254c6d0-12.php#unique-entry-id-12</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/cc245b73def6870253e8cd9e2254c6d0-12.php#unique-entry-id-12</guid><content:encoded><![CDATA[Ken was recently featured in an <a href="http://www.owasp.org" rel="external">OWASP</a> Podcast as part of their ongoing series of podcasts.  <a href="http://www.owasp.org/index.php/Podcast_10" rel="external">Click here</a> for a link to the podcast notes.<br />]]></content:encoded></item><item><title>Hands-on 3-day IDS tutorial added</title><dc:creator>Ken@KRvW.com</dc:creator><category>Announcements</category><dc:date>2009-02-23T17:35:25-05:00</dc:date><link>http://www.KRvW.com/events_log/files/1fcafa5414365bf8428010e951c0cbbd-11.php#unique-entry-id-11</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/1fcafa5414365bf8428010e951c0cbbd-11.php#unique-entry-id-11</guid><content:encoded><![CDATA[By popular demand, we&rsquo;ve recently added a hands-on 3-day workshop on intrusion detection and prevention systems.  See our <a href="../training/training.html" rel="self" title="Training">course descriptions</a> for details.]]></content:encoded></item><item><title>OWASP: Helping web developers write secure code</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-02-03T11:01:14-05:00</dc:date><link>http://www.KRvW.com/events_log/files/193e5047fd51d1f1a6f9032fa5beefa0-10.php#unique-entry-id-10</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/193e5047fd51d1f1a6f9032fa5beefa0-10.php#unique-entry-id-10</guid><content:encoded><![CDATA[In Ken&rsquo;s February column, <a href="http://itmanagement.earthweb.com/features/article.php/3800326/OWASP-Helping-Web-Developers-Develop-Securely.htm" rel="external">OWASP: Helping Web Developers Develop Securely</a>, he talks about some of the great work being done at <a href="http://www.owasp.org" rel="external">OWASP</a> to help software developers figure out how to write secure web applications.<br /><br /><br />]]></content:encoded></item><item><title>Speaking at FIRST in Kyoto&#x2c; Japan</title><dc:creator>Ken@KRvW.com</dc:creator><category>Events</category><dc:date>2009-01-30T13:05:44-05:00</dc:date><link>http://www.KRvW.com/events_log/files/3cf456a2eee4ad24764ad2465ef536ff-9.php#unique-entry-id-9</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/3cf456a2eee4ad24764ad2465ef536ff-9.php#unique-entry-id-9</guid><content:encoded><![CDATA[In addition to the <a href="http://www.KRvW.com/events_log/files/2f7de4a203b4548deb40c5500eb42ce9-5.php" rel="external" title="Events and announcements:Some public speaking engagements in early 2009">2009 public speaking engagements listed previously</a>, Ken will also be speaking at this year&rsquo;s FIRST conference in Kyoto, Japan.  The conference runs from 28 June through 3 July.  Details are available at the  <a href="http://www.first.org/">FIRST</a> website.<br /><br />Ken will be presenting a session on &ldquo;The essential role of CSIRT in secure software development&rdquo; in which he&rsquo;ll highlight things that incident responders can and ought to be doing to assist in an organization&rsquo;s software development efforts.<br /><br />]]></content:encoded></item><item><title>CWE/SANS TOP 25 Most Dangerous Programming Errors</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-01-12T16:29:55-05:00</dc:date><link>http://www.KRvW.com/events_log/files/2ea3826989196da6869887f847674620-8.php#unique-entry-id-8</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/2ea3826989196da6869887f847674620-8.php#unique-entry-id-8</guid><content:encoded><![CDATA[MITRE&rsquo;s CWE and the SANS Institute together announced today a list of the 25 most dangerous programming problems.  The full story can be found here:<br /><br /><a href="http://www.sans.org/top25errors//">SANS Institute - CWE/SANS TOP 25 Most Dangerous Programming Errors</a><br /><br />Ken helped out early on with the effort by reviewing and commenting on early drafts.  It&rsquo;s a useful effort that should help us better understand the major underlying problems in our code today.  The list should be a must-read for all software developers.<br /><br />]]></content:encoded></item><item><title>Hack forced Twitter into &#x22;full security review&#x22;</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-01-08T09:16:57-05:00</dc:date><link>http://www.KRvW.com/events_log/files/2b1d7debb3defe5b6d8a20364d172185-7.php#unique-entry-id-7</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/2b1d7debb3defe5b6d8a20364d172185-7.php#unique-entry-id-7</guid><content:encoded><![CDATA[Ken is quoted in Sharon Gaudin&rsquo;s latest Computerworld article, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyId=17&articleId=9125239&intsrc=hm_topic">Hack forces Twitter into 'full security review'</a>.<br />]]></content:encoded></item><item><title>Column: Security nightmare in the mobile app gold rush?</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2009-01-07T13:49:53-05:00</dc:date><link>http://www.KRvW.com/events_log/files/bb365f3385ec72288c29ba3fb21b307a-6.php#unique-entry-id-6</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/bb365f3385ec72288c29ba3fb21b307a-6.php#unique-entry-id-6</guid><content:encoded><![CDATA[This month, Ken takes a look at some of the dangers facing mobile application developers in the iPhone (and other) application gold rush.  His column, <a href="http://itmanagement.earthweb.com/secu/article.php/3794691/Security+Nightmare+in+the+iPhone+App+Gold+Rush.htm">Security Nightmare in the iPhone App Gold Rush</a> is now up.<br /><br />]]></content:encoded></item><item><title>Some public speaking engagements in early 2009</title><dc:creator>Ken@KRvW.com</dc:creator><category>Announcements</category><category>Events</category><dc:date>2008-12-03T11:07:17-05:00</dc:date><link>http://www.KRvW.com/events_log/files/2f7de4a203b4548deb40c5500eb42ce9-5.php#unique-entry-id-5</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/2f7de4a203b4548deb40c5500eb42ce9-5.php#unique-entry-id-5</guid><content:encoded><![CDATA[Our 2009 speaking calendar is taking shape quickly.  We have several Q1 commitments already, and several others in the works for Q2 and beyond.<br /><br />Here&rsquo;s quick look at some of what we&rsquo;ll be doing in Q1 and early Q2:<br /><br /><ul class="disc"><li>Ken will be doing a 1-day tutorial on web application security essentials -- inside the OWASP Top-10 -- at <a href="http://distrinet.cs.kuleuven.be/events/essos2009/" rel="external">ESSoS | International Symposium on Engineering Secure Software and Systems</a>, in Leuven, Belgium, 04-06 February 2009.</li><li>Again for 2009, Ken will be on the faculty for the annual <a href="http://www.secappdev.org/" rel="external">SecAppDev 2009</a> seminar in Leuven, Belgium, 02-06 March 2009.</li><li>Ken will present a 1/2-day tutorial at <a href="http://www.sdexpo.com/" rel="external">SD West 2008</a>, in Santa Clara, California, 09-13 March 2009.  </li></ul><ul class="disc"><li>Ken will be presenting a 3-day in-depth seminar on Intrusion Detection and Prevention for <a href="http://www.adastra.com.sg/latest_event_list" rel="external">AdAstra</a>, in Singapore, Singapore, 23-25 March 2009.</li></ul><ul class="disc"><li>Continuing our strong support for Technology Transfer S.r.l., Ken will be teaching an in-depth 3-day seminar on <a href="http://www.technologytransfer.eu/event/408/Building_Secure_Web_Applications_in_Java/J2EE.html" rel="external">Building Secure Web Applications in Java/J2EE</a>, in Rome, Italy, 27-29 April 2009.</li><li><span style="color:#FF0306;font-weight:bold; ">LATE BREAKING</span>: Ken will be doing a 1-day tutorial on the OWASP Top-10 security issues at <a href="http://conference.auscert.org.au/conf2009/">AusCERT2009</a>, in Brisbane, Australia, 17-22 May 2009.</li></ul><br />If you&rsquo;re looking for in-depth technical training at your conference or internally at your company, please don&rsquo;t hesitate to contact us.  We&rsquo;ll gladly work with you to put together a tailored offering that fits perfectly with your needs.<br />]]></content:encoded></item><item><title>Column: Safe online shopping</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2008-12-03T11:05:33-05:00</dc:date><link>http://www.KRvW.com/events_log/files/dd1e60ed3e94bf214f61a947f4bdd57e-4.php#unique-entry-id-4</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/dd1e60ed3e94bf214f61a947f4bdd57e-4.php#unique-entry-id-4</guid><content:encoded><![CDATA[In this month&rsquo;s column, &ldquo;<a href="http://www.esecurityplanet.com/features/article.php/3788486/Safe-Online-Shopping-a-Tech-Experts-Tips.htm" rel="external">Safe Online Shopping: a Tech Expert&rsquo;s Tips</a>,&rdquo; Ken provides some pointers that end users can take to be secure and confident in their holiday shopping.<br /><br />]]></content:encoded></item><item><title>Column: The problem with penetration testing.</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2008-11-16T11:21:05-05:00</dc:date><link>http://www.KRvW.com/events_log/files/98d94d46623174672f3be43c0de442db-3.php#unique-entry-id-3</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/98d94d46623174672f3be43c0de442db-3.php#unique-entry-id-3</guid><content:encoded><![CDATA[In his November column, Ken discusses a major problem that happens far too often in penetration testing: failing to adapt to the language of the audience.  If we really want to have penetration testing--or security testing of any kind--affect real change, we need to write to the audience of the software developer, not (just) the IT Security manager.  The column can be<a href="http://itmanagement.earthweb.com/secu/article.php/3783256/Security+Watch:+Problems+with+Penetration+Testing.htm" rel="external"> found here on datamation</a>.<br /><br />]]></content:encoded></item><item><title>October column</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2008-10-07T12:58:13-04:00</dc:date><link>http://www.KRvW.com/events_log/files/fcd95f4b7bf4c7450c013a2c3737f592-2.php#unique-entry-id-2</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/fcd95f4b7bf4c7450c013a2c3737f592-2.php#unique-entry-id-2</guid><content:encoded><![CDATA[Ken&rsquo;s <a href="http://itmanagement.earthweb.com/secu/article.php/3776116/When+Did+Security+Pros+Forget+the+User?.htm" rel="external">October column</a> has hit the web.<br /><br />This month&rsquo;s topic was about understanding how users will make use of security features in products, and using that knowledge to make the products better.<br />]]></content:encoded></item><item><title>Interviewed on Silver Bullet Podcast</title><dc:creator>Ken@KRvW.com</dc:creator><category>In the news</category><dc:date>2008-10-01T09:51:54-04:00</dc:date><link>http://www.KRvW.com/events_log/files/67fb9cc3cb5e149754a4957d8f3bf140-1.php#unique-entry-id-1</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/67fb9cc3cb5e149754a4957d8f3bf140-1.php#unique-entry-id-1</guid><content:encoded><![CDATA[Ken was recently a guest on <a href="http://www.cigital.com/gem" rel="external">Gary McGraw</a>&rsquo;s <a href="http://www.cigital.com/silverbullet/" rel="external">Silver Bullet</a> podcast.  The podcast is <a href="http://www.cigital.com/silverbullet/show-030/" rel="external">available for listening or download here</a>.<br /><br />The topic was on software security, covering many aspects of what is happening in the field today.<br /><br />]]></content:encoded></item><item><title>New events format</title><dc:creator>Ken@KRvW.com</dc:creator><category>Announcements</category><dc:date>2008-09-29T14:31:40-04:00</dc:date><link>http://www.KRvW.com/events_log/files/9841ccce9d2dc0be81ee88cd975d1230-0.php#unique-entry-id-0</link><guid isPermaLink="true">http://www.KRvW.com/events_log/files/9841ccce9d2dc0be81ee88cd975d1230-0.php#unique-entry-id-0</guid><content:encoded><![CDATA[We&rsquo;ve started this &ldquo;blog&rdquo; format page for KRvW-related announcements, upcoming events, etc.  Feedback is always welcome.<br /><br />Ken<br />]]></content:encoded></item></channel>
</rss>