﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Toronto Area Security Klatch - Events</title>
    <description>If you're unable to attend an event but are interested in what TASK covered, as well as any resources that we introduced, provided or discussed, this is a great page to visit. 

Presentations (or partial presentations) are linked below where possible. Some TASK meetings are heavily demo focused, or information that can not be distributed is presented. For maximum value, be sure to join us every month!

Thanks to all who attend our monthly meetings and make them such success!  </description>
    <link>http://www.task.to/Events/tabid/351/BlogId/2/Default.aspx</link>
    <language>en-US</language>
    <webMaster>admin@task.to</webMaster>
    <pubDate>Fri, 30 Jul 2010 20:38:23 GMT</pubDate>
    <lastBuildDate>Fri, 30 Jul 2010 20:38:23 GMT</lastBuildDate>
    <docs>http://backend.userland.com/rss</docs>
    <generator>Blog RSS Generator Version 3.5.1.19887</generator>
    <item>
      <title>TASK August - The Best of Blackhat, Defcon, and Vegas ... Baby!</title>
      <description>&lt;p&gt;Wednesday, 25 August - TASK presents its eyes-on, from-the-floor report from the Vegas security conferences, featuring cutting-edge attacks and defences, new data security research, and the traumatic effects of letting 5,000+ hackers loose on the city of Vegas!&lt;/p&gt;&lt;a href=http://www.task.to/Events/tabid/351/EntryId/67/TASK-August-The-Best-of-Blackhat-Defcon-and-Vegas-Baby.aspx&gt;More...&lt;/a&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/67/TASK-August-The-Best-of-Blackhat-Defcon-and-Vegas-Baby.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/67/TASK-August-The-Best-of-Blackhat-Defcon-and-Vegas-Baby.aspx</guid>
      <pubDate>Wed, 07 Jul 2010 14:16:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=67</trackback:ping>
    </item>
    <item>
      <title>TASK July - Meeting is Cancelled</title>
      <description>&lt;p&gt;No TASK meeting in July&lt;/p&gt;&lt;a href=http://www.task.to/Events/tabid/351/EntryId/66/TASK-July-Meeting-is-Cancelled.aspx&gt;More...&lt;/a&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/66/TASK-July-Meeting-is-Cancelled.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/66/TASK-July-Meeting-is-Cancelled.aspx</guid>
      <pubDate>Wed, 07 Jul 2010 14:15:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=66</trackback:ping>
    </item>
    <item>
      <title>TASK June – It’s Maker's Month! </title>
      <description>&lt;p&gt;Several TASK "regulars" are involved in what's informally known as the "Maker Community"; small, grass-roots groups that meet to push the limits of home-grown technology projects and artistic expression with a fierce DIY ethos. We invited a few groups to present their current projects and interests and we'll be receiving presentations from Seth Hardy (Site 3 coLaboratory) and James Arden (Think|Haus) - both leaders in the Canadian Maker's space. &lt;br /&gt;
 &lt;/p&gt;&lt;a href=http://www.task.to/Events/tabid/351/EntryId/65/TASK-June-It-s-Makers-Month.aspx&gt;More...&lt;/a&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/65/TASK-June-It-s-Makers-Month.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/65/TASK-June-It-s-Makers-Month.aspx</guid>
      <pubDate>Thu, 17 Jun 2010 15:38:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=65</trackback:ping>
    </item>
    <item>
      <title>Payment Card Fraud - May 26, 2010</title>
      <description>&lt;div class="Normal"&gt;
&lt;p&gt;&lt;span style="font-size: larger;"&gt;&lt;strong&gt;Payment Card Fraud &lt;/strong&gt;&lt;/span&gt;(Sponsored  by &lt;span style="line-height: 115%; font-family: "Arial","sans-serif"; color: black; font-size: 10pt;"&gt;Giesecke &amp; Devrient; &lt;span style="font-family: "Arial","sans-serif"; font-size: 10pt;"&gt;&lt;a href="http://www.gi-de.com/"&gt;www.gi-de.com&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="line-height: 115%; font-family: "Arial","sans-serif"; color: black; font-size: 10pt;"&gt;&lt;span style="font-family: "Arial","sans-serif"; font-size: 10pt;"&gt;&lt;b&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;Topic 1: EMV in Canada&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;The rollout of chip-enabled credit cards in Canada is  nearing completion. This coordinated set of presentations will focus on  the technology – how it works, which governing bodies and standards are  involved, and what types of fraud risk are mitigated via the use of EMV  (and which ones are not). Finally, the presentation will also cover some  of the new technologies in EMV and mobile payments. The following is a  detailed list of topics to be covered:&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Chip-based Payment Cards - Governing Bodies, EMVCo,  Standards and Specifications&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Specifications of the Major Payment Associations  (Visa, MC, Amex)&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Smart Card Chip Security - Hardware and Software  Components&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;EMV Payment Transactions – Online, Offline and  Contactless&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Card Risk Management Parameters and CVM List&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;New Technologies in EMV Payments (including Display  Card Technology and Mobile Phone Payments)&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 18pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;•&lt;span style="font: 7pt 'Times New Roman';"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Payments Fraud - Trending and the Benefits of EMV&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt; &lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;Speakers:&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; margin: 0cm 0cm 12pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Matthew Tremmaglia, Giesecke and  Devrient (G&amp;D)&lt;br /&gt;
Matthew joined G&amp;D in 2007 as part of the Strategic Account  Management Team. During his career at G&amp;D, he has worked closely  with many Canadian financial institutions as they launch their EMV  migrations to chip based payment cards. Currently, Matthew is working on  initiatives in Canada that span EMV: Instant Issuance, Mobile payments,  Transit solutions and a variety of other innovative concepts that  leverage high-security products. &lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: normal; margin: 0cm 0cm 12pt;"&gt;&lt;span style="color: black; font-size: 10pt;"&gt;Nick Pisarev, Giesecke &amp;  Devrient&lt;br /&gt;
Nick has over 10 years of international experience in the payment  industry. He joined G&amp;D Canada in 2004 bringing with him a reputable  knowledge in smart card and secure payment technologies from the  European market. Managing the Emerging Technology team, Nick’s extensive  experience has been instrumental in assisting Canadian Financial  Institutions for the successful migration to EMV chip technology. In  collaboration with G&amp;D’s international Product and R&amp;D teams and  working closely with the Payment Associations, Nick is helping to  pioneer new technologies in the Canadian payment market. This includes  dual interface payment card products, mobile payment solutions and  2-factor authentication.  &lt;/span&gt;&lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="line-height: 115%; color: black; font-size: 10pt;"&gt;Fred Hopper, Giesecke &amp; Devrient&lt;/span&gt;&lt;span style="line-height: 115%; color: black; font-size: 10pt;"&gt;&lt;br clear="all" /&gt;
&lt;/span&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;Fred is  G&amp;D’s Director of Security and you may remember his Payment Card  Technology presentation at TASK in June 2007. His background is  originally in IT Infrastructure and during the past decade he has  specialized in Information and Physical Security, working both as a  consultant and as a security department head where he has developed an  expertise in payment card security best practices and compliance.  He is  an active participant in the Canadian financial card security community  and has assisted law enforcement investigations and prosecutions in  payment card counterfeiting.  Fred is also a CISSP and CISA and  occasionally speaks at conferences on topics such as phone spoofing and  targeted phishing. &lt;/span&gt;&lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;b&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;Topic 2: A Law Enforcement Perspective on Payment Card  Fraud&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;This presentation will provide a law enforcement  perspective on the payment card fraud trends starting with appearance of  card skimming in the late 1990’s up to Project Instrument, the largest  payment card counterfeiting prosecution in Canadian history. Jacques  will also discuss an interesting encryption issue in this case which may  be of interest to TASK members. Can defendants be forced to provide the  passwords necessary to decrypt encrypted media seized by police? Must  the state release the same encrypted media without receiving the  necessary passwords in order to know what they are releasing?&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;Speaker:&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin: 0cm 0cm 10pt;"&gt;&lt;span style="line-height: 115%; font-size: 10pt;"&gt;Jacques Bois, Ontario Provincial Police (OPP)&lt;br /&gt;
Jacques is a 21 year veteran of the OPP. He spent the first eight years  in uniform capacity before accepting a Detective position within the  OPP's Behavioural Sciences Section. From there, he transferred to the  Anti-Rackets Section where he investigated enterprise crimes, before  joining the Payment Card and Identity Crime Unit - a Unit he eventually  managed. Jacques returned to Field Crime Unit duties three years ago and  currently holds the rank of Detective Staff Sergeant. He oversees four  Detachment Crime Units, the Central Region Major Incident Support Unit,  and is the program manager for the OPP Central Region Abuse Issues and  DNA Program.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;+++++++++++++++++++++++++++++++++++++++++++++++++&lt;br /&gt;
TASK - MAY MEETING&lt;br /&gt;
&lt;br /&gt;
Location:  The Bahen Centre for Information Technology, U of T&lt;br /&gt;
                   40 St. George Street, M5S 2E4&lt;br /&gt;
                   NOTE:  This is NOT where we met last month, or even  the month before ...&lt;br /&gt;
Time:         6:00 PM to 9:00 PM&lt;br /&gt;
+++++++++++++++++++++++++++++++++++++++++++++++++&lt;/p&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/64/Payment-Card-Fraud-May-26-2010.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/64/Payment-Card-Fraud-May-26-2010.aspx</guid>
      <pubDate>Wed, 26 May 2010 23:30:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=64</trackback:ping>
    </item>
    <item>
      <title>April TASK meeting &amp; SecTor 2010 - April 28, 2010</title>
      <description>&lt;p&gt;&lt;strong&gt;Presentation 0.5 - Conference Overview &lt;/strong&gt;
&lt;div&gt;Robert Beggs, DigitalDefence&lt;/div&gt;
&lt;div&gt;The Canadian Technical Security Conference (Cornwall) will be  reviewed. This annual conference focused on technical security - "bugs",  and "bug sweeping".&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;strong&gt;Presentation 1 - Covert Use of Data Resources&lt;/strong&gt; Robert Beggs,  DigitalDefence&lt;/div&gt;
&lt;div&gt;A data system (laptop, iPhone) can not only be hacked, but it can  be used to conduct covert surveillance on a target. Keyloggers  and  compromised cameras and microphones extend surveillance  capabilities.  &lt;/div&gt;
&lt;div&gt; This talk will provide an overview and practical examples on  how  systems are compromised, as well as how to rapidly detect and  respond  to the compromise.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;strong&gt;Presentation 2 - An Examination of Two Recent Attacks + "Hacking" &lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Certifications&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;Terry Cutler, Security Researcher&lt;/div&gt;
&lt;div&gt;The Aurora breach that targeted Google and 34 other companies, and  the kneber botnet variant that managed to infiltrate nearly  2,500  corporate networks, are targeted attacks. During the first half  of  &lt;/div&gt;
&lt;div&gt;our talks, we will use cutting-edge tools such as CORE IMPACT to  demonstrate how they worked (and why they were so effective), and how to  detect and mitigate their effects. The attack will also demonstrate  getting access to a corporate using a spear-phishing attack via  Linkedin.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
During the second half of the talk, we'll switch gears to talk  about  the practice of certifying ethical hackers/penetration  testers. Which certification is "the best one", and how is the market  accepting these certifications? Come prepared for a lively discussion!&lt;br /&gt;
&lt;br /&gt;
&lt;div&gt;LOCATION&lt;/div&gt;
&lt;div&gt;Wednesday, 28 April 2010 - 6:00 to 9:00&lt;/div&gt;
&lt;div&gt;Health Sciences Building, 155 College Street Toronto, M5T 3M7 - 6th  Floor&lt;/div&gt;
&lt;/div&gt;
&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;</description>
      <link>http://task.cms.ca/Events/tabid/351/EntryId/63/April-TASK-meeting-SecTor-2010-April-28-2010.aspx</link>
      <guid isPermaLink="true">http://task.cms.ca/Events/tabid/351/EntryId/63/April-TASK-meeting-SecTor-2010-April-28-2010.aspx</guid>
      <pubDate>Wed, 28 Apr 2010 23:30:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=63</trackback:ping>
    </item>
    <item>
      <title>Vulnerability Madness! - March 31, 2010</title>
      <description>&lt;p&gt;&lt;strong&gt;March Meeting - Vulnerability Madness!  Speakers: &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;1. &lt;strong&gt; Roy Firestein, DigitalDefence&lt;/strong&gt;&lt;br /&gt;
"Security Vulnerabilities in Cable Modems"&lt;br /&gt;
Roy has conducted research to identify vulnerabilities in the default  installation of commercial cable modems (typical of the type installed  in the Toronto area).  He will outline his research, and let you know  how you can prevent attacks against your home and small business  networks.&lt;/p&gt;
&lt;p&gt;2.  &lt;strong&gt;Ted LeRay, Independent Researcher&lt;/strong&gt;&lt;br /&gt;
"BRST - the Border Router Security Tool (a SourceForge Project")&lt;br /&gt;
Cisco border routers (routers between the firewall and the Internet) are  ubiquitous and are often not as secure as they can be. Border routers  are exposed to the Internet and should be thoroughly hardened. Learn how  to disable unneed services, enable desireable services, handle spoofed  traffic, secure remote access, and more. The goal of the BRST project is  to make securing border routers easy for administrators and freely  accessible to everyone.&lt;br /&gt;
See: &lt;a href="http://sourceforge.net/projects/borderroutersec/"&gt;http://sourceforge.net/projects/borderroutersec/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;3.  &lt;strong&gt;Tyler Reguly, Security Researcher&lt;/strong&gt;&lt;br /&gt;
"Something about Web Vulnerabilities"&lt;br /&gt;
Tyler has been conducting research on some of the more esoteric and  interesting aspects of website vulnerabilities - as per normal, he's  holding off on the specific details at this time ... but we'll update  the site when we can squeeze a bit more information from him!&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/62/Vulnerability-Madness-March-31-2010.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/62/Vulnerability-Madness-March-31-2010.aspx</guid>
      <pubDate>Wed, 31 Mar 2010 23:30:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=62</trackback:ping>
    </item>
    <item>
      <title>Forensics Evening - February 22, 2010</title>
      <description>&lt;p&gt;&lt;span style="font-family: Arial;"&gt;&lt;strong&gt;Topic:"Building an Information Security Startup in Canada" - Richard Reiner, Enomaly&lt;/strong&gt;&lt;br /&gt;
Richard, former Chief Security and Technology Officer at Telus Canada, is one of Canada's most seasoned entrepeneurs specializing in Information Security.  A member of multiple advisory and venture capital groups, he has gained a unique perspective on the trials, tribulations, and successes of security startups in Canada.  He will share his experiences during his talk, and also comment on security in the cloud...&lt;/span&gt;&lt;/p&gt;&lt;a href=http://www.task.to/Events/tabid/351/EntryId/61/Forensics-Evening-February-22-2010.aspx&gt;More...&lt;/a&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/61/Forensics-Evening-February-22-2010.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/61/Forensics-Evening-February-22-2010.aspx</guid>
      <pubDate>Mon, 22 Feb 2010 16:40:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=61</trackback:ping>
    </item>
    <item>
      <title>Direct Access - November 25, 2009 </title>
      <description>&lt;p&gt;&lt;span class="text"&gt;&lt;b&gt;Topic: Lifting the Lid: DirectAccess in Windows 7&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Speaker: Pat Telford&lt;/b&gt;&lt;br /&gt;
A new remote access strategy is taking form with the release of Windows 7 and Windows Server 2008 R2. DirectAccess uses IPv6, IPsec, and some DNS frigonometry to allow clients roaming the internet to get secure access to internal resources without a VPN. It works from the moment you lift the lid on your laptop and allows IT administrators to manage those troublesome, never-at-home computers. But you need to understand how the underlying technologies work to be able to assess its security and suitability for your organization. This session will dig into some of the technical details and things to be aware of in this new technology. Presentation can be &lt;a href="http://www.task.to/LinkClick.aspx?fileticket=AVDx3J0%2bvmE%3d&amp;tabid=351"&gt;downloaded here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Topic: RF Countersurveillance&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Speaker: Byron Sonne&lt;/b&gt;&lt;br /&gt;
RF Countersurveillance is an entry level talk to the basics of trunk-tracking radio scanners and how to use them. Trunk-tracking radio systems are in use by almost all police forces and a large number of businesses. Everything from equipment to programming, as well as regulatory and legal ramifications will be covered. &lt;/span&gt;&lt;/p&gt;</description>
      <link>http://www.task.to/Events/tabid/351/EntryId/60/Direct-Access-November-25-2009.aspx</link>
      <guid isPermaLink="true">http://www.task.to/Events/tabid/351/EntryId/60/Direct-Access-November-25-2009.aspx</guid>
      <pubDate>Wed, 25 Nov 2009 17:30:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=60</trackback:ping>
    </item>
    <item>
      <title> SecTor Talks - October 28, 2009 </title>
      <description>&lt;p&gt;&lt;span class="text"&gt;&lt;span class="text"&gt;&lt;b&gt;Hacking the Privacy Legislation - Tracy Ann Kosa&lt;/b&gt; &lt;br /&gt;
In today’s environment of particularly scarce resources, privacy can be easily buried under its sexier older sister - security. But the need to balance the two is an ongoing concern when it comes to any system that collects, uses and discloses personal information. This session will focus on exploring the differences between the two, and identifying what areas of the privacy legislation are mainly unenforced or unenforceable. In addition, it will identify what people, processes and technical requirements overlap and give you better bang for your compliance dollar. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Portable Document Malware, the Office, and You - Get owned with it, can't do business without it - Seth Hardy&lt;/b&gt; &lt;br /&gt;
Many new types of malware, particularly targeted attacks against high-value targets, are using a very effective vector: common document formats such as Word, PowerPoint, and PDF. Unlike executables, businesses can't just block these ubiquitous file types. While there are ways to spot this kind of malware, many antivirus companies are lagging behind with generic detection, making AV evasion simpler than you'd be comfortable with. &lt;br /&gt;
We'll start with a high level overview of the file formats for Microsoft Office (Word, Excel, PowerPoint) and PDF, and see how they can be used to distribute malware. Then, we'll take a look at why these formats are difficult to scan using traditional (signature-based) antivirus techniques. Finally, we'll cover effective (heuristic-based, deep inspection) methods for spotting malware which attempts to hide in file formats which can't just be blocked. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Crimeware: Web Exploitation Kits Revealed - Roy Firestein&lt;/b&gt; &lt;br /&gt;
The session introduces the attendee to how crimeware has become increasingly popular in recent years, the indistinguishable similarities with legitimate business and the dangers the internet community is facing. There will also be a live demonstration of the infamous Mpack (or other similar kit), including a minor exercise encouraging one to identify methods to mitigate or detect such scenarios. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <link>http://task.cms.ca/Events/tabid/351/EntryId/59/-SecTor-Talks-October-28-2009.aspx</link>
      <guid isPermaLink="true">http://task.cms.ca/Events/tabid/351/EntryId/59/-SecTor-Talks-October-28-2009.aspx</guid>
      <pubDate>Wed, 28 Oct 2009 17:28:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=59</trackback:ping>
    </item>
    <item>
      <title>15min SpeedTalks - September 30, 2009 </title>
      <description>&lt;p&gt;&lt;span class="text"&gt;&lt;span class="text"&gt;&lt;b&gt;Topic: SpeedTalks.&lt;/b&gt;&lt;br /&gt;
&lt;ul&gt;
    &lt;li&gt;Ms. Mary-Lynn Manton and several students will be presenting a brief  	overview of the information security program at Seneca College, and some of  	the research that they have been conducting.&lt;/li&gt;
    &lt;li&gt;Mr. Eldon Sprickerhoff, will be presenting: The Rumours of My Death Have  	Been Greatly Exaggerated - Redeeming NIDS in the Corporate Environment&lt;/li&gt;
    &lt;li&gt;Mr. Serge Gorbunov, speaking on the Canadian Honeynet Project&lt;/li&gt;
    &lt;li&gt;Mr. Colin McGregor, speaking on Damn Vulnerable Linux&lt;/li&gt;
    &lt;li&gt;Mr. Byron Sonne and Jeremy Richards will talk on “Hacking Public  	Opinion”&lt;/li&gt;
    &lt;li&gt;Mr. Chris Kulbakas will be speaking on formal methods and PAM for Linux&lt;/li&gt;
    &lt;li&gt;Mr. Feroz Hyder will speak about academic security in a college  	environment&lt;/li&gt;
&lt;/ul&gt;
If you have an idea for a talk, please email us at info_at_task_dot_to&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <link>http://task.cms.ca/Events/tabid/351/EntryId/58/15min-SpeedTalks-September-30-2009.aspx</link>
      <guid isPermaLink="true">http://task.cms.ca/Events/tabid/351/EntryId/58/15min-SpeedTalks-September-30-2009.aspx</guid>
      <pubDate>Wed, 30 Sep 2009 17:25:00 GMT</pubDate>
      <trackback:ping>http://www.task.to/DesktopModules/Blog/Trackback.aspx?id=58</trackback:ping>
    </item>
  </channel>
</rss>