<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Educause Security Discussion</title>
    <link>http://seclists.org/#educause</link>
    <atom:link href="http://seclists.org/rss/educause.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Securing networks and computers in an academic environment.</description>
    <pubDate>Tue, 22 May 2012 22:30:09 GMT</pubDate>
    <lastBuildDate>Tue, 22 May 2012 22:30:09 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: IPv6 and DHCP</title>
    <link>http://seclists.org/educause/2012/q2/206</link>
    <description>&lt;p&gt;Posted by Curtis, Bruce on May 22&lt;/p&gt;  In the anything else category would be that Macintoshes did not have an IPv6 DHCP client until Lion Mac OS X 7.  So &lt;br&gt;
if you have some older Macs on the network they will still need to use SLAAC.&lt;br&gt;
&lt;br&gt;
  Even with DHCPv6 on a subnet some clients may still use IPv6 Privacy addresses for outgoing connections.&lt;br&gt;
&lt;br&gt;
---&lt;br&gt;
Bruce Curtis                         bruce.curtis () ndsu edu&lt;br&gt;
Certified NetAnalyst II                701-231-8527&lt;br&gt;
North Dakota State...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 22:16:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/206</guid>
  </item>
  <item>
    <title>Chief Information Security Officer position announcement - Kansas State University</title>
    <link>http://seclists.org/educause/2012/q2/205</link>
    <description>&lt;p&gt;Posted by Anthony Phillips on May 22&lt;/p&gt;Chief Information Security Officer - Kansas State University&lt;br&gt;
&lt;br&gt;
The Office of Information Technology Services at Kansas State University is&lt;br&gt;
seeking applicants for a Chief Information Security Officer.  &lt;br&gt;
&lt;br&gt;
The Chief Information Security Officer (CISO) leads the planning,&lt;br&gt;
development, and implementation of the Kansas State University information&lt;br&gt;
systems security program to promote K-State information systems reliability&lt;br&gt;
and accessibility while...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 18:48:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/205</guid>
  </item>
  <item>
    <title>eDiscovery - E-mail Archiving Policy &amp; Software</title>
    <link>http://seclists.org/educause/2012/q2/204</link>
    <description>&lt;p&gt;Posted by Carlos Lobato on May 22&lt;/p&gt;All,&lt;br&gt;
&lt;br&gt;
If you have an e-mail archiving policy and use an &amp;quot;E-mail Management Platform/software&amp;quot; to monitor i.e. ensure &lt;br&gt;
compliance, would you share a copy of your policy and let us know the name of the tool your University uses.&lt;br&gt;
&lt;br&gt;
Thanks,&lt;br&gt;
&lt;br&gt;
Carlos S. Lobato, CISA, CIA&lt;br&gt;
IT Compliance Officer&lt;br&gt;
&lt;br&gt;
New Mexico State University&lt;br&gt;
Information and Communication Technologies&lt;br&gt;
MSC 3AT PO Box 30001&lt;br&gt;
Las Cruces, NM  88003-8001&lt;br&gt;
&lt;br&gt;
Phone: 575-646-5902&lt;br&gt;
Fax:...&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 14:54:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/204</guid>
  </item>


  <item>
    <title>Re: Hard Disk Degaussers</title>
    <link>http://seclists.org/educause/2012/q2/203</link>
    <description>&lt;p&gt;Posted by Chris Green on May 21&lt;/p&gt;Our form is &lt;a  rel=&quot;nofollow&quot; href=&quot;http://main.uab.edu/Sites/it/documents/80781.pdf&quot;&gt;http://main.uab.edu/Sites/it/documents/80781.pdf&lt;/a&gt; which is then batched and taken off site for shredding &lt;br&gt;
and/or incineration (tape media).&lt;br&gt;
&lt;br&gt;
+1 to Steve Werby.  Degaussers don&amp;apos;t give you a visual indication they didn&amp;apos;t work.&lt;br&gt;
&lt;br&gt;
From: The EDUCAUSE Security Constituent Group Listserv [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:SECURITY&quot;&gt;mailto:SECURITY&lt;/a&gt; () LISTSERV EDUCAUSE EDU] On Behalf Of Dan &lt;br&gt;
Sarazen&lt;br&gt;
Sent: Monday, May 21, 2012 7:09 AM&lt;br&gt;
To: SECURITY () LISTSERV EDUCAUSE EDU...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 13:34:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/203</guid>
  </item>
  <item>
    <title>Re: Webcast Today - May 21 regarding SANS training</title>
    <link>http://seclists.org/educause/2012/q2/202</link>
    <description>&lt;p&gt;Posted by Beth Young on May 21&lt;/p&gt;Don&amp;apos;t forget: REN-ISAC and CACR are hosting a web seminar with SANS&lt;br&gt;
today to talk about the next aggregate purchasing window. Join us to&lt;br&gt;
learn how you can get exceptional SANS training at a steeply&lt;br&gt;
discounted price.&lt;br&gt;
&lt;br&gt;
Date: Monday, May 21, 2012&lt;br&gt;
Time: 11:00 Eastern Daylight Time&lt;br&gt;
&lt;br&gt;
Agenda for web seminar:&lt;br&gt;
- Introduction by Doug Pearson&lt;br&gt;
- Securing The Human security awareness training&lt;br&gt;
- OnDemand technical training&lt;br&gt;
- Voucher Credits for live...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 12:28:06 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/202</guid>
  </item>
  <item>
    <title>Re: Hard Disk Degaussers</title>
    <link>http://seclists.org/educause/2012/q2/201</link>
    <description>&lt;p&gt;Posted by Dan Sarazen on May 21&lt;/p&gt;HI All,&lt;br&gt;
&lt;br&gt;
Sorry for hi-jacking this thread, but can anybody tell me what they do (If&lt;br&gt;
anything) to document the sanitization of hard-drives? Once they are&lt;br&gt;
removed from the PC (Which is what is usually tracked in the asset&lt;br&gt;
inventory) how do you track the hard-drives to show they have all been&lt;br&gt;
through the degausser?&lt;br&gt;
&lt;br&gt;
Or do you?&lt;br&gt;
&lt;br&gt;
Thanks,&lt;br&gt;
Dan&lt;br&gt;
&lt;br&gt;
*From:* The EDUCAUSE Security Constituent Group Listserv [mailto:&lt;br&gt;
SECURITY () LISTSERV EDUCAUSE EDU] *On...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 12:08:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/201</guid>
  </item>
  <item>
    <title>Re: Hard Disk Degaussers</title>
    <link>http://seclists.org/educause/2012/q2/200</link>
    <description>&lt;p&gt;Posted by Shamblin, Quinn on May 21&lt;/p&gt;We just got one of these which is doing a very good job.   &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.semshred.com/manual_hard_drive_crushers&quot;&gt;http://www.semshred.com/manual_hard_drive_crushers&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Contact me off list if you want a picture of what this thing does.  They also have a powered one.&lt;br&gt;
&lt;br&gt;
The manual one does need to be bolted to something, but it can destroy a hard drive in 5-10 seconds depending on the a &lt;br&gt;
variety of factors.&lt;br&gt;
&lt;br&gt;
Quinn R Shamblin...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 11:51:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/200</guid>
  </item>
  <item>
    <title>Re: Hard Disk Degaussers</title>
    <link>http://seclists.org/educause/2012/q2/199</link>
    <description>&lt;p&gt;Posted by Steve Werby on May 20&lt;/p&gt;Paul,&lt;br&gt;
&lt;br&gt;
Hard drive destruction is handled by our university&amp;apos;s surplus property&lt;br&gt;
department. They use a hard drive shredder that works well (it replaced&lt;br&gt;
a drill press), but can&amp;apos;t destroy small storage media like SIM cards and&lt;br&gt;
SD cards. My previous university used a manually powered hard drive&lt;br&gt;
bender, which was also effective and about 1/3 of the cost. In a past&lt;br&gt;
environment I discovered a degausser that was in use, but when my office&lt;br&gt;
tested...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 00:37:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/199</guid>
  </item>


  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/198</link>
    <description>&lt;p&gt;Posted by Everett, Alex D on May 18&lt;/p&gt;Well put, Louis.&lt;br&gt;
There must be a good reason why you had fewer- maybe more systems with AV (it was a wake up call for many here) or more &lt;br&gt;
secure web surfing habits for your users.&lt;br&gt;
&lt;br&gt;
Sincerely,&lt;br&gt;
&lt;br&gt;
Alex Everett, CISSP, CCNA&lt;br&gt;
University of North Carolina&lt;br&gt;
&lt;br&gt;
Alex&lt;br&gt;
&lt;br&gt;
You are correct Apple knew about this we all know that a response was slow incoming. I am not sure why Flashback was a &lt;br&gt;
non-event for us, since I have a very small population on McAfee...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 14:47:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/198</guid>
  </item>
  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/197</link>
    <description>&lt;p&gt;Posted by Louis APONTE on May 18&lt;/p&gt;Alex&lt;br&gt;
 &lt;br&gt;
You are correct Apple knew about this we all know that a response was&lt;br&gt;
slow incoming. I am not sure why Flashback was a non-event for us, since&lt;br&gt;
I have a very small population on McAfee anti-malware 1.x or&lt;br&gt;
(9.1.0.4478) I spot checked critical systems at the start of this, what&lt;br&gt;
I found was tons of needed updates queued up. I guess what I said badly&lt;br&gt;
was you need an AV solution in place (McAfee does rather well on snow&lt;br&gt;
leopard and Mt lion ),...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 14:22:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/197</guid>
  </item>


  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/196</link>
    <description>&lt;p&gt;Posted by Cal Frye on May 17&lt;/p&gt;We use Intego VirusBarrier here. Didn&amp;apos;t find the first cases, but is&lt;br&gt;
fairly good at cleaning them up afterward. It can be a bit too&lt;br&gt;
aggressive by default, but doesn&amp;apos;t seem to impair performance much at all.&lt;br&gt;</description>
    <pubDate>Thu, 17 May 2012 21:22:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/196</guid>
  </item>
  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/195</link>
    <description>&lt;p&gt;Posted by Justin Azoff on May 17&lt;/p&gt;The majority of flashback infected machines were personal laptops that&lt;br&gt;
were already infected while on an off campus location.  Almost all were&lt;br&gt;
student owned machines, but a few were faculty/staff.&lt;br&gt;
&lt;br&gt;
We would see IDS alerts &amp;lt; 10 seconds after the WPA login.&lt;br&gt;
&lt;br&gt;
We focused on detection+suspension, we had ~200 infections total.&lt;br&gt;</description>
    <pubDate>Thu, 17 May 2012 21:09:56 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/195</guid>
  </item>
  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/194</link>
    <description>&lt;p&gt;Posted by John Ladwig on May 17&lt;/p&gt;Which &amp;quot;network security mitigation techniques,&amp;quot; didn&amp;apos;t work out for Flashback at your site?&lt;br&gt;
&lt;br&gt;
   -jml&lt;br&gt;
&lt;br&gt;
From: The EDUCAUSE Security Constituent Group Listserv [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:SECURITY&quot;&gt;mailto:SECURITY&lt;/a&gt; () LISTSERV EDUCAUSE EDU] On Behalf Of Everett, &lt;br&gt;
Alex D&lt;br&gt;
Sent: Thursday, May 17, 2012 3:51 PM&lt;br&gt;
To: SECURITY () LISTSERV EDUCAUSE EDU&lt;br&gt;
Subject: Re: [SECURITY] Malware (antivirus) software for Macintosh&lt;br&gt;
&lt;br&gt;
Louis:&lt;br&gt;
&lt;br&gt;
Maybe I am misreading this, but Apple Updates did not...&lt;br&gt;</description>
    <pubDate>Thu, 17 May 2012 20:55:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/194</guid>
  </item>
  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/193</link>
    <description>&lt;p&gt;Posted by Everett, Alex D on May 17&lt;/p&gt;Louis:&lt;br&gt;
&lt;br&gt;
Maybe I am misreading this, but Apple Updates did not offer protection in time, though patching is of course sound &lt;br&gt;
advice.&lt;br&gt;
A Java vulnerability was not patched until after exploitation took place.&lt;br&gt;
We did have good experience with anti-malware software if the user had it already installed.&lt;br&gt;
We had poor experience with network security mitigation technologies.&lt;br&gt;
&lt;br&gt;
References:...&lt;br&gt;</description>
    <pubDate>Thu, 17 May 2012 20:52:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/193</guid>
  </item>
  <item>
    <title>Re: Malware (antivirus) software for Macintosh</title>
    <link>http://seclists.org/educause/2012/q2/192</link>
    <description>&lt;p&gt;Posted by Gallese, Brady T. on May 17&lt;/p&gt;Also using Symantec Endpoint Protection 12.1 here.  We saw some issues with version 11 as John mention, but things have &lt;br&gt;
been very good with 12.1.  I like that the macs are centrally managed for reporting, just like our PC clients - pricing &lt;br&gt;
is also the same as our PC clients.  There haven&amp;apos;t been many mac–only viruses show up, but it&amp;apos;s been great for stopping &lt;br&gt;
the PC viruses that the macs had been carriers for.&lt;br&gt;
&lt;br&gt;
Regards,&lt;br&gt;
Brady Gallese...&lt;br&gt;</description>
    <pubDate>Thu, 17 May 2012 20:43:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/educause/2012/q2/192</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

