<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Reading List</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx</link><description>Reading List Many people have asked me to put together a list of links to things to read that may help them become a security expert. I am not sure I can do that, but doing some reading is not a bad starting point. What you read out of this really depends</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Interesting Finds</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx#419496</link><pubDate>Tue, 14 Feb 2006 14:13:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419496</guid><dc:creator>Jason Haley</dc:creator><description /></item><item><title>re: Reading List</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx#419520</link><pubDate>Tue, 14 Feb 2006 18:36:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419520</guid><dc:creator>Brian</dc:creator><description>Jesper, with the importance of &amp;quot;People Security&amp;quot; and the useful things that Steve Riley and yourself have presented on this topic in the last few years I think it would be a great contribution to the security community for Steve and yourself to consider publishing more on this topic. &amp;nbsp;Another book would be highly appropriate on this topic since this seems to be the hardest aspect of security to bring across to a business.</description></item><item><title>re: Reading List</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx#419559</link><pubDate>Wed, 15 Feb 2006 00:38:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419559</guid><dc:creator>Lars</dc:creator><description>Jesper, about Mitnick: &amp;quot;..defrauding his victims of millions of dollars in the process..&amp;quot;. As far as I know, I think it has never been proved in court or otherwise that there ever was any great financial loss for the victims or any economic gain for Mitnick himself at the time. True, there was cost in cleaning up after his security breaches, but Mitnick never to my knowledge deprived his victims of revenue by illigally obtaining their software for personal review or use. I understand your point about not really feeling comfortable about recommending his book as he is in fact now gaining from his past criminal activities (he did it, not study it), but I think it's inappropriate to label him wrongfully as having defrauded his victims of huge costs if he did not.&lt;br&gt;&lt;br&gt;Otherwise, I'm a great fan of you and Steve, love your way of getting down to the real security issues as seen in your webcasts and your book.&lt;br&gt;&lt;br&gt;All the best,&lt;br&gt;Lars&lt;br&gt;Denmark&lt;br&gt; </description></item><item><title>re: Reading List</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx#419567</link><pubDate>Wed, 15 Feb 2006 02:22:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419567</guid><dc:creator>Susan</dc:creator><description>One blog that is for sure on my must reads (besides yours and Mr. Riley's of course) is &amp;nbsp;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/msrc"&gt;http://blogs.technet.com/msrc&lt;/a&gt;&lt;br&gt;&lt;br&gt;The MSRC blog will have late breaking security issues posted long before it's on the official channels.&lt;br&gt;&lt;br&gt;Another one of interest is the Swiss Security blog&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/ms_schweiz_security_blog/default.aspx"&gt;http://blogs.technet.com/ms_schweiz_security_blog/default.aspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Antimalware blog (which always looks like you are typing animalware) &lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/antimalware/"&gt;http://blogs.technet.com/antimalware/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</description></item><item><title>re: Reading List</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx#419571</link><pubDate>Wed, 15 Feb 2006 03:01:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419571</guid><dc:creator>jesper</dc:creator><description>Brian, I wish I knew enough about people security, but I really do not feel like I do. I am trying to study it though.&lt;br&gt;&lt;br&gt;Lars, I don't recall all the details about what exactly Mitnick profited from, but the legal and clean-up costs should not be overlooked. Regardless of whether the criminal profited from the crime, the victims lost.&lt;br&gt;&lt;br&gt;Susan, good pointers, but I was mostly looking for learning opportunities, not merely keeping up on new events. I may have to &amp;nbsp;add those though. It is very hard to draw the line in this business. As we see above, sometimes learning means you have to go study things you would rather not.</description></item><item><title>re: Reading List</title><link>http://blogs.technet.com/jesper_johansson/archive/2006/02/13/419438.aspx#419734</link><pubDate>Thu, 16 Feb 2006 18:03:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419734</guid><dc:creator>Jonathan</dc:creator><description>I just finished reading Marcus Ranum's list and now I'm going back to read over the rest of that site. &amp;nbsp;There's a lot of good information in there and he's really made it approachable. &amp;nbsp;Thanks for the heads-up on this, Jesper.</description></item></channel></rss>