<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Intentional Security Blindness</title>
	<atom:link href="http://www.bloginfosec.com/2008/04/29/intentional-security-blindness/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bloginfosec.com/2008/04/29/intentional-security-blindness/</link>
	<description>An Information Security Magazine in a Blog Format</description>
	<lastBuildDate>Mon, 30 Jan 2012 11:01:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Anish</title>
		<link>http://www.bloginfosec.com/2008/04/29/intentional-security-blindness/comment-page-1/#comment-4536</link>
		<dc:creator>Anish</dc:creator>
		<pubDate>Wed, 30 Apr 2008 09:43:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2008/04/29/intentional-security-blindness/#comment-4536</guid>
		<description>I agree with you on the point that &quot;Higher Ups&quot; do put security at stake, I have seen that in small companies where they have ACL&#039;s , audits happening every 3 months, they follow the principal of least privilege but when these things are happening by default every net work share needs to  have a user who is the CEO of the company and the single point of failure happens when he looses his Password / Laptop.

No matter what the Network Share is or what server it is, it can be Payroll, it can be HR, it can be IT stuff the CEO has to be added... 

And yes u cannot blame him if he changed some figures in your Excel Sheet and he wont even bother to drop u an email regarding the modification.

Why do the Higher Ups do it ? Sometimes just for the sake of showing Power and sometimes to prove their stupidity.

Anish</description>
		<content:encoded><![CDATA[<p>I agree with you on the point that &#8220;Higher Ups&#8221; do put security at stake, I have seen that in small companies where they have ACL&#8217;s , audits happening every 3 months, they follow the principal of least privilege but when these things are happening by default every net work share needs to  have a user who is the CEO of the company and the single point of failure happens when he looses his Password / Laptop.</p>
<p>No matter what the Network Share is or what server it is, it can be Payroll, it can be HR, it can be IT stuff the CEO has to be added&#8230; </p>
<p>And yes u cannot blame him if he changed some figures in your Excel Sheet and he wont even bother to drop u an email regarding the modification.</p>
<p>Why do the Higher Ups do it ? Sometimes just for the sake of showing Power and sometimes to prove their stupidity.</p>
<p>Anish</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Wright</title>
		<link>http://www.bloginfosec.com/2008/04/29/intentional-security-blindness/comment-page-1/#comment-4470</link>
		<dc:creator>Scott Wright</dc:creator>
		<pubDate>Tue, 29 Apr 2008 11:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2008/04/29/intentional-security-blindness/#comment-4470</guid>
		<description>This same group is also susceptible to what I call the &quot;immunity by importance&quot; paradox. Many executives feel hindered by the rules that are supposed to apply to their staff, and feel that because their work is &quot;different&quot; or &quot;special&quot;, they should be immune. 

However, nothing could be further from the truth, as evidenced by the growing phenomenon of &quot;Whaling&quot; - phishing attacks targeted at the &quot;big fish&quot; in an organization who often use their status as an excuse to bypass security - making C-Level management very attractive targets for attacks from outside (or even inside).</description>
		<content:encoded><![CDATA[<p>This same group is also susceptible to what I call the &#8220;immunity by importance&#8221; paradox. Many executives feel hindered by the rules that are supposed to apply to their staff, and feel that because their work is &#8220;different&#8221; or &#8220;special&#8221;, they should be immune. </p>
<p>However, nothing could be further from the truth, as evidenced by the growing phenomenon of &#8220;Whaling&#8221; &#8211; phishing attacks targeted at the &#8220;big fish&#8221; in an organization who often use their status as an excuse to bypass security &#8211; making C-Level management very attractive targets for attacks from outside (or even inside).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

