Should RegRipper include XML output?
- Yes
- No
- Not everything needs XML output. Give it a rest!!
- Tools should always include an XML output option.
Should Twitter Control Spam Accounts?
- Yes, accounts should be vetted to determine they are a real person
- Yes, accounts should be marked as personal or business to help people decide who to permit.
- No, just lock your account and manage your own friends.
- No, there is no way to vet accounts. The Internet is just a free for all and we should get over it.
What is your opinion on Virus Response for Small/Medium Sized Businesses
- Just run your virus scanner and spyware scanner, clean the malware, and drive on with business as usual.
- Backup the critical files, DBan the drive, virus scan the backups, and reinstall
- Investigate the root cause, counsel the individual who infected the system, and then proceed with number 1.
- Investigate the root cause, counsel the individual who infected the system, and then proceed with number 2
Will businesses be safer if they limit the amount of processing power and programs avaliable to end-users by moving to thin client solutions?
- Absolutely, this is the direction we should move to agressively.
- Most businesses should move toward thin client solutions as it will make the business more secure, but it will not make the Internet safer.
- Thin client solutions do not provide any added benefit to the security situation of a business or the Internet.
- Just get rid of the end-user. Most people should not be allowed to touch computers.
- The cycle of life will prevail. Businesses will move to thin clients and then eventually back to unlimited access and permissions to all. LIfe is just a big circle and security just doesn't matter that much.
Are presenting skills and group discussion skills different skill sets?
- All security professionals should be able to present well and lead conversations.
- Security managers are the only ones who need to lead both presentations and group discussions.
- Technical security professionals should only be required to give technical presentations.
- These skill should not be required as a necessary skills within the security industry.
Should you tell your employer about your blog?
- You should tell them during your interview or before you start blogging.
- You should not worry about it.
- You should blog under a pseudonym.
- Blogging is for people with too much time on their hands....get to work.
Would you take a SANS training course via the SANS Mentor program?
- No
- Maybe, depends on the instructor
- Yes, if my employer paid for it
- Yes, I would pay for it myself
Security Ripcord








