<?xml version="1.0" encoding="UTF-8"?>
<GoodreadsResponse>
	<Request>
		<authentication>false</authentication>
		    <method><![CDATA[]]></method>
	</Request>
	<user id="130718">
  <name><![CDATA[Doug]]></name>
  <user-name><![CDATA[]]></user-name>
  <link><![CDATA[http://www.goodreads.com/user/show/130718-doug]]></link>
  
  
    <updates-rss-url><![CDATA[http://www.goodreads.com/user/updates_rss/130718?key=7c982e3d122ff25310607f22318f233bde936e5d]]></updates-rss-url>
    <reviews-rss-url><![CDATA[http://www.goodreads.com/review/list_rss/130718?key=7c982e3d122ff25310607f22318f233bde936e5d&shelf=%23ALL%23]]></reviews-rss-url>
    <friends-count type="integer">47</friends-count>
    <reviews-count type="integer">69</reviews-count>
    <user_shelves type="array">
  <user_shelf>
    <book_count type="integer">47</book_count>
    <description nil="true"></description>
    <exclusive_flag type="boolean">true</exclusive_flag>
    <id type="integer">5809667</id>
    <name>read</name>
  </user_shelf>
  <user_shelf>
    <book_count type="integer">10</book_count>
    <description nil="true"></description>
    <exclusive_flag type="boolean">true</exclusive_flag>
    <id type="integer">266087</id>
    <name>currently-reading</name>
  </user_shelf>
  <user_shelf>
    <book_count type="integer">12</book_count>
    <description nil="true"></description>
    <exclusive_flag type="boolean">true</exclusive_flag>
    <id type="integer">266086</id>
    <name>to-read</name>
  </user_shelf>
  <user_shelf>
    <book_count type="integer">6</book_count>
    <description nil="true"></description>
    <exclusive_flag type="boolean">false</exclusive_flag>
    <id type="integer">292628</id>
    <name>couldnt-finish</name>
  </user_shelf>
  <user_shelf>
    <book_count type="integer">2</book_count>
    <description nil="true"></description>
    <exclusive_flag type="boolean">false</exclusive_flag>
    <id type="integer">266105</id>
    <name>handy-for-re-reading</name>
  </user_shelf>
</user_shelves>


        <updates type="array">
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'The First Directorate: My 32 Years in Intelligence and Espionage Against the West']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/79198038</link>
  	
    	<description>
    		<![CDATA[
    			Doug marked as to-read:	<a href="http://www.goodreads.com/book/show/821696.The_First_Directorate_My_32_Years_in_Intelligence_and_Espionage_Against_the_West" class="bookTitle">The First Directorate: My 32 Years in Intelligence and Espionage Against the West (Hardcover)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/428559.Oleg_Kalugin" class="authorName">Oleg Kalugin</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=to-read" class="actionLinkLite">to-read</a>
	
	<br/>



          
    			  a recommendation from Mom
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'The Tipping Point']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/59922450</link>
  	
    	<description>
    		<![CDATA[
    			Doug marked as to-read:	<a href="http://www.goodreads.com/book/show/2612.The_Tipping_Point" class="bookTitle">The Tipping Point (Paperback)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/1439.Malcolm_Gladwell" class="authorName">Malcolm Gladwell</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=to-read" class="actionLinkLite">to-read</a>
	
	<br/>



          
    			  
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'Consider Phlebas']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/58460410</link>
  	
    	<description>
    		<![CDATA[
    			Doug is currently reading:	<a href="http://www.goodreads.com/book/show/12010.Consider_Phlebas" class="bookTitle">Consider Phlebas (Paperback)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/7628.Iain_M_Banks" class="authorName">Iain M. Banks</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=currently-reading" class="actionLinkLite">currently-reading</a>
	
	<br/>



          
    			  
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'Fifty Dead Men Walking']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/53104491</link>
  	
    	<description>
    		<![CDATA[
    			Doug marked as to-read:	<a href="http://www.goodreads.com/book/show/1486980.Fifty_Dead_Men_Walking" class="bookTitle">Fifty Dead Men Walking (Paperback)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/66120.Martin_McGartland" class="authorName">Martin McGartland</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=to-read" class="actionLinkLite">to-read</a>
	
	<br/>



          
    			  
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="comment">
        
  
  
  
  
    
    	<title>
    		<![CDATA[new comment from Doug]]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/43091980</link>
  	<description>
  		<![CDATA[
  			New comment on <a href="http://www.goodreads.com/user/show/130718" class="userReview" style="font-weight: bold">Doug</a>'s review of 
  		<a href="http://www.goodreads.com/book/show/113934.The_Goal" class="bookTitle">The Goal</a>
  		<br/><span class="by">by</span>
  		<a href="http://www.goodreads.com/author/show/66037.Eliyahu_M_Goldratt" class="authorName">Eliyahu M. Goldratt</a>

  		<br/><br/>				
  		I can't believe there was ever a time people ran a business without thinking about cash flow.
  		]]>
  	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'Vibes']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/45028203</link>
  	
    	<description>
    		<![CDATA[
    			Doug gave <img alt="4 of 5 stars" class="star" height="15" src="http://www.goodreads.com/images/layout/stars/red_star_4_of_5.gif?1259883815" title="4 of 5 stars" width="75" /> to:	<a href="http://www.goodreads.com/book/show/3212848.Vibes" class="bookTitle">Vibes (Hardcover)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/504627.Amy_Kathleen_Ryan" class="authorName">Amy Kathleen Ryan</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=couldnt-finish" class="actionLinkLite">couldnt-finish</a>
	
	<br/>



          
    			  A recommendation from Amy Ryan.<br/><br/>I bought book this because I like the author.  I read the first five or ten pages, and the writing style is light, clever and hilarious.  I laughed on every page but had to admit I don't find a lot of interest in young adult fiction and wasn't connecting with the 15 year old female protagonist.<br/><br/>I passed it off to a bored 14 year old girl at my dinner party full of boring adults last night, and by the time everyone was putting on scarves and packing up to leave she had read through half the book!  It's hers now; I'm hoping she passes it on to a friend when she's done.
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'The New School of Information Security']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/43606346</link>
  	
    	<description>
    		<![CDATA[
    			Doug gave <img alt="3 of 5 stars" class="star" height="15" src="http://www.goodreads.com/images/layout/stars/red_star_3_of_5.gif?1259883815" title="3 of 5 stars" width="75" /> to:	<a href="http://www.goodreads.com/book/show/3085015.The_New_School_of_Information_Security" class="bookTitle">The New School of Information Security (Hardcover)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/1320024.Adam_Shostack" class="authorName">Adam Shostack</a>
    			<br/>
    			



          
    			  Recommendation from Robin Shostack...<br/><br/>This book speaks to CIO/CSOs and not to security professionals.  I recommend this book for anybody who consumes security solutions or needs to make security software purchasing decisions.<br/><br/>The book is full of good, rich examples and is well written.<br/><br/>I have a big problem in that I flatly disagree with the thesis, which is that the &quot;new&quot; focus on security should be an intense review of security breaches.<br/><br/>Let me back up.  I think you can act upon security in a number of ways.  I'm splitting the levels of understanding into four for purposes of this review.  The most regressive, ineffective method is to concentrate on breaches.  Not to say there's no value in this; studying failures is good, I want somebody to do it and I want to read the results.  But it's not actually doing anything.  You've still lost your data, or lost your reputation, or perhaps you've already gone out of business.<br/><br/>The status quo is what I would call the &quot;sophomore&quot; level: focusing on attacks.  Intrusion detection falls in this space, and it can be effective and you probably don't want to do without it... but it's not a good return on effort.<br/><br/>To begin thinking about the security problem with an adult perspective is to place your focus on threats.  You simply get a lot more bang out of understanding what's at stake and how an attacker (or bug) would most likely compromise what you care about the most.<br/><br/>The highest level of understanding I can think of is to focus on prevention.  This is either the next step from understanding threats, or it's simultaneous with doing so.  Should we even hold that thing the attackers want so badly?  Is there missing input validation in my gateway application to that resource?  Are access controls really set up the way they were designed to be?<br/><br/>I felt a little lost in that the endnotes were not numbered, but maybe I'm a just a nerd and it's for the best.<br/><br/>The publisher stuck a sneak preview of _Geekonomics_ into the end and I'm interested in reading that now.
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'Secure Programming with Static Analysis: Getting Software Security Right with Static Analysis']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/9714509</link>
  	
    	<description>
    		<![CDATA[
    			Doug gave <img alt="4 of 5 stars" class="star" height="15" src="http://www.goodreads.com/images/layout/stars/red_star_4_of_5.gif?1259883815" title="4 of 5 stars" width="75" /> to:	<a href="http://www.goodreads.com/book/show/1543272.Secure_Programming_with_Static_Analysis_Getting_Software_Security_Right_with_Static_Analysis" class="bookTitle">Secure Programming with Static Analysis: Getting Software Security Right with Static Analysis (Addison-Wesley Software Security)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/718872.Brian_Chess" class="authorName">Brian Chess</a>
    			<br/>
    			



          
    			  Disclaimer: I work with Brian and Jacob at Fortify.<br/><br/>Wow, does what it says on the tin.  Explains the nose to tail of what static analysis will do for you, including how you should interpret the results and what you should expect to get out of it.<br/><br/>In terms of real world use, the book is light on the subject of how static analysis fits in with dynamic analysis, architectural reviews, threat modeling etc. but this is outside the stated scope anyway.<br/><br/>I'm a strong believer that computer assisted code reviews are the only way we as a civilization are going to escape from the information security problem we have now.<br/><br/>An excellent reference for the low level of how best to remedy or mitigate all the most common types of vulnerabilities.  I got hold of an electronic copy and reference this all the time in my professional work.
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'Slouching Towards Bethlehem: Essays']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/43417618</link>
  	
    	<description>
    		<![CDATA[
    			Doug marked as to-read:	<a href="http://www.goodreads.com/book/show/424.Slouching_Towards_Bethlehem_Essays" class="bookTitle">Slouching Towards Bethlehem: Essays (Paperback)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/238.Joan_Didion" class="authorName">Joan Didion</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=to-read" class="actionLinkLite">to-read</a>
	
	<br/>



          
    			  I read an excerpt from these in school and have always wanted to read the whole thing.
    			
    		]]>
    	</description>
  	
    

      </update>
            <update type="review">
        
  
  
  
    
    	<title>
    		<![CDATA[Doug added 'The Goal']]>
    	</title>
  	  	<link>http://www.goodreads.com/review/show/43091980</link>
  	
    	<description>
    		<![CDATA[
    			Doug gave <img alt="3 of 5 stars" class="star" height="15" src="http://www.goodreads.com/images/layout/stars/red_star_3_of_5.gif?1259883815" title="3 of 5 stars" width="75" /> to:	<a href="http://www.goodreads.com/book/show/113934.The_Goal" class="bookTitle">The Goal (Paperback)</a>
    			<span class="by">by</span>
    			<a href="http://www.goodreads.com/author/show/66037.Eliyahu_M_Goldratt" class="authorName">Eliyahu M. Goldratt</a>
    			<br/>
    			

	<span class="userReview">bookshelves: </span>
	
		<a href="http://www.goodreads.com/review/list/130718?shelf=to-read" class="actionLinkLite">to-read</a>
	
	<br/>



          
    			  A recommendation from Roger Thornton
    			
    		]]>
    	</description>
  	
    

      </update>
          </updates>
      
</user>

</GoodreadsResponse>