<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: attorney]]></title>
    <link>http://securityratty.com/tag/attorney</link>
    <description></description>
    <pubDate>Thu, 14 Aug 2008 08:20:24 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Gloria Jeans Coffee Website, gloriajeans.com, Hacked, Atleast 511 Customers Credit Crads Details Stolen]]></title>
      <link>http://securityratty.com/article/3a2ba3b8fb714ffe3875487c8f86aca2</link>
      <guid>http://securityratty.com/article/3a2ba3b8fb714ffe3875487c8f86aca2</guid>
      <description><![CDATA[Earlier this month, gloriajeans.com website was the subject of an attack that allowed an unknown person or persons to obtain the addresses and credit card numbers of 511 of the customers as they were...]]></description>
      <content:encoded><![CDATA[Earlier this month, gloriajeans.com website was the subject of an attack that allowed an unknown person or persons to obtain the addresses and credit card numbers of 511 of the customers as they were placing orders on the site. According to New Hampshire State Attorney General, Gloria Jeans Coffee (Gloria Jean&#8217;s) recently experienced a data [...]]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 17:49:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gloria jeans">gloria jeans</category>
      <category domain="http://securityratty.com/tag/gloria jeans coffee">gloria jeans coffee</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/unknown person">unknown person</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/gloriajeans">gloriajeans</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://cyberinsecure.com/gloria-jeans-coffee-website-gloriajeanscom-hacked-atleast-511-customers-credit-crads-details-stolen/">Gloria Jeans Coffee Website, gloriajeans.com, Hacked, Atleast 511 Customers Credit Crads Details Stolen</source>
    </item>
    <item>
      <title><![CDATA["Scareware" Vendors Sued]]></title>
      <link>http://securityratty.com/article/116941f75bd6ea940dba21e55c3187e7</link>
      <guid>http://securityratty.com/article/116941f75bd6ea940dba21e55c3187e7</guid>
      <description><![CDATA[This is good : Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of &quot;scareware&quot; purveyors, scam artists who use fake security alerts to frighten consumers into paying...]]></description>
      <content:encoded><![CDATA[<p>This is <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">good</a>:</p>

<blockquote>Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of "scareware" purveyors, scam artists who use fake security alerts to frighten consumers into paying for worthless computer security software.

<p>The case filed by the Washington attorney general's office names Texas-based Branch Software and its owner James Reed McCreary IV, alleging that McCreary's company caused targeted PCs to pop up misleading security alerts about security threats on the victims' computers. The alerts warned users that their systems were "damaged and corrupted" and instructed them to visit a Web site to purchase a copy of Registry Cleaner XP for $39.95.</blockquote></p>

<p>I would have thought that existing scam laws would be enough, but Washington state actually has a specific law about this sort of thing:</p>

<blockquote>The lawsuits were filed under Washington's Computer Spyware Act, which among other things punishes individuals who prey on user concerns regarding spyware or other threats. Specifically, the law makes it illegal to misrepresent the extent to which software is required for computer security or privacy, and it provides actual damages or statutory damages of $100,000 per violation, whichever is greater.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RIHdM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RIHdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=V0u2M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=V0u2M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:03:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alerts">alerts</category>
      <category domain="http://securityratty.com/tag/fake security alerts">fake security alerts</category>
      <category domain="http://securityratty.com/tag/week filed lawsuits">week filed lawsuits</category>
      <category domain="http://securityratty.com/tag/security alerts">security alerts</category>
      <category domain="http://securityratty.com/tag/filed">filed</category>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <category domain="http://securityratty.com/tag/washington attorney">washington attorney</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/lawsuits">lawsuits</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/scareware_vendo.html">"Scareware" Vendors Sued</source>
    </item>
    <item>
      <title><![CDATA[PSS World Medical applicants affected by job boards breach]]></title>
      <link>http://securityratty.com/article/5a90e0838a48ae8e73177a9a1bfb90ee</link>
      <guid>http://securityratty.com/article/5a90e0838a48ae8e73177a9a1bfb90ee</guid>
      <description><![CDATA[In a breach notification letter sent to the New Hampshire State Attorney General, PSS World Medical states that the company recently became aware of an incident involving unauthorized access to...]]></description>
      <content:encoded><![CDATA[In a breach notification letter sent to the New Hampshire State Attorney General, PSS World Medical states that the company &#8220;recently became aware of an incident involving unauthorized access&#8221; to company&#8217;s career board website. The unauthorized access resulted in the exposure of personal information belonging to job applicants and others that may have posted their [...]]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 18:41:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pss world medical">pss world medical</category>
      <category domain="http://securityratty.com/tag/breach notification letter">breach notification letter</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/company recently">company recently</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/job applicants">job applicants</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/hampshire">hampshire</category>
      <source url="http://cyberinsecure.com/pss-world-medical-applicants-affected-by-job-boards-breach/">PSS World Medical applicants affected by job boards breach</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Seven]]></title>
      <link>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</link>
      <guid>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</guid>
      <description><![CDATA[In case you haven't heard - Microsoft and the Washington state are suing a U.S based -- naturally -- &quot;scareware&quot; vendor Branch Software

We won't tolerate the use of alarmist warnings or deceptive...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/V5DqP_zsvuk/s1600-h/lawsuit_got_one.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="161" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/FVk3TrvBJIo/s200-R/lawsuit_got_one.gif" width="200" /></a>In case you haven't heard - <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">Microsoft and the Washington state</a> are suing a U.S based -- naturally -- "scareware" vendor Branch Software :<br />
<br />
"<i>We won't tolerate the use of alarmist warnings or deceptive 'free scans' to  trick consumers into buying software to fix a problem that doesn't even exist,"  Washington <b style="font-weight: normal;">Attorney General Rob McKenna</b> said. <b>"We've repeatedly  proven that Internet companies that prey on consumers' anxieties are within our  reach.</b></i><b>"</b><br />
<br />
Sadly, Branch Software is the tip of the iceberg on the top of the affiliates participating in different affiliation based programs, which similar to <a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">IBSOFTWARE CYPRUS</a> and <a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Interactivebrands</a>, which I've been tracking down for a while, are the aggregators of scareware<b><span style="font-weight: normal;"> that popped up on the radars due to their extensive portfolios. These three companies offering software bundles or plain simple fake software, are somewhere in between the food chain of this ecosystem, with the real vendors paying out the commissions on a per installation basis slowly starting to issue invitation codes that they've distributed only across invite-only forums/sections of particular forums.</span></b><br />
<br />
Behind these brands is everyone that is participating in the franchise and is putting personal efforts into monetizing the high payout rates that the fake security software vendor is paying for successful installation. These high payout rates -- with the financing naturally coming straight from other criminal activities online -- are in fact so high, that I can easily say that the last two quarters we've witnesses the largest increase of such domains ever, and they're only heating up since the typosquatting possibilities are countless and they seem to know that as well.<br />
<br />
It's important to point out that their business model of acquiring traffic is outsourced to all the affiliates that do the blackhat SEO, SQL injections, web sessions hijacking of malware infected hosts in order to monetize, so basically, you have an affiliates network whose actions are directly driving the growth into all these areas. Throwing money into the underground marketplace as a "financial injection", is proving itself as a growth factor, and incentive for innovation on behalf of all the participants.<br />
<br />
Here are some of the most recent fake security software domains, a "deja vu" moment with a known RBN domain from a "previous life" that is also parked at one of the servers, and evidence that typosquatting for fraudulent purposes is still pretty active with a dozen of Norton Antivirus related domains, some of which have already started issuing "fake security notices" by brandjacking the vendor for traffic acquisition purposes.<br />
<br />
<b>Antivirus-Alert .com </b>(203.117.111.47) where<b> pepato .org</b> a domain that was used in the <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">Wired.com and History.com IFRAME injections</a>, which back in March was also hosted at Hostfresh (58.65.238.59).<br />
<br />
<b>softload2008name .com</b> (78.157.143.250)<br />
<b>softload2008nm .com<br />
softload2008n .com<br />
softload2008jq .com</b><br />
<br />
<b>microantivir-2009 .com</b> (91.208.0.223)<br />
<b>scanner.microantivir-2009 .com<br />
microantivir2009 .com<br />
microantivirus-2009 .com<br />
microantivirus2009 .com</b><br />
<br />
<b>ms-scan .com</b> (91.208.0.228)<br />
<b>msscanner .com</b><br />
<b>ms-scanner .com</b><br />
<br />
<b>Personalantispy .com</b> (93.190.139.197)<br />
<b>freepcsecure .com<br />
quickinstallpack .com<br />
quickdownloadpro .com<br />
advancedcleaner .com<br />
performanceoptimizer .com<br />
internetanonymizer .com</b><br />
<br />
<b>ieprogramming .com</b> (92.62.101.83)<br />
<b>uptodatepage .com<br />
fileliveupdate .com<br />
qwertypages .com<br />
sharedupdates .com<br />
ierenewals .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/eJI5I5BgGoQ/s1600-h/norton_alert.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/Rpjz8LY4LEQ/s200-R/norton_alert.png" /></a><b>norton-antivirus-alert .com<br />
norton-anti-virus-2007 .com <br />
norton-antivirus-2007 .com <br />
norton-antivirus2007 .com <br />
nortonantivirus2007 .com <br />
norton-antivirus-2008 .com <br />
nortonantivirus2008 .com <br />
nortonantivirus2008freedownload .com <br />
norton-antivirus-2009 .com <br />
nortonantivirus2009 .com <br />
norton-antivirus-2010 .com <br />
nortonantivirus2010 .com <br />
nortonantivirus360 .com <br />
nortonantivirus8 .com <br />
nortonantivirusa .com <br />
nortonantivirusactivation .com <br />
norton-antivirus-alert .com <br />
nortonantivirusalerts .com <br />
norton--anti-virus .com <br />
norton-anti-virus .com <br />
norton-antivirus .com <br />
nortonanti-virus .com <br />
nortonantivirus.com <br />
nortonantiviruscom .com <br />
nortonantiviruscorporate .com <br />
nortonantiviruscorporateedition .com <br />
nortonantiviruscoupon .com <br />
nortonantivirusdefinition .com <br />
nortonantivirusdefinitions .com <br />
nortonantivirusdirect .com</b><br />
<br />
Fake Antivirus Inc. is not going away as long as the affiliate based model remains active. If the real vendors were greedy enough not to share the revenues with others, they would have been the one popping up on the radar, compared to the situation where it's the affiliate network's participations greed that's increasing their visibility online.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Cybersquatting Symantec's Norton AntiVirus</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">Cybersquatting Security Vendors for Fraudulent Purposes</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake  Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">EstDomains  and Intercage VS Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake  Security Software Domains Serving Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got  Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake  PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy  Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating  Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The  Malicious ISPs You Rarely See in Any Report</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=88nnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=88nnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=F8uQL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=F8uQL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T1xil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T1xil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eAF4l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eAF4l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rdg2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rdg2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nXveL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nXveL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=moMol"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=moMol" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407645950" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 12:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/vendor branch software">vendor branch software</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/software bundles">software bundles</category>
      <category domain="http://securityratty.com/tag/branch software">branch software</category>
      <category domain="http://securityratty.com/tag/norton antivirus">norton antivirus</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407645950/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</source>
    </item>
    <item>
      <title><![CDATA[Microsoft and the Washington Attorney General Against Scareware Pushers]]></title>
      <link>http://securityratty.com/article/23b1343fa2382419e1f8620a0ac1a120</link>
      <guid>http://securityratty.com/article/23b1343fa2382419e1f8620a0ac1a120</guid>
      <description><![CDATA[Washington states top law enforcement official has filed suit against a man accused of bombarding end users with misleading messages designed to trick them into buying software to fix PC problems that...]]></description>
      <content:encoded><![CDATA[Washington state&#8217;s top law enforcement official has filed suit against a man accused of bombarding end users with misleading messages designed to trick them into buying software to fix PC problems that don&#8217;t exist.
The complaint, filed in Washington state court by Attorney General Rob McKenna&#8217;s office, names James Reed McCreary IV of The Woodlands, Texas, [...]]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 20:46:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <category domain="http://securityratty.com/tag/filed suit">filed suit</category>
      <category domain="http://securityratty.com/tag/rob mckennas office">rob mckennas office</category>
      <category domain="http://securityratty.com/tag/filed">filed</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/texas">texas</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/messages">messages</category>
      <category domain="http://securityratty.com/tag/complaint">complaint</category>
      <source url="http://cyberinsecure.com/microsoft-and-the-washington-attorney-general-against-scareware-pushers/">Microsoft and the Washington Attorney General Against Scareware Pushers</source>
    </item>
    <item>
      <title><![CDATA[Washington state pursues 'scareware' distributors]]></title>
      <link>http://securityratty.com/article/6f4edd021bdbcb73e8622c27f3004250</link>
      <guid>http://securityratty.com/article/6f4edd021bdbcb73e8622c27f3004250</guid>
      <description><![CDATA[The Washington state attorney general's office has sued a Texas man for sending &quot;scareware&quot; and is asking the court to require him to stop his activities and pay restitution to people who fell for his...]]></description>
      <content:encoded><![CDATA[The Washington state attorney general's office has sued a Texas man for sending "scareware" and is asking the court to require him to stop his activities and pay restitution to people who fell for his alleged scam.]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <category domain="http://securityratty.com/tag/scareware">scareware</category>
      <category domain="http://securityratty.com/tag/texas">texas</category>
      <category domain="http://securityratty.com/tag/sued">sued</category>
      <category domain="http://securityratty.com/tag/require">require</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/activities">activities</category>
      <source url="http://www.networkworld.com/news/2008/092908-washington-state-pursues-scareware.html?fsrc=rss-security">Washington state pursues 'scareware' distributors</source>
    </item>
    <item>
      <title><![CDATA[RIAA seeks sanctions against defense lawyer in copyright case]]></title>
      <link>http://securityratty.com/article/7b7e7a83497d9266132759758c80699b</link>
      <guid>http://securityratty.com/article/7b7e7a83497d9266132759758c80699b</guid>
      <description><![CDATA[The RIAA accused New York attorney Ray Beckerman of engaging in &quot;vexatious litigation&quot; in a case involving an alleged copyright...]]></description>
      <content:encoded><![CDATA[The RIAA accused New York attorney Ray Beckerman of engaging in "vexatious litigation" in a case involving an alleged copyright violator.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:90b107b049664f557fca8c23498d5f8d:slPHRtPVfUtEAQd54HHHpmmVGCqYJtqEf3GTEm%2F67uegs%2B8%2FJEv9msHvVqK8ZTix7SSyq98u1Iey0g%2FzIG7vlmRk5XNbOXzxxvBVwlG9fXk%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ae835305f3fa39990eee1176534b4b51:EcmTLJ5rRO2pSNqsEzwxfDAdPl8DCJ2vith3pIY3W4%2BNBRvZQrkag5XvA52SYSj2FCuJ0mLdRaUXqra2N02XQ7pwIqFv0ikCKnQ5m7T0iuo%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:769679819540dc3ea86a722169a60c54:1b7%2FRt2RuCI5HXctOPP0a5NIR7rje65xB8GbKHfe4RElDkoiiSoDR294paQCfh1rme27fLLawa1d4UYaCedOdzafxtrrk87ELRHc%2FKGujOY%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:f22d1570c92dfcbc264e1c12c38864dd:2HXjAxgdyjOMZzPMxkZyhbaAgPPJodgpjbTUUJHW%2BkuFr3DZQmYXn6OFfT8PagdGY6JFsrcWEBUiRLKBwGV6shttzzRZLrJsE89M3yAw0Ns%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=00387ca75e59c04655dba1d7a1541f88"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=00387ca75e59c04655dba1d7a1541f88" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=00387ca75e59c04655dba1d7a1541f88" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/copyright violator">copyright violator</category>
      <category domain="http://securityratty.com/tag/vexatious litigation">vexatious litigation</category>
      <category domain="http://securityratty.com/tag/riaa">riaa</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=00387ca75e59c04655dba1d7a1541f88">RIAA seeks sanctions against defense lawyer in copyright case</source>
    </item>
    <item>
      <title><![CDATA[VP Nominee Sarah Palin, Hacker?]]></title>
      <link>http://securityratty.com/article/8e3f93f782545f8440786e956b4d45a5</link>
      <guid>http://securityratty.com/article/8e3f93f782545f8440786e956b4d45a5</guid>
      <description><![CDATA[John McCains pick for VP, Sarah Palin, knows a thing or two about retrieving evidence from a computer. The mainstream reporting calls her a hacker because she is able to retrieve files from the...]]></description>
      <content:encoded><![CDATA[<p>John McCain&#8217;s pick for VP, Sarah Palin, knows a thing or two about retrieving evidence from a computer.  The mainstream reporting calls her a &#8220;hacker&#8221; because she is able to retrieve files from the Windows recycle bin. </p>
<p>The <a href="http://dwb.adn.com/front/story/5572779p-5504444c.html">Anchorage Daily News reports</a> back in September 2004:</p>
<blockquote><p>Sarah Palin never thought of herself as an investigator.  Yet there she was, hacking uncomfortably into Randy Ruedrich&#8217;s computer, looking for evidence that the state Republican Party boss had broken the state ethics law while a member of the Alaska Oil &amp; Gas Conservation Commission.</p>
<p class="story_readable">The next week, when Palin went back to work at the AOGCC, she noticed that Ruedrich had removed his pictures from the walls and the personal effects from his desk. But as she and an AOGCC technician worked their way around his computer password at the behest of an assistant attorney general in Fairbanks, they found his cleanup had not extended to his electronic files.</p>
<p class="story_readable">The technician &#8220;said it looked like he tried to delete this, but she knew a way to go around and get some of the deleted stuff,&#8221; Palin said in an interview. &#8220;I didn&#8217;t know what I was looking for, but I was there.&#8221;</p>
</blockquote>
<p>And this is how <a href="http://www.salon.com/opinion/feature/2007/08/13/alaska/index1.html">Salon reports</a> the same incident:</p>
<blockquote><p>&#8220;In a neat symbolic fit, the agent responsible for Alaska&#8217;s current moment of reform and modernization is a woman, a breed once nearly as rare in far Northwest politics as a Democrat. Sarah Palin, a libertarian and hockey mom from the fast-growing suburbs of Anchorage, began her political career &#8212; as an appointed member of the state&#8217;s Oil and Gas Commission &#8212; by hacking into the computer of another commissioner, Randy Ruedrich, chairman of the Alaska Republican Party. Palin was seeking the evidence that she would eventually use to charge him with an improper relationship with lobbyists. (Ruedrich would later settle state ethics charges against him by paying a $12,000 fine.)&#8221;</p></blockquote>
<p>Is this where the McCain administration is going to get their computer security expertise?  She&#8217;s not a security expert but it is nice to see someone at the level of state govenor who knows their way around a computer.</p>
]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 14:51:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/palin">palin</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/randy ruedrichs computer">randy ruedrichs computer</category>
      <category domain="http://securityratty.com/tag/computer password">computer password</category>
      <category domain="http://securityratty.com/tag/computer security expertise">computer security expertise</category>
      <category domain="http://securityratty.com/tag/technician">technician</category>
      <category domain="http://securityratty.com/tag/aogcc technician">aogcc technician</category>
      <category domain="http://securityratty.com/tag/randy ruedrich">randy ruedrich</category>
      <source url="http://www.veracode.com/blog/2008/08/vp-nominee-sarah-palin-hacker/">VP Nominee Sarah Palin, Hacker?</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hacking Injunction Lifted]]></title>
      <link>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</link>
      <guid>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</guid>
      <description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at...]]></description>
      <content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the<a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mbta">mbta</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/students publicly">students publicly</category>
      <category domain="http://securityratty.com/tag/defcon presentation">defcon presentation</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/mbta hackers">mbta hackers</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/judge">judge</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/">MBTA Hacking Injunction Lifted</source>
    </item>
    <item>
      <title><![CDATA[Kids with Cell Phones in Emergencies]]></title>
      <link>http://securityratty.com/article/cfaf0428c49f446db4722e74309138c9</link>
      <guid>http://securityratty.com/article/cfaf0428c49f446db4722e74309138c9</guid>
      <description><![CDATA[In the middle of a sensationalist article about risks to children and how giving them cell phones can help, there's at least one person who gets it. Since the 1999 Columbine High School shootings and...]]></description>
      <content:encoded><![CDATA[<p>In the middle of a <a href="http://www.cnn.com/2008/TECH/ptech/08/11/cellphones.kids/index.html">sensationalist article</a> about risks to children and how giving them cell phones can help, there's at least one person who gets it.</p>

<blockquote>Since the 1999 Columbine High School shootings and the 9/11 terrorist attacks, many parents feel better having a way to contact their children. But hundreds of students on cell phones during an emergency can cause problems for responders.

<p>"There's a huge difference between feeling safer and being safer," says Kenneth Trump, president of National School Safety and Security Services.</p>

<p>According to Trump, students' cell phone use during emergencies can do three things: increase the spread of rumors about the situation, expedite parental traffic at a scene that needs to be controlled and accelerate the overload of cell-phone systems in the area.</p>

<p>Tom Hautton, an attorney for the National School Board Association, said that cell phones in schools also can lead to classroom distractions, text-message cheating and inappropriate photographs and videos being spread around campus.</blockquote></p>

<p>We are just naturally inclined to make irrational security decisions when it comes to our children.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=U1TUKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=U1TUKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=6SGplK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=6SGplK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 08:20:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cell phones">cell phones</category>
      <category domain="http://securityratty.com/tag/irrational security decisions">irrational security decisions</category>
      <category domain="http://securityratty.com/tag/trump">trump</category>
      <category domain="http://securityratty.com/tag/expedite parental traffic">expedite parental traffic</category>
      <category domain="http://securityratty.com/tag/kenneth trump">kenneth trump</category>
      <category domain="http://securityratty.com/tag/national school safety">national school safety</category>
      <category domain="http://securityratty.com/tag/huge difference">huge difference</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/kids_with_cell.html">Kids with Cell Phones in Emergencies</source>
    </item>
  </channel>
</rss>
