<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: balance]]></title>
    <link>http://securityratty.com/tag/balance</link>
    <description></description>
    <pubDate>Mon, 09 Jun 2008 07:04:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Technology Tales from Thailand: KBank Fraud Management]]></title>
      <link>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</link>
      <guid>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</guid>
      <description><![CDATA[In The Magical ATM Card and SMS Message in Thailand we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Magical ATM Card and SMS Message in Thailand" rel="bookmark" href="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/"><span style="color: #105cb6;">The Magical ATM Card and SMS Message in Thailand</span></a> we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and in <a title="Keyloggers: Why Banks Need Two-Factor Authentication" rel="bookmark" href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/"><span style="color: #105cb6;">Keyloggers: Why Banks Need Two-Factor Authentication</span></a> I described how <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">KBank</a> uses SMS-based one-time-passwords (OTP) to authenticate transactions.   </p>
<p>In addition to the above services, KBank offers a service that permits users to receive an SMS message that details any change in account balance and/or point-of-sale (POS) transaction with your debit card.   I really like this service and the feeling of security knowing when, where and by how much my balance changes or my debit card is used in a transaction.    The KBank POS SMS notification is so fast that when I present my card to a merchant I normally receive an SMS message detailing the transaction before the merchant returns for my signature.  (There is an unfortunate lag in the balance change notification that can run minutes to hours behind real-time, but the POS VISA debit card notification is real-time).</p>
<p>As the story goes,  I should have been using my KBank card and account a few weeks ago and not my US-based VISA debit dard.  Why?</p>
<p>My US-based VISA debit card was cloned sometime on or before August 8th.   I am really careful with this card, so I was surprised the magnetic strip was cloned at a POS merchant.   The fraudster made 7 fraudulent transactions beginning on August 8th for a total of around $2500 USD, mostly on August 11th, before I discovered the fraudulent transactions viewing my account on-line.</p>
<p>This would not have happened with KBank SMS-based transaction notification services.</p>
<p>The first transaction with my cloned VISA debit card was less than $50 USD (I assume the fraudster was &#8220;testing the water&#8221;).   If I was using my KBank card, I would have received an immediate SMS message detailing a POS transaction in Bangkok when I was physically far away from Bangkok in Chiang Mai.   I could have immediately called the bank (or logged in) and blocked the debit card, limiting potential losses to the bank or the merchant to one fraudulent transaction, not seven.</p>
<p>In addition, KBank offers what they call a Web-Shopping VISA card, where you can go into your on-line account (verified by SMS OTP as mentioned) and request a VISA debit card number (with expiration date, CCV etc).   You set the limit from 0 to 500,000 THB (Thai Baht) per day; and you can login to your account and change this anytime (authenticating your transaction with another SMS-based OTP). You can also block or cancel this number anytime and apply for another one.</p>
<p>I am amazed that in Thailand I receive much better anti-fraud prevention and detection services than with banks in the US.   I know of no bank or brokerage in the US that offers the same quality of service and security as KBank in Thailand.  </p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:16:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visa debit card">visa debit card</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/visa card">visa card</category>
      <category domain="http://securityratty.com/tag/kbank">kbank</category>
      <category domain="http://securityratty.com/tag/kbank card">kbank card</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/transaction notification services">transaction notification services</category>
      <category domain="http://securityratty.com/tag/fraudulent transaction">fraudulent transaction</category>
      <source url="http://www.thecepblog.com/2008/08/20/technology-tales-from-thailand/">Technology Tales from Thailand: KBank Fraud Management</source>
    </item>
    <item>
      <title><![CDATA[Follow Windows 7 Engineering]]></title>
      <link>http://securityratty.com/article/00030fea89f556b799e34f490dcb2463</link>
      <guid>http://securityratty.com/article/00030fea89f556b799e34f490dcb2463</guid>
      <description><![CDATA[Seeking to promote &quot;an open and honest, and two-way, discussion about how we balance all of these interests and deliver software on the scale of Windows,&quot; Microsoft has launched the Engineering...]]></description>
      <content:encoded><![CDATA[Seeking to promote "an open and honest, and two-way, discussion about how we balance all of these interests and deliver software on the scale of Windows," Microsoft has launched the <a href="http://blogs.msdn.com/e7/default.aspx" target="_blank">Engineering Windows 7 blog,</a> hosted by two senior Microsoft stars, <A href="http://www.microsoft.com/presspass/exec/devaan/" target="_blank">Jon DeVaan</A> and <A href="http://www.microsoft.com/presspass/exec/ssinofsky/" target="_blank">Steven Sinofsky.</A>

A two-way discussion probably doesn't mean they are taking orders for features, but they will listen to concerns of the technical community and respond to them publicly. They specifically ask for topic suggestions (I've already sent one in). Not too many years ago this sort of thing was unthinkable at Microsoft, but it's been moving steadily in this direction.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/vAz-9017J-0" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 16:54:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/senior microsoft stars">senior microsoft stars</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/two-way discussion">two-way discussion</category>
      <category domain="http://securityratty.com/tag/discussion">discussion</category>
      <category domain="http://securityratty.com/tag/two-way">two-way</category>
      <category domain="http://securityratty.com/tag/topic suggestions">topic suggestions</category>
      <category domain="http://securityratty.com/tag/jon devaan">jon devaan</category>
      <category domain="http://securityratty.com/tag/deliver software">deliver software</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/vAz-9017J-0/follow_windows_7_engineering.html">Follow Windows 7 Engineering</source>
    </item>
    <item>
      <title><![CDATA[76Service - Cybercrime as a Service Going Mainstream]]></title>
      <link>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</link>
      <guid>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</guid>
      <description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/vEaSMC2S8nI/s1600-h/76service.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/qhgjQh39ej8/s200-R/76service.JPG" style="border: 0pt none ;" /></a>Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can partion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely.<br />
<br />
<a href="http://www.youtube.com/watch?v=lw9IeuKkNbc">The infamous 76service</a>, a cybercrime as a service web interface where customers basically collect the final output out of the banking malware botnet during the specific period of time for which they've purchases access to the service, is going mainstream, with 76Service's Spring Edition apparently leaking out, and cybercriminals enjoying its interoperability potential by introducing different banking trojans in their campaigns. <br />
<br />
In this post, I'll discuss the 76service's spring.edition that has been combined with a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher banking malware</a>, an a popular <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">web malware exploitation kit</a>, with two campaigns currently hosting 5.51GB of stolen banking data based on over 1 million compromised hosts 59% of which are based in Russia. Screenshots courtesy of an egocentric underground show-off.<br />
<br />
<a href="http://www.cio.com/article/print/135500">Some general info on the 76service</a> :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/JXHZFuBb6Rs/s1600-h/76service1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/2qZfVy6YfU8/s200-R/76service1.JPG" style="border: 0pt none ;" /></a>"<i>Subscribers could log in with their assigned user name and     password any time during the 30-day project. They’d be     met with a screen that told them which of their bots was     currently active, and a side bar of management options. For     example, they could pull down the latest drops—data     deposits that the Gozi-infected machines they subscribed to     sent to the servers, like the 3.3 GB one Jackson had     found. A project was like an investment portfolio. Individual     Gozi-infected machines were like stocks and subscribers bought     a group of them, betting they could gain enough personal     information from their portfolio of infected machines to make a     profit, mostly by turning around and selling credentials on the     black market. (In some cases, subscribers would use a few of     the credentials themselves). Some machines, like some stocks, would under perform and     provide little private information. But others would land the     subscriber a windfall of private data. The point was to     subscribe to several infected machines to balance that risk,     the way Wall Street fund managers invest in many stocks to     offset losses in one company with gains in another.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/uGe8GuhDvRg/s1600-h/76service2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/88IxypeBf74/s200-R/76service2.JPG" style="border: 0pt none ;" /></a>The 76service empowers everyone who is either not willing to spend time and resources for building and maintaining a botnet, launching campaigns, and SQL injecting hundreds of thousands of sites in order to take advantage of the long tail of malware infected sites that theoretically can outpace the traffic that could come from a SQL injected high-profile site.<br />
<br />
Next to the spring.edition, <a href="http://secureworks.com/research/threats/gozi/">the winter edition's price starts from $1000 and goes to $2000</a>, which is all a matter of who you're buying it from, unless of course you haven't come across leaked copies :<br />
<br />
"<i>Assuming that the dealer offering what he claimed was the 76service kit was correct, the profit is not only in the kit, but in selling value added services like exploitation, compromised servers/accounts, database configuration, and customization of the interface. Prices start between $1000 to $2000 and go up based on added services. The underground payment methods generally involve hard-to-track virtual currencies, whose central authority is in a jurisdiction where regulation is liberal to non-existent, and feature non-reversible transactions. The individual or group called "76service" was easy to track down on the Web, but not in person.</i>" <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/nl-OA3FHPs0/s1600-h/76service3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/8zS6gcoEdvk/s200-R/76service3.JPG" style="border: 0pt none ;" /></a>It's interesting to monitor how services aiming to provide specific malicious services are vertically integrating by expanding their portfolio of related services -- taka a spamming vendor that will offer the segmented email databases, the advanced metrics, and the localization of the spam messages to different languages -- or letting the buyer have full control of anything that comes out of a particular botnet for a specific period of time in which he has bought access to it. For instance, DDoS for hire matured into botnet for hire, which evolved into today's "What type of stolen data do you want?" for hire mentality I'm starting to see emerging, next to the usual interest in improving the metrics and thereby the probability for a more succesful campaign. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/4s3Mkgb-NOY/s1600-h/metafisher1_ukstories.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/Bt7wKW7IPcE/s200-R/metafisher1_ukstories.jpg" style="border: 0pt none ;" /></a>Ironically, this cybercrime model is so efficient that the people behind it cannot seem to be able to process all of the stolen data, which like a great deal of underground assets loses its value if not sold as fast as possible. The result of this oversupply of stolen data are the increasing number of services selling raw logs segmented based on a particular country for a specific period of time.<br />
<br />
Time for a remotely exploitable vulnerability in yet another malware kit about to go mainstream? Definitely, unless of course backdooring it and releasing it doesn't achieve the obvious results of controlling someone else's cybercrime ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><br />
<br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NWhwdK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NWhwdK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7zGnyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7zGnyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rqgfok"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rqgfok" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zA7GDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zA7GDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4r7WMK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4r7WMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=880FjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=880FjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3wtOmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3wtOmk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/363878623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/76service">76service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/malware botnet">malware botnet</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/mysterious 76service server">mysterious 76service server</category>
      <category domain="http://securityratty.com/tag/web service">web service</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/363878623/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</source>
    </item>
    <item>
      <title><![CDATA[Memo to the President]]></title>
      <link>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</link>
      <guid>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>Obama has a cyber security plan.</p>

<p>It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.</p>

<p>I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.</p>

<p>One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p></p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.schneier.com/blog/archives/2008/05/dualuse_technol_1.html">use it, too</a>.

<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> <a href="http://www.schneier.com/essay-025.html">software</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.schneier.com/essay-116.html">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  </p>

<p>Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  </p>

<p>Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.</p>

<p>If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.</p>

<p>Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> immensely in the long run.</p>

<p>Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.</p>

<p>Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.</p>

<p>And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/08/securitymatters_0807">originally appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LZGCXK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LZGCXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=56vyIK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=56vyIK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/memo_to_the_pre.html">Memo to the President</source>
    </item>
    <item>
      <title><![CDATA[Memo to Next President: How to Get Cyber Security Right]]></title>
      <link>http://securityratty.com/article/3cc71e9b8aab182bc3e96444e8660442</link>
      <guid>http://securityratty.com/article/3cc71e9b8aab182bc3e96444e8660442</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>
Obama has a cyber security plan.
</p><p>
It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.
</p><p>
I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.
</p><p>
One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/blog_securitymatters_0501 ">use it, too</a>.
</p>
<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> software <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.wired.com/politics/security/commentary/securitymatters/2006/06/71032">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  
</p><p>
Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  
</p><p>
Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> (.pdf) how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.
</p><p>
If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.
</p><p>
Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> (.pdf) immensely in the long run.
</p><p>
Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.
</p><p>
Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.
</p><p>
And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.

<p>
---
</p>

<p><em>Bruce Schneier is chief security technology officer of BT, and author of </em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=0ca9e7363b324d8d77996a8ec3f346da" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=0ca9e7363b324d8d77996a8ec3f346da" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=OUzpZK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=OUzpZK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jCsEfk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jCsEfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Xtv7Xk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Xtv7Xk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ZOA0EK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ZOA0EK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=bpRgSK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=bpRgSK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=3GI8fk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=3GI8fk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=tfYGEk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=tfYGEk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Ed9rWK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Ed9rWK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/358550437" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/358550481" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/358550481/securitymatters_0807">Memo to Next President: How to Get Cyber Security Right</source>
    </item>
    <item>
      <title><![CDATA[Q&A with Sergey Katsev of Coyote Point Systems]]></title>
      <link>http://securityratty.com/article/e57e1ace426f0aef838f8f362c558571</link>
      <guid>http://securityratty.com/article/e57e1ace426f0aef838f8f362c558571</guid>
      <description><![CDATA[I recently had the opportunity to sit down with Sergey Katsev , an Engineering Project Manager at Coyote Point Systems and discuss his experiences with InteropNet and talk about the Coyote Point...]]></description>
      <content:encoded><![CDATA[<p>I recently had the opportunity to sit down with <a href="http://www.facebook.com/profile.php?id=24405331" target="_blank">Sergey Katsev</a>, an Engineering Project Manager at <a href="http://coyotepoint.com/" target="_blank">Coyote Point Systems</a> and discuss his experiences with InteropNet and talk about the Coyote Point products.  With a couple of years of experience as a vendor for Interop, he had some interesting insights in to how participating in the InteropNet can help a vendor.</p>
<p><strong>ScienceLogic:</strong> How long have you been involved in InteropNet?</p>
<p><strong>Katsev: </strong>I started at Coyote Point 3 years ago and <a href="http://blog.interop.com/2006" target="_blank">InteropNet 2006</a> was my first &#8220;big&#8221; assignment.  This was the first time Coyote Point had put in a proposal to participate, so we were very excited when we were selected.</p>
<p><strong></strong></p>
<p><strong>ScienceLogic: </strong>How long has Coyote Point been involved in Interop overall?</p>
<p><strong>Katsev: </strong>We&#8217;ve been exhibiting at Interop for a number of years, and after seeing the InteropNet in action, we decided to submit a proposal in &#8216;06.  We were actually one of the first companies in the load balancing/traffic management space (we&#8217;ve been doing this for almost 10 years), so we have a lot of experience to share with InteropNet.</p>
<p><strong>ScienceLogic:</strong> What is your role at Coyote Point?</p>
<p>My official title is &#8220;Engineering Project Manager&#8221;.  Basically, that means that I&#8217;m in charge of product releases and maintenance.  It sounds like a weird title for someone participating in InteropNet, but I&#8217;ve actually found it extremely useful since my position means that I don&#8217;t get to see our systems out in the field a lot.  We&#8217;ve added several features and have ideas for others just from my experiences at InteropNet.</p>
<p><strong></strong></p>
<p><strong>ScienceLogic:</strong> What do the Coyote Point products do?</p>
<p><strong>Katsev: </strong>Coyote Point makes a Traffic Management appliance called <a href="http://coyotepoint.com/products/e650.php" target="_blank">Equalizer</a>.  What this means is that any traffic destined for a datacenter&#8217;s servers goes through our appliances and we make sure that the server which is best equipped to handle it, does.  Our systems sit between the clients and the servers and monitor the client traffic and the state of the servers.  If the clients start sending more traffic, we&#8217;ll balance it out so that no server is overloaded.  If one of the servers stops responding or starts responding very slowly, we&#8217;ll steer traffic away from that server.</p>
<p><strong>ScienceLogic: </strong>In what way are your products being used as part of InteropNet?</p>
<p><strong>Katsev: </strong>In the InteropNet, we&#8217;re utilizing a lot of our expertise:  We&#8217;re making sure that traffic is balanced and servers are redundant for show services such as DNS and SMTP.  We&#8217;re also using our geographic load balancing technology to ensure that the ScienceLogic EM7 appliances and some other internal NOC services are available from anywhere, with the lowest latency, with our <a href="http://www.coyotepoint.com/products/xcel.php" target="_blank">SSL acceleration </a>and <a href="http://www.coyotepoint.com/products/express.php" target="_blank">GZIP compression technology</a>.  Finally, we&#8217;re helping logistics in the NOC by allowing a physical separation between systems <a href="http://blog.interop.com/interopnet/2008/04/what-are-these-peds-you-speak-of" target="_blank">located in the NOC</a> and those in an emergency rack outside of the NOC.  If either of these two locations were to fail, the network will continue operating without a glitch.</p>
<p><strong>ScienceLogic:</strong> Are there any special considerations for Interop that cause you to deploy your systems there differently that any other place?</p>
<p><strong>Katsev: </strong>Interop is definitely different than most of our customer installations.   One difference from a standard environment is that the network (at least this year) is one large flat network, with pieces carved out where extra security is needed.  Because of this, we can actually run our failover pairs of Equalizer systems in a non-standard configuration where the two peers are in different racks, or even on different floors.  That&#8217;s one of the things that I really like about InteropNet &#8212; it definitely brings new ideas to mind, which end up becoming &#8217;special configuration&#8217; white papers after the show.</p>
<p><strong>ScienceLogic:</strong> Has InteropNet taught you anything that caused you to actually change your product?</p>
<p><strong>Katsev: </strong>In addition to the failover configuration differences I mentioned above, participating in InteropNet has actually caused us to add several new features and allowed configurations.  One example is the &#8220;no-spoof&#8221; option for <a href="http://www.springerlink.com/content/dcmmpmb53rjp5hr8/" target="_blank">Layer 4 clusters</a>.  Prior to the 2006 shows, we always &#8217;spoofed&#8217; the client&#8217;s IP address when talking to a server so that the server would see the client&#8217;s IP address instead of our own.  At Interop, we ran into a special configuration which would&#8217;ve been very difficult to set up in this manner, so our engineers added this feature, and it&#8217;s been very a very popular configuration with our customers ever since.</p>
<p>We have also had a couple of business relationships that extended outside of the show.  In 2006, we had a good experience using <a href="http://www.spirent.com/analysis/index.cfm?media=3&amp;ws=2" target="_blank">Spirent Communications</a> gear to benchmark the network, so we ended up purchasing a couple of these systems to test our products.  More recently, we have found a way to bundle our Equalizer e350si load balancers with the ScienceLogic <a href="http://www.sciencelogic.com/techdiagram.htm" target="_blank">EM7 collector appliances</a> to help ScienceLogic get the best performance in load balancing large quantities of syslog messages to be processed.  If it wasn&#8217;t for our participation in InteropNet, neither of these relationships would&#8217;ve happened.</p>
<p><strong>ScienceLogic: </strong>What’s the best part of being involved with InteropNet?  What do you most look forward to?</p>
<p><strong>Katsev: </strong>InteropNet is an amazing networking opportunity (no pun intended).  The group of engineers that put the network together every year is, well, amazing.  There is so much combined experience that any question instantly has several possible answers, and the best answer is chosen very quickly.  One of the &#8217;sayings&#8217; at Interop is &#8220;if you run into a problem, ask someone&#8230; we&#8217;ve probably seen that problem before&#8230; five times.&#8221;  One would think that being part of InteropNet is the same thing, year after year.  However, in the two years that I&#8217;ve been part of this (for four shows), there have been huge differences in the way that the network is designed and put together.  These are both because the vendors selected every year are different, and because the engineers who design the network change from year to year.  Somehow, though, when all is said and done, we have a <a href="http://blog.sciencelogic.com/interop-las-vegas-2008-some-interesting-stats/06/2008" target="_blank">network that works</a>.</p>
<p><strong>ScienceLogic:</strong> You don’t have to answer this one if you’re not comfortable… What would you like to see changed with the way things are done at InteropNet?</p>
<p><strong>Katsev: </strong>This isn&#8217;t a cop-out&#8230; I really can&#8217;t think of anything I would do differently.  Sure, there are small problems that pop up sometimes, but every project has those, and the people at InteropNet are more than capable of figuring them all out.  In fact, I know that Interop started out as a show to test the interoperability of devices&#8230; but I&#8217;m still amazed that all of these devices actually talk to each other and <a href="http://blog.sciencelogic.com/qa-with-geoff-horne-of-interopnet/06/2008" target="_blank">&#8220;play nice&#8221; together</a>.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Q%26%23038%3BA+with+Sergey+Katsev+of+Coyote+Point+Systems&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fqa-with-sergey-katsev-of-coyote-point-systems%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 12:34:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/katsev">katsev</category>
      <category domain="http://securityratty.com/tag/sergey katsev">sergey katsev</category>
      <category domain="http://securityratty.com/tag/interopnet">interopnet</category>
      <category domain="http://securityratty.com/tag/coyote">coyote</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/sciencelogic em7 appliances">sciencelogic em7 appliances</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/client traffic">client traffic</category>
      <source url="http://blog.sciencelogic.com/qa-with-sergey-katsev-of-coyote-point-systems/08/2008">Q&amp;A with Sergey Katsev of Coyote Point Systems</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</link>
      <guid>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</guid>
      <description><![CDATA[A handful of scam mails currently in circulation, including one mention of &quot;groundnut oil&quot; that seems so bizarre I had to highlight it in bold text. All this and more, after the jump
Subject
FROM THE...]]></description>
      <content:encoded><![CDATA[
        A handful of scam mails currently in circulation, including one mention of "groundnut oil" that seems so bizarre I had to highlight it in bold text. All this and more, after the jump...<br />  
        Subject:<br />FROM THE DESK OF MR. STEVEN JAMES<br />From:<br />"Steven James"&lt;steven@fristbnkngplc.net&gt;<br />Date:<br />Mon, 30 Jun 2008 19:17:03 +0100<br />BCC:<br /><br />FROM THE DESK OF MR. STEVEN JAMES<br />CHAIRMAN INTERNATIONAL RELATION<br />FIRST BANK OF NIGERIA PLC<br /># 1 BANK ROAD WUSE FCT <br />ABUJA-NIGERIA.<br />PHONE: +234-80-66520277<br />Email: stevenjames809@live.co.uk&nbsp; <br /><br /><br />Very Urgent Attention,<br /><br />Please permit me to introduce my humble self to you, my name is Mr. Steven James, I am the Manager of International Relation with First Bank of Nigeria Plc, I 'm 38yrs old, and I got your email address from a friend of mine, and my confidence reposed on you. I hope you read this message carefully and reply me immediately. Although we have not met before, but I suggest that this transaction will bring us together.<br /><br />My dear, we had a customer, a foreigner but base here in Nigeria, his Name was Mr. Hamilton Creek. He is from Atlanta Georgia United State of America, but based here with his wife and his two children, Mr. Hamilton has being banking with us for the past 4yrs and some time in August 2002, Mr. Hamilton was on his way to his house, and <b>unfortunately ran into a Trailer load of Groundnut Oil, and died&nbsp;&nbsp; immediately, Their car got burnt, no single soul was saved, Mr. Hamilton Creek and His entire family was confirmed dead.</b><br /><br />My Board of Directors and the Management of First Bank has mandated and instructed me to look for Mr. Hamilton Creek? Relation(s) and his Next of&nbsp; Kin to come and claim his fund, Since August 2003 till date, I have been looking for his relation's or his next of Kin to come and claim his fund which he Deposited with our bank, I have contacted his Embassy and after 3days, his Ambassador told me that Mr. Hamilton Creek has no relation and no next of Kin, their Ambassador told me that he used his first son as His next of kin, but it is quite unfortunate that Mr. Hamilton Creek Died with all his family members.<br /><br />The reason why I contacted you is thus, Mr. Hamilton is dead, and his only son who supposed to inherit his properties and money also died with him. As at this moment, nobody or person[s] is coming to&nbsp;&nbsp; claim this Money from our bank. The Board of Directors and management of our bank told me that if nobody or person[s] apply for the claim of Mr. Hamilton Fund, the bank will return the entire Fund into our Federal reserve. In the Light of the above, I want you to stand as the next of kin to Late Mr. Hamilton Creek; it might interest you to know that he had a Domiciliary Bank Account with our Bank and he has a total sum of US$9.2M Nine Million Two Hundred thousand Dollars, this is the exact amount which he had in his domiciliary account before the ugly incident occurred, and this money is still in his account as unclaimed money.<br /><br />This transaction is very easy and simple, and it is 100% risk free, I'm the Manager for International Relations with First Bank of Nigeria Plc, and the Management and Board of Directors of the Bank are waiting for me to provide to them the Relation or next of Kin to late Mr. Hamilton Creek, of which I told them that I am still searching the next of kin to the deceased. Finally, if you are interested with this transaction, I will front you to the bank as the only next of kin to late Mr. Hamilton Creek, and I will let the bank know that you are the only right person to inherit Late Mr. Hamilton Funds and properties. If you are interested, just email me or call me on my&nbsp;&nbsp; direct and private line#: +234-80-27536038 and late Mr. Hamilton's Funds will be credited into your account and all his Properties will be released to you either through Courier Services or the Bank will Cargo all his properties to you in any were you want it.<br /><br />So reply me immediately and feel free to ask any question with regards to this transaction. You will take 50% of the US$9.2M. Which is? US$4.600, 000.00 Four Million Six Hundred Thousand Dollars, while the Balance of the same amount will be mine.<br /><br />Your swift response will be highly appreciated.<br /><br />Thanks and have a nice day.<br /><br />Friendly Regards<br /><br />Mr. Steven James<br /><br />*******************************************************************************************<br /><br />Subject:<br />REPRESENTATIVE NEEDED<br />From:<br />DFS SALES LTD UK &lt;info@dfs.net&gt;<br />Date:<br />Tue, 01 Jul 2008 23:00:55 +0800<br />To:<br />undisclosed-recipients: ;<br /><br /><br />COMPLIMENT OF THE DAY TO YOU.<br /><br />I am PETER WOODS from DFS SALES LTD UK.(<br />Website: www.dfs-online.co.uk ) Visit our site<br /><br />We are into&nbsp; furnitures and we sell shares to people in<br />Canada,America, Australia and Europe.<br /><br />We are in need of a book keeper. someone who can represent our company<br />in his/her country.<br /><br />Our client in your location will contact you and make the company<br />payment to you.<br /><br />You will be entitle to 11% of every payment been made out to you.<br /><br />This is because most of our officer are from china and they do not<br /><br />understand english very well.its hard for them to contact our<br />customers.<br /><br />Our head office is located in CHINA. But we have a sub-office in the<br />uk.<br /><br />If you are interested, Kindly send the entries for more understanding.<br /><br />NAME IN FULL :.........<br />COMPANY NAME: .....<br />POSITION:......<br />FULL ADDRESS: .......<br />CITY/TOWN:........<br />STATE:............<br />ZIP CODE:........<br />COUNTRY:.......<br />MOBILE:.......<br />HOME TEL: .....<br />EMAIL ADDRESS: ........<br />OCCUPATION: ...........<br />BANK NAME :.......<br />AGE:............<br /><br />You are to send the above details to<br /><br />NAME : PETER WOODS.<br />EMAIL : dfs_woods@yahoo.co.uk<br />PHONE NUMBER : +44-704-575-0212<br /><br />HOPE TO HEAR FROM YOU<br /><br /><br />*****************************************************************************************<br /><br />To:<br />undisclosed-recipients:;<br /><br />Good day!!!<br /><br />&nbsp;We have been waiting for you since to contact me for your Confirmable Bank Draft of ?18 Million (Eighteen Million Pounds sterling) but we did not hear from you since for a couple of weeks now. Then we went to the bank to confirm if the draft that expired or getting near to expire and Metropolitan Police Uk told us that before the funds will get to your hand that it will expire.So I told him to cash the ?18 Million (Eighteen Million Pounds sterling) to cash payment to avoid losing this fund under expiration as I will be out of the country for a 6 Months Course.<br /><br />&nbsp;What you have to do now is to contact FED EX COURIER SERVICES as soon as possible to know when they will deliver of your funds to you because of the expiring date. For your information we have paid for the delivering Charge Insurance premium. The only money you will send to the FED EX COURIER SERVICES to deliver your cheque direct to your postal Address in your country is ?250.00 being Security Keeping Fee of the Courier Company so far. Again don't be deceived by anybody to pay any other money except ?250.00 for the Security Keeping Fee.We would have paid that but they said no because they don't know when you will contact them and in case of demurrage. You have to contact FED EX COURIER SERVICES now for the delivery of your Draft with this<br />information below:<br /><br />&nbsp;CONTROLLER: Mrs.Helen Williams<br />&nbsp;NAME: FED EX COURIER SERVICES<br />&nbsp;ADDRESS: fedexofficeuk@gmail.com<br />&nbsp;PHONE NUMBER: +447024080684<br /><br />&nbsp;IF YOU ARE THE OWENER OF THE FUNDS AND YOU WILL SEND YOUR INFORMATION TO US SO THAT WE CAN DELIVERY YOUR FUNDS TO YOU WITHIN THE NEXT 84HRS TIME.IF YOU DO NOT RECEIVED YOUR FUNDS WITHIN THE NEXT 72HRS TIME AND YOU REPORT US THE UK FBI AND THE METROPOLITAN POLICE (SCOTLAND YARD) or YOU CONTACT YOUR LAWYER TO TAKE UP PROCEDURES AGAINST US.<br /><br />&nbsp;Let me repeat again try to contact them as soon as you receive this mail to avoid any further delay and remember to pay them their Security keeping fee of ?250.00 for their immediate action. The FED EX COURIER SERVICES don't know the contents of the funds. This is to avoid them delaying with the funds.<br /><br />&nbsp;Thanks as you contact them today.<br /><br />&nbsp;Yours Faithfully<br /><br />&nbsp;Mrs Helen Williams.<br /><br /><b>(The above actually comes with a nifty graphic that they've thrown in, thinking it makes it all look more legitimate. It doesn't, but here it is anyway):</b><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fedx1.jpg" src="http://blog.spywareguide.com/images/fedx1.jpg" class="mt-image-none" style="" height="64" width="472" /></span>
<br /><br />....altogether now: oooooh. A slightly shorter 419 roundup than usual, but I'm sure I'll have piles of the things next week.<br /><br /><br /><div class="moz-text-plain" wrap="true" graphical-quote="true" style="font-family: -moz-fixed; font-size: 13px;" lang="x-cyrillic"><pre wrap=""><br /><br /><br /><br /><br /></pre></div><div><br /></div>
    ]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 13:11:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hamilton fund">hamilton fund</category>
      <category domain="http://securityratty.com/tag/hamilton">hamilton</category>
      <category domain="http://securityratty.com/tag/hamilton creek">hamilton creek</category>
      <category domain="http://securityratty.com/tag/draft">draft</category>
      <category domain="http://securityratty.com/tag/confirmable bank draft">confirmable bank draft</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/domiciliary bank account">domiciliary bank account</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/hamilton funds">hamilton funds</category>
      <source url="http://blog.spywareguide.com/2008/07/your-419-mail-roundup-1.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Security Certification Rules Could Shake Up IT Mgmt]]></title>
      <link>http://securityratty.com/article/4f82425b41fbf0177d2fd2faa45c0e29</link>
      <guid>http://securityratty.com/article/4f82425b41fbf0177d2fd2faa45c0e29</guid>
      <description><![CDATA[This seems to a well intentioned but, misguided attempt by the Office of Management and Budget. They are attempting to establish minimum requirements for professional certification for IT workers
Hmm...]]></description>
      <content:encoded><![CDATA[<p>This seems to a well intentioned but, misguided attempt by the Office of Management and Budget. They are attempting to establish minimum requirements for professional certification for IT workers. </p>
<p>Hmm.</p>
<p>From GCN:</p>
<blockquote><p>“This is a change we have not faced in the IT security industry before,” he added.</p>
<p>The closest parallel has been in the Defense Department, which anticipated OMB’s reaction in this area. DOD’s Directive 8570 on information assurance, approved in December 2005, requires all of the department’s information assurance workers to obtain an accredited commercial certification in computer security. DOD has approved 13 certifications for the directive.</p>
<p>The DOD requirement already has thrown what one conference attendee called a giant monkey wrench into the IT security manpower market.</p>
<p>“If OMB issues a similar requirement, it’s going to throw the supply and demand curve even more out of balance,” he said.</p>
<p>Datesman agreed, saying it probably would take years for the supply of certified workers to catch up with demand. A CISSP certification requires five years’ experience. “You don’t mint them out of college,” he said. </p></blockquote>
<p>OK, this is where this trolley leaves the track. I have met CISSP certified folks that I would wager they&#8217;d be lucky to fight their way out of a wet paper bag. &#8220;Don&#8217;t mint them out of college&#8221; is a phrase that I&#8217;d argue. I would offer that the ISC2 should start auditing certified members. The validity of the CISSP cert is becoming diluted in the eyes of the market.</p>
<p>A picture is worth a thousand words.</p>
<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2007/08/notacissp.jpg" alt="Myrcurial at Defcon" /></center></p>
<p>It&#8217;s great for the mandatory HR tick box but, how many of these folks actually have the ability? Sure they can memorize some flash cards and pass a test but, are they effective? Some, not so much.</p>
<p>On the face of it this is a good idea. </p>
<p>Like all good intentions, they make great paving stones on the road to hell. </p>
<p><a href="http://www.gcn.com/online/vol1_no1/46543-1.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=qIkGql"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=qIkGql" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CehK5I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CehK5I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CQohOi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CQohOi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xF5oKi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xF5oKi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=qY7Wui"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=qY7Wui" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=TNh3Mi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=TNh3Mi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/320492452" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:33:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cissp cert">cissp cert</category>
      <category domain="http://securityratty.com/tag/cissp">cissp</category>
      <category domain="http://securityratty.com/tag/cissp certification requires">cissp certification requires</category>
      <category domain="http://securityratty.com/tag/requires">requires</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/security manpower market">security manpower market</category>
      <category domain="http://securityratty.com/tag/giant monkey wrench">giant monkey wrench</category>
      <category domain="http://securityratty.com/tag/dod requirement">dod requirement</category>
      <category domain="http://securityratty.com/tag/establish minimum requirements">establish minimum requirements</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/320492452/">Security Certification Rules Could Shake Up IT Mgmt</source>
    </item>
    <item>
      <title><![CDATA[A question of trust and identity]]></title>
      <link>http://securityratty.com/article/c70bf356e7480ddc69ea5a6759de33fd</link>
      <guid>http://securityratty.com/article/c70bf356e7480ddc69ea5a6759de33fd</guid>
      <description><![CDATA[What is the right balance between security and privacy? This is a common starting point in many policy discussions, especially in government. Its a trick question because it presets the conversation...]]></description>
      <content:encoded><![CDATA[What is the right balance between security and privacy? This is a common starting point in many policy discussions, especially in government. It’s a trick question because it presets the conversation as a balancing act between two values as if they are antithetical – they are not. In practical terms, privacy is security. ]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/policy discussions">policy discussions</category>
      <category domain="http://securityratty.com/tag/practical terms">practical terms</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/trick question">trick question</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/antithetical">antithetical</category>
      <category domain="http://securityratty.com/tag/values">values</category>
      <category domain="http://securityratty.com/tag/common">common</category>
      <source url="http://www.networkworld.com/columnists/2008/061008-andreas.html?fsrc=rss-security">A question of trust and identity</source>
    </item>
    <item>
      <title><![CDATA[Monday Potpourri]]></title>
      <link>http://securityratty.com/article/1e0e8ae13eb3919dc152dd3deac4c032</link>
      <guid>http://securityratty.com/article/1e0e8ae13eb3919dc152dd3deac4c032</guid>
      <description><![CDATA[There are some days where nothing strikes me as interesting enough to blog. Than there are days like today where there are just too many things that I find compelling enough to comment on. So rather...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>There are some days where nothing strikes me as interesting enough to blog.&nbsp; Than there are days like today where there are just too many things that I find compelling enough to comment on.&nbsp; So rather than do 4 or 5 posts today, let me condense all of this goodness (I hope) into one post:</p>

<p>1. <a class="zem_slink" title="Sophos" href="http://www.sophos.com/" rel="homepage">Sophos</a> releases &quot;<a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&amp;newsId=20080609005331&amp;newsLang=en">financial results ahead of analysts expectations</a>&quot;. While I applaud the Sophos folks for making public their revenue numbers (at least gross, net and deferred totals it seems), I am not sure what analysts they are talking about.&nbsp; As a private company, it is not like people are trading their stock and the financial analyst crowd is putting their numbers on the street.&nbsp; 200+m is a lot of revenue, even for an AV company and 40+m to the bottom line is impressive, but until you are public, no one is holding your feet to the fire and analyst coverage is just not the same.</p>

<p><span style="color: #0033cc;">Authors note: <strong>Dr. Jan Hruska</strong>, co-founder of Sophos wrote me off line and gave me permission to publish this comment: </span><span style="font-size: 0.8em;"></span>2. <a href="http://blogs.zdnet.com/BTL/?p=9046&amp;tag=nl.e539">Apple is ready to enter the platform war</a> - Larry Dignan over at ZDNet has some good comments and stats on Apple vying with Microsoft and Linux/open source to be &quot;the platform&quot; of the future. I agree that the <a class="zem_slink" title="IPhone" href="http://en.wikipedia.org/wiki/IPhone" rel="wikipedia">iPhone</a> and <a class="zem_slink" title="IPod" href="http://en.wikipedia.org/wiki/IPod" rel="wikipedia">iPod</a> are Trojan Horses into the enterprise and along with the <a class="zem_slink" title="Macintosh" href="http://en.wikipedia.org/wiki/Macintosh" rel="wikipedia">Mac</a> represent a viable platform that could compete with Microsoft and the Linux/open source crowd.&nbsp; However, I don't think you can judge how many developers are developing Mac/iPhone apps based on the crowd at the upcoming WWDC (worldwide developer conference).&nbsp; <a class="zem_slink" title="Steve Jobs" href="http://www.youtube.com/watch?v=D1R-jKKp3NA" rel="youtube">Steve Jobs</a> is a master showman and I think these conferences have become media events.&nbsp; Many people are there to to twitter and report and to &quot;be there&quot;.</p>

<p><span style="color: #0033cc;"><strong>In October last year we prepared for a float on the London Stock Exchange. As a part of the exercise we had analysts from the three sponsor banks produce their projections for revenue etc for the next three years. We did better that their projections for 2007/08.</strong></span></p>



<p>Larry is right though that Apple has to balance being too iPhone and iPod crazy at the risk of ignoring the &quot;real&quot; platform here the Mac.&nbsp; His example about PGP developing a Mac version is a great point.&nbsp; I have heard many other security companies likewise bringing Mac versions to market. This graphic I think shows the point well:</p>

<p><a href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/06/09/pgp_mac.png"><img title="Pgp_mac" height="216" alt="Pgp_mac" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/06/09/pgp_mac.png" width="300" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></a>&nbsp; But my ultimate point on this one is that the ultimate platform will be the web.&nbsp; What the underlying OS is for future web apps should be somewhat meaningless.&nbsp; The webtop platform would seem to me to be the platform going forward!</p>

<p>In any event the WWDC should be a lot of fun and I will be watching to see if any new reports come out.</p>

<p>3. <a href="http://www.techworld.com/mobility/news/index.cfm?newsid=101703&amp;email">Belden buys Trapeze</a> - Another independent WLAN provider gets bought. Doesn't seem like a great multiple, 133m on 2007 revenue of 56m.&nbsp; There are not many independent WLAN providers out there now.&nbsp; Meru Networks is probably the biggest of the bunch. You don't hear too many people saying that wireless is not here yet anymore.</p>

<p><a href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/06/09/roi.jpg"><img title="Roi" height="95" alt="Roi" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/06/09/roi.jpg" width="300" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> 4. <a href="http://www.mcafee.com/us/enterprise/products/tools/ad/roi/">McAfee still chasing the dragon on security ROI</a> - McAfee announced that using the Forrester Economic Impact Calculator you can now easily find out your ROI from buying a McAfee product. They have a very nice diagram that I have pasted in here. They ask you to plug in a few numbers about type of security you want, desktops, laptops and servers and presto - they give you an ROI.&nbsp; I didn't call them to get the scoop, but it really underwhelmed me.&nbsp; Looks like smoke and mirrors to me, just like many of these security ROIs do.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/4f9c782a-d16e-400c-8655-1a13063c2658/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=4f9c782a-d16e-400c-8655-1a13063c2658" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 07:04:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/platform">platform</category>
      <category domain="http://securityratty.com/tag/platform war">platform war</category>
      <category domain="http://securityratty.com/tag/roi">roi</category>
      <category domain="http://securityratty.com/tag/security roi">security roi</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/webtop platform">webtop platform</category>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/mac versions">mac versions</category>
      <category domain="http://securityratty.com/tag/viable platform">viable platform</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/monday-potpourr.html">Monday Potpourri</source>
    </item>
  </channel>
</rss>
