<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: book]]></title>
    <link>http://securityratty.com/tag/book</link>
    <description></description>
    <pubDate>Mon, 15 Sep 2008 20:40:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The asymmetry of data loss - data thief has an upper hand]]></title>
      <link>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</link>
      <guid>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</guid>
      <description><![CDATA[I read this awesome book by Dan Geer, Economics and Strategies of Data Security . This gave me structure for my thoughts about a complex topic such as data security
When a data owner's (a business)...]]></description>
      <content:encoded><![CDATA[<P>I read this&nbsp;awesome book by Dan Geer, <A href="http://www.verdasys.com/thoughtleadership/">Economics and Strategies of Data Security</A>. This gave me structure&nbsp;for my thoughts about a complex topic such as data security. </P>
<P>When&nbsp;a&nbsp;data owner's (a business)&nbsp;sensitive data is breached it is&nbsp;difficult to quantify the monetary loss. According to respectable survey sources, the average cost of sensitive data breach for a large size company is about $50,000. I am attempting here to think about this in simple mathametical terms:</P>
<P>There is a data breach. From the data owner's perspective the loss is:</P>
<P><FONT color=#3366ff>Loss&nbsp;= Cost to protect data&nbsp;+ Loss of business due to data theft aka cost of competitive disadvantage</FONT></P>
<P>From the data thief's perspective</P>
<P><FONT color=#3333ff>Net Gain= [Cost of producing the data&nbsp; *&nbsp; Data freshness factor] - Cost to steal the data + Profit of business due to data aka gain of competitive advantage</FONT></P>
<P>From the above two equations it is very clear that this is not a zero sum game. There is a clear cost asymmetry for a data owner and for a data thief. When there is an asymmetry there is an opportunity. Data owner&nbsp;would not even know that the&nbsp;data is lost because&nbsp;the original copy of the data may be still intact - data thief could have simply copied the data.&nbsp;Data theft does not look like&nbsp;a car theft, there is no vacuum left behind.&nbsp;</P>
<P><STRONG><EM>This motivates a data thief to keep the cost to steal low, steal highly valuable data that has&nbsp;a long shelf life and in a way that data owner will never even be aware of theft.</EM></STRONG></P>
<P>From&nbsp;a data thief's perspective, the cost to steal data if kept high would disincentive him. Moreover, Data freshness factor, i.e. how valuable this data is over period of time plays an important role.&nbsp;A good example is content of today's newspaper is hardly valuable tomorrow, but the content of newspaper two days ahead (if can be procured)would be invaluable. Data relevance is a function of time and other marketplace variables - &nbsp;Data freshness Factor accounts for that variable. A good way to discourage data thief is to increase his/her cost to steal the data. There are other inferences from the above equation. If there exists&nbsp;no competitive advantage&nbsp;with the stolen data, hardly any thief would even venture&nbsp;to steal the&nbsp;data in the first place. If the cost of producing data is very low, then probably thief can just produce the data himself and would not attempt to steal the data. If the cost of&nbsp;theft is kept high, it would definitely deter the data thief from stealing data using technical mechanisms, then the data thief would&nbsp;exploit weak links in data security&nbsp;such as use of social engineering to get access to the data.</P>
<P>From data owner perspective protecting data becomes very important. How much would the owner be willing to spend? Not definitely the cost equal to cost of producing the data. 1% to 10% of cost of producing data is considered prudent. For a data owner it is difficult to estimate cost of data protection of a specific data, because it is not easy to chunkify data protection costs. Moreover, as Dan Geer says in his book, a data owner has to protect himself from number of intruders not just one.</P>
<P><EM><STRONG>It pays for a data owner to: be aware of data breaches (or data leaks), employ appropriate&nbsp;mechanisms to protect the data; the cost of protection which&nbsp;is fractional cost of&nbsp;the valuable&nbsp;data and&nbsp;enhance information security awareness of personnel who handle the data.</STRONG></EM></P>
<P><STRONG><EM>Data loss is not a zero sum game. The advantage is in favor of a data thief (data thieves rather).&nbsp;Data owner does not give much thought&nbsp;on&nbsp;the value of data&nbsp;unless&nbsp;there is a data theft.&nbsp;But,&nbsp;a&nbsp;data thief&nbsp;has every reason to think about economics of data theft before he acts to steal the data else data thief won't survive in this game and he is very well aware of his advantageous position.</EM></STRONG></P>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:33:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data owner perspective">data owner perspective</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/thief">thief</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data freshness factor">data freshness factor</category>
      <category domain="http://securityratty.com/tag/data protection costs">data protection costs</category>
      <category domain="http://securityratty.com/tag/discourage data thief">discourage data thief</category>
      <category domain="http://securityratty.com/tag/protect data">protect data</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html">The asymmetry of data loss - data thief has an upper hand</source>
    </item>
    <item>
      <title><![CDATA[Passgen tool from my book]]></title>
      <link>http://securityratty.com/article/10fd1ee17e5b6f22fc7c246edbe0163b</link>
      <guid>http://securityratty.com/article/10fd1ee17e5b6f22fc7c246edbe0163b</guid>
      <description><![CDATA[Way back in 2005, Jesper Johannson and I wrote Protect Your Windows Network . Its still available , and although its product set is now somewhat dated (Windows XP and Server 2003), much of the...]]></description>
      <content:encoded><![CDATA[<p>Way back in 2005, <a target="_blank" href="http://msinfluentials.com/blogs/jesper/">Jesper Johannson</a> and I wrote <em>Protect Your Windows Network</em>. It’s <a target="_blank" href="http://www.amazon.com/dp/0321336437">still available</a>, and although its product set is now somewhat dated (Windows XP and Server 2003), much of the practical advice about security policies, social engineering, security dependencies, and how to think about security remains relevant. That’s because we strove to write something more lasting than a simple configuration guide.</p>  <p>On the CD-ROM accompanying the book we included a tool called Passgen. In the book, we recommended that you maintain separate passwords on every local administrator and service account in your enterprise. This is, of course, almost impossible to manage without something to automate it for you. That’s what Passgen does. The tool generates unique passwords based on known input (an identifier and passphrase you define), sets those passwords remotely, and allows you to retrieve them later.</p>  <p>For a while Jesper maintained a web site for the book, running on a server in his house. His <a target="_blank" href="http://www.comcast.net/terms/subscriber/">ISP</a> changed <a target="_blank" href="http://www.comcast.net/terms/use/">policies</a> and made it impractical to continue running the site. But because the tool is still so useful, I’ve put a copy in my <a target="_blank" href="http://steveriley-ms.spaces.live.com/">SkyDrive</a>—look in the “<a target="_blank" href="http://cid-45497626ab321d20.skydrive.live.com/browse.aspx/Passgen">Passgen</a>” folder.</p>  <p>Also, note that I’ve put a new section in the right-side column, “Resources for you.” Here’s where I’ll keep links to bits and pieces that many of you will find relevant and interesting.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3130067" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 16:42:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/passwords remotely">passwords remotely</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/unique passwords based">unique passwords based</category>
      <category domain="http://securityratty.com/tag/relevant">relevant</category>
      <category domain="http://securityratty.com/tag/security remains relevant">security remains relevant</category>
      <category domain="http://securityratty.com/tag/windows network">windows network</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx">Passgen tool from my book</source>
    </item>
    <item>
      <title><![CDATA[Have CrackBerry, Will Travel]]></title>
      <link>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</link>
      <guid>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</guid>
      <description><![CDATA[Blogger: Dan Blum
It is no surprise for us to hear loose lips flapping in India about a capability to decrypt Blackberry and other carrier traffic
After all, weve done basic threat analysis for years...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>It is no surprise for us to hear loose lips flapping in India about <a href="http://economictimes.indiatimes.com/At_last_govt_cracks_BlackBerry_code/articleshow/3510719.cms">a capability to decrypt Blackberry and other carrier traffic</a>.</p>

<p>After all, we’ve done basic threat analysis for years and it was only months ago that I was brought into a company-wide CISO meeting at a U.S. defense contractor to help them hash out their travel policy for mobile devices. Going into the meeting, I knew their policy restricted taking devices to a list of countries considered dangerous – but there was an exemption for BlackBerries.</p>

<p>Our research uncovered that BlackBerry is pretty secure in most respects. It has transport encryption along with optional password protection, remote kill, disk encryption, and S/MIME encryption. Viruses have not flourished on this functionally limited and closed platform. Few if any third party add on programs are required for additional protection. Nonetheless, I went into the meeting prepared to talk with the CISOs about the risks and security limitations of life on BlackBerry.</p>

<p>Was the BlackBerry exemption reasonable? At the time, BlackBerry transport encryption was not known to have been broken (to be fair, the article listed above still qualifies as rumor, not certainty of breakage). However, I pointed out that it is dangerous to assume well-equipped attackers like military or intelligence organizations can’t crack transport encryption. And even if they haven’t cracked the BlackBerry network and whole disk encryption features, sophisticated adversaries have other attack paths. Check out Neal Stephenson’s excellent book <a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1222262354&amp;sr=1-1">Cryptonomicon</a> for a description of how a talented adversary might “see” your keystrokes and screen images through a motel room wall, for example.</p>

<p>If one of your employees – such as a key scientist, project manager, or executive – is targeted for surveillance and is carrying sensitive data through certain countries, one could argue that he or she had better undergo serious counter-intelligence training.&nbsp; Learn to spot and shake tails, sneak into dark alleys for that BlackBerry fix. Learn to paper the closet with layers of aluminum foil and send messages in the dark. Defend that BlackBerry with encryption, long passphrases, and kung fu. But unless James Bond is running your company, I doubt this is what your executives have in mind for the next business trip!</p>

<p>Assuming your organization’s lower level employees are like needles in a haystack and won’t be bothered could be an exercise in wishful thinking. It is always possible that nation states are monitoring some or all of the airwaves. Not so long ago the NSA had a massive a covert surveillance program in place. Years before the government was reportedly snarfing up terabytes of emails and crunching them through a program called Carnivore. And of course, selective monitoring of people on watch lists continues on a large scale. This is just the surveillance we know about in the U.S. We suspect there’s more behind the scenes and especially in countries such as China. Even if you train your non-specifically-targeted low level employees to write and speak in search-keyword-free code, the carnivore programs of the world are pretty good at sniffing out those interesting needles – such as descriptions of your business plans, manufacturing processes, and trade secrets.</p>

<p>Sound paranoid? I admit that I don’t know what the probabilities of being targeted or monitored are – just that it can happen. It’s the height of arrogance to believe that a nation state can’t get your information if they’ve targeted it and you’re within their borders. And it’s dangerous to rely on security by obscurity when medium or high consequence information must be protected.</p>

<p>What can be done? If key personnel can't dispense with the BlackBerry (or any other email device) during international travel to those countries where information may be most at risk, they (the users) should limit communications to what they’d feel comfortable uttering over a potentially-monitored telephone call. Controlling incoming communications – messages sent by others – is a harder problem. Until data loss prevention (DLP) products become more contextually sensitive about the travel issues, it may be best not to synchronize the BlackBerry with the overseas user’s home mailbox. Instead, have the user give out a temporary address for the BlackBerry and warn senders to be discreet. </p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/402766223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry transport encryption">blackberry transport encryption</category>
      <category domain="http://securityratty.com/tag/transport encryption">transport encryption</category>
      <category domain="http://securityratty.com/tag/exemption">exemption</category>
      <category domain="http://securityratty.com/tag/blackberry exemption reasonable">blackberry exemption reasonable</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption features">disk encryption features</category>
      <category domain="http://securityratty.com/tag/blackberry fix">blackberry fix</category>
      <category domain="http://securityratty.com/tag/decrypt blackberry">decrypt blackberry</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/402766223/have-crackberry.html">Have CrackBerry, Will Travel</source>
    </item>
    <item>
      <title><![CDATA[XSF & XSS: Double your pleasure, double your fun]]></title>
      <link>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</link>
      <guid>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</guid>
      <description><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less...]]></description>
      <content:encoded><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less familiar with is <a href="http://www.xssed.com/news/26/Cross-site_framed/" target="_blank">cross-site framing</a>, which largely couples the best of both above-mentioned vulnerabilities. <br />What then, if there's a cross-site framing vulnerability coupled with cross-site scripting in the content offered by the frame? All sorts of problems come to mind: phishing, malware, credential theft; all arguably twice removed from the attacker's source, tucked away in the context of two victim sites.<br />First, I'll discuss the original XSS issue that led to this finding.<br />Recently, I was investigating a flawed parameter in <a href="http://www.openhire.com/" target="_blank">Openhire</a>, a career posting vendor used by major companies like <a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?company_id=15635&version=1" target="_blank">Crate&Barrel</a>, Eileen Fisher, Enterprise, Benjamin Moore, Scottrade, and Getty Images.<br />Most of these sites simply link to the Openhire offering that hosts job postings on their behalf which, in turn, has been crafted to look like the referring site.<br />As an example, here's Scottrade's employment page hosted by Openhire.<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624</a></span><br /><br />Standard stuff, looks nicely like the Scottrade site, so everything's cool, right?<br />Wrong? What if someone hosting a service on your behalf suffers a security gap?<br /><span style="font-weight:bold;">You're only as strong as your weakest link!</span><br />Here's the posting for an Application Security Engineer (funny, eh?) at Scottrade as hosted on their behalf by Openhire:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80</a></span><br /><br />Now here the same job posting spewing massive cookie data:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</a></span><br /><br />Screen shot offered below, as the code above will likely be repaired very soon by Openhire. I notified them this past Thursday.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s1600-h/Scottrade_Openhire.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s320/Scottrade_Openhire.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248697340769067154" /></a><br /><br />It's bad enough when there's an application security hole in code someone else is hosting on your behalf, but what if your method of displaying said code is also at risk? Enter the Getty Images Jobs page.<br /><br /><span style="font-style:italic;"><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778</a></span><br /><br />Watch what happens when you pull the Openhire code. Can you say self-replicating frame loop from hell (in Firefox)? Trust me your browser will crash if you leave this running too long. This will likely be fixed soon, so if the URL doesn't work, the screen shot exemplifies the issue.<br /><br /><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html</a><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s1600-h/GettyonGetty.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s320/GettyonGetty.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248710327339022210" /></a><br /><br />What if, instead of Openhire's Getty Images page, or nothing at all (which obviously creates its own issue), we drop in an arbitrary URL?<br />Yep, you guessed it.<br /><span style="font-style:italic;"><br />http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://www.xssed.com/news/26/Cross-site_framed/</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s1600-h/Getty_XSF.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s320/Getty_XSF.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248706395295990562" /></a><br /><br />Now, bringing it all home for double the pleasure, double the fun, what if we coupled the original Openhire cross-site scripting vuln with Getty Images cross-site frame vuln?<br /><br />It hurts twice as much, in my book.<br /><br /><span style="font-style:italic;">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s1600-h/Getty%2BScottrade.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s320/Getty%2BScottrade.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248708789483249346" /></a><br /><br />The lessons learned:<br />1) Ensure your partners are writing secure code on you behalf.<br />2) Ensure that the code you utilize to incorporate said partner's code is also well written. ;-)<br /><br />Double the headache, double the dumb.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html&title=XSF%20&%20XSS:%20Double%20your%20pleasure,%20double%20your%20fun " title="XSF & XSS: Double your pleasure, double your fun ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html" title="XSF & XSS: Double your pleasure, double your fun ">digg</a>]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 17:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/openhire code">openhire code</category>
      <category domain="http://securityratty.com/tag/openhire">openhire</category>
      <category domain="http://securityratty.com/tag/original openhire cross-site">original openhire cross-site</category>
      <category domain="http://securityratty.com/tag/scottrade site">scottrade site</category>
      <category domain="http://securityratty.com/tag/scottrade">scottrade</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/secure code">secure code</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html">XSF &amp; XSS: Double your pleasure, double your fun</source>
    </item>
    <item>
      <title><![CDATA[Fraud Detection in Financial Services Reloaded]]></title>
      <link>http://securityratty.com/article/ded3c6e73beb9af7e3aaa5abae657b06</link>
      <guid>http://securityratty.com/article/ded3c6e73beb9af7e3aaa5abae657b06</guid>
      <description><![CDATA[I read an interesting post bythe former CTO of out-of-business Kaskad Technology , where event processing colleague Colin Clark respectfully disagrees with my assesement of the (lack of) capabilitesin...]]></description>
      <content:encoded><![CDATA[<p>I read an <a href="http://colinclarkeventprocessing.com/?p=154" target="_blank">interesting post</a> by the former CTO of <a href="http://rulecore.com/CEPblog/?p=279" target="_blank">out-of-business Kaskad Technology</a>, where event processing colleague Colin Clark respectfully disagrees with my assesement of the (lack of) capabilites in current-generation &#8220;CEP engines&#8221; for detecting complex fraud in financial services.  I&#8217;ll respond with a quote from my September 2007 post,  <a title="End Users Should Define the CEP Market." rel="bookmark" href="http://www.thecepblog.com/2007/12/17/end-users-should-define-the-cep-market/"><span style="color: #105cb6;">End Users Should Define the CEP Market.</span></a></p>
<blockquote><p><em>&#8220;Experienced end users are very intelligent. </em></p>
<p><em>These end users know the complex event processing problems they need to solve; and they know the limitations of the current COTS approaches marketed by the CEP community.  Even in Thailand, a country many of you might mistakenly think is not very advanced technologically, there are experts in telecommunications (who run large networks) who are working on very difficult fraud detection applications, and they use neural networks and say the results are very good.   However, there is not one CEP vendor, that I know of, who offers true CEP capability in the form of neural nets. </em></p>
<p><em>Almost every major bank, telco, etc. has the same opinion, and the same problem. They need much more capability than streaming joins, selects and rules to solve their complex event processing problems that Dr. Luckham outlined in his book.   The software vendors are attempting to define the CEP market to match their capability; unfortunately, their capabilities do not meet the requirements of the vast majority of end users who have CEP problems to solve.</em></p>
<p><em>If the current CEP platforms were truely solving complex event processing problems, annual sales would be orders of magnitudes higher.  Hence, the users have already voted.   The problem is that the CEP community is not listening.&#8221;</em></p></blockquote>
<p>Not to be overly repetitive,  but the last part of this quote from a year ago is worth highlighting:</p>
<blockquote><p><em>&#8220;If the current CEP platforms were truely solving complex event processing problems, annual sales would be orders of magnitudes higher.  Hence, the users have already voted.   The problem is that the CEP community is not listening.&#8221;</em></p></blockquote>
<p>Frankly speaking, nothing in the &#8220;CEP world&#8221; has changed, technologically speaking, since this September 2007 post was written.  From a sales perspective, we have seen less CEP-related sales in 2008 than in prior years.   If these so called CEP products were actually capability of detecting &#8220;real&#8221; complex network-centric situations (threats) in real-time, they would be selling faster than a cup of ice water in the blazing hot Sahara desert.</p>
<p>Don&#8217;t shoot the messenger.  Build better detection engines!</p>
<p>On the other hand, maybe complex detection is too hard for most of these companies and that is why they focus on routing, mediation and relatively simple rule-based scenarios, versus complex event processing?</p>
]]></content:encoded>
      <pubDate>Sat, 20 Sep 2008 18:36:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/versus complex event">versus complex event</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep products">cep products</category>
      <category domain="http://securityratty.com/tag/cep community">cep community</category>
      <category domain="http://securityratty.com/tag/cep vendor">cep vendor</category>
      <category domain="http://securityratty.com/tag/current cep platforms">current cep platforms</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/sales">sales</category>
      <source url="http://www.thecepblog.com/2008/09/20/fraud-detection-in-financial-services-reloaded/">Fraud Detection in Financial Services Reloaded</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: Airport Pasta-Sauce Interdiction Considered Harmful]]></title>
      <link>http://securityratty.com/article/9b6db0f25f815641ea3655ef3cb29af5</link>
      <guid>http://securityratty.com/article/9b6db0f25f815641ea3655ef3cb29af5</guid>
      <description><![CDATA[Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been...]]></description>
      <content:encoded><![CDATA[<p>
Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been too dangerous. And to demonstrate how dangerous he really thought that jar was, he blithely tossed it in a nearby bin of similar liquid bottles and sent me on my way.
</p><p>
There are two classes of contraband at airport security checkpoints: the class that will get you in trouble if you try to bring it on an airplane, and the class that will cheerily be taken away from you if you try to bring it on an airplane. This difference is important: Making security screeners confiscate anything from that second class is a waste of time. All it does is harm innocents; it doesn't stop terrorists at all.
</p><p>
Let me explain. If you're caught at airport security with a bomb or a gun, the screeners aren't just going to take it away from you. They're going to call the police, and you're going to be stuck for a few hours answering a lot of awkward questions. You may be arrested, and you'll almost certainly miss your flight. At best, you're going to have a very unpleasant day.
</p><p>
This is why articles about how screeners don't catch <a href="http://www.cnn.com/2008/US/01/28/tsa.bombtest/index.html">every</a> -- or even <a href="http://www.homelandstupidity.us/2007/10/25/tsa-screeners-fail-most-bomb-tests/">a</a> <a href="http://www.homelandstupidity.us/2006/10/31/tsa-screeners-still-fail-to-find-guns-bombs/">majority</a> -- of guns and bombs that <a href="http://www.boston.com/news/local/articles/2003/10/16/logan_screeners_fail_weapons_tests/">go through the checkpoints</a> don't bother me. The screeners don't have to be perfect; they just have to be good enough. No terrorist is going to base his plot on getting a gun through airport security if there's decent chance of getting caught, because the consequences of getting caught are too great.
</p><p>
Contrast that with a terrorist plot that requires a 12-ounce bottle of liquid. There's no evidence that the London liquid bombers actually had a workable plot, but assume for the moment they did. If some copycat terrorists try to bring their liquid bomb through airport security and the screeners catch them -- like they caught me with my bottle of pasta sauce -- the terrorists can simply try again. They can try again and again. They can keep trying until they succeed. Because there are no consequences to trying and failing, the screeners have to be 100 percent effective. Even if they slip up one in a hundred times, the plot can succeed.
</p><p>
The same is true for knitting needles, pocketknives, scissors, corkscrews, cigarette lighters and whatever else the airport screeners are confiscating this week. If there's no consequence to getting caught with it, then confiscating it only hurts innocent people. At best, it mildly annoys the terrorists.
</p><p>
To fix this, airport security has to make a choice. If something is dangerous, treat it as dangerous and treat anyone who tries to bring it on as potentially dangerous. If it's not dangerous, then stop trying to keep it off airplanes. Trying to have it both ways just distracts the screeners from actually making us safer.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is chief security technology officer of BT. His new book is </cite>Schneier on Security<cite>.

</p><br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=aefd56c11b2eee64280f816001ed44dc"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=aefd56c11b2eee64280f816001ed44dc"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=aefd56c11b2eee64280f816001ed44dc" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=K4hTL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=K4hTL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gnANl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gnANl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7cfHl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7cfHl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lizGL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lizGL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=4j0mL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=4j0mL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=McKUl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=McKUl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=F517l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=F517l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=FIJtL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=FIJtL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/396484059" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/396484061" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 14:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security screeners">security screeners</category>
      <category domain="http://securityratty.com/tag/airport security checkpoints">airport security checkpoints</category>
      <category domain="http://securityratty.com/tag/checkpoints">checkpoints</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/liquid">liquid</category>
      <category domain="http://securityratty.com/tag/london liquid bombers">london liquid bombers</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/396484061/securitymatters_0918">Security Matters: Airport Pasta-Sauce Interdiction Considered Harmful</source>
    </item>
    <item>
      <title><![CDATA[Sarah Palins Yahoo Mailbox Compromised]]></title>
      <link>http://securityratty.com/article/ac59a9d84fd041913c53dc58fc6479a7</link>
      <guid>http://securityratty.com/article/ac59a9d84fd041913c53dc58fc6479a7</guid>
      <description><![CDATA[A group of individuals has compromised VP candidate Sarah Palins personal email and sent the information to Wikileaks which has posted the information publicly
http://wikileaks.org/wiki/Sarah Palin...]]></description>
      <content:encoded><![CDATA[<p>A group of individuals has compromised VP candidate Sarah Palin&#8217;s personal email and sent the information to Wikileaks which has posted the information publicly.</p>
<p><a href="http://wikileaks.org/wiki/Sarah_Palin_Yahoo_email_hack_2008">http://wikileaks.org/wiki/Sarah_Palin_Yahoo_email_hack_2008</a></p>
<blockquote><p>Circa midnight Tuesday the 16th of September (EST) Wikileaks&#8217; sources loosely affiliated with the activist group &#8216;anonymous&#8217; gained access to U.S. Republican Party Vice-presidential candidate Sarah Palin&#8217;s Yahoo email account <em>gov.palin@yahoo.com</em>. Governor Palin has come under criticism for using private email accounts to avoid government transparency mechanisms. The zip archive made available by Wikileaks contains screen shots of Palin&#8217;s inbox, example emails, address book and two family photos. The list of correspondence, together with the account name, appears to re-enforce the criticism.</p></blockquote>
<p>Internet security has finally become an issue in presidential politics.</p>
<p>Palin&#8217;s use of a Yahoo account has been the subject of <a href="http://seattletimes.nwsource.com/html/nationworld/2008180084_palinemail15.html">recent newspaper articles</a>.  The Washington Post <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/09/AR2008090903044.html">published her Yahoo email address</a>, which was likely a precursor to the attack.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 11:57:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wikileaks">wikileaks</category>
      <category domain="http://securityratty.com/tag/palins">palins</category>
      <category domain="http://securityratty.com/tag/wikileaks sources loosely">wikileaks sources loosely</category>
      <category domain="http://securityratty.com/tag/information publicly">information publicly</category>
      <category domain="http://securityratty.com/tag/palins inbox">palins inbox</category>
      <category domain="http://securityratty.com/tag/circa midnight tuesday">circa midnight tuesday</category>
      <category domain="http://securityratty.com/tag/yahoo account">yahoo account</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://www.veracode.com/blog/2008/09/sarah-palins-yahoo-mailbox-compromised/">Sarah Palins Yahoo Mailbox Compromised</source>
    </item>
    <item>
      <title><![CDATA[The Importance of Trust]]></title>
      <link>http://securityratty.com/article/a237a38c2b93a16a5d0702327c562838</link>
      <guid>http://securityratty.com/article/a237a38c2b93a16a5d0702327c562838</guid>
      <description><![CDATA[As an instructor and trainer, I am constantly reinforcing the importance of living by one's word

Integrity, Honor, Loyalty - all of these fine characteristics are the building blocks upon which...]]></description>
      <content:encoded><![CDATA[As an instructor and trainer, I am constantly reinforcing the importance of living by one's word.  <br /><span id="fullpost"><br />Integrity, Honor, Loyalty - all of these fine characteristics are the building blocks upon which reputations are raised.  It is of the utmost importance in any walk of life to "live by your word", but in the security profession - especially where the protecting of life is concerned, it is everything. <br /></span><br />I attended National Stadium last night and watched the Washington Nationals beat the New York Mets.  I was fortunate to have been invited to enjoy the game from the president's box.  During the pre-dinner networking, I ran into a business owner whom I had met a few years previously.  He had been introduced to me at that time as his business involved him being around some area celebrity sporting stars.<br /><br />Being interested in a chance to possibly offer executive protection services to these stars, I arranged to meet with this business owner to discuss how we might be able to assist one another.  I remember it was during the winter and the roads were a little suspect in places as I drove the 25-30 miles to be closer to his location.  <br /><br />I arrived a little early, as is my custom and waited for him to arrive.  It became clear after about an hour that he was experiencing some difficulty or had some other reason for being so late.  I left a few voice mails and called it quits after around 90 minutes.  He never returned any of my calls but when I reached him about a week later he admitted that something else had come up.  Unfortunately, he did not think it worth his while to let me know this with a phone call.<br /><br />So, here I am last night and this same person is introduced to me once again.  Maybe he didn't remember back three years ago because he started to tell me about some connection that he knew that may be a "good fit" for my company.  His small talk fell on deaf ears.  He had already lost all credibility with me and eventhough I have not thought about it once in the inetrvening years, as soon as I saw him it came back as clear as day.<br /><br />In his book; "The Speed of Trust", the author Stephen M.R. Covey sums it up best - "keeping commitments is based on the principles of integrity, performance, courage and humility.  It is the perfect balance of character and competence. Particularly, it involves integrity (character) and your ability to do what you say you are going to do (competence)."<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 15:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/importance">importance</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business owner">business owner</category>
      <category domain="http://securityratty.com/tag/integrity">integrity</category>
      <category domain="http://securityratty.com/tag/involves integrity">involves integrity</category>
      <category domain="http://securityratty.com/tag/utmost importance">utmost importance</category>
      <category domain="http://securityratty.com/tag/competence">competence</category>
      <category domain="http://securityratty.com/tag/security profession">security profession</category>
      <category domain="http://securityratty.com/tag/deaf ears">deaf ears</category>
      <source url="http://www.thebulletproofblog.com/2008/09/importance-of-trust.html">The Importance of Trust</source>
    </item>
    <item>
      <title><![CDATA[Security and Usability]]></title>
      <link>http://securityratty.com/article/3a16ecbcde196b667a2b0e6a1e503627</link>
      <guid>http://securityratty.com/article/3a16ecbcde196b667a2b0e6a1e503627</guid>
      <description><![CDATA[My copy arrived this morning and I have only managed a 15 minute glance but its rare a book that is so on topic appears that I had to post. Its not what I expected. Each chapter is authored by a small...]]></description>
      <content:encoded><![CDATA[My copy arrived this morning and I have only managed a 15 minute glance but it&#8217;s rare a book that is so &#8220;on topic&#8221; appears that I had to post. It&#8217;s not what I expected. Each chapter is authored by a small team and it looks like overall it has a varied writing style and [...]]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 06:49:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/topic appears">topic appears</category>
      <category domain="http://securityratty.com/tag/minute glance">minute glance</category>
      <category domain="http://securityratty.com/tag/style">style</category>
      <category domain="http://securityratty.com/tag/chapter">chapter</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/rare">rare</category>
      <category domain="http://securityratty.com/tag/copy">copy</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <source url="http://securitybuddha.com/2008/09/16/security-and-usability/">Security and Usability</source>
    </item>
    <item>
      <title><![CDATA[Live Blogging from GOVCERT.NL 2008 - David Rice Speaking]]></title>
      <link>http://securityratty.com/article/b812655ba5e022590908c261f54a40e8</link>
      <guid>http://securityratty.com/article/b812655ba5e022590908c261f54a40e8</guid>
      <description><![CDATA[So, David Rice of &quot;Geekonomics&quot; fame is speaking; the content is pretty much the same as the book, but he sure can speak! :-) [see my review of the book here

The message is the same: cybercrime is...]]></description>
      <content:encoded><![CDATA[So, <a href="http://www.geekonomicsbook.com/">David Rice of "Geekonomics" fame</a> is speaking; the content is pretty much the same as the book, but he sure can speak! :-)  [see my review of the book <a href="http://chuvakin.blogspot.com/2008/06/it-changed-my-life-my-review-of.html">here</a>]<br /><br />The message is the same: cybercrime is due to bad software; market motivates people to create bad software ("don't worry - be crappy" idea); market will fail to create secure software, etc.<br /><br />Result? The <span style="font-style: italic;">0wned world.<br /><br /></span>So, how to you make insecure software MORE expensive to create than secure software? Laws? Insurance? What else will help? Only time will tell...<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MhPzL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MhPzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=7FZvL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=7FZvL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=UXbvL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=UXbvL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/394005708" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/david rice">david rice</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/bad software">bad software</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/insecure software">insecure software</category>
      <category domain="http://securityratty.com/tag/0wned world">0wned world</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/review">review</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/394005708/live-blogging-from-govcertnl-2008-david.html">Live Blogging from GOVCERT.NL 2008 - David Rice Speaking</source>
    </item>
  </channel>
</rss>
