<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: canada]]></title>
    <link>http://securityratty.com/tag/canada</link>
    <description></description>
    <pubDate>Sat, 12 Jul 2008 10:49:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Memo to the President]]></title>
      <link>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</link>
      <guid>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>Obama has a cyber security plan.</p>

<p>It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.</p>

<p>I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.</p>

<p>One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p></p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.schneier.com/blog/archives/2008/05/dualuse_technol_1.html">use it, too</a>.

<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> <a href="http://www.schneier.com/essay-025.html">software</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.schneier.com/essay-116.html">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  </p>

<p>Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  </p>

<p>Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.</p>

<p>If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.</p>

<p>Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> immensely in the long run.</p>

<p>Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.</p>

<p>Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.</p>

<p>And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/08/securitymatters_0807">originally appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LZGCXK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LZGCXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=56vyIK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=56vyIK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/memo_to_the_pre.html">Memo to the President</source>
    </item>
    <item>
      <title><![CDATA[Starbucks Canada Frees Wi-Fi in Its Stores]]></title>
      <link>http://securityratty.com/article/9e0592f1bfaf004a664f648ddd3a1c24</link>
      <guid>http://securityratty.com/article/9e0592f1bfaf004a664f648ddd3a1c24</guid>
      <description><![CDATA[The Canadian branch of the coffee giant has secured a free Wi-Fi deal for customers: Just as Starbucks American stores are offering limited but free Wi-Fi in about 8,000 stores for its customers...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.newswire.ca/en/releases/archive/August2008/08/c2573.html"><strong>The Canadian branch of the coffee giant has secured a free Wi-Fi deal for customers:</strong></a> Just as Starbucks American stores are offering limited but free Wi-Fi in about 8,000 stores for its customers through a partnership with provider AT&T, Starbucks's northern brethren are opening its 650 company-operated locations that have Bell hotspots to free use by customers. Terms appear the same as in the states: 2 hours of free use per day with the regular use of a Starbucks Card.</p>

<p>And, as with the AT&T deal, Bell's Internet customers get unlimited access in Starbucks's stores. The deal starts up immediately, as Bell is the current operator. AT&T is transitioning to running Starbucks in the U.S., taking over by the end of 2008 from T-Mobile.<br />
</p>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/starbucks">starbucks</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/stores">stores</category>
      <category domain="http://securityratty.com/tag/starbucks card">starbucks card</category>
      <category domain="http://securityratty.com/tag/starbucks american stores">starbucks american stores</category>
      <category domain="http://securityratty.com/tag/free wi-fi deal">free wi-fi deal</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/internet customers">internet customers</category>
      <source url="http://wifinetnews.com/archives/008414.html">Starbucks Canada Frees Wi-Fi in Its Stores</source>
    </item>
    <item>
      <title><![CDATA[Email Hacking Going Commercial - Part Two]]></title>
      <link>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</link>
      <guid>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</guid>
      <description><![CDATA[Malware authors seeking financial gains from releasing their trojans often promote them as Remote Access Tools , which if we exclude the built-in anti-sandboxing and antivirus software killing...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/No0eDRtdb8s/s1600-h/hire_to_hack.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/BK1B_uN_Iew/s200-R/hire_to_hack.png" style="border: 0pt none ;" /></a>Malware authors seeking financial gains from releasing their trojans often promote them as <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Remote Access Tools</a>, which if we exclude the built-in anti-sandboxing and antivirus software killing capabilities, <a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html">could pass for a RAT</a>. In a similar deceptive fashion, <a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">email hacking services are pitched as email password recovery services</a>. <br />
<br />
Hacking as a Service sites seems to be popping out like mushrooms these days, thanks primarily due to the fact that yesterday's script kiddies are today's entrepreneurs trying to even monetize the process of bruteforcing. Here's their pitch :<br />
<br />
"<i>Well.. There is nothing different in our       services. Like other group, we simply crack email addresses       , and provide you the current password used by the victim to       you for a suitable price. Nothing unique that we can brag       about....&nbsp; We don't hack NASA or CIA , we cannot hack a       bank and steal a million dollars.. We just crack email       password .. AND WE DO A HECK OF A JOB IN IT !! We cannot be as presentable as the other       groups, trying to look as formal and corporate, as if they       are running a Major Corporate Office. However they present       it...password retrieval, online investigation.. access       recovery...blah blah blah..&nbsp; the most simplest way to       put it is.. : Email Password Cracking: !! And since everyone else is busy faking       it, or trying to be more presentable, we utilize our skills       to get you what you want.. i.e. THE EMAIL PASSWORD. No       buttering up, no marketing skills..&nbsp; plain hardcore       hacking !! So, since you now know what we do , and       want us to do the job for you, please proceed to the order       page for your relevant TARGET EMAIL and submit your request.       All said and done, we will get the elusive password &amp; send       you a couple of proofs. You decide upon the authenticity of       the proofs, and let us know if you are comfortable going       ahead with the payment. PAY US, AND YOU GET THE PASSWORD !And as they say.......</i>"<br />
<br />
How much are they charging for the bruteforcing? $150 for starters, which is prone to increase due to their bla bla bla about how sophisticated it was to obtain the password - given they actually manage to deliver the goods :&nbsp; <br />
<br />
<div class="separator" style="text-align: center; clear: both;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/aVdgDf7K46o/s1600-h/hire_to_hack1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/wsy8qQ3XtGQ/s200-R/hire_to_hack1.png" style="border: 0pt none ;" width="200" /></a></div>"<i>Many groups charge a fixed price for an email cracking. We undertake more kinds of projects than anyone else. Frankly, each email is a different project in itself. We cannot charge you $100, for something which we can do for $50. Subsequently, we cannot charge you $100, for something which should be priced at $200. But we charge a minimum of $150 USD so that we end up taking orders from ONLY those who really need it. It is a small amount for the level of satisfaction, facts/truth and relief that you would ultimately achieve from this.It depends upon the nature of the job, the accessibility factor. and many other reasons likes:-<br />
<br />
1- The email service provider<br />
2- The target itself. How net-savvy he/she is.<br />
3- Complexity of the password<br />
4- Urgency of job and many other things collectively.<br />
<br />
We will let you know our charges once we have the desired results only. Be assured, we wont charge you the moon. We charge only what we deserve, and is acceptable by you. Trust us !!</i>"<br />
<br />
Some of their answers to the frequently asked questions :<br />
<br />
" <i>- <b>Who are you? Where are you from</b>?<br />
We are Hire2Hack Group. Member of our group are students in information technology, at some university in England, France, Italy, Japan, Australia, Canada, Brasilia and at United States of America.<br />
<br />
- <b>What services do you provide?</b><br />
We can hack ANY EMAIL password for you very fast, reliable, secure and worldwide for a suitable price.<br />
<br />
- <b>Can you really hack password or just a making a shit scam?</b><br />
Well, lot of people, lot of groups, companies do this service, but not guaranteed. This is only you can choose which group you want to Order. Be careful with these people. You can believe only on them who claims to provide proof before you really pay them.<br />
<br />
- <b>Is there any tool available to crack password?</b><br />
Yes there is. And we are not giving it to you.<br />
<br />
- <b>How long does it takes to crack a password?</b><br />
Each account is different and hacking time vary. On average, it might take about 1 to 3 days, but it may take anywhere from 24 hours to 30 days or more depending on how difficult is the hacking of each account.<br />
<br />
- <b>How can I believe you, that you got password?</b><br />
We will provide you some good proofs before requesting you to pay us. The proof can be anything, you can decide what kind proof you need.<br />
<br />
- <b>Is there person will know that his/her email id has been cracked?</b><br />
No, we provide you only the original password. That mean the current active password. Your victim/target will not realized that she/he has been hacked. NEVER, we said !<br />
<br />
- <b>How I will pay you, I do not have credit card or I do not want to give my credit card number on net?</b><br />
Well, you can use international money transfer service such as Western Union (www.westernunion.com) or Money Gram (www.moneygram.com). These services immediate transfer money on same day or same hour. You can locate their agents in yours area from their website.<br />
<br />
- <b>Do I have to give you my password?</b><br />
No. Any service which requires your password is simply trying to scam you out of access to your account.<br />
<br />
- <b>How will I know you really have the password?</b><br />
We will show you the proofs.. which are mostly convincing.<br />
<br />
- <b>Since you have the password anyway, will you give it to me?</b><br />
NO. Do not waste your time or ours. We will not release the password until full payment is made - no exceptions. We have had people request our service and once we recover the password, they reset the subject account then ask us for the original password so they can reset it back - the answer will be no. We have also had people ask if they could have the password since we've already recovered it and they cannot pay - the answer will be no. No password will be released until payment has been made in full - no exceptions.<br />
<br />
- <b>Will you recover more than one password? Can I request more than one email account?</b><br />
Yes, but a separate request must be filled out for each one as you will only be billed for each successful recovery. If we have previously recovered a password for you and you have not paid, we will not begin any new request for you until your previous request is paid in full with exceptions for our established clientele. We charge at minimum US $100 for each account hacked.<br />
<br />
- <b>Do you reset or change the current password?</b><br />
No. We do not try to guess the current password or the secret question's answer, we do not change their password. We give you only the Original password, which the victim is currently using.<br />
<br />
- <b>Is this confidential? Do you share my information with anyone else</b>?<br />
No, Not at all, Not in any case, its a trust between you and us. Your information will be respected as long as you abide by our Terms and Conditions and Privacy policy. We keep your personal records and requests confidential in our database but we respect your right to privacy and will not rent, share, sell, or trade any personal information unless required by law. <b>But, if you engage in any spamming or fraudulent actives, Your information will be given to the appropriate authorities.</b></i>"<br />
<br />
So you've got script kiddies cracking email addresses and probably engaging in the rest of the usual cybercrime activities, who are spam sensitive, and would expose their customers if they start spamming from the cracked emails? Now that's socially responsible, isn't it.<br />
<br />
Targeted attacks are sexy, but bruteforcing email accounts no matter the number of proxies and wordlists that they have access to is so irrelevant, that social engineering a potential victim into infecting herself with malware through a live exploit URL seems to be the method of choice, next to a plain simple phishing email of course. In this case, what they're asking for in respect to the victim's details is the victim's country and victim's language, so that a localized social engineering or phishing attack can take place. However, this particular group seems to be using a standard bruteforcing tool.<br />
<br />
One thing's for sure - cybercrime is getting easier to outsource, and with potential customers starting to have access to services they didn't a couple of years ago, <a href="http://ddanchev.blogspot.com/2008/08/phishers-backdooring-phishing-pages-to.html">fake scammers are also emerging in between the real ones</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q4SazK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q4SazK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=v68SQK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=v68SQK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fTxCfk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fTxCfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m5GSCk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m5GSCk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rFpJlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rFpJlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hDloOK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hDloOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kzNwqk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kzNwqk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/359698182" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:31:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crack password">crack password</category>
      <category domain="http://securityratty.com/tag/crack">crack</category>
      <category domain="http://securityratty.com/tag/crack email password">crack email password</category>
      <category domain="http://securityratty.com/tag/email password">email password</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/original password">original password</category>
      <category domain="http://securityratty.com/tag/current password">current password</category>
      <category domain="http://securityratty.com/tag/password retrieval">password retrieval</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/359698182/email-hacking-going-commercial-part-two.html">Email Hacking Going Commercial - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Memo to Next President: How to Get Cyber Security Right]]></title>
      <link>http://securityratty.com/article/3cc71e9b8aab182bc3e96444e8660442</link>
      <guid>http://securityratty.com/article/3cc71e9b8aab182bc3e96444e8660442</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>
Obama has a cyber security plan.
</p><p>
It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.
</p><p>
I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.
</p><p>
One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/blog_securitymatters_0501 ">use it, too</a>.
</p>
<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> software <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.wired.com/politics/security/commentary/securitymatters/2006/06/71032">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  
</p><p>
Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  
</p><p>
Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> (.pdf) how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.
</p><p>
If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.
</p><p>
Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> (.pdf) immensely in the long run.
</p><p>
Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.
</p><p>
Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.
</p><p>
And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.

<p>
---
</p>

<p><em>Bruce Schneier is chief security technology officer of BT, and author of </em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=0ca9e7363b324d8d77996a8ec3f346da" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=0ca9e7363b324d8d77996a8ec3f346da" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=OUzpZK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=OUzpZK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jCsEfk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jCsEfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Xtv7Xk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Xtv7Xk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ZOA0EK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ZOA0EK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=bpRgSK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=bpRgSK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=3GI8fk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=3GI8fk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=tfYGEk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=tfYGEk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Ed9rWK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Ed9rWK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/358550437" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/358550481" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/358550481/securitymatters_0807">Memo to Next President: How to Get Cyber Security Right</source>
    </item>
    <item>
      <title><![CDATA[Random Killing on a Canadian Greyhound Bus]]></title>
      <link>http://securityratty.com/article/bc4696b6a26761ebc94ae2e2e488c3b0</link>
      <guid>http://securityratty.com/article/bc4696b6a26761ebc94ae2e2e488c3b0</guid>
      <description><![CDATA[After a random and horrific knife decapitation on a Greyhound bus last week
does this surprise anyone
A grisly slaying on a Greyhound bus has prompted calls for tighter security on Canadian bus lines,...]]></description>
      <content:encoded><![CDATA[<p>After a <a href="http://www.saskatoonhomepage.ca/index.php?option=com_content&task=view&id=13065&Itemid=374">random and horrific knife decapitation</a> on a Greyhound bus last week, <blockquote><br />
does <a href="http://www.cbc.ca/canada/story/2008/08/01/bus-slaying-security.html">this</a> surprise anyone:</p>

<p><bockquote>A grisly slaying on a Greyhound bus has prompted calls for tighter security on Canadian bus lines, despite the company and Canada's transport agency calling the stabbing death a tragic but isolated incident.</p>

<p>Greyhound spokeswoman Abby Wambaugh said bus travel is the safest mode of transportation, even though bus stations do not have metal detectors and other security measures used at airports.</blockquote></p>

<p>Despite editorials telling people <a href="http://lfpress.ca/newsstand/Opinion/Editorials/2008/08/02/6337056-sun.html">not to overreact</a>, it's <a href="http://thechronicleherald.ca/Canada/1070711.html">easy to</a>:</p>

<blockquote>"Hearing about this incident really worries me," said Donna Ryder, 56, who was waiting Thursday at the bus depot in Toronto.

<p>"I’m in a wheelchair and what would I be able to do to defend myself? Probably nothing. So that’s really scary."</p>

<p>Ryder, who was heading to Kitchener, Ont., said buses are essentially the only way she can get around the province, as her wheelchair won’t fit on Via Rail trains. As it is her main option for travel, a lack of security is troubling, she said.</p>

<p>"I guess we’re going to have to go the airline way, maybe have a search and baggage check, X-ray maybe," she said.</p>

<p>"Really, I don’t know what you can do about security anymore."</blockquote></p>

<p>Of course, airplane security <a href="http://www.sindark.com/2008/08/01/greyhound-bus-security/">won't work on busses</a>.</p>

<p>But -- more to the point -- <a href="http://www.schneier.com/blog/archives/2007/05/rare_risk_and_o_1.html">this essay</a> I wrote on overreacting to rare risks applies here:</p>

<blockquote>People tend to base risk analysis more on personal story than on data, despite the old joke that "the plural of anecdote is not data." If a friend gets mugged in a foreign country, that story is more likely to affect how safe you feel traveling to that country than abstract crime statistics. 

<p>We give storytellers we have a relationship with more credibility than strangers, and stories that are close to us more weight than stories from foreign lands. In other words, proximity of relationship affects our risk assessment. And who is everyone's major storyteller these days? Television.</blockquote></p>

<p>Which is why Canadians are talking about increasing security on long-haul busses, and not Americans.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GUhTfK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GUhTfK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=pwQX0K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=pwQX0K" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 02:19:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/tighter security">tighter security</category>
      <category domain="http://securityratty.com/tag/airplane security">airplane security</category>
      <category domain="http://securityratty.com/tag/greyhound bus">greyhound bus</category>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/security anymore">security anymore</category>
      <category domain="http://securityratty.com/tag/abstract crime statistics">abstract crime statistics</category>
      <category domain="http://securityratty.com/tag/travel">travel</category>
      <category domain="http://securityratty.com/tag/rare risks applies">rare risks applies</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/random_killing.html">Random Killing on a Canadian Greyhound Bus</source>
    </item>
    <item>
      <title><![CDATA[Do You Speak E-Discovery? You Should, Even in Europe]]></title>
      <link>http://securityratty.com/article/83b90f1f212111ff6dbba328b609d249</link>
      <guid>http://securityratty.com/article/83b90f1f212111ff6dbba328b609d249</guid>
      <description><![CDATA[How often have you watched the news on television and seen people carrying boxes full of electronic media and digital files out of some well-known company's headquarters? It's a familiar scene in the...]]></description>
      <content:encoded><![CDATA[How often have you watched the news on television and seen people carrying boxes full of electronic media and digital files out of some well-known company's headquarters? It's a familiar scene in the United States, because of the number of companies subject to e-discovery actions. But even though this subject is disturbing the sleep of CIOs in companies large and small in the U.S. - and even though vendors of tools supporting e-discovery are all looking for the next "killer app" - most Europeans just look on and say, "What on earth is this 'e-discovery'?"<br />
<br />
The concept of legal discovery (called "e-discovery" when electronic information is involved) is unique to the "common law" countries - notably the U.S., the U.K., Canada, Australia and New Zealand. Discovery in common-law civil litigation is a form of interrogatory in which both parties agree to the pretrial exchange of information, so that the plaintiff can prosecute a cause for action and the defendant can build a defense. By contrast, in countries with legal systems based on the Roman or Napoleonic traditions - which is to say, most of continental Europe - the obligation to produce information that is relevant to the cause for action is nowhere as comprehensive as the obligation attached to discovery in common law.<br />
<br />
There is an important difference between criminal and civil litigation, irrespective of a country's legal system. In a criminal case, if the authorities have a warrant or an indictment, the subject is obligated to produce relevant information, and this is true both in common-law countries and in continental Europe. In civil litigation, however, only common law requires the pretrial production of information and its exchange between affected parties. In non-common-law civil litigation, the relevant information is produced before the judge for consideration and evaluation.<br />
<br />
Despite these differences, there are some important lessons for all Europeans about e-discovery and about legal discovery in general. The first is that if an external party demands information, whether during civil or criminal proceedings, it pays to deliver that information quickly. Gartner has seen many cases where enterprises simply didn't know how to find the requested information or couldn't produce it for several days - just long enough to generate some damaging media coverage.<br />
<br />
The second lesson: It also pays to be able to deliver precisely the information requested. Law enforcement officers may seize folders and binders, disks and tapes, files and e-mails, reports and logs - anything they can get their hands on, really. This may include information that is not relevant to the case, and it may include information that is highly sensitive. This information will be reviewed, processed and analyzed, and some of this sensitive information might leak to the public or to competitors. It's much better to be prepared to hand over just the requested and required information.<br />
<br />
The e-discovery landscape is made even more confusing by international jurisdictional differences. In the global economy, a business relationship with an entity in the U.S. is becoming more the rule than the exception. But a company's duty to release information following a U.S. legal discovery claim - for example, for a European subsidiary - and how that would be seen in relation with European privacy legislation remain unclear at best. E-discovery rules require quick delivery of information that has not been tampered with, but privacy protection requires that personal data be removed first.<br />
<br />
E-discovery simply does not exist in most European legal systems, but European companies would be well-advised to familiarize themselves with the concept, in case an e-discovery claim originates elsewhere. Companies that have processes and automation for information archiving and retrieval, document and records management, and a retention policy (including disposal when information is no longer needed) will be well-prepared for any e-discovery claims that arise.]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 08:05:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-discovery">e-discovery</category>
      <category domain="http://securityratty.com/tag/e-discovery simply">e-discovery simply</category>
      <category domain="http://securityratty.com/tag/e-discovery actions">e-discovery actions</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/include information">include information</category>
      <category domain="http://securityratty.com/tag/discovery">discovery</category>
      <category domain="http://securityratty.com/tag/produce relevant information">produce relevant information</category>
      <category domain="http://securityratty.com/tag/e-discovery claims">e-discovery claims</category>
      <source url="http://blog.gartner.com/blog/security.php?x=0&amp;itemid=3732">Do You Speak E-Discovery? You Should, Even in Europe</source>
    </item>
    <item>
      <title><![CDATA[Cost/Benefit Analysis of Airline Security]]></title>
      <link>http://securityratty.com/article/033b2789311d93701b77cbecf63c9596</link>
      <guid>http://securityratty.com/article/033b2789311d93701b77cbecf63c9596</guid>
      <description><![CDATA[This report , &quot;Assessing the risks, costs and benefits of United States aviation security measures&quot; by Mark Stewart and John Mueller, is excellent reading: The United States Office of Management and...]]></description>
      <content:encoded><![CDATA[This <a href="http://hdl.handle.net/1959.13/28097">report</a>, "Assessing the risks, costs and benefits of United States aviation security measures" by Mark Stewart and John Mueller, is excellent reading:

<blockquote>The United States Office of Management and Budget has recommended the use of cost-benefit assessment for all proposed federal regulations. Since 9/11 government agencies in Australia, United States, Canada, Europe and elsewhere have devoted much effort and expenditure to attempt to ensure that a 9/11 type attack involving hijacked aircraft is not repeated. This effort has come at considerable cost, running in excess of US$6 billion per year for the United States Transportation Security Administration (TSA) alone. In particular, significant expenditure has been dedicated to two aviation security measures aimed at preventing terrorists from hijacking and crashing an aircraft into buildings and other infrastructure: (i) Hardened cockpit doors and (ii) Federal Air Marshal Service. These two security measures cost the United States government and the airlines nearly $1 billion per year. This paper seeks to discover whether aviation security measures are cost-effective by considering their effectiveness, their cost and expected lives saved as a result of such expenditure. An assessment of the Federal Air Marshal Service suggests that the annual cost is $180 million per life saved. This is greatly in excess of the regulatory safety goal of $1-$10 million per life saved. As such, the air marshal program would seem to fail a cost-benefit analysis. In addition, the opportunity cost of these expenditures is considerable, and it is highly likely that far more lives would have been saved if the money had been invested instead in a wide range of more cost-effective risk mitigation programs. On the other hand, hardening of cockpit doors has an annual cost of only $800,000 per life saved, showing that this is a cost-effective security measure.</blockquote>

From the body:

<blockquote>Hardening cockpit doors has the highest risk reduction (16.67%) at lowest additional cost of $40 million. On the other hand, the Federal Air Marshal Service costs $900 million pa but reduces risk by only 1.67%. The Federal Air Marshal Service may be more cost-effective if it is able to show extra benefit over the cheaper measure of hardening cockpit doors. However, the Federal Air Marshal Service seems to have significantly less benefit which means that hardening cockpit doors is the more cost-effective measure.</blockquote>

Cost-benefit analysis is definitely the way to look at these security measures.  It's hard for people to do, because it requires putting a dollar value on a human life -- something we can't possibly do with our own.  But as a society, it is something we do again and again: when we raise or lower speed limits, when we ban a certain pesticide, when we enact building codes.  Insurance companies do it all the time.  We do it implicitly, because we can't talk about it explicitly.  I think there is considerable value in talking about it.

(Note the table on page 5 of the report, which lists the cost per lives saved for a variety of safety and security measures.)

The final paper will eventually be published in the <i>Journal of Transportation Security</i>.  I never even knew there was such a thing.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=x80u9J"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=x80u9J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=UrhygJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=UrhygJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 01:53:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cost-effective">cost-effective</category>
      <category domain="http://securityratty.com/tag/cost-effective security measure">cost-effective security measure</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/cost-effective measure">cost-effective measure</category>
      <category domain="http://securityratty.com/tag/opportunity cost">opportunity cost</category>
      <category domain="http://securityratty.com/tag/cost-benefit analysis">cost-benefit analysis</category>
      <category domain="http://securityratty.com/tag/additional cost">additional cost</category>
      <category domain="http://securityratty.com/tag/cost-benefit assessment">cost-benefit assessment</category>
      <category domain="http://securityratty.com/tag/benefit">benefit</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/costbenefit_ana.html">Cost/Benefit Analysis of Airline Security</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</link>
      <guid>http://securityratty.com/article/90bb58ffbec02539c2d62e825dbe8146</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 13:20:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://www.blueboxpodcast.com/2008/07/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...]]></title>
      <link>http://securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</link>
      <guid>http://securityratty.com/article/f67dc99a7a07715d84135662a2d7276b</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 17, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-080-2008-04-17.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance &#8211; getting it organized now</li><br />
		<li><a href="http://www.tmcnet.com/webinar/ingate-systems/">Ingate <span class="caps">SIP </span>Trunking webinar now available</a> (and a note about participating in things like this)</li><br />
		<li><a href="http://voipsa.org/blog/2008/04/08/this-blog-site-was-hacked-how-it-was-done-and-why-you-need-to-upgrade-wordpress-now/">VOIPSA blog site hacked</a></li></p>

<p><li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/14/quarterly-voip-vulnerabilities-summary/">Quarterly VoIP Vulnerabilities Summary</a></li><br />
<li>VoIPshield <a href="http://www.voipshield.com/research">list of vulnerabilities</a></li><br />
		<li><a href="http://tools.cisco.com/security/center/viewAlert.x?alertId=15565">Cisco Advisory</a></li><br />
		<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml">Cisco Advisory about Disaster Recovery Framework</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/02/voipshield-announces-discovery-of-over-100-vulnerabilities-in-cisco-avaya-nortel-voip-systems/">VoIPshield announces discovery of over 100 vulnerabilities</a> along with a <a href="http://voipsa.org/blog/2008/04/03/voip-security-youtube-videos-voipshields-voip-hacker-video/">YouTube video</a></li><br />
<li><a href="http://advice.cio.com/al_sacco/voip_security_warning_a_hundred_flaws_in_three_leading_products">CIO</a></li><br />
		<li>Washington Post: <a href="http://blog.washingtonpost.com/securityfix/2008/04/reach_out_and_hack_someone.html?nav=rss_blog">Reach Out And Hack Someone</a></li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/gnucitizen-research-discovery-default-key-algorithm-in-thomson-and-bt-home-hub-routers/">GNUcitizen research discovery: Default key algorithm in Thomson and <span class="caps">BT </span>Home Hub routers</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-security-033108/">The Essential Guide to VoIP Security</a></li><br />
<li>Information Week: <a href="http://www.informationweek.com/blog/main/archives/2008/04/securing_voip_w.html">Securing VoIP with SecureLogix</a> &#8211; includes YouTube video with Mark Collier</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/04/hackers-attack-international-space-station-email-lets-hope-voip-isnt-next/">VoIP and the International Space Station</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/16/xplico-network-forensic-analysis-tool/">Xplico Network Forensic Analysis Tool</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/17/australians-falling-victim-to-foreign-phone-hackers/">Australians falling victim to foreign phone hackers</a></li><br />
		<li>VoIP News Australia: <a href="http://www.voipnews.com.au/content/view/1747/159/">How <span class="caps">ACMA </span>Plans to Regulate VoIP</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/community/node/26992">Government agencies rejecting VoIP?</a></li><br />
	<br />
<li><a href="http://www.lpi.org/en/lpi/english/about_lpi/news/news/lpi_to_develop_enterprise_level_security_exam">Linux Professional Institute to develop enterprise-level security exam</a></li><br />
		<li><a href="http://www.cbc.ca/technology/story/2008/04/02/tech-bell.html">Net neutrality and Bell Canada</a></li><br />
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=1024">Attacks escalate on critical U.S. government networks: Will a Manhattan Project work?</a></li><br />
		<li><a href="http://xs-sniper.com/blog/2008/04/14/google-xss/">Google <span class="caps">XSS </span>Attack</a> (interesting as it shows the complexity of such attacks)</li></p>

<p><li>The Economist: <a href="http://www.economist.com/specialreports/displaystory.cfm?story_id=10950394">Special Report: The New Nomadism</a></li><br />
<li><a href="http://voipsa.org/blog/2008/04/10/voice-biometrics-conference-may-14-15-2008/">VoiceBiometrics</a> &#8211; May 14-15, New York</li><br />
		<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>44:22 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=fNSqdO"><img src="http://feeds.feedburner.com/~a/BlueBox?i=fNSqdO" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=lbjc2J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lbjc2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=7bk2TJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7bk2TJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=3wwMDJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=3wwMDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=sD0qZJ"><img src="http://feeds.feedburner.com/~f/BlueBox?i=sD0qZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Y7dDJj"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Y7dDJj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uKgX6J"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uKgX6J" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/336458984" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 12:22:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip news australia">voip news australia</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/voipsa blog site">voipsa blog site</category>
      <category domain="http://securityratty.com/tag/voipsa">voipsa</category>
      <category domain="http://securityratty.com/tag/voipshield vulnerabilities">voipshield vulnerabilities</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/336458984/blue-box-80-voi.html">Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</source>
    </item>
    <item>
      <title><![CDATA[Young Canadian Model Murdered in Shanghai.]]></title>
      <link>http://securityratty.com/article/5f5db7658c71a70694e1d8076bdf2a7c</link>
      <guid>http://securityratty.com/article/5f5db7658c71a70694e1d8076bdf2a7c</guid>
      <description><![CDATA[This is a very sad story . It needs to get out so other young girls and their parents can learn from this tragedy

I traveled to China last year on a two week business trip. One of the thoughts that...]]></description>
      <content:encoded><![CDATA[This is a very <a href="http://www.msnbc.msn.com/id/25642790/">sad story</a>.  It needs to get out so other young girls and their parents can learn from this tragedy.<br /><span id="fullpost"><br />I traveled to China last year on a two week business trip. One of the thoughts that struck me was that it appeared to be a very law abiding society.  Then when I visited Tiananmen Square, I was reminded of the scene when Government tanks turned on young student protestors and masacared them.  There is much about China that lays beneath the surface.<br /><br />Diana O'Brien was a young model from Canada who was lured to China with promises of "catwalk" modelling opportunities.  Once she arrived there, the opportunities became offers to dance in bars.  Apparently, many young girls go to China thinking they are breaking into the big time when in reality, many of these modelling agencies inlvolve little more than an apartment and a cell phone.<br /><br />The JH model managment company that Diana worked for disappeared when news of her murder broke.  Their website was taken down on Thursday.  Although an official from the State Security Bureau would not comment, her murder seems to have been committed by a street criminal who stabbed her to death near her apartment for her belongings.  <br /><br />Young women and the parents of young women, need to know what they are getting themselves into before they travel to a strange place and put their lives in the hands of people who see them merely as a way to make money.  This coming in the wake of the summer Olympics might cause some to question their own saftey in Beijing.  Some of the age old principles still hold true; Beaware of your surroundings, Never travel alone - always have at least one companion at all times, Always let people know where you are going, Carry a cell phone (and pepper spray it is is allowed)to enable you to call for help.<br /><br />In the streets of Beijing and Shanghai, people will approach you all of the time trying to get you to buy; fake watches, perfume, stamps and many other things.  Most of these people are legitimately trying to make a sale but you do not know who are the ones that may be trying to pick-pocket you or surround you to rob you or lure you off a busy street where you won't be seen so easily.  Walk briskly past them and ignore them.  You should shop whee you are not being hassled and therfore can concentrate on your safety.            <br /><br /></span><em></em><div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 12 Jul 2008 10:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/model managment company">model managment company</category>
      <category domain="http://securityratty.com/tag/week business trip">week business trip</category>
      <category domain="http://securityratty.com/tag/walk briskly past">walk briskly past</category>
      <category domain="http://securityratty.com/tag/hold true">hold true</category>
      <category domain="http://securityratty.com/tag/travel">travel</category>
      <source url="http://www.thebulletproofblog.com/2008/07/young-canadian-model-murdered-in.html">Young Canadian Model Murdered in Shanghai.</source>
    </item>
  </channel>
</rss>
