<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: child]]></title>
    <link>http://securityratty.com/tag/child</link>
    <description></description>
    <pubDate>Wed, 18 Jun 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Gonzo: Two Thumbs In and Up]]></title>
      <link>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</link>
      <guid>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</guid>
      <description><![CDATA[Just saw the Hunter S. Thompson movie - Gonzo , and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Hunter_S._Thompson"></a><a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-pi"><img  class="at-xid-6a00d83451c75869e200e553c045c48834 " alt="180px-Gonzo_citation" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-320wi" style="margin: 0px 5px 5px 0px;"></a> Just saw the Hunter S. Thompson movie - <a href="http://www.rottentomatoes.com/m/gonzo_the_life_and_work_of_dr_hunter_s_thompson/">Gonzo</a>, and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view of the high highs and the low lows. Weaves in writing, politics, and fame seamlessly.

I have never really had as much fun as early on in my career in the early-mid 90s I was a web programmer in Aspen, hacking CGI/PERL. Among the most fun things was building and running HST's site. My boss, Ed, was his neighbor. Ed was also seriously allergic to bees. One day he was alone in his house and got stung. He was dying. Luckily Hunter was due over to his house to watch a basketball game, walked in and called 911. My boss woke up in the ambulance with Hunter pounding on him chest and screaming at him. Ed said - "Waking up to that face screaming at me, I didn't know if I was alive or dead."

Seeing the movie it was also great to see a lot of the Woody Creek folks again like George Stranahan, who lovingly said about Hunter - "my friend and neighbor who never paid his rent, broke up my marriage and taught my children to smoke dope. "

Of course, there was no way he could match his early productivity and this is true of almost all artists. Most of the last two decades were wasted from a writing standpoint. However his <a href="http://proxy.espn.go.com/espn/page2/story?id=1250751">piece</a> written on 9/11 is as good as its gets:

</p><blockquote><p>
	The towers are gone now, reduced to bloody rubble, along with all hopes for Peace in Our Time, in the United States or any other country. Make no mistake about it: We are At War now -- with somebody -- and we will stay At War with that mysterious Enemy for the rest of our lives. 	
	</p></blockquote><blockquote><p>It will be a Religious War, a sort of Christian Jihad, fueled by religious hatred and led by merciless fanatics on both sides. It will be guerilla warfare on a global scale, with no front lines and no identifiable enemy. Osama bin Laden may be a primitive "figurehead" -- or even dead, for all we know -- but whoever put those All-American jet planes loaded with All-American fuel into the Twin Towers and the Pentagon did it with chilling precision and accuracy. The second one was a dead-on bullseye. Straight into the middle of the skyscraper. 	
	</p></blockquote><blockquote><p>Nothing -- even George Bush's $350 billion "Star Wars" missile defense system -- could have prevented Tuesday's attack, and it cost next to nothing to pull off. Fewer than 20 unarmed Suicide soldiers from some apparently primitive country somewhere on the other side of the world took out the World Trade Center and half the Pentagon with three quick and costless strikes on one day. The efficiency of it was terrifying. 	
	</p></blockquote><blockquote><p>We are going to punish somebody for this attack, but just who or what will be blown to smithereens for it is hard to say. Maybe Afghanistan, maybe Pakistan or Iraq, or possibly all three at once. Who knows? Not even the Generals in what remains of the Pentagon or the New York papers calling for WAR seem to know who did it or where to look for them. 	
	</p></blockquote><blockquote><p>This is going to be a very expensive war, and Victory is not guaranteed -- for anyone, and certainly not for anyone as baffled as George W. Bush. All he knows is that his father started the war a long time ago, and that he, the goofy child-President, has been chosen by Fate and the global Oil industry to finish it Now. He will declare a National Security Emergency and clamp down Hard on Everybody, no matter where they live or why. If the guilty won't hold up their hands and confess, he and the Generals will ferret them out by force. 	
	</p></blockquote><blockquote><p>Good luck. He is in for a profoundly difficult job -- armed as he is with no credible Military Intelligence, no witnesses and only the ghost of Bin Laden to blame for the tragedy.
	
</p></blockquote><p>


One unintended lesson I take away from Hunter's life is how important patience is. Obama is a politician and may yet disappoint us all, but I gotta believe Hunter would be seriously impressed. If he had waited another couple of years, he may have seen a lot of the stuff he fought for in 1968 and 72 come to fruition. Sometimes you are just 36-40 years ahead of your time and you have to be ok with that and figure out how to deal if possible. (Note - it sure sometimes feels this way in software security).

Speaking of security:

</p><blockquote>
	<p><a href="http://www.ram.org/contrib/security.html">Security</a> 	
	</p></blockquote><blockquote><p>by Hunter S. Thompson (1955). 	
	</p></blockquote><blockquote><p>Security ... what does this word mean in relation to life as we know it today? For the most part, it means safety and freedom from worry. It is said to be the end that all men strive for; but is security a utopian goal or is it another word for rut? 	
	</p></blockquote><blockquote><p>Let us visualize the secure man; and by this term, I mean a man who has settled for financial and personal security for his goal in life. In general, he is a man who has pushed ambition and initiative aside and settled down, so to speak, in a boring, but safe and comfortable rut for the rest of his life. His future is but an extension of his present, and he accepts it as such with a complacent shrug of his shoulders. His ideas and ideals are those of society in general and he is accepted as a respectable, but average and prosaic man. But is he a man? has he any self-respect or pride in himself? How could he, when he has risked nothing and gained nothing? What does he think when he sees his youthful dreams of adventure, accomplishment, travel and romance buried under the cloak of conformity? How does he feel when he realizes that he has barely tasted the meal of life; when he sees the prison he has made for himself in pursuit of the almighty dollar? If he thinks this is all well and good, fine, but think of the tragedy of a man who has sacrificed his freedom on the altar of security, and wishes he could turn back the hands of time. A man is to be pitied who lacked the courage to accept the challenge of freedom and depart from the cushion of security and see life as it is instead of living it second-hand. Life has by-passed this man and he has watched from a secure place, afraid to seek anything better What has he done except to sit and wait for the tomorrow which never comes? 	
	</p></blockquote><blockquote><p>Turn back the pages of history and see the men who have shaped the destiny of the world. Security was never theirs, but they lived rather than existed. Where would the world be if all men had sought security and not taken risks or gambled with their lives on the chance that, if they won, life would be different and richer? It is from the bystanders (who are in the vast majority) that we receive the propaganda that life is not worth living, that life is drudgery, that the ambitions of youth must he laid aside for a life which is but a painful wait for death. These are the ones who squeeze what excitement they can from life out of the imaginations and experiences of others through books and movies. These are the insignificant and forgotten men who preach conformity because it is all they know. These are the men who dream at night of what could have been, but who wake at dawn to take their places at the now-familiar rut and to merely exist through another day. For them, the romance of life is long dead and they are forced to go through the years on a treadmill, cursing their existence, yet afraid to die because of the unknown which faces them after death. They lacked the only true courage: the kind which enables men to face the unknown regardless of the consequences. 	
	</p></blockquote><blockquote><p>As an afterthought, it seems hardly proper to write of life without once mentioning happiness; so we shall let the reader answer this question for himself: who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed?
</p></blockquote><p>

A ship is safest at port, but thats not why we build ships. 
</p>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 06:10:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/sought security">sought security</category>
      <category domain="http://securityratty.com/tag/personal security">personal security</category>
      <category domain="http://securityratty.com/tag/national security emergency">national security emergency</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/expensive war">expensive war</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/hunter">hunter</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/gonzo-two-thumbs-in-and-up.html">Gonzo: Two Thumbs In and Up</source>
    </item>
    <item>
      <title><![CDATA[Lompoc's Comeback]]></title>
      <link>http://securityratty.com/article/d8cd53c51e38bfdb65f16dbc0871b978</link>
      <guid>http://securityratty.com/article/d8cd53c51e38bfdb65f16dbc0871b978</guid>
      <description><![CDATA[I've been citing Lompoc, Calif., as a poster child of what can go wrong in municipal Wi-Fi for a few years: But I apparently have to change my tune. Lompoc, near Santa Barbara, had unreasonable...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/lock.jpg" align="right" border="0" hspace="5" /><a href="http://news.yahoo.com/s/pcworld/20080714/tc_pcworld/148403"><strong>I've been citing Lompoc, Calif., as a poster child of what can go wrong in municipal Wi-Fi for a few years:</strong></a> But I apparently have to change my tune. Lompoc, near Santa Barbara, had unreasonable expectations, if you read their first and second RFPs. The first provider built a network that Lompoc found unacceptable and they bid it out for a second network to be built (some of these details are murky and some under dispute).</p>

<p>What's been clear is that after spending more than $3m, the city couldn't acquire more than a few hundred regular subscribers, about 10 percent of the point they'd need to pay expenses and pay down capital outlay. But it turns out that the backend was as important as their network deployment, IDG News Service reports.</p>

<p>The latest city network administrator brought in Aptilo Networks for backend authentication and session processing, opened the network to 15-minute free trials, and started accepted ad hoc payment. The new network guru also let outsourced contracts expire and brought customer support and other services back in house to reduce expenses and improve the feedback loop. He discovered their existing authentication system was licensed for 500 users, so that might have explained their failure to grow, too.</p>

<p>The city now has 1,000 regular users at all levels, from pay-as-you-go to monthly household subscriptions. They've revised breakeven down to 2,000 subscribers, and say they are breakeven for expenses.</p>

<p>The other problem Lompoc had, by the way, is that the cable and telephone companies didn't sit still. I exaggerate, but when Lomopoc was planning its network, it had very poor coverage for its 42,000 residents for DSL and cable modem service. When the Wi-Fi network was announced, the incumbents started pulling copper, coax, and fiber, and dramatically improved network coverage. The $3m wasn't entirely ill spent so far: it was a kind of reverse incentive to the private companies to get their act together.</p>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 06:57:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/city">city</category>
      <category domain="http://securityratty.com/tag/city network administrator">city network administrator</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network coverage">network coverage</category>
      <category domain="http://securityratty.com/tag/network guru">network guru</category>
      <category domain="http://securityratty.com/tag/lompoc">lompoc</category>
      <category domain="http://securityratty.com/tag/network deployment">network deployment</category>
      <category domain="http://securityratty.com/tag/cable">cable</category>
      <source url="http://wifinetnews.com/archives/008396.html">Lompoc's Comeback</source>
    </item>
    <item>
      <title><![CDATA[Wait a min, I use Comcast!]]></title>
      <link>http://securityratty.com/article/e6910e178cb8848fa30c13f64299bd81</link>
      <guid>http://securityratty.com/article/e6910e178cb8848fa30c13f64299bd81</guid>
      <description><![CDATA[Cmon Comcast, Im ashamed ! I use your service. On another note, way to go Verizon, Im a user with you too


clipped from tech.blorge.com
AOL, AT&amp;T join child porn battle
clipped from tech.blorge.com
...]]></description>
      <content:encoded><![CDATA[<div > Cmon Comcast, Im ashamed ! I use your service.<br/>On another note, way to go Verizon, Im a user with you too. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/3AEB931C-33D8-4D87-824B-6DE7626D4EB8/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/35f7e0ef-70fb-42c2-b759-a20bce05fec3/3AEB931C-33D8-4D87-824B-6DE7626D4EB8/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://tech.blorge.com/Structure:%20/2008/07/10/aol-att-join-child-porn-battle/" href="http://tech.blorge.com/Structure:%20/2008/07/10/aol-att-join-child-porn-battle/" style="font-size: 11px;">tech.blorge.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://tech.blorge.com/Structure:%20/2008/07/10/aol-att-join-child-porn-battle/ --><H3><A title="Permanent Link: AOL, AT&#038;T join child porn battle" rel="bookmark" href="http://tech.blorge.com/Structure: /2008/07/10/aol-att-join-child-porn-battle/">AOL, AT&#038;T join child porn battle</A></H3></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/3AEB931C-33D8-4D87-824B-6DE7626D4EB8/" title="go to this clipmark"><img src="http://content8.clipmarks.com/images/clip-icon.gif" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://tech.blorge.com/Structure:%20/2008/07/10/aol-att-join-child-porn-battle/" href="http://tech.blorge.com/Structure:%20/2008/07/10/aol-att-join-child-porn-battle/" style="font-size: 11px;">tech.blorge.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://tech.blorge.com/Structure:%20/2008/07/10/aol-att-join-child-porn-battle/ --><P>AT&#038;T and AOL (the largest and third-largest ISPs respectively) committed to blocking access to all newsgroups with child porn, along with offending websites stored on their servers. Verizon, Time Warner and Sprint had already agreed to this action.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/3AEB931C-33D8-4D87-824B-6DE7626D4EB8/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 12:09:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blorge">blorge</category>
      <category domain="http://securityratty.com/tag/verizon">verizon</category>
      <category domain="http://securityratty.com/tag/child porn">child porn</category>
      <category domain="http://securityratty.com/tag/tech">tech</category>
      <category domain="http://securityratty.com/tag/aol">aol</category>
      <category domain="http://securityratty.com/tag/time warner">time warner</category>
      <category domain="http://securityratty.com/tag/comcast">comcast</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/sprint">sprint</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=503">Wait a min, I use Comcast!</source>
    </item>
    <item>
      <title><![CDATA[Williamson County Schools learns of breach reported nine months ago]]></title>
      <link>http://securityratty.com/article/ab879007319944481d6c7e5668489293</link>
      <guid>http://securityratty.com/article/ab879007319944481d6c7e5668489293</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/11/08

Organization
Williamson County Schools

Contractor/Consultant/Branch
None

Victims
Students

3,052 ACT students and 2,117 students who took the...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wcs.jpg" width="109" align="right" height="123"><font size="2"><b>Date Reported: </b><br>7/11/08<br><br><b>Organization: </b><br><a href="http://www.wcs.edu/">Williamson County Schools</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Students*<br><br><font size="1">*"3,052 ACT students and 2,117 students who took the second grade test were affected", Source: <a href="http://www.wcs.edu/student_information_conf.htm%20">Student Information News Conference Text 7/11/08</a><br></font> <br><span style="font-weight: bold;">Number Affected:</span><br>5,169<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, testing scores, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"FRANKLIN, Tenn.- It now appears a security breach at Williamson County schools was much worse than expected. School officials now say more than 5,000 students may have been affected when a school employee accidently posted their personal information online."<br><br>Reference URL:<br><a href="http://www.wcs.edu/student_information_conf.htm">Williamson County Student Information News Conference</a> <br><a href="http://www.newschannel5.com/Global/story.asp?S=8662746">News Channel 5</a> <br><a href="http://www.wreg.com/Global/story.asp?S=8657599">WREG Channel 3 News</a> <br><a href="http://www.wsmv.com/news/16843341/detail.html#-">WSMV Channel 4 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Liberty Coalition<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>FRANKLIN, Tenn.- It now appears a security breach at Williamson County schools was much worse than expected. School officials now say more than 5,000 students may have been affected when a school employee accidently posted their personal information online.<br><br>Now the county could lose some federal funding because of the mistake.<br><span style="font-style: italic;">[Evan] Do you really think that this will happen?&nbsp; If we looked deeper into the way the public school systems handle confidential information, half of the school districts would lose funding.&nbsp; Williamson County is in good company across the country.</span><br style="font-style: italic;"><br>The school district had to notify the Department of Education because this was a federal violation.<br><br>Director of Schools, Rebecca Sharber is taking on the responsibility of fixing the problem.<br><br>"I'm the head of the school system. I'm accountable," said Sharber.<br><span style="font-style: italic;">[Evan] What a fantastic statement.&nbsp; Corporate CEOs, non-profit executive directors, etc. ARE ultimately responsible for the protection of information.&nbsp; Ms. Sharber just earned my respect.</span><br style="font-style: italic;"><br>"It certainly is distressing to me that information was ever out there," said Sharber.<br><br>According to school officials, former assessment specialist, Chris Nugent is responsible for the computer mix-up.<br><br>He resigned Friday.<br><br>"Mr. Nugent has resigned his position as Assessment Specialist, effective immediately."<br><br>It was August last year when Nugent mistakenly loaded the info on a personal web page, but he never alerted the district.<br><br>They only found out a couple of weeks ago.<br><br>"A principal who had been contacted by a parent brought this to our attention on June 26th."<br><br>"The information given to us indicated that our assessment specialist, Chris Nugent, was involved. This was the first we had heard of this situation."<br><br>"We began our investigation immediately asking Mr. Nugent to gather all data that could possibly be associated with this situation."<br><br>"We thought at that time he would be able to supply the names of students possibly involved in the most timely manner."<br><br>"When Mr. Nugent was unable to get that information for us, our attorney Jason Golden contacted the Liberty Coalition, the organization that had posted the Internet report presented to us by the principal."<br><span style="font-style: italic;">[Evan] The Liberty Coalition posted the information surrounding the breach in October, 2007, many months before the victims were ever made aware.</span><br style="font-style: italic;"><br>"Yesterday afternoon, the Liberty Coalition was able to provide the names of the students affected."<br><br>"Our investigation indicates that the student information was posted on a private website created by Mr. Nugent sometime during the month of August, 2007."<br><br>"On August 28, 2007, the Liberty Coalition notified Mr. Nugent that private student information was on his web site."<br><br>"On August 29, 2007, the web site was shut down."<br><br>"Mr. Nugent did not notify school authorities."<br><br>"Our investigation has established that Mr. Nugent had confidential student files on the same thumb-drive with his personal files."<br><br>"We believe that when Mr. Nugent uploaded his personal files to a web site he created, he inadvertently uploaded our student files."<br><br>Sharber said the first step will be to look at revising policies on student information.<br><br>They will also pay for fraud alerts for the students.<br><br>It could cost the district hundreds of thousands of dollars to pay for those fraud alerts.<br><br>"I would say to other school districts they need to really, really check their policies and procedures on how student data is being used," said Sharber.<br><span style="font-style: italic;">[Evan] Again, did I mention that I respect Ms. Sharber?&nbsp; This statement is very good advice.</span><br><br>More than 5,000 students had their security information posted.<br><br>Most of those are high school students who took the ACT in the 2006-2007 school year, and second graders who took the TCAP the same year.<br><br>"We have learned that most students who took the second grade TCAP achievement test and most students who took the ACT test during the 2006-07 school year had social security numbers on a private website during August of 2007."<br><span style="font-style: italic;">[Evan] Is there some kind of legal requirement that states that a Social Security number must be tied to test scores, or was this just poor judgment?&nbsp; Are/were Social Security numbers used as student IDs at the district?</span><br style="font-style: italic;"><br>"Our review of the records shows that 3,052 ACT students and 2,117 students who took the second grade test were affected."<br><br>The information was on the internet for about a month.<br><br>"I want to thank the parents of Williamson County Schools for their patience and understanding and the positive suggestions they have shared as we have conducted our investigation and gone public with this information.", said Sharber<br><span style="font-style: italic;">[Evan] The Liberty Coalition went public with </span><a style="font-style: italic;" href="https://www.ssnbreach.org/release.php?g=13">this breach</a><span style="font-style: italic;"> in October, 2007.&nbsp; I appreciate the motives of the Liberty Coalition, but I am not pleased with the way they report breaches.&nbsp; I'll elaborate below in the commentary section.</span><br style="font-style: italic;"><br>"I understand the anxiety that our parents are experiencing.", said Sharber<br><br>"On Monday, we will be calling all parents of students whose social security numbers were exposed to let them know their child was affected, and we will follow up that phone call with a letter."<br><br>"We are working to locate a security company, and at our expense, we will cover the cost of fraud protection for the students affected."<br><span style="font-style: italic;">[Evan] I hope that the school locates a good "security company".&nbsp; Of course </span><a style="font-style: italic;" href="http://www.frsecure.com">FRSecure</a><span style="font-style: italic;"> would be glad to help.&nbsp; I promise to keep the plugs to a minimum <img src="http://breachblog.com/emoticons/smile.png" border="0" />.</span><br style="font-style: italic;"><br><span style="font-weight: bold;">Commentary:</span><br>OK.&nbsp; We all know that a breach affecting kids is especially bad.&nbsp; We all know that we are all human and all humans make mistakes.&nbsp; I presume that there are a number of risky information security behaviors at Williamson County Schools.&nbsp; This risky behavior just so happened to expose personal information online.&nbsp; What other risky behaviors will be addressed at the school district?<br><br>Now about the Liberty Coalition's role.&nbsp; I appreciate the motives of Aaron Titus and the Liberty Coalition.&nbsp; He maintains the SSNBreach.org web site where he publicizes information security breaches that his organization finds (or is informed about).&nbsp; My attention was first drawn to Aaron Titus in August 2007, when he reported the <a href="https://www.ssnbreach.org/release.php?g=1">Louisiana Board of Regents breach</a> affecting ~200,000 people.&nbsp; What drew my attention to his report was not the breach itself, but the way in which it he proceeded to report it.&nbsp; Lyger at Attrition.org covers it well <a href="http://attrition.org/security/rant/z/privacy.html">here</a>.<br><br>In this case, the Liberty Coalition publicly posted this breach in October, 2007 which is more than 9 months before the victims were ever made aware!&nbsp; According to the Liberty Coalition press release; "We updated this press release after becoming aware of Mr. Nugent's relationship with the school district. The Liberty Coalition also worked directly with district officials to help them notify the affected individuals."&nbsp; It would have been nice if the victims were notified prior to a public press release.&nbsp; I wonder why Mr. Nugent's relationship with the school district wasn't known earlier.&nbsp; I don't have the details that the Liberty Coalition does surrounding this breach, so I can only speculate.<br><br>The fact that some breaches are reported on SSNBreach.org prior to notification (in this case nine months), I chose to generally not report them here at The Breach Blog. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/12/wcs.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 12 Jul 2008 20:12:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/school students">school students</category>
      <category domain="http://securityratty.com/tag/schools">schools</category>
      <category domain="http://securityratty.com/tag/williamson county schools">williamson county schools</category>
      <category domain="http://securityratty.com/tag/williamson county">williamson county</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/school authorities">school authorities</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <source url="http://breachblog.com/2008/07/12/wcs.aspx">Williamson County Schools learns of breach reported nine months ago</source>
    </item>
    <item>
      <title><![CDATA[AT&T, AOL join other ISPs to block child porn]]></title>
      <link>http://securityratty.com/article/b3b5568f10b2ef7538c4ce2a6c0e2e10</link>
      <guid>http://securityratty.com/article/b3b5568f10b2ef7538c4ce2a6c0e2e10</guid>
      <description><![CDATA[AT&amp;T and AOL have joined three other major Internet service providers in eliminating access to child pornography newsgroups, New York Attorney General Andrew Cuomo said...]]></description>
      <content:encoded><![CDATA[AT&T and AOL have joined three other major Internet service providers in eliminating access to child pornography newsgroups, New York Attorney General Andrew Cuomo said Friday.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=10334?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=10334?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/child pornography newsgroups">child pornography newsgroups</category>
      <category domain="http://securityratty.com/tag/aol">aol</category>
      <category domain="http://securityratty.com/tag/york attorney">york attorney</category>
      <category domain="http://securityratty.com/tag/andrew cuomo">andrew cuomo</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <source url="http://www.networkworld.com/news/2008/071108-att-aol-join-other-isps.html?fsrc=rss-security">AT&amp;T, AOL join other ISPs to block child porn</source>
    </item>
    <item>
      <title><![CDATA[How Can I Find Them? They Haven't Gone Missing!]]></title>
      <link>http://securityratty.com/article/521b9f6d9f84284358b728d75d93f7cb</link>
      <guid>http://securityratty.com/article/521b9f6d9f84284358b728d75d93f7cb</guid>
      <description><![CDATA[I've often highlighted the utterly worthless spam messages that seem to endlessly circulate on Facebook, usually warning not to add (insert random name here) because they're an evil hacker and will...]]></description>
      <content:encoded><![CDATA[
        I've often highlighted the utterly worthless spam messages that seem to endlessly circulate on Facebook, usually warning not to add (insert random name here) because they're an evil hacker and will destroy your PC, kill your family and so on.<br /><br />Well, today I came across another such message:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="norris1.jpg" src="http://blog.spywareguide.com/images/norris1.jpg" class="mt-image-none" style="" height="94" width="313" /></span></div><br /> <div><br />.....insert gag about them being related to Chuck here....but underneath that message was something far more interesting:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/norris21.html" onclick="window.open('http://blog.spywareguide.com/images/norris21.html','popup','width=304,height=434,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/norris2-thumb-304x434.gif" alt="norris2.gif" class="mt-image-none" style="" height="434" width="304" /></a></span><br /></div><br /></div><div><br />Sounds serious, right? It seems personal, because it's their friend missing which adds a little more urgency - they provide a contact email address to notify them on, and it mentions a real world example of someone who went missing and was found via the Internet.<br /><br />However.<br /><br />Dig into this a little bit, and it all becomes clear quite quickly that something isn't quite right here. For starters, search for the missing persons name and there is no mention of him ever "going missing". Nothing on websites, news pages....it's like the whole thing is a work of fiction. In fact, buried in unrelated entries is the following snippet from a page on myyearbook.com:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/norris3.html" onclick="window.open('http://blog.spywareguide.com/images/norris3.html','popup','width=586,height=89,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/norris3-thumb-386x58.jpg" alt="norris3.jpg" class="mt-image-none" style="" height="58" width="386" /></a></span><br /></div></div><div><div align="center"><br />Click to Enlarge<br /></div><br />Check out the name of the "hacker" you shouldn't add. It seems someone has simply swiped the name and started pasting it into spam messages. A quick search of Facebook confirms the <a href="http://www.facebook.com/people/Nour_Ajouz/650060261">name and face go together</a>.<br /><br />A quick search for the email address listed as a contact brings up more interesting posts, this time posted to a personal blog:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/norris51.html" onclick="window.open('http://blog.spywareguide.com/images/norris51.html','popup','width=496,height=487,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/norris5-thumb-396x388.gif" alt="norris5.gif" class="mt-image-none" style="" height="388" width="396" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Same text....same reference to "real world" example....same email address. This person sure does get through a lot of missing friends! Note that this "missing person" chain letter has now stepped outside of Facebook and into other websites and networks.<br /><br />At this point, you're probably wondering about the validity of the "real world" example, aren't you? Well, that would be a good idea! Notice they don't give any detail - it simply says "That is how the girl from Stevens Point was found by circulation of her picture on TV", and expect you to accept it as is. If you go searching for that phrase, it doesn't take long to find a page on Snopes.com regarding a <a href="http://www.snopes.com/inboxer/missing/penny.asp">missing girl hoax</a> that stretches back some years:<br /><br /><i>"Please look at the picture, read what her father says, then forward his message on. Maybe if everyone passes this on, someone will see this child. That is how the girl from Stevens Point was found by circulation of her picture on tv..."</i><br /><br />An email hoax, wrapped up and repackaged for the Facebook generation.<br /></div><div><br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 08:45:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/contact email address">contact email address</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/real world">real world</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/facebook confirms">facebook confirms</category>
      <category domain="http://securityratty.com/tag/girl hoax">girl hoax</category>
      <category domain="http://securityratty.com/tag/facebook generation">facebook generation</category>
      <category domain="http://securityratty.com/tag/girl">girl</category>
      <category domain="http://securityratty.com/tag/evil hacker">evil hacker</category>
      <source url="http://blog.spywareguide.com/2008/07/how-can-i-find-them-they-haven.html">How Can I Find Them? They Haven't Gone Missing!</source>
    </item>
    <item>
      <title><![CDATA[Can The Gov Be Trusted With Your Personal Data?]]></title>
      <link>http://securityratty.com/article/f09583068525ca2d56abe689ff8ea4e0</link>
      <guid>http://securityratty.com/article/f09583068525ca2d56abe689ff8ea4e0</guid>
      <description><![CDATA[Survey says(insert buzzer noise
Faith in the (UK) govs ability to securely manage personal data is out the window
From Reuters
The inquiries followed Britains biggest data loss scandal, when two discs...]]></description>
      <content:encoded><![CDATA[<p>Survey says&#8230;(insert buzzer noise)</p>
<p>Faith in the (UK) gov&#8217;s ability to securely manage personal data is out the window. </p>
<p>From Reuters:</p>
<blockquote><p>The inquiries followed Britain’s biggest data loss scandal, when two discs containing child benefit records, including names, addresses and bank details, of some 25 million people, went missing after being put in the post by a junior employee.</p>
<p>The reports concluded that it wasn’t individuals who were to blame - some 30 were officials played some role in events leading to the loss of the discs - but institutional and systematic failures at Britain’s tax authority.</p>
<p>But the HMRC is not alone in such security breaches. A separate report into a stolen laptop containing the details of 600,000 potential recruits revealed similar failings at the Ministry of Defence. In all, four MoD computers had been stolen since 2004 and the report said the MoD was probably in breach of several principles set out in the Data Protection Act.</p></blockquote>
<p>Well, where do you stand? Do you trust your respective government not to punt on data security? </p>
<p>Read on.</p>
<p><a href="http://blogs.reuters.com/uknews/2008/06/25/can-the-government-be-trusted-with-your-personal-data/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=770kXb"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=770kXb" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=pFZPzI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=pFZPzI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=hm8i3i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=hm8i3i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=pnvfai"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=pnvfai" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=en11wi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=en11wi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=EkCewi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=EkCewi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/320499028" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:44:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/loss">loss</category>
      <category domain="http://securityratty.com/tag/data loss scandal">data loss scandal</category>
      <category domain="http://securityratty.com/tag/britains">britains</category>
      <category domain="http://securityratty.com/tag/britains tax authority">britains tax authority</category>
      <category domain="http://securityratty.com/tag/data protection act">data protection act</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/child benefit records">child benefit records</category>
      <category domain="http://securityratty.com/tag/mod computers">mod computers</category>
      <category domain="http://securityratty.com/tag/bank details">bank details</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/320499028/">Can The Gov Be Trusted With Your Personal Data?</source>
    </item>
    <item>
      <title><![CDATA[Some of the other noteworthy breaches last week, 6/16/08 - 6/22/08]]></title>
      <link>http://securityratty.com/article/807b1e3ccc47c175a72b57ee98773462</link>
      <guid>http://securityratty.com/article/807b1e3ccc47c175a72b57ee98773462</guid>
      <description><![CDATA[Technorati Tag: Security Breach

The Breach Blog

Just SOME of the other noteworthy breaches from the past week (6/16/08 - 6/22/08

Citibank Hack Blamed for Alleged ATM Crime Spree
By Kevin Poulsen,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/tbblogo.jpg" width="192" align="right" height="96"><font size="2"><font size="3"><span style="font-weight: bold;">The Breach Blog</span></font><br><br>Just <span style="font-weight: bold;">SOME </span>of the other noteworthy breaches from the past week (6/16/08 - 6/22/08)<br><br><font style="font-weight: bold;" size="3"><a href="%20http://blog.wired.com/27bstroke6/2008/06/citibank-atm-se.html">Citibank Hack Blamed for Alleged ATM Crime Spree</a></font><br>By Kevin Poulsen, Wired.com, 6/18/08<br><br></font><div style="margin-left: 40px;"><font size="2">A computer intrusion into a Citibank server that processes ATM withdrawals led to two Brooklyn men making hundreds of fraudulent withdrawals from New York City cash machines in February, pocketing at least $750,000 in cash, according to federal prosecutors. </font><br><br><font size="2">The ATM crime spree is apparently the first to be publicly linked to the breach of a major U.S. bank's systems, experts say. </font><br></div><font size="2"><br><font style="font-weight: bold;" size="3"><a href="http://www.networkworld.com/news/2008/061808-security-firm-finds-server-with.html">Security firm finds server with health-care data</a></font><br>By Jeremy Kirk, NetworkWorld, 6/18/08<br><br></font><div style="margin-left: 40px;"><font size="2">Security researchers with <a href="http://www.finjan.com/">Finjan Software</a> are seeing a growing thirst from cybercriminals for data other than credit-card numbers, with the latest findings including servers containing passwords leading to heath-care records and airline systems data. </font><br><br><font size="2">The problem is two-fold: sensitive data is being stolen after PCs are infected with malicious software, and then that data sent to unprotected remote servers, said Yuval Ben-Itzhak, chief technology officer for Finjan. The content of those servers is then indexed by search engines, leaving it open to anyone who uses the right query terms. </font><br></div><font size="2"><br><font size="3"><a style="font-weight: bold;" href="http://www.wsbt.com/news/local/20465589.html">Bank scam spreads as institutions look for possible source of breach</a></font><br>By Leanne Tokars, WSBT Channel 22 News, 6/18/08<br><br></font><div style="margin-left: 40px;"><font size="2">SOUTH BEND - An international bank scam is spreading, and there is some idea how that information may have gotten out.</font><br><br><font size="2">Hundreds of people and dozens of banks and credit unions across our area are trying to recover from a major security breach.</font><br><br><font style="font-style: italic;" size="2">[Evan] This story is related to the "<a href="http://breachblog.com/2008/06/05/1stsource.aspx">1st Source Bank reissues all debit cards in response to breach</a>" posting on 5/30/08.&nbsp; Another supporting story;<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyId=17&amp;articleId=9101158&amp;intsrc=hm_topic"> Fraudulent ATM transactions overseas could be tied to Indiana bank breach</a></font><span style="font-style: italic;">&nbsp; This is a winding storyline.</span><br></div><font size="2"><br><font size="3"><a style="font-weight: bold;" href="http://www.topnews.in/parents-livid-over-database-putting-student-profiles-pictures-online-247747">Parents livid over database putting student profiles, pictures online</a></font><br>By Mohit Joshi, Top News, 6/16/08<br><br></font><div style="margin-left: 40px;"><font size="2">Melbourne, June 16: With the State government planning to post the profile of every state school student on its intranet database, called OneSchool, parents in Australia are livid over the fact that it will make their kids vulnerable to paedophiles.</font><br><br><font size="2">OneSchool, will provide each and every detail of the state's 480,000 public school students enrolled from Prep to Year 12, for which, the photographs, personal details, career aspirations, off-campus activities and student performance records are already being collected from all 1251 state schools.</font><br><br><font style="font-style: italic;" size="2">[Evan] I think I’d be livid too.&nbsp; Are parents given the opportunity to opt out, without penalty or lost opportunities?</font><span style="font-style: italic;">&nbsp; "According to Education Minister Rod Welford, if the parents refuse to
give their consent to their child being profiled, they could also be
denied access to public education."</span></div><font size="2"><br><font size="3"><a style="font-weight: bold;" href="http://news.bbc.co.uk/2/hi/uk_news/politics/7459579.stm">Blears PC loss - officials blamed </a></font><br>BBC News, 6/17/08<br><br></font><div style="margin-left: 40px;"><font size="2">Information on a computer stolen from Communities Secretary Hazel Blears' office had been sent in breach of data security rules, it has emerged. </font><br><br><font size="2">The Communities and Local Government department admitted its officials had "not fully" complied with guidance on handling sensitive data. </font><br><br><font size="2">Its top civil servant Peter Housden said "no damage had been done" as the documents were not secret.</font><br><br><font size="2">The computer contained a combination of constituency and government information relating to defence and extremism.</font><br><br><font style="font-style: italic;" size="2">[Evan] It is disappointing to read about breaches where the government does not follow its own laws and regulations.&nbsp; Mr. Housden claims that the files were "not secret".&nbsp; They certainly weren’t public, were they?</font><br></div><font size="2"><br><font style="font-weight: bold;" size="3"><a href="http://www.dailymail.co.uk/news/article-1027457/Personal-details-20-000-patients-stolen-hospital-new-security-blunder.html">Personal details of thousands of patients stolen from hospital in new security blunder</a></font><br>By James Tozer, The Daily Mail, 6/18/08<br><br></font><div style="margin-left: 40px;"><font size="2">Laptops holding tens of thousands of patients' records have been stolen from a hospital and a GP's home, it emerged yesterday. </font><br><br><font size="2">In the latest lost personal data scandal, the information was stored on the machines in contravention of NHS guidelines. </font><br><br><font size="2">It was revealed that details of 20,000 patients were on six laptops stolen earlier this month from filing cabinets at St George's Hospital, in Tooting, South West London. </font><br><br><font style="font-style: italic;" size="2">[Evan]&nbsp; This is six stolen laptops in one month, and the four breaches in one year?!&nbsp; The exposed information in this breach was "names, postcodes, hospital numbers and dates of birth".&nbsp; Check out the excuse for storing confidential information on these poorly secured laptops; "Normally such information is stored on the hospital's central network, but because of technical problems it was being stored temporarily on the laptops."</font><br></div><font size="2"><br><br><b>To Readers:</b>&nbsp; I am testing this weekly "Other noteworthy breaches" post.&nbsp; I am using this first one to gauge interest and decide if it is something we should continue.&nbsp; Please feel free to comment.<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/23/062308.aspx%E2%80%9D%20type=" text="" javascript="" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 04:11:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/major security breach">major security breach</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/airline systems data">airline systems data</category>
      <category domain="http://securityratty.com/tag/breaches">breaches</category>
      <category domain="http://securityratty.com/tag/noteworthy breaches">noteworthy breaches</category>
      <category domain="http://securityratty.com/tag/indiana bank breach">indiana bank breach</category>
      <category domain="http://securityratty.com/tag/sensitive data">sensitive data</category>
      <source url="http://breachblog.com/2008/06/23/062308.aspx">Some of the other noteworthy breaches last week, 6/16/08 - 6/22/08</source>
    </item>
    <item>
      <title><![CDATA[Security Circumvented: My Anti-Virus]]></title>
      <link>http://securityratty.com/article/5704ba277530cbbd6aec5c9efb9863d9</link>
      <guid>http://securityratty.com/article/5704ba277530cbbd6aec5c9efb9863d9</guid>
      <description><![CDATA[I recently needed to renew the anti-virus subscription on my tablet PC. Of course, Symantec popped up and let me know well in advance, and of course, I waited until the almost-last-day before I...]]></description>
      <content:encoded><![CDATA[<p><strong>I recently needed to renew the anti-virus subscription</strong> on my tablet PC. Of course, Symantec popped up and let me know well in advance, and of course, I waited until the almost-last-day before I renewed. </p><p>When my renewal options appeared, there was a selection to upgrade to the shiny new Norton 360. Woo hoo! It listed all these great new security features&#8230; I don&#8217;t remember what they were&#8230; but, they sounded REALLY great (I promise).</p><p>So I went with the upgrade, instead of the anti-virus signature renewal. <em>Okay</em>. </p><p>It did <strong>seem</strong> like a good idea at the time. However, in addition to my overly-protective Vista popups eeeevvvvery time I want to run something, connect somewhere, or wipe my nose&#8230; Now, I have the Vista pop up AND the Norton 360 popup.&nbsp;<em>Okay</em>.</p><p>Except, the Norton pops up with flagrantly ambiguous information like &#8220;An application is trying to access your Internet.&#8221; Do I want to allow it? I don&#8217;t know. How am I supposed to know-&nbsp;<strong>which</strong> application wants to access my Internet? Oh, it&#8217;s not going to tell me. <em>Okay</em>.</p><p>Well, I guess I&#8217;ll click &#8216;Allow&#8217; because I have no clue <strong>what</strong> is trying to access my Internet, but I&#8217;ll assume it&#8217;s something that I have somehow asked to access my Internet&#8230; and I&#8217;ll be quite upset if whatever I clicked on doesn&#8217;t work. So YES, ALLOW. <em>Okay again.</em></p><p>And what was the point in that? One click has transformed to three, and I&#8217;m no more secure than I was before, I&#8217;m just being forced to make more clicks to <u>earn</u> my insecurity. So today I am the poster child of what NOT to do. </p><p><strong>Security circumvented</strong> is quite possibly worse than no security at all. I see visions of &#8216;invalid browser certificate&#8217; notices dancing in my head. </p><p># # #</p>
]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 23:31:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/norton pops">norton pops</category>
      <category domain="http://securityratty.com/tag/norton">norton</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/security features">security features</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/flagrantly ambiguous information">flagrantly ambiguous information</category>
      <category domain="http://securityratty.com/tag/anti-virus signature renewal">anti-virus signature renewal</category>
      <category domain="http://securityratty.com/tag/possibly worse">possibly worse</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/20/security-circumvented-my-anti-virus.html">Security Circumvented: My Anti-Virus</source>
    </item>
    <item>
      <title><![CDATA[Q&A: A misconfigured laptop; a wrecked life]]></title>
      <link>http://securityratty.com/article/2d817161708186002da80d867851d501</link>
      <guid>http://securityratty.com/article/2d817161708186002da80d867851d501</guid>
      <description><![CDATA[Michael Fiola's laptop set off a chain of events that would cost him his job, his friends and about a year of his life, as he fought criminal charges that he had downloaded child pornography onto the...]]></description>
      <content:encoded><![CDATA[Michael Fiola's laptop set off a chain of events that would cost him his job, his friends and about a year of his life, as he fought criminal charges that he had downloaded child pornography onto the laptop. He talks about the case, which prosecutors dropped last week.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=bR4ZjY"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=bR4ZjY" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/314739251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 18 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/laptop set">laptop set</category>
      <category domain="http://securityratty.com/tag/fought criminal charges">fought criminal charges</category>
      <category domain="http://securityratty.com/tag/child pornography">child pornography</category>
      <category domain="http://securityratty.com/tag/michael fiola">michael fiola</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/314739251/article.do">Q&amp;A: A misconfigured laptop; a wrecked life</source>
    </item>
  </channel>
</rss>
