<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: company]]></title>
    <link>http://securityratty.com/tag/company</link>
    <description></description>
    <pubDate>Wed, 01 Oct 2008 00:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Disk Containing Data on 17 Million T-Mobile Customers Missing, The Data Is For Sale]]></title>
      <link>http://securityratty.com/article/b7d7d76e0604b84cbe7c11b2c852ec6f</link>
      <guid>http://securityratty.com/article/b7d7d76e0604b84cbe7c11b2c852ec6f</guid>
      <description><![CDATA[In 2006, 17 million German customer records were stolen from T-Mobile, a mobile network operator headquartered in Bonn, Germany. T-Mobile has admitted the incident where stolen customer records...]]></description>
      <content:encoded><![CDATA[In 2006, 17 million German customer records were stolen from T-Mobile, a mobile network operator headquartered in Bonn, Germany. T-Mobile has admitted the incident where stolen customer records included names, addresses, phone numbers, dates of birth and email addresses.
Silent about the data loss for more than two years, the company published its version of events [...]]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 07:44:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/t-mobile">t-mobile</category>
      <category domain="http://securityratty.com/tag/email addresses">email addresses</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/mobile network operator">mobile network operator</category>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/customer records">customer records</category>
      <category domain="http://securityratty.com/tag/birth">birth</category>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <source url="http://cyberinsecure.com/disk-containing-data-on-17-million-t-mobile-customers-missing-the-data-is-for-sale/">Disk Containing Data on 17 Million T-Mobile Customers Missing, The Data Is For Sale</source>
    </item>
    <item>
      <title><![CDATA[Hacking Your VoIP Box From The Net]]></title>
      <link>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</link>
      <guid>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</guid>
      <description><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read this recent blog from McAfee's Avert Labs and you may wonder. An Avert analyst, reading about vulnerabilities in the...]]></description>
      <content:encoded><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read <a href="http://www.avertlabs.com/research/blog/index.php/2008/09/29/the-lack-of-attention-in-voip-devices/">this recent blog from McAfee's Avert Labs</a> and you may wonder.

An Avert analyst, reading about vulnerabilities in the Cisco IP phone model 7960 then used Google to try to find publicly-accessible 7960 phones. He found "almost 10" (does that mean 9? awkward turn of phrase). 1 of them had the vulnerable firmware version  And the vulnerability was that the phone's web interface reveals a lot of sensitive network information, so the company that holds that phone has a vulnerable network.

What was revealed by the phone? "...the IP addresses of the TFTP server/router/DNS server/DHCP server/Cisco Call Manager, as well as some application links, internal device configuration, and debugging information. If there are any exploitable vulnerabilities in one of these linked servers, attackers could use this information to stage further attacks."

There's always more to test for, and mistakes you in device configuration can have dire consequences.
<p><a href="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/a"><img src="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/sIcbcZ5FSGQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 13:06:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive network information">sensitive network information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/device configuration">device configuration</category>
      <category domain="http://securityratty.com/tag/internal device configuration">internal device configuration</category>
      <category domain="http://securityratty.com/tag/phone model">phone model</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/exploitable vulnerabilities">exploitable vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerable network">vulnerable network</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/sIcbcZ5FSGQ/hacking_your_voip_box_from_the_net.html">Hacking Your VoIP Box From The Net</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.3.08]]></title>
      <link>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</link>
      <guid>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</guid>
      <description><![CDATA[Well finally, an upside to the financial crisis more students in computer science. After the dot-com crash, enrollment went down in computer science, almost 50% since 2003. Many students shifted their...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/africa-map.jpg" border="0" alt="africa-map" width="204" height="240" align="left" /> Well finally, an upside to the financial crisis – more students in computer science. After the dot-com crash, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9066659" target="_blank">enrollment went down</a> in computer science, almost 50% since 2003. Many students <a href="http://www.washingtontechnology.com/online/1_1/33584-1.html" target="_blank">shifted their interest from the technology field</a> to banking and finance because they thought they’d make more money. And now the financial crisis could scare them into <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115616&amp;source=rss_news" target="_blank">choosing majors and careers that are “safer alternatives”</a>, like IT. And perhaps the trend is reversing for those already on Wall Street as well. Ben Worthen writes about the influx of resumes Kodiak Venture Partners has been getting: <a href="http://blogs.wsj.com/biztech/?s=wall+street+jobs" target="_blank">from financial-services vets who want to work at tech startups</a>, – not to “strike it rich” this time around, but just to make a living. And it’s not just the tech workers. Seems like the ones that don’t even have any real IT experience are looking too – for jobs as VPs of marketing (harrumph). (<a href="http://www.fas.org/irp/imint/docs/rst/Sect6/africa-map.jpg" target="_blank"><em>img from www.fas.org</em></a>)</p>
<p>I’m sure you already know about the other “network management” – where ISPs and carriers get their hands publicly slapped for limiting bandwidth to high-traffic offenders. But when is this kind of “network management” a good thing? At a panel sponsored by the FCC in DC, reps from carriers and ISPs discussed what steps they’ve been taking <a href="http://www.networkworld.com/news/2008/091808-telcos-pandemic.html?hpg1=bn" target="_blank">to prepare for a pandemic</a> or other major global crisis – that would force workers to stay at home or work from more remote locations to limit exposure.</p>
<p>Are people paying attention to ICANN? They’re saying that IPv4 will be fully <a href="http://blog.icann.org/?p=365" target="_blank">allocated in the next two or three years</a>. Does anyone care? In their bid to make people care, ICANN talks about the state of IPv6 adoption and <a href="http://www.thestandard.com/news/2008/09/30/africa-faster-adopting-ipv6-according-icann">touts Africa as the most rapid adopter</a>.</p>
<p><a href="http://blogs.zdnet.com/service-oriented/?p=1187" target="_blank">SOA soon part of the ‘cloud’</a>? No, please no.</p>
<p>Microsoft – The Silver Lining in Every Cloud. Joe Wilcox over at eWeek’s Microsoft Watch, has been <a href="http://www.microsoft-watch.com/content/corporate/steve_ballmer_sure_has_lots_to_say.html?kc=EWWHNEMNL10022008STR4" target="_blank">following Steve Ballmer</a> around and collecting some nice quotes on how the company is transitioning. “For many years, we had kind of what I would call the all-encompassing mission, vision and scorecard statement: a computer on every desk and in every home. …Well, our footprint and portfolio is broader than that. “ [In every hand and of course, in every cloud…] “So, as a vision statement we talk about creating seamless experiences that combine the magic of software, the power of the Internet across a world of devices.” The magic of software – something I haven’t thought about for a while. And:</p>
<blockquote><p>&#8220;You need a real platform in the cloud. When we wanted to go after the PC, we built an operating system. When we wanted to go after the phone, we built an operating system. When we wanted to go after the enterprise, we built an operating system. We&#8217;ll announce a new operating system, one that runs in the cloud and has a wide variety of capabilities.”</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:55:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/computer science">computer science</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/financial crisis">financial crisis</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/eweeks microsoft">eweeks microsoft</category>
      <source url="http://blog.sciencelogic.com/links-list-10308/10/2008">Links List 10.3.08</source>
    </item>
    <item>
      <title><![CDATA[A oldie but still not a goodie!]]></title>
      <link>http://securityratty.com/article/0e17047624dae2129fdb4a17722b079b</link>
      <guid>http://securityratty.com/article/0e17047624dae2129fdb4a17722b079b</guid>
      <description><![CDATA[Ah, Gator. Where for art thou? Im here,,just under another name and still looking to make some money off unknowing users


clipped from www.techdirt.com

Is The Original Spyware Company Finally Dead
...]]></description>
      <content:encoded><![CDATA[<div > Ah, Gator. Where for art thou?<br/>Im here,,just under another name and still looking to make some money off unknowing users. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/FDDE9819-D939-4F3C-B33F-979CAF853C6F/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/8b3057a3-b60d-4b0d-94b5-c0a927dfc093/FDDE9819-D939-4F3C-B33F-979CAF853C6F/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.techdirt.com/articles/20081001/0217292422.shtml" href="http://www.techdirt.com/articles/20081001/0217292422.shtml" style="font-size: 11px;">www.techdirt.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.techdirt.com/articles/20081001/0217292422.shtml -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Is The Original Spyware Company Finally Dead?</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.techdirt.com/articles/20081001/0217292422.shtml --><DIV><br />
As the whole spyware (the companies in the space preferred the adware label) got a bad name, Gator first <A href="http://www.techdirt.com/articles/20031022/1420248_F.shtml">threatened to sue</A> anyone who called its product spyware, and then eventually decided to shed the baggage of the Gator name and <A href="http://techdirt.com/articles/20031029/2338247.shtml">renamed itself Claria</A>. &#8212; insisting that it was now a legitimate advertising firm.  Except, the charges of spyware kept flying in Claria&#8217;s direction.  The company <A href="http://www.techdirt.com/articles/20040812/0215203.shtml">tried and failed</A> to go public, and then, once again, insisted that it was <A href="http://techdirt.com/articles/20060321/1511205.shtml">getting out of the adware business</A> and <A href="http://www.techdirt.com/articles/20050214/2225207_F.shtml">moving into &#8220;behavioral advertising&#8221;</A> &#8212; which, most people realized was just another term for what it had been doing in the past.<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/FDDE9819-D939-4F3C-B33F-979CAF853C6F/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_021008033702"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021008033702&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=021008033702&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=021008033702&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_021008033702" /></a></P>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 11:37:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/product spyware">product spyware</category>
      <category domain="http://securityratty.com/tag/original spyware company">original spyware company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/gator">gator</category>
      <category domain="http://securityratty.com/tag/clarias direction">clarias direction</category>
      <category domain="http://securityratty.com/tag/adware business">adware business</category>
      <category domain="http://securityratty.com/tag/art thou">art thou</category>
      <category domain="http://securityratty.com/tag/adware label">adware label</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=635">A oldie but still not a goodie!</source>
    </item>
    <item>
      <title><![CDATA["Scareware" Vendors Sued]]></title>
      <link>http://securityratty.com/article/116941f75bd6ea940dba21e55c3187e7</link>
      <guid>http://securityratty.com/article/116941f75bd6ea940dba21e55c3187e7</guid>
      <description><![CDATA[This is good : Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of &quot;scareware&quot; purveyors, scam artists who use fake security alerts to frighten consumers into paying...]]></description>
      <content:encoded><![CDATA[<p>This is <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">good</a>:</p>

<blockquote>Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of "scareware" purveyors, scam artists who use fake security alerts to frighten consumers into paying for worthless computer security software.

<p>The case filed by the Washington attorney general's office names Texas-based Branch Software and its owner James Reed McCreary IV, alleging that McCreary's company caused targeted PCs to pop up misleading security alerts about security threats on the victims' computers. The alerts warned users that their systems were "damaged and corrupted" and instructed them to visit a Web site to purchase a copy of Registry Cleaner XP for $39.95.</blockquote></p>

<p>I would have thought that existing scam laws would be enough, but Washington state actually has a specific law about this sort of thing:</p>

<blockquote>The lawsuits were filed under Washington's Computer Spyware Act, which among other things punishes individuals who prey on user concerns regarding spyware or other threats. Specifically, the law makes it illegal to misrepresent the extent to which software is required for computer security or privacy, and it provides actual damages or statutory damages of $100,000 per violation, whichever is greater.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RIHdM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RIHdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=V0u2M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=V0u2M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:03:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alerts">alerts</category>
      <category domain="http://securityratty.com/tag/fake security alerts">fake security alerts</category>
      <category domain="http://securityratty.com/tag/week filed lawsuits">week filed lawsuits</category>
      <category domain="http://securityratty.com/tag/security alerts">security alerts</category>
      <category domain="http://securityratty.com/tag/filed">filed</category>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <category domain="http://securityratty.com/tag/washington attorney">washington attorney</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/lawsuits">lawsuits</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/scareware_vendo.html">"Scareware" Vendors Sued</source>
    </item>
    <item>
      <title><![CDATA[Frustrated researcher details iPhone security bugs]]></title>
      <link>http://securityratty.com/article/114cdfe50262c3f0542801c1b2a2d499</link>
      <guid>http://securityratty.com/article/114cdfe50262c3f0542801c1b2a2d499</guid>
      <description><![CDATA[Annoyed at Apple for failing to act, Israeli researcher Aviv Raff has disclosed details about a pair of iPhone security flaws that he first reported to the company in...]]></description>
      <content:encoded><![CDATA[Annoyed at Apple for failing to act, Israeli researcher Aviv Raff has disclosed details about a pair of iPhone security flaws that he first reported to the company in July.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:eb2b3c5fc3579885172b65022cf24d10:LHZJKsJ64JO5o2oZiIcG%2BBXdvI0cP8JtxurBMo5tP7HKYSeK9RJypZa6EepURa13LqJ25ct8vCwS'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0a722174b9e56c513728e526b36353c3:jEmjx1JIGseDrt0FJfTpsP3sz5Jtsh6%2FgAniTxoSzP82dlV7Gpt4PwnP9OXMc4IUF%2Fbr6UK%2Bz5eiVg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:06666bed768e310811e459b359b5f35f:yWAsCBamXP6absT4PNM5%2B693gFdjxxmPjc7Gi4mIh5b8PF30hkT5Eic2b44AviMNttUvt3M%2B84nJlA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:04e91a74b5c31a9ea19c004618a5f724:lY6yJCqT%2Fm4MPumLeDp0ZAk1nMI3%2Bubs%2BgebcSjOFSgi%2FmIdHGUaXsrK4QN9OZzz58CFyH0tSqrwcg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=392e66186d37f167de66963c10829394" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=392e66186d37f167de66963c10829394" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iphone security flaws">iphone security flaws</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/pair">pair</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/july">july</category>
      <category domain="http://securityratty.com/tag/act">act</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=392e66186d37f167de66963c10829394">Frustrated researcher details iPhone security bugs</source>
    </item>
    <item>
      <title><![CDATA[Skype says it was unaware of China message-logging]]></title>
      <link>http://securityratty.com/article/dfa804cb52ff75868a16fb882edee02f</link>
      <guid>http://securityratty.com/article/dfa804cb52ff75868a16fb882edee02f</guid>
      <description><![CDATA[Skype was unaware of a major privacy problem affecting Skype users in China, the company's president said...]]></description>
      <content:encoded><![CDATA[Skype was unaware of a major privacy problem affecting Skype users in China, the company's president said Thursday.]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/skype users">skype users</category>
      <category domain="http://securityratty.com/tag/unaware">unaware</category>
      <category domain="http://securityratty.com/tag/major privacy">major privacy</category>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <category domain="http://securityratty.com/tag/president">president</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://www.networkworld.com/news/2008/100208-skype-says-it-was-unaware.html?fsrc=rss-security">Skype says it was unaware of China message-logging</source>
    </item>
    <item>
      <title><![CDATA[Furniture maker uses NAC gear for more than NAC]]></title>
      <link>http://securityratty.com/article/99f89705a18f81f2306021804668c0c0</link>
      <guid>http://securityratty.com/article/99f89705a18f81f2306021804668c0c0</guid>
      <description><![CDATA[When Chad Clement joined worldwide office furniture maker Haworth 18 months ago, he discovered the company needed to get a handle on network...]]></description>
      <content:encoded><![CDATA[When Chad Clement joined worldwide office furniture maker Haworth 18 months ago, he discovered the company needed to get a handle on network security.]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/months ago">months ago</category>
      <category domain="http://securityratty.com/tag/chad clement">chad clement</category>
      <category domain="http://securityratty.com/tag/handle">handle</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://www.networkworld.com/news/2008/100208-forescout.html?fsrc=rss-security">Furniture maker uses NAC gear for more than NAC</source>
    </item>
    <item>
      <title><![CDATA[The asymmetry of data loss - data thief has an upper hand]]></title>
      <link>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</link>
      <guid>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</guid>
      <description><![CDATA[I read this awesome book by Dan Geer, Economics and Strategies of Data Security . This gave me structure for my thoughts about a complex topic such as data security
When a data owner's (a business)...]]></description>
      <content:encoded><![CDATA[<P>I read this&nbsp;awesome book by Dan Geer, <A href="http://www.verdasys.com/thoughtleadership/">Economics and Strategies of Data Security</A>. This gave me structure&nbsp;for my thoughts about a complex topic such as data security. </P>
<P>When&nbsp;a&nbsp;data owner's (a business)&nbsp;sensitive data is breached it is&nbsp;difficult to quantify the monetary loss. According to respectable survey sources, the average cost of sensitive data breach for a large size company is about $50,000. I am attempting here to think about this in simple mathametical terms:</P>
<P>There is a data breach. From the data owner's perspective the loss is:</P>
<P><FONT color=#3366ff>Loss&nbsp;= Cost to protect data&nbsp;+ Loss of business due to data theft aka cost of competitive disadvantage</FONT></P>
<P>From the data thief's perspective</P>
<P><FONT color=#3333ff>Net Gain= [Cost of producing the data&nbsp; *&nbsp; Data freshness factor] - Cost to steal the data + Profit of business due to data aka gain of competitive advantage</FONT></P>
<P>From the above two equations it is very clear that this is not a zero sum game. There is a clear cost asymmetry for a data owner and for a data thief. When there is an asymmetry there is an opportunity. Data owner&nbsp;would not even know that the&nbsp;data is lost because&nbsp;the original copy of the data may be still intact - data thief could have simply copied the data.&nbsp;Data theft does not look like&nbsp;a car theft, there is no vacuum left behind.&nbsp;</P>
<P><STRONG><EM>This motivates a data thief to keep the cost to steal low, steal highly valuable data that has&nbsp;a long shelf life and in a way that data owner will never even be aware of theft.</EM></STRONG></P>
<P>From&nbsp;a data thief's perspective, the cost to steal data if kept high would disincentive him. Moreover, Data freshness factor, i.e. how valuable this data is over period of time plays an important role.&nbsp;A good example is content of today's newspaper is hardly valuable tomorrow, but the content of newspaper two days ahead (if can be procured)would be invaluable. Data relevance is a function of time and other marketplace variables - &nbsp;Data freshness Factor accounts for that variable. A good way to discourage data thief is to increase his/her cost to steal the data. There are other inferences from the above equation. If there exists&nbsp;no competitive advantage&nbsp;with the stolen data, hardly any thief would even venture&nbsp;to steal the&nbsp;data in the first place. If the cost of producing data is very low, then probably thief can just produce the data himself and would not attempt to steal the data. If the cost of&nbsp;theft is kept high, it would definitely deter the data thief from stealing data using technical mechanisms, then the data thief would&nbsp;exploit weak links in data security&nbsp;such as use of social engineering to get access to the data.</P>
<P>From data owner perspective protecting data becomes very important. How much would the owner be willing to spend? Not definitely the cost equal to cost of producing the data. 1% to 10% of cost of producing data is considered prudent. For a data owner it is difficult to estimate cost of data protection of a specific data, because it is not easy to chunkify data protection costs. Moreover, as Dan Geer says in his book, a data owner has to protect himself from number of intruders not just one.</P>
<P><EM><STRONG>It pays for a data owner to: be aware of data breaches (or data leaks), employ appropriate&nbsp;mechanisms to protect the data; the cost of protection which&nbsp;is fractional cost of&nbsp;the valuable&nbsp;data and&nbsp;enhance information security awareness of personnel who handle the data.</STRONG></EM></P>
<P><STRONG><EM>Data loss is not a zero sum game. The advantage is in favor of a data thief (data thieves rather).&nbsp;Data owner does not give much thought&nbsp;on&nbsp;the value of data&nbsp;unless&nbsp;there is a data theft.&nbsp;But,&nbsp;a&nbsp;data thief&nbsp;has every reason to think about economics of data theft before he acts to steal the data else data thief won't survive in this game and he is very well aware of his advantageous position.</EM></STRONG></P>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:33:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data owner perspective">data owner perspective</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/thief">thief</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data freshness factor">data freshness factor</category>
      <category domain="http://securityratty.com/tag/data protection costs">data protection costs</category>
      <category domain="http://securityratty.com/tag/discourage data thief">discourage data thief</category>
      <category domain="http://securityratty.com/tag/protect data">protect data</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html">The asymmetry of data loss - data thief has an upper hand</source>
    </item>
    <item>
      <title><![CDATA[Mobile workers are leaking your data]]></title>
      <link>http://securityratty.com/article/aea347657fed81e92413e819a82347d8</link>
      <guid>http://securityratty.com/article/aea347657fed81e92413e819a82347d8</guid>
      <description><![CDATA[As workforces become increasingly mobile, lines are blurring between work life and personal life. This could lead to risky or reckless use of company IT resources, resulting in leakage of sensitive...]]></description>
      <content:encoded><![CDATA[As workforces become increasingly mobile, lines are blurring between work life and personal life. This could lead to risky or reckless use of company IT resources, resulting in leakage of sensitive data, according to a Cisco study.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:4ea7c2c997ac6f46c82141152ce06d3c:fPn1lNwKe%2FCzf6K%2FZbM4ZNDYITEzjkEO%2BQwuuYgHRODln5h1VheD8LHEF4WfSYjzKvaGs%2FaIcWlL'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7e355886e2624a11826fe661016e1d62:3ZS0x%2B%2Fb4svXKPd3PcySJvyApR2fmREIwK2lQk2s3rupdzvfwcETC%2B%2FXO36HUuBUL0z%2Fph61zWWZpA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cb1f27d5d7c8fafcb6055ecc337dd0ff:E3dep6NvP1bAsrHntm8cKGEptlFhLSKzAIByCa4BzhF%2Bav3HCrGONNtiGGXhV0cHfmqiglS67BqBgQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:38b25d67bfaec85ae3e6b9278d9407c8:R2UWpEhq9r1CDUlcUp0JmeCuPCj7EGKOqlCOkqaZEASp4ZfLeRA39SRPud8fteySdduvgShnFQq9QA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=203836244c192bf4d2c38576fa4084b9" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=203836244c192bf4d2c38576fa4084b9" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/personal life">personal life</category>
      <category domain="http://securityratty.com/tag/sensitive data">sensitive data</category>
      <category domain="http://securityratty.com/tag/cisco study">cisco study</category>
      <category domain="http://securityratty.com/tag/increasingly mobile">increasingly mobile</category>
      <category domain="http://securityratty.com/tag/resources">resources</category>
      <category domain="http://securityratty.com/tag/lead">lead</category>
      <category domain="http://securityratty.com/tag/lines">lines</category>
      <category domain="http://securityratty.com/tag/workforces">workforces</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=203836244c192bf4d2c38576fa4084b9">Mobile workers are leaking your data</source>
    </item>
  </channel>
</rss>
