<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: computers]]></title>
    <link>http://securityratty.com/tag/computers</link>
    <description></description>
    <pubDate>Tue, 12 Aug 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[TSA Follies]]></title>
      <link>http://securityratty.com/article/f014b8f845713a3e6bc73c172d773b7c</link>
      <guid>http://securityratty.com/article/f014b8f845713a3e6bc73c172d773b7c</guid>
      <description><![CDATA[They break planes : Citing sources within the aviation industry, ABC News reports an overzealous TSA employee attempted to gain access to the parked aircraft by climbing up the fuselage... reportedly...]]></description>
      <content:encoded><![CDATA[<p>They <a href="http://www.aero-news.net/index.cfm?ContentBlockID=340a79d6-839a-470d-b662-944325cea23d">break planes</a>:</p>

<blockquote>Citing sources within the aviation industry, ABC News reports an overzealous TSA employee attempted to gain access to the parked aircraft by climbing up the fuselage... reportedly using the Total Air Temperature (TAT) probes mounted to the planes' noses as handholds.

<p>"The brilliant employees used an instrument located just below the cockpit window that is critical to the operation of the onboard computers," one pilot wrote on an American Eagle internet forum. "They decided this instrument, the TAT probe, would be adequate to use as a ladder."</blockquote></p>

<p>They <a href="http://www.cnn.com/2008/US/08/19/tsa.watch.list/index.html?iref=mpstoryview">harass innocents</a>:</p>

<blockquote>James Robinson is a retired Air National Guard brigadier general and a commercial pilot for a major airline who flies passenger planes around the country.

<p>He has even been certified by the Transportation Security Administration to carry a weapon into the cockpit as part of the government's defense program should a terrorist try to commandeer a plane.</p>

<p>But there's one problem: James Robinson, the pilot, has difficulty even getting to his plane because his name is on the government's terrorist "watch list."</blockquote></p>

<p>It's easy to <a href="http://edition.cnn.com/2008/US/08/19/tsa.watch.list/index.html">sneak by them</a>:</p>

<blockquote>The third-grader has been on the watch list since he was 5 years old. Asked whether he is a terrorist, he said, "I don't know."

<p>Though he doesn't even know what a terrorist is, he is embarrassed that trips to the airport cause a ruckus, said his mother, Denise Robinson.</p>

<p>[...]</p>

<p>Denise Robinson says she tells the skycaps her son is on the list, tips heavily and is given boarding passes. And booking her son as "J. Pierce Robinson" also has let the family bypass the watch list hassle.</blockquote></p>

<p>And <a href="http://www.i-hacked.com/content/view/267/48/">here's</a> how to sneak lockpicks past them.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8fHJ7K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8fHJ7K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LcgXdK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LcgXdK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 05:12:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flies passenger planes">flies passenger planes</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/planes">planes</category>
      <category domain="http://securityratty.com/tag/list hassle">list hassle</category>
      <category domain="http://securityratty.com/tag/sneak lockpicks past">sneak lockpicks past</category>
      <category domain="http://securityratty.com/tag/james robinson">james robinson</category>
      <category domain="http://securityratty.com/tag/denise robinson">denise robinson</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <category domain="http://securityratty.com/tag/pilot">pilot</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/tsa_follies.html">TSA Follies</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi]]></title>
      <link>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</link>
      <guid>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</guid>
      <description><![CDATA[Houston flips switch on free downtown Wi-Fi: Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://blogs.chron.com/techblog/archives/2008/08/it_lives_city_of_houston_turns_on_free_downto.html"><strong>Houston flips switch on free downtown Wi-Fi:</strong></a> Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid when they missed a milestone, and the firm later walked away.) The downtown area now has a limited pilot project that's free; the real effort in Houston is supposed to be at 10 housing projects and in parks where service would be used to bridge the digital divide and improve the quality of life. How, exactly, is part of what's being tested.</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/18/MNH312BTS1.DTL&hw=wi+fi&sn=004&sc=589"><strong>That's ASCII, not hex:</strong></a> An article on wardriving raises security hackles by repeating some slightly overheated statements about Wi-Fi security. The article opens with a 63-character ASCII WPA passphrase, which is later described as "hex." (ASCII passphrases in WPA can be up to 63 "printable" characters - ASCII 32 to 127 - while a hex version of a 256-bit TKIP or AES password is 64 hexadecimal digits long.) The article tries to conflate Wi-Fi attacks that led to the largest set of breaches in retail credit-card systems and wardriving, a hobbyist activity that's never been looked on very favorably by law enforcement. The sense of ennui of wardriving pioneers is pretty clear; when Wi-Fi is everywhere and generally secured, it's far less interesting. The wardriver in the article convinced the reporter that a maximum-length WPA passphrase stored on a USB drive for automatic use was the best way to go. But, really, 20 characters containing letters and punctuation and no words found in a dictionary along with changing your network's SSID (network name) provides all the security you'll ever need for a home or small business. (If you need more, deploy WPA/WPA2 Personal.)</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/16/BUA712BH1O.DTL&hw=wi+fi&sn=001&sc=1000"><strong>Green Wi-Fi's Senegal efforts hit snags:</strong></a> The folks at Green Wi-Fi are well motivated, and they're running up against all forms of security theater and bureaucracy both here and in Senegal, where they have an active project. The San Francisco Chronicle notes the group's effort to build solar-powered, self-sustaining Internet access via mesh networked nodes. Getting devices out of the country, clearing customs in Senegal, and hooking up their solar system all hit problems they're working through. As with the One Laptop Per Child program, I see a "build it and they will come" mentality in <a href="http://www.green-wifi.org/"><strong>Green Wi-Fi's mission statement</strong></a>: the notion that providing computing power and Internet access will result in good things, rather than an effort to figure out what good things need to be achieved, and whether computers and the Internet will assist. </p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 06:26:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi attacks">wi-fi attacks</category>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/wi-fi security">wi-fi security</category>
      <category domain="http://securityratty.com/tag/free downtown wi-fi">free downtown wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ascii">ascii</category>
      <category domain="http://securityratty.com/tag/security theater">security theater</category>
      <source url="http://wifinetnews.com/archives/008423.html">Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[Cyberattack Against Georgia Preceded Real Attack]]></title>
      <link>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</link>
      <guid>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</guid>
      <description><![CDATA[This is interesting: Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end,...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/13/technology/13cyber.html">This</a> is interesting:</p>

<blockquote>Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end, Georgia, with a population of just 4.6 million and a relative latecomer to the Internet, saw little effect beyond inaccessibility to many of its government Web sites, which limited the government's ability to spread its message online and to connect with sympathizers around the world during the fighting with Russia.

<p>[...]</p>

<p>In Georgia, media, communications and transportation companies were also attacked, according to security researchers. Shadowserver saw the attack against Georgia spread to computers throughout the government after Russian troops entered the Georgian province of South Ossetia. The National Bank of Georgia's Web site was defaced at one point. Images of 20th-century dictators as well as an image of Georgia's president, Mr. Saakashvili, were placed on the site. "Could this somehow be indirect Russian action? Yes, but considering Russia is past playing nice and uses real bombs, they could have attacked more strategic targets or eliminated the infrastructure kinetically," said Gadi Evron, an Israeli network security expert. "The nature of what's going on isn't clear," he said.</p>

<p>[...]</p>

<p>In addition to D.D.O.S. attacks that crippled Georgia's limited Internet infrastructure, researchers said there was evidence of redirection of Internet traffic through Russian telecommunications firms beginning last weekend. The attacks continued on Tuesday, controlled by software programs that were located in hosting centers controlled by a Russian telecommunications firms. A Russian-language Web site, stopgeorgia.ru, also continued to operate and offer software for download used for D.D.O.S. attacks.</blockquote></p>

<p>Welcome to 21st century warfare.</p>

<blockquote>"It costs about 4 cents per machine," Mr. Woodcock said. "You could fund an entire cyberwarfare campaign for the cost of replacing a tank tread, so you would be foolish not to."</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FRnMDK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FRnMDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=O8aHKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=O8aHKK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 09:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/indirect russian action">indirect russian action</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/georgian government">georgian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/russian troops">russian troops</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <category domain="http://securityratty.com/tag/georgia spread">georgia spread</category>
      <category domain="http://securityratty.com/tag/government web sites">government web sites</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/cyberattack_aga.html">Cyberattack Against Georgia Preceded Real Attack</source>
    </item>
    <item>
      <title><![CDATA[Old laws dont cover Cybercrime]]></title>
      <link>http://securityratty.com/article/f9bae1b796c4a6d1b215809f4cbd3027</link>
      <guid>http://securityratty.com/article/f9bae1b796c4a6d1b215809f4cbd3027</guid>
      <description><![CDATA[We really need to get our laws updated quickly. Cybercrime is up 20
Businesses are being targeted more routinely


clipped from www.crime-research.org

Scene of the Cybercrime: Inside Todays...]]></description>
      <content:encoded><![CDATA[<div>We really need to get our laws updated quickly. Cybercrime is up 20%.<br />
Businesses are being targeted more routinely.</div>
<table style="border: 4px solid #e5e5e5; margin: 12px 0px; background: #ffffff none repeat scroll 0%; font-family: arial; color: #333333; width: 100%; clear: left;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top">
<table class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top">
<table style="border-bottom: 1px solid #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee; background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><a title="go to this clipmark" href="http://clipmarks.com/clipmark/64B02289-0173-4D25-8D18-B2E876E5E3D6/"><img style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" src="http://content.clipmarks.com/blog_icon/a09d3640-cf18-4e6d-b96e-e15292ab93eb/64B02289-0173-4D25-8D18-B2E876E5E3D6/" border="0" alt="" width="19" height="19" /></a>clipped from <a style="font-size: 11px;" title="http://www.crime-research.org/news/10.08.2008/3498/" href="http://www.crime-research.org/news/10.08.2008/3498/">www.crime-research.org</a></td>
</tr>
</tbody>
</table>
<table style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/10.08.2008/3498/ --></p>
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Scene of the Cybercrime: Inside Today&#8217;s Cybercrime World</div>
</td>
</tr>
</tbody>
</table>
<table style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/10.08.2008/3498/ --></p>
<div>
<div></div>
<p>Today we live and work in a world of global connectivity. We can exchange casual conversation or conduct multimillion-dollar monetary transactions with people on the other side of the planet quickly and inexpensively. The proliferation of personal computers, easy access to the Internet, and a booming market for related new communications devices have changed the way we spend our leisure time and the way we do business.</p></div>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td style="background:transparent;border-width:0px;padding:0px;"></td>
<td style="border-width: 0px; padding: 0px; background: transparent none repeat scroll 0%; width: 107px;" width="107" align="right"><a title="blog or email this clip" href="http://clipmarks.com/share/64B02289-0173-4D25-8D18-B2E876E5E3D6/blog/"><img style="border-width:0px;padding:0px;margin:0px;" src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" /></a></td>
</tr>
</tbody>
</table>
</div>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 12:38:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/exchange casual conversation">exchange casual conversation</category>
      <category domain="http://securityratty.com/tag/planet quickly">planet quickly</category>
      <category domain="http://securityratty.com/tag/quickly">quickly</category>
      <category domain="http://securityratty.com/tag/communications devices">communications devices</category>
      <category domain="http://securityratty.com/tag/easy access">easy access</category>
      <category domain="http://securityratty.com/tag/monetary transactions">monetary transactions</category>
      <category domain="http://securityratty.com/tag/personal computers">personal computers</category>
      <category domain="http://securityratty.com/tag/leisure time">leisure time</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=561">Old laws dont cover Cybercrime</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack - Is it really this easy?]]></title>
      <link>http://securityratty.com/article/f6ec916b224830aa520ce767a8418965</link>
      <guid>http://securityratty.com/article/f6ec916b224830aa520ce767a8418965</guid>
      <description><![CDATA[A lot of the focus of the MBTA vs MIT case has been discussion of the CharlieCards . These are MiFare classic cards which have been known to be broken earlier this year . There is also a paper...]]></description>
      <content:encoded><![CDATA[<p>A lot of the focus of the MBTA vs MIT case has been discussion of the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieCards</a>.  These are MiFare classic cards which have been <a href="http://en.wikipedia.org/wiki/MIFARE#Security">known to be broken earlier this year</a>.  There is also a paper disposable card called the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieTicket</a> that uses a magnetic stripe.  The MIT students presentation states that these are cloneable and forgeable using a $150 magnetic stripe reader/writer.</p>
<p>From the <a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf">Confidential Memo Prepared for the MBTA</a> which was publicly disclosed by the MBTA is court filing:</p>
<p><a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf"><img class="alignnone size-full wp-image-241" title="memo-excerpt" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/memo-excerpt.png" alt="" width="678" height="127" /></a></p>
<p>This seems to break all the rules of integrity of sensitive data storage. How could someone store money on a magnetic stripe in 2008 and not store an identifier that references the account in a central database?</p>
<p>The tickets do have a unique identifier generated when the card is initially purchased so a fraud detection system could be in place or is planned. But this would require tracking the value on the ticket or the usage of the ticket centrally so it isn&#8217;t clear why the value is stored on the card in the first place.</p>
<p>There are so many question about the security of this public system.  Fraud costs the Massachusetts taxpayer money and refitting an insecure, ill-designed system costs the Massachusetts taxpayer money. [Disclosure: I am a Massachusetts taxpayer.]</p>
<p>It should be a requirement that the current system or the (hopefully) upgraded system be tested by an independent organization that specializes in cryptosystems.  If the independent testing uncovers vulnerabilities, they need to be fixed before the system is fielded. Then the system should be retested to verify the fixes.  Once the system is deemed secure by an independent organization, a summary of the test document should be published for public inspection.  It should include the types of testing conducted and the results.</p>
<p>The public trust requires inspection of taxpayer funded projects to make sure they meet acceptible standards and vendors held responsible for deficiencies.  Projects that use computers and software should not get a free pass. It will be interesting to see if the CharlieTicket system is ever held up to public scrutiny.</p>
<p><img src="file:///C:/DOCUME~1/cwysopal/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:19:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer">massachusetts taxpayer</category>
      <category domain="http://securityratty.com/tag/taxpayer">taxpayer</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/fraud detection system">fraud detection system</category>
      <category domain="http://securityratty.com/tag/system costs">system costs</category>
      <category domain="http://securityratty.com/tag/public system">public system</category>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer money">massachusetts taxpayer money</category>
      <category domain="http://securityratty.com/tag/charlieticket system">charlieticket system</category>
      <category domain="http://securityratty.com/tag/charlieticket">charlieticket</category>
      <source url="http://www.veracode.com/blog/?p=238">MBTA Hack - Is it really this easy?</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack: Is It Really This Easy?]]></title>
      <link>http://securityratty.com/article/1b9874427cf921ef00de8a56a8a8cab9</link>
      <guid>http://securityratty.com/article/1b9874427cf921ef00de8a56a8a8cab9</guid>
      <description><![CDATA[A lot of the focus of the MBTA vs MIT case has been discussion of the CharlieCards . These are MiFare classic cards which have been known to be broken earlier this year . There is also a paper...]]></description>
      <content:encoded><![CDATA[<p>A lot of the focus of the MBTA vs MIT case has been discussion of the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieCards</a>.  These are MiFare classic cards which have been <a href="http://en.wikipedia.org/wiki/MIFARE#Security">known to be broken earlier this year</a>.  There is also a paper disposable card called the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieTicket</a> that uses a magnetic stripe.  The MIT students presentation states that these are cloneable and forgeable using a $150 magnetic stripe reader/writer.</p>
<p>From the <a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf">Confidential Memo Prepared for the MBTA</a> which was publicly disclosed by the MBTA is court filing:</p>
<p><a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf"><center><img class="alignnone size-full wp-image-241 photoborder" title="memo-excerpt" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/memo-excerpt.png" alt="" width="576" height="108" /></center></a></p>
<p>This seems to break all the rules of integrity of sensitive data storage. How could someone store money on a magnetic stripe in 2008 and not store an identifier that references the account in a central database?</p>
<p>The tickets do have a unique identifier generated when the card is initially purchased so a fraud detection system could be in place or is planned. But this would require tracking the value on the ticket or the usage of the ticket centrally so it isn&#8217;t clear why the value is stored on the card in the first place.</p>
<p>There are so many question about the security of this public system.  Fraud costs the Massachusetts taxpayer money and refitting an insecure, ill-designed system costs the Massachusetts taxpayer money. [Disclosure: I am a Massachusetts taxpayer.]</p>
<p>It should be a requirement that the current system or the (hopefully) upgraded system be tested by an independent organization that specializes in cryptosystems.  If the independent testing uncovers vulnerabilities, they need to be fixed before the system is fielded. Then the system should be retested to verify the fixes.  Once the system is deemed secure by an independent organization, a summary of the test document should be published for public inspection.  It should include the types of testing conducted and the results.</p>
<p>The public trust requires inspection of taxpayer funded projects to make sure they meet acceptible standards and vendors held responsible for deficiencies.  Projects that use computers and software should not get a free pass. It will be interesting to see if the CharlieTicket system is ever held up to public scrutiny.</p>
<p><img src="file:///C:/DOCUME~1/cwysopal/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:19:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer">massachusetts taxpayer</category>
      <category domain="http://securityratty.com/tag/taxpayer">taxpayer</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/fraud detection system">fraud detection system</category>
      <category domain="http://securityratty.com/tag/system costs">system costs</category>
      <category domain="http://securityratty.com/tag/public system">public system</category>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer money">massachusetts taxpayer money</category>
      <category domain="http://securityratty.com/tag/charlieticket system">charlieticket system</category>
      <category domain="http://securityratty.com/tag/charlieticket">charlieticket</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hack-is-it-really-this-easy/">MBTA Hack: Is It Really This Easy?</source>
    </item>
    <item>
      <title><![CDATA[Anti-Georgia spammers building new botnet]]></title>
      <link>http://securityratty.com/article/fb40e81f04b22ace544dd6979a548459</link>
      <guid>http://securityratty.com/article/fb40e81f04b22ace544dd6979a548459</guid>
      <description><![CDATA[Hackers targeting Georgia in the midst of its conflict with Russia have started sending out a new batch of malicious spam messages, apparently with the aim of building a new botnet network of...]]></description>
      <content:encoded><![CDATA[Hackers targeting Georgia in the midst of its conflict with Russia have started sending out a new batch of malicious spam messages, apparently with the aim of building a new botnet network of remote-controlled computers.]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious spam messages">malicious spam messages</category>
      <category domain="http://securityratty.com/tag/botnet network">botnet network</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/apparently">apparently</category>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <category domain="http://securityratty.com/tag/conflict">conflict</category>
      <category domain="http://securityratty.com/tag/aim">aim</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/midst">midst</category>
      <source url="http://www.networkworld.com/news/2008/081508-anti-georgia-spammers-building-new.html?fsrc=rss-security">Anti-Georgia spammers building new botnet</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Meraki Modifies, Drops Standard; Tempe's Phoenix?; Remote Wake, Wi-Fi Need Not Apply]]></title>
      <link>http://securityratty.com/article/a930349b033e6f56c6098e0b152daddf</link>
      <guid>http://securityratty.com/article/a930349b033e6f56c6098e0b152daddf</guid>
      <description><![CDATA[Meraki reworks product line, drops new sales of community flavor: The cheap mesh router company has mutated slightly once again. The partly-Google-backed firm founded by MIT RoofNet &quot;graduates&quot; built...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://meraki.com/"><strong>Meraki reworks product line, drops new sales of community flavor:</strong></a> The cheap mesh router company has mutated slightly once again. The partly-Google-backed firm founded by MIT RoofNet "graduates" built the company on the notion that they could sell $50 routers that could mesh with each other, and use a robust central management system they developed. Over time, the $50 price didn't hold up for commercial networks of scale. Last October, the <a href="http://wifinetnews.com/archives/007973.html"><strong>company mishandled a change</strong></a> in its business model when they abruptly announced a $100 increase in price for newly purchased nodes under their Meraki Pro level for any network that wanted to control whether or not ads appeared, have user accounts, and charge for service. (They eventually <a href="http://wifinetnews.com/archives/007979.html"><strong>recovered, apologized, and reworked</strong></a> some of the transition details.) <img src="http://wifinetnews.com//images/2008/meraki_indoor.jpg" alt="meraki_indoor.jpg" border="0" width="175" height="111" align="right" />The company continued to offer a $50 indoor and $100 outdoor Standard level nodes for networks that required ads and had other limits. As of a few days ago, Standard is dead, and the Meraki mini has been upgraded to the <a href="http://meraki.com/products_services/hardware/indoor/"><strong>Meraki Indoor</strong></a> ($150). The Indoor has signal strength LEDs on the side for better help in placing units, an internal antenna, and better resilience against power fluctuations. The company <a href="http://meraki.com/support/faq/"><strong>explains its move</strong></a> in eliminating Standard by noting that most customers moved to Pro. It's not precisely the end of idealism (nor did that happen last October), as Meraki is still one of the major commercial mesh vendors, and their products are still vastly easier and a fraction of the cost of higher-end competitors.<br clear="all"></p>

<p><a href="http://www.eastvalleytribune.com/story/123037"><strong>New life for dead Tempe network?</strong></a> Another firm has expressed interest in buying the pennies on the dollar assets that remain of the former Kite Networks installation in Tempe from the firm that financed the venture as long as they can negotiate a new, more favorable deal with the city for mounting and removal rights. CTC, Inc., which the East Valley Tribune reports runs networks in the Kansas City, Mo., area, thinks there's an opportunity. The article notes that reception problems were due in part to the prevalence of stucco in Tempe, common in the southwest. Stucco walls layer plaster or other materials on a wire mesh for strength that turns a house into a bit of an accidental <a href="http://en.wikipedia.org/wiki/Faraday_cage"><strong>Faraday cage</strong></a>, partially shielding the home from electromagnetic radiation. (Could I go so far to say that Tempe's network could be a phoenix? Ouch.)</p>

<p><a href="http://www.usatoday.com/tech/products/2008-08-14-intel-wake-up-pcs_N.htm"><strong>Wake up, you darn computer:</strong></a> Intel's new Remote Wake motherboards won't work with Wi-Fi, it's important to note. The feature, announced today, will let an incoming VoIP call (the articles all say "phone call over the Internet") to wake a computer, as long as the call comes from a particular source. Of course, the standard SIP protocol for VoIP doesn't have the kind of security and integrity that would allow this; Intel has to overcome the problem with network address translation that renders most computer unreachable from outside the local network without a separate service like GoToMyPC or LogMeIn; and it will only work for computers connected via Ethernet to a local network, because Wi-Fi is off when a computer sleeps, while Ethernet can remain lightly active. I don't have the protocol details yet, but there's long been a <a href="http://en.wikipedia.org/wiki/Wake-on-LAN"><strong>Wake on LAN protocol</strong></a> that required support in a router, operating system, and Ethernet card; Intel may be leveraging this.</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:32:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meraki">meraki</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network address translation">network address translation</category>
      <category domain="http://securityratty.com/tag/dead tempe network">dead tempe network</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/tempe">tempe</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/meraki indoor">meraki indoor</category>
      <category domain="http://securityratty.com/tag/meraki mini">meraki mini</category>
      <source url="http://wifinetnews.com/archives/008420.html">Wee-Fi: Meraki Modifies, Drops Standard; Tempe's Phoenix?; Remote Wake, Wi-Fi Need Not Apply</source>
    </item>
    <item>
      <title><![CDATA[Former prosecutor: U.K. hacker's extradition is inevitable]]></title>
      <link>http://securityratty.com/article/21912b4d615b7460b2e5b2b700d67cdc</link>
      <guid>http://securityratty.com/article/21912b4d615b7460b2e5b2b700d67cdc</guid>
      <description><![CDATA[A European court has held up an order to extradite Gary McKinnon to the U.S. to face charges of hacking into military computers in New Jersey and...]]></description>
      <content:encoded><![CDATA[A European court has held up an order to extradite Gary McKinnon to the U.S. to face charges of hacking into military computers in New Jersey and Virginia.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=Yn1QM4"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=Yn1QM4" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/364284819" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/extradite gary mckinnon">extradite gary mckinnon</category>
      <category domain="http://securityratty.com/tag/military computers">military computers</category>
      <category domain="http://securityratty.com/tag/european court">european court</category>
      <category domain="http://securityratty.com/tag/virginia">virginia</category>
      <category domain="http://securityratty.com/tag/held">held</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/charges">charges</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/364284819/article.do">Former prosecutor: U.K. hacker's extradition is inevitable</source>
    </item>
    <item>
      <title><![CDATA[European court delays British hacker's extradition to U.S.]]></title>
      <link>http://securityratty.com/article/fee3d285466187c9a5077e40c3643b60</link>
      <guid>http://securityratty.com/article/fee3d285466187c9a5077e40c3643b60</guid>
      <description><![CDATA[Gary McKinnon, the London resident accused of hacking into U.S. military computers in 2001 and 2002, won't be extradited to face charges until Aug. 28 at the...]]></description>
      <content:encoded><![CDATA[Gary McKinnon, the London resident accused of hacking into U.S. military computers in 2001 and 2002, won't be extradited to face charges until Aug. 28 at the earliest.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=mvFR0T"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=mvFR0T" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/363216374" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/london resident">london resident</category>
      <category domain="http://securityratty.com/tag/military computers">military computers</category>
      <category domain="http://securityratty.com/tag/gary mckinnon">gary mckinnon</category>
      <category domain="http://securityratty.com/tag/aug">aug</category>
      <category domain="http://securityratty.com/tag/charges">charges</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/363216374/article.do">European court delays British hacker's extradition to U.S.</source>
    </item>
  </channel>
</rss>
