<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: con]]></title>
    <link>http://securityratty.com/tag/con</link>
    <description></description>
    <pubDate>Sat, 16 Aug 2008 05:58:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Good Get Conned-When Trust is Biological]]></title>
      <link>http://securityratty.com/article/3190bf9fa3c48c293c4965ef526cb117</link>
      <guid>http://securityratty.com/article/3190bf9fa3c48c293c4965ef526cb117</guid>
      <description><![CDATA[Bruce Schnier linked to an interesting article a while back, discussing how brain chemistry causes you to trust people when demonstrate that they trust you, especially when theyre relying on you and...]]></description>
      <content:encoded><![CDATA[<p>Bruce Schnier<a rel="nofollow" target="_blank" href="http://www.schneier.com/blog/archives/2008/11/the_neuroscienc.html"> linked </a>to an interesting article a while back, discussing how brain chemistry causes you to trust people when demonstrate that they trust you, especially when they&#8217;re relying on you and may be vulnerable&#8230;interesting stuff:</p>
<blockquote><p>THOMAS is a powerful brain circuit that releases the neurochemical oxytocin when we are trusted and induces a desire to reciprocate the trust we have been shown&#8211;even with strangers. The key to a con is not that you trust the conman, <em>but that he shows he trusts you</em>. Conmen ply their trade by appearing fragile or needing help, by seeming vulnerable. Because of THOMAS, the human brain makes us feel good when we help others&#8211;this is the basis for attachment to family and friends and cooperation with strangers</p></blockquote>
<p>So my question: if real-life cons can easily<a rel="nofollow" target="_blank" href="http://blogs.psychologytoday.com/blog/the-moral-molecule/200811/how-run-a-con"> scam people</a> by appearing to depend on them, how does this affect the scams we see on the Net? Clearly some online cons rely on this method &#8212; the Nigerian bank scam being a prime example. It seems like social engineering scams particularly rely on this method &#8212; but not all scams. And of course many other vulnerabilities just seem to rely on people&#8217;s habits to just click links willy-nilly online, which is an impersonal event. If the net were a more personal place, we might see many more of those kinds of scams.</p>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 11:00:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/trust people">trust people</category>
      <category domain="http://securityratty.com/tag/online cons rely">online cons rely</category>
      <category domain="http://securityratty.com/tag/rely">rely</category>
      <category domain="http://securityratty.com/tag/scams">scams</category>
      <category domain="http://securityratty.com/tag/easily scam people">easily scam people</category>
      <category domain="http://securityratty.com/tag/nigerian bank scam">nigerian bank scam</category>
      <category domain="http://securityratty.com/tag/powerful brain circuit">powerful brain circuit</category>
      <category domain="http://securityratty.com/tag/impersonal event">impersonal event</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/471798036/">The Good Get Conned-When Trust is Biological</source>
    </item>
    <item>
      <title><![CDATA[The Neuroscience of Cons]]></title>
      <link>http://securityratty.com/article/1612b3705bc2d5e59aa4c3d5c4ee99ae</link>
      <guid>http://securityratty.com/article/1612b3705bc2d5e59aa4c3d5c4ee99ae</guid>
      <description><![CDATA[Fascinating : The key to a con is not that you trust the conman, but that he shows he trusts you . Conmen ply their trade by appearing fragile or needing help, by seeming vulnerable. Because of THOMAS...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blogs.psychologytoday.com/blog/the-moral-molecule/200811/how-run-a-con">Fascinating</a>: </p>

<blockquote>The key to a con is not that you trust the conman, <i>but that he shows he trusts you</i>. Conmen ply their trade by appearing fragile or needing help, by seeming vulnerable. Because of THOMAS [The Human Oxytocin Mediated Attachment System], the human brain makes us feel good when we help others--this is the basis for attachment to family and friends and cooperation with strangers. "I need your help" is a potent stimulus for action.</blockquote>

<p>This is interesting.  They say that all cons rely on the mark's greed to work. But this short essay implies that greed is only a secondary factor.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xsRHN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xsRHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=7DDsN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=7DDsN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 03:32:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attachment system">attachment system</category>
      <category domain="http://securityratty.com/tag/attachment">attachment</category>
      <category domain="http://securityratty.com/tag/short essay implies">short essay implies</category>
      <category domain="http://securityratty.com/tag/cons rely">cons rely</category>
      <category domain="http://securityratty.com/tag/human oxytocin">human oxytocin</category>
      <category domain="http://securityratty.com/tag/greed">greed</category>
      <category domain="http://securityratty.com/tag/secondary factor">secondary factor</category>
      <category domain="http://securityratty.com/tag/human brain">human brain</category>
      <category domain="http://securityratty.com/tag/potent stimulus">potent stimulus</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_neuroscienc.html">The Neuroscience of Cons</source>
    </item>
    <item>
      <title><![CDATA[Show 032 - An Interview with Jeremiah Grossman]]></title>
      <link>http://securityratty.com/article/b0449f2ccd72f29ee2665301bb7c2d9e</link>
      <guid>http://securityratty.com/article/b0449f2ccd72f29ee2665301bb7c2d9e</guid>
      <description><![CDATA[The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman. Gary and Jeremiah discuss clickjacking, cross-site request...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Jeremiah Grossman" title="Jeremiah Grossman" src="http://www.cigital.com/silverbullet/jgrossman-125.png" style="padding-left: 7px;" /></p>
<p>The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.</p>
<ul>
<li><a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a></li>
<li><a href="http://jeremiahgrossman.blogspot.com/2008/10/clickjacking-web-pages-can-see-and-hear.html">Clickjacking</a></li>
<li><a href="http://www.webadminblog.com/index.php/2008/09/24/new-0day-browser-exploit-clickjacking-owasp-appsec-nyc-2008/">Adobe 0-day Browser Exploit</a></li>
<li><a href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf">Cross-Site Request Forgeries: Exploitation and Prevention</a> [PDF]</li>
<li><a href="http://www.cs.princeton.edu/sip/pub/spoofing.php3">Web Spoofing: An Internet Con Game</a> by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2007/05/web-application-scan-o-meter.html">Web application scan-o-meter</a></li>
<li><a href="http://1.bp.blogspot.com/_JdybrokZBAk/SO_rUc-ebPI/AAAAAAAABOY/dKbFPJfv1Cs/s1600-h/badgewall.jpg">The &#8220;Wall of Fame&#8221;</a></li>
</ul>
<p></p>
]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 23:17:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/jeremiah grossman">jeremiah grossman</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/web application scan-o-meter">web application scan-o-meter</category>
      <category domain="http://securityratty.com/tag/chief technology officer">chief technology officer</category>
      <category domain="http://securityratty.com/tag/internet con game">internet con game</category>
      <category domain="http://securityratty.com/tag/whitehat security">whitehat security</category>
      <category domain="http://securityratty.com/tag/conferences jeremiah">conferences jeremiah</category>
      <category domain="http://securityratty.com/tag/32nd episode">32nd episode</category>
      <category domain="http://securityratty.com/tag/prevention pdf">prevention pdf</category>
      <source url="http://www.cigital.com/silverbullet/show-032/">Show 032 - An Interview with Jeremiah Grossman</source>
    </item>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/4f1c46cc8d2c53438d8656355e1bfa74</link>
      <guid>http://securityratty.com/article/4f1c46cc8d2c53438d8656355e1bfa74</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>
<p><a href="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/a"><img src="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/H4w0W-ygK2s" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/H4w0W-ygK2s/i.php">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/91dad2a3ec5ac9d4f78bd2d1a2bb18c2</link>
      <guid>http://securityratty.com/article/91dad2a3ec5ac9d4f78bd2d1a2bb18c2</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/215684d0c6bd7ef7ac4756e6b556cf79</link>
      <guid>http://securityratty.com/article/215684d0c6bd7ef7ac4756e6b556cf79</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>
<p><a href="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/a"><img src="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/f9ViIhlukDU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/f9ViIhlukDU/i.php">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[The Psychology of Con Men]]></title>
      <link>http://securityratty.com/article/3f555c636d79a33adf94d30184296085</link>
      <guid>http://securityratty.com/article/3f555c636d79a33adf94d30184296085</guid>
      <description><![CDATA[Interesting : My all-time favourite [short con] only makes the con artist a few dollars every time he does it, but I absolutely love it. These guys used to go door-to-door in the 1970s selling...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.abc.net.au/rn/lawreport/stories/2008/2376933.htm">Interesting</a>:</p>

<blockquote>My all-time favourite [short con] only makes the con artist a few dollars every time he does it, but I absolutely love it. These guys used to go door-to-door in the 1970s selling lightbulbs and they would offer to replace every single lightbulb in your house, so all your old lightbulbs would be replaced with a brand new lightbulb, and it would cost you, say $5, so a fraction of the cost of what new lightbulbs would cost. So the man comes in, he replaces each lightbulb, every single one in the house, and does it, you can check, and they all work, and then he takes all the lightbulbs that he's just taken from the person's house, goes next door and then sells them the same lightbulbs again. So it's really just moving lightbulbs from one house to another and charging people a fee to do it.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aYL9M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aYL9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dKvMM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dKvMM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 01:57:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lightbulbs">lightbulbs</category>
      <category domain="http://securityratty.com/tag/single">single</category>
      <category domain="http://securityratty.com/tag/single lightbulb">single lightbulb</category>
      <category domain="http://securityratty.com/tag/house">house</category>
      <category domain="http://securityratty.com/tag/lightbulb">lightbulb</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/door-to-door">door-to-door</category>
      <category domain="http://securityratty.com/tag/absolutely love">absolutely love</category>
      <category domain="http://securityratty.com/tag/con artist">con artist</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_psychology_1.html">The Psychology of Con Men</source>
    </item>
    <item>
      <title><![CDATA[Lords debate Personal Internet Security]]></title>
      <link>http://securityratty.com/article/e68b4f70acd9eac9c340126b268863eb</link>
      <guid>http://securityratty.com/article/e68b4f70acd9eac9c340126b268863eb</guid>
      <description><![CDATA[Last Friday the House of Lords debated their Science and Technology Committees report on Personal Internet Security (from Summer 2007) and because the Governments response was so weak the additional...]]></description>
      <content:encoded><![CDATA[<p>Last Friday the House of Lords <a href="http://www.publications.parliament.uk/pa/ld200708/ldhansrd/text/81010-0006.htm#08101048000005">debated</a> their Science and Technology Committee&#8217;s report on <a href="http://www.publications.parliament.uk/pa/ld200607/ldselect/ldsctech/165/165i.pdf">Personal Internet Security</a> (from Summer 2007) and &#8212; because the Government&#8217;s response was so weak &#8212; the <a href="http://www.publications.parliament.uk/pa/ld200708/ldselect/ldsctech/131/131.pdf">additional follow-up report</a> that was published in Spring 2008. Since I had acted as the specialist adviser to the Committee, I went down to Westminster to sit &#8220;<a href="http://www.parliament.uk/about/glossary.cfm?ref=belowth_5748">below the bar</a>&#8220;, in one of the best seats in the House, and observe.</p>
<p><a href="http://www.theyworkforyou.com/peer/lord_broers">Lord Broers</a>, the Committee Chairman during the first inquiry, kicked things off, followed by various Lords who had sat on the Committee (and two others who hadn&#8217;t) then the opposition lead, Viscount Bridgeman, who put his party&#8217;s point of view (of which more in another article). Lord Brett (recently elevated to a <a href="http://en.wikipedia.org/wiki/Lord-in-Waiting">Lord in Waiting</a> &#8212; ie a whip), then replied to the debate and finally Lord Broers summarised and formally moved the &#8220;take note&#8221; motion which, as is custom and practice, the Lords then consented to <em>nem con</em>.</p>
<p>The Government speech in such a debate is partially pre-written, and should then consist of a series of responses to the various issues raised and answers to the questions put in the previous speeches. The Minister himself doesn&#8217;t write any of this, that&#8217;s done by civil servants from his department, sitting in a special &#8220;box&#8221; at the end of the chamber behind him.</p>
<p>However, since the previous speeches were so strongly critical of the Government&#8217;s position, and so many questions were put as to what was to be done next, I was able to see from my excellent vantage point (as TV viewers would never be able to) the almost constant flow of hastily scribbled notes from the box to the Minister &#8212; including one note that went to Lord Broers, due to an addressing error by the scribblers!</p>
<p>The result of this barrage of material was that Lord Brett ended up with so many bits of paper that he completely gave up trying to juggle them, read out just one, and promised to write to everyone concerned with the rest of the ripostes.</p>
<p>Of course it didn&#8217;t help that he&#8217;d only been in the job for five days and this was his first day at the dispatch box. But the number of issues he had to address would almost certainly have flummoxed a five-year veteran as well.</p>
<p>Amusing though this might be to watch, this does not bode well for the Government getting to grips with the issues raised in the reports. In technical areas such as &#8220;Personal Internet Security&#8221;, policy is almost entirely driven by the civil servants and not by the politicians.</p>
<p>So it is particularly disappointing that the pre-written parts of the Minister&#8217;s speech &#8212; the issues that the civil servants expected to come up and which they felt positive about addressing &#8212; were only a small proportion of the issues that were actually addressed in the debate.</p>
<p>It still seems as if the <a href="http://i.abcnews.com/2020/story?id=3131332&#038;page=1">penny hasn&#8217;t dropped</a> in Whitehall <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 18:57:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal internet security">personal internet security</category>
      <category domain="http://securityratty.com/tag/lord">lord</category>
      <category domain="http://securityratty.com/tag/lord broers">lord broers</category>
      <category domain="http://securityratty.com/tag/lords">lords</category>
      <category domain="http://securityratty.com/tag/civil servants">civil servants</category>
      <category domain="http://securityratty.com/tag/box">box</category>
      <category domain="http://securityratty.com/tag/lord brett">lord brett</category>
      <category domain="http://securityratty.com/tag/dispatch box">dispatch box</category>
      <category domain="http://securityratty.com/tag/issues">issues</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/13/lords-debate-personal-internet-security/">Lords debate Personal Internet Security</source>
    </item>
    <item>
      <title><![CDATA[This American Life on Scamming the Scammers]]></title>
      <link>http://securityratty.com/article/a0f43444bc9afa0cd221b17cea1a78e0</link>
      <guid>http://securityratty.com/article/a0f43444bc9afa0cd221b17cea1a78e0</guid>
      <description><![CDATA[A recent episode of This American Life featured a couple of Nigerian scammers who were being scammed by three other guys. Does it serve them right or is it just dangerous? Either way, its good once in...]]></description>
      <content:encoded><![CDATA[<p>A recent episode of &#8220;This American Life&#8221; featured a couple of Nigerian scammers &#8212; who were being scammed by three other guys. Does it serve them right or is it just dangerous? Either way, it&#8217;s good once in a while to see a case where the scammers get scammed back, instead of unwitting consumers.</p>
<p>From the <a rel="nofollow" target="_blank" href="http://consumerist.com/5050068/listen-to-these-vigilantes-scam-nigerian-419-scammers">Consumerist</a>:</p>
<blockquote><p>Last week, &#8220;This American Life&#8221; featured a 30-minute piece on people who scam the scammers—in this case, three guys who prey upon small-time Nigerian con men and <a rel="nofollow" target="_blank" href="http://www.thisamericanlife.org/Radio_Episode.aspx?episode=363">try to trick them into placing themselves in mortal danger</a>. &#8220;This American Life&#8221; tells how they almost got a guy to enter a Western Union office in Chad carrying an anti-Muslim/pro-Bush note that announces his intention to rob the place. Whether you think these stunts are funny probably depends on your level of empathy even for criminals, and whether you think the avengers ever fully succeed. But c&#8217;mon, getting someone in another country to <a rel="nofollow" target="_blank" href="http://forum.419eater.com/forum/viewtopic.php?t=133890">hold up a sign that&#8217;s offensive in your language</a> is pretty much <em>always</em> funny</p></blockquote>
<p>Listen to the episode over at<a rel="nofollow" target="_blank" href="http://www.thisamericanlife.org/Radio_Episode.aspx?episode=363"> this American Life.</a></p>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 10:58:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/american life">american life</category>
      <category domain="http://securityratty.com/tag/american life tells">american life tells</category>
      <category domain="http://securityratty.com/tag/scammers">scammers</category>
      <category domain="http://securityratty.com/tag/episode">episode</category>
      <category domain="http://securityratty.com/tag/recent episode">recent episode</category>
      <category domain="http://securityratty.com/tag/small-time nigerian con">small-time nigerian con</category>
      <category domain="http://securityratty.com/tag/nigerian scammers">nigerian scammers</category>
      <category domain="http://securityratty.com/tag/western union office">western union office</category>
      <category domain="http://securityratty.com/tag/mortal danger">mortal danger</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/395620772/">This American Life on Scamming the Scammers</source>
    </item>
    <item>
      <title><![CDATA[Corporate Identity Theft]]></title>
      <link>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</link>
      <guid>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</guid>
      <description><![CDATA[I remember a talk by the value investor Mason Hawkins (Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at...]]></description>
      <content:encoded><![CDATA[<p>I remember a <a href="http://www.bengrahaminvesting.ca/Resources/videos.htm#hawkins">talk</a>&#160;by the value investor&#160;<a href="http://en.wikipedia.org/wiki/Mason_Hawkins">Mason Hawkins</a>&#160;(Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at some point, where there is a rule of law. Here is one example of what he is worried about and why investing in places where your assets have no legal protection does not give the investor a margin of safety.</p><div>Hermitage Fund was until recently the largest fund in Russia. From the Business Week story<a href="http://hermitagefund.com/index.pl/news/article.html?id=895"> &quot;Hijacking the Hermitage Fund&quot;</a></div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>Corruption, intimidation, robbery, violent assault, forgery, large-scale fraud. No, not the subject of the latest John Grisham novel, but sensational allegations, made public Apr. 4 by Hermitage Capital Management -- until recently the largest foreign portfolio investor in Russia. In a detailed and damning report, titled Criminal Justice -- Russian-Style, Hermitage alleges the fund&#39;s Russian subsidiaries have fallen victim to an elaborate con designed to defraud the fund of hundreds of millions of dollars.&#160;<br />&#160;&#160;<br />The most sensational part of Hermitage&#39;s allegations is that the attempted larceny was carried out with the direct connivance of officials in the Russian police. Hermitage alleges the police seized documents and equipment that were instrumental to the attempted fraud, which involved bogus court cases based on forged documents, the aim of which was to sue Hermitage subsidiaries for hundreds of millions of dollars. &quot;The most shocking thing is not that there are corporate raiders in Russia who attempt to steal your shares,&quot; says Jamison Firestone, managing partner of Firestone Duncan, Hermitage&#39;s law firm. &quot;The shocking thing is that the police worked hand-in-hand with them, and actually performed the theft of the documents so that the corporate raiders could then do their work.&quot;</p></blockquote><div><br /><div>From the most recent Hermitage Fund letter, here is the current state:</div><br /><br /></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>So the two-pronged scam worked in one area and failed in another. The perpetrators weren’t able to steal the assets from us based on the fake court claims, but they were able to steal $230 million from the Russian government by filing amended tax returns on behalf of our stolen companies. What makes this story even more shocking is that we filed six 255-page criminal complaints with the Russian authorities in December last year, one month before the tax fraud took place, and they did nothing to stop it. Two complaints were sent to the Russian General Prosecutor, two to the Russian State Investigative Committee and two to the Internal Affairs Department of the Interior Ministry. There was enough information to prevent the fraud and indict a number of people behind it if the government had acted.&#160;</p><p>Instead of doing anything to save the Russian state from this highly sophisticated and organized looting, two of our complaints were thrown out immediately; two were returned to the same Interior Ministry official we were complaining about (essentially, he was being asked to “investigate himself”); and one was thrown out for “lack of any crime committed.” Only one complaint was taken seriously. It was taken up by the Russian State Investigative Committee in early February, but before it could get any traction, the case was lowered to the South region of the Moscow district of the State Investigative Committee (the lowest level of the Committee) and by June, another senior Interior Ministry official whom we had named in our complaint had joined the “investigation” team (again, to “investigate himself”). To this day there has been no serious response by the Russian authorities to this massive fraud against the Russian state.&#160;</p><p>As we described in our April letter, the problem of corporate “raiding” is now so endemic in Russia that President Medvedev speaks about it as one of the biggest problems faced by Russian businesses. In this case, raiders have taken this problem to a new and absurd extreme by “raiding” the Russian state itself and so far getting away with it. Together with HSBC, we will shortly be filing new criminal complaints with the Russian General Prosecutor and Russian State Investigative Committee as well as with many law enforcement authorities outside of Russia. It is hard to predict what will happen next in this unfolding and unbelievable saga, but as always we will keep you updated on any further developments as they arise.</p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><p>Of course we see individual identity theft on a regular basis (actually as Ross Anderson points out its not really identity theft but poor controls on the bank&#39;s parts using SSNs as secrets and so on), but you dont see a major corporation stolen every day.</p>]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 05:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian police">russian police</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian government">russian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/russian-style">russian-style</category>
      <category domain="http://securityratty.com/tag/hermitage">hermitage</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/corporate-identity-theft.html">Corporate Identity Theft</source>
    </item>
  </channel>
</rss>
