<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: convenient]]></title>
    <link>http://securityratty.com/tag/convenient</link>
    <description></description>
    <pubDate>Mon, 25 Aug 2008 11:37:51 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Safe Computing During The Holiday Season]]></title>
      <link>http://securityratty.com/article/832646954f5f9c892ef83ef66398bd73</link>
      <guid>http://securityratty.com/article/832646954f5f9c892ef83ef66398bd73</guid>
      <description><![CDATA[The holiday season is a time of increased online activity. During the hustle and bustle that surrounds this time of year, whats more convenient than saving a little time (and money) by shopping and...]]></description>
      <content:encoded><![CDATA[The holiday season is a time of increased online activity. During the hustle and bustle that surrounds this time of year, whats more convenient than saving a little time (and money) by shopping and b...]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 11:32:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday season">holiday season</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/online activity">online activity</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/convenient">convenient</category>
      <category domain="http://securityratty.com/tag/surrounds">surrounds</category>
      <category domain="http://securityratty.com/tag/bustle">bustle</category>
      <category domain="http://securityratty.com/tag/hustle">hustle</category>
      <source url="http://www.net-security.org/article.php?id=1190">Safe Computing During The Holiday Season</source>
    </item>
    <item>
      <title><![CDATA[Use Encryption to Safeguard Your Data]]></title>
      <link>http://securityratty.com/article/ec3de127db603d8b8cd6c4d1f0fea00d</link>
      <guid>http://securityratty.com/article/ec3de127db603d8b8cd6c4d1f0fea00d</guid>
      <description><![CDATA[A discreetly tucked-away folder that contains your résumé, your tax returns, and other important files may be convenient for you, but it's also a gold mine for online crooks who steal and sell...]]></description>
      <content:encoded><![CDATA[A discreetly tucked-away folder that contains your résumé, your tax returns, and other important files may be convenient for you, but it's also a gold mine for online crooks who steal and sell digital data on a thriving black market.]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/discreetly tucked-away folder">discreetly tucked-away folder</category>
      <category domain="http://securityratty.com/tag/black market">black market</category>
      <category domain="http://securityratty.com/tag/gold mine">gold mine</category>
      <category domain="http://securityratty.com/tag/tax returns">tax returns</category>
      <category domain="http://securityratty.com/tag/online crooks">online crooks</category>
      <category domain="http://securityratty.com/tag/digital data">digital data</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/convenient">convenient</category>
      <category domain="http://securityratty.com/tag/rsum">rsum</category>
      <source url="http://www.networkworld.com/news/2008/111308-use-encryption-to-safeguard-your.html?fsrc=rss-security">Use Encryption to Safeguard Your Data</source>
    </item>
    <item>
      <title><![CDATA[Get a Windows Server on the Fly in the Amazon Cloud]]></title>
      <link>http://securityratty.com/article/d76698803ebfafb9786b04c89ddf8556</link>
      <guid>http://securityratty.com/article/d76698803ebfafb9786b04c89ddf8556</guid>
      <description><![CDATA[Amazon's EC2 (Elastic Compute Cloud) was cool enough with its initial platform. Now it is offering Windows support on the EC2 platform . Thanks to Jesper's Blog for the tip. Like a lot about the EC2,...]]></description>
      <content:encoded><![CDATA[<a href="http://www.eweek.com/c/a/Cloud-Computing/Amazon-and-Cloud-Computing/">Amazon's EC2 (Elastic Compute Cloud) was cool enough</a> with its initial platform. Now it is offering <a href="http://aws.amazon.com/windows/">Windows support on the EC2 platform</a>. Thanks to <a href="http://msinfluentials.com/blogs/jesper/archive/2008/10/24/need-a-spare-windows-box.aspx">Jesper's Blog</a> for the tip.

Like a lot about the EC2, this turns out to be really convenient for developers. Did you ever want to develop or test a Windows Web app on a real server, not just your test desktop, and not have to get a real server to do it? Now you can just virtualize up a Windows server in the cloud and it's yours: A virtual server running Windows Server 2003, SQL Server and all the .NET stuff preinstalled.

<a href="http://developer.amazonwebservices.com/connect/entry.jspa?externalID=1767&categoryID=100%20">A security white paper from Amazon</a> describes the configuration of the Windows system images available and their differences from a standard Windows Server installation. Setup from the user's standpoint looks really easy; Jesper said it took him 5 minutes.

A Security Configuration Wizard walks you through an attack surface reduction process, which helps you to turn off services that are not needed and restrict communications channels that should not be permitted. In the end you can save the image and spin off new ones to meet your new standards as necessary.

EC2 is a great development for developers and a great way for Amazon to leverage all the work it has put into building its infrastructure. I see a lot of opportunities available.
<p><a href="http://feedads.googleadservices.com/~a/oB3bliI9e8xgWRUXc4n3sQBHTso/a"><img src="http://feedads.googleadservices.com/~a/oB3bliI9e8xgWRUXc4n3sQBHTso/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/Vy537Y6vypQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 08:26:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/amazon">amazon</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/ec2">ec2</category>
      <category domain="http://securityratty.com/tag/ec2 platform">ec2 platform</category>
      <category domain="http://securityratty.com/tag/amazon describes">amazon describes</category>
      <category domain="http://securityratty.com/tag/real server">real server</category>
      <category domain="http://securityratty.com/tag/elastic compute cloud">elastic compute cloud</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/Vy537Y6vypQ/get_a_windows_server_on_the_fly_in_the_amazon_cloud.html">Get a Windows Server on the Fly in the Amazon Cloud</source>
    </item>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[Privacy In the Cloud: Show Me The Money]]></title>
      <link>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</link>
      <guid>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</guid>
      <description><![CDATA[Privacy is a lot like universal healthcare. Many agree its a good idea in concept, but few people want to pay for it
Richard Stallman - the man that gave us GNU - doesnt trust Cloud providers with his...]]></description>
      <content:encoded><![CDATA[<p><img class="alignright" style="float: right; border: 0; margin: 3px;" src="http://farm3.static.flickr.com/2052/2404940312_e759c4030d_m_d.jpg" alt="Locker" width="180" height="240" />Privacy is a lot like universal healthcare.  Many agree its a good idea in concept, but few people want to pay for it.</p>
<p>Richard Stallman - the man that gave us <a href="http://www.gnu.org/">GNU</a> - <a href="http://www.guardian.co.uk/technology/2008/sep/29/cloud.computing.richard.stallman">doesn&#8217;t trust Cloud providers with his data</a> and says you shouldn&#8217;t either.  Richard believes we should store our private data on our own computers using &#8216;free&#8217; (as in <a href="http://www.gnu.org/gnu/thegnuproject.html">freedom</a>) software.  The ironic part for Richard is that a significant portion of the Cloud is powered by open source software which he indirectly created (think <a href="http://gcc.gnu.org/">gcc</a>).</p>
<p>Richard sees it as a question of control.  Control is important but it isn&#8217;t the only variable.  Rather, I see it as a question of control, competence and economics.</p>
<p>The quick rebuttal to Richards&#8217; view is this: the average computer user is <a href="http://www.stallman.org/photos/rms-full-size.jpg">not as smart as you</a>.  Control is not the same as competence.  Control is about exercising choice, not about requiring everyone in the world to develop sufficient skills to protect complex hardware and software systems (aka their computer) against <a href="http://ddanchev.blogspot.com/">ever increasing threats</a>.</p>
<p>My view is that privacy is not &#8216;free&#8217;.  It comes at a cost.  Whether you run your own systems or rely on someone else to do it, there is a cost.  There is cost in designing and implementing mechanisms to support privacy.  Beyond upfront costs there are ongoing expenditures to ensure privacy is maintained e.g. maintaining access control lists, testing and applying security patches, data leakage prevention etc.  None of these things are &#8216;free&#8217;.</p>
<p>If we agree that privacy costs money then how much is your privacy worth?</p>
<p>Stop for a second - think of a number&#8230;  </p>
<p>Now did we all think of the <a href="http://pbskids.org/sesame/coloring/images/07_grover.gif">same number</a>?</p>
<p>The problem with a one size fits all approach to privacy is that we each place a different value on it.</p>
<p>Checking in on the <a href="http://epic.org/">EPIC</a> site, I saw this:  </p>
<blockquote><p>A new report from <a href="http://www.pewinternet.org/">Pew Internet and American Life Project</a> indicates that &#8220;cloud computing&#8221; applications, such as web-based email and other web apps, are raising new privacy concerns. The report <a href="http://www.pewinternet.org/press_release.asp?r=306" target="_blank">Use of Cloud Computing: Applications and Services</a> found that 69% of online Americans use webmail services, store data online, or use software programs such as word processing applications whose functionality is located on the web. At the same time, &#8220;users report high levels of concern when presented with scenarios in which companies may put their data to uses of which they may not be aware.&#8221; For example, 90% of respondents said that they &#8220;would be very concerned if the company at which their data were stored sold it to another party,&#8221; 80% say &#8220;they would be very concerned if companies used their photos or other data in marketing campaigns,&#8221; and 68% of &#8220;users of at least one of the six cloud applications say they would be very concerned if companies who provided these services analyzed their information and then displayed ads to them based on their actions.&#8221;</p></blockquote>
<p>What does that tell us?</p>
<p>The average (American) Internet user finds Cloud services convenient but has concerns about how their privacy might be affected by Cloud providers actions (duh!).  The survey identifies a lack of awareness in how private data is used in some consumer based Cloud services (consistent with web advertising awareness surveys).  </p>
<p>Unfortunately, the results of this survey are not very actionable.  The survey doesn&#8217;t mention whether these are all &#8216;free&#8217; Cloud services (we can only assume they are) or ask the respondents what their expectations of privacy are and how much they would be willing to pay for different privacy assurance levels. </p>
<p>On a sidenote, respondents were not asked if they had actually read the privacy agreement for the services they signed up to.  But the providers know if they did or not&#8230;  Or at least, they have the data to figure it out.  At sign up time they can measure the time between displaying the privacy agreement and the user clicking &#8216;I accept&#8217;.  If its just a few seconds then its pretty obvious there was more scrolling than reading going on.  But I think we can probably guess the answer without the data ;-).</p>
<p>I believe we need to be able to link expectation of privacy with cost.</p>
<ul>
<li>How much are you willing to pay for privacy?  What level of privacy assurance do you need?</li>
<li>How much is your Cloud Provider paying to protect your privacy today?  What privacy services could they reasonably offer if they had customers willing to pay?  How might this compare with how you manage your private data on your home computer today?</li>
</ul>
<p>The cynical view is that we expect privacy but don&#8217;t want to pay for it.  Its a bit like uptime - there is a parallel universe out there, where internal IT departments allegedly meet their 99.999% uptime SLAs, but when Gmail goes down, the Sergey Brin witchcraft dolls come out.</p>
<p>From a provider perspective, the &#8220;cost&#8221; of privacy invariably gets bundled under that line item called &#8216;Information Security&#8217;.  And don&#8217;t be fooled, the cost of privacy in reality is more than the salary of the person employed to be the privacy advocate (if there is one).  If we can&#8217;t see how much our providers are spending on our privacy then how can we judge if they are spending enough?  And what is enough?  And what can I get if I&#8217;m willing to pay a little extra?</p>
<p>Personally, I would rather we get some transparency around privacy costs and assessment of offerings.  However, without a sufficiently sized market of customers willing to pay for privacy assurance and Cloud Providers willing to be more open, I won&#8217;t hold my breath.</p>
<p>What about you?  Would you be prepared to pay for privacy?  Should providers be more transparent about what they do and don&#8217;t do and how they do it?<br />
 <br />
 </p>
<p> </p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/419000947" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 19:49:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/trust cloud providers">trust cloud providers</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/cloud providers actions">cloud providers actions</category>
      <category domain="http://securityratty.com/tag/cloud applications">cloud applications</category>
      <category domain="http://securityratty.com/tag/privacy costs money">privacy costs money</category>
      <category domain="http://securityratty.com/tag/privacy assurance levels">privacy assurance levels</category>
      <category domain="http://securityratty.com/tag/privacy assurance">privacy assurance</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/419000947/">Privacy In the Cloud: Show Me The Money</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Overcome the e-discovery and DLP .PST challenge]]></title>
      <link>http://securityratty.com/article/ca7beeab7f68d54f9c65c4f015109979</link>
      <guid>http://securityratty.com/article/ca7beeab7f68d54f9c65c4f015109979</guid>
      <description><![CDATA[PST files are convenient storage for users, but bad news for DLP control and e-discovery processes. Here's how to deal with...]]></description>
      <content:encoded><![CDATA[.PST files are convenient storage for users, but bad news for DLP control and e-discovery processes.  Here's how to deal with them.]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 03:53:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-discovery processes">e-discovery processes</category>
      <category domain="http://securityratty.com/tag/dlp control">dlp control</category>
      <category domain="http://securityratty.com/tag/pst files">pst files</category>
      <category domain="http://securityratty.com/tag/convenient storage">convenient storage</category>
      <category domain="http://securityratty.com/tag/bad news">bad news</category>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/overcome-the-ediscovery-and-dlp-pst-challenge-27188">Overcome the e-discovery and DLP .PST challenge</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More]]></title>
      <link>http://securityratty.com/article/457365225a8b72096232f2b375549cff</link>
      <guid>http://securityratty.com/article/457365225a8b72096232f2b375549cff</guid>
      <description><![CDATA[New version of Windows Mobile software to share cell data connections over Wi-Fi: Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.wmwifirouter.com/"><strong>New version of Windows Mobile software to share cell data connections over Wi-Fi:</strong></a> Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data connections over Wi-Fi, turning your phone into a micro-hotspot. The software can also share a cell connection via Bluetooth or USB. The software costs $30 or &euro;20, and requires Internet (Connection) Sharing (ICS), which some providers may have removed from your phone. (The company set the price at US$30 before the euro drop, so is offering a kind of discount over their real &euro;20 price for the moment.)</p>

<p><a href="http://www.nytimes.com/2008/09/11/technology/personaltech/11smart.html?_r=1&8cir&emc=cirb1&oref=slogin"><strong>The New York Times rounds up using cell phones as hotspots:</strong></a> Though the reporter, Bob Tedeschi, mentions the issue of having to have an unlimited data plan to avoid unpleasant charges, and worries about bad drains and malicious users, he doesn't note that many carriers don't allow this kind of sharing or routing without a separate "tethering" plan, that can run $20 or more per month. Also, U.S. carriers have now all imposed a 5 GB per month reasonable use cap; some will cut you off, some charge you more, some cancel your service based on exceeding this use.</p>

<p><a href="http://www.networkworld.com/news/2008/090908-ieee-considers-gigabit.html?hpg1=bn"><strong>Gigabit Wi-Fi? Someday:</strong></a> TechWorld considers the IEEE's Very High Throughput (VHT) study group, which wants to start work on 1 Gbps or faster Wi-Fi standard for completion in 2012. With 802.11n offering raw symbol rates up to 600 Mbps--even though no devices have shipped with the radios and antennas to offer that optional high speed yet--there's interest in other frequencies that would allow faster encodings, as well as aggregating multiple links to achieve high speed rates. My experience in testing and using 2.4 GHz with Draft N would show that wide or aggregated channels doesn't work very well. The article's writer, Peter Judge, notes that ultrawideband had potential (over short distances) to approach the gigabit mark, but that UWB hasn't really reached the market in any substantive way years after it was promised to be a big technology.</p>

<p><a href="http://www.nbc5i.com/news/17435300/detail.html"><strong>Flight attendants express concerns about in-flight broadband porn:</strong></a> When I've spoken to airlines, industry experts, and service providers, I find that they all have stories about how porn is viewed on computers, through DVD players, and in convenient magazine form on planes today. Adding the Internet may provide new salacious imagery, but the problem predates Internet access, and filtering Internet service is never as good a solution as a social one. Someone idiotic enough to view porn on a plane over the Internet is also stupid enough to bring along inappropriate DVDs they watch while seated next to children. Flight attendants already have the power vested in them to take care of this. The flight attendants for American might be expressing this concern as part of a bargaining issue, where their responsibilities but not commensurate pay have increased.</p>

<p><a href="http://www.kxly.com/Global/story.asp?S=8989329"><strong>Spokane ends free Wi-Fi:</strong></a> Remember Vivato? Boy, I sure do. A company with a reach far exceeding its grasp, Vivato initially powered Spokane's downtown network. The network has continued to run on some basis--I'm not sure using what equipment--and now will move from free to fee. OneEighty Networks will charge about $10 per month to cover the costs of the network, for which local businesses at one point chipped in.</p>

<p><a href="http://www.onair.aero/"><strong>Brazilian TAM airline signs up for in-flight calling, messaging:</strong></a> OnAir has signed up the Brazilian carrier TAM, which will deploy the service on its Airbus A320 craft. Brazil hasn't yet provided regulatory approval, so no launch date is noted. TAM is the largest domestic and international carrier for Brazil.</p>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 07:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/faster wi-fi standard">faster wi-fi standard</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software costs">software costs</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <source url="http://wifinetnews.com/archives/008436.html">Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More</source>
    </item>
    <item>
      <title><![CDATA[My LA Times Op Ed on Photo ID Checks at Airport]]></title>
      <link>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</link>
      <guid>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</guid>
      <description><![CDATA[Opinion
The TSA's useless photo ID rules
No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work
By Bruce Schneier
August 28, 2008
The...]]></description>
      <content:encoded><![CDATA[<p>Opinion</p>

<p><a href="http://www.latimes.com/news/opinion/la-oe-schneier28-2008aug28,0,3099808.story">The TSA's useless photo ID rules</a></p>

<p>No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work.</p>

<p>By Bruce Schneier </p>

<p>August 28, 2008</p>

<p>The TSA is tightening its photo ID rules at airport security. Previously, people with expired IDs or who claimed to have lost their IDs were subjected to secondary screening. Then the Transportation Security Administration realized that meant someone on the government's no-fly list -- the list that is supposed to keep our planes safe from terrorists -- could just fly with no ID. </p>

<p>Now, people without ID must also answer personal questions from their credit history to ascertain their identity. The TSA will keep records of who those ID-less people are, too, in case they're trying to probe the system.</p>

<p>This may seem like an improvement, except that the photo ID requirement is a joke. Anyone on the no-fly list can easily fly whenever he wants. Even worse, the whole concept of matching passenger names against a list of bad guys has negligible security value.</p>

<p>How to fly, even if you are on the no-fly list: Buy a ticket in some innocent person's name. At home, before your flight, check in online and print out your boarding pass. Then, save that web page as a PDF and use Adobe Acrobat to change the name on the boarding pass to your own. Print it again. At the airport, use the fake boarding pass and your valid ID to get through security. At the gate, use the real boarding pass in the fake name to board your flight.</p>

<p>The problem is that it is unverified passenger names that get checked against the no-fly list. At security checkpoints, the TSA just matches IDs to whatever is printed on the boarding passes. The airline checks boarding passes against tickets when people board the plane. But because no one checks ticketed names against IDs, the security breaks down.</p>

<p>This vulnerability isn't new. It isn't even subtle. I first wrote about it in 2006. I asked Kip Hawley, who runs the TSA, about it in 2007. Today, any terrorist smart enough to Google "print your own boarding pass" can bypass the no-fly list.</p>

<p>This gaping security hole would bother me more if the very idea of a no-fly list weren't so ineffective. The system is based on the faulty notion that the feds have this master list of terrorists, and all we have to do is keep the people on the list off the planes. </p>

<p>That's just not true. The no-fly list -- a list of people so dangerous they are not allowed to fly yet so innocent we can't arrest them -- and the less dangerous "watch list" contain a combined 1 million names representing the identities and aliases of an estimated 400,000 people. There aren't that many terrorists out there; if there were, we would be feeling their effects. </p>

<p>Almost all of the people stopped by the no-fly list are false positives. It catches innocents such as Ted Kennedy, whose name is similar to someone's on the list, and Islam Yusuf (formerly Cat Stevens), who was on the list but no one knew why.</p>

<p>The no-fly list is a Kafkaesque nightmare for the thousands of innocent Americans who are harassed and detained every time they fly. Put on the list by unidentified government officials, they can't get off. They can't challenge the TSA about their status or prove their innocence. (The U.S. 9th Circuit Court of Appeals decided this month that no-fly passengers can sue the FBI, but that strategy hasn't been tried yet.) </p>

<p>But even if these lists were complete and accurate, they wouldn't work. Timothy McVeigh, the Unabomber, the D.C. snipers, the London subway bombers and most of the 9/11 terrorists weren't on any list before they committed their terrorist acts. And if a terrorist wants to know if he's on a list, the TSA has approved a convenient, $100 service that allows him to figure it out: the Clear program, which issues IDs to "trusted travelers" to speed them through security lines. Just apply for a Clear card; if you get one, you're not on the list.</p>

<p>In the end, the photo ID requirement is based on the myth that we can somehow correlate identity with intent. We can't. And instead of wasting money trying, we would be far safer as a nation if we invested in intelligence, investigation and emergency response -- security measures that aren't based on a guess about a terrorist target or tactic.</p>

<p>That's the TSA: Not doing the right things. Not even doing right the things it does.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=0Nd83L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=0Nd83L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uz4JRL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uz4JRL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 01:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/no-fly list">no-fly list</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/transportation security administration">transportation security administration</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/ids">ids</category>
      <category domain="http://securityratty.com/tag/matches ids">matches ids</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/my_la_times_op.html">My LA Times Op Ed on Photo ID Checks at Airport</source>
    </item>
    <item>
      <title><![CDATA[Security Risks for Mobile Computing on Public WLANs: Hotspot Registration]]></title>
      <link>http://securityratty.com/article/045ceb9b510071422cbb772f26d49452</link>
      <guid>http://securityratty.com/article/045ceb9b510071422cbb772f26d49452</guid>
      <description><![CDATA[Wireless broadband internet access via hotspots is convenient for both the casual surfer and the internet-dependent teleworker. Unfortunately, current security technologies integrated into wireless...]]></description>
      <content:encoded><![CDATA[Wireless broadband internet access via hotspots is convenient for both the casual surfer and the internet-dependent teleworker. Unfortunately, current security technologies integrated into wireless LA...]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 11:37:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/current security technologies">current security technologies</category>
      <category domain="http://securityratty.com/tag/casual surfer">casual surfer</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/hotspots">hotspots</category>
      <category domain="http://securityratty.com/tag/teleworker">teleworker</category>
      <category domain="http://securityratty.com/tag/convenient">convenient</category>
      <source url="http://www.net-security.org/article.php?id=1171">Security Risks for Mobile Computing on Public WLANs: Hotspot Registration</source>
    </item>
  </channel>
</rss>
