<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: costly]]></title>
    <link>http://securityratty.com/tag/costly</link>
    <description></description>
    <pubDate>Tue, 22 Jul 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The High Cost of Being Wrong: Why Data Detection Matters]]></title>
      <link>http://securityratty.com/article/3955f2f7da3fc70f757fc4bdf39c17c5</link>
      <guid>http://securityratty.com/article/3955f2f7da3fc70f757fc4bdf39c17c5</guid>
      <description><![CDATA[Imagine you see a car stopped on some train tracks, and you hear a train coming. How do you react? Do you ignore the sound of the train, thinking it wont hit the car? In that same vein, not having an...]]></description>
      <content:encoded><![CDATA[<p>Imagine you see a car stopped on some train tracks, and you hear a train  coming. How do you react? Do you ignore the sound of the train, thinking it  won&rsquo;t hit the car? In that same vein, not having an <strong>accurate</strong><strong> data loss prevention (DLP</strong>) <strong>solution</strong> in place within your  organization is akin to standing by and watching that train wreck about to  happen &ndash; all while pretending you can&rsquo;t see what&rsquo;s going on even though the  train&rsquo;s horn is blaring.</p>
<p>In my ten years of experience in the search and categorization space, I  can tell you that the risk of a DLP software policy allowing <strong>false negatives</strong>, when sensitive  documents are missed by the policy and considered safe, <strong>is potentially extremely costly to a company...</strong>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 04:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/train tracks">train tracks</category>
      <category domain="http://securityratty.com/tag/train">train</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/dlp software policy">dlp software policy</category>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/train wreck">train wreck</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/trains horn">trains horn</category>
      <category domain="http://securityratty.com/tag/false negatives">false negatives</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1372">The High Cost of Being Wrong: Why Data Detection Matters</source>
    </item>
    <item>
      <title><![CDATA[Of Planes and Ships]]></title>
      <link>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</link>
      <guid>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</guid>
      <description><![CDATA[Tom Barnett is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.thomaspmbarnett.com/weblog/2008/09/column_121.html">Tom Barnett</a> is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the &quot;nail it to the wall&quot; quote at the end):</p><p><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">One of the main problems in counterterrorism today is that there are so many people and vehicles, and so much data and material, moving through globalization&#39;s myriad networks that it seems virtually impossible to track it all effectively. Nowhere has this problem been more acute than on the high seas.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In 2006, Adm. Harry Ulrich, then U.S. commander of NATO Naval Forces Europe, decided to do something about it. Despite having virtually no resources, his dream was to transpose the global air-traffic control system onto sea traffic.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Worldwide, aircraft are transparent, because they&#39;re all required to carry an identification beacon that allows them to be tracked leaving and entering airports, and monitored between airports, by a global network of sensors. Act suspiciously and somebody&#39;s fighter aircraft will soon be on your tail.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">No such pervasive system currently exists globally for maritime traffic. While bigger ships carry an ID beacon similar to aircraft, without a shared monitoring network, that&#39;s like tracking only selected commercial jets and giving everyone else a pass.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">So Ulrich, upon taking command, asked a simple question: &quot;If we can do that in the air, why can&#39;t we do it on the sea?&quot; He made a point of pioneering his sea-traffic-control effort first inside the Mediterranean, where NATO&#39;s southern naval forces have historically been concentrated, but his real target was waters off Africa -- the most ungoverned maritime space in the world.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich knew the U. S. Navy couldn&#39;t do it alone, much less bring Africa&#39;s meager coast-guard-like navies up to snuff so they could do it on their own. So he quickly created a network of assets -- both public and private -- to manage that space, modeling his monitoring system on international air-traffic control.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich began stitching together a network of shore-based sensors ringing the Mediterranean. His naval command then began initial monitoring by tapping into the International Maritime Organization&#39;s existing Automated Identification System, transforming NATO&#39;s ability to track ship traffic in the Med.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Almost overnight, NATO went from tracking dozens of ships on the Mediterranean to thousands, and instead of getting the data sometimes up to 72 hours late, now the contacts were being tracked in one to five minutes -- to an accuracy within 50 feet on the earth&#39;s surface.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When the classic big-firm systems integrators told Ulrich it would be too costly to pull it off, the admiral turned to the Volpe Center in Cambridge, Massachusetts, a U.S. Department of Transportation research center. Instead of hundreds of millions of dollars, Ulrich&#39;s initial network cost $900,000. The shore-based receivers are small, roughly the size of a radar dish you might find on a pleasure craft.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The strength of the system is a function of its reach: the more countries join, the larger the shared operational picture. By the time Ulrich retired at the end of 2007, he had enlisted 32 countries throughout the Mediterranean, the North Atlantic, along the west coast of Africa, around the Black Sea, and in the Pacific. Today, the network continues to spread around the planet.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; font-size: 14px; line-height: 20px; "><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">With Ulrich&#39;s system in place, local police, coast guards, and border patrols catch most bad guys, obviating American military responses. As Harry told me for an article I wrote about his work in a fall 2007 issue of Esquire, </span><span style="font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;I don&#39;t do defense; I do security. When you talk defense, you talk containment and mutually assured destruction. When you talk security, you talk collaboration and networking. This is the future.&quot;</span></span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The admiral&#39;s legacy program, the Maritime Safety and Security Information System, earned the Volpe Center a prestigious &quot;Innovations in American Government&quot; award this month from Harvard University&#39;s Ash Institute for Democratic Governance and Innovation.</span></p></blockquote><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Security Collaboration + Networking &#160;= Federation. This is indeed the future - SAML came along just at the nick of time.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When you assume that to do access control you must have &quot;Complete Mediation&quot; in Saltzer and Schroeder&#39;s terms of the subject (users), the objects (data), the session, and the roles, then you are going to have an interesting life trying to deliver anything. And if you do it will mucho expensive.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">if you take the federated autonomous nodes approach, agree upon an attribute schema plus a protection model for same, and basic protocol, you are then free to move about the country. Security doesn&#39;t have to equal centralization or high cost. Get the attributes from point a to point b securely.</span></div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 19:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architect">security architect</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/identification system">identification system</category>
      <category domain="http://securityratty.com/tag/initial network cost">initial network cost</category>
      <category domain="http://securityratty.com/tag/initial">initial</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/ulrich">ulrich</category>
      <category domain="http://securityratty.com/tag/time ulrich">time ulrich</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/of-planes-and-ships.html">Of Planes and Ships</source>
    </item>
    <item>
      <title><![CDATA[Enough with all the passwords!]]></title>
      <link>http://securityratty.com/article/6349d38f11816f8e34daaa2d373f8621</link>
      <guid>http://securityratty.com/article/6349d38f11816f8e34daaa2d373f8621</guid>
      <description><![CDATA[Source: Novell) Typical companies have 70 or more applications requiring a password or similar credentials to get to them. Misplaced or forgotten passwords result in expensive, frequent calls to the...]]></description>
      <content:encoded><![CDATA[<b>(Source: Novell)</b> Typical companies have 70 or more applications requiring a password or similar credentials to get to them. Misplaced or forgotten passwords result in expensive, frequent calls to the help desk. Now there are single sign-on solutions to this costly dilemma and they could be the end to this down-side of application creep.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:dbd7f601c383df565f82c449845cd6f2:vIzNXqUQrbkV0UZsB2qohuIMIZm98NRfIoVT2%2BG24o5b7mCEHyJosYPDqnLSGyPV9iD4W4RsuXdVDHveOoCkYLM%2FLw3un2zOfTTd5BudDIM%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:6317f18fb9bc9af514a9da7248ae4fdd:F0yBVrNU%2BrZSBLsiytS0QwtEBEsGKiMjGKdpSVKGP5E%2Fbhz4H1HEiw5IiaOcDyk31bSBp47clAnFLnQf2pjQ6Y%2Fz7%2FuBzB9aJIxEapbo4ss%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:53d7b8bae04da0e0b4920e9a14da3621:DRl1PQnp%2BU1m0Y0H%2BXUk9Zv9jC3%2FnF%2Fe7EsOD%2FJJSvkMQTBWU8vihm3fvz75WzvRaQsZprWA3l7KyllsLd%2F6sliQKKWHbImYUf9cRnFwhVc%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:85282acbdc474bd27699943830a79f6a:2v0rpL1lFy4GwfS7sZjnEXpY%2BodDqHGg%2BkZS9KyzKP34i7DXt3Pud4X3P%2Bi3Pc47b832ywHhmGiM9InFvBSAI%2BPYMNWukQY7TcfyGEvIeO0%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a9455ee0a448c6dd770b96f91056a6e6" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a9455ee0a448c6dd770b96f91056a6e6" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/single sign-on solutions">single sign-on solutions</category>
      <category domain="http://securityratty.com/tag/passwords result">passwords result</category>
      <category domain="http://securityratty.com/tag/application creep">application creep</category>
      <category domain="http://securityratty.com/tag/frequent calls">frequent calls</category>
      <category domain="http://securityratty.com/tag/similar credentials">similar credentials</category>
      <category domain="http://securityratty.com/tag/costly dilemma">costly dilemma</category>
      <category domain="http://securityratty.com/tag/typical companies">typical companies</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/down-side">down-side</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a9455ee0a448c6dd770b96f91056a6e6">Enough with all the passwords!</source>
    </item>
    <item>
      <title><![CDATA[A Costly Crush]]></title>
      <link>http://securityratty.com/article/cafa2263c602a0dce807786d68e28098</link>
      <guid>http://securityratty.com/article/cafa2263c602a0dce807786d68e28098</guid>
      <description><![CDATA[I've seen a few blog posts over the last couple of days, with people complaining about an application on Facebook charging them crazy amounts of money. Certainly, there's a lot of angry Facebook users...]]></description>
      <content:encoded><![CDATA[
        I've seen a few <a href="http://www.sokhodom.com/2008-09-02-bad-facebook-application-lead-to-heavy-phone-bill/">blog posts</a> over the last couple of days, with people complaining about an application on Facebook charging them crazy amounts of money. Certainly, there's a lot of angry Facebook users out there:<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/crushtracker01.html" onclick="window.open('http://blog.spywareguide.com/images/crushtracker01.html','popup','width=387,height=448,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/crushtracker0-thumb-287x332.gif" alt="crushtracker0.gif" class="mt-image-none" style="" height="332" width="287" /></a></span>
<br />Click to Enlarge<br /></div><br />Some more complaints? Sure, I can do that:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush1.gif" src="http://blog.spywareguide.com/images/hugecrush1.gif" class="mt-image-none" style="" height="347" width="309" /></span></div><br /><br /><div align="left">There are many, many more like the above comments out there. One slight problem with all of this is that the complaints are scattered across a whole range of different Crush application forums - in short, they're <i>all</i> being blamed, but they can't <i>all</i> be doing this, can they? What's the alternative, though?<br /><br />A short while ago, I wrote about <a href="http://blog.spywareguide.com/2008/07/interesting-advert-placements.html">deceptive advert placements</a> with regards another facebook application. It seems we have a similar situation here, where an "enterprising" Ad network is placing Facebook-style buttons onto installer pages and hoping people will be fooled. As it turns out, it seems to be working. While attempting to install one randomly selected Crush application, I noticed the following advert at the top of the installer splash (highlighted in red):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush3.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush3.html','popup','width=660,height=320,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush3-thumb-360x174.gif" alt="hugecrush3.gif" class="mt-image-none" style="" height="174" width="360" /></a></span><br />Click to Enlarge<br /></div><br />It's easy to imagine a regular Facebook user thinking this is part of the application install and clicking "Ok". Do that, and you're taken to a site called Amazingchat(dot)net that throws up a fake message regarding you having "7 New Crush Messages" (and uses geolocational technology to point a targeted message your way). If you look like you're in the UK, you'll see this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush41.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush41.html','popup','width=662,height=404,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush4-thumb-362x220.gif" alt="hugecrush4.gif" class="mt-image-none" style="" height="220" width="362" /></a></span><br />Click to Enlarge<br /></div><br />Wow, FOUR of my (fake and non-existent) messages are from Sheffield! How about if I look like I'm in the States? You've guessed it....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush5.gif" src="http://blog.spywareguide.com/images/hugecrush5.gif" class="mt-image-none" style="" height="42" width="318" /></span></div>
<br /><br />Windy City, here I come!<br /><br />Not. It's looking promising so far, though. If we can just go to the next screen and see something utterly useless advertised in exchange for lots of money....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush666.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush666.html','popup','width=552,height=371,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush666-thumb-352x236.gif" alt="hugecrush666.gif" class="mt-image-none" style="" height="236" width="352" /></a></span><br />Click to Enlarge<br /></div><br />Horoscopes for only ?9 / $15 a week? WOW!<br /><br />Also, there go your savings.<br /><br />Could this be the site at the heart of so many complaints? Well, let's quickly check who runs it...<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush7.gif" src="http://blog.spywareguide.com/images/hugecrush7.gif" class="mt-image-none" style="" height="140" width="587" /></span><br /><br />"Sms-helpdesk", eh? I do believe I've seen a <a href="http://www.facebook.com/topic.php?uid=4874299673&amp;topic=3908">long thread</a> concerning people having issues with large bills for phone messages. Indeed, a rep from sms-helpdesk actually appears to be posting there:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush8.gif" src="http://blog.spywareguide.com/images/hugecrush8.gif" class="mt-image-none" style="" height="479" width="370" /></span></div><br /><br />Shame it seems some people can't even get through to the supposed helpline. Perhaps "Denise" would be better off tackling the deceptive placement of adverts made to look like installer buttons, not to mention non-existent crush messages based around geolocational targeting?<br /><br />Just a thought...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 11:24:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/facebook application">facebook application</category>
      <category domain="http://securityratty.com/tag/crush application">crush application</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/application install">application install</category>
      <category domain="http://securityratty.com/tag/regular facebook user">regular facebook user</category>
      <category domain="http://securityratty.com/tag/crush application forums">crush application forums</category>
      <category domain="http://securityratty.com/tag/angry facebook users">angry facebook users</category>
      <category domain="http://securityratty.com/tag/crush messages">crush messages</category>
      <source url="http://blog.spywareguide.com/2008/09/a-costly-crush.html">A Costly Crush</source>
    </item>
    <item>
      <title><![CDATA[Run Through PCI DSS 1.2 Changes]]></title>
      <link>http://securityratty.com/article/ce0e02f57e234e1b64d186272da31186</link>
      <guid>http://securityratty.com/article/ce0e02f57e234e1b64d186272da31186</guid>
      <description><![CDATA[Finally, I found time to read PCI DSS 1.2. change doc. So
Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network...]]></description>
      <content:encoded><![CDATA[<p>Finally, I found time to read PCI DSS 1.2. change doc. So:</p>  <ul>   <li>Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network device&quot; cloud) - see Req 1 </li>    <li>From the &quot;WTH dept&quot;: anti-virus is a MUST on <strong>ALL</strong> platforms - Req 5. Please ship me some of the stuff they are smoking; I want it! BTW, I am <a href="http://www.govcert.nl/symposium/index.html">going to Amsterdam soon</a> :-) </li>    <li>WAF or code review for web application security is still a stupid &quot;OR&quot; - Req 6.6. OMG, please, <a href="http://www.tssci-security.com/archives/2008/06/27/week-of-war-on-wafs-day-5-final-thoughts/">software security folks</a>, teach them the truth.</li>    <li>Can we kill &quot;plain text passwords&quot; once and for all? Req 8 tries to achieve that noble goal (good thing!) </li>    <li>Visit your offsite data storage - good (if costly) idea - added to Req 9. Requirements to secure electronic AND&#160; paper media&#160; are solid too.</li>    <li>Love it, love it! Req 10 explains that logs needs to be actually available: 'three months of audit trail history must be &#8220;<strong>immediately available for analysis</strong>&#8221; or <strong>quickly accessible'</strong> (bye-bye, silly log dumps...)</li>    <li>Some vulnerability stuff clarified in Req 11, mostly about ASVs and pentesting.</li>    <li>Scope of security policy is expanded to &quot;employee-facing technologies&quot; (what a term!) - Req 12</li>    <li>All over: more references to wireless&#160; (WEP, access points, hidden SSIDs, etc) - indeed, recent data losses are often due to insecure wireless.</li> </ul>  <p>Overall, a minor change that, sadly, doesn't touch a few KEY areas, such as virtualization, for one.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=oED2TK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=oED2TK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pUb9XK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pUb9XK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bX5cGK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bX5cGK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/375460383" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 07:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/req">req</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/offsite data storage">offsite data storage</category>
      <category domain="http://securityratty.com/tag/insecure wireless">insecure wireless</category>
      <category domain="http://securityratty.com/tag/audit trail history">audit trail history</category>
      <category domain="http://securityratty.com/tag/silly log dumps">silly log dumps</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/plain text passwords">plain text passwords</category>
      <category domain="http://securityratty.com/tag/vulnerability stuff">vulnerability stuff</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/375460383/run-through-pci-dss-12-changes.html">Run Through PCI DSS 1.2 Changes</source>
    </item>
    <item>
      <title><![CDATA[The Growing Security Skills Shortage]]></title>
      <link>http://securityratty.com/article/6f0a31fa5334384c34fb7f51cba96b5b</link>
      <guid>http://securityratty.com/article/6f0a31fa5334384c34fb7f51cba96b5b</guid>
      <description><![CDATA[We are regularly hearing from our security clients about their difficulties finding people with the right skills or when they do finally find them, these people are too costly to employ because their...]]></description>
      <content:encoded><![CDATA[<p><img title="Jonathan Penn" alt="Jonathan Penn" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Jonathan-Penn.gif" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></p>

<p>We are regularly hearing from our security clients about their difficulties finding people with the right skills – or when they do finally find them, these people are too costly to employ because their skills are in such demand.</p>



<p>Indeed, the “unavailability of people with the right skills” was cited as a top challenge for security groups in both our <a href="http://www.forrester.com/go?docid=44366">enterprise</a> and <a href="http://www.forrester.com/go?docid=44692">SMB</a> surveys.</p>



<p>In comparing need for talent across 25 different IT roles, Forrester analysts came to the conclusion that information security experts are among <a href="http://www.forrester.com/go?docid=46400">the hottest roles in IT</a>, sharing the top spot with information/data architects.</p>



<p>The skills shortage is likely to get worse before it gets better. We’re unlikely to see a significant spike in security experts’ salaries to attract those we need to hire: large changes in compensation for senior security personnel would run against the current of economic belt-tightening. Another typical approach to offsetting the shortage would be to train up: foster the career development and advancement of existing security personnel on our payroll. However, with all the outsourcing that is going on – and which will increasingly occur – there is a shrinking pool from which to find people with “the right stuff” worth championing their advancement.</p>



<p>We could look outside of security to others in IT, or even to co-workers in other departments or business groups. But given how poor a job IT Security does of marketing its value proposition, I don’t hold much hope for attracting non-security people.</p>



<p>What do you think? Are we about to hit a very big wall when it comes to skills and staffing? Are you presently feeling the pain of a skills shortage? Do you see such a shortage looming? What measures are you taking to acquire and nurture talent? Which ones are successful and why?</p>



<p>I welcome your thoughts on the topic.</p>

]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 05:02:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/senior security personnel">senior security personnel</category>
      <category domain="http://securityratty.com/tag/security clients">security clients</category>
      <category domain="http://securityratty.com/tag/security experts salaries">security experts salaries</category>
      <category domain="http://securityratty.com/tag/skills shortage">skills shortage</category>
      <category domain="http://securityratty.com/tag/shortage">shortage</category>
      <category domain="http://securityratty.com/tag/information security experts">information security experts</category>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/security personnel">security personnel</category>
      <source url="http://blogs.forrester.com/srm/2008/08/the-growing-sec.html">The Growing Security Skills Shortage</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Smackdown on data criminals]]></title>
      <link>http://securityratty.com/article/2fb6d43eeb3824a910e01d61357c7f4a</link>
      <guid>http://securityratty.com/article/2fb6d43eeb3824a910e01d61357c7f4a</guid>
      <description><![CDATA[The long arm of the law finally flexed in a major indictment of criminals who were charged with hacking and stealing credit cards from major retailers

Eleven folks were charged with the crimes...]]></description>
      <content:encoded><![CDATA[The long arm of the law finally flexed in a <a href="http://www.marketwatch.com/news/story/retail-hacking-ring-charged-stealing/story.aspx?guid=%7B0AD56640-FAC5-4DF4-8729-A0F5989438ED%7D&amp;dist=hppr">major indictment of criminals </a>who were charged with hacking and stealing credit cards from major retailers.<br /><br />Eleven folks were charged with the crimes ranging from conspiracy, computer intrusion, fraud and identity theft.<br /><br />Interesting nuggets from the report:<br /><ul><li>They hacked nine major U.S. retailers, stole and sold more than 40 million credit and debit card numbers...</li><li>Apparently this is the single largest and most complex identity theft case ever charged in this country</li></ul>"<span style="font-style: italic;">While technology has made our lives much easier it has also created new vulnerabilities. This case clearly shows how strokes on a keyboard with a criminal purpose can have costly results. Consumers, companies and governments from around the world must further develop ways to protect our sensitive personal and business information and detect those, whether here or abroad, that conspire to exploit technology for criminal gain,</span>" said U.S. Attorney Michael J. Sullivan.<br /><br />I agree with the US Attorney - we need better ways to prevent such hacking. But one point is clear again in this case - those who hack work for increasingly sophisticated criminal enterprises and will deploy significant resources to steal as long as the returns are worth it.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=3AbsmK"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=3AbsmK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=Eoj8uk"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=Eoj8uk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=7t5n4K"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=7t5n4K" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/356757053" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 17:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/major">major</category>
      <category domain="http://securityratty.com/tag/major indictment">major indictment</category>
      <category domain="http://securityratty.com/tag/complex identity theft">complex identity theft</category>
      <category domain="http://securityratty.com/tag/retailers">retailers</category>
      <category domain="http://securityratty.com/tag/major retailers">major retailers</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/attorney michael">attorney michael</category>
      <category domain="http://securityratty.com/tag/deploy significant resources">deploy significant resources</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/356757053/smackdown-on-data-criminals.html">Smackdown on data criminals</source>
    </item>
    <item>
      <title><![CDATA[Easy Google Income]]></title>
      <link>http://securityratty.com/article/78a5400adaadfa51b7dc44e905a348a8</link>
      <guid>http://securityratty.com/article/78a5400adaadfa51b7dc44e905a348a8</guid>
      <description><![CDATA[Here's an interesting piece of spam trying to cash in on the Google name that could wind up being quite costly for anyone willing to take a chance and see what it's all about. This was sent to one of...]]></description>
      <content:encoded><![CDATA[
        Here's an interesting piece of spam trying to cash in on the Google name that could wind up being quite costly for anyone willing to take a chance and see what it's all about. This was sent to one of my friends:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/goffer0.html" onclick="window.open('http://blog.spywareguide.com/images/goffer0.html','popup','width=537,height=530,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/goffer0-thumb-337x332.jpg" alt="goffer0.jpg" class="mt-image-none" style="" height="332" width="337" /></a></span><br /> </div><div><div align="center"><br />Click to Enlarge<br /></div><br />Is it a good thing or a bad thing that the office is based in the West Indies and to unsubscribe your email goes to Romania? At any rate, they don't seem to <a href="http://blog.spywareguide.com/images/goffer1.jpg">want my patronage</a> - unfortunately, I'm not particularly interested in free iPods or a Nintendo Wii so a few clicks later and I'm where I should be:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/goffer2.html" onclick="window.open('http://blog.spywareguide.com/images/goffer2.html','popup','width=878,height=697,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/goffer2-thumb-378x300.jpg" alt="goffer2.jpg" class="mt-image-none" style="" height="300" width="378" /></a></span><br /></div></div><div><div align="center"><br />Click to Enlarge<br /></div><br />At the bottom of the page, it says <i>"Google does not sponsor, endorse, and is no way affiliated with Easy Net Income or this promotion."</i><br /><br />Well, they could have fooled me what with all the Google material they've splashed across the site. The quote in the box is interesting, too: <i>"Riches range from a few hundred dollars a month to $50,000 or more a year".</i><br /><br />Go hunting on USA Today though, and the quote doesn't have anything to do with something called "Easy Google Income" - it's to do with <a href="http://www.usatoday.com/tech/news/2005-03-10-google-ads-usat_x.htm">Adsense</a>. Bits missing have been reinserted and bolded:<br /><br />"<b>Tales of AdSense</b> riches range from a few hundred dollars a month to
$50,000 or more a year, <b>though high-dollar paydays are rare. They
require a Web site with tons of traffic and the ability to put in
18-hour days working the system</b>.<br /><br />I think the missing parts are kind of important, don't you? Of course, the CD title clearly makes you think you're going to get some mysterious money magnet, but stops short of telling you whether it would be a program, ebook or magical leprechaun.<br /><br />In fact, what happens is you apparently sign up for the CD at the cost of subscribing yourself to some kind of "free trial" - at the end of which, you have to pay $39.90 a month for access to training courses to "Internet Wealth University" (I swear I'm not making this up). There's also an "activation fee" charged immediately to the card you subscribe with, though I'm guessing you only enter your details once you've entered your name / address and moved onto the second page (which I'm not about to do, in case you were wondering).<br /><br />Internet Wealth University must have an awful lot of poor students, going by the problems people are having <a href="http://www.ripoffreport.com/reports/0/356/RipOff0356749.htm">unsubscribing</a>.<br /><br /><i>"When you try to call the company, you get an automated answering system
that tells you all representatives are busy and then puts you on
hold-forever, or they disconnect you after 5 minutes!"</i><br /><br />Indeed, there's quite a lot of people <a href="http://answers.yahoo.com/question/index?qid=20080630072422AA4Irmi">wondering</a> what this is all about, including the <a href="http://www.friendsinbusiness.com/board1/index.cgi/noframes/read/136859">inevitable concern</a> over <a href="http://answers.yahoo.com/question/index?qid=20080419232112AAh35aR">billing issues</a>.<br /><br />Our advice? Steer well clear. There is a lot of money up for grabs here, but it's all being netted by the people running these websites. Their customers don't appear to be so lucky...<br /><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 13:58:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/easy google income">easy google income</category>
      <category domain="http://securityratty.com/tag/google material">google material</category>
      <category domain="http://securityratty.com/tag/adsense riches range">adsense riches range</category>
      <category domain="http://securityratty.com/tag/internet wealth university">internet wealth university</category>
      <category domain="http://securityratty.com/tag/adsense">adsense</category>
      <category domain="http://securityratty.com/tag/riches range">riches range</category>
      <category domain="http://securityratty.com/tag/mysterious money magnet">mysterious money magnet</category>
      <category domain="http://securityratty.com/tag/awful lot">awful lot</category>
      <source url="http://blog.spywareguide.com/2008/07/easy-google-income.html">Easy Google Income</source>
    </item>
    <item>
      <title><![CDATA[Aiming to make data-breach research easier]]></title>
      <link>http://securityratty.com/article/a03bc9484d5408e4cd632abaa5b82347</link>
      <guid>http://securityratty.com/article/a03bc9484d5408e4cd632abaa5b82347</guid>
      <description><![CDATA[The monstrous data breaches involving millions of records make all the headlines TJX, AOL, the Veterans Administration. However, it's those whoppers combined with the rat-a-tat-tat of seemingly daily...]]></description>
      <content:encoded><![CDATA[The monstrous data breaches involving millions of records make all the headlines — TJX, AOL, the Veterans Administration. However, it's those whoppers combined with the rat-a-tat-tat of seemingly daily divulgences involving lesser-known entities and fewer victims that add up to a costly and so-far-uncontrolled societal headache.]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monstrous data breaches">monstrous data breaches</category>
      <category domain="http://securityratty.com/tag/seemingly daily divulgences">seemingly daily divulgences</category>
      <category domain="http://securityratty.com/tag/societal headache">societal headache</category>
      <category domain="http://securityratty.com/tag/veterans administration">veterans administration</category>
      <category domain="http://securityratty.com/tag/headlines tjx">headlines tjx</category>
      <category domain="http://securityratty.com/tag/lesser-known entities">lesser-known entities</category>
      <category domain="http://securityratty.com/tag/fewer victims">fewer victims</category>
      <category domain="http://securityratty.com/tag/aol">aol</category>
      <category domain="http://securityratty.com/tag/records">records</category>
      <source url="http://www.networkworld.com/columnists/2008/072308netbuzz.html?fsrc=rss-security">Aiming to make data-breach research easier</source>
    </item>
  </channel>
</rss>
