<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: daughter]]></title>
    <link>http://securityratty.com/tag/daughter</link>
    <description></description>
    <pubDate>Mon, 28 Apr 2008 08:45:21 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[[Offtopic] Beginning Hacker]]></title>
      <link>http://securityratty.com/article/2edc744f41ac00b3f052fedc2a320f8d</link>
      <guid>http://securityratty.com/article/2edc744f41ac00b3f052fedc2a320f8d</guid>
      <description><![CDATA[My daughter and I were playing a little online Dora computer game today. As we got to one of the screens where you're supposed the click the letters Dora tells you to, Elise decided it would be more...]]></description>
      <content:encoded><![CDATA[My daughter and I were playing a little online Dora computer game today.  As we got to one of the screens where you're supposed the click the letters Dora tells you to, Elise decided it would be more fun to experiment with the game to see what happens when you click the wrong letters instead.  She liked the reaction from the game as it repeatedly tried to tell her the "right" thing to do and she deliberately ignored it.<br /><br />Makes me pretty proud - don't do what the software expects you to do, break the rules instead and see what happens.<br /><br />Courtesy of my friends at <a href="http://www.isecpartners.com/">iSec Partners</a>, here she is dressed in her hacker garb.<br /><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_o5jlQKhaoXk/SJ-pHSGfo0I/AAAAAAAAANo/0p9-CwtB6ps/s1600-h/IMG_2290_2.JPG"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_o5jlQKhaoXk/SJ-pHSGfo0I/AAAAAAAAANo/0p9-CwtB6ps/s400/IMG_2290_2.JPG" alt="" id="BLOGGER_PHOTO_ID_5233087234611061570" border="0" /></a><img src="http://feeds.feedburner.com/~r/SecurityRetentive/~4/362069048" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 10 Aug 2008 15:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/letters dora tells">letters dora tells</category>
      <category domain="http://securityratty.com/tag/software expects">software expects</category>
      <category domain="http://securityratty.com/tag/wrong letters">wrong letters</category>
      <category domain="http://securityratty.com/tag/isec partners">isec partners</category>
      <category domain="http://securityratty.com/tag/pretty proud">pretty proud</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/hacker garb">hacker garb</category>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/experiment">experiment</category>
      <source url="http://feeds.feedburner.com/~r/SecurityRetentive/~3/362069048/offtopic-begining-hacker.html">[Offtopic] Beginning Hacker</source>
    </item>
    <item>
      <title><![CDATA[Fugitive spammer dead in apparent murder-suicide]]></title>
      <link>http://securityratty.com/article/5eb33436e1926a40842af2cdf1f91a5d</link>
      <guid>http://securityratty.com/article/5eb33436e1926a40842af2cdf1f91a5d</guid>
      <description><![CDATA[Spammer and escaped convict Eddie Davidson shot his wife and three-year-old daughter before turning the gun on himself Thursday night in Bennet,...]]></description>
      <content:encoded><![CDATA[Spammer and escaped convict Eddie Davidson shot his wife and three-year-old daughter before turning the gun on himself Thursday night in Bennet, Colorado.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=OBwgMQ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=OBwgMQ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/345461372" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 07:29:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spammer">spammer</category>
      <category domain="http://securityratty.com/tag/thursday night">thursday night</category>
      <category domain="http://securityratty.com/tag/three-year-old daughter">three-year-old daughter</category>
      <category domain="http://securityratty.com/tag/wife">wife</category>
      <category domain="http://securityratty.com/tag/bennet">bennet</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/colorado">colorado</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/345461372/article.do">Fugitive spammer dead in apparent murder-suicide</source>
    </item>
    <item>
      <title><![CDATA[It's a crime-filled week in IT land]]></title>
      <link>http://securityratty.com/article/fe73c956a34a7a8e8fc8425dc546e0dd</link>
      <guid>http://securityratty.com/article/fe73c956a34a7a8e8fc8425dc546e0dd</guid>
      <description><![CDATA[In an unusual week for IT news, headlines were dominated by alleged crime, actual crime and crime that could be in the offing. Technical details of the dreaded DNS flaw were inadvertently released,...]]></description>
      <content:encoded><![CDATA[In an unusual week for IT news, headlines were dominated by alleged crime, actual crime and crime that could be in the offing. Technical details of the dreaded DNS flaw were inadvertently released, leading to publication of the attack code, there were more twists and turns in the story of the jailed San Francisco network administrator, and a convicted spammer who walked away from a minimum-security prison apparently killed his wife, their young daughter and himself. And, we sadly learned that Carnegie Mellon professor Randy Pausch died -- he inspired countless people with his "Last Lecture" that is a YouTube classic.]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crime">crime</category>
      <category domain="http://securityratty.com/tag/actual crime">actual crime</category>
      <category domain="http://securityratty.com/tag/dns flaw">dns flaw</category>
      <category domain="http://securityratty.com/tag/countless people">countless people</category>
      <category domain="http://securityratty.com/tag/technical details">technical details</category>
      <category domain="http://securityratty.com/tag/youtube classic">youtube classic</category>
      <category domain="http://securityratty.com/tag/attack code">attack code</category>
      <category domain="http://securityratty.com/tag/prison apparently">prison apparently</category>
      <category domain="http://securityratty.com/tag/unusual week">unusual week</category>
      <source url="http://www.networkworld.com/news/2008/072508-its-a-crime-filled-week-in.html?fsrc=rss-security">It's a crime-filled week in IT land</source>
    </item>
    <item>
      <title><![CDATA[How personal information wound up at the side of the road is a mystery]]></title>
      <link>http://securityratty.com/article/42893bd55f98a595373bc046f7b93a94</link>
      <guid>http://securityratty.com/article/42893bd55f98a595373bc046f7b93a94</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/10/08

Organization
Liberty Furniture

a North Carolina based company with Mid-South ties to Cromcraft - a furniture warehouse in Tate County&quot;,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/liberty.jpg" width="200" align="right" height="150"><font size="2"><b>Date Reported: </b><br>7/10/08<br><br><b>Organization: </b><br>Liberty Furniture*<br><br><font size="1">*"a North Carolina based company with Mid-South ties to Cromcraft - a furniture warehouse in Tate County", Mississippi.&nbsp; According to the report, Liberty Furniture may have gone out of business more than 20 years ago.</font><br><br><b>Contractor/Consultant/Branch:</b><br>Unknown<br><br><b>Victims:</b><br>Former employees<br><br><b>Number Affected:</b><br>"hundreds, maybe even thousands of people"<br><br><b>Types of Data:</b><br>Personal information including W-2 forms and tax forms containing names, addresses, and Social Security numbers<br><br><b>Breach Description:</b><br>"Eyewitness News Everywhere Uncovers the personal information of hundreds, maybe even thousands of people - dumped along a Mid-South road."<br><br><b>Reference URL:</b><br><a href="http://www.myeyewitnessnews.com/news/local/story.aspx?content_id=1601248c-3496-44ad-a2a3-053a779e9edf">Eyewitness News Everywhere</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Kevin Holmes, Eyewitness News Everywhere<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>Eyewitness News Everywhere Uncovers the personal information of hundreds, maybe even thousands of people - dumped along a Mid-South road.<br><span style="font-style: italic;">[Evan] For those readers who may be unsure where this "Mid-South" is located, in this case it is Mississippi.</span><br><br>We even found W-2 forms, tax forms with people's names, addresses and social security numbers.<br><br>Investigators in Tate County are trying to figure out how the papers got there.<br><br>Larry Davis made the discovery.<br><br>He says he was driving into town when he came across thousands of forms.<br><br>"That's just uncalled for...you are entrusting these people with a lot of information that could ruin you very quickly, but yet they treat it like it's trash," said Davis.<br><span style="font-style: italic;">[Evan] I think most people share Mr. Davis' feelings.&nbsp; It is puzzling.&nbsp; What was the person who dumped the information on the side of the road thinking, supposing the the person was thinking and supposing the information was dumped and not lost (i.e. fell off a truck).</span><br><br>Financial records, shipping order forms, and W-2's of former employees<br><br>"Stupidity on the person that threw it out on the road.&nbsp; The people who disposed of these, there should be some legal action against them, but to me that's mismanagement," said Davis.<br><span style="font-style: italic;">[Evan] Again, I think many people share the same feelings as Mr. Davis.</span><br><br>Many of the records are from Liberty Furniture, a North Carolina based company with Mid-South ties to Cromcraft - a furniture warehouse in Tate County<br><br>"There all from North Carolina, how did they get here?&nbsp; This is Mississippi.&nbsp; We got some strong wind, but they ain't that strong," says Davis. <br><br>Even Cromcraft employees were shocked when we brought this to their attention. <br><br>Most of the W-2's are from the late 1970's and early 80's.<br><span style="font-style: italic;">[Evan] Wow!&nbsp; These W-2's are 20-30+ years old?!</span><br><br>we're told Liberty Furniture went out of business more than twenty years ago.<br><br>Larry Davis' daughter Susan Herron said, "This could be someone's grandparents on fixed income, now their social security number is floating around somewhere and it's awful, people need to be more careful."<br><br>Eyewitness News Everywhere caught up with one of the former employees whose personal information was exposed. <br><br>"My initial feeling was a very sinking, horrified, scared, feeling....You feel vulnerable and hope your social security number hasn't fallen into the wrong hands.&nbsp; So I have to be diligent in checking my credit report," said the employee.<br><span style="font-style: italic;">[Evan] It is interesting to read how a person feels when they learn that their personal information has been compromised.&nbsp; I feel bad for these people.&nbsp; This employee doesn't need to feel "horrified and scared", but he/she does nonetheless, and it's all due to negligence.&nbsp; This is just one reason why information security is so personal to me.</span><br><br>Other former Liberty Furniture employees tell Eyewitness News Everywhere they will be doing the same thing - checking their credit report.<br><br>Eyewitness News Everywhere will keep those forms in a secure place until we hand them over to the proper authorities.<br><br><span style="font-weight: bold;">Commentary:</span><br>There is a lot of mystery surrounding this breach.&nbsp; How did the information get there?&nbsp; Why was the information still kept?&nbsp; Who was in possession of the information before it was found on the side of the road?&nbsp; Why wasn't the information already destroyed if the company who was responsible for it is no longer in business?<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/10/liberty.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 06:50:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/road">road</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/w-2 forms">w-2 forms</category>
      <category domain="http://securityratty.com/tag/liberty furniture employees">liberty furniture employees</category>
      <category domain="http://securityratty.com/tag/w-2">w-2</category>
      <category domain="http://securityratty.com/tag/eyewitness news">eyewitness news</category>
      <category domain="http://securityratty.com/tag/liberty furniture">liberty furniture</category>
      <source url="http://breachblog.com/2008/07/10/liberty.aspx">How personal information wound up at the side of the road is a mystery</source>
    </item>
    <item>
      <title><![CDATA[U.S. Arms Dealer Tests Legal Bounds in Middle East Arms Bazaar]]></title>
      <link>http://securityratty.com/article/a494b708fadf3d4f453c6495d8064dc2</link>
      <guid>http://securityratty.com/article/a494b708fadf3d4f453c6495d8064dc2</guid>
      <description><![CDATA[Former congressman Curt Weldon is helping broker deals between Russian and Ukranian weapons suppliers and the Iraqi and Libyan governments as part of his new job with a private American defense...]]></description>
      <content:encoded><![CDATA[<p>
Former congressman Curt Weldon is helping broker deals between Russian and Ukranian weapons suppliers and the Iraqi and Libyan governments as part of his new job with a private American defense consulting firm, Wired.com has learned. 
</p>

<p>
Weldon, who is currently being investigated by the FBI over alleged corruption during his time in office, visited Libya in March to discuss a possible military deal, according to a letter describing the trip from Weldon to <a href="http://www.ds-pa.com/">Defense Solutions</a> CEO Timothy Ringgold. In May, Weldon, together with Ringgold and another company representative, traveled to Moscow to discuss working with Russia's weapons-export agency on arms sales to the Middle East.
</p>

<p>
Both trips were part of the company's effort to tap into the growing -- and often legally murky -- market for selling weapons from former Eastern Bloc countries to the Middle East and Afghanistan.
</p>



<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 250px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/weldon_350px.jpg" width="250px" alt="Curt Weldon">

<div id="caption">

Ex-Rep. Curt Weldon, R-Penn., is helping broker deals between Russian weapons suppliers and the Iraqi and Libyan governments through his company, Defense Solutions.<br />
<em>Photo: H. Rumph Jr/AP</em>

</div> 

</div>

<p>
The Russians want to sell weapons to Iraq directly, but "must go slow on Iraq because of political reasons" and want to work with an "intermediary" like Defense Solutions, CEO Ringgold subsequently wrote to colleagues. "They have not spoken with any American company that can offer the quid pro quo that we can or that has the connections in Russia that we have," he boasted.
</p>



<p>
A few years ago, an American company proposing to sell weapons to Libya might have triggered a congressional hearing. So, too, would have a proposal to conduct arms deals with Russia, which the United States has accused of selling high-tech weapons to Syria and Iran. 
</p>

<p>However, U.S. government efforts to rapidly equip countries like Afghanistan and Iraq -- which have largely Soviet-origin weapons -- have created legal ambiguities and loopholes in export controls that didn't exist in years past and given rise to a new class of arms trade middlemen. So, even though both Libya and the Russian arms export agency are on official U.S. blacklists, government officials and analysts involved in weapons sales say the rules have become unclear as the push to equip allies in the global war on terror has blazed new but uncertain legal ground. 
</p>




<p>
Eagerly stepping into that virgin territory is <a href="http://www.ds-pa.com/">Defense Solutions</a>, a Pennsylvania-based company that is carving out a small but lucrative niche in a new international arms bazaar. The firm boasts as its advisors a number of influential Washington insiders, such as retired General Barry McCaffrey, the former White House drug czar.
</p>

<p>
Helping the firm make key connections is Curt Weldon, a former Republican congressman from Pennsylvania at the center of an FBI investigation into alleged conflicts of interest during his time in office.  Weldon, now a key executive at Defense Solutions, is working with the company to set up these weapons deals.
</p>

<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 350px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/btr_60_350px.jpg" alt="">

<div id="caption">

Defense Solutions has also proposed refurbishing Libya's BTR-60 armored personnel carriers, according to a sales proposal seen by Wired.com. Defense Solutions denies drafting a sales proposal to Libya.

</div> 

</div>

<p>
It's an unusual, if not an entirely unexpected chapter for Weldon, whose time in office included frequent trips to Russia. As an influential member of the House Armed Services Committee, Weldon pushed for multibillion-dollar defense programs, like ballistic missile defense, and earned a reputation as a foreign policy gadfly, boasting of his contacts with officials in nations labeled by the administration as "rogue states" such as Libya and North Korea. Weldon's wild claims about a 9/11 cover-up and his sensationalist book warning of an Iranian terror plot, sometimes earned him official scorn and public ridicule, but it was accusations that he steered contracts to Eastern European businesses linked to his daughter's lobbying firm that drew the government's attention.
</p>


<!--pagebreak-->
<p>
Weldon was voted out of office in 2006 just weeks after the FBI raided his daughter's home, and that of one of her associates.
</p>

<p>
Weldon did not respond to e-mails and phone requests to be interviewed or comment for this article. But in a 2006 interview, before the FBI probe was public, Weldon spoke enthusiastically about setting up a "front company" to work with the Russian arms agency, Rosoboronexport. Weldon hoped this company could sell weapons to the Middle East, and other regions, particularly to countries where the U.S. has strained relations. He claimed the director of Rosoboronexport approached him to work with "an American company that would act as a front for weapons these nations want to buy."
</p>

<p>
Weldon called the proposal an "unbelievable offer."
</p>

<p>
The administration, he acknowledged at the time, did not welcome the idea of an American company selling Russian weapons to potentially unfriendly countries. But two years later, Weldon, now a private citizen and chief strategic officer for Defense Solutions, appears to be working on precisely that sort of deal. And whether illegal or not, Defense Solutions' business represents a new phenomenon in the international arms trade business.
</p>

<p>
In years past arms brokers -- firms or individuals who serve as middlemen to facilitate weapons sales between countries -- were largely the stuff of spy thrillers. Unlike traditional American defense companies, like Lockheed Martin or Boeing, which typically sell weapons directly to NATO countries or other governments regarded as friendly to the United States, brokers are often small outfits run by people with sometimes questionable experience and reputations they will sell to anyone. One of the most infamous arms brokers, a Russian named <a href="http://en.wikipedia.org/wiki/Victor_Bout">Viktor Bout</a>, is charged by the United States, United Nations, Interpol and others of funneling arms to terrorists and rebels around the world. He was recently arrested in Thailand. The United States is requesting his extradition on charges of supplying arms to a terrorist organization.
</p>

<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 350px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/bmp_1_350px.jpg" alt="" />

<div id="caption">

Two Marines lower the trim vane on the front of an Iraqi BMP-1 mechanized infantry combat vehicle that was captured during Operation Desert Storm. The American defense consulting firm Defense Solutions has proposed refurbishing Libya's aging fleet of BMP-1s. Defense Solutions denies drafting a sales proposal to Libya.

</div> 

</div>

<p>
But ironically, Iraq has fueled a new market for these professional middlemen; the United States is funneling billions of dollars into modernizing Iraq's army so that the country's government can fend for itself after coalition troops withdraw. And Iraq's largely Soviet-equipped military is a natural market for Eastern European countries brimming with old or out-of-date equipment they would like to unload. The middlemen, in these cases, serve a key role by allowing the U.S. government to do business with an American company, which in turn buys equipment from Eastern Bloc countries in deals worth hundreds of millions of dollars, much of it financed with U.S. taxpayer dollars.
</p>

<p>
One of Defense Solutions' sales -- a deal to sell Hungarian-owed T-72 tanks to Iraq in 2005 -- was typical of these new foreign military sales. But on the more questionable side is the company's plans to work with Rosoboronexport, which is barred from doing business with the U.S. government, and Libya, which is still on the State Department's arms embargo list. 
</p>

<p>
The Eastern European-Middle East arms-brokering business, while in some cases sanctioned by the U.S. government, has run into problems, including outright corruption and quality. Defense contractor Dale Stoffel, the president of Wye Oak Technology, and another American were gunned down in Iraq in December 2004 after Stoffel alleged that the Iraqi Ministry of Defense was involved in a kickback scheme. Like Defense Solutions, the company Stoffel worked for was refurbishing the Iraq's army Eastern Bloc equipment.
</p>

<p>
Another problem is quality. Weapons from the former Soviet Bloc, which the U.S. military euphemistically calls "nonstandard equipment," have been flagged as substandard, acknowledges Brigadier General Charles Luckey, who is in charge of security assistance at <a href="http://www.mnstci.iraq.centcom.mil/">Multi-National Security Transition Command-Iraq</a>. In an interview from Iraq, Brigadier General Luckey said: "One of the frustrating things about buying nonstandard [weapons], is that I'm the guy who has to deal with the fact that some broker I've never heard of allowed weapons to get to Iraq before they were inspected."
</p>

<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 350px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/tank_350px.jpg" alt="" />

<div id="caption">

Defense Solutions is carving a new niche in the arms trade, selling Soviet-made weapons to Middle Eastern countries like Afghanistan and Iraq. Defense Solutions sold Hungarian-owed T-72 tanks to Iraq in 2005.

</div> 

</div>


<p>
In one high-profile case, Iraqi officials alleged that a corrupt firm sold them $400 million in shoddy helicopters from Poland. More recently, a company led by a 21-year-old and a former masseur was offered a U.S. government contract worth nearly $300 million to sell ammunition to Afghanistan. The ammunition turned out to be outdated and of dubious origin and several people connected with the company have been indicted. A congressional investigation concluded that the company, which was on a State Department watch list, was able to take advantage of regulatory loopholes by using middlemen.
</p>

<p>
For those concerned about illicit arms trade, this new wave of weapons deals is rife with the potential for corruption and abuse, but for companies eager to pursue markets once regarded as dubious, it represents a lucrative business opportunity.  The problem in these cases, according to those familiar with arms sales, is that it's no longer clear what's legal and what's not.
</p>
<!--pagebreak-->
<p>
Rachel Stohl, an expert on international arms trade and a senior analyst at Center for Defense Information, says that in many ways, the rush to equip Iraq has led the United States to throw caution to the wind. She points to a report by the Government Accountability Office last year that found that some 190,000 weapons sold to Iraq have gone missing. "I think the reality is we won't know, until way after the fact, about all of these irregularities with the Iraq weapons provision program," she said. "We were providing them all these assault rifles that have gone missing. Why? They were not following the standard procedures that were in place."
</p>

<p>
But Iraq and Afghanistan aren't the only markets available to arms brokers like Defense Solutions. The gradual normalization of relations with Libya opens another door into a quasi-legal area of sales. 
</p>

<p>
Like Iraq, Libya has a substantial arsenal of Soviet-origin military weapons, offering a potential market for brokers working with Russia and other former Soviet states. But even when there's not an outright ban, sales to the Middle East are often fraught with controversy, particularly to countries like Libya, which was under international sanction for more than a decade. Even as sanctions against it have been lifted, European companies proposing to sell arms to Libya have faced steep criticism, particularly since the country is still ruled by dictator Muammar Gaddafi, who took power in a military coup in 1969. 
</p>

<p>
While the United States lifted Libya's "state sponsor of terrorism" designation in 2006, other restrictions, such as on the sale of arms, remain in place. A State Department spokesperson confirmed that exports of "lethal munitions" to Libya, such as tanks or related equipment, are still banned, although sales of nonlethal equipment are now allowed on a case-by-case basis.
</p>

<p>
In late March, Weldon traveled to Libya for a weeklong trip at the invitation of the <a href="http://gdf.org.ly/index.php?lang=ar&Page=101&lang=en">Gaddafi Foundation</a>, a group run by the son of Libya's leader, and the chairman of Libya's foreign affairs committee, according to <a href="http://blog.wired.com/defense/files/libya_trip_report.doc">the report he sent to Defense Solutions</a> (.pdf), a copy of which was obtained by Wired.com. The trip reports states: "Agreement reached for Weldon to quickly return to Libya for meetings with son [of Libyan leader Gaddafi] Morti regarding defense and security cooperation."
</p>

<p>
A document dated April 16, just two weeks after Weldon's trip, outlines Defense Solutions' proposal to Libya to refurbish the country's fleet of armored vehicles, including its T-72 tanks, BMP-1 infantry fighting vehicles, and BTR-60 armored personnel carriers. A copy of the sales proposal, also provided to Wired.com, is on Defense Solutions' letterhead, appears to bear the signature of company CEO Timothy Ringgold, and is addressed to Libya's defense procurement council. "Defense Solutions is committed to delivering a full end-to-end solution to its clients," the proposal states. "Besides refurbishing these vehicles, we are capable of providing a full logistics support package, including a two year supply of spare parts, maintenance and repair services, and operator, maintenance, and repair training."
</p>

<p>
In an interview with Wired.com, Ringgold admitted that he's interested in doing business in Libya and confirms receiving Weldon's trip report from Libya, but denies drafting or signing an arms-sale proposal. "I've never made such a document to Libya," Ringgold insisted, after being read the proposal, and told that his signature is on it.
</p>

<p>
In addition to the Libyan arms-deal document, Wired.com has also reviewed copies of e-mails from Ringgold discussing the Libyan deal.
</p>

<p>
While Ringgold denies proposing an arms sale to Libya, he is open about speaking with Rosoboronexport, which has been on a U.S. government sanctions list since 2006, after the Russian state agency allegedly violated the Iran and Syria Nonproliferation Act. An April e-mail provided to Wired.com describes Ringgold, Weldon and Stephan Minikes, a senior advisor to Defense Solutions and a former ambassador, meeting with Rosoboronexport. The conversations included a number of potential deals, including supplying Mi-17 helicopters to Afghanistan and spare parts for Iraq's infantry fighting vehicles. Ringgold wrote to colleagues following the visit, describing the meetings as a "spectacular success," saying the Russian agency "has the ability to undercut all cost proposals from brokers."
</p>

<p>
Ringgold confirmed those discussions and said that his company has sought to do business with Rosoboronexport. Asked whether Ringgold considers his dealings with Russia to be legal, he argued that U.S. companies could work with Rosoboronexport on a "case-by-case" basis. "The particular purpose of the meeting we had -- and I want to be crystal clear -- was in response to a U.S. government requirement," he said.
</p>

<p>
A number of officials at the State Department and in the Pentagon, when contacted for this article, could not say whether working with Rosoboronexport is legal or not. A Pentagon spokeswoman said she was familiar with the issue, but deferred the question to the State Department. When asked about Rosoboronexport's status on the blacklist, John Herzberg, a State Department spokesman replied: "What's on there is on there."
</p>

<p>
Asked whether, given the ban, there was any way a company could legally work with Rosoboronexport, as Ringgold suggested, Herzberg provided an equivocal answer. "At the stage of the process we're at, I'm unable to give you an answer," he said. "You can try elsewhere in government, and maybe they'll be braver than me."
</p>

<p>
In an interview from Iraq, General Luckey conceded it was a murky area, but said, "My understanding is they are currently on our no-go list." 
</p>

<p>
The confusion over debarred parties has even led the U.S. government into its own legal tangles, according to Jim McAleese, a Washington attorney who specializes in government contracting and foreign military sales. Because the Russian government violated U.S. nonproliferation laws, even NASA had to go to Congress to ensure it could work with Russia on Soyuz flights to the international space station. "What I'm warning you about is, don't be surprised by the confusion," McAleese said. "There are a whole bunch of different statutes that were adopted piecemeal and were never intended to be reconciled."
</p>

<p>
But it's the very ambiguity of the law that troubles those who monitor export control. "It's highly unusual to do anything with the Russians, particularly Rosoboronexport," said Scott Jones, director of Export Control Programs at the <a href="http://www.uga.edu/cits/">Center for International Trade and Security</a> at the University of Georgia. 
</p>

<p>
Legal or not, reputable American companies simply don't want to work with banned entities, Jones said, for fear of risking their reputations and business. "Even if it's not an outright prohibition, most companies don't want to put themselves in a liability situation that has really bad PR … and they stay away from it," Jones said. "But if that's your business, pimping out arms from the U.S. or Russia, that's the way it works, and you push as much as possible."
</p>

<p>
Finding any U.S. defense company working with the Russian government at this point would be "remarkable," Jones added.
</p>

<p>
In the meantime, the future for Weldon is unclear. The FBI investigation continues and Weldon's former chief of staff recently pleaded guilty to a conspiracy charge and is cooperating with the government, notes Melanie Sloan, the executive director of <a href="http://www.citizensforethics.org/">Citizens for Responsibility and Ethics in Washington</a>, which filed a complaint against Weldon in 2004. Sloan speculated that Weldon may be charged with "honest service fraud" for misusing his office for personal gain. "It's an easier standard than bribery," she said. "I wouldn't be surprised [if he's charged] with bribery, but I think it will be honest services fraud."
</p>

<p>
Ringgold insists that he and Weldon are on the right side of the law. "Everything we do is in strict compliance with international and U.S. law and we operate only in the best interests of the U.S. government," he said. "I didn't serve 30 years in the United States Army to throw that away on a whim."
</p>

<p>
Asked if Weldon is still working for the company, Ringgold replied: "Absolutely, proudly so." 
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=3c1b81ed8ecb441b359b5fd6e6dec750" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=3c1b81ed8ecb441b359b5fd6e6dec750" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=f5EjSJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=f5EjSJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zYmkhj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zYmkhj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=S9Ojfj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=S9Ojfj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xPEQRJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xPEQRJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=OTsesJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OTsesJ" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=wFj1Jj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=wFj1Jj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=OExjrj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OExjrj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=DKk6TJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=DKk6TJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/326164069" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/326164070" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 18:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/arms brokers">arms brokers</category>
      <category domain="http://securityratty.com/tag/brokers">brokers</category>
      <category domain="http://securityratty.com/tag/infamous arms brokers">infamous arms brokers</category>
      <category domain="http://securityratty.com/tag/defense">defense</category>
      <category domain="http://securityratty.com/tag/firm defense solutions">firm defense solutions</category>
      <category domain="http://securityratty.com/tag/arms">arms</category>
      <category domain="http://securityratty.com/tag/arms trade">arms trade</category>
      <category domain="http://securityratty.com/tag/international arms trade">international arms trade</category>
      <category domain="http://securityratty.com/tag/russian weapons suppliers">russian weapons suppliers</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/326164070/defense_solutions">U.S. Arms Dealer Tests Legal Bounds in Middle East Arms Bazaar</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central bank">central bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/office email address">office email address</category>
      <category domain="http://securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[2.2 million billing records missing on stolen backup tape]]></title>
      <link>http://securityratty.com/article/5c8436d56efb6533033af7a1ca7f75d9</link>
      <guid>http://securityratty.com/article/5c8436d56efb6533033af7a1ca7f75d9</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/10/08

Organization
University of Utah

Contractor/Consultant/Branch
University of Utah Hospitals &amp; Clinics
Perpetual Storage, Inc

Victims
Patients
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/uhc.jpg" align="right" height="49" width="201"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/10/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.utah.edu/portal/site/uuhome/">University of Utah</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://healthcare.utah.edu/index.cfm">University of Utah Hospitals &amp; Clinics</a> <br><a href="http://www.perpetualstorage.com/index_home.htm">Perpetual Storage, Inc.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>"approximately 2.2 million"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, related demographic information and diagnostic codes" additionally, "Records for a subset of 1.3 million patients also contained Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"SALT LAKE CITY (AP) - Billing records of 2.2 million patients at the University of Utah Hospitals and Clinics were stolen from a vehicle after a courier failed to immediately take them to a storage center"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://healthcare.utah.edu/publicaffairs/news/current/billing_theft.html">University of Utah Hospitals &amp; Clinics</a> <br><a href="http://www.sltrib.com/ci_9540210">The Salt Lake Tribune</a> <br><a href="http://www.kutv.com/content/news/local/story.aspx?content_id=76de0817-3ffe-4f8e-9764-506795954fa1">Associated Press via KUTV Channel 2 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of Utah Hospitals &amp; Clinics<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>SALT LAKE CITY (AP) - Billing records of 2.2 million patients at the University of Utah Hospitals and Clinics were stolen from a vehicle after a courier failed to immediately take them to a storage center<br><span style="font-style: italic;">[Evan] There is no mention of encryption in any of the news reports I have read regarding this breach, so I am going to go ahead and assume that it was not used.&nbsp; As you read through the publicly available details of this breach below, you will probably agree that the courier driver made an idiotic mistake that he almost certainly regrets, but the University of Utah Hospitals &amp; Clinics is the custodian of this information that should have identified the risks involved with transporting confidential patient records off-site.&nbsp; One of those risks is the possibility that a backup tape may become lost of stolen, which is obviously the case in this breach.&nbsp; Where were preventative controls to account for this unacceptable (in most cases) risk, like encryption?</span><br><br>The records, described only as backup information tapes, contained Social Security numbers of 1.3 million people treated at the university over the last 16 years<br><br>people would be notified by a letter at a cost of $500,000 just for stamps and envelopes<br><span style="font-style: italic;">[Evan] How much would it have cost to encrypt the information on the tapes?&nbsp; The State of Utah has an exemption in their breach notification law for encrypted information.</span><br><br>The hospital also pledged free credit monitoring<br><br>The records were in a gray metal box<br><br>The courier, whose name was not released, picked them up in his Ford Explorer on June 1<br><br>instead of driving directly to a storage center, he worked a second job and then went home<br><span style="font-style: italic;">[Evan] This is the idiotic mistake I was writing about earlier.</span><br><br>The next day, he discovered that someone had broken into his Ford Explorer outside his Kearns home and taken the box<br><br>The driver worked for Perpetual Storage Inc. for 18 years and was fired.<br><br>Authorities declined to say how easy or difficult it would be to read the records.<br><br>The sheriff believes the thief probably thought the box contained money.<br><span style="font-style: italic;">[Evan] What it contains could probably be turned into a helluva lot of money!</span><br><br>"The investigation indicates that the theft was probably a random car burglary, and there is no evidence that the information on the tapes has been accessed or used for identity theft," said Salt Lake County Sheriff Jim Winder.<br><span style="font-style: italic;">[Evan] Eight days (June 2nd - June 10th) is probably a little too soon for evidence to appear of identity theft.</span><br><br>There's no evidence any of the information on the tapes has been accessed; besides, anyone trying to use the tapes would need specialized equipment to view the contents, Winder said.<br><span style="font-style: italic;">[Evan] Specialized equipment like a tape drive?</span><br><br>Eighty percent of the 2.2 million people live in Utah or Idaho, Betz said. The hospital is offering a $1,000 reward for the records. (Lorris Betz, M.D., Ph.D, Senior Vice President for Health Sciences)<br><br>The University of Utah Hospitals &amp; Clinics is offering a $1,000 reward for the return of the tapes, no questions asked.&nbsp; Those wishing to claim the reward may call the Sheriff’s Department at (801) 743-7000.<br>[Evan] To think of this in pure financial terms.&nbsp; A person could return the tape for $1,000 or could access the tape, sell the information and make maybe $5,000.000+.&nbsp;&nbsp;&nbsp; Maybe a good preventative control for organizations is to assume that criminals are stupid as part of your risk management program (seriously though, it's not).</font><br><font size="2"><br>"We understand this is unwelcome news to our patients," said Betz.<br><br>The university had worked with Perpetual Storage for 12 years before the theft<br><br>The University of Utah Hospitals &amp; Clinics has suspended deliveries of backup tapes to Perpetual Storage pending the review of all procedures and protocols for transporting and storing backup data.<br><br>Additionally, the health-care system is taking the following steps on behalf of its 2.2 million patients.<br></font><ul><li><font size="2">Mailing notification letters to all 2.2 million patients and guarantors;</font></li><li>Providing free credit monitoring and restoration service to patients whose records included Social Security numbers;</li><li>Providing a toll-free information line at 1-866-581-3599 to respond to questions; and</li><li>Establishing a website at <a href="http://healthcare.utah.edu/billingrecordstheft">healthcare.utah.edu/billingrecordstheft</a> that provides information and resources.<br></li></ul><font size="2"><br><span style="font-weight: bold;">Victim Reaction:</span><br>Tuesday's news was especially unsettling for people like Will Taylor, of West Valley City, whose premature daughter is a patient at University Hospital. Taylor has already been the victim of identity theft once, when thieves racked up credit card charges in his name. <br><br>"I will ask [the hospital] what precautions I can take and what they are doing about it," he said.<br><br>"If our information isn't safe, then what is?" patient Dan Christenson, of Salt Lake City, said Tuesday after learning of the theft. <br><br><span style="font-weight: bold;">Commentary:</span><br>I would be more understanding if this were the first breach ever reported where a backup was stolen that contained personal information, but it's not.&nbsp; Employing backup tapes without encryption is a very well documented risk, so why do large organizations still accept it? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>March, 2008 - <a href="http://breachblog.com/2008/03/14/uhc.aspx">Stolen University Health Care laptop requires notification of 4800</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/11/uhc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 08:33:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/backup tape">backup tape</category>
      <category domain="http://securityratty.com/tag/backup">backup</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/backup information tapes">backup information tapes</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/utah">utah</category>
      <category domain="http://securityratty.com/tag/million people live">million people live</category>
      <source url="http://breachblog.com/2008/06/11/uhc.aspx">2.2 million billing records missing on stolen backup tape</source>
    </item>
    <item>
      <title><![CDATA[Sometimes danger lurks right under our nose.]]></title>
      <link>http://securityratty.com/article/60d561dc35d92bd6e3f06ac8f71c0ba7</link>
      <guid>http://securityratty.com/article/60d561dc35d92bd6e3f06ac8f71c0ba7</guid>
      <description><![CDATA[When Executive Protecion Specialists think and speak about &quot;Threat Assessment&quot;, they are usually focusing on a known or suspected danger that may prove life-threatening. Sometimes, that danger may...]]></description>
      <content:encoded><![CDATA[When Executive Protecion Specialists think and speak about "Threat Assessment", they are usually focusing on a known or suspected danger that may prove life-threatening.  Sometimes, that danger may already have made itself at home and is silently destroying lives and eating away at victims like a cancerous growth. <br /><span id="fullpost"><br />One such story was highlighted by the "Washington Post Magazine" on May 25th, 2008.  It involved a young girl who had been molested and raped by her own father.  A man who was something of a hero to many.  A man who had walked side by side with Dr. martin Luther king and who was only a few feet away from the Civil Rights leader when he was assasinated.  That man is James Bevel.<br /></span><br /><br />I had the pleasure of listening to Col. Dave Grossman speaking at UCLA last April. He was eloquent in his description of how young lives are taken and families estroyed by School killings.  He also spoke about those who prey on the less suspecting.  He equated it to the Wolves hunting down and eating sheep.  Mr. Bevel appears to be one of those parasitic wolves.  <br /><br />For years he raped his little daughter, telling her it was something of an "experiment".  In his mind, he didn't think that it mattered.  His unfathomable belief (and apparently remains the same until this day) is that all women are prostitutes until they reach a certain age, when sex is set aside for procreation.  This beleif allowed him to allegedly rape his eight year old daughter on many occassions.<br /><br />His daughter, Aaralyn Mills, finally found the courage to step foward and contact the Police in 2005.  She assisted the Leesburg authorities to tape record her conversation with her father.  In that conversation, James Bevel admitted raoping his daughter and that it was part of a scientific process.  Unfortunately, her mother, like many other mothers, did not want or couldn't face the truth.  This gave the big, bad wolf all the space he needed to desecrate the little sheep.  <br /><br />Sadly, men like this are living throughout our communities.  they come in all shapes, sizes nd colors.  Some are Doctors, Community leaders, Priests, Police Officers, Electricians and Preachers.  If you have been entrusted with the job of protecting an innocent lamb, be a strong and fearful sheepdog and protect your flock, with your very life if need be.  Be brave like Aaralyn Mills.  She stepped forward at this time in her life because her father who has many children with many different women has now a young daughter and her half-siter is afraid that he will rape her too.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 18:23:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/daughter">daughter</category>
      <category domain="http://securityratty.com/tag/danger">danger</category>
      <category domain="http://securityratty.com/tag/aaralyn mills">aaralyn mills</category>
      <category domain="http://securityratty.com/tag/james bevel">james bevel</category>
      <category domain="http://securityratty.com/tag/allegedly rape">allegedly rape</category>
      <category domain="http://securityratty.com/tag/washington post magazine">washington post magazine</category>
      <category domain="http://securityratty.com/tag/parasitic wolves">parasitic wolves</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/police officers">police officers</category>
      <source url="http://www.thebulletproofblog.com/2008/06/sometimes-danger-lurks-right-under-our.html">Sometimes danger lurks right under our nose.</source>
    </item>
    <item>
      <title><![CDATA[Two HSBC breaches with similar circumstances]]></title>
      <link>http://securityratty.com/article/00ff10de6ac5a9494418f28bae55cbac</link>
      <guid>http://securityratty.com/article/00ff10de6ac5a9494418f28bae55cbac</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/28/08

Organization
Hong Kong and Shanghai Banking Corporation (&quot;HSBC

Contractor/Consultant/Branch
HSBC Branch at Bayview &amp; Major Mackenzie (CA
HSBC...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/hsbc.jpg" align="right" height="47" width="154"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/28/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.hsbc.com/1/2/">Hong Kong and Shanghai Banking Corporation ("HSBC")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www2.hsbc.ca/HICServlet?cmd_LocateBranch=&amp;BranchArea=ontario&amp;BranchCity=Richmond%20Hill&amp;BranchPrevious=cmd_GetCAMap=,cmd_LocateBranchCity=%7CBranchArea=ontario&amp;accept-language=en-CA">HSBC Branch at Bayview &amp; Major Mackenzie (CA)</a> <br>HSBC Branch in UK (Cheshire)<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown, "hundreds of bank customers" in Canada<br><br><span style="font-weight: bold;">Types of Data:</span><br>"personal information" in Canada, and "credit card applications and overdraft review dates, photocopies of a passport, driving licences, a marriage certificate, bank account sort codes and account numbers" in the UK<br><br><span style="font-weight: bold;">Breach Description:</span><br>Two breaches were reported in the past week affecting HSBC customers in Canada and the UK.&nbsp; In Canada, "A Richmond Hill man was driving in his neighbourhood Saturday night when he spotted a bank bag full of cancelled cheques on the side of the road."&nbsp; In the UK "papers, which relate to current bank accounts and applications, were found in a quiet road in Sale by children playing in the street."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://toronto.ctv.ca/servlet/an/local/CTVNews/20080601/HSBC_security_080601/20080601/?hub=TorontoNewHome">CTV News Toronto</a> <br><a href="http://www.wigantoday.net/wigannews/Children-find-secret-bank-files.4125352.jp">Wigan Observer</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>CTV News Toronto and Richard Bean at the Wigan Observer<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br><span style="font-weight: bold;">In Canada:</span><br>A Richmond Hill man was driving in his neighbourhood Saturday night when he spotted a bank bag full of cancelled cheques on the side of the road.<br><br>He took the bag to a police station after a quick peek inside revealed the personal information of hundreds of bank customers.<br><span style="font-style: italic;">[Evan] Information security aims to reduce the risk of unauthorized disclosure, modification, and destruction of confidential information to an "acceptable level" no matter what form the confidential information takes.&nbsp; Unauthorized disclosure of confidential information on paper is just as damaging as unauthorized disclosure of confidential information on a backup tape, CD, laptop, etc.</span><br><br>he was in the Bayview Avenue and Major Mackenzie Drive area when he spotted the redbag at the side of the road with the HSBC bank logo emblazoned at the front.<br><span style="font-style: italic;">[Evan] I presume that this bag was lost in shipment.&nbsp; Was the information in the bag or the bag itself inventoried?&nbsp; Do you suppose the bank would have ever noticed that the bag was missing?</span><br><br>the bag belonged to the HSBC branch at Bayview and Major Mackenzie<br><br>"There were about 300 of them," he told CTV Toronto Saturday night. "There were more documents in there destroyed by the rain."<br><br>he tried to contact the bank but didn't have much luck<br><br>York Regional Police are speaking with bank officials as they investigate how the sensitive information ended up on the side of a road.<br><br><span style="font-weight: bold;">In the UK:</span><br>An investigation is under way after bank details of Wigan customers were found dumped in Cheshire.<br><span style="font-style: italic;">[Evan] Does "dumped" mean thrown away, like in a dumpster?</span><br><br>The confidential 60-page sheaf of A4 documents, featured lists of customers of high street bank HSBC.<br><br>Among the information contained in the papers were credit card applications and overdraft review dates, photocopies of a passport, driving licences, a marriage certificate, bank account sort codes and account numbers.<br><span style="font-style: italic;">[Evan] Sheesh.&nbsp; A bad guy (or gal) could do a helluva lot of damage with this information.</span><br><br>The papers, which relate to current bank accounts and applications, were found in a quiet road in Sale by children playing in the street.<br><br>Lynne Stewart, 47, whose children found the documents, has informed the police and is waiting for them to collect them<br><br>She said: "I would be extremely worried and angry if I was a customer of theirs because this is just the type of stuff that criminal gangs would love to get their hands on." She has now filled a bag with as many of the computer print-offs she could find, although fears that many more have blown away on the windiest day of the year.<br><br>The papers were initially found by her nine-year-old daughter Xxxxxx who then alerted her brother Xxxxxx, 12.<br><span style="font-style: italic;">[Evan] My comment here is not related to the breach itself, but I feel a little uncomfortable using children's names publicly.</span><br><br>Neither understood the significance of the papers – although Mrs Stewart immediately did.<br><br>She said: "Reece had been to get his ball back after it had bounced into a sub-station and says he saw a pile on top of the transformer and they were whistling around in the gale.<br><br>"But it was Jessica who grabbed one as it blew past her in the street and showed it to me.<br><br>"I have counted at least 15 pages of lists of names and account details before you even start to talk about letters applying for credit cards and photo copies of personal documents which people have sent to the bank when they have made these applications. <br>"I find it very alarming that this kind of information is just blowing about in the street.<br><span style="font-style: italic;">[Evan] No doubt!</span><br><br>"Surely in this day and age when ID fraud is all over the news the bank should be more careful about this information being printed out on paper."<br><br>A spokesman for HSBC, which has branches in Mesnes Road and Wallgate, said: "HSBC is investigating the find of documents found in Greater Manchester over the weekend. <br><br>"The security of our customers' personal information is of paramount importance and we have stringent procedures in place to guard against their loss.<br><span style="font-style: italic;">[Evan] Is everyone aware of and following the "stringent procedures"?</span><br><br>"Without speculating on how this occurred, something has clearly gone wrong, and we are extremely disappointed to hear of these particular circumstances.<br><br>"When the cause of the incident has been determined, we will be reviewing our processes to ensure this does not happen again."<br><span style="font-style: italic;">[Evan] In my opinion, promises that are made but cannot be fulfilled lead to a loss of confidence.</span><br><br><span style="font-weight: bold;">A UK Victim's Reaction:</span><br>"I can't believe it. The first I knew was when I was contacted by the person who found them. It is unforgivable that the bank would firstly lose such confidential details and then fail to tell its clients what had happened."<br><br>"I have been with this bank since I was a young lad and it is very disappointing indeed."<br><br><span style="font-weight: bold;">Commentary:</span><br>Let's take this from both sides for a second.&nbsp; Poor information security practice led to these two breaches.&nbsp; Real lives are affected when these things happen and HSBC should be more careful in the way they protect confidential personal information.&nbsp; I count five publicly reported breaches from HSBC in the past six months including the two in this post.&nbsp; There are likely more that weren't reported publicly as well.<br><br>Now the other side, for arguments sake.&nbsp; HSBC is a huge company with ~10,000 offices in 83 countries and territories around the world.&nbsp; I presume that they also have hundreds of thousands of customers (maybe millions).&nbsp; Information security breaches in companies this large and diverse are bound to happen.&nbsp; It isn't possible to eliminate them, so the best you can hope to do is reduce risk to a level that is "acceptable" to management and shareholders.&nbsp; Information security personnel are not in the risk elimination business, we are in the risk reduction business.&nbsp; This is reality. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>May, 2008 - <a href="http://breachblog.com/2008/05/14/hsbc.aspx">HSBC loses a server in branch renovation</a> <br>April, 2008 - <a href="http://www.networkworld.com/news/2008/040708-hsbc-loses-disc-with-370000.html?fsrc=rss-security">HSBC loses disc with 370,000 customer details</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/06/hsbc.aspx">Five-year-old wanders into bank branch after-hours</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/02/hsbc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 05:40:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/bank customers">bank customers</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/bank officials">bank officials</category>
      <category domain="http://securityratty.com/tag/bank bag">bank bag</category>
      <category domain="http://securityratty.com/tag/bag">bag</category>
      <category domain="http://securityratty.com/tag/bank branch after-hours">bank branch after-hours</category>
      <category domain="http://securityratty.com/tag/street bank hsbc">street bank hsbc</category>
      <category domain="http://securityratty.com/tag/street">street</category>
      <source url="http://breachblog.com/2008/06/02/hsbc.aspx">Two HSBC breaches with similar circumstances</source>
    </item>
    <item>
      <title><![CDATA[Watching CNN can ruin your day!]]></title>
      <link>http://securityratty.com/article/503630703b2b86284896969a96c99fda</link>
      <guid>http://securityratty.com/article/503630703b2b86284896969a96c99fda</guid>
      <description><![CDATA[When I work from my home office I usually keep CNN on in the background to keep up on the world. However, I have to say that it is just too damn depressing. A sample of today's news


Gas prices...]]></description>
      <content:encoded><![CDATA[<p>When I work from my home office I usually keep CNN on in the background to keep up on the world.  However, I have to say that it is just too damn depressing.  A sample of today's news:<br><br><ol><li>Gas prices continue to go up about a penny or two a day, over 30 cents in last few weeks!  </li><li>Oil hit new highs</li><li>Credit card companies are raising interest rates and fees drastically</li><li>Food staples like wheat, rice, etc. are up from 10% and up</li><li>Some crazy nut in Austria locked his daughter in a dungeon for 24 years and fathered 7 children with her, one who died and he disposed of the body (This is just a disgusting story)</li><li>Home prices remain depressed and foreclosures remain high</li><li>Airlines either have to merge or go out of business</li></ol><br>Geez, what this country needs is a good fantasy for us to lose ourselves in.  A new Star Wars or something to take our mind off of dealing with reality.  It has got to get better, doesn't it?<br></p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=qaJX3I"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=qaJX3I" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wE7uUG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wE7uUG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=riRFhG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=riRFhG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=7FaSJG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=7FaSJG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2sufKG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2sufKG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FD9qmg"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FD9qmg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Vaklxg"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Vaklxg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/279533454" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Apr 2008 08:45:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gas prices continue">gas prices continue</category>
      <category domain="http://securityratty.com/tag/credit card companies">credit card companies</category>
      <category domain="http://securityratty.com/tag/home prices remain">home prices remain</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/foreclosures remain">foreclosures remain</category>
      <category domain="http://securityratty.com/tag/oil hit">oil hit</category>
      <category domain="http://securityratty.com/tag/star wars">star wars</category>
      <category domain="http://securityratty.com/tag/food staples">food staples</category>
      <category domain="http://securityratty.com/tag/crazy nut">crazy nut</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/279533454/watching-cnn-ca.html">Watching CNN can ruin your day!</source>
    </item>
  </channel>
</rss>
