<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: democrat]]></title>
    <link>http://securityratty.com/tag/democrat</link>
    <description></description>
    <pubDate>Wed, 06 Feb 2008 03:44:05 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Liberal Democrat leader visits our lab]]></title>
      <link>http://securityratty.com/article/a69300e89ab3d33e212394e88a14206b</link>
      <guid>http://securityratty.com/article/a69300e89ab3d33e212394e88a14206b</guid>
      <description><![CDATA[This week, Nick Clegg , leader of the UK Liberal Democrat Party, and David Howarth , MP for Cambridgeshire, visited our hardware security lab for a demonstration of Chip &amp; PIN fraud techniques
They...]]></description>
      <content:encoded><![CDATA[<p>This week, <a href="http://www.nickclegg.com/">Nick Clegg</a>, leader of the UK Liberal Democrat Party, and <a href="http://www.davidhowarth.org.uk/">David Howarth</a>, MP for Cambridgeshire, visited our <a href="http://www.cl.cam.ac.uk/research/security/tamper/">hardware security lab</a> for a demonstration of <a href="http://www.cl.cam.ac.uk/research/security/banking/">Chip &amp; PIN fraud techniques</a>.</p>

<a href='http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/clegg-visit3/' title='clegg-visit3'><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/10/clegg-visit3.jpg" width="150" height="112" class="attachment-thumbnail" alt="" /></a>
<a href='http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/clegg-visit1/' title='clegg-visit1'><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/10/clegg-visit1.jpg" width="150" height="112" class="attachment-thumbnail" alt="" /></a>
<a href='http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/clegg-visit5/' title='clegg-visit5'><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/10/clegg-visit5.jpg" width="150" height="112" class="attachment-thumbnail" alt="" /></a>

<p>They used this visit to announce their new <a href="http://www.nickclegg.com/2008/10/new-protections-against-identity-fraud-needed-clegg/">party policy on protections against identity fraud</a>. At present, credit rating companies are exempt from aspects of the Data Protection Act and can forward personal information about an individual&#8217;s financial history to companies without the subject&#8217;s consent. Clegg proposes to give individuals the rights to &#8220;freeze&#8221; their credit records, making it more difficult for fraudsters to impersonate others.</p>
<p>See also the <a href="http://www.cambridge-news.co.uk/cn_news_home/DisplayArticle.asp?ID=358491">Cambridge Evening News article</a> and <a href="http://www.cambridge-news.co.uk/cn_video/media/16th_October_2008_Nick_Clegg_visit_to_Cambridge_Computer_Labs_DJ.wmv">video interview</a>.</p>
]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 15:05:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/individuals financial history">individuals financial history</category>
      <category domain="http://securityratty.com/tag/individuals">individuals</category>
      <category domain="http://securityratty.com/tag/data protection act">data protection act</category>
      <category domain="http://securityratty.com/tag/credit records">credit records</category>
      <category domain="http://securityratty.com/tag/forward personal information">forward personal information</category>
      <category domain="http://securityratty.com/tag/pin fraud techniques">pin fraud techniques</category>
      <category domain="http://securityratty.com/tag/liberal democrat party">liberal democrat party</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/hardware security lab">hardware security lab</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/">Liberal Democrat leader visits our lab</source>
    </item>
    <item>
      <title><![CDATA[Extremism in defense of security is no vice]]></title>
      <link>http://securityratty.com/article/833ca0b56cb572826821838ff01100cf</link>
      <guid>http://securityratty.com/article/833ca0b56cb572826821838ff01100cf</guid>
      <description><![CDATA[During his acceptance speech for the 1964 Republican presidential nomination, Barry Goldwater proclaimed &quot;extremism in the defense of liberty is no vice.&quot; As a supporter of a strong defense during a...]]></description>
      <content:encoded><![CDATA[During his acceptance speech for the 1964 Republican presidential nomination, Barry Goldwater proclaimed "…extremism in the defense of liberty is no vice." As a supporter of a strong defense during a time when the Vietnam peace movement was gathering momentum, Goldwater was portrayed as an extremist by his political rivals. Even though this image of a hawkish warmonger would be used to the Democrat's advantage during the presidential campaign, Goldwater stood by his principles.]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/defense">defense</category>
      <category domain="http://securityratty.com/tag/goldwater">goldwater</category>
      <category domain="http://securityratty.com/tag/goldwater stood">goldwater stood</category>
      <category domain="http://securityratty.com/tag/barry goldwater">barry goldwater</category>
      <category domain="http://securityratty.com/tag/strong defense">strong defense</category>
      <category domain="http://securityratty.com/tag/republican presidential nomination">republican presidential nomination</category>
      <category domain="http://securityratty.com/tag/vietnam peace movement">vietnam peace movement</category>
      <category domain="http://securityratty.com/tag/acceptance speech">acceptance speech</category>
      <category domain="http://securityratty.com/tag/vice">vice</category>
      <source url="http://www.networkworld.com/columnists/2008/090408-oped.html?fsrc=rss-security">Extremism in defense of security is no vice</source>
    </item>
    <item>
      <title><![CDATA[VP Nominee Sarah Palin, Hacker?]]></title>
      <link>http://securityratty.com/article/8e3f93f782545f8440786e956b4d45a5</link>
      <guid>http://securityratty.com/article/8e3f93f782545f8440786e956b4d45a5</guid>
      <description><![CDATA[John McCains pick for VP, Sarah Palin, knows a thing or two about retrieving evidence from a computer. The mainstream reporting calls her a hacker because she is able to retrieve files from the...]]></description>
      <content:encoded><![CDATA[<p>John McCain&#8217;s pick for VP, Sarah Palin, knows a thing or two about retrieving evidence from a computer.  The mainstream reporting calls her a &#8220;hacker&#8221; because she is able to retrieve files from the Windows recycle bin. </p>
<p>The <a href="http://dwb.adn.com/front/story/5572779p-5504444c.html">Anchorage Daily News reports</a> back in September 2004:</p>
<blockquote><p>Sarah Palin never thought of herself as an investigator.  Yet there she was, hacking uncomfortably into Randy Ruedrich&#8217;s computer, looking for evidence that the state Republican Party boss had broken the state ethics law while a member of the Alaska Oil &amp; Gas Conservation Commission.</p>
<p class="story_readable">The next week, when Palin went back to work at the AOGCC, she noticed that Ruedrich had removed his pictures from the walls and the personal effects from his desk. But as she and an AOGCC technician worked their way around his computer password at the behest of an assistant attorney general in Fairbanks, they found his cleanup had not extended to his electronic files.</p>
<p class="story_readable">The technician &#8220;said it looked like he tried to delete this, but she knew a way to go around and get some of the deleted stuff,&#8221; Palin said in an interview. &#8220;I didn&#8217;t know what I was looking for, but I was there.&#8221;</p>
</blockquote>
<p>And this is how <a href="http://www.salon.com/opinion/feature/2007/08/13/alaska/index1.html">Salon reports</a> the same incident:</p>
<blockquote><p>&#8220;In a neat symbolic fit, the agent responsible for Alaska&#8217;s current moment of reform and modernization is a woman, a breed once nearly as rare in far Northwest politics as a Democrat. Sarah Palin, a libertarian and hockey mom from the fast-growing suburbs of Anchorage, began her political career &#8212; as an appointed member of the state&#8217;s Oil and Gas Commission &#8212; by hacking into the computer of another commissioner, Randy Ruedrich, chairman of the Alaska Republican Party. Palin was seeking the evidence that she would eventually use to charge him with an improper relationship with lobbyists. (Ruedrich would later settle state ethics charges against him by paying a $12,000 fine.)&#8221;</p></blockquote>
<p>Is this where the McCain administration is going to get their computer security expertise?  She&#8217;s not a security expert but it is nice to see someone at the level of state govenor who knows their way around a computer.</p>
]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 14:51:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/palin">palin</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/randy ruedrichs computer">randy ruedrichs computer</category>
      <category domain="http://securityratty.com/tag/computer password">computer password</category>
      <category domain="http://securityratty.com/tag/computer security expertise">computer security expertise</category>
      <category domain="http://securityratty.com/tag/technician">technician</category>
      <category domain="http://securityratty.com/tag/aogcc technician">aogcc technician</category>
      <category domain="http://securityratty.com/tag/randy ruedrich">randy ruedrich</category>
      <source url="http://www.veracode.com/blog/2008/08/vp-nominee-sarah-palin-hacker/">VP Nominee Sarah Palin, Hacker?</source>
    </item>
    <item>
      <title><![CDATA[Chertoff Misleads on Laptop Searches, Feingold Charges]]></title>
      <link>http://securityratty.com/article/ad39c294de237eaa73192dd448436345</link>
      <guid>http://securityratty.com/article/ad39c294de237eaa73192dd448436345</guid>
      <description><![CDATA[In an interview with Wired.com, Homeland Security Chief Michael Chertoff blatantly mischaracterized when border agents can search Americans' laptops, Sen. Russ Feingold charges. The Wisconsin Democrat...]]></description>
      <content:encoded><![CDATA[In an interview with Wired.com, Homeland Security Chief Michael Chertoff blatantly mischaracterized when border agents can search Americans' laptops, Sen. Russ Feingold charges. The Wisconsin Democrat says Congress needs to step in to protect Americans from intrusive searches of their electronics.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a9f267e30a395264e71760110242505e" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a9f267e30a395264e71760110242505e" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=9sUvGK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=9sUvGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=10yW3k"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=10yW3k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Pe3gSk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Pe3gSk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=VdrNjK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=VdrNjK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=HZubTK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=HZubTK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=9f9ktk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=9f9ktk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=q0xNjk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=q0xNjk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=S9srPK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=S9srPK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/358839394" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/358839403" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 16:46:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/americans">americans</category>
      <category domain="http://securityratty.com/tag/protect americans">protect americans</category>
      <category domain="http://securityratty.com/tag/russ feingold charges">russ feingold charges</category>
      <category domain="http://securityratty.com/tag/wisconsin democrat">wisconsin democrat</category>
      <category domain="http://securityratty.com/tag/border agents">border agents</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/intrusive">intrusive</category>
      <category domain="http://securityratty.com/tag/step">step</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/358839403/chertoff-mislea.html">Chertoff Misleads on Laptop Searches, Feingold Charges</source>
    </item>
    <item>
      <title><![CDATA[Employee fraud hits Baptist Health in Arkansas]]></title>
      <link>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</link>
      <guid>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/2/08

Organization
Baptist Health

Baptist Health is the largest not-for-profit healthcare organization in Arkansas

Contractor/Consultant/Branch
None...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/baptisthealth.jpg" width="120" align="right" height="274"><font size="2"><b>Date Reported: </b><br>7/2/08<br><br><b>Organization: </b><br><a href="http://www.baptist-health.org/">Baptist Health*</a><br><br><font size="1">*Baptist Health is the largest not-for-profit healthcare organization in Arkansas</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, and reason for coming to Baptist Health"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"LITTLE ROCK (AP) - A North Little Rock woman has been arrested for using financial information from patients at Baptist Health to illegally obtain Wal-Mart gift cards for her own use. The hospital has notified about 1,800 patrons of the ID theft."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wxvt.com/Global/story.asp?S=8609129&amp;nav=menu1344_2">Associated Press via WXVT Channel 15 News</a> <br><a href="http://arkansasmatters.com/content/fulltext/news/?cid=80211">KARK Channel 4 News</a> <br><a href="http://www.nwanews.com/adg/News/230290/">Arkansas Democrat-Gazette</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Toby Manthey, Arkansas Democrat-Gazette<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Baptist Health has sent letters warning about 1,800 patients that the hospital system’s records may have been breached<br><span style="font-style: italic;">[Evan] Uh, "may have been breached"?!</span><br><br>The notification came after the arrest of a Baptist Health employee at a Wal-Mart store on 25 counts of financial identity fraud.<br><span style="font-style: italic;">[Evan] Wouldn't life be grand if we could trust our employees?&nbsp; Maybe, I suppose.</span><br><br>The letters, mailed last week, follow the firing of the woman in early June<br><br>North Little Rock police say Tamara Hill, 30, of that city worked at Baptist Health Medical Center-North Little Rock in the emergency department.<br><br>Hill, an admissions clerk, was arrested May 30 at the Wal-Mart<br><br>Ebony Flowers, 25, also of North Little Rock, was arrested at the store the same day on three counts of identity fraud<br><br>Flowers was listed in a police report as a janitor for the North Little Rock School District<br><span style="font-style: italic;">[Evan] Key word is "was".</span><br><br>Baptist Health recorded more than 950,000 patient visits systemwide in 2007, a number that includes repeat visits.<br><br>Mark Lowman, spokesman for the Little Rock-based Baptist Health system, confirmed that the system fired the employee after notification of the arrest.<br><br>Police reports say the women used a victim’s personal information to obtain temporary Wal-Mart "account authorization numbers" - credit cards, essentially - used to buy Wal-Mart gift cards.<br><br>The victim reported to police that he had not authorized the transactions<br><br>the same victim confirmed he was a Baptist Health patient<br><br>He expressed appreciation of the handling of the case by the system and by the North Little Rock police. <br><br>Among the items found during a search connected with the arrest of Hill was personal information for 24 other people, including "screen shots" - printouts showing the exact appearance of the images on a computer screen - that showed victims’ personal information.<br><span style="font-style: italic;">[Evan] This seems like confirmation that "may have been breached" is not all that accurate.</span><br><br>Also found were four Wal-Mart gift cards and $ 1,490 in cash<br><br>Police found a small bag of marijuana on Flowers, according to the reports. In a search connected with her arrest, they also discovered a. 25-caliber magazine with six bullets, as well as a receipt for four of the gift cards and information on three-identity theft victims.<br><span style="font-style: italic;">[Evan] A thug.</span><br><br>The U. S. Secret Service is helping with the investigation. <br><br>"Due to a breach of our information systems security policies, there is a possibility that some personal information, such as your name, address, date of birth, Social Security number, and reason for coming to Baptist Health, was accessed by an unauthorized person."<br><span style="font-style: italic;">[Evan] This is from the letter to the victims.</span><br><br>No information in the patient’s "medical records" and no information about the patient’s diagnosis or prognosis was accessed<br><br>while no "medical record" information was accessed, the letter mentioned the patient’s "reason for coming" to the system possibly was accessed<br><br>Lowman said a reason stated by a patient using the system isn’t considered medical information because the reason is a layman’s explanation, not one from a medical professional.<br><span style="font-style: italic;">[Evan] This is Mark Lowman, spokesman for the Little Rock-based Baptist Health system</span><br><br>He said the breach wouldn’t violate the Health Insurance Portability and Accountability Act, or HIPAA. <br><br>But Pam Dixon, executive director of the San Diego-based World Privacy Forum, a privacy advocacy group, thinks all the information mentioned in the letter falls under HIPAA.<br><br>"It doesn’t matter that [it’s not ] a prognosis or diagnosis," she said. <br><span style="font-style: italic;">[Evan] Splitting hairs.&nbsp; The bottom line is that confidential personal information was stolen and there are victims.&nbsp; Whether or not it is a HIPAA violation seems somewhat irrelevant.</span><br><br>Dixon found the system’s letter lacking in several respects, such as clarifying the exact meaning of a "reason for coming to Baptist Health." The letter also should have mentioned when and for how long the breach occurred, she said.<br><br>"Almost all breach letters have that," Dixon added.<br><span style="font-style: italic;">[Evan] Almost all breach letters have what?&nbsp; A mention about for how long the breach occurred?&nbsp; I must be reading some of the wrong breach letters because it seems to me that this information is 50/50 at best.&nbsp; Also missing is the "we have no reason to believe that the information will be misused", but this one doesn't fit does it?</span><br><br>Dixon said Baptist Health should have offered in the letter to set up free credit monitoring for victims.<br><span style="font-style: italic;">[Evan] Why?&nbsp; One year (or two) of credit monitoring is almost useless.&nbsp; Credit monitoring alerts a victim after fraud has already occurred and one year (or two) of monitoring is too limited for information that has a much longer lifespan.&nbsp; I guess credit monitoring would be better than nothing, but not by much.</span><br><br>Lowman said the health system continually conducts audits to know which staff members are accessing what information, and whether or not the access is appropriate.<br><span style="font-style: italic;">[Evan] Good!</span><br><br>"We’re always looking to provide better audits and better oversight of private, confidential and protected information," Lowman said.<br><span style="font-style: italic;">[Evan] And Good!</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Preventing and detecting employee fraud has always been a challenge.&nbsp; This doesn't mean we give up though.&nbsp; We have some tools at our disposal such as employee background checks, role-based access control, segregation of duties, and job rotation to name a few.<br><br>I don't think that these two crooks are anything more than common criminals.&nbsp; The fact of the matter is that identity theft and fraud are very easy crimes to commit and require very little skill. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/10/baptisthealth.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 20:00:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/confidential personal information">confidential personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/baptist health system">baptist health system</category>
      <category domain="http://securityratty.com/tag/health system">health system</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/victims personal information">victims personal information</category>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/baptist health">baptist health</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <source url="http://breachblog.com/2008/07/10/baptisthealth.aspx">Employee fraud hits Baptist Health in Arkansas</source>
    </item>
    <item>
      <title><![CDATA[White House Refused to Open Pollutants E-Mail]]></title>
      <link>http://securityratty.com/article/3561498fbd3f53dfa2cf831de7741413</link>
      <guid>http://securityratty.com/article/3561498fbd3f53dfa2cf831de7741413</guid>
      <description><![CDATA[This is by far one of the more asinine things I have read in a while and speaks volumes to lunacy in the White House. The WH refused to open an email that was sent by the EPA because they disagreed...]]></description>
      <content:encoded><![CDATA[<p>This is by far one of the more asinine things I have read in a while and speaks volumes to lunacy in the White House. The WH <b>refused</b> to open an email that was sent by the EPA because they disagreed with the conclusion that greenhouse gases are pollutants. </p>
<p>So, they played three monkeys and said, &#8220;la la la, I can&#8217;t see it. la la la&#8221; (<i>not an exact quote</i>) But, that&#8217;s not where the absurdity ends. The EPA could have sent a printed copy and that would have been the end of it.  </p>
<p>Nope. </p>
<p>Instead they rewrote the conclusions to make more palatable for the dunking bird-set. Email has always been a best effort tool that has morphed into business critical function over the years. But, to say they wouldn&#8217;t open an email&#8230;wow. Remember folks, if you are a Republican or Democrat be sure to <b>VOTE</b>. You have a responsibility.</p>
<p>From NY Times:</p>
<blockquote><p>Over the past five days, the officials said, the White House successfully put pressure on the E.P.A. to eliminate large sections of the original analysis that supported regulation, including a finding that tough regulation of motor vehicle emissions could produce $500 billion to $2 trillion in economic benefits over the next 32 years. The officials spoke on condition of anonymity because they were not authorized to discuss the matter.</p>
<p>Both documents, as prepared by the E.P.A., “showed that the Clean Air Act can work for certain sectors of the economy, to reduce greenhouse gases,” one of the senior E.P.A. officials said. “That’s not what the administration wants to show. They want to show that the Clean Air Act can’t work.” </p></blockquote>
<p>November can&#8217;t come soon enough.</p>
<p><a href="http://www.nytimes.com/2008/06/25/washington/25epa.html?_r=1&amp;oref=slogin">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=MMl8uC"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=MMl8uC" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=6TbNFI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=6TbNFI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=cavZ7i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=cavZ7i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=ES8N5i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=ES8N5i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=6vN1Wi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=6vN1Wi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=SCqOei"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=SCqOei" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/320504211" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:54:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/white house">white house</category>
      <category domain="http://securityratty.com/tag/clean air act">clean air act</category>
      <category domain="http://securityratty.com/tag/reduce greenhouse gases">reduce greenhouse gases</category>
      <category domain="http://securityratty.com/tag/greenhouse gases">greenhouse gases</category>
      <category domain="http://securityratty.com/tag/regulation">regulation</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/motor vehicle emissions">motor vehicle emissions</category>
      <category domain="http://securityratty.com/tag/business critical function">business critical function</category>
      <category domain="http://securityratty.com/tag/tough regulation">tough regulation</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/320504211/">White House Refused to Open Pollutants E-Mail</source>
    </item>
    <item>
      <title><![CDATA[Online theft and fraud involves OSU Bookstore customers]]></title>
      <link>http://securityratty.com/article/8476417975cb621bc420aa71c01e43ab</link>
      <guid>http://securityratty.com/article/8476417975cb621bc420aa71c01e43ab</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/3/08

Organization
Oregon State University

Contractor/Consultant/Branch
OSU Bookstore, Inc

OSU Bookstore is a nonprofit corporation that has been...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/osubooks.jpg" align="right" height="51" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/3/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://oregonstate.edu/">Oregon State University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.osubookstore.com/">OSU Bookstore, Inc.</a>* <br><br><font size="1">*OSU Bookstore is a nonprofit corporation that has been serving Oregon State University and the town of Corvallis since 1914. Our main store is located in the Memorial Union on the Oregon State University campus.&nbsp; Today, as in 1914, the bookstore is governed by a Board of Directors composed of faculty, staff, and students of Oregon State University.</font><br><br><span style="font-weight: bold;">Victims:</span><br>Online customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>"as many as 4,700"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Personal information including credit card numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The Oregon State Police is investigating the theft of personal information from as many as 4,700 online customers of the OSU Bookstore who used credit cards to purchase items."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.dhonline.com/articles/2008/06/03/news/local/5loc10_osu.txt">Albany Democrat Herald</a> <br><a href="http://www.kval.com/news/local/19535104.html">Associated Press via KVAL Channel 13 News</a> <br><a href="http://www.kval.com/news/local/19549224.html">KVAL Channel 13 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Albany Democrat Herald<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>CORVALLIS, Ore. (AP) - Oregon State officials say credit card scammers may have defrauded 4,700 online customers of the school's bookstore.<br><br>In March, OSP began investigation into a report that approximately 30 OSU Bookstore customers’ personal information may have been compromised following online orders.<br><span style="font-style: italic;">[Evan] Unfortunately, the bookstore did not appear to be monitoring web traffic to and from the server to detect unusual (and potentially attack) traffic. The fact that this detective control was missing from the security architecture meant that the bookstore had to rely on customers to tell them something was wrong.&nbsp; An incident response should have probably been initiated at this point (March not May).</span><br><br>Then last week, telephone calls and e-mails began coming into the bookstore from customers who had noticed fraudulent charges on their credit cards almost immediately after placing online orders<br><br>Bookstore General Manager Steve Eckrich says servers were shut down when the security breach was discovered.<br><span style="font-style: italic;">[Evan] 2+ months after the bookstore was originally notified that something was wrong.&nbsp; At the time of this post, the site is still down.</span><br><br><img src="http://images.quickblogcast.com/95781-88451/osubooksdown.jpg" border="0" width="576"><br><br>"They tried different attacks and our Web site evidently had one vulnerability in it," said General Manager Steve Eckrich.<br><span style="font-style: italic;">[Evan] I would bet my cup of coffee that the Web site had more than on vulnerability!&nbsp; I love my coffee.&nbsp; Where is the IDS/IPS?</span><br><br>The Bookstore has alerted its online customers who had made a purchase<br><br>State Police Lieutenant Jeff Lanz says the security breach appears to have originated outside the university, but where is unknown.<br><br>The OSU Bookstore has hired an outside agency to help with its own investigation and to provide guidance on strengthened security safeguards for its computing network.<br><span style="font-style: italic;">[Evan] Good call it just stinks that the bookstore was reactive and not proactive.</span><br><br>"We'll be using their recommendations not only to solve that particular problem that was exploited but to add additional layers of security on top of that so that information is not exposed or cannot be exposed in the way that it was,"<br><span style="font-style: italic;">[Evan] Another good call.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Obviously the OSU Bookstore did not employ the proper security controls to #1 secure the site, #2 detect a breach, and #3 respond to a breach.&nbsp; Three strikes.&nbsp; Poor planning and poor implementation.&nbsp; I hope that OSU Bookstore, Inc. takes the proper steps to formalize their information security program and reduce risk.&nbsp; We'll see. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/04/osubooks.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 05:42:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bookstore">bookstore</category>
      <category domain="http://securityratty.com/tag/osu bookstore">osu bookstore</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/06/05/osubooks.aspx">Online theft and fraud involves OSU Bookstore customers</source>
    </item>
    <item>
      <title><![CDATA[Stolen SunGard laptop affects at least 10 post-secondary schools]]></title>
      <link>http://securityratty.com/article/1617ae0ac3225e4776e688f447ddbccc</link>
      <guid>http://securityratty.com/article/1617ae0ac3225e4776e688f447ddbccc</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/17/08

Organization
Various post-secondary schools, including but not necessarily limited to
Central Connecticut State University
Eastern Connecticut...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sungard.jpg" align="right" height="72" width="199"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/17/08<br><br><span style="font-weight: bold;">Organization: </span><br>Various post-secondary schools, including but not necessarily limited to:<br><a href="http://www.ccsu.edu/">Central Connecticut State University</a> <br><a href="http://www.easternct.edu/">Eastern Connecticut State University</a> <br><a href="http://www.southernct.edu/">Southern Connecticut State University</a> <br><a href="http://www.wcsu.edu/%203502">Western Connecticut State University</a> <br><a href="http://www.nmc.edu/">Northwestern Michigan College</a> <br><a href="http://www.nwmissouri.edu/%201100">Northwest Missouri State University</a> <br><a href="http://www.buffalostate.edu/">Buffalo State College</a><br><a href="http://www.brockport.edu/">State University College at Brockport</a><br><a href="http://www.monroecc.edu/">Monroe Community College</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.sungardhe.com/index.aspx">SunGard Higher Education</a>*<br><br><font size="1">*From the SunGard Higher Education "About Us" page:<br>"SunGard Higher Education provides software, strategic consulting, and technology management services to colleges and universities. We help more than 1,600 institutions worldwide strengthen institutional performance by improving constituent services, increasing accountability, and enhancing the education experience.<br><br>SunGard Higher Education has a vision to unify people, process, and technology in an environment that addresses the needs of higher education institutions and the people they serve. We call this vision the Unified Digital Campus."</font><br><font style="font-style: italic;" size="1">[Evan] All of "the needs" except one critical one... SECURITY!</font><br><br><span style="font-weight: bold;">Victims:</span><br>Students and a limited number of employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown, but at least 23702<br><br><span style="font-weight: bold;">Types of Data:</span><br>Personal information including names, Social Security numbers and financial aid information<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A laptop belonging to a consultant at SunGard Higher Education was stolen on March 13, 2008. The theft was immediately reported to law enforcement but the laptop has not been recovered. After analyzing a backup of the computer, SunGard Higher Education found that the stolen laptop contained data from projects with a number of customers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.sungardhe.com/laptoptheft">SunGard Higher Education (general)</a> <br><a href="http://www.newstimes.com/ci_8956150?source=most_emailed">The News-Times (Connecticut State University Schools)</a> <br><a href="http://www.newsday.com/news/local/wire/connecticut/ny-bc-ct--stolenlaptop0417apr17,0,6006519.story">Associated Press Connecticut (Connecticut State University System)</a> <br><a href="http://www.mlive.com/newsflash/michigan/index.ssf?/base/news-52/1208630945313100.xml&amp;storylist=newsmichigan">Associated Press Michigan (Northwestern Michigan College)</a> <br><a href="http://www.maryvilledailyforum.com/articles/2008/04/17/news/news3.txt">Maryville Daily Forum (Northwest Missouri State University)</a> <br><a href="http://www.buffalonews.com/home/story/325975.html">The Buffalo News (Buffalo State College)</a> <br><a href="http://www.democratandchronicle.com/apps/pbcs.dll/article?AID=/20080419/NEWS01/804190328/1002/NEWS">Democrat and Chronicle (State University of New York schools)</a> <br><a href="http://www.nmc.edu/news/2008/041804-potential-data-theft.html">Northwestern Michigan College</a> <br><a href="http://www.buffalostate.edu/privatedata/">Buffalo State College</a> <br><a href="http://www.brockport.edu/newsbureau/1063.html">State University College at Brockport</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>SunGard Higher Education<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A laptop belonging to a consultant at SunGard Higher Education was stolen on March 13, 2008. The theft was immediately reported to law enforcement but the laptop has not been recovered. After analyzing a backup of the computer, SunGard Higher Education found that the stolen laptop contained data from projects with a number of customers.<br><br>Security teams from affected institutions and SunGard Higher Education are working together to analyze and verify the data and notify affected individuals.<br><br>The laptop was protected with a strong password to access the operating system.<br><span style="font-style: italic;">[Evan] It could be the strongest damn password in the world and still not provide an adequate level of security in my opinion.&nbsp; Operating system passwords (especially Windows) can be bypassed in a matter of seconds.&nbsp; This is a poor attempt to minimize the incident.</span><br><br>The computer was password-protected but contained unencrypted files with personally identifiable data<br><span style="font-style: italic;">[Evan] Even though encryption is not the "end all", it would have (in conjunction with other controls) reduced the risk of exposure to a level that is acceptable to many organizations (mine included).</span><br><br>All affected customers have been notified. Customer names will not be disclosed for privacy and security reasons as the investigation continues.<br><span style="font-style: italic;">[Evan] We already know of at least 10 post-secondary institutions.</span><br><br>The laptop was stolen in New York on March 13 and state officials say it contains the names and personal information of 3,502 present and former students of the four CSU universities. <br><br>could put the personal information of 1,600 Northern Michigan College students from 2003 at risk.<br><br>could potentially put personal information about Northwest Missouri State University students and alumni in the wrong hands.<br><br>Northwest believes it followed all appropriate internal procedures for protecting the privacy of its students. For its part, SunGard Higher Education has accepted responsibility for this incident and is working with the University to minimize any adverse consequences.<br><span style="font-style: italic;">[Evan] This is a classic misunderstanding of the roles and responsibilities for information security governance and management.&nbsp; The custodians of the personal information were the schools AND SunGard, not only SunGard.&nbsp; It is the responsibility of the schools (as co-custodians) to require certain information protections from their vendors and contractors.&nbsp; This should be done through policy, contractual language and regular audit/enforcement.</span><br><br>Social Security numbers of about 16,000 current and former Buffalo State College students<br><br>affected thousands of students at State University College at Buffalo, State University College at Brockport and Monroe Community College.<br><br>We believe that the laptop was stolen for the hardware rather than the data. We do not know if any personally identifiable data was accessed by the thieves.<br><span style="font-style: italic;">[Evan] This is another statement meant to minimize the impact of the incident.&nbsp; I do not doubt that often times computer equipment is stolen for the hardware value, but how do we know?&nbsp; I am guessing that more and more criminals are examining the contents of poorly secured computing devices and looking for additional opportunities.&nbsp; The "laptop was stolen for the hardware" argument doesn't work anymore.</span><br><br>The nature of that employee’s job included analysis of customer data as part of software implementation and upgrade projects.<br><br>The laptop was taken from an employee of SunGard, a Pennsylvania-based computer software company that provides Buffalo State’s records system, said Voldemar Innus, a college vice president and chief information officer.<br><br>Innus also said the laptop was secure.<br><span style="font-style: italic;">[Evan] No offense Mr. Innus, but the laptop <span style="font-weight: bold;">WAS NOT</span> secure.</span><br><br>"The laptop was stolen for its own worth as hardware," Innus said. "We do not believe it was stolen because of the information that was on it. And it was heavily password protected, we’re told."<br><br>"The risk I would say is not that high, but that doesn’t matter," Innus said. "There are steps we need to take because of what happened."<br><span style="font-style: italic;">[Evan] People like to throw these terms like "secure" and "risk" around without any validation.&nbsp; How did Mr. Innus determine the risk (of exposure and/or misuse) with respect to this incident?</span><br><br>The data was originally provided for SunGard to perform various services for the university system, but it was apparently retained longer than necessary to perform those services,<br><br>A dedicated Web site containing updated information may be accessed at <a href="http://www.sungardhe.com/laptoptheft.%3Cbr%3E%3Cbr%3EA">www.sungardhe.com/laptoptheft.<br><br></a>A help desk has been established with a toll-free number, (866) 520-2408, to respond to questions from affected individuals.<br><br>Credit monitoring will be provided at no cost to the affected individuals, for a period of one year.<br><span style="font-style: italic;">[Evan] Credit monitoring is a post-fraud activity.&nbsp; One year is very limited for information that has a much longer lifespan.</span><br><br>Buffalo State student reaction:<br>In a campus dormitory, Ben Bissell, a sophomore special education major, and his friend Thomas Dennis, a freshman English education major, were making housing arrangements for next year. Bissell said he got the e-mail and was aware of the situation. Dennis was not. <br><br>Bissell was surprised such sensitive information could be placed in such a portable device as a laptop, which could easily be lost or stolen. <br><span style="font-style: italic;">[Evan] Mr. Bissell is a "data owner" in this instance.&nbsp; The school and SunGard are "data custodians".&nbsp; In simplistic terms, data owners dictate what level of protection is required for the data that they own and data custodians apply the designated level of protection.&nbsp; Did the school and SunGard apply the designated level of protection in this case?</span><br><br>"You’d think it would be somewhat secure," Bissell said of his personal information. <br><br>He plans to closely monitor his bank statements and account activity following the announcement.<br>&nbsp;<br>Omar Vargas, a sophomore elementary education major, told a reporter it was the first he had heard of the stolen laptop, admitting he feels "less secure" knowing about it.<br>&nbsp;<br>"There’s enough things to handle being on campus, like going to classes and deadlines," Vargas said. "Then, just to find out my personal information is threatened is like, man, who knows what that could jeopardize."<br><span style="font-style: italic;">[Evan] Very true.&nbsp; If we all just did what we were supposed to do, we wouldn't have to worry so much about what others aren't doing.</span><br><br>"I could wind up with bad credit when I’m on a good roll."<br><br><span style="font-weight: bold;">Commentary:</span><br>I provided a lot of my commentary above.&nbsp; There is no excuse that I can think of for such poor information security practice and management.&nbsp; Can the people running these companies (such as SunGard) and those responsible for information security claim they didn't know any better?&nbsp; Does it not go against SunGard Higher Education (or school) policy to store confidential information on a laptop while relying solely on operating system level passwords?<br><br>Nuts. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/21/sungard.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 10:49:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/university system">university system</category>
      <category domain="http://securityratty.com/tag/data custodians apply">data custodians apply</category>
      <category domain="http://securityratty.com/tag/data custodians">data custodians</category>
      <category domain="http://securityratty.com/tag/information security governance">information security governance</category>
      <category domain="http://securityratty.com/tag/sungard">sungard</category>
      <source url="http://breachblog.com/2008/04/21/sungard.aspx">Stolen SunGard laptop affects at least 10 post-secondary schools</source>
    </item>
    <item>
      <title><![CDATA[Senator: Let's Spend $1B to monitor P2P for illegal files]]></title>
      <link>http://securityratty.com/article/5bc5edcc6265f327d50fa6815a4c20ea</link>
      <guid>http://securityratty.com/article/5bc5edcc6265f327d50fa6815a4c20ea</guid>
      <description><![CDATA[A prominent Senate Democrat on Wednesday said federal and local police should use custom software to monitor peer-to-peer networks for illegal activity, and wants to spend $1 billion in tax dollars to...]]></description>
      <content:encoded><![CDATA[A prominent Senate Democrat on Wednesday said federal and local police should use custom software to monitor peer-to-peer networks for illegal activity, and wants to spend $1 billion in tax dollars to make that happen.]]></content:encoded>
      <pubDate>Thu, 17 Apr 2008 18:50:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monitor peer-to-peer networks">monitor peer-to-peer networks</category>
      <category domain="http://securityratty.com/tag/local police">local police</category>
      <category domain="http://securityratty.com/tag/tax dollars">tax dollars</category>
      <category domain="http://securityratty.com/tag/illegal activity">illegal activity</category>
      <category domain="http://securityratty.com/tag/custom software">custom software</category>
      <category domain="http://securityratty.com/tag/democrat">democrat</category>
      <category domain="http://securityratty.com/tag/billion">billion</category>
      <category domain="http://securityratty.com/tag/federal">federal</category>
      <category domain="http://securityratty.com/tag/prominent">prominent</category>
      <source url="http://digg.com/security/Senator_Let_s_Spend_1B_to_monitor_P2P_for_illegal_files">Senator: Let's Spend $1B to monitor P2P for illegal files</source>
    </item>
    <item>
      <title><![CDATA[Thoughts on Super Tuesday]]></title>
      <link>http://securityratty.com/article/9040d83d600ef02abaec5ca52d5c3f1c</link>
      <guid>http://securityratty.com/article/9040d83d600ef02abaec5ca52d5c3f1c</guid>
      <description><![CDATA[Since I chimed in on Super Bowl Sunday, let me press my luck and talk about the primaries of Super Tuesday. I stayed up late tonight switching between CNN and Fox News to really get a &quot;fair and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=320,height=240,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/02/05/vote_2008.jpg"><img title="Vote_2008" height="135" alt="Vote_2008" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/02/05/vote_2008.jpg" width="180" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></a> Since I chimed in on Super Bowl Sunday, let me press my luck and talk about the primaries of Super Tuesday. I stayed up late tonight switching between CNN and Fox News to really get a &quot;fair and balanced&quot; view of what was going on.&nbsp; I must say that in all of the years I have been watching presidential races (and the first one I remember was '68), I don't remember both parties having such close races this late in the season.&nbsp; Without letting my own political beliefs get in the way here is my analysis:<br /><br />1. The Republicans - They are in a fight for the soul of this party.&nbsp; Though all three leading candidates claim the title of heir to the Regan revolution, in my mind it is a bit different.&nbsp; Mike Huckabee, clearly is the choice of the Karl Rove wing of the party. He is the choice of the religious right and the South.&nbsp; This is the bedrock of the Republican presidential majority.&nbsp; Taking them on is John McCain who is a genuine war hero, but independent enough to stand for what he believes in and has the record and stature to stand up for it.&nbsp; He makes no bones that he is all about the traditional Republican argument of being strong in foreign policy and probably a bit less involved in economic matters. Finally, you have Mitt Romney who represents, to me anyway, the traditional Republican big business view.&nbsp; So who wins this fight for what it means to be a Republican.&nbsp; Are the Republicans a party of the religious right who vote primarily on social issues such as abortion, gay rights, etc.&nbsp; Are the Republicans the party of big business/small government which was their traditional stand as I grew up. Or finally are they the party who is best suited to keeping America safe and recognizing our own self-proclaimed &quot;manifest destiny&quot;.&nbsp; I guess the rest of the primary season will answer that question.<br /><br />2. The Democrats - Obama has certainly energized a large section of the populace. He is bringing people who never voted or are usually very under represented in elections into the process and that is a good thing.&nbsp; However, when you examine the wins, a Democratic winning their primary in Utah, Alaska and Idaho is just not very exciting. He has as no chance of winning those states in the general election. On the other hand Hillary has certainly demonstrated her ability to win in the traditional Democratic states (including Michigan and Florida, whose votes will have to count in a close race). But is she electable in a general election.&nbsp; She is a lightening rod for Republican wrath it seems.&nbsp; Maybe it is part of that vast right wing conspiracy that she always spoke about.&nbsp; What is interesting on the Democratic side, is I really don't just see a lot of difference in their positions.&nbsp; In fact most people I speak to say it would be cool if they would just join up and run as a ticket.&nbsp; Of course who is on top and bottom is the key to that one, but I don't think it will happen, to much ego there.<br /><br />So, here we are Super Tuesday is over and still no conclusive answers. This is what I do know.&nbsp; No matter who wins the primaries, 40% of this country is going to vote Republican and 40% is going to vote Democrat.&nbsp; It is who the other 20% vote for that will will determine the next President.&nbsp; But as someone who remembers the Civil Rights movement and the womans lib movement.&nbsp; I can tell you that I am thrilled as an American to see in my life time that either an African-American or a woman will be the nominee of one of the major parties.&nbsp; I think it will be a while until we see something like that on the Republican side, but it will come.&nbsp; In the meantime I am looking forward to seeing how this all plays out. But this race is not done so yet, it is up to you to decide who wins.&nbsp; Get out and vote!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=Ypfhg0"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=Ypfhg0" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Bxm0x9E"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Bxm0x9E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=d4mSUxE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=d4mSUxE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Pe7avmE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Pe7avmE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=UWT4QhE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=UWT4QhE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ZBwScmE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ZBwScmE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=z0Fmx3E"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=z0Fmx3E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=9EhYt9E"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=9EhYt9E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DVkp7Me"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DVkp7Me" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qzUz4AE"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qzUz4AE" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 06 Feb 2008 03:44:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vote republican">vote republican</category>
      <category domain="http://securityratty.com/tag/vote">vote</category>
      <category domain="http://securityratty.com/tag/republican">republican</category>
      <category domain="http://securityratty.com/tag/republican presidential majority">republican presidential majority</category>
      <category domain="http://securityratty.com/tag/traditional republican argument">traditional republican argument</category>
      <category domain="http://securityratty.com/tag/traditional republican">traditional republican</category>
      <category domain="http://securityratty.com/tag/super tuesday">super tuesday</category>
      <category domain="http://securityratty.com/tag/vote primarily">vote primarily</category>
      <category domain="http://securityratty.com/tag/party">party</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/230087416/thoughts-on-sup.html">Thoughts on Super Tuesday</source>
    </item>
  </channel>
</rss>
