<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: denials]]></title>
    <link>http://securityratty.com/tag/denials</link>
    <description></description>
    <pubDate>Wed, 12 Mar 2008 14:26:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Downed Georgian Drone Stirs International Incident]]></title>
      <link>http://securityratty.com/article/1a8a08b72f8a57adacfd50dd7d051c14</link>
      <guid>http://securityratty.com/article/1a8a08b72f8a57adacfd50dd7d051c14</guid>
      <description><![CDATA[Georgia's claim that a Russian MiG shot down one of its drones brings condemnation from the United States, denials from Russia and a nice little video clip from Russia...]]></description>
      <content:encoded><![CDATA[Georgia's claim that a Russian MiG shot down one of its drones brings condemnation from the United States, denials from Russia and a nice little video clip from Russia Today.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b7c79c676189030fff79ed1e06259e91" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b7c79c676189030fff79ed1e06259e91" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Pvo48fG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Pvo48fG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=F7QtIag"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=F7QtIag" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xo4qGtg"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xo4qGtg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=4XGUHYG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=4XGUHYG" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=aJXdCpG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=aJXdCpG" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Gp6yHBg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Gp6yHBg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=KSe3Dpg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=KSe3Dpg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=C9JrM8G"><img src="http://feeds.wired.com/~f/wired/politics/security?i=C9JrM8G" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/277019454" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/277019457" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Apr 2008 00:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian mig shot">russian mig shot</category>
      <category domain="http://securityratty.com/tag/drones brings condemnation">drones brings condemnation</category>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <category domain="http://securityratty.com/tag/video clip">video clip</category>
      <category domain="http://securityratty.com/tag/claim">claim</category>
      <category domain="http://securityratty.com/tag/nice">nice</category>
      <category domain="http://securityratty.com/tag/denials">denials</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/277019457/drone-shoot-dow.html">Downed Georgian Drone Stirs International Incident</source>
    </item>
    <item>
      <title><![CDATA[Teen Involved in MySpace Suicide Hoax Says Adult Also Participated]]></title>
      <link>http://securityratty.com/article/17c9576693ad64a5e51111e8284b3997</link>
      <guid>http://securityratty.com/article/17c9576693ad64a5e51111e8284b3997</guid>
      <description><![CDATA[Despite denials, 47-year-old Lori Drew actively participated in the MySpace hoax that led to the suicide of 13-year-old Megan Meier, according to a teenager who admits her own role in the...]]></description>
      <content:encoded><![CDATA[Despite denials, 47-year-old Lori Drew actively participated in the MySpace hoax that led to the suicide of 13-year-old Megan Meier, according to a teenager who admits her own role in the tragedy.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=03db846d93ee10714a81530fc64c2885" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=03db846d93ee10714a81530fc64c2885" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2C1k0qG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2C1k0qG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Hhum0Ag"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Hhum0Ag" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IdLW23g"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IdLW23g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=8WG1FxG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=8WG1FxG" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=nV3vFpG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nV3vFpG" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=oxDJjvg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oxDJjvg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=CqGiSEg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=CqGiSEg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=JACCczG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=JACCczG" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/262168887" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/262168894" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 15:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/13-year-old megan meier">13-year-old megan meier</category>
      <category domain="http://securityratty.com/tag/myspace hoax">myspace hoax</category>
      <category domain="http://securityratty.com/tag/47-year-old lori">47-year-old lori</category>
      <category domain="http://securityratty.com/tag/suicide">suicide</category>
      <category domain="http://securityratty.com/tag/tragedy">tragedy</category>
      <category domain="http://securityratty.com/tag/led">led</category>
      <category domain="http://securityratty.com/tag/teenager">teenager</category>
      <category domain="http://securityratty.com/tag/actively">actively</category>
      <category domain="http://securityratty.com/tag/denials">denials</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/262168894/teen-fingers-lo.html">Teen Involved in MySpace Suicide Hoax Says Adult Also Participated</source>
    </item>
    <item>
      <title><![CDATA[5 Lessons on Public Disclosure From Elliot Spitzer]]></title>
      <link>http://securityratty.com/article/903b8c49dfb4f1b49906d969804523ba</link>
      <guid>http://securityratty.com/article/903b8c49dfb4f1b49906d969804523ba</guid>
      <description><![CDATA[Regardless of what you think about now former governor Spitzer and what he did, we can learn a lot from how he handled the public disclosure of his err vulnerability Here are 5 lessons you can use if...]]></description>
      <content:encoded><![CDATA[<p>Regardless of what you think about now former governor Spitzer and what he did, we can learn a lot from how he handled the public disclosure of his err &#8220;vulnerability&#8221; Here are 5 lessons you can use if you ever find yourself involved in a public disclosure of a vulnerability on your web site or a disclosure of a massive breach.</p>
<p>1. Understand that you have been caught.</p>
<p>Spitzer quickly understood that the cards where stacked against him and decided denials and platitudes where not going to work for him. Perhaps as a former prosecutor he knew how strong the case was against him. If you are dealing with an incident it is important to understand that excuses for poor security are not helpful right now and dealing with the task at hand has to take top priority. Also do not try to deflect by making up stories of honeypots, false alarms, or &#8220;really it is not a problem&#8221; statements.</p>
<p>2. Get out in front.</p>
<p>Maybe it is just because I am on the west coast, but it seemed like as soon as I heard the story I also heard that he had a press conference. This is a pretty quick response. In this case he probably knew it was coming since The New York Times probably gave him a courtesy call. You are not going to be that lucky so you will be playing catch up but it is important to respond quickly and decisively.</p>
<p>3. Don&#8217;t give up the ghost.</p>
<p>Spitzer&#8217;s first press conference was masterful. He admitted everything and nothing at the same time. This is when a good PR person can prove invaluable to the Incident Response Team. You want to acknowledge the problem, give concert steps you are taking, and buy time to get all your ducks in a row. If you are dealing with a large leak of credit cards for example you are going to need some time to figure out just what the heck is going on, who is effected, and what your response is going to be all while waiting for law enforcement to get out of the way.</p>
<p>4. Use the time you just bought.</p>
<p>Assuming you did #3 reasonably well you now have some time to figure out how you are going to respond. If you have law enforcement involved your hands are probably somewhat ties as they are going to want to control the flow of information. One area law enforcement is not going to get involved with is how you are going to respond to your customers. This template seems to have already been written, credit monitoring for a year and some gift cards. You can do better!</p>
<p>5. Cut your loses.</p>
<p>At some point you are going to need to get back to work and put this incident behind you. If the police are not involved this should probably be sooner rather than later. I have seen companies sink a lot of time and effort into trying to catch the person when there is little chance of getting anything out of it. I worked several cases where I tracked the attacker back to some non-US country that is practically impossible to get anything done and especially if it is just you and not the feds. There is some joy in finding out who did it but your time and money      is generally better spent finding out how it happened and correcting the the issue then finding out who. The who is most times irrelevant (unless it is an insider of course).</p>
<p class="a2a_link"><a href="http://www.addtoany.com/?sitename=Grumpy Security Guy&amp;siteurl=http://www.grumpysecurityguy.com&amp;linkname=5 Lessons on Public Disclosure From Elliot Spitzer&amp;linkurl=http://www.grumpysecurityguy.com/5-lessons-on-public-disclosure-from-elliot-spitzer/&amp;type=page"><img src="http://www.addtoany.com/bookmark.gif" width="91" height="17" border="0" title="Add to any service" alt="Add to any service"/></a>
</p><div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://www.grumpysecurityguy.com/top-10-underground-security-resources/" rel="bookmark" title="Permanent Link: Top 10 &#8220;Underground&#8221; Security Resources" >Top 10 &#8220;Underground&#8221; Security Resources</a></span><div class="aizattos_related_posts_excerpt">Not underground like the Russian Business Network but not as well known as some people think. These ...</div></li><li><span class="aizattos_related_posts_title"><a href="http://www.grumpysecurityguy.com/fight-cross-site-scripting-in-your-net-apps/" rel="bookmark" title="Permanent Link: Fight Cross Site Scripting in your .NET Apps" >Fight Cross Site Scripting in your .NET Apps</a></span><div class="aizattos_related_posts_excerpt">Microsoft just released a free Visual Source Safe plugin to help identify XSS (Cross Site Scripting)...</div></li><li><span class="aizattos_related_posts_title"><a href="http://www.grumpysecurityguy.com/5-security-predictions-for-2008/" rel="bookmark" title="Permanent Link: 5 Security Predictions for 2008" >5 Security Predictions for 2008</a></span><div class="aizattos_related_posts_excerpt">1. We will see the first multi-website XSS worm.

I think we will finally get a true cross site XS...</div></li><li><span class="aizattos_related_posts_title"><a href="http://www.grumpysecurityguy.com/top-10-security-stories-of-2007/" rel="bookmark" title="Permanent Link: Top 10 Security Stories of 2007" >Top 10 Security Stories of 2007</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://www.grumpysecurityguy.com/mythbusting-ssl/" rel="bookmark" title="Permanent Link: Mythbusting SSL" >Mythbusting SSL</a></span></li></ul></div><p>Post from: <a href="http://www.grumpysecurityguy.com">Grumpy Security Guy</a></p>
<p><a href="http://www.grumpysecurityguy.com/5-lessons-on-public-disclosure-from-elliot-spitzer/">5 Lessons on Public Disclosure From Elliot Spitzer</a></p>

<p><a href="http://feeds.feedburner.com/~a/GrumpySecurityGuy?a=25JRPS"><img src="http://feeds.feedburner.com/~a/GrumpySecurityGuy?i=25JRPS" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=ll0g4MF"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=ll0g4MF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=t2Vkt5F"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=t2Vkt5F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=u1yl9wf"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=u1yl9wf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=tt7SqEf"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=tt7SqEf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=ws4zuoF"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=ws4zuoF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=07edTvF"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=07edTvF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=7fnFJKF"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=7fnFJKF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=QFENndf"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=QFENndf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GrumpySecurityGuy?a=sKq2WOf"><img src="http://feeds.feedburner.com/~f/GrumpySecurityGuy?i=sKq2WOf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GrumpySecurityGuy/~4/250246151" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 14:26:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/public disclosure">public disclosure</category>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/response">response</category>
      <category domain="http://securityratty.com/tag/pretty quick response">pretty quick response</category>
      <category domain="http://securityratty.com/tag/cross site">cross site</category>
      <category domain="http://securityratty.com/tag/fight cross site">fight cross site</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/incident response team">incident response team</category>
      <source url="http://feeds.feedburner.com/~r/GrumpySecurityGuy/~3/250246151/">5 Lessons on Public Disclosure From Elliot Spitzer</source>
    </item>
  </channel>
</rss>
