<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dennis]]></title>
    <link>http://securityratty.com/tag/dennis</link>
    <description></description>
    <pubDate>Tue, 12 Feb 2008 12:03:09 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Speaking of Security Podcast #123]]></title>
      <link>http://securityratty.com/article/7c6bde3b610c9fe31746a6ef7b3051f1</link>
      <guid>http://securityratty.com/article/7c6bde3b610c9fe31746a6ef7b3051f1</guid>
      <description><![CDATA[Click to Download/Listen (07:03

Recent updates to the Fair and Accurate Credit Transactions Act (FACTA) of 2003 mandate that U.S. financial institutions and creditors must comply with the Identity...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1354">Click to Download/Listen</a> (07:03)<br><br />Recent updates to the Fair and Accurate Credit Transactions Act (FACTA) of 2003   mandate that U.S. financial institutions and creditors must <strong>comply with   the Identity Theft Red Flag provisions by November 1, 2008</strong>. Amanda Van Veen speaks with EMC's resident <a href="http://rsa.com/node.aspx?id=3479" target="_blank">FACTA</a> expert, Dennis Mayer from <a href="http://www.emc.com/services/consulting/business/offerings/compliance-management-financial-services.htm" target="_blank">EMC Consulting</a> about the upcoming deadline and what it means to those who must comply.<br /><br /><br />]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facta">facta</category>
      <category domain="http://securityratty.com/tag/resident facta expert">resident facta expert</category>
      <category domain="http://securityratty.com/tag/credit transactions act">credit transactions act</category>
      <category domain="http://securityratty.com/tag/dennis mayer">dennis mayer</category>
      <category domain="http://securityratty.com/tag/emc">emc</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <category domain="http://securityratty.com/tag/amanda van">amanda van</category>
      <category domain="http://securityratty.com/tag/financial institutions">financial institutions</category>
      <category domain="http://securityratty.com/tag/creditors">creditors</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1354">Speaking of Security Podcast #123</source>
    </item>
    <item>
      <title><![CDATA[Show 029 - An Interview with Dennis Fisher]]></title>
      <link>http://securityratty.com/article/ed23afa251e7ed42c51726c5d78957a6</link>
      <guid>http://securityratty.com/article/ed23afa251e7ed42c51726c5d78957a6</guid>
      <description><![CDATA[On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget. Dennis helps run SearchSecurity.com and...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Dennis Fisher" title="Dennis Fisher" src="http://www.cigital.com/silverbullet/dfisher-108.png" style="padding-left: 7px;" /></p>
<p>On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and <em>Information Security Magazine</em>.  Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state of software security, and which is harder: being a fry cook at Hardees or working as a PR flack.</p>
<ul>
<li><a href="http://security.blogs.techtarget.com/author/security/">Dennis&#8217; blog</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1239802,00.html">TJX</a></li>
<li><a href="http://music.aol.com/video/dirty-laundry/the-eagles/tag/joe-walsh/1354381">Joe Walsh plays dirty laundry</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1237978">Software Security Grows</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/2008/07/31/the-state-of-software-security">Dennis&#8217; un-named podcast</a></li>
<li><a href="http://www.youtube.com/watch?v=f99PcP0aFNE">Series of Tubes</a></li>
<li><a href="http://www.hardees.com/">Hardees</a></li>
<li><a href="http://www.cs.washington.edu/research/systems/privacy.htm">Nike/iPod</a></li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 11:05:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dennis">dennis</category>
      <category domain="http://securityratty.com/tag/dennis fisher">dennis fisher</category>
      <category domain="http://securityratty.com/tag/dennis discuss">dennis discuss</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/software security grows">software security grows</category>
      <category domain="http://securityratty.com/tag/dennis helps">dennis helps</category>
      <category domain="http://securityratty.com/tag/tjx privacy breach">tjx privacy breach</category>
      <category domain="http://securityratty.com/tag/tjx">tjx</category>
      <category domain="http://securityratty.com/tag/gary talks">gary talks</category>
      <source url="http://www.cigital.com/silverbullet/show-029/">Show 029 - An Interview with Dennis Fisher</source>
    </item>
    <item>
      <title><![CDATA[Vulnerability in SNMP 3]]></title>
      <link>http://securityratty.com/article/51ac6442a07e08115c26e79b4e77336a</link>
      <guid>http://securityratty.com/article/51ac6442a07e08115c26e79b4e77336a</guid>
      <description><![CDATA[Dennis Fisher blogs over at SearchSecurity.com about a new critical flaw found in SNMPv3 . I have blogged before how some NAC vendors that utilize SNMP have tried to fool unknowing sys admins that...]]></description>
      <content:encoded><![CDATA[<p>Dennis Fisher blogs over at SearchSecurity.com about a <a href="http://security.blogs.techtarget.com/2008/06/10/critical-flaw-found-in-snmpv3/">new critical flaw found in SNMPv3</a>. I have blogged before how some NAC vendors that utilize SNMP have tried to fool unknowing sys admins that SNMP stands for security network management protocol, instead of simple NMP. <br><br>The SNMP zealots have always tried to counter the SNMP is not secure arguments by pointing to v3 as very security method and now this flaw is found. How many more will be found? In any event glad they found and fixed this. Now if they could just find someone using SNMPv3 it would be great!</p><blockquote></blockquote>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=jWr0nD"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=jWr0nD" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2GwKGI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2GwKGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=EiqtHI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=EiqtHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qizSPI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qizSPI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=9tzXNI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=9tzXNI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=k1Eloi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=k1Eloi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=0mXTHi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=0mXTHi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/309585000" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 03:17:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/snmp">snmp</category>
      <category domain="http://securityratty.com/tag/snmp stands">snmp stands</category>
      <category domain="http://securityratty.com/tag/snmp zealots">snmp zealots</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/dennis fisher blogs">dennis fisher blogs</category>
      <category domain="http://securityratty.com/tag/critical flaw">critical flaw</category>
      <category domain="http://securityratty.com/tag/nac vendors">nac vendors</category>
      <category domain="http://securityratty.com/tag/sys admins">sys admins</category>
      <category domain="http://securityratty.com/tag/security method">security method</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/309585000/vulnerability-i.html">Vulnerability in SNMP 3</source>
    </item>
    <item>
      <title><![CDATA[Way to go Dennis!]]></title>
      <link>http://securityratty.com/article/4aea82937193f02f74748f2ca5bfcb28</link>
      <guid>http://securityratty.com/article/4aea82937193f02f74748f2ca5bfcb28</guid>
      <description><![CDATA[A story with a good ending. So many Vets dont get what they deserve form us


clipped from www.steamboatpilot.com
Country, community, commencement


Craig The year was 1964, and Dennis Collins, a...]]></description>
      <content:encoded><![CDATA[<div > A story with a good ending. So many Vets dont get what they deserve form us.<br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/7BF3AD95-6403-4A7A-8B43-94E91085E8F6/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/75b9fc3b-e42d-4d2a-a4f2-0f1e0b915827/7BF3AD95-6403-4A7A-8B43-94E91085E8F6/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.steamboatpilot.com/news/2008/may/24/country_community_commencement/" href="http://www.steamboatpilot.com/news/2008/may/24/country_community_commencement/" style="font-size: 11px;">www.steamboatpilot.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.steamboatpilot.com/news/2008/may/24/country_community_commencement/ --><H2 class="story-headline">Country, community, commencement</H2></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.steamboatpilot.com/news/2008/may/24/country_community_commencement/ --><P><SPAN class="dateline">Craig</SPAN> — The year was 1964, and Dennis Collins, a wild, 17-year-old Moffat County High School junior, had a family tradition to follow and a country to protect.</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.steamboatpilot.com/news/2008/may/24/country_community_commencement/ --><P>Collins, 60, joins more than 150 high school seniors in donning cap and gown and receiving their high school diplomas during commencement services in the MCHS gymnasium.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/7BF3AD95-6403-4A7A-8B43-94E91085E8F6/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Sun, 25 May 2008 10:56:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dennis collins">dennis collins</category>
      <category domain="http://securityratty.com/tag/collins">collins</category>
      <category domain="http://securityratty.com/tag/commencement services">commencement services</category>
      <category domain="http://securityratty.com/tag/commencement">commencement</category>
      <category domain="http://securityratty.com/tag/17-year-old moffat county">17-year-old moffat county</category>
      <category domain="http://securityratty.com/tag/family tradition">family tradition</category>
      <category domain="http://securityratty.com/tag/deserve form">deserve form</category>
      <category domain="http://securityratty.com/tag/school diplomas">school diplomas</category>
      <category domain="http://securityratty.com/tag/mchs gymnasium">mchs gymnasium</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=461">Way to go Dennis!</source>
    </item>
    <item>
      <title><![CDATA[Stolen SunGard laptop affects at least 10 post-secondary schools]]></title>
      <link>http://securityratty.com/article/1617ae0ac3225e4776e688f447ddbccc</link>
      <guid>http://securityratty.com/article/1617ae0ac3225e4776e688f447ddbccc</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/17/08

Organization
Various post-secondary schools, including but not necessarily limited to
Central Connecticut State University
Eastern Connecticut...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sungard.jpg" align="right" height="72" width="199"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/17/08<br><br><span style="font-weight: bold;">Organization: </span><br>Various post-secondary schools, including but not necessarily limited to:<br><a href="http://www.ccsu.edu/">Central Connecticut State University</a> <br><a href="http://www.easternct.edu/">Eastern Connecticut State University</a> <br><a href="http://www.southernct.edu/">Southern Connecticut State University</a> <br><a href="http://www.wcsu.edu/%203502">Western Connecticut State University</a> <br><a href="http://www.nmc.edu/">Northwestern Michigan College</a> <br><a href="http://www.nwmissouri.edu/%201100">Northwest Missouri State University</a> <br><a href="http://www.buffalostate.edu/">Buffalo State College</a><br><a href="http://www.brockport.edu/">State University College at Brockport</a><br><a href="http://www.monroecc.edu/">Monroe Community College</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.sungardhe.com/index.aspx">SunGard Higher Education</a>*<br><br><font size="1">*From the SunGard Higher Education "About Us" page:<br>"SunGard Higher Education provides software, strategic consulting, and technology management services to colleges and universities. We help more than 1,600 institutions worldwide strengthen institutional performance by improving constituent services, increasing accountability, and enhancing the education experience.<br><br>SunGard Higher Education has a vision to unify people, process, and technology in an environment that addresses the needs of higher education institutions and the people they serve. We call this vision the Unified Digital Campus."</font><br><font style="font-style: italic;" size="1">[Evan] All of "the needs" except one critical one... SECURITY!</font><br><br><span style="font-weight: bold;">Victims:</span><br>Students and a limited number of employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown, but at least 23702<br><br><span style="font-weight: bold;">Types of Data:</span><br>Personal information including names, Social Security numbers and financial aid information<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A laptop belonging to a consultant at SunGard Higher Education was stolen on March 13, 2008. The theft was immediately reported to law enforcement but the laptop has not been recovered. After analyzing a backup of the computer, SunGard Higher Education found that the stolen laptop contained data from projects with a number of customers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.sungardhe.com/laptoptheft">SunGard Higher Education (general)</a> <br><a href="http://www.newstimes.com/ci_8956150?source=most_emailed">The News-Times (Connecticut State University Schools)</a> <br><a href="http://www.newsday.com/news/local/wire/connecticut/ny-bc-ct--stolenlaptop0417apr17,0,6006519.story">Associated Press Connecticut (Connecticut State University System)</a> <br><a href="http://www.mlive.com/newsflash/michigan/index.ssf?/base/news-52/1208630945313100.xml&amp;storylist=newsmichigan">Associated Press Michigan (Northwestern Michigan College)</a> <br><a href="http://www.maryvilledailyforum.com/articles/2008/04/17/news/news3.txt">Maryville Daily Forum (Northwest Missouri State University)</a> <br><a href="http://www.buffalonews.com/home/story/325975.html">The Buffalo News (Buffalo State College)</a> <br><a href="http://www.democratandchronicle.com/apps/pbcs.dll/article?AID=/20080419/NEWS01/804190328/1002/NEWS">Democrat and Chronicle (State University of New York schools)</a> <br><a href="http://www.nmc.edu/news/2008/041804-potential-data-theft.html">Northwestern Michigan College</a> <br><a href="http://www.buffalostate.edu/privatedata/">Buffalo State College</a> <br><a href="http://www.brockport.edu/newsbureau/1063.html">State University College at Brockport</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>SunGard Higher Education<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A laptop belonging to a consultant at SunGard Higher Education was stolen on March 13, 2008. The theft was immediately reported to law enforcement but the laptop has not been recovered. After analyzing a backup of the computer, SunGard Higher Education found that the stolen laptop contained data from projects with a number of customers.<br><br>Security teams from affected institutions and SunGard Higher Education are working together to analyze and verify the data and notify affected individuals.<br><br>The laptop was protected with a strong password to access the operating system.<br><span style="font-style: italic;">[Evan] It could be the strongest damn password in the world and still not provide an adequate level of security in my opinion.&nbsp; Operating system passwords (especially Windows) can be bypassed in a matter of seconds.&nbsp; This is a poor attempt to minimize the incident.</span><br><br>The computer was password-protected but contained unencrypted files with personally identifiable data<br><span style="font-style: italic;">[Evan] Even though encryption is not the "end all", it would have (in conjunction with other controls) reduced the risk of exposure to a level that is acceptable to many organizations (mine included).</span><br><br>All affected customers have been notified. Customer names will not be disclosed for privacy and security reasons as the investigation continues.<br><span style="font-style: italic;">[Evan] We already know of at least 10 post-secondary institutions.</span><br><br>The laptop was stolen in New York on March 13 and state officials say it contains the names and personal information of 3,502 present and former students of the four CSU universities. <br><br>could put the personal information of 1,600 Northern Michigan College students from 2003 at risk.<br><br>could potentially put personal information about Northwest Missouri State University students and alumni in the wrong hands.<br><br>Northwest believes it followed all appropriate internal procedures for protecting the privacy of its students. For its part, SunGard Higher Education has accepted responsibility for this incident and is working with the University to minimize any adverse consequences.<br><span style="font-style: italic;">[Evan] This is a classic misunderstanding of the roles and responsibilities for information security governance and management.&nbsp; The custodians of the personal information were the schools AND SunGard, not only SunGard.&nbsp; It is the responsibility of the schools (as co-custodians) to require certain information protections from their vendors and contractors.&nbsp; This should be done through policy, contractual language and regular audit/enforcement.</span><br><br>Social Security numbers of about 16,000 current and former Buffalo State College students<br><br>affected thousands of students at State University College at Buffalo, State University College at Brockport and Monroe Community College.<br><br>We believe that the laptop was stolen for the hardware rather than the data. We do not know if any personally identifiable data was accessed by the thieves.<br><span style="font-style: italic;">[Evan] This is another statement meant to minimize the impact of the incident.&nbsp; I do not doubt that often times computer equipment is stolen for the hardware value, but how do we know?&nbsp; I am guessing that more and more criminals are examining the contents of poorly secured computing devices and looking for additional opportunities.&nbsp; The "laptop was stolen for the hardware" argument doesn't work anymore.</span><br><br>The nature of that employee’s job included analysis of customer data as part of software implementation and upgrade projects.<br><br>The laptop was taken from an employee of SunGard, a Pennsylvania-based computer software company that provides Buffalo State’s records system, said Voldemar Innus, a college vice president and chief information officer.<br><br>Innus also said the laptop was secure.<br><span style="font-style: italic;">[Evan] No offense Mr. Innus, but the laptop <span style="font-weight: bold;">WAS NOT</span> secure.</span><br><br>"The laptop was stolen for its own worth as hardware," Innus said. "We do not believe it was stolen because of the information that was on it. And it was heavily password protected, we’re told."<br><br>"The risk I would say is not that high, but that doesn’t matter," Innus said. "There are steps we need to take because of what happened."<br><span style="font-style: italic;">[Evan] People like to throw these terms like "secure" and "risk" around without any validation.&nbsp; How did Mr. Innus determine the risk (of exposure and/or misuse) with respect to this incident?</span><br><br>The data was originally provided for SunGard to perform various services for the university system, but it was apparently retained longer than necessary to perform those services,<br><br>A dedicated Web site containing updated information may be accessed at <a href="http://www.sungardhe.com/laptoptheft.%3Cbr%3E%3Cbr%3EA">www.sungardhe.com/laptoptheft.<br><br></a>A help desk has been established with a toll-free number, (866) 520-2408, to respond to questions from affected individuals.<br><br>Credit monitoring will be provided at no cost to the affected individuals, for a period of one year.<br><span style="font-style: italic;">[Evan] Credit monitoring is a post-fraud activity.&nbsp; One year is very limited for information that has a much longer lifespan.</span><br><br>Buffalo State student reaction:<br>In a campus dormitory, Ben Bissell, a sophomore special education major, and his friend Thomas Dennis, a freshman English education major, were making housing arrangements for next year. Bissell said he got the e-mail and was aware of the situation. Dennis was not. <br><br>Bissell was surprised such sensitive information could be placed in such a portable device as a laptop, which could easily be lost or stolen. <br><span style="font-style: italic;">[Evan] Mr. Bissell is a "data owner" in this instance.&nbsp; The school and SunGard are "data custodians".&nbsp; In simplistic terms, data owners dictate what level of protection is required for the data that they own and data custodians apply the designated level of protection.&nbsp; Did the school and SunGard apply the designated level of protection in this case?</span><br><br>"You’d think it would be somewhat secure," Bissell said of his personal information. <br><br>He plans to closely monitor his bank statements and account activity following the announcement.<br>&nbsp;<br>Omar Vargas, a sophomore elementary education major, told a reporter it was the first he had heard of the stolen laptop, admitting he feels "less secure" knowing about it.<br>&nbsp;<br>"There’s enough things to handle being on campus, like going to classes and deadlines," Vargas said. "Then, just to find out my personal information is threatened is like, man, who knows what that could jeopardize."<br><span style="font-style: italic;">[Evan] Very true.&nbsp; If we all just did what we were supposed to do, we wouldn't have to worry so much about what others aren't doing.</span><br><br>"I could wind up with bad credit when I’m on a good roll."<br><br><span style="font-weight: bold;">Commentary:</span><br>I provided a lot of my commentary above.&nbsp; There is no excuse that I can think of for such poor information security practice and management.&nbsp; Can the people running these companies (such as SunGard) and those responsible for information security claim they didn't know any better?&nbsp; Does it not go against SunGard Higher Education (or school) policy to store confidential information on a laptop while relying solely on operating system level passwords?<br><br>Nuts. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/21/sungard.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 10:49:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/university system">university system</category>
      <category domain="http://securityratty.com/tag/data custodians apply">data custodians apply</category>
      <category domain="http://securityratty.com/tag/data custodians">data custodians</category>
      <category domain="http://securityratty.com/tag/information security governance">information security governance</category>
      <category domain="http://securityratty.com/tag/sungard">sungard</category>
      <source url="http://breachblog.com/2008/04/21/sungard.aspx">Stolen SunGard laptop affects at least 10 post-secondary schools</source>
    </item>
    <item>
      <title><![CDATA[Welcome to Microsoft Dennis Groves]]></title>
      <link>http://securityratty.com/article/b3436df5d4d82446f3131eda7fa22553</link>
      <guid>http://securityratty.com/article/b3436df5d4d82446f3131eda7fa22553</guid>
      <description><![CDATA[I have been waiting to send this email since January; welcome to Microsoft Dennis Groves. Dennis will be a Technical Product Manager for the Connected Information Security Framework (more on that as...]]></description>
      <content:encoded><![CDATA[I have been waiting to send this email since January; welcome to Microsoft Dennis Groves. Dennis will be a Technical Product Manager for the Connected Information Security Framework (more on that as promised next week). Dennis started OWASP with me back in the day and we have been trying to find a way to work [...]]]></content:encoded>
      <pubDate>Wed, 16 Apr 2008 10:29:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft dennis groves">microsoft dennis groves</category>
      <category domain="http://securityratty.com/tag/dennis">dennis</category>
      <category domain="http://securityratty.com/tag/information security framework">information security framework</category>
      <category domain="http://securityratty.com/tag/technical product manager">technical product manager</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/january">january</category>
      <source url="http://securitybuddha.com/2008/04/16/welcome-to-microsoft-dennis-groves/">Welcome to Microsoft Dennis Groves</source>
    </item>
    <item>
      <title><![CDATA[Captching]]></title>
      <link>http://securityratty.com/article/4117a54df497d1ac4f8423959fa6ef61</link>
      <guid>http://securityratty.com/article/4117a54df497d1ac4f8423959fa6ef61</guid>
      <description><![CDATA[Dennis Groves just sent me this, made me chuckle. Earlier this year an XSS Worm contest was going on. A few people got passionate about the ethics but essentially everyone watched on to an anticipated...]]></description>
      <content:encoded><![CDATA[
Dennis Groves just sent me this, made me chuckle. Earlier this year an XSS Worm contest was going on. A few people got passionate about the ethics but essentially everyone watched on to an anticipated dull outcome. I wonder wether a competition to share exploit code to generate the most ridiculous words on a Public [...]]]></content:encoded>
      <pubDate>Fri, 22 Feb 2008 20:21:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/share exploit code">share exploit code</category>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <category domain="http://securityratty.com/tag/dull outcome">dull outcome</category>
      <category domain="http://securityratty.com/tag/ridiculous words">ridiculous words</category>
      <category domain="http://securityratty.com/tag/dennis groves">dennis groves</category>
      <category domain="http://securityratty.com/tag/competition">competition</category>
      <category domain="http://securityratty.com/tag/chuckle">chuckle</category>
      <category domain="http://securityratty.com/tag/ethics">ethics</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://securitybuddha.com/2008/02/22/captching/">Captching</source>
    </item>
    <item>
      <title><![CDATA[Malicious Advertising (Malvertising) Increasing]]></title>
      <link>http://securityratty.com/article/37f3f9caf6504e11892262d9abcaab70</link>
      <guid>http://securityratty.com/article/37f3f9caf6504e11892262d9abcaab70</guid>
      <description><![CDATA[In the wake of the recent malvertising incidents, it's about time we get to the bottom of the campaigns, define the exact hosts and IPs participating, all of their current campaigns, and who's behind...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp3.blogger.com/_wICHhTiQmrA/R7z0Lqd7luI/AAAAAAAABZA/rrRqUaH-p9k/s1600-h/malvertising_providers.jpg"><img id="BLOGGER_PHOTO_ID_5169274953530054370" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R7z0Lqd7luI/AAAAAAAABZA/rrRqUaH-p9k/s200/malvertising_providers.jpg" border="0" /></a>In the wake of the recent malvertising incidents, it's about time we get to the bottom of the campaigns, define the exact hosts and IPs participating, all of their current campaigns, and who's behind them. Who's been hit at the first place? <a href="http://blog.trendmicro.com/malicious-banners-target-expediacom-and-rhapsodycom/">Expedia</a>, <a href="http://www.theregister.co.uk/2008/01/30/excite_and_rhapsody_rogue_ads/">Excite</a>, <a href="http://campustechnology.com/articles/58272/">Rhapsody</a>, <a href="http://blog.trendmicro.com/myspace-excite-and-blick-serve-up-malicious-banner-ads/">MySpace</a>, all major <a href="http://blog.washingtonpost.com/securityfix/2008/01/malwarelaced_banner_ads_at_mys.html">web properties</a>. Now let's outline the malicious parties involved. These are the currently active domains delivering malicious flash advertisements that were, and still participate in the rogue ads attacks :</div><br /><div></div>01. <span style="font-weight: bold;">quinquecahue.com (190.15.64.190)</span><br />quinquecahue.com/swf/gnida.swf?campaign=tautonymus<br />quinquecahue.com/swf/gnida.swf?campaign=atliverish<br />quinquecahue.com/statsg.php?campaign=meatrichia<br /><div>quinquecahue.com/swf/gnida.swf?campaign=atticismus</div><br /><div></div>02. <span style="font-weight: bold;">akamahi.net (190.15.64.185)</span><br />akamahi.net/swf/gnida.swf?cam<br />akamahi.net/swf/gnida.swf?campaign=innational<br />akamahi.net/swf/gnida.swf?campaign=annalistno<br />akamahi.net/statsg.php?u=1199891594&amp;campaign=annalistno<br /><br /><div></div>03. <span style="font-weight: bold;">thetechnorati.com (190.15.64.191)</span><br />thetechnorati.com/swf/gnida.swf?campaign=ofcavalier<br />thetechnorati.com/swf/gnida.swf?campaign=whoduniton<br />thetechnorati.com/statsg.php?u=1198689218<br /><br /><div></div>04. <span style="font-weight: bold;">vozemiliogaranon.com (190.15.64.192)</span><br />vozemiliogaranon.com/statss.php?campaign=zoolatrymy<br />vozemiliogaranon.com/swf/gnida.swf?campaign=zoolatrymy<br />vozemiliogaranon.com/statss.php?campaign=revenantan<br /><br /><div></div>05. <span style="font-weight: bold;">newbieadguide.com (190.15.64.188)</span><br />newbieadguide.com/statsg.php?campaign=missblue<br />newbieadguide.com/statsg.php?campaign=2rapid1y<br />newbieadguide.com/statsg.php?campaign=missblue<br />newbieadguide.com/statsg.php?campaign=germanit<br />newbieadguide.com/swf/gnida.swf?campaign=ta5temix<br />newbieadguide.com/swf/gnida.swf?campaign=c0pperin<br />newbieadguide.com/swf/gnida.swf?campaign=remain0r<br />newbieadguide.com/swf/gnida.swf?campaign=mi1eroof<br />newbieadguide.com/swf/gnida.swf?campaign=m9in9re9<br /><br /><div></div>06. <span style="font-weight: bold;">traffalo.com (84.243.252.94)</span><br />traffalo.com/swf/gnida.swf?campaign=atekistics<br />traffalo.com/swf/gnida.swf?campaign=byagnostic<br />traffalo.com/statsg.php?u=1201711626<div>traffalo.com/statsg.php?u=1202224809</div><br /><div></div>07. <span style="font-weight: bold;">burnads.com (84.243.252.85)</span><br />burnads.com/swf/gnida.swf?campaign=1akeweak<br />burnads.com/swf/gnida.swf?campaign=flatfootup<br /><br /><div></div>08. <span style="font-weight: bold;">v0zemili0garan0n.com</span><br />v0zemili0garan0n.com/statsg.php?u=1199391035<br /><br /><div></div>09. <span style="font-weight: bold;">adtraff.com (84.243.252.84)</span><br />adtraff.com/swf/gnida.swf?campaign=forcejoe<br />adtraff.com/swf/gnida.swf?campaign=forcejoe<br />adtraff.com/swf/gnida.swf?campaign=forcejoe<br /><div>adtraff.com/swf/gnida.swf?campaign=forcejoe</div>adtraff.com/swf/gnida.swf?campaign=forcejoe<br />adtraff.com/swf/gnida.swf?campaign=weightt0<br /><br /><div></div>10. <span style="font-weight: bold;">mysurvey4u.com (194.110.67.22)</span><br />mysurvey4u.com/swf/gnida.swf?campaign=rubberu5<br /><div>mysurvey4u.com/swf/gnida.swf?campaign=me9ntthe</div><br /><div></div>11. <span style="font-weight: bold;">traveltray.com (194.110.67.23)</span><br />traveltray.com/swf/gnida.swf?campaign=pavoninean<br /><br /><div></div>12. <span style="font-weight: bold;">tds.promoplexer.com (217.20.175.39)</span><br />tds.promoplexer.com/statsg.php<br />adtds2.promoplexer.com/in.cgi?2<br /><div></div><br />Additional domains sharing IPs with some of the domains, ones that will eventually used in upcoming campaigns :<br /><div></div><br /><span style="font-weight: bold;">aboutstat.com</span><br /><span style="font-weight: bold;">newstat.net</span><br /><span style="font-weight: bold;">officialstat.com</span><br /><span style="font-weight: bold;">stathisranch.net</span><br /><div><span style="font-weight: bold;">station-appraisals.net</span><br /></div><br /><div></div>Contact details of the fake new media advertising agencies :<br /><br /><div></div>- Traffalo - "<span style="font-style: italic;">A Leader in Online Behavioral Marketing</span>"<br />Phone: +46-40-627-1655<br />Fax: +46-8-501-09210<br /><br /><div></div>- MyServey4u - "<span style="font-style: italic;">Relax At Home ... And Get Paid For Your Opinion!</span>"<br />mysurvey4u.com<br /><br />- AdTraff - "<span style="font-style: italic;">Leader enterprise in Online Marketing</span>"<p>Phone number: +49-511-26-098-2104<br />Fax: +353-1-633-51-70<br /></p><p><span style="font-weight: bold;">Detection rate :</span><br /></p><p>gnida.swf : Result: 21/32 (65.63%)<br />Trojan-Downloader.SWF.Gida.a; Troj/Gida-A<br /><span style="font-weight: bold;">File size</span>: 3186 bytes<br /><span style="font-weight: bold;">MD5</span>: 015ebcd3ad6fef1cb1b763ccdd63de0c<br /><span style="font-weight: bold;">SHA1</span>: 5150568667809b1443b5187ce922b490fe884349<br />packers: Swf2Swc<br /></p><p>The bottom line - who's behind it? Now that pretty much all the domains involved are known, as well as the structure of the campaign itself, it's interesting to discuss where are all the advertisements pointing to. Can you name a three letter acronym for a cybercrime powerhouse? Yep, RBN's historical customers' base, still using <a href="http://rbnexploit.blogspot.com/2007/11/rbn-pc-hijacking-via-banner-ads-on.html">RBN's infrastructure and services</a>. Here's further analysis of this particular case as well - <a href="http://www.trustedsource.org/download/research_publications/SCJan08.pdf">Inside Rogue Flash Ads</a>, by Dennis Elser and Micha Pekrul, Secure Computing Corporation, Germany, as well as <a href="http://code.google.com/p/erlswf">a tool</a> specifically written to <a href="http://pentaphase.de/index.php?/archives/29-Erlang-unscrables-SWF.html">detect and prevent</a> such types of <a href="http://pentaphase.de/index.php?/archives/28-SWF-in-a-nutshell-and-the-malware-tragedy.html">malvertising practices</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ch36vfE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ch36vfE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dy0A5KE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dy0A5KE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KskYxZe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KskYxZe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XzsNCge"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XzsNCge" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=COUE7lE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=COUE7lE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VJBXStE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VJBXStE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZXY4wUe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZXY4wUe" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/238573685" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 20 Feb 2008 19:33:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/swf">swf</category>
      <category domain="http://securityratty.com/tag/comswfgnida">comswfgnida</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/newbieadguide">newbieadguide</category>
      <category domain="http://securityratty.com/tag/comstatsg">comstatsg</category>
      <category domain="http://securityratty.com/tag/adtraff">adtraff</category>
      <category domain="http://securityratty.com/tag/active domains">active domains</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/traffalo">traffalo</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/238573685/malicious-advertising-malvertising.html">Malicious Advertising (Malvertising) Increasing</source>
    </item>
    <item>
      <title><![CDATA[Checklists -The Preserve of the Intelligent]]></title>
      <link>http://securityratty.com/article/6c4d47cc81a1826a38bc9f17399f0dc5</link>
      <guid>http://securityratty.com/article/6c4d47cc81a1826a38bc9f17399f0dc5</guid>
      <description><![CDATA[As the New Yorker says If something so simple can transform intensive care, what else can it do?. Dennis Groves sent me this article a week ago and I read it twice. Each time I couldnt stop myself...]]></description>
      <content:encoded><![CDATA[As the New Yorker says &#8220;If something so simple can transform intensive care, what else can it do?&#8221;. Dennis Groves sent me this article a week ago and I read it twice. Each time I couldn&#8217;t stop myself thinking about how many people in the information security industry shun checklists and considering why this is. [...]]]></content:encoded>
      <pubDate>Sun, 17 Feb 2008 04:51:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/transform intensive care">transform intensive care</category>
      <category domain="http://securityratty.com/tag/dennis groves">dennis groves</category>
      <category domain="http://securityratty.com/tag/week ago">week ago</category>
      <category domain="http://securityratty.com/tag/yorker">yorker</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <source url="http://securitybuddha.com/2008/02/17/checklists-the-preserve-of-the-intelligent/">Checklists -The Preserve of the Intelligent</source>
    </item>
    <item>
      <title><![CDATA[Theft from vendor affects Modesto City Schools employees]]></title>
      <link>http://securityratty.com/article/592543590c35731d2d9c029ff59afde2</link>
      <guid>http://securityratty.com/article/592543590c35731d2d9c029ff59afde2</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/11/08

Organization
Modesto City Schools

Contractor/Consultant/Branch
Systematic Automation Inc

Victims
School district employees

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/modschools.jpg" align="right" height="111" width="120"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.monet.k12.ca.us/mcsnew/" target="_blank"> Modesto City Schools</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456" target="_blank"> Systematic Automation Inc.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>School district employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>3,500<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, birth dates and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>A computer hard drive containing sensitive personal information belonging to Modesto City School district employees was stolen from Systematic Automation Inc. in Fullerton, California.&nbsp; Systematic Automation Inc. prints annual benefits summaries for employees.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.modbee.com/local/story/208868.html" target="_blank"> The Modesto Bee online story</a> <br><a href="http://www.kcra.com/news/15276289/detail.html" target="_blank"> KCRA Channel 3 News story</a> <br><a href="http://www.news10.net/display_story.aspx?storyid=38353" target="_blank"> ABC News Channel 10 story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>KCRA Channel 3 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>All 3,500 employees were affected by the breach, which happened after a computer drive with names, addresses, birth dates and Social Security numbers was stolen from a Southern California data processing firm in Fullerton.<br><br>Systematic Automation Inc., prints benefits information for employees including health benefits for the district.<br><br>The hard drive and three monitors were stolen at 4:30 a.m. in a "window smash" burglary, said Sgt. Linda King with the Fullerton Police Department.<br><br>An e-mail was sent out to all affected employees.<br><br>Snelling said the district sent the employee information in an encrypted format to Systematic Automation, where it apparently was stored on the computer in an unencrypted format.<br><span style="font-style: italic;">[Evan] Good and bad.&nbsp; Good that the school district encrypted the information before sending it out.&nbsp; Bad that the school either did not communicate it's security expectations well or enforce them through regular audits of vendors.</span><br><br>"We want to do the accountable thing, which is to let everyone know so they can take their own steps to protect themselves," Modesto City Schools Superintendent Arturo Flores said.<br><br>Director of Business Services Dennis Snelling said no cases of identity theft connected with the data breach have been reported.<br><br>"We’re keeping an eye out," Snelling said. "We want our people to be able to protect themselves."<br><br>Snelling said other agencies had their data compromised in the theft, but he did not have details.<br><span style="font-style: italic;">[Evan] Not cool.</span><br><br>Snelling sent a memo by e-mail and hard copy on paper just before 2 p.m. to warn employees and provide information about how to monitor for fraud.<br><br>District officials said they plan to look into the security practices of each agency to which that receives employee information is sent.<br><span style="font-style: italic;">[Evan] Excellent addition to their practices.&nbsp; Vendors and contractors are extensions of the organization.</span><br><br>"We’d certainly be taking that up with Systematic Automation," he said. Employees with concerns can contact Louise Baker, supervisor of payroll and benefits, at 576-4192.<br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"There are a lot of very unhappy people," said Ray Duran, vice president of the Modesto Teachers Association. "I just hate to think all my stuff is out there. We know these things happen. We just hope the district will find a way to remedy the problem."<br><span style="font-style: italic;">[Evan] Unfortunately, there is little remedy for exposed information.&nbsp; Once information has been exposed, it stays exposed.</span><br><br>Sonoma Elementary teacher Judy Pierce said she was pleased at how quickly the district notified district employees and provided steps to help prevent identity theft.<br><br>"I think all of us hope in our lifetime we won’t be faced with these issues," Pierce said. "But (the district) gave us an entire two pages of steps of who to go to, who to contact. It made it very, very easy for us to follow through on it."<br><br><span style="font-weight: bold;">Commentary:</span><br>I am actually impressed with how well the school responded to this breach.&nbsp; It appears that they notified employees in a timely manner.&nbsp; The school also appears to know a thing or two about information security as demonstrated by encrypting the data and now recognizing the importance of evaluating vendor security practices. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/12/modschools.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 12 Feb 2008 12:03:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/district officials">district officials</category>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/district employees">district employees</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <category domain="http://securityratty.com/tag/school district employees">school district employees</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/provide information">provide information</category>
      <source url="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</source>
    </item>
  </channel>
</rss>
