<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dirty]]></title>
    <link>http://securityratty.com/tag/dirty</link>
    <description></description>
    <pubDate>Tue, 15 Jul 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[XRumer Spambot Cracks Captchas]]></title>
      <link>http://securityratty.com/article/8e16e4882509e89db49f04e7c4d2deb7</link>
      <guid>http://securityratty.com/article/8e16e4882509e89db49f04e7c4d2deb7</guid>
      <description><![CDATA[Weve known CAPTCHAs are insecure for some time, but now even the CAPTCHA-alternatives (often based on identifying cats from dogs or other animals) have proven insecure. Gmail, Windows Live hotmail and...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;ve known CAPTCHAs are insecure for some time, but now even the CAPTCHA-alternatives (often based on identifying cats from dogs or other animals) have proven insecure. Gmail, Windows Live hotmail and other popular sites were hacked as early as <a rel="nofollow" target="_blank" href="http://http://arstechnica.com/news.ars/post/20080415-gone-in-60-seconds-spambot-cracks-livehotmail-captcha.html">February</a>. Recently another defeat has come in the form of <a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Xrumer">XRumer,</a> a <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081002-right-back-at-ya-captcha-bad-guys-crack-gmail-hotmail.html">spam bot</a> that posts messages on blogs and through email in order to boost search engine rankings.</p>
<p>What&#8217;s the solution? Ars Technica suggests there might not be a good one, in part because malware distributors can go so far as to hire real people to do their dirty work:</p>
<blockquote><p>Instead of trying to build better CAPTCHA-cracking programs, the malware industry went out and got itself some humans of its own. This effectively bypasses the primary security strength of the CAPTCHA system and leaves it entirely dependent on what we&#8217;ll call secondary security characteristics. CAPTCHAs are often complex (particularly these days), which does increase the chance that they&#8217;ll be misread (and returned incorrectly), while the font and display of the characters themselves are at least somewhat unfamiliar to the CAPTCHA crackers sitting on the other side of the world.</p></blockquote>
<p>Sometimes those captcha phrases are pretty incoherent to me too. When I post over at Craigslist sometimes it says I&#8217;ve gotten its Captcha wrong, and I end up wondering if secretly I&#8217;m a bot?? Apparently not a very smart one either.</p>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:40:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/captchas">captchas</category>
      <category domain="http://securityratty.com/tag/bot">bot</category>
      <category domain="http://securityratty.com/tag/primary security strength">primary security strength</category>
      <category domain="http://securityratty.com/tag/windows live hotmail">windows live hotmail</category>
      <category domain="http://securityratty.com/tag/spam bot">spam bot</category>
      <category domain="http://securityratty.com/tag/ars technica suggests">ars technica suggests</category>
      <category domain="http://securityratty.com/tag/hire real people">hire real people</category>
      <category domain="http://securityratty.com/tag/popular sites">popular sites</category>
      <category domain="http://securityratty.com/tag/xrumer">xrumer</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/410515365/">XRumer Spambot Cracks Captchas</source>
    </item>
    <item>
      <title><![CDATA["Would you feel safe with this man looking after you?]]></title>
      <link>http://securityratty.com/article/8449600c6be4b5f5790eebbbff0d12d3</link>
      <guid>http://securityratty.com/article/8449600c6be4b5f5790eebbbff0d12d3</guid>
      <description><![CDATA[That was the caption under the picture of Rocker,Ted Nugent, in last Tuesday's Guardian . Nugent had volunteered to be Sir Paul McCartney's &quot;Bodyguard&quot; when he played a concert in Israel
...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_1UFxC-OgSnA/SN_3k0Kss4I/AAAAAAAAAGc/0WSQmbx1zdU/s1600-h/Mugshot__TED-NUGENT.jpg"><img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_1UFxC-OgSnA/SN_3k0Kss4I/AAAAAAAAAGc/0WSQmbx1zdU/s320/Mugshot__TED-NUGENT.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5251187902388155266" /></a><br />That was the caption under the picture of Rocker,Ted Nugent, in last Tuesday's <a href="http://www.guardian.co.uk/music/2008/sep/23/paul.mccartney.popandrock">Guardian</a>.  Nugent had volunteered to be Sir Paul McCartney's "Bodyguard" when he played a concert in Israel. <br /><span id="fullpost"><br />Unfortunately,this is what our industry has to tolerate.  Many people, from broken down celebrity deer hunters to jail guards think that if you know how to shoot a rifle or open a gate for inmates to go to the yard, it automatically follows that you know everything about protecting the life of a executive.       <br /></span><br />So, Ted Nugent knows how to play guitar and shoot deer.  Just what part of that background would equip him to keep the former Beetle safe in the Middle East?  It is certainly not like Mr. Nugent is trying to pull the wool over our eyes when it comes to any specialized training he may have received.  "I'm Dirty Harry with a ponytail", claims the singer.<br /><br />First of all Mr. Nugent, "Dirty Harry" was a film produced by Hollywood to entertain people, not a "training aid".  Secondly, even if we were to stretch our imaginations and consider Harry Callaghan's actions, we would recall that the character was a Police Detective and as such, would have undergone rigourous training at a professional Police Academy.<br /><br />Refering to reported Islamic Extremist Death Threats made against McCartney if he insisted on playing the concert, Nugent informed us that he "will not bend or waiver to Voodoo Religions or Whackjobs".  <br /><br />It is unknown whether or not Mr. Nugent thinks that Islamic Extremists come from Haiti, but if he is serious about a future career in Executive Protection, we would advise him to attend our <a href="http://www.sextonsecurity.com/training.html">upcoming course in Dubai </a>next month where he will not only learn first hand the Art of Personal Protection, but he will also learn about Middle Eastern Cultures, Tradition and Religion.<br /><br />Unfortunately, there's no way of predicting how much culture we may be able to pass on to Mr. Nugent, as the course is only a little over a week long.  We will also be teaching etiquette and which knife and fork to use when attending a formal event with your Principal.  That's right Ted, you don't get to tear the meat from the bone with your hands.  <br /><br />Someone call the U.A.E. and let the Hilton know that we may have to stay longer than planned.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 16:44:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ted nugent">ted nugent</category>
      <category domain="http://securityratty.com/tag/nugent">nugent</category>
      <category domain="http://securityratty.com/tag/ted">ted</category>
      <category domain="http://securityratty.com/tag/dirty harry">dirty harry</category>
      <category domain="http://securityratty.com/tag/deer">deer</category>
      <category domain="http://securityratty.com/tag/sir paul mccartney">sir paul mccartney</category>
      <category domain="http://securityratty.com/tag/mccartney">mccartney</category>
      <category domain="http://securityratty.com/tag/celebrity deer hunters">celebrity deer hunters</category>
      <category domain="http://securityratty.com/tag/professional police academy">professional police academy</category>
      <source url="http://www.thebulletproofblog.com/2008/09/would-you-feel-safe-with-this-man.html">"Would you feel safe with this man looking after you?</source>
    </item>
    <item>
      <title><![CDATA[Over half admit they dont know if they are secure!]]></title>
      <link>http://securityratty.com/article/f2c80233382d89f76c872775fe5df122</link>
      <guid>http://securityratty.com/article/f2c80233382d89f76c872775fe5df122</guid>
      <description><![CDATA[Educating the masses continues to be a problem even with all the latest headlines about ID theft


clipped from www.net-security.org


Lack of awareness of privacy and security software



The results...]]></description>
      <content:encoded><![CDATA[<div > Educating the masses continues to be a problem even with all the latest headlines about ID theft.<br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/EBD2CEAE-4FA1-4DC7-AB32-E49F7F600075/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/055d2311-f252-453a-a9c5-8b82eaba411f/EBD2CEAE-4FA1-4DC7-AB32-E49F7F600075/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.net-security.org/secworld.php?id=6567" href="http://www.net-security.org/secworld.php?id=6567" style="font-size: 11px;">www.net-security.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.net-security.org/secworld.php?id=6567 --><DIV class="dernek-text"><br />
Lack of awareness of privacy and security software</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.net-security.org/secworld.php?id=6567 --><DIV><br />
The results show that an alarmingly high proportion of users did not know what software was running on their computers to ensure they had adequate protection from hackers, malware, viruses, ‘dirty’ websites, and other online threats. More than one-tenth of respondents (13%) said they did not have any anti-virus software installed on their machines at all, while a further 9% did not know if anti-virus was installed. Almost one-fifth of respondents (19%) did not know if they had firewalls installed.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/EBD2CEAE-4FA1-4DC7-AB32-E49F7F600075/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_240908114518"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=240908114518&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=240908114518&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=240908114518&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_240908114518" /></a></P>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 19:45:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security software">security software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/anti-virus software">anti-virus software</category>
      <category domain="http://securityratty.com/tag/anti-virus">anti-virus</category>
      <category domain="http://securityratty.com/tag/respondents">respondents</category>
      <category domain="http://securityratty.com/tag/online threats">online threats</category>
      <category domain="http://securityratty.com/tag/masses continues">masses continues</category>
      <category domain="http://securityratty.com/tag/dirty websites">dirty websites</category>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=627">Over half admit they dont know if they are secure!</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[Port and cargo security: How is the U.S.A. doing now?]]></title>
      <link>http://securityratty.com/article/46e3d58903b489106ccc029c6a12ebc6</link>
      <guid>http://securityratty.com/article/46e3d58903b489106ccc029c6a12ebc6</guid>
      <description><![CDATA[In a 2006 interview, you gave the country a D+ grade when it comes to the current state of port and cargo security. And that D+ was up from an F a few years prior. Where do we stand now in 2008? We...]]></description>
      <content:encoded><![CDATA[In a 2006 interview, you gave the country a D+ grade when it comes to the current state of port and cargo security. And that D+ was up from an F a few years prior. Where do we stand now in 2008? We are moving probably to a C-minus. There are essentially three challenges in the area of port security and cargo security. The first is that potentially our ports can be used as a conduit to bring destructive things into country, such as a dirty bomb, a radiological device, or, in a worst case scenario, a nuclear bomb. So the first set of challenges is to figure out how do I find the needle in haystack in the tremendous volume of cargo and in a complex environment like our ports if someone wanted to smuggle something in.]]></content:encoded>
      <pubDate>Sun, 14 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cargo">cargo</category>
      <category domain="http://securityratty.com/tag/cargo security">cargo security</category>
      <category domain="http://securityratty.com/tag/port">port</category>
      <category domain="http://securityratty.com/tag/port security">port security</category>
      <category domain="http://securityratty.com/tag/dirty bomb">dirty bomb</category>
      <category domain="http://securityratty.com/tag/complex environment">complex environment</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/ports">ports</category>
      <source url="http://www.networkworld.com/news/2008/091508-port-cargo-security.html?fsrc=rss-security">Port and cargo security: How is the U.S.A. doing now?</source>
    </item>
    <item>
      <title><![CDATA[What's Going on Between Asprox and Rock Phish? ]]></title>
      <link>http://securityratty.com/article/fc95ce7833adc3cdfb7b5c321e80348a</link>
      <guid>http://securityratty.com/article/fc95ce7833adc3cdfb7b5c321e80348a</guid>
      <description><![CDATA[When a small phishing gang decides to upgrade its infrastructure, it is often done in a quick and dirty fashion. The transition is almost immediate, and often buggy and unprofessional. But what...]]></description>
      <content:encoded><![CDATA[When a small phishing gang decides to upgrade its infrastructure, it is often done in a quick and dirty fashion. The transition is almost immediate, and often buggy and unprofessional. But what happens when a gang on the scale of the Rock Phish group decides to abandon its old methods and upgrade its botnet infrastructure? It is done slowly, smoothly but most importantly -- professionally. 

The RSA FraudAction Research Labs recently gathered information that indicates major changes in the tactics employed by the Rock Phish gang. We have reason to believe that the gang is replacing its phishing infrastructure, and upgrading it to an advanced <a href="http://www.honeynet.org/papers/ff/fast-flux.html">Fast-Flux</a> botnet. <B>We also believe that this new infrastructure belongs to none other than the infamous Asprox Botnet, which has recently been spreading itself using surges of SQL injection attacks...</b>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rock phish">rock phish</category>
      <category domain="http://securityratty.com/tag/gang">gang</category>
      <category domain="http://securityratty.com/tag/gang decides">gang decides</category>
      <category domain="http://securityratty.com/tag/rock phish gang">rock phish gang</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/botnet infrastructure">botnet infrastructure</category>
      <category domain="http://securityratty.com/tag/infrastructure belongs">infrastructure belongs</category>
      <category domain="http://securityratty.com/tag/infamous asprox botnet">infamous asprox botnet</category>
      <category domain="http://securityratty.com/tag/decides">decides</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1338">What's Going on Between Asprox and Rock Phish? </source>
    </item>
    <item>
      <title><![CDATA[Show 029 - An Interview with Dennis Fisher]]></title>
      <link>http://securityratty.com/article/ed23afa251e7ed42c51726c5d78957a6</link>
      <guid>http://securityratty.com/article/ed23afa251e7ed42c51726c5d78957a6</guid>
      <description><![CDATA[On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget. Dennis helps run SearchSecurity.com and...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Dennis Fisher" title="Dennis Fisher" src="http://www.cigital.com/silverbullet/dfisher-108.png" style="padding-left: 7px;" /></p>
<p>On the 29th episode of The Silver Bullet Security Podcast, Gary talks with Dennis Fisher, executive editor of The Security Media Group at TechTarget.  Dennis helps run SearchSecurity.com and <em>Information Security Magazine</em>.  Gary and Dennis discuss the current &#8220;BS factor&#8221; in security journalism, shopping at TJ Maxx right after the TJX privacy breach, the state of software security, and which is harder: being a fry cook at Hardees or working as a PR flack.</p>
<ul>
<li><a href="http://security.blogs.techtarget.com/author/security/">Dennis&#8217; blog</a></li>
<li><a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1239802,00.html">TJX</a></li>
<li><a href="http://music.aol.com/video/dirty-laundry/the-eagles/tag/joe-walsh/1354381">Joe Walsh plays dirty laundry</a></li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1237978">Software Security Grows</a></li>
<li><a href="http://securitywireweekly.blogs.techtarget.com/2008/07/31/the-state-of-software-security">Dennis&#8217; un-named podcast</a></li>
<li><a href="http://www.youtube.com/watch?v=f99PcP0aFNE">Series of Tubes</a></li>
<li><a href="http://www.hardees.com/">Hardees</a></li>
<li><a href="http://www.cs.washington.edu/research/systems/privacy.htm">Nike/iPod</a></li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 11:05:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dennis">dennis</category>
      <category domain="http://securityratty.com/tag/dennis fisher">dennis fisher</category>
      <category domain="http://securityratty.com/tag/dennis discuss">dennis discuss</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/software security grows">software security grows</category>
      <category domain="http://securityratty.com/tag/dennis helps">dennis helps</category>
      <category domain="http://securityratty.com/tag/tjx privacy breach">tjx privacy breach</category>
      <category domain="http://securityratty.com/tag/tjx">tjx</category>
      <category domain="http://securityratty.com/tag/gary talks">gary talks</category>
      <source url="http://www.cigital.com/silverbullet/show-029/">Show 029 - An Interview with Dennis Fisher</source>
    </item>
    <item>
      <title><![CDATA[Ah, the joys of blogging!]]></title>
      <link>http://securityratty.com/article/2e21442e3f94142ee989877a5ea060c4</link>
      <guid>http://securityratty.com/article/2e21442e3f94142ee989877a5ea060c4</guid>
      <description><![CDATA[People ask why do you blog? In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while. Here is one I...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>People ask why do you blog?&nbsp; In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while.&nbsp; Here is one I received today from a person alleging to be a Julie Peterson:</p><blockquote><p><em>Julie Peterson commented on </em><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/safe-access-win.html"><em>Safe Access wins SC Magazine Award Reader Trust Award, again!</em></a><em>: </em></p>

<p><em>Dressed in a tuxedo and chewing those rubber chicken breasts at the award ceremony is your idea of fun? Aren't you the same mentally retarded idiot who said in 2007 that you hated SC awards and that anyone can buy the SC awards with a sponsorship? Why do you think people give over $10k as sponsorship for the SC awards? Who is watching the awards except other vendors? By the way you suck big time with your rubbish blogs. Didn't networld magazine give you the boot within 3 months? Think before you write Mr. mental. Well done on winning, but please, dont give the impression that you cant buy an award from SC! And don't forget to eat your medication pills tonight, otherwise from your hair it is obvious you ran away from a mental hospital.</em> </p></blockquote><p>First of all Julie, let me thank you for your kind words! You made the statement and let me answer your questions for you.</p>

<p>1. Is dressing in a tuxedo and chewing rubber chicken breasts my idea of fun?&nbsp; Actually, I do enjoy dressing up in a tuxedo once in a while.&nbsp; The food at the awards ceremony was actually pretty good, if not diet friendly, as were the cocktails.&nbsp; The entertainment at the awards show was pretty good as well. Catching up with friends you had not seen for a while and networking with industry peers was pretty worthwhile too.&nbsp; Maybe your idea of a good time is putting on a bowling shirt and swilling a couple of beers and pretzels before going home and undressing into your dirty ripped underwear. Hey I say to each his own.</p>

<p>2. I am not the idiot who in 2007 said that I hated the SC awards and that anyone can buy the SC awards with a sponsorship.&nbsp; I am the idiot who <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/08/ssaaty-blog-win.html">said that about the InfoSec Products Guide</a> award by the folks at Silicon Valley Communications.&nbsp; In contrast I have always said nice things about the SC awards. I actually have a lot of respect for them.&nbsp; Also for the record, StillSecure has never been a sponsor of the SC Magazine awards. I have seen sponsors who did not win awards as well.&nbsp; So looks like you got that one wrong Julie, but it happens.</p>

<p>3. ???Networld??? magazine didn???t give me the boot within 3 months.&nbsp; They never had the chance, as I never wrote for ???networld, network world or any other magazine. Maybe you have me confused with Mike Rothman or Mitchell Ashley, who do and did write for Network World. But let me assure you that I do try and think before I write.</p>

<p>4. Regarding what medication pills I take and does my hair make it obvious I ran away from a mental hospital. I don???t take any medication, maybe I should.&nbsp; Better living through chemistry you know ;-)&nbsp; As to my hair, what can I say.&nbsp; At this stage I am happy I have any hair at all.&nbsp; My wife always says when I get my haircut it looks like a Buzz Lightyear style, but no one ever mentioned a mental hospital look to it.&nbsp; In any event sorry it doesn???t appeal to you.</p>

<p>So who is this troll Julie Peterson?&nbsp; Could it be Richard Stiennon in drag?&nbsp; Maybe his wife striking out?&nbsp; Maybe another one of my fans?&nbsp; Who knows, but these sort of comments keep me juiced about blogging and remind me of how much fun I have doing it.&nbsp; Thanks again Julie!</p></div>
]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 14:10:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/troll julie peterson">troll julie peterson</category>
      <category domain="http://securityratty.com/tag/julie peterson">julie peterson</category>
      <category domain="http://securityratty.com/tag/networld magazine">networld magazine</category>
      <category domain="http://securityratty.com/tag/magazine">magazine</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/win awards">win awards</category>
      <category domain="http://securityratty.com/tag/magazine awards">magazine awards</category>
      <category domain="http://securityratty.com/tag/awards ceremony">awards ceremony</category>
      <category domain="http://securityratty.com/tag/julie">julie</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/ah-the-joys-of.html">Ah, the joys of blogging!</source>
    </item>
    <item>
      <title><![CDATA[Ah, the joys of blogging!]]></title>
      <link>http://securityratty.com/article/822d1a6ac16159dd85108200273bf839</link>
      <guid>http://securityratty.com/article/822d1a6ac16159dd85108200273bf839</guid>
      <description><![CDATA[People ask why do you blog? In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while. Here is one I...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>People ask why do you blog?&nbsp; In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while.&nbsp; Here is one I received today from a person alleging to be a Julie Peterson:</p><blockquote><p><em>Julie Peterson commented on </em><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/safe-access-win.html"><em>Safe Access wins SC Magazine Award Reader Trust Award, again!</em></a><em>: </em></p>

<p><em>Dressed in a tuxedo and chewing those rubber chicken breasts at the award ceremony is your idea of fun? Aren't you the same mentally retarded idiot who said in 2007 that you hated SC awards and that anyone can buy the SC awards with a sponsorship? Why do you think people give over $10k as sponsorship for the SC awards? Who is watching the awards except other vendors? By the way you suck big time with your rubbish blogs. Didn't networld magazine give you the boot within 3 months? Think before you write Mr. mental. Well done on winning, but please, dont give the impression that you cant buy an award from SC! And don't forget to eat your medication pills tonight, otherwise from your hair it is obvious you ran away from a mental hospital.</em> </p></blockquote><p>First of all Julie, let me thank you for your kind words! You made the statement and let me answer your questions for you.</p>

<p>1. Is dressing in a tuxedo and chewing rubber chicken breasts my idea of fun?&nbsp; Actually, I do enjoy dressing up in a tuxedo once in a while.&nbsp; The food at the awards ceremony was actually pretty good, if not diet friendly, as were the cocktails.&nbsp; The entertainment at the awards show was pretty good as well. Catching up with friends you had not seen for a while and networking with industry peers was pretty worthwhile too.&nbsp; Maybe your idea of a good time is putting on a bowling shirt and swilling a couple of beers and pretzels before going home and undressing into your dirty ripped underwear. Hey I say to each his own.</p>

<p>2. I am not the idiot who in 2007 said that I hated the SC awards and that anyone can buy the SC awards with a sponsorship.&nbsp; I am the idiot who <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/08/ssaaty-blog-win.html">said that about the InfoSec Products Guide</a> award by the folks at Silicon Valley Communications.&nbsp; In contrast I have always said nice things about the SC awards. I actually have a lot of respect for them.&nbsp; Also for the record, StillSecure has never been a sponsor of the SC Magazine awards. I have seen sponsors who did not win awards as well.&nbsp; So looks like you got that one wrong Julie, but it happens.</p>

<p>3. “Networld” magazine didn’t give me the boot within 3 months.&nbsp; They never had the chance, as I never wrote for “networld, network world or any other magazine. Maybe you have me confused with Mike Rothman or Mitchell Ashley, who do and did write for Network World. But let me assure you that I do try and think before I write.</p>

<p>4. Regarding what medication pills I take and does my hair make it obvious I ran away from a mental hospital. I don’t take any medication, maybe I should.&nbsp; Better living through chemistry you know ;-)&nbsp; As to my hair, what can I say.&nbsp; At this stage I am happy I have any hair at all.&nbsp; My wife always says when I get my haircut it looks like a Buzz Lightyear style, but no one ever mentioned a mental hospital look to it.&nbsp; In any event sorry it doesn’t appeal to you.</p>

<p>So who is this troll Julie Peterson?&nbsp; Could it be Richard Stiennon in drag?&nbsp; Maybe his wife striking out?&nbsp; Maybe another one of my fans?&nbsp; Who knows, but these sort of comments keep me juiced about blogging and remind me of how much fun I have doing it.&nbsp; Thanks again Julie!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=SHtn9x"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=SHtn9x" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=6lQ41J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=6lQ41J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wHd2XJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wHd2XJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ubGPNJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ubGPNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=19TqYJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=19TqYJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DScy2j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DScy2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=D7Fxhj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=D7Fxhj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/349857433" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 13:12:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/troll julie peterson">troll julie peterson</category>
      <category domain="http://securityratty.com/tag/julie peterson">julie peterson</category>
      <category domain="http://securityratty.com/tag/networld magazine">networld magazine</category>
      <category domain="http://securityratty.com/tag/magazine">magazine</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/win awards">win awards</category>
      <category domain="http://securityratty.com/tag/awards ceremony">awards ceremony</category>
      <category domain="http://securityratty.com/tag/magazine awards">magazine awards</category>
      <category domain="http://securityratty.com/tag/julie">julie</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/349857433/ah-the-joys-of.html">Ah, the joys of blogging!</source>
    </item>
    <item>
      <title><![CDATA[How CAPTCHA got trashed]]></title>
      <link>http://securityratty.com/article/01cc1e0cc73b1ba6bee2ef0dcbd5e859</link>
      <guid>http://securityratty.com/article/01cc1e0cc73b1ba6bee2ef0dcbd5e859</guid>
      <description><![CDATA[CAPTCHA used to be an easy and useful way for Web administrators to authenticate users. Now it's an easy and useful way for malware authors and spammers to do their dirty...]]></description>
      <content:encoded><![CDATA[CAPTCHA used to be an easy and useful way for Web administrators to authenticate users. Now it's an easy and useful way for malware authors and spammers to do their dirty work.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=98301?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=98301?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/easy">easy</category>
      <category domain="http://securityratty.com/tag/web administrators">web administrators</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/captcha">captcha</category>
      <category domain="http://securityratty.com/tag/dirty">dirty</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <source url="http://www.networkworld.com/news/2008/071408-how-captcha-got.html?fsrc=rss-security">How CAPTCHA got trashed</source>
    </item>
  </channel>
</rss>
