<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: divulge]]></title>
    <link>http://securityratty.com/tag/divulge</link>
    <description></description>
    <pubDate>Tue, 11 Dec 2007 18:20:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Express Scripts user? Sorry.]]></title>
      <link>http://securityratty.com/article/8043f7fcbe07519e37e714d538ec6762</link>
      <guid>http://securityratty.com/article/8043f7fcbe07519e37e714d538ec6762</guid>
      <description><![CDATA[Yeah, Ive used the service a couple of time in the last few years. Sigh


clipped from blog.wired.com

Extortion Plot Threatens to Divulge Millions of Patients Prescriptions


Express Scripts said it...]]></description>
      <content:encoded><![CDATA[<div > Yeah, Ive used the service a couple of time in the last few years. <br/>Sigh. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/81D25E91-1C5B-4EDA-9F08-B67D3299956D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/c0489055-8fb4-4eb3-a5c9-19e74251870d/81D25E91-1C5B-4EDA-9F08-B67D3299956D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html" href="http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html" style="font-size: 11px;">blog.wired.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Extortion Plot Threatens to Divulge Millions of Patients&#8217; Prescriptions</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html --><P>Express Scripts said it has received an anonymous letter containing the names of some 75 clients that includes dates of birth, Social Security numbers and their prescriptions. The letter threatens to expose millions of patient records if Express Scripts does not pay an undisclosed amount of money.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/81D25E91-1C5B-4EDA-9F08-B67D3299956D/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_071108045615"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=071108045615&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=071108045615&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=071108045615&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_071108045615" /></a></P>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 13:56:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/express scripts">express scripts</category>
      <category domain="http://securityratty.com/tag/extortion plot threatens">extortion plot threatens</category>
      <category domain="http://securityratty.com/tag/patients prescriptions">patients prescriptions</category>
      <category domain="http://securityratty.com/tag/prescriptions">prescriptions</category>
      <category domain="http://securityratty.com/tag/letter threatens">letter threatens</category>
      <category domain="http://securityratty.com/tag/anonymous letter">anonymous letter</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/expose millions">expose millions</category>
      <category domain="http://securityratty.com/tag/patient records">patient records</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=650">Express Scripts user? Sorry.</source>
    </item>
    <item>
      <title><![CDATA[Extortion Plot Threatens to Divulge Millions of Patients' Prescriptions]]></title>
      <link>http://securityratty.com/article/7482fa30301d89232b266687bfedef5e</link>
      <guid>http://securityratty.com/article/7482fa30301d89232b266687bfedef5e</guid>
      <description><![CDATA[A St. Louis company managing medical prescriptions of 50 million people says it has alerted the FBI of an extortion plot threatening to divulge the names and prescriptions of millions of its clients....]]></description>
      <content:encoded><![CDATA[A St. Louis company managing medical prescriptions of 50 million people says it has alerted the FBI of an extortion plot threatening to divulge the names and prescriptions of millions of its clients. Express Scripts says it received a letter announcing the plot, which seeks an undisclosed amount of money.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=80367e4ddab655ec90ba4e34e26d8764" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=80367e4ddab655ec90ba4e34e26d8764" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=18dJN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=18dJN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=DaaCn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=DaaCn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Qny1n"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Qny1n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=cqhrN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=cqhrN" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=RykfN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=RykfN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=WjRdn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=WjRdn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=frLjn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=frLjn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=XKk1N"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XKk1N" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/444932343" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/444932475" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 20:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/extortion plot">extortion plot</category>
      <category domain="http://securityratty.com/tag/prescriptions">prescriptions</category>
      <category domain="http://securityratty.com/tag/plot">plot</category>
      <category domain="http://securityratty.com/tag/medical prescriptions">medical prescriptions</category>
      <category domain="http://securityratty.com/tag/express scripts">express scripts</category>
      <category domain="http://securityratty.com/tag/millions">millions</category>
      <category domain="http://securityratty.com/tag/divulge">divulge</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/louis company">louis company</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/444932475/extortion-plot.html">Extortion Plot Threatens to Divulge Millions of Patients' Prescriptions</source>
    </item>
    <item>
      <title><![CDATA[Disgruntled Employee Holds San Francisco Computer Network Hostage]]></title>
      <link>http://securityratty.com/article/be309884378ab0d749fd697793fc09a1</link>
      <guid>http://securityratty.com/article/be309884378ab0d749fd697793fc09a1</guid>
      <description><![CDATA[Trusted insiders can do a lot of damage : Childs created a password that granted him exclusive access to the system, authorities said. He initially gave pass codes to police, but they didn't work....]]></description>
      <content:encoded><![CDATA[Trusted insiders can do a <a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/14/BAOS11P1M5.DTL&tsp=1">lot of damage</a>:

<blockquote>Childs created a password that granted him exclusive access to the system, authorities said. He initially gave pass codes to police, but they didn't work. When pressed, Childs refused to divulge the real code even when threatened with arrest, they said.

He was taken into custody Sunday. City officials said late Monday that they had made some headway into cracking his pass codes and regaining access to the system.

Childs has worked for the city for about five years. One official with knowledge of the case said he had been disciplined on the job in recent months for poor performance and that his supervisors had tried to fire him. 

"They weren't able to do it - this was kind of his insurance policy," said the official, speaking on condition of anonymity because the attempted firing was a personnel matter.

Authorities say Childs began tampering with the computer system June 20. The damage is still being assessed, but authorities say undoing his denial of access to other system administrators could cost millions of dollars.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=powZyJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=powZyJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Lp0QJJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Lp0QJJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 07:43:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/system administrators">system administrators</category>
      <category domain="http://securityratty.com/tag/computer system june">computer system june</category>
      <category domain="http://securityratty.com/tag/exclusive access">exclusive access</category>
      <category domain="http://securityratty.com/tag/childs">childs</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/pass codes">pass codes</category>
      <category domain="http://securityratty.com/tag/city officials">city officials</category>
      <category domain="http://securityratty.com/tag/authorities">authorities</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/disgruntled_emp.html">Disgruntled Employee Holds San Francisco Computer Network Hostage</source>
    </item>
    <item>
      <title><![CDATA[Cloudsecurity.org Interviews Guido van Rossum: Google App Engine, Python and Security]]></title>
      <link>http://securityratty.com/article/a2cf6f2181968ed75532873c1bdb09fe</link>
      <guid>http://securityratty.com/article/a2cf6f2181968ed75532873c1bdb09fe</guid>
      <description><![CDATA[In this interview, cloudsecurity.org talks to Guido van Rossum about Python , Google App Engine and security
Guido is the creator of the Python programming language and more recently, Google App...]]></description>
      <content:encoded><![CDATA[<p><a title="Guido van Rossum in Google Uniform" href="http://www.python.org/~guido/" target="_blank"><img src="http://www.python.org/~guido/images/IMG_2192.jpg" border="0" alt="Guido Homepage" /></a></p>
<p>In this interview, cloudsecurity.org talks to <a title="Homepage of Guido van Rossum" href="http://www.python.org/~guido/">Guido van Rossum</a> about <a title="Python website" href="http://python.org">Python</a>, <a title="Description of Google AppEngine" href="http://code.google.com/appengine/docs/whatisgoogleappengine.html">Google App Engine</a> and security.</p>
<p>Guido is the creator of the Python programming language and more recently, Google App Engine team member.  His involvement with the App Engine project was pretty late - the code &#8220;was almost ready for release&#8221; when he get involved.  The security architect of App Engine was primarily project lead, <a title="Kevin Gibbs Campfire Transcript" href="http://code.google.com/appengine/articles/cf1-text.html">Kevin Gibbs</a>, supported by the rest of the App Engine crew and the Google Security Team.</p>
<h4>The Interview</h4>
<p><em>cloudsecurity.org: What security principles did you follow for App Engine?<br />
</em></p>
<p>GvR: While I can&#8217;t share any specifics on what we&#8217;re doing to secure App Engine, I can say that the main principle we&#8217;ve followed could be called &#8220;defense in depth&#8221;. We&#8217;re not relying exclusively on a secure interpreter, or any other single security layer, to protect our users.</p>
<p><em>cloudsecurity.org: Please provide some examples of how those principles played out in terms of the current implementation?<br />
</em> <em> </em></p>
<p>GvR: Sorry, we don&#8217;t divulge such information.</p>
<p><em>cloudsecurity.org: What criteria did you apply to Python module selection?</em></p>
<p>GvR: We first looked for modules that were useful and straightforward to audit. If a module was large or complex, we&#8217;d only audit it (fixing things we found) if it was deemed essential or at least useful for a large number of users; otherwise we&#8217;d exclude it.</p>
<p><em>cloudsecurity.org: What do you see as the security risks inherent in exposing an interpreter runtime in a shared environment?<br />
</em></p>
<p>GvR: <span>I presume you&#8217;re asking about risks to users, like providing accidental access to data belonging to another app. We&#8217;ve taken extensive measures to isolate different apps from each other. For example, each app runs in a separate process, and the datastore prevents an app from accessing data belonging to other apps.</span></p>
<p><em>cloudsecurity.org: I recently attended a fascinating talk by <a title="Justin Ferguson" href="http://eusecwest.com/justin-ferguson-interpreter-vm-attacks.html" target="_blank">Justin Ferguson</a> (a Seattle based security consultant) at <a title="eusecwest" href="http://www.eusecwest.com/" target="_blank">eusecwest</a> in London.  He gave a great talk exploring security vulnerabilities in language interpreters and specifically highlighted some security weaknesses in Python App Engine.  What are your thoughts on his research and specifically the Python issues he highlighted?  When do you anticipate they will get fixed?<br />
</em></p>
<p>GvR: We&#8217;ve anticipated all of the possibilities raised in Justin&#8217;s talk, and took measures to protect our users. Justin highlighted weaknesses in Python, but not in App Engine. Furthermore, our security model does not rely solely upon protections within the Python interpreter; there are additional protections that these external analyses have missed.<em><br />
</em><br />
<em>cloudsecurity.org: How do you contain an attacker that exploits bugs in App Engine from exploiting the underlying OS and potentially interfering with other users processes or attacking backend systems?<br />
</em></p>
<p>GvR: You are correct that there are strong measures in place, but I&#8217;m not at liberty to discuss details.</p>
<p><em>cloudsecurity.org: Python was the first language to get the App Engine treatment, what language is next and what are some of the language specific security challenges the team has had to deal with?<br />
</em></p>
<p>GvR: Although I can&#8217;t comment on what language is next, we are working on this, and have gotten a lot of great feedback from our developers. As far as language-specific security challenges, they stemmed mostly from the complexity of the Python interpreter. We spent a lot of time auditing this, and did a great deal more than just identifying buffer overflows.  I can also add that Google is actively researching the security of interpreted languages.  Google engineers routinely contribute security fixes to open source projects, including but not limited to Python.<em><br />
</em><br />
<em>cloudsecurity.org: How does the team decide when &#8216;enough is enough&#8217; in terms of hardening the interpreter?<br />
</em> <em> </em></p>
<p>GvR: That&#8217;s not really how we approach it. We realize that security is an ongoing effort, and try to stay ahead of threats through continuous monitoring and testing.</p>
<p><em>cloudsecurity.org: Some <a style="color: #551a8b;" title="commentators" href="http://blog.ianbicking.org/2008/04/13/app-engine-and-pylons/" target="_blank">commentators</a> have suggested that perhaps the difficulty of auditing the implementation led to some modules being more heavily restricted than perhaps necessary.  What are your thoughts on that and what plans, if any, are there to bring back code objects/functions that were eliminated in the initial release?  (with the benefit of hindsight).<br />
</em> <em> </em></p>
<p>GvR: The only thing we are likely to put back is the _ast module, which was not audited based upon an underestimation of its usefulness (see my answer to question #3 above).  We will also put back some dummy functions and other objects whose absence currently prevents some popular frameworks from being loaded without modifications. For example, some harmless functionality in the imp module will come back. We&#8217;re also looking into making urllib2 work (to some extent), though that&#8217;s not really a security issue but merely a matter of API adjustment.</p>
<p><em>cloudsecurity.org: It is reported that Google encourages small groups to go off and create.  How involved were the Google security team with App Engine in terms of design and implementation review/testing?  Given the dynamics, is it possible to have a meaningful security process that shadows the development process?<br />
</em> <em> </em></p>
<p>GvR: The Google Security team is involved in everything we do. They have been extremely helpful.</p>
<p><em>cloudsecurity.org: How can people report security weaknesses they discover in App Engine?  What commitment does Google give in terms of dealing vulnerability reports?<br />
</em> <em> </em></p>
<p>GvR: There is a standard process for submitting security issues. See <a title="http://www.google.com/corporate/security.html" href="http://www.google.com/corporate/security.html" target="_blank">http://www.google.com/corporate/security.html</a>. Google moves very fast to protect its users when a verifiable security vulnerability is reported.<span><em><br />
</em></span><br />
<em>cloudsecurity.org: One concern is the potential misuse of App Engine to exploit security vulnerabilities in visitors browsers.  This is not a new problem per se, shared hosting providers know all about this.  But with Google and other Cloud providers, the scalability potential is much higher.  What are your thoughts on this and what pro-active steps is Google taking to detect and terminate evil apps?<br />
</em> <em> </em></p>
<p>GvR: This is high on our list of concerns. We deal with this through a combination of restrictions on what you can do (e.g. certain HTTP headers and ports are off-limits) and, again, monitoring.</p>
<p><em>cloudsecurity.org: Beyond App Engine, what role do you think Python will play in the Cloud both now and in the future?<br />
</em> <em> </em></p>
<p>GvR: Sorry, I&#8217;m not prone to philosophizing about the future.</p>
<p><em>cloudsecurity.org: Trust is often cited as a barrier to enterprise adoption of Cloud Computing.  What role do you personally think Google can play in building that trust?<br />
</em> <em> </em></p>
<p>GvR: I think trust is built up over a long period of experience. Our actions in terms of being open to our users will be the most important factor in establishing trust. Of course, Google&#8217;s reputation also helps: everybody understands that Google doesn&#8217;t want its name associated with a bad product.</p>
<p><em>cloudsecurity.org: Looking at the Cloud Computing landscape beyond Google, what are your thoughts on the current state of Cloud Computing and Security?<br />
</em></p>
<p>GvR: It&#8217;s obvious that Cloud Computing is only just taking off. The next few years will be very exciting.</p>
<p><em>cloudsecurity.org: Lastly, what are some of your favourite App Engine apps?<br />
</em></p>
<p>GvR: There are too many to enumerate. If you insist on a highlight, well, I like Rietveld (<a title="http://codereview.appspot.com" href="http://codereview.appspot.com/" target="_blank">http://codereview.appspot.com</a>), a tool for collaborative code review which I (largely) wrote myself. It is open source and includes some essential components from Mondrian, a similar internal tool which I created before I joined the App Engine team.</p>
<h4><strong>Thanks</strong></h4>
<p>My thanks to Guido for his time and sharing his views.</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/324271347" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 15:03:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/app engine">app engine</category>
      <category domain="http://securityratty.com/tag/google app engine">google app engine</category>
      <category domain="http://securityratty.com/tag/app">app</category>
      <category domain="http://securityratty.com/tag/app engine treatment">app engine treatment</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/app engine project">app engine project</category>
      <category domain="http://securityratty.com/tag/app engine crew">app engine crew</category>
      <category domain="http://securityratty.com/tag/secure app engine">secure app engine</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/324271347/">Cloudsecurity.org Interviews Guido van Rossum: Google App Engine, Python and Security</source>
    </item>
    <item>
      <title><![CDATA[Sites' personal questions may pose security risk]]></title>
      <link>http://securityratty.com/article/ae1a62ee77ed93758aa705d91afb8c6a</link>
      <guid>http://securityratty.com/article/ae1a62ee77ed93758aa705d91afb8c6a</guid>
      <description><![CDATA[Is it safe to divulge your first pet's name, mother's maiden name or other information in 'knowledge-based authentication'...]]></description>
      <content:encoded><![CDATA[Is it safe to divulge your first pet's name, mother's maiden name or other information in 'knowledge-based authentication' methods?
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=A8bfrf"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=A8bfrf" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/259073853" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 27 Mar 2008 10:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pet">pet</category>
      <category domain="http://securityratty.com/tag/safe">safe</category>
      <category domain="http://securityratty.com/tag/divulge">divulge</category>
      <category domain="http://securityratty.com/tag/methods">methods</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/mother">mother</category>
      <category domain="http://securityratty.com/tag/authentication">authentication</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/259073853/article.do">Sites' personal questions may pose security risk</source>
    </item>
    <item>
      <title><![CDATA[Fraud Due to a Credit Card Breach]]></title>
      <link>http://securityratty.com/article/e45496bf94cf332f04296176b8d3830f</link>
      <guid>http://securityratty.com/article/e45496bf94cf332f04296176b8d3830f</guid>
      <description><![CDATA[This sort of story is nothing new: Hannaford said credit and debit card numbers were stolen during the card authorization process and about 4.2 million unique account numbers were exposed
But it's...]]></description>
      <content:encoded><![CDATA[<p>This sort of <a href="http://www.breitbart.com/article.php?id=D8VFDD180&show_article=1">story</a> is nothing new:</p>

<blockquote>Hannaford said credit and debit card numbers were stolen during the card authorization process and about 4.2 million unique account numbers were exposed.</blockquote>

<p>But it's rare that we see statistics about the actual risk of fraud:</p>

<blockquote>The company is aware of about 1,800 cases of fraud reported so far relating to the breach.</blockquote>

<p>And this is interesting:</p>

<blockquote>"Visa and MasterCard have stipulated in their contracts with retailers that they will not divulge who the source is when a data breach occurs," Spitzer said. "We've been engaged in a dialogue for a couple years now about changing this rule.... Without knowing who the retailer is that caused the breach, it's hard for banks to conduct a good investigation on behalf of their consumers. And it's a problem for consumers as well, because if they know which retailer is responsible, they can rule themselves out for being at risk if they don't shop at that retailer."</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=NYGDhjF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=NYGDhjF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=fKTsmHF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=fKTsmHF" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 21 Mar 2008 03:39:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/data breach occurs">data breach occurs</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/million unique account">million unique account</category>
      <category domain="http://securityratty.com/tag/actual risk">actual risk</category>
      <category domain="http://securityratty.com/tag/card authorization process">card authorization process</category>
      <category domain="http://securityratty.com/tag/retailer">retailer</category>
      <category domain="http://securityratty.com/tag/rule">rule</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/fraud_due_to_a.html">Fraud Due to a Credit Card Breach</source>
    </item>
    <item>
      <title><![CDATA[Group points to VOIP flaw in DSL home gateway]]></title>
      <link>http://securityratty.com/article/ba080e6dd71158789e5c80ace0311f1e</link>
      <guid>http://securityratty.com/article/ba080e6dd71158789e5c80ace0311f1e</guid>
      <description><![CDATA[A flaw in a DSL home gateway could lead broadband users to divulge personal information over the phone to someone they erroneously believe is calling from their bank, according to a group of...]]></description>
      <content:encoded><![CDATA[A flaw in a DSL home gateway could lead broadband users to divulge personal information over the phone to someone they erroneously believe is calling from their bank, according to a group of self-styled ethical hackers.]]></content:encoded>
      <pubDate>Sun, 20 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dsl home gateway">dsl home gateway</category>
      <category domain="http://securityratty.com/tag/lead broadband users">lead broadband users</category>
      <category domain="http://securityratty.com/tag/divulge personal information">divulge personal information</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/ethical hackers">ethical hackers</category>
      <category domain="http://securityratty.com/tag/erroneously">erroneously</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <source url="http://www.networkworld.com/news/2008/012108-group-points-to-voip-flaw.html?fsrc=rss-security">Group points to VOIP flaw in DSL home gateway</source>
    </item>
    <item>
      <title><![CDATA[PGP and the 5th Amendment]]></title>
      <link>http://securityratty.com/article/40fe3718bcffd32d11f0253e5e6c9569</link>
      <guid>http://securityratty.com/article/40fe3718bcffd32d11f0253e5e6c9569</guid>
      <description><![CDATA[A Vermont federal judge has ruled that a person cannot be compelled by police to divulge his PGP key. This is by no means the end of the legal debate (Orin Kerr comments), but it's certainly good...]]></description>
      <content:encoded><![CDATA[A Vermont federal judge has ruled that a person cannot be compelled by police to divulge his PGP key. This is by no means the end of the legal debate (Orin Kerr comments), but it's certainly good news....<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/excerpts?a=IR1UutC"><img src="http://feeds.feedburner.com/~f/schneier/excerpts?i=IR1UutC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/excerpts?a=Hgig80C"><img src="http://feeds.feedburner.com/~f/schneier/excerpts?i=Hgig80C" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/excerpts?a=GNibSzC"><img src="http://feeds.feedburner.com/~f/schneier/excerpts?i=GNibSzC" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 24 Dec 2007 03:49:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/orin kerr comments">orin kerr comments</category>
      <category domain="http://securityratty.com/tag/vermont federal judge">vermont federal judge</category>
      <category domain="http://securityratty.com/tag/pgp key">pgp key</category>
      <category domain="http://securityratty.com/tag/ruled">ruled</category>
      <category domain="http://securityratty.com/tag/divulge">divulge</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <category domain="http://securityratty.com/tag/legal">legal</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <source url="http://www.schneier.com/blog/archives/2007/12/pgp_and_the_5th.html">PGP and the 5th Amendment</source>
    </item>
    <item>
      <title><![CDATA[Wow - AI Bot Phishing! Cool!]]></title>
      <link>http://securityratty.com/article/bd61f08bfb6b40fafd6f3251c95803a4</link>
      <guid>http://securityratty.com/article/bd61f08bfb6b40fafd6f3251c95803a4</guid>
      <description><![CDATA[Picked from SANS Newsletter : &quot;--Russian Chat Bots Gather Information
December 10, 2007

An artificial intelligence program circulating in Russian chat forums
flirts with human users in an attempt to...]]></description>
      <content:encoded><![CDATA[Picked from <a href="http://www.sans.org/newsletters/">SANS Newsletter</a>: "--Russian Chat Bots Gather Information<br />(December 10, 2007)<br /><br /><span style="font-weight: bold;">An artificial intelligence program circulating in Russian chat forums</span><br /><span style="font-weight: bold;">flirts with human users in an attempt to get them to <span style="font-style: italic;">divulge personally</span></span><br /><span style="font-weight: bold;"><span style="font-style: italic;">identifiable information.</span>  People have fallen prey to CyberLover because</span><br /><span style="font-weight: bold;">it is difficult for them to tell that they are not talking with a real</span><br /><span style="font-weight: bold;">person.  </span>The program can create up to 10 relationships in 30 minutes,<br />and assembles dossiers for each relationship that include names, contact<br />information and photographs. So far, CyberLover has just been spotted<br />in Russian chat rooms, but others are urged to use caution while<br />chatting." (original source <a href="http://www.zdnetasia.com/news/security/printfriendly.htm?AT=62035388-39000005c">here</a>)<br /><a href="http://www.zdnetasia.com/news/security/printfriendly.htm?AT=62035388-39000005c" target="_blank"></a><br />Wow, this is cool! Does it just match your perceptions about what the life in the 21st century would be like? :-) Robots stealing from people - how crass :-)<br /><br />And, pleeeeease, don't just respond this "people are stupid" :-)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MISLvCC"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MISLvCC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YDnAEaC"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YDnAEaC" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/199018986" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 11 Dec 2007 18:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian chat">russian chat</category>
      <category domain="http://securityratty.com/tag/russian chat forums">russian chat forums</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/artificial intelligence program">artificial intelligence program</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/identifiable information">identifiable information</category>
      <category domain="http://securityratty.com/tag/21st century">21st century</category>
      <category domain="http://securityratty.com/tag/assembles dossiers">assembles dossiers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/199018986/wow-ai-bot-phishing-cool.html">Wow - AI Bot Phishing! Cool!</source>
    </item>
  </channel>
</rss>
