<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dutch]]></title>
    <link>http://securityratty.com/tag/dutch</link>
    <description></description>
    <pubDate>Thu, 22 May 2008 18:30:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for August]]></title>
      <link>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</link>
      <guid>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</guid>
      <description><![CDATA[Here's a concise summary of all of my posts at Zero Day for August. If interested, consider going through July's summary , subscribe yourself to my personal feed , or Zero Day's main feed , and stay...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/GbK1dWvgJFs/s1600-h/zeroday_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/5TbgDFTdET4/s200-R/zeroday_august.png" /></a>Here's a concise summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a> for August. If interested, consider going through <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summary</a>, subscribe yourself to <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal feed</a>, or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a>, and stay informed.<br />
<br />
Some of the notable articles are - <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a> ; <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a> and <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1620">Cuil's stance on privacy - "We have no idea who you are"</a><br />
<b>02. </b><a href="http://blogs.zdnet.com/security/?p=1641">Phishers increasingly scamming other phishers</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1655">Consumer Reports urges Mac users to dump Safari, cites lack of phishing protection</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1657">Fake CNN news items malware campaign spreading rapidly</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1664">CNET's Clientside developer blog serving Adobe Flash exploits</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1712">Researcher discovers Nokia S40 security vulnerabilities, demands 20,000 euros to release details</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1717">Intel proactively fixes security flaws in its chips</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1723">1.5m spam emails sent from compromised University accounts</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1741">Fortune 500 companies use of email spoofing countermeasures declining</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1743">China busts hacking ring, managed to penetrate 10 gov't databases</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1750">Scammers caught backdooring chip and PIN terminals</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1754">SpamZa - opt in spamming service fighting to remain online</a><br />
<b>15.</b> <a href="http://blogs.zdnet.com/security/?p=1765">FEMA's PBX network hacked, over 400 calls made to the Middle East</a><br />
<b>16.</b> <a href="http://blogs.zdnet.com/security/?p=1782">Typosquatting the U.S presidential election - a security risk?</a><br />
<b>17.</b> <a href="http://blogs.zdnet.com/security/?p=1788">Hundreds of Dutch web sites hacked by Islamic hackers</a><br />
<b>18.</b> <a href="http://blogs.zdnet.com/security/?p=1796">Twitter's "me too" anti-spam strategy</a><br />
<b>19.</b> <a href="http://blogs.zdnet.com/security/?p=1806">Malware detected at the International Space Station</a><br />
<b>20.</b> <a href="http://blogs.zdnet.com/security/?p=1814">Taiwan busts hacking ring, 50 million personal records compromised</a><br />
<b>21.</b> <a href="http://blogs.zdnet.com/security/?p=1815">MSN Norway serving Flash exploits through malvertising</a><br />
<b>22.</b> <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q40d6L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q40d6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7EXTjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7EXTjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E4X5Il"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E4X5Il" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZxvQTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZxvQTl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8PfjsL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8PfjsL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bOWuvL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bOWuvL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RGgc1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RGgc1l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/383219682" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 03:40:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/adobe flash exploits">adobe flash exploits</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/flash exploits">flash exploits</category>
      <category domain="http://securityratty.com/tag/undetectable malware">undetectable malware</category>
      <category domain="http://securityratty.com/tag/inside india">inside india</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/million personal records">million personal records</category>
      <category domain="http://securityratty.com/tag/clientside developer blog">clientside developer blog</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/383219682/summarizing-zero-days-posts-for-august.html">Summarizing Zero Day's Posts for August</source>
    </item>
    <item>
      <title><![CDATA[Full Disclosure and the Boston Farecard Hack]]></title>
      <link>http://securityratty.com/article/40a098c4c848de62a0921d68f8cef2e7</link>
      <guid>http://securityratty.com/article/40a098c4c848de62a0921d68f8cef2e7</guid>
      <description><![CDATA[In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of &quot;full disclosure,&quot; asking whether researchers should be permitted to...]]></description>
      <content:encoded><![CDATA[<p>In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of "full disclosure," asking whether researchers should be permitted to disclose details of a fare-card vulnerability that allows people to ride the subway for free.</p>

<p>The "Oyster card" used on the <a href="http://www.schneier.com/essay-229.html">London Tube</a> was at issue in the Dutch case, and a similar fare card used on the <a href="http://blog.wired.com/27bstroke6/2008/08/injunction-requ.html">Boston "T"</a> was the center of the U.S. case. The Dutch court got it right, and the American court, in Boston, <a href="http://blog.wired.com/27bstroke6/2008/08/computer-scient.html ">got it wrong</a> from the start -- despite facing an open-and-shut case of First Amendment prior restraint.</p>

<p>The U.S. court has since <a href="http://blog.wired.com/27bstroke6/2008/08/federal-judge-t.html ">seen the error</a> of its ways -- but the damage is done. The MIT security researchers who were prepared to discuss their Boston findings at the DefCon security conference were <a href="http://blog.wired.com/27bstroke6/2008/08/eff-to-appeal-r.html ">prevented</a> from giving their talk.</p>

<p>The <a href="http://www.schneier.com/essay-146.html">ethics</a> of <a href="http://www.schneier.com/crypto-gram-0111.html#1">full disclosure</a> are intimately familiar to those of us in the computer-security field.  Before full disclosure became the norm, researchers would quietly disclose vulnerabilities to the vendors -- who would routinely ignore them. Sometimes vendors would even threaten researchers with legal action if they disclosed the vulnerabilities. </p>

<p>Later on, researchers started disclosing the existence of a vulnerability but not the details.  Vendors responded by denying the security holes' existence, or calling them just theoretical.  It wasn't until full disclosure became the norm that vendors began consistently fixing vulnerabilities quickly.  Now that vendors routinely patch vulnerabilities, researchers generally give them advance notice to allow them to patch their systems before the vulnerability is published.  But even with this "responsible disclosure" protocol, it's the threat of disclosure that motivates them to patch their systems.  Full disclosure <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/letter081208.pdf">is the mechanism</a> (.pdf) by which computer security improves.</p>

<p>Outside of computer security, secrecy is much more the norm.  Some security communities, like locksmiths, behave much like medieval guilds, divulging the secrets of their profession only to those within it.  These communities <a href="http://news.cnet.com/8301-1009_3-10002138-83.html?tag=mncol">hate</a> <a href="http://www.slate.com/id/2195862/">open</a> <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20080711.wlpicking11/EmailBNStory/lifeMain/">research</a>, and have <a href="http://www.schneier.com/crypto-gram-0302.html#1">responded</a> with <a href="http://www.crypto.com/papers/kiss.html">surprising vitriol</a> to <a href="http://www.crypto.com/papers/flattery.html">researchers</a> who have found serious vulnerabilities in <a href="http://www.wired.com/culture/lifestyle/news/2004/09/64987">bicycle locks</a>, <a href="http://www.crypto.com/papers/safelocks.pdf">combination safes</a> (.pdf), <a href="http://www.crypto.com/masterkey.html">master-key systems</a> and <a href="http://blog.wired.com/27bstroke6/2008/08/medeco-locks-cr.html">many</a> other <a href="http://en.wikipedia.org/wiki/Lock_bumping">security devices</a>.  </p>

<p>Researchers have received a similar reaction from other communities more used to secrecy than openness.  Researchers -- sometimes <a href="http://compsci.ca/blog/lanschool-threatens-compscica-with-legal-actions/">young students</a> -- who discovered and published flaws in copyright-protection schemes, <a href="http://www.freedom-to-tinker.com/?p=1265">voting-machine security</a> and now wireless access cards have all suffered recriminations and sometimes lawsuits for not keeping the vulnerabilities secret.  When Christopher Soghoian created a website allowing people to print fake airline boarding passes, he got <a href="http://www.schneier.com/blog/archives/2006/11/forge_your_own.html">several unpleasant visits</a> from the FBI.</p>

<p>This preference for secrecy comes from confusing a vulnerability with information <em>about</em> that vulnerability.  Using <a href="http://www.schneier.com/crypto-gram-0205.html#1">secrecy as a security measure</a> is fundamentally fragile.  It assumes that the bad guys don't do their own security research.  It assumes that no one else will find the same vulnerability.  It assumes that information won't leak out even if the research results are suppressed.  These assumptions are all incorrect.</p>

<p>The problem isn't the researchers; it's the products themselves.  Companies will only design security as good as what their customers know to ask for.  Full disclosure helps customers evaluate the security of the products they buy, and educates them in how to ask for better security.  The Dutch court got it exactly right when it <a href="http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=true&searchtype=ljn&ljn=BD7578&u_ljn=BD7578">wrote</a>: "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."</p>

<p>In a world of forced secrecy, vendors make inflated claims about their products, vulnerabilities don't get fixed, and customers are no wiser.  Security research is stifled, and security technology doesn't improve.  The only beneficiaries are the bad guys.</p>

<p>If you'll forgive the analogy, the ethics of full disclosure parallel the ethics of not paying kidnapping ransoms.  We all know why we don't pay kidnappers: It encourages more kidnappings.  Yet in every kidnapping case, there's someone -- a spouse, a parent, an employer -- with a good reason why, in this one case, we should make an exception. </p>

<p>The reason we want researchers to publish vulnerabilities is because that's how security improves. But in every case there's someone -- the Massachusetts Bay Transit Authority, the locksmiths, an election machine manufacturer -- who argues that, in this one case, we should make an exception.</p>

<p>We shouldn't.  The benefits of responsibly publishing attacks greatly outweigh the potential harm. Disclosure encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers.  It's how we learn about security, and how we improve future security.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/08/securitymatters_0821">previously appeared</a> on Wired.com.</p>

<p>EDITED TO ADD (8/26):  Matt Blaze has a <a href="http://www.crypto.com/blog/security_through_restraining_orders/">good essay</a> on the topic.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Jzhf7K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Jzhf7K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=e3TDeK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=e3TDeK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 02:04:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer security improves">computer security improves</category>
      <category domain="http://securityratty.com/tag/security improves">security improves</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/mit security researchers">mit security researchers</category>
      <category domain="http://securityratty.com/tag/security devices">security devices</category>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/security properly">security properly</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/full_disclosure.html">Full Disclosure and the Boston Farecard Hack</source>
    </item>
    <item>
      <title><![CDATA[Boston Court's Meddling With 'Full Disclosure' Is Unwelcome]]></title>
      <link>http://securityratty.com/article/b65bde3bbcffdced12efa1287ce8e1e0</link>
      <guid>http://securityratty.com/article/b65bde3bbcffdced12efa1287ce8e1e0</guid>
      <description><![CDATA[In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of &quot;full disclosure,&quot; asking whether researchers should be permitted to...]]></description>
      <content:encoded><![CDATA[<p>
In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of "full disclosure," asking whether researchers should be permitted to disclose details of a fare-card vulnerability that allows people to ride the subway for free.
</p><p>
The "Oyster card" used on the <a href="http://www.schneier.com/essay-229.html">London Tube</a> was at issue in the Dutch case, and a similar fare card used on the <a href="http://blog.wired.com/27bstroke6/2008/08/injunction-requ.html">Boston "T"</a> was the center of the U.S. case. The Dutch court got it right, and the American court, in Boston, <a href="http://blog.wired.com/27bstroke6/2008/08/computer-scient.html ">got it wrong</a> from the start -- despite facing an open-and-shut case of First Amendment prior restraint.
</p><p>
The U.S. court has since <a href="http://blog.wired.com/27bstroke6/2008/08/federal-judge-t.html ">seen the error</a> of its ways -- but the damage is done. The MIT security researchers who were prepared to discuss their Boston findings at the DefCon security conference were <a href="http://blog.wired.com/27bstroke6/2008/08/eff-to-appeal-r.html ">prevented</a> from giving their talk.
</p><p>
The <a href="http://www.schneier.com/essay-146.html">ethics</a> of <a href="http://www.schneier.com/crypto-gram-0111.html#1">full disclosure</a> are intimately familiar to those of us in the computer-security field.  Before full disclosure became the norm, researchers would quietly disclose vulnerabilities to the vendors -- who would routinely ignore them. Sometimes vendors would even threaten researchers with legal action if they disclosed the vulnerabilities. 
</p><p>
Later on, researchers started disclosing the existence of a vulnerability but not the details.  Vendors responded by denying the security holes' existence, or calling them just theoretical.  It wasn't until full disclosure became the norm that vendors began consistently fixing vulnerabilities quickly.  Now that vendors routinely patch vulnerabilities, researchers generally give them advance notice to allow them to patch their systems before the vulnerability is published.  But even with this "responsible disclosure" protocol, it's the threat of disclosure that motivates them to patch their systems.  Full disclosure <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/letter081208.pdf">is the mechanism</a> (.pdf) by which computer security improves.
</p><p>
Outside of computer security, secrecy is much more the norm.  Some security communities, like locksmiths, behave much like medieval guilds, divulging the secrets of their profession only to those within it.  These communities <a href="http://news.cnet.com/8301-1009_3-10002138-83.html?tag=mncol">hate</a> <a href="http://www.slate.com/id/2195862/">open</a> <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20080711.wlpicking11/EmailBNStory/lifeMain/">research</a>, and have <a href="http://www.schneier.com/crypto-gram-0302.html#1">responded</a> with <a href="http://www.crypto.com/papers/kiss.html">surprising vitriol</a> to <a href="http://www.crypto.com/papers/flattery.html">researchers</a> who have found serious vulnerabilities in <a href="http://www.wired.com/culture/lifestyle/news/2004/09/64987">bicycle locks</a>, <a href="http://www.crypto.com/papers/safelocks.pdf">combination safes</a> (.pdf), <a href="http://www.crypto.com/masterkey.html">master-key systems</a> and <a href="http://blog.wired.com/27bstroke6/2008/08/medeco-locks-cr.html">many</a> other <a href="http://en.wikipedia.org/wiki/Lock_bumping">security devices</a>.  
</p><p>
Researchers have received a similar reaction from other communities more used to secrecy than openness.  Researchers -- sometimes <a href="http://compsci.ca/blog/lanschool-threatens-compscica-with-legal-actions/">young students</a> -- who discovered and published flaws in copyright-protection schemes, <a href="http://www.freedom-to-tinker.com/?p=1265">voting-machine security</a> and now wireless access cards have all suffered recriminations and sometimes lawsuits for not keeping the vulnerabilities secret.  When Christopher Soghoian created a website allowing people to print fake airline boarding passes, he got <a href="http://www.schneier.com/blog/archives/2006/11/forge_your_own.html">several unpleasant visits</a> from the FBI.
</p><p>
This preference for secrecy comes from confusing a vulnerability with information <em>about</em> that vulnerability.  Using <a href="http://www.schneier.com/crypto-gram-0205.html#1">secrecy as a security measure</a> is fundamentally fragile.  It assumes that the bad guys don't do their own security research.  It assumes that no one else will find the same vulnerability.  It assumes that information won't leak out even if the research results are suppressed.  These assumptions are all incorrect.
</p><p>
The problem isn't the researchers; it's the products themselves.  Companies will only design security as good as what their customers know to ask for.  Full disclosure helps customers evaluate the security of the products they buy, and educates them in how to ask for better security.  The Dutch court got it exactly right when it <a href="http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=true&searchtype=ljn&ljn=BD7578&u_ljn=BD7578">wrote</a>: "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."
</p><p>
In a world of forced secrecy, vendors make inflated claims about their products, vulnerabilities don't get fixed, and customers are no wiser.  Security research is stifled, and security technology doesn't improve.  The only beneficiaries are the bad guys.
</p><p>
If you'll forgive the analogy, the ethics of full disclosure parallel the ethics of not paying kidnapping ransoms.  We all know why we don't pay kidnappers: It encourages more kidnappings.  Yet in every kidnapping case, there's someone -- a spouse, a parent, an employer -- with a good reason why, in this one case, we should make an exception. 
</p><p>
The reason we want researchers to publish vulnerabilities is because that's how security improves. But in every case there's someone -- the Massachusetts Bay Transit Authority, the locksmiths, an election machine manufacturer -- who argues that, in this one case, we should make an exception.
</p><p>
We shouldn't.  The benefits of responsibly publishing attacks greatly outweigh the potential harm. Disclosure encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers.  It's how we learn about security, and how we improve future security.
</p>
<p>---</p>

<p>
<em>Bruce Schneier is Chief Security Technology Officer of BT Global Services and author of </em><a href="http://www.schneier.com/bf.html">Beyond Fear: Thinking Sensibly About Security in an Uncertain World</a><em>. You can read more of his writings on his <a href="http://www.schneier.com/">website</a>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=bca653e99d30d29fe90a724af1243458" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=bca653e99d30d29fe90a724af1243458" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=FBzLDK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=FBzLDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=I2e1pk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=I2e1pk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=znpbtk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=znpbtk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=bR68YK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=bR68YK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=AMJk5K"><img src="http://feeds.wired.com/~f/wired/politics/security?i=AMJk5K" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=ZF5tzk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ZF5tzk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=iWkWjk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=iWkWjk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=f5xemK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=f5xemK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/370586608" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/370586609" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer security improves">computer security improves</category>
      <category domain="http://securityratty.com/tag/security improves">security improves</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/mit security researchers">mit security researchers</category>
      <category domain="http://securityratty.com/tag/security devices">security devices</category>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/security properly">security properly</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/370586609/securitymatters_0821">Boston Court's Meddling With 'Full Disclosure' Is Unwelcome</source>
    </item>
    <item>
      <title><![CDATA[Dutch police, FBI rein in large botnet]]></title>
      <link>http://securityratty.com/article/5c22652220634e010867b124841a5e0c</link>
      <guid>http://securityratty.com/article/5c22652220634e010867b124841a5e0c</guid>
      <description><![CDATA[The botnet created by a teenager who was arrested by Dutch police in a sting operation is most notable for its total reliance on social engineering to spread, computer security experts said...]]></description>
      <content:encoded><![CDATA[The botnet created by a teenager who was arrested by Dutch police in a sting operation is most notable for its total reliance on social engineering to spread, computer security experts said Thursday.]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dutch police">dutch police</category>
      <category domain="http://securityratty.com/tag/computer security experts">computer security experts</category>
      <category domain="http://securityratty.com/tag/total reliance">total reliance</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/teenager">teenager</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <category domain="http://securityratty.com/tag/notable">notable</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <source url="http://www.networkworld.com/news/2008/081408-dutch-police-fbi-rein-in.html?fsrc=rss-security">Dutch police, FBI rein in large botnet</source>
    </item>
    <item>
      <title><![CDATA[Hacking Mifare Transport Cards]]></title>
      <link>http://securityratty.com/article/3a7dba1bb2685c0c225ca69eddd304c7</link>
      <guid>http://securityratty.com/article/3a7dba1bb2685c0c225ca69eddd304c7</guid>
      <description><![CDATA[London's Oyster card has been cracked , and the final details will become public in October. NXP Semiconductors, the Philips spin-off that makes the system, lost a court battle to prevent the...]]></description>
      <content:encoded><![CDATA[<p>London's Oyster card has been <a href="http://www.guardian.co.uk/technology/2008/jun/26/hitechcrime.oystercards">cracked</a>, and the final details will become public in October. NXP Semiconductors, the Philips spin-off that makes the system, lost a court battle to prevent the researchers from publishing. People might be able to use this information to ride for free, but the sky won't be falling. And the publication of this serious vulnerability actually makes us all safer in the long run.</p>

<p>Here's the story. Every Oyster card has a radio-frequency identification chip that communicates with readers mounted on the ticket barrier. That chip, the "Mifare Classic" chip, is used in hundreds of other transport systems as well — Boston, Los Angeles, Brisbane, Oslo, Amsterdam, Taipei, Shanghai, Rio de Janeiro — and as an access pass in thousands of companies, schools, hospitals, and government buildings around Britain and the rest of the world.</p>

<p>The security of Mifare Classic is terrible. This is not an exaggeration; it's kindergarten cryptography. Anyone with any security experience would be embarrassed to put his name to the design. NXP attempted to deal with this embarrassment by keeping the design secret.</p>

<p>The group that <a href="http://www.ru.nl/ds/research/rfid/">broke</a> Mifare Classic is from Radboud University Nijmegen in the Netherlands. They <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article4184481.ece">demonstrated the attack</a> by riding the Underground for free, and by <a href="http://www.youtube.com/watch?v=NW3RGbQTLhE">breaking into</a> a building. Their two papers (one is already <a href="http://www.cs.ru.nl/~flaviog/publications/Attack.MIFARE.pdf">online</a>) will be published at <a href="http://www.scc.rhul.ac.uk/CARDIS/">two</a> <a href="http://www.isac.uma.es/esorics08/">conferences</a> this autumn.</p>

<p>The second paper is the one that NXP <a href="http://news.cnet.com/8301-10784_3-9985886-7.html?hhTest=1">sued</a> <a href="http://www.secureidnews.com/news/2008/07/10/nxp-sues-to-prevent-hackers-from-releasing-mifare-flaws/">over</a>. They called disclosure of the attack "irresponsible," warned that it will cause "immense damages," and claimed that it "will jeopardize the security of assets protected with systems incorporating the Mifare IC." The <a href="http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=true&amp;searchtype=ljn&amp;ljn=BD7578&amp;u_ljn=BD7578">Dutch court</a> would have none of it:  "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."</p>

<p>Exactly right. More generally, the notion that secrecy supports security is <a href="http://www.schneier.com/crypto-gram-0205.html#1">inherently flawed</a>. Whenever you see an organization claiming that design secrecy is necessary for security — in ID cards, in voting machines, in airport security — it invariably means that its security is lousy and it has no choice but to hide it. Any competent cryptographer would have designed Mifare's security with an open and public design.</p>

<p>Secrecy is fragile. Mifare's security was based on the belief that no one would discover how it worked; that's why NXP had to muzzle the Dutch researchers. But that's just wrong. Reverse-engineering isn't hard. <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=spam__malware_and_vulnerabilities&amp;articleId=9078038&amp;taxonomyId=85">Other</a> <a href="http://www.cs.virginia.edu/~evans/pubs/usenix08/">researchers</a> <a href="http://eprint.iacr.org/2008/166">had</a> <a href="http://staff.science.uva.nl/~delaat/sne-2006-2007/p41/Report.pdf">already</a> <a href="http://www.translink.nl/media/bijlagen/nieuws/TNO_ICT_-_Security_Analysis_OV-Chipkaart_-_public_report.pdf">exposed</a> Mifare's lousy security. A Chinese company even <a href="http://www.fmsh.com/english/product_chipcard.php?product=FM11RF32">sells</a> a <a href="http://www.fmsh.com/english/products/FM11RF32_FS_ENG.pdf">compatible chip</a>. Is there any doubt that the bad guys already know about this, or will soon enough?</p>

<p>Publication of this attack might be expensive for NXP and its customers, but it's good for security overall. Companies will only design security as good as their customers know to ask for. NXP's security was so bad because customers didn't know how to evaluate security: either they don't know what questions to ask, or didn't know enough to distrust the marketing answers they were given. This court ruling encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers.</p>

<p>It's unclear how this break will affect <a href="http://www.tfl.gov.uk/">Transport for London</a>. Cloning takes only a few seconds, and the thief only has to brush up against someone carrying a legitimate Oyster card. But it requires an RFID reader and a small piece of software which, while feasible for a techie, are too complicated for the average fare dodger. The police are likely to quickly arrest anyone who tries to sell cloned cards on any scale. TfL <a href="http://news.cnet.co.uk/software/0,39029694,49297810,00.htm">promises</a> <a href="http://www.techradar.com/news/world-of-tech/tfl-responds-to-oyster-hack-runling-428238">to</a> turn off any cloned cards within 24 hours, but that will hurt the innocent victim who had his card cloned more than the thief.</p>

<p>The vulnerability is far more serious to the companies that use Mifare Classic as an access pass. It would be very interesting to know how NXP presented the system's security to them.</p>

<p>And while these attacks only pertain to the Mifare Classic chip, it makes me suspicious of the entire product line. NXP sells a more secure chip and has another on the way, but given the number of basic cryptography mistakes NXP made with Mifare Classic, one has to wonder whether the "more secure" versions will be sufficiently so.</p>

<p>This essay <a href="http://www.guardian.co.uk/technology/2008/aug/07/hacking.security">originally appeared</a> in the <i>Guardian</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lyT29K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lyT29K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3HhhnK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3HhhnK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 02:07:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mifare">mifare</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/design secrecy">design secrecy</category>
      <category domain="http://securityratty.com/tag/mifare classic chip">mifare classic chip</category>
      <category domain="http://securityratty.com/tag/secrecy">secrecy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/secrecy supports security">secrecy supports security</category>
      <category domain="http://securityratty.com/tag/security properly">security properly</category>
      <category domain="http://securityratty.com/tag/chip">chip</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/hacking_mifare.html">Hacking Mifare Transport Cards</source>
    </item>
    <item>
      <title><![CDATA[RFID chipmaker loses suit, says users must take 'urgent' action]]></title>
      <link>http://securityratty.com/article/ec8de170c9f6f4c2822f9c343ff6ccaa</link>
      <guid>http://securityratty.com/article/ec8de170c9f6f4c2822f9c343ff6ccaa</guid>
      <description><![CDATA[A Dutch court has ruled that Radboud University Nijmegen researchers can publish a paper outlining flaws in an RFID chip manufactured by NXP...]]></description>
      <content:encoded><![CDATA[A Dutch court has ruled that Radboud University Nijmegen researchers can publish a paper outlining flaws in an RFID chip manufactured by NXP Semiconductors.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=C2ytZV"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=C2ytZV" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/343942183" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dutch court">dutch court</category>
      <category domain="http://securityratty.com/tag/nxp semiconductors">nxp semiconductors</category>
      <category domain="http://securityratty.com/tag/radboud university">radboud university</category>
      <category domain="http://securityratty.com/tag/rfid chip">rfid chip</category>
      <category domain="http://securityratty.com/tag/ruled">ruled</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/publish">publish</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/343942183/article.do">RFID chipmaker loses suit, says users must take 'urgent' action</source>
    </item>
    <item>
      <title><![CDATA[Random Stupidity in the Name of Terrorism]]></title>
      <link>http://securityratty.com/article/c81bd0a4e004add0a54874f8bf604a84</link>
      <guid>http://securityratty.com/article/c81bd0a4e004add0a54874f8bf604a84</guid>
      <description><![CDATA[An air traveller in Canada is first told by an airline employee that it is &quot;illegal&quot; to say certain words, and then that if he raised a fuss he would be falsely accused: When we boarded a little...]]></description>
      <content:encoded><![CDATA[An air traveller in Canada is first <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20080627.blatch28/BNStory/specialComment/home">told</a> by an airline employee that it is "illegal" to say certain words, and then that if he raised a fuss he would be falsely accused:

<blockquote>When we boarded a little later, I asked for the ninny's name. He refused and hissed, "If you make a scene, I'll call the pilot and you won't be flying tonight."</blockquote>

More on the British <a href="http://www.theregister.co.uk/2008/06/23/police_photographer_stops/">war on photographers</a>.

A British man is forced to give up his <a href="http://uk.news.yahoo.com/skynews/20080624/tuk-bus-spotter-labelled-a-paedophile-45dbed5.html">hobby</a> of photographing busses due to harrassment.

<blockquote>The credit controller, from Gloucester, says he now suffers "appalling" abuse from the authorities and public who doubt his motives.

The bus-spotter, officially known as an omnibologist, said: "Since the 9/11 attacks there has been a crackdown.

"The past two years have absolutely been the worst. I have had the most appalling abuse from the public, drivers and police over-exercising their authority.

Mr McCaffery, who is married, added: "We just want to enjoy our hobby without harassment.

"I can deal with the fact someone might think I'm a terrorist, but when they start saying you're a paedophile it really hurts."</blockquote>

Is <a href="http://www.cnn.com/2008/WORLD/meast/07/02/israel.bulldozer/">everything</a> illegal and damaging now terrorism?

<blockquote>Israeli authorities are investigating why a Palestinian resident of Jerusalem rammed his bulldozer into several cars and buses Wednesday, killing three people before Israeli police shot him dead.

Israeli authorities are labeling it a terrorist attack, although they say there is no clear motive and the man -- a construction worker -- acted alone. It is not known if he had links to any terrorist organization.</blockquote>

Boston public school locked down after someone <a href="http://www.boston.com/news/odd/articles/2008/06/25/school_locked_down_after_ninja_sighted_in_woods/">saw</a> a ninja:

<blockquote>Turns out the ninja was actually a camp counselor dressed in black karate garb and carrying a plastic sword.

Police tell the Asbury Park Press the man was late to a costume-themed day at a nearby middle school.</blockquote>

And finally, not terrorism-related but a fine newspaper headline:  "<a href="http://ap.google.com/article/ALeqM5h1AqbvSMYPxJrla6-Fgym8WIzEsgD91KNJD00">Giraffe helps camels, zebras escape from circus</a>":

<blockquote>Amsterdam police say 15 camels, two zebras and an undetermined number of llamas and potbellied swine briefly escaped from a traveling Dutch circus after a giraffe kicked a hole in their cage.</blockquote>

Are llamas really that hard to count?<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=eQI3GJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=eQI3GJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=tEUVdJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=tEUVdJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 08:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/israeli police shot">israeli police shot</category>
      <category domain="http://securityratty.com/tag/giraffe">giraffe</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <category domain="http://securityratty.com/tag/israeli authorities">israeli authorities</category>
      <category domain="http://securityratty.com/tag/giraffe helps camels">giraffe helps camels</category>
      <category domain="http://securityratty.com/tag/authorities">authorities</category>
      <category domain="http://securityratty.com/tag/boston public school">boston public school</category>
      <category domain="http://securityratty.com/tag/terrorist organization">terrorist organization</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/random_stupidit.html">Random Stupidity in the Name of Terrorism</source>
    </item>
    <item>
      <title><![CDATA[Hackers Crack London Tube's Ticketing System]]></title>
      <link>http://securityratty.com/article/49975bd42ea9f20ed79f8fcec26e45c8</link>
      <guid>http://securityratty.com/article/49975bd42ea9f20ed79f8fcec26e45c8</guid>
      <description><![CDATA[Dutch security researchers rode the London Underground free for a day after easily using an ordinary laptop to clone the &quot;smartcards&quot; commuters use to pay fares, a hack that highlights a serious...]]></description>
      <content:encoded><![CDATA[Dutch security researchers rode the London Underground free for a day after easily using an ordinary laptop to clone the "smartcards" commuters use to pay fares, a hack that highlights a serious security flaw because similar cards provide access to thousands of government offices, hospitals and schools.]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 17:51:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/london underground free">london underground free</category>
      <category domain="http://securityratty.com/tag/dutch security researchers">dutch security researchers</category>
      <category domain="http://securityratty.com/tag/security flaw">security flaw</category>
      <category domain="http://securityratty.com/tag/government offices">government offices</category>
      <category domain="http://securityratty.com/tag/ordinary laptop">ordinary laptop</category>
      <category domain="http://securityratty.com/tag/fares">fares</category>
      <category domain="http://securityratty.com/tag/thousands">thousands</category>
      <category domain="http://securityratty.com/tag/easily">easily</category>
      <category domain="http://securityratty.com/tag/highlights">highlights</category>
      <source url="http://digg.com/security/Hackers_Crack_London_Tube_s_Ticketing_System">Hackers Crack London Tube's Ticketing System</source>
    </item>
    <item>
      <title><![CDATA[Dutch launch open-source smart card software project]]></title>
      <link>http://securityratty.com/article/4849f13455f71d5cecdf37759041bd50</link>
      <guid>http://securityratty.com/article/4849f13455f71d5cecdf37759041bd50</guid>
      <description><![CDATA[A Dutch charity is funding an open-source project to design smart card software that offers stronger protection of personal data in light of security vulnerabilities found with cards used today in the...]]></description>
      <content:encoded><![CDATA[A Dutch charity is funding an open-source project to design smart card software that offers stronger protection of personal data in light of security vulnerabilities found with cards used today in the U.S., U.K. and Netherlands.]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/offers stronger protection">offers stronger protection</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/dutch charity">dutch charity</category>
      <category domain="http://securityratty.com/tag/open-source project">open-source project</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/light">light</category>
      <category domain="http://securityratty.com/tag/netherlands">netherlands</category>
      <source url="http://www.networkworld.com/news/2008/062008-dutch-launch-open-source-smart-card.html?fsrc=rss-security">Dutch launch open-source smart card software project</source>
    </item>
    <item>
      <title><![CDATA[Marines Land in Afghanistan -- with Biometrics]]></title>
      <link>http://securityratty.com/article/341f8023eff4009290265af98b94419d</link>
      <guid>http://securityratty.com/article/341f8023eff4009290265af98b94419d</guid>
      <description><![CDATA[A year ago this June, Taliban fighters streamed into the remote town of Chora in southern Afghanistan expecting an easy victory over impoverished villagers. Instead, they met heavy resistance from...]]></description>
      <content:encoded><![CDATA[<p>A year ago this June, Taliban fighters streamed into the remote town of Chora in southern Afghanistan expecting an easy victory over impoverished villagers. Instead, they met heavy resistance from scores of uniformed Afghan men.</p>

<p>Those so-called Afghan National Auxiliary Police (ANAP), all formerly in the service of local warlords, had received two months of training by Dutch and American soldiers and were now the first line of defense against the Taliban.</p>

<p>Arming tribesmen was a risky idea. True, this sort of tribal initiative had been effective in Iraq. But NATO commanders feared that Afghan loyalties to their warlords ran too deep. NATO was “arming people who were not necessarily in line with the [Afghan] government,” U.S. Brig. Gen. Robert Cone told Wired.com.</p>

<p>So, last month, NATO fired the auxiliary cops and scrapped the tribal strategy, leaving gaping holes in Afghanistan's defenses. The fix? Marines, of course, armed with fingerprint pads, iris scanners and electronic databases.</p>

<p>With these biometric tools, the Marines are planning to recruit new cops who have no ties to tribal warlords. “We know there are some shadow police and some militia-type police,” Lt. Col. Ray Hall, the Marine commander, said. “Once we go through the vetting process, we'll have everybody screened … so that problem should go away.”</p>


<p>That means scanning every new recruit's unique iris “eye prints,” logging their thumb prints and feeding it all into a growing, but still very spotty, national database linked to criminal and intelligence records. If a cop has any known warlord ties, he's disqualified from serving.</p>


<p>CIA teams used FBI biometrics while hunting for known Al Qaeda operatives in Afghanistan in 2001, and since then, the military has gathered data on almost every Afghan it comes in regular contact with.</p>

<p>There's one more problem. Not all the military databases can talk to one another. “We haven't standardized,” said Larry Schneider, a Northrop Grumman VP who last year was working on collapsing many biometrics systems into just one.</p>

<p>Until everyone is looking at the same data, seditious Afghan cops will probably keep falling through the cracks. </p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8e864b5693d073a8576ef6a5f0dcd116" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8e864b5693d073a8576ef6a5f0dcd116" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=P1dSOH"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=P1dSOH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xrzogh"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xrzogh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=nJh6oh"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=nJh6oh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Di90gH"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Di90gH" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=WFlSZH"><img src="http://feeds.wired.com/~f/wired/politics/security?i=WFlSZH" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=e7NoWh"><img src="http://feeds.wired.com/~f/wired/politics/security?i=e7NoWh" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=GYyrjh"><img src="http://feeds.wired.com/~f/wired/politics/security?i=GYyrjh" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=5IrDNH"><img src="http://feeds.wired.com/~f/wired/politics/security?i=5IrDNH" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/296157070" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/296157079" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 22 May 2008 18:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/afghan">afghan</category>
      <category domain="http://securityratty.com/tag/afghan government">afghan government</category>
      <category domain="http://securityratty.com/tag/seditious afghan cops">seditious afghan cops</category>
      <category domain="http://securityratty.com/tag/afghanistan">afghanistan</category>
      <category domain="http://securityratty.com/tag/cops">cops</category>
      <category domain="http://securityratty.com/tag/afghan loyalties">afghan loyalties</category>
      <category domain="http://securityratty.com/tag/nato commanders">nato commanders</category>
      <category domain="http://securityratty.com/tag/nato">nato</category>
      <category domain="http://securityratty.com/tag/warlords">warlords</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/296157079/biometrics_afghan_marines">Marines Land in Afghanistan -- with Biometrics</source>
    </item>
  </channel>
</rss>
