<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: e-discovery]]></title>
    <link>http://securityratty.com/tag/e-discovery</link>
    <description></description>
    <pubDate>Mon, 06 Oct 2008 19:00:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Data Mining for Terrorists Doesn't Work]]></title>
      <link>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</link>
      <guid>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</guid>
      <description><![CDATA[According to a massive report from the National Research Council, data mining for terrorists doesn't work. Here's a good summary: The report was written by a committee whose members include William...]]></description>
      <content:encoded><![CDATA[<p>According to a <a href="http://www.nap.edu/catalog.php?record_id=12452">massive report</a> from the National Research Council, data mining for terrorists doesn't work.  <a href="http://news.cnet.com/8301-13578_3-10059987-38.html?part=rss&subj=news&tag=2547-1_3-0-20">Here's</a> a good summary:</p>

<blockquote>The report was written by a committee whose members include William Perry, a professor at Stanford University; Charles Vest, the former president of MIT; W. Earl Boebert, a retired senior scientist at Sandia National Laboratories; Cynthia Dwork of Microsoft Research; R. Gil Kerlikowske, Seattle's police chief; and Daryl Pregibon, a research scientist at Google.

<p>They admit that far more Americans live their lives online, using everything from VoIP phones to Facebook to RFID tags in automobiles, than a decade ago, and the databases created by those activities are tempting targets for federal agencies. And they draw a distinction between subject-based data mining (starting with one individual and looking for connections) compared with pattern-based data mining (looking for anomalous activities that could show illegal activities).</p>

<p>But the authors conclude the type of data mining that government bureaucrats would like to do--perhaps inspired by watching too many episodes of the Fox series 24--can't work. "If it were possible to automatically find the digital tracks of terrorists and automatically monitor only the communications of terrorists, public policy choices in this domain would be much simpler. But it is not possible to do so."</p>

<p>A summary of the recommendations:</p>

<ul><li>U.S. government agencies should be required to follow a systematic process to evaluate the effectiveness, lawfulness, and consistency with U.S. values of every information-based program, whether classified or unclassified, for detecting and countering terrorists before it can be deployed, and periodically thereafter.

<p><li>Periodically after a program has been operationally deployed, and in particular before a program enters a new phase in its life cycle, policy makers should (carefully review) the program before allowing it to continue operations or to proceed to the next phase.</p>

<p><li>To protect the privacy of innocent people, the research and development of any information-based counterterrorism program should be conducted with synthetic population data... At all stages of a phased deployment, data about individuals should be rigorously subjected to the full safeguards of the framework.</p>

<p><li>Any information-based counterterrorism program of the U.S. government should be subjected to robust, independent oversight of the operations of that program, a part of which would entail a practice of using the same data mining technologies to "mine the miners and track the trackers."</p>

<p><li>Counterterrorism programs should provide meaningful redress to any individuals inappropriately harmed by their operation.</p>

<p><li>The U.S. government should periodically review the nation's laws, policies, and procedures that protect individuals' private information for relevance and effectiveness in light of changing technologies and circumstances. In particular, Congress should re-examine existing law to consider how privacy should be protected in the context of information-based programs (e.g., data mining) for counterterrorism.</ul></blockquote></p>

<p><a href="http://www.nytimes.com/2008/10/08/washington/08data.html">Here</a> <a href="http://blog.wired.com/27bstroke6/2008/10/data-mining-for.html">are</a> <a href="http://techdirt.com/articles/20081007/1242002479.shtml">more</a> news articles on the report.  I <a href="http://www.schneier.com/essay-108.html">explained</a> why data mining wouldn't find terrorists back in 2005.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=w2YwM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=w2YwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=sK5kM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=sK5kM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 02:35:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/synthetic population data">synthetic population data</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/program enters">program enters</category>
      <category domain="http://securityratty.com/tag/research scientist">research scientist</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/microsoft research">microsoft research</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/data_mining_for_1.html">Data Mining for Terrorists Doesn't Work</source>
    </item>
    <item>
      <title><![CDATA[POPE Rules!]]></title>
      <link>http://securityratty.com/article/0efd3abe24c9f19a5b177dfb1c91d227</link>
      <guid>http://securityratty.com/article/0efd3abe24c9f19a5b177dfb1c91d227</guid>
      <description><![CDATA[OMFG, this sooo made my day today. Mike Rothman &quot;communicates&quot; with P.O.P.E . and produces deep, lasting, impacting insight (&quot;incite?&quot;) on career, skills, etc

My fave piece: &quot;But ultimately I fancy...]]></description>
      <content:encoded><![CDATA[OMFG, <a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">this </a>sooo made my day today. Mike Rothman <a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">"communicates" with P.O.P.E</a>. and produces deep, lasting, impacting insight ("incite?") on career, skills, etc.<br /><br />My fave piece: "But ultimately I fancy myself to be a builder and [his new job] gives me the opportunity to build a strong strategy and marketing function." Amen to that! Even though Mike can be a "talker" too, not only a "builder."<br /><br /><a href="http://securityincite.com/blog/mike-rothman/career-advice-from-the-pope">Read it!</a><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=g8nyM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=g8nyM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=h7slM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=h7slM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=6u8kM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=6u8kM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/415211313" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 11:09:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mike">mike</category>
      <category domain="http://securityratty.com/tag/mike rothman">mike rothman</category>
      <category domain="http://securityratty.com/tag/produces deep">produces deep</category>
      <category domain="http://securityratty.com/tag/strong strategy">strong strategy</category>
      <category domain="http://securityratty.com/tag/fave piece">fave piece</category>
      <category domain="http://securityratty.com/tag/builder">builder</category>
      <category domain="http://securityratty.com/tag/function">function</category>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/opportunity">opportunity</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/415211313/pope-rules.html">POPE Rules!</source>
    </item>
    <item>
      <title><![CDATA[Tenn. student indicted for hacking Palin's e-mail]]></title>
      <link>http://securityratty.com/article/7c2688b677117f0cc6d9c24b26f2cd38</link>
      <guid>http://securityratty.com/article/7c2688b677117f0cc6d9c24b26f2cd38</guid>
      <description><![CDATA[The Tennessee college student who came under suspicion as the hacker who broke into the e-mail account of vice presidential candidate Sarah Palin has been indicted by a federal grand...]]></description>
      <content:encoded><![CDATA[The Tennessee college student who came under suspicion as the hacker who broke into the e-mail account of vice presidential candidate Sarah Palin has been indicted by a federal grand jury.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:24a7da4fcaef57af8e5c3adccf4c01ee:lPQi71Ep5ZL2IM%2F7ngVjpVf1tOpD80wO0dLRvEB7nFTnNxAl94aJWuNe4fVtqfFLF6g5VwESQVVm'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c8c50797519e84ee0cea0140fa7f728b:OGQGpLs76HqHTtZC3cpj6eckPrN%2FGkPjdmJ8hzepjjA7l3sKDmSo9a%2B0j%2B%2Fe7ez2W%2FmPCKpjS%2BmKSQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5e7684fabee745e619f63fa26309daf1:wDUmO4of6AEBzsdJ9y7GREmH%2F1fvt5oY0hh1b0m5uDePMgPFLBrzXQh6sBu6zXv%2B95HvIEDtiy2JGQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5a3d52939d24cd40fe82d50282bcada4:yo2dceotwAllcZFQcJZePMjl2jde0kCytfpxA7zSR%2B0l8%2F9Eb5MO356cgi3YJ9xJ5vV1UwM%2FyvIM8w%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=9296a669728ea3309de7ceb244294be0"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=9296a669728ea3309de7ceb244294be0"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=9296a669728ea3309de7ceb244294be0" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal grand jury">federal grand jury</category>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/vice presidential">vice presidential</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/suspicion">suspicion</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9296a669728ea3309de7ceb244294be0">Tenn. student indicted for hacking Palin's e-mail</source>
    </item>
    <item>
      <title><![CDATA[Symantec to buy e-mail security vendor MessageLabs]]></title>
      <link>http://securityratty.com/article/8a32a03c0d25a48d5ef8c371e26acc85</link>
      <guid>http://securityratty.com/article/8a32a03c0d25a48d5ef8c371e26acc85</guid>
      <description><![CDATA[Symantec said today it will pay $695 million for MessageLabs, a security vendor that filters out spam and malicious Web traffic. The deal is expected to close by the end of...]]></description>
      <content:encoded><![CDATA[Symantec said today it will pay $695 million for MessageLabs, a security vendor that filters out spam and malicious Web traffic. The deal is expected to close by the end of December.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:80aa91f93d60f53958df408312ffd766:CUMbnFlwzTi4g0y8VnNrjJye%2FUvYc24zfhS9s654YVEnUd5X9oumpZlRX%2Bb7CRZsS95XRpHPmNJs'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:121a234fa35dcd3d6b4cca1c45204d08:o7Qdg18Ar%2Bx43cFM6KHbrswq1DR4jr4b6XqikDS5%2F%2BrRTJUos%2FSWZMFUVrBbux65SCd43ZGiTZvTQQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:167962321d7d8b3b4bc2c790eb67f867:cRFQ%2FXCr26U%2FafqwMR5TIpjQ0vgDaMezC1oVBRFVWjWfIWTMbHySY%2FFuUUK5inuZ4mEEarJZcctUrQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:4775607837c2530b9cbf1bc376381013:KOAQDH5RPYhyNi1FB2A9TQd5kGKO5jWgFTEgv%2BRmMLIKknEUhXwozemqZA8cAuVvhural%2BLJsYTUzQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=10ec6cb7f9e8a75ba4cf5a0d56d59d7e" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=10ec6cb7f9e8a75ba4cf5a0d56d59d7e" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security vendor">security vendor</category>
      <category domain="http://securityratty.com/tag/malicious web traffic">malicious web traffic</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/messagelabs">messagelabs</category>
      <category domain="http://securityratty.com/tag/filters">filters</category>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/close">close</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=10ec6cb7f9e8a75ba4cf5a0d56d59d7e">Symantec to buy e-mail security vendor MessageLabs</source>
    </item>
    <item>
      <title><![CDATA[US man indicted for hacking Palin's e-mail account]]></title>
      <link>http://securityratty.com/article/cf8d43137452a74790c06b8a54535a8e</link>
      <guid>http://securityratty.com/article/cf8d43137452a74790c06b8a54535a8e</guid>
      <description><![CDATA[A 20-year-old Tennessee man has been indicted for hacking into an e-mail account of U.S. vice presidential candidate Sarah Palin, according to court...]]></description>
      <content:encoded><![CDATA[A 20-year-old Tennessee man has been indicted for hacking into an e-mail account of U.S. vice presidential candidate Sarah Palin, according to court records.]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/vice presidential">vice presidential</category>
      <category domain="http://securityratty.com/tag/court records">court records</category>
      <category domain="http://securityratty.com/tag/20-year-old tennessee">20-year-old tennessee</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <source url="http://www.networkworld.com/news/2008/100808-us-man-indicted-for-hacking.html?fsrc=rss-security">US man indicted for hacking Palin's e-mail account</source>
    </item>
    <item>
      <title><![CDATA[Symantec to buy e-mail security vendor MessageLabs]]></title>
      <link>http://securityratty.com/article/f19ea96b2343ebccf9459623b4d0df52</link>
      <guid>http://securityratty.com/article/f19ea96b2343ebccf9459623b4d0df52</guid>
      <description><![CDATA[Symantec will pay US$695 million for MessageLabs, a security vendor that offers a hosted spam and Web traffic filtering...]]></description>
      <content:encoded><![CDATA[Symantec will pay US$695 million for MessageLabs, a security vendor that offers a hosted spam and Web traffic filtering service.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=13681?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=13681?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security vendor">security vendor</category>
      <category domain="http://securityratty.com/tag/web traffic">web traffic</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/us695 million">us695 million</category>
      <category domain="http://securityratty.com/tag/messagelabs">messagelabs</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/offers">offers</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <source url="http://www.networkworld.com/news/2008/100808-symantec-to-buy-e-mail-security.html?fsrc=rss-security">Symantec to buy e-mail security vendor MessageLabs</source>
    </item>
    <item>
      <title><![CDATA[Do-Not-Call Lists]]></title>
      <link>http://securityratty.com/article/1d97f48fe3acc2f6696968268a3884a0</link>
      <guid>http://securityratty.com/article/1d97f48fe3acc2f6696968268a3884a0</guid>
      <description><![CDATA[Turns out you can add anyone's number -- or remove anyone's number -- to/from the Canadian do-not-call list. You can also add (but not remove) numbers to the U.S. do-not-call list , though only up to...]]></description>
      <content:encoded><![CDATA[<p>Turns out you can <a href="https://www.lnnte-dncl.gc.ca/">add anyone's number</a> -- or remove anyone's number -- to/from the Canadian do-not-call list. You can also add (but not remove) numbers to the <a href="https://www.donotcall.gov/register/reg.aspx">U.S. do-not-call list</a>, though only up to three at a time, and you have to provide a valid e-mail address to confirm the addition.</p>

<p>Here's my idea.  If you're a company, add every one of your customers to the list.  That way, none of your competitors will be able to cold call them.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=czAmM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=czAmM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=loLhM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=loLhM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 11:51:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/canadian do-not-call list">canadian do-not-call list</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/do-not-call list">do-not-call list</category>
      <category domain="http://securityratty.com/tag/valid e-mail address">valid e-mail address</category>
      <category domain="http://securityratty.com/tag/remove">remove</category>
      <category domain="http://securityratty.com/tag/cold call">cold call</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/tofrom">tofrom</category>
      <category domain="http://securityratty.com/tag/competitors">competitors</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_canadian_do.html">Do-Not-Call Lists</source>
    </item>
    <item>
      <title><![CDATA[Innovators, Imitators and Idiots]]></title>
      <link>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</link>
      <guid>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</guid>
      <description><![CDATA[Charlie Rose interviews Warren Buffett


Charlie Rose
And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage. We just lost sight...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;">Charlie Rose <a href="http://www.cnbc.com/id/26982338/page/2/">interviews</a> Warren Buffett:</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage.&#0160; We just lost sight of risk and leverage of what was appropriate?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.&#0160; Again, because it pays off for a while.&#0160; You know, you can lose leverage, and it&#39;s the only way a smart guy can go broke.&#0160; If you owe money, you can&#39;t pay them out.&#0160; You just pay for everything, you do smart things, you eventually get very rich.&#0160; If you do smart things and use leverage and do one wrong thing along the way, it could wipe you out, because anything times zero is zero.&#0160; But it&#39;s reinforcing when the people around you are doing it successfully, you&#39;re doing it successfully, and it&#39;s a lot like Cinderella at the ball.&#0160; I mean you know at midnight everything is going to turn to pumpkins and mice; right?&#0160; But if the evening goes along, I mean, you know, the guys look better all the time, the music sounds better, it&#39;s more and more fun, you think why the hell should I leave at quarter of 12.&#0160; I&#39;ll leave at two minutes to 12.&#0160; But the trouble is, there are no clocks on the wall.&#0160; And everybody thinks they&#39;re going to leave at two minutes to 12.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating <a href="http://1raindrop.typepad.com/1_raindrop/2007/11/dhandho-infosec.html">risk and uncertainty</a>. As our current financial situation shows, its a hard thing to pull off</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And should wise people have known better?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">People should always know better.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">I mean people -- people don&#39;t get -- they don&#39;t get smarter about things that get as basic as greed and you can&#39;t stand to see your neighbor getting rich.&#0160; You know you&#39;re smarter than he is, and he&#39;s doing these things, you know, and he&#39;s getting rich, and your spouse is getting unhappy with you because you aren&#39;t doing -- pretty soon you start doing it.&#0160; And so you get what I call the natural progression, the three Is.&#0160; The innovators, the imitators, and the idiots.&#0160; And that&#39;s what happens.&#0160; Everybody just kind of goes along.&#0160; And you look kind of silly if you disagree.&#0160; I mean, you know, you could have these crazy Internet valuations in the late 1990s, but they prove themselves out in the market.&#0160; The next day they were selling for more than they were the day before, and people said, you know, you&#39;re crazy if you don&#39;t get in on this.&#0160; So it&#39;s very human.&#0160; Now, with housing it&#39;s something even more dramatic than that, because most people aspire to own their own home.&#0160; And if you really think that houses prices are going to go up next year and the year after, you feel if I don&#39;t buy it this year, I&#39;m going to have to buy it next year.&#0160; That&#39;s not true of an Internet stock.&#0160; But it&#39;s true of a home.&#0160; And when somebody makes it very easy for you to do it by saying you don&#39;t really have to put up my money, you can lie about your income a little, or we&#39;ll give you 100 percent mortgage, you&#39;re going to do it, because everybody that&#39;s done it has been proven right.&#0160; You have what they call social tools, and, you know, you&#39;re going to feel like an idiot if you didn&#39;t do it, because the house cost more.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system.</span></div><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Oh, I think confidence will come back.&#0160; I will tell you this.&#0160; This country is going -- be living better ten years from now than it is now.&#0160; It will be living better in 20 years from now than ten years from now.&#0160; The ingredients that made this country, you know, the miracle of the world -- I mean we had a seven for one improvement in the average American standard of living in the 20th century.&#0160; Now, we had the great depression, we had two world wars, we had the flu epidemic.&#0160; You know, we had oil shock.&#0160; You know, we had all these terrible things happen.&#0160; But something about the American system unleashed more and of a potential to human beings over that hundred years so that we had a seven for one improvement in -- there&#39;s never been any -- I mean, you have centuries where if you&#39;ve got a 1 percent improvement, then it&#39;s something.&#0160; So we&#39;ve got a great system.&#0160; And we&#39;ve got more productive capacity now than we ever have.&#0160; The American worker is more productive than he&#39;s ever been.&#0160; We&#39;ve got more people to do it.&#0160; We&#39;ve got all the ingredients for a sensational future.&#0160; It&#39;s just that right now the athlete&#39;s on the floor.&#0160; But we -- this is a super athlete.</span></p></blockquote><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Again, we want to look at risk events in a broader, long term context. In Buffett&#39;s words its - &quot;be fearful when others are greedy and greedy when others are fearful.&quot; As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* Buffett&#39;s partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive.</span></div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/oeprational risk">oeprational risk</category>
      <category domain="http://securityratty.com/tag/risk events">risk events</category>
      <category domain="http://securityratty.com/tag/risk-reward balance">risk-reward balance</category>
      <category domain="http://securityratty.com/tag/wise people">wise people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/buffett raises">buffett raises</category>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/blind risk acceptance">blind risk acceptance</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/innovators-imitators-and-idiots.html">Innovators, Imitators and Idiots</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Eight]]></title>
      <link>http://securityratty.com/article/8679b7cba84c40cf05ac706ffff136e1</link>
      <guid>http://securityratty.com/article/8679b7cba84c40cf05ac706ffff136e1</guid>
      <description><![CDATA[In the spirit of &quot; taking a bite out of cybercrime &quot;, here are the latest fake security software domains, typosquatted and already acquiring traffic through a dozen of malware campaigns redirecting to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrE3tf04BI/AAAAAAAACQQ/kcG-puPQ2zs/s1600-h/fake_security_software_october.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrE3tf04BI/AAAAAAAACQQ/uqK0Of48ME4/s200-R/fake_security_software_october.PNG" /></a>In the spirit of "<a href="http://bp3.blogger.com/_wICHhTiQmrA/R3WKqj8-MnI/AAAAAAAABSw/9FrQmDwhpb4/s1600-h/mcgruff_cybercrime.jpg">taking a bite out of cybercrime</a>", here are the latest fake security software domains, typosquatted and already acquiring traffic through a dozen of malware campaigns redirecting to most of them :<br />
<br />
<b>antivirus-scanner-online.com</b> (67.205.75.14)<br />
<br />
<b>archivepacker.com</b> (78.157.142.111)<br />
<b>winpacker.com<br />
xh-codec.net</b><br />
<br />
<b>securedownloadcenter.com</b> (89.18.189.44)<br />
<b>winupdates-server.com<br />
browserssecuritypage.com<br />
megatradetds0.com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: left;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrFf0onJVI/AAAAAAAACQY/L3D_vlP23hU/s1600-h/fake_security_software_october1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrFf0onJVI/AAAAAAAACQY/omtYi_kxTos/s200-R/fake_security_software_october1.PNG" /></a></div><b>quickscanpc.com</b> (78.159.118.144)<br />
<b>clickchecker6.com<br />
</b><br />
<b>gensoftdownload.com</b> (91.203.93.25) <br />
<br />
<b>online-av-scan2008.com</b> (66.232.105.232)<br />
<b>anothersoftportal09.com</b><br />
<b>bigfreesoftarchive.com</b><br />
<b>celebs-on-video-08.com</b><br />
<b>celebs-on-video-2008.com</b><br />
<b>cleansoftportal2009.com</b><br />
<b>hot-p0rntube.com</b><br />
<b>hot-porn-tube-2008.com</b><br />
<b>hot-porn-tube2008.com</b><br />
<b>hot-porn-tube2009.com</b><br />
<b>justdomain08.com</b><br />
<b>new-porntube-2008.com</b><br />
<b>online-av-scan2008.com</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrGSntRZ4I/AAAAAAAACQg/iIu0w9kigNc/s1600-h/fake_security_software_october2.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrGSntRZ4I/AAAAAAAACQg/AIs6ZzzeXmI/s200-R/fake_security_software_october2.PNG" /></a><b>s0ftvvarep0rtal.com<br />
s0ftvvareportal.com<br />
s0ftvvareportal08.com<br />
s0ftwarep0rtal08.com<br />
softportalforfun.com<br />
softportalforfun08.com<br />
softportalforfun2008.com<br />
softvvareportal.com<br />
softvvareportal08.com<br />
softvvareportal2008.com<br />
trustedsoftportal06.com<br />
trustedsoftportal2008.com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrG2J5DAiI/AAAAAAAACQo/PHQM9BSuc6A/s1600-h/fake_security_software_october3.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrG2J5DAiI/AAAAAAAACQo/emqLynBbpqo/s200-R/fake_security_software_october3.PNG" /></a><b>antivirus-online-08.com</b> (89.187.48.155; 218.106.90.227)<br />
<b>anti-virus-xp.com<br />
anti-virus-xp.net<br />
anti-virusxp2008.net<br />
antimalware09.com<br />
antivirxp.net<br />
av-xp08.net<br />
av-xp2008.com<br />
av-xp2008.net<br />
avx08.net<br />
axp2008.com<br />
e-antiviruspro.com<br />
eantivirus-payment.com<br />
ekerberos.com<br />
online-security-systems.com<br />
xpprotector.com<br />
youpornzztube.com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrHASFNdfI/AAAAAAAACQw/qIj8zB5yVAY/s1600-h/fake_software_october.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrHASFNdfI/AAAAAAAACQw/ARL4Yobkx74/s200-R/fake_software_october.png" /></a><b>sp-preventer.com</b> (92.241.163.32)<br />
<b>spypreventers.com</b><br />
<br />
<b>u-a-v-2008.com</b> (92.241.163.31)<br />
<b>uav2008.com</b><br />
<br />
<b>power-avcc.com</b> (92.62.101.57)<br />
<b>power-avc.com<br />
pvrantivirus.com</b><br />
<br />
<b>m-s-a-v-c.com</b> (92.62.101.55)<br />
<b>ms-avcc.com<br />
ms-avc.com</b><br />
<br />
<b>wav2008.com</b> (92.241.163.30)<br />
<b>wiav2009.com</b><br />
<b>win-av.com<br />
windows-av.com<br />
windowsav.com&nbsp;</b><br />
<br />
You know the drill.<b>&nbsp;</b><br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <b></b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1QWvM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1QWvM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=r6QfM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=r6QfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q76lm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q76lm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JZP6m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JZP6m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YNGWM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YNGWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MxVcM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MxVcM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2Vfm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2Vfm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413758015" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 03:21:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://securityratty.com/tag/av-xp2008">av-xp2008</category>
      <category domain="http://securityratty.com/tag/anti-virus-xp">anti-virus-xp</category>
      <category domain="http://securityratty.com/tag/antimalware09">antimalware09</category>
      <category domain="http://securityratty.com/tag/uav2008">uav2008</category>
      <category domain="http://securityratty.com/tag/axp2008">axp2008</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413758015/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</source>
    </item>
    <item>
      <title><![CDATA[UK Government gives 1 billion to log every E-mail and SMS]]></title>
      <link>http://securityratty.com/article/75e79da518d182db5bcf2c882ca31814</link>
      <guid>http://securityratty.com/article/75e79da518d182db5bcf2c882ca31814</guid>
      <description><![CDATA[Known as the Interception Modernisation Programme, the scheme would enable GCHQ, MI5 and MI6 personnel, and also police, to access complete information on every text, email and visit to a website made...]]></description>
      <content:encoded><![CDATA[Known as the Interception Modernisation Programme, the scheme would enable GCHQ, MI5 and MI6 personnel, and also police, to access complete information on every text, email and visit to a website made in this country...]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 19:00:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/access complete information">access complete information</category>
      <category domain="http://securityratty.com/tag/interception modernisation programme">interception modernisation programme</category>
      <category domain="http://securityratty.com/tag/mi6 personnel">mi6 personnel</category>
      <category domain="http://securityratty.com/tag/enable gchq">enable gchq</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/visit">visit</category>
      <category domain="http://securityratty.com/tag/mi5">mi5</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <source url="http://digg.com/security/UK_Government_gives_p1_billion_to_log_every_E_mail_and_SMS">UK Government gives 1 billion to log every E-mail and SMS</source>
    </item>
  </channel>
</rss>
