<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ease]]></title>
    <link>http://securityratty.com/tag/ease</link>
    <description></description>
    <pubDate>Wed, 23 Jul 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Do you have poorly trained security guards working for you? If you do, al-Qa'ida may be watching]]></title>
      <link>http://securityratty.com/article/d3bb73a510242a5cb3d3116bdd9cd56c</link>
      <guid>http://securityratty.com/article/d3bb73a510242a5cb3d3116bdd9cd56c</guid>
      <description><![CDATA[It seems strange that the Department of Homeland Security would be mentioning a recording by deceased al-Qa'ida operative Yousef Al-Ayeeri made before his death in 2003

Eventhough DHS said there was...]]></description>
      <content:encoded><![CDATA[It seems strange that the Department of Homeland Security would be mentioning a <a href="http://deepbackground.msnbc.msn.com/archive/2008/10/06/1501940.aspx">recording by deceased al-Qa'ida operative Yousef Al-Ayeeri </a>made before his death in 2003.  <br /><span id="fullpost"><br />Eventhough DHS said there was no credible or specific information, they still deemed it necessary to release the note because it is "important for local authorities, building owners and operators to be aware of potential attack tactics". <br /></span><br />Apparently, Al-Ayeeri made the recording to encourage other al-Qa'ida operatives to take over a publicly accessible building(s) in the U.S. and destroy it by using a series of strategically placed explosives.<br /><br />What makes the plan especially interesting to a security consultant is the way Al-Ayeeri describes the ease with which operatives would be able to take over public buildings.  His recording advises that it will be quite easy due to "poorly trained and lightly armed or unarmed security guards".<br /><br />What does this tell us?  It tells us that terrorists are carrying out surveillance right under our noses and taking notes when they observe a breach of security or "poorly trained security".<br /><br />Hopefully none of you reading this have "poorly trained security" working for you.  If you did, how would you know?  Perhaps it is time to have a security review and or/survey of your premises conducted.  <br /><br />They say "dead men can't talk", but it nearly seems like this one is sending out a warning.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 19 Oct 2008 15:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security consultant">security consultant</category>
      <category domain="http://securityratty.com/tag/security guards">security guards</category>
      <category domain="http://securityratty.com/tag/security review">security review</category>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/poorly">poorly</category>
      <category domain="http://securityratty.com/tag/al-qa">al-qa</category>
      <category domain="http://securityratty.com/tag/al-ayeeri">al-ayeeri</category>
      <category domain="http://securityratty.com/tag/potential attack tactics">potential attack tactics</category>
      <source url="http://www.thebulletproofblog.com/2008/10/do-you-have-poorly-trained-security.html">Do you have poorly trained security guards working for you? If you do, al-Qa'ida may be watching</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: CSIRO Wins Patent Appeal; Zune-Fi in SF; Kodak ESP 9]]></title>
      <link>http://securityratty.com/article/95aa70e977b254cabeb9c3b2679b4b8d</link>
      <guid>http://securityratty.com/article/95aa70e977b254cabeb9c3b2679b4b8d</guid>
      <description><![CDATA[Australian tech office wins appeal: Buffalo sinks further into the hole as it loses its appeal against a judgement over its use of what the Australian CSIRO technical agency asserts is its patented...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.zdnet.com.au/news/hardware/soa/CSIRO-victorious-in-Wi-Fi-appeal/0,130061702,339292134,00.htm?omnRef=1337"><strong>Australian tech office wins appeal:</strong></a> Buffalo sinks further into the hole as it loses its appeal against a judgement over its use of what the Australian CSIRO technical agency asserts is its patented technology used in all 802.11 implementations. The case, in the patent-holder-friendly US Eastern District Court of Texas--a venue that may be dethroned as a <em>forum coveniens</em> for patentholders' suits in new legislation--prevents Buffalo from importing or selling gear in the US with Wi-Fi technology embedded. In Japan, the patent office threw out CSIRO's patent. While Cisco paid CSIRO as the result of an acquisition of an Australian company a few years ago, most US-based technology giants are involved in resisting the patent's continued validation and enforcement. I've read the patent and some of the suits, and as a non-patent expert, it's clear CSIRO original invention didn't cover what's at stake. However, CSIRO was allowed in a subsequent filing to extend its patent to cover already-in-use technology in a way that seems odd to me, but happens in patents all the time. Many millions of dollars and many more years may be expended before a resolution happens. CSIRO apparently isn't asking for insane fees, although anything paid to them would be passed along to consumers. If companies settled, this might result in an increase of 1 to 5 percent on retail prices. It may ultimately effect WiMax, too, though no suits in that area have been filed.</p>

<p><a href="http://news.cnet.com/8301-10805_3-10046542-75.html"><strong>Finding Zune-Fi:</strong></a> Ina Fried of News.com wanders the polite streets of San Francisco in search of Zune connections over Wi-Fi. She finds a few, and has a good experience. One cafe owner sees the ease with which she can stream music and calls it cool. She can't connect at the long-running Google-sponsored free Wi-Fi at Union Square, however, which means the Wi-Fi likely has an accept button that must be pressed. Surely Microsoft could insert a little technology that would allow a browser-free acceptance of terms? Probably involves Yet Another Protocol: the Wi-Fi Terms Browser-Free Presentation Protocol (WTBFPP).</p>

<p><img src="http://wifinetnews.com//images/2008/kodakesp9.jpg" alt="kodakesp9.jpg" border="0" width="150" height="120" align="right" /><a href="http://www.kodak.com/eknec/PageQuerier.jhtml?pq-path=13572&pq-locale=en_US"><strong>Kodak adds interesting Wi-Fi enabled all-in-one:</strong></a> The new Kodak ESP 9 is a multi-function printer (fax, scan, print, copy) that connects to a network via Wi-Fi or Ethernet. The $300 device spits out 30 pages per minutes in color, 32 ppm in black only. Kodak claims that the model line to which the ESP belongs uses ink in a vastly more efficient manner than the "average of comparable consumer inkjet printers." </p>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 05:53:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csiro">csiro</category>
      <category domain="http://securityratty.com/tag/patent">patent</category>
      <category domain="http://securityratty.com/tag/cover">cover</category>
      <category domain="http://securityratty.com/tag/cover already-in-use technology">cover already-in-use technology</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/kodak">kodak</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wi-fi technology">wi-fi technology</category>
      <source url="http://wifinetnews.com/archives/008452.html">Wee-Fi: CSIRO Wins Patent Appeal; Zune-Fi in SF; Kodak ESP 9</source>
    </item>
    <item>
      <title><![CDATA[Network skill level gap is growing, but growth opportunities abound!]]></title>
      <link>http://securityratty.com/article/a4929ca88458feb902376bc7bd38e824</link>
      <guid>http://securityratty.com/article/a4929ca88458feb902376bc7bd38e824</guid>
      <description><![CDATA[A recent IDC report sponsored by the Cisco Learning Institute reveals a huge networking skills gap is emerging in North America, which spells trouble for enterprises. Listen to this: 600,000 IT...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/exam.jpg" border="0" alt="Test Quiz" width="240" height="160" align="left" /> A recent IDC report sponsored by the Cisco Learning Institute reveals <a href="http://www.networkworld.com/newsletters/itlead/2008/080408itlead1.html" target="_blank">a huge networking skills gap</a> is emerging in North America, which spells trouble for enterprises. Listen to this: “600,000 IT workers were needed to install, configure, manage and secure networks in North America in 2007, 14% of the total IT workforce.” However, IDC reports that another 180,000 engineers with wireless as well as traditional network engineering experience will need to be added by 2011 to keep pace with advances in technology that is transforming the role of the network.</p>
<p>The convergence of voice and video traffic are quickly transforming the growing complexity of networks at a torrid pace. IDC estimates that the skills gap in VOIP should grow to 19% by 2011.</p>
<p>This changing profile in the role of the network plays a key role in the skills shortage. Network enabled collaboration tools such as social networking apps and the Webex conferencing/collaboration solutions we use in our business each and every day are demanding a new set of IT skills to deliver business value.</p>
<p>My perspective is two-fold on this issue; the first is what I have seen in the resources we have attempted to hire! We give a very straightforward quick written/oral test to all new technical hires. This requires basic networking knowledge and some Unix commands. On average, (after filters from reputable recruiting firms, some with 5-10 years experience) less than 10% pass muster for the first filter we use in our hiring process. This is a troubling fact, which has cost us considerable time and effort to secure the right resources with competent skills. So I can say from our market assessment in a very strong technological job skills market, core Unix and networking foundation skills are slipping.</p>
<p>The second is that we as an IT Operations Management (ITOM) industry need to keep pushing hard to build better proactive and intuitive solutions to aggregate instrumentation from all Data Center tools, including more work around VOIP, video streaming, and collaboration so that we can ease this transition. If ITOM solutions become more proactive across the typical Cisco infrastructure that is commonly installed in the Data Center, we can free up some additional time for advanced “emerging technologies” training where existing IT workers can enhance their core skills and re-invigorate their careers. We have to do a much better job of getting our existing IT professionals trained on emerging technologies!</p>
<p>While there’s less that ScienceLogic can do around <a href="http://www.cisco.com/web/learning/le3/learning_career_certifications_and_learning_paths_home.html" target="_blank">training</a>, we certainly strive to do our part to enhance a day in the life of the networking engineers who use our solutions to simplify monitoring of increasingly complex networking, <a href="http://www.networkworld.com/news/2008/080608-p-g.html" target="_blank">Wireless, VOIP, and collaboration needs</a>.</p>
]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 17:06:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/foundation skills">foundation skills</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/skills gap">skills gap</category>
      <category domain="http://securityratty.com/tag/skills shortage">skills shortage</category>
      <category domain="http://securityratty.com/tag/intuitive solutions">intuitive solutions</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/traditional network">traditional network</category>
      <category domain="http://securityratty.com/tag/recent idc report">recent idc report</category>
      <source url="http://blog.sciencelogic.com/network-skill-level-gap-is-growing-but-growth-opportunities-abound/08/2008">Network skill level gap is growing, but growth opportunities abound!</source>
    </item>
    <item>
      <title><![CDATA[Changes to PCI standard not expected to up ante on protecting payment card data]]></title>
      <link>http://securityratty.com/article/bf27c281117cda1a2c49240f942ee290</link>
      <guid>http://securityratty.com/article/bf27c281117cda1a2c49240f942ee290</guid>
      <description><![CDATA[An update of the Payment Card Industry Data Security Standard, or PCI, may ease some of the compliance challenges facing businesses that handle cardholder...]]></description>
      <content:encoded><![CDATA[An update of the Payment Card Industry Data Security Standard, or PCI, may ease some of the compliance challenges facing businesses that handle cardholder data.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=htckdq"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=htckdq" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/370408352" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/handle cardholder data">handle cardholder data</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/compliance challenges">compliance challenges</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/ease">ease</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/370408352/article.do">Changes to PCI standard not expected to up ante on protecting payment card data</source>
    </item>
    <item>
      <title><![CDATA[The web browser is sick but wheres the cure?]]></title>
      <link>http://securityratty.com/article/c1a26694b7d3db2c185a5f976e06cc90</link>
      <guid>http://securityratty.com/article/c1a26694b7d3db2c185a5f976e06cc90</guid>
      <description><![CDATA[Blogger: Ramon Krikken
The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Ramon Krikken</p>

<p>The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it does by itself, and other parts are taken care of by handlers and plug-ins. In doing so, it displays hypertext, images, videos, and even runs active content like Flash, JavaScript, and ActiveX. </p>

<p>But however much we love the browser, we’ve also come to hate the myriad of vulnerabilities that affect it. Everything from cross-site scripting to remote code execution via maliciously formed animated cursor files and Flash content can make browsing a hazardous activity. The browser is sick, and that’s not desirable for a platform we use for important business and personal transactions.</p>

<p>Worsening the browser’s diagnosis is the <a href="http://taossa.com.nyud.net:8080/archive/bh08sotirovdowdslides.pdf">recent paper</a> from Mark Dowd and Alexander Sotirov, sub-titled “Setting back browser security by 10 years,” which discusses how to bypass Microsoft Vista’s memory protection capabilities with some added effort for the exploit designers. It’s not that all of the techniques are necessarily new, but the browser appears to be particularly vulnerable to easy exploitation. </p>

<p>Surprising? Not exactly, when we take into account that the browser is suffering from the same disease as the general purpose operating system: bloat and compatibility. We expect the browser to do ever more, but everything we used it for before still needs to work as if it were yesterday. It feels a bit like people insisting on using a cardboard box as a safe, and wondering why their money keeps getting stolen.</p>

<p>It’s not like we haven’t been working on the browser’s cure, though. There have been some improvements in the browsers themselves, the operating systems have also implemented compensating controls, but most of all, there has been an enormous push for securing the web applications that deliver the data in the first place. Unfortunately, the latter two won’t help secure the browser in the long run.</p>

<p>The first issue is that not all content will come from ‘nice’ servers, the second that the server can only make an educated guess on how a browser will parse and render a given set of data, and the third that operating system controls have their own limitations, whether by design or implementation (for example needing to re-compile existing code to enable certain protections.) The browser, in the end, has to be mostly responsible for keeping itself safe; the operating system must assist it in doing so.</p>

<p>So we’re in a pickle. The browser is sick (and the operating system is too), but it’s hard to cure it without a redesign that will undoubtedly impact compatibility, the ever-so-desired multi-functionality, or its ease of use. We can layer defenses by using web filtering in the enterprise environment, but in the end – for the consumer market in particular – we need to fix the browser itself. I can think of a few things I think might help: </p>

<ul><li>Some kind of <a href="http://people.mozilla.com/~bsterne/site-security-policy/">site security policy</a>&nbsp; to restrict where the browser loads auxiliary content from, and which data it can ‘trust’, when loading a web page (I’d prefer mandatory enforcement, and adding an HTML tag to be able to indicate blocks of untrustworthy data.)</li>

<li>Restricted compartments for plug-ins to run in, ensuring that their bugs cannot easily affect the whole browser.</li>

<li>Better software development practices for the plug-ins and content parsers themselves, so that they’re less vulnerable, and compiled with the latest protection measures to begin with.</li></ul>

<p>All of this means more work, and some of it means a lot of unhappy reactions when things stop working. Even then we will of course still have to deal with additional vulnerabilities, such as those that may be present in hardware, but we will at least have taken prudent steps to ‘find a cure.’</p>

</div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/364862623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 07:11:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/web browser">web browser</category>
      <category domain="http://securityratty.com/tag/browser appears">browser appears</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/cure">cure</category>
      <category domain="http://securityratty.com/tag/browser security">browser security</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/runs active content">runs active content</category>
      <category domain="http://securityratty.com/tag/browsers cure">browsers cure</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/364862623/the-web-browser.html">The web browser is sick but wheres the cure?</source>
    </item>
    <item>
      <title><![CDATA[The web browser is sick ??? but where???s the cure?]]></title>
      <link>http://securityratty.com/article/ed0b490e06092c5b7a4f3957bd361fa2</link>
      <guid>http://securityratty.com/article/ed0b490e06092c5b7a4f3957bd361fa2</guid>
      <description><![CDATA[Blogger: Ramon Krikken
The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Ramon Krikken</p>

<p>The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it does by itself, and other parts are taken care of by handlers and plug-ins. In doing so, it displays hypertext, images, videos, and even runs active content like Flash, JavaScript, and ActiveX. </p>

<p>But however much we love the browser, we???ve also come to hate the myriad of vulnerabilities that affect it. Everything from cross-site scripting to remote code execution via maliciously formed animated cursor files and Flash content can make browsing a hazardous activity. The browser is sick, and that???s not desirable for a platform we use for important business and personal transactions.</p>

<p>Worsening the browser???s diagnosis is the <a href="http://taossa.com.nyud.net:8080/archive/bh08sotirovdowdslides.pdf">recent paper</a> from Mark Dowd and Alexander Sotirov, sub-titled ???Setting back browser security by 10 years,??? which discusses how to bypass Microsoft Vista???s memory protection capabilities with some added effort for the exploit designers. It???s not that all of the techniques are necessarily new, but the browser appears to be particularly vulnerable to easy exploitation. </p>

<p>Surprising? Not exactly, when we take into account that the browser is suffering from the same disease as the general purpose operating system: bloat and compatibility. We expect the browser to do ever more, but everything we used it for before still needs to work as if it were yesterday. It feels a bit like people insisting on using a cardboard box as a safe, and wondering why their money keeps getting stolen.</p>

<p>It???s not like we haven???t been working on the browser???s cure, though. There have been some improvements in the browsers themselves, the operating systems have also implemented compensating controls, but most of all, there has been an enormous push for securing the web applications that deliver the data in the first place. Unfortunately, the latter two won???t help secure the browser in the long run.</p>

<p>The first issue is that not all content will come from ???nice??? servers, the second that the server can only make an educated guess on how a browser will parse and render a given set of data, and the third that operating system controls have their own limitations, whether by design or implementation (for example needing to re-compile existing code to enable certain protections.) The browser, in the end, has to be mostly responsible for keeping itself safe; the operating system must assist it in doing so.</p>

<p>So we???re in a pickle. The browser is sick (and the operating system is too), but it???s hard to cure it without a redesign that will undoubtedly impact compatibility, the ever-so-desired multi-functionality, or its ease of use. We can layer defenses by using web filtering in the enterprise environment, but in the end ??? for the consumer market in particular ??? we need to fix the browser itself. I can think of a few things I think might help: </p>

<ul><li>Some kind of <a href="http://people.mozilla.com/~bsterne/site-security-policy/">site security policy</a>&nbsp; to restrict where the browser loads auxiliary content from, and which data it can ???trust???, when loading a web page (I???d prefer mandatory enforcement, and adding an HTML tag to be able to indicate blocks of untrustworthy data.)</li>

<li>Restricted compartments for plug-ins to run in, ensuring that their bugs cannot easily affect the whole browser.</li>

<li>Better software development practices for the plug-ins and content parsers themselves, so that they???re less vulnerable, and compiled with the latest protection measures to begin with.</li></ul>

<p>All of this means more work, and some of it means a lot of unhappy reactions when things stop working. Even then we will of course still have to deal with additional vulnerabilities, such as those that may be present in hardware, but we will at least have taken prudent steps to ???find a cure.???</p>

</div>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 07:11:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/web browser">web browser</category>
      <category domain="http://securityratty.com/tag/browser appears">browser appears</category>
      <category domain="http://securityratty.com/tag/browser security">browser security</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/runs active content">runs active content</category>
      <category domain="http://securityratty.com/tag/web page">web page</category>
      <category domain="http://securityratty.com/tag/system controls">system controls</category>
      <source url="http://srmsblog.burtongroup.com/2008/08/the-web-browser.html">The web browser is sick ??? but where???s the cure?</source>
    </item>
    <item>
      <title><![CDATA[Listening to the evidence]]></title>
      <link>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</link>
      <guid>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</guid>
      <description><![CDATA[Last week the House of Commons Culture, Media and Sport Select Committee published a report of their inquiry into Harmful content on the Internet and in video games . They make a number of...]]></description>
      <content:encoded><![CDATA[<p>Last week the <a href="http://www.parliament.uk/parliamentary_committees/culture__media_and_sport.cfm">House of Commons Culture, Media and Sport Select Committee</a> published a report of their inquiry into &#8220;<a href="http://www.publications.parliament.uk/pa/cm200708/cmselect/cmcumeds/353/353.pdf">Harmful content on the Internet and in video games</a>&#8220;. They make a number of recommendations including a self-regulatory body to set rules for Internet companies to force them to protect users; that sites should provide a &#8220;watershed&#8221; so that grown-up material cannot be viewed before 9pm; that YouTube should screen material for forbidden content; that &#8220;<a href="http://www.spiked-online.com/index.php?/site/article/4633/">suicide websites</a>&#8221; should be blocked; that ISPs should be forced to block child sexual abuse image websites whatever the cost, and that blocking of bad content was generally desirable.</p>
<p>You will discern a certain amount of enthusiasm for blocking, and for a &#8220;<a href="http://www.yes-minister.com/polterms.htm#Politicians">something must be done</a>&#8221; approach. However, in coming to their conclusions, they do not, in my view, seem to have listened too hard to the evidence, or sought out expertise elsewhere in the world&#8230;<br />
<span id="more-351"></span><br />
Google/YouTube told them that 10 hours of video was posted every minute, and the amount is increasing. In the oral evidence session an MP helpfully suggested: &#8220;That video content is tagged. You do not need to look at every single minute of video content. Surely you could have people who would look at the video content which is tagged with labels which suggest it could be inappropriate.&#8221; Of course &#8220;<a href="http://lostria.blogspot.com/2008/01/fertility-slaps.html">happy_slapping.wmv</a>&#8221; or &#8220;<a href="http://www.phrases.org.uk/meanings/bunny-boiler.html">fluffy_bunnies.avi</a>&#8221; must always contain exactly what it says on the tin (<a href="http://en.wikipedia.org/wiki/Not%21">not!</a>) but unaccountably Google said it was a &#8220;fair suggestion&#8221;, so perhaps my cynicism is misplaced.</p>
<p>However, back to blocking.</p>
<p>I submitted <a href="http://www.cl.cam.ac.uk/~rnc1/080129-cms.pdf">some evidence of my own</a>, which the committee summarised, reasonably accurately:</p>
<blockquote><p>Dr Richard Clayton, a researcher in the Security Group of the Computer Laboratory at Cambridge University and author of several academic papers on methods for blocking access to Internet content, pointed out that there was no single blocking method which was both inexpensive and discerning enough to block access to only one part of a large website (such as FaceBook). In his view, the fatal flaw of all network-level blocking schemes was the ease with which they could be overcome, either by encrypting content or by the use of proxy services hosted outside the UK.</p></blockquote>
<p>The committee&#8217;s conclusion, having read this was:</p>
<blockquote><p>At a time of rapid technological change, it is difficult to judge whether blocking access to Internet content at network level by Internet service providers is likely to become ineffective in the near future. However, this is not a reason for not doing so while it is still effective for the overwhelming majority of users.</p></blockquote>
<p>which I suppose logically means that the committee thinks that blocking should now be discarded as a policy option &#8212; but somehow I think that isn&#8217;t their intended meaning.</p>
<p>The Committee should perhaps have a look at <a href="http://www.acma.gov.au/webwr/_assets/main/lib310554/isp-level_internet_content_filtering_trial-report.pdf">this Australian report</a>, which found that ISP level content filtering (and in Australia the politicians want to use ISP level filtering to provide a child-friendly Internet) did work (up to a point) at Tier 3 (the smallest) ISPs. The <a href="http://en.wikiquote.org/wiki/Evelyn_Waugh#Scoop_.281938.29">up-to-a-point</a> is that unlike previous tests the systems didn&#8217;t completely wreck the browsing experience by slowing it down. However, the systems blocked only 85-98% of illegal material and similar percentages of material suitable for adults but not for younger children. Interestingly some products were better at different categories.</p>
<p>Getting that many sites wrong is really quite significant, so it&#8217;s difficult to see this as a ringing endorsement for blocking the web. Additionally, the Australian report found that the blocking was useless on &#8220;non-web&#8221; protocols (such as peer-to-peer) and their report specifically didn&#8217;t consider cost, or ease of circumvention &#8212; so it&#8217;s not just UK politicians not wanting to consider evidence on that topic!</p>
<p>Finally, I should note that the Culture Media and Sport Committee has also ignored some rather more recent academic work. The MPs have put into their report that they were horrified to discover that child sexual abuse images took 24 hours to remove in the UK. What (should they ever learn of it) will they make of the recent discovery by <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and myself that shows that if the website is hosted abroad then <a href="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">a month is more to be expected</a>?</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 20:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/isp level content">isp level content</category>
      <category domain="http://securityratty.com/tag/video games">video games</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/bad content">bad content</category>
      <category domain="http://securityratty.com/tag/video content">video content</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/evidence">evidence</category>
      <category domain="http://securityratty.com/tag/child-friendly internet">child-friendly internet</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/08/listening-to-the-evidence/">Listening to the evidence</source>
    </item>
    <item>
      <title><![CDATA[Indictments Against Largest ID Theft Ring Ever]]></title>
      <link>http://securityratty.com/article/159412d8049db4c0dd6a8e114a645515</link>
      <guid>http://securityratty.com/article/159412d8049db4c0dd6a8e114a645515</guid>
      <description><![CDATA[It was really big news yesterday , but I don't think it's that much of a big deal. These crimes are still easy to commit and it's still too hard to catch the criminals. Catching one gang, even a large...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/05/AR2008080501859.html?hpid=moreheadlines">It</a> <a href="http://money.cnn.com/2008/08/05/news/companies/card_fraud/?postversion=2008080604">was</a> <a href="http://technology.timesonline.co.uk/tol/news/world/us_and_americas/article4468114.ece">really</a> <a href="http://www.iht.com/articles/ap/2008/08/06/business/NA-US-Retailer-Fraud-Indictment.php">big</a> <a href="http://www.theregister.co.uk/2008/08/06/id_fraud_hacking_case/">news</a> <a href="http://ap.google.com/article/ALeqM5hlC-7Qgf2_9ytmu5kKBpnEf5XzeQD92D20KG0">yesterday</a>, but I don't think it's that much of a big deal.  These crimes are still easy to commit and it's still too hard to catch the criminals.  Catching one gang, even a large one, isn't going to make us any safer.</p>

<p>If we want to <a href="http://www.schneier.com/blog/archives/2005/04/mitigating_iden.html">mitigate identity theft</a>, we have to make it harder for people to get credit, make transactions, and generally do financial business remotely:</p>

<blockquote>The crime involves two very separate issues. The first is the privacy of personal data. Personal privacy is important for many reasons, one of which is impersonation and fraud. As more information about us is collected, correlated, and sold, it becomes easier for criminals to get their hands on the data they need to commit fraud. This is what's been in the news recently: ChoicePoint, LexisNexis, Bank of America, and so on. But data privacy is more than just fraud. Whether it is the books we take out of the library, the websites we visit, or the contents of our text messages, most of us have personal data on third-party computers that we don't want made public. The posting of Paris Hilton's phone book on the Internet is a celebrity example of this.

<p>The second issue is the ease with which a criminal can use personal data to commit fraud. It doesn't take much personal information to apply for a credit card in someone else's name. It doesn't take much to submit fraudulent bank transactions in someone else's name. It's surprisingly easy to get an identification card in someone else's name. Our current culture, where identity is verified simply and sloppily, makes it easier for a criminal to impersonate his victim.</p>

<p>Proposed fixes tend to concentrate on the first issue -- making personal data harder to steal -- whereas the real problem is the second. If we're ever going to manage the risks and effects of electronic impersonation, we must concentrate on preventing and detecting fraudulent transactions.</blockquote></p>

<p>I am, however, impressed that we managed to pull together the police forces from several countries to prosecute this case.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=DF8G3K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=DF8G3K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aICGEK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aICGEK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 08:45:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal data harder">personal data harder</category>
      <category domain="http://securityratty.com/tag/harder">harder</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/commit fraud">commit fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/commit">commit</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/personal privacy">personal privacy</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/indictments_aga.html">Indictments Against Largest ID Theft Ring Ever</source>
    </item>
    <item>
      <title><![CDATA[Upping The IPS Ante]]></title>
      <link>http://securityratty.com/article/81aa745b480141b489146432f5c59ee0</link>
      <guid>http://securityratty.com/article/81aa745b480141b489146432f5c59ee0</guid>
      <description><![CDATA[My colleague at Forrester, Chris Silva, recently commented upon the recent Air Defense acquisition by Motorola. Looking at the deal through the security lens, I completely agree with Chris that this...]]></description>
      <content:encoded><![CDATA[<p>My colleague at Forrester, Chris Silva, recently commented upon the recent Air Defense acquisition by Motorola.&nbsp; Looking at the deal through the security lens, I completely agree with Chris that this will help ease integration of wireless security into wireless infrastructure.&nbsp; It's good to see one of the major wireless brands step up and take wireless security seriously.&nbsp; Perhaps that other major wireless vendor will get the hint...</p>

<blockquote><p><span style="color: #636363;"><a href="http://blogs.forrester.com/it_infrastructure/2008/07/upping-the-ips.html">Upping The IPS Ante</a></span></p></blockquote>

<blockquote><p><span style="color: #8a8a8a;">	
Motorola <a href="http://www.airdefense.net/newsandpress/07_28_08.php">announced</a> this week its intentions to acquires Wireless IDS/IPS vendor <a href="http://www.airdefense.net/">AirDefense</a>.
The acquisition may provide a bit of deja vu to readers who recall the
acquisition of Network Chemistry's wireless IDS/IPS assets by Aruba
Networks <a href="http://www.arubanetworks.com/company/news/release.php?id=25">in 2007</a>. 

</span></p>

<p><span style="color: #8a8a8a;">Meru Networks, eschewing acquisition for product introduction made <a href="http://www.merunetworks.com/news/press_releases/index.php?articleID=072808">its own announcement</a>
on Monday, announcing the company's RF Barrier, an active RF management
solution that aims to solve the problem of what the vendor is calling
&quot;leaky RF.&quot; The Meru solution actively blocks 802.11 RF from escaping
the physical confines of a WLAN deployment to thwart external &quot;parking
lot&quot; attacks by closing Wi-Fi based attack avenues. </span></p>

<p><span style="color: #8a8a8a;">In fact, 2007 - 2008 has been a time focused on shoring up the security
of the WLAN as the networks become more critical to <a href="http://www.forrester.com/Research/Document/0,7211,42451,00.html">over 50%</a>
of
enterprises Forrester sees investing in the networks today. As the
networks are more pervasive, moving toward covering the entire physical
environment, and more employees are relying on Wi-Fi to access
corporate data and applications, it's high-time to secure the WLAN.</span></p>

<p><span style="color: #8a8a8a;">In the case of Motorola, the Wi-Fi network is especially critical. As the vendor embarks on selling its message of the <a href="http://www.informationweek.com/news/mobility/converence/showArticle.jhtml?articleID=206904190">all-wireless enterprise</a>,
where WLANs will interconnect not only users to the network, but
networke edge devices -- such as WLAN access points -- to the network
along with storage, printers and other peripheral devices, the WLAN is
citical and, therefore, a major focus for security. </span></p>

<p><span style="color: #8a8a8a;">In markets such as retail, standards like the Payment Card
Industry's Data Security Standard dictate wireless security, but
compliance and regulation aside, it is becoming easier to secure the
WLAN, regardless of the industry you are in. Vendors are rapily working
to close security gaps with product enhancements and new product
introductions. Look for a broader suite of solutions to address
security coming from your primary network vendor; while this won't
negate the need to&nbsp; integrate these add-on network elements, the single
source should ease integration to some degree. </span></p>

<p><span style="color: #8a8a8a;">How secure do you feel your organization's WLAN is today? What are
your concerns either about securing the network or its current lack of
security?</span></p></blockquote>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 11:14:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/address security">address security</category>
      <category domain="http://securityratty.com/tag/security lens">security lens</category>
      <category domain="http://securityratty.com/tag/data security standard">data security standard</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/wireless security">wireless security</category>
      <source url="http://blogs.forrester.com/srm/2008/07/upping-the-ips.html">Upping The IPS Ante</source>
    </item>
    <item>
      <title><![CDATA[The End of Neosploit? ]]></title>
      <link>http://securityratty.com/article/22c40c5c106567f6526fcaa06a7deaef</link>
      <guid>http://securityratty.com/article/22c40c5c106567f6526fcaa06a7deaef</guid>
      <description><![CDATA[The first and most important thing when trying to grow a pool of malware-infected PCs is the infection stage. The goal is to infect as many users as possible, as quickly as possible -- and remain...]]></description>
      <content:encoded><![CDATA[The first and most important thing when trying to grow a pool of malware-infected PCs is the infection stage. The goal is to infect as many users as possible, as quickly as possible -- and remain undetected for as long as possible.
<P>
Neosploit is a brand that could be relied upon to solve that problem rather well. Designed to ease the infection stage, Neosploit is an infection kit which exploits numerous system vulnerabilities and infects PCs worldwide with any type of malware. Neosploit checks "candidate" PCs in order to find vulnerabilities, and once these are found, the PC will be infected with the malware of the criminal's choice.
<P><b>
However, <a href="http://www.rsa.com/blog/blog.aspx?author=RSAF">the RSA FraudAction Research Labs</a> recently received information indicating that we may soon see the last of this "Neosploitation".</b>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/neosploit">neosploit</category>
      <category domain="http://securityratty.com/tag/infects pcs worldwide">infects pcs worldwide</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <category domain="http://securityratty.com/tag/infection stage">infection stage</category>
      <category domain="http://securityratty.com/tag/neosploit checks">neosploit checks</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/infection kit">infection kit</category>
      <category domain="http://securityratty.com/tag/remain">remain</category>
      <category domain="http://securityratty.com/tag/solve">solve</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1314">The End of Neosploit? </source>
    </item>
  </channel>
</rss>
