<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: elite]]></title>
    <link>http://securityratty.com/tag/elite</link>
    <description></description>
    <pubDate>Wed, 26 Dec 2007 04:50:42 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[That Password-Protected Site Of Yours - It Ain't Protected]]></title>
      <link>http://securityratty.com/article/7740b6bcd6072c8c71bc1217d6649ef8</link>
      <guid>http://securityratty.com/article/7740b6bcd6072c8c71bc1217d6649ef8</guid>
      <description><![CDATA[It's one of the simplest hacks we've seen in a long time, and the more elite computer users have known about it for a while, but it's still kinda cool and just a little bit unnerving: A hacker has...]]></description>
      <content:encoded><![CDATA[It's one of the simplest hacks we've seen in a long time, and the more elite computer users have known about it for a while, but it's still kinda cool and just a little bit unnerving: A hacker has revealed a way to use Google and other search engines to gain unauthorized access to password-protected content on a dizzying number of websites.]]></content:encoded>
      <pubDate>Sun, 24 Aug 2008 13:21:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/elite computer users">elite computer users</category>
      <category domain="http://securityratty.com/tag/engines">engines</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/gain">gain</category>
      <category domain="http://securityratty.com/tag/cool">cool</category>
      <source url="http://digg.com/security/That_Password_Protected_Site_Of_Yours_It_Ain_t_Protected">That Password-Protected Site Of Yours - It Ain't Protected</source>
    </item>
    <item>
      <title><![CDATA[A Continental nightmare]]></title>
      <link>http://securityratty.com/article/d55712f73fd5b2c5c1b199e3992cca03</link>
      <guid>http://securityratty.com/article/d55712f73fd5b2c5c1b199e3992cca03</guid>
      <description><![CDATA[The state of the airline industry is a travesty. Today United announced that they are joining American in charging a fee for even the first bag of checked luggage. Combined with the ban on liquids...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>The state of the airline industry is a travesty.&nbsp; Today United announced that they are joining American in charging a fee for even the first bag of checked luggage.&nbsp; Combined with the ban on liquids that makes it hard to carry on anything, you are forced to pay up.&nbsp; This is on top of the already jacked up prices and fuel surcharges they are already charging.&nbsp; They also charge if you want to fly stand by now, extra for exit seats, aisles, etc, etc.&nbsp; It is not one airline worse than another, they are all pretty bad.&nbsp; </p> <p>Today's travel nightmare though comes courtesy of Continental Airlines.&nbsp; I rarely fly Continental because in coach I find their seats are to close together and my knees get crushed.&nbsp; But flying home from Denver today, they were the cheapest so I booked the flight.&nbsp; </p> <p>I was scheduled to be on a 4:50 flight out of Denver into Houston.&nbsp; An hour layover, an 8:55 flight from Houston to Ft Lauderdale and I would get me home around midnight.&nbsp; Long day for sure.&nbsp; So I finished up my meetings and stuff early in Boulder and saw that Continental had a 2:30 flight from Denver to Houston and a 7:10 connection to Ft Lauderdale that would get me in around 10:20pm.&nbsp; I left StillSecure HQ around noon and was at Denver airport by about 12:45.&nbsp; I went to the Continental counter and asked to get on the earlier flight.&nbsp; Because I am a platinum medallion member of Delta, as a Sky Team member, I am an elite plus level passenger on Continental. In days gone by that would qualify me for same day ticket changes for free.&nbsp; Not anymore it doesn't!&nbsp; I don't understand what the price of fuel has to do with charging me for same day ticket changes.&nbsp; Anyway, they said I could fly stand by for free until June 17th, when even standby is going to cost an extra fee (again they blamed it on fuel costs).</p> <p>So they put me on standby and told me my luggage would go on the earlier flight.&nbsp; I then went to the 2:30 flights gate and waited.&nbsp; The ticket counter agent told me about 20 minutes before take off that they only had me as a silver medallion and due to my low status I was far down the list and would not make the flight.&nbsp; My luggage would though.&nbsp; OK, so I will hang at the airport and work a few hours.&nbsp; Just before the plane takes off they call my name and tell me to wait at the end of the jetway.&nbsp; They are checking the plane and if there is a seat I can take it.&nbsp; I get the last seat on the plane, a middle seat.&nbsp; </p> <p>I arrive at Houston and proceed to the gate for the 7:10 flight to Ft Lauderdale.&nbsp; I check in with the agent and she tells me the folks in Denver only put me on standby for the Denver Houston flight and I am not on stand by for the Ft Lauderdale flight.&nbsp; She can put me on and I will probably make it, but my luggage will be going on the later flight.&nbsp; Now mind you I can see the plane I just got off of out the window and could have gone to the jetway and told the guys unloading the luggage to grab my bag.&nbsp; Not wanting to wait two hours in Ft Lauderdale late at night for my luggage to arrive and not wanting to drive down the next day to pick it up I say thanks, but no thanks and decide to wait another two hours for the later flight that my luggage will be on.</p> <p>I board my 8:55 flight as scheduled and we take off headed for Ft Lauderdale, due to land at 12:15 or so.&nbsp; The plane is hot as heck and about a half hour into the flight the pilot says that we have a pressurization problem and am turning back to Houston!&nbsp; We turn back and upon arrival near Houston, he tells us we have too much fuel to land and will have to fly around to burn it off.&nbsp; We have no air conditioning, it is hot as can be and they are telling me how much they charge because of the cost of fuel that they are now flying around in circles to burn off!</p> <p>We land in Houston, they find another plane and we finally take off from Houston around 11:45 or so. I am writing this on the plane and am due to land about 2:30am. If I find my luggage came on the earlier flight I am going to kill someone.&nbsp; In the meantime, I have had enough of Continental for a while and they won't see me on their planes very soon.</p> <p>End of story, we landed around 2:45 and my luggage was waiting for me, having arrived on the earlier flight.&nbsp; The Continental employee at the baggage claim will remember Alan Shimel for a while, as I gave him a piece of my mind.</p></div>
]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 00:34:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/denver airport">denver airport</category>
      <category domain="http://securityratty.com/tag/denver">denver</category>
      <category domain="http://securityratty.com/tag/denver houston flight">denver houston flight</category>
      <category domain="http://securityratty.com/tag/flight">flight</category>
      <category domain="http://securityratty.com/tag/lauderdale flight">lauderdale flight</category>
      <category domain="http://securityratty.com/tag/continental">continental</category>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/continental airlines">continental airlines</category>
      <category domain="http://securityratty.com/tag/luggage">luggage</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/a-continental-n.html">A Continental nightmare</source>
    </item>
    <item>
      <title><![CDATA[A Continental nightmare]]></title>
      <link>http://securityratty.com/article/1e535b8d7814aa9ad0c695c5888d81a6</link>
      <guid>http://securityratty.com/article/1e535b8d7814aa9ad0c695c5888d81a6</guid>
      <description><![CDATA[The state of the airline industry is a travesty. Today United announced that they are joining American in charging a fee for even the first bag of checked luggage. Combined with the ban on liquids...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>The state of the airline industry is a travesty.&nbsp; Today United announced that they are joining American in charging a fee for even the first bag of checked luggage.&nbsp; Combined with the ban on liquids that makes it hard to carry on anything, you are forced to pay up.&nbsp; This is on top of the already jacked up prices and fuel surcharges they are already charging.&nbsp; They also charge if you want to fly stand by now, extra for exit seats, aisles, etc, etc.&nbsp; It is not one airline worse than another, they are all pretty bad.&nbsp; </p> <p>Today's travel nightmare though comes courtesy of Continental Airlines.&nbsp; I rarely fly Continental because in coach I find their seats are to close together and my knees get crushed.&nbsp; But flying home from Denver today, they were the cheapest so I booked the flight.&nbsp; </p> <p>I was scheduled to be on a 4:50 flight out of Denver into Houston.&nbsp; An hour layover, an 8:55 flight from Houston to Ft Lauderdale and I would get me home around midnight.&nbsp; Long day for sure.&nbsp; So I finished up my meetings and stuff early in Boulder and saw that Continental had a 2:30 flight from Denver to Houston and a 7:10 connection to Ft Lauderdale that would get me in around 10:20pm.&nbsp; I left StillSecure HQ around noon and was at Denver airport by about 12:45.&nbsp; I went to the Continental counter and asked to get on the earlier flight.&nbsp; Because I am a platinum medallion member of Delta, as a Sky Team member, I am an elite plus level passenger on Continental. In days gone by that would qualify me for same day ticket changes for free.&nbsp; Not anymore it doesn't!&nbsp; I don't understand what the price of fuel has to do with charging me for same day ticket changes.&nbsp; Anyway, they said I could fly stand by for free until June 17th, when even standby is going to cost an extra fee (again they blamed it on fuel costs).</p> <p>So they put me on standby and told me my luggage would go on the earlier flight.&nbsp; I then went to the 2:30 flights gate and waited.&nbsp; The ticket counter agent told me about 20 minutes before take off that they only had me as a silver medallion and due to my low status I was far down the list and would not make the flight.&nbsp; My luggage would though.&nbsp; OK, so I will hang at the airport and work a few hours.&nbsp; Just before the plane takes off they call my name and tell me to wait at the end of the jetway.&nbsp; They are checking the plane and if there is a seat I can take it.&nbsp; I get the last seat on the plane, a middle seat.&nbsp; </p> <p>I arrive at Houston and proceed to the gate for the 7:10 flight to Ft Lauderdale.&nbsp; I check in with the agent and she tells me the folks in Denver only put me on standby for the Denver Houston flight and I am not on stand by for the Ft Lauderdale flight.&nbsp; She can put me on and I will probably make it, but my luggage will be going on the later flight.&nbsp; Now mind you I can see the plane I just got off of out the window and could have gone to the jetway and told the guys unloading the luggage to grab my bag.&nbsp; Not wanting to wait two hours in Ft Lauderdale late at night for my luggage to arrive and not wanting to drive down the next day to pick it up I say thanks, but no thanks and decide to wait another two hours for the later flight that my luggage will be on.</p> <p>I board my 8:55 flight as scheduled and we take off headed for Ft Lauderdale, due to land at 12:15 or so.&nbsp; The plane is hot as heck and about a half hour into the flight the pilot says that we have a pressurization problem and am turning back to Houston!&nbsp; We turn back and upon arrival near Houston, he tells us we have too much fuel to land and will have to fly around to burn it off.&nbsp; We have no air conditioning, it is hot as can be and they are telling me how much they charge because of the cost of fuel that they are now flying around in circles to burn off!</p> <p>We land in Houston, they find another plane and we finally take off from Houston around 11:45 or so. I am writing this on the plane and am due to land about 2:30am. If I find my luggage came on the earlier flight I am going to kill someone.&nbsp; In the meantime, I have had enough of Continental for a while and they won't see me on their planes very soon.</p> <p>End of story, we landed around 2:45 and my luggage was waiting for me, having arrived on the earlier flight.&nbsp; The Continental employee at the baggage claim will remember Alan Shimel for a while, as I gave him a piece of my mind.</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=o5NE6F"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=o5NE6F" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=T6Z75I"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=T6Z75I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=6TmiRI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=6TmiRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1CQVvI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1CQVvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=3SKgkI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=3SKgkI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=xnNSLi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=xnNSLi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=mACLdi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=mACLdi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/311007353" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 23:35:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/denver airport">denver airport</category>
      <category domain="http://securityratty.com/tag/denver">denver</category>
      <category domain="http://securityratty.com/tag/denver houston flight">denver houston flight</category>
      <category domain="http://securityratty.com/tag/flight">flight</category>
      <category domain="http://securityratty.com/tag/lauderdale flight">lauderdale flight</category>
      <category domain="http://securityratty.com/tag/continental">continental</category>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/continental airlines">continental airlines</category>
      <category domain="http://securityratty.com/tag/luggage">luggage</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/311007353/a-continental-n.html">A Continental nightmare</source>
    </item>
    <item>
      <title><![CDATA[Whats with all of the new ads? Forbes, business and finance blog network]]></title>
      <link>http://securityratty.com/article/2fc287046336e652e3cfbd4fe0664c7b</link>
      <guid>http://securityratty.com/article/2fc287046336e652e3cfbd4fe0664c7b</guid>
      <description><![CDATA[For those who read my blog via feed reader and not on the web site itself, you may not have noticed the new ads and member badge from the Forbes Business and Finance Blog Network . I received an...]]></description>
      <content:encoded><![CDATA[<p>For those who read my blog via feed reader and not on the web site itself, you may not have noticed the new ads and member badge from the <a href="http://www.forbes.com/businesswire/feeds/businesswire/2008/03/24/businesswire20080324005547r1.html">Forbes Business and Finance Blog Network</a>.  I received an invitation to join an elite list of 400 blogs handpicked by Forbes.  They will syndicate content and sell advertising for the site.  There are some other cool benefits that go along with the membership. I was very proud to be selected for this, but frankly was worried about too many ads.  If you get a chance, check out the site and have a look.  I know it means I am going commercial, but am hoping it will lead to a broader audience.<br></p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=pKc9Ux"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=pKc9Ux" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=aL8IeH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=aL8IeH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=uOMAwH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=uOMAwH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=X0ydPH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=X0ydPH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=GvScPH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=GvScPH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vT2DLh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vT2DLh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=H5FL3h"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=H5FL3h" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/284406316" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 05 May 2008 20:23:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/finance blog network">finance blog network</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/forbes">forbes</category>
      <category domain="http://securityratty.com/tag/ads">ads</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/forbes business">forbes business</category>
      <category domain="http://securityratty.com/tag/feed reader">feed reader</category>
      <category domain="http://securityratty.com/tag/elite list">elite list</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/284406316/whats-with-all.html">Whats with all of the new ads? Forbes, business and finance blog network</source>
    </item>
    <item>
      <title><![CDATA[On Travel and Airlines]]></title>
      <link>http://securityratty.com/article/abe14d53a0a0043442cf14d0a097853f</link>
      <guid>http://securityratty.com/article/abe14d53a0a0043442cf14d0a097853f</guid>
      <description><![CDATA[Inspired by this , of course
So, I am sitting here in San Jose Airport even though I am supposed to be flying to Hartford, CT to speak at OWASP . Why am I sitting here? Well, 'cause the NWA plane got...]]></description>
      <content:encoded><![CDATA[<p>Inspired by <a href="http://rationalsecurity.typepad.com/blog/2008/04/off-topic-south.html">this</a>, of course.</p> <p>So, I am sitting here in&nbsp; San Jose Airport even though I am supposed to be flying to Hartford, CT to <u><a href="http://chuvakin.blogspot.com/2008/04/anton-on-bad-logs-next-week.html">speak at OWASP</a></u>. Why am I sitting here? Well, 'cause the NWA plane got <em>a flat tire</em> (literally, I actually noticed the flat while "deplaning") and the nearest replacement tire&nbsp; is in San Francisco. A three hour delay -&gt; missed connection -&gt; missing my conference presentation (which sucks hard!)</p> <p>I do travel a lot (especially lately), but I am still amazed when smart people <a href="http://rationalsecurity.typepad.com/blog/2008/04/off-topic-south.html">follow the logic</a> of "weather delay + wet luggage&nbsp; = airline sucks."&nbsp; Admittedly, I had fun travel stories (<u><a href="http://chuvakin.blogspot.com/2007/06/on-travel.html">here</a></u> and <u><a href="http://chuvakin.blogspot.com/search/label/travel">overall here</a></u>), but I never bitch about airlines. I guess I am funny that way. To top it off, I like US Airways (gasp!), which definitely makes me a weirdo among the "high-travel cognocenti" :-)</p> <p>What is the reason for this "phenomenon"? Here it is: I am used to expecting A LOT from an airline and, so far, I have always gotten it. <em>ALWAYS</em>! Specifically, I expect "not dying at the hands of the airline that is transporting me."&nbsp; That means A LOT to me, it really does :-)&nbsp; And, so far, it worked marvelously!</p> <p>So, anything else is an awesome perk! For example, I was flying United&nbsp; (with which I don't have any Elite status) from JFK to SFO and right after my attempt to stand-by for an earlier flight failed and I was about to stick my wireless card in and do some work, the gate agent called my name.&nbsp; I approached the gate thinking they bumped me or took away my coveted exit row seat. On the opposite, the gate agent said "Mr Chuvakin, would you mind if we upgrade you?" -&nbsp; "No, not at all."&nbsp; So I got my comfy United p.s. business class seat and a good breakfast (as well as some sleep)...</p> <p>Some would say that I have "lowered my expectations", but I beg to differ: I do expect a lot. And I get it, which is, some say, a key to [travel] happiness :-)</p> <p>Finally, apologies to my <u><a href="http://duckdown.blogspot.com/">OWASP CT chapter</a></u> audience: sorry, next time!</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:b0678e81-eaf2-4d87-9db0-07085bc6b3ba" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/travel" rel="tag">travel</a>, <a href="http://technorati.com/tags/airlines" rel="tag">airlines</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=e7X9bG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=e7X9bG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=7JKEDG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=7JKEDG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/281028880" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 09:23:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/travel">travel</category>
      <category domain="http://securityratty.com/tag/high-travel cognocenti">high-travel cognocenti</category>
      <category domain="http://securityratty.com/tag/fun travel stories">fun travel stories</category>
      <category domain="http://securityratty.com/tag/travel happiness">travel happiness</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/airline sucks">airline sucks</category>
      <category domain="http://securityratty.com/tag/airline">airline</category>
      <category domain="http://securityratty.com/tag/airlines">airlines</category>
      <category domain="http://securityratty.com/tag/smart people follow">smart people follow</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/281028880/on-travel-and-airlines.html">On Travel and Airlines</source>
    </item>
    <item>
      <title><![CDATA[World's elite hackers warn chains of cyber terrorism threat]]></title>
      <link>http://securityratty.com/article/4f79241e2c62c78419513a24d2b571e6</link>
      <guid>http://securityratty.com/article/4f79241e2c62c78419513a24d2b571e6</guid>
      <description><![CDATA[High street chains will be the next victims of cyber terrorism, some of the world's elite hackers have warned. Criminals could use the kind of tactics which crippled Estonia's government and some...]]></description>
      <content:encoded><![CDATA[High street chains will be the next victims of cyber terrorism, some of the world's elite hackers have warned. Criminals could use the kind of tactics which crippled Estonia's government and some firms last year. ]]></content:encoded>
      <pubDate>Sat, 26 Apr 2008 09:31:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/elite hackers">elite hackers</category>
      <category domain="http://securityratty.com/tag/cyber terrorism">cyber terrorism</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/street chains">street chains</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/firms">firms</category>
      <category domain="http://securityratty.com/tag/tactics">tactics</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <source url="http://digg.com/security/World_s_elite_hackers_warn_chains_of_cyber_terrorism_threat">World's elite hackers warn chains of cyber terrorism threat</source>
    </item>
    <item>
      <title><![CDATA[Inside the Multimillion-Dollar Battle to Host the Air Force's New 'Cyber Command']]></title>
      <link>http://securityratty.com/article/4acf67bb38c278e0e552ef67c01aeffa</link>
      <guid>http://securityratty.com/article/4acf67bb38c278e0e552ef67c01aeffa</guid>
      <description><![CDATA[From Yuba City, California, to Bellevue, Nebraska, communities are fighting it out to host the headquarters of the Air Force's new Cyber Command, an elite force dedicated to defeating the enemy in...]]></description>
      <content:encoded><![CDATA[From Yuba City, California, to Bellevue, Nebraska, communities are fighting it out to host the headquarters of the Air Force's new Cyber Command, an elite force dedicated to defeating the enemy in cyberspace. With billions in contracts and local spending on the line, who will win the future of warfare?<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9213ddb74b5edea54b46246ac5fd0b2d" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9213ddb74b5edea54b46246ac5fd0b2d" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=yfXfblE"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=yfXfblE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Yh9tDOe"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Yh9tDOe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jTnWWXe"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jTnWWXe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=OgvDtSE"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=OgvDtSE" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=OrtFZ5E"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OrtFZ5E" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Oomukue"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Oomukue" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nH4lUge"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nH4lUge" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=lgEHzuE"><img src="http://feeds.wired.com/~f/wired/politics/security?i=lgEHzuE" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/232903835" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/232904955" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 10 Feb 2008 23:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/air force">air force</category>
      <category domain="http://securityratty.com/tag/cyber command">cyber command</category>
      <category domain="http://securityratty.com/tag/elite force">elite force</category>
      <category domain="http://securityratty.com/tag/yuba city">yuba city</category>
      <category domain="http://securityratty.com/tag/host">host</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/california">california</category>
      <category domain="http://securityratty.com/tag/local">local</category>
      <category domain="http://securityratty.com/tag/future">future</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/232904955/click.phdo">Inside the Multimillion-Dollar Battle to Host the Air Force's New 'Cyber Command'</source>
    </item>
    <item>
      <title><![CDATA[OmniAmerican Bank targeted by cyber criminals]]></title>
      <link>http://securityratty.com/article/726c4a052fe955720d99ad62680b2d66</link>
      <guid>http://securityratty.com/article/726c4a052fe955720d99ad62680b2d66</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/24/08

Organization
OmniAmerican Bank

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types of Data
Internal bank...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/omni.jpg" align="right" height="45" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/24/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.omniamerican.com/" target="_blank"> OmniAmerican Bank</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Internal bank systems and account numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>An "international gang of cyber criminals" breached OmniAmerican bank systems and used a variety of information to create new personal identification numbers (PINs) and fake debit cards.&nbsp; The criminals then used the cards at to make withdrawls at ATMs in Eastern Europe, Russia, Ukraine, Britain, Canada and New York.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.star-telegram.com/business/story/429367.html" target="_blank"> Star-Telegram Story</a> <br><a href="http://www.sacbee.com/103/story/660690.html" target="_blank"> Sacramento Bee Story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Barry Shlachter, Star-Telegram<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>An international gang of cyber criminals hacked into OmniAmerican Bank's records, the bank's president disclosed Wednesday.<br><br>They stole scores of account numbers, created new PINs, fabricated debit cards, then withdrew cash from ATMs in Eastern Europe, including Russia and Ukraine, as well as in Britain, Canada and New York.<br><span style="font-style: italic;">[Evan] This is either a geographically disperse "gang", or the information was sold to various buyers.</span><br><br>"It was a pretty sophisticated scheme," said Tim Carter, president of the Fort Worth-based bank.<br><span style="font-style: italic;">[Evan] I wonder how sophisticated this attack really was.&nbsp; My first suspicion is a targeted (spear) phishing attack, which isn't very sophisticated.</span><br><br>The amount stolen is not yet known, he said, describing it only as "minimal." No depositors will lose money, he said.<br><br>Fewer than 100 accounts, some of them dormant, were compromised, all with a daily withdrawal limit of less than $1,000, he said.<br><br>After discovering the fraudulent activity Friday afternoon, OmniAmerican placed temporary limits on some ATM and debit-card transactions and suspended some electronic banking services, which were restored Sunday, Carter said. At no time were customer deposits at risk, he stressed. "We reduced by half the dollar amount that could be withdrawn and limited [access] to Texas. We cut out anything outside Texas," Carter said.<br><span style="font-style: italic;">[Evan] Seems like a logical response, but what a hassle for customers.&nbsp; As of Monday morning, the warning below is still posted on OmniAmerican's home page.<br><br><img src="http://images.quickblogcast.com/95781-88451/omninotice.jpg" border="0" width="310"><br></span><br>The unauthorized withdrawals were stopped Friday, and bank employees worked over the weekend to deal with the damage, he said.<br><span style="font-style: italic;">[Evan] The unauthorized withdrawls made on accounts that were known to have been compromised at least.</span><br><br>The bank learned of the breach from customers inquiring about unusual activity in their accounts, from internal monitoring and from a law-enforcement agency, which Carter declined to name.<br><br>Letters alerting check-card holders of the fraudulent activity were mailed Wednesday, the bank said.<br><br>OmniAmerican is also issuing approximately 40,000 new debit cards as a safeguard against future fraudulent activity, Carter said. Each needs a revised personal identification number.<br><br>Martin Carmichael, the Plano-based chief security officer at McAfee, a computer-security firm, said this type of cyber-attack has become "a commonplace occurrence," although some banks are reluctant to admit that their security has been breached.<br><span style="font-style: italic;">[Evan] I agree with Mr. Carmichael.&nbsp; In my work with banks, they all expect to lose a certain amount of money.&nbsp; They say it comes with the territory.&nbsp; If a breach is disclosed to the public, it could negatively affect customer confidence which equates to lost revenue.&nbsp; Lost dollars due to customer confidence usually outweigh the lost dollars from the breach itself.&nbsp; I guess anyway.&nbsp; Banks are attacked and/or compromised every day because they have the one thing everybody wants…money.</span><br><br>Carmichael said OmniAmerican apparently fell victim to one of the more skilled gangs of criminal hackers.<br><span style="font-style: italic;">[Evan] Again, I question how skilled an attacker really needs to be.&nbsp; Many "skilled" attackers go unnoticed and why would skilled attackers stop at "fewer than 100 accounts" before calling attention to themselves?</span><br><br>"If you look at the sophistication of it -- going in, modifying PINs, issuing cards -- this is not a kid out there," he said. "This appears to be something set up. Time was involved in executing it."<br><br>Whoever they are, he said, "they're elite, more elegant, and it's difficult for banks and many enterprises to keep pace with their activities.<br><br>"Banks are under a great amount of pressure to balance risk and shareholder value," said Carmichael, speaking from Las Vegas, where he is attending a conference. "They could do more, [but they] have a hard time justifying the cost until an incident occurs."<br><span style="font-style: italic;">[Evan] Very well put, sad and true.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Maybe this was a sophisticated attack like some are claiming.&nbsp; I just think about how easy it could be to carry out a spear phishing attack either to download and install malware or collect a password of a bank employee (because many people use one password for everything) and proxy the network traffic through compromised systems in other countries.&nbsp; Phishing and other attacks based on human behavior are usually much more successful than high-tech exploits.<br><br>OmniAmerican deserves some credit for a firm and decisive incident response. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/28/omni.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 28 Jan 2008 08:26:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/omniamerican bank">omniamerican bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/omniamerican bank systems">omniamerican bank systems</category>
      <category domain="http://securityratty.com/tag/omniamerican">omniamerican</category>
      <category domain="http://securityratty.com/tag/internal">internal</category>
      <category domain="http://securityratty.com/tag/internal bank systems">internal bank systems</category>
      <category domain="http://securityratty.com/tag/debit cards">debit cards</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/bank employees">bank employees</category>
      <source url="http://breachblog.com/2008/01/28/omni.aspx">OmniAmerican Bank targeted by cyber criminals</source>
    </item>
    <item>
      <title><![CDATA[Keeping up with global regulations]]></title>
      <link>http://securityratty.com/article/559ef8f11119e494430084dd94c09135</link>
      <guid>http://securityratty.com/article/559ef8f11119e494430084dd94c09135</guid>
      <description><![CDATA[The Foreign Corrupt Practices Act (FCPA) has been seemingly more newsworthy than usual recently (even impacting Hollywood elite ), with somewhat conflicting accounts of the US cracking down on bribery...]]></description>
      <content:encoded><![CDATA[<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span face="Times New Roman">The Foreign Corrupt Practices Act (FCPA) has been seemingly more newsworthy than usual recently (even impacting </span><a href="http://www.varietyasiaonline.com/content/view/5167/53/"><span face="Times New Roman">Hollywood elite</span></a><span face="Times New Roman">), with somewhat conflicting accounts of the US </span><a href="http://www.financeweek.co.uk/cgi-bin/item.cgi?id=5794&amp;d=11&amp;h=24&amp;f=254"><span face="Times New Roman">cracking down</span></a><span face="Times New Roman"> on bribery both here and abroad, and the rationale for the US to </span><a href="http://www.nytimes.com/2007/12/23/magazine/23wwln-phenomenon-t.html?ref=magazine"><span face="Times New Roman">accept some level of bribery</span></a><span face="Times New Roman"> for the sake of broader national interests.</span></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span face="Times New Roman">The interesting issue here is not the level of enforcement, but the inability of companies to keep track of legislation applying to them. </span><a href="http://www.financeweek.co.uk/cgi-bin/item.cgi?id=5794&amp;d=11&amp;h=24&amp;f=254"><span face="Times New Roman">This article</span></a><span face="Times New Roman"> quotes a KPMG spokesperson referring to a study that found that nearly half of respondent didn’t know that the FCPA applied to their operations, specifically commenting, “Companies appear to be exposing themselves to increased risk of prosecution through a mixture of lack of awareness of the anti-bribery rules, and a lack of engagement even when they are aware.”</span></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span face="Times New Roman">Tracking, understanding, updating, and communicating regulatory requirements are often significant gaps in corporate compliance programs, and certainly gaps that the vendor community is looking to solve.<span style="mso-spacerun: yes"> </span>Note how the leading compliance management platforms are demonstrating leadership with some of these capabilities in </span><a href="http://www.forrester.com/forrtrack/redirect.jsp?lr=%2Fgo%3Fdocid%3D41751&amp;panid=13&amp;rbgid=2"><span face="Times New Roman">The Forrester Wave™: Enterprise Governance, Risk, And Compliance Platforms, Q4 2007</span></a><span face="Times New Roman"> released last week. </span></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"></p>

<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span face="Times New Roman">As companies continue to expand operations overseas, exposing themselves to new and changing regulatory environments, these capabilities will likely play an even more crucial role in 2008 in the competition of leading compliance platforms.<span style="mso-spacerun: yes">&nbsp; </span>Compliance officers should certainly keep these as criteria when evaluating possible solutions.<span style="mso-spacerun: yes">&nbsp; </span>Expect more research from Forrester in this area as well.</span></p>]]></content:encoded>
      <pubDate>Fri, 28 Dec 2007 11:03:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companies continue">companies continue</category>
      <category domain="http://securityratty.com/tag/bribery">bribery</category>
      <category domain="http://securityratty.com/tag/anti-bribery rules">anti-bribery rules</category>
      <category domain="http://securityratty.com/tag/operations">operations</category>
      <category domain="http://securityratty.com/tag/compliance platforms">compliance platforms</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/expand operations overseas">expand operations overseas</category>
      <category domain="http://securityratty.com/tag/compliance management platforms">compliance management platforms</category>
      <category domain="http://securityratty.com/tag/forrester">forrester</category>
      <source url="http://blogs.forrester.com/srm/2007/12/keeping-up-with.html">Keeping up with global regulations</source>
    </item>
    <item>
      <title><![CDATA["Tiger Team" Reality TV Show]]></title>
      <link>http://securityratty.com/article/2d594398497cb201808b5cc67b6bb68e</link>
      <guid>http://securityratty.com/article/2d594398497cb201808b5cc67b6bb68e</guid>
      <description><![CDATA[On Court TV: This vérité action series follows Tiger Team a group of elite professionals hired to infiltrate major business and corporate interests with the objective of exposing weaknesses in the...]]></description>
      <content:encoded><![CDATA[On Court TV: This vérité action series follows Tiger Team ­ a group of elite professionals hired to infiltrate major business and corporate interests with the objective of exposing weaknesses in the world’s most sophisticated security systems, defeating criminals at...<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/excerpts?a=plIHinC"><img src="http://feeds.feedburner.com/~f/schneier/excerpts?i=plIHinC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/excerpts?a=UVTJJbC"><img src="http://feeds.feedburner.com/~f/schneier/excerpts?i=UVTJJbC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/excerpts?a=7joAs6C"><img src="http://feeds.feedburner.com/~f/schneier/excerpts?i=7joAs6C" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 26 Dec 2007 04:50:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tiger team">tiger team</category>
      <category domain="http://securityratty.com/tag/vrit action series">vrit action series</category>
      <category domain="http://securityratty.com/tag/elite professionals hired">elite professionals hired</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <category domain="http://securityratty.com/tag/court tv">court tv</category>
      <category domain="http://securityratty.com/tag/major business">major business</category>
      <category domain="http://securityratty.com/tag/weaknesses">weaknesses</category>
      <category domain="http://securityratty.com/tag/objective">objective</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <source url="http://www.schneier.com/blog/archives/2007/12/tiger_team_real.html">"Tiger Team" Reality TV Show</source>
    </item>
  </channel>
</rss>
