<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: employ]]></title>
    <link>http://securityratty.com/tag/employ</link>
    <description></description>
    <pubDate>Thu, 05 Jun 2008 05:42:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The asymmetry of data loss - data thief has an upper hand]]></title>
      <link>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</link>
      <guid>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</guid>
      <description><![CDATA[I read this awesome book by Dan Geer, Economics and Strategies of Data Security . This gave me structure for my thoughts about a complex topic such as data security
When a data owner's (a business)...]]></description>
      <content:encoded><![CDATA[<P>I read this&nbsp;awesome book by Dan Geer, <A href="http://www.verdasys.com/thoughtleadership/">Economics and Strategies of Data Security</A>. This gave me structure&nbsp;for my thoughts about a complex topic such as data security. </P>
<P>When&nbsp;a&nbsp;data owner's (a business)&nbsp;sensitive data is breached it is&nbsp;difficult to quantify the monetary loss. According to respectable survey sources, the average cost of sensitive data breach for a large size company is about $50,000. I am attempting here to think about this in simple mathametical terms:</P>
<P>There is a data breach. From the data owner's perspective the loss is:</P>
<P><FONT color=#3366ff>Loss&nbsp;= Cost to protect data&nbsp;+ Loss of business due to data theft aka cost of competitive disadvantage</FONT></P>
<P>From the data thief's perspective</P>
<P><FONT color=#3333ff>Net Gain= [Cost of producing the data&nbsp; *&nbsp; Data freshness factor] - Cost to steal the data + Profit of business due to data aka gain of competitive advantage</FONT></P>
<P>From the above two equations it is very clear that this is not a zero sum game. There is a clear cost asymmetry for a data owner and for a data thief. When there is an asymmetry there is an opportunity. Data owner&nbsp;would not even know that the&nbsp;data is lost because&nbsp;the original copy of the data may be still intact - data thief could have simply copied the data.&nbsp;Data theft does not look like&nbsp;a car theft, there is no vacuum left behind.&nbsp;</P>
<P><STRONG><EM>This motivates a data thief to keep the cost to steal low, steal highly valuable data that has&nbsp;a long shelf life and in a way that data owner will never even be aware of theft.</EM></STRONG></P>
<P>From&nbsp;a data thief's perspective, the cost to steal data if kept high would disincentive him. Moreover, Data freshness factor, i.e. how valuable this data is over period of time plays an important role.&nbsp;A good example is content of today's newspaper is hardly valuable tomorrow, but the content of newspaper two days ahead (if can be procured)would be invaluable. Data relevance is a function of time and other marketplace variables - &nbsp;Data freshness Factor accounts for that variable. A good way to discourage data thief is to increase his/her cost to steal the data. There are other inferences from the above equation. If there exists&nbsp;no competitive advantage&nbsp;with the stolen data, hardly any thief would even venture&nbsp;to steal the&nbsp;data in the first place. If the cost of producing data is very low, then probably thief can just produce the data himself and would not attempt to steal the data. If the cost of&nbsp;theft is kept high, it would definitely deter the data thief from stealing data using technical mechanisms, then the data thief would&nbsp;exploit weak links in data security&nbsp;such as use of social engineering to get access to the data.</P>
<P>From data owner perspective protecting data becomes very important. How much would the owner be willing to spend? Not definitely the cost equal to cost of producing the data. 1% to 10% of cost of producing data is considered prudent. For a data owner it is difficult to estimate cost of data protection of a specific data, because it is not easy to chunkify data protection costs. Moreover, as Dan Geer says in his book, a data owner has to protect himself from number of intruders not just one.</P>
<P><EM><STRONG>It pays for a data owner to: be aware of data breaches (or data leaks), employ appropriate&nbsp;mechanisms to protect the data; the cost of protection which&nbsp;is fractional cost of&nbsp;the valuable&nbsp;data and&nbsp;enhance information security awareness of personnel who handle the data.</STRONG></EM></P>
<P><STRONG><EM>Data loss is not a zero sum game. The advantage is in favor of a data thief (data thieves rather).&nbsp;Data owner does not give much thought&nbsp;on&nbsp;the value of data&nbsp;unless&nbsp;there is a data theft.&nbsp;But,&nbsp;a&nbsp;data thief&nbsp;has every reason to think about economics of data theft before he acts to steal the data else data thief won't survive in this game and he is very well aware of his advantageous position.</EM></STRONG></P>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:33:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data owner perspective">data owner perspective</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/thief">thief</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data freshness factor">data freshness factor</category>
      <category domain="http://securityratty.com/tag/data protection costs">data protection costs</category>
      <category domain="http://securityratty.com/tag/discourage data thief">discourage data thief</category>
      <category domain="http://securityratty.com/tag/protect data">protect data</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html">The asymmetry of data loss - data thief has an upper hand</source>
    </item>
    <item>
      <title><![CDATA[Around The Web For Friday]]></title>
      <link>http://securityratty.com/article/854f3c7cd7fbfd4b803df29d7a415b9d</link>
      <guid>http://securityratty.com/article/854f3c7cd7fbfd4b803df29d7a415b9d</guid>
      <description><![CDATA[Were frequently asked what were reading and what we like in blog posts, so here are some interesting things that hit our RSS readers that you may have missed
COBIT rivals ITIL from The IT Skeptic...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;re frequently asked what we&#8217;re reading and what we like in blog posts, so here are some interesting things that hit our RSS readers that you may have missed:</p>
<p><a href="http://www.itskeptic.org/node/692"><strong>COBIT rivals ITIL from The IT Skeptic</strong></a></p>
<blockquote><p>&#8220;Everyone is tiptoeing around the fact that COBIT offers a significant competitive body of knowledge (BOK) to ITIL. Sure ITIL goes into more depth in places, but to say COBIT sits over the top is to grossly understate the overlap. COBIT extends a long way down into the &#8220;how&#8221; and it does it with an intellectual rigour that ITIL lacks.&#8221;</p></blockquote>
<p>Interesting stuff that.  A detailed mapping might help some folks.  Either way, the good news for those keen on understanding risk management is that governance metrics, done right, allow us to understand a part of that &#8220;capability to manage risk&#8221; we&#8217;re always looking for.   Assurance, verification and the acquisition and interpretation of knowledge is king.   Speaking of which&#8230;.</p>
<p><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/09/how-to-tell-when-nothing-happens.html"><strong>How To Tell When &#8220;Nothing Happens&#8221; by Pete Lindstrom</strong></a></p>
<blockquote><p>&#8220;&#8230;problem is that, it isn&#8217;t really true that &#8220;nothing happens&#8221; when you employ some specific security control to prevent an exploit. Not only that, but even when it is difficult to collect data on what didn&#8217;t happen, one can devise experiments to tell how frequently that nothing occurred.&#8221;</p></blockquote>
<p><em>Good</em> analysis is all about the uncertainty.   Speaking of accounting for uncertainty&#8230;</p>
<p><a href="http://1raindrop.typepad.com/1_raindrop/2008/09/assets-good-until-reached-for.html"><strong>Assets Good Until Reached For by Gunnar Peterson</strong></a></p>
<blockquote><p>&#8220;If you have a 100,000 dekstops or 100,000 servers it hard to manage. You will need to automate and to do that you need to abstract, but you should also realize that its a drawing on a whiteboard not reality. You need abstraction assurance.&#8221;</p></blockquote>
<p>And there&#8217;s the trick.  We might call &#8220;abstraction assurance&#8221; an analog to &#8220;confidence&#8221; or &#8220;uncertainty&#8221; in certain priors (metrics) or posteriors (calculated values based on those metrics).  The stronger that abstraction assurance is, the less uncertainty we have in our knowledge and the better our ability to create wisdom from that knowledge (you know, make decisions).</p>
<p><a href="http://www.emergentchaos.com/archives/2005/12/epstein_snow_an.html"><strong>Epstein, Snow and Flake: Three Views of Software Security by Adam Shostack</strong></a></p>
<p>Adam&#8217;s focus is on software security, but the discussion here can be abstracted out into the broader realm of risk management quite nicely.</p>
<p><a href="http://www.securityfocus.com/brief/825?ref=rss"><strong>Two-thirds of firms hit by cybercrime from Security Focus</strong></a></p>
<p>The US DoJ says that in 2005 (there&#8217;s some timely data) 2/3 of their surveyed firms detected at least one cybercrime.  &#8220;Cybercrime&#8221; is &#8220;classified &#8230; into cyber attacks, cyber theft, and other incidents.&#8221;  Pretty general.  Also from the report:  &#8220;Computer viruses made up more than half of all cyber attacks.&#8221;</p>
<p>(That sound you hear is me tapping my forehead lightly on large iron object)</p>
<p><a href="http://blog.ca-grc.com/2008/09/lessons-learned-from-%E2%80%9Cpersonal%E2%80%9D-risk-management/"><strong>Lessons Learned from “Personal” Risk Management By: Christopher Daugherty</strong></a></p>
<blockquote><p>&#8220;This process is what I call “personal risk management.”  All of us have done it and will continue to do so.  Why is it, then, many companies have ignored following similar principles with the on-going health of the business?  This is a debate with many different answers so I ask you to select the best answer for your employer:</p>
<p>a) Have not ignored as this keeps me awake at night!</p>
<p>b) Please restate the problem, I cannot hear well with my head buried in the sand.</p>
<p>c) We passed our SOX audit so we checked this off the list!</p>
<p>d) We are informed of the challenge but we have a business to run and profits to make</p>
<p>e) Is this what internal audit and risk management has been telling us?&#8221;</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 08:56:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/call abstraction assurance">call abstraction assurance</category>
      <category domain="http://securityratty.com/tag/abstraction assurance">abstraction assurance</category>
      <category domain="http://securityratty.com/tag/personal risk management">personal risk management</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/assurance">assurance</category>
      <category domain="http://securityratty.com/tag/itil">itil</category>
      <category domain="http://securityratty.com/tag/itil lacks">itil lacks</category>
      <category domain="http://securityratty.com/tag/cobit rivals itil">cobit rivals itil</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=450">Around The Web For Friday</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[The Growing Security Skills Shortage]]></title>
      <link>http://securityratty.com/article/6f0a31fa5334384c34fb7f51cba96b5b</link>
      <guid>http://securityratty.com/article/6f0a31fa5334384c34fb7f51cba96b5b</guid>
      <description><![CDATA[We are regularly hearing from our security clients about their difficulties finding people with the right skills or when they do finally find them, these people are too costly to employ because their...]]></description>
      <content:encoded><![CDATA[<p><img title="Jonathan Penn" alt="Jonathan Penn" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Jonathan-Penn.gif" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></p>

<p>We are regularly hearing from our security clients about their difficulties finding people with the right skills – or when they do finally find them, these people are too costly to employ because their skills are in such demand.</p>



<p>Indeed, the “unavailability of people with the right skills” was cited as a top challenge for security groups in both our <a href="http://www.forrester.com/go?docid=44366">enterprise</a> and <a href="http://www.forrester.com/go?docid=44692">SMB</a> surveys.</p>



<p>In comparing need for talent across 25 different IT roles, Forrester analysts came to the conclusion that information security experts are among <a href="http://www.forrester.com/go?docid=46400">the hottest roles in IT</a>, sharing the top spot with information/data architects.</p>



<p>The skills shortage is likely to get worse before it gets better. We’re unlikely to see a significant spike in security experts’ salaries to attract those we need to hire: large changes in compensation for senior security personnel would run against the current of economic belt-tightening. Another typical approach to offsetting the shortage would be to train up: foster the career development and advancement of existing security personnel on our payroll. However, with all the outsourcing that is going on – and which will increasingly occur – there is a shrinking pool from which to find people with “the right stuff” worth championing their advancement.</p>



<p>We could look outside of security to others in IT, or even to co-workers in other departments or business groups. But given how poor a job IT Security does of marketing its value proposition, I don’t hold much hope for attracting non-security people.</p>



<p>What do you think? Are we about to hit a very big wall when it comes to skills and staffing? Are you presently feeling the pain of a skills shortage? Do you see such a shortage looming? What measures are you taking to acquire and nurture talent? Which ones are successful and why?</p>



<p>I welcome your thoughts on the topic.</p>

]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 05:02:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/senior security personnel">senior security personnel</category>
      <category domain="http://securityratty.com/tag/security clients">security clients</category>
      <category domain="http://securityratty.com/tag/security experts salaries">security experts salaries</category>
      <category domain="http://securityratty.com/tag/skills shortage">skills shortage</category>
      <category domain="http://securityratty.com/tag/shortage">shortage</category>
      <category domain="http://securityratty.com/tag/information security experts">information security experts</category>
      <category domain="http://securityratty.com/tag/skills">skills</category>
      <category domain="http://securityratty.com/tag/security personnel">security personnel</category>
      <source url="http://blogs.forrester.com/srm/2008/08/the-growing-sec.html">The Growing Security Skills Shortage</source>
    </item>
    <item>
      <title><![CDATA[Great Trend Micro article on Understanding Malware]]></title>
      <link>http://securityratty.com/article/a1e037e7a2efc121e989d6fb3ef16620</link>
      <guid>http://securityratty.com/article/a1e037e7a2efc121e989d6fb3ef16620</guid>
      <description><![CDATA[Reading this article will be worth your time. Cyber criminals are constantly coming up with new angles to get you to become infected with their Malware


clipped from newsletters.trendmicro.com
...]]></description>
      <content:encoded><![CDATA[<div > Reading this article will be worth your time.<br/>Cyber criminals are constantly coming up with new angles to get you to become infected with their Malware. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/95783F43-2539-4DAF-B269-4A4A74FAA8A1/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/d3bb0194-f21e-4917-ac72-c7e66c9de51f/95783F43-2539-4DAF-B269-4A4A74FAA8A1/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL" href="http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL" style="font-size: 11px;">newsletters.trendmicro.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL --></p>
<table background="undefined" bgcolor="">
<tr><TD valign="top" colspan="2">Malicious URLs: Ticket to Malware</TD></tr>
</table>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL --><DIV><br />
To better understand malicious URLs, it helps to divide them into two broad categories: 1) URLs that use social engineering to initially entice users to click on them, and 2) techniques that do not involve social engineering, but instead employ various technological means. </DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/95783F43-2539-4DAF-B269-4A4A74FAA8A1/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 11:33:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/urls">urls</category>
      <category domain="http://securityratty.com/tag/malicious urls">malicious urls</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/involve social">involve social</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/entice users">entice users</category>
      <category domain="http://securityratty.com/tag/cyber criminals">cyber criminals</category>
      <category domain="http://securityratty.com/tag/broad categories">broad categories</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=542">Great Trend Micro article on Understanding Malware</source>
    </item>
    <item>
      <title><![CDATA[Email Hacking Going Commercial]]></title>
      <link>http://securityratty.com/article/c942d386cfed24bfc702c39e34ba0eea</link>
      <guid>http://securityratty.com/article/c942d386cfed24bfc702c39e34ba0eea</guid>
      <description><![CDATA[This email hacking as a service offering is the direct result of the public release of a DIY hacking kit consisting of each and every publicly known vulnerability for a variety of web based email...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SIb2scvQlJI/AAAAAAAAB80/xZ9U_kM3uFY/s1600-h/email_hacking_for_hire.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SIb2scvQlJI/AAAAAAAAB80/h8JpVAHsl1E/s200-R/email_hacking_for_hire.png" style="border: 0pt none ;" /></a>This email hacking as a service offering is the direct result of the public release of a <a href="http://ddanchev.blogspot.com/2008/04/web-email-exploitation-kit-in-wild.html">DIY hacking kit consisting of each and every publicly known vulnerability for a variety of web based email service providers</a>, with the idea to make it easier for someone to execute their attacks more efficiently. Outsource the hacking of someone's email, and receive a proof in the form of a screenshot of the inbox, next to a guarantee that you'll be able to get back in even after they've changed their passwords? Too good to be true, but since they only charge after they provide you with a proof that they did the job, they could be in fact attempting to hack these emails, compared to the majority of cases where scammers scam the scammers. The service works in 7 steps :<br />
<br />
"<i><b>1-</b> Submit your case to one of our experts.<br />
<b>2-</b> After successful submission , you will be sent a confirmation email along with your Case Reference Number (CRN) .<br />
<b>3-</b> Our expert(s) will revert back to you in a few minutes with the details, the charges &amp; the turn-around time. You may also be asked to provided additional information through a private form if required by our expert.<br />
<b>4-</b> Once our expert has all the required information, you will be provided a username/password to our client area where you can view the real-time progress of your case.<br />
<b>5-</b> Within a matter of hours (maximum 72 hrs), you can see the results. Our expert will provide you with proof-of-success , which you can verify and confirm.<br />
<b>6- </b>Once you have verified the authenticity of success, you will be sent detailed payment instructions. You will be asked to pay using anyone of our multiple payment methods.<br />
<b>7-</b> Once the payment is realized, we will provide you the requisite information</i>"<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SIgn4G_LUJI/AAAAAAAAB9E/gUjdnUIhb2I/s1600-h/email_hacking_for_hire2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SIgn4G_LUJI/AAAAAAAAB9E/K90KY6BFmtc/s200-R/email_hacking_for_hire2.png" style="border: 0pt none ;" /></a>Who's doing the actual email hacking? Independent contractors on behalf of the service as it looks like :<br />
<br />
"<i>Most other groups employ phishing , trojans or viruses which could damage or even alert the target. Our experts use techniques which are developed by themselves , not shared by anyone. We don't ask them how they do it, but as long as they provide us the desired results, its ok for us. Since we test their methods while they are on probation period with us, we check if the target is being alerted or not. As of now, for the past 4 years, we have NOT RECEIVED A SINGLE COMPLAINT IN THIS REGARD, which is testimonial to the ingenuity of the methods used by CSP.</i>"<br />
<br />
How would they prove that they've managed to hack the email account before requesting the payment?<br />
<br />
"<i><b>1-</b> Multiple screenshots of the mailbox<br />
<b>2-</b> A copy of your own email which you had sent to the target<br />
<b>3-</b> A copy / part of the address-book of the target mailbox.</i>"<br />
<br />
Ironically, a hypothetical questionarry that I once speculated a private detection would require from someone interested in <a href="http://ddanchev.blogspot.com/2007/04/outsourcing-spying-on-your-wife.html">Outsourcing The Spying on Their Wife</a>, in order to set the foundations for a successful social engineering attack, is being used by the email hacking group.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BtCtQJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BtCtQJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3ICiRJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3ICiRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sz7zbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sz7zbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a0Galj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a0Galj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OnvMKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OnvMKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=u7PbTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=u7PbTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6TRHXj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6TRHXj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/344330657" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 22:04:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/confirmation email">confirmation email</category>
      <category domain="http://securityratty.com/tag/methods">methods</category>
      <category domain="http://securityratty.com/tag/multiple payment methods">multiple payment methods</category>
      <category domain="http://securityratty.com/tag/actual email">actual email</category>
      <category domain="http://securityratty.com/tag/payment">payment</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/mailbox">mailbox</category>
      <category domain="http://securityratty.com/tag/target mailbox">target mailbox</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/344330657/email-hacking-going-commercial.html">Email Hacking Going Commercial</source>
    </item>
    <item>
      <title><![CDATA["many of Colt's clients" affected by breach, CNET included]]></title>
      <link>http://securityratty.com/article/3313abd868212bd3a9ed98811169e851</link>
      <guid>http://securityratty.com/article/3313abd868212bd3a9ed98811169e851</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/13/08

Organization
CNET Networks, Inc. (&quot;CNET

Contractor/Consultant/Branch
Colt Express Outsourcing Services, Inc. (&quot;Colt

Victims
current and former...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/colt.jpg" width="78" align="right" height="69"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/13/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.cnetnetworks.com/">CNET Networks, Inc. ("CNET")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.colthr.com/">Colt Express Outsourcing Services, Inc. ("Colt")</a><br><br><span style="font-weight: bold;">Victims:</span><br>"current and former employees and their dependants"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"around 6,500"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"first names, last names, date of birth, Social Security numbers, address, employer, hire date, benefits group numbers, and relationship to the policy holder"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Colt informed our client by this letter that on Memorial Day, Monday, May 26, 2008, Colt's offices in Walnut Creek, California were burglarized.&nbsp; Certain computer equipment was taken which contains the human resources data of several of their clients, including CNET.&nbsp; The theft of this equipment may have compromised the personal information of our client's current and former employees and their dependants, and our client is working to understand the extent of any exposure for its employees."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.oag.state.md.us/idtheft/Breach%20Notices/ITU-153493.pdf">Maryland State Attorney General breach notification</a><br><a href="http://www.pcworld.com/businesscenter/article/147460/cnet_employees_notified_after_data_breach.html">PCWorld</a> <br><a href="http://www.webpronews.com/topnews/2008/06/24/cnet-affected-by-security-breach">WebProNews</a> <br><a href="http://www.pogowasright.org/article.php?story=20080619103835325">PogoWasRight</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Maryland State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>On June 6, 2008, CNET received the attached letter from Colt Express Outsourcing Services, Inc., ("Colt") who has provided our client with employee benefit plan administrative services for the past 8 years.<br><br>Colt informed our client by this letter that on Memorial Day, Monday, May 26, 2008, Colt's offices in Walnut Creek, California were burglarized.<br><span style="font-style: italic;">[Evan] Uh Oh!, this is starting to read like and smell like the </span><a style="font-style: italic;" href="http://breachblog.com/2008/02/11/asi.aspx">ASI breach</a><span style="font-style: italic;"> reported in February.</span><br><br>The breach occurred on Memorial Day, Monday, May 26, 2008, between approximately 4:30 p.m. and 5:00 p.m. PST, when someone broke into Colt Express's office at 2125 Oak Grove Road, Suite 210, Walnut Creek, California, 94598<br><br>Certain computer equipment was taken which contains the human resources data of several of their clients, including CNET. <br><span style="font-style: italic;">[Evan] According to a CNET spokesperson, via PogoWasRight.org, the "computer equipment" did not employ encryption to protect the information.&nbsp; Encryption could have been a prudent control in a defense-in-depth approach, a mitigating control to protect information against a physical break-in and theft.</span><br><br>The theft of this equipment may have compromised the personal information of our client's current and former employees and their dependants, and our client is working to understand the extent of any exposure for its employees.<br><span style="font-style: italic;">[Evan] Not "may have", but did.&nbsp; Information security and control can no longer be reasonably assured, which in my book constitutes a compromise.</span><br><br>Colt has also informed us that they reported the break-in to Walnut Creek police and to REACT High Tech Crimes Task Force in Silicon Valley when they discovered the burglary and that there is an ongoing criminal investigation.<br><br>report number 08-12367<br><br>In speaking directly with the Walnut Creek Police on June 12, 2008, Officer Greg Leonard, the primary investigator for the incident informed us that they are not aware of any misuse of personal information as a result of this theft at this time.<br><br>The information included first names, last names, Social Security numbers, address, employer, hire date, benefits group numbers, and relationship to the policy holder for around 6,500 of our client's current and former employees, and their dependants.<br><br><img src="http://images.quickblogcast.com/95781-88451/cnetnumbers.jpg" width="435" border="0"><br><br>some of your current and former employees and their dependants during the time period of 01-Aug-00 to present.<br><span style="font-style: italic;">[Evan] August 1st, 2000 through May 26th, 2008 is almost eight years of information!&nbsp; I wonder what the data retention policy states at Colt, supposing one exists.</span><br><br>We do not have any understanding that the computers stored personal health information.<br><br>Our client is providing written notification to all affected individuals at the last home address we have on record<br><br>Although there is no evidence of misuse of the data to date, our client's notification will also inform affected individuals that it has contracted with Equifax to provide Equifax Credit Watch Gold with 3 in 1 Monitoring service, including identity theft insurance, for one full year at no cost.<br><span style="font-style: italic;">[Evan] I have said it before, and I will say it again.&nbsp; One year of semi-effective protection should not be considered adequate for information that has a usable life that far exceeds this time frame.&nbsp; It should be pointed out howevere that it is better than nothing and the company is not required to offer it.</span><br><br>Although we are not aware of the exact number of individuals affected by the Colt breach, we do know that we were among many of Colt's clients whose data were stored on the stolen computers.<br><span style="font-style: italic;">[Evan] The word that catches my attention almost immediately is "many".&nbsp; How many clients will be affected in the end?&nbsp; PogoWasRight is already following up on another company that may be affected.</span><br><br>Colt Express takes the protection of its customer and personal information very seriously.<br><span style="font-style: italic;">[Evan] Making a statement like this and the demonstration by action are two entirely different matters.&nbsp; An organization such as Colt Express creates, collects, stores and transfers very sensitive information as an integral part of their business.&nbsp; This being said, I wonder why this information was not protected better.</span><br><br>Colt Express is taking steps to ensure that a potential data security breach does not occur in the future.<br><br>We installed an alarm system on Friday, May 30th.<br><span style="font-style: italic;">[Evan] Are we to assume that there was none prior to May 30th?&nbsp; I hope not!</span><br><br>Colt Express is looking into what additional steps may be taken to provide enhanced security.<br><br>By this letter and enclosures, we are providing you with all the information we believe you need, and that we are able to give you.&nbsp; We do not have the resources, financial and otherwise, to assist you further.<br><span style="font-style: italic;">[Evan] Say huh?</span><br><br>Towards the end of last year, our customer base was reduced to an unsustainable level.<br><br>Colt has been in the process of going out of business, while at the same time providing time for remaining customers to find alternative solutions.<br><span style="font-style: italic;">[Evan] This is a twist.&nbsp; How long has the company been in the process of going out of business and was CNET (and the "many" other clients) aware of it?&nbsp; If so, this could have been a sign that could have spurred some action.&nbsp; Then again, maybe not.</span><br><br><img src="http://images.quickblogcast.com/95781-88451/cnetcolthomepage.jpg" width="241" border="0"><br><font size="1">http://www.colthr.com/</font><br><br><br><br>Those decisions are now final.<br><br>We are firmly committed to protecting all of the information that is entrusted to us both before and after we close down.<br><br>We sincerely apologize for the inconvenience and concern this incident will cause.<br><br><span style="font-weight: bold;">Commentary:</span><br>As I stated earlier in the post, I am a little fearful that this breach could end up as significant or more significant (in terms of number of people and organizations affected) than the <a href="http://breachblog.com/2008/02/11/asi.aspx">ASI breach</a> reported in February.&nbsp; The ASI breach was the 2nd most popular posting in The Breach Blog's history at the time, based on number of online page reads and comments posted.<br><br>This breach has got me thinking.&nbsp; Some of the key risks that we address with the organizations we work with are those involving the management of vendor and third-party relationships.&nbsp; Ideally, information security personnel are involved throughout the relationship, including the initial vendor feasibility assessment.&nbsp; Vendors and "trusted" third-parties need to be held to the same high security standards that we set for the organization.&nbsp; The methods in which this can be accomplished vary from organization to organization, but typically include risk assessments (initial and ongoing), information security requirements built into contractual language, and enforcement actions if necessary.&nbsp; If a vendor is not encrypting confidential information or employing burglar alarms, it is known (and hopefully addressed). <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/25/colt.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 07:25:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/protect information">protect information</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/information security requirements">information security requirements</category>
      <category domain="http://securityratty.com/tag/colt">colt</category>
      <source url="http://breachblog.com/2008/06/25/colt.aspx">"many of Colt's clients" affected by breach, CNET included</source>
    </item>
    <item>
      <title><![CDATA[Canadian farmer personal information on stolen CCGA laptop]]></title>
      <link>http://securityratty.com/article/59ad7c04243f6352dc04e5847a1515dd</link>
      <guid>http://securityratty.com/article/59ad7c04243f6352dc04e5847a1515dd</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/4/08

Organization
Government of Canada

Contractor/Consultant/Branch
Canadian Canola Growers Association (CCGA

Victims
Farmers

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/ccga.jpg" align="right" height="82" width="168"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/4/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.gc.ca/home.html">Government of Canada</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.ccga.ca/OrganizationHome.htm">Canadian Canola Growers Association (CCGA)</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Farmers<br><br><span style="font-weight: bold;">Number Affected:</span><br>~32,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"social insurance numbers, bank account numbers and other data"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"OTTAWA, June 5 (UPI) -- Prairie farmers in Canada are upset the federal government waited two months to tell them a laptop computer containing their personal data was missing."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.winnipegfreepress.com/breakingnews/story/4182176p-4771903c.html">Winnipeg Free Press</a> <br><a href="http://www.cbc.ca/consumer/story/2008/06/05/canola-information.html">CBC News</a> <br><a href="http://www.upi.com/Top_News/2008/06/05/Personal_data_on_32000_farmers_missing/UPI-66311212671633/">United Press International</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Lindsay Wiebe, Winnipeg Free Press<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>About 32,000 Canadian farmers are on the alert after learning a laptop containing their financial information has been stolen.<br><br>The laptop was stolen when a programmer working for the Canadian Canola Growers Association took the machine off-site for routine maintenance.<br><span style="font-style: italic;">[Evan] No offense to programmers, but in my experience the ways they use information can be some of the most dangerous threats to information security.&nbsp; There is no reason for a programmer to EVER have access to confidential production information.&nbsp; Programmers should only be permitted to work with scrubbed information in a test and/or development environment.</span><br><br>CCGA general manager Rick White described the theft as a classic "smash and grab."<br><span style="font-style: italic;">[Evan] Also classic as in another organization that either does not know how or is unwilling to properly secure confidential information.</span><br><br>The laptop has the bank account numbers and social insurance numbers of farmers who applied for Agriculture Canada's advance payments program, which is administered by the CCGA on behalf of the federal government.<br><br>Although the theft happened March 30, Canadians weren't sent letters until last week informing them<br><br>The federal department has sent letters out to all farmers affected by the theft.<br><br>The letter said the laptop was stolen from an undisclosed, remote location in Manitoba.<br><br>"We treat this very seriously," White said. "This is an unfortunate incident, a very low-risk one."<br><span style="font-style: italic;">[Evan] Mr. White is probably not well versed in risk analysis.&nbsp; Or incident response for that matter.</span><br><br>the strict security measures being used on the laptop reduce the chances of information being misused, White said.<br><span style="font-style: italic;">[Evan] Like what?</span><br><br>"There was a very strong password protection on it, [and] there was a biometric fingerprint reader on it," he said. "That would prohibit anyone other than the user or the person with the password to access the data on the laptop."<br><span style="font-style: italic;">[Evan] These are "strict security measures"?&nbsp; My emphatic answer is NO!&nbsp; These "strict security measures" are easily bypassed.</span><br><br>but the data was not encrypted<br><span style="font-style: italic;">[Evan] The missing piece of the puzzle.&nbsp; Why go through all of the (self-proclaimed) "strict security measures" and not employ encryption.&nbsp; What you get with full-disk encryption is pre-boot authentication and this defeats the boot to CD attack.</span><br><br>Agriculture Canada spokesman Sean Malone said there were security features on the laptop, but a sophisticated hacker could likely bypass them.<br><span style="font-style: italic;">[Evan] No sophistication required.&nbsp; A novice could figure it out with Google, a CD, and 15 minutes.</span><br><br>So far, there have been no reports of identity theft among the farmers, the report said.<br><br>Pitblado LLP privacy lawyer Brian Bowman said the CCGA and agriculture department deserve credit for notifying people of the breach -- a move not required by Manitoba law.<br><span style="font-style: italic;">[Evan] Just because CCGA is not required by law, doesn't mean that they deserve any credit for notification.&nbsp; The information belongs to the victims not CCGA, and as owners of the information don't you think they should be informed of an incident that has the potential affect them personally?</span><br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"If they're devilish enough to steal a computer, maybe they're devilish enough to do something with the information," <br><br>"What frustrates me is that they've treated this like it's no skin off their back,"<br><br>"They've known this since then and they're only getting the letters out now?"<br><br>"I don't want to find out a mortgage has been taken out on our farm."<br><br><span style="font-weight: bold;">Commentary:</span><br>It is bad enough for an organization to lose confidential information on a poorly protected laptop, but what makes this more troubling is the apparent fact that they still view the practice that led to the breach as a low risk.&nbsp; Clueless and sad. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Government of Canada:<br>December, 2007 - <a href="http://breachblog.com/2007/12/05/passport.aspx">Passport Canada web site suffers serious breach</a> <br>November, 2007 - <a href="http://breachblog.com/2007/11/26/servicecanada.aspx">Service Canada stolen laptop affects more than 1,600</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/08/ccga.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 08 Jun 2008 15:32:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/laptop affects">laptop affects</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/strict security measures">strict security measures</category>
      <category domain="http://securityratty.com/tag/ccga">ccga</category>
      <category domain="http://securityratty.com/tag/laptop computer">laptop computer</category>
      <source url="http://breachblog.com/2008/06/08/ccga.aspx">Canadian farmer personal information on stolen CCGA laptop</source>
    </item>
    <item>
      <title><![CDATA[AT&T management information on stolen laptop]]></title>
      <link>http://securityratty.com/article/2a7e7d1645c0c310fb2a37602fad248d</link>
      <guid>http://securityratty.com/article/2a7e7d1645c0c310fb2a37602fad248d</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/4/08

Organization
AT&amp;T

Contractor/Consultant/Branch
None

Victims
AT&amp;T management personnel

Number Affected
Unknown

Types of Data
Compensation...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/att.jpg" align="right" height="67" width="128"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/4/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.att.com/gen/landing-pages?pid=3309">AT&amp;T</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>AT&amp;T management personnel<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Compensation information, including employee names, Social Security numbers, and salary and bonus information.<br><br><span style="font-weight: bold;">Breach Description:</span><br>"An undisclosed number of management-level workers at AT&amp;T have been notified that their personal information was stored unencrypted on a stolen laptop."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.pogowasright.org/article.php?story=20080603133358351">PogoWasRight</a> <br><a href="http://www.scmagazineus.com/ATT-management-staff-data-on-stolen-laptop/article/110884/">SC Magazine</a> <br><a href="http://www.networkworld.com/community/node/28453">NetworkWorld</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>PogoWasRight<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>An undisclosed number of management-level workers at AT&amp;T have been notified that their personal information was stored unencrypted on a stolen laptop.<br><span style="font-style: italic;">[Evan] Don't you think that a well known (and respected) company like AT&amp;T would have had the forethought to encrypt laptops?</span><br><br>Employees were first alerted to the theft on the evening of May 22nd by email from Bill Blase, Senior Executive Vice President - Human Resources.<br><br>This is to alert you to the recent theft of an AT&amp;T employee's laptop computer that contained AT&amp;T management compensation information<br><br>The laptop was stolen May 15 from the car of an employee<br><br>The data on the computer was not encrypted -- a violation of company policy -- and included names, Social Security numbers and in some cases, salary and bonus information.<br><br>No customer or client data were on the stolen laptop.<br><br>the company would not disclose the number of affected individuals, but there is no reason to believe any of the data was being targeted when the machine was stolen.<br><br>AT&amp;T repeatedly declined to disclose the number of employees affected "as a matter of policy."<br><br>"Usually these are property crimes in which the drive is wiped clean and resold for profit,"<br><span style="font-style: italic;">[Evan] This used to be the case, but do you think the same still holds true today?&nbsp; If a thief is going to go through the trouble of wiping the drive, it seems plausible that he/she may also attempt to access/review the information contained on it.&nbsp; Hardware value = ~$1000, Information value = ~$10, $20, $50+ per record.&nbsp; Do the math and it soon becomes apparent that a thief can profit much more by selling the information.&nbsp; I presume that some thieves know this.</span><br><br>The employee who was in possession of the laptop when it was stolen has been disciplined.<br><span style="font-style: italic;">[Evan] Was it the employee's responsibility to encrypt the information, or was it his/her responsibility to not store confidential information on it?&nbsp; If the employee was aware of his/her responsibilities, then I can understand the disciplinary action.&nbsp; If not, then AT&amp;T has much bigger problems.</span><br><br>"There are a number of rules governing the handling of encrypted material and the mobile devices handling that material that employees must follow," Sharp said. "It is up to the employee to ensure that any sensitive material is encrypted."<br><span style="font-style: italic;">[Evan] Really?&nbsp; It is "up to the employee" to ensure that sensitive material is encrypted?&nbsp; Most of the users I work with wouldn't know the first thing about how to encrypt information.&nbsp; This is why we usually implement policies, standards and procedures to encrypt the entire contents of hard drives as part of the standard laptop build.&nbsp; Encryption is then semi-transparent and we don't need to worry about an incident such as this.&nbsp; Take information security out of the hands of employees if feasible.</span><br><br>AT&amp;T used the breach as a reminder that employees must follow policies.<br><span style="font-style: italic;">[Evan] Hopefully this isn't the only time employees are reminded to follow policies.</span><br><br>We deeply regret this incident. <br><br>You will soon hear about additional steps we're taking to reinforce our policies to safeguard sensitive personal information and ensure strict compliance in order to avoid incidents like this in the future.<br><br>The telecom also says that it is "in the process of encrypting devices," but that may be small comfort to those whose data were on the stolen laptop.<br><span style="font-style: italic;">[Evan] Sheesh, hundreds if not thousands of breaches involving lost and/or stolen laptops affecting millions of people and now AT&amp;T is "in the process of encrypting devices"?&nbsp; To AT&amp;T's credit, they do employ thousands of mobile devices which take time to encrypt and it's better late than never.&nbsp; Explain this to the people affected.</span><br><br>AT&amp;T is offering free credit monitoring to those affected<br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"I'm very disappointed in my company,"<br><br>"Eight days passed before we were notified ... and it took up to another 10 days to be informed about requesting a fraud alert and to be given instructions for signing up for credit watch."<br><br>"It is pathetic that the largest telecom company in the world -- with more than 100 million customers -- doesn't encrypt basic personal information,"<br><br>"I receive company internal e-mails reminding me to contact our legislators about relieving the company of the burdens of regulation," he says. "What happened here shows the company isn't ready to have those burdens lifted."<br><br><span style="font-weight: bold;">Commentary:</span><br>Excellent work at <a href="http://www.pogowasright.org">PogoWasRight.org</a>.&nbsp; Their report contains copies of the actual AT&amp;T correspondence.&nbsp; Obviously, AT&amp;T should have known better.<br><br>The Breach Blog was notified via a comment from the wife of an affected employee on May 28th, but we did not have enough information to report.&nbsp; The comment was not approved by me either because the commenter used her real name (out of protection for her and her husband).<br><br><img src="http://images.quickblogcast.com/95781-88451/attcomment.jpg" border="0" width="700"><br><br><span style="font-weight: bold;">Past Breaches:</span><br>August, 2007 - <a href="http://breachblog.com/2007/08/31/att-stolen-laptop-unknown-number-of-former-employees-affected.aspx">AT&amp;T Stolen Laptop, Unknown Number of Former Employees Affected</a> <br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/08/att.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 08 Jun 2008 14:28:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/att employee">att employee</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/actual att correspondence">actual att correspondence</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <source url="http://breachblog.com/2008/06/08/att.aspx">AT&amp;T management information on stolen laptop</source>
    </item>
    <item>
      <title><![CDATA[Online theft and fraud involves OSU Bookstore customers]]></title>
      <link>http://securityratty.com/article/8476417975cb621bc420aa71c01e43ab</link>
      <guid>http://securityratty.com/article/8476417975cb621bc420aa71c01e43ab</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/3/08

Organization
Oregon State University

Contractor/Consultant/Branch
OSU Bookstore, Inc

OSU Bookstore is a nonprofit corporation that has been...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/osubooks.jpg" align="right" height="51" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/3/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://oregonstate.edu/">Oregon State University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.osubookstore.com/">OSU Bookstore, Inc.</a>* <br><br><font size="1">*OSU Bookstore is a nonprofit corporation that has been serving Oregon State University and the town of Corvallis since 1914. Our main store is located in the Memorial Union on the Oregon State University campus.&nbsp; Today, as in 1914, the bookstore is governed by a Board of Directors composed of faculty, staff, and students of Oregon State University.</font><br><br><span style="font-weight: bold;">Victims:</span><br>Online customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>"as many as 4,700"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Personal information including credit card numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The Oregon State Police is investigating the theft of personal information from as many as 4,700 online customers of the OSU Bookstore who used credit cards to purchase items."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.dhonline.com/articles/2008/06/03/news/local/5loc10_osu.txt">Albany Democrat Herald</a> <br><a href="http://www.kval.com/news/local/19535104.html">Associated Press via KVAL Channel 13 News</a> <br><a href="http://www.kval.com/news/local/19549224.html">KVAL Channel 13 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Albany Democrat Herald<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>CORVALLIS, Ore. (AP) - Oregon State officials say credit card scammers may have defrauded 4,700 online customers of the school's bookstore.<br><br>In March, OSP began investigation into a report that approximately 30 OSU Bookstore customers’ personal information may have been compromised following online orders.<br><span style="font-style: italic;">[Evan] Unfortunately, the bookstore did not appear to be monitoring web traffic to and from the server to detect unusual (and potentially attack) traffic. The fact that this detective control was missing from the security architecture meant that the bookstore had to rely on customers to tell them something was wrong.&nbsp; An incident response should have probably been initiated at this point (March not May).</span><br><br>Then last week, telephone calls and e-mails began coming into the bookstore from customers who had noticed fraudulent charges on their credit cards almost immediately after placing online orders<br><br>Bookstore General Manager Steve Eckrich says servers were shut down when the security breach was discovered.<br><span style="font-style: italic;">[Evan] 2+ months after the bookstore was originally notified that something was wrong.&nbsp; At the time of this post, the site is still down.</span><br><br><img src="http://images.quickblogcast.com/95781-88451/osubooksdown.jpg" border="0" width="576"><br><br>"They tried different attacks and our Web site evidently had one vulnerability in it," said General Manager Steve Eckrich.<br><span style="font-style: italic;">[Evan] I would bet my cup of coffee that the Web site had more than on vulnerability!&nbsp; I love my coffee.&nbsp; Where is the IDS/IPS?</span><br><br>The Bookstore has alerted its online customers who had made a purchase<br><br>State Police Lieutenant Jeff Lanz says the security breach appears to have originated outside the university, but where is unknown.<br><br>The OSU Bookstore has hired an outside agency to help with its own investigation and to provide guidance on strengthened security safeguards for its computing network.<br><span style="font-style: italic;">[Evan] Good call it just stinks that the bookstore was reactive and not proactive.</span><br><br>"We'll be using their recommendations not only to solve that particular problem that was exploited but to add additional layers of security on top of that so that information is not exposed or cannot be exposed in the way that it was,"<br><span style="font-style: italic;">[Evan] Another good call.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Obviously the OSU Bookstore did not employ the proper security controls to #1 secure the site, #2 detect a breach, and #3 respond to a breach.&nbsp; Three strikes.&nbsp; Poor planning and poor implementation.&nbsp; I hope that OSU Bookstore, Inc. takes the proper steps to formalize their information security program and reduce risk.&nbsp; We'll see. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/04/osubooks.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 05:42:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bookstore">bookstore</category>
      <category domain="http://securityratty.com/tag/osu bookstore">osu bookstore</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/06/05/osubooks.aspx">Online theft and fraud involves OSU Bookstore customers</source>
    </item>
  </channel>
</rss>
