<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: extremely]]></title>
    <link>http://securityratty.com/tag/extremely</link>
    <description></description>
    <pubDate>Wed, 08 Oct 2008 00:42:07 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Not Your Father's Data Breach]]></title>
      <link>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</link>
      <guid>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</guid>
      <description><![CDATA[I am surprised this doesn't happen more often, or become public when it does happen, and I suspect it will


Corporate custodians of confidential medical data should be closely monitoring events...]]></description>
      <content:encoded><![CDATA[<p>I am surprised <a href="http://www.stltoday.com/blogzone/the-platform/published-editorials/2008/11/express-scripts-data-breach-is-bitter-medicine/"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">this</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> doesn&#39;t happen more often, or become public when it does happen, and I suspect it will:</span></p><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Corporate custodians</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;of confidential medical data should be closely monitoring events connected to a nightmarish computer security breach in the St. Louis region.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Express Scripts is one of the nation’s largest pharmacy benefits managers. The company, with headquarters in St. Louis County, handles approximately 500 million prescriptions per year for 50 million workers at 1,600 American companies. Early in October, it received an extortion letter, the details of which it released on Nov. 6.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The letter included personal information on about 75 Express Scripts clients — Social Security numbers, dates of birth and, in some cases, information about prescription medications. Whoever sent the letter demanded money from the company — the amount has not been disclosed — and threatened to use the Internet to reveal personal and medical information about millions of people if the demands were not met.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Beyond&#0160;</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">the scale of the problem for Express Scripts — and the potential impact on the company is enormous — the issue extends well beyond the mounting concerns about identity theft, a phenomenon with which most people have become at least somewhat familiar.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The greater problem is the unique nature of personal medical records, the importance of moving to computerization of such records to improve health safety and reduce costs and the irreversibility of the damage people can suffer if confidential medical information becomes public. The stakes are so high that a federal law establishes strict standards for maintaining the privacy of medical information and stiff fines for failing to do so.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Medical records of all kinds — paper and, especially, electronic — must be protected with the most sophisticated kinds of security systems available, including backup protections and automatic alerts of security violations. Yet Express Scripts learned of this breach in the “worst way,” as InformationWeek.com security correspondent George Hulme put it in an online report: “via an extortion letter.”</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The Express Scripts</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;breach raises many questions for all elements of the health industry: hospitals, clinics and doctors’ practices, benefits management firms, insurance companies, pharmacies, employers and government agencies:</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Are they using the most advanced information security technology possible? Do they minimize the amount of data they collect and keep it only as long as necessary? Do they have strict protocols governing access to personal and medical data — and systems to enforce those protocols? If criminals were to hack into their systems, how would the companies know? How soon? And are the systems capable of instantly cutting off illegal access as soon as a breach is discovered?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Confronted</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;with a grave breach of electronic security, Express Scripts has responded by contacting law enforcement, establishing an informational website, offering a substantial reward and hiring a private consulting firm to help clients who have privacy concerns and investigate situations that “appear to be tied to identity theft” and provide “identity restoration services.” There is no question that the company is taking the situation extremely seriously.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Given the ongoing criminal situation, information about how Express Scripts’ data systems were compromised — and whether it could have been avoided — has yet to be disclosed. But the American people have the right to expect that their sensitive personal and medical information is zealously protected and kept secure — not only by Express Scripts but also by every person or company entrusted with it.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The reason I am surprised this doesn&#39;t happen more often is that many Fortune 500 companies have oceans and oceans of personal data. Almost the only companies that have even tried to get to a medium level assurance are financial companies, yet many of the other companies have as much or even more data, with lower assurance. All that was lacking in the mix was an incentive and a bit of creativity and risk taking by the bad guys.</span></span></p><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">I posted this to the security metrics list and Andy Jaquith quoted it in his great book S<a href="http://1raindrop.typepad.com/1_raindrop/2007/08/chicken-soup-fo.html">ecurity Metrics</a>:</span></div><div><span style="color: #333333; line-height: 17px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; ">&quot;Customers and customer relationships...have tangible measurable value to businesses, and their value is much easier to communicate to those who fund projects. So in an enterprise risk management scenartio, their vlaue informs the risk management process...[For example, consider] a farmer deciding which crop to grow. A farmer interested in short term profits may grow the same high yield crop every year, but over time this would burn the fields out. The long term focused farmer would rotate the crops and invest in things that build the value of the farm and soil over time. Investing in security on behalf of your customers is like this. The investment made in securing your customer&#39;s data build current and future value for them. Measuring the value of the customer and relationships helps to target where to allocate security resources.&quot;</span></p></blockquote><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">Of course this is the opposite of how most organizations do risk management and security architecture, and now, the fields have turned brown.<br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">(Thanks to Chris for pointing me to this story)</span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 06:37:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/medical information">medical information</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/personal medical records">personal medical records</category>
      <category domain="http://securityratty.com/tag/medical records">medical records</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/not-your-fathers-data-breach.html">Not Your Father's Data Breach</source>
    </item>
    <item>
      <title><![CDATA[Risk or Security Management: What's In a Term?]]></title>
      <link>http://securityratty.com/article/0136fe88d711ff0de5b473f4a5b2d0c4</link>
      <guid>http://securityratty.com/article/0136fe88d711ff0de5b473f4a5b2d0c4</guid>
      <description><![CDATA[When Gartner security and risk analysts give presentations, write research or talk to clients, we often get criticized for using the terms security and risk management interchangeably. This is deemed...]]></description>
      <content:encoded><![CDATA[When Gartner security and risk analysts give presentations, write research or talk to clients, we often get criticized for using the terms security and risk management interchangeably. This is deemed to be confusing by the audience as they try to articulate a clear differentiation between these terms. Indeed, in large sections of our client base, vigorous debate is being held on defining, differentiating and positioning information security vs. information risk management.<br />
<br />
Well, maybe such a clear differentiation is not always required. Maybe security and risk management is so intertwined that continuously trying to separate them becomes counterproductive. Let's try to look at this objectively: I can make a clear argument that security is an integral part of risk management. But I can make a similarly cogent argument that risk management is an integral part of security management. The definition is largely in the eye of the beholder. It is contextual and situational. Maybe security and risk management are not the two sides of the same coin - maybe these disciplines are so integrated that they ARE the coin. The business is interested in the coin, not the pictures embossed on either side of it.<br />
<br />
I am not arguing that the security and risk management are one and the same. They are indeed discrete disciplines with different functions and activities. And from an organizational perspective, is it important the different roles are named appropriately to the responsibilities of the individuals concerned. But let's be frank, does your business really care whether you call yourself a security manager or a risk manager? All they want is for (both of?) you to help them manage your information security and IT risks appropriately.<br />
<br />
Risk management and security management. It's not either/or. Black or white. So here is my call: Let's spend less time debating and arguing the differences, and more time on using and maturing these extremely important, completely interrelated disciplines.]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 11:59:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management interchangeably">risk management interchangeably</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/security management">security management</category>
      <category domain="http://securityratty.com/tag/terms">terms</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/terms security">terms security</category>
      <category domain="http://securityratty.com/tag/gartner security">gartner security</category>
      <source url="http://blog.gartner.com/blog/security.php?x=0&amp;itemid=4041">Risk or Security Management: What's In a Term?</source>
    </item>
    <item>
      <title><![CDATA[Reading a Letter from the Envelope it Was In]]></title>
      <link>http://securityratty.com/article/276000a9e19b868dbfa632e293532cbe</link>
      <guid>http://securityratty.com/article/276000a9e19b868dbfa632e293532cbe</guid>
      <description><![CDATA[Fascinating : Paul Kelly and colleagues at Loughborough University found that a disulfur dinitride (S 2 N 2 ) polymer turned exposed fingerprints brown, as the polymer reaction was initiated from the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.physorg.com/news145517878.html">Fascinating</a>:</p>

<blockquote>Paul Kelly and colleagues at Loughborough University found that a disulfur dinitride (S<sub>2</sub>N<sub>2</sub>) polymer turned exposed fingerprints brown, as the polymer reaction was initiated from the near-undetectable remaining residues.

<p>Traces of inkjet printer ink can also initiate the polymer. The detection limit is so low that details of a printed letter previously in an envelope could be read off the inside of the envelope after being exposed to S<sub>2</sub>N<sub>2</sub>.</p>

<p>"A one-covers-all versatile system like this has obvious potential," says Kelly.</p>

<p>"This work has demonstrated that it is possible to obtain fingerprints from surfaces that hitherto have been considered extremely difficult, if not impossible, to obtain," says Colin Lewis, scientific advisor at the UK Ministry of Defence. "The method proposed has shown that this system could well provide capabilities which could significantly enhance the tools available to forensic scientists in the future."</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SQQYN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SQQYN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nEITN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nEITN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 04:55:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/envelope">envelope</category>
      <category domain="http://securityratty.com/tag/polymer reaction">polymer reaction</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/one-covers-all versatile system">one-covers-all versatile system</category>
      <category domain="http://securityratty.com/tag/polymer">polymer</category>
      <category domain="http://securityratty.com/tag/inkjet printer ink">inkjet printer ink</category>
      <category domain="http://securityratty.com/tag/kelly">kelly</category>
      <category domain="http://securityratty.com/tag/obtain">obtain</category>
      <category domain="http://securityratty.com/tag/obtain fingerprints">obtain fingerprints</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/reading_a_lette.html">Reading a Letter from the Envelope it Was In</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Releases Emergency Patch For Critical Windows Vulnerability]]></title>
      <link>http://securityratty.com/article/e9fe767ddd9bdb8b6ec01768b3f18a55</link>
      <guid>http://securityratty.com/article/e9fe767ddd9bdb8b6ec01768b3f18a55</guid>
      <description><![CDATA[Microsoft has released an out-of-band patch to fix an extremely critical vulnerability that exposes Windows users to remote code execution attacks. The emergency update comes just one week after the...]]></description>
      <content:encoded><![CDATA[Microsoft has released an out-of-band patch to fix an extremely critical vulnerability that exposes Windows users to remote code execution attacks.
The emergency update comes just one week after the regularly scheduled Patch Tuesday and follows the discovery of a targeted zero-day attack, Microsoft said in an advisory. The vulnerability is rated critical on Windows 2000, [...]]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 21:01:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <category domain="http://securityratty.com/tag/extremely critical vulnerability">extremely critical vulnerability</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/exposes windows users">exposes windows users</category>
      <category domain="http://securityratty.com/tag/patch tuesday">patch tuesday</category>
      <category domain="http://securityratty.com/tag/zero-day attack">zero-day attack</category>
      <category domain="http://securityratty.com/tag/emergency">emergency</category>
      <source url="http://cyberinsecure.com/microsoft-releases-emergency-patch-for-critical-windows-vulnerability/">Microsoft Releases Emergency Patch For Critical Windows Vulnerability</source>
    </item>
    <item>
      <title><![CDATA[A horse's ass approach to virtualization security - Part 3 - Data is the "constant"]]></title>
      <link>http://securityratty.com/article/af1e0093472ebbd2f739b12a4817fa7e</link>
      <guid>http://securityratty.com/article/af1e0093472ebbd2f739b12a4817fa7e</guid>
      <description><![CDATA[The third in the series where I am trying to think through the current approaches to securing virtual environments

See part one and two here

Virtualization enables organizations to optimally manage...]]></description>
      <content:encoded><![CDATA[The third in the series where I am trying to think through the current approaches to securing virtual environments...<br /><br />See <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization.html">part one</a> and <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization_22.html">two here</a>...<br /><br />Virtualization enables organizations to optimally manage their infrastructure resources. It can provide significant cost benefits (by sharing resources), flexibility (by just-in-time allocation of resources where they are needed), and agility (speed of provisioning resources).  Therefore, organizations have been able to virtualize:<br /><ul><li><span style="font-weight: bold;">Devices/OS</span>: Companies such as VMWare, Citrix, Microsoft, and Sun are providing hypervisor, virtual machine, and virtual device solutions where several virtual “devices,” “servers,” or “desktops” can mimic separate physical devices.</li><li><span style="font-weight: bold;">Networks</span>: Virtualized networks enable dynamic collaboration by slicing bandwidth into virtual, isolated channels that can be assigned to a particular set of devices, real or virtual.  Setting up new connections and collaborative environments becomes extremely easy.</li><li><span style="font-weight: bold;">Applications</span>: Virtual applications can either be streamed down to execute on local desktops (Microsoft App-V or Altiris SVS) or executed remotely from server farms such as Citrix XenApp.  This allows applications to be portable and accessible from anywhere while reducing inter-application conflicts.</li></ul>However, organizations will never be able to virtualize the fourth element, I talked about in teh <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization_22.html">second blog</a> post — the data itself. The focus of device, network, and application virtualization is about flexibility, resource sharing, and agility. This involves short life spans, since these elements are brought up to fulfill a specific short term task, and upon completion, they are brought down or even deleted. Data, however, has a lifetime <span style="font-weight: bold; font-style: italic;">beyond </span>the short term and will therefore live on for further use or analysis in a non-virtual or subsequent virtual world.<br /><br />This makes data the “constant” in a dynamically changing environment — even if the location of data itself is virtualized. Data will also have the longest lifetime of the four elements in the infrastructure and thus will have to live “outside” of the virtual environment. Therefore, from a security standpoint, it is imperative that data becomes the focus of protection - and we dont just continue protecting the infrastructure.  Data is the critical asset, and since it travels across boundaries and lives longer than virtual elements, it can be easily compromised.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=nM7eM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=nM7eM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=xKbIm"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=xKbIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=JcSvM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=JcSvM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/430031380" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 16:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/virtual devices">virtual devices</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/virtual applications">virtual applications</category>
      <category domain="http://securityratty.com/tag/subsequent virtual world">subsequent virtual world</category>
      <category domain="http://securityratty.com/tag/virtual environments">virtual environments</category>
      <category domain="http://securityratty.com/tag/non-virtual">non-virtual</category>
      <category domain="http://securityratty.com/tag/virtual machine">virtual machine</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/430031380/horses-ass-approach-to-virtualization_23.html">A horse's ass approach to virtualization security - Part 3 - Data is the "constant"</source>
    </item>
    <item>
      <title><![CDATA[Critical Flaws Patched In Opera 9.61, New Zero-day Vulnerability Remains Unpatched]]></title>
      <link>http://securityratty.com/article/08b28c8efcd3e5bd944c65c603c869da</link>
      <guid>http://securityratty.com/article/08b28c8efcd3e5bd944c65c603c869da</guid>
      <description><![CDATA[New Opera 9.61 makers correct an issue where History Search could be used to reveal browser history (rated extremely severe). Also fixed: a Fast Forward bug that allows cross-site scripting (highly...]]></description>
      <content:encoded><![CDATA[New Opera 9.61 makers correct an issue where History Search could be used to reveal browser history (rated extremely severe). Also fixed: a Fast Forward bug that allows cross-site scripting (highly severe) and an information disclosure flaw in news feeds (also highly severe). On the same day Opera shipped a browser update with patches for [...]]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 07:24:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/opera">opera</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/reveal browser history">reveal browser history</category>
      <category domain="http://securityratty.com/tag/history">history</category>
      <category domain="http://securityratty.com/tag/highly severe">highly severe</category>
      <category domain="http://securityratty.com/tag/day opera">day opera</category>
      <category domain="http://securityratty.com/tag/fast forward bug">fast forward bug</category>
      <category domain="http://securityratty.com/tag/information disclosure flaw">information disclosure flaw</category>
      <category domain="http://securityratty.com/tag/news feeds">news feeds</category>
      <source url="http://cyberinsecure.com/critical-flaws-patched-in-opera-961-new-zero-day-vulnerability-remains-unpatched/">Critical Flaws Patched In Opera 9.61, New Zero-day Vulnerability Remains Unpatched</source>
    </item>
    <item>
      <title><![CDATA[The High Cost of Being Wrong: Why Data Detection Matters]]></title>
      <link>http://securityratty.com/article/3955f2f7da3fc70f757fc4bdf39c17c5</link>
      <guid>http://securityratty.com/article/3955f2f7da3fc70f757fc4bdf39c17c5</guid>
      <description><![CDATA[Imagine you see a car stopped on some train tracks, and you hear a train coming. How do you react? Do you ignore the sound of the train, thinking it wont hit the car? In that same vein, not having an...]]></description>
      <content:encoded><![CDATA[<p>Imagine you see a car stopped on some train tracks, and you hear a train  coming. How do you react? Do you ignore the sound of the train, thinking it  won&rsquo;t hit the car? In that same vein, not having an <strong>accurate</strong><strong> data loss prevention (DLP</strong>) <strong>solution</strong> in place within your  organization is akin to standing by and watching that train wreck about to  happen &ndash; all while pretending you can&rsquo;t see what&rsquo;s going on even though the  train&rsquo;s horn is blaring.</p>
<p>In my ten years of experience in the search and categorization space, I  can tell you that the risk of a DLP software policy allowing <strong>false negatives</strong>, when sensitive  documents are missed by the policy and considered safe, <strong>is potentially extremely costly to a company...</strong>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 04:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/train tracks">train tracks</category>
      <category domain="http://securityratty.com/tag/train">train</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/dlp software policy">dlp software policy</category>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/train wreck">train wreck</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/trains horn">trains horn</category>
      <category domain="http://securityratty.com/tag/false negatives">false negatives</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1372">The High Cost of Being Wrong: Why Data Detection Matters</source>
    </item>
    <item>
      <title><![CDATA[Given the Current Economic Turmoil, What Should IT Managers Do?]]></title>
      <link>http://securityratty.com/article/c3cb795253913d9e8117ca429595355f</link>
      <guid>http://securityratty.com/article/c3cb795253913d9e8117ca429595355f</guid>
      <description><![CDATA[Gartner's Compliance &amp; Risk Management Research Community met recently and considered what IT managers should do given the economic turmoil spreading around the world

What started as a problem with...]]></description>
      <content:encoded><![CDATA[Gartner's Compliance & Risk Management Research Community met recently and considered what IT managers should do given the economic turmoil spreading around the world.<br />
<br />
What started as a problem with risky mortgages in hot real estate markets in the United States has spread to Wall Street with a devastating impact on the financial health and well being of a number of banks and an insurance company. Each day, the turmoil spreads, first to the equity and commodity markets where investors and speculators attempt to preserve what capital remains. Next, the central banks and governments rush in with an infusion of liquidity in an attempt to keep the money flowing through the world's financial market.<br />
<br />
The media commentary on the current financial crisis sounds the tone that all the laws of economics and free markets no longer apply. The reporters sound as if the next developments will be Mother Nature suspending the laws of physics and gravity. Against this backdrop, CIOs and IT managers wonder, "What do we do?"<br />
<br />
There is no denying that business as usual is not currently happening. To speculate or attempt to deal with the regulatory fallout that will follow this financial crisis is currently a waste of time. The central focus that CIOs must address now is what impact will this financial crisis have on IT in the next budget cycle. Also, how can IT help the enterprise demonstrate trustworthiness to key stakeholders, maintain critical functions that drive revenue and cash flow, and focus on the needs of the people who work for your organization.<br />
<br />
At the heart of the current financial crisis is a lack in confidence in the credit markets. Government officials report that interbank lending has ground to a halt, which prompted the U.S. Federal Reserve to step in on 7 October 2008 and offer direct short term lending to U.S. corporations. <br />
<br />
First, to combat this lack of confidence permeating the market, enterprises should take extraordinary means to increase their financial transparency and demonstrate that they have the ability to meet their obligations to creditors, customers, and the communities where they are located. Senior management must develop and exercise a voice in the public policy dialog immediately - and voluntarily. Do not wait for Congressional subpoenas, shareholder meetings, or ambush interviews by the media. Tell the world, honestly, about the state of your company and its plans for the near term and the long view.<br />
<br />
Second, everyone must develop a laser-like focus on the organization's value proposition, those intangible reasons that define why your enterprise exists. To leverage an old cliché, every oar must be in the water and pulling in the same direction. The goal is not just to make it to the finish line, but to survive. Ancillary or tertiary projects must be postponed for a later time; and tasks that improve customer service, remove friction from processes, and increase cash flow should be top priorities.  <br />
<br />
Finally, think about the people who work for you. No doubt they are scared by the uncertainty about the future. Management must be honest and open in keeping the rank and file apprised of the organization's situation. They should be encouraged to communicate that information in a timely fashion with friends and neighbors in the community. Management should be extremely sensitive to non-work related issues that may have an impact on employee morale and well being. The most obvious is related to housing, mortgage default and potential foreclosure. However, it can extend beyond the most obvious issues. The problem with short-term lending is also having an impact on some governmental agencies, and some school districts are cutting back to only four days of instruction, forcing many parents to scramble and find new daycare arrangements. ]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 07:38:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial crisis">financial crisis</category>
      <category domain="http://securityratty.com/tag/current financial crisis">current financial crisis</category>
      <category domain="http://securityratty.com/tag/increase cash flow">increase cash flow</category>
      <category domain="http://securityratty.com/tag/increase">increase</category>
      <category domain="http://securityratty.com/tag/central focus">central focus</category>
      <category domain="http://securityratty.com/tag/cash flow">cash flow</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/senior management">senior management</category>
      <category domain="http://securityratty.com/tag/obvious issues">obvious issues</category>
      <source url="http://blog.gartner.com/blog/security.php?x=0&amp;itemid=3968">Given the Current Economic Turmoil, What Should IT Managers Do?</source>
    </item>
    <item>
      <title><![CDATA[Q&A: Threats to the US critical communications infrastructure]]></title>
      <link>http://securityratty.com/article/3ac65876027ae352d58b61c59fb5c4f4</link>
      <guid>http://securityratty.com/article/3ac65876027ae352d58b61c59fb5c4f4</guid>
      <description><![CDATA[Paul Parisi is the CTO of DNSstuff.com and has an extremely broad and deep technical background offering reality based solutions to everyday issues. In this interview he discusses the biggest...]]></description>
      <content:encoded><![CDATA[Paul Parisi is the CTO of DNSstuff.com and has an extremely broad and deep technical background offering reality based solutions to everyday issues. In this interview he discusses the biggest threats ...]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 12:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reality based solutions">reality based solutions</category>
      <category domain="http://securityratty.com/tag/deep technical background">deep technical background</category>
      <category domain="http://securityratty.com/tag/extremely broad">extremely broad</category>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <category domain="http://securityratty.com/tag/everyday issues">everyday issues</category>
      <category domain="http://securityratty.com/tag/paul parisi">paul parisi</category>
      <category domain="http://securityratty.com/tag/dnsstuff">dnsstuff</category>
      <category domain="http://securityratty.com/tag/cto">cto</category>
      <category domain="http://securityratty.com/tag/discusses">discusses</category>
      <source url="http://www.net-security.org/article.php?id=1182">Q&amp;A: Threats to the US critical communications infrastructure</source>
    </item>
    <item>
      <title><![CDATA[A Life or Death InfoSec Subversion]]></title>
      <link>http://securityratty.com/article/ce84889e3d8b870803c3f3d97330cfdd</link>
      <guid>http://securityratty.com/article/ce84889e3d8b870803c3f3d97330cfdd</guid>
      <description><![CDATA[Details about failures of complex and well-implemented information-based attacks on systems are extremely difficult to obtain. However, here the authors examine a real-life analoguean information...]]></description>
      <content:encoded><![CDATA[Details about failures of complex and well-implemented information-based attacks on systems are extremely difficult to obtain. However, here the authors examine a real-life analogue—an information attack on a highly complex security system, that of the Colombian guerrilla group FARC. This operation included a man-in-the-middle attack, targeted denial of service (DoS), and authentication subversion. The attack on FARC's communications structure is interesting not only because of its electronic and analog components, but also because it was a life or death matter. The authors examine the hostages' liberation from an information security perspective, compiling data from several Colombian newspapers and magazines and using the most accepted version of the events.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=344380c94465538d8840535190445e21"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=344380c94465538d8840535190445e21"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=344380c94465538d8840535190445e21" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/authors examine">authors examine</category>
      <category domain="http://securityratty.com/tag/information security perspective">information security perspective</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/communications structure">communications structure</category>
      <category domain="http://securityratty.com/tag/death matter">death matter</category>
      <category domain="http://securityratty.com/tag/colombian guerrilla">colombian guerrilla</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/colombian newspapers">colombian newspapers</category>
      <category domain="http://securityratty.com/tag/extremely difficult">extremely difficult</category>
      <source url="http://www.pheedo.com/click.phdo?i=344380c94465538d8840535190445e21">A Life or Death InfoSec Subversion</source>
    </item>
  </channel>
</rss>
