<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fearful]]></title>
    <link>http://securityratty.com/tag/fearful</link>
    <description></description>
    <pubDate>Thu, 17 Jan 2008 04:35:09 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rational Risk Management, Angry Italians, and Irrational Security Analysts]]></title>
      <link>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</link>
      <guid>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</guid>
      <description><![CDATA[Hope you all had a great weekend. I had meant to point you earlier to a FAIR analysis that Chris Hayes did over at his Blog . But Ive been a little busy, and before I could mention it, Stuart King put...]]></description>
      <content:encoded><![CDATA[<p>Hope you all had a great weekend.  I had meant to point you earlier to a <strong><a href="http://risktical.com/2008/11/06/security-template-exception-part-2-%E2%80%93-the-assessment/">FAIR analysis that Chris Hayes did over at his Blog</a></strong>.  But I&#8217;ve been a little busy, and before I could mention it, Stuart King <strong><a href="http://www.computerweekly.com/blogs/stuart_king/2008/11/ive-written-up-a-report.html">put up a kind of angry response</a></strong> on his ComputerWorld blog.  Snark aside, there are a couple of other really troubling aspects of Stuart&#8217;s reaction to Chris&#8217; analysis that I thought we could talk about this morning.</p>
<blockquote><p>The problem is that (Chris&#8217; analysis is) completely impractical. I&#8217;ll take a recent, and fairly typical situation as an example. I was taking issue with the manner in which remote access was being provisioned for a third party vendor to connect to a system hosted by one of our European business units. To cut a long story short, it was not only a breach of policy but highly insecure. I wanted the access to be disconnected, the business unit director wanted my risk assessment. And he didn&#8217;t want to wait for it.</p>
<p>To quote Chris Hayes, spending time on working out <em> <strong>the expected effectiveness of controls, over a given timeframe, as measured against a baseline level of force </strong></em>was not going to pacify an angry Italian fearful that my decision was going to cost him money. He wanted my explanation of the risk and more importantly, what I was going to offer as a solution to keep his business functioning</p></blockquote>
<p>As Chris is someone who actually does this for a living in a large company, and this is typical of his actual day job, I really find Stuart&#8217;s &#8220;impractical&#8221; comment to be, um, misinformed.</p>
<p>Also, I think Stuart mistakes the purpose of a risk analysis.  The purpose of the risk analysis is not to force someone to be &#8220;secure&#8221;, but to provide knowledge for decision making.  Using it as a &#8220;hammer&#8221; to knock in the nail of your personal risk tolerance impairs efficiency and in the long run retards &#8220;security&#8221; as it creates political resentment.  Seriously, who cares if something might violate policy or not in a pre-implementation discussion?  Policies are not stone tablets handed down from on high, they are state-in-time codification of the <em><strong>data owners </strong></em>risk tolerance.  This risk tolerance changes sometimes, and that&#8217;s OK.</p>
<p>To that extent, I appreciate (and I&#8217;m sure Chris does, as well) that risk analysis does not create rationality in the data owner.  Someone who sees you as a speedbump on the route to progress they may not be ready to appreciate your point of view even if it is stated in the most rational manner possible.   But it&#8217;s worth noting (and Stuart&#8217;s example is indicative of this point) that <em><strong>risk analysis does not create rationality in the analyst, either</strong></em>.  If one is being so &#8220;security minded&#8221; as to ignore the risk tolerance of the business owner - we&#8217;re bound to get a reaction similar to that Stuart encountered.  In fact, a practical risk analysis like Chris performed on his blog, done in 30 minutes, should identify the critical point of disagreement between Stuart and the data owner (again, Stuart doesn&#8217;t own the data, the agitated Italian does).</p>
<p>But let&#8217;s stay rational and open to alternatives to what Chris offers.  Stuart states his approach to risk analysis as:</p>
<blockquote><p>When I need to document a risk assessment I use a very simple form: list the threats, state the level of vulnerability, list the associated operational costs and potential revenue hits. High, medium, or low risk? Describe the controls and options. Write up who needs to do what, and how much of their time it&#8217;s going to take. Job done.</p></blockquote>
<p>At first glance, I don&#8217;t think what Chris has done is any less efficient, and it provides greater insight (using Frequency and Capability instead of just &#8216;listing the threats&#8217;).  But what is key here is that Chris&#8217; approach is consistent and defensible.  Less generous risk geeks and CSO&#8217;s I know would have no little difficulty with Stuart&#8217;s approach.  But to particularly answer Stuart&#8217;s main objection (impracticality) I would offer that with practice, Chris&#8217; work is probably quicker and easier than Stuart&#8217;s described process as it eliminates much of the ambiguity an immature risk analysis creates - reducing the need for further discussion and arguments with data owners (regardless of disposition or nationality).</p>
<p>Finally the irony of Stuart&#8217;s post is that the reason he had this confrontation may in fact be because he was incapable of bringing a salient model for risk to the table, one that identified the factors that create risk and developed a defensible belief statement concerning risk.   We&#8217;ll never know if one would have helped him in this isolated instance, but I can tell you that in organizations like Chris&#8217;, good risk models and strong risk anlayses create operational efficiencies, reduce costs, and streamlines intra-departmental communications.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 13:43:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk tolerance">risk tolerance</category>
      <category domain="http://securityratty.com/tag/risk models">risk models</category>
      <category domain="http://securityratty.com/tag/practical risk analysis">practical risk analysis</category>
      <category domain="http://securityratty.com/tag/strong risk anlayses">strong risk anlayses</category>
      <category domain="http://securityratty.com/tag/generous risk geeks">generous risk geeks</category>
      <category domain="http://securityratty.com/tag/immature risk analysis">immature risk analysis</category>
      <category domain="http://securityratty.com/tag/quote chris hayes">quote chris hayes</category>
      <category domain="http://securityratty.com/tag/chris hayes">chris hayes</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=520">Rational Risk Management, Angry Italians, and Irrational Security Analysts</source>
    </item>
    <item>
      <title><![CDATA[Innovators, Imitators and Idiots]]></title>
      <link>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</link>
      <guid>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</guid>
      <description><![CDATA[Charlie Rose interviews Warren Buffett


Charlie Rose
And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage. We just lost sight...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;">Charlie Rose <a href="http://www.cnbc.com/id/26982338/page/2/">interviews</a> Warren Buffett:</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage.&#0160; We just lost sight of risk and leverage of what was appropriate?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.&#0160; Again, because it pays off for a while.&#0160; You know, you can lose leverage, and it&#39;s the only way a smart guy can go broke.&#0160; If you owe money, you can&#39;t pay them out.&#0160; You just pay for everything, you do smart things, you eventually get very rich.&#0160; If you do smart things and use leverage and do one wrong thing along the way, it could wipe you out, because anything times zero is zero.&#0160; But it&#39;s reinforcing when the people around you are doing it successfully, you&#39;re doing it successfully, and it&#39;s a lot like Cinderella at the ball.&#0160; I mean you know at midnight everything is going to turn to pumpkins and mice; right?&#0160; But if the evening goes along, I mean, you know, the guys look better all the time, the music sounds better, it&#39;s more and more fun, you think why the hell should I leave at quarter of 12.&#0160; I&#39;ll leave at two minutes to 12.&#0160; But the trouble is, there are no clocks on the wall.&#0160; And everybody thinks they&#39;re going to leave at two minutes to 12.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating <a href="http://1raindrop.typepad.com/1_raindrop/2007/11/dhandho-infosec.html">risk and uncertainty</a>. As our current financial situation shows, its a hard thing to pull off</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And should wise people have known better?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">People should always know better.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">I mean people -- people don&#39;t get -- they don&#39;t get smarter about things that get as basic as greed and you can&#39;t stand to see your neighbor getting rich.&#0160; You know you&#39;re smarter than he is, and he&#39;s doing these things, you know, and he&#39;s getting rich, and your spouse is getting unhappy with you because you aren&#39;t doing -- pretty soon you start doing it.&#0160; And so you get what I call the natural progression, the three Is.&#0160; The innovators, the imitators, and the idiots.&#0160; And that&#39;s what happens.&#0160; Everybody just kind of goes along.&#0160; And you look kind of silly if you disagree.&#0160; I mean, you know, you could have these crazy Internet valuations in the late 1990s, but they prove themselves out in the market.&#0160; The next day they were selling for more than they were the day before, and people said, you know, you&#39;re crazy if you don&#39;t get in on this.&#0160; So it&#39;s very human.&#0160; Now, with housing it&#39;s something even more dramatic than that, because most people aspire to own their own home.&#0160; And if you really think that houses prices are going to go up next year and the year after, you feel if I don&#39;t buy it this year, I&#39;m going to have to buy it next year.&#0160; That&#39;s not true of an Internet stock.&#0160; But it&#39;s true of a home.&#0160; And when somebody makes it very easy for you to do it by saying you don&#39;t really have to put up my money, you can lie about your income a little, or we&#39;ll give you 100 percent mortgage, you&#39;re going to do it, because everybody that&#39;s done it has been proven right.&#0160; You have what they call social tools, and, you know, you&#39;re going to feel like an idiot if you didn&#39;t do it, because the house cost more.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system.</span></div><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Oh, I think confidence will come back.&#0160; I will tell you this.&#0160; This country is going -- be living better ten years from now than it is now.&#0160; It will be living better in 20 years from now than ten years from now.&#0160; The ingredients that made this country, you know, the miracle of the world -- I mean we had a seven for one improvement in the average American standard of living in the 20th century.&#0160; Now, we had the great depression, we had two world wars, we had the flu epidemic.&#0160; You know, we had oil shock.&#0160; You know, we had all these terrible things happen.&#0160; But something about the American system unleashed more and of a potential to human beings over that hundred years so that we had a seven for one improvement in -- there&#39;s never been any -- I mean, you have centuries where if you&#39;ve got a 1 percent improvement, then it&#39;s something.&#0160; So we&#39;ve got a great system.&#0160; And we&#39;ve got more productive capacity now than we ever have.&#0160; The American worker is more productive than he&#39;s ever been.&#0160; We&#39;ve got more people to do it.&#0160; We&#39;ve got all the ingredients for a sensational future.&#0160; It&#39;s just that right now the athlete&#39;s on the floor.&#0160; But we -- this is a super athlete.</span></p></blockquote><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Again, we want to look at risk events in a broader, long term context. In Buffett&#39;s words its - &quot;be fearful when others are greedy and greedy when others are fearful.&quot; As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* Buffett&#39;s partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive.</span></div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/oeprational risk">oeprational risk</category>
      <category domain="http://securityratty.com/tag/risk events">risk events</category>
      <category domain="http://securityratty.com/tag/risk-reward balance">risk-reward balance</category>
      <category domain="http://securityratty.com/tag/wise people">wise people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/buffett raises">buffett raises</category>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/blind risk acceptance">blind risk acceptance</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/innovators-imitators-and-idiots.html">Innovators, Imitators and Idiots</source>
    </item>
    <item>
      <title><![CDATA[$13 Billion of U.S. Taxpayers Money was Stolen or Wasted in Iraq.]]></title>
      <link>http://securityratty.com/article/e47ddb39bd9befd964ed4262d0b883f6</link>
      <guid>http://securityratty.com/article/e47ddb39bd9befd964ed4262d0b883f6</guid>
      <description><![CDATA[This article in yesterday's &quot;Washington Post&quot; was sickening to read but hardly comes as a surprise

It is also sad to read that there was most likely involvement by Iraqi Government officials and U.S....]]></description>
      <content:encoded><![CDATA[This article in yesterday's <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/22/AR2008092202053.html">"Washington Post" </a>was sickening to read but hardly comes as a surprise.<br /><span id="fullpost"><br />It is also sad to read that there was most likely involvement by Iraqi Government officials and U.S. contractors.  The investigator who testified as to the waste and theft was fearful of his life as 32 of his fellow investigative co-workers have been killed.  <br /></span><br />One scheme involved officials from the Iraqi Defense Ministry setting up a front company that received $1.7 Billion in U.S. funds to buy guns, armoured vehicles and other equipment.  Only a small percentage was ever purchased and in one case, they had bullet-proof vests delivered that were defective and useless.<br /><br />In another case involving Iraqis and U.S. contractors, $24.4 million was spent on an electricity project that "only existed on paper".  The worst part was that money sent to the Defense Ministry was discovered to have been diverted to Al-Qaeda and found its way to bank accounts in Jordan and other places.<br /><br />Let us hope the Government spends the proposed $700 Billion bail out funds in a more responsible and accountable manner.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 00:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/billion">billion</category>
      <category domain="http://securityratty.com/tag/iraqi defense ministry">iraqi defense ministry</category>
      <category domain="http://securityratty.com/tag/defense ministry">defense ministry</category>
      <category domain="http://securityratty.com/tag/iraqi government officials">iraqi government officials</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/billion bail">billion bail</category>
      <category domain="http://securityratty.com/tag/fellow investigative co-workers">fellow investigative co-workers</category>
      <category domain="http://securityratty.com/tag/funds">funds</category>
      <category domain="http://securityratty.com/tag/front company">front company</category>
      <source url="http://www.thebulletproofblog.com/2008/09/13-billion-of-us-taxpayers-money-was.html">$13 Billion of U.S. Taxpayers Money was Stolen or Wasted in Iraq.</source>
    </item>
    <item>
      <title><![CDATA["many of Colt's clients" affected by breach, CNET included]]></title>
      <link>http://securityratty.com/article/3313abd868212bd3a9ed98811169e851</link>
      <guid>http://securityratty.com/article/3313abd868212bd3a9ed98811169e851</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/13/08

Organization
CNET Networks, Inc. (&quot;CNET

Contractor/Consultant/Branch
Colt Express Outsourcing Services, Inc. (&quot;Colt

Victims
current and former...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/colt.jpg" width="78" align="right" height="69"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/13/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.cnetnetworks.com/">CNET Networks, Inc. ("CNET")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.colthr.com/">Colt Express Outsourcing Services, Inc. ("Colt")</a><br><br><span style="font-weight: bold;">Victims:</span><br>"current and former employees and their dependants"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"around 6,500"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"first names, last names, date of birth, Social Security numbers, address, employer, hire date, benefits group numbers, and relationship to the policy holder"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Colt informed our client by this letter that on Memorial Day, Monday, May 26, 2008, Colt's offices in Walnut Creek, California were burglarized.&nbsp; Certain computer equipment was taken which contains the human resources data of several of their clients, including CNET.&nbsp; The theft of this equipment may have compromised the personal information of our client's current and former employees and their dependants, and our client is working to understand the extent of any exposure for its employees."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.oag.state.md.us/idtheft/Breach%20Notices/ITU-153493.pdf">Maryland State Attorney General breach notification</a><br><a href="http://www.pcworld.com/businesscenter/article/147460/cnet_employees_notified_after_data_breach.html">PCWorld</a> <br><a href="http://www.webpronews.com/topnews/2008/06/24/cnet-affected-by-security-breach">WebProNews</a> <br><a href="http://www.pogowasright.org/article.php?story=20080619103835325">PogoWasRight</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Maryland State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>On June 6, 2008, CNET received the attached letter from Colt Express Outsourcing Services, Inc., ("Colt") who has provided our client with employee benefit plan administrative services for the past 8 years.<br><br>Colt informed our client by this letter that on Memorial Day, Monday, May 26, 2008, Colt's offices in Walnut Creek, California were burglarized.<br><span style="font-style: italic;">[Evan] Uh Oh!, this is starting to read like and smell like the </span><a style="font-style: italic;" href="http://breachblog.com/2008/02/11/asi.aspx">ASI breach</a><span style="font-style: italic;"> reported in February.</span><br><br>The breach occurred on Memorial Day, Monday, May 26, 2008, between approximately 4:30 p.m. and 5:00 p.m. PST, when someone broke into Colt Express's office at 2125 Oak Grove Road, Suite 210, Walnut Creek, California, 94598<br><br>Certain computer equipment was taken which contains the human resources data of several of their clients, including CNET. <br><span style="font-style: italic;">[Evan] According to a CNET spokesperson, via PogoWasRight.org, the "computer equipment" did not employ encryption to protect the information.&nbsp; Encryption could have been a prudent control in a defense-in-depth approach, a mitigating control to protect information against a physical break-in and theft.</span><br><br>The theft of this equipment may have compromised the personal information of our client's current and former employees and their dependants, and our client is working to understand the extent of any exposure for its employees.<br><span style="font-style: italic;">[Evan] Not "may have", but did.&nbsp; Information security and control can no longer be reasonably assured, which in my book constitutes a compromise.</span><br><br>Colt has also informed us that they reported the break-in to Walnut Creek police and to REACT High Tech Crimes Task Force in Silicon Valley when they discovered the burglary and that there is an ongoing criminal investigation.<br><br>report number 08-12367<br><br>In speaking directly with the Walnut Creek Police on June 12, 2008, Officer Greg Leonard, the primary investigator for the incident informed us that they are not aware of any misuse of personal information as a result of this theft at this time.<br><br>The information included first names, last names, Social Security numbers, address, employer, hire date, benefits group numbers, and relationship to the policy holder for around 6,500 of our client's current and former employees, and their dependants.<br><br><img src="http://images.quickblogcast.com/95781-88451/cnetnumbers.jpg" width="435" border="0"><br><br>some of your current and former employees and their dependants during the time period of 01-Aug-00 to present.<br><span style="font-style: italic;">[Evan] August 1st, 2000 through May 26th, 2008 is almost eight years of information!&nbsp; I wonder what the data retention policy states at Colt, supposing one exists.</span><br><br>We do not have any understanding that the computers stored personal health information.<br><br>Our client is providing written notification to all affected individuals at the last home address we have on record<br><br>Although there is no evidence of misuse of the data to date, our client's notification will also inform affected individuals that it has contracted with Equifax to provide Equifax Credit Watch Gold with 3 in 1 Monitoring service, including identity theft insurance, for one full year at no cost.<br><span style="font-style: italic;">[Evan] I have said it before, and I will say it again.&nbsp; One year of semi-effective protection should not be considered adequate for information that has a usable life that far exceeds this time frame.&nbsp; It should be pointed out howevere that it is better than nothing and the company is not required to offer it.</span><br><br>Although we are not aware of the exact number of individuals affected by the Colt breach, we do know that we were among many of Colt's clients whose data were stored on the stolen computers.<br><span style="font-style: italic;">[Evan] The word that catches my attention almost immediately is "many".&nbsp; How many clients will be affected in the end?&nbsp; PogoWasRight is already following up on another company that may be affected.</span><br><br>Colt Express takes the protection of its customer and personal information very seriously.<br><span style="font-style: italic;">[Evan] Making a statement like this and the demonstration by action are two entirely different matters.&nbsp; An organization such as Colt Express creates, collects, stores and transfers very sensitive information as an integral part of their business.&nbsp; This being said, I wonder why this information was not protected better.</span><br><br>Colt Express is taking steps to ensure that a potential data security breach does not occur in the future.<br><br>We installed an alarm system on Friday, May 30th.<br><span style="font-style: italic;">[Evan] Are we to assume that there was none prior to May 30th?&nbsp; I hope not!</span><br><br>Colt Express is looking into what additional steps may be taken to provide enhanced security.<br><br>By this letter and enclosures, we are providing you with all the information we believe you need, and that we are able to give you.&nbsp; We do not have the resources, financial and otherwise, to assist you further.<br><span style="font-style: italic;">[Evan] Say huh?</span><br><br>Towards the end of last year, our customer base was reduced to an unsustainable level.<br><br>Colt has been in the process of going out of business, while at the same time providing time for remaining customers to find alternative solutions.<br><span style="font-style: italic;">[Evan] This is a twist.&nbsp; How long has the company been in the process of going out of business and was CNET (and the "many" other clients) aware of it?&nbsp; If so, this could have been a sign that could have spurred some action.&nbsp; Then again, maybe not.</span><br><br><img src="http://images.quickblogcast.com/95781-88451/cnetcolthomepage.jpg" width="241" border="0"><br><font size="1">http://www.colthr.com/</font><br><br><br><br>Those decisions are now final.<br><br>We are firmly committed to protecting all of the information that is entrusted to us both before and after we close down.<br><br>We sincerely apologize for the inconvenience and concern this incident will cause.<br><br><span style="font-weight: bold;">Commentary:</span><br>As I stated earlier in the post, I am a little fearful that this breach could end up as significant or more significant (in terms of number of people and organizations affected) than the <a href="http://breachblog.com/2008/02/11/asi.aspx">ASI breach</a> reported in February.&nbsp; The ASI breach was the 2nd most popular posting in The Breach Blog's history at the time, based on number of online page reads and comments posted.<br><br>This breach has got me thinking.&nbsp; Some of the key risks that we address with the organizations we work with are those involving the management of vendor and third-party relationships.&nbsp; Ideally, information security personnel are involved throughout the relationship, including the initial vendor feasibility assessment.&nbsp; Vendors and "trusted" third-parties need to be held to the same high security standards that we set for the organization.&nbsp; The methods in which this can be accomplished vary from organization to organization, but typically include risk assessments (initial and ongoing), information security requirements built into contractual language, and enforcement actions if necessary.&nbsp; If a vendor is not encrypting confidential information or employing burglar alarms, it is known (and hopefully addressed). <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/25/colt.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 07:25:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/protect information">protect information</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/information security requirements">information security requirements</category>
      <category domain="http://securityratty.com/tag/colt">colt</category>
      <source url="http://breachblog.com/2008/06/25/colt.aspx">"many of Colt's clients" affected by breach, CNET included</source>
    </item>
    <item>
      <title><![CDATA[Sometimes danger lurks right under our nose.]]></title>
      <link>http://securityratty.com/article/60d561dc35d92bd6e3f06ac8f71c0ba7</link>
      <guid>http://securityratty.com/article/60d561dc35d92bd6e3f06ac8f71c0ba7</guid>
      <description><![CDATA[When Executive Protecion Specialists think and speak about &quot;Threat Assessment&quot;, they are usually focusing on a known or suspected danger that may prove life-threatening. Sometimes, that danger may...]]></description>
      <content:encoded><![CDATA[When Executive Protecion Specialists think and speak about "Threat Assessment", they are usually focusing on a known or suspected danger that may prove life-threatening.  Sometimes, that danger may already have made itself at home and is silently destroying lives and eating away at victims like a cancerous growth. <br /><span id="fullpost"><br />One such story was highlighted by the "Washington Post Magazine" on May 25th, 2008.  It involved a young girl who had been molested and raped by her own father.  A man who was something of a hero to many.  A man who had walked side by side with Dr. martin Luther king and who was only a few feet away from the Civil Rights leader when he was assasinated.  That man is James Bevel.<br /></span><br /><br />I had the pleasure of listening to Col. Dave Grossman speaking at UCLA last April. He was eloquent in his description of how young lives are taken and families estroyed by School killings.  He also spoke about those who prey on the less suspecting.  He equated it to the Wolves hunting down and eating sheep.  Mr. Bevel appears to be one of those parasitic wolves.  <br /><br />For years he raped his little daughter, telling her it was something of an "experiment".  In his mind, he didn't think that it mattered.  His unfathomable belief (and apparently remains the same until this day) is that all women are prostitutes until they reach a certain age, when sex is set aside for procreation.  This beleif allowed him to allegedly rape his eight year old daughter on many occassions.<br /><br />His daughter, Aaralyn Mills, finally found the courage to step foward and contact the Police in 2005.  She assisted the Leesburg authorities to tape record her conversation with her father.  In that conversation, James Bevel admitted raoping his daughter and that it was part of a scientific process.  Unfortunately, her mother, like many other mothers, did not want or couldn't face the truth.  This gave the big, bad wolf all the space he needed to desecrate the little sheep.  <br /><br />Sadly, men like this are living throughout our communities.  they come in all shapes, sizes nd colors.  Some are Doctors, Community leaders, Priests, Police Officers, Electricians and Preachers.  If you have been entrusted with the job of protecting an innocent lamb, be a strong and fearful sheepdog and protect your flock, with your very life if need be.  Be brave like Aaralyn Mills.  She stepped forward at this time in her life because her father who has many children with many different women has now a young daughter and her half-siter is afraid that he will rape her too.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 18:23:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/daughter">daughter</category>
      <category domain="http://securityratty.com/tag/danger">danger</category>
      <category domain="http://securityratty.com/tag/aaralyn mills">aaralyn mills</category>
      <category domain="http://securityratty.com/tag/james bevel">james bevel</category>
      <category domain="http://securityratty.com/tag/allegedly rape">allegedly rape</category>
      <category domain="http://securityratty.com/tag/washington post magazine">washington post magazine</category>
      <category domain="http://securityratty.com/tag/parasitic wolves">parasitic wolves</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/police officers">police officers</category>
      <source url="http://www.thebulletproofblog.com/2008/06/sometimes-danger-lurks-right-under-our.html">Sometimes danger lurks right under our nose.</source>
    </item>
    <item>
      <title><![CDATA[Security Perception: Fear vs Anger]]></title>
      <link>http://securityratty.com/article/96a0f45d27c72e1caf62ec8f9c48c8d1</link>
      <guid>http://securityratty.com/article/96a0f45d27c72e1caf62ec8f9c48c8d1</guid>
      <description><![CDATA[If you're fearful, you think you're more at risk than if you're angry: In the aftermath of September 11th, we realized that, tragically, we were presented with an opportunity to find out whether our...]]></description>
      <content:encoded><![CDATA[<p>If you're fearful, you think you're <a href="http://www.hks.harvard.edu/news-events/publications/insight/management/jennifer-lerner">more at risk</a> than if you're angry:</p>

<blockquote>In the aftermath of September 11th, we realized that, tragically, we were presented with an opportunity to find out whether our lab research could predict how the country as a whole would react to the attacks and how U.S. citizens would perceive future risks of terrorism. We did a nationwide field experiment, the first of its kind. As opposed to the participants in our lab studies, the participants in our nationwide field study did have strong feelings about the issues at stake -- September 11th and possible future attacks -- and they also had a lot of information about these issues as well. We wondered whether the same emotional carryover that we found in our lab studies would occur -- whether fear and anger would still have opposing effects.

<p>In pilot tests, we identified some media coverage of the attacks (video clips) that triggered a sense of fear, and some coverage that triggered a sense of anger. We randomly assigned participants from around the country to be exposed to one of those two conditions -- media reports that were known to trigger fear or reports that were known to trigger anger. Next, we asked participants to predict how much risk, if any, they perceived in a variety of different events. For example, they were asked to predict the likelihood of another terrorist attack on the United States within the following 12 months and whether they themselves expected to be victims of potential future attacks. They made many other risk judgments about themselves, the country, and the world as a whole. They also rated their policy preferences.</p>

<p>The results mirrored those of our lab studies. Specifically, people who saw the anger-inducing video clip were subsequently more optimistic on a whole series of judgments about the future -- their own future, the country’s future, and the future of the world. In contrast, the people who saw the fear-inducing video clip were less optimistic about their own future, the country’s future, and the world’s future. Policy preferences also differed as a function of exposure to the different media/emotion conditions.  Participants who saw the fear-inducing clip subsequently endorsed less aggressive and more conciliatory policies than did participants who saw the anger-inducing clip, even though the clip was only a few minutes long and participants had had weeks to form their own policy opinions regarding responses to terrorism.</blockquote></p>

<p>So, to summarize: we should not be fearful of future terrorist attacks, we should be angry that our government has done such a poor job safeguarding our liberties. And that if we take this second approach, we are more likely to respond effectively to future terrorist attacks.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=O50D2EF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=O50D2EF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=V1oSRIF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=V1oSRIF" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Sun, 23 Mar 2008 09:42:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/potential future attacks">potential future attacks</category>
      <category domain="http://securityratty.com/tag/future attacks">future attacks</category>
      <category domain="http://securityratty.com/tag/future">future</category>
      <category domain="http://securityratty.com/tag/future terrorist attacks">future terrorist attacks</category>
      <category domain="http://securityratty.com/tag/perceive future risks">perceive future risks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/worlds future">worlds future</category>
      <category domain="http://securityratty.com/tag/clip subsequently">clip subsequently</category>
      <category domain="http://securityratty.com/tag/subsequently">subsequently</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/security_percep.html">Security Perception: Fear vs Anger</source>
    </item>
    <item>
      <title><![CDATA[Logging Poll #6 "Which Logs Do You LOOK At?" Analysis]]></title>
      <link>http://securityratty.com/article/e0dd2e601a9e1751299e2793ae9c16ff</link>
      <guid>http://securityratty.com/article/e0dd2e601a9e1751299e2793ae9c16ff</guid>
      <description><![CDATA[This poll on looking at logs poll was relatively popular; lets see what we can learn (live results are also here

First , what are the top 3 log types that people look at? They are
Unix/Linux server...]]></description>
      <content:encoded><![CDATA[<p>This poll on looking at logs&nbsp; poll was relatively popular; lets see what we can learn (live results are also here).</p> <p><a href="http://lh3.google.com/anton.chuvakin/R9B3v893BRI/AAAAAAAADO4/RXwza_K5W_s/image%5B6%5D"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="440" alt="image" src="http://lh3.google.com/anton.chuvakin/R9B3w893BSI/AAAAAAAADPA/PhkAPF9i4H4/image_thumb%5B2%5D" width="459" border="0"></a> </p> <p><strong>First</strong>, what are the top 3 log types that people look at? They are:</p> <ol> <li>Unix/Linux server syslog</li> <li>Web server logs</li> <li>Firewall logs</li></ol> <p>How does that compare with the top 3 log types that people collect (see picture showing results from <a href="http://chuvakin.blogspot.com/2007/10/poll-results-which-logs-do-you-collect.html">my previous poll</a> below)? </p> <p><a href="http://lh3.google.com/anton.chuvakin/R9B32893BTI/AAAAAAAADPI/HrN-K1wDZMY/image%5B8%5D"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="222" alt="image" src="http://lh6.google.com/anton.chuvakin/R9B34s93BUI/AAAAAAAADPQ/fctICLpFYBI/image_thumb%5B4%5D" width="251" border="0"></a> </p> <p>These are:</p> <ol> <li>Unix/Linux server syslog</li> <li>Firewall logs</li> <li>Web server logs</li></ol> <p>Huh? They are the same - doesn't it just make sense? What are the possibilities here?</p> <p>a. People only collect the logs they plan to look at, OR</p> <p>b. People look at logs they collect (duh!).</p> <p>Strangely, I find a) unlikely; I think most people collect more than they can review and that the incident/issue response and compliance needs drive collection more than review or analysis.</p> <p>Another observation is that all of the "big 3" log types are useful for security, operations and compliance and not just for security (like NIDS/NIPS logs). Is that why they are so popular?</p> <p><strong>Second</strong>, I was fearful that "<strong>I only look at whatever logs needed for the incident/issue investigation</strong>" will win. It didn't!!! This to me indicates that proactive log review is not as unpopular as I feared. Good! <a href="http://chuvakin.blogspot.com/2008/02/new-morning-new-logs-life-goes-on.html">It is working</a>.</p> <p><strong>Third</strong>, obviously, nobody (well, 4%...) looks at all logs they collect.</p> <p><strong>Fourth</strong>, much more people look at Unix/Linux logs than Windows server logs (factor of 3x); this is not entirely unexpected and my next poll will drill down into this.\</p> <p><strong>Finally</strong>, I am SHOCKED that people don't look at NIDS/NIPS logs (only 11% do). <em>People, what's wrong with you? :-)</em> Why have you deployed those beasts if you don't look at what they produce? Then again, maybe you haven't :-(</p> <p>Next poll coming up!</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:e7ff1e4a-92e0-4603-a143-4566381d081e" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/logs" rel="tag">logs</a>, <a href="http://technorati.com/tags/polls" rel="tag">polls</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=RTct4hF"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=RTct4hF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=KzUWJVF"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=KzUWJVF" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/247040077" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Mar 2008 12:01:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/logs poll">logs poll</category>
      <category domain="http://securityratty.com/tag/windows server logs">windows server logs</category>
      <category domain="http://securityratty.com/tag/nidsnips logs">nidsnips logs</category>
      <category domain="http://securityratty.com/tag/firewall logs">firewall logs</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/people collect">people collect</category>
      <category domain="http://securityratty.com/tag/web server logs">web server logs</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/247040077/logging-poll-6-logs-do-you-look-at.html">Logging Poll #6 "Which Logs Do You LOOK At?" Analysis</source>
    </item>
    <item>
      <title><![CDATA[Fear Is Unhealthy]]></title>
      <link>http://securityratty.com/article/b094e3e68c5ff92fd0e2aa937227f6b6</link>
      <guid>http://securityratty.com/article/b094e3e68c5ff92fd0e2aa937227f6b6</guid>
      <description><![CDATA[The New York Times writes about a plausible connection between fear and heart disease: Which is more of a threat to your health: Al Qaeda or the Department of Homeland Security
An intriguing new study...]]></description>
      <content:encoded><![CDATA[<p><i>The New York Times</i> writes about a <a href="http://www.nytimes.com/2008/01/15/science/15tier.html?_r=1&scp=1&sq=Fear+Tierney&oref=slogin">plausible connection</a> between fear and heart disease:</p>

<blockquote>Which is more of a threat to your health: Al Qaeda or the Department of Homeland Security?

<p>An intriguing new study suggests the answer is not so clear-cut. Although it’s impossible to calculate the pain that terrorist attacks inflict on victims and society, when statisticians look at cold numbers, they have variously estimated the chances of the average person dying in America at the hands of international terrorists to be comparable to the risk of dying from eating peanuts, being struck by an asteroid or drowning in a toilet.</p>

<p>But worrying about terrorism could be taking a toll on the hearts of millions of Americans. The evidence, published last week in the Archives of General Psychiatry, comes from researchers who began tracking the health of a representative sample of more than 2,700 Americans before September 2001. After the attacks of Sept. 11, the scientists monitored people’s fears of terrorism over the next several years and found that the most fearful people were three to five times more likely than the rest to receive diagnoses of new cardiovascular ailments.</p>

<p>[...]</p>

<p>After controlling for various factors (age, obesity, smoking, other ailments and stressful life events), the researchers found that the people who were acutely stressed after the 9/11 attacks and continued to worry about terrorism -- about 6 percent of the sample -- were at least three times more likely than the others in the study to be given diagnoses of new heart problems.</p>

<p>If you extrapolate that percentage to the adult population of America, it works out to more than 10 million people. No one knows what fraction of them might consequently die of a stroke or heart attack -- plenty of other factors affect heart disease -- but if it were merely 0.0003 percent, that would be higher than the 9/11 death toll.</p>

<p>Of course, statistics of any sort, even when the numbers are rock solid, don’t mean much to people when they’re assessing threats. Risk researchers have found that even when people know the numbers, they’re less worried about death tolls than about how the deaths occur. They have good reasons -- called “rival rationalities” -- for fearing catastrophes that kill large numbers at once because these events affect the whole community and damage the social fabric.</blockquote></p>

<p>It doesn't surprise me that fear of terrorism is more harmful than actual terrorism.  That's the whole point of terrorism: an amplification of fear through the mass media.</p>

<p><a href="http://www.schneier.com/blog/archives/2006/08/what_the_terror.html">Refuse to be terrorized</a>:</p>

<blockquote>The point of terrorism is to cause terror, sometimes to further a political goal and sometimes out of sheer hatred. The people terrorists kill are not the targets; they are collateral damage. And blowing up planes, trains, markets or buses is not the goal; those are just tactics. The real targets of terrorism are the rest of us: the billions of us who are not killed but are terrorized because of the killing. The real point of terrorism is not the act itself, but our reaction to the act.

<p>And we're doing exactly what the terrorists want.</p>

<p>[...]</p>

<p>The surest defense against terrorism is to refuse to be terrorized. Our job is to recognize that terrorism is just one of the risks we face, and not a particularly common one at that. And our job is to fight those politicians who use fear as an excuse to <a href="http://www.schneier.com/essay-045.html">take away</a> our liberties and promote <a href="http://en.wikipedia.org/wiki/Security_theater">security theater</a> that wastes money and doesn't make us any safer.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hy6cf9D"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hy6cf9D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8bVoWiD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8bVoWiD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=zPwrgtD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=zPwrgtD" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 17 Jan 2008 04:35:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people terrorists kill">people terrorists kill</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/actual terrorism">actual terrorism</category>
      <category domain="http://securityratty.com/tag/kill">kill</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/fear">fear</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/fearful people">fearful people</category>
      <source url="http://www.schneier.com/blog/archives/2008/01/fear_is_unhealt.html">Fear Is Unhealthy</source>
    </item>
  </channel>
</rss>
