<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fifty]]></title>
    <link>http://securityratty.com/tag/fifty</link>
    <description></description>
    <pubDate>Sun, 22 Jun 2008 17:58:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links List 11.17.08]]></title>
      <link>http://securityratty.com/article/85b0ee0a0390b793b97cc896d3067a94</link>
      <guid>http://securityratty.com/article/85b0ee0a0390b793b97cc896d3067a94</guid>
      <description><![CDATA[Wow. I think we all know that we can take or leave surveys numbers dont mean a lot without context. In this case the context is the current economic meltdown. The Society for Information Management...]]></description>
      <content:encoded><![CDATA[<p>Wow. I think we all know that we can take or leave surveys – numbers don’t mean a lot without context. In this case the “context” is the current economic meltdown. The Society for Information Management (SIM) released the results of their 2008 IT Trends Survey – predicting an “upbeat” forecast for IT jobs; the HUGE caveat here is that the study was conducted before all the recent economic woes. Apparently organizations are using IT to <a href="http://blogs.zdnet.com/BTL/?p=10765" target="_blank">drive efficiencies, streamline operations, and cut costs</a> rather than just slashing the IT budget to save money during the downturn. What would be a nice follow-up: a quick second survey comparing responses before and after. Regardless Jerry Luftman, SIM vice president of academic affairs, still says the survey results demonstrate “that the overall state of IT remains very strong.”</p>
<p><img style="margin: 5px" src="http://images.google.com/url?q=http://disney-clipart.com/Chicken-Little/Disney-Chicken-Little.jpg&amp;usg=AFQjCNGA4kajmvy1h_lrcRnuywgV7_X0aQ" alt="" width="198" height="201" align="left" />The sky is falling! Trip Chowdhry, the analyst with Global Equities Research who claimed Red Hat was ‘rubbish and the entire LAMP stack is potty, too’ published some eye-opening predictions, predominantly negative, about tech business in Silicon Valley. Now <a href="http://news.cnet.com/8301-13505_3-10094221-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">Chowdhry claims that “almost every VC funded open-source company</a> is struggling and will run out of money within the next six months.” (Probably not the most unbiased guy about open source) Matt Asay argues that organizations in general are struggling, but open-source companies are not that high on the list. (But are they high on the VC “axe” list??) He notes Alfresco, Pentaho and JasperSoft are some of the players with ‘millions in the bank and growing revenue.’ Asay also says Chowdhry has a responsibility to do real due diligence and not create myths. Take that, Chicken Little! (<a href="http://disney-clipart.com/Chicken-Little/Disney-Chicken-Little.jpg" target="_blank"><em>img from Disney-Clipart</em></a>)</p>
<p>We’re not as far behind as we thought we were. Google presented the results of a study they conducted about how IPv6- capable “ordinary users” are at the RIPE meeting in Dubai a few weeks ago. Turns out Apple Macs drive IPv6 penetration in the US. <a href="http://arstechnica.com/news.ars/post/20081113-google-more-macs-mean-higher-ipv6-usage-in-us.html" target="_blank">Fifty-two percent of all IPv6 users in the U.S. own a Mac</a> and use 6to4 (creating IPv6 addresses from an IPv4 address and tunneling packets) – making the US fifth in the list of countries using IPv6. Russia and France took first and second place with .76 and .65 percent IPv6-enabled traffic . The US is at .45 percent. Worldwide, 0.238 percent of Google users’ systems are IPv6-enabled and prefer to use IPv6 over IPv4.</p>
<p>Obama’s win = Google’s win? Apparently Google <a href="http://blogs.cioinsight.com/biztech30/content/2008_campaign/google_vs_microsoft_the_obama_factor.html?kc=rss" target="_blank">CEO Eric Schmidt and President-Elect Obama are very good buddies</a> and “this terrifies Microsoft”. Now competitors are more on guard against Google’s growing empire and popularity. Although Schmidt was mentioned as a possible candidate for the country’s new national CTO position, he said he would not accept the post if asked. I guess that’s one less thing Microsoft has to worry about.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 19:35:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/survey results">survey results</category>
      <category domain="http://securityratty.com/tag/results">results</category>
      <category domain="http://securityratty.com/tag/ipv6 addresses">ipv6 addresses</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/open-source company">open-source company</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/fifty-two percent">fifty-two percent</category>
      <source url="http://blog.sciencelogic.com/links-list-111708/11/2008">Links List 11.17.08</source>
    </item>
    <item>
      <title><![CDATA[Over half of U.K. firms have lost data]]></title>
      <link>http://securityratty.com/article/10f384c32a3393eb84ff4206ec6183f4</link>
      <guid>http://securityratty.com/article/10f384c32a3393eb84ff4206ec6183f4</guid>
      <description><![CDATA[Fifty-five percent of British companies have lost data and 49% of them have had over two breaches in the last two years, according to a new survey of 785 IT...]]></description>
      <content:encoded><![CDATA[Fifty-five percent of British companies have lost data and 49% of them have had over two breaches in the last two years, according to a new survey of 785 IT professionals.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:331716acd8ce8120e96a0d40612dae10:hGWPqNG8nxYHJ4tbJQ%2FEHovx3VHlgGYTCXfWOGsBxLcgSt9rtkwkAsMAZOzZFucUzfC%2FKY6bAT5P'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:aebcd0a2087e4235ca18ce44054c5877:zYroPCJiUZ6BikSuUxm19v5whm2d%2FQonkomI93Qv6X6uUQrCmmfhkI9xP2j%2BeYqgBuCTZG1%2Bf0Ch%2Fw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:8cc7d0a3ec4ac2ea8a5bb75fc0c174fa:6e1j%2BVX3RoWYMqSzqdkZFE9swn3Ud9k3UhgJexyGvfLuBbz%2FlQ7CBxxC2XzKuNXwJiOtX60%2BuQMJMw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7daf4d413081c67186eb1fef1bea428d:OIIUA8bK4mBPpGYY%2FnJf7s3EM1go52IZnWXzjHFEq4hP1jx%2BKAkdQBaU2lojigzg%2FfUYF1JZ2mZ0aw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=fde81d38d5124eb550c990b2a81d6f10"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=fde81d38d5124eb550c990b2a81d6f10"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=fde81d38d5124eb550c990b2a81d6f10" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lost data">lost data</category>
      <category domain="http://securityratty.com/tag/fifty-five percent">fifty-five percent</category>
      <category domain="http://securityratty.com/tag/british companies">british companies</category>
      <category domain="http://securityratty.com/tag/professionals">professionals</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/breaches">breaches</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=fde81d38d5124eb550c990b2a81d6f10">Over half of U.K. firms have lost data</source>
    </item>
    <item>
      <title><![CDATA[On The History of Event Processing: Global Network Monitoring]]></title>
      <link>http://securityratty.com/article/0a39883e48015e3b5b486ebc5391de1e</link>
      <guid>http://securityratty.com/article/0a39883e48015e3b5b486ebc5391de1e</guid>
      <description><![CDATA[In A Short History of Complex Event Processing. Part 1: Beginnings , David Luckham opens his history discussion by saying
Event processing has been going on for more than fifty years
However, in On...]]></description>
      <content:encoded><![CDATA[<p>In <a title="A Short History of Complex Event Processing.  Part 1: Beginnings" rel="bookmark" href="http://complexevents.com/?p=321">A Short History of Complex Event Processing. Part 1: Beginnings</a>, David Luckham opens his history discussion by saying;</p>
<blockquote><p>&#8220;Event processing has been going on for more than fifty years.&#8221;</p></blockquote>
<p>However, in <a href="http://epthinking.blogspot.com/2008/08/on-event-processing-as-discipline-and.html" target="_blank">On Event Processing as a Discipline and Some Subsets</a> another colleague mistakenly blogs,</p>
<blockquote><p><em>&#8220;&#8230; <span>people who dealt in this area [network management and event correlation] have never investigated event processing in the larger sense (e.g. looking at additional patterns), and this area has also not spawned the event processing discipline.&#8221;</span></em></p></blockquote>
<p>If you examine just one page from the <a href="http://pavg.stanford.edu/cep/" target="_blank">CEP history at Stanford</a>, researchers there outlined their view of the future applications for CEP, as follows:</p>
<ul>
<li>Instant Insight  - hierarchical event viewing applied to the Enterprise IT layer.
<ul>
<li><a href="http://pavg.stanford.edu/cep/instantinsightpaper.pdf">Analysing business processes</a></li>
</ul>
</li>
<li><a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt" target="_blank">Network Level Monitoring and Management</a></li>
<li><a href="http://pavg.stanford.edu/ID/">Cyber Security: Network Intrusion Detection</a></li>
<li>Enterprise Monitoring and Management</li>
<li><a href="http://pavg.stanford.edu/cep/final-version-131102.pdf">Modeling and Simulation of Collaborative Business Processes </a></li>
<li>Business Policy Monitoring</li>
<li>Analysis and Debugging of Distributed Systems</li>
</ul>
<p>These applications areas mentioned by Stanford researchers, including Professor Luckham, support and validate our recent discussion <a title="Magic Quadrant for IT Event Correlation and Analysis, 2007" rel="bookmark" href="http://www.thecepblog.com/2008/08/26/magic-quadrant-for-it-event-correlation-and-analysis-2007/"><span style="color: #105cb6;">Magic Quadrant for IT Event Correlation and Analysis, 2007</span></a> where we concluded that <em>&#8220;event correlation and event analysis is Gartner’s closest magic quadrant (MQ)  [...] relates directly to complex event processing (and event processing in general).&#8221;  </em></p>
<p>If you take a detailed look at the 1999 CEP presentation, <a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt" target="_blank">Defeating Large Scale Attacks: Technology and Strategies for Global Network Monitoring</a> you will readily see that our colleagues are incorrect when they says that event correlational and network management folks have never investigated event processing in the &#8220;larger sense&#8221;.  For example, the 1999 slides above, Stanford, slide 6, is titled &#8220;Complex Event Processing,&#8221; defining CEP from the application perspective of event correlation;</p>
<p><em>Complex Event Processing</em></p>
<ul>
<li>Accept network ‘events’ from any source
<ul>
<li>CISCO NetFlow FlowCollector, tcpdump</li>
</ul>
</li>
<li>Correlates events based on content and temporal relationship between events</li>
<li>Event Processing Agents (EPAs) connected in an Event Processing Network (EPNs)</li>
<li>Both post-mortem and real-time processing</li>
</ul>
<p>This single event correlational project example from David&#8217;s team at Stanford examined the challenging event correlation problems in the context of hierarchical events, maps, patterns, visualization tools, event processing models, patterns languages, network management abstraction layers, and more.  Those core event processing problems from this 1999 example, very large and complex then, still exist today and are much more large and complex - precisely why it is called &#8220;complex event processing.&#8221;</p>
<p>It is quite obvious, in just this one example, that many folks have been looking at event correlation as a motivating application for event processing, in a larger context, for a long time, contrary to what our colleagues write in their &#8220;history of event processing&#8221; posts.  </p>
<p>In a future post I will completely debuke these event processing &#8220;history revisionists.&#8221;   I will illustrate very clearly how the history of event processing goes back at least a decade, and perhaps two (twenty years) before the history outlined in posts like <a href="http://epthinking.blogspot.com/2008/08/on-research-and-practice-in-event.html" target="_blank">On Research and Practice in Event Processing</a> and <a href="http://www.eventstreamprocessing.com/cep-history.htm" target="_blank">The History of Complex Event Processing</a>. </p>
<p>David Luckam stated that the art-and-science of event processing goes back around 50 years. </p>
<p>I am not sure I will go all the way back to 1960 in my next post on the history of event processing.  However,  I will go back at least to the early days of Internet Protocol (IP) networking and illustrate why distributed IP networking, network management and network security, is one of the key  motivating factors for what we now call &#8220;event processing&#8221; and &#8220;complex event processing.&#8221;</p>
]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 06:17:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event correlational">event correlational</category>
      <category domain="http://securityratty.com/tag/event correlation problemsin">event correlation problemsin</category>
      <category domain="http://securityratty.com/tag/core event">core event</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/event correlation">event correlation</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/hierarchical event">hierarchical event</category>
      <source url="http://www.thecepblog.com/2008/08/30/on-the-history-of-event-processing-global-network-monitoring/">On The History of Event Processing: Global Network Monitoring</source>
    </item>
    <item>
      <title><![CDATA[Straight Talking Warren Buffett]]></title>
      <link>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</link>
      <guid>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</guid>
      <description><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards

Mr. Buffett...]]></description>
      <content:encoded><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards. <br /><span id="fullpost"><br />Mr. Buffett came straight out and accused Mr. Edwards of soliciting and taking money by deceitful means during his unsuccessful Presidential bid earlier this year.  According to Mr. Buffett, John Edwards knew back then that it was only a matter of time before the media uncovered the story of his mistress and alleged love-child.  <br />  <br /></span><br />Unfortunately, this did not stop him from asking suporters to fund his campaign.  Had people knew about the extra-marital affair, they most likely would not have sent in their hard earned dollars as there was no chance that he could continue in the race once the damning news broke.  Mr. Buffett suggested that Edwards should cut back on a few of those expensive haircuts and return those fifty and one hundred dollar donations that came in from ordinary hard working followers.<br /><br />This sentiment rings true for my industry.  At our training courses, we focus on Ethics at the beginning of the course and it runs throughout the training.  Nobody is saying that we are not human and we do not make mistakes - we all do, but covering up the truth to further your own selfish goals is a practice that would probably even disgust the animal Kingdom - except the reptiles possibly.<br /><br />Thank you Mr. Buffett for being so frank and forthright in this era of sterile political correctness.  This is why I enjoy working with successful business people and despise the empty promises and double-talking of policticians, to whatever party they belong.  To those of you in the security world, again I implore you to never forget that your word is your bond and at the end of the day, your reputation will live on after you are long gone.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/edwards">edwards</category>
      <category domain="http://securityratty.com/tag/john edwards">john edwards</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/successful business people">successful business people</category>
      <category domain="http://securityratty.com/tag/sterile political correctness">sterile political correctness</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/unsuccessful presidential bid">unsuccessful presidential bid</category>
      <category domain="http://securityratty.com/tag/ordinary hard">ordinary hard</category>
      <source url="http://www.thebulletproofblog.com/2008/08/straight-talking-warren-buffett.html">Straight Talking Warren Buffett</source>
    </item>
    <item>
      <title><![CDATA[ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars]]></title>
      <link>http://securityratty.com/article/913d52903ceaedff758808be4b11d5bf</link>
      <guid>http://securityratty.com/article/913d52903ceaedff758808be4b11d5bf</guid>
      <description><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, such as this one , based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy...]]></description>
      <content:encoded><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, <a href="http://www.domainnamenews.com/miscellaneous/icann-board-resolution-kills-domain-tasting/1689">such as this one</a>, based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy change. But there was confusion over exactly what the policy was; most people just assumed it followed the recommendations of the GNSO council from April.  The incomplete information caused some confused analysis such as <a href="http://www.cadna.org/en/newsroom/press-releases/icann-tasting-solution">this from CADNA (the Coalition Against Domain Name Abuse)</a>.

I asked ICANN and they sent me the actual e-mail that they sent out to registrars. It is published below. My analysis of it is in <a href="http://www.eweek.com/c/a/Security/Yes-Domain-Tasting-Will-End/">a column on eWEEK</a>.

<blockquote>
Dear Registrar,

This message is intended to explain how certain decisions that were made by the ICANN Board of Directors at its meeting in Paris last week may affect your registrar.

Specifically, the Board adopted GNSO recommendations on domain tasting that included both budget and non-budget provisions designed to restrict the applicability of the Add Grace Period (AGP).  Please note that this message is a summary of changes that affect registrars.  You should refer to the adopted budget document and adopted motions for further information.


Summary of Important Timing Issues

After several months of discussion and public comment on both the budget and the GNSO recommendations, the Board has approved the proposed budget containing a provision for collecting transaction fees above a threshold during the AGP.  Effective 1 July 2008, the registrar-level transaction fee will be collected on transactions, including names added on or after 1 July
2008 and deleted during the Add Grace Period above a certain minimum threshold.  Each "transaction" will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if
offered)
will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  The budget assumes the transaction fee rate will remain at US ./send.20.

The second change prohibits registries from issuing refunds above a similar threshold for names registered and deleted during the AGP (although some registries have made plans to charge for such transactions independent of this motion).  The implementation timing of this change has not been set, but should be expected to take place over a period of some months.  ICANN staff will solicit public comments and post a registrar advisory prior to implementation of this aspect of the GNSO recommendation.


Budget - Registrar Fees Effective 1 July 2008

The Operating Plan and Budget details for 2008-2009 fiscal year can be found at:

http://www.icann.org/en/financials/proposed-opplan-budget-v3-fy09-25jun0
8-en.pdf

Relevant section from the approved budget:

* Registrar-Level Transaction Fees

In FY08 the per transaction-year rate was ./send.20 (or a 5 cent discount from the established ./send.25 rate).  The draft FY09 budget assumes that the ./send.20 rate will continue for registrar transaction fees.  As in past years, each transaction will be defined as one-year domain registration increment caused by a successful add renewal or transfer command.  FY09 revenue is estimated to be .4 million for registrar-level transaction fees.  Each "transaction"
will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if offered) will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  Therefore per-transaction fee will continue to be charged for each one-year increment of every transaction (e.g.  at a ./send.20 fee level, the fee for a three-year renewal will be US ./send.60), and registrars will continue to have the option to "defer" payment of the fees for the years beyond one for each transaction.  n

Note, as in previous years, ICANN can collect such fees directly from the registrars only if they are "expressly approved by registrars who account, in the aggregate, for payment of two-thirds of all registrar-level fees collected by ICANN." ICANN will shortly undertake the process of requesting such approval for the 2008-09 fiscal year.  While ICANN is grateful for consistent approval by registrars of fee levels in prior years, and is optimistic about such approval this year, if for some reason the necessary approval is not achieved, the fees will be collected by ICANN, as permitted under the registry agreements through the registries.  (Note that the amount of such fees varies by registry, but in no case exceeds US ./send.25.) Registries will then be able to collect those payments from registrars to the extent permitted under the relevant contracts.  It is expected that the same transaction increments (including AGP) will be covered, whether collected directly by ICANN or in! directly by the registries, so registrars should anticipate this liability under either scenario.


ICANN Board Resolution

Whereas, ICANN community stakeholders are increasingly concerned about domain tasting, which is the practice of using the add grace period (AGP) to register domain names in bulk in order to test their profitability.

Whereas, on 17 April 2008, the GNSO Council approved, by a Supermajority vote, a motion to prohibit any gTLD operator that has implemented an AGP from offering a refund for any domain name deleted during the AGP that exceeds 10% of its net new registrations in that month, or fifty domain names, whichever is greater.  <http://gnso.icann.org/meetings/minutes-gnso-17apr08.shtml>

Whereas, on 25 April 2008, the GNSO Council forwarded its formal "Report to the ICANN Board - Recommendation for Domain Tasting"
<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>,
which outlines the full text of the motion and the full context and procedural history of this proceeding.

Whereas, the Board is also considering the Proposed FY 09 Operating Plan and Budget <http://www.icann.org/financials/fiscal-30jun09.htm>, which includes (at the encouragement of the GNSO Council) a proposal similar to the GNSO policy recommendation to expand the applicability of the ICANN transaction fee in order to limit domain tasting.

Resolved (2008.06.26.06), the Board adopts the GNSO policy recommendation on domain tasting, and directs staff to implement the policy following appropriate comment and notice periods on the implementation documents.


Domain tasting motion approved by the GNSO Council 17 April 2008

<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>

Whereas, the GNSO Council has discussed the Issues Report on Domain Tasting and the Final Outcomes Report of the ad hoc group on Domain Tasting;

Whereas, the GNSO Council resolved on 31 October 2007 to launch a PDP on Domain Tasting;

Whereas, the GNSO Council authorized on 17 January 2008 the formation of a small design team to develop a plan for the deliberations on the Domain Tasting PDP (the "Design Team"), the principal volunteers to which had been members of the Ad Hoc Group on Domain Tasting and were well-informed of both the Final Outcomes Report of the Ad Hoc Group on Domain Tasting and the GNSO Initial Report on Domain Tasting (collectively with the Issues Report, the "Reports on Domain Tasting");

Whereas, the GNSO Council has received the Draft Final Report on Domain Tasting;

Whereas, PIR, the .org registry operator, has amended its Registry Agreement to charge an Excess Deletion Fee; and both NeuStar, the .biz registry operator, and Afilias, the .info registry operator, are seeking amendments to their respective Registry Agreements to modify the existing AGP;

The GNSO Council recommends to the ICANN Board of Directors that:

1.  The applicability of the Add Grace Period shall be restricted for any gTLD which has implemented an AGP ("Applicable gTLD Operator").
Specifically, for each Applicable gTLD Operator:

  a.  During any given month, an Applicable gTLD Operator may not offer any
  refund to a registrar for any domain names deleted during the AGP that
  exceed (i) 10% of that registrar's net new registrations in that month
  (defined as total new registrations less domains deleted during AGP), or
  (ii) fifty (50) domain names, whichever is greater.

  b.  A Registrar may seek an exemption from the application of such
  restriction in a specific month, upon the documented showing of
  extraordinary circumstances.  For any Registrar requesting such an
  exemption, the Registrar must confirm in writing to the Registry Operator
  how, at the time the names were deleted, these extraordinary circumstances
  were not known, reasonably could not have been known, and were outside of
  the Registrar's control.  Acceptance of any exemption will be at the sole
  reasonable discretion of the Registry Operator, however "extraordinary
  circumstances" which reoccur regularly will not be deemed extraordinary.

  c.  In addition to all other reporting requirements to ICANN, each
  Applicable gTLD Operator shall identify each Registrar that has sought an
  exemption, along with a brief descriptive identification of the type of
  extraordinary circumstance and the action (if any) that was taken by the
  Applicable gTLD Operator.

2.  Implementation and execution of these recommendations shall be monitored by the GNSO.  Specifically;

  a.  ICANN Staff shall analyze and report to the GNSO at six month intervals
  for two years after implementation, until such time as the GNSO resolves
  otherwise, with the goal of determining;

    i.  How effectively and to what extent the policies have been implemented
    and followed by Registries and Registrars, and

    ii.  Whether or not modifications to these policies should be considered
    by the GNSO as a result of the experiences gained during the
    implementation and monitoring stages,

  b.  The purpose of these monitoring and reporting requirements are to allow
  the GNSO to determine when, if ever, these recommendations and any ensuing
  policy require additional clarification or attention based on the results
  of the reports prepared by ICANN Staff.

</blockquote>

<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=152f487f101abbcdd9c900fc3eb46268" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=152f487f101abbcdd9c900fc3eb46268" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/330098895" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 11:42:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/fees directly">fees directly</category>
      <category domain="http://securityratty.com/tag/fees">fees</category>
      <category domain="http://securityratty.com/tag/registrar fees effective">registrar fees effective</category>
      <category domain="http://securityratty.com/tag/effective">effective</category>
      <category domain="http://securityratty.com/tag/registrar-level fees">registrar-level fees</category>
      <category domain="http://securityratty.com/tag/fee">fee</category>
      <category domain="http://securityratty.com/tag/per-transaction fee">per-transaction fee</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/330098895/ch_icanns_announcement_of_antidomain_tasting_measures_to_registrars.html">ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars</source>
    </item>
    <item>
      <title><![CDATA[ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars]]></title>
      <link>http://securityratty.com/article/1438af7a2605c2bbe5326444d5bd9d27</link>
      <guid>http://securityratty.com/article/1438af7a2605c2bbe5326444d5bd9d27</guid>
      <description><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, such as this one , based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy...]]></description>
      <content:encoded><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, <a href="http://www.domainnamenews.com/miscellaneous/icann-board-resolution-kills-domain-tasting/1689">such as this one</a>, based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy change. But there was confusion over exactly what the policy was; most people just assumed it followed the recommendations of the GNSO council from April.  The incomplete information caused some confused analysis such as <a href="http://www.cadna.org/en/newsroom/press-releases/icann-tasting-solution">this from CADNA (the Coalition Against Domain Name Abuse)</a>.

I asked ICANN and they sent me the actual e-mail that they sent out to registrars. It is published below. My analysis of it is in <a href="http://www.eweek.com/c/a/Security/Yes-Domain-Tasting-Will-End/">a column on eWEEK</a>.

<blockquote>
Dear Registrar,

This message is intended to explain how certain decisions that were made by the ICANN Board of Directors at its meeting in Paris last week may affect your registrar.

Specifically, the Board adopted GNSO recommendations on domain tasting that included both budget and non-budget provisions designed to restrict the applicability of the Add Grace Period (AGP).  Please note that this message is a summary of changes that affect registrars.  You should refer to the adopted budget document and adopted motions for further information.


Summary of Important Timing Issues

After several months of discussion and public comment on both the budget and the GNSO recommendations, the Board has approved the proposed budget containing a provision for collecting transaction fees above a threshold during the AGP.  Effective 1 July 2008, the registrar-level transaction fee will be collected on transactions, including names added on or after 1 July
2008 and deleted during the Add Grace Period above a certain minimum threshold.  Each "transaction" will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if
offered)
will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  The budget assumes the transaction fee rate will remain at US ./send.20.

The second change prohibits registries from issuing refunds above a similar threshold for names registered and deleted during the AGP (although some registries have made plans to charge for such transactions independent of this motion).  The implementation timing of this change has not been set, but should be expected to take place over a period of some months.  ICANN staff will solicit public comments and post a registrar advisory prior to implementation of this aspect of the GNSO recommendation.


Budget - Registrar Fees Effective 1 July 2008

The Operating Plan and Budget details for 2008-2009 fiscal year can be found at:

http://www.icann.org/en/financials/proposed-opplan-budget-v3-fy09-25jun0
8-en.pdf

Relevant section from the approved budget:

* Registrar-Level Transaction Fees

In FY08 the per transaction-year rate was ./send.20 (or a 5 cent discount from the established ./send.25 rate).  The draft FY09 budget assumes that the ./send.20 rate will continue for registrar transaction fees.  As in past years, each transaction will be defined as one-year domain registration increment caused by a successful add renewal or transfer command.  FY09 revenue is estimated to be .4 million for registrar-level transaction fees.  Each "transaction"
will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if offered) will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  Therefore per-transaction fee will continue to be charged for each one-year increment of every transaction (e.g.  at a ./send.20 fee level, the fee for a three-year renewal will be US ./send.60), and registrars will continue to have the option to "defer" payment of the fees for the years beyond one for each transaction.  n

Note, as in previous years, ICANN can collect such fees directly from the registrars only if they are "expressly approved by registrars who account, in the aggregate, for payment of two-thirds of all registrar-level fees collected by ICANN." ICANN will shortly undertake the process of requesting such approval for the 2008-09 fiscal year.  While ICANN is grateful for consistent approval by registrars of fee levels in prior years, and is optimistic about such approval this year, if for some reason the necessary approval is not achieved, the fees will be collected by ICANN, as permitted under the registry agreements through the registries.  (Note that the amount of such fees varies by registry, but in no case exceeds US ./send.25.) Registries will then be able to collect those payments from registrars to the extent permitted under the relevant contracts.  It is expected that the same transaction increments (including AGP) will be covered, whether collected directly by ICANN or in! directly by the registries, so registrars should anticipate this liability under either scenario.


ICANN Board Resolution

Whereas, ICANN community stakeholders are increasingly concerned about domain tasting, which is the practice of using the add grace period (AGP) to register domain names in bulk in order to test their profitability.

Whereas, on 17 April 2008, the GNSO Council approved, by a Supermajority vote, a motion to prohibit any gTLD operator that has implemented an AGP from offering a refund for any domain name deleted during the AGP that exceeds 10% of its net new registrations in that month, or fifty domain names, whichever is greater.  <http://gnso.icann.org/meetings/minutes-gnso-17apr08.shtml>

Whereas, on 25 April 2008, the GNSO Council forwarded its formal "Report to the ICANN Board - Recommendation for Domain Tasting"
<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>,
which outlines the full text of the motion and the full context and procedural history of this proceeding.

Whereas, the Board is also considering the Proposed FY 09 Operating Plan and Budget <http://www.icann.org/financials/fiscal-30jun09.htm>, which includes (at the encouragement of the GNSO Council) a proposal similar to the GNSO policy recommendation to expand the applicability of the ICANN transaction fee in order to limit domain tasting.

Resolved (2008.06.26.06), the Board adopts the GNSO policy recommendation on domain tasting, and directs staff to implement the policy following appropriate comment and notice periods on the implementation documents.


Domain tasting motion approved by the GNSO Council 17 April 2008

<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>

Whereas, the GNSO Council has discussed the Issues Report on Domain Tasting and the Final Outcomes Report of the ad hoc group on Domain Tasting;

Whereas, the GNSO Council resolved on 31 October 2007 to launch a PDP on Domain Tasting;

Whereas, the GNSO Council authorized on 17 January 2008 the formation of a small design team to develop a plan for the deliberations on the Domain Tasting PDP (the "Design Team"), the principal volunteers to which had been members of the Ad Hoc Group on Domain Tasting and were well-informed of both the Final Outcomes Report of the Ad Hoc Group on Domain Tasting and the GNSO Initial Report on Domain Tasting (collectively with the Issues Report, the "Reports on Domain Tasting");

Whereas, the GNSO Council has received the Draft Final Report on Domain Tasting;

Whereas, PIR, the .org registry operator, has amended its Registry Agreement to charge an Excess Deletion Fee; and both NeuStar, the .biz registry operator, and Afilias, the .info registry operator, are seeking amendments to their respective Registry Agreements to modify the existing AGP;

The GNSO Council recommends to the ICANN Board of Directors that:

1.  The applicability of the Add Grace Period shall be restricted for any gTLD which has implemented an AGP ("Applicable gTLD Operator").
Specifically, for each Applicable gTLD Operator:

  a.  During any given month, an Applicable gTLD Operator may not offer any
  refund to a registrar for any domain names deleted during the AGP that
  exceed (i) 10% of that registrar's net new registrations in that month
  (defined as total new registrations less domains deleted during AGP), or
  (ii) fifty (50) domain names, whichever is greater.

  b.  A Registrar may seek an exemption from the application of such
  restriction in a specific month, upon the documented showing of
  extraordinary circumstances.  For any Registrar requesting such an
  exemption, the Registrar must confirm in writing to the Registry Operator
  how, at the time the names were deleted, these extraordinary circumstances
  were not known, reasonably could not have been known, and were outside of
  the Registrar's control.  Acceptance of any exemption will be at the sole
  reasonable discretion of the Registry Operator, however "extraordinary
  circumstances" which reoccur regularly will not be deemed extraordinary.

  c.  In addition to all other reporting requirements to ICANN, each
  Applicable gTLD Operator shall identify each Registrar that has sought an
  exemption, along with a brief descriptive identification of the type of
  extraordinary circumstance and the action (if any) that was taken by the
  Applicable gTLD Operator.

2.  Implementation and execution of these recommendations shall be monitored by the GNSO.  Specifically;

  a.  ICANN Staff shall analyze and report to the GNSO at six month intervals
  for two years after implementation, until such time as the GNSO resolves
  otherwise, with the goal of determining;

    i.  How effectively and to what extent the policies have been implemented
    and followed by Registries and Registrars, and

    ii.  Whether or not modifications to these policies should be considered
    by the GNSO as a result of the experiences gained during the
    implementation and monitoring stages,

  b.  The purpose of these monitoring and reporting requirements are to allow
  the GNSO to determine when, if ever, these recommendations and any ensuing
  policy require additional clarification or attention based on the results
  of the reports prepared by ICANN Staff.

</blockquote>

<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=8eea0eb864e902bc67c9b814b1af0256"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=8eea0eb864e902bc67c9b814b1af0256"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=8eea0eb864e902bc67c9b814b1af0256" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/338277687" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 11:42:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/fees directly">fees directly</category>
      <category domain="http://securityratty.com/tag/fees">fees</category>
      <category domain="http://securityratty.com/tag/registrar fees effective">registrar fees effective</category>
      <category domain="http://securityratty.com/tag/effective">effective</category>
      <category domain="http://securityratty.com/tag/registrar-level fees">registrar-level fees</category>
      <category domain="http://securityratty.com/tag/fee">fee</category>
      <category domain="http://securityratty.com/tag/per-transaction fee">per-transaction fee</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/338277687/ch_icanns_announcement_of_antidomain_tasting_measures_to_registrars.html">ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars</source>
    </item>
    <item>
      <title><![CDATA[ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars]]></title>
      <link>http://securityratty.com/article/266456c2c42bc5e4cf836f3ca19af1c2</link>
      <guid>http://securityratty.com/article/266456c2c42bc5e4cf836f3ca19af1c2</guid>
      <description><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, such as this one , based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy...]]></description>
      <content:encoded><![CDATA[The recent new that ICANN had taken measures to combat Domain Tasting came out in blogs, <a href="http://www.domainnamenews.com/miscellaneous/icann-board-resolution-kills-domain-tasting/1689">such as this one</a>, based on second-hand news. ICANN had sent an e-mail to registrars announcing the policy change. But there was confusion over exactly what the policy was; most people just assumed it followed the recommendations of the GNSO council from April.  The incomplete information caused some confused analysis such as <a href="http://www.cadna.org/en/newsroom/press-releases/icann-tasting-solution">this from CADNA (the Coalition Against Domain Name Abuse)</a>.

I asked ICANN and they sent me the actual e-mail that they sent out to registrars. It is published below. My analysis of it is in <a href="http://www.eweek.com/c/a/Security/Yes-Domain-Tasting-Will-End/">a column on eWEEK</a>.

<blockquote>
Dear Registrar,

This message is intended to explain how certain decisions that were made by the ICANN Board of Directors at its meeting in Paris last week may affect your registrar.

Specifically, the Board adopted GNSO recommendations on domain tasting that included both budget and non-budget provisions designed to restrict the applicability of the Add Grace Period (AGP).  Please note that this message is a summary of changes that affect registrars.  You should refer to the adopted budget document and adopted motions for further information.


Summary of Important Timing Issues

After several months of discussion and public comment on both the budget and the GNSO recommendations, the Board has approved the proposed budget containing a provision for collecting transaction fees above a threshold during the AGP.  Effective 1 July 2008, the registrar-level transaction fee will be collected on transactions, including names added on or after 1 July
2008 and deleted during the Add Grace Period above a certain minimum threshold.  Each "transaction" will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if
offered)
will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  The budget assumes the transaction fee rate will remain at US ./send.20.

The second change prohibits registries from issuing refunds above a similar threshold for names registered and deleted during the AGP (although some registries have made plans to charge for such transactions independent of this motion).  The implementation timing of this change has not been set, but should be expected to take place over a period of some months.  ICANN staff will solicit public comments and post a registrar advisory prior to implementation of this aspect of the GNSO recommendation.


Budget - Registrar Fees Effective 1 July 2008

The Operating Plan and Budget details for 2008-2009 fiscal year can be found at:

http://www.icann.org/en/financials/proposed-opplan-budget-v3-fy09-25jun0
8-en.pdf

Relevant section from the approved budget:

* Registrar-Level Transaction Fees

In FY08 the per transaction-year rate was ./send.20 (or a 5 cent discount from the established ./send.25 rate).  The draft FY09 budget assumes that the ./send.20 rate will continue for registrar transaction fees.  As in past years, each transaction will be defined as one-year domain registration increment caused by a successful add renewal or transfer command.  FY09 revenue is estimated to be .4 million for registrar-level transaction fees.  Each "transaction"
will continue to be defined as a one-year domain registration increment caused by a successful add, renewal or transfer command, but this year any domain names deleted during the AGP (if offered) will be included as transactions if they exceed the maximum of (i) 10% of that registrar's net new registrations in that month (defined as total new registrations less domains deleted during AGP), or (ii) fifty (50) domain names, whichever is greater.  Therefore per-transaction fee will continue to be charged for each one-year increment of every transaction (e.g.  at a ./send.20 fee level, the fee for a three-year renewal will be US ./send.60), and registrars will continue to have the option to "defer" payment of the fees for the years beyond one for each transaction.  n

Note, as in previous years, ICANN can collect such fees directly from the registrars only if they are "expressly approved by registrars who account, in the aggregate, for payment of two-thirds of all registrar-level fees collected by ICANN." ICANN will shortly undertake the process of requesting such approval for the 2008-09 fiscal year.  While ICANN is grateful for consistent approval by registrars of fee levels in prior years, and is optimistic about such approval this year, if for some reason the necessary approval is not achieved, the fees will be collected by ICANN, as permitted under the registry agreements through the registries.  (Note that the amount of such fees varies by registry, but in no case exceeds US ./send.25.) Registries will then be able to collect those payments from registrars to the extent permitted under the relevant contracts.  It is expected that the same transaction increments (including AGP) will be covered, whether collected directly by ICANN or in! directly by the registries, so registrars should anticipate this liability under either scenario.


ICANN Board Resolution

Whereas, ICANN community stakeholders are increasingly concerned about domain tasting, which is the practice of using the add grace period (AGP) to register domain names in bulk in order to test their profitability.

Whereas, on 17 April 2008, the GNSO Council approved, by a Supermajority vote, a motion to prohibit any gTLD operator that has implemented an AGP from offering a refund for any domain name deleted during the AGP that exceeds 10% of its net new registrations in that month, or fifty domain names, whichever is greater.  <http://gnso.icann.org/meetings/minutes-gnso-17apr08.shtml>

Whereas, on 25 April 2008, the GNSO Council forwarded its formal "Report to the ICANN Board - Recommendation for Domain Tasting"
<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>,
which outlines the full text of the motion and the full context and procedural history of this proceeding.

Whereas, the Board is also considering the Proposed FY 09 Operating Plan and Budget <http://www.icann.org/financials/fiscal-30jun09.htm>, which includes (at the encouragement of the GNSO Council) a proposal similar to the GNSO policy recommendation to expand the applicability of the ICANN transaction fee in order to limit domain tasting.

Resolved (2008.06.26.06), the Board adopts the GNSO policy recommendation on domain tasting, and directs staff to implement the policy following appropriate comment and notice periods on the implementation documents.


Domain tasting motion approved by the GNSO Council 17 April 2008

<http://gnso.icann.org/issues/domain-tasting/domain-tasting-board-report
-gnso-council-25apr08.pdf>

Whereas, the GNSO Council has discussed the Issues Report on Domain Tasting and the Final Outcomes Report of the ad hoc group on Domain Tasting;

Whereas, the GNSO Council resolved on 31 October 2007 to launch a PDP on Domain Tasting;

Whereas, the GNSO Council authorized on 17 January 2008 the formation of a small design team to develop a plan for the deliberations on the Domain Tasting PDP (the "Design Team"), the principal volunteers to which had been members of the Ad Hoc Group on Domain Tasting and were well-informed of both the Final Outcomes Report of the Ad Hoc Group on Domain Tasting and the GNSO Initial Report on Domain Tasting (collectively with the Issues Report, the "Reports on Domain Tasting");

Whereas, the GNSO Council has received the Draft Final Report on Domain Tasting;

Whereas, PIR, the .org registry operator, has amended its Registry Agreement to charge an Excess Deletion Fee; and both NeuStar, the .biz registry operator, and Afilias, the .info registry operator, are seeking amendments to their respective Registry Agreements to modify the existing AGP;

The GNSO Council recommends to the ICANN Board of Directors that:

1.  The applicability of the Add Grace Period shall be restricted for any gTLD which has implemented an AGP ("Applicable gTLD Operator").
Specifically, for each Applicable gTLD Operator:

  a.  During any given month, an Applicable gTLD Operator may not offer any
  refund to a registrar for any domain names deleted during the AGP that
  exceed (i) 10% of that registrar's net new registrations in that month
  (defined as total new registrations less domains deleted during AGP), or
  (ii) fifty (50) domain names, whichever is greater.

  b.  A Registrar may seek an exemption from the application of such
  restriction in a specific month, upon the documented showing of
  extraordinary circumstances.  For any Registrar requesting such an
  exemption, the Registrar must confirm in writing to the Registry Operator
  how, at the time the names were deleted, these extraordinary circumstances
  were not known, reasonably could not have been known, and were outside of
  the Registrar's control.  Acceptance of any exemption will be at the sole
  reasonable discretion of the Registry Operator, however "extraordinary
  circumstances" which reoccur regularly will not be deemed extraordinary.

  c.  In addition to all other reporting requirements to ICANN, each
  Applicable gTLD Operator shall identify each Registrar that has sought an
  exemption, along with a brief descriptive identification of the type of
  extraordinary circumstance and the action (if any) that was taken by the
  Applicable gTLD Operator.

2.  Implementation and execution of these recommendations shall be monitored by the GNSO.  Specifically;

  a.  ICANN Staff shall analyze and report to the GNSO at six month intervals
  for two years after implementation, until such time as the GNSO resolves
  otherwise, with the goal of determining;

    i.  How effectively and to what extent the policies have been implemented
    and followed by Registries and Registrars, and

    ii.  Whether or not modifications to these policies should be considered
    by the GNSO as a result of the experiences gained during the
    implementation and monitoring stages,

  b.  The purpose of these monitoring and reporting requirements are to allow
  the GNSO to determine when, if ever, these recommendations and any ensuing
  policy require additional clarification or attention based on the results
  of the reports prepared by ICANN Staff.

</blockquote><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/xJKws7q3qKE" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 11:42:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/fees directly">fees directly</category>
      <category domain="http://securityratty.com/tag/fees">fees</category>
      <category domain="http://securityratty.com/tag/registrar fees effective">registrar fees effective</category>
      <category domain="http://securityratty.com/tag/effective">effective</category>
      <category domain="http://securityratty.com/tag/registrar-level fees">registrar-level fees</category>
      <category domain="http://securityratty.com/tag/fee">fee</category>
      <category domain="http://securityratty.com/tag/per-transaction fee">per-transaction fee</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/xJKws7q3qKE/ch_icanns_announcement_of_antidomain_tasting_measures_to_registrars.html">ICANN's Announcement Of Anti-Domain Tasting Measures To Registrars</source>
    </item>
    <item>
      <title><![CDATA[i-safe has some great articles for your online safety]]></title>
      <link>http://securityratty.com/article/f470eb7663376ebdd5f7fd86ba299b73</link>
      <guid>http://securityratty.com/article/f470eb7663376ebdd5f7fd86ba299b73</guid>
      <description><![CDATA[They have a bunch of learning modules for kids to seniors to law enforcement. Check em out


clipped from ilearn.isafe.org




Which module do I watch
There are five options with five different users...]]></description>
      <content:encoded><![CDATA[<div > They have a bunch of learning modules for kids to seniors to law enforcement.<br/>Check em out. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/7B4D00A9-9504-4F00-8581-42A32D13F197/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/630dd2ed-47c4-492e-9618-a3c06d1d33f0/7B4D00A9-9504-4F00-8581-42A32D13F197/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://ilearn.isafe.org/" href="http://ilearn.isafe.org/" style="font-size: 11px;">ilearn.isafe.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://ilearn.isafe.org/ -->
<div align="center"><img src="http://content8.clipmarks.com/blog_cache/ilearn.isafe.org/img/78E588FE-B979-4052-B66A-517B012F3DAE" alt="" /></div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://ilearn.isafe.org/ --><P><B>Which module do I watch?</B><br />
There are five options with five different users in mind. Those registered as educators with i-SAFE have the greatest<br />
	access to view the modules because you work closely with students and parents. Those registered as parents and fifty+<br />
	have access to either of those modules since many users fit both categories. However, students are limited to the i-MENTOR<br />
	Training Network. And the Operation i-SHIELD module is reserved for those in law enforcement. Below is a breakdown of each<br />
	module. To begin, please register by creating a user name and password at the top of this page. That will help direct you to<br />
	the appropriate i-LEARN module. Enjoy!</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/7B4D00A9-9504-4F00-8581-42A32D13F197/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 19:25:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/module">module</category>
      <category domain="http://securityratty.com/tag/operation i-shield module">operation i-shield module</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/i-learn module">i-learn module</category>
      <category domain="http://securityratty.com/tag/modules">modules</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/users fit">users fit</category>
      <category domain="http://securityratty.com/tag/i-safe">i-safe</category>
      <category domain="http://securityratty.com/tag/parents">parents</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=489">i-safe has some great articles for your online safety</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central bank">central bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/office email address">office email address</category>
      <category domain="http://securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Petroleum Wholesale charged with exposing customers]]></title>
      <link>http://securityratty.com/article/1e0eee4c18853dda51b902995e1d952a</link>
      <guid>http://securityratty.com/article/1e0eee4c18853dda51b902995e1d952a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/19/08

Organization
Petroleum Wholesale, L. P

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types of Data
sensitive...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/pw.jpg" width="200" align="right" height="93"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/19/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.petroleumwholesale.com/sunmart.web/homepage.html">Petroleum Wholesale, L. P.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"sensitive personal information, including Social Security numbers, bank account numbers, and credit or debit card information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>”HOUSTON -- Petroleum Wholesale, which operated Sunmart Travel Centers and Convenience Stores in 10 states, was charged by the Texas Attorney General of improperly disposing of customer records"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.hcnonline.com/site/news.cfm?newsid=19788139&amp;BRD=1574&amp;PAG=461&amp;dept_id=532238&amp;rfi=6">The Pasadena Citizen</a> <br><a href="http://www.khou.com/news/local/crime/stories/khou080619_jj_storeid.1c30dcf3.html">KHOU-TV Channel 11 News</a> <br><a href="http://www.csnews.com/csn/news/article_display.jsp?vnu_content_id=1003819492">Convenience Store News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Pasadena Citizen<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>HOUSTON - Texas Attorney General Greg Abbott today charged Houston-based Petroleum Wholesale, L.P., which operates Sunmart Travel Centers &amp; Convenience Stores in 10 states, for exposing its customers to identity theft.<br><br>According to the state's enforcement action, Petroleum Wholesale improperly discarded customer records containing sensitive personal information, including Social Security numbers, bank account numbers, and credit or debit card information.<br><br>"This defendant is charged with failing to protect its customers' sensitive information," Attorney General Abbott said.<br><br>"With more than 20,000 Texas victims each year, identity theft remains one of the nation's fastest-growing crimes. The Office of the Attorney General will continue working to protect Texans from identity theft."<br><br>Investigators with the Office of the Attorney General (OAG) discovered that the company improperly discarded hundreds of customer records in a publicly-accessible trash container outside its former headquarters.<br><span style="font-style: italic;">[Evan] According to information posted on the Petroleum Wholesale web site, "Petroleum Wholesale services more than 350 retail locations throughout ten states."&nbsp; This breach has the potential to affect many, many people.</span><br><br>According to investigators, the records included sales receipts with customers' names and full credit or debit card numbers with expiration dates.<br><br>The records also included returned checks, along with forms listing customers' names, banking routing numbers, driver's license and Social Security numbers.<br><br>The defendant is charged with violating the 2005 Identity Theft Enforcement and Protection Act, which requires the safeguarding and proper destruction of clients' sensitive personal information.<br><br>State law establishes penalties of up to $50,000 per violation of the Act.<br><span style="font-style: italic;">[Evan] This could add up quick.&nbsp; What's a better business decision, a few hundred bucks for a cross-cut shredder and accompanying procedures, or fifty grand per incident?&nbsp; Although, I am not sure that a shredder and procedures are not all that is needed in Petroleum Wholesale's information security program (assuming one exists).</span><br><br>The OAG also charged the company with violating Chapter 35 of the Business and Commerce Code, which requires businesses to develop retention and disposal procedures for their clients' personal information.<br><br>The law provides for civil penalties of up to $500 for each abandoned record.<br><br>For more information about preventing identity theft, contact the Office of the Attorney General at (800) 252-8011 or visit the agency's Web site at <a href="http://www.texasattorneygeneral.gov.<br><br><span">www.texasattorneygeneral.gov.<br><br><span</a> style="font-weight: bold;">Commentary:</span><br>One question that isn't clear from the news reports is whether or not this was a common practice at Petroleum Wholesale.&nbsp; Organizations should take heed of this case.&nbsp; I think actions taken by Mr. Abbott and other State Attorney Generals will only become more frequent.<br><br>I look forward to more information in the future about this case. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/22/pw.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 22 Jun 2008 17:58:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/petroleum wholesale">petroleum wholesale</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/company improperly">company improperly</category>
      <category domain="http://securityratty.com/tag/improperly">improperly</category>
      <category domain="http://securityratty.com/tag/debit card information">debit card information</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <source url="http://breachblog.com/2008/06/22/pw.aspx">Petroleum Wholesale charged with exposing customers</source>
    </item>
  </channel>
</rss>
