<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: forbes]]></title>
    <link>http://securityratty.com/tag/forbes</link>
    <description></description>
    <pubDate>Mon, 31 Mar 2008 17:45:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[VC and IPO Outlook]]></title>
      <link>http://securityratty.com/article/33a99f11764689af12c7674da3dc0464</link>
      <guid>http://securityratty.com/article/33a99f11764689af12c7674da3dc0464</guid>
      <description><![CDATA[Forbes interviews venture capitalist Charlie Harris. He is the Chairman of Harris and Harris (NASDAQ: TINY ) a venture capital fund which is focused on funding nanotech companies. He is bullish...]]></description>
      <content:encoded><![CDATA[<p>Forbes <a href="http://www.forbes.com/video/?video=fvn/wolf/jw_harris110508">interviews</a> venture capitalist Charlie Harris. He is the Chairman of <a href="http://tinytechvc.com/">Harris and Harris</a>&#0160;(NASDAQ:<a href="http://finance.google.com/finance?q=tiny">TINY</a>) a venture capital fund which is focused on funding nanotech companies. He is bullish looking forward from today for a couple of reasons</p><br /><div>1. We have an eight year back log of good companies and ideas due to a poor IPO environment, we have had an eight year drought in IPOs but still lots of good ideas out there.</div><br /><div>2. Clean tech theme has a lot of room left to grow</div><br /><div>3. The recent financial crisis has revealed and removed a lot of risks</div><br /><div>4. The best businesses are started in times of economic distress. Dislocation equals opportunity. Companies that start during financial distress have tremendous discipline to survive.</div><br /><div>Somewhat surprisingly for a person with 100% of his fund invested in nanotech, he does not see nanotech as the leader of a next IPO bookm. He seems to see nanotech as an enabling technology (my words not his) so you will see nanotech enabling clean fuel, cancer drugs and so on, and these individual spaces could boom, but not an &quot;all things nanotech&quot; type boom.</div>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 06:07:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nanotech companies">nanotech companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/nanotech">nanotech</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <category domain="http://securityratty.com/tag/venture capital fund">venture capital fund</category>
      <category domain="http://securityratty.com/tag/poor ipo environment">poor ipo environment</category>
      <category domain="http://securityratty.com/tag/dislocation equals opportunity">dislocation equals opportunity</category>
      <category domain="http://securityratty.com/tag/clean tech theme">clean tech theme</category>
      <category domain="http://securityratty.com/tag/recent financial crisis">recent financial crisis</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/vc-and-ipo-outlook.html">VC and IPO Outlook</source>
    </item>
    <item>
      <title><![CDATA[Alright Dell! Youre winning me back!]]></title>
      <link>http://securityratty.com/article/f96fe1bc88527cb71cfd103f324de1aa</link>
      <guid>http://securityratty.com/article/f96fe1bc88527cb71cfd103f324de1aa</guid>
      <description><![CDATA[Im starting to think maybe we can still have something together here


clipped from www.forbes.com
Dell spent $770,000 to lobby in second quarter


In addition, the company lobbied on data security...]]></description>
      <content:encoded><![CDATA[<div > Im starting to think maybe we can still have something together here. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/3052D0CC-725A-4F6D-9958-1B1D52C962B6/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/7695b2b0-9b6f-42c3-b5f0-adf73df91800/3052D0CC-725A-4F6D-9958-1B1D52C962B6/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.forbes.com/feeds/ap/2008/07/30/ap5271321.html" href="http://www.forbes.com/feeds/ap/2008/07/30/ap5271321.html" style="font-size: 11px;">www.forbes.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.forbes.com/feeds/ap/2008/07/30/ap5271321.html -->Dell spent $770,000 to lobby in second quarter</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.forbes.com/feeds/ap/2008/07/30/ap5271321.html --><P>In addition, the company lobbied on data security legislation as well as proposals to crack down on spyware and phishing scams. Spyware are computer programs that can surreptitiously access hard drives to track online behavior and steal sensitive personal data, while phishing scams use fake e-mails and fraudulent Web sites to trick consumers into releasing credit card numbers and other personal information.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/3052D0CC-725A-4F6D-9958-1B1D52C962B6/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 19:38:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/surreptitiously access hard">surreptitiously access hard</category>
      <category domain="http://securityratty.com/tag/track online behavior">track online behavior</category>
      <category domain="http://securityratty.com/tag/data security legislation">data security legislation</category>
      <category domain="http://securityratty.com/tag/fraudulent web sites">fraudulent web sites</category>
      <category domain="http://securityratty.com/tag/sensitive personal data">sensitive personal data</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/scams">scams</category>
      <category domain="http://securityratty.com/tag/fake e-mails">fake e-mails</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=526">Alright Dell! Youre winning me back!</source>
    </item>
    <item>
      <title><![CDATA[Links List 7.25.08]]></title>
      <link>http://securityratty.com/article/630a1fc26c11310563527f51eaebf464</link>
      <guid>http://securityratty.com/article/630a1fc26c11310563527f51eaebf464</guid>
      <description><![CDATA[The Wall Street Journal reports that the military is taking Tech Lessons . It seems that over the last few years, the DISA CIO has been visiting different tech companies to learn about cutting-edge...]]></description>
      <content:encoded><![CDATA[<p>The Wall Street Journal reports that the military is taking “<a href="http://blogs.wsj.com/biztech/2008/07/24/the-military-takes-tech-lessons/?mod=djemTECH" target="_blank">Tech Lessons</a>”. It seems that over the last few years, the DISA CIO has been visiting different tech companies to learn about cutting-edge technologies that might be able to help soldiers in the battlefield. CIO Garing identified social networks and mashups as great technologies for smaller projects with potentially more immediate impact than the traditional years-long IT projects of the past. He should check out NAPA and the Collaboration Project [link to Dan Munz Q&amp;A] which highlights just how government agencies and orgs are already doing what he’s talking about.
<p>Just what I was waiting for, <a href="http://news.cnet.com/8301-13505_3-9996318-16.html" target="_blank">open source takes on cloud computing</a>. <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<p>We had a very interesting call this week with analyst firm, <a href="http://www.the451group.com/report_view/report_view.php?entity_id=54199" target="_blank">The 451 Group</a>, about the cloud and who is really doing what in this space now. Trying to separate the hype from reality, just like everyone else.
<p><a href="http://vmblog.com/archive/2008/07/23/forbes-interviews-vmware-ceo-paul-maritz-after-financial-analyst-call.aspx" target="_blank">After a disappointing (to analysts and the street) financial analyst call on Tuesday, VMware&#8217;s stock reached an all time low, almost back to the IPO stage</a>. In a follow-up interview, Forbes asked the new CEO what he thinks about the stock price, the analysts saying VMware doesn&#8217;t have a solid or innovative growth plan for the future, and whether <a href="http://vmware.com/" target="_blank">VMware</a> should be <a href="http://www.forbes.com/2008/07/22/vmware-maritz-qa-tech-intel-cx_wt_0722techvmware.html" target="_blank">part of EMC or not</a> (their backhand way of bringing up the whole Diane Greene thing…he didn’t fall for it).&nbsp;
<p>Wait for it…wait for it…we have been waiting for it. VMware announced plans to <a href="http://www.eweek.com/c/a/Infrastructure/VMwares-ESXi-Hypervisor-for-Free/?kc=EWKNLNAV07242008STR1" target="_blank">launch a free version of its ESXI hypervisor</a> starting July 28. I have to question the timing on this one. <a href="http://redmondmag.com/news/rss.asp?editorialsid=10067" target="_blank">Why didn’t they do this before Hyper-v came out</a> and try to at least undercut the Microsoft announcement? VMware is and should be the leader in this space but they act like they’re playing from behind. And to Wall Street, perception counts for a lot.
<p>Surprisingly, there hasn’t been a lot of coverage after the June 2008 OMB mandate on IPv6 readiness. But one interesting follow-up, <a href="http://www.networkworld.com/news/2008/072108-ipv6nat.html" target="_blank">a feature is set to be added to IPv6 which the upgrade was supposed to eliminate</a>. One of the <a href="http://www.circleid.com/posts/nat_just_say_no/">design goals</a> for IPv6 was that it would rid the Internet of network address translation (NAT), gateways that match increasingly scarce public IPv4 addresses with private IPv4 addresses used inside corporations, government agencies and other organizations.&nbsp; NAT adds complexity and cost, but due to the length of time it’s taken to migrate from IPv4 to IPv6, engineers may create special NAT devices to translate between IPv4-only and IPv6-only hosts and hopefully nudge along the transition to IPv6. IEEE is all set to meet on this topic later this month.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+7.25.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-72508%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 08:28:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ipv6-only hosts">ipv6-only hosts</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/ipv6 readiness">ipv6 readiness</category>
      <category domain="http://securityratty.com/tag/nat">nat</category>
      <category domain="http://securityratty.com/tag/special nat devices">special nat devices</category>
      <category domain="http://securityratty.com/tag/financial analyst call">financial analyst call</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/ipv4 addresses">ipv4 addresses</category>
      <category domain="http://securityratty.com/tag/ipv4">ipv4</category>
      <source url="http://blog.sciencelogic.com/links-list-72508/07/2008">Links List 7.25.08</source>
    </item>
    <item>
      <title><![CDATA["Metro" employee information mistakenly posted to Web]]></title>
      <link>http://securityratty.com/article/cd2d242bebb5e31e3d326420f3f89e22</link>
      <guid>http://securityratty.com/article/cd2d242bebb5e31e3d326420f3f89e22</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/14/08

Organization
Washington Metropolitan Area Transit Authority (&quot;Metro

Contractor/Consultant/Branch
None

Victims
past and present employees
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/metro.jpg" width="45" align="right" height="54"><font size="2"><b>Date Reported: </b><br>7/14/08<br><br><b>Organization: </b><br><a href="http://www.wmata.com/default.cfm">Washington Metropolitan Area Transit Authority ("Metro")</a> <br><br><b>Contractor/Consultant/Branch:</b><br>None<br><br><b>Victims:</b><br>"past and present employees"<br><br><b>Number Affected:</b><br>4,675<br><br><b>Types of Data:</b><br>Names and Social Security numbers<br><br><b>Breach Description:</b><br>"Metro has advised nearly 4,700 past and present employees that their social security numbers were published accidentally on the transit agency’s Web site last month."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wmata.com/about/MET_NEWS/PressReleaseDetail.cfm?ReleaseID=2194">Metro Press Release</a> <br><a href="http://www.forbes.com/feeds/ap/2008/07/14/ap5213364.html">Associated Press via Forbes.com</a> <br><a href="http://www.nbc4.com/news/16881050/detail.html">NBC Channel 4 News</a> <br><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/07/14/AR2008071402245.html">The Washington Post</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Washington Metropolitan Area Transit Authority<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Metro has advised nearly 4,700 past and present employees that their social security numbers were published accidentally on the transit agency’s Web site last month.<br><br>The information was posted between June 9 and 25 as part of a solicitation from Metro to companies interested in providing worker’s compensation and risk management services.<br><span style="font-style: italic;">[Evan] Rather than post this information to a public web site, why wasn't a more secure method of tranmission used such as VPN or secure FTP?</span><br><br>The document mistakenly included the social security numbers of 4,675 employees.<br><span style="font-style: italic;">[Evan] According to Metro spokeswoman Candace Smith the sensitive information was supposed to be redacted.&nbsp; I wonder how well this mandate was communicated to the employee(s) responsible for compiling and posting the information.</span><br><br>A smaller group of employees had their names and social security numbers posted in the lengthy document. Metro officials continue to analyze the information for any other data breaches.<br><br>Three Metro employees have been disciplined<br><br>The three disciplined employees, including a manager, have been suspended for up to a month without pay, officials said.<br><span style="font-style: italic;">[Evan] This implies that the employees responsible for the mistake should have known better.&nbsp; We can probably assume that they were informed of the proper procedure, but did not follow it.</span><br><br>Letters warning of the breach were sent out to the affected employees.<br><br>The letter urges employees to watch their credit reports for signs of identity theft.<br><br>Last week, the agency set up a separate Web site where employees can determine whether their numbers were among those posted. <br><br>The agency is offering the 4,700 employees one year of free credit report monitoring, $25,000 in identity theft insurance and counseling services.<br><br>"We deeply regret this incident, and believe the likelihood of misuse of the information is low," said Metro Chief Safety Officer Ronald Keele.<br><br>"However, we have taken additional steps to protect employee information by bolstering Internet security and requiring more checks and balances of materials before they are being released publicly."<br><span style="font-style: italic;">[Evan] Checks and balances are typically lacking in these types of breaches, so I think it’s a good sign that Metro is addressing these.</span><br><br>Metro officials say they are not alone in this type of data breach.<br><span style="font-style: italic;">[Evan] So what?</span><br><br>According to the Identity Theft Resource Center, data breaches at businesses, governments and universities were up 69 percent in the first half of 2008 compared with a similar period in 2007.<br><br><span style="font-weight: bold;">Commentary:</span><br>The end result of this oversight is three disciplined employees (with no pay for a month) and nearly 4,700 people with an increased risk of identity theft.&nbsp; Forethought is there for a reason, whether or not you use it is your choice. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/metro.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 06:39:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/metro officials continue">metro officials continue</category>
      <category domain="http://securityratty.com/tag/metro officials">metro officials</category>
      <category domain="http://securityratty.com/tag/metro">metro</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/letter urges employees">letter urges employees</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/metro employees">metro employees</category>
      <category domain="http://securityratty.com/tag/employees responsible">employees responsible</category>
      <source url="http://breachblog.com/2008/07/15/metro.aspx">"Metro" employee information mistakenly posted to Web</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/12a646d6f75cd20c5bdf249647b13de5</link>
      <guid>http://securityratty.com/article/12a646d6f75cd20c5bdf249647b13de5</guid>
      <description><![CDATA[Synopsis: Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #78, a 32-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 32-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3">Download the show here</a> (MP3, 15MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on March 27, 2008. Yes, that was over two months ago... we know...</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance</li><br />
		<li>Dan met with Craig Bowser down at VoiceCon, also David Endler, Mark Collier, etc.</li><br />
		<li>Jonathan met with Dean Elwood, Martyn Davies, etc.</li><br />
		<li><a href="http://voipsa.org/blog/2008/03/21/four-new-security-vulnerabilities-in-asterisk-time-to-upgrade/">Four Asterisk vulnerabilities</a></li><br />
<li>The Economist: <a href="http://www.economist.com/printedition/displaystory.cfm?story_id=10789393">Bugging The Cloud</a></li><br />
<li>Forbes: <a href="http://www.forbes.com/technology/2008/03/18/zimmerman-hacking-voip-tech-security-cx_ag_0318voip.html">How to Make Your Phone Untappable</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/voip-spying-031308/">VoIP: Who Might Be Spying on Your Communications? (Hint &#8211; It&#8217;s Not Just the <span class="caps">NSA</span></a></li><br />
		<li>VoIP News: <a href="http://www.voip-news.com/feature/17-wiretap-signs-031908/">Listen Up: 17 Signs That You Are Being Wiretapped</a></li><br />
<li>eChannelLine: <a href="http://www.echannelline.com/usa/brief.cfm?item=15198">Businesses lagging in securing VoIP</a> (also <a href="http://www.computerweekly.com/Articles/2008/03/25/229961/security-being-ignored-as-voip-deployments-increase.htm">ComputerWeekly.com</a> and <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&#38;newsId=20080324005525&#38;newsLang=en">news release</a> )</li><br />
		<li>eChannelLine: <a href="http://www.echannelline.com/usa/story.cfm?item=23076">Ingate launches enhanced security for VoIP and <span class="caps">SIP</span></a> (also <a href="http://www.voipplanet.com/solutions/article.php/3735601">Enterprise VoIPPlanet</a> )</li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/24/hacking-zyxel-gateways/">Hacking Zyxel Gateways</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/17/vishing-attacks/">Vishing Attacks</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/19/fbi-voip-surveillance-requirements-leaked/">FBI VoIP Surveillance Requirements Leaked</a> (also in <a href="http://www.fiercevoip.com/story/fbi-voip-docs-leaked-again/2008-03-17">FierceVoIP</a> and <a href="http://yro.slashdot.org/article.pl?sid=08/03/15/2021257">Slashdot</a> )</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/20/hackers-send-thousands-of-fake-calls-to-deaf-people/">Hackers Send Thousands of Fake Calls to Deaf People</a></li><br />
<li>SnapVoIP: <a href="http://snapvoip.blogspot.com/2008/03/unified-communications-in-virtual.html">Unified Communications in Virtual Worlds to Solve &#8216;Tower of Babel&#8217; for Intelligence Agencies</a></li><br />
		<li><a href="http://www.textually.org/textually/archives/2008/03/019464.htm">Israeli-made Cryptophone attracts world spy agencies</a> pointing to <a href="http://www.tikalnetworks.com/voip/index.php?cid=29">product site</a></li><br />
<li>BlogInfoSec.com: <a href="http://www.bloginfosec.com/2008/03/25/save-the-whales/">Save The Whales</a> (about a new form of phishing)</li><br />
<li>Network Computing: <a href="http://www.networkcomputing.com/immersion/dataprivacy/showArticle.jhtml?articleID=206904104">Your Data and the <span class="caps">P2P </span>Peril</a></li><br />
<li>NetQoS: <a href="http://www.networkperformancedaily.com/2008/03/voip_monitor_v11_released_and_1.html">VoIP Monitor 1.1 released</a></li><br />
<li><span class="caps">PC </span>World: <a href="http://www.pcworld.com/article/id,143810-c,webservices/article.html">FaceTime Security Product Scans Skype&#8217;s Encrypted IM</a> and <a href="http://www.earthtimes.org/articles/show/facetime-provides-unmatched-malware-prevention-for-leading-voip-and-chat-software,322357.shtml">news release</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-ipcs-solution-for-teleworkers-rated-avaya-compliant,318456.shtml">Sipera <span class="caps">IPCS </span>Solution for Teleworkers Rated &#8216;Avaya Compliant&#8217;</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/extreme-networks-boosts-security-for-converged-voice-and-data-networks,317382.shtml">Extreme Networks Boosts Security for Converged Voice and Data Networks with New Tools</a></li></p>

<p><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>32:27 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 12:30:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip monitor">voip monitor</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/asterisk vulnerabilities">asterisk vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/06/blue-box-79-ast.html">Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/6ff472aef8df8c39ce9d47bf4fe36d51</link>
      <guid>http://securityratty.com/article/6ff472aef8df8c39ce9d47bf4fe36d51</guid>
      <description><![CDATA[Synopsis: Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #78, a 32-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 32-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3">Download the show here</a> (MP3, 15MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on March 27, 2008. Yes, that was over two months ago... we know...</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance</li><br />
		<li>Dan met with Craig Bowser down at VoiceCon, also David Endler, Mark Collier, etc.</li><br />
		<li>Jonathan met with Dean Elwood, Martyn Davies, etc.</li><br />
		<li><a href="http://voipsa.org/blog/2008/03/21/four-new-security-vulnerabilities-in-asterisk-time-to-upgrade/">Four Asterisk vulnerabilities</a></li><br />
<li>The Economist: <a href="http://www.economist.com/printedition/displaystory.cfm?story_id=10789393">Bugging The Cloud</a></li><br />
<li>Forbes: <a href="http://www.forbes.com/technology/2008/03/18/zimmerman-hacking-voip-tech-security-cx_ag_0318voip.html">How to Make Your Phone Untappable</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/voip-spying-031308/">VoIP: Who Might Be Spying on Your Communications? (Hint &#8211; It&#8217;s Not Just the <span class="caps">NSA</span></a></li><br />
		<li>VoIP News: <a href="http://www.voip-news.com/feature/17-wiretap-signs-031908/">Listen Up: 17 Signs That You Are Being Wiretapped</a></li><br />
<li>eChannelLine: <a href="http://www.echannelline.com/usa/brief.cfm?item=15198">Businesses lagging in securing VoIP</a> (also <a href="http://www.computerweekly.com/Articles/2008/03/25/229961/security-being-ignored-as-voip-deployments-increase.htm">ComputerWeekly.com</a> and <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&#38;newsId=20080324005525&#38;newsLang=en">news release</a> )</li><br />
		<li>eChannelLine: <a href="http://www.echannelline.com/usa/story.cfm?item=23076">Ingate launches enhanced security for VoIP and <span class="caps">SIP</span></a> (also <a href="http://www.voipplanet.com/solutions/article.php/3735601">Enterprise VoIPPlanet</a> )</li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/24/hacking-zyxel-gateways/">Hacking Zyxel Gateways</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/17/vishing-attacks/">Vishing Attacks</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/19/fbi-voip-surveillance-requirements-leaked/">FBI VoIP Surveillance Requirements Leaked</a> (also in <a href="http://www.fiercevoip.com/story/fbi-voip-docs-leaked-again/2008-03-17">FierceVoIP</a> and <a href="http://yro.slashdot.org/article.pl?sid=08/03/15/2021257">Slashdot</a> )</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/20/hackers-send-thousands-of-fake-calls-to-deaf-people/">Hackers Send Thousands of Fake Calls to Deaf People</a></li><br />
<li>SnapVoIP: <a href="http://snapvoip.blogspot.com/2008/03/unified-communications-in-virtual.html">Unified Communications in Virtual Worlds to Solve &#8216;Tower of Babel&#8217; for Intelligence Agencies</a></li><br />
		<li><a href="http://www.textually.org/textually/archives/2008/03/019464.htm">Israeli-made Cryptophone attracts world spy agencies</a> pointing to <a href="http://www.tikalnetworks.com/voip/index.php?cid=29">product site</a></li><br />
<li>BlogInfoSec.com: <a href="http://www.bloginfosec.com/2008/03/25/save-the-whales/">Save The Whales</a> (about a new form of phishing)</li><br />
<li>Network Computing: <a href="http://www.networkcomputing.com/immersion/dataprivacy/showArticle.jhtml?articleID=206904104">Your Data and the <span class="caps">P2P </span>Peril</a></li><br />
<li>NetQoS: <a href="http://www.networkperformancedaily.com/2008/03/voip_monitor_v11_released_and_1.html">VoIP Monitor 1.1 released</a></li><br />
<li><span class="caps">PC </span>World: <a href="http://www.pcworld.com/article/id,143810-c,webservices/article.html">FaceTime Security Product Scans Skype&#8217;s Encrypted IM</a> and <a href="http://www.earthtimes.org/articles/show/facetime-provides-unmatched-malware-prevention-for-leading-voip-and-chat-software,322357.shtml">news release</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-ipcs-solution-for-teleworkers-rated-avaya-compliant,318456.shtml">Sipera <span class="caps">IPCS </span>Solution for Teleworkers Rated &#8216;Avaya Compliant&#8217;</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/extreme-networks-boosts-security-for-converged-voice-and-data-networks,317382.shtml">Extreme Networks Boosts Security for Converged Voice and Data Networks with New Tools</a></li></p>

<p><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>32:27 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=i1mO1B"><img src="http://feeds.feedburner.com/~a/BlueBox?i=i1mO1B" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=YWUw1I"><img src="http://feeds.feedburner.com/~f/BlueBox?i=YWUw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=74RvnI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=74RvnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=c8gwAI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=c8gwAI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=HpdUtI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=HpdUtI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=p9H2li"><img src="http://feeds.feedburner.com/~f/BlueBox?i=p9H2li" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=oUodVI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=oUodVI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/308280975" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 11:30:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip monitor">voip monitor</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/asterisk vulnerabilities">asterisk vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/308280975/blue-box-79-ast.html">Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Whats with all of the new ads? Forbes, business and finance blog network]]></title>
      <link>http://securityratty.com/article/2fc287046336e652e3cfbd4fe0664c7b</link>
      <guid>http://securityratty.com/article/2fc287046336e652e3cfbd4fe0664c7b</guid>
      <description><![CDATA[For those who read my blog via feed reader and not on the web site itself, you may not have noticed the new ads and member badge from the Forbes Business and Finance Blog Network . I received an...]]></description>
      <content:encoded><![CDATA[<p>For those who read my blog via feed reader and not on the web site itself, you may not have noticed the new ads and member badge from the <a href="http://www.forbes.com/businesswire/feeds/businesswire/2008/03/24/businesswire20080324005547r1.html">Forbes Business and Finance Blog Network</a>.  I received an invitation to join an elite list of 400 blogs handpicked by Forbes.  They will syndicate content and sell advertising for the site.  There are some other cool benefits that go along with the membership. I was very proud to be selected for this, but frankly was worried about too many ads.  If you get a chance, check out the site and have a look.  I know it means I am going commercial, but am hoping it will lead to a broader audience.<br></p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=pKc9Ux"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=pKc9Ux" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=aL8IeH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=aL8IeH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=uOMAwH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=uOMAwH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=X0ydPH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=X0ydPH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=GvScPH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=GvScPH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vT2DLh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vT2DLh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=H5FL3h"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=H5FL3h" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/284406316" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 05 May 2008 20:23:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/finance blog network">finance blog network</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/forbes">forbes</category>
      <category domain="http://securityratty.com/tag/ads">ads</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/forbes business">forbes business</category>
      <category domain="http://securityratty.com/tag/feed reader">feed reader</category>
      <category domain="http://securityratty.com/tag/elite list">elite list</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/284406316/whats-with-all.html">Whats with all of the new ads? Forbes, business and finance blog network</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-04-23 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/417251685333e9ecf8ea48f684ddafa6</link>
      <guid>http://securityratty.com/article/417251685333e9ecf8ea48f684ddafa6</guid>
      <description><![CDATA[Mining Government Tech Dollars - Forbes.com
Principles of Information-Centric Security | securosis.com
Errata Security: Why the &quot;Pentrate and Patch&quot; idea is not only great, but also essential: A...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.forbes.com/technology/2008/04/22/washington-entrepreneurs-splunk-tech-enter-cx-atg_0423splunk.html">Mining Government Tech Dollars - Forbes.com</a></li>
<li><a href="http://securosis.com/2008/03/05/principles-of-information-centric-security/">Principles of Information-Centric Security | securosis.com</a></li>
<li><a href="http://erratasec.blogspot.com/2008/04/why-pentrate-and-patch-idea-is-not-only.html">Errata Security: Why the &quot;Pentrate and Patch&quot; idea is not only great, but also essential: A response to Ranum and Lindstrom</a></li>
<li><a href="http://www.slideshare.net/anton_chuvakin/six-mistakes-of-log-management-2008">Six Mistakes of Log Management 2008 &raquo; SlideShare</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/276649487" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/errata security">errata security</category>
      <category domain="http://securityratty.com/tag/government tech dollars">government tech dollars</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/response">response</category>
      <category domain="http://securityratty.com/tag/slideshare">slideshare</category>
      <category domain="http://securityratty.com/tag/mistakes">mistakes</category>
      <category domain="http://securityratty.com/tag/principles">principles</category>
      <category domain="http://securityratty.com/tag/lindstrom">lindstrom</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/276649487/anton18">Links for 2008-04-23 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[UBS Explains Risk Management Gone Wrong]]></title>
      <link>http://securityratty.com/article/5c387c88d006f42d6098649cbbd6f869</link>
      <guid>http://securityratty.com/article/5c387c88d006f42d6098649cbbd6f869</guid>
      <description><![CDATA[Big news in risk management this week as UBS released a report to shareholders describing the situation that has led to roughly $37 billion in write-downs so far related to the company's subprime...]]></description>
      <content:encoded><![CDATA[<p>Big news in risk management this week as UBS released a report to shareholders describing the situation that has led to roughly $37 billion in write-downs so far related to the company's subprime exposures (see articles in <a href="http://www.reuters.com/article/telecomm/idUSL2141872120080422">Reuters</a> , <a href="http://www.forbes.com/markets/2008/04/21/ubs-shareholder-report-markets-equity-cx_vr_0421markets23.html">Forbes</a> , the <a href="http://online.wsj.com/article/SB120894128753637907.html?mod=googlenews_wsj">Wall Street Journal</a> , and <a href="http://www.businessweek.com/ap/financialnews/D906CUPG0.htm">BusinessWeek</a>).</p>

<p>Overarching causes described in the report are not surprising; control failures, an overly aggressive focus on short-term growth, and excessive risk taking are among the high level issues addressed. Also in the report, however, are scores of more detailed explanations of control failures in more than 20 different categories. Specific problems on the list include:</p>

<p>• Gaps in risk management expertise<br />• Failure to respond to wider industry concerns<br />• Lack of comprehensive Subprime risk assessment<br />• Complex and incomplete risk reporting<br />• Inadequate systems (related to infrastructure investment)<br />• Lack of strategic coordination<br />• Asymmetric risk/reward compensation</p>

<p>The list goes on, providing a substantial study guide for risk managers and auditors on problems to avoid. And because of the unfortunately massive losses due to these failures, the report also offers a bit of cost justification support for your new, broad risk management initiatives.</p>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 12:49:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management expertise">risk management expertise</category>
      <category domain="http://securityratty.com/tag/control failures">control failures</category>
      <category domain="http://securityratty.com/tag/failures">failures</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/wider industry concerns">wider industry concerns</category>
      <category domain="http://securityratty.com/tag/cost justification support">cost justification support</category>
      <category domain="http://securityratty.com/tag/list include">list include</category>
      <category domain="http://securityratty.com/tag/wall street journal">wall street journal</category>
      <source url="http://blogs.forrester.com/srm/2008/04/ubs-explains-ri.html">UBS Explains Risk Management Gone Wrong</source>
    </item>
    <item>
      <title><![CDATA[Customers of 14 Advance Auto Parts stores are victims of intrusion]]></title>
      <link>http://securityratty.com/article/24ce995cc05837ce18ecd03ab78c51ad</link>
      <guid>http://securityratty.com/article/24ce995cc05837ce18ecd03ab78c51ad</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/31/08

Organization
Advance Auto Parts, Inc

Headquartered in Roanoke, Va., Advance Auto Parts is the second-largest retailer of automotive aftermarket...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/advance.jpg" align="right" height="52" width="201">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/31/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.advanceautoparts.com/">Advance Auto Parts, Inc.</a>*<br><br><font size="1">*Headquartered in Roanoke, Va., Advance Auto Parts is the second-largest retailer of automotive aftermarket parts, accessories, batteries, and maintenance items in the United States, based on store count and sales. As of December 29, 2007, the Company operated 3,261 stores in 40 states, Puerto Rico, and the Virgin Islands. The Company serves both the do-it-yourself and professional installer markets.</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers that made purchases and one of 14 retail stores<br><br><span style="font-weight: bold;">Number Affected:</span><br>56,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"financial information" including "credit card, debit card and checking account information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Advance Auto Parts Inc. (AAP) said data from 14 of its stores may have been affected by a network intrusion, potentially compromising financial information of up to 56,000 customers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://phx.corporate-ir.net/phoenix.zhtml?c=130560&amp;p=irol-newsArticle&amp;t=Regular&amp;id=1123808&amp;">Advance Auto Parts News Release</a> <br><a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200803311739DOWJONESDJONLINE000764_FORTUNE5.htm">CNNMoney</a> <br><a href="http://www.forbes.com/reuters/feeds/reuters/2008/03/31/2008-03-31T235003Z_01_N31433790_RTRIDST_0_AUTOS-ADVANCEAUTO-UPDATE-2-NETWORK-INTRUS.html">Reuters via Forbes.com</a> <br><a href="http://www.eweek.com/c/a/Security/Auto-Parts-Retailer-Notifies-Customers-of-Network-Breach/">eWeek.com</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Advance Auto Parts, Inc.<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>ROANOKE, Va.--(BUSINESS WIRE)--March 31, 2008--Advance Auto Parts, Inc. (NYSE:AAP), a leading automotive aftermarket retailer of parts, accessories and maintenance items, released information today regarding the Company becoming the victim of a network intrusion.<br><span style="font-style: italic;">[Evan] I don't think of the company as a "victim".&nbsp; I think of the people and possibly the banks that may have to reissue cards and reimburse the people as victims.</span><br><br>The investigation by Advance Auto Parts revealed that data from 14 of its stores may have been impacted, potentially compromising customer financial information of up to 56,000 customers.<br><br>The following 14 Advance Auto Parts stores were affected by this network intrusion:<br><br><span style="font-weight: bold;">Affected Store Address&nbsp;</span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <span style="font-weight: bold;">City&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; State</span><br>----------------------------------------------------------------------<br>2920 Martin Luther King Jr. Drive&nbsp; Atlanta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Georgia<br>----------------------------------------------------------------------<br>6100 Old National Highway&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; College Park&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Georgia<br>----------------------------------------------------------------------<br>1354 Harrisburg Pike&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Columbus&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ohio<br>----------------------------------------------------------------------<br>950 E Boston Street&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Covington&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Louisiana<br>----------------------------------------------------------------------<br>2055 South Locust St.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Canal Fulton&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ohio<br>----------------------------------------------------------------------<br>422 US Highway 80 W&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Garden City&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Georgia<br>----------------------------------------------------------------------<br>2414 Belle Chase Highway&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Gretna&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Louisiana<br>----------------------------------------------------------------------<br>1370 Ashland Road&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Mansfield&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ohio<br>----------------------------------------------------------------------<br>6645 E. Shelby Dr.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Memphis&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Tennessee<br>----------------------------------------------------------------------<br>179 Sgt Prentiss Drive&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Natchez&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Mississippi<br>----------------------------------------------------------------------<br>5185 Jimmy Carter Blvd.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Norcross&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Georgia<br>----------------------------------------------------------------------<br>936 N. Gospel St.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Paoli&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Indiana<br>----------------------------------------------------------------------<br>6300 W. Broad St.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Richmond&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Virginia<br>----------------------------------------------------------------------<br>1802 Teall Ave.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Syracuse&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; New York<br>----------------------------------------------------------------------<br><span style="font-style: italic;">[Evan] I don't recognize any pattern in the store locations.&nbsp; I wonder if there is a pattern elsewhere.&nbsp; Why these stores, or is this just all that is known at this point?</span><br><br>Advance has notified its credit, debit and check processors.<br><br>As a precautionary measure, the Company has also started sending letters directly to the impacted customers whom it has been able to identify. Customers who purchased products in the 14 stores and who do not receive a letter can call the toll-free number listed below to determine if they have been impacted.<br><br>Advance is also working with the appropriate law enforcement officials who are conducting a criminal investigation.<br><br>The Company believes that the incident has been contained. However, the Company is continuing to investigate and has partnered with a leading global third party security expert to assist in the investigation. <br><br>In addition, Advance continually partners with leading experts to enhance the security of information technology systems.<br><span style="font-style: italic;">[Evan] Like who?&nbsp; What makes a person a leading expert?</span><br><br>"Safeguarding our customers' confidential financial information is extremely important to Advance Auto Parts, and we take this responsibility very seriously," said Darren Jackson, President and Chief Executive Officer.<br><span style="font-style: italic;">[Evan] I respect the fact that the CEO of the company addresses the public regarding this breach.&nbsp; It demonstrates that Mr. Jackson understands his role and ultimate responsibility for information security.</span><br><br>Advance has also established a special toll-free number with dedicated resources for potentially impacted customers who made purchases in the 14 stores to call to ask questions. The special toll-free number is 1-800-704-1154. Customer service representatives will be available to answer questions seven days a week from 8 am until 12 midnight EDT through May 31, 2008.<br><br>Advance is offering the affected customers a credit monitoring product from a national credit reporting agency at no cost for one year.<br><br>"We sincerely apologize for any inconvenience this attack on our network may cause. Advance Auto Parts has been dedicated for the past 75 years to earning customer trust and for providing Legendary Customer Service. We strive to serve each and every customer better than anyone else," said Jackson. "We truly appreciate the business of each Advance Auto Parts customer."<br><br><span style="font-weight: bold;">Commentary:</span><br>There are many many details missing from this news release.&nbsp; I expect more details to follow as people continue to ask questions and demand answers.&nbsp; A "network intrusion" is very general and implies an outsider attack.&nbsp; Why these 14 stores?<br><br>Stay tuned... <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/31/advance.aspx" type="text/javascript" charset="utf-8"></script></font>]]></content:encoded>
      <pubDate>Mon, 31 Mar 2008 17:45:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/advance auto">advance auto</category>
      <category domain="http://securityratty.com/tag/advance">advance</category>
      <category domain="http://securityratty.com/tag/confidential financial information">confidential financial information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/stores">stores</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/account information">account information</category>
      <source url="http://breachblog.com/2008/03/31/advance.aspx">Customers of 14 Advance Auto Parts stores are victims of intrusion</source>
    </item>
  </channel>
</rss>
