<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: france]]></title>
    <link>http://securityratty.com/tag/france</link>
    <description></description>
    <pubDate>Mon, 30 Jun 2008 06:25:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Is That a Coffee Table or a Munition?]]></title>
      <link>http://securityratty.com/article/bcc3ebc100f5b51c419148587e587e92</link>
      <guid>http://securityratty.com/article/bcc3ebc100f5b51c419148587e587e92</guid>
      <description><![CDATA[One of the standard software security prescriptions for the SDLC is to data classification and enforce least privilege. From a security perspective this sounds fantastic, especially on a whiteboard....]]></description>
      <content:encoded><![CDATA[<p>One of the standard software security prescriptions for the SDLC is to data classification and enforce least privilege. From a security perspective this sounds fantastic, especially on a whiteboard. When the rubber meets the real world road, things often turn out slightly different.&#0160;</p><br /><div>It turns out that it is hard to conduct business with excessive granularity.</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e201053619a7a7970b-pi" style="display: inline;"><a href="http://www.economist.com/displaystory.cfm?story_id=11965352"><img alt="D3408BB1" class="at-xid-6a00d83451c75869e201053619a7a7970b " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e201053619a7a7970b-320wi" /></a></a><span style="font-family: &#39;Trebuchet MS&#39;; ">
</span> <br /></div><br /><div>Here is an <a href="http://www.economist.com/displaystory.cfm?story_id=11965352">article</a> from The Economist on the challenges of space technology, commercialization and information sharing. This is widely applicable to corporate information security policies:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-weight: bold; line-height: normal; ">Gravity is not the main obstacle for America’s space business. Government is</span></p><p><span style="font-family: Verdana; line-height: normal; ">IN THE spring of 2006 Robert Bigelow needed to take a stand on a trip to Russia to keep a satellite off the floor. The stand was made of aluminium. It had a circular base and legs. It was, says the entrepreneur and head of Bigelow Aerospace in Nevada, “indistinguishable from a common coffee table”. Nonetheless, the American authorities told Mr Bigelow that this coffee table was part of a satellite assembly and so counted as a munition. During the trip it would have to be guarded by two security officers at all times.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal;"><br /></span><span style="font-family: Verdana; line-height: normal; ">Exporting technology has always presented a dilemma for America. The country leads the world in most technologies and some of these give it a military advantage. If export rules are too lax, foreign powers will be able to put American technology in their systems, or copy it. But if the rules are too tight, then it will stifle the industries that depend upon sales to create the next generation of technology.</span><br /><span style="font-family: Verdana; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">It is a difficult balance to strike and critics charge that America has erred on the side of stifling. They claim that overly strict export controls have so damaged the space industry that America’s national security is now threatened by its dwindling leadership in space technology. The system, they complain, fails to distinguish between militarily sensitive hardware that should be controlled and widely available commercial technologies, such as lithium-ion batteries and solar cells. The zealous application of the export rules is the American space industry’s biggest handicap.</span></p></blockquote><div><span style="font-family: Verdana; font-weight: bold; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal; ">Read the whole thing its fascinating. So what started off as well intentioned asset protection eventually compromised the most important asset of all - strategic advantage.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;">So what&#39;s a better model? I am partial to think about these sorts of problems as free trade agreements. Each integration point should have a set of policies, and enforcement mechanisms that also include compensating transactions.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;">For example, did you know that in the US you can buy companies that trade on other exchanges through ADRs? You buy the ADR of say a French Telco which trades on a European exchange only you buy the ADR on the NYSE or Nasdaq. Then the French Telco issues you a dividend because you are a shareholder, but the French government withholds the dividend for foreign owners. Yet because there is a free trade agreement between the two countries, the US lets you write off the unreceived portion of the dividend on your taxes. (this may or may not be the case in US-France just an example). Anyway, its not a silver bullet but its an interesting strategy.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 09:40:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/coffee table">coffee table</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/american technology">american technology</category>
      <category domain="http://securityratty.com/tag/free trade agreement">free trade agreement</category>
      <category domain="http://securityratty.com/tag/trade">trade</category>
      <category domain="http://securityratty.com/tag/space technology">space technology</category>
      <category domain="http://securityratty.com/tag/french telco issues">french telco issues</category>
      <category domain="http://securityratty.com/tag/common coffee table">common coffee table</category>
      <category domain="http://securityratty.com/tag/information security policies">information security policies</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/is-that-a-coffee-table-or-a-munition.html">Is That a Coffee Table or a Munition?</source>
    </item>
    <item>
      <title><![CDATA[Links List 11.17.08]]></title>
      <link>http://securityratty.com/article/85b0ee0a0390b793b97cc896d3067a94</link>
      <guid>http://securityratty.com/article/85b0ee0a0390b793b97cc896d3067a94</guid>
      <description><![CDATA[Wow. I think we all know that we can take or leave surveys numbers dont mean a lot without context. In this case the context is the current economic meltdown. The Society for Information Management...]]></description>
      <content:encoded><![CDATA[<p>Wow. I think we all know that we can take or leave surveys – numbers don’t mean a lot without context. In this case the “context” is the current economic meltdown. The Society for Information Management (SIM) released the results of their 2008 IT Trends Survey – predicting an “upbeat” forecast for IT jobs; the HUGE caveat here is that the study was conducted before all the recent economic woes. Apparently organizations are using IT to <a href="http://blogs.zdnet.com/BTL/?p=10765" target="_blank">drive efficiencies, streamline operations, and cut costs</a> rather than just slashing the IT budget to save money during the downturn. What would be a nice follow-up: a quick second survey comparing responses before and after. Regardless Jerry Luftman, SIM vice president of academic affairs, still says the survey results demonstrate “that the overall state of IT remains very strong.”</p>
<p><img style="margin: 5px" src="http://images.google.com/url?q=http://disney-clipart.com/Chicken-Little/Disney-Chicken-Little.jpg&amp;usg=AFQjCNGA4kajmvy1h_lrcRnuywgV7_X0aQ" alt="" width="198" height="201" align="left" />The sky is falling! Trip Chowdhry, the analyst with Global Equities Research who claimed Red Hat was ‘rubbish and the entire LAMP stack is potty, too’ published some eye-opening predictions, predominantly negative, about tech business in Silicon Valley. Now <a href="http://news.cnet.com/8301-13505_3-10094221-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">Chowdhry claims that “almost every VC funded open-source company</a> is struggling and will run out of money within the next six months.” (Probably not the most unbiased guy about open source) Matt Asay argues that organizations in general are struggling, but open-source companies are not that high on the list. (But are they high on the VC “axe” list??) He notes Alfresco, Pentaho and JasperSoft are some of the players with ‘millions in the bank and growing revenue.’ Asay also says Chowdhry has a responsibility to do real due diligence and not create myths. Take that, Chicken Little! (<a href="http://disney-clipart.com/Chicken-Little/Disney-Chicken-Little.jpg" target="_blank"><em>img from Disney-Clipart</em></a>)</p>
<p>We’re not as far behind as we thought we were. Google presented the results of a study they conducted about how IPv6- capable “ordinary users” are at the RIPE meeting in Dubai a few weeks ago. Turns out Apple Macs drive IPv6 penetration in the US. <a href="http://arstechnica.com/news.ars/post/20081113-google-more-macs-mean-higher-ipv6-usage-in-us.html" target="_blank">Fifty-two percent of all IPv6 users in the U.S. own a Mac</a> and use 6to4 (creating IPv6 addresses from an IPv4 address and tunneling packets) – making the US fifth in the list of countries using IPv6. Russia and France took first and second place with .76 and .65 percent IPv6-enabled traffic . The US is at .45 percent. Worldwide, 0.238 percent of Google users’ systems are IPv6-enabled and prefer to use IPv6 over IPv4.</p>
<p>Obama’s win = Google’s win? Apparently Google <a href="http://blogs.cioinsight.com/biztech30/content/2008_campaign/google_vs_microsoft_the_obama_factor.html?kc=rss" target="_blank">CEO Eric Schmidt and President-Elect Obama are very good buddies</a> and “this terrifies Microsoft”. Now competitors are more on guard against Google’s growing empire and popularity. Although Schmidt was mentioned as a possible candidate for the country’s new national CTO position, he said he would not accept the post if asked. I guess that’s one less thing Microsoft has to worry about.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 19:35:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/survey results">survey results</category>
      <category domain="http://securityratty.com/tag/results">results</category>
      <category domain="http://securityratty.com/tag/ipv6 addresses">ipv6 addresses</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/open-source company">open-source company</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/fifty-two percent">fifty-two percent</category>
      <source url="http://blog.sciencelogic.com/links-list-111708/11/2008">Links List 11.17.08</source>
    </item>
    <item>
      <title><![CDATA[French President Sarkozy's bank account hacked]]></title>
      <link>http://securityratty.com/article/7bfd96825ab83e741ba7bfd129561c59</link>
      <guid>http://securityratty.com/article/7bfd96825ab83e741ba7bfd129561c59</guid>
      <description><![CDATA[The French government is investigating the theft of small amounts of money from the personal bank account of France's president, Nicolas...]]></description>
      <content:encoded><![CDATA[The French government is investigating the theft of small amounts of money from the personal bank account of France's president, Nicolas Sarkozy.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ba25336e4edb035ca37ad5018935eea4:819oNHhSt7adzYZeQclp2O6ZdzKihM6Z2YIzUxEjXhyx8Bw0Te8hBpfupzakVQmd%2FvcgTdcHvrrX'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d7b42c7d62840a49dd86d3402b3f97de:D0F4kxOf%2BICdCky%2F7i5arXTuXHfK3O%2BsSkpCY7%2Bk6QKnFcJCEChbX0vXvNVfbedwPrjFTo%2F1nzhqIw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fe0fbdd45c11a4a5166983541fe7de86:wA08ED8UvcUpAp0Rn2Uj8NGHog6kq2dDqFE8e7GXC%2FdtxDkpI6aVeixZ588L%2FyKUsAZ34ecx%2FHhOSg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:db8158400631b7c187aa81f835281d8f:K2oCc%2BllqJ0JYvORx0lT9qcYfRS4i1PWaqjTtW02vvb%2B6rTM6nPkSmQk5JJ8dzsqhuhkyJXeZkfo%2Fg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=b1af5eef26293d054ae3ec8bc78d1a28"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=b1af5eef26293d054ae3ec8bc78d1a28"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=b1af5eef26293d054ae3ec8bc78d1a28" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal bank account">personal bank account</category>
      <category domain="http://securityratty.com/tag/french government">french government</category>
      <category domain="http://securityratty.com/tag/nicolas sarkozy">nicolas sarkozy</category>
      <category domain="http://securityratty.com/tag/president">president</category>
      <category domain="http://securityratty.com/tag/france">france</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <category domain="http://securityratty.com/tag/amounts">amounts</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=b1af5eef26293d054ae3ec8bc78d1a28">French President Sarkozy's bank account hacked</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.29.08]]></title>
      <link>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</link>
      <guid>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</guid>
      <description><![CDATA[ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents reported that third-quarter IT spending was lower than previously planned while 12...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="240" alt="michaelphelps" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/michaelphelps.jpg" width="174" align="left" border="0" /> ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents <a href="http://www.infoworld.com/article/08/08/27/Grim_outlook_for_US_IT_spending_1.html?source=NLC-DAILY&amp;cgd=2008-08-28" target="_blank">reported that third-quarter IT spending was lower</a> than previously planned &#8211; while 12 percent spent more than planned. Thirty-five percent cited higher energy costs as the top factor for spending slowdown. </p>
<p>Parlez-vous open source? While wide-spread open source usage is still debated in many companies, the French have been advocating for <a href="http://www.infoworld.com/article/08/08/28/35NF-open-source-france-lessons_1.html" target="_blank">all open source all the time in government and education</a>. French President Nicolas Sarkozy set up an economic commission that recommended tax benefits to stimulate more open source development. Lesson learned from France: start &#8216;em early. &#8220;All students in France use open source.&#8221;</p>
<p>Just in time for Labor Day, John Edwards (no, not that one) comes out with an informative guide on &#8220;<a href="http://www.infoworld.com/article/08/08/27/35NF-cloud-providers_1.html" target="_blank">Who provides what in the cloud</a>&#8221;. No doubt, this will be a rapidly expanding list, but what&#8217;s really interesting is the comment on the article. People have very strong opinions on the cloud&#8230;</p>
<p>Research firm Aberdeen Group reports that <a href="http://www.cio.com/article/445863/Network_Management_Tips_for_Managing_Costs?page=1" target="_blank">network costs will increase</a> slightly more than 5 percent over 2007. Contributing factors: &#8220;need for speed&#8221;, shift from standard to mobile PCs (more end points of connectivity), and the ever-expanding network. And of course the hidden costs of multiple tools with multiple management consoles &#8211; if you&#8217;re not smart enough to choose say a comprehensive network management solution that is vendor agnostic&#8230;One tool to monitor them all&#8230;</p>
<p>And just because I miss the Olympics already, here&#8217;s an irreverent take on what it&#8217;s like to lose to Michael Phelps. <a href="http://www.thetechstop.net/?p=1503">http://www.thetechstop.net/?p=1503</a></p>
<p>Enjoy your long Labor Day Weekend!</p>
]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 10:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/source development">source development</category>
      <category domain="http://securityratty.com/tag/thirty percent">thirty percent</category>
      <category domain="http://securityratty.com/tag/labor day">labor day</category>
      <category domain="http://securityratty.com/tag/source usage">source usage</category>
      <category domain="http://securityratty.com/tag/costs">costs</category>
      <category domain="http://securityratty.com/tag/energy costs">energy costs</category>
      <category domain="http://securityratty.com/tag/thirty-five percent cited">thirty-five percent cited</category>
      <source url="http://blog.sciencelogic.com/links-list-82908/08/2008">Links List 8.29.08</source>
    </item>
    <item>
      <title><![CDATA[Email Hacking Going Commercial - Part Two]]></title>
      <link>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</link>
      <guid>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</guid>
      <description><![CDATA[Malware authors seeking financial gains from releasing their trojans often promote them as Remote Access Tools , which if we exclude the built-in anti-sandboxing and antivirus software killing...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/No0eDRtdb8s/s1600-h/hire_to_hack.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/BK1B_uN_Iew/s200-R/hire_to_hack.png" style="border: 0pt none ;" /></a>Malware authors seeking financial gains from releasing their trojans often promote them as <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Remote Access Tools</a>, which if we exclude the built-in anti-sandboxing and antivirus software killing capabilities, <a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html">could pass for a RAT</a>. In a similar deceptive fashion, <a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">email hacking services are pitched as email password recovery services</a>. <br />
<br />
Hacking as a Service sites seems to be popping out like mushrooms these days, thanks primarily due to the fact that yesterday's script kiddies are today's entrepreneurs trying to even monetize the process of bruteforcing. Here's their pitch :<br />
<br />
"<i>Well.. There is nothing different in our       services. Like other group, we simply crack email addresses       , and provide you the current password used by the victim to       you for a suitable price. Nothing unique that we can brag       about....&nbsp; We don't hack NASA or CIA , we cannot hack a       bank and steal a million dollars.. We just crack email       password .. AND WE DO A HECK OF A JOB IN IT !! We cannot be as presentable as the other       groups, trying to look as formal and corporate, as if they       are running a Major Corporate Office. However they present       it...password retrieval, online investigation.. access       recovery...blah blah blah..&nbsp; the most simplest way to       put it is.. : Email Password Cracking: !! And since everyone else is busy faking       it, or trying to be more presentable, we utilize our skills       to get you what you want.. i.e. THE EMAIL PASSWORD. No       buttering up, no marketing skills..&nbsp; plain hardcore       hacking !! So, since you now know what we do , and       want us to do the job for you, please proceed to the order       page for your relevant TARGET EMAIL and submit your request.       All said and done, we will get the elusive password &amp; send       you a couple of proofs. You decide upon the authenticity of       the proofs, and let us know if you are comfortable going       ahead with the payment. PAY US, AND YOU GET THE PASSWORD !And as they say.......</i>"<br />
<br />
How much are they charging for the bruteforcing? $150 for starters, which is prone to increase due to their bla bla bla about how sophisticated it was to obtain the password - given they actually manage to deliver the goods :&nbsp; <br />
<br />
<div class="separator" style="text-align: center; clear: both;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/aVdgDf7K46o/s1600-h/hire_to_hack1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/wsy8qQ3XtGQ/s200-R/hire_to_hack1.png" style="border: 0pt none ;" width="200" /></a></div>"<i>Many groups charge a fixed price for an email cracking. We undertake more kinds of projects than anyone else. Frankly, each email is a different project in itself. We cannot charge you $100, for something which we can do for $50. Subsequently, we cannot charge you $100, for something which should be priced at $200. But we charge a minimum of $150 USD so that we end up taking orders from ONLY those who really need it. It is a small amount for the level of satisfaction, facts/truth and relief that you would ultimately achieve from this.It depends upon the nature of the job, the accessibility factor. and many other reasons likes:-<br />
<br />
1- The email service provider<br />
2- The target itself. How net-savvy he/she is.<br />
3- Complexity of the password<br />
4- Urgency of job and many other things collectively.<br />
<br />
We will let you know our charges once we have the desired results only. Be assured, we wont charge you the moon. We charge only what we deserve, and is acceptable by you. Trust us !!</i>"<br />
<br />
Some of their answers to the frequently asked questions :<br />
<br />
" <i>- <b>Who are you? Where are you from</b>?<br />
We are Hire2Hack Group. Member of our group are students in information technology, at some university in England, France, Italy, Japan, Australia, Canada, Brasilia and at United States of America.<br />
<br />
- <b>What services do you provide?</b><br />
We can hack ANY EMAIL password for you very fast, reliable, secure and worldwide for a suitable price.<br />
<br />
- <b>Can you really hack password or just a making a shit scam?</b><br />
Well, lot of people, lot of groups, companies do this service, but not guaranteed. This is only you can choose which group you want to Order. Be careful with these people. You can believe only on them who claims to provide proof before you really pay them.<br />
<br />
- <b>Is there any tool available to crack password?</b><br />
Yes there is. And we are not giving it to you.<br />
<br />
- <b>How long does it takes to crack a password?</b><br />
Each account is different and hacking time vary. On average, it might take about 1 to 3 days, but it may take anywhere from 24 hours to 30 days or more depending on how difficult is the hacking of each account.<br />
<br />
- <b>How can I believe you, that you got password?</b><br />
We will provide you some good proofs before requesting you to pay us. The proof can be anything, you can decide what kind proof you need.<br />
<br />
- <b>Is there person will know that his/her email id has been cracked?</b><br />
No, we provide you only the original password. That mean the current active password. Your victim/target will not realized that she/he has been hacked. NEVER, we said !<br />
<br />
- <b>How I will pay you, I do not have credit card or I do not want to give my credit card number on net?</b><br />
Well, you can use international money transfer service such as Western Union (www.westernunion.com) or Money Gram (www.moneygram.com). These services immediate transfer money on same day or same hour. You can locate their agents in yours area from their website.<br />
<br />
- <b>Do I have to give you my password?</b><br />
No. Any service which requires your password is simply trying to scam you out of access to your account.<br />
<br />
- <b>How will I know you really have the password?</b><br />
We will show you the proofs.. which are mostly convincing.<br />
<br />
- <b>Since you have the password anyway, will you give it to me?</b><br />
NO. Do not waste your time or ours. We will not release the password until full payment is made - no exceptions. We have had people request our service and once we recover the password, they reset the subject account then ask us for the original password so they can reset it back - the answer will be no. We have also had people ask if they could have the password since we've already recovered it and they cannot pay - the answer will be no. No password will be released until payment has been made in full - no exceptions.<br />
<br />
- <b>Will you recover more than one password? Can I request more than one email account?</b><br />
Yes, but a separate request must be filled out for each one as you will only be billed for each successful recovery. If we have previously recovered a password for you and you have not paid, we will not begin any new request for you until your previous request is paid in full with exceptions for our established clientele. We charge at minimum US $100 for each account hacked.<br />
<br />
- <b>Do you reset or change the current password?</b><br />
No. We do not try to guess the current password or the secret question's answer, we do not change their password. We give you only the Original password, which the victim is currently using.<br />
<br />
- <b>Is this confidential? Do you share my information with anyone else</b>?<br />
No, Not at all, Not in any case, its a trust between you and us. Your information will be respected as long as you abide by our Terms and Conditions and Privacy policy. We keep your personal records and requests confidential in our database but we respect your right to privacy and will not rent, share, sell, or trade any personal information unless required by law. <b>But, if you engage in any spamming or fraudulent actives, Your information will be given to the appropriate authorities.</b></i>"<br />
<br />
So you've got script kiddies cracking email addresses and probably engaging in the rest of the usual cybercrime activities, who are spam sensitive, and would expose their customers if they start spamming from the cracked emails? Now that's socially responsible, isn't it.<br />
<br />
Targeted attacks are sexy, but bruteforcing email accounts no matter the number of proxies and wordlists that they have access to is so irrelevant, that social engineering a potential victim into infecting herself with malware through a live exploit URL seems to be the method of choice, next to a plain simple phishing email of course. In this case, what they're asking for in respect to the victim's details is the victim's country and victim's language, so that a localized social engineering or phishing attack can take place. However, this particular group seems to be using a standard bruteforcing tool.<br />
<br />
One thing's for sure - cybercrime is getting easier to outsource, and with potential customers starting to have access to services they didn't a couple of years ago, <a href="http://ddanchev.blogspot.com/2008/08/phishers-backdooring-phishing-pages-to.html">fake scammers are also emerging in between the real ones</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q4SazK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q4SazK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=v68SQK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=v68SQK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fTxCfk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fTxCfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m5GSCk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m5GSCk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rFpJlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rFpJlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hDloOK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hDloOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kzNwqk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kzNwqk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/359698182" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:31:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crack password">crack password</category>
      <category domain="http://securityratty.com/tag/crack">crack</category>
      <category domain="http://securityratty.com/tag/crack email password">crack email password</category>
      <category domain="http://securityratty.com/tag/email password">email password</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/original password">original password</category>
      <category domain="http://securityratty.com/tag/current password">current password</category>
      <category domain="http://securityratty.com/tag/password retrieval">password retrieval</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/359698182/email-hacking-going-commercial-part-two.html">Email Hacking Going Commercial - Part Two</source>
    </item>
    <item>
      <title><![CDATA[McAfee's Site Advisor Blocking n.runs AG - "for starters"]]></title>
      <link>http://securityratty.com/article/980eb4d1bd34b658bcb6d139b3d762f1</link>
      <guid>http://securityratty.com/article/980eb4d1bd34b658bcb6d139b3d762f1</guid>
      <description><![CDATA[Following the recent, and now fixed false positive blocking sans.org due to the already considered malicious dshield.org and giac.org it's also interesting to note that n.runs AG ( nruns.com ), whose...]]></description>
      <content:encoded><![CDATA[<div class="" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SJHp1ZiyMHI/AAAAAAAAB-8/ALBebqDtrl0/s1600-h/nruns_siteadvisor_false.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJHp1ZiyMHI/AAAAAAAAB-8/1_qCXyFB8b8/s200-R/nruns_siteadvisor_false.bmp" style="border: 0pt none ;" /></a>Following the recent, and now fixed <a href="http://isc.sans.org/diary.html?storyid=4799">false positive blocking sans.org</a> due to the already considered malicious <b>dshield.org</b> and <b>giac.org</b> it's also interesting to note that n.runs AG (<b>nruns.com</b>), whose <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">research into vulnerabilities in antivirus products</a> received a lot of attention lately, is also flagged as <a href="http://www.siteadvisor.com/sites/nruns.com/downloads/15713425/">a dangerous site</a>.</div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"><br />
Excluding the conspiracy theories, a false positive when your solution is integrated in the second most popular search engine is bad, especially when other <a href="http://www.google.com/safebrowsing/diagnostic?site=nruns.com">automated crawling approaches</a> are successfully detecting the site as a non-malicious one. How come? It's all a matter of how you define malicious activity, and what exactly are you trying to protect your users from.<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJMiqmiaOxI/AAAAAAAAB_M/T74a9Ztjt8U/s1600-h/invisiblethings_siteadvisor.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJMiqmiaOxI/AAAAAAAAB_M/JtWk3WVLlug/s200-R/invisiblethings_siteadvisor.bmp" style="border: 0pt none ;" /></a>In this case, Site Advisor seems to be trying to protect the end user from herself, but flagging sites hosting some sort of hacking/pen-testing tool in a clear directory structure, since SiteAdvisor isn't capable of automatically flagging a SQL injected site as a malicious one, the approach it takes for assessing whether or not a specific site is malicious is flawed, namely integrating McAfee's signatures based malware database and flagging a site hosting anything detected as malware as a badware site itself. <a href="http://www.theregister.co.uk/2008/08/01/siteadvisor_sans_snafu/page2.html">McAfee's comments</a>:</div><div class="" style="text-align: left; clear: both;"><br />
"<i>Our tests are very accurate," Dowling said. "The frequency of false positives is fewer than one a month. Changes in classifications we make are almost always because sites have changed their behaviour. "The email tests are the ones than have the most false positives. Users can have confidence in our ratings.</i>"<br />
<br />
</div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SJMjH58t8FI/AAAAAAAAB_U/jFxueEROzkM/s1600-h/hackinthebox_siteadvisor.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJMjH58t8FI/AAAAAAAAB_U/Wj65aLQMO3M/s200-R/hackinthebox_siteadvisor.bmp" style="border: 0pt none ;" /></a>There are even more surprising false positives, such as, <b>Hack in the Box security conference, Defcon.org, Zone-H France, Invisiblethings.org, AME Info - Middle East business and financial news</b> and more :</div><div class="" style="text-align: left; clear: both;"><a href="http://www.siteadvisor.com/sites/milw0rm.com"><b>milw0rm.com</b></a></div><div class="" style="text-align: left; clear: both;"><a href="http://www.siteadvisor.com/sites/hackinthebox.org/summary/"><b>hackinthebox.org</b></a></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/defcon.org">defcon.org</a> <br />
<a href="http://www.siteadvisor.com/sites/hitb.org"><b>hitb.org</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/invisiblethings.org/summary/"><b>invisiblethings.org</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/zone-h.fr/summary/"><b>zone-h.fr</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/ussrback.com/summary/"><b>ussrback.com</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><b><a href="http://www.siteadvisor.com/sites/ameinfo.com">ameinfo.com</a></b><br />
<br />
</b>Take for instance the Hack in the Box security conference, which is considered as the <a href="http://www.siteadvisor.com/sites/hitb.org/downloads/11950271/">download publisher of a file hosted at packetstormsecurity.org</a>. What's interesting to point out is that just like a huge percentage of already flagged as potentially harmful sites that haven't been re-checked in months, with Hack in the Box's case the link was last checked in February, 2008. And since <b>hitb.org</b> is now distributing spyware, any site that it links to is also flagged as badware, like <b>hackinthebox.org</b> itself :<br />
<br />
"<i>When we tested this site we found links to hitb.org, which we found to be a distributor of downloads some people consider adware, spyware or other potentially unwanted programs.</i>'<br />
<br />
These sites aren't SQL injected, IFRAME-ed or embedded with malware whatsoever, so it's like flagging a gun store as a malicious store because of the inventory there - wrong generalization aiming to bring order into the underground chaos at the first place is prone to result in lots of false positives, <a href="http://ddanchev.blogspot.com/2007/07/insecure-bureaucracy-in-germany.html">a wrong mentality that certain countries are starting to embrace</a>.</div><br />
The bottom line - is the "<i>do not visit unknown or potentially harmful sites</i>" security tip on the verge of extinction? Probably, as these days, exploited legitimate sites are hosting or redirecting to more malware than potentially harmful sites are.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6BU3YK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6BU3YK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WYGGVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WYGGVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=osuqWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=osuqWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ysc5ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ysc5ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S0nWuK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S0nWuK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x7tmHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x7tmHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdrCPk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdrCPk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/355386532" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 05:42:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site advisor">site advisor</category>
      <category domain="http://securityratty.com/tag/org due">org due</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/dangerous site">dangerous site</category>
      <category domain="http://securityratty.com/tag/specific site">specific site</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/harmful sites">harmful sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/355386532/mcafees-site-advisor-blocking-nruns-ag.html">McAfee's Site Advisor Blocking n.runs AG - "for starters"</source>
    </item>
    <item>
      <title><![CDATA[World War II Deception Story]]></title>
      <link>http://securityratty.com/article/ffeef2b2ecdc9709d491f4a4c3ecd7f5</link>
      <guid>http://securityratty.com/article/ffeef2b2ecdc9709d491f4a4c3ecd7f5</guid>
      <description><![CDATA[Great security story from an obituary of former OSS agent Roger Hall: One of his favorite OSS stories involved a colleague sent to occupied France to destroy a seemingly impenetrable German tank at a...]]></description>
      <content:encoded><![CDATA[<p>Great <a href="http://www.philly.com/inquirer/obituaries/20080723_Roger_Hall___Poked_fun_at_spies__89.html">security story</a> from an obituary of former OSS agent Roger Hall:</p>

<blockquote>One of his favorite OSS stories involved a colleague sent to occupied France to destroy a seemingly impenetrable German tank at a key crossroads. The French resistance found that grenades were no use. 

<p>The OSS man, fluent in German and dressed like a French peasant, walked up to the tank and yelled, "Mail!" </p>

<p>The lid opened, and in went two grenades.</blockquote></p>

<p>Hall's book about his OSS days, <a href="http://www.amazon.com/Youre-Stepping-Cloak-Dagger-Bluejacket/dp/1591143535/ref=pd_bbs_sr_1"><i>You're Stepping on My Cloak and Dagger,</i></a> is a must read.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=urokhJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=urokhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=TBL5AJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=TBL5AJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 09:50:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oss">oss</category>
      <category domain="http://securityratty.com/tag/oss days">oss days</category>
      <category domain="http://securityratty.com/tag/favorite oss stories">favorite oss stories</category>
      <category domain="http://securityratty.com/tag/grenades">grenades</category>
      <category domain="http://securityratty.com/tag/french resistance">french resistance</category>
      <category domain="http://securityratty.com/tag/french peasant">french peasant</category>
      <category domain="http://securityratty.com/tag/key crossroads">key crossroads</category>
      <category domain="http://securityratty.com/tag/security story">security story</category>
      <category domain="http://securityratty.com/tag/dagger">dagger</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/world_war_ii_de.html">World War II Deception Story</source>
    </item>
    <item>
      <title><![CDATA[Selling 0day Exploit Code]]></title>
      <link>http://securityratty.com/article/6fecfbd98ce0e43927152713256b4ea0</link>
      <guid>http://securityratty.com/article/6fecfbd98ce0e43927152713256b4ea0</guid>
      <description><![CDATA[We all know it happens, but it is rarely exposed as clearly as Adam Pennenberg did in his article for Fast Company, The Black Market Code Industry . It turns out that this 0day seller was an HP...]]></description>
      <content:encoded><![CDATA[<p>We all know it happens, but it is rarely exposed as clearly as Adam Pennenberg did in his article for Fast Company, <a href="http://www.fastcompany.com/magazine/127/nexttech-fear-of-a-black-hat.html">The Black Market Code Industry</a>.  It turns out that this 0day seller was an HP employee:</p>
<blockquote><p>According to the consultant who snared Marester, his quarry&#8217;s skills appear quite sophisticated. His wares, if they performed as advertised, could help a hacker take down machines running that particular software anywhere in the world. His real name is Steve Rigano; he&#8217;s a self-employed network consultant from Grenoble, France, who works full time at HP, where he is listed in the switchboard and maintains an hp.com email address. He told me that he saw nothing wrong with offering tools and techniques that targeted the company providing his paycheck.</p>
<p>A self-taught hacker, Rigano says he discovered the vulnerabilities and coded the exploits on his own time, which he says is none of HP&#8217;s business. &#8220;I have the right to sell what I want,&#8221; he says. He told me he attracted mostly Chinese and Russian buyers, but claimed he never found takers for the HP or SAP &#8220;vulns&#8221; and exploits. He said he stopped selling black-market code in January but didn&#8217;t explain why.</p></blockquote>
<p>Most security companies I have been acquainted with frown on this type of activity, as I am sure HP has.  It&#8217;s hard for them to sell security products and services when their employees are selling the very tools the company is purportedly defending against.</p>
]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 14:55:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast company">fast company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/consultant">consultant</category>
      <category domain="http://securityratty.com/tag/rigano">rigano</category>
      <category domain="http://securityratty.com/tag/steve rigano">steve rigano</category>
      <category domain="http://securityratty.com/tag/self-taught hacker">self-taught hacker</category>
      <category domain="http://securityratty.com/tag/network consultant">network consultant</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/sap vulns">sap vulns</category>
      <source url="http://www.veracode.com/blog/?p=116">Selling 0day Exploit Code</source>
    </item>
    <item>
      <title><![CDATA[Skyhook Expands Wi-Fi Positioning to Cell, GPS]]></title>
      <link>http://securityratty.com/article/828076f3d31c309f8a15ddea305e261f</link>
      <guid>http://securityratty.com/article/828076f3d31c309f8a15ddea305e261f</guid>
      <description><![CDATA[Skyhook Wireless will combine information from Wi-Fi wardriving, GPS radios, and cell tower signals for better location: The pitch at Skyhook Wireless is that despite its accuracy, satellite-based GPS...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.skyhookwireless.com/press/skyhookxps.php"><strong>Skyhook Wireless will combine information from Wi-Fi wardriving, GPS radios, and cell tower signals for better location:</strong></a> The pitch at Skyhook Wireless is that despite its accuracy, satellite-based GPS remains relatively expensive, that it's slow to get a fix when it powers up, and that it's not accurate enough in the middle of cities. Their XPS 2.0 system leverages GPS with the advantages of Skyhook's Wi-Fi signal database and algorithms along with cell-tower triangulation.</p>

<p>Ted Morgan, the head of Skyhook, explained in an interview that while GPS is certainly the gold standard, and while it works well in stand-alone devices designed for continuous use and navigation, it's not the right choice by itself for mobile devices. It can take 5 or 10 minutes for a GPS-only device to get an accurate fix on the satellites it needs to give you accurate information. (Various shortcuts can provide less accurate information more quickly.)</p>

<p>"This notion of 'tell a user or consumer to stand outside for 30 seconds before they can search for the nearest pharmacy' is pretty silly," Morgan said. He noted that with all the radios now found in newer mobile devices, using several of them produces a fast and much more accurate result. The iPhone 3G, for instance, sports quad-band 2G, tri-band 3G, Bluetooth, Wi-Fi, and GPS chips.</p>

<p>Morgan said that A-GPS (assisted GPS) already combines cell tower information with GPS. A cell phone can be told approximately where it is, and thus instead of cycling through 24 satellites, start with the two that are most directly overhead. This can reduce the time to gain a location to as little as 20 seconds, Morgan said, although any kind of movement usually lengthens the time to 30 to 60 seconds.</p>

<p>Skyhook's system takes advantage of this aspect of A-GPS. They let a GPS system grab onto two satellites quickly to correct data from their Wi-Fi Position System (WPS). Morgan said that this reduces the WPS error by 35 to 40 percent through "weak fixes."</p>

<p>Within cities' concrete canyons, "you can only get a true GPS fix about 70 percent of the time outdoor, but you get two satellites all the time," Morgan said. "In the entire footprint, we're able to use this hybrid technology, even though GPS is only available 70 percent of the time." Outside of metro areas, cell towers can still be used to improve GPS startup times.</p>

<p>Skyhook has continued to expand its European coverage for WPS; they cover about 8,000 cities in the US and Canada, which is roughly 70 percent of the population; "it looks exactly like a cellular coverage map," Morgan said, and includes "any town with five streets in it."</p>

<p>In Europe, their current big push, partly because of their inclusion in the iPhone, they cover 70 percent of population in the current countries--the UK, France, and Germany--but they're now at 50 percent of the population of the rest of Western Europe. They're working assiduously in Japan, Korea, Hong Kong, and Australia as well, and looking into China and India. India has very little Wi-Fi, so they may rely more on cell towers there.</p>

<p>The company also announced a <a href="http://www.skyhookwireless.com/press/skyhookcsr.php"><strong>partnership with wireless chip maker CSR today</strong></a>, which is a major providers of Wi-Fi and Bluetooth chips to computer and handset makers. Nearly a year and a half ago, Skyhook <a href="http://www.skyhookwireless.com/press/skyhooksirf.php"><strong>partnered with SiRF</strong></a>, the dominant worldwide chip supplier for stand-alone GPS gear, that's also making a push into mobile devices. Skyhook obviously needs a win with a cell chip maker, like Infineon, Broadcom, or Qualcomm, given the XPS technology, to score a place in tens of millions of cell phones beyond the iPhone.</p>

<p>Skyhook's technology most recently appeared in a soon-to-ship model of the Eye-Fi--the <a href="http://www.eye.fi/products/explore/"><strong>Explore</strong></a>. The $130 Secure Digital card with Wi-Fi built in allows you to take pictures with any camera, and have the Wi-Fi signal space recorded for later lookup when you upload photos. The pictures are geotagged with that information. The card can optionally be used with Wayport's 10,000 strong Wi-Fi network in the U.S for $15 extra per month. David Pogue of The New York Times <strong><a href="http://www.nytimes.com/2008/06/26/technology/personaltech/26pogue.html?_r=1&amp;oref=slogin">recently wrote up</a></strong> the Eye-Fi Explore.</p>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 06:25:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gps">gps</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/a-gps">a-gps</category>
      <category domain="http://securityratty.com/tag/stand-alone gps gear">stand-alone gps gear</category>
      <category domain="http://securityratty.com/tag/gps system grab">gps system grab</category>
      <category domain="http://securityratty.com/tag/skyhook">skyhook</category>
      <category domain="http://securityratty.com/tag/gps-only device">gps-only device</category>
      <category domain="http://securityratty.com/tag/gps chips">gps chips</category>
      <category domain="http://securityratty.com/tag/gps radios">gps radios</category>
      <source url="http://wifinetnews.com/archives/008384.html">Skyhook Expands Wi-Fi Positioning to Cell, GPS</source>
    </item>
  </channel>
</rss>
