<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: gfi]]></title>
    <link>http://securityratty.com/tag/gfi</link>
    <description></description>
    <pubDate>Mon, 30 Apr 2007 07:11:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Q&A: E-mail spam and Software as a Service (SaaS) solutions]]></title>
      <link>http://securityratty.com/article/87c54c54327d8210db9b3ec6f7ab16b3</link>
      <guid>http://securityratty.com/article/87c54c54327d8210db9b3ec6f7ab16b3</guid>
      <description><![CDATA[David Vella is the Director of Product Management at GFI with experience in quality assurance, network administration and software development. In this Q&amp;A he provides insight into e-mail spam and...]]></description>
      <content:encoded><![CDATA[David Vella is the Director of Product Management at GFI with experience in quality assurance, network administration and software development. In this Q&A he provides insight into e-mail spam and Sof...]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 13:32:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-mail spam">e-mail spam</category>
      <category domain="http://securityratty.com/tag/quality assurance">quality assurance</category>
      <category domain="http://securityratty.com/tag/software development">software development</category>
      <category domain="http://securityratty.com/tag/network administration">network administration</category>
      <category domain="http://securityratty.com/tag/product management">product management</category>
      <category domain="http://securityratty.com/tag/david vella">david vella</category>
      <category domain="http://securityratty.com/tag/insight">insight</category>
      <category domain="http://securityratty.com/tag/sof">sof</category>
      <category domain="http://securityratty.com/tag/experience">experience</category>
      <source url="http://www.net-security.org/article.php?id=1163">Q&amp;A: E-mail spam and Software as a Service (SaaS) solutions</source>
    </item>
    <item>
      <title><![CDATA[How to Block NDR Spam]]></title>
      <link>http://securityratty.com/article/a5e63bcaba0c5cbc6bbb00dcc2552131</link>
      <guid>http://securityratty.com/article/a5e63bcaba0c5cbc6bbb00dcc2552131</guid>
      <description><![CDATA[In this paper, submitted by GFI, They provide a technical explanation of NDR Spam and recommend solutions that can prevent or limit exposure to this kind of unsolicited...]]></description>
      <content:encoded><![CDATA[In this paper, submitted by GFI, They provide a technical explanation of NDR Spam and recommend solutions that can prevent or limit exposure to this kind of unsolicited email.]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ndr spam">ndr spam</category>
      <category domain="http://securityratty.com/tag/limit exposure">limit exposure</category>
      <category domain="http://securityratty.com/tag/technical explanation">technical explanation</category>
      <category domain="http://securityratty.com/tag/recommend solutions">recommend solutions</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/gfi">gfi</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/provide">provide</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <source url="http://www.infosecwriters.com/texts.php?op=display&amp;id=628">How to Block NDR Spam</source>
    </item>
    <item>
      <title><![CDATA[Q&A: E-mail Security Threats and Countermeasures]]></title>
      <link>http://securityratty.com/article/4867e518bf8629156350b8d04e8d6209</link>
      <guid>http://securityratty.com/article/4867e518bf8629156350b8d04e8d6209</guid>
      <description><![CDATA[David Vella is the Director of Product Management at GFI with experience in quality assurance, network administration and software development. In this Q&amp;A he provides insight into e-mail security...]]></description>
      <content:encoded><![CDATA[David Vella is the Director of Product Management at GFI with experience in quality assurance, network administration and software development. In this Q&A he provides insight into e-mail security thr...]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 14:09:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-mail security thr">e-mail security thr</category>
      <category domain="http://securityratty.com/tag/quality assurance">quality assurance</category>
      <category domain="http://securityratty.com/tag/software development">software development</category>
      <category domain="http://securityratty.com/tag/network administration">network administration</category>
      <category domain="http://securityratty.com/tag/product management">product management</category>
      <category domain="http://securityratty.com/tag/david vella">david vella</category>
      <category domain="http://securityratty.com/tag/insight">insight</category>
      <category domain="http://securityratty.com/tag/experience">experience</category>
      <category domain="http://securityratty.com/tag/gfi">gfi</category>
      <source url="http://www.net-security.org/article.php?id=1142">Q&amp;A: E-mail Security Threats and Countermeasures</source>
    </item>
    <item>
      <title><![CDATA[Iowa DNR loses personal information on 7,000]]></title>
      <link>http://securityratty.com/article/3eb649001a20e2d52da1da1e282ad875</link>
      <guid>http://securityratty.com/article/3eb649001a20e2d52da1da1e282ad875</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/11/07

Organization
State of Iowa

Contractor/Consultant/Branch
Department of Natural Resources (DNR
Salem Associates

Victims
Waste water and...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/iowadnr.jpg" align="right" height="46" width="200"><font size="2"><b>Date Reported: </b><br>12/11/07<br><br><b>Organization: </b><br>State of Iowa<br><br><b>Contractor/Consultant/Branch:</b><br>Department of Natural Resources (DNR)<br>Salem Associates<br><br><b>Victims:</b><br>Waste water and drinking water worker permit applicants<br><br><b>Number Affected:</b><br>7,000<br><br><b>Types of Data:</b><br>Applicant data including names, addresses, phone numbers, and Social Security numbers.<br><br><b>Breach Description:</b><br>An employee of Salem Associates, a contractor working for the Iowa DNR lost a thumb (flash) drive containing sensitive personal information belonging to DNR waster water and drinking water permit and certification applicants.<br><br><b>Reference URL:</b><br><a href="http://www.kcrg.com/news/local/12370426.html" target="_blank"> KCRG-TV News Story</a><br><a href="http://www.radioiowa.com/gestalt/go.cfm?objectid=CF28C030-FEF8-ECE2-A269954AD5226B59" target="_blank"> Radio Iowa News Story</a><br><a href="http://desmoinesregister.com/apps/pbcs.dll/article?AID=/20071212/NEWS03/712120357/-1/LIFE04" target="_blank"> The Des Moines Register</a><br><br><b>Report Credit:</b><br>Mike Wagner, Managing Editor with KCRG-TV News<br><br><b>Response:</b><br>From the online sources cited above:<br><br>A contractor for the Iowa Department of Natural Resources lost a computer flash drive containing the names and Social Security numbers of more than 7,000 Iowans<br><br>The information on the flash drive was about people who operate water and sewage treatment plants, landfills and well-drilling operations.<br><br>the records, kept by Salem Associates of Des Moines on behalf of the DNR, were related to the certifications.<br><i>[Evan] Salem Associates is a an IT services contractor for the DNR.&nbsp; You would think that a company that makes a living off of IT would know better than to copy un-encrypted confidential data to a thumb drive.</i><br><br>Salem told DNR managers on Dec. 5 that the flash drive…went missing on Nov. 21 and probably ended up in the trash at the department's office complex in Des Moines.<br><br>Liz Christiansen, deputy director of the DNR, sent a letter to the affected people on Friday. <br><br>The records included information about retirees in addition to active workers.<br><br>Rick Hindman, an information technology supervisor at the DNR, said that Iowa government policy bans the use of flash drives to back up sensitive information but that the DNR's policy is not as specific. <br><i>[Evan] A non-specific policy is doomed to fail as is the entire program built around it.</i><br><br>The department was already reviewing its security policies when the Salem incident happened and probably will ban the use of flash drives in similar situations, he said.<br><i>[Evan] Probably?&nbsp; If the Iowa DNR decides not to ban them, I hope they at least decide to control them (encrypt).</i><br><br>State law and U.S. Environmental Protection Agency rules often require that Social Security numbers be listed on the databases, Hindman said.<br><i>[Evan] Is this true?&nbsp; Ugh, outdated regulation and bureaucracy.</i><br><br>He said it is unlikely that people could access the records even if they had the flash drive. That's because the file was a backup copy that would have to be restored, meaning the user would need the same program used to create the file - a program that isn't on many home or office computers. "The information is not encrypted, but it isn't very accessible," Hindman said.<br><i>[Evan] Just because the data "isn't very accessible" does not mean it is secure and it does not excuse the Iowa DNR from treating confidential data in risky manner.&nbsp; This is nothing more than an attempt to minimize the situation and draw attention away from the true problem(s).</i><br><br>He said the state has not received any reports of fraud or identity theft and doubts that it will.<br><br>The DNR is paying for a year's worth of credit-monitoring service for the workers. The workers have been told to contact the Iowa attorney general's office if they suspect fraud or identity theft.<br><i>[Evan] One year of credit monitoring may help all of those people who have expriring Social Security numbers.&nbsp; Do you have an expiring Social Security number?&nbsp; I don't.</i><br><br>"We sincerely apologize for the inconvenience this situation causes you and reiterate our commitment to achieving and maintaining information technology security systems," Christiansen said in her letter.<br><br><b>Victim Reaction:</b><br>"We were told the state system is secure and there is no way anyone could hack into it," - Scott Smith of the Boone County landfill and past president of the state landfill operators association.<br><br>"They don't have to hack to get the information - they are handing it out on flash drives." - Scott Smith<br><br><b>Commentary:</b><br>Breaches like this irk me.&nbsp; An employee working for an IT contractor for some reason thought it would be OK to copy confidential data onto a thumb drive.&nbsp; Thumb drives are inherently an information security nightmare if they are not properly controlled.&nbsp; They are small, high-capacity and easily lost or stolen.&nbsp; Some of the options we have explored in the past include disabling USB ports and employing technological controls (check out <a href="http://www.truecrypt.org/" target="_blank"> TrueCrypt</a>, <a href="http://www.becrypt.com/" target="_blank"> BeCrypt Connect Protect</a>, <a href="http://www.gfi.com/" target="_blank"> GFI EndPointSecurity</a> and <a href="http://www.checkpoint.com/pointsec/" target="_blank"> Pointsec</a> to name just a few).<br><br>According to a May, 2007 <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=199300021" target="_blank"> Information Week article</a>, "Thumb Drives Replace Malware As Top Security Concern"<br><br>Why is the DNR policy "not as specific"? <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/19/iowadnr.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Wed, 19 Dec 2007 11:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iowa dnr">iowa dnr</category>
      <category domain="http://securityratty.com/tag/iowa">iowa</category>
      <category domain="http://securityratty.com/tag/iowa dnr decides">iowa dnr decides</category>
      <category domain="http://securityratty.com/tag/iowa dnr lost">iowa dnr lost</category>
      <category domain="http://securityratty.com/tag/iowa department">iowa department</category>
      <category domain="http://securityratty.com/tag/dnr">dnr</category>
      <category domain="http://securityratty.com/tag/computer flash drive">computer flash drive</category>
      <category domain="http://securityratty.com/tag/drive">drive</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://breachblog.com/2007/12/19/iowadnr.aspx">Iowa DNR loses personal information on 7,000</source>
    </item>
    <item>
      <title><![CDATA[Quick Tool Update: GFI EndPointScan]]></title>
      <link>http://securityratty.com/article/92bcae0aa671ef34e1a21ae7993e850f</link>
      <guid>http://securityratty.com/article/92bcae0aa671ef34e1a21ae7993e850f</guid>
      <description><![CDATA[GIF just released a new tool that's targeted at keeping control of removable media &amp; all forms of storage devices (fixed &amp;...]]></description>
      <content:encoded><![CDATA[GIF just released a new tool that's targeted at keeping control of removable media & all forms of storage devices (fixed & temporary).]]></content:encoded>
      <pubDate>Mon, 30 Apr 2007 07:11:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/removable media">removable media</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/storage devices">storage devices</category>
      <category domain="http://securityratty.com/tag/fixed">fixed</category>
      <category domain="http://securityratty.com/tag/forms">forms</category>
      <category domain="http://securityratty.com/tag/temporary">temporary</category>
      <category domain="http://securityratty.com/tag/gif">gif</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://blogs.ittoolbox.com/security/endpoint/archives/quick-tool-update-gfi-endpointscan-16009">Quick Tool Update: GFI EndPointScan</source>
    </item>
    <item>
      <title><![CDATA[Quick Tool Update: GFI EndPointScan]]></title>
      <link>http://securityratty.com/article/c360113bd0fc4e775df3035f5355e520</link>
      <guid>http://securityratty.com/article/c360113bd0fc4e775df3035f5355e520</guid>
      <description><![CDATA[GIF just released a new tool that's targeted at keeping control of removable media &amp; all forms of storage devices (fixed &amp;...]]></description>
      <content:encoded><![CDATA[GIF just released a new tool that's targeted at keeping control of removable media & all forms of storage devices (fixed & temporary).]]></content:encoded>
      <pubDate>Mon, 30 Apr 2007 07:11:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/removable media">removable media</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/storage devices">storage devices</category>
      <category domain="http://securityratty.com/tag/fixed">fixed</category>
      <category domain="http://securityratty.com/tag/forms">forms</category>
      <category domain="http://securityratty.com/tag/temporary">temporary</category>
      <category domain="http://securityratty.com/tag/gif">gif</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/endpoint-security/quick-tool-update-gfi-endpointscan-16009">Quick Tool Update: GFI EndPointScan</source>
    </item>
  </channel>
</rss>
