<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hotel]]></title>
    <link>http://securityratty.com/tag/hotel</link>
    <description></description>
    <pubDate>Wed, 27 Aug 2008 09:45:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Death Toll of Hotel Bombing in Pakistan Continues to Rise]]></title>
      <link>http://securityratty.com/article/d7f9dda0825a1155b2802353af14c9f2</link>
      <guid>http://securityratty.com/article/d7f9dda0825a1155b2802353af14c9f2</guid>
      <description><![CDATA[It was no coincidence that the bombing in Islamabad which killed more than 40 and injured more than 250 was a popular place for foreigners to meet

U.S. military personnel were attending the Marriott...]]></description>
      <content:encoded><![CDATA[It was no coincidence that the <a href="http://abcnews.go.com/International/Story?id=5846991&page=2">bombing in Islamabad</a> which killed more than 40 and injured more than 250 was a popular place for foreigners to meet. <br /><span id="fullpost"><br />U.S. military personnel were attending the Marriott when the bomb exploded.  The horrific injuries were not limited to foreigners however, as many Muslims were breaking their Ramadan fast and eating there at the time. <br /></span><br />Of course, the terrorists have shown us in the past that they are not opposed to killing other Muslims as was the case in the World Trade Center bombings in 2001<br />The Islamabad Marriott was said to have been well fortified.  If it wasn't afterall, let us hope that Hotel chains like the Marriott review the security of their overseas locations.  <br /><br />One thing is for sure, any overseas location that is considered a gathering place for foreigners, especially Americans in places like Pakistan, India, etc., will continue to be Prime Targets.  Serious surveys need to be conducted and overall security needs to be enhanced.  Vehicular access needs to be closely monitored and controlled in the more hostile regions.  Marriott and all the others need to focus on counter surveillance measures to ensure the safety of their guests.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 23:39:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/islamabad">islamabad</category>
      <category domain="http://securityratty.com/tag/islamabad marriott">islamabad marriott</category>
      <category domain="http://securityratty.com/tag/marriott">marriott</category>
      <category domain="http://securityratty.com/tag/marriott review">marriott review</category>
      <category domain="http://securityratty.com/tag/counter surveillance measures">counter surveillance measures</category>
      <category domain="http://securityratty.com/tag/foreigners">foreigners</category>
      <category domain="http://securityratty.com/tag/hostile regions">hostile regions</category>
      <category domain="http://securityratty.com/tag/vehicular access">vehicular access</category>
      <category domain="http://securityratty.com/tag/overseas location">overseas location</category>
      <source url="http://www.thebulletproofblog.com/2008/09/death-toll-of-hotel-bombing-in-pakistan.html">Death Toll of Hotel Bombing in Pakistan Continues to Rise</source>
    </item>
    <item>
      <title><![CDATA[Islamabad Bomb's Secret Ingredient]]></title>
      <link>http://securityratty.com/article/31bf0779bea8cdfcc3bc2cdac41a96ed</link>
      <guid>http://securityratty.com/article/31bf0779bea8cdfcc3bc2cdac41a96ed</guid>
      <description><![CDATA[The terrorist attack on the Marriott Hotel in Islamabad, Pakistan caused massive destruction and loss of life. One of the reasons why: The bomb contained a lethal accelerant, found in some of the...]]></description>
      <content:encoded><![CDATA[The terrorist attack on the Marriott Hotel in Islamabad, Pakistan caused massive destruction and loss of life. One of the reasons why: The bomb contained a lethal accelerant, found in some of the world's most powerful munitions.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=933d6afae5f8d36930ed4f89501b1e2c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=933d6afae5f8d36930ed4f89501b1e2c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=z802L"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=z802L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=pCK6l"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=pCK6l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=VMnNl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=VMnNl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=t94OL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=t94OL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=NbM3L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=NbM3L" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=MKsrl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=MKsrl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=6mmzl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=6mmzl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=APxnL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=APxnL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/399850809" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/399850810" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 09:06:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/islamabad">islamabad</category>
      <category domain="http://securityratty.com/tag/terrorist attack">terrorist attack</category>
      <category domain="http://securityratty.com/tag/bomb">bomb</category>
      <category domain="http://securityratty.com/tag/marriott hotel">marriott hotel</category>
      <category domain="http://securityratty.com/tag/massive destruction">massive destruction</category>
      <category domain="http://securityratty.com/tag/powerful munitions">powerful munitions</category>
      <category domain="http://securityratty.com/tag/lethal accelerant">lethal accelerant</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/399850810/marriott-attack.html">Islamabad Bomb's Secret Ingredient</source>
    </item>
    <item>
      <title><![CDATA[SDL Press Tour Announcements]]></title>
      <link>http://securityratty.com/article/a59f58bb44b7c02ada643ca33c630f24</link>
      <guid>http://securityratty.com/article/a59f58bb44b7c02ada643ca33c630f24</guid>
      <description><![CDATA[Steve Lipner here

Last week I participated in a press tour talking to press and analysts about the evolution of the SDL. Most of our past discussions with press and analysts have centered on folks...]]></description>
      <content:encoded><![CDATA[<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><FONT color=#002060 size=3 face=Calibri>Steve Lipner here.</FONT></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT color=#002060 size=3 face=Calibri>&nbsp;</FONT></o:p></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><FONT size=3><FONT color=#002060><FONT face=Calibri>Last week I participated in a “press tour” talking to press and analysts about the evolution of the SDL. Most of our past discussions with press and analysts have centered on folks who follow security, but this time we also spoke with publications and analysts who write for software development organizations.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>I was struck by the extent to which the folks who focus on development have been grappling with many of the issues about developing secure software that we’ve focused on here at Microsoft.<SPAN style="COLOR: red"><o:p></o:p></SPAN></FONT></FONT></FONT></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><o:p><FONT color=#002060 size=3 face=Calibri>&nbsp;</FONT></o:p></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><FONT size=3><FONT color=#002060><FONT face=Calibri>Security beat reporters, whom we have been working with for years, have been exposed to a regular stream of news on the latest bugs, worms and viruses, and Microsoft’s ability to react quickly to customers affected by those attacks with patches has been the industry story for many years.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Last week, I had an opportunity to get out and tell the other side of the story – what we are doing proactively as a major software vendor and platform provider to help eliminate vulnerabilities during the development process.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Based on feedback from reporters and analysts who know this space, our work to take Microsoft’s SDL best practices and share them externally has clearly been a need in the industry for a long time.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></FONT></FONT></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><o:p><FONT color=#002060 size=3 face=Calibri>&nbsp;</FONT></o:p></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><FONT color=#002060 size=3 face=Calibri>The specific occasion that motivated me to spend a week in conference rooms, airplanes and hotel rooms was today’s announcement of new initiatives in sharing aspects of the SDL with the development community.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These initiatives don’t make secure development a “cut and dried” process, but I believe they will take things one step further toward enabling developers to build more secure software.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>I’d encourage you to look at our </FONT><A href="http://msdn.microsoft.com/en-us/security/cc967276.aspx"><FONT size=3 face=Calibri>announcements</FONT></A><FONT color=#002060 size=3 face=Calibri>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>I’m really excited that we’re taking these new steps to share more of our secure development practices and tools with developers who need them.</FONT></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><o:p><FONT color=#002060 size=3 face=Calibri>&nbsp;</FONT></o:p></P>
<P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal><FONT color=#002060 size=3 face=Calibri>As always, we’d welcome your feedback about these new programs and what we should do next.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8954076" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 12:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/development">development</category>
      <category domain="http://securityratty.com/tag/secure development practices">secure development practices</category>
      <category domain="http://securityratty.com/tag/software development organizations">software development organizations</category>
      <category domain="http://securityratty.com/tag/development process">development process</category>
      <category domain="http://securityratty.com/tag/press">press</category>
      <category domain="http://securityratty.com/tag/secure development">secure development</category>
      <category domain="http://securityratty.com/tag/press tour">press tour</category>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/practices">practices</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx">SDL Press Tour Announcements</source>
    </item>
    <item>
      <title><![CDATA[Sheraton Lounge with Free Wi-Fi in Central Park's Sheep Meadow]]></title>
      <link>http://securityratty.com/article/85bc48b364e027f67ed3da6a64247a80</link>
      <guid>http://securityratty.com/article/85bc48b364e027f67ed3da6a64247a80</guid>
      <description><![CDATA[Sheraton builds lounge in Central Park with Wi-Fi: It's a publicity stunt, but the hotel chain wants to promote the fact that it's updated its hotel lounges or some nonsense, so they've taken over the...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.1010wins.com/pages/2974788.php?contentType=4&contentId=2753225"><strong>Sheraton builds lounge in Central Park with Wi-Fi:</strong></a> It's a publicity stunt, but the hotel chain wants to promote the fact that it's updated its hotel lounges or some nonsense, so they've taken over the famous Sheep Meadow, blanketing it in free Wi-Fi through September, and offering snacks and such next Monday. Central Park <a href="http://www.nycgovparks.org/sub_your_park/wifi/index.html"><strong>already has some Wi-Fi</strong></a>, including at Sheep Meadow.<br />
</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:49:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sheep meadow">sheep meadow</category>
      <category domain="http://securityratty.com/tag/central park">central park</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/famous sheep meadow">famous sheep meadow</category>
      <category domain="http://securityratty.com/tag/sheraton builds lounge">sheraton builds lounge</category>
      <category domain="http://securityratty.com/tag/hotel chain">hotel chain</category>
      <category domain="http://securityratty.com/tag/publicity stunt">publicity stunt</category>
      <category domain="http://securityratty.com/tag/hotel lounges">hotel lounges</category>
      <source url="http://wifinetnews.com/archives/008443.html">Sheraton Lounge with Free Wi-Fi in Central Park's Sheep Meadow</source>
    </item>
    <item>
      <title><![CDATA[A New Security Breach in Google Docs Revealed]]></title>
      <link>http://securityratty.com/article/caf2790afa2996d6a38ac70d10ec784a</link>
      <guid>http://securityratty.com/article/caf2790afa2996d6a38ac70d10ec784a</guid>
      <description><![CDATA[I am a big fan of Google and, over time, I have started to enjoy the freedom from my desktop with Google Docs . For example, when I keep track of business expenses I have found it easier to update a...]]></description>
      <content:encoded><![CDATA[<p>I am a big fan of Google and, over time, I have started to enjoy the freedom from my desktop with <a href="http://docs.google.com/">Google Docs</a>.  For example, when I keep track of business expenses I have found it easier to update a Google Spreadsheet versus depending on Microsoft Excel on my laptop because I can update from anywhere in the world and share with my bookkeeper too.     So, I&#8217;ve been using Google Docs more lately.</p>
<p>Today, however, I discovered a huge security breach in Google Docs.  While I was in my account working on a spreadsheet I suddenly found my Google Doc account listing many documents that did not belong to me.  I clicked on one of the documents and the results are in the image below, where my Google Doc session appears to have &#8220;crossed over&#8221; with another users.</p>
<p><img style="width: 474px; height: 443px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach.jpg" alt="" /></p>
<p>I decided to do a bit more exploring and take a few more screenshots, because I don&#8217;t yet know how to reproduct this security breach.  The image below show a Google document (fifth from the top) which is not owned by me, &#8220;owned by me&#8221;. However, when I click on this mysterious &#8220;owned by me&#8221; document, it is owned by another user.  Here is another screenshot below; you can click on the image for the full-screen version.</p>
<p><a href="http://www.thecepblog.com/imgs/google.docs.security.breach2.jpg"><img style="width: 474px; height: 443px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach2.jpg" alt="" /></a></p>
<p>Again, here is another example of the same security violation with two documents. As above, you can click on the image for a full-screen version.</p>
<p><a href="http://www.thecepblog.com/imgs/google.docs.security.breach4.jpg"><img style="width: 473px; height: 442px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach4.jpg" alt="" /></a></p>
<p>I contacted the owner of the Google Docs account which I had suddenly and mysteriously &#8220;crossed sessions&#8221; with today.   I asked him if he was in Thailand (since a few of the documents were in Thai) and he said yes, however he say he did not have any Thai language documents in his account.    However, as you can see from the screenshot, the Google Docs menu shows this person as &#8220;the owner&#8221; of a Thai language document.  He also mentioned that, today, he saw &#8220;wierd documents&#8221; in his account that did not belong to him (or &#8220;normally&#8221; shared with him).</p>
<p>Unfortunately, I was having problems with the Internet connection in my hotel room so I could not continue to investigate the breach.  When I logged back in a few hours later, everything was back to normal.  So far, all is &#8220;normal&#8221; and I have not been able to repeat this breach.</p>
<p>I suspect the Google Docs flaw comes from a JavaScript error in how Google manages user sessions.  The bottom line is that the security breach is real and dangerous.  Your Google Docs, and I suspect other Google applications that use the same session management code, are vulnerable.  There may be an underlying XSS vulnerability as well.</p>
<p>Note: Reposted from my original post on the <a href="http://blog.isc2.org/isc2_blog/2008/09/serious-securit.html" target="_blank">ISC2 blog</a>.</p>
]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 07:59:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google docs">google docs</category>
      <category domain="http://securityratty.com/tag/google docs menu">google docs menu</category>
      <category domain="http://securityratty.com/tag/google docs flaw">google docs flaw</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google docs account">google docs account</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/thai language documents">thai language documents</category>
      <source url="http://www.thecepblog.com/2008/09/15/a-new-security-breach-in-google-docs-revealed/">A New Security Breach in Google Docs Revealed</source>
    </item>
    <item>
      <title><![CDATA[Too Many Events, Too Little Time]]></title>
      <link>http://securityratty.com/article/50b43f8b0380bf4469fd976197e64cf6</link>
      <guid>http://securityratty.com/article/50b43f8b0380bf4469fd976197e64cf6</guid>
      <description><![CDATA[ScienceLogicians will be scattering around the nation next week to cover 5 shows. Where well be

Interop NY
East Coast version of this major networking show. ScienceLogic is the official provider for...]]></description>
      <content:encoded><![CDATA[<p>ScienceLogicians will be scattering around the nation next week to cover 5 shows. Where we&#8217;ll be:</p>
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="107" alt="interopny" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/interopny1.gif" width="214" border="0" /> </p>
<p><a href="http://www.interop.com/" target="_blank">Interop NY</a></p>
<ul>
<li>East Coast version of this major networking show. ScienceLogic is the official provider for network monitoring and help desk for <a href="http://www.interop.com/newyork/event-highlights/interopnet/sponsors.php">InteropNet</a>, the world&#8217;s largest temporary network. See us in action in the NOC. Stop by the booth, #1045, to chat, pick up your own deck of <a href="http://www.sciencelogic.com/carddeck.htm" target="_blank">EM7 cards</a>, or fill out a <a href="http://www.sciencelogic.com/pressrelease_20071114.htm" target="_blank">survey</a> for a free t-shirt. </li>
<li>When: Conference runs from Mon 9/15 &#8211; Friday 9/19. Expo days are Wed 9/17 &#8211; Thurs 9/18. </li>
<li>Where: The Javits Center, NYC. </li>
</ul>
<p>&#160;</p>
<p>&#160;<img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="101" alt="vmware" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/vmware.png" width="296" border="0" /> </p>
<p><a href="http://www.vmworld.com/conferences/2008" target="_blank">VMworld 2008</a></p>
<ul>
<li>The largest virtualization show put on by VMware, the leader in the space. VMworld is only a couple of years old but growing like gangbusters. This year&#8217;s show should be an interesting one in light of all the turmoil surrounding VMware and Microsoft&#8217;s putsch, oops I meant push, into the space with Hyper-V. </li>
<li>When: Mon 9/15 is Partner Day. Conference runs from Tues 9/16 &#8211; Thurs 9/18 </li>
<li>Where: The Venetian Hotel, Las Vegas. </li>
</ul>
<p>&#160;</p>
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="57" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image0021.jpg" width="305" border="0" /></p>
<p><a href="http://www.hsvsummit.com/na/2008/" target="_blank">Hosting Transformation Summit</a></p>
<ul>
<li>Executive-level hosting/service provider show run by The 451 Group (and Tier 1). The analysts at The 451 Group and Tier 1 discuss state of the industry and trends. </li>
<li>When: Mon 9/15 &#8211; Wed 9/17 </li>
<li>Where: The Mirage, Las Vegas </li>
</ul>
<p>&#160;</p>
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="61" alt="clip_image002[5]" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image0025.jpg" width="304" border="0" /></p>
<p><a href="http://www.icesummit.com/na/2008/" target="_blank">ICE Summit</a></p>
<ul>
<li>Also run by The 451 Group, the ICE (Infrastructure Computing for the Enterprise) Summit will focus on &#8220;virtualization in context&#8221;. This overlaps the last day of VMworld (personally making my life a little harder). </li>
<li>When: Thurs 9/18 </li>
<li>Where: The Mirage, Las Vegas </li>
</ul>
<p>&#160;</p>
<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="85" alt="in500inc5000" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/in500inc5000.png" width="294" border="0" /> </p>
<p>Inc 500 / Inc 5000 <a href="http://secure.lenos.com/lenos/inc/Inc500WashingtonDC/" target="_blank">Conference &amp; Awards Ceremony</a></p>
<ul>
<li>Since we made it on the list (<a href="http://blog.sciencelogic.com/sciencelogic-makes-it-onto-the-inc-500-list-of-fastest-growing-private-companies-in-us/08/2008" target="_blank">#350</a>!), we thought we should show the flag at the Inc 500 conference, culminating in an awards gala on Saturday night. </li>
<li>When: Thurs 9/18 &#8211; Sat 9/20 </li>
<li>Where: Gaylord National Resort &amp; Convention Center at the National Harbor (DC) </li>
</ul>
<p>Stay tuned for live blogging and video from the various events with always lively commentary from the ScienceLogicians.</p>
]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 11:00:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/conference runs">conference runs</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/summit">summit</category>
      <category domain="http://securityratty.com/tag/transformation summit">transformation summit</category>
      <category domain="http://securityratty.com/tag/thurs">thurs</category>
      <category domain="http://securityratty.com/tag/ice summit">ice summit</category>
      <category domain="http://securityratty.com/tag/ice">ice</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://blog.sciencelogic.com/too-many-events-too-little-time/09/2008">Too Many Events, Too Little Time</source>
    </item>
    <item>
      <title><![CDATA[Best Western Forced to Play Defense on Breach Disclosure]]></title>
      <link>http://securityratty.com/article/27b346176997536a8a946fea65474769</link>
      <guid>http://securityratty.com/article/27b346176997536a8a946fea65474769</guid>
      <description><![CDATA[A dispute between Best Western and a Scottish newspaper over the scope of a data breach at the hotel chain highlighted the need from companies to get out in front on breach disclosures, rather than...]]></description>
      <content:encoded><![CDATA[A dispute between Best Western and a Scottish newspaper over the scope of a data breach at the hotel chain highlighted the need from companies to get out in front on breach disclosures, rather than being forced into damage-control mode.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=E7CyDe"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=E7CyDe" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/380148449" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 03:33:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotel chain">hotel chain</category>
      <category domain="http://securityratty.com/tag/scottish newspaper">scottish newspaper</category>
      <category domain="http://securityratty.com/tag/western">western</category>
      <category domain="http://securityratty.com/tag/breach disclosures">breach disclosures</category>
      <category domain="http://securityratty.com/tag/damage-control mode">damage-control mode</category>
      <category domain="http://securityratty.com/tag/data breach">data breach</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/dispute">dispute</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/380148449/article.do">Best Western Forced to Play Defense on Breach Disclosure</source>
    </item>
    <item>
      <title><![CDATA[If there were gold medals for Data Leakage...]]></title>
      <link>http://securityratty.com/article/9ec180dabd953b9e40bf780ac4cd7485</link>
      <guid>http://securityratty.com/article/9ec180dabd953b9e40bf780ac4cd7485</guid>
      <description><![CDATA[I've just returned from my summer vacation, somewhat foolishly deciding to spend it under canvas in the south-west of the UK and expecting to get good weather. If my tent had leaked as badly in the...]]></description>
      <content:encoded><![CDATA[I've just returned from my summer vacation, somewhat foolishly deciding to spend it under canvas in the south-west of the UK and expecting to get good weather. If my tent had leaked as badly in the last couple of weeks as data seems to have been leaking in the UK during the same period, I'd be in need of an <a href="http://en.wikipedia.org/wiki/Aqua_Lung">aqualung</a> by now! If it were an Olympic sport, Britain would have beaten China for pole position in the <a href="http://news.bbc.co.uk/sport2/hi/olympics/medals_table/default.stm">medals table</a>!
<P>
It all started with the loss of a <a href="http://news.bbc.co.uk/1/hi/uk_politics/7575989.stm">memory stick</a> by a UK Government contractor which contained somewhere around 120,000 records, including the details of 10,000 of our nation's most serious criminals. <B>We then heard about a compromise at global hotel chain Best Western...</b>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global hotel chain">global hotel chain</category>
      <category domain="http://securityratty.com/tag/olympic sport">olympic sport</category>
      <category domain="http://securityratty.com/tag/summer vacation">summer vacation</category>
      <category domain="http://securityratty.com/tag/pole position">pole position</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/government contractor">government contractor</category>
      <category domain="http://securityratty.com/tag/medals table">medals table</category>
      <category domain="http://securityratty.com/tag/memory stick">memory stick</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1334">If there were gold medals for Data Leakage...</source>
    </item>
    <item>
      <title><![CDATA[Every Time I See It, I Think About Logs]]></title>
      <link>http://securityratty.com/article/7e754795cecdb8c9e750c52bdba8758c</link>
      <guid>http://securityratty.com/article/7e754795cecdb8c9e750c52bdba8758c</guid>
      <description><![CDATA[Hotel chain now says data of just 10 guests was exposed; newspaper claims 8 million &quot; ( here

Can't they look at logs and know for sure? Hmmm

Do they have logs

Do they know whether they have logs
...]]></description>
      <content:encoded><![CDATA["Hotel chain now says data of just <span style="font-weight: bold;">10 guests </span>was exposed; newspaper claims<span style="font-weight: bold;"> 8 million</span>" (<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9113499">here</a>)<br /><br />Can't they look at logs and know for sure? Hmmm...<br /><br />Do they have logs?<br /><br />Do they know whether they have logs?<br /><br />Do they know what are logs?<br /><br />Ehmmmm...<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CtlELK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CtlELK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=vc36KK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=vc36KK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=yl7OGK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=yl7OGK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/376518778" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 10:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/hotel chain">hotel chain</category>
      <category domain="http://securityratty.com/tag/newspaper claims">newspaper claims</category>
      <category domain="http://securityratty.com/tag/ehmmmm">ehmmmm</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/guests">guests</category>
      <category domain="http://securityratty.com/tag/hmmm">hmmm</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/376518778/every-time-i-see-it-i-think-about-logs.html">Every Time I See It, I Think About Logs</source>
    </item>
    <item>
      <title><![CDATA[Best Western Rebuts Claims of Massive Data Breach]]></title>
      <link>http://securityratty.com/article/1f08218d0cf9d08a50a56ca3c551ece6</link>
      <guid>http://securityratty.com/article/1f08218d0cf9d08a50a56ca3c551ece6</guid>
      <description><![CDATA[Best Western International and the Sunday Herald newspaper of Scotland are duking it out over a story which reports that a hacker stole the records of 8 million customers from the hotel chain's global...]]></description>
      <content:encoded><![CDATA[Best Western International and the Sunday Herald newspaper of Scotland are duking it out over a story which reports that a hacker stole the records of 8 million customers from the hotel chain's global network in the "the greatest cyber-heist in world history." Best Western says 10 people were affected at one hotel.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b4a67e5ea9cc98c6e9393c741fea0fdd" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b4a67e5ea9cc98c6e9393c741fea0fdd" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TLFKNK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TLFKNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rGFaWk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rGFaWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IwFkSk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IwFkSk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AmXXuK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AmXXuK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=Guh3jK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Guh3jK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IFYaBk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IFYaBk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=sOvMck"><img src="http://feeds.wired.com/~f/wired/politics/security?i=sOvMck" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qFUDqK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qFUDqK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/376205367" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/376205368" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/western">western</category>
      <category domain="http://securityratty.com/tag/hotel chain">hotel chain</category>
      <category domain="http://securityratty.com/tag/western international">western international</category>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/sunday herald newspaper">sunday herald newspaper</category>
      <category domain="http://securityratty.com/tag/global network">global network</category>
      <category domain="http://securityratty.com/tag/million customers">million customers</category>
      <category domain="http://securityratty.com/tag/world history">world history</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/376205368/DATA_BREACH_DISPUTE">Best Western Rebuts Claims of Massive Data Breach</source>
    </item>
  </channel>
</rss>
