<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: houses]]></title>
    <link>http://securityratty.com/tag/houses</link>
    <description></description>
    <pubDate>Wed, 30 Apr 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The opt-out from hell]]></title>
      <link>http://securityratty.com/article/e2ac86231138c2d34a97b7acfc4cd2ec</link>
      <guid>http://securityratty.com/article/e2ac86231138c2d34a97b7acfc4cd2ec</guid>
      <description><![CDATA[One problem with making your email address available (which I will continue to do, don't worry) is that folks with something to sell assume you're interested in their stuff. To wit, let's consider an...]]></description>
      <content:encoded><![CDATA[<p>One problem with making your email address available (which I will continue to do, don't worry) is that folks with something to sell assume you're interested in their stuff. To wit, let's consider an email I received today (copied, headers and all, after my griping).</p>  <p>Note that if I want to opt out of further communications, I have to do <em>two separate things</em> -- which actually becomes three things.</p>  <ul>   <li>First I have to click the last link to opt out of future TechTarget spam. (Yes, I deleted the actual links. But certainly none of <em>my</em> trustworthy readers would attempt to re-subscribe me, right...? &lt;g&gt; </li>    <li>But that isn't enough -- I <em>also</em> have to separately opt out of future Avaya spam! (Why does the no-more-from-Avaya link live on a techtargetmail.com server? Whatever.) Clicking on that link eventually does land me on an avaya.com page, where I have to confirm my email address and indicate they don't have my permission to send me spam. Hmm, too difficult to embed my email in that link, when the other techtargetmail.com link <em>did</em> embed my email? </li>    <li>Then after submitting it, another page pops up telling me that I'll soon receive an email with <em>additional</em> instructions! In this email there's a link -- to avaya.com with my email address embedded -- that I must click, I guess to double plus confirm that yes, I really really really do wish never to hear from you again. Clicking that link takes me to a page that promises my &quot;permissions have successfully been set. Thank you.&quot; </li> </ul>  <p>A pox on both your houses, TechTarget and Avaya. I never asked for your stuff. Go away.</p>  <p>Spam, my friends, is only going to <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/12/AR2008091201211.html?hpid=topnews" target="_blank">get</a> <a href="http://voices.washingtonpost.com/securityfix/2008/09/virginia_anti-spam_law_overtur.html?hpid=news-col-blogs" target="_blank">worse</a>. It was so easy to <a href="http://en.wikipedia.org/wiki/Junk_fax" target="_blank">ban junk faxes</a> in 1991. But even those regulations were <a href="http://en.wikipedia.org/wiki/Junk_Fax_Prevention_Act_of_2005" target="_blank">weakened in 2005</a>. So do you really think we'll see anything even remotely logical for outlawing spam? I doubt it, unless we the citizens foment a revolt. Let's get cracking! </p>  <p>&#160;</p>  <hr />  <p><font face="Courier New" size="2">Received: from SVC-EXGWY-E801.partners.extranet.microsoft.com (10.251.24.242)      <br />by tk5-exhub-c102.redmond.corp.microsoft.com (157.54.18.53) with Microsoft       <br />SMTP Server (TLS) id 8.1.291.1; Tue, 16 Sep 2008 11:27:56 -0700       <br />Received: from mail139-wa4-R.bigfish.com (216.32.181.113) by       <br />mail04.microsoft.com (10.253.160.184) with Microsoft SMTP Server (TLS) id       <br />8.1.291.1; Tue, 16 Sep 2008 11:27:55 -0700       <br />Received: from mail139-wa4 (localhost.localdomain [127.0.0.1])&#160;&#160;&#160; by       <br />mail139-wa4-R.bigfish.com (Postfix) with ESMTP id 018C11184C2&#160;&#160;&#160; for       <br />&lt;steriley@microsoft.com&gt;; Tue, 16 Sep 2008 18:27:50 +0000 (UTC)       <br />X-BigFish: ps16(zz18c1K1936K2b7wcak69jzzzz2af1jz2fh6bh5eh65h)       <br />X-Spam-TCS-SCL: 4:0       <br />Received: by mail139-wa4 (MessageSwitch) id 1221589667478982_28100; Tue, 16       <br />Sep 2008 18:27:47 +0000 (UCT)       <br />Received: from pp.techtargetmail.com (pp.techtargetmail.com [65.211.80.227])       <br />&#160;&#160;&#160; by mail139-wa4.bigfish.com (Postfix) with SMTP id 46566978071&#160;&#160;&#160; for       <br />&lt;steriley@microsoft.com&gt;; Tue, 16 Sep 2008 18:27:47 +0000 (UTC)       <br />DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=pp.techtargetmail.com; b=iOmibOrM91/1Ugy2gj3QbWo74T2m3GuhmwxZCXJQpFT+nwRES8QKg+4vjt48SNp7WWJExG61Ge+DtnKD3KVI3KwqTKzkPRVrEBF0DCHhYot6VAG/EyEr5vb5RhBz+91yvNhbIqITzGnuQ+uBDJzyc6gU0FHfBl0Fa3S/phcPELM=;       <br />Message-ID: &lt;a818b044.724694.236c8ee748f7dd97.1.n.4.2971370188@pp.techtargetmail.com&gt;       <br />Date: Tue, 16 Sep 2008 14:27:47 -0400       <br />thread-index: a818b044.724694.236c8ee748f7dd97.1.n.4       <br />Reply-To: Avaya &lt;a818b044.724694.236c8ee748f7dd97.1.n.4@pp.techtargetmail.com&gt;       <br />From: Avaya &lt;Avaya@pp.techtargetmail.com&gt;       <br />To: Steve Riley &lt;steriley@microsoft.com&gt;       <br />Subject: 7 Tips to Ensure Readiness for UC Deployment       <br />MIME-Version: 1.0       <br />Content-Type: text/plain       <br />Content-Transfer-Encoding: 7bit       <br />Content-Class: urn:content-classes:message       <br />Importance: normal       <br />Priority: normal       <br />X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4133       <br />Return-Path: a818b044.724694.236c8ee748f7dd97.1.n.4@pp.techtargetmail.com       <br />X-MS-Exchange-Organization-PRD: pp.techtargetmail.com       <br />Received-SPF: Pass (SVC-EXGWY-E801.partners.extranet.microsoft.com: domain       <br />of Avaya@pp.techtargetmail.com designates 65.211.80.227 as permitted sender)       <br />receiver=SVC-EXGWY-E801.partners.extranet.microsoft.com;       <br />client-ip=65.211.80.227; helo=mail139-wa4-R.bigfish.com;       <br />X-MS-Exchange-Organization-PCL: 2       <br />X-MS-Exchange-Organization-Antispam-Report: DV:3.3.6916.600;SV:3.3.6916.813;SID:SenderIDStatus Pass;OrigIP:65.211.80.227       <br />X-MS-Exchange-Organization-SCL: 2       <br />X-MS-Exchange-Organization-SenderIdResult: PASS</font></p>  <p><font face="Courier New" size="2">The following message was sent to you as a subscriber to third party offers from a TechTarget property, including our network of Search sites, Bitpipe.com, CIO Decisions Magazine, Information Security Magazine, Storage Magazine, KnowledgeStorm, TheServerSide.com and/or TheServerSide.NET. To unsubscribe, see below.      <br />____________________________________________________________ </font></p>  <p><font face="Courier New" size="2">How should you evaluate the move to unified communications (UC)? Who within which parts of an organization will benefit? Will UC reduce the time to market? Read this E-Guide for answers to these questions and a better look at how the value of UC will, at first, be less of a financial issue and more of a productivity improvement issue that translates into financial benefits. Download this white paper now: </font><a href="http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1"><font face="Courier New" size="2">http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1</font></a></p>  <p><font face="Courier New" size="2">When implementing unified communications, there are a number of important issues to think about and questions to ask. This E-Guide analyzes seven phases to ensure you reap the full benefits of UC in each. If you're ready to take the plunge but you're not sure your business or your infrastructure is - download this E-Guide now. </font></p>  <p><font face="Courier New" size="2">Click here to learn more: </font><a href="http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1"><font face="Courier New" size="2">http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1</font></a></p>  <p><font face="Courier New" size="2">&quot;If you do not wish to receive future promotions directly from Avaya please forward this e-mail to <u>{link removed}</u> ; please note that there is a separate opt-out procedure below to be removed from the list from which this email originated.&quot;       <br />____________________________________________________________ </font></p>  <p><font face="Courier New" size="2">Please do not reply to this email.&#160; To unsubscribe from all future third party offers from all TechTarget properties, simply click here: <u>{link removed}</u></font></a></p>  <p><font face="Courier New" size="2">TechTarget | 117 Kendrick Street, Suite 800 | Needham, MA 02494</font> </p>  <hr /><img src="http://blogs.technet.com/aggbug.aspx?PostID=3124873" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 15:22:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/smtp server">smtp server</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/smtp">smtp</category>
      <category domain="http://securityratty.com/tag/x-spam-tcs-scl">x-spam-tcs-scl</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/future avaya spam">future avaya spam</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/microsoft smtp server">microsoft smtp server</category>
      <category domain="http://securityratty.com/tag/avaya">avaya</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/16/the-opt-out-from-hell.aspx">The opt-out from hell</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[DOJ files complaint against online ad firm]]></title>
      <link>http://securityratty.com/article/e9cdf6618b5e6ba0550162bb93e58e07</link>
      <guid>http://securityratty.com/article/e9cdf6618b5e6ba0550162bb93e58e07</guid>
      <description><![CDATA[The U.S. Department of Justice is seeking to seize two houses and US$53 million from the owner of an Internet-based business allegedly engaged in a &quot;massive&quot; Ponzi scheme, the agency...]]></description>
      <content:encoded><![CDATA[The U.S. Department of Justice is seeking to seize two houses and US$53 million from the owner of an Internet-based business allegedly engaged in a "massive" Ponzi scheme, the agency said.]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/us53 million">us53 million</category>
      <category domain="http://securityratty.com/tag/ponzi scheme">ponzi scheme</category>
      <category domain="http://securityratty.com/tag/business allegedly">business allegedly</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/massive">massive</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/houses">houses</category>
      <category domain="http://securityratty.com/tag/justice">justice</category>
      <category domain="http://securityratty.com/tag/agency">agency</category>
      <source url="http://www.networkworld.com/news/2008/080608-doj-files-complaint-against-online.html?fsrc=rss-security">DOJ files complaint against online ad firm</source>
    </item>
    <item>
      <title><![CDATA[Think "liability" if you want to stay out of trouble.]]></title>
      <link>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</link>
      <guid>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</guid>
      <description><![CDATA[I speak a lot about liability, but not everyone gets it

I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard...]]></description>
      <content:encoded><![CDATA[I speak a lot about liability, but not everyone gets it.<br /><span id="fullpost"><br />I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard liability)pay little attention to potential lawsuits.  The latest category to leave themselves open, have been auctioneers. <br /></span><br />The current foreclosure crisis has meant that many properties are being auctioned off.  We have been providing security officers at some of the properties in order to make sure that people do not try to steal or commit vandalism when viewing the houses.  There was an incident recently in which a bidder decided to withdraw his offer after his bid became the winning bid.  He probaly got cold feet.<br /><br />While he should not have reneged on his offer to buy the property, it was a civil matter best left to civil remedy.  Unfortunately, the auctioneers involved decided to take the law into their own hands and would not let the man leave the property.  The man became anxious and informed them that he was having difficulty breathing and needed to go to his car for his asthma medication.  <br /><br />Was this true?  Maybe, maybe not - but would it be wise to gamble with a person's health when you already had their personal details and you could easily have obtained his vehicle registration if he decided to leave?<br />Thankfully, our security officer knew better that to get involved with blocking the man's way.  The auctioneers stood in front of his vehicle and yelled at him.  Eventually the man drove off.     <br /><br />If you represent a financial institution, a law firm or an auctioneering firm, you need to think twice before you act inappropriately.  I have no doubt that had that man had a serious attack and if he died as a result, his next of kin would have sued for umpteen millions.  When it comes to situations like this, you need to think rationally and realize what is involved.  What was the worse thing that could have happened when the person decided to renege on his offer?  <br /><br />Apparently, he would have signed forms and the like and most probably he could be sued civilly for not fulfilling his obligations after delivering the winning bid.  At the end of the day, the note holder would be in a strong position.  Even if the person had given false information and could not be subsequently located, all they had to do was to put the property back on the market.  What could that have cost, a couple of thousand in extra advertising and the like?  That would have been much better than having to pay the next of kin many millions - not to mention the bad publicity.<br /><br />We talk a lot about liability because it is a very real threat.  Think "threat mitigation".  Those who do not, may pay a very high price.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 21:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/liability">liability</category>
      <category domain="http://securityratty.com/tag/lawyers disregard liability">lawyers disregard liability</category>
      <category domain="http://securityratty.com/tag/law firm">law firm</category>
      <category domain="http://securityratty.com/tag/auctioneers stood">auctioneers stood</category>
      <category domain="http://securityratty.com/tag/auctioneers">auctioneers</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/lawyers">lawyers</category>
      <category domain="http://securityratty.com/tag/property">property</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.thebulletproofblog.com/2008/08/think-liability-if-you-want-to-stay-out.html">Think "liability" if you want to stay out of trouble.</source>
    </item>
    <item>
      <title><![CDATA[Help EFF Continue the Fight Against Warrantless Wiretapping!]]></title>
      <link>http://securityratty.com/article/cb31e91ff88905f8510b8445973f2788</link>
      <guid>http://securityratty.com/article/cb31e91ff88905f8510b8445973f2788</guid>
      <description><![CDATA[Got this in a email this morning, makes me sad, maybe you can help,,, I feel as if my concerns are not being given adequate attention with my elected officials. Especially the ones I voted into...]]></description>
      <content:encoded><![CDATA[<pre>Got this in a email this morning, makes me sad, maybe you can help,,,
I feel as if my concerns are not being given adequate
attention with my elected officials.
Especially the ones I voted into office.

Dear Friend of Freedom,

In a move that I can only describe as cowardice, Congress
just passed legislation meant to immunize telephone
companies for their illegal, disloyal, and irresponsible
behavior. EFF has been fighting against telecom immunity,
and we need your help to bring the fight to the next level:

<a class="moz-txt-link-freetext" href="http://secure.eff.org/wiretapping">http://secure.eff.org/wiretapping</a>

Two and a half years ago, EFF sued AT&amp;T on behalf of its
customers, seeking to hold the telecom giant responsible
for its craven complicity in the White House&#8217;s illegal
warrantless wiretapping program.

Since then, the phone companies and their allies in
Washington have spent tens of millions of dollars lobbying
Congress to grant them retroactive immunity. They ran
ridiculous fear-mongering attack ads against any politician
who dared to oppose them. President Bush threatened to veto
any bill that allowed EFF&#8217;s lawsuit to continue.

Yesterday, Congress completely capitulated to the
President&#8217;s threats and voted to let the telecoms off the
hook. If the telecoms are not held accountable, the
administration will remain unchecked in its warrantless
wiretapping of innocent Americans. This must stop!

We need your help to take the fight to the next level.
We&#8217;re going to challenge Congress&#8217;s unconstitutional grant
of immunity in our case against AT&amp;T. We&#8217;re going to fight
for a congressional repeal of immunity in the next
Congress. And we&#8217;re going to file a new lawsuit against the
government, challenging its warrantless surveillance
practices, past, present and future.

Now, more than ever, we need your support!

<a class="moz-txt-link-freetext" href="http://secure.eff.org/wiretapping">http://secure.eff.org/wiretapping</a>

The fight for civil liberties would never have come this
far without your help. We can&#8217;t give up now. Help EFF
today!

Sincerely,
Shari

&#8211;
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
Shari Steele
Executive Director
Electronic Frontier Foundation
454 Shotwell Street
San Francisco CA 94110
<a class="moz-txt-link-freetext" href="http://www.eff.org/">http://www.eff.org/</a>

Membership &amp; donation queries:
<a class="moz-txt-link-abbreviated" href="mailto:membership@eff.org">membership@eff.org</a>

All other queries:
<a class="moz-txt-link-abbreviated" href="mailto:information@eff.org">information@eff.org</a></pre>
]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 10:18:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eff">eff</category>
      <category domain="http://securityratty.com/tag/eff sued att">eff sued att</category>
      <category domain="http://securityratty.com/tag/fight">fight</category>
      <category domain="http://securityratty.com/tag/warrantless">warrantless</category>
      <category domain="http://securityratty.com/tag/immunity">immunity</category>
      <category domain="http://securityratty.com/tag/retroactive immunity">retroactive immunity</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/congress completely">congress completely</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=499">Help EFF Continue the Fight Against Warrantless Wiretapping!</source>
    </item>
    <item>
      <title><![CDATA[Coreflood, more Microsoft-Yahoo, iPhone plans]]></title>
      <link>http://securityratty.com/article/2facb816dd1e0eee0e3cf51555779434</link>
      <guid>http://securityratty.com/article/2facb816dd1e0eee0e3cf51555779434</guid>
      <description><![CDATA[A Trojan horse program that has been around for about six years is now being used to steal system-administrator passwords, including those at banking and brokerage houses, according to security...]]></description>
      <content:encoded><![CDATA[A Trojan horse program that has been around for about six years is now being used to steal system-administrator passwords, including those at banking and brokerage houses, according to security researchers. And it could be that six years from now we'll still be talking about Microsoft's aim to buy Yahoo's search business, which could involve obtaining the entire company and breaking it apart. Meanwhile, early adopters will undoubtedly be out in force on July 11 to be among the first to buy the new iPhone 3G.]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trojan horse program">trojan horse program</category>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/entire company">entire company</category>
      <category domain="http://securityratty.com/tag/brokerage houses">brokerage houses</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/involve">involve</category>
      <source url="http://www.networkworld.com/news/2008/070308-coreflood-more-microsoft-yahoo-iphone.html?fsrc=rss-security">Coreflood, more Microsoft-Yahoo, iPhone plans</source>
    </item>
    <item>
      <title><![CDATA[42 Days In A Hole?]]></title>
      <link>http://securityratty.com/article/cca674dee75b546491e9846bc571c44c</link>
      <guid>http://securityratty.com/article/cca674dee75b546491e9846bc571c44c</guid>
      <description><![CDATA[Jeebus. The UK govt has apparently been into the Bush White Houses private stash of recreational horticulture
Being commanded about by the child-monster has slowed down my news consumption. So, big...]]></description>
      <content:encoded><![CDATA[<p>Jeebus. The UK gov&#8217;t has apparently been into the Bush White House&#8217;s private stash of recreational horticulture. </p>
<p>Being commanded about by the child-monster has slowed down my news consumption. So, big thanks to Portswigger for the heads up. Apparently the UK gov&#8217;t wants to set the new detention limit without charges to 42 days. This has triggered a firestorm.</p>
<p>From BBC:</p>
<blockquote><p>Shadow home secretary David Davis has resigned as an MP.</p>
<p>He is to force a by-election in his Haltemprice and Howden constituency which he will fight on the issue of the new 42-day terror detention limit.</p>
<p>Mr Davis told reporters outside the House of Commons he believed his move was a &#8220;noble endeavour&#8221; to stop the erosion of British civil liberties.</p>
<p>The 59-year-old is one of the best known Tory MPs and his resignation came as a complete surprise in Westminster.</p>
<p>He told reporters outside the Commons: &#8220;I will argue in this by-election against the slow strangulation of fundamental British freedoms by this government.&#8221;</p>
<p>BBC Political Editor Nick Robinson said it was an extraordinary move which was almost without precedent in British politics. </p></blockquote>
<p>Read on.</p>
<p><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/7450627.stm">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=VYFdtX"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=VYFdtX" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=wECTXI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=wECTXI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=MCOcRi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=MCOcRi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=VDLfni"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=VDLfni" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=gym2Ri"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=gym2Ri" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YWzh7i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YWzh7i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/310417717" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 09:58:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/british civil liberties">british civil liberties</category>
      <category domain="http://securityratty.com/tag/extraordinary move">extraordinary move</category>
      <category domain="http://securityratty.com/tag/bush white houses">bush white houses</category>
      <category domain="http://securityratty.com/tag/fundamental british freedoms">fundamental british freedoms</category>
      <category domain="http://securityratty.com/tag/recreational horticulture">recreational horticulture</category>
      <category domain="http://securityratty.com/tag/news consumption">news consumption</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/detention limit">detention limit</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/310417717/">42 Days In A Hole?</source>
    </item>
    <item>
      <title><![CDATA[PCI compliance, building the base]]></title>
      <link>http://securityratty.com/article/ddd7130b171cf628c993b909a4292619</link>
      <guid>http://securityratty.com/article/ddd7130b171cf628c993b909a4292619</guid>
      <description><![CDATA[Blogger: Randall Gamby
An alarming trend is beginning to surface within SMB PCI compliant companies, like Hannaford Brothers ( http://www.networkworld.com/news/2008/031708-hannaford-data-breach.html...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>An alarming trend is beginning to surface within SMB “PCI compliant” companies, like Hannaford Brothers (<a href="http://www.networkworld.com/news/2008/031708-hannaford-data-breach.html">http://www.networkworld.com/news/2008/031708-hannaford-data-breach.html</a>), Okemo Mountain Resort (<a href="http://www.okemo.com/okemowinter/security_update.asp">http://www.okemo.com/okemowinter/security_update.asp</a>), etc. Credit data is being stolen!&nbsp; While this is exceedingly bad, I have a theory on why this is happening.&nbsp; </p>

<p>Before I get into my theory I’d first like to talk about military bases.&nbsp; As we all know, the military contains a lot of top secret information.&nbsp; So how does, say the U.S. Army, protect it?&nbsp; First, they classify what information needs to be protected.&nbsp; Next they find a piece of property that they can physically secure.&nbsp; Once the property has been thoroughly checked (no listening devices or mines buried in the ground) they construct a series of secure buildings to house the data. They then put up a fence with a limited number of gates with guard houses and guards to protect it. Then, most importantly, after certifying the security of the base, they use sentries to periodically patrol the perimeter of the grounds to ensure unauthorized access is not gained by spies sneaking in under the fence.</p>

<p>So what does this have to do with PCI compliance for SMBs?&nbsp; Well the process of PCI certification is similar to what a military branch would do to secure their information.&nbsp; Enterprises identify and classify what data falls under PCI compliance. They validate that the systems that contain the information are controlled properly and are locked down through processes and technologies. Then they build a fence of security around the systems to ensure only properly authorized personnel have access to them.&nbsp; Finally they certify that the protections meet PCI compliance requirements. But unlike the military, I theorize that a lot of SMBs, short on personnel and resources, quit here.&nbsp; In exploring the topic I’ve found that there’s an attitude by some executives that PCI compliance is a gate.&nbsp; Once SMB organizations achieve PCI compliance, some move on to the next pressing security problem.&nbsp; But this is the wrong attitude.&nbsp; Just as the military found out eons ago, they must be constantly on guard because spies are always looking for kinks in the defense perimeter in order to slip in and gain access to information without authorization.&nbsp; </p>

<p>It seems that SMBs are the most at risk of not having “guard patrols” constantly patrolling the perimeter due to the cost and resources needed to monitor and report on the security’s on-going effectiveness and the bad guys are now sneaking in stealing the very data they created these defenses to protect. </p>

<p>So what’s the warning? Whether you’re a SMB or Global Enterprise, PCI compliance is a gate, that’s pretty much a fact, but it can’t be left unguarded.&nbsp; Time, money and resources must be allocated on an on-going basis else the bad guys will sneak in undetected and you may find yourself making a breach disclosure that wasn’t detected until it was too late.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/310488267" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 07:54:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/pci compliance requirements">pci compliance requirements</category>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/top secret information">top secret information</category>
      <category domain="http://securityratty.com/tag/military branch">military branch</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/guard">guard</category>
      <category domain="http://securityratty.com/tag/guard houses">guard houses</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/310488267/pci-compliance.html">PCI compliance, building the base</source>
    </item>
    <item>
      <title><![CDATA[PCI compliance, building the base]]></title>
      <link>http://securityratty.com/article/76ccae9d968892639b29b7cad153cd24</link>
      <guid>http://securityratty.com/article/76ccae9d968892639b29b7cad153cd24</guid>
      <description><![CDATA[Blogger: Randall Gamby
An alarming trend is beginning to surface within SMB ???PCI compliant??? companies, like Hannaford Brothers (...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>An alarming trend is beginning to surface within SMB ???PCI compliant??? companies, like Hannaford Brothers (<a href="http://www.networkworld.com/news/2008/031708-hannaford-data-breach.html">http://www.networkworld.com/news/2008/031708-hannaford-data-breach.html</a>), Okemo Mountain Resort (<a href="http://www.okemo.com/okemowinter/security_update.asp">http://www.okemo.com/okemowinter/security_update.asp</a>), etc. Credit data is being stolen!&nbsp; While this is exceedingly bad, I have a theory on why this is happening.&nbsp; </p>

<p>Before I get into my theory I???d first like to talk about military bases.&nbsp; As we all know, the military contains a lot of top secret information.&nbsp; So how does, say the U.S. Army, protect it?&nbsp; First, they classify what information needs to be protected.&nbsp; Next they find a piece of property that they can physically secure.&nbsp; Once the property has been thoroughly checked (no listening devices or mines buried in the ground) they construct a series of secure buildings to house the data. They then put up a fence with a limited number of gates with guard houses and guards to protect it. Then, most importantly, after certifying the security of the base, they use sentries to periodically patrol the perimeter of the grounds to ensure unauthorized access is not gained by spies sneaking in under the fence.</p>

<p>So what does this have to do with PCI compliance for SMBs?&nbsp; Well the process of PCI certification is similar to what a military branch would do to secure their information.&nbsp; Enterprises identify and classify what data falls under PCI compliance. They validate that the systems that contain the information are controlled properly and are locked down through processes and technologies. Then they build a fence of security around the systems to ensure only properly authorized personnel have access to them.&nbsp; Finally they certify that the protections meet PCI compliance requirements. But unlike the military, I theorize that a lot of SMBs, short on personnel and resources, quit here.&nbsp; In exploring the topic I???ve found that there???s an attitude by some executives that PCI compliance is a gate.&nbsp; Once SMB organizations achieve PCI compliance, some move on to the next pressing security problem.&nbsp; But this is the wrong attitude.&nbsp; Just as the military found out eons ago, they must be constantly on guard because spies are always looking for kinks in the defense perimeter in order to slip in and gain access to information without authorization.&nbsp; </p>

<p>It seems that SMBs are the most at risk of not having ???guard patrols??? constantly patrolling the perimeter due to the cost and resources needed to monitor and report on the security???s on-going effectiveness and the bad guys are now sneaking in stealing the very data they created these defenses to protect. </p>

<p>So what???s the warning? Whether you???re a SMB or Global Enterprise, PCI compliance is a gate, that???s pretty much a fact, but it can???t be left unguarded.&nbsp; Time, money and resources must be allocated on an on-going basis else the bad guys will sneak in undetected and you may find yourself making a breach disclosure that wasn???t detected until it was too late.</p></div>
]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 07:54:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/pci compliance requirements">pci compliance requirements</category>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/top secret information">top secret information</category>
      <category domain="http://securityratty.com/tag/military branch">military branch</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/credit data">credit data</category>
      <category domain="http://securityratty.com/tag/guard">guard</category>
      <source url="http://srmsblog.burtongroup.com/2008/06/pci-compliance.html">PCI compliance, building the base</source>
    </item>
    <item>
      <title><![CDATA[Data breach laws cover everyone ]]></title>
      <link>http://securityratty.com/article/28d28dac7ce9057c2a0d19f983222f1f</link>
      <guid>http://securityratty.com/article/28d28dac7ce9057c2a0d19f983222f1f</guid>
      <description><![CDATA[During the first Laptop Safety Seminar we gave in Indianapolis on April 23, I was surprised at how many questions we got from the audience about basic wireless laptop security. Of course, when my...]]></description>
      <content:encoded><![CDATA[During the first Laptop Safety Seminar we gave in Indianapolis on April 23, I was surprised at how many questions we got from the audience about basic wireless laptop security. Of course, when my co-presenter Kim Brand of sponsor FileEngine demonstrated how easy it is to hack a Windows computer over the type of Wi-Fi service provided by coffee houses and hotels, the questions started coming even faster.]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptop safety seminar">laptop safety seminar</category>
      <category domain="http://securityratty.com/tag/co-presenter kim brand">co-presenter kim brand</category>
      <category domain="http://securityratty.com/tag/coffee houses">coffee houses</category>
      <category domain="http://securityratty.com/tag/windows computer">windows computer</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/sponsor fileengine">sponsor fileengine</category>
      <category domain="http://securityratty.com/tag/wi-fi service">wi-fi service</category>
      <category domain="http://securityratty.com/tag/hotels">hotels</category>
      <category domain="http://securityratty.com/tag/indianapolis">indianapolis</category>
      <source url="http://www.networkworld.com/columnists/2008/042808gaskin.html?fsrc=rss-security">Data breach laws cover everyone </source>
    </item>
  </channel>
</rss>
