<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: inflict]]></title>
    <link>http://securityratty.com/tag/inflict</link>
    <description></description>
    <pubDate>Thu, 17 Jan 2008 04:35:09 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Employee Fraud Spiralling Out of Control in the UK]]></title>
      <link>http://securityratty.com/article/e73530104c782e83900fa4a31dabab72</link>
      <guid>http://securityratty.com/article/e73530104c782e83900fa4a31dabab72</guid>
      <description><![CDATA[You have read it before on TheBulletProofBlog - the tougher times get, the more likelihood that people will resort to criminal measures


We reported it regarding the theft of copper from Churches,...]]></description>
      <content:encoded><![CDATA[You have read it before on TheBulletProofBlog - the tougher times get, the more likelihood that people will resort to criminal measures.  <br /><br /><span id="fullpost"><br />We reported it regarding the theft of copper from Churches, Hospitals, Schools - even from new homes still under construction.  We brought to your attention the fact that thieves have become bolder, evidenced by the theft of manhole covers in public streets and drilling into fuel tanks on vehicles as petrol and diesel prices rise.<br /></span><br />In "<a href="http://www.personneltoday.com/articles/2008/09/01/47259/employee-fraud-rises-as-credit-crunch-hits.html">Personneltoday</a>", it is reported that employers have been put on "red alert" as the downturn in the economy is prompting employees to make ends meet by dishonest means.  One figure that employers every where are bound to find shocking is the fact that employee fraud has cost UK companies more than 77 Million Pounds Sterling (approx. $150,000,000.00),just in the first half of this year alone.<br /><br />The most disturbing aspect of this figure is the fact that it is up from 10 Million Pounds Sterling (approx. $18,000,000.00)in the same period last year.  This represents more than an 8 fold increase in employee fraud in a 12 month period.<br /><br />The report was conducted by the accountancy firm BDO Stoy Hayward.  Mr. Simon Bevan, the head of fraud services there attributes the escalation in criminal activity amongst employees to; "spiralling personal debt as a result of mortgage,food and fuel price hike".  Sound familiar?<br /><br />The population of the UK is one sixth that of the United States.  It is frightening to imagine what the figures will look like from U.S. businesses at the end of this year and beyond.  In 2002, employee fraud and abuse cost U.S. businesses $6 Billion Dollars (independently reported by the "Association of Certified Fraud Examiners" of which SEXTON is a member).<br /><br />What would be the outcome to U.S, businesses if fraud costs escalated 8 fold to $48 Billion Dollars by year's end?  How many would go under? How much further damage would that inflict on the already struggling economy?  The economic circumstances in the U.S. are certainly similar to those of the UK.  <br /><br />U.S. businesses beware.  Be proactive and fight fraud and abuse before it is too late.  Your very survival just may depend upon it.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 06:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/businesses beware">businesses beware</category>
      <category domain="http://securityratty.com/tag/million pounds">million pounds</category>
      <category domain="http://securityratty.com/tag/billion dollars">billion dollars</category>
      <category domain="http://securityratty.com/tag/period">period</category>
      <category domain="http://securityratty.com/tag/fold increase">fold increase</category>
      <category domain="http://securityratty.com/tag/fold">fold</category>
      <category domain="http://securityratty.com/tag/fuel price hike">fuel price hike</category>
      <source url="http://www.thebulletproofblog.com/2008/09/employee-fraud-spiralling-out-of.html">Employee Fraud Spiralling Out of Control in the UK</source>
    </item>
    <item>
      <title><![CDATA[Listen up IT geeks and users alike!]]></title>
      <link>http://securityratty.com/article/6ea6fa125a00ce3783fd2d2f44ad649c</link>
      <guid>http://securityratty.com/article/6ea6fa125a00ce3783fd2d2f44ad649c</guid>
      <description><![CDATA[You gotta read this great article about online security. The author should run for president. His common sense is a breath of fresh air. Great Article, Im reading part II now


clipped from...]]></description>
      <content:encoded><![CDATA[<div > You gotta read this great article about online security.<br/>The author should run for president. His common sense is a breath of fresh air.<br/>Great Article, Im reading part II now. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/62BA819F-0E18-4C65-AC12-D9D08D5CB3B6/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/ac933c46-9c8a-428d-8832-81a843861ed2/62BA819F-0E18-4C65-AC12-D9D08D5CB3B6/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://technet.microsoft.com/en-us/magazine/cc626076.aspx" href="http://technet.microsoft.com/en-us/magazine/cc626076.aspx" style="font-size: 11px;">technet.microsoft.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://technet.microsoft.com/en-us/magazine/cc626076.aspx --><SPAN class="ColumnSmallHead">Passwords and Credit Cards, Part 1</SPAN></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://technet.microsoft.com/en-us/magazine/cc626076.aspx --><DIV class="ArticleNormalPara" id="id0080007">Some days it feels like most of the security advice and many of the security technologies we inflict upon our users is inactionable, incorrect, incomprehensible, or (in many cases) some combination of the three. In this three-part series, I am going to look at some of the ways we confuse users by giving advice and deploying technologies that are guilty of one or more of these three I&#8217;s. </DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/62BA819F-0E18-4C65-AC12-D9D08D5CB3B6/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Mon, 07 Jul 2008 16:38:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/technologies">technologies</category>
      <category domain="http://securityratty.com/tag/security technologies">security technologies</category>
      <category domain="http://securityratty.com/tag/security advice">security advice</category>
      <category domain="http://securityratty.com/tag/advice">advice</category>
      <category domain="http://securityratty.com/tag/confuse users">confuse users</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/fresh air">fresh air</category>
      <category domain="http://securityratty.com/tag/common sense">common sense</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=495">Listen up IT geeks and users alike!</source>
    </item>
    <item>
      <title><![CDATA[The Epileptics Forum Attack]]></title>
      <link>http://securityratty.com/article/ca92d922ea8c6553fec97674a5570733</link>
      <guid>http://securityratty.com/article/ca92d922ea8c6553fec97674a5570733</guid>
      <description><![CDATA[Now that's a weird example of a successful targeted attack abusing epileptics' photo sensitivity . Hackers post seizure causing flashing images at an Epileptics forum

Internet griefers descended on...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/R_CS8V281EI/AAAAAAAABgw/-U3g0FlwCyY/s1600-h/epilepsy_forum_seizure_attack.jpg"><img id="BLOGGER_PHOTO_ID_5183804736460870722" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R_CS8V281EI/AAAAAAAABgw/-U3g0FlwCyY/s200/epilepsy_forum_seizure_attack.jpg" border="0" /></a>Now that's a weird example of a <a href="http://it.slashdot.org/article.pl?no_d2=1&amp;sid=08/03/29/206207">successful targeted attack abusing epileptics' photo sensitivity</a>. <a href="http://www.wired.com/politics/security/news/2008/03/epilepsy">Hackers post seizure causing flashing images at an Epileptics forum</a> :<br /><br />"<em>Internet griefers descended on an epilepsy support message board last weekend and used JavaScript code and flashing computer animation to trigger migraine headaches and seizures in some users. The nonprofit Epilepsy Foundation, which runs the forum, briefly closed the site Sunday to purge the offending messages and to boost security. The incident, possibly the first computer attack to inflict physical harm on the victims, began Saturday, March 22, when attackers used a script to post hundreds of messages embedded with flashing animated gifs.</em>"<br /><br />Mentioning the attack would mean nothing if I'm not to provide screenshots of the forum postings courtesy of user Pedrobear, and the actual seizure image used, which in the case of this attack was <strong>pics.ohlawd.net/img/seizure.gif</strong>.<strong> </strong>And if you think <strong>seizure.gif</strong> is mean, <a href="http://www.ukpuzzle.com/puzzles/014.jpg">optical illusions such as this one</a> can cause the same effects to everyone if you're to stare at it for more than five seconds.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aYRGVXF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aYRGVXF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VNTaerF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VNTaerF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PXkl5lf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PXkl5lf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eBIATKf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eBIATKf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LukFrYF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LukFrYF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JofANWF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JofANWF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7EW1hGf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7EW1hGf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/261133557" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 30 Mar 2008 22:40:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/epileptics forum">epileptics forum</category>
      <category domain="http://securityratty.com/tag/forum">forum</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/seizure">seizure</category>
      <category domain="http://securityratty.com/tag/actual seizure image">actual seizure image</category>
      <category domain="http://securityratty.com/tag/epileptics">epileptics</category>
      <category domain="http://securityratty.com/tag/computer attack">computer attack</category>
      <category domain="http://securityratty.com/tag/forum postings courtesy">forum postings courtesy</category>
      <category domain="http://securityratty.com/tag/hackers post seizure">hackers post seizure</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/261133557/epileptics-forum-attack.html">The Epileptics Forum Attack</source>
    </item>
    <item>
      <title><![CDATA[Lawsuit could force RIAA to reveal investigation techniques]]></title>
      <link>http://securityratty.com/article/c9ed096c0d506dc77c82bbc2a58cbbe6</link>
      <guid>http://securityratty.com/article/c9ed096c0d506dc77c82bbc2a58cbbe6</guid>
      <description><![CDATA[A notorious RIAA case that involved the deposition of an eight-year-old girl could yet inflict major &quot;sunshine&quot; on the music industry's investigation of alleged file...]]></description>
      <content:encoded><![CDATA[A notorious RIAA case that involved the deposition of an eight-year-old girl could yet inflict major "sunshine" on the music industry's investigation of alleged file sharers.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=zbitTz"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=zbitTz" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/251177141" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Mar 2008 10:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/inflict major">inflict major</category>
      <category domain="http://securityratty.com/tag/file sharers">file sharers</category>
      <category domain="http://securityratty.com/tag/notorious riaa">notorious riaa</category>
      <category domain="http://securityratty.com/tag/investigation">investigation</category>
      <category domain="http://securityratty.com/tag/music industry">music industry</category>
      <category domain="http://securityratty.com/tag/eight-year-old girl">eight-year-old girl</category>
      <category domain="http://securityratty.com/tag/deposition">deposition</category>
      <category domain="http://securityratty.com/tag/sunshine">sunshine</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/251177141/article.do">Lawsuit could force RIAA to reveal investigation techniques</source>
    </item>
    <item>
      <title><![CDATA[Fear Is Unhealthy]]></title>
      <link>http://securityratty.com/article/b094e3e68c5ff92fd0e2aa937227f6b6</link>
      <guid>http://securityratty.com/article/b094e3e68c5ff92fd0e2aa937227f6b6</guid>
      <description><![CDATA[The New York Times writes about a plausible connection between fear and heart disease: Which is more of a threat to your health: Al Qaeda or the Department of Homeland Security
An intriguing new study...]]></description>
      <content:encoded><![CDATA[<p><i>The New York Times</i> writes about a <a href="http://www.nytimes.com/2008/01/15/science/15tier.html?_r=1&scp=1&sq=Fear+Tierney&oref=slogin">plausible connection</a> between fear and heart disease:</p>

<blockquote>Which is more of a threat to your health: Al Qaeda or the Department of Homeland Security?

<p>An intriguing new study suggests the answer is not so clear-cut. Although it’s impossible to calculate the pain that terrorist attacks inflict on victims and society, when statisticians look at cold numbers, they have variously estimated the chances of the average person dying in America at the hands of international terrorists to be comparable to the risk of dying from eating peanuts, being struck by an asteroid or drowning in a toilet.</p>

<p>But worrying about terrorism could be taking a toll on the hearts of millions of Americans. The evidence, published last week in the Archives of General Psychiatry, comes from researchers who began tracking the health of a representative sample of more than 2,700 Americans before September 2001. After the attacks of Sept. 11, the scientists monitored people’s fears of terrorism over the next several years and found that the most fearful people were three to five times more likely than the rest to receive diagnoses of new cardiovascular ailments.</p>

<p>[...]</p>

<p>After controlling for various factors (age, obesity, smoking, other ailments and stressful life events), the researchers found that the people who were acutely stressed after the 9/11 attacks and continued to worry about terrorism -- about 6 percent of the sample -- were at least three times more likely than the others in the study to be given diagnoses of new heart problems.</p>

<p>If you extrapolate that percentage to the adult population of America, it works out to more than 10 million people. No one knows what fraction of them might consequently die of a stroke or heart attack -- plenty of other factors affect heart disease -- but if it were merely 0.0003 percent, that would be higher than the 9/11 death toll.</p>

<p>Of course, statistics of any sort, even when the numbers are rock solid, don’t mean much to people when they’re assessing threats. Risk researchers have found that even when people know the numbers, they’re less worried about death tolls than about how the deaths occur. They have good reasons -- called “rival rationalities” -- for fearing catastrophes that kill large numbers at once because these events affect the whole community and damage the social fabric.</blockquote></p>

<p>It doesn't surprise me that fear of terrorism is more harmful than actual terrorism.  That's the whole point of terrorism: an amplification of fear through the mass media.</p>

<p><a href="http://www.schneier.com/blog/archives/2006/08/what_the_terror.html">Refuse to be terrorized</a>:</p>

<blockquote>The point of terrorism is to cause terror, sometimes to further a political goal and sometimes out of sheer hatred. The people terrorists kill are not the targets; they are collateral damage. And blowing up planes, trains, markets or buses is not the goal; those are just tactics. The real targets of terrorism are the rest of us: the billions of us who are not killed but are terrorized because of the killing. The real point of terrorism is not the act itself, but our reaction to the act.

<p>And we're doing exactly what the terrorists want.</p>

<p>[...]</p>

<p>The surest defense against terrorism is to refuse to be terrorized. Our job is to recognize that terrorism is just one of the risks we face, and not a particularly common one at that. And our job is to fight those politicians who use fear as an excuse to <a href="http://www.schneier.com/essay-045.html">take away</a> our liberties and promote <a href="http://en.wikipedia.org/wiki/Security_theater">security theater</a> that wastes money and doesn't make us any safer.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hy6cf9D"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hy6cf9D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8bVoWiD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8bVoWiD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=zPwrgtD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=zPwrgtD" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 17 Jan 2008 04:35:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people terrorists kill">people terrorists kill</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/actual terrorism">actual terrorism</category>
      <category domain="http://securityratty.com/tag/kill">kill</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/fear">fear</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/fearful people">fearful people</category>
      <source url="http://www.schneier.com/blog/archives/2008/01/fear_is_unhealt.html">Fear Is Unhealthy</source>
    </item>
  </channel>
</rss>
