<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: jersey]]></title>
    <link>http://securityratty.com/tag/jersey</link>
    <description></description>
    <pubDate>Sun, 27 Apr 2008 05:43:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Facebook tests New Jersey's icon for reporting predators, pornography]]></title>
      <link>http://securityratty.com/article/f9b4025d1e8bd046aee9568b5fc3fb56</link>
      <guid>http://securityratty.com/article/f9b4025d1e8bd046aee9568b5fc3fb56</guid>
      <description><![CDATA[Facebook Inc. is testing an icon created by the state of New Jersey to provide online users with a way to report predators and inappropriate content to law enforcement...]]></description>
      <content:encoded><![CDATA[Facebook Inc. is testing an icon created by the state of New Jersey to provide online users with a way to report predators and inappropriate content to law enforcement authorities.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=G66fwO"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=G66fwO" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/383372794" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/law enforcement authorities">law enforcement authorities</category>
      <category domain="http://securityratty.com/tag/provide online users">provide online users</category>
      <category domain="http://securityratty.com/tag/icon">icon</category>
      <category domain="http://securityratty.com/tag/report predators">report predators</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/383372794/article.do">Facebook tests New Jersey's icon for reporting predators, pornography</source>
    </item>
    <item>
      <title><![CDATA[Facebook tests New Jersey's icon for reporting predators, pornography]]></title>
      <link>http://securityratty.com/article/b954cf35f88f1556626a3c5f539d2b1b</link>
      <guid>http://securityratty.com/article/b954cf35f88f1556626a3c5f539d2b1b</guid>
      <description><![CDATA[Facebook Inc. is testing an icon created by the state of New Jersey to provide online users with a way to report predators and inappropriate content to law enforcement...]]></description>
      <content:encoded><![CDATA[Facebook Inc. is testing an icon created by the state of New Jersey to provide online users with a way to report predators and inappropriate content to law enforcement authorities.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:86b2c1ac881d298056e6a1336f38d62a:LyMvujE6gZ5JRkWTcRzipuQHz6kuv%2B7nG7%2FrejCAoynTDLUy8KCRuesrPri0p%2BLT0rPKHVvkBSJocli%2BP4m7N%2Bi7NBoMTwzqgyROPg5eL7U%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:e0815c1c3ed968deb59ffb2cc9d91344:mhhrLMsOXn1kKqu1kMHk4XFq7JmwIJxaMLAECbUv8Ugpzms4xLZftHc2voNRUjQPNo5aM9voeB1LxnbSOzMVms1qcXpCS0FkiQXdxFLXTj4%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:2d28a5adb1f59d9a9a656d3aa591fcaf:npGOw%2B8UcEtBJWkOPPvwYGE%2FBHVtK6NHrYXJie4eLddk%2FYIsZ%2B7U9iP4xE74K2B3gAkmeCc4wL%2FwEPOFb0pf%2Fqs%2ByI5k1KB6M9c4B6feZQA%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ab42b103e575645035f76d28f49d93fe:X5k%2FXDEdwWPuQ5I6rBQCYCYenu4iMkz2iEX6h%2FllQh1AbvTIalam2IFljxlnDFryfG5C9uKD9KgJSU36Tzi%2BBzBv%2BPyjPDkd2u712BVtauM%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=50fd6e4fe8bb62579eb04efaa8a612e4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=50fd6e4fe8bb62579eb04efaa8a612e4" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/law enforcement authorities">law enforcement authorities</category>
      <category domain="http://securityratty.com/tag/provide online users">provide online users</category>
      <category domain="http://securityratty.com/tag/icon">icon</category>
      <category domain="http://securityratty.com/tag/report predators">report predators</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=50fd6e4fe8bb62579eb04efaa8a612e4">Facebook tests New Jersey's icon for reporting predators, pornography</source>
    </item>
    <item>
      <title><![CDATA[Former prosecutor: U.K. hacker's extradition is inevitable]]></title>
      <link>http://securityratty.com/article/21912b4d615b7460b2e5b2b700d67cdc</link>
      <guid>http://securityratty.com/article/21912b4d615b7460b2e5b2b700d67cdc</guid>
      <description><![CDATA[A European court has held up an order to extradite Gary McKinnon to the U.S. to face charges of hacking into military computers in New Jersey and...]]></description>
      <content:encoded><![CDATA[A European court has held up an order to extradite Gary McKinnon to the U.S. to face charges of hacking into military computers in New Jersey and Virginia.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=Yn1QM4"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=Yn1QM4" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/364284819" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/extradite gary mckinnon">extradite gary mckinnon</category>
      <category domain="http://securityratty.com/tag/military computers">military computers</category>
      <category domain="http://securityratty.com/tag/european court">european court</category>
      <category domain="http://securityratty.com/tag/virginia">virginia</category>
      <category domain="http://securityratty.com/tag/held">held</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/charges">charges</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/364284819/article.do">Former prosecutor: U.K. hacker's extradition is inevitable</source>
    </item>
    <item>
      <title><![CDATA[Metro Round-Up: Cablevision Update; Springfield (Mich.)]]></title>
      <link>http://securityratty.com/article/04d2b01379cd1ae8f0505f615eab7ead</link>
      <guid>http://securityratty.com/article/04d2b01379cd1ae8f0505f615eab7ead</guid>
      <description><![CDATA[Cablevision says it's already spent $20m towards its plan to build out Wi-Fi across its operating territory: The cable firm has $300m budgeted to put Wi-Fi in place for its higher-tier subscribers at...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><a href="http://www.newsday.com/business/ny-bzwifi0801,0,5681847.story"><strong>Cablevision says it's already spent $20m towards its plan to build out Wi-Fi across its operating territory:</strong></a> The cable firm has $300m budgeted to put Wi-Fi in place for its higher-tier subscribers at no cost across Long Islands and parts of New Jersey and Connecticut, as well as New York City and Westchester County. Cablevision thinks their network will be good enough to replace cell phones across their coverage, which ties in with the quadruple play many cable operators are aiming for: data, voice, video, and mobile.</p>

<p><a href="http://www.battlecreekenquirer.com/apps/pbcs.dll/article?AID=/20080801/NEWS01/808010366/1002/NEWS01"><strong>Springfield, Mich., puts in its first antennas for a city-wide network:</strong></a> The network is being built with a $750,000 grant from a state development corporation to extend access and improve the business climate. Access will cost $10 per month for residents after an initial free period while the service powers up.</p>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 10:49:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/city-wide network">city-wide network</category>
      <category domain="http://securityratty.com/tag/cablevision">cablevision</category>
      <category domain="http://securityratty.com/tag/extend access">extend access</category>
      <category domain="http://securityratty.com/tag/initial free period">initial free period</category>
      <category domain="http://securityratty.com/tag/replace cell phones">replace cell phones</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/higher-tier subscribers">higher-tier subscribers</category>
      <category domain="http://securityratty.com/tag/development corporation">development corporation</category>
      <source url="http://wifinetnews.com/archives/008408.html">Metro Round-Up: Cablevision Update; Springfield (Mich.)</source>
    </item>
    <item>
      <title><![CDATA[New Jersey's Gift to Music]]></title>
      <link>http://securityratty.com/article/47c16bc9bb06e7ac68de07f8cff7e776</link>
      <guid>http://securityratty.com/article/47c16bc9bb06e7ac68de07f8cff7e776</guid>
      <description><![CDATA[Wow. Just wow. So the Feelies are playing together again after 18 years or so! I have really enjoyed some of the offshoots like Wake Ooloo , but I really never thought I would get to hear the real...]]></description>
      <content:encoded><![CDATA[<a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e5538ce4108834-pi"><img class="at-xid-6a00d83451c75869e200e5538ce4108834" alt="Earth86b" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e5538ce4108834-320pi" style="margin: 0px 5px 5px 0px;" /></a>Wow. Just wow. So <a href="http://www.geocities.com/thefeeliesweb/index.htm">the Feelies</a> are playing together again after 18 years or so! I have really enjoyed some of the offshoots like <a href="http://www.geocities.com/wakeooloo/">Wake Ooloo</a>, but I really never thought I would get to hear the real Feelies again. Amazing. 

If you know them you are excited as me that they are playing in Hoboken next month. If not, then everything good that REM did in the early 80s was taken from "Crazy Rhythms", and I will put "The Good Earth" with any other record.
]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 17:41:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/feelies">feelies</category>
      <category domain="http://securityratty.com/tag/real feelies">real feelies</category>
      <category domain="http://securityratty.com/tag/crazy rhythms">crazy rhythms</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/offshoots">offshoots</category>
      <category domain="http://securityratty.com/tag/80s">80s</category>
      <category domain="http://securityratty.com/tag/earth">earth</category>
      <category domain="http://securityratty.com/tag/record">record</category>
      <category domain="http://securityratty.com/tag/ooloo">ooloo</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/06/new-jerseys-gift-to-music.html">New Jersey's Gift to Music</source>
    </item>
    <item>
      <title><![CDATA[2 Congressmen Say Chinese Hacked Their Computers]]></title>
      <link>http://securityratty.com/article/6743f8154cc07735a448939ce78ae69c</link>
      <guid>http://securityratty.com/article/6743f8154cc07735a448939ce78ae69c</guid>
      <description><![CDATA[Two House members -- Virginia's Frank Wolf and New Jersey's Chris Smith -- say their Capitol Hill computers, containing information about political dissidents from around the world, have been hacked...]]></description>
      <content:encoded><![CDATA[Two House members -- Virginia's Frank Wolf and New Jersey's Chris Smith -- say their Capitol Hill computers, containing information about political dissidents from around the world, have been hacked by sources apparently working out of China.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e7ab9b930ddfc4c57295ef2f5dd62c2c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e7ab9b930ddfc4c57295ef2f5dd62c2c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=qaDifI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=qaDifI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=5lzlti"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=5lzlti" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lf8Msi"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lf8Msi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=P4qiwI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=P4qiwI" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=IodJjI"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IodJjI" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Hanpsi"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Hanpsi" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=OLl4Ki"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OLl4Ki" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TyxYjI"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TyxYjI" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/309884775" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/309884776" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 15:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/capitol hill computers">capitol hill computers</category>
      <category domain="http://securityratty.com/tag/frank wolf">frank wolf</category>
      <category domain="http://securityratty.com/tag/sources apparently">sources apparently</category>
      <category domain="http://securityratty.com/tag/chris smith">chris smith</category>
      <category domain="http://securityratty.com/tag/political dissidents">political dissidents</category>
      <category domain="http://securityratty.com/tag/virginia">virginia</category>
      <category domain="http://securityratty.com/tag/house">house</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/309884776/CHINA_HACKING">2 Congressmen Say Chinese Hacked Their Computers</source>
    </item>
    <item>
      <title><![CDATA[Bus Defended Against Terrorists Who Want to Reenact the Movie Speed ]]></title>
      <link>http://securityratty.com/article/6d6dbff9dd490080fec45cd143be3722</link>
      <guid>http://securityratty.com/article/6d6dbff9dd490080fec45cd143be3722</guid>
      <description><![CDATA[We're spending money on this ? ...a new GPS device enables authorities to remotely control a bus -- slowing it down to 5 mph and preventing it from restarting once it has stopped. The device has been...]]></description>
      <content:encoded><![CDATA[<p>We're spending money on <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">this</a>?</p>

<blockquote>...a new GPS device enables authorities to remotely control a bus -- slowing it down to 5 mph and preventing it from restarting once it has stopped. The device has been installed on thousands of local commuter and tourist buses.

<p>The technology is designed to prevent a terrorist from ramming a bus filled with people and explosives into buildings or tunnels.</p>

<p>Private bus companies have received millions of dollars from the Department of Homeland Security for the security systems. It costs $1,500 to equip each bus, with $50-per-bus monthly maintenance costs.</p>

<p>Gray Line double-decker tourist buses and Coach USA have spent hundreds of thousands of dollars in federal funds to install 3,000 devices. After receiving a $124,000 federal grant, DeCamp Bus Lines is installing the device on its 80 commuter buses, which travel routes from northern New Jersey to the Port Authority Bus Terminal in Midtown.</p>

<p>New Jersey Transit is currently in the process of equipping all of its roughly 3,000 buses with the technology. NJ Transit Chief of Police Joseph Bober said: "This enhanced technology helps us protect our bus drivers and customers. It's another proactive tool to protect our property, employees and customers."</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=7J4PZI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=7J4PZI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=zTKjoI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=zTKjoI" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 08:31:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bus">bus</category>
      <category domain="http://securityratty.com/tag/bus drivers">bus drivers</category>
      <category domain="http://securityratty.com/tag/bus companies">bus companies</category>
      <category domain="http://securityratty.com/tag/decamp bus lines">decamp bus lines</category>
      <category domain="http://securityratty.com/tag/buses">buses</category>
      <category domain="http://securityratty.com/tag/tourist buses">tourist buses</category>
      <category domain="http://securityratty.com/tag/technology helps">technology helps</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/commuter buses">commuter buses</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/bus_defended_ag.html">Bus Defended Against Terrorists Who Want to Reenact the Movie Speed </source>
    </item>
    <item>
      <title><![CDATA[LPL Financial reports eighteen compromised logons]]></title>
      <link>http://securityratty.com/article/cacd9aa988fd370cb50e60d379a7975a</link>
      <guid>http://securityratty.com/article/cacd9aa988fd370cb50e60d379a7975a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/6/08

Organization
LPL Financial

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
10,219

Types of Data
names, addresses, phone...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/lpl.jpg" align="right" height="60" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/6/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.lpl.com/">LPL Financial</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>10,219<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses, phone numbers, account numbers, Social Security numbers, and dates of birth"<br><br><span style="font-weight: bold;">Breach Description:</span><br>LPL Financial recently notified the Maryland State Attorney General of a breach in which "hackers compromised the logon passwords of fourteen financial advisors and four assistants of LPL Financial ("LPL")."&nbsp; The "hackers used these passwords to gain access to customer accounts in order to "pump and dump" penny stocks."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.oag.state.md.us/idtheft/Breach%20Notices/ITU-152079.pdf">Maryland State Attorney General breach notification</a>&nbsp; <br><br><span style="font-weight: bold;">Report Credit:</span><br>Maryland State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>We write to advise you of incidents in which hackers compromised the logon passwords of fourteen financial advisors and four assistants of LPL Financial ("LPL").<br><span style="font-style: italic;">[Evan] How does a "hacker" compromise usernames and passwords of eighteen people working for the same company?&nbsp; Compromised logon server, spear phishing, malware?</span><br><br>To our knowledge, the hackers used these passwords to gain access to customer accounts in order to "pump and dump" penny stocks.<br><br>Attempted transactions were intercepted and either rejected or reversed.<br><br>No losses were passed on to customers<br><br>Hackers compromised the logon passwords of fourteen financial advisors and four assistants in branch offices located in New Jersey, Illinois, Rhode Island, Pennsylvania, Colorado, Texas, California, Georgia and Connecticut over the course of several months.<br><br>These incidents affected approximately 10,219 individuals<br><br>The information that was potentially accessible included unencrypted names, addresses and Social Security numbers of customers and non-customer beneficiaries.<br><span style="font-style: italic;">[Evan] I don't know the architecture of LPL's network or other infrastructure components, but I question why customers or financial advisors need access to Social Security numbers as part of a trading system.&nbsp; I know that LPL needs to store Social Security numbers for tax and other reporting purposes, but financial advisors, traders and customers don't need access to them.</span><br><br>At this time, LPL has no specific knowledge that any customer information was accessed or misused as a consequence of the breach<br><br>We also are unaware of any personal instance of identity theft related to these incidents.<br><br>LPL learned of the first incident on July 16, 2007 and took the following actions: (1) notified law enforcement; (2) notified our primary regulator, the Financial Industry Regulatory Authority; (3) investigated the situation; (4) determined what information had been compromised; and (5) notified and offered solutions to the affected individuals.<br><br>LPL has taken several important steps to improve its level of data security and compliance<br><br>LPL has increased the profile of data security issues within the company at all levels, up to and including senior management.<br><br>In March 2008, LPL hired Marc Loewenthal as SVP - Chief Security/Privacy Officer, a newly created position at LPL.<br><span style="font-style: italic;">[Evan] This is the first breach notification that I have read that included this type of information.&nbsp; I don't know Mr. Loewenthal (which doesn't say too much), but I do know that he is stepping into a pressure situation.</span><br><br>Mr. Loewenthal has extensive experience in the area of data protection.&nbsp; As a member of senior management, he reports directly to the Chief Risk Officer of LPL.<br><span style="font-style: italic;">[Evan] I like when I read about information security personnel occupying "senior management" positions.&nbsp; Effective information security management needs to be as "senior" as possible in order to effect change in the organization.&nbsp; Information security governance is NOT an IT issue, but an organizational issue.&nbsp; There needs to be more good CISOs and CSOs.</span><br><br>In addition, LPL has developed a new, comprehensive information privacy and security program with new policies and procedures that were implemented in April 2008.<br><br>In August 2007, LPL engaged the services of Kroll Inc. ("Kroll"), a risk consulting company, to provide various services<br><br>In addition, LPL has commenced a project to enhance security on its advisor facing trading and operations systems in September 2007 and expects the project to complete in December 2008.<br><span style="font-style: italic;">[Evan] Details are not available, but I would be interested in knowing more.&nbsp; Maybe removal of SSNs from the advisor facing trading systems and two-factor authentication are part of the mix.</span><br><br>Finally, LPL recently engaged the services of Edwards Angell Palmer &amp; Dodge LLP to advise Mr. Loewenthal and LPL's in-house counsel as needed on information privacy and security issues.<br><br>LPL Financial is providing affected individuals with credit protection services from Kroll, Inc.<br><br>If you have any questions or feel you have an identity theft issue, please call ID TheftSmart at 1-800-588-9839 between 9:00 a.m. and 6:00 p.m. (Eastern Time), Monday through Friday.<br><br>If you want to talk to someone at LPL Financial to clarify or discuss the contents of this letter, please call us 1-800-558-7567, option 3 - Customer Service, between 9:00 a.m. and 6:00 p.m. (Eastern Time), Monday through Friday.<br><br>We apologize for any inconvenience or concern this situation may cause.<br><br>We at LPL Financial believe it is important for you to be fully informed of any potential risk resulting from this incident.<br><br>We remain committed to maintaining customer privacy as a key priority and will continue to take the needed steps to protect your information.<br><br><span style="font-weight: bold;">Commentary:</span><br>What makes this breach so interesting to me is the fact that there were at least 18 points of attack.&nbsp; I don't get the feeling that this was some sophisticated high-tech "hack" of LLP Financial's systems.&nbsp; It is much easier to craft an email or call someone and convince them to give you their login information.&nbsp; <br><br>Good luck Mr. Loewenthal, I'm sure you'll do fine! <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/20/lpl.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 04:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lpl financial">lpl financial</category>
      <category domain="http://securityratty.com/tag/lpl">lpl</category>
      <category domain="http://securityratty.com/tag/lpl financial recently">lpl financial recently</category>
      <category domain="http://securityratty.com/tag/lpl recently">lpl recently</category>
      <category domain="http://securityratty.com/tag/login information">login information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security governance">information security governance</category>
      <category domain="http://securityratty.com/tag/information privacy">information privacy</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://breachblog.com/2008/05/20/lpl.aspx">LPL Financial reports eighteen compromised logons</source>
    </item>
    <item>
      <title><![CDATA[Way to go Interpol !]]></title>
      <link>http://securityratty.com/article/07bfd5718227281c211158a01faeaa80</link>
      <guid>http://securityratty.com/article/07bfd5718227281c211158a01faeaa80</guid>
      <description><![CDATA[Interpol appeal unmasks US actor as child abuse suspect Operation IDent-ification
By John Leyden ? More by this author
Published Thursday 8th May 2008 17:44 GMT
Find out how to eradicate 99.7% of spam...]]></description>
      <content:encoded><![CDATA[<h2>Interpol appeal unmasks US actor as child abuse suspect</h2>
<h3 class="Standfirst">Operation IDent-ification</h3>
<div class="Byline">By <a title="Send email to the author" href="http://forms.theregister.co.uk/mail_author/?story_url=/2008/05/08/operation_ident_arrest/">John Leyden</a> <small class="MoreByAuthor">? <a title="More stories from this site by John Leyden" href="http://search.theregister.co.uk/?author=John%20Leyden">More by this author</a></small></div>
<div class="Date"><small>Published Thursday 8th May 2008 17:44 GMT</small></div>
<hr id="UnderDate" />
<div class="TopTextLink"><script type="text/javascript"><!--
 if (rand%5==0) {document.write('\x3Ca href="http://ad.doubleclick.net/clk;199609644;13533154;m?http://whitepapers.theregister.co.uk/paper/view/415?td=toptxt"&gt;Find out how to eradicate 99.7% of spam\x3C/a&gt;');}
 else if (rand%5==1) {document.write('\x3Ca href="http://ad.doubleclick.net/clk;199609644;13533154;m?http://whitepapers.theregister.co.uk/paper/view/419?td=toptxt"&gt;Prime yourself for security on the web: Food for thought on how to approach web security\x3C/a&gt;');}
 else if (rand%5==2) {document.write('\x3Ca href="http://ad.doubleclick.net/clk;201385165;13533154;v?http://ad.doubleclick.net/click;h=v2|3983|0|0|%2a|c;201267273;0-0;0;26465975;31-1|1;26199947|26217801|1;;%3fhttp://www.sun.com/x64/intel/tnb.jsp?cid=924497"&gt;Test Drive Sun&#039;s Quad-Core Intel Xeon systems today\x3C/a&gt;\x3Cimg src="http://ad.doubleclick.net/imp;v1;f;201267273;0-0;0;26465975;1|1;26199947|26217801|1;;cs=h%3fhttp://ad.doubleclick.net/dot.gif?'+rand+'" border="0" /&gt;');}
 else if (rand%5==3) {document.write('\x3Ca href="http://ad.doubleclick.net/clk;194493542;13533154;f?http://clk.atdmt.com/MSI/go/thrgepan0020000022msi/direct/01/"&gt;$10,000 Panda Challenge - are you really protected?\x3C/a&gt;\x3Cimg src="http://view.atdmt.com/MSI/view/thrgepan0020000022msi/direct/01/'+rand+'" /&gt;');}
 else {document.write('\x3Ca href="http://whitepapers.theregister.co.uk/paper/view/417/desktopsupportseminar?td=ttl"&gt;See what the experts have to say on attracting, retaining and developing IT talent\x3C/a&gt;');}
// --></script><a href="http://ad.doubleclick.net/clk;199609644;13533154;m?http://whitepapers.theregister.co.uk/paper/view/415?td=toptxt">Find out how to eradicate 99.7% of spam</a> <noscript>&amp;lt;a href=&#8221;http://whitepapers.theregister.co.uk/paper/view/417/desktopsupportseminar?td=toptxt&#8221;&amp;gt;See what the experts have to say on attracting, retaining and developing IT talent&amp;lt;/a&amp;gt;</noscript></div>
<p>A man matching the description of a suspected child abuser who became the target of an international manhunt earlier this week has been arrested in the US.</p>
<p>Wayne Nelson Corliss, 58, was arrested in Union City, New Jersey on Thursday - two days after Interpol published photos resembling him. The actor, whose stage name is Casey Wane, is suspected of sexually abusing at least three boys aged between six and ten in south east Asia between April 2000 and May 2001.</p>
<p><img src="http://regmedia.co.uk/2008/05/06/child_abuse_suspect.jpg" alt="" width="240" height="240" align="right" /></p>
<p>Interpol Secretary General Ronald Noble hailed Corliss&#8217;s arrest: “Two days ago, this man’s nationality, identity and location were totally unknown. All we had to go by were a series of graphic photographs in which the suspect was seen sexually abusing young children and our confidence that the public and police worldwide would once again respond&#8230; That two days later, the primary suspect is now in custody is an outstanding achievement and a credit to the citizens, media and law enforcement worldwide who responded to Interpol’s call.”</p>
<p>In March 2006, police in Norwary found images of the abuse on the PC of a convicted paedophile. Two years of police investigation failed to identify the grey-haired, bespectacled suspect, or even his nationality. This prompted Interpol to publish six pictures of the man on Tuesday, in only its second appeal to find a suspected paedophile.</p>
<p>Last year a similar appeal uncovered the identity of Canadian Christopher Paul Neil, who is in jail awaiting trial on child abuse charges. German police unscrambled an image of Neil&#8217;s face that had been &#8220;swirled&#8221; to hide his identity. The picture was contained in a cache of child abuse images, and its publication by Interpol last October quickly led to his arrest in Thailand.</p>
<p>More from Interpol <a href="http://www.interpol.int/Public/ICPO/PressReleases/PR2008/PR200815.asp">here</a>. ®</p>
]]></content:encoded>
      <pubDate>Thu, 08 May 2008 14:08:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/interpol">interpol</category>
      <category domain="http://securityratty.com/tag/interpol appeal unmasks">interpol appeal unmasks</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/german police">german police</category>
      <category domain="http://securityratty.com/tag/suspect operation ident-ification">suspect operation ident-ification</category>
      <category domain="http://securityratty.com/tag/suspect">suspect</category>
      <category domain="http://securityratty.com/tag/appeal">appeal</category>
      <category domain="http://securityratty.com/tag/interpol secretary">interpol secretary</category>
      <category domain="http://securityratty.com/tag/police investigation">police investigation</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=448">Way to go Interpol !</source>
    </item>
    <item>
      <title><![CDATA[Former Verizon Wireless employee charged with identity theft]]></title>
      <link>http://securityratty.com/article/06c9bb2496c0c73a99cb61582ab9491c</link>
      <guid>http://securityratty.com/article/06c9bb2496c0c73a99cb61582ab9491c</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/22/08

Organization
Verizon Wireless

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types of Data
Name, address,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/verizon.jpg" align="right" height="76" width="183"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/22/08<br><br>Organization: <br><a href="http://www.verizonwireless.com/b2c/index.html">Verizon Wireless</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Name, address, Social Security number, and/or Verizon Wireless account number<br><br><span style="font-weight: bold;">Breach Description:</span><br>A former employee of Verizon Wireless who worked in a telesales position has been charged with identity theft by the Somerset County, New Jersey Prosecutor's Office.&nbsp; According to Verizon Wireless, it appears that he may have taken sensitive personal information belonging to Verizon Wireless customers during his employment from November, 2003 to January, 2005.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/verizon.pdf">New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>a former Verizon Wireless telesales employee apparently obtained sensitive personal information about them from our records from late 2003 through early 2005.<br><br>Verizon Wireless is providing this notice to let you know that a former Verizon Wireless employee appears to have obtained, in violation of our policies, sensitive customer personal information, which may include your name, address, social security number, and/or Verizon Wireless account number.<br><span style="font-style: italic;">[Evan] As I have said before in other similar breaches, employee fraud is often a difficult problem for information security professionals to tackle.&nbsp; This holds especially true when dealing with positions in the company that have statistically high turnover rates, like telesales, customer service, etc.&nbsp; These employees need a certain level of access to perform their job functions, but the access that they are granted needs to be as granular as possible.&nbsp; There are many controls that we try to apply like background checks (initial and periodic), role-based access control, monitoring, etc., but sometimes even the best controls can be circumvented.&nbsp; Remember that we are not in the risk elimination business, we are in the risk reduction business.</span><br><br>This former employee was arrested on March 27, 2008<br><br>The former employee has been charged with identity theft by the Somerset County, New Jersey Prosecutor's office, and we understand that he is likely to be indicted shortly.<br><br>We do not know the exact circumstances of this theft since we have not spoken to this individual.<br><br>However, based on copies of documents provided to us by the Prosecutor's office, it appears that he may have printed computers screens containing customer's names, addresses and social security numbers.<br><br>It appears that he may have taken this sensitive information about you while he worked for us in a telesales position for a little over a year, from November 2003 to January 2005.<br><br>Approximately two years ago, long before we learned of this incident, we modified our systems so that they no longer allow telesales employees to access a customer's full social security number after that number has been used for an initial credit check.<br><span style="font-style: italic;">[Evan] This was/is a good preventative control and a wise decision.&nbsp; I assume that Verizon has an extensive risk management and information security presence within the company.&nbsp; Verizon Wireless employs roughly 69,000 people and an estimated 65.7 million customers, so you can imagine the amount of sensitive personal information that they must control.</span><br><br>Although we do not have evidence that our former employee succeeded in stealing your identity, it is possible that this occurred given the nature of his offense.<br><br>We sincerely apologize for any inconvenience this may cause you<br><br><span style="font-weight: bold;">Commentary:</span><br>Verizon Wireless is providing affected persons with one year of credit monitoring. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>None</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/27/verizon.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 27 Apr 2008 05:43:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/verizon wireless">verizon wireless</category>
      <category domain="http://securityratty.com/tag/verizon">verizon</category>
      <category domain="http://securityratty.com/tag/verizon wireless customers">verizon wireless customers</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <source url="http://breachblog.com/2008/04/27/verizon.aspx">Former Verizon Wireless employee charged with identity theft</source>
    </item>
  </channel>
</rss>
