<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: lady]]></title>
    <link>http://securityratty.com/tag/lady</link>
    <description></description>
    <pubDate>Tue, 06 May 2008 15:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Audacity of Capital Markets]]></title>
      <link>http://securityratty.com/article/850f85c1d4f79f75ab94faca2b325146</link>
      <guid>http://securityratty.com/article/850f85c1d4f79f75ab94faca2b325146</guid>
      <description><![CDATA[It it fairly well established that overt risk tasking, greed and corporate arrogance by financial services companies have destroyed the real estate market and crippled the global economy. Countless...]]></description>
      <content:encoded><![CDATA[<p>It it fairly well established that overt risk tasking, greed and corporate arrogance by financial services companies have destroyed the real estate market and crippled the global economy.    Countless millions of folks have lost their homes and life savings.  This corporate arrogance and greed was like a &#8220;greed virus,&#8221; spreading across the world like a plague.</p>
<p>A similar arrogance is happening in CEP-land, where, it seems, each and every financial services event processing application is now a &#8220;CEP application&#8221; just because someone in capital markets puts &#8220;CEP&#8221; in the same paragraph.     I find it ridiculous that the same market of folks who have helped destroy the global economy are now the world&#8217;s self-proclaimed authorities on complex event processing.  Amazing, if you really think about it, isn&#8217;t it?</p>
<p>I read many posts these days by folks in the capital markets trading world, claiming their message routing application is &#8220;CEP,&#8221; or their algo trading application is &#8220;CEP,&#8221;  - feeds and speed, typical of what &#8220;turns on&#8221; the financial services folks.   As an editorial note: I recall when I worked for a software company, folks on the same team who worked on Wall Street would look down on folks with many years of IT experience outside of financial services.   Some would say &#8220;he is only a security guy&#8221; in their attempt to put down anyone who does not have trading floor IT experience on their resume.    I found it all quite ridiculous and foolish.</p>
<p>My resume, for what it is worth, has a number of financial services companies, including either assessing, architecting or building large scale security systems for S.W.I.F.T, Chase or SBC.   This experience does not seem to &#8220;count&#8221; with the trading floor folks, since security is more about getting things right, not just supporting a form of gaming or gambling with other peoples money, with more feeds and speeds the better.</p>
<p>Of late, as I have watched the CEP/EP space evolve,  and unfortunately, I see a similar type of &#8220;capital markets virus&#8221; spreading into CEP-land.   Folks on the trading side of financial services seem to think that whatever they say or do is right, and whatever others outside of the trading side do is wrong.  These folks are quick to ridicule others who have far more experience than they do, outside of the trading floor of capital markets.</p>
<blockquote><p>After all, mostly what they do on the trading side is route orders -  and if a little old lady in a small town in Iowa loses her life savings because of a bad investment decision, it means little to the folks on the trading floor, the market folks are into feeds and speed - just keep the beast alive.  Place your bet on this market or that one!   Away we go, faster and faster!!!!</p></blockquote>
<p>I am sometimes a little sad to observe the same audacity in the CEP world.  Instead of focusing on the hard complex problems that require accuracy, the original set of problems defined when the phrase &#8220;complex event processing&#8221; was minted, the capital market folks have hijacked the term for their marketing purposes in algo trading and order managment systems.  These same people ridicule others who are working to solve the (originally stated) complex event processing problems, problems the capital market traders seemingly cannot understand, since they have never worked on complex network or security management problems.</p>
<p>Nevermind, that these &#8220;ultra low latency&#8221; systems cannot accurately detect a complex money laundering scheme or an elaborate fraud.   Nevermind that these &#8220;CEP engines&#8221; cannot accuracy insure that Average Joe does not lose his hard earned money in a fraud scheme.</p>
<p>I have no problem with folks in capital markets using the term CEP, but they should not ridicule those in technical areas that are not focused on keeping the &#8220;trading beast&#8221; alive so people can lose their life savings in a blink of an eye; but instead focused on solving complex problems such as the class of problems called out when the three letter acronym &#8220;CEP&#8221; was created.</p>
]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 07:18:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/capital market folks">capital market folks</category>
      <category domain="http://securityratty.com/tag/market folks">market folks</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/financial services folks">financial services folks</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/capital markets">capital markets</category>
      <category domain="http://securityratty.com/tag/hard complex">hard complex</category>
      <category domain="http://securityratty.com/tag/complex money">complex money</category>
      <source url="http://www.thecepblog.com/2008/09/19/the-audacity-of-capital-markets/">The Audacity of Capital Markets</source>
    </item>
    <item>
      <title><![CDATA[Thoughts on Token Security]]></title>
      <link>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</link>
      <guid>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</guid>
      <description><![CDATA[RSnake has a piece up on Token Security which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially...]]></description>
      <content:encoded><![CDATA[<p>RSnake has a piece up on <a href="http://www.darkreading.com/blog.asp?blog_sectionid=403">Token Security</a> which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially in a space that is as overloaded as identity. That <span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">said, I think RSnake is taking too narrow of a view, specifically B2C, on federation and tokens</span><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">. It is true that works on the web eventually filters into the enterprise, but it is also true that sometimes that things that start out as enterprise technologies later become cost effective on the web. So I would not assume that the current status quo on the web will hold. I don&#39;t think it will, the identity problems are too big and there is too much money at stake.</span></p><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I encourage you to read his article, here are some of my thoughts<br /></span><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;consumers hate tokens.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Except that people use atm cards every day. Consumers will absolutely be inconvenienced, if there is some value created. The problem today is not the token, its the lack of a value proposition to the person you are inconveniencing.&#160;</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Everyone wants to be the single federation platform for everyone else.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This will never work. and that&#39;s a good thing. i think most companies already realize this though. I think the walled garden model has gone the way of the dodo.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Federation will never work. It won’t work because the single most important consumer Web applications in the world are scared of it. Banks hate the concept because it becomes a weakest link in the chain problem.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Federation works quite well. have a look at google for one example. The reason banks hate federation is that their infosec people have a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">mainframe mindset</span></a><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">, they are focused only on resource protection. the problem is they dont run mainframes on closed networks, they went and connected it to the web and so now they need to think about subject and claim security not just resource security. its not hatred its a lack of understanding stemming from a legacy mindset.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Linking up identity providers and relying parties into a federation has been a solved problem for quite some time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Tokens don’t actually solve most security problems, like man-in-the-middle, phishing, and keystroke-logging malware.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 1. there are no silver bullets in security</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 2. dont forget rule 1</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">but...</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...there is a rule 3</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 3. just because a security mechanism doesnt solve all of our problems doesnt mean its worthless.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I see this with security consultants all the time, they playa hate on static analysis or some scanning tool where they can find hundreds of things the tool doesn&#39;t. Fair point except 99.9999% of IT can&#39;t and won&#39;t find them. Engineering is about solving one incremental problem at a time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Oh yes, and finally, consumers are going to have to carry around 13 of them just to make sure they can log into whatever they need to log into since no one will federate.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This misses the point of federation. i carry around one atm card its up to banks, Visa, Cirrus and so on to make sure i get my cash. the funny thing about banks not understanding federation is that they have the bet example right in front of their noses, the problem is its in a different department so they never see it.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Global federation is nowhere near a solid concept in the consumer space, despite what the vendors will try to sell you.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 4. do your own due diligence</span></p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Tokens and federation are important building blocks for our digital future. I will leave you with a </span><a href="http://1raindrop.typepad.com/1_raindrop/2007/01/integrated_tran.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">story</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> that</span><a href="http://en.wikipedia.org/wiki/Robert_Morris_%28cryptographer%29"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> Robert Morris Sr.</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> told at Defcon several years ago:</span></div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;This is a long term problem. If you work on it and make any progress against it, you&#39;ll find yourself much smarter at the far end, than you were at the near end.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When I was in Norway about 5 years ago, I was there very close to the summer solstice. I was wandering around town at 2 o&#39;clock in the morning and there was plenty of light out. You come to a sign that says New Minsk about 60 km and it points south.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And I ask the lady &quot;what country is this?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">She scratched her head for a bit, and said &quot;well I think its Norway&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I said &quot;well who plows the roads?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;well Norway does, but he have to pay them.&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">There is a triple boundary in this town that I was in between Norway, Finland and Russia.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">But what I did there, was, I had a card about wallet size, I stuck it into a machine, I punched in four digits, and it gave me about 2,000 krone, whatever the hell that is.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Now there are a lot of participants in that transaction. When I put a card into that machine, punch in a pin, and it gurgles for awhile, and finally gives me, a fairly large amount of money. There are a lot of participants in that transaction. The bank that owned the machine that gave me the money, it gave some money away -- that bank wants it back. The pin is necessary to convince my own bank that I&#39;m me. But I don&#39;t want my pin to be broadcast all over the world. My bank in the us, it hasn&#39;t really given out or taken in any money, really. But there is a lot of credits involved here. Somebody needs to charge somebody else for having more money&#160;available. Even though there was actually no cash transfer.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And the problem that I have in mind is</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- who are all the participants in an ATM transaction?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- what do those participants need to satisfy their problems?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- how is that in fact done?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In a general way, does the atm system actually work in some reasonable sense? To which the answer is by the way: yes. The atm system damn well works. With extremely high reliability and accuracy. It surprises me. Its quite a bit different than voting machines.</span></p></blockquote>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 12:35:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/global federation">global federation</category>
      <category domain="http://securityratty.com/tag/federation">federation</category>
      <category domain="http://securityratty.com/tag/single federation platform">single federation platform</category>
      <category domain="http://securityratty.com/tag/security mechanism">security mechanism</category>
      <category domain="http://securityratty.com/tag/resource security">resource security</category>
      <category domain="http://securityratty.com/tag/security consultants">security consultants</category>
      <category domain="http://securityratty.com/tag/consumer web applications">consumer web applications</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/thoughts-on-token-security.html">Thoughts on Token Security</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware - Part Three]]></title>
      <link>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</link>
      <guid>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</guid>
      <description><![CDATA[Continue the Fake Porn Sites Serving Malware and Fake Porn Sites Serving Malware - Part Two series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/3Th9wGTcre4/s1600-h/fake_porn_zlob_codec_localized.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/1aZSLqClTi4/s200-R/fake_porn_zlob_codec_localized.JPG" /></a>Continue the <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> and <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three different hosting locations, re-establishing connections between malicious ISPs for yet another time in between exposing the domains and the download locations sharing the same IPs.<br />
<br />
<b>downlfreesexgirlbeach .com</b> first redirects to <b>infodist1 .com/in.cgi?2 </b>then to <b>watchnenjoy.com/index.php?id=1314&amp;style=black</b>, and finally to the front end to the codec's download location <b>handmadeclips .com</b>, where the codec is downloaded from <b>fwlprocedure .com</b>.  Behind these domains, we can easily expose many other fake porn sites and pharmaceutical scams, next to a small portfolio of domains specifically used for hosting the binaries. Due to the obvious rotation I've encountered several times so far, a fake porn site today, is tomorrow's blackhat SEO content farm :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/DX-IaOAduVs/s1600-h/fake_porn_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/k9h1_E21wag/s200-R/fake_porn_august.JPG" /></a><b>downlfreesexgirlbeach .com</b> - (88.214.198.25)<br />
<b>vids365 .com<br />
downlfreesexgirlbeach .com<br />
top.only-bi .com<br />
wikiei .com<br />
paysuperporn .com<br />
aboutsexporn .com<br />
freactor .com<br />
cheapofficialpills .com<br />
finance-leaders.comnudenakedboys .com<br />
photosgayboys&nbsp; .com<br />
uniqueincest.com<br />
shyincest .com<br />
banrnd.central-xxx .com<br />
tvisklick .info<br />
thebg .net<br />
termion .net<br />
xoxvids .net<br />
bestpricepills .net<br />
bcodecnow .net</b><br />
<br />
<b>infodist1 .com</b> - (88.214.204.40)<br />
<b>farmasearch2008 .com<br />
flaxxvid .com<br />
xanax777pills .com<br />
18virgingirls .com<br />
girlnudegallaryvideox .com<br />
allxxxpornogerlsx .com<br />
jproshin .info<br />
familytaboo .info<br />
fullsitehost .info<br />
20searchonlinesite .net<br />
add-your-video .net<br />
blogs4y .net</b><br />
<br />
<div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/MaMXiAw02F8/s1600-h/downlfreesexgirlbeach_viz.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/znHGKTmbcHE/s200-R/downlfreesexgirlbeach_viz.JPG" /></a><b>adult-shemale .com</b> - (88.214.198.25)<br />
<b>adult-tranny .com<br />
all-shemale&nbsp; .com&nbsp;&nbsp;&nbsp; <br />
bcodecnow .net<br />
best-tranny .com&nbsp;&nbsp;&nbsp; <br />
bestguyportal .com<br />
bestmoviez .com&nbsp;&nbsp;&nbsp; <br />
central-xxx .com<br />
downlfreesexgirlbeach .com&nbsp;&nbsp;&nbsp; <br />
gallery-boy .com<br />
hiosexywomensxxxgirlsx .com&nbsp;&nbsp;&nbsp; <br />
lady-dick .com<br />
bcodecnow .net<br />
mytoppharmacy .com<br />
nakednudeboys .com&nbsp;&nbsp;&nbsp; <br />
nakednudemen .com<br />
nudenakedboys .com<br />
only-bi .com<br />
only-shemale .com<br />
page-reviews .com<br />
paulaslosingit .com<br />
photosgayboys .com<br />
stud-boys .com&nbsp;&nbsp;&nbsp; <br />
the0download .com<br />
wikiei .com&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; <br />
moviez .com<br />
hiosexywomensxxxgirlsx .com<br />
sexygirlsisuniformh0t .com&nbsp;&nbsp;&nbsp; <br />
the0download .com</b><br />
<br />
<b>flwprocedure .com </b>- (77.91.231.201)<b><br />
movupdate .com<br />
flwupdate .com<br />
formatmpeg .com<br />
movieexternal .com<br />
flwtool .com <br />
aviexecution .com<br />
releasedvideo .com<br />
wmvcompressor .com<br />
movieopens .com<br />
mpegapparatus .com<br />
flwassistant .com<br />
flwinstrument .com<br />
piterserv .com<br />
wovview .com</b><br />
<br />
<b>Some info on a sample codec :</b><br />
Scanners Result: 11/36 (30.56%)<br />
Trojan-Downloader.Win32.Zlob.cos<br />
Trojan.Popuper.7315<br />
File size: 10240 bytes <br />
MD5...: 467e4e78974dc8b2ee5d7da024daf31a <br />
SHA1..: 311e0c710bb15761ef3dace54b55489830cf5803<br />
<br />
Phones back to <b>69.50.164.50</b>/this/is/stereo/music.php?param=0;1314;1550; <b>69.50.164.50</b>/this/is/stereo/jazz.php?param=49325611;2:191:5|7:271:0|6:130:0|9:0:5|34:65536:0 and to <b>85.255.119.244</b>/this/is/stereo/music.php?param=0;4135;1548.<br />
<br />
When <b>Emil Kaperski's</b> owned <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">InterCage, Inc.</a> (69.50.164.50) meets <a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">UkrTeleGroup Ltd.</a> (85.255.119.244) previously known as <b>Andrei Kislizin's</b> owned InHoster, you know you're on the right track.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kUs27K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kUs27K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sRXTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sRXTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOsoWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOsoWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnooek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnooek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R3T9kK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R3T9kK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WaKp6K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WaKp6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R12pRk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R12pRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/375241515" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 05:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/sample codec">sample codec</category>
      <category domain="http://securityratty.com/tag/locations">locations</category>
      <category domain="http://securityratty.com/tag/fake porn site">fake porn site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/375241515/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</source>
    </item>
    <item>
      <title><![CDATA[Don't put your foot in it, Mr. President]]></title>
      <link>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</link>
      <guid>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</guid>
      <description><![CDATA[Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting

The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s1600-h/george-w-bush.jpg"><img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s320/george-w-bush.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5234855916132700978" /></a><br />Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting.<br /><span id="fullpost"><br />The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other side.  The President had his right foot resting on his left knee, thereby exposing his shoe sole.  That is a huge "no no" in Asia and the Middle East. <br /></span><br />As I said, thankfully the First Lady, Laura Bush was the recipient of the President's sole-waving but it made me wonder if he changed legs at a later stage and "flashed" the Chinese official.  I figure it was a high ranking official or else he would hardly be sat next to the President of the United States.<br /><br />What has this to do with security?  It is one of the topics we teach to our budding bodyguards during our intensive Executive Protection course in the United States and abroad.  You could have a very successful business meeting or trip, either overseas or at home, but ruin it by insulting (albeit unintentionally)a foreign guest.  It is very important for those wroking around forein nationals to be aware of their customs and traditions.  <br /><br />This is not that difficult these days with all of the materials available.  One of the best books I have found is; "Kiss, Bow or Shake Hands".  This book and others like it, will advise the reader on the correct course of action to take when dealing with people from a host of different countries.  Not that I expect the President to read the book, afterall, he must have Protocol officers to keep an eye on him.  My question is, were they brought to China? <br /><br />For the rest of us who are not lucky enough to have our own Protocol officers to keep us out of trouble, we'll just have to read the book.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/president">president</category>
      <category domain="http://securityratty.com/tag/president bush">president bush</category>
      <category domain="http://securityratty.com/tag/chinese official">chinese official</category>
      <category domain="http://securityratty.com/tag/official">official</category>
      <category domain="http://securityratty.com/tag/protocol officers">protocol officers</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/intensive executive protection">intensive executive protection</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/shoe sole">shoe sole</category>
      <source url="http://www.thebulletproofblog.com/2008/08/dont-put-your-foot-in-it-mr-president.html">Don't put your foot in it, Mr. President</source>
    </item>
    <item>
      <title><![CDATA[Grande Theft Auto... What Was He Thinking?]]></title>
      <link>http://securityratty.com/article/5fc9689d682ba6a01acf0996732651bd</link>
      <guid>http://securityratty.com/article/5fc9689d682ba6a01acf0996732651bd</guid>
      <description><![CDATA[Well, it didnt happen to me- but heres another J! True Security Story for you
I went to the salon today to get my nails did and was greeted with quite a ruckus. The entire staff is Vietnamese- no big...]]></description>
      <content:encoded><![CDATA[<p><strong>Well, it didn&#8217;t happen to me- but here&#8217;s another J! True Security&nbsp;Story for you&#8230; </strong></p><p>I went to the salon today to &#8216;get my nails did&#8217; and was greeted with quite a ruckus. The entire staff is Vietnamese- no big surprise there- but the owners and most employees speak English extremely well and so everyone is always chit-chatting throughout the salon. </p><p>The wife side of the husband-wife team was especially giddy as she&nbsp;shared a little gem of a story with me today&#8230; and I didn&#8217;t feel&nbsp;I&#8217;d be doing you justice to keep it to myself.&nbsp;</p><p>They (the salon staff) all live in one of the larger cities here in NC. One of their friends (a middle-aged guy) was out shopping Monday and was sitting in his car in a parking lot during a coming- or going- to a store.&nbsp;A young girl (mid-20&#8217;s) came up to his car and motioned to ask for use of his cell phone. </p><p><em>Now, at this point in the story, I could have told you the rest&#8230; </em></p><p><span class="full-image-float-right"><img style="width: 141px; height: 125px" alt="photo_girlcell.jpg" src="http://www.securityuncorked.com/storage/photo_girlcell.jpg?__SQUARESPACE_CACHEVERSION=1215058444622" /></span>He opened the window a bit and the young lady asked to borrow his phone for a moment to call a family member. Turns out she had some car troubles and needed a ride. Being the nice gentleman that he is, he lent her the phone and she took a couple of steps away to make the call. Only&#8230; she didn&#8217;t stop. Evidently she got about 4 cars down the row&nbsp;before our chivalrous guy got out of the car and gave chase. </p><p>When he got in reach, she pushed him down to the ground and - <em>yep</em> - ran back to <em>his</em> car, phone still in hand&#8230; and drove away. </p><p>He now has no car and no phone. So, ironically enough, <em>he</em> then had to approach a stranger and politely ask for the use of their cell to phone home and let the group know he was bamboozled. A few tears were shed, but his wife assured him it would be fine and he shouldn&#8217;t be scared. (No, I&#8217;m not making that up). </p><p><em>I was giggling right along with her (and the guy&#8217;s wife, who happened to be there). </em></p><p>Moments later I thought to myself, &#8220;<em>I hope that doesn&#8217;t happen to me</em>!&#8221; Almost in the same instant I realized&#8230; it probably wouldn&#8217;t. I&#8217;ve been a bit of a paranoid freak since I was little, thanks probably in most part to having two ex-military intelligence parents. For all my life I&#8217;ve been raised with <a class="offsite-link-inline" href="http://www.schneier.com/blog/archives/2008/03/the_security_mi.html" target="_blank">&#8216;the security mindset&#8217;</a>&nbsp;as <a class="offsite-link-inline" href="http://www.schneier.com/" target="_blank">Schneier</a>&nbsp;refers to it. </p><p>Always suspicious&#8230; always calculating&#8230; always aware&#8230; and certainly never underestimating a situation. </p><p>And so then I had to muse&#8230; WHAT WAS HE THINKING leaving the car running and unlocked to go after the siren with the cell? For the sake of politeness, I kept my question to my &#8216;inside voice&#8217;, but I do have to wonder why you&#8217;d sacrifice the security of a vehicle for a $50 cell phone.</p><p><strong>The moral of the story&#8230;&nbsp; There are two</strong>. 1) Involve someone with a &#8216;security mindset&#8217; and 2) Your security is only as strong as your people. A sweet damsel in distress&#8230; social engineering at it&#8217;s finest&#8230; </p><p># # #</p>
]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 00:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phone home">phone home</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/security mindset">security mindset</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/true security story">true security story</category>
      <category domain="http://securityratty.com/tag/car troubles">car troubles</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/7/3/grande-theft-auto-what-was-he-thinking.html">Grande Theft Auto... What Was He Thinking?</source>
    </item>
    <item>
      <title><![CDATA[Tucson area Domino's Pizza customer information exposed]]></title>
      <link>http://securityratty.com/article/8a47859f1eed2fddfeb4d9a0979c73fb</link>
      <guid>http://securityratty.com/article/8a47859f1eed2fddfeb4d9a0979c73fb</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/18/08

Organization
Domino's Pizza

Contractor/Consultant/Branch
Unnamed former owner of 24 Tucson area locations

Victims
Customers

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dominos.jpg" align="right" height="176" width="175"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/18/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.dominos.com/home/index.jsp">Domino's Pizza</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Unnamed former owner of 24 Tucson area locations&nbsp;&nbsp;&nbsp;&nbsp; <br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names and credit card numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Hundreds of credit card receipts dating back as many as five years were found "blowing in the wind" after a former owner of 24 Domino's Pizza stores in the Tucson, Arizona area was found to have been discarding boxes of old records near her home.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.kvoa.com/Global/story.asp?S=8516485&amp;nav=HMO6HMaY">KVOA Channel 4 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Tom McNamara, KVOA Channel 4 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>Investigators found credit card numbers blowing in the wind for anyone to see.<br><br>These piles and papers strewn across the alley contain hundreds of old receipts from Domino's Pizza stores.<br><br>When we got a call about this, we went down to University Avenue and Euclid and saw these receipts were three, four, and even five years old.<br><span style="font-style: italic;">[Evan] Is there any business reason to keep credit card receipts for this period of time?&nbsp; I suppose a case could be made that these should be kept for up to seven years for </span><a style="font-style: italic;" href="http://www.irs.gov/businesses/small/article/0,,id=98513,00.html">tax purposes</a><span style="font-style: italic;">.</span><br><br>We contacted the former owner of 24 Domino's Pizza stores in Tucson.<br><span style="font-style: italic;">[Evan] This could have been a very risky breach in terms of overall potential impact considering the number of affected persons.&nbsp; 24 stores, x number of credit card transactions per year, and 5 years could add up to a pretty significant number.</span><br><br>She won't talk with us on-camera, but told us she'd been discarding boxes of old records near her home and somehow all those receipts got loose.<br><span style="font-style: italic;">[Evan] Incidents like this tear me up.&nbsp; I very much doubt that this lady had any malicious intention behind her actions, but nonetheless her actions could have caused considerable inconvenience (and possible loss) to a number of individuals.&nbsp; I presume that she just didn't know any better.</span><br><br>We found Scott Brumage's name and credit card number on one of those receipts in the alley.<br><br>Tom McNamara asks him, "See that? Recognize that name? Recognize the number?" Scotts nods, "Uh huh."<br><br>Tom asks, "Well how'd you feel when we called you out of the blue and told you what we'd found? What went through your mind?"<br><br>"It was just kind of surreal at first because I like to think I can trust using my card [because of] the convenience and everything of course."<br><br>Scott was startled to see his name and card numbers on our screen.<br><br>He says he's ordered a lot of pizzas over the years and expects privacy and protection when he pays for his pepperoni pie.<br><span style="font-style: italic;">[Evan] Is this an unreasonable expectation?&nbsp; Maybe it is an unreasonable expectation, given the current environment and considering the bigger picture (merchants, processors, banks, "the system", etc.).&nbsp; I don't think that it is an unreasonable requirement, but requirements, expectations and practices are not in alignment.</span><br><br>Scotts tells us, "I don't know. [I'm] just dumbfounded, other than they need to figure a better way of disposing."<br><span style="font-style: italic;">[Evan] It is dumbfounding, isn't it.&nbsp; I often wonder what people are thinking when they do some of the things they do.</span><br><br>The Investigators contacted the Federal Trade Commission in Washington and they say thieves could potentially use discarded credit card numbers even if the card has expired. The numbers on the card in many cases are still the same.<br><br>They say there could be enough information on the receipt to help a thief reveal more information about you, such as your social security number.<br><br>It's small comfort for Scott. He says, "I'm hoping this is a one time only [situation]. They might have just lost a loyal customer."<br><span style="font-style: italic;">[Evan] The impact to the victim is usually pretty clear and easy to quantify.&nbsp; The impact to the business (or organization) is not usually as easy to measure.&nbsp; In a competitive business like pizza sales, companies need to identify and communicate differentiators like ingredient quality, service, taste, price, location, etc.&nbsp; Maybe if customers viewed information security practices as an important differentiator, businesses would put more time and effort into securing information.&nbsp; Pipe dream?</span><br><br>In this case, the Investigators contacted Tucson Police and several officers came to collect the records we found and have them destroyed.<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach reminds me of a <a href="http://breachblog.com/2008/06/11/cotton.aspx#comment-1124161">recent discussion</a> I had online with Benjamin Wright in the comments section of the "<a href="http://breachblog.com/2008/06/11/cotton.aspx">Cotton Traders confirms that their website was compromised</a>" breach.&nbsp; He makes a very good argument regarding accountability in credit card breaches.&nbsp; My responses to him are included. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/18/dominos.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 18 Jun 2008 06:43:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card transactions">credit card transactions</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card receipts">credit card receipts</category>
      <category domain="http://securityratty.com/tag/credit card breaches">credit card breaches</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/pizza">pizza</category>
      <category domain="http://securityratty.com/tag/receipts">receipts</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/tucson">tucson</category>
      <source url="http://breachblog.com/2008/06/18/dominos.aspx">Tucson area Domino's Pizza customer information exposed</source>
    </item>
    <item>
      <title><![CDATA[Amusing Moment On a Train]]></title>
      <link>http://securityratty.com/article/c5a7e531a034b518f3d51c4cbf80acb0</link>
      <guid>http://securityratty.com/article/c5a7e531a034b518f3d51c4cbf80acb0</guid>
      <description><![CDATA[I have these moments when I get to ride the train where I see and hear some of the oddest things. Last week I was riding the train when I heard this guy in the car behind me exclaim ah crap and begin...]]></description>
      <content:encoded><![CDATA[<p>I have these moments when I get to ride the train where I see and hear some of the oddest things. Last week I was riding the train when I heard this guy in the car behind me exclaim &#8220;ah crap&#8221; and begin dialing his cell phone. </p>
<p>&#8220;Uh hi honey, sorry to wake you. Could you login to my email for me?&#8221;</p>
<p>Ah, the fun begins I thought. </p>
<p>&#8220;OK, my user name is  [REDACTED] and my password is [REDACTED]&#8221;</p>
<p>Sigh, some folks just don&#8217;t get it. But, it gets better.</p>
<p>&#8220;No sweetie, that&#8217;s for my Gmail account&#8221;</p>
<p>Score.</p>
<p>At this point I glance around the train to see that I wasn&#8217;t the only person that found this fella&#8217;s call amusing. There were smirks to be seen. Then this takes a darker turn, for him at least.</p>
<p>&#8220;Now, sweetie I&#8217;ll need you to order a wireless router from [REDACTED] and my credit card number is 5, 5&#8230; </p>
<p>He proceeded to read out the entire number with expiry date and CVN. I was a little worried for the guy at this point. But, I guess Darwin was right. Then I heard a woman&#8217;s voice utter, &#8220;jackass&#8221;. I glanced up to see a little old lady shaking her head as she looked at the loud talker in disgust. A smile crept across my face.</p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=OhHTxC"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=OhHTxC" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=7UwL9I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=7UwL9I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=rZEyFi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=rZEyFi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=IcOzti"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=IcOzti" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=z0bggi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=z0bggi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=ecYqSi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=ecYqSi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/312935190" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 16 Jun 2008 06:39:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/train">train</category>
      <category domain="http://securityratty.com/tag/womans voice utter">womans voice utter</category>
      <category domain="http://securityratty.com/tag/sweetie">sweetie</category>
      <category domain="http://securityratty.com/tag/gmail account">gmail account</category>
      <category domain="http://securityratty.com/tag/loud talker">loud talker</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/wireless router">wireless router</category>
      <category domain="http://securityratty.com/tag/fellas call">fellas call</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/312935190/">Amusing Moment On a Train</source>
    </item>
    <item>
      <title><![CDATA[Fly through airport security with Clear, but you don't have less security]]></title>
      <link>http://securityratty.com/article/f3778a613754d2131eeac02a94cd6468</link>
      <guid>http://securityratty.com/article/f3778a613754d2131eeac02a94cd6468</guid>
      <description><![CDATA[A couple of weeks ago I was offered a free year membership in the Clear airport security program for registered travelers. Though my home airports of Ft Lauderdale and West Palm Beach don't yet offer...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/clear.jpg"><img height="145" alt="clear" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/clear_thumb.jpg" width="139" align="left" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; MARGIN: 0px 5px 5px 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a> A couple of weeks ago I was offered a free year membership in the <a href="http://www.flyclear.com/index.html" target="_blank">Clear airport security program</a> for registered travelers.&nbsp; Though my home airports of Ft Lauderdale and West Palm Beach don't yet offer Clear access, I fly enough in airports that do like Denver and Regan that I thought for free, what do I have to lose.&nbsp; I filled out the forms on line and last time I was in Regan airport I handed it in along with fingerprints, Iris scans, passport, etc.&nbsp; This past week my Clear card came in the mail and I have been looking forward to using it.</p>

<p>I thought that with my background check and all, they knew that I was a low risk for terrorist or other type of activity and therefore would not be subject to the same scrutiny and testing that we all endure when we have to fly.&nbsp; Turns out that I don't think that is exactly the case.&nbsp; However what it does do is allow you to go right to the front of the line in security, much to the dismay of others waiting on those lines.</p>

<p>The experience was great.&nbsp; I went to a special entrance for Clear members where I was met by a very helpful young lady.&nbsp; She escorted me to a Clear machine where we inserted my card and did a fingerprint scan.&nbsp; After that was done she escorted me to another young lady who walked me past all of the people waiting on line (and a long line it was).&nbsp; At the head of the line, the Clear lady gave my boarding pass and ID to the TSA person.&nbsp; The TSA person checked my id and pass, same as always and they passed me through.&nbsp; Than my Clear escort brought me to a special metal detector line which had no one on it, just waiting for me.&nbsp; Again skipping another line.&nbsp; I put my computer and other metal objects in the same old grey bin, took off my shoes and went through the metal detector.&nbsp; I thanked the Clear escort came out the other side, scooped up my stuff and proceeded to my gate.&nbsp; The entire process took less than 3 minutes I bet!&nbsp; That was great!&nbsp; The looks on the faces of the people I bypassed on line also gave me a perverse pleasure as well, I will admit.</p>

<p>After finishing this though I sat down and thought about it.&nbsp; What security did bypass?&nbsp; They still checked my ID and boarding pass. I still went through the metal detector and took off my shoes.&nbsp; In fact if anything security was added to my check in, as they now did a fingerprint match.&nbsp; So fact is, with all of the background checks and everything, having the Clear program did not relieve me of any security obligations and tests. In fact it added to them.&nbsp; What it did give me was a &quot;first class&quot; personal escort to the front of the line and than a first class que for the metal detectors.&nbsp; Because I was willing to pay some money and have a background search, I got the first class treatment.</p>

<p>To me this is not a scalable solution.&nbsp; As more Clear passengers come on board, having a dedicated person walking me through the security line is just not going to work.&nbsp; Also, lets be clear (no pun intended), this is not about going through less security.&nbsp; Why the background check and all?&nbsp; This is about paying money and skipping the line, but still going through the same security procedures that everyone else goes through.&nbsp; Just faster.&nbsp; Hey, don't get me wrong.&nbsp; I loved it!&nbsp; But I was wrong to think this was about bypassing security, this is a &quot;first class&quot; traveler lane.&nbsp; As long as you are &quot;clear&quot; with that, it is good by me!</p></div>
]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 09:26:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security line">security line</category>
      <category domain="http://securityratty.com/tag/airport security program">airport security program</category>
      <category domain="http://securityratty.com/tag/line">line</category>
      <category domain="http://securityratty.com/tag/security procedures">security procedures</category>
      <category domain="http://securityratty.com/tag/background check">background check</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/security obligations">security obligations</category>
      <category domain="http://securityratty.com/tag/background">background</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/fly-through-air.html">Fly through airport security with Clear, but you don't have less security</source>
    </item>
    <item>
      <title><![CDATA[Fly through airport security with Clear, but you don't have less security?]]></title>
      <link>http://securityratty.com/article/ff09269bb2fbd1d5211d58a23c93599e</link>
      <guid>http://securityratty.com/article/ff09269bb2fbd1d5211d58a23c93599e</guid>
      <description><![CDATA[A couple of weeks ago I was offered a free year membership in the Clear airport security program for registered travelers. Though my home airports of Ft Lauderdale and West Palm Beach don't yet offer...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/clear.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 5px 5px 0px; border-left: 0px; border-bottom: 0px" height="145" alt="clear" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/clear_thumb.jpg" width="139" align="left" border="0"></a> A couple of weeks ago I was offered a free year membership in the <a href="http://www.flyclear.com/index.html" target="_blank">Clear airport security program</a> for registered travelers.&nbsp; Though my home airports of Ft Lauderdale and West Palm Beach don't yet offer Clear access, I fly enough in airports that do like Denver and Regan that I thought for free, what do I have to lose.&nbsp; I filled out the forms on line and last time I was in Regan airport I handed it in along with fingerprints, Iris scans, passport, etc.&nbsp; This past week my Clear card came in the mail and I have been looking forward to using it.</p> <p>I thought that with my background check and all, they knew that I was a low risk for terrorist or other type of activity and therefore would not be subject to the same scrutiny and testing that we all endure when we have to fly.&nbsp; Turns out that I don't think that is exactly the case.&nbsp; However what it does do is allow you to go right to the front of the line in security, much to the dismay of others waiting on those lines.</p> <p>The experience was great.&nbsp; I went to a special entrance for Clear members where I was met by a very helpful young lady.&nbsp; She escorted me to a Clear machine where we inserted my card and did a fingerprint scan.&nbsp; After that was done she escorted me to another young lady who walked me past all of the people waiting on line (and a long line it was).&nbsp; At the head of the line, the Clear lady gave my boarding pass and ID to the TSA person.&nbsp; The TSA person checked my id and pass, same as always and they passed me through.&nbsp; Than my Clear escort brought me to a special metal detector line which had no one on it, just waiting for me.&nbsp; Again skipping another line.&nbsp; I put my computer and other metal objects in the same old grey bin, took off my shoes and went through the metal detector.&nbsp; I thanked the Clear escort came out the other side, scooped up my stuff and proceeded to my gate.&nbsp; The entire process took less than 3 minutes I bet!&nbsp; That was great!&nbsp; The looks on the faces of the people I bypassed on line also gave me a perverse pleasure as well, I will admit.</p> <p>After finishing this though I sat down and thought about it.&nbsp; What security did bypass?&nbsp; They still checked my ID and boarding pass. I still went through the metal detector and took off my shoes.&nbsp; In fact if anything security was added to my check in, as they now did a fingerprint match.&nbsp; So fact is, with all of the background checks and everything, having the Clear program did not relieve me of any security obligations and tests. In fact it added to them.&nbsp; What it did give me was a "first class" personal escort to the front of the line and than a first class que for the metal detectors.&nbsp; Because I was willing to pay some money and have a background search, I got the first class treatment.</p> <p>To me this is not a scalable solution.&nbsp; As more Clear passengers come on board, having a dedicated person walking me through the security line is just not going to work.&nbsp; Also, lets be clear (no pun intended), this is not about going through less security.&nbsp; Why the background check and all?&nbsp; This is about paying money and skipping the line, but still going through the same security procedures that everyone else goes through.&nbsp; Just faster.&nbsp; Hey, don't get me wrong.&nbsp; I loved it!&nbsp; But I was wrong to think this was about bypassing security, this is a "first class" traveler lane.&nbsp; As long as you are "clear" with that, it is good by me!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=W8nuzy"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=W8nuzy" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JR6aYI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JR6aYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=NFcYcI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=NFcYcI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1ZVVqI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1ZVVqI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=pCSkoI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=pCSkoI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=XHPWQi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=XHPWQi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HHQGDi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HHQGDi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/304685966" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 08:26:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security line">security line</category>
      <category domain="http://securityratty.com/tag/airport security program">airport security program</category>
      <category domain="http://securityratty.com/tag/line">line</category>
      <category domain="http://securityratty.com/tag/security procedures">security procedures</category>
      <category domain="http://securityratty.com/tag/background check">background check</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/security obligations">security obligations</category>
      <category domain="http://securityratty.com/tag/background">background</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/304685966/fly-through-air.html">Fly through airport security with Clear, but you don't have less security?</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Senior PC - not just for the elderly]]></title>
      <link>http://securityratty.com/article/b40833af463c4e7344afed3fa409ff04</link>
      <guid>http://securityratty.com/article/b40833af463c4e7344afed3fa409ff04</guid>
      <description><![CDATA[My mother-in-law is, to give her some credit, an intelligent lady. However, faced with an upgrade from Windows XP to Vista and IE7 from IE6 and you have a situation akin to explaining quadratic...]]></description>
      <content:encoded><![CDATA[
      My mother-in-law is, to give her some credit, an intelligent lady. However, faced with an upgrade from Windows XP to Vista and IE7 from IE6 and you have a situation akin to explaining quadratic equations to a two year old. Both circumstances will result in heavy objects being thrown around in frustration. 

So, the idea of Microsoft to provide a range of "<a href="http://www.microsoft.com/enable/aging/seniorpc.aspx">Senior PC packages</a>" is, in my mind, borderline genius and something I wish I had thought of first. Computer Weekly <a href="http://www.microsoft.com/enable/aging/seniorpc.aspx">mock the idea</a> in this weeks magazine, something I think is very unfair given that I'm sure some of their editorial team are getting on a bit and would probably be able to make good use of the built-in prescription software...

If home computing can be made as easy as taking the PC out of the box, plugging it in and turning it on (not a word from the Mac users please - I know you've been able to do this for years) then that's to be encouraged for everyone, not just the elderly. And if it stops the "support" calls from my mother-in-law then that's priceless!
      
   ]]></content:encoded>
      <pubDate>Tue, 06 May 2008 15:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/built-in prescription software">built-in prescription software</category>
      <category domain="http://securityratty.com/tag/computer weekly mock">computer weekly mock</category>
      <category domain="http://securityratty.com/tag/heavy objects">heavy objects</category>
      <category domain="http://securityratty.com/tag/intelligent lady">intelligent lady</category>
      <category domain="http://securityratty.com/tag/mother-in-law">mother-in-law</category>
      <category domain="http://securityratty.com/tag/situation akin">situation akin</category>
      <category domain="http://securityratty.com/tag/quadratic equations">quadratic equations</category>
      <category domain="http://securityratty.com/tag/idea">idea</category>
      <category domain="http://securityratty.com/tag/editorial team">editorial team</category>
      <source url="http://www.computerweekly.com/blogs/stuart_king/2008/05/my-motherinlaw-is-to-give.html">Microsoft Senior PC - not just for the elderly</source>
    </item>
  </channel>
</rss>
