<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: launch]]></title>
    <link>http://securityratty.com/tag/launch</link>
    <description></description>
    <pubDate>Mon, 22 Sep 2008 14:30:46 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ePolicing - Tomorrow the world?]]></title>
      <link>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</link>
      <guid>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</guid>
      <description><![CDATA[This week has finally seen an announcement that the Police Central e-crime Unit (PCeU) is to be funded by the Home Office. However, the largesse amounts to just 3.5 million of new money spread over...]]></description>
      <content:encoded><![CDATA[<p>This week has finally seen an <a href="http://press.homeoffice.gov.uk/press-releases/new-specialist-ecrime-unit">announcement</a> that the <a href="http://www.met.police.uk/pceu/index.htm">Police Central e-crime Unit</a> (PCeU) is to be funded by the Home Office. However, the largesse amounts to just £3.5 million of new money spread over three years, with the Met putting up a further £3.9 million &#8212; but whether the Met&#8217;s contribution is &#8220;new&#8221; or reflects a move of resources from their existing <a href="http://www.met.police.uk/computercrime/">Computer Crime Unit</a> I could not say.</p>
<p>The announcement is of course Good News &#8212; because once the PCeU is up and running next Spring, it should plug (to the limited extent that £2 million a year can plug) the &#8220;level 2&#8243; eCrime gap that I&#8217;ve <a href="http://www.lightbluetouchpaper.org/2006/02/06/mysterious-and-menacing/">written</a> <a href="http://www.lightbluetouchpaper.org/2006/10/13/mainstreaming-ecrime/">about</a> <a href="http://www.lightbluetouchpaper.org/2007/02/11/soca-we-just-want-your-money/">before</a>. viz: that SOCA tackles &#8220;serious and organised crime&#8221; (level 3), your local police force tackles local villains (level 1), but if criminals operate outside their force&#8217;s area &#8212; and on the Internet this is more likely than not &#8212; yet they don&#8217;t meet SOCA&#8217;s threshold, then who is there to deal with them?</p>
<p>In particular, the PCeU is envisaged to be the unit that deals with the intelligence packages coming from the <a href="http://www.cityoflondon.police.uk/CityPolice/ECD/Fraud/">City of London Fraud Squad&#8217;s</a> new online Fraud Reporting <a href="http://www.kablenet.com/kd.nsf/Frontpage/356DD0A1942F3A998025745F0049092C?OpenDocument">website</a> (once intended to launch in November 2008, now scheduled for Summer 2009).</p>
<p>Of course everyone expects the website to generate more reports of eCrime than could ever be dealt with (even with much more money), so the effectiveness of the PCeU in dealing with eCriminality will depend upon their prioritisation criteria, and how carefully they select the cases they tackle.</p>
<p>Nevertheless, although the news this week shows that the Home Office have finally understood the need to fund more ePolicing, I don&#8217;t think that they are thinking about the problem in a sufficiently global context.</p>
<p>A little history lesson might be in order to explain why.<br />
<span id="more-401"></span></p>
<p>Back in 1930&#8217;s, <a href="http://www.fbi.gov/libref/historic/famcases/clyde/clyde.htm">Bonnie and Clyde</a> and other US bank robbers were using the new-fangled automobile to flee across state lines &#8212; creating jurisdictional problems as a result. The US solution was to make bank robbery (along with auto-theft and other related offences) into federal offences rather keeping them as state-specific infractions. In particular this meant that the FBI could provide federal level policing (tracking down and killing <a href="http://en.wikipedia.org/wiki/John_Dillinger">John Dillinger</a> for example).</p>
<p>We have the same jurisdictional issues dealing with cyberspace, with criminals in one country fleecing consumers in another while using systems hosted in a third. The <a href="http://conventions.coe.int/Treaty/EN/Treaties/Html/185.htm">Convention on Cybercrime</a> addresses part of the problem by trying to ensure international consistency where eLaws are specifically needed (which of course is only the case for small parts of eCriminality, <a href="http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060035_en_1">fraud</a> is fraud whether eEnabled or not). However, there is limited inter-jurisdictional <em>co-ordination</em> for eCrime investigations &#8212; for example <a href="http://www.interpol.int/">Interpol</a> (often <a href="http://en.wikipedia.org/wiki/Interpol#Interpol_in_popular_culture">incorrectly perceived</a> to be international police force)  merely keeps a large database and passes faxes from one place to another.</p>
<p>In practice, most cross-border investigations are done as &#8220;joint operations&#8221; and the jointness is usually very limited &#8212; one force does all the legwork and a liaison officer in the other country deals with local paperwork. There&#8217;s usually a <a href="http://www.phrases.org.uk/meanings/quid-pro-quo.html">quid pro quo</a> element to these joint operations, for budgeting reasons if no other.</p>
<p>What isn&#8217;t happening, or at least only in a handful of very specialised areas, is any international co-operation in setting priorities or selecting cases to pursue. Every country is doing its own thing about eCrime, and there&#8217;s a widespread impression that any criminal who can operate from &#8220;across the state line&#8221; is essentially immune from serious investigation.</p>
<p>We identified this problem last year when we (<a href="http://www.cl.cam.ac.uk/~rja14/">Ross Anderson</a>, <a href="http://www.inf.tu-dresden.de/index.php?node_id=489">Rainer Böhme</a>, <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a>) wrote a report on <a href="http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&#038;_int_mark_20080131.pdf">Security Economics and the Internal Market</a> for <a href="http://www.enisa.europa.eu/">ENISA</a>. It&#8217;s not an easy one to fix whilst politicians (and populaces) are unwilling to see &#8220;foreign&#8221; police officers operating in their country, and the establishment of a truly international &#8220;cyber police force&#8221; seems equally unlikely.</p>
<p>Our policy proposal to tackle the issue harks back to WWII&#8217;s <a href="http://www.archives.gov/research/holocaust/finding-aid/military/rg-331.html">SHAEF</a>, which has morphed into similar arrangements within <a href="http://www.nato.int/shape/about/background2.htm">NATO</a>. In essence liaison officers from multiple forces would sit around a single table, working with a central coordinator, to set policy and decide which investigations to pursue. They would then communicate back to their own countries, who have specifically budgeted to provide appropriate assistance. So it&#8217;s very like &#8220;joint operations&#8221;, but the scheme is multi-laterial, and has a true command and control function in the centre &#8212; who will quickly learn to shy away from politically sensitive topics and make a real impact on eCriminality.</p>
<p>To summarise then, a <a href="http://www.cartoonbank.com/item/34449">welcome</a> to the Home Office for finally finding a small amount of funding for some country-wide ePolicing; but it&#8217;s well past time to be working on world-wide initiatives.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 13:57:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecrime gap">ecrime gap</category>
      <category domain="http://securityratty.com/tag/ecrime">ecrime</category>
      <category domain="http://securityratty.com/tag/provide federal level">provide federal level</category>
      <category domain="http://securityratty.com/tag/ecrime investigations">ecrime investigations</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/level">level</category>
      <category domain="http://securityratty.com/tag/country deals">country deals</category>
      <category domain="http://securityratty.com/tag/deals">deals</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/02/epolicing-tomorrow-the-world/">ePolicing - Tomorrow the world?</source>
    </item>
    <item>
      <title><![CDATA[Managed Fast Flux Provider - Part Two]]></title>
      <link>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</link>
      <guid>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</guid>
      <description><![CDATA[We're slowly entering into a stage where RBN bullet proof hosting franchises are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/geleqRWDOE0/s1600-h/pharma_spam_fastflux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/8PTQr8G6mBM/s200-R/pharma_spam_fastflux.png" /></a>We're slowly entering into a stage where <a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">RBN bullet proof hosting franchises</a> are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as "mirrored hosting" which in practice is plain simple fast flux network consisting of RBN-alike purchased netblocks, and naturally, botnet infected hosts.<br />
<br />
Managed fast-fluxing is only starting to go mainstream, for instance, in July I found evidence that <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">money mule recruiters were using ASProx's infected hosts as hosting infrastructure</a>, and in November, 2007, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">an infamous spamming software vendor</a> was also found to have been offering fast-flux services in the past.<br />
<br />
In this most recent fast-flux service, we have a known spammer and botnet master that in between self-serving himself on is way to ensure his portfolio of scammy domains remains online for a "little longer", is commercializing fast-fluxing and is offered a DIY service :<br />
<br />
"<i>Finally after hardwork and great appreciation from our normal bullet proof  hosting/server clients we are able to launch Mirrored hosting. What is </i><i>Mirrored hosting</i><i> ?</i><br />
<i><br />
================<br />
</i><i>Mirrored hosting</i><i> is a powerful mirrored  web hosting management, uses multiple Virtual servers to host  website with 100% uptime. </i><i>Mirrored hosting </i><i>is a combination of two things, which  are:<br />
<br />
1. Specially Designed Virtual Servers</i><br />
<i> 2. Powerful  Automated Control Panel</i><br />
<br />
<i>How does it work ?<br />
===============&nbsp;</i><br />
<br />
<i>Mirrored hosting</i><i> uses specially configured Virtual Servers making them link with the </i><i>Mirrored hosting</i><i> Control Panel  which is then controlled by our own control panel allowing us to provide smooth  streamline hosting with no downtime. No one is able to trace original IP of the  server or the place where the files are hosted so the websites/domains hosted  have a 100% Uptime. This is achieved by unique customisation of our Virtual Servers.<br />
<br />
<b>Actually, it takes ips around the world and our  powerful control panel just rotates the ips every 15 minutes. though all these  ips you will see will be fake no one can trace the orignal ip where files are  hosted. Sometimes the ip is from China, Korea, USA, UK, Japan, Lithuania etc.</b></i>"<br />
<br />
The concept has always been there for cybercriminals to take advantage of, but once it matures into a managed service it would undoubtedly lower down the entry barriers allowing yesterday's average phishers to take advantage of what only the "pros" were used to.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AO71M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AO71M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xZIrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xZIrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZGgOm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZGgOm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e7OAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e7OAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVPbM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVPbM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iS1HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iS1HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQOUm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQOUm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409475392" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/recent fast-flux service">recent fast-flux service</category>
      <category domain="http://securityratty.com/tag/powerful control panel">powerful control panel</category>
      <category domain="http://securityratty.com/tag/control panel">control panel</category>
      <category domain="http://securityratty.com/tag/virtual servers">virtual servers</category>
      <category domain="http://securityratty.com/tag/multiple virtual servers">multiple virtual servers</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409475392/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</source>
    </item>
    <item>
      <title><![CDATA[The Genesis of Complex Event Processing: Asymmetric Capabilities]]></title>
      <link>http://securityratty.com/article/58ed1db82fe051447218ff6d60c32d71</link>
      <guid>http://securityratty.com/article/58ed1db82fe051447218ff6d60c32d71</guid>
      <description><![CDATA[More often than not, folks working in the field of complex event processing do not truly understand CEP. We often see the same folks try to position and mischaracterize CEP as business process...]]></description>
      <content:encoded><![CDATA[<p>More often than not, folks working in the field of complex event processing do not truly understand CEP.   We often see the same folks try to position and mischaracterize CEP as business process orchestration, business process management, event-driven architecture or even an evolution of service-oriented architecture.    Well-intended, this mischaracterization of CEP is often for sales and marketing purposes.  However, sometimes the mischaracterization of CEP is from a lack of understanding of what CEP was designed to accomplish.  These mischaracterizations have very little to do with the original intent of complex event processing.</p>
<p>Originally, researchers in CEP were not trying to solve a problem of streaming data or streaming events.   Often we read this mischaracterization by folks in the database/streaming domain, as they were focused on the low latency processing of streaming events.   A natural extension of this research has been stream processing software (often called &#8220;engines&#8221;) that process streaming data with continuous queries, for example market data feeds for algo-trading or best market order execution.  This mischaracterization is partly responsible for why we see many order processing applications in market data stream processing mislabled as &#8220;complex event processing&#8221; applications.</p>
<p>The genesis of complex event processing was not the stream processing need for &#8220;feeds and speed&#8221; but the processing capability to solve what can be characterized as the &#8220;problem of asymmetric capabilties&#8221;.   The term &#8220;asymmetric&#8221; has been used in the military domain. For example we often hear the term &#8220;<a href="http://en.wikipedia.org/wiki/Asymmetric_warfare" target="_blank">asymmetric warfare</a>.&#8221;  However, in general the concept of &#8220;asymmetrical processing capablities&#8221; is the true genesis for CEP and related processing concepts and domains.   It is this genesis that distinguishes CEP from EDA, SOA, SOR, and so many other technology oriented concepts.</p>
<p>In order to illustrate what I mean by &#8220;asymmetrical processing capablities&#8221; we will take the example of the evolution of rocketry.    In the early days, scientists learned how to make rockets, I assume with gunpowder and similar chemical compounds to launch rockets.   Over many years the application of rocketry advanced much faster than the ability to understand the situations created in the sky.    In other words, folks could fill the skies with rockets long before they had the capability to track and identify (or sense and respond to)  the rockets in real time.</p>
<p>Therefore, the concept of &#8220;asymmetrical processing capablities&#8221; is the situation where there is a capability, such as &#8220;launch a rocket, sense-and-respond,&#8221; that is asymmetric in nature.    In other words, the capability to detect multiple rocket launches creates an asymmetric situation where it is easy to launch rockets, but hard to detect and defend against those launches.</p>
<p>The same concept can be applied to everyday air travel.   If we could only fly airplanes, but did not have the capability to track the planes, understand situations in airspace, and then respond to changing situations, air travel would be quite difficult.   Lucky for us, the global traveller, there is symmetry in the capabilities to build and fly aircraft and the capabilities to detect, track and follow the evolving situations in the sky.</p>
<p>The genesis of CEP was to solve the problem of asymmetry in cyberspace, or if you prefer, distributed data networks.   The folks who identified, early on,  the problems associated with asymmetry in cyberspace were folks working the the field of network and security management.    This is because there has been, and is currently, a great asymmetry between the capablities to &#8220;launch a process or transaction&#8221; in cyberspace and the capabilties to detect and track what is going on in the same domain.</p>
<p>In my next post on this topic, we will go into some details of this asymmetry and review the first CEP projects from Stanford University in the context of asymmetric processing capabilities in cyberspace.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 13:31:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asymmetric">asymmetric</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/market data stream">market data stream</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/term asymmetric warfare">term asymmetric warfare</category>
      <category domain="http://securityratty.com/tag/term asymmetric">term asymmetric</category>
      <category domain="http://securityratty.com/tag/distinguishes cep">distinguishes cep</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/asymmetric capabilties">asymmetric capabilties</category>
      <source url="http://www.thecepblog.com/2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</source>
    </item>
    <item>
      <title><![CDATA[Private Rockets Could Boost Military, Too]]></title>
      <link>http://securityratty.com/article/fffd7a3e65cd62e01d3ea21a6ab2b124</link>
      <guid>http://securityratty.com/article/fffd7a3e65cd62e01d3ea21a6ab2b124</guid>
      <description><![CDATA[Elon Musk puts the first privately developed rocket in orbit. And that could have huge military consequences if the company can turn the one-time launch into a regular...]]></description>
      <content:encoded><![CDATA[Elon Musk puts the first privately developed rocket in orbit. And that could have huge military consequences if the company can turn the one-time launch into a regular event.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2ba4b3f7bc5c3188e9032b0eddbf4a34" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2ba4b3f7bc5c3188e9032b0eddbf4a34" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=mLeeL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=mLeeL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IRC2l"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IRC2l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gvtsl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gvtsl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ceFrL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ceFrL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=RrM5L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=RrM5L" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=84XMl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=84XMl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=JRFfl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=JRFfl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=CCpWL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=CCpWL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/406486363" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/406486365" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:53:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/huge military consequences">huge military consequences</category>
      <category domain="http://securityratty.com/tag/one-time launch">one-time launch</category>
      <category domain="http://securityratty.com/tag/elon musk">elon musk</category>
      <category domain="http://securityratty.com/tag/regular event">regular event</category>
      <category domain="http://securityratty.com/tag/privately">privately</category>
      <category domain="http://securityratty.com/tag/rocket">rocket</category>
      <category domain="http://securityratty.com/tag/orbit">orbit</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/406486365/spacex.html">Private Rockets Could Boost Military, Too</source>
    </item>
    <item>
      <title><![CDATA[Mozilla rushes to fix Firefox password bug]]></title>
      <link>http://securityratty.com/article/e3f82d54ebeb80d8e944feb3d5cab38a</link>
      <guid>http://securityratty.com/article/e3f82d54ebeb80d8e944feb3d5cab38a</guid>
      <description><![CDATA[Just a day after it released Firefox 3.0.2 to fix 11 vulnerabilities, Mozilla said that an overlooked password bug requires a fast-track update it hopes to launch next...]]></description>
      <content:encoded><![CDATA[Just a day after it released Firefox 3.0.2 to fix 11 vulnerabilities, Mozilla said that an overlooked password bug requires a fast-track update it hopes to launch next week.]]></content:encoded>
      <pubDate>Sat, 27 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/password bug requires">password bug requires</category>
      <category domain="http://securityratty.com/tag/mozilla">mozilla</category>
      <category domain="http://securityratty.com/tag/fix">fix</category>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/launch">launch</category>
      <category domain="http://securityratty.com/tag/fast-track">fast-track</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://www.networkworld.com/news/2008/092608-mozilla-rushes-to-fix-firefox.html?fsrc=rss-security">Mozilla rushes to fix Firefox password bug</source>
    </item>
    <item>
      <title><![CDATA[Mozilla rushes to fix Firefox password bug]]></title>
      <link>http://securityratty.com/article/b6dc51d09dce29ae74ae26bedf0ed087</link>
      <guid>http://securityratty.com/article/b6dc51d09dce29ae74ae26bedf0ed087</guid>
      <description><![CDATA[Mozilla Corp. said an overlooked password bug requires a fast-track update it hopes to launch next...]]></description>
      <content:encoded><![CDATA[Mozilla Corp. said an overlooked password bug requires a fast-track update it hopes to launch next week.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5ecaf0370ca4d0bbb06c87180145e041:HQEh06rqvCEnMyJCwDMjEumUXJGBtdMyoK2%2FNc6uSBD4ELlX9NJSoINLa%2B8NU2pGcdl0a5iim0Tw'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bbd814fdc781a5d3173e2b2f0696154c:Vj6ezQCaiSO4wnytobusAKMZehzlOGeTv7lG2z4npMubVy4Vz3%2Fms5fPrH2MqtrnXGZql1Ka1uDD9Q%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d895253e928301eb24e55a99b59770d6:hrmYgR6FS27bDmxyTv6Jw72QCSH%2FEVB2wYb7hEr3Snin6aW%2Fx7xKQSOgLIN9jADS4s0U%2B1BMJRM50g%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6a0ce7dbf22a2396619b1ee7aa4590ab:vRhkjjrakn%2BMgeHjEKhKVpq%2FX20faK%2FLPnQoGLTHFZPoZ0MGBoyRU93YD1AqCS7GAiiShBalmfn2XA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=39b15efa3519299480dbeffb6864c079" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=39b15efa3519299480dbeffb6864c079" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/password bug requires">password bug requires</category>
      <category domain="http://securityratty.com/tag/mozilla corp">mozilla corp</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/launch">launch</category>
      <category domain="http://securityratty.com/tag/fast-track">fast-track</category>
      <category domain="http://securityratty.com/tag/hopes">hopes</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=39b15efa3519299480dbeffb6864c079">Mozilla rushes to fix Firefox password bug</source>
    </item>
    <item>
      <title><![CDATA[250k of Harvested Hotmail Emails Go For?]]></title>
      <link>http://securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</link>
      <guid>http://securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</guid>
      <description><![CDATA[50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/fQ_TqPImTk0/s1600-h/harvested_hotmail_sale.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="113" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/YJqc75ZUQgE/s200-R/harvested_hotmail_sale.png" width="200" /></a>$50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to know about. Moreover, what someone is offering for sale, may in fact be already available as a value-added addition to a managed spamming service.<br />
<br />
With metrics and quality assurance applied in a growing number of spam and phishing campaigns, filling in the niche of email harvesting by distinguishing between different types of obfuscated emails by releasing an easily embeddable module, was an anticipated move. What's to come? <a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Spam and malware campaigns across social networks</a> "as usual" will propagate faster thanks to the ongoing harvesting of usernames within social networks, that would later on get imported in Web 2.0 "marketing" tools targeting the high-trafficked sites and automatically spamming them.<br />
<br />
From a spammer's perspective, geolocating these 250k emails could increase their selling prices since the buyers would be able to launch localized attacks with messages in the native languages of the receipts. Is the demand for quality email databases fueling the developments of this market segment, or are the spammers self-serving themselves and cashing-in by reselling what they've already abused a log time ago? That seems to be the case, since there's no way a buyer could verify the freshness of the harvested emails database and whether or not it has already been abused. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/yhy61idSl6I/s1600-h/segmented_harvested_emails.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="200" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/xFYzYTCaDes/s200-R/segmented_harvested_emails.JPG" width="152" /></a>For the time being, we've got several developed and many other developing market segments within spamming and phishing as different markets with different players. On one hand are the legitimately looking spamming providers offering "direct marketing services" working with lone spammers who find a reliable business partner in the face of the spamming vendor whose customers drive both side's business models. On the other hand, you've got the <a href="http://blogs.zdnet.com/security/?p=1835">spammers excelling in outsourcing the automatic account registration process</a>, coming up with ways to build a spamming infrastructure -- already available as a module to integrate in <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming services</a> -- using legitimate services as a provider of the infrastructure.<br />
<br />
Despite that the arms race seems to be going on at several different fronts, spammers VS the industry and spammers VS spammers fighting for market share, the entire underground ecosystem is clearly allocating a lot of resources for research and development in order to ensure that they are always a step ahead of the industry.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting  Youtube Usernames for Spamming</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands  of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/automatic-email-harvesting-20.html">Automatic  Email Harvesting 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - the Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/inside-email-harvesters-configuration.html">Inside an Email Harvester's Configuration File</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">Segmenting and Localizing Spam Campaigns</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample.html">Shots from the Malicious Wild West - Sample Four</a><br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=De2zL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=De2zL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CYcFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CYcFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OQPDl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OQPDl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lhexl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lhexl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sZRFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sZRFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ifNGL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ifNGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BYibl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BYibl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402968423" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 08:13:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email harvester">email harvester</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/lone spammers">lone spammers</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <category domain="http://securityratty.com/tag/250k emails">250k emails</category>
      <category domain="http://securityratty.com/tag/automatic email">automatic email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402968423/250k-of-harvested-hotmail-emails-go-for.html">250k of Harvested Hotmail Emails Go For?</source>
    </item>
    <item>
      <title><![CDATA[Clarity on Qantas' Plans: OnAir and Aeromobile]]></title>
      <link>http://securityratty.com/article/d054a83a986c1d357ea394b9721e5121</link>
      <guid>http://securityratty.com/article/d054a83a986c1d357ea394b9721e5121</guid>
      <description><![CDATA[Trade mag Flightglobal gets the full story on Qantas' in-flight calling, texting, and Internet plans: A few days ago, it seemed to come out that Qantas had dropped Aeromobile (its test partner last...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.flightglobal.com/articles/2008/09/24/316457/qantas-reveals-connectivity-plans-for-a380s-a330s-and.html"><strong>Trade mag Flightglobal gets the full story on Qantas' in-flight calling, texting, and Internet plans:</strong></a> A few days ago, it seemed to come out that Qantas had dropped Aeromobile (its test partner last year) for OnAir, and was moving to Internet service on A380s instead of in-flight cell calling and texting. Flightglobal clears the air, and reveals that Qantas will offer all of the above. (I wrote about this in "<a href="http://wifinetnews.com/archives/008448.html"><strong>Sorry, Qantas, No Unfettered Broadband</strong></a>.")</p>

<p>OnAir was chosen for A380 service, with the initial rollout--especially for international flights--using the 64 Kbps Inmarsat satellite offering, which is too paltry for anything but limited text communication. When the recently launched Pacific satellite is active--which may take up to a year--OnAir and Qantas can upgrade to the luxurious nearly 500 Kbps per channel service. </p>

<p>The head of OnAir is pushing some mighty serious horsehockey, however, when he says as quoted by Flightglobal that he "is confident that once the full service is up and running, passengers will be able to access the Internet 'in exactly the same way as they can on the ground.'" That may be the case in terms of access, but not in terms of cost. The cost will be enormously high unless OnAir has a magic deal with Inmarsat that's previously undisclosed. I suspect a per MB charge will be in effect that will discourage much use. Calls and texting could be carried over the same system, of course.</p>

<p>Qantas plans to continue to work with Aeromobile for domestic service, with calls and texting available, on their Boeing 767-300s and Airbus A330-200s, Flightglobal reports. Aeromobile has plans to launch a full Internet service later this year using cached and live content. [link via <a href="http://www.setteb.it/"><strong>Fabio Zambelli</strong></a>]</p>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 12:01:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/qantas">qantas</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/channel service">channel service</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/qantas plans">qantas plans</category>
      <category domain="http://securityratty.com/tag/onair">onair</category>
      <category domain="http://securityratty.com/tag/flightglobal">flightglobal</category>
      <category domain="http://securityratty.com/tag/trade mag flightglobal">trade mag flightglobal</category>
      <source url="http://wifinetnews.com/archives/008458.html">Clarity on Qantas' Plans: OnAir and Aeromobile</source>
    </item>
    <item>
      <title><![CDATA[Eye-Fi Adds Upgrade Track at Yearly Fee]]></title>
      <link>http://securityratty.com/article/3e1647519eaf22ed342316fc64fccf49</link>
      <guid>http://securityratty.com/article/3e1647519eaf22ed342316fc64fccf49</guid>
      <description><![CDATA[The Wi-Fi sharing digital memory card Eye-Fi adds another option for its product line: If you've purchased or plan to purchase an Eye-Fi, starting 5-Oct-2008, you can upgrade the model of card you...]]></description>
      <content:encoded><![CDATA[<p><strong><a href="http://www.eye.fi/news/press-releases/">The Wi-Fi sharing digital memory card Eye-Fi adds another option for its product line:</a></strong> If you've purchased or plan to purchase an Eye-Fi, starting 5-Oct-2008, you can upgrade the model of card you purchased by paying a yearly subscription fee. This provides more of a try-and-see mode for Eye-Fi's slightly more expensive offerings.</p>

<p>Eye-Fi divided its Wi-Fi SD card line-up into three parts earlier in the year: Home, which transfers to a computer ($80); Share, which uploads to a computer and to Eye-Fi's servers, which relay them to gallery, print, and social services ($100); and Explore, which ties in Wi-Fi positioning and one year of a Wayport hotspot subscription for uploads ($130). I wrote <strong><a href="http://wifinetnews.com/archives/008418.html">a long review of the Eye-Fi Explore</a></strong> on 12-Aug-2008.</p>

<p><img src="http://wifinetnews.com//images/2008/eye-fi_cards_sharer_sm.jpg" align="right"/>If you bought a Home, you can upgrade to the Share service for $10 per year, and if you bought either a Home or Share, you can add geotagging for $15 per year and hotspot access for $15 per year. It's a smart move, since original Eye-Fi card buyers already had a firmware upgrade that converted their card into a Share model; they'll now be able upgrade to the full featureset. This is something I thought the company was offering at launch months ago, and I speculated it would be easy to add.</p>

<p>Eye-Fi also added two new photo sharing services: Apple's MobileMe and AdoramaPix. I cannot think of any other firm that Apple has partnered with to allow direct MobileMe uploads, although this may be technically less a big deal than it sounds. But I believe it's unique--only the iPhone and iPhoto software can transfers images into MobileMe's galleries; I'll need to investigate further. It's a good feather in Eye-Fi's cap.</p>

<p>Finally, Eye-Fi says they'll release tweaked firmware on 5-Oct as well that will double the speed of photo transfers from their cards to a computer on the local network.</p>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 18:07:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eye-fi">eye-fi</category>
      <category domain="http://securityratty.com/tag/upgrade">upgrade</category>
      <category domain="http://securityratty.com/tag/eye-fi explore">eye-fi explore</category>
      <category domain="http://securityratty.com/tag/explore">explore</category>
      <category domain="http://securityratty.com/tag/direct mobileme uploads">direct mobileme uploads</category>
      <category domain="http://securityratty.com/tag/share service">share service</category>
      <category domain="http://securityratty.com/tag/mobileme">mobileme</category>
      <category domain="http://securityratty.com/tag/share">share</category>
      <category domain="http://securityratty.com/tag/transfers">transfers</category>
      <source url="http://wifinetnews.com/archives/008453.html">Eye-Fi Adds Upgrade Track at Yearly Fee</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: Hypervisor Quick Poll]]></title>
      <link>http://securityratty.com/article/5f4e1b85bcb4d172e0ed7994ef95ea8e</link>
      <guid>http://securityratty.com/article/5f4e1b85bcb4d172e0ed7994ef95ea8e</guid>
      <description><![CDATA[On the final day of Interop NY 2008 , we conducted a second quick poll of attendees ( check out the first poll on virtualization here ), asking which hypervisors were currently in use. In asking the...]]></description>
      <content:encoded><![CDATA[<p><b><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" height="99" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image002.gif" width="91" align="left" border="0"></b>On the final day of <a href="http://www.interop.com/">Interop NY 2008</a>, we conducted a second quick poll of attendees (<a href="http://blog.sciencelogic.com/interop-ny-virtualization-quick-poll/09/2008">check out the first poll on virtualization here</a>), asking which hypervisors were currently in use. In asking the question, we had certain assumptions – mainly that most people were currently using VMware – and that the real question here was to gauge how quickly Microsoft Hyper-V adoption was coming along. The results both confirmed what we thought and surprised us.
<p><b>The Results: </b>
<p><b><i>Which hypervisor(s) are you currently using?</i></b><i></i>
<ul>
<li><b>72%</b> VMware </li>
<li><b>17%</b> Using something else </li>
<li><b>9%</b> Hyper-V and VMware </li>
<li><b>2%</b> Hyper-V </li>
</ul>
<p>(based on 46 responses)
<p>So the VMware responses were in line with what we thought, although I’ve seen numbers up to 90% share of the market. And about 10% are at least playing with Hyper-V – pretty good numbers just a few months out from launch. But look at 17% using a hypervisor other than Hyper-V and VMware!
<p>We know from talking with people that several brought up Xen. I have to tell you that other than from media and analysts, we never hear about Xen (Citrix), which is why we didn’t include it in the survey as a specific selection. Perhaps it took the introduction of Hyper-V, with the attendant marketing juggernaut, to break people of the VMware-only habit. Xen couldn’t really carry that “heterogeneous” hypervisor environment message on its own, but now that Hyper-V is available, the genie’s out of the bottle. Bears watching.
<p>On another note: We were more successful in hanging onto our marbles on day two – people seemed more in tune to the poll and less focused on collecting giveaways than on day one! [Note: no attendees were <a href="http://blog.sciencelogic.com/interop-ny-virtualization-quick-poll/09/2008">irrevocably harmed</a> during the execution of the polls. :)] At Interop Vegas, May 17 – 19, 2009, we’ll be about a year out from Microsoft launching Hyper-V and will make sure to ask the same question then to track changes in hypervisor adoption.</p>
]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 14:30:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware-only habit">vmware-only habit</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/quick poll">quick poll</category>
      <category domain="http://securityratty.com/tag/hypervisor">hypervisor</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/hyper-v">hyper-v</category>
      <category domain="http://securityratty.com/tag/hyper-v pretty">hyper-v pretty</category>
      <category domain="http://securityratty.com/tag/vmware responses">vmware responses</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <source url="http://blog.sciencelogic.com/interop-ny-hypervisor-quick-poll/09/2008">Interop NY: Hypervisor Quick Poll</source>
    </item>
  </channel>
</rss>
