<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: mistakes]]></title>
    <link>http://securityratty.com/tag/mistakes</link>
    <description></description>
    <pubDate>Sat, 27 Sep 2008 11:03:46 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rational Risk Management, Angry Italians, and Irrational Security Analysts]]></title>
      <link>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</link>
      <guid>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</guid>
      <description><![CDATA[Hope you all had a great weekend. I had meant to point you earlier to a FAIR analysis that Chris Hayes did over at his Blog . But Ive been a little busy, and before I could mention it, Stuart King put...]]></description>
      <content:encoded><![CDATA[<p>Hope you all had a great weekend.  I had meant to point you earlier to a <strong><a href="http://risktical.com/2008/11/06/security-template-exception-part-2-%E2%80%93-the-assessment/">FAIR analysis that Chris Hayes did over at his Blog</a></strong>.  But I&#8217;ve been a little busy, and before I could mention it, Stuart King <strong><a href="http://www.computerweekly.com/blogs/stuart_king/2008/11/ive-written-up-a-report.html">put up a kind of angry response</a></strong> on his ComputerWorld blog.  Snark aside, there are a couple of other really troubling aspects of Stuart&#8217;s reaction to Chris&#8217; analysis that I thought we could talk about this morning.</p>
<blockquote><p>The problem is that (Chris&#8217; analysis is) completely impractical. I&#8217;ll take a recent, and fairly typical situation as an example. I was taking issue with the manner in which remote access was being provisioned for a third party vendor to connect to a system hosted by one of our European business units. To cut a long story short, it was not only a breach of policy but highly insecure. I wanted the access to be disconnected, the business unit director wanted my risk assessment. And he didn&#8217;t want to wait for it.</p>
<p>To quote Chris Hayes, spending time on working out <em> <strong>the expected effectiveness of controls, over a given timeframe, as measured against a baseline level of force </strong></em>was not going to pacify an angry Italian fearful that my decision was going to cost him money. He wanted my explanation of the risk and more importantly, what I was going to offer as a solution to keep his business functioning</p></blockquote>
<p>As Chris is someone who actually does this for a living in a large company, and this is typical of his actual day job, I really find Stuart&#8217;s &#8220;impractical&#8221; comment to be, um, misinformed.</p>
<p>Also, I think Stuart mistakes the purpose of a risk analysis.  The purpose of the risk analysis is not to force someone to be &#8220;secure&#8221;, but to provide knowledge for decision making.  Using it as a &#8220;hammer&#8221; to knock in the nail of your personal risk tolerance impairs efficiency and in the long run retards &#8220;security&#8221; as it creates political resentment.  Seriously, who cares if something might violate policy or not in a pre-implementation discussion?  Policies are not stone tablets handed down from on high, they are state-in-time codification of the <em><strong>data owners </strong></em>risk tolerance.  This risk tolerance changes sometimes, and that&#8217;s OK.</p>
<p>To that extent, I appreciate (and I&#8217;m sure Chris does, as well) that risk analysis does not create rationality in the data owner.  Someone who sees you as a speedbump on the route to progress they may not be ready to appreciate your point of view even if it is stated in the most rational manner possible.   But it&#8217;s worth noting (and Stuart&#8217;s example is indicative of this point) that <em><strong>risk analysis does not create rationality in the analyst, either</strong></em>.  If one is being so &#8220;security minded&#8221; as to ignore the risk tolerance of the business owner - we&#8217;re bound to get a reaction similar to that Stuart encountered.  In fact, a practical risk analysis like Chris performed on his blog, done in 30 minutes, should identify the critical point of disagreement between Stuart and the data owner (again, Stuart doesn&#8217;t own the data, the agitated Italian does).</p>
<p>But let&#8217;s stay rational and open to alternatives to what Chris offers.  Stuart states his approach to risk analysis as:</p>
<blockquote><p>When I need to document a risk assessment I use a very simple form: list the threats, state the level of vulnerability, list the associated operational costs and potential revenue hits. High, medium, or low risk? Describe the controls and options. Write up who needs to do what, and how much of their time it&#8217;s going to take. Job done.</p></blockquote>
<p>At first glance, I don&#8217;t think what Chris has done is any less efficient, and it provides greater insight (using Frequency and Capability instead of just &#8216;listing the threats&#8217;).  But what is key here is that Chris&#8217; approach is consistent and defensible.  Less generous risk geeks and CSO&#8217;s I know would have no little difficulty with Stuart&#8217;s approach.  But to particularly answer Stuart&#8217;s main objection (impracticality) I would offer that with practice, Chris&#8217; work is probably quicker and easier than Stuart&#8217;s described process as it eliminates much of the ambiguity an immature risk analysis creates - reducing the need for further discussion and arguments with data owners (regardless of disposition or nationality).</p>
<p>Finally the irony of Stuart&#8217;s post is that the reason he had this confrontation may in fact be because he was incapable of bringing a salient model for risk to the table, one that identified the factors that create risk and developed a defensible belief statement concerning risk.   We&#8217;ll never know if one would have helped him in this isolated instance, but I can tell you that in organizations like Chris&#8217;, good risk models and strong risk anlayses create operational efficiencies, reduce costs, and streamlines intra-departmental communications.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 13:43:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk tolerance">risk tolerance</category>
      <category domain="http://securityratty.com/tag/risk models">risk models</category>
      <category domain="http://securityratty.com/tag/practical risk analysis">practical risk analysis</category>
      <category domain="http://securityratty.com/tag/strong risk anlayses">strong risk anlayses</category>
      <category domain="http://securityratty.com/tag/generous risk geeks">generous risk geeks</category>
      <category domain="http://securityratty.com/tag/immature risk analysis">immature risk analysis</category>
      <category domain="http://securityratty.com/tag/quote chris hayes">quote chris hayes</category>
      <category domain="http://securityratty.com/tag/chris hayes">chris hayes</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=520">Rational Risk Management, Angry Italians, and Irrational Security Analysts</source>
    </item>
    <item>
      <title><![CDATA[Microsoft vows Windows 7 will fix Vista mistakes]]></title>
      <link>http://securityratty.com/article/428140c95e397e58ec06992a17b31426</link>
      <guid>http://securityratty.com/article/428140c95e397e58ec06992a17b31426</guid>
      <description><![CDATA[Microsoft for the first time publicly demonstrated Windows 7, and the software maker insists that the next major release of its PC operating system will reflect lessons learned from the widely panned...]]></description>
      <content:encoded><![CDATA[Microsoft for the first time publicly demonstrated Windows 7, and the software maker insists that the next major release of its PC operating system will reflect lessons learned from the widely panned Windows Vista.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:8248e08a1b8e4d682c58d92efc516990:e%2FVqWvOTHd6ml%2FtaDrtA6MRiltlRizxtrG7Dm%2FApXLG5DzMFRkHsu7XPqmSDlaI9Rmn1WRHJ7YXx'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:07526cd1b76dba93af412b761dee6aca:fwyK3G6HyNnnCyURu9OjhAYfhqDKUaDw38e4nn5HBHOPlQ7kNGsxp%2FROmeF8RawdtgnuVO1VZ4YQhw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7228a3452a6d81de45610a9b9b53032f:hyNejfpNpTlMIznniYrZ9NNlqT0no2cEyyxM%2FC4i8EAdYBI97jEPVDynKkU9XrcV44xTwyGn5brSyA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0681783e862c67d073069ed7d8f22efb:7XjWo7Xy6NHat8x9gKGAUlKtW6EXXPDY31yyA3u1J4if0XF2kut0yGMBjC8e7ie1z0ZjpJ23fwPk2A%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=e5518dbee4063a66c50c54a8ff9f83e2"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=e5518dbee4063a66c50c54a8ff9f83e2" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=e5518dbee4063a66c50c54a8ff9f83e2" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows vista">windows vista</category>
      <category domain="http://securityratty.com/tag/software maker insists">software maker insists</category>
      <category domain="http://securityratty.com/tag/reflect lessons">reflect lessons</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/major release">major release</category>
      <category domain="http://securityratty.com/tag/time publicly">time publicly</category>
      <category domain="http://securityratty.com/tag/widely">widely</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e5518dbee4063a66c50c54a8ff9f83e2">Microsoft vows Windows 7 will fix Vista mistakes</source>
    </item>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[Does Risk Management Make Sense?]]></title>
      <link>http://securityratty.com/article/1c474a0ca5e46c2d82ff6187ee46f0eb</link>
      <guid>http://securityratty.com/article/1c474a0ca5e46c2d82ff6187ee46f0eb</guid>
      <description><![CDATA[We engage in risk management all the time, but it only makes sense if we do it right
Risk management&quot; is just a fancy term for the cost-benefit tradeoff associated with any security decision. It's...]]></description>
      <content:encoded><![CDATA[<p>We engage in risk management all the time, but it only makes sense if we do it right. </p>

<p>"Risk management" is just a fancy term for the cost-benefit tradeoff associated with any security decision. It's what we do when we react to fear, or try to make ourselves feel secure. It's the fight-or-flight reflex that evolved in primitive fish and remains in all vertebrates. It's instinctual, intuitive and fundamental to life, and one of the brain's primary functions. </p>

<p>Some have hypothesized that humans have a "risk thermostat" that tries to maintain some optimal risk level. It explains why we drive our motorcycles faster when we wear a helmet, or are more likely to take up smoking during wartime. It's our natural risk management in action. </p>

<p>The problem is our brains are intuitively suited to the sorts of risk management decisions endemic to living in small family groups in the East African highlands in 100,000 BC, and not to living in the New York City of 2008. We make </p>

<p>systematic risk management mistakes -- miscalculating the probability of rare events, reacting more to stories than data, responding to the feeling of security rather than reality, and making decisions based on irrelevant context. And that risk cockpit of ours? It's not nearly as finely tuned as we might like it to be. </p>

<p>Like a rabbit that responds to an oncoming car with its default predator avoidance behavior -- dart left, dart right, dart left, and at the last moment jump -- instead of just getting out of the way, our Stone Age intuition doesn't serve us well in a modern technological society. So when we in the security industry use the term "risk management," we don't want you to do it by trusting your gut. We want you to do risk management consciously and intelligently, to analyze the tradeoff and make the best decision. </p>

<p>This means balancing the costs and benefits of any security decision -- buying and installing a new technology, implementing a new procedure or forgoing a common precaution. It means allocating a security budget to mitigate different risks by different amounts. It means buying insurance to transfer some risks to others. It's what businesses do, all the time, about everything. IT security has its own risk management decisions, based on the threats and the technologies. </p>

<p>There's never just one risk, of course, and bad risk management decisions often carry an underlying tradeoff. Terrorism policy in the U.S. is based more on politics than actual security risk, but the politicians who make these decisions are concerned about the risks of not being re-elected. </p>

<p>Many corporate security decisions are made to mitigate the risk of lawsuits rather than address the risk of any actual security breach. And individuals make risk management decisions that consider not only the risks to the corporation, but the risks to their departments' budgets, and to their careers. </p>

<p>You can't completely remove emotion from risk management decisions, but the best way to keep risk management focused on the data is to formalize the methodology. That's what companies that manage risk for a living -- insurance companies, financial trading firms and arbitrageurs -- try to do. They try to replace intuition with models, and hunches with mathematics. </p>

<p>The problem in the security world is we often lack the data to do risk management well. Technological risks are complicated and subtle. We don't know how well our network security will keep the bad guys out, and we don't know the cost to the company if we don't keep them out. And the risks change all the time, making the calculations even harder. But this doesn't mean we shouldn't try. </p>

<p>You can't avoid risk management; it's fundamental to business just as to life. The question is whether you're going to try to use data or whether you're going to just react based on emotions, hunches and anecdotes. </p>

<p>This essay appeared as the first half of a <a href="http://searchsecurity.techtarget.com/loginMembersOnly/1,289498,sid14_gci1332745,00.html?">point-counterpoint</a> with Marcus Ranum in <i>Information Security</i> magazine.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=etFHM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=etFHM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=KYvhM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=KYvhM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 09:25:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management decisions">risk management decisions</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/avoid risk management">avoid risk management</category>
      <category domain="http://securityratty.com/tag/natural risk management">natural risk management</category>
      <category domain="http://securityratty.com/tag/risk management consciously">risk management consciously</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security world">security world</category>
      <category domain="http://securityratty.com/tag/information security magazine">information security magazine</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/does_risk_manag.html">Does Risk Management Make Sense?</source>
    </item>
    <item>
      <title><![CDATA[7 Online Blunders That Invite Identity Theft]]></title>
      <link>http://securityratty.com/article/699f90e8a8ac198938a862e1df183941</link>
      <guid>http://securityratty.com/article/699f90e8a8ac198938a862e1df183941</guid>
      <description><![CDATA[These common mistakes can ruin your computer or invite identity...]]></description>
      <content:encoded><![CDATA[These common mistakes can ruin your computer or invite identity theft]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 11:10:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/invite identity theft">invite identity theft</category>
      <category domain="http://securityratty.com/tag/common mistakes">common mistakes</category>
      <category domain="http://securityratty.com/tag/ruin">ruin</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <source url="http://digg.com/security/7_Online_Blunders_That_Invite_Identity_Theft">7 Online Blunders That Invite Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[7 Online Blunders That Invite Identity Theft]]></title>
      <link>http://securityratty.com/article/74ec2668b01f32fdc2a51b6071ea690d</link>
      <guid>http://securityratty.com/article/74ec2668b01f32fdc2a51b6071ea690d</guid>
      <description><![CDATA[These common mistakes can ruin your computer or invite identity...]]></description>
      <content:encoded><![CDATA[These common mistakes can ruin your computer or invite identity theft<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/UyfMCzGVlyY" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 11:10:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/invite identity theft">invite identity theft</category>
      <category domain="http://securityratty.com/tag/common mistakes">common mistakes</category>
      <category domain="http://securityratty.com/tag/ruin">ruin</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/UyfMCzGVlyY/7_Online_Blunders_That_Invite_Identity_Theft">7 Online Blunders That Invite Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[Hacking Your VoIP Box From The Net]]></title>
      <link>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</link>
      <guid>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</guid>
      <description><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read this recent blog from McAfee's Avert Labs and you may wonder. An Avert analyst, reading about vulnerabilities in the...]]></description>
      <content:encoded><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read <a href="http://www.avertlabs.com/research/blog/index.php/2008/09/29/the-lack-of-attention-in-voip-devices/">this recent blog from McAfee's Avert Labs</a> and you may wonder.

An Avert analyst, reading about vulnerabilities in the Cisco IP phone model 7960 then used Google to try to find publicly-accessible 7960 phones. He found "almost 10" (does that mean 9? awkward turn of phrase). 1 of them had the vulnerable firmware version  And the vulnerability was that the phone's web interface reveals a lot of sensitive network information, so the company that holds that phone has a vulnerable network.

What was revealed by the phone? "...the IP addresses of the TFTP server/router/DNS server/DHCP server/Cisco Call Manager, as well as some application links, internal device configuration, and debugging information. If there are any exploitable vulnerabilities in one of these linked servers, attackers could use this information to stage further attacks."

There's always more to test for, and mistakes you in device configuration can have dire consequences.
<p><a href="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/a"><img src="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/sIcbcZ5FSGQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 13:06:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive network information">sensitive network information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/device configuration">device configuration</category>
      <category domain="http://securityratty.com/tag/internal device configuration">internal device configuration</category>
      <category domain="http://securityratty.com/tag/phone model">phone model</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/exploitable vulnerabilities">exploitable vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerable network">vulnerable network</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/sIcbcZ5FSGQ/hacking_your_voip_box_from_the_net.html">Hacking Your VoIP Box From The Net</source>
    </item>
    <item>
      <title><![CDATA[AntiVirus XP ads on Google?]]></title>
      <link>http://securityratty.com/article/fbe1e948b35797683a6cb1847cb24142</link>
      <guid>http://securityratty.com/article/fbe1e948b35797683a6cb1847cb24142</guid>
      <description><![CDATA[So, If I had clicked on this ad, and dnloaded this awful program and my puter was infected,,,, Would Google be responsible


clipped from www.2-spyware.com

Time for vengeance: AntiVirus XP...]]></description>
      <content:encoded><![CDATA[<div > So, If I had clicked on this ad, and dnloaded this awful program and my puter was infected,,,,<br/>Would Google be responsible? </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/0591D79E-5625-46DF-A69C-648E98927C9D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/24356b93-5430-4d1c-8b56-02ef5d918cb2/0591D79E-5625-46DF-A69C-648E98927C9D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.2-spyware.com/news/post428.html" href="http://www.2-spyware.com/news/post428.html" style="font-size: 11px;">www.2-spyware.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.2-spyware.com/news/post428.html -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Time for vengeance: AntiVirus XP distributors sued</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.2-spyware.com/news/post428.html --><P>Malware vendors hide well, however they do make mistakes. Distributors of Antivirus XP were bold enough and dumb enough to buy advertisements on Google Adwords! You get it right: someone looking for anti-virus software on Google search engine was offered Antivirus XP by official adds from Google. The scam was noticed pretty soon. Security experts all over the web guess that this mistake was the one that revealed names of AntivirusXP vendors. Victims of Antivirus XP can start celebrating as the distributors won’t get away easily.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/0591D79E-5625-46DF-A69C-648E98927C9D/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_031008031203"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=031008031203&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=031008031203&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=031008031203&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_031008031203" /></a></P>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 11:12:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/google adwords">google adwords</category>
      <category domain="http://securityratty.com/tag/distributors">distributors</category>
      <category domain="http://securityratty.com/tag/distributors sued">distributors sued</category>
      <category domain="http://securityratty.com/tag/malware vendors hide">malware vendors hide</category>
      <category domain="http://securityratty.com/tag/anti-virus software">anti-virus software</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/awful program">awful program</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=637">AntiVirus XP ads on Google?</source>
    </item>
    <item>
      <title><![CDATA[Five mistakes security pros would make again]]></title>
      <link>http://securityratty.com/article/820ddf7ceb22e457bf492e07ad17dc7b</link>
      <guid>http://securityratty.com/article/820ddf7ceb22e457bf492e07ad17dc7b</guid>
      <description><![CDATA[Ten years ago, Michael Riva was network administrator for a top-five American consultancy. Employees were downloading graphic pictures and videos onto the network. Riva told his boss a proxy server...]]></description>
      <content:encoded><![CDATA[Ten years ago, Michael Riva was network administrator for a top-five American consultancy. Employees were downloading graphic pictures and videos onto the network. Riva told his boss a proxy server with content filtering might be in order; his boss laughed and suggested they put in a bigger file server instead.]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/michael riva">michael riva</category>
      <category domain="http://securityratty.com/tag/bigger file server">bigger file server</category>
      <category domain="http://securityratty.com/tag/riva">riva</category>
      <category domain="http://securityratty.com/tag/network administrator">network administrator</category>
      <category domain="http://securityratty.com/tag/top-five american consultancy">top-five american consultancy</category>
      <category domain="http://securityratty.com/tag/boss">boss</category>
      <category domain="http://securityratty.com/tag/graphic pictures">graphic pictures</category>
      <category domain="http://securityratty.com/tag/proxy server">proxy server</category>
      <source url="http://www.networkworld.com/news/2008/092908-five-mistakes-security-pros-would.html?fsrc=rss-security">Five mistakes security pros would make again</source>
    </item>
    <item>
      <title><![CDATA[Huh? Elected officials held accountable?]]></title>
      <link>http://securityratty.com/article/9e083b7a721e2a7294b607e981471adb</link>
      <guid>http://securityratty.com/article/9e083b7a721e2a7294b607e981471adb</guid>
      <description><![CDATA[I woke up in another universe this morning. Here in this universe, elected officials are held accountable for their mistakes that harm you. I suspect though that collecting on the courts award will be...]]></description>
      <content:encoded><![CDATA[<div > I woke up in another universe this morning. Here in this universe, elected officials are held accountable for their mistakes that harm you.<br/>I suspect though that collecting on the courts award will be another nightmare altogether. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/13363943-34BB-498A-A917-56EABD121550/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/cc5dd35b-332f-43b0-abf6-c61a32d8092f/13363943-34BB-498A-A917-56EABD121550/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343" href="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343" style="font-size: 11px;">news.cincinnati.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Elected officials can be sued in ID theft, court rules</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343 --><P>Elected officials can be sued if they place your private information online and someone uses it to steal your identity, an Ohio appeals court ruled Friday in overturning a lower court ruling.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/13363943-34BB-498A-A917-56EABD121550/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_270908030346"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_270908030346" /></a></P>]]></content:encoded>
      <pubDate>Sat, 27 Sep 2008 11:03:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/held accountable">held accountable</category>
      <category domain="http://securityratty.com/tag/sued">sued</category>
      <category domain="http://securityratty.com/tag/information online">information online</category>
      <category domain="http://securityratty.com/tag/courts award">courts award</category>
      <category domain="http://securityratty.com/tag/nightmare altogether">nightmare altogether</category>
      <category domain="http://securityratty.com/tag/court rules">court rules</category>
      <category domain="http://securityratty.com/tag/lower court">lower court</category>
      <category domain="http://securityratty.com/tag/universe">universe</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=631">Huh? Elected officials held accountable?</source>
    </item>
  </channel>
</rss>
