<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: news]]></title>
    <link>http://securityratty.com/tag/news</link>
    <description></description>
    <pubDate>Fri, 26 Sep 2008 08:56:15 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-10-03 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/68de2ec5e50b7e831d8511a04ab659fe</link>
      <guid>http://securityratty.com/article/68de2ec5e50b7e831d8511a04ab659fe</guid>
      <description><![CDATA[Ries' Pieces: McCain vs. Obama. Coke vs. Pepsi
PCI DSS News and Information PCI version 1.2
Security Ripcord Blog Archive Increase Your Logging
Logging can be good for business | Thailand News |...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://ries.typepad.com/ries_blog/2008/09/how-to-become-president.html">Ries' Pieces: McCain vs. Obama. Coke vs. Pepsi</a></li>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=181">PCI DSS News and Information &raquo; PCI version 1.2</a></li>
<li><a href="http://www.cutawaysecurity.com/blog/archives/342">Security Ripcord &raquo; Blog Archive &raquo; Increase Your Logging</a></li>
<li><a href="http://news.tourthailand.org/outlook-news/logging-can-be-good-for-business.html">Logging can be good for business | Thailand News | Thailand Daily News</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/410844509" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/thailand daily news">thailand daily news</category>
      <category domain="http://securityratty.com/tag/information pci version">information pci version</category>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <category domain="http://securityratty.com/tag/thailand news">thailand news</category>
      <category domain="http://securityratty.com/tag/ries">ries</category>
      <category domain="http://securityratty.com/tag/mccain">mccain</category>
      <category domain="http://securityratty.com/tag/obama">obama</category>
      <category domain="http://securityratty.com/tag/pieces">pieces</category>
      <category domain="http://securityratty.com/tag/coke">coke</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/410844509/anton18">Links for 2008-10-03 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Money meltdown, Ozzie's cloud, security worries]]></title>
      <link>http://securityratty.com/article/d4c8a90dbbb22938be850c3f4dd5bf8e</link>
      <guid>http://securityratty.com/article/d4c8a90dbbb22938be850c3f4dd5bf8e</guid>
      <description><![CDATA[At least those of us who are fans of professional baseball have the playoffs to take our minds off the grim news this week (at least that's the case for fans of the teams that are winning). The U.S....]]></description>
      <content:encoded><![CDATA[At least those of us who are fans of professional baseball have the playoffs to take our minds off the grim news this week (at least that's the case for fans of the teams that are winning). The U.S. financial system meltdown smacked world markets and set off a whole lot of worry, which tended to overshadow all the other news.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=73179?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=73179?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial system meltdown">financial system meltdown</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/grim news">grim news</category>
      <category domain="http://securityratty.com/tag/fans">fans</category>
      <category domain="http://securityratty.com/tag/professional baseball">professional baseball</category>
      <category domain="http://securityratty.com/tag/world markets">world markets</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/teams">teams</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.networkworld.com/news/2008/100308-money-meltdown-ozzies-cloud-security.html?fsrc=rss-security">Money meltdown, Ozzie's cloud, security worries</source>
    </item>
    <item>
      <title><![CDATA[ePolicing - Tomorrow the world?]]></title>
      <link>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</link>
      <guid>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</guid>
      <description><![CDATA[This week has finally seen an announcement that the Police Central e-crime Unit (PCeU) is to be funded by the Home Office. However, the largesse amounts to just 3.5 million of new money spread over...]]></description>
      <content:encoded><![CDATA[<p>This week has finally seen an <a href="http://press.homeoffice.gov.uk/press-releases/new-specialist-ecrime-unit">announcement</a> that the <a href="http://www.met.police.uk/pceu/index.htm">Police Central e-crime Unit</a> (PCeU) is to be funded by the Home Office. However, the largesse amounts to just £3.5 million of new money spread over three years, with the Met putting up a further £3.9 million &#8212; but whether the Met&#8217;s contribution is &#8220;new&#8221; or reflects a move of resources from their existing <a href="http://www.met.police.uk/computercrime/">Computer Crime Unit</a> I could not say.</p>
<p>The announcement is of course Good News &#8212; because once the PCeU is up and running next Spring, it should plug (to the limited extent that £2 million a year can plug) the &#8220;level 2&#8243; eCrime gap that I&#8217;ve <a href="http://www.lightbluetouchpaper.org/2006/02/06/mysterious-and-menacing/">written</a> <a href="http://www.lightbluetouchpaper.org/2006/10/13/mainstreaming-ecrime/">about</a> <a href="http://www.lightbluetouchpaper.org/2007/02/11/soca-we-just-want-your-money/">before</a>. viz: that SOCA tackles &#8220;serious and organised crime&#8221; (level 3), your local police force tackles local villains (level 1), but if criminals operate outside their force&#8217;s area &#8212; and on the Internet this is more likely than not &#8212; yet they don&#8217;t meet SOCA&#8217;s threshold, then who is there to deal with them?</p>
<p>In particular, the PCeU is envisaged to be the unit that deals with the intelligence packages coming from the <a href="http://www.cityoflondon.police.uk/CityPolice/ECD/Fraud/">City of London Fraud Squad&#8217;s</a> new online Fraud Reporting <a href="http://www.kablenet.com/kd.nsf/Frontpage/356DD0A1942F3A998025745F0049092C?OpenDocument">website</a> (once intended to launch in November 2008, now scheduled for Summer 2009).</p>
<p>Of course everyone expects the website to generate more reports of eCrime than could ever be dealt with (even with much more money), so the effectiveness of the PCeU in dealing with eCriminality will depend upon their prioritisation criteria, and how carefully they select the cases they tackle.</p>
<p>Nevertheless, although the news this week shows that the Home Office have finally understood the need to fund more ePolicing, I don&#8217;t think that they are thinking about the problem in a sufficiently global context.</p>
<p>A little history lesson might be in order to explain why.<br />
<span id="more-401"></span></p>
<p>Back in 1930&#8217;s, <a href="http://www.fbi.gov/libref/historic/famcases/clyde/clyde.htm">Bonnie and Clyde</a> and other US bank robbers were using the new-fangled automobile to flee across state lines &#8212; creating jurisdictional problems as a result. The US solution was to make bank robbery (along with auto-theft and other related offences) into federal offences rather keeping them as state-specific infractions. In particular this meant that the FBI could provide federal level policing (tracking down and killing <a href="http://en.wikipedia.org/wiki/John_Dillinger">John Dillinger</a> for example).</p>
<p>We have the same jurisdictional issues dealing with cyberspace, with criminals in one country fleecing consumers in another while using systems hosted in a third. The <a href="http://conventions.coe.int/Treaty/EN/Treaties/Html/185.htm">Convention on Cybercrime</a> addresses part of the problem by trying to ensure international consistency where eLaws are specifically needed (which of course is only the case for small parts of eCriminality, <a href="http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060035_en_1">fraud</a> is fraud whether eEnabled or not). However, there is limited inter-jurisdictional <em>co-ordination</em> for eCrime investigations &#8212; for example <a href="http://www.interpol.int/">Interpol</a> (often <a href="http://en.wikipedia.org/wiki/Interpol#Interpol_in_popular_culture">incorrectly perceived</a> to be international police force)  merely keeps a large database and passes faxes from one place to another.</p>
<p>In practice, most cross-border investigations are done as &#8220;joint operations&#8221; and the jointness is usually very limited &#8212; one force does all the legwork and a liaison officer in the other country deals with local paperwork. There&#8217;s usually a <a href="http://www.phrases.org.uk/meanings/quid-pro-quo.html">quid pro quo</a> element to these joint operations, for budgeting reasons if no other.</p>
<p>What isn&#8217;t happening, or at least only in a handful of very specialised areas, is any international co-operation in setting priorities or selecting cases to pursue. Every country is doing its own thing about eCrime, and there&#8217;s a widespread impression that any criminal who can operate from &#8220;across the state line&#8221; is essentially immune from serious investigation.</p>
<p>We identified this problem last year when we (<a href="http://www.cl.cam.ac.uk/~rja14/">Ross Anderson</a>, <a href="http://www.inf.tu-dresden.de/index.php?node_id=489">Rainer Böhme</a>, <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a>) wrote a report on <a href="http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&#038;_int_mark_20080131.pdf">Security Economics and the Internal Market</a> for <a href="http://www.enisa.europa.eu/">ENISA</a>. It&#8217;s not an easy one to fix whilst politicians (and populaces) are unwilling to see &#8220;foreign&#8221; police officers operating in their country, and the establishment of a truly international &#8220;cyber police force&#8221; seems equally unlikely.</p>
<p>Our policy proposal to tackle the issue harks back to WWII&#8217;s <a href="http://www.archives.gov/research/holocaust/finding-aid/military/rg-331.html">SHAEF</a>, which has morphed into similar arrangements within <a href="http://www.nato.int/shape/about/background2.htm">NATO</a>. In essence liaison officers from multiple forces would sit around a single table, working with a central coordinator, to set policy and decide which investigations to pursue. They would then communicate back to their own countries, who have specifically budgeted to provide appropriate assistance. So it&#8217;s very like &#8220;joint operations&#8221;, but the scheme is multi-laterial, and has a true command and control function in the centre &#8212; who will quickly learn to shy away from politically sensitive topics and make a real impact on eCriminality.</p>
<p>To summarise then, a <a href="http://www.cartoonbank.com/item/34449">welcome</a> to the Home Office for finally finding a small amount of funding for some country-wide ePolicing; but it&#8217;s well past time to be working on world-wide initiatives.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 13:57:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecrime gap">ecrime gap</category>
      <category domain="http://securityratty.com/tag/ecrime">ecrime</category>
      <category domain="http://securityratty.com/tag/provide federal level">provide federal level</category>
      <category domain="http://securityratty.com/tag/ecrime investigations">ecrime investigations</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/level">level</category>
      <category domain="http://securityratty.com/tag/country deals">country deals</category>
      <category domain="http://securityratty.com/tag/deals">deals</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/02/epolicing-tomorrow-the-world/">ePolicing - Tomorrow the world?</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-10-01 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</link>
      <guid>http://securityratty.com/article/2e61bbf8f65cea7668e676362729b6b6</guid>
      <description><![CDATA[Behavioral Monitoring | securosis.com
Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization
E-Commerce News: ID...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securosis.com/2008/09/23/behavioral-monitoring/">Behavioral Monitoring | securosis.com</a></li>
<li><a href="http://briefingsdirectblog.blogspot.com/2008/09/improved-insights-and-analysis-from-it.html">Dana Gardner's BriefingsDirect: Improved insights and analysis from IT systems logs helps reduce complexity risks from virtualization</a></li>
<li><a href="http://www.ecommercetimes.com/story/64598.html">E-Commerce News: ID Security: New PCI Security Standard Falls Short</a></li>
<li><a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">Enterprise Architecture: From Incite comes Insight...: How many fingers are required to count the number of clueless IT Security Professionals?</a></li>
<li><a href="http://www.csoonline.com/article/print/450190">IT Security: Can We Be Compliant and Yet Insecure?</a></li>
<li><a href="http://blogs.gartner.com/greg_young/2008/09/30/get-rich-quick-with-network-security/">Get Rich Quick With Network Security</a></li>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/09/ids-vitamins-or-prophylactic.html">Rational Survivability: IDS: Vitamins Or Prophylactic?</a></li>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=174">PCI DSS News and Information &raquo; Great Expectations?</a></li>
<li><a href="http://www.estoregfoa.org/StaticContent/staticpages/TM0508.htm#1c">GFOA Treasury Management</a></li>
<li><a href="http://forensics.sans.org/community/top7_forensic_trends.php">SANS - Computer Forensics - Top 7 New IR/Forensic Trends In 2008</a><br/>
SANS Top 7 New IR/Forensic Trends In 2008</li>
<li><a href="http://securitybuddha.com/2008/09/30/you-might-be-a-pm-if/">You Might be a PM if&hellip; &laquo; Mark Curphey - SecurityBuddha.com</a></li>
<li><a href="http://blogs.computerworld.com/security_is_not_a_solution">Security is not a solution | Computerworld Blogs</a><br/>
Security is not a solution</li>
<li><a href="http://www.andrewhay.ca/archives/385">Andrew Hay &raquo; Blog Archive &raquo; Secure Life Ep 3</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408931097" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/computerworld blogs security">computerworld blogs security</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/sans top">sans top</category>
      <category domain="http://securityratty.com/tag/irforensic trends">irforensic trends</category>
      <category domain="http://securityratty.com/tag/sans">sans</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408931097/anton18">Links for 2008-10-01 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[In the News: London's Free Wifi, Cybercrime Everywhere]]></title>
      <link>http://securityratty.com/article/0093444ed8b6ae04ebe08a5e2f42a3c3</link>
      <guid>http://securityratty.com/article/0093444ed8b6ae04ebe08a5e2f42a3c3</guid>
      <description><![CDATA[ID Theft Service Crawls the Web on Consumers' BehalfProactivity always beats passivity, especially when it comes to identity theft. That's why ASC (Affinion Security Center), an ID-theft...]]></description>
      <content:encoded><![CDATA[ID Theft Service Crawls the Web on Consumers' BehalfProactivity always beats passivity, especially when it comes to identity theft. That's why ASC (Affinion Security Center), an ID-theft preve...]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 11:42:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/affinion security center">affinion security center</category>
      <category domain="http://securityratty.com/tag/theft service crawls">theft service crawls</category>
      <category domain="http://securityratty.com/tag/id-theft preve">id-theft preve</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/beats passivity">beats passivity</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/asc">asc</category>
      <category domain="http://securityratty.com/tag/consumers">consumers</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/408698816/">In the News: London's Free Wifi, Cybercrime Everywhere</source>
    </item>
    <item>
      <title><![CDATA[Protect yourselves from identity fraud]]></title>
      <link>http://securityratty.com/article/2d5527de63a883eccd4dd52baa574670</link>
      <guid>http://securityratty.com/article/2d5527de63a883eccd4dd52baa574670</guid>
      <description><![CDATA[Soon youll be seeing the infomercials on late nite TV. Its becoming very profitable, easy set up, even tutoring


clipped from news.cnet.com

Behind the scenes of online fraud



Fraudsters arent just...]]></description>
      <content:encoded><![CDATA[<div > Soon you&#8217;ll be seeing the infomercials on late nite TV.<br/>Its becoming very profitable, easy set up, even tutoring. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/F3D2C488-5ECA-4C1C-9234-F72627E7787F/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e39e0526-6ef5-4791-8146-a5dc9f35d899/F3D2C488-5ECA-4C1C-9234-F72627E7787F/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title" href="http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title" style="font-size: 11px;">news.cnet.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Behind the scenes of online fraud</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title --><P><br />
Fraudsters aren&#8217;t just targeting bank customers. They are also luring victims off social networks, where they harvest sensitive private information, and online gaming sites, where they steal accomplished avatars and accounts and sell them for money, Rivner says. </P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title --><P><br />
Online fraud tools have price tags just like any other software. For example, the Mpack Infection Kit costs $700, a Dream BotBuilder costs $500, and at just $350, the Limbo Trojan is practically a steal, according to Rivner. </P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title --><P><br />
For people who don&#8217;t have the skills to install, run, and manage their own Trojans and other tools, fraudsters are offering fraud software as a service for $299 a month, &#8220;which means anyone can do it,&#8221; he says.</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cnet.com/8301-1009_3-10051688-83.html?tag=mncol;title --><P><br />
While online attacks get the headlines, a bigger risk is from skimmers, fake faceplates for ATM machines that steal card data from the magnetic strip. The data is then used to make forged cards.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/F3D2C488-5ECA-4C1C-9234-F72627E7787F/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_290908013218"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=290908013218&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=290908013218&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=290908013218&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_290908013218" /></a></P>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 09:32:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/online fraud tools">online fraud tools</category>
      <category domain="http://securityratty.com/tag/online attacks">online attacks</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/fraud software">fraud software</category>
      <category domain="http://securityratty.com/tag/dream botbuilder costs">dream botbuilder costs</category>
      <category domain="http://securityratty.com/tag/card data">card data</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=633">Protect yourselves from identity fraud</source>
    </item>
    <item>
      <title><![CDATA[Short takes]]></title>
      <link>http://securityratty.com/article/8f505e3486dd70da4fa62212e1ce07fb</link>
      <guid>http://securityratty.com/article/8f505e3486dd70da4fa62212e1ce07fb</guid>
      <description><![CDATA[Brief IT news...]]></description>
      <content:encoded><![CDATA[Brief IT news items.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9b48bb0810550cae1d7cd2610caaeaf8:WHyNBmUBWPQQgvVAR51tTIeWRk2hRRz%2FuySgSJQst9kCg6%2FqCdQALpExdN8ZWsw5MCUwXtaqxD9w'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:773abfa6a254860d06c8deb2e0b4f440:iJgC6dwckAF83f5CFWioSQ1y24XUkz58qdp6MqEcrjx7LiK9x8SsUrw5aqb0LRPNc0pT4EnrzwDGsA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:af9be679ad3cb02342974e232c61b439:guIuOq4H5cmLeSKfo6f7S1XybkSo9Dl62iHSLmVDs0WW487EUoWbx%2BvqkOpSTOoouIhLKvTjp%2F0Ouw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:27deaff8c502590eb489466d2e6fcd90:u8JP4VRooxtwdUMpWWXlwsq%2BAeLjmymrfGMHk8QQUGxQWNjTe2wsxbsQEfo%2FqPdPDJ5NfWevmJDBag%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=046644533371a97491233d5336994a11" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=046644533371a97491233d5336994a11" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/news items">news items</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=046644533371a97491233d5336994a11">Short takes</source>
    </item>
    <item>
      <title><![CDATA[FAQ: Clickjacking - should you be worried?]]></title>
      <link>http://securityratty.com/article/ee8fbd44c287a162484e3f7975a10ab2</link>
      <guid>http://securityratty.com/article/ee8fbd44c287a162484e3f7975a10ab2</guid>
      <description><![CDATA[Last week, a pair of security researchers spread the news that a new class of vulnerabilities, called &quot;clickjacking,&quot; puts users of every major browser at risk from possible...]]></description>
      <content:encoded><![CDATA[Last week, a pair of security researchers spread the news that a new class of vulnerabilities, called "clickjacking," puts users of every major browser at risk from possible attack.]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security researchers spread">security researchers spread</category>
      <category domain="http://securityratty.com/tag/major browser">major browser</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/pair">pair</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/class">class</category>
      <source url="http://www.networkworld.com/news/2008/092908-faq-clickjacking-should-you.html?fsrc=rss-security">FAQ: Clickjacking - should you be worried?</source>
    </item>
    <item>
      <title><![CDATA[Huh? Elected officials held accountable?]]></title>
      <link>http://securityratty.com/article/9e083b7a721e2a7294b607e981471adb</link>
      <guid>http://securityratty.com/article/9e083b7a721e2a7294b607e981471adb</guid>
      <description><![CDATA[I woke up in another universe this morning. Here in this universe, elected officials are held accountable for their mistakes that harm you. I suspect though that collecting on the courts award will be...]]></description>
      <content:encoded><![CDATA[<div > I woke up in another universe this morning. Here in this universe, elected officials are held accountable for their mistakes that harm you.<br/>I suspect though that collecting on the courts award will be another nightmare altogether. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/13363943-34BB-498A-A917-56EABD121550/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/cc5dd35b-332f-43b0-abf6-c61a32d8092f/13363943-34BB-498A-A917-56EABD121550/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343" href="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343" style="font-size: 11px;">news.cincinnati.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Elected officials can be sued in ID theft, court rules</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343 --><P>Elected officials can be sued if they place your private information online and someone uses it to steal your identity, an Ohio appeals court ruled Friday in overturning a lower court ruling.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/13363943-34BB-498A-A917-56EABD121550/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_270908030346"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_270908030346" /></a></P>]]></content:encoded>
      <pubDate>Sat, 27 Sep 2008 11:03:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/held accountable">held accountable</category>
      <category domain="http://securityratty.com/tag/sued">sued</category>
      <category domain="http://securityratty.com/tag/information online">information online</category>
      <category domain="http://securityratty.com/tag/courts award">courts award</category>
      <category domain="http://securityratty.com/tag/nightmare altogether">nightmare altogether</category>
      <category domain="http://securityratty.com/tag/court rules">court rules</category>
      <category domain="http://securityratty.com/tag/lower court">lower court</category>
      <category domain="http://securityratty.com/tag/universe">universe</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=631">Huh? Elected officials held accountable?</source>
    </item>
    <item>
      <title><![CDATA[Around The Web For Friday]]></title>
      <link>http://securityratty.com/article/854f3c7cd7fbfd4b803df29d7a415b9d</link>
      <guid>http://securityratty.com/article/854f3c7cd7fbfd4b803df29d7a415b9d</guid>
      <description><![CDATA[Were frequently asked what were reading and what we like in blog posts, so here are some interesting things that hit our RSS readers that you may have missed
COBIT rivals ITIL from The IT Skeptic...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;re frequently asked what we&#8217;re reading and what we like in blog posts, so here are some interesting things that hit our RSS readers that you may have missed:</p>
<p><a href="http://www.itskeptic.org/node/692"><strong>COBIT rivals ITIL from The IT Skeptic</strong></a></p>
<blockquote><p>&#8220;Everyone is tiptoeing around the fact that COBIT offers a significant competitive body of knowledge (BOK) to ITIL. Sure ITIL goes into more depth in places, but to say COBIT sits over the top is to grossly understate the overlap. COBIT extends a long way down into the &#8220;how&#8221; and it does it with an intellectual rigour that ITIL lacks.&#8221;</p></blockquote>
<p>Interesting stuff that.  A detailed mapping might help some folks.  Either way, the good news for those keen on understanding risk management is that governance metrics, done right, allow us to understand a part of that &#8220;capability to manage risk&#8221; we&#8217;re always looking for.   Assurance, verification and the acquisition and interpretation of knowledge is king.   Speaking of which&#8230;.</p>
<p><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/09/how-to-tell-when-nothing-happens.html"><strong>How To Tell When &#8220;Nothing Happens&#8221; by Pete Lindstrom</strong></a></p>
<blockquote><p>&#8220;&#8230;problem is that, it isn&#8217;t really true that &#8220;nothing happens&#8221; when you employ some specific security control to prevent an exploit. Not only that, but even when it is difficult to collect data on what didn&#8217;t happen, one can devise experiments to tell how frequently that nothing occurred.&#8221;</p></blockquote>
<p><em>Good</em> analysis is all about the uncertainty.   Speaking of accounting for uncertainty&#8230;</p>
<p><a href="http://1raindrop.typepad.com/1_raindrop/2008/09/assets-good-until-reached-for.html"><strong>Assets Good Until Reached For by Gunnar Peterson</strong></a></p>
<blockquote><p>&#8220;If you have a 100,000 dekstops or 100,000 servers it hard to manage. You will need to automate and to do that you need to abstract, but you should also realize that its a drawing on a whiteboard not reality. You need abstraction assurance.&#8221;</p></blockquote>
<p>And there&#8217;s the trick.  We might call &#8220;abstraction assurance&#8221; an analog to &#8220;confidence&#8221; or &#8220;uncertainty&#8221; in certain priors (metrics) or posteriors (calculated values based on those metrics).  The stronger that abstraction assurance is, the less uncertainty we have in our knowledge and the better our ability to create wisdom from that knowledge (you know, make decisions).</p>
<p><a href="http://www.emergentchaos.com/archives/2005/12/epstein_snow_an.html"><strong>Epstein, Snow and Flake: Three Views of Software Security by Adam Shostack</strong></a></p>
<p>Adam&#8217;s focus is on software security, but the discussion here can be abstracted out into the broader realm of risk management quite nicely.</p>
<p><a href="http://www.securityfocus.com/brief/825?ref=rss"><strong>Two-thirds of firms hit by cybercrime from Security Focus</strong></a></p>
<p>The US DoJ says that in 2005 (there&#8217;s some timely data) 2/3 of their surveyed firms detected at least one cybercrime.  &#8220;Cybercrime&#8221; is &#8220;classified &#8230; into cyber attacks, cyber theft, and other incidents.&#8221;  Pretty general.  Also from the report:  &#8220;Computer viruses made up more than half of all cyber attacks.&#8221;</p>
<p>(That sound you hear is me tapping my forehead lightly on large iron object)</p>
<p><a href="http://blog.ca-grc.com/2008/09/lessons-learned-from-%E2%80%9Cpersonal%E2%80%9D-risk-management/"><strong>Lessons Learned from “Personal” Risk Management By: Christopher Daugherty</strong></a></p>
<blockquote><p>&#8220;This process is what I call “personal risk management.”  All of us have done it and will continue to do so.  Why is it, then, many companies have ignored following similar principles with the on-going health of the business?  This is a debate with many different answers so I ask you to select the best answer for your employer:</p>
<p>a) Have not ignored as this keeps me awake at night!</p>
<p>b) Please restate the problem, I cannot hear well with my head buried in the sand.</p>
<p>c) We passed our SOX audit so we checked this off the list!</p>
<p>d) We are informed of the challenge but we have a business to run and profits to make</p>
<p>e) Is this what internal audit and risk management has been telling us?&#8221;</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 08:56:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/call abstraction assurance">call abstraction assurance</category>
      <category domain="http://securityratty.com/tag/abstraction assurance">abstraction assurance</category>
      <category domain="http://securityratty.com/tag/personal risk management">personal risk management</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/assurance">assurance</category>
      <category domain="http://securityratty.com/tag/itil">itil</category>
      <category domain="http://securityratty.com/tag/itil lacks">itil lacks</category>
      <category domain="http://securityratty.com/tag/cobit rivals itil">cobit rivals itil</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=450">Around The Web For Friday</source>
    </item>
  </channel>
</rss>
