<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: northern]]></title>
    <link>http://securityratty.com/tag/northern</link>
    <description></description>
    <pubDate>Mon, 23 Jun 2008 08:28:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Modelling The Global Financial Meltdown]]></title>
      <link>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</link>
      <guid>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</guid>
      <description><![CDATA[Yesterday I received a call from Penny Grosman , Senior Editor, Wall Street &amp; Technology . Penny was interested in my opinion, Will risk management applications be the next killer app for CEP on Wall...]]></description>
      <content:encoded><![CDATA[<p>Yesterday I received a call from <a href="http://www.wallstreetandtech.com/penny-crosman/" target="_blank">Penny Grosman</a>, Senior Editor, <a href="http://www.wallstreetandtech.com/" target="_blank">Wall Street &amp; Technology</a>.   Penny was interested in my opinion, &#8220;Will risk management applications be the next killer app for CEP&#8221; on Wall Street.    I enjoyed talking with Penny.  She caught up with me leaving a tailor&#8217;s shop in Chiang Mai, so I hope she did not mind hearing my stories of buying unique Northern Thai cotton fabric and designing my own casual shirts in the economic turndown.</p>
<p>We read many stories on the net where folks claim that the current financial crisis could have been avoided with more or better use of technology.     This is expected, as software companies and IT professionals will often try to piggy-backtheir business development strategy on the &#8220;crisis of the day&#8221; to sell more goods and services.    Honestly, in this current situation, the main technology that we needed was simple, accurate financial models.</p>
<p>For example, in the chart above, the US economy was doing quite well with US federal funds rates low.   Housing prices in the US were skyrocketing and there was a concern about inflation.    There was an understandable concern the sustainability of that economy.</p>
<p style="text-align: center;"><img class="aligncenter" style="vertical-align: bottom;" src="http://www.thewrittenblog.com/main_1/images/97kcpv16xjh0uvsi8k7kdhaw.gif" alt="" width="277" height="415" /></p>
<p>So, in perhaps one the most ill-advised Federal Reserve actions of many decades, the folks at the helm of the Fed decided to raise their lending rates around 500 percent over a two year period.</p>
<p>As we all know, primarily because of the action by the Fed, the world faces perhaps the worst economic disaster in modern times, while the US Executive Branch and the Congress fight over how to spend $700 Billion taxpayer dollars to inject liquidity into the markets to try to head off a global financial disaster.</p>
<p>It is amazing to me that the US Federal Government, or their advisors, does not have simple financial models with cause-and-effect analysis such as:</p>
<ul>
<li>Homeowners with adjustable rate mortuages will not be able to make payments;and</li>
<li>Housing prices will fall dramatically; then</li>
<li>Homeowners will default on loans where the collateral is much less than the asset value, and</li>
<li>Banks will suffer great losses, and</li>
<li>Lending will come to a halt, then</li>
<li>Banks will collapse, then</li>
<li>Wall Street will exit the markets in panic</li>
<li>&#8230; and more trouble&#8230;.. !!</li>
</ul>
<p>There are and continue to be a lot of discussion and opinions about how risk management needs improvement. and I agree.   We will also read folks talk about how technology can be used to help solve this problem, including CEP/EP and related software (see also <!-- This wrapper class appears only on Page and Single Post pages. --><a title="Capital Market CEP Fantasy Land" rel="bookmark" href="../2008/06/23/capital-market-cep-fantasy-land/">Capital Market CEP Fantasy Land</a>). However, as much I would be pleased to see more CEP/EP applications and use cases, I do not believe that event processing technology is really very useful to solve the core problem of the current financial crisis.</p>
<p>The core problem is, seemingly, that our &#8220;financial experts&#8221; do not even have simple models that will illustrate what will or could happen when you raise the fed lending rates 500 percent in two years in an economy pregnant with adjustable rate mortgages.</p>
<p>To me, this does not appear to be rocket science.  The negligence by the US Federal Reserve and their advisors is astonishing.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 02:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/simple financial models">simple financial models</category>
      <category domain="http://securityratty.com/tag/financial models">financial models</category>
      <category domain="http://securityratty.com/tag/current financial crisis">current financial crisis</category>
      <category domain="http://securityratty.com/tag/crisis">crisis</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wall street">wall street</category>
      <category domain="http://securityratty.com/tag/main technology">main technology</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <source url="http://www.thecepblog.com/2008/10/02/modelling-the-global-financial-meltdown/">Modelling The Global Financial Meltdown</source>
    </item>
    <item>
      <title><![CDATA[Hand Grenades as Weapons of Mass Destruction]]></title>
      <link>http://securityratty.com/article/e03129712b52a9ce93ee85bc9633c091</link>
      <guid>http://securityratty.com/article/e03129712b52a9ce93ee85bc9633c091</guid>
      <description><![CDATA[I get that this is terrorism: A 24-year-old convert to Islam has been sentenced to 35 years in prison for plotting to set off hand grenades in a crowded shopping mall during the Christmas season
But I...]]></description>
      <content:encoded><![CDATA[<p>I get that <a href="http://news.yahoo.com/s/ap/20080930/ap_on_re_us/terror_sentence;_ylt=AttmTC5Ji0gidcvcR8JejpnZa7gF">this</a> is terrorism:</p>

<blockquote>A 24-year-old convert to Islam has been sentenced to 35 years in prison for plotting to set off hand grenades in a crowded shopping mall during the Christmas season.</blockquote>

<p>But I thought "weapons of mass destruction" was reserved for nuclear, chemical, and biological weapons.</p>

<blockquote>He was arrested in 2006 on charges of scheming to use weapons of mass destruction at the Cherryvale Mall in the northern Illinois city of Rockford.</blockquote>

<p>Like the <a href="http://www.schneier.com/blog/archives/2008/08/the_continuing_1.html">continuing cheapening of the word "terrorism</a>," we are now cheapening the term "weapons of mass destruction."</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=rEwFM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=rEwFM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RGl4M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RGl4M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:37:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mass destruction">mass destruction</category>
      <category domain="http://securityratty.com/tag/weapons">weapons</category>
      <category domain="http://securityratty.com/tag/biological weapons">biological weapons</category>
      <category domain="http://securityratty.com/tag/hand grenades">hand grenades</category>
      <category domain="http://securityratty.com/tag/mall">mall</category>
      <category domain="http://securityratty.com/tag/northern illinois city">northern illinois city</category>
      <category domain="http://securityratty.com/tag/cherryvale mall">cherryvale mall</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/christmas season">christmas season</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/hand_grenades_a.html">Hand Grenades as Weapons of Mass Destruction</source>
    </item>
    <item>
      <title><![CDATA[Starbucks Canada Frees Wi-Fi in Its Stores]]></title>
      <link>http://securityratty.com/article/9e0592f1bfaf004a664f648ddd3a1c24</link>
      <guid>http://securityratty.com/article/9e0592f1bfaf004a664f648ddd3a1c24</guid>
      <description><![CDATA[The Canadian branch of the coffee giant has secured a free Wi-Fi deal for customers: Just as Starbucks American stores are offering limited but free Wi-Fi in about 8,000 stores for its customers...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.newswire.ca/en/releases/archive/August2008/08/c2573.html"><strong>The Canadian branch of the coffee giant has secured a free Wi-Fi deal for customers:</strong></a> Just as Starbucks American stores are offering limited but free Wi-Fi in about 8,000 stores for its customers through a partnership with provider AT&T, Starbucks's northern brethren are opening its 650 company-operated locations that have Bell hotspots to free use by customers. Terms appear the same as in the states: 2 hours of free use per day with the regular use of a Starbucks Card.</p>

<p>And, as with the AT&T deal, Bell's Internet customers get unlimited access in Starbucks's stores. The deal starts up immediately, as Bell is the current operator. AT&T is transitioning to running Starbucks in the U.S., taking over by the end of 2008 from T-Mobile.<br />
</p>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/starbucks">starbucks</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/stores">stores</category>
      <category domain="http://securityratty.com/tag/starbucks card">starbucks card</category>
      <category domain="http://securityratty.com/tag/starbucks american stores">starbucks american stores</category>
      <category domain="http://securityratty.com/tag/free wi-fi deal">free wi-fi deal</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/internet customers">internet customers</category>
      <source url="http://wifinetnews.com/archives/008414.html">Starbucks Canada Frees Wi-Fi in Its Stores</source>
    </item>
    <item>
      <title><![CDATA[The Fallacy of Self-Fulfilling CEP Use Case Studies]]></title>
      <link>http://securityratty.com/article/47aaa0956d45ca036911731d192fc4e3</link>
      <guid>http://securityratty.com/article/47aaa0956d45ca036911731d192fc4e3</guid>
      <description><![CDATA[I am back at the glaring computer screenafter a day in Lamphun , Northern Thailand, hanging out will my friends who are preparing for a Bonsai tree competition.I spent the dayeating Thai and Chinese...]]></description>
      <content:encoded><![CDATA[<p>I am back at the glaring computer screen after a day in <a href="http://en.wikipedia.org/wiki/Lamphun" target="_blank">Lamphun</a>, Northern Thailand, hanging out will my friends who are preparing for a Bonsai tree competition.  I spent the day eating Thai and Chinese food and relaxing in a lounge chair under imported blue palm trees with the sound of exotic birds making background music to keep me entertained.</p>
<p>Back to CEP and EPTS, there are folks who appear to believe they may define &#8220;CEP&#8221; by the current use cases from self-described CEP vendors. Frankly speaking, I am puzzled by the bottom-up approach.</p>
<p>The bottom-up approach is a bit like saying &#8220;We have a lot of prototype rockets being built, so let&#8217;s define the future of space travel based on the prototypes!&#8221;</p>
<p>It really makes little sense, at least to me, to attempt to define CEP based on what the current generation products (self-described CEP products) are capable of doing.   </p>
<p>From my persective, it would be more beneficial to customers to define the types of complex events (and situations) businesses need to detect in real-time and match the technologies and solution architectures to detect those events, in real-time, with high confidence.</p>
<p>A lot of this &#8220;top down thinking&#8221; has been already done.</p>
<p>IT businesses need to detect operational threats and problems, and be able to pinpoint, with very high accuracy, where the problem is in a complex network, for example.  This problem remains mostly unsolved with a very low signal-to-noise ratio.</p>
<p>Also, most businesses would like to detect fraud and other criminal activity on their network before the activities adversely impacts their business.   This problem remains unsolved for most companies.</p>
<p>Scientific researchers seek models of weather, epidemiology, and so much more; and they need event processing solutions to obtain situational knowledge into current events and predict future ones.  We know how difficult predicting the weather can be!</p>
<p>Folks on the ground need to model urban traffic as events and design better event-driven traffic models and solutions.</p>
<p>The list of important event processing challenges we face go on and on.  </p>
<p>While I see some merit in the bottom-up approach, it is better for users to define what are practical &#8220;complex event&#8221; related problems and then look for the solutions, vs. define the solution and then look for the problem.</p>
<p>From a strategic perspective,  self-fulfilling CEP use case studies are interesting, but they hould not limit the vision, definition, and future of processing complex events; and be careful of use case <a href="http://en.wikipedia.org/wiki/List_of_fallacies" target="_blank">fallacies</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 11:30:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep products">cep products</category>
      <category domain="http://securityratty.com/tag/believethey maydefine cep">believethey maydefine cep</category>
      <category domain="http://securityratty.com/tag/detect">detect</category>
      <category domain="http://securityratty.com/tag/liketo detect fraud">liketo detect fraud</category>
      <category domain="http://securityratty.com/tag/cep vendors">cep vendors</category>
      <category domain="http://securityratty.com/tag/current generation products">current generation products</category>
      <category domain="http://securityratty.com/tag/complex events">complex events</category>
      <category domain="http://securityratty.com/tag/define">define</category>
      <source url="http://www.thecepblog.com/2008/08/06/the-fallacy-of-self-fulfilling-cep-use-case-studies/">The Fallacy of Self-Fulfilling CEP Use Case Studies</source>
    </item>
    <item>
      <title><![CDATA[Card Wars: The Phantom Menace]]></title>
      <link>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</link>
      <guid>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</guid>
      <description><![CDATA[Just like George Lucas cant help but return to his old projects , I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of phantomwithdrawals.com ,...]]></description>
      <content:encoded><![CDATA[<p>Just like George Lucas can&#8217;t help but <a href="http://www.cinematical.com/2005/05/25/lucas-idea-for-new-star-wars-prequel/">return to his old projects</a>, I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of <a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a>, freshly re-vamped, updated and turned into a Wiki editable by the general public.</p>
<p>In fact, it&#8217;s not just great artists like Mr. Lucas and I starting up old projects, our honourable colleagues wearing the black hats have got the same idea. We have new victims reporting in, <a href="http://www.newsvine.com/_news/2008/07/01/1629600-citibank-atm-breach-reveals-pin-security-problems">rumours</a>&nbsp;<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-issues.html">abound</a> of an auth system compromise at Citi, the Ombudsman is backlogged with months of disputed withdrawal cases, and some like <a href="http://www.guardian.co.uk/technology/2008/jan/03/hitechcrime.news">Alain Job</a> are even going to court.</p>
<p>One original contributor to the phantom case histories has just been hit by a second phantom withdrawal five years on and is chalking up another case in the files. While her new phantom is a bread-and-butter skim incident (a magstripe clone used in the far east), amongst this mass, true phantoms &#8212; the real mystery cases &#8212; are on the rise too. Two new victims with whom I have been corresponding very kindly offered to fund the hosting for the revamped site.</p>
<p>Let&#8217;s consider one of these mysteries. The McGaughey case has been reported in the media in Northern Ireland: dozens of withdrawals taking place over four weeks, totaling almost five thousand pounds, all within a ten mile radius of the McGaughey&#8217;s home. Summarised that way it looks like a classic first party fraud (couple short on cash withdraw money, then deny it later). But no-one in the family is short on cash, the McGaugheys look after their card details carefully, and have solid <a href="http://www.bridgewebs.com/derryvolgie/">alibis</a> at the time of many of the withdrawals, and the interlocking pattern of real and disputed withdrawals is such that any third party would have a hard time taking and returning the card (whether covertly or in collusion with the McGaugheys). No-one appears to have either the means or the motive.</p>
<p>Unusually the bank has been very cooperative, providing logs from their authorisation system (<A href="http://www.aciworldwide.com/products/detail.aspx?product_id=236">BASE24</a>), including all of the cryptograms, input data and transaction parameters covering the affected transactions. Everything turns on the Application Transaction Counter (ATC), an on-card counter which increments with every transaction initiated. If an EMV chip can be fully cloned (secret keys and all), then it will have to submit an ATC value when transacting, and if used in parallel with the real card, it won&#8217;t be long before the same number pops up twice in the auth system, or large gaps in the sequence appear. The McGaughey&#8217;s ATC sequence appears to interlock perfectly: clearly the original card was used?</p>
<p>Of course logs can be misinterpreted (<a href="http://news.bbc.co.uk/1/hi/programmes/newsnight/7265437.stm">Badger</a>) or even faked, auth systems may not work as expected, and customers may lie and cheat following all sorts of agendas; just around the corner the missing piece of the jigsaw may lie, which reveals the truth behind the case. And there is the totally separate matter of who should suffer the loss in the interim, whilst the truth remains unclear. <a href="http://www.lightbluetouchpaper.org/2008/04/09/new-banking-code-shifts-more-liability-to-customers/">Liability for disputed withdrawals</a> is the most hotly contested issue of all.</p>
<p><a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a> can&#8217;t do much more for the McGaugheys, but it can bear witness. Documenting the incidence of phantoms and the experiences of customers disputing them adds much needed transparency to the process, and helps researchers and experts seek out the really interesting cases.</p>
<p>Maybe we can lift the lid and discover the truth behind the &#8220;phantom menace&#8221; &#8212; everyone is united in that goal at least &#8212; but let&#8217;s also hope that Episode 2: <a href="http://www.epaynews.com/index.cgi?survey=&#038;ref=browse&#038;f=view&#038;id=11497625028614136145&#038;block=">Attack of the Clones</a> has not yet started shooting!</p>
<p>Mike.</p>
]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 11:06:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/phantom">phantom</category>
      <category domain="http://securityratty.com/tag/real">real</category>
      <category domain="http://securityratty.com/tag/real card">real card</category>
      <category domain="http://securityratty.com/tag/card details">card details</category>
      <category domain="http://securityratty.com/tag/phantom menace">phantom menace</category>
      <category domain="http://securityratty.com/tag/phantom withdrawal">phantom withdrawal</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/application transaction counter">application transaction counter</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/05/card-wars-the-phantom-menace/">Card Wars: The Phantom Menace</source>
    </item>
    <item>
      <title><![CDATA[Delta Opts for Broadband Fleet Deployment]]></title>
      <link>http://securityratty.com/article/db5e01012dbeef6ef5baab0f213a6214</link>
      <guid>http://securityratty.com/article/db5e01012dbeef6ef5baab0f213a6214</guid>
      <description><![CDATA[Delta Airlines says they'll put Internet access on every plane: Delta is the first major U.S. airline to take the full-on plunge into fleet in-flight broadband service. The company said that it will...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://news.delta.com/article_display.cfm?article_id=11127"><strong>Delta Airlines says they'll put Internet access on every plane:</strong></a> Delta is the first major U.S. airline to take the full-on plunge into fleet in-flight broadband service. The company said that it will equip 330 planes by 2009, starting with 130 MD craft this year, with Aircell's service. The Gogo Internet offering costs $10 for flights up to 3 hours and $13 for longer flights. </p>

<p>Delta's competitors with broadband interest, like Alaska, Southwest, and American, each have a different plan of attack. Alaska will test service soon with Row 44, which uses Ku-band satellite access, albeit with higher speeds and far lower costs, the company says, than Boeing's doomed Connexion service. Row 44 touts their over-water ability, critical for Alaska, which flies plenty of routes to the great northern state and to Mexico. A test is what's scheduled; not deployment. </p>

<p>Southwest <a href="http://www.row44.com/news?u=southwest-chooses-row-44"><strong>did some deal with Row 44</strong></a>, but nothing further has been forthcoming. Summer's almost over, and we haven't heard more about the "four aircraft" mentioned in the linked press release.</p>

<p>American has the most fully formed plan, but they, too, are testing Aircell's service, and will shortly launch service on 15 trans-continental 767-200s, flying largely routes among SFO, LAX, JFK, and Miami. The company said in the past that they would decide on fleet deployment after the pilot stage.</p>

<p>I shouldn't forget Virgin America, which planned Internet access as part of a set of already-deployed in-flight networked services, but they have under a couple dozen planes at the moment, so they're not a real competitor except on a few routes. Their launch date hasn't been set.</p>

<p>Delta's announcement makes it clear that air-Fi is coming soon, and will likely change how business travelers plan trips. If you can get productive work done during a flight, that changes the financial equation of the trip's cost, and your time out of the office. Pair in-flight Wi-Fi with a cell data card, and you may curse the fact that you're always connected. </p>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 07:27:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shortly launch service">shortly launch service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/delta">delta</category>
      <category domain="http://securityratty.com/tag/pair in-flight wi-fi">pair in-flight wi-fi</category>
      <category domain="http://securityratty.com/tag/in-flight">in-flight</category>
      <category domain="http://securityratty.com/tag/test service">test service</category>
      <category domain="http://securityratty.com/tag/fleet deployment">fleet deployment</category>
      <category domain="http://securityratty.com/tag/deployment">deployment</category>
      <category domain="http://securityratty.com/tag/flight">flight</category>
      <source url="http://wifinetnews.com/archives/008410.html">Delta Opts for Broadband Fleet Deployment</source>
    </item>
    <item>
      <title><![CDATA[The Magical ATM Card and SMS Message in Thailand]]></title>
      <link>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</link>
      <guid>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</guid>
      <description><![CDATA[It was not too long ago that I penned Keyloggers: Why Banks Need Two-Factor Authentication . In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor...]]></description>
      <content:encoded><![CDATA[<p>It was not too long ago that I penned <a href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/">Keyloggers: Why Banks Need Two-Factor Authentication</a>. In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor authentication (2FA) with one-time password (OTP) to authenticate transactions.</p>
<p>One of my favorite banks in Thailand is <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">K-Bank</a>. With K-Bank I can simply walk up to an ATM machine and pay a mobile phone bill, purchase mutual funds, buy insurance, or transact an ever-growing list of services payable at the modern and sleek K-Bank ATM.</p>
<p>For example, tomorrow I fly to Chiang Mai in Northern Thailand and found K-Bank&#8217;s service amazingly better than in the US. For example, I booked my flight as usual (over the phone, but could have used the Internet) and told the reservation agent I was going to pay by ATM. He simply gave me a PayCode and told me I had three hours to go to the ATM and enter the PayCode to perfect my reservation.  I also got the PayCode via SMS.  This gave me the time I needed to make sure I had <a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/pictures/" target="_blank">booked the perfect boutique hotel</a> in Chiang Mai, the <strong><a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/review/" target="_blank">Fern Paradise</a>.</strong></p>
<p>Then, I went out into the beautiful Thai weather and completely my airplane reservation at the ATM machine; which also printed out a receipt with my flight details and reservation number.</p>
<p>It sometimes amazes me how much further advanced some services are in Thailand compared to the US. To me, it feels more secure not to use an on-line payment center or give out my credit card details over the phone. I can simply book a ticket, take a PayCode, and complete the transaction at a nice modern, shiny, K-Bank ATM machine.</p>
<p>Who knows, maybe soon I can select the perfect window seat at the ATM and the receipt will act as my boarding pass!</p>
]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 09:30:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/atm">atm</category>
      <category domain="http://securityratty.com/tag/k-bank atm machine">k-bank atm machine</category>
      <category domain="http://securityratty.com/tag/sleek k-bank atm">sleek k-bank atm</category>
      <category domain="http://securityratty.com/tag/k-bank">k-bank</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/atm machine">atm machine</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/perfect window seat">perfect window seat</category>
      <category domain="http://securityratty.com/tag/perfect">perfect</category>
      <source url="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/">The Magical ATM Card and SMS Message in Thailand</source>
    </item>
    <item>
      <title><![CDATA[When your hotel does funerals]]></title>
      <link>http://securityratty.com/article/7a31420cf206dd2cfc4b681fe0a369fc</link>
      <guid>http://securityratty.com/article/7a31420cf206dd2cfc4b681fe0a369fc</guid>
      <description><![CDATA[So another week, another travel nightmare. This week I am in the DC area for a few days, than flying over to Ohio and then back home. Staying in the DC/Northern Va area I made hotel reservations...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So another week, another travel nightmare.&nbsp; This week I am in the DC area for a few days, than flying over to Ohio and then back home.&nbsp; Staying in the DC/Northern Va area I made hotel reservations through our corporate Expedia account (which is now called Egencia BTW). Though it is fine for airline reservations, I regret it every time I make a hotel reservation on Expedia.&nbsp; This time I reserved a room at the <a href="http://www.google.com/aclk?sa=L&amp;ai=B953Ve6WGSLmnCIHceNvFuMMG-O_QGNDqiswB_LTwvwfgpxIIABABGAEoAjgBUOK2vZn8_____wFgyaaZjeykgBDIAQHIAtiqsgHZA9i4qLGuQL7D&amp;sig=AGiWqtw77p9SVu7mO_lOJ0ulJrBj4rf-rg&amp;q=http://www.virginiansuites.com/%3Fsrc%3Dppc_google_brand">Virginian Suites</a>. I had never heard of it, but it was only $158, which is really cheap for around here.&nbsp; It had 3 stars and sounded good, so I booked it.</p>

<p>I arrived tonight and as I pulled up I have to say that I thought I made a good choice. It is a converted apartment building and every room is actually a studio type of apartment. It has free parking and is located near where I have meetings in Arlington. I gave my name at the desk and they had my reservation, looking good!&nbsp; I was given keys to room 707 and headed on up.&nbsp; I got to room 707 and tried to open the door.&nbsp; No luck, the keys didn???t work. After a moment or two of trying to make the keys work, the door opens and the guy who is staying in the room wants to know what I am doing trying to get in. Well I was reminded of an old Robert Schimmel comedy routine and ran away from there as fast as I could.&nbsp; </p>

<p>I went back down to the desk and told them what happened.&nbsp; The woman at the desk apologized, she meant to write room 700, not 707.&nbsp; While I am waiting for her to correct this and issue new keys, I am looking at the schedule of events at the hotel today.&nbsp; That is when I notice that one of the main events of the day was a someone???s funeral!&nbsp; Thats right, it seems the hotel is used for funerals in the area.&nbsp; That just freaked me out.&nbsp; Now I am getting Six Feet Under deja vu here.&nbsp; I don???t know, call me squeamish, but I just don???t feel good about staying at a hotel that doubles as a funeral home. To top it off, the Internet access here sucks. It is so slow that I am watching the paint dry.&nbsp; Maybe I should go down and catch a funeral or two while I wait for a page to load.&nbsp; In any event, I think this will be the last time I stay here.&nbsp; I just can???t wait for what the rest of this week brings!</p></div>
]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:41:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/hotel reservations">hotel reservations</category>
      <category domain="http://securityratty.com/tag/hotel reservation">hotel reservation</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/funeral home">funeral home</category>
      <category domain="http://securityratty.com/tag/week brings">week brings</category>
      <category domain="http://securityratty.com/tag/funeral">funeral</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/when-your-hotel.html">When your hotel does funerals</source>
    </item>
    <item>
      <title><![CDATA[When your hotel does funerals]]></title>
      <link>http://securityratty.com/article/cb3246b5c2e5a9f8d7ce414decd6efd3</link>
      <guid>http://securityratty.com/article/cb3246b5c2e5a9f8d7ce414decd6efd3</guid>
      <description><![CDATA[So another week, another travel nightmare. This week I am in the DC area for a few days, than flying over to Ohio and then back home. Staying in the DC/Northern Va area I made hotel reservations...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So another week, another travel nightmare.&nbsp; This week I am in the DC area for a few days, than flying over to Ohio and then back home.&nbsp; Staying in the DC/Northern Va area I made hotel reservations through our corporate Expedia account (which is now called Egencia BTW). Though it is fine for airline reservations, I regret it every time I make a hotel reservation on Expedia.&nbsp; This time I reserved a room at the <a href="http://www.google.com/aclk?sa=L&amp;ai=B953Ve6WGSLmnCIHceNvFuMMG-O_QGNDqiswB_LTwvwfgpxIIABABGAEoAjgBUOK2vZn8_____wFgyaaZjeykgBDIAQHIAtiqsgHZA9i4qLGuQL7D&amp;sig=AGiWqtw77p9SVu7mO_lOJ0ulJrBj4rf-rg&amp;q=http://www.virginiansuites.com/%3Fsrc%3Dppc_google_brand">Virginian Suites</a>. I had never heard of it, but it was only $158, which is really cheap for around here.&nbsp; It had 3 stars and sounded good, so I booked it.</p>

<p>I arrived tonight and as I pulled up I have to say that I thought I made a good choice. It is a converted apartment building and every room is actually a studio type of apartment. It has free parking and is located near where I have meetings in Arlington. I gave my name at the desk and they had my reservation, looking good!&nbsp; I was given keys to room 707 and headed on up.&nbsp; I got to room 707 and tried to open the door.&nbsp; No luck, the keys didn’t work. After a moment or two of trying to make the keys work, the door opens and the guy who is staying in the room wants to know what I am doing trying to get in. Well I was reminded of an old Robert Schimmel comedy routine and ran away from there as fast as I could.&nbsp; </p>

<p>I went back down to the desk and told them what happened.&nbsp; The woman at the desk apologized, she meant to write room 700, not 707.&nbsp; While I am waiting for her to correct this and issue new keys, I am looking at the schedule of events at the hotel today.&nbsp; That is when I notice that one of the main events of the day was a someone’s funeral!&nbsp; Thats right, it seems the hotel is used for funerals in the area.&nbsp; That just freaked me out.&nbsp; Now I am getting Six Feet Under deja vu here.&nbsp; I don’t know, call me squeamish, but I just don’t feel good about staying at a hotel that doubles as a funeral home. To top it off, the Internet access here sucks. It is so slow that I am watching the paint dry.&nbsp; Maybe I should go down and catch a funeral or two while I wait for a page to load.&nbsp; In any event, I think this will be the last time I stay here.&nbsp; I just can’t wait for what the rest of this week brings!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=bAF3vT"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=bAF3vT" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TtFnXJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TtFnXJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FF9XkJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FF9XkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CgaObJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CgaObJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=kuNdRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=kuNdRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=KCgbwj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=KCgbwj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BQjQzj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BQjQzj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/343165828" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 18:45:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/hotel reservations">hotel reservations</category>
      <category domain="http://securityratty.com/tag/hotel reservation">hotel reservation</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/funeral home">funeral home</category>
      <category domain="http://securityratty.com/tag/funeral">funeral</category>
      <category domain="http://securityratty.com/tag/week brings">week brings</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/343165828/when-your-hotel.html">When your hotel does funerals</source>
    </item>
    <item>
      <title><![CDATA[The Arizona Office of the Auditor General finds plenty of holes]]></title>
      <link>http://securityratty.com/article/7c68cfbfdcec6acecbe25fdbae0ec186</link>
      <guid>http://securityratty.com/article/7c68cfbfdcec6acecbe25fdbae0ec186</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/19/08

Organization
The Arizona Board of Regents

Contractor/Consultant/Branch
Arizona State University
University of Arizona
Northern Arizona...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/abor.jpg" width="82" align="right" height="102"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/19/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.abor.asu.edu/">The Arizona Board of Regents</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.asu.edu/">Arizona State University</a> <br><a href="http://www.arizona.edu/">University of Arizona</a> <br><a href="http://home.nau.edu/">Northern Arizona University</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Students, faculty and staff<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 10,000"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, Social Security numbers, student identification numbers, addresses, phone numbers, e-mail addresses and user accounts<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The Office of the Auditor General has conducted a performance audit of information technology security at Arizona State University (ASU), the University of Arizona (UA), and Northern Arizona University (NAU) pursuant to Arizona Revised Statutes (A.R.S.) §41-2958."&nbsp; "ASU’s, UA’s, and NAU's Web-based applications are vulnerable. Auditors were able to gain unauthorized access to sensitive information, such as social security numbers, and could have modified or deleted important university information."<br><br><span style="font-weight: bold;">Reference URL:</span><br>Arizona Office of the Auditor General's report titled "<a href="http://www.auditorgen.state.az.us/Reports/Universities/UniversitySystemWide/Performance/08-04/08-04.pdf">Arizona’s Universities—Information Technology Security</a>" <br><a href="http://www.azstarnet.com/sn/hourlyupdate/244720.php">The Arizona Daily Star </a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Arizona Office of the Auditor General<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The Office of the Auditor General has conducted a performance audit of information technology security at Arizona State University (ASU), the University of Arizona (UA), and Northern Arizona University (NAU) pursuant to Arizona Revised Statutes (A.R.S.)<br>§41-2958.<br><br>Information technology (IT) security practices are important for Arizona's universities to protect large amounts of sensitive and confidential information that are stored on their computer systems, including information for more than 122,000 students and nearly 25,000 faculty and staff.<br><br>Universities in general are attractive targets for computer hackers because universities traditionally have a strong culture of academic freedom that values open access to information and a free exchange of ideas.<br><br>University IT security problems are occurring more often through weaknesses in computer programs called Web-based applications.<br><br>The Arizona universities combined use at least 205 significant Web-based applications for educational and administrative purposes, such as curriculum and course management, documenting personal information for admissions and financial aid, and processing financial, payroll, and other transactions, such as purchasing parking permits.<br><br>ASU’s, UA’s, and NAU's Web-based applications are vulnerable.<br><br>Auditors were able to gain unauthorized access to sensitive information, such as social security numbers, and could have modified or deleted important university information.<br><br>Auditors were able to gain this access by exploiting some critical and commonly found weaknesses that exist in many of the universities' Web-based applications.<br><br>Security weaknesses in one Web-based application allowed auditors to access a database and obtain more than 10,000 records with names and social security numbers.<br><br>Auditors also obtained other records that contained student identification numbers, addresses, phone numbers, and e-mail addresses.<br><br>Auditors also had the ability to modify and delete this information.<br><br>In two other applications, auditors were able to exploit a security weakness that would have allowed them to take over a large number of user accounts, including accounts with high-level access.<br><br>In many applications, auditors discovered a security flaw that would allow an attacker to take over user accounts and install malicious software.<br><br>Auditors did not attempt to identify every flaw that may exist because the testing was designed to determine what the impact could be if certain identified vulnerabilities were successfully exploited.<br><br>To better protect the information processed through their Web-based applications,<br>ASU, UA, and NAU need to:<br><br></font><ul><li><font size="2">Conduct regular security assessments of Web-based applications. The universities first need to determine how many Web-based applications they have and then make provisions to regularly update their lists of applications.&nbsp; They then need to develop and implement procedures for regularly conducting security reviews of their critical Web-based applications.</font></li></ul><font size="2"><span style="font-style: italic;">[Evan] Even though it seems like it’s the same story in company after company, I am still amazed by how many organizations don't know what or how many applications that have (not to mention servers, clients, routers, switches, wireless access points, etc.)!&nbsp; Its pretty hard to secure something if you don't know it exists, and just because you don't know it exists does not mean you are not responsible for it.</span><br><br></font><ul><li><font size="2">Develop a university-wide policy and associated procedures for updating Web servers, which are computers that host Web-based applications. Software vulnerabilities are constantly being discovered and publicized, and the universities need to develop or enhance: (1) procedures for identifying vulnerabilities relevant to their Web servers, (2) a timeline for reacting to notifications of newly discovered Web server vulnerabilities, and (3) a process for determining whether to apply a software update, establish another control to address the Web server vulnerability, or accept the risk of not updating the software.</font></li><li>Ensure that security is built into the process for developing Web-based applications. According to ASU, UA, and NAU officials, none of them have university-wide security standards for developing applications. According to an IT best practice, building security into the development process is more cost-effective and secure than applying it afterwards.</li><li>Provide training to application developers so that they are aware of common Web-based application vulnerabilities and methodologies that can be used to avoid them. None of the universities have a training program that is mandatory for all users and geared toward an individual's role within the university.<br></li></ul><font size="2"><br>All three Arizona universities have taken some key steps toward developing an overall<br>IT security approach; however, additional work is needed.<br><br><span style="font-weight: bold;">Creating information security staffs</span>--Over the past few years, ASU, UA, and NAU have established and filled information security officer (ISO) positions and made these ISOs responsible for information security efforts university-wide.&nbsp; Until the ISOs were hired, the universities have not had any staff whose sole responsibility included directing and coordinating all aspects of information security across the university.<br><span style="font-style: italic;">[Evan] Typically, this position is more effective if it reports directly to an executive such as CEO, President, etc.&nbsp; Information security is not an IT problem, and often times there is a conflict of interest if an ISO reports up through the IT organization.</span><br><br><span style="font-weight: bold;">Developing information security programs</span>--The universities are at varying stages in developing formal programs to guide their information security efforts, but none have yet developed all the standards or procedures needed to support a complete information security program. The universities are in the beginning stages of implementing their information security programs, in part because the ISO positions are relatively new.<br><br style="font-style: italic;"><span style="font-style: italic;">[Evan] The report goes on to address specific findings and recommendations for all three of the schools.&nbsp; In my opinion, the report is very well-written and definitely worth your reading time!</span><br><br><span style="font-weight: bold;">Commentary:</span><br>I didn't provide much commentary on the Auditor General's report because it really speaks for itself.&nbsp; It was a good read (for a security guy anyway).&nbsp; Kudos to the Arizona legislature for funding the audit, Kudos to the Auditor General on the findings, the report, and the excellent recommendations, and Kudos to the schools for their agreements and plans for improvement.&nbsp; I feel a little giddy and I'm not really sure why.<br><br>Is anyone planning to notify the people whose information was found to be vulnerable to attack and exploit?&nbsp; I would be surprised if the auditors were the first to find these chinks in the armor.<br><br>I highly recommend reading the <a href="http://www.auditorgen.state.az.us/Reports/Universities/UniversitySystemWide/Performance/08-04/08-04.pdf">report</a>. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/23/abor.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 08:28:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security officer">information security officer</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security staffs">information security staffs</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/university information">university information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/sensitive">sensitive</category>
      <source url="http://breachblog.com/2008/06/23/abor.aspx">The Arizona Office of the Auditor General finds plenty of holes</source>
    </item>
  </channel>
</rss>
