<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: orlando]]></title>
    <link>http://securityratty.com/tag/orlando</link>
    <description></description>
    <pubDate>Tue, 22 Apr 2008 20:47:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Speaking of Security Podcast #129]]></title>
      <link>http://securityratty.com/article/3d6451afa0da1cc27194a7e6a986f6b7</link>
      <guid>http://securityratty.com/article/3d6451afa0da1cc27194a7e6a986f6b7</guid>
      <description><![CDATA[Click to Download/Listen (07:52

This week's Speaking of Security podcast features an on-the-scene report from the Gartner Identity and Access Management Summit, one of the key shows on the security...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1389">Click to Download/Listen</a> (07:52)<br><br />This week's Speaking of Security podcast features an on-the-scene report from the Gartner Identity and Access Management Summit, one of the key shows on the security event calendar.  The Summit was held last week in Orlando, Florida. <br />]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/access management summit">access management summit</category>
      <category domain="http://securityratty.com/tag/summit">summit</category>
      <category domain="http://securityratty.com/tag/security podcast features">security podcast features</category>
      <category domain="http://securityratty.com/tag/security event calendar">security event calendar</category>
      <category domain="http://securityratty.com/tag/gartner identity">gartner identity</category>
      <category domain="http://securityratty.com/tag/on-the-scene report">on-the-scene report</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/orlando">orlando</category>
      <category domain="http://securityratty.com/tag/held">held</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1389">Speaking of Security Podcast #129</source>
    </item>
    <item>
      <title><![CDATA[North America Recap]]></title>
      <link>http://securityratty.com/article/4c2bab97ffef28b37a1841c6d4902b75</link>
      <guid>http://securityratty.com/article/4c2bab97ffef28b37a1841c6d4902b75</guid>
      <description><![CDATA[I was one of the 650 attendees at the recent annual North American PCI Community Meeting . Held at the Omni Champions Gate resort in Orlando, it was great to speak with many of the merchants, banks...]]></description>
      <content:encoded><![CDATA[I was one of the 650 attendees at the recent annual <a href="https://www.pcisecuritystandards.org/pdfs/09-25-08.pdf" target="_blank">North American PCI Community Meeting</a>.  Held at the Omni Champions Gate resort in Orlando, it was great to speak with many of the merchants, banks and service providers in attendance about the challenges they are facing.]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/omni champions">omni champions</category>
      <category domain="http://securityratty.com/tag/orlando">orlando</category>
      <category domain="http://securityratty.com/tag/attendance">attendance</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/held">held</category>
      <category domain="http://securityratty.com/tag/attendees">attendees</category>
      <category domain="http://securityratty.com/tag/resort">resort</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1363">North America Recap</source>
    </item>
    <item>
      <title><![CDATA["Catch Me, Yes YOU Can": Realized Threats at the Corner Store]]></title>
      <link>http://securityratty.com/article/cfe4e6883d78190bc8fc3d36305bf27f</link>
      <guid>http://securityratty.com/article/cfe4e6883d78190bc8fc3d36305bf27f</guid>
      <description><![CDATA[just returned from the Payment Card Industry's 2008 Members Council Meeting in Orlando, Florida. We had a blast despite the mood being somewhat dampened as a result of the uncertainty of the global...]]></description>
      <content:encoded><![CDATA[ just returned from the <a href="https://www.pcisecuritystandards.org/pdfs/pr_080930_PCIDSSv1-2.pdf" target="_blank">Payment Card Industry's</a> 2008 Members Council Meeting in Orlando, Florida.  We had a blast despite the mood being somewhat dampened as a result of the uncertainty of the global financial markets (heartfelt thanks to those wise souls who've been living outside of their means and taking undue personal and commercial financial risk...).  Anyhew, I met so many interesting people from both merchants and from the card brands like Visa, MasterCard, American Express, Discover & JCB International Co., Ltd.]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payment card industry">payment card industry</category>
      <category domain="http://securityratty.com/tag/commercial financial risk">commercial financial risk</category>
      <category domain="http://securityratty.com/tag/global financial markets">global financial markets</category>
      <category domain="http://securityratty.com/tag/wise souls">wise souls</category>
      <category domain="http://securityratty.com/tag/card brands">card brands</category>
      <category domain="http://securityratty.com/tag/american express">american express</category>
      <category domain="http://securityratty.com/tag/jcb international">jcb international</category>
      <category domain="http://securityratty.com/tag/undue personal">undue personal</category>
      <category domain="http://securityratty.com/tag/orlando">orlando</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1364">"Catch Me, Yes YOU Can": Realized Threats at the Corner Store</source>
    </item>
    <item>
      <title><![CDATA[Florida's Agency for Health Care Administration reports a breach]]></title>
      <link>http://securityratty.com/article/9fbf858547c6670a14d3e4ee147593fc</link>
      <guid>http://securityratty.com/article/9fbf858547c6670a14d3e4ee147593fc</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/7/08

Organization
State of Florida

Contractor/Consultant/Branch
Agency for Health Care Administration

Victims
registered organ donors

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/ahca.jpg" width="111" align="right" height="42"><font size="2"><strong>Date Reported: </strong><br>7/7/08<br><br><strong>Organization: </strong><br><a href="http://www.myflorida.com/">State of Florida</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.fdhc.state.fl.us/">Agency for Health Care Administration</a> <br><br><span style="font-weight: bold;">Victims:</span><br>registered organ donors<br><br><span style="font-weight: bold;">Number Affected:</span><br>"about 55,000"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses, birth dates, driver license numbers and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"TALLAHASSEE, Fla. - State health officials say a security breach in the Organ and Tissue Donor Registry may have exposed thousands of donors' personal information, including their social security numbers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.ahca.myflorida.com/Organ/faq.htm">AHCA FAQs</a> <br><a href="http://www.heraldtribune.com/article/20080707/APN/807071178">Sarasota Herald-Tribune</a> <br><a href="http://www.wctv.tv/home/headlines/24080734.html">WCTV CBS News</a> <br><a href="http://www.baltimoresun.com/topic/orl-b3report09_508jul09,0,4124063.story">Orlando Sentinel</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Sarasota Herald-Tribune<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>TALLAHASSEE, Fla. - State health officials say a security breach in the Organ and Tissue Donor Registry may have exposed thousands of donors' personal information, including their social security numbers.<br><br>The Agency for Health Care Administrations said Monday it has corrected the flaw, which may have allowed unauthorized users to view the personal information of roughly 55,000 donors.<br><br>"We stopped all access to the database, identified the flaws and corrected them."<br><span style="font-style: italic;">[Evan]&nbsp; This breach makes me wonder a couple of things.&nbsp; Is information security testing part of the development lifecycle and change control?&nbsp; I also wonder if AHCA uses a formal change control process with segregated development, test, and production environments.</span><br><br>The database includes donors' names, addresses, birth dates and driver license numbers.<br><br>The agency is sending letters to inform individuals of the flaw.<br><span style="font-style: italic;">[Evan] What kind of flaw, do you suppose?&nbsp; A Code flaw, an administrative/process flaw, a configuration flaw?</span><br><br>AHCA Secretary Holly Benson said they have not received any indication that the information was accessed inappropriately.<br><span style="font-style: italic;">[Evan] No logging?&nbsp; Logging of the systems, processes, and people accessing confidential information is a must.&nbsp; Extensive logging would be able to determine if the information "was accessed inappropriately" (assuming the logs weren't subject to unauthorized modification).</span><br><br>The breach happened on June 20 and was fixed a day later, but officials say they thought it best to make the public aware.<br><span style="font-style: italic;">[Evan] What does the "breach happened on June 20" mean?&nbsp; It could mean that a flaw was detected on June 20, but could have been in existence for longer.&nbsp; It could mean that a vulnerability was actually exploited on June 20.&nbsp; I guess it really depends on your definition.&nbsp; I assume that the author means that something changed (code push, updated information, configuration, etc.) on June 20.</span><br><br>"If you have not received a letter our logs note that your information was not affected by this security flaw."<br><br>A couple of FAQs:<br>Q: If I have additional questions regarding this issue, what should I do?<br>A: You can call 866 757 0677.&nbsp; This number is open Monday through Friday from 8AM to 7PM Eastern.<br><br>Q: If I am a registered donor and I receive a letter, does this mean that I am a victim of identity theft?<br>A: No. It is unlikely that someone has accessed your information or used it inappropriately. It does not mean that you are a victim of identity theft or that the information may be used to commit fraud. The Agency for Health Care Administration wanted to let you know about the incident so you are aware and may take steps as you see fit.<br><span style="font-style: italic;">[Evan] Again, poor logging and other detective controls lead to statements such as "It is unlikely that someone accessed...".</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Ugh!&nbsp; I am left with too many questions about this breach.&nbsp; On the surface, this breach doesn't look all that significant unless of course, you are a victim.&nbsp; When I read into it more, I realize that I have some serious concerns surrounding process, control, and detection mechanisms used at AHCA.&nbsp; With less detail, it is easier to imagine. <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">State of Florida:</span><br>January, 2008 - <a href="http://breachblog.com/2008/01/04/dcf.aspx">Five stolen Florida Department of Children and Families laptops</a> <br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/09/ahca.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 07:15:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/configuration flaw">configuration flaw</category>
      <category domain="http://securityratty.com/tag/health care administration">health care administration</category>
      <category domain="http://securityratty.com/tag/database includes donors">database includes donors</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <source url="http://breachblog.com/2008/07/09/ahca.aspx">Florida's Agency for Health Care Administration reports a breach</source>
    </item>
    <item>
      <title><![CDATA[Security Thoughts from TechEd 2008]]></title>
      <link>http://securityratty.com/article/a3d4e71cb168d507868ea3b8a865378a</link>
      <guid>http://securityratty.com/article/a3d4e71cb168d507868ea3b8a865378a</guid>
      <description><![CDATA[Hi, this week is a post from Michael Howard and Laura Machado de Wright, who both attended and presented at TechEd 2008 in Orlando the week of June 2 nd
First up is Laura
I have been a Security...]]></description>
      <content:encoded><![CDATA[<P>Hi, this week is a post from Michael Howard and Laura Machado de Wright, who both attended and presented at TechEd 2008 in Orlando the week of June 2<SUP>nd</SUP>. </P>
<P>First up is Laura. </P>
<P>I have been a Security Program Manager for the last 3 years, working as a security advisor for a variety of products across Microsoft and the last seven months as a member of the SDL policy team.</P>
<P>&nbsp;It's been a few years since I've been to TechEd, and this was my first time attending as a member of the security team. TechEd is now a two week conference, with one week dedicated to developers and&nbsp; the other to IT professionals. &nbsp;I think that breaking down the conference into a Developer week and an ITPro week was a good idea, and it allowed us to have good conversations with people who wanted more information about the SDL. I did two main things at TechEd:, I presented on threat modeling, and I spent a lot of time talking to customers at the SDL booth. At the SDL booth, we heard questions ranging from "What does the SDL stand for?" to "Our Web site was hacked; how do I stop it from happening again?" It was encouraging hearing people interested to hear more specifics about how we implement the SDL at Microsoft, and thinking through how they can apply it in their own companies.&nbsp; My understanding from other TechEd veterans in our booth is that interest in the SDL seemed higher, which is great.</P>
<P>During my Threat Modeling session, , most of the feedback and follow-up questions were similar to the ones in the booth: how to expand the threat modeling processes to their own companies, and how to get started. </P>
<P>My typical response to both questions is to start small and do what makes sense for your organization. At &nbsp;Microsoft, for example, when we introduce new SDL requirements, we usually start with a few teams so we can refine the requirement and supporting tools before expanding the requirements to a broader group. Similarly, while we have a core set of requirements that all teams have to meet, there are other requirements that are specific to a platform, scenario, or functionality. For example, there are some requirements that make sense for desktop-oriented products, but do not make sense for mobile devices. &nbsp;You may very likely have to make changes to our policies to make them relevant to your organization, your scenarios, and functionality. </P>
<P>Now over to Michael.</P>
<P>Hi, Michael here.</P>
<P>One of the joys of presenting at TechEd each year is hearing from real people about the issues they face using our products in the real world; rarely are the issues pure philosophical security geekness. This year I gave two talks and one "chalk talk." The talks were "Top Ten Strategies <BR>To Secure Your Code" and "How To Review Your Code<BR>and Test For Security Bugs", and the chalk talk, which was a lot of fun, was simply answering numerous developer questions.</P>
<P>It's interesting to gauge overall security awareness from our customers, and there is no doubt that over the years, the level of security knowledge and maturity has risen. I think it's possible to evaluate overall security maturity by the questions posed. Some years ago, security was never really a topic of discussion other than those that relate to security technologies, such as how to use and manage X.509 certificates. About four years ago the tide really changed and people started asking more questions about "secure" application deployment and management, and developers wanted to learn more about securing their code; especially C and C++ code. Even then there was still a reliance on exterior defenses like firewalls. All too often I would hear people claim that they don't need to focus on securing their apps because a firewall was in the way. Heck, <A href="http://blogs.msdn.com/david_leblanc/" mce_href="http://blogs.msdn.com/david_leblanc/">David</A> and I documented this excuse in the original version of Writing Secure Code (Appendix D, "Lame Excuses We've Heard, #6, ‘We're Secure-we use a Firewall'") way back in 2002.</P>
<P>Fast forward to 2008.</P>
<P>Things have obviously changed. I don't know if finally the security message is getting through because many people asked me highly specific questions about securing their apps and how best to use the defenses we offer in Windows Vista and Windows Server 2008. </P>
<P>I still hear the firewall excuse a little, but not too much!</P>
<P>Perhaps the most telling trend I saw this year was a great deal of interest in the SDL. Not cursory, "that looks interesting" interest, but, "how can I implement this in my company" interest. After answering specific questions, I pointed most folks to&nbsp; Jeremy's "<A href="http://blogs.msdn.com/sdl/archive/2008/03/06/crawling-toward-sdl.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/03/06/crawling-toward-sdl.aspx">Crawling Toward SDL</A>" post on the subject.</P>
<P>In my opinion, getting to a point where you want to change your development process shows you really understand there's an issue that needs fixing. </P>And that's goodness.<img src="http://blogs.msdn.com/aggbug.aspx?PostID=8657045" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 11:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/numerous developer questions">numerous developer questions</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/highly specific questions">highly specific questions</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/security knowledge">security knowledge</category>
      <category domain="http://securityratty.com/tag/sdl requirements">sdl requirements</category>
      <category domain="http://securityratty.com/tag/maturity">maturity</category>
      <category domain="http://securityratty.com/tag/security maturity">security maturity</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/06/26/security-thoughts-from-teched-2008.aspx">Security Thoughts from TechEd 2008</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</link>
      <guid>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</guid>
      <description><![CDATA[Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s1600-h/porn_codecs.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s200/porn_codecs.JPG" alt="" id="BLOGGER_PHOTO_ID_5215822602249819938" border="0" /></a>Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting of over twenty different domains serving the usual Zlob malware variants, we have a decent abuse of a template for a porn site.<br /><br />The easy of management of such domain farms and the availability of templates for high trafficked topic segments such as celebrities and pornography, continue contributing to the increasing number of Zlob variants served through fake codecs. Moreover, once set up, the malicious infrastructure starts attracting now just generic search traffic, but also traffic coming from affiliates with whom revenue is shared on the basis of the number of people that downloaded the codec.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s1600-h/fake_porn_sites_ATRIVO.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s200/fake_porn_sites_ATRIVO.JPG" alt="" id="BLOGGER_PHOTO_ID_5215850339125738802" border="0" /></a>In this campaign, the malicious doorway that expands the entire ecosystem is located at <span style="font-weight: bold;">search-</span><span style="font-weight: bold;">top.com/in.cgi?5&amp;parameter=drs</span> (66.96.85.113). A redirector that appears to <a href="http://www.lavasoftsupport.com/index.php?showtopic=2662">have been operating since 2006</a>, according to this forum posting.<br /><br />What follows on-the-fly, are all the fake porn sites whose legitimately looking videos attempt to download a Zlob malware variant from a single location - <span style="font-weight: bold;">vipcodec.net</span>. Here are all the fake porn sites, and the associated campaigns in this redirection :<br /><br /><span style="font-weight: bold;">watchnenjoy .com</span>/index.php?id=1287&amp;style=white<br /><span style="font-weight: bold;">craziestclips .com</span>/index.php?id=1287&amp;q=<br /><span style="font-weight: bold;">immensevids .com</span><br /><span style="font-weight: bold;">planetfreepornmovies .com</span>/?t=1&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/edmund/16551689/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/rosalyn/1742941675/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/emiline/108846601/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/inde/964842117/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/elnora/648311952/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/verge/1734135233/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/dal/1663381205/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .ne</span><span style="font-weight: bold;">t</span>/gretchen/515268975/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s1600-h/porn_domainfarm_codecs_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s200/porn_domainfarm_codecs_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5215861114847986306" border="0" /></a><span style="font-weight: bold;">abc-adult .com</span>/lillah/1467790484/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/jenne/434165228/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/ette/681831796/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/mime/65729013/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/alfe/550398461/1/&amp;id=1219<br /><span style="font-weight: bold;">group-ad</span><span style="font-weight: bold;">ult .net</span>/demerias/867452637/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rhode/167691118/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/hephsibah/1254235416/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/hence/1684651134/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/kendra/371598555/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/link/1334727639/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/flo/84660854/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/assene/875893411/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/charlotta/972714195/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/orlando/761508522/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/jemima/1405735776/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/obadiah/263904242/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/douglas/1110779475/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/lydde/1844064103/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marcia/1627490290/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/cono/295680123/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/wes/1733468207/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/wib/648341815/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/greg/2064937302/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/maris/33184936/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/regina/1273816838/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/gwendolyn/869744046/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/carthaette/1021629112/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/ninell/1522355420/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/waldo/755290223/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/green/669090607/1/&amp;id=1219<br /><span style="font-weight: bold;">try-adult .com</span>/lula/447057398/1/&amp;id=1219<br /><span style="font-weight: bold;">visit-adult .net</span>/jay/1021153563/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/rosa/849017739/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/hannah/2111126283/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/robin/2114086747/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/geraldine/921262381/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/christine/1821111087/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/frederica/364993202/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/kerste/735582753/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/vine/715820953/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/newt/1835463160/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s1600-h/zlob_codec_setup.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s200/zlob_codec_setup.png" alt="" id="BLOGGER_PHOTO_ID_5215866033022980914" border="0" /></a><span style="font-weight: bold;">try-adult .com</span>/max/602914725/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/cille/1420660046/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/phililpa/178057959/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/lise/1379126759/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marianne/1083617952/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/emile/1173468576/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/patse/155685496/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/verna/625840253/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/aubrey/190928373/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .</span><span style="font-weight: bold;">net</span>/alphinias/1345158043/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rosa/223743611/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/nerva/1509620489/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/leet/1619667733/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/roberta/887345003/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/tore/1032556395/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/bo/1963737386/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/karon/136085893/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/tense/1523522750/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/hopp/1955964399/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/vanne/350822489/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/deb/1451360694/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/moll/1511640690/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/obediah/562846948/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/tamarra/776122096/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/aristotle/1046422029/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/titia/158157566/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/gay/1297835054/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/katherine/2136357734/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/azubah/1197502147/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/claes/770105101/1/&amp;id=1219<br /><br />Associated fake porn sites :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s1600-h/fake_porn_sites_ATRIVO1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s200/fake_porn_sites_ATRIVO1.JPG" alt="" id="BLOGGER_PHOTO_ID_5215866908634145938" border="0" /></a><span style="font-weight: bold;">pornbrake .com</span> <span style="font-weight: bold;"><br />sexnitro .net</span> <span style="font-weight: bold;"><br />brakesex .net</span> <span style="font-weight: bold;"><br />pornnitro .net</span> <span style="font-weight: bold;"><br />adultbookings .com</span> <span style="font-weight: bold;"><br />qazsex .com</span><br /><span style="font-weight: bold;">lightporn .net</span> <span style="font-weight: bold;"><br />delfiporn .net</span> <span style="font-weight: bold;"><br />pornqaz .com</span> <span style="font-weight: bold;"><br />megazporn .com</span> <span style="font-weight: bold;"><br />uinsex .com</span><br /><span style="font-weight: bold;">xerosex .com</span> <span style="font-weight: bold;"><br />serviceporn .com</span> <span style="font-weight: bold;"><br />aboutadultsex .com</span> <span style="font-weight: bold;"><br />superliveporn .com</span> <span style="font-weight: bold;"><br />bestpriceporn .com</span> <span style="font-weight: bold;"><br />contactporn .net</span> <span style="font-weight: bold;"><br />relatedporn .com</span> <span style="font-weight: bold;"><br />landporno .com</span> <span style="font-weight: bold;"><br />adultsper .com</span> <span style="font-weight: bold;"><br />plus-porn .com</span> <span style="font-weight: bold;"><br />adultstarworld .com</span><br /><span style="font-weight: bold;">cutadult .com</span> <span style="font-weight: bold;"><br />moviexxxhotel .com</span> <span style="font-weight: bold;"><br />porno-go .com</span> <span style="font-weight: bold;"><br />pornxxxfilm .com</span> <span style="font-weight: bold;"><br />porn-sea .com</span> <span style="font-weight: bold;"><br />review-sex .com</span> <span style="font-weight: bold;"><br />sureadult .com</span> <span style="font-weight: bold;"><br />browseadult .com</span> <span style="font-weight: bold;"><br />network-adult .com</span> <span style="font-weight: bold;"><br />timeadult .com</span> <span style="font-weight: bold;"><br />virtual-sexy .net</span><br /><span style="font-weight: bold;">funxxxporn .com</span> <span style="font-weight: bold;"><br />loweradult .com</span> <span style="font-weight: bold;"><br />adultfilmsite .com</span> <span style="font-weight: bold;"><br />xxxallvideo .com</span> <span style="font-weight: bold;"><br />custom-sex .com</span> <span style="font-weight: bold;"><br />g</span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s1600-h/fake_porn_sites_ATRIVO2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s200/fake_porn_sites_ATRIVO2.JPG" alt="" id="BLOGGER_PHOTO_ID_5215867747702294034" border="0" /></a><span style="font-weight: bold;">allerypictures .net</span> <span style="font-weight: bold;"><br />usaadultvideo .com</span><br /><span style="font-weight: bold;">adultmovieplus .com</span> <span style="font-weight: bold;"><br />porn-cruise .com</span> <span style="font-weight: bold;"><br />clubxxxvideo .com</span> <span style="font-weight: bold;"><br />mitadult .com</span> <span style="font-weight: bold;"><br />galleryalbum .net</span> <span style="font-weight: bold;"><br />xxxteenfilm .com</span> <span style="font-weight: bold;"><br />hardcorevideosite .com</span> <span style="font-weight: bold;"><br />helpadult .com</span> <span style="font-weight: bold;"><br />portaladult .net</span> <span style="font-weight: bold;"><br />service-sex .com</span> <span style="font-weight: bold;"><br />driveadult .com</span> <span style="font-weight: bold;"><br />access-porno .com</span> <span style="font-weight: bold;"><br />time-sex .com</span> <span style="font-weight: bold;"><br />plus-adult .com</span> <span style="font-weight: bold;"><br />worldadultvideo .com</span><br /><span style="font-weight: bold;">key-adult .com</span><br /><span style="font-weight: bold;">estatesex .com</span> <span style="font-weight: bold;"><br />superadultfriend .com</span><br /><span style="font-weight: bold;">superporncity .com</span> <span style="font-weight: bold;"><br />zero-porno .com</span> <span style="font-weight: bold;"><br />scanadult .com</span> <span style="font-weight: bold;"><br />adultsexpro .com</span> <span style="font-weight: bold;"><br />adultzoneworld .com</span> <span style="font-weight: bold;"><br />porntimeguide .com</span> <span style="font-weight: bold;"><br />usbestporn .com</span> <span style="font-weight: bold;"><br />adulttow .com</span> <span style="font-weight: bold;"><br />look-porn .com</span><br /><span style="font-weight: bold;">galleryclick .net</span><br /><span style="font-weight: bold;">micro-sex .com</span> <span style="font-weight: bold;"><br />estatesex .com</span> <span style="font-weight: bold;"><br />try-sex .com</span> <span style="font-weight: bold;"><br />0bucksforpornmovie .com</span> <span style="font-weight: bold;"><br />gays-video-xxx .com</span> <span style="font-weight: bold;"><br />hackthegrid .com</span> <span style="font-weight: bold;"><br />savetop .info</span> <span style="font-weight: bold;"><br />vidsplanet .net</span> <span style="font-weight: bold;"><br />freexxxhere .com</span> <span style="font-weight: bold;"><br />gestkoeporno .com</span><br /><span style="font-weight: bold;">tv-adult .info</span> <span style="font-weight: bold;"><br />gays-adult-video .com</span> <span style="font-weight: bold;"><br />matures-video .com</span> <span style="font-weight: bold;"><br />analcekc .com</span> <span style="font-weight: bold;"><br />tabletskard .in</span> <span style="font-weight: bold;"><br />molodiedevki .com</span> <span style="font-weight: bold;"><br />dom-porno .com</span> <span style="font-weight: bold;"><br />pornoaziatki .com</span> <span style="font-weight: bold;"><br />latinosvideo .com</span> <span style="font-weight: bold;"><br />geiporno .com</span> <span style="font-weight: bold;"><br />sweetfreeporn .com</span><br /><br />If exposing a huge domains portfolio of currently active redirectors has the potential to ruin someone's vacation, then consider someone's vacation ruined already.<br /><br /><span style="font-weight: bold;">Related posts:<br /></span><a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br /><a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br /><a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XlaQvI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XlaQvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cI4v2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cI4v2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U4oTAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U4oTAi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LbooCi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LbooCi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MITw1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MITw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nqHRRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nqHRRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2sf0Xi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2sf0Xi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/319853315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 08:16:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/about-adult">about-adult</category>
      <category domain="http://securityratty.com/tag/scan-porn">scan-porn</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/name-adult">name-adult</category>
      <category domain="http://securityratty.com/tag/useporn">useporn</category>
      <category domain="http://securityratty.com/tag/porn-the">porn-the</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/319853315/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[University of Florida student information online for years]]></title>
      <link>http://securityratty.com/article/70535b81354ea161a0135979f7d38509</link>
      <guid>http://securityratty.com/article/70535b81354ea161a0135979f7d38509</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/11/08

Organization
University of Florida

Contractor/Consultant/Branch
Office for Academic Support and Institutional Services

Victims
Students
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/uflorida.jpg" align="right" height="165" width="165"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.ufl.edu/">University of Florida</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://web.oasis.ufl.edu/">Office for Academic Support and Institutional Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Students <br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 11,300"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"GAINESVILLE, Fla. - University of Florida officials today mailed letters of notification to more than 11,300 current and former students regarding a privacy breach that resulted in names, addresses and Social Security numbers being posted online that may have been accessible to the public."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://privacy.ufl.edu/CLASBreach/">University of Florida</a> <br><a href="http://www.miamiherald.com/top_stories/story/565567.html">Miami Herald</a> <br><a href="http://insideuf.ufl.edu/2008/06/10/clas-breach/">Inside UF</a> <br><a href="http://www.upi.com/Top_News/2008/06/11/Security_breached_at_Florida_university/UPI-38151213211913/">United Press International</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of Florida<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>GAINESVILLE, Fla. - University of Florida officials today mailed letters of notification to more than 11,300 current and former students regarding a privacy breach that resulted in names, addresses and Social Security numbers being posted online that may have been accessible to the public.<br><span style="font-style: italic;">[Evan] Not "may have been".&nbsp; The information was accessible to the public and was not even protected by a password.</span><br><br>The student information was actively used from 2003 through 2005 and remained posted until it was recently discovered during a routine audit of UF systems.<br><span style="font-style: italic;">[Evan] If I am reading this right, this means that some of the personal information was available publicly for ~5 years!</span><br><br>School officials emphasized that the site would not have been easy to find and they do not believe it was accessed by anyone outside the school.<br><span style="font-style: italic;">[Evan] There is no security through obscurity.</span><br><br>"The risk of someone outside actually finding this information and using it inappropriately is very low," - Steve Orlando, UF Spokesman<br><span style="font-style: italic;">[Evan] I wonder how Mr. Orlando came to the conclusion that the risk of disclosure and misuse is "very low".&nbsp; As I understand, the server was publicly accessible, presumably via the internet.&nbsp; If so, was the site indexed by search engines like Google, Yahoo, and Microsoft?&nbsp; It is much easier to find information through a search index because folder structure is much less relevant.&nbsp; The fact that this information was available for 3-5 years adds to the risk too.&nbsp; I only know what I read and based on this and experience, I wouldn't classify this as a "very low" risk situation.&nbsp; Either way, the risk was increased due to poor information security practice and was not necessary. </span><br><br>"We've done computer forensics, and we don't have any evidence that anybody accessed this information," he added.<br><span style="font-style: italic;">[Evan] This indicates poor logging and monitoring which are both essential detective controls (in most situations).&nbsp; Information security personnel (or admins) should be empowered to reconstruct events.</span><br><br>"But because we can't say that with absolute certainty, we're going through with the notification out of an abundance of caution," Orlando said.<br><span style="font-style: italic;">[Evan] I am NOT a fan of the "abundance of caution" claims that seem more popular in breach notifications lately.&nbsp; Organizations would be best advised to use an "abundance of caution" in the prevention and early detection of breaches by applying sound information security principles.</span><br><br>Since 2005, the site has been "dormant but accessible," said university spokesman Steve Orlando. "It was just sitting there."<br><br>The information has been removed and is no longer available online or elsewhere in the UF systems.<br><br>The breach occurred when former student employees of the Office for Academic Support and Institutional Service, or OASIS, program created online records of students participating in the program.<br><br>The student employees posted the information online so that they could work with it from remote locations, but they did not install security measures to keep others from accessing it as well<br><span style="font-style: italic;">[Evan] I have so many questions and arguments.&nbsp; Were the students aware of the risks?&nbsp; If not, then there is probably an information security training and awareness problem.&nbsp; Why was it necessary to include Social Security numbers in the records?&nbsp; Why were the seemingly untrained students allowed to post the information without being stopped or detected?&nbsp; I have many more questions, but I am starting to confuse myself now.</span><br><br>The university sent letters of notification to about 11,300 students whose information is believed to have been potentially compromised.<br><span style="font-style: italic;">[Evan] Here's my take on the word "compromised".&nbsp; If an organization cannot provide reasonable assurance that the information has not been subject to unauthorized disclosure, modification, or destruction, then the information has been "compromised".&nbsp; </span><br><br>University officials were unable to find contact information for about 570, so they are asking students who were enrolled in CLAS from 2003 to 2005 and did not receive a letter but who believe their information may have been compromised to call UF’s Privacy Office Hotline at 866-876-HIPA and provide the requested information.<br><br>Anyone who thinks he or she may be one of the 570 people who were not notified is urged to go to <a href="http://privacy.ufl.edu">privacy.ufl.edu</a> and read the information posted there before calling the privacy hotline.<br><br>"This would certainly appear to be the largest privacy breach we've had," Orlando said.<br><br>We're in the process of strengthening some of those policies regarding what information can be posted and what security measures should be in place<br><span style="font-style: italic;">[Evan] Good start.</span><br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"Why would it be necessary to use a Social Security number instead of something else?" asked Reixach, pointing out that students were given ID numbers. "It's just silly".<br><br>"It's negligence on their part, especially if anyone has been affected with identity theft,"<br><br>Johann Arias, a spring CLAS graduate, had not heard about the breach Wednesday and said UF should be doing more to notify those affected.<br><br>"They always make information very prominent when you have a hold or owe them money," Arias said.<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a case where poorly trained students are granted access or obtained access to confidential information and posted the information to an unsecured location which went undetected for years.&nbsp; Bad all around.&nbsp; <br><br><span style="font-weight: bold;">Past Breaches:</span><br>May, 2008 - <a href="http://breachblog.com/2008/05/22/uflorida.aspx">University of Florida doctor loses job over breach</a> <br>November, 2007 - <a href="http://breachblog.com/2007/11/28/uf.aspx">University of Florida student info online</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/12/uflorida.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 06:41:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information online">information online</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security personnel">information security personnel</category>
      <category domain="http://securityratty.com/tag/student information">student information</category>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/install security measures">install security measures</category>
      <source url="http://breachblog.com/2008/06/12/uflorida.aspx">University of Florida student information online for years</source>
    </item>
    <item>
      <title><![CDATA[The best way to get customer service? Blog or Twit them]]></title>
      <link>http://securityratty.com/article/d37d7096488b80fac5676e7d97c43601</link>
      <guid>http://securityratty.com/article/d37d7096488b80fac5676e7d97c43601</guid>
      <description><![CDATA[I was reading an article in the Orlando Sentinel newspaper this morning (I know who reads newspapers anymore), about how so many companies are tracking unhappy customers by monitoring blogs and even...]]></description>
      <content:encoded><![CDATA[<p>I was reading an <a href="http://www.orlandosentinel.com/orl-horowitz2408may24,0,4901151.column">article in the Orlando Sentinel newspaper</a> this morning (I know who reads newspapers anymore), about how so many companies are tracking unhappy customers by monitoring blogs and even twitter messages. It reminded me of a <a href="http://rationalsecurity.typepad.com/blog/2008/04/off-topic-south.html">story that Chris Hoff</a> had a while back about Southwest Airlines monitoring his Twitter message <br><br>The story in the Sentinel had two opposite corporate views on this. One was Comcast who quickly turned a negative blog post and experience into a positive one by reaching out to the customer and fixing their problem. The customer than ran an updated blog post to commend Comcast. Much the same way Hoff did in his post on Southwest. The polar opposite of this was Spirit Airlines, whose spokesperson according to the article said, "she wasn't concerned and that Spirit doesn't let blog posts affect its policies and procedures." Well a year later that article is still the number 3 search result on Google if you pull up Spirit Airlines. It has over a 1000 comments with many people saying they didn't fly Spirit as a result. I wonder if Spirit Airlines still feels the same way about not listening to blogs?<br><br>The article mentions a few other companies that monitor blogs and twitter and message boards. It also mentions a web site called <a href="http://www.getsatisfaction.com/">getsatisfaction.com</a> where over 3000 companies monitor to help consumers iron out customer service issues.<br><br>They always said the pen was mightier than the sword. In todays world maybe the keyboard is too.</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=5rfdlw"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=5rfdlw" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=0IGncH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=0IGncH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=x6Y8IH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=x6Y8IH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=7456SH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=7456SH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=uZInIH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=uZInIH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=D5oAsh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=D5oAsh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=40Q85h"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=40Q85h" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/297188965" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 24 May 2008 03:44:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/negative blog post">negative blog post</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/customer">customer</category>
      <category domain="http://securityratty.com/tag/spirit airlines">spirit airlines</category>
      <category domain="http://securityratty.com/tag/airlines">airlines</category>
      <category domain="http://securityratty.com/tag/spirit">spirit</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/article mentions">article mentions</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/297188965/the-best-way-to.html">The best way to get customer service? Blog or Twit them</source>
    </item>
    <item>
      <title><![CDATA[Long holiday weekend]]></title>
      <link>http://securityratty.com/article/3fb81ad86d4640e59613718da849034e</link>
      <guid>http://securityratty.com/article/3fb81ad86d4640e59613718da849034e</guid>
      <description><![CDATA[I am really looking forward to a long holiday weekend with the family. We are driving up to Orlando to stop in Disney World and SeaWorld. Going to check out the new water park they opened there called...]]></description>
      <content:encoded><![CDATA[<div><img title="Aquatica_logo" alt="Aquatica_logo" src="http://www.stillsecureafteralltheseyears.com/photos/uncategorized/2008/05/23/aquatica_logo.png" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px"></img> I am really looking forward to a long holiday weekend with the family. We are driving up to Orlando to stop in Disney World and SeaWorld. Going to check out the new water park they opened there called <a href="http://www.aquaticabyseaworld.com/Site/flash/homepage/Default.aspx">Aquatica</a>. It has water rides unlike any we have ever seen. A day there and two days at Disney should have the kids in a great mood. Lets see what kind of mood it leaves me in. Waiting on long lines in the sweltering heat is not a lot of fun, plus I can only imagine what it is going to cost to fill up the gas tank to drive up there!</div>

<div></div>

<div>Anyway, won't be much blogging going on this weekend.</div>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=IwMYaT"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=IwMYaT" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=dtEOaH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=dtEOaH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=kjMTjH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=kjMTjH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=0U6aKH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=0U6aKH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=eL4heH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=eL4heH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=dseknh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=dseknh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=5F13th"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=5F13th" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/296539357" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 23 May 2008 03:47:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <category domain="http://securityratty.com/tag/holiday weekend">holiday weekend</category>
      <category domain="http://securityratty.com/tag/water rides unlike">water rides unlike</category>
      <category domain="http://securityratty.com/tag/disney world">disney world</category>
      <category domain="http://securityratty.com/tag/disney">disney</category>
      <category domain="http://securityratty.com/tag/mood">mood</category>
      <category domain="http://securityratty.com/tag/gas tank">gas tank</category>
      <category domain="http://securityratty.com/tag/water park">water park</category>
      <category domain="http://securityratty.com/tag/orlando">orlando</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/296539357/long-holiday-we.html">Long holiday weekend</source>
    </item>
    <item>
      <title><![CDATA[I'm the security guy. I used to have a security guy, but he died. Now I'm the security guy]]></title>
      <link>http://securityratty.com/article/a030dec74a3f3894d4a1b2c78898943e</link>
      <guid>http://securityratty.com/article/a030dec74a3f3894d4a1b2c78898943e</guid>
      <description><![CDATA[While attending the SANS event in Orlando this week I had a chance to meet a fellow who works at a company that is a StillSecure customer. I had never met this particular guy before, so I asked him...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><img title="The_producers" alt="The_producers" src="http://www.stillsecureafteralltheseyears.com/photos/uncategorized/2008/04/22/the_producers.jpg" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /> While attending the SANS event in Orlando this week I had a chance to meet a fellow who works at a company that is a StillSecure customer.&nbsp; I had never met this particular guy before, so I asked him how long he had been working in security at the company.&nbsp; The answer I got reminded me of an old quote from the move &quot;The Producers&quot; - </p><blockquote><p><em>-Who d'ya want? -I beg your pardon? -Who d'ya want? Nobody gets in the building unless I know who they want. I'm the concierge. My husband used to be the concierge, but he's dead. Now I'm the concierge.</em></p></blockquote><p>This guy had worked at the company for a number of years in the network department. They had a &quot;guy who did the security&quot;.&nbsp; He is the one that bought the StillSecure product.&nbsp; Evidently a while back the security guy left the company.&nbsp; It is not clear whether he quit or was asked to leave, but the bottom line is they had no security guy. Instead of hiring another security guy, they made this poor SOB the security guy.&nbsp; He inherited a bunch of security products including our own and a bunch of &quot;open source stuff&quot;.&nbsp; This guy didn't even know where to begin. </p>

<p>After floundering around for a while, he made a smart move and signed up for some security training from SANS and is just beginning to realize how much he doesn't know.&nbsp; But it will still be some time before he is in a position to handle the security at his company, that by the way has SOX issues to deal with.&nbsp; I suggested that perhaps he look into some MSSP service to help him out.&nbsp; I am going to try and help this fellow out as much as I can, but he has a tall order.</p>

<p>How many others are out there in the same boat?&nbsp; How many people have had the security role thrust on them, without the training or expertise to make it happen.&nbsp; The greatest tools in the world, won't make up for this lack of skills and experience.&nbsp; Is it any wonder that we have a breach a day announced and our security seems to be in such disarray? We should let security be handled by security professionals or else we deserve what we get!</p></div>
]]></content:encoded>
      <pubDate>Tue, 22 Apr 2008 20:47:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security guy">security guy</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/security role thrust">security role thrust</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/concierge">concierge</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/im-the-security.html">I'm the security guy. I used to have a security guy, but he died. Now I'm the security guy</source>
    </item>
  </channel>
</rss>
