<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: orleans]]></title>
    <link>http://securityratty.com/tag/orleans</link>
    <description></description>
    <pubDate>Tue, 15 Jan 2008 19:49:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Army Contractor Accused of Murder Is Out on Bail]]></title>
      <link>http://securityratty.com/article/8e538c7b4a49be20216b17d911656904</link>
      <guid>http://securityratty.com/article/8e538c7b4a49be20216b17d911656904</guid>
      <description><![CDATA[Don Ayala, a U.S. Army contractor accused of a revenge killing in Afghanistan, is back in the United States and out on bail in New Orleans. Ayala was part of an Army &quot;Human Terrain Team,&quot; a program...]]></description>
      <content:encoded><![CDATA[Don Ayala, a U.S. Army contractor accused of a revenge killing in
Afghanistan, is back in the United States and out on bail in New Orleans. Ayala was part of an Army "Human Terrain Team," a program that embeds social scientists in combat units.<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=84e90403ff1ce01911fc3e0d1f6c7c6a&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=84e90403ff1ce01911fc3e0d1f6c7c6a&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=84e90403ff1ce01911fc3e0d1f6c7c6a" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gsqUN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gsqUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Qsfvn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Qsfvn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=73V4n"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=73V4n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=n5r6N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=n5r6N" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=oecJN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oecJN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Jjq1n"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Jjq1n" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=JAyfn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=JAyfn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=ZHsMN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ZHsMN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/466377996" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/466377997" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 22:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/army">army</category>
      <category domain="http://securityratty.com/tag/army contractor">army contractor</category>
      <category domain="http://securityratty.com/tag/human terrain team">human terrain team</category>
      <category domain="http://securityratty.com/tag/embeds social scientists">embeds social scientists</category>
      <category domain="http://securityratty.com/tag/ayala">ayala</category>
      <category domain="http://securityratty.com/tag/bail">bail</category>
      <category domain="http://securityratty.com/tag/combat units">combat units</category>
      <category domain="http://securityratty.com/tag/orleans">orleans</category>
      <category domain="http://securityratty.com/tag/afghanistan">afghanistan</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/466377997/human-terrain-m.html">Army Contractor Accused of Murder Is Out on Bail</source>
    </item>
    <item>
      <title><![CDATA[Blackwater Preps for Hurricane Gustav]]></title>
      <link>http://securityratty.com/article/0b62df6a433b2afd278f5f889cf5c670</link>
      <guid>http://securityratty.com/article/0b62df6a433b2afd278f5f889cf5c670</guid>
      <description><![CDATA[New Orleans is being evacuated once again, as Hurricane Gustav lumbers towards the Gulf Coast. Everyone from the U.S. military to the British Royal Navy to Blackwater is gearing up to...]]></description>
      <content:encoded><![CDATA[New Orleans is being evacuated once again, as Hurricane Gustav lumbers towards the Gulf Coast. Everyone from the U.S. military to the British Royal Navy to Blackwater is gearing up to respond.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=ae0d74adc3a98b37980a86f97ab02128" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=ae0d74adc3a98b37980a86f97ab02128" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=EWPN0K"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=EWPN0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rH0dtk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rH0dtk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ez9nfk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ez9nfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=piuXdK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=piuXdK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=RMS91K"><img src="http://feeds.wired.com/~f/wired/politics/security?i=RMS91K" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=h3actk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=h3actk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=7E2xsk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=7E2xsk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=1wethK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=1wethK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/379996276" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/379996277" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 31 Aug 2008 19:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/british royal navy">british royal navy</category>
      <category domain="http://securityratty.com/tag/hurricane gustav lumbers">hurricane gustav lumbers</category>
      <category domain="http://securityratty.com/tag/gulf coast">gulf coast</category>
      <category domain="http://securityratty.com/tag/blackwater">blackwater</category>
      <category domain="http://securityratty.com/tag/orleans">orleans</category>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/respond">respond</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/379996277/officials-made.html">Blackwater Preps for Hurricane Gustav</source>
    </item>
    <item>
      <title><![CDATA[New Orleans IT departments brace for Tropical Storm Gustav]]></title>
      <link>http://securityratty.com/article/6c0163d1608064f5cf294d981823a7b0</link>
      <guid>http://securityratty.com/article/6c0163d1608064f5cf294d981823a7b0</guid>
      <description><![CDATA[As Tropical Storm Gustav approaches the Gulf Coast this weekend and threatens to become a hurricane, the IT lessons learned from the devastating Hurricanes Katrina and Rita that smashed New Orleans...]]></description>
      <content:encoded><![CDATA[As Tropical Storm Gustav approaches the Gulf Coast this weekend and threatens to become a hurricane, the IT lessons learned from the devastating Hurricanes Katrina and Rita that smashed New Orleans and other areas in 2005 are on the minds of many worried IT managers.]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/orleans">orleans</category>
      <category domain="http://securityratty.com/tag/gulf coast">gulf coast</category>
      <category domain="http://securityratty.com/tag/hurricanes katrina">hurricanes katrina</category>
      <category domain="http://securityratty.com/tag/threatens">threatens</category>
      <category domain="http://securityratty.com/tag/hurricane">hurricane</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <category domain="http://securityratty.com/tag/lessons">lessons</category>
      <category domain="http://securityratty.com/tag/rita">rita</category>
      <category domain="http://securityratty.com/tag/managers">managers</category>
      <source url="http://www.networkworld.com/news/2008/082908-new-orleans-it-departments-brace.html?fsrc=rss-security">New Orleans IT departments brace for Tropical Storm Gustav</source>
    </item>
    <item>
      <title><![CDATA[EarthLink Shutters New Orleans, Staunches Own Losses]]></title>
      <link>http://securityratty.com/article/9705fcd4afe10a8b02f4bdfac2dd6f51</link>
      <guid>http://securityratty.com/article/9705fcd4afe10a8b02f4bdfac2dd6f51</guid>
      <description><![CDATA[The Big Easy gets a big loss with EarthLink's pullout: InformationWeek reports that EarthLink attempted to sell the network, get the city to buy it, and then to simply give the network (and its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><a href="http://www.informationweek.com/news/mobility/muni/showArticle.jhtml?articleID=207402189"><strong>The Big Easy gets a big loss with EarthLink's pullout:</strong></a> InformationWeek reports that EarthLink attempted to sell the network, get the city to buy it, and then to simply give the network (and its obligations) away, but had no takers on any front. </p>

<p>EarthLink <a href="http://ir.earthlink.net/secfiling.cfm?filingID=1104659-08-26319"><strong>announced its most recent quarter's earnings</strong></a> a few days ago, and they managed to turn a GAAP profit, while staunching the bleeding of so many businesses that had no short-term and seemingly little medium-term potential for net revenue. The company dramatically slashed its marketing, which they found only caused subscribers to join and quit. While revenue dropped from $290m to $235m year over year in Q1, operating costs and expenses were cut from $321m to $198m, with the most noticeable drop in sales and marketing ($99m to $31m) and operations and customer support ($60m to $39m). They recorded $58m in earnings versus a year ago's $22m loss. </p>

<p>Employees dropped from 2,108 to 922 during the period, while subscribers dropped from 5.7m to 3.6m. But it's worth noting that the biggest drop happened last year already: the 31-Dec-2007 subscriber count was 3.9m. They're making slightly more money from each of those remaining customers, and have slightly lower churn. Their municipal write-off is lower, too, as they've taken most of the expense, and have offloaded more and more of their future obligations.</p>

<p>The company still has the same problem that it had before it started unwinding its services beyond dial-up and broadband: None of its markets are expanding, and it has increasingly poor access to reasonably priced broadband to resell to customers, as no cable or DSL providers are obligated to provide true wholesale rates.<br />
</p>]]></content:encoded>
      <pubDate>Fri, 25 Apr 2008 11:52:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/earthlink">earthlink</category>
      <category domain="http://securityratty.com/tag/slightly lower churn">slightly lower churn</category>
      <category domain="http://securityratty.com/tag/slightly">slightly</category>
      <category domain="http://securityratty.com/tag/lower">lower</category>
      <category domain="http://securityratty.com/tag/loss">loss</category>
      <category domain="http://securityratty.com/tag/increasingly poor access">increasingly poor access</category>
      <category domain="http://securityratty.com/tag/earnings">earnings</category>
      <category domain="http://securityratty.com/tag/drop">drop</category>
      <category domain="http://securityratty.com/tag/noticeable drop">noticeable drop</category>
      <source url="http://wifinetnews.com/archives/008291.html">EarthLink Shutters New Orleans, Staunches Own Losses</source>
    </item>
    <item>
      <title><![CDATA[Hacking Power Networks]]></title>
      <link>http://securityratty.com/article/827c4e5d935db9b3586563a48e95974d</link>
      <guid>http://securityratty.com/article/827c4e5d935db9b3586563a48e95974d</guid>
      <description><![CDATA[The CIA unleashed a big one at a SANS conference : On Wednesday, in New Orleans, US Central Intelligence Agency senior analyst Tom Donahue told a gathering of 300 US, UK, Swedish, and Dutch government...]]></description>
      <content:encoded><![CDATA[<p>The CIA unleashed a big one at <a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=10&issue=5">a SANS conference</a>:</p>

<blockquote>On Wednesday, in New Orleans, US Central Intelligence Agency senior analyst Tom Donahue told a gathering of 300 US, UK, Swedish, and Dutch government officials and engineers and security managers from electric, water, oil & gas and other critical industry asset owners from all across North America, that "We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. We have information that cyber attacks have been used to disrupt power equipment in several regions outside the United States. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet."

<p>According to Mr. Donahue, the CIA actively and thoroughly considered the benefits and risks of making this information public, and came down on the side of disclosure.</blockquote></p>

<p>I'll bet.  There's nothing like an vague unsubstantiated rumor to forestall reasoned discussion.  But, of course, <a href="http://www.engadget.com/2008/01/19/hackers-reportedly-targeting-cities-power-systems/">everyone</a> <a href="http://www.forbes.com/2008/01/18/cyber-attack-utilities-tech-intel-cx_ag_0118attack.html">is</a> <a href="http://www.ibls.com/internet_law_news_portal_view.aspx?s=latestnews&id=1963">writing</a> <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=205901631">about</a> <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/18/AR2008011803277.html">it</a> <a href="http://www.pcworld.com/article/id,141564-c,hackers/article.html">anyway</a>.</p>

<p>SANS's Alan Paller is happy to <a href="http://www.forbes.com/2008/01/18/cyber-attack-utilities-tech-intel-cx_ag_0118attack.html">add details</a>:</p>

<blockquote>In the past two years, hackers have in fact successfully penetrated and extorted multiple utility companies that use SCADA systems, says Alan Paller, director of the SANS Institute, an organization that hosts a crisis center for hacked companies. "Hundreds of millions of dollars have been extorted, and possibly more. It's difficult to know, because they pay to keep it a secret," Paller says. "This kind of extortion is the biggest untold story of the cybercrime industry."</blockquote>

<p>And to up the <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=205901631">fear factor</a>:</p>

<blockquote>The prospect of cyberattacks crippling multicity regions appears to have prompted the government to make this information public. The issue "went from 'we should be concerned about to this' to 'this is something we should fix now,' " said Paller. "That's why, I think, the government decided to disclose this."</blockquote>

<p>More <a href="http://www.ibls.com/internet_law_news_portal_view.aspx?s=latestnews&id=1963">rumor</a>:</p>

<blockquote>An attendee of the meeting said that the attack was not well-known through the industry and came as a surprise to many there. Said the person who asked to remain anonymous, "There were apparently a couple of incidents where extortionists cut off power to several cities using some sort of attack on the power grid, and it does not appear to be a physical attack."</blockquote>

<p>And more <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/18/AR2008011803277.html">hyperbole</a> from someone in the industry:</p>

<blockquote>Over the past year to 18 months, there has been "a huge increase in focused attacks on our national infrastructure networks, . . . and they have been coming from outside the United States," said Ralph Logan, principal of the Logan Group, a cybersecurity firm.

<p>It is difficult to track the sources of such attacks, because they are usually made by people who have disguised themselves by worming into three or four other computer networks, Logan said. He said he thinks the attacks were launched from computers belonging to foreign governments or militaries, not terrorist groups."</blockquote></p>

<p>I'm more than a bit skeptical here.  To be sure -- <a href="http://www.schneier.com/blog/archives/2007/10/staged_attack_c.html">fake staged attacks</a> aside -- there are serious risks to SCADA systems (Ganesh Devarajan <a href="http://www.defcon.org/html/defcon-15/dc-15-speakers.html#Devarajan">gave a talk at DefCon</a> this year about some potential attack vectors), although at this point I think they're more a future threat than present danger.  But this CIA tidbit tells us nothing about how the attacks happened.  Were they against SCADA systems?  Were they against TCP/IP systems?  Were they against Windows?  Insiders may have been involved, so was this a computer security vulnerability at all?  We have no idea.</p>

<p>Cyber-extortion is certainly on the rise; we see it at Counterpane. Primarily it's against fringe industries -- online gambling, online gaming, online porn -- operating offshore in countries like Bermuda and the Cayman Islands.  It is going mainstream, but this is the first I've heard of it targeting power companies.  Certainly possible, but is that part of the CIA rumor or was it tacked on afterwards?</p>

<p>And <a href="http://en.wikipedia.org/wiki/List_of_power_outages">here's</a> list of power outages.  Which ones were hacker caused?  Some details would be nice.</p>

<p>I'd like a little bit more information before I start panicking.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=CcqAWvD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=CcqAWvD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SStleeD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SStleeD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SRKOXVD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SRKOXVD" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 22 Jan 2008 11:24:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/power">power</category>
      <category domain="http://securityratty.com/tag/power companies">power companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/cia actively">cia actively</category>
      <category domain="http://securityratty.com/tag/power outages">power outages</category>
      <category domain="http://securityratty.com/tag/cia">cia</category>
      <category domain="http://securityratty.com/tag/cia rumor">cia rumor</category>
      <category domain="http://securityratty.com/tag/disrupt power equipment">disrupt power equipment</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <source url="http://www.schneier.com/blog/archives/2008/01/hacking_power_n.html">Hacking Power Networks</source>
    </item>
    <item>
      <title><![CDATA[Fun Read: "Busting the 10 Myths About Data Protection"]]></title>
      <link>http://securityratty.com/article/99245b89066e19694de15216d872113b</link>
      <guid>http://securityratty.com/article/99245b89066e19694de15216d872113b</guid>
      <description><![CDATA[I am sitting here in New Orleans , preparing for tomorrow's SANS Lunch and Learn (come over! it'll be fun since I will talk about &quot;worst practices&quot; again) and - yes! you guessed right! - a blogging...]]></description>
      <content:encoded><![CDATA[I am sitting here in <a href="http://www.sans.org/security08/">New Orleans</a>, preparing for tomorrow's <a href="http://www.sans.org/security08/vendor.php">SANS Lunch and Learn</a> (come over! it'll be fun since I will <a href="http://www.sans.org/security08/vendor.php">talk about "worst practices"</a> again) and - <span style="font-style: italic;">yes! you guessed right!</span> - a blogging frenzy descended upon me...<br /><br />First, a fun Read: "<a href="http://www.cio.com/article/171551/Busting_the_Myths_About_Data_Protection/3">Busting the 10 Myths About Data Protection</a>"<br /><br />For example: "<em>Myth No. 4 </em><strong>I should be most concerned about protecting my data from data theft and malicious internal leaks." or  ""<br /></strong><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=zJiVEiD"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=zJiVEiD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=kka34eD"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=kka34eD" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/217478963" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jan 2008 19:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data protection">data protection</category>
      <category domain="http://securityratty.com/tag/data theft">data theft</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/malicious internal leaks">malicious internal leaks</category>
      <category domain="http://securityratty.com/tag/sans lunch">sans lunch</category>
      <category domain="http://securityratty.com/tag/myths">myths</category>
      <category domain="http://securityratty.com/tag/worst practices">worst practices</category>
      <category domain="http://securityratty.com/tag/orleans">orleans</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/217478963/fun-read-busting-10-myths-about-data.html">Fun Read: "Busting the 10 Myths About Data Protection"</source>
    </item>
  </channel>
</rss>
