<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: overseas]]></title>
    <link>http://securityratty.com/tag/overseas</link>
    <description></description>
    <pubDate>Fri, 15 Aug 2008 16:57:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[No Court Order Needed to Spy on Americans Overseas, Appeals Court Rules]]></title>
      <link>http://securityratty.com/article/f122524e53ae750bfb90e8d1242de99b</link>
      <guid>http://securityratty.com/article/f122524e53ae750bfb90e8d1242de99b</guid>
      <description><![CDATA[The government does not need a judge's approval to wiretap Americans overseas, an appeals court ruled, rejecting the appeal of an American convicted of helping plan the 1998 East Africa embassy...]]></description>
      <content:encoded><![CDATA[The government does not need a judge's approval to wiretap Americans overseas, an appeals court ruled, rejecting the appeal of an American convicted of helping plan the 1998 East Africa embassy bombings. The ruling comes as rights groups challenge the government's warrantless wiretapping program and newly granted powers to set up electronic dragnets inside the United States.<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=f8839069d601fd60cba8ceeee8211737&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f8839069d601fd60cba8ceeee8211737&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f8839069d601fd60cba8ceeee8211737" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=UlQ2N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=UlQ2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AMMgn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AMMgn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=cGhvn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=cGhvn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=feHjN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=feHjN" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=6cYYN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=6cYYN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=C8VOn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=C8VOn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=ywbxn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ywbxn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=AiHKN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=AiHKN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/466638136" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/466638137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 16:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wiretap americans overseas">wiretap americans overseas</category>
      <category domain="http://securityratty.com/tag/electronic dragnets inside">electronic dragnets inside</category>
      <category domain="http://securityratty.com/tag/appeals court ruled">appeals court ruled</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/rights">rights</category>
      <category domain="http://securityratty.com/tag/appeal">appeal</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/powers">powers</category>
      <category domain="http://securityratty.com/tag/challenge">challenge</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/466638137/no-court-order.html">No Court Order Needed to Spy on Americans Overseas, Appeals Court Rules</source>
    </item>
    <item>
      <title><![CDATA[They didn't go away you know....]]></title>
      <link>http://securityratty.com/article/265b22f7a3a1ac42a1aa3d3c8f7bd79d</link>
      <guid>http://securityratty.com/article/265b22f7a3a1ac42a1aa3d3c8f7bd79d</guid>
      <description><![CDATA[Listening to a discussion on CNN the day after President elect Obama won the U.S. Presidential race, made me think about what the terrorists may be thinking

It really is fairly easy for the average...]]></description>
      <content:encoded><![CDATA[Listening to a discussion on CNN the day after President elect Obama won the U.S. Presidential race, made me think about what the terrorists may be thinking. <br /><span id="fullpost"><br />It really is fairly easy for the average citizen to push these thoughts out of their mind, but we should always keep it somewhere in our minds - close enough to recall it when necessary.<br /></span><br />Bill Clinton was "tested" early in his Presidency as was the U.K.'s new Prime Minister - Gordon Brown.  In PM Brown's case it came 72 hours after the Election in Britain.  How long may we wait to see something here..or overseas, but definitely aimed at inflciting U.S. casualties?<br /><br />Bottom line - we should always remian alert and open to the idea that something could happen and we can not afford to drop our guard and think "they have gone".  Terrorists have great amounts of patience.  They conduct surveillance right under the noses of their intended victims.  As the old saying goes; "we have to be successful every single time - they only have to be lucky once".<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 03:02:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/brown">brown</category>
      <category domain="http://securityratty.com/tag/gordon brown">gordon brown</category>
      <category domain="http://securityratty.com/tag/president elect obama">president elect obama</category>
      <category domain="http://securityratty.com/tag/single time">single time</category>
      <category domain="http://securityratty.com/tag/conduct surveillance">conduct surveillance</category>
      <category domain="http://securityratty.com/tag/bill clinton">bill clinton</category>
      <category domain="http://securityratty.com/tag/remian alert">remian alert</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/presidential race">presidential race</category>
      <source url="http://www.thebulletproofblog.com/2008/11/they-didnt-go-away-you-know.html">They didn't go away you know....</source>
    </item>
    <item>
      <title><![CDATA[Overseas companies practice safer security than U.S firms -- or do they?]]></title>
      <link>http://securityratty.com/article/1b3d2dd6faf1e68b85f2d67588ef09ad</link>
      <guid>http://securityratty.com/article/1b3d2dd6faf1e68b85f2d67588ef09ad</guid>
      <description><![CDATA[Two global surveys that compare how U.S. companies handle security issues with their counterparts overseas offer cautionary data for firms looking to outsource...]]></description>
      <content:encoded><![CDATA[Two global surveys that compare how U.S. companies handle security issues with their counterparts overseas offer cautionary data for firms looking to outsource operations.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5cf713f0521937fe47c0b185f67153c6:fq3LwPrAv765CXmFROXDiALX9KMz2PTA0iuzyN%2FEes%2Be%2B8VaIWYNVaI0mRBXxTQRU2RuSSGLPCKO'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9ea06fd7e3fab8f2749e55fde4376690:zNlYXJ8WNQz5AG7u%2BjFYgCPSc9XLBHfV20KqTd3EmaaZQnYCQXjddeGYmslXBNl4pLl%2BmQhwoOCAHQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a4301f67259505b60059d76c7a3b63da:Gq%2BfkMGTlnQGqMqh8d05tG%2FWHg%2FirYtqqz%2F3ziIVGlhNW5MaGnoiqhavsclMSNjrRcFLLfY85D4QXg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2c1662a0381aec7e7c7cc88f46b465bc:WHNiTAmsYUnjhieS%2FdrMVN2k2ek9tx7weFixapGuLanHb%2F9Nt4TvMk1HuFflF2BmqA5U2LLlWgnrjA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=435d836079cc90211eb7fbdbd556cefa"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=435d836079cc90211eb7fbdbd556cefa" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=435d836079cc90211eb7fbdbd556cefa" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global surveys">global surveys</category>
      <category domain="http://securityratty.com/tag/firms">firms</category>
      <category domain="http://securityratty.com/tag/outsource operations">outsource operations</category>
      <category domain="http://securityratty.com/tag/compare">compare</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=435d836079cc90211eb7fbdbd556cefa">Overseas companies practice safer security than U.S firms -- or do they?</source>
    </item>
    <item>
      <title><![CDATA[The Importance of Advance Planning in Executive Protection]]></title>
      <link>http://securityratty.com/article/e1d474ffbd2af02b7c262a8172d013f8</link>
      <guid>http://securityratty.com/article/e1d474ffbd2af02b7c262a8172d013f8</guid>
      <description><![CDATA[I was delighted to see the Herald Standard quoting an executive/close protection agent regarding the importance of Advance work

Sy Alli is an E.P./C.P. team leader for &quot;Limited Brands Inc.,&quot; and was...]]></description>
      <content:encoded><![CDATA[I was delighted to see the <a href="http://www.heraldstandard.com/site/news.cfm?newsid=20151834&BRD=2280&PAG=461&dept_id=480247&rfi=6">Herald Standard </a>quoting an executive/close protection agent regarding the importance of Advance work.<br /><span id="fullpost"><br />Sy Alli is an E.P./C.P. team leader for "Limited Brands Inc.," and was speaking at the California University of Pennsylvania's 2nd annual conference on Corporate and Homeland Security.<br /><br />Mr. Alli was describing a previous trip to Indonesia where he was in charge of the advance to make sure everything was in place before the Principal arrived out with the other protective agents.  Very accurately, he described the need to cover every minute detail from the routes of travel to the alternative routes and to include such important features as local hospitals should medical treatment be needed.<br /><br />Another important point highlighted was the need for agents to have access to contacts in different countries who could assist with logistics, general and specialized support on the ground, current political situations, etc.  <br /><br />Far too often I am approached by security persons (and not even all are qualified/trained in executive or close protection)who find out that we may have overseas work and want to be included.  On some occassions, those requesting to be included on the detail did not even have a current passport!<br /><br />If you are serious about making a career out of this line of work, you owe it to yourself to do your homework.  Over the years I have developed hundreds of contacts all over the world who will respond immediately and who can be trusted to support us in any number of situations and scenarios.  <br /><br />This took a lot of preparing and involved constant contact.  It is not something that you throw together a day before your client is scheduled to arrive in a country.  If you have people in different parts of the country, or world if you wish to work globally, who can assist when you are in need, you will be able to facilitate your client in a way that will not only gain his/her admiration, but will undoubtedly cement your position in that client's security detail.<br /><br />In these unsure times, there is a lot to be said for knowing your job is safe for the foreseeable future.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 16:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/detail">detail</category>
      <category domain="http://securityratty.com/tag/security detail">security detail</category>
      <category domain="http://securityratty.com/tag/current political situations">current political situations</category>
      <category domain="http://securityratty.com/tag/advance">advance</category>
      <category domain="http://securityratty.com/tag/situations">situations</category>
      <category domain="http://securityratty.com/tag/2nd annual conference">2nd annual conference</category>
      <category domain="http://securityratty.com/tag/gain hisher admiration">gain hisher admiration</category>
      <category domain="http://securityratty.com/tag/agents">agents</category>
      <category domain="http://securityratty.com/tag/routes">routes</category>
      <source url="http://www.thebulletproofblog.com/2008/10/importance-of-advance-planning-in.html">The Importance of Advance Planning in Executive Protection</source>
    </item>
    <item>
      <title><![CDATA[Female Bodyguards Get the Job Done.]]></title>
      <link>http://securityratty.com/article/732503f31e4a0e42349e8fe161ff34fd</link>
      <guid>http://securityratty.com/article/732503f31e4a0e42349e8fe161ff34fd</guid>
      <description><![CDATA[Those who think that Bodyguarding is a job best left to men - think again


The Dublin City Herald recently ran a story about Lisa Baldwin, from Dublin, who is a female Personal Protection/Close...]]></description>
      <content:encoded><![CDATA[Those who think that Bodyguarding is a job best left to men - think again.<br /><span id="fullpost"><br /><br />The Dublin City Herald recently ran a <a href="http://www.herald.ie/national-news/city-news/brain-not-brawn-size-10-bodyguard-lisa-proves-that-being-in-security-doesnt-mean-you-have-to-be-big-and-burly-1484410.html">story about Lisa Baldwin,</a> from Dublin, who is a female Personal Protection/Close Protection Specialist based in the U.K.  Ms. Baldwin is in high demand by Middle Eastern clients who wish to have their women and children protected by female agents.<br /><br /></span><br />That is exactly why SEXTON EXECUTIVE SECURITY(<a href="http://www.sextonsecurity.com/">www.sextonsecurity.com</a>)designed a <a href="http://www.sextonsecurity.com/training.html">Middle East E.P./C.P. course </a>that will be held in the U.A.E. from the 11th of October through the 18th.  The President, John Sexton summed it up as follows; "We saw the need for agents from all over the world to be able to train in the Middle East and to experience the culture,tradition and religion first hand".  "Middle Eastern clients are extremely important to our industry", he added "and it behooves all agents involved in providing safety for these families to become conversant with every aspect of their lives in order to be able to offer the best protection possible". <br /><br />SEXTON will also have a group of female trainees attending their Executive Protection course in San Diego, California in December.  <a href="http://www.herald.ie/national-news/city-news/brain-not-brawn-size-10-bodyguard-lisa-proves-that-being-in-security-doesnt-mean-you-have-to-be-big-and-burly-1484410.html">Lisa Baldwin is described in the Herald</a> as being "one of the world's few female bodyguards".  Many women around the world now recognize that by undergoing professional training like Ms. Baldwin, they can be assigned to prestigious contracts and make a very lucrative living.    <br /><br />Ms. Baldwin's petite stature does not prevent her from succeeding in a mostly male-dominated industry.  "You realise you're not in Iraq, you're in London", she advises.  Very true.  Smart protectors understand that the Art of Personal Protection is about using your mind and not your brawn.  The differences between working in Iraq and London/New York/Dubai are like night and day.  <br /><br />Unfortunately, if the agent does not receive proper training, they may very well fail to realise the difference.  There is one type of training needed for a Hostile environment such as Iraq or Afghanistan and a completely different one for the corporate/private sector.  A security contractor coming fresh out of a hostile environment will often find it extremely difficult providing protection in a covert, "grey man" style.  <br /><br />Fortunately for them, Sexton Executive Security's focus is on private clients and their E.P./C.P. corporate training program can help those returning form overseas contracts to make the transition smooth and profitable.<br /><br />In the corporate/private family world, you don't have heavy weaponry to rely upon but as Ms. Baldwin states; "Its all about the mind and prevention".  Like the old saying goes; "an ounce of prevention is worth a pound of cure".<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 17:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/john sexton">john sexton</category>
      <category domain="http://securityratty.com/tag/sexton">sexton</category>
      <category domain="http://securityratty.com/tag/lisa baldwin">lisa baldwin</category>
      <category domain="http://securityratty.com/tag/baldwin">baldwin</category>
      <category domain="http://securityratty.com/tag/sexton executive security">sexton executive security</category>
      <category domain="http://securityratty.com/tag/middle eastern clients">middle eastern clients</category>
      <category domain="http://securityratty.com/tag/clients">clients</category>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/executive protection">executive protection</category>
      <source url="http://www.thebulletproofblog.com/2008/09/female-bodyguards-get-job-done.html">Female Bodyguards Get the Job Done.</source>
    </item>
    <item>
      <title><![CDATA[Have CrackBerry, Will Travel]]></title>
      <link>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</link>
      <guid>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</guid>
      <description><![CDATA[Blogger: Dan Blum
It is no surprise for us to hear loose lips flapping in India about a capability to decrypt Blackberry and other carrier traffic
After all, weve done basic threat analysis for years...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>It is no surprise for us to hear loose lips flapping in India about <a href="http://economictimes.indiatimes.com/At_last_govt_cracks_BlackBerry_code/articleshow/3510719.cms">a capability to decrypt Blackberry and other carrier traffic</a>.</p>

<p>After all, we’ve done basic threat analysis for years and it was only months ago that I was brought into a company-wide CISO meeting at a U.S. defense contractor to help them hash out their travel policy for mobile devices. Going into the meeting, I knew their policy restricted taking devices to a list of countries considered dangerous – but there was an exemption for BlackBerries.</p>

<p>Our research uncovered that BlackBerry is pretty secure in most respects. It has transport encryption along with optional password protection, remote kill, disk encryption, and S/MIME encryption. Viruses have not flourished on this functionally limited and closed platform. Few if any third party add on programs are required for additional protection. Nonetheless, I went into the meeting prepared to talk with the CISOs about the risks and security limitations of life on BlackBerry.</p>

<p>Was the BlackBerry exemption reasonable? At the time, BlackBerry transport encryption was not known to have been broken (to be fair, the article listed above still qualifies as rumor, not certainty of breakage). However, I pointed out that it is dangerous to assume well-equipped attackers like military or intelligence organizations can’t crack transport encryption. And even if they haven’t cracked the BlackBerry network and whole disk encryption features, sophisticated adversaries have other attack paths. Check out Neal Stephenson’s excellent book <a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1222262354&amp;sr=1-1">Cryptonomicon</a> for a description of how a talented adversary might “see” your keystrokes and screen images through a motel room wall, for example.</p>

<p>If one of your employees – such as a key scientist, project manager, or executive – is targeted for surveillance and is carrying sensitive data through certain countries, one could argue that he or she had better undergo serious counter-intelligence training.&nbsp; Learn to spot and shake tails, sneak into dark alleys for that BlackBerry fix. Learn to paper the closet with layers of aluminum foil and send messages in the dark. Defend that BlackBerry with encryption, long passphrases, and kung fu. But unless James Bond is running your company, I doubt this is what your executives have in mind for the next business trip!</p>

<p>Assuming your organization’s lower level employees are like needles in a haystack and won’t be bothered could be an exercise in wishful thinking. It is always possible that nation states are monitoring some or all of the airwaves. Not so long ago the NSA had a massive a covert surveillance program in place. Years before the government was reportedly snarfing up terabytes of emails and crunching them through a program called Carnivore. And of course, selective monitoring of people on watch lists continues on a large scale. This is just the surveillance we know about in the U.S. We suspect there’s more behind the scenes and especially in countries such as China. Even if you train your non-specifically-targeted low level employees to write and speak in search-keyword-free code, the carnivore programs of the world are pretty good at sniffing out those interesting needles – such as descriptions of your business plans, manufacturing processes, and trade secrets.</p>

<p>Sound paranoid? I admit that I don’t know what the probabilities of being targeted or monitored are – just that it can happen. It’s the height of arrogance to believe that a nation state can’t get your information if they’ve targeted it and you’re within their borders. And it’s dangerous to rely on security by obscurity when medium or high consequence information must be protected.</p>

<p>What can be done? If key personnel can't dispense with the BlackBerry (or any other email device) during international travel to those countries where information may be most at risk, they (the users) should limit communications to what they’d feel comfortable uttering over a potentially-monitored telephone call. Controlling incoming communications – messages sent by others – is a harder problem. Until data loss prevention (DLP) products become more contextually sensitive about the travel issues, it may be best not to synchronize the BlackBerry with the overseas user’s home mailbox. Instead, have the user give out a temporary address for the BlackBerry and warn senders to be discreet. </p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/402766223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry transport encryption">blackberry transport encryption</category>
      <category domain="http://securityratty.com/tag/transport encryption">transport encryption</category>
      <category domain="http://securityratty.com/tag/exemption">exemption</category>
      <category domain="http://securityratty.com/tag/blackberry exemption reasonable">blackberry exemption reasonable</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption features">disk encryption features</category>
      <category domain="http://securityratty.com/tag/blackberry fix">blackberry fix</category>
      <category domain="http://securityratty.com/tag/decrypt blackberry">decrypt blackberry</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/402766223/have-crackberry.html">Have CrackBerry, Will Travel</source>
    </item>
    <item>
      <title><![CDATA[Death Toll of Hotel Bombing in Pakistan Continues to Rise]]></title>
      <link>http://securityratty.com/article/d7f9dda0825a1155b2802353af14c9f2</link>
      <guid>http://securityratty.com/article/d7f9dda0825a1155b2802353af14c9f2</guid>
      <description><![CDATA[It was no coincidence that the bombing in Islamabad which killed more than 40 and injured more than 250 was a popular place for foreigners to meet

U.S. military personnel were attending the Marriott...]]></description>
      <content:encoded><![CDATA[It was no coincidence that the <a href="http://abcnews.go.com/International/Story?id=5846991&page=2">bombing in Islamabad</a> which killed more than 40 and injured more than 250 was a popular place for foreigners to meet. <br /><span id="fullpost"><br />U.S. military personnel were attending the Marriott when the bomb exploded.  The horrific injuries were not limited to foreigners however, as many Muslims were breaking their Ramadan fast and eating there at the time. <br /></span><br />Of course, the terrorists have shown us in the past that they are not opposed to killing other Muslims as was the case in the World Trade Center bombings in 2001<br />The Islamabad Marriott was said to have been well fortified.  If it wasn't afterall, let us hope that Hotel chains like the Marriott review the security of their overseas locations.  <br /><br />One thing is for sure, any overseas location that is considered a gathering place for foreigners, especially Americans in places like Pakistan, India, etc., will continue to be Prime Targets.  Serious surveys need to be conducted and overall security needs to be enhanced.  Vehicular access needs to be closely monitored and controlled in the more hostile regions.  Marriott and all the others need to focus on counter surveillance measures to ensure the safety of their guests.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 23:39:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/islamabad">islamabad</category>
      <category domain="http://securityratty.com/tag/islamabad marriott">islamabad marriott</category>
      <category domain="http://securityratty.com/tag/marriott">marriott</category>
      <category domain="http://securityratty.com/tag/marriott review">marriott review</category>
      <category domain="http://securityratty.com/tag/counter surveillance measures">counter surveillance measures</category>
      <category domain="http://securityratty.com/tag/foreigners">foreigners</category>
      <category domain="http://securityratty.com/tag/hostile regions">hostile regions</category>
      <category domain="http://securityratty.com/tag/vehicular access">vehicular access</category>
      <category domain="http://securityratty.com/tag/overseas location">overseas location</category>
      <source url="http://www.thebulletproofblog.com/2008/09/death-toll-of-hotel-bombing-in-pakistan.html">Death Toll of Hotel Bombing in Pakistan Continues to Rise</source>
    </item>
    <item>
      <title><![CDATA[New Book: Schneier on Security]]></title>
      <link>http://securityratty.com/article/1d45bea3e56c2f81a2c88653e686ef25</link>
      <guid>http://securityratty.com/article/1d45bea3e56c2f81a2c88653e686ef25</guid>
      <description><![CDATA[I have a new book coming out: Schneier on Security . It's a collection of my essays, all written from June 2002 to June 2008. They're all on my website , so regular readers won't have missed anything...]]></description>
      <content:encoded><![CDATA[<p>I have a new book coming out: <a href="http://www.schneier.com/book-sos.html"><i>Schneier on Security</i></a>.  It's a collection of my essays, all written from June 2002 to June 2008.  They're all on my <a href="http://www.schneier.com/essays.html">website</a>, so regular readers won't have missed anything if they don't buy this book.  But for those of you who want my essays in one easy-to-read place, or are planning to be shipwrecked on a desert island without Web access and would like to spend your time there pondering the sorts of questions I discuss in my essays, or want to give copies of my essays to friends and relatives as gifts, this book is for you.  There are only 90 shopping days before Christmas.</p>

<p>The hardcover book retails for $30, but Amazon is already <a href="http://www.amazon.com/exec/obidos/ASIN/0470395354/counterpane/">selling it</a> for $20.  If you want a signed copy, <a href="mailto:schneier@schneier.com">e-mail me</a>.  I'll send you a signed copy for $30, including U.S. shipping, and $40, including shipping overseas.  Yes, Amazon is cheaper -- and you can always find me at a conference and ask me to sign the book.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gpCzL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gpCzL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BmkyL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BmkyL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 03:18:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/hardcover book retails">hardcover book retails</category>
      <category domain="http://securityratty.com/tag/essays">essays</category>
      <category domain="http://securityratty.com/tag/schneier">schneier</category>
      <category domain="http://securityratty.com/tag/web access">web access</category>
      <category domain="http://securityratty.com/tag/copy">copy</category>
      <category domain="http://securityratty.com/tag/regular readers">regular readers</category>
      <category domain="http://securityratty.com/tag/amazon">amazon</category>
      <category domain="http://securityratty.com/tag/june">june</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/new_book_schnei.html">New Book: Schneier on Security</source>
    </item>
    <item>
      <title><![CDATA[Corporate Identity Theft]]></title>
      <link>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</link>
      <guid>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</guid>
      <description><![CDATA[I remember a talk by the value investor Mason Hawkins (Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at...]]></description>
      <content:encoded><![CDATA[<p>I remember a <a href="http://www.bengrahaminvesting.ca/Resources/videos.htm#hawkins">talk</a>&#160;by the value investor&#160;<a href="http://en.wikipedia.org/wiki/Mason_Hawkins">Mason Hawkins</a>&#160;(Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at some point, where there is a rule of law. Here is one example of what he is worried about and why investing in places where your assets have no legal protection does not give the investor a margin of safety.</p><div>Hermitage Fund was until recently the largest fund in Russia. From the Business Week story<a href="http://hermitagefund.com/index.pl/news/article.html?id=895"> &quot;Hijacking the Hermitage Fund&quot;</a></div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>Corruption, intimidation, robbery, violent assault, forgery, large-scale fraud. No, not the subject of the latest John Grisham novel, but sensational allegations, made public Apr. 4 by Hermitage Capital Management -- until recently the largest foreign portfolio investor in Russia. In a detailed and damning report, titled Criminal Justice -- Russian-Style, Hermitage alleges the fund&#39;s Russian subsidiaries have fallen victim to an elaborate con designed to defraud the fund of hundreds of millions of dollars.&#160;<br />&#160;&#160;<br />The most sensational part of Hermitage&#39;s allegations is that the attempted larceny was carried out with the direct connivance of officials in the Russian police. Hermitage alleges the police seized documents and equipment that were instrumental to the attempted fraud, which involved bogus court cases based on forged documents, the aim of which was to sue Hermitage subsidiaries for hundreds of millions of dollars. &quot;The most shocking thing is not that there are corporate raiders in Russia who attempt to steal your shares,&quot; says Jamison Firestone, managing partner of Firestone Duncan, Hermitage&#39;s law firm. &quot;The shocking thing is that the police worked hand-in-hand with them, and actually performed the theft of the documents so that the corporate raiders could then do their work.&quot;</p></blockquote><div><br /><div>From the most recent Hermitage Fund letter, here is the current state:</div><br /><br /></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>So the two-pronged scam worked in one area and failed in another. The perpetrators weren’t able to steal the assets from us based on the fake court claims, but they were able to steal $230 million from the Russian government by filing amended tax returns on behalf of our stolen companies. What makes this story even more shocking is that we filed six 255-page criminal complaints with the Russian authorities in December last year, one month before the tax fraud took place, and they did nothing to stop it. Two complaints were sent to the Russian General Prosecutor, two to the Russian State Investigative Committee and two to the Internal Affairs Department of the Interior Ministry. There was enough information to prevent the fraud and indict a number of people behind it if the government had acted.&#160;</p><p>Instead of doing anything to save the Russian state from this highly sophisticated and organized looting, two of our complaints were thrown out immediately; two were returned to the same Interior Ministry official we were complaining about (essentially, he was being asked to “investigate himself”); and one was thrown out for “lack of any crime committed.” Only one complaint was taken seriously. It was taken up by the Russian State Investigative Committee in early February, but before it could get any traction, the case was lowered to the South region of the Moscow district of the State Investigative Committee (the lowest level of the Committee) and by June, another senior Interior Ministry official whom we had named in our complaint had joined the “investigation” team (again, to “investigate himself”). To this day there has been no serious response by the Russian authorities to this massive fraud against the Russian state.&#160;</p><p>As we described in our April letter, the problem of corporate “raiding” is now so endemic in Russia that President Medvedev speaks about it as one of the biggest problems faced by Russian businesses. In this case, raiders have taken this problem to a new and absurd extreme by “raiding” the Russian state itself and so far getting away with it. Together with HSBC, we will shortly be filing new criminal complaints with the Russian General Prosecutor and Russian State Investigative Committee as well as with many law enforcement authorities outside of Russia. It is hard to predict what will happen next in this unfolding and unbelievable saga, but as always we will keep you updated on any further developments as they arise.</p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><p>Of course we see individual identity theft on a regular basis (actually as Ross Anderson points out its not really identity theft but poor controls on the bank&#39;s parts using SSNs as secrets and so on), but you dont see a major corporation stolen every day.</p>]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 05:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian police">russian police</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian government">russian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/russian-style">russian-style</category>
      <category domain="http://securityratty.com/tag/hermitage">hermitage</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/corporate-identity-theft.html">Corporate Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[Don't put your foot in it, Mr. President]]></title>
      <link>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</link>
      <guid>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</guid>
      <description><![CDATA[Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting

The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s1600-h/george-w-bush.jpg"><img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s320/george-w-bush.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5234855916132700978" /></a><br />Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting.<br /><span id="fullpost"><br />The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other side.  The President had his right foot resting on his left knee, thereby exposing his shoe sole.  That is a huge "no no" in Asia and the Middle East. <br /></span><br />As I said, thankfully the First Lady, Laura Bush was the recipient of the President's sole-waving but it made me wonder if he changed legs at a later stage and "flashed" the Chinese official.  I figure it was a high ranking official or else he would hardly be sat next to the President of the United States.<br /><br />What has this to do with security?  It is one of the topics we teach to our budding bodyguards during our intensive Executive Protection course in the United States and abroad.  You could have a very successful business meeting or trip, either overseas or at home, but ruin it by insulting (albeit unintentionally)a foreign guest.  It is very important for those wroking around forein nationals to be aware of their customs and traditions.  <br /><br />This is not that difficult these days with all of the materials available.  One of the best books I have found is; "Kiss, Bow or Shake Hands".  This book and others like it, will advise the reader on the correct course of action to take when dealing with people from a host of different countries.  Not that I expect the President to read the book, afterall, he must have Protocol officers to keep an eye on him.  My question is, were they brought to China? <br /><br />For the rest of us who are not lucky enough to have our own Protocol officers to keep us out of trouble, we'll just have to read the book.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/president">president</category>
      <category domain="http://securityratty.com/tag/president bush">president bush</category>
      <category domain="http://securityratty.com/tag/chinese official">chinese official</category>
      <category domain="http://securityratty.com/tag/official">official</category>
      <category domain="http://securityratty.com/tag/protocol officers">protocol officers</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/intensive executive protection">intensive executive protection</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/shoe sole">shoe sole</category>
      <source url="http://www.thebulletproofblog.com/2008/08/dont-put-your-foot-in-it-mr-president.html">Don't put your foot in it, Mr. President</source>
    </item>
  </channel>
</rss>
