<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: owner]]></title>
    <link>http://securityratty.com/tag/owner</link>
    <description></description>
    <pubDate>Mon, 29 Sep 2008 14:33:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rational Risk Management, Angry Italians, and Irrational Security Analysts]]></title>
      <link>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</link>
      <guid>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</guid>
      <description><![CDATA[Hope you all had a great weekend. I had meant to point you earlier to a FAIR analysis that Chris Hayes did over at his Blog . But Ive been a little busy, and before I could mention it, Stuart King put...]]></description>
      <content:encoded><![CDATA[<p>Hope you all had a great weekend.  I had meant to point you earlier to a <strong><a href="http://risktical.com/2008/11/06/security-template-exception-part-2-%E2%80%93-the-assessment/">FAIR analysis that Chris Hayes did over at his Blog</a></strong>.  But I&#8217;ve been a little busy, and before I could mention it, Stuart King <strong><a href="http://www.computerweekly.com/blogs/stuart_king/2008/11/ive-written-up-a-report.html">put up a kind of angry response</a></strong> on his ComputerWorld blog.  Snark aside, there are a couple of other really troubling aspects of Stuart&#8217;s reaction to Chris&#8217; analysis that I thought we could talk about this morning.</p>
<blockquote><p>The problem is that (Chris&#8217; analysis is) completely impractical. I&#8217;ll take a recent, and fairly typical situation as an example. I was taking issue with the manner in which remote access was being provisioned for a third party vendor to connect to a system hosted by one of our European business units. To cut a long story short, it was not only a breach of policy but highly insecure. I wanted the access to be disconnected, the business unit director wanted my risk assessment. And he didn&#8217;t want to wait for it.</p>
<p>To quote Chris Hayes, spending time on working out <em> <strong>the expected effectiveness of controls, over a given timeframe, as measured against a baseline level of force </strong></em>was not going to pacify an angry Italian fearful that my decision was going to cost him money. He wanted my explanation of the risk and more importantly, what I was going to offer as a solution to keep his business functioning</p></blockquote>
<p>As Chris is someone who actually does this for a living in a large company, and this is typical of his actual day job, I really find Stuart&#8217;s &#8220;impractical&#8221; comment to be, um, misinformed.</p>
<p>Also, I think Stuart mistakes the purpose of a risk analysis.  The purpose of the risk analysis is not to force someone to be &#8220;secure&#8221;, but to provide knowledge for decision making.  Using it as a &#8220;hammer&#8221; to knock in the nail of your personal risk tolerance impairs efficiency and in the long run retards &#8220;security&#8221; as it creates political resentment.  Seriously, who cares if something might violate policy or not in a pre-implementation discussion?  Policies are not stone tablets handed down from on high, they are state-in-time codification of the <em><strong>data owners </strong></em>risk tolerance.  This risk tolerance changes sometimes, and that&#8217;s OK.</p>
<p>To that extent, I appreciate (and I&#8217;m sure Chris does, as well) that risk analysis does not create rationality in the data owner.  Someone who sees you as a speedbump on the route to progress they may not be ready to appreciate your point of view even if it is stated in the most rational manner possible.   But it&#8217;s worth noting (and Stuart&#8217;s example is indicative of this point) that <em><strong>risk analysis does not create rationality in the analyst, either</strong></em>.  If one is being so &#8220;security minded&#8221; as to ignore the risk tolerance of the business owner - we&#8217;re bound to get a reaction similar to that Stuart encountered.  In fact, a practical risk analysis like Chris performed on his blog, done in 30 minutes, should identify the critical point of disagreement between Stuart and the data owner (again, Stuart doesn&#8217;t own the data, the agitated Italian does).</p>
<p>But let&#8217;s stay rational and open to alternatives to what Chris offers.  Stuart states his approach to risk analysis as:</p>
<blockquote><p>When I need to document a risk assessment I use a very simple form: list the threats, state the level of vulnerability, list the associated operational costs and potential revenue hits. High, medium, or low risk? Describe the controls and options. Write up who needs to do what, and how much of their time it&#8217;s going to take. Job done.</p></blockquote>
<p>At first glance, I don&#8217;t think what Chris has done is any less efficient, and it provides greater insight (using Frequency and Capability instead of just &#8216;listing the threats&#8217;).  But what is key here is that Chris&#8217; approach is consistent and defensible.  Less generous risk geeks and CSO&#8217;s I know would have no little difficulty with Stuart&#8217;s approach.  But to particularly answer Stuart&#8217;s main objection (impracticality) I would offer that with practice, Chris&#8217; work is probably quicker and easier than Stuart&#8217;s described process as it eliminates much of the ambiguity an immature risk analysis creates - reducing the need for further discussion and arguments with data owners (regardless of disposition or nationality).</p>
<p>Finally the irony of Stuart&#8217;s post is that the reason he had this confrontation may in fact be because he was incapable of bringing a salient model for risk to the table, one that identified the factors that create risk and developed a defensible belief statement concerning risk.   We&#8217;ll never know if one would have helped him in this isolated instance, but I can tell you that in organizations like Chris&#8217;, good risk models and strong risk anlayses create operational efficiencies, reduce costs, and streamlines intra-departmental communications.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 13:43:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk tolerance">risk tolerance</category>
      <category domain="http://securityratty.com/tag/risk models">risk models</category>
      <category domain="http://securityratty.com/tag/practical risk analysis">practical risk analysis</category>
      <category domain="http://securityratty.com/tag/strong risk anlayses">strong risk anlayses</category>
      <category domain="http://securityratty.com/tag/generous risk geeks">generous risk geeks</category>
      <category domain="http://securityratty.com/tag/immature risk analysis">immature risk analysis</category>
      <category domain="http://securityratty.com/tag/quote chris hayes">quote chris hayes</category>
      <category domain="http://securityratty.com/tag/chris hayes">chris hayes</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=520">Rational Risk Management, Angry Italians, and Irrational Security Analysts</source>
    </item>
    <item>
      <title><![CDATA[The Ill Effects of Banning Security Research]]></title>
      <link>http://securityratty.com/article/b72a55401bc7d6c28427d7aee13f4dd4</link>
      <guid>http://securityratty.com/article/b72a55401bc7d6c28427d7aee13f4dd4</guid>
      <description><![CDATA[The Indian police are having trouble with SIM card cloning: Police had no idea that one SIM card could be used simultaneously from two handsets before the detention of Nazir Ahmed for interrogation....]]></description>
      <content:encoded><![CDATA[<p>The Indian police are <a href="http://timesofindia.indiatimes.com/PDATOI/pdaarticleshow/3670337.cms">having trouble</a> with SIM card cloning:</p>

<blockquote>Police had no idea that one SIM card could be used simultaneously from two handsets before the detention of Nazir Ahmed for interrogation. Nazir was picked up from Morigaon after an SMS from his mobile number in the name of ISF-IM claimed responsibility for Thursday's blasts in Assam. 

<p>Nazir had a Reliance connection and an Eve handset. Each handset of this particular model has a unique International Mobile Equipment Identity (IMEI) number. Cops found that two IMEI numbers were using the same SIM. Accordingly there were two record sheets of calls and SMSes from Nazir's mobile number. The record of the SMS to the media was found in only one sheet, which forced police to believe that Nazir's SIM might have been cloned and someone else was using the duplicate card, with or without the owner's knowledge. </p>

<p>"We stumbled upon this technological surprise that Nazir Ahmed's SIM card was used in two handsets," Assam IG (Law and Order) Bhaskarjyoti Mahanta said.</blockquote></p>

<p>So far, not that interesting.  There are lots of vulnerabilities in technological systems, and it's generally a race between the good guys and the bad guys to see who finds them first.  It's the last sentence of this article that's significant:</p>

<blockquote>The experts said no one has actually done any research on SIM card cloning because the activity is illegal in the country.</blockquote>

<p>If the good guys can't even participate, the bad guys will always win.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=6uyUN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=6uyUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=mvzBN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=mvzBN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 03:26:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/sim card">sim card</category>
      <category domain="http://securityratty.com/tag/sim">sim</category>
      <category domain="http://securityratty.com/tag/nazir ahmed">nazir ahmed</category>
      <category domain="http://securityratty.com/tag/nazir">nazir</category>
      <category domain="http://securityratty.com/tag/bad guys">bad guys</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/indian police">indian police</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_ill_effects_1.html">The Ill Effects of Banning Security Research</source>
    </item>
    <item>
      <title><![CDATA[On Small Companies and PCI Compliance]]></title>
      <link>http://securityratty.com/article/e0e1165c2e26892133c37ebe3e10c017</link>
      <guid>http://securityratty.com/article/e0e1165c2e26892133c37ebe3e10c017</guid>
      <description><![CDATA[Read this post ( &quot;E-Commerce Startups deal with PCI compliance &quot; at &quot;PCI Anwsers&quot; Blog ) and weeeeeeep: &quot;I once was talking with a small business owner who was reading through the Self-Assessment...]]></description>
      <content:encoded><![CDATA[Read <a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">this post</a> (<a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">"E-Commerce Startups deal with PCI compliance</a>" at <a href="http://pcianswers.com">"PCI Anwsers" Blog</a>) and weeeeeeep:  "I once was talking with a small business owner who was reading through the Self-Assessment Questionnaire (SAQ) and stopped at the first question, which basically said, Do you have a properly configured firewall? <span style="font-weight: bold;"> The business owner called into the back room and asked the store manager, “Hey, do we have a firewall?”</span>  <span style="font-weight: bold;">The store manager replied that he thought they had a fire extinguisher which was up to date.  </span>I then watched as the store manger<span style="font-weight: bold;"> checked the “In Place” box</span> on the form stating they had a properly configured firewall in place."<br /><br />Wonna "sell  PCI compliance" to small businesses? One need to get smart in a very special way! :-)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=McEHN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=McEHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=g0W2N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=g0W2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IAe6N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IAe6N" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/442458664" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 08:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/store manager">store manager</category>
      <category domain="http://securityratty.com/tag/business owner">business owner</category>
      <category domain="http://securityratty.com/tag/e-commerce startups deal">e-commerce startups deal</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <category domain="http://securityratty.com/tag/self-assessment questionnaire">self-assessment questionnaire</category>
      <category domain="http://securityratty.com/tag/properly">properly</category>
      <category domain="http://securityratty.com/tag/fire extinguisher">fire extinguisher</category>
      <category domain="http://securityratty.com/tag/store manger">store manger</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/442458664/on-small-companies-and-pci-compliance.html">On Small Companies and PCI Compliance</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Eleven]]></title>
      <link>http://securityratty.com/article/dd23ca162e5039b0778690b29b0acf4a</link>
      <guid>http://securityratty.com/article/dd23ca162e5039b0778690b29b0acf4a</guid>
      <description><![CDATA[The following portfolio of fake security software appear to have been integrated within traffic redirection doorways during the weekend, consequently redirecting hundreds of thousands of users...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQcoWrAwDhI/AAAAAAAACYM/hL4k2i537X4/s1600-h/rogue_centralized_hosting.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQcoWrAwDhI/AAAAAAAACYM/c5tjrvleLEY/s200-R/rogue_centralized_hosting.png" /></a>The following portfolio of fake security software appear to have been integrated within traffic redirection doorways during the weekend, consequently redirecting hundreds of thousands of users acquired from blackhat hat SEO, malvertising, email spam and SQL injections, to non-existent security vendors and their non-existent security products. Here's an excerpt from one of the templates that they're using :<br />
<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQco6eUW1XI/AAAAAAAACYc/USB3godWxaY/s1600-h/rogue_october_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQco6eUW1XI/AAAAAAAACYc/Kc-DfO7qUVY/s200-R/rogue_october_2008_3.png" /></a>"<i>Since its first establishement in 2001, Antivirus V.I.P consistently maintained its position as one of the world's leading companies in antivirus research and product development. Antivirus V.I.P is known mostly for Antivirus V.I.P, its powerful mix of Anti-Malware, Anti-Virus, Anti-Trojan, Anti-Backdoor, Anti-Worm and Anti-PornoDial in one program. Antivirus V.I.P scans and removes trojans and other malware, which can be placed on a computer without the owner's knowledge.<br />
<br />
Antivirus V.I.P is a powerful and easy-to-use Trojan horses, Viruses and all types of Malware removal software, which detects and eliminates more than 100'000 Trojan Horses and Spywares. It also detects viruses, trojans, worms, spyware, malicious ActiveX controls and Java applets. The latest version of Antivirus V.I.P features outstanding detection abilities, together with high performance. Antivirus V.I.P creates best anti-virus, anti-trojan and anti-spyware security solutions that protect computer users from ever-increasing cyber threats and all the dangers of the new century.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQcrQbexmhI/AAAAAAAACYs/x_K6qt2NuU4/s1600-h/vip_antivirus_october_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQcrQbexmhI/AAAAAAAACYs/D87XRsXKMtM/s200-R/vip_antivirus_october_2008.png" /></a>And the domains and their associated IPs :<br />
<br />
<b>antivirus-freescan .com</b> (208.72.169.100)<br />
<b>defendyourpc .com</b><br />
<b>mycupupdate .com</b><br />
<b>secureupdatecenter .com</b><br />
<b>secureupdateserver .com</b><br />
<b>webscannertools .com</b><br />
<b>secureyourpayments .com</b><br />
<b>protection-overview .com</b><br />
<br />
<b>save-my-pc-now .com</b> (84.243.196.136; 89.149.227.196; 89.149.227.232)<br />
<b>antivirus-pcscan .com</b><br />
<b>hiqualityscan .com</b><br />
<b>active-scanner .com</b><br />
<b>perfectscanner .com</b><br />
<br />
<b>livesecurityinfo .com</b> (216.240.134.208)<br />
<b>protection-freescan .com</b><br />
<b>antvirushelp .com</b><br />
<b>prosecurity-audit .com</b><br />
<br />
<b>scan-my-pc .com</b> (89.149.251.56)<br />
<b>securedclickhere .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQc6IW2xBkI/AAAAAAAACY0/R15FrjONQCE/s1600-h/rogue_october_2008_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQc6IW2xBkI/AAAAAAAACY0/tr0RIbAL8VU/s200-R/rogue_october_2008_2.png" /></a><b>premiumlivescan .com</b> (78.159.118.217; 89.149.253.215; 216.240.134.211)<br />
<b>quick-live-scan .com</b><br />
<br />
<b>ekerberos .com</b> (77.244.220.134; 119.47.81.140; 218.106.90.227)<br />
<b>virtualpcguard .com</b> (67.55.81.200)<br />
<b>antivirus-vip .com</b> (216.32.76.87)<br />
<br />
As I've pointed numerous times in the past, on the majority of occasions the "campaigners" aren't fully taking advantage of the evasive features that their traffic management kits empower them with.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><b></b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wa1iM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wa1iM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7kRgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7kRgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pNtTm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pNtTm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MB9bm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MB9bm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0C8cM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0C8cM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=G9HBM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=G9HBM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xx2jm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xx2jm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/434922712" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 09:15:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/portfolio">portfolio</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/antivirus-vip">antivirus-vip</category>
      <category domain="http://securityratty.com/tag/antivirus research">antivirus research</category>
      <category domain="http://securityratty.com/tag/protect computer users">protect computer users</category>
      <category domain="http://securityratty.com/tag/easy-to-use trojan horses">easy-to-use trojan horses</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/434922712/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</source>
    </item>
    <item>
      <title><![CDATA[Irongeek needs hats, black or white does not matter]]></title>
      <link>http://securityratty.com/article/038b37860c2cd4185464da0b54670cc9</link>
      <guid>http://securityratty.com/article/038b37860c2cd4185464da0b54670cc9</guid>
      <description><![CDATA[I know this seems like and odd request, but I'm in need of some hats to wear at the gym and to cons. If you are a vendor or owner of some security product or site please contact me and I can send you...]]></description>
      <content:encoded><![CDATA[I know this seems like and odd request, but I'm in need of some hats to wear at the gym and to cons. If you are a vendor or owner of some security product or site please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a> and I can send you my snail mail address (not that it's hard to Google for it, I dropped my docs long ago).
<p><a href="http://feedads.googleadservices.com/~a/fSjeEIj82fxmdaNjv3xyT5T_AzY/a"><img src="http://feedads.googleadservices.com/~a/fSjeEIj82fxmdaNjv3xyT5T_AzY/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/3NxCbHRq25I" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 17:16:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/snail mail address">snail mail address</category>
      <category domain="http://securityratty.com/tag/hats">hats</category>
      <category domain="http://securityratty.com/tag/security product">security product</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/contact">contact</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/cons">cons</category>
      <category domain="http://securityratty.com/tag/gym">gym</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/3NxCbHRq25I/i.php">Irongeek needs hats, black or white does not matter</source>
    </item>
    <item>
      <title><![CDATA[Irongeek needs hats, black or white does not matter]]></title>
      <link>http://securityratty.com/article/d5e0476bc5060d367c55f4c48977c668</link>
      <guid>http://securityratty.com/article/d5e0476bc5060d367c55f4c48977c668</guid>
      <description><![CDATA[I know this seems like and odd request, but I'm in need of some hats to wear at the gym and to cons. If you are a vendor or owner of some security product or site please contact me and I can send you...]]></description>
      <content:encoded><![CDATA[I know this seems like and odd request, but I'm in need of some hats to wear at the gym and to cons. If you are a vendor or owner of some security product or site please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a> and I can send you my snail mail address (not that it's hard to Google for it, I dropped my docs long ago).]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 17:16:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/snail mail address">snail mail address</category>
      <category domain="http://securityratty.com/tag/hats">hats</category>
      <category domain="http://securityratty.com/tag/security product">security product</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/contact">contact</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/cons">cons</category>
      <category domain="http://securityratty.com/tag/gym">gym</category>
      <source url="http://www.irongeek.com/i.php?page=contact">Irongeek needs hats, black or white does not matter</source>
    </item>
    <item>
      <title><![CDATA[Sarah Palin and Security Questions]]></title>
      <link>http://securityratty.com/article/1eba1cf0b2be12e62853ecfc357cf52d</link>
      <guid>http://securityratty.com/article/1eba1cf0b2be12e62853ecfc357cf52d</guid>
      <description><![CDATA[I've always looked at security questions used to automate user password recovery with quite a bit of skepticism . What's the point of requiring strong passwords if you allow anyone to reset the...]]></description>
      <content:encoded><![CDATA[<p>I&#39;ve always looked at <a href="http://goodsecurityquestions.com" target="_blank">security questions</a> used to automate user password recovery with <a href="http://www.pluralsight.com/community/blogs/keith/archive/2006/05/24/24964.aspx" target="_blank">quite a bit of skepticism</a>. What&#39;s the point of requiring strong passwords if you allow anyone to reset the password on an account by answering a (potentially inane) question? And just how many good security questions are there, and how many web sites will ask similar questions, allowing the owner of one web site to reset a user&#39;s password at another site that uses the same question? I&#39;m pretty sure that the typical user will tend to select the same security question if it&#39;s available at multiple sites. In many web sites I&#39;ve seen, the security question is clearly the weak link in the chain.</p> <p>Apparently <a href="http://voices.washingtonpost.com/securityfix/2008/10/son_of_tenn_lawmaker_indicted.html?hpid=news-col-blogs" target="_blank">a fellow recently was indicted</a> on charges of <a href="http://blog.wired.com/27bstroke6/2008/09/palin-e-mail-ha.html" target="_blank">hacking</a> into the Republican vice presidential nominee&#39;s Yahoo <a href="http://wikileaks.org/wiki/VP_contender_Sarah_Palin_hacked" target="_blank">email account</a>, by simply doing some research on the Internet to find her birthday, zip code, and the answer to her security question, &quot;Where did you meet your spouse?&quot; All told the attack reportedly took under an hour to complete.</p> <p>Given the level of interest in Palin and other public figures, and the large amount of information about them available to the public, it makes sense that they will be some of the easiest targets for attacks like this.</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=53812" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 04:09:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security question">security question</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/security questions">security questions</category>
      <category domain="http://securityratty.com/tag/question">question</category>
      <category domain="http://securityratty.com/tag/typical user">typical user</category>
      <category domain="http://securityratty.com/tag/user password recovery">user password recovery</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/yahoo email account">yahoo email account</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/10/09/sarah-palin-and-security-questions.aspx">Sarah Palin and Security Questions</source>
    </item>
    <item>
      <title><![CDATA["Scareware" Vendors Sued]]></title>
      <link>http://securityratty.com/article/116941f75bd6ea940dba21e55c3187e7</link>
      <guid>http://securityratty.com/article/116941f75bd6ea940dba21e55c3187e7</guid>
      <description><![CDATA[This is good : Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of &quot;scareware&quot; purveyors, scam artists who use fake security alerts to frighten consumers into paying...]]></description>
      <content:encoded><![CDATA[<p>This is <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">good</a>:</p>

<blockquote>Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of "scareware" purveyors, scam artists who use fake security alerts to frighten consumers into paying for worthless computer security software.

<p>The case filed by the Washington attorney general's office names Texas-based Branch Software and its owner James Reed McCreary IV, alleging that McCreary's company caused targeted PCs to pop up misleading security alerts about security threats on the victims' computers. The alerts warned users that their systems were "damaged and corrupted" and instructed them to visit a Web site to purchase a copy of Registry Cleaner XP for $39.95.</blockquote></p>

<p>I would have thought that existing scam laws would be enough, but Washington state actually has a specific law about this sort of thing:</p>

<blockquote>The lawsuits were filed under Washington's Computer Spyware Act, which among other things punishes individuals who prey on user concerns regarding spyware or other threats. Specifically, the law makes it illegal to misrepresent the extent to which software is required for computer security or privacy, and it provides actual damages or statutory damages of $100,000 per violation, whichever is greater.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RIHdM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RIHdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=V0u2M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=V0u2M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:03:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alerts">alerts</category>
      <category domain="http://securityratty.com/tag/fake security alerts">fake security alerts</category>
      <category domain="http://securityratty.com/tag/week filed lawsuits">week filed lawsuits</category>
      <category domain="http://securityratty.com/tag/security alerts">security alerts</category>
      <category domain="http://securityratty.com/tag/filed">filed</category>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <category domain="http://securityratty.com/tag/washington attorney">washington attorney</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/lawsuits">lawsuits</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/scareware_vendo.html">"Scareware" Vendors Sued</source>
    </item>
    <item>
      <title><![CDATA[The asymmetry of data loss - data thief has an upper hand]]></title>
      <link>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</link>
      <guid>http://securityratty.com/article/1279b28b3737ccdc02880482fc1987c9</guid>
      <description><![CDATA[I read this awesome book by Dan Geer, Economics and Strategies of Data Security . This gave me structure for my thoughts about a complex topic such as data security
When a data owner's (a business)...]]></description>
      <content:encoded><![CDATA[<P>I read this&nbsp;awesome book by Dan Geer, <A href="http://www.verdasys.com/thoughtleadership/">Economics and Strategies of Data Security</A>. This gave me structure&nbsp;for my thoughts about a complex topic such as data security. </P>
<P>When&nbsp;a&nbsp;data owner's (a business)&nbsp;sensitive data is breached it is&nbsp;difficult to quantify the monetary loss. According to respectable survey sources, the average cost of sensitive data breach for a large size company is about $50,000. I am attempting here to think about this in simple mathametical terms:</P>
<P>There is a data breach. From the data owner's perspective the loss is:</P>
<P><FONT color=#3366ff>Loss&nbsp;= Cost to protect data&nbsp;+ Loss of business due to data theft aka cost of competitive disadvantage</FONT></P>
<P>From the data thief's perspective</P>
<P><FONT color=#3333ff>Net Gain= [Cost of producing the data&nbsp; *&nbsp; Data freshness factor] - Cost to steal the data + Profit of business due to data aka gain of competitive advantage</FONT></P>
<P>From the above two equations it is very clear that this is not a zero sum game. There is a clear cost asymmetry for a data owner and for a data thief. When there is an asymmetry there is an opportunity. Data owner&nbsp;would not even know that the&nbsp;data is lost because&nbsp;the original copy of the data may be still intact - data thief could have simply copied the data.&nbsp;Data theft does not look like&nbsp;a car theft, there is no vacuum left behind.&nbsp;</P>
<P><STRONG><EM>This motivates a data thief to keep the cost to steal low, steal highly valuable data that has&nbsp;a long shelf life and in a way that data owner will never even be aware of theft.</EM></STRONG></P>
<P>From&nbsp;a data thief's perspective, the cost to steal data if kept high would disincentive him. Moreover, Data freshness factor, i.e. how valuable this data is over period of time plays an important role.&nbsp;A good example is content of today's newspaper is hardly valuable tomorrow, but the content of newspaper two days ahead (if can be procured)would be invaluable. Data relevance is a function of time and other marketplace variables - &nbsp;Data freshness Factor accounts for that variable. A good way to discourage data thief is to increase his/her cost to steal the data. There are other inferences from the above equation. If there exists&nbsp;no competitive advantage&nbsp;with the stolen data, hardly any thief would even venture&nbsp;to steal the&nbsp;data in the first place. If the cost of producing data is very low, then probably thief can just produce the data himself and would not attempt to steal the data. If the cost of&nbsp;theft is kept high, it would definitely deter the data thief from stealing data using technical mechanisms, then the data thief would&nbsp;exploit weak links in data security&nbsp;such as use of social engineering to get access to the data.</P>
<P>From data owner perspective protecting data becomes very important. How much would the owner be willing to spend? Not definitely the cost equal to cost of producing the data. 1% to 10% of cost of producing data is considered prudent. For a data owner it is difficult to estimate cost of data protection of a specific data, because it is not easy to chunkify data protection costs. Moreover, as Dan Geer says in his book, a data owner has to protect himself from number of intruders not just one.</P>
<P><EM><STRONG>It pays for a data owner to: be aware of data breaches (or data leaks), employ appropriate&nbsp;mechanisms to protect the data; the cost of protection which&nbsp;is fractional cost of&nbsp;the valuable&nbsp;data and&nbsp;enhance information security awareness of personnel who handle the data.</STRONG></EM></P>
<P><STRONG><EM>Data loss is not a zero sum game. The advantage is in favor of a data thief (data thieves rather).&nbsp;Data owner does not give much thought&nbsp;on&nbsp;the value of data&nbsp;unless&nbsp;there is a data theft.&nbsp;But,&nbsp;a&nbsp;data thief&nbsp;has every reason to think about economics of data theft before he acts to steal the data else data thief won't survive in this game and he is very well aware of his advantageous position.</EM></STRONG></P>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 02:33:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data owner perspective">data owner perspective</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/thief">thief</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data freshness factor">data freshness factor</category>
      <category domain="http://securityratty.com/tag/data protection costs">data protection costs</category>
      <category domain="http://securityratty.com/tag/discourage data thief">discourage data thief</category>
      <category domain="http://securityratty.com/tag/protect data">protect data</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html">The asymmetry of data loss - data thief has an upper hand</source>
    </item>
    <item>
      <title><![CDATA[Root of Trust ?]]></title>
      <link>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</link>
      <guid>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</guid>
      <description><![CDATA[Ive given some talks this year about the Internets insecure infrastructure stressing that fundamental protocols such as BGP and DNS cannot really be trusted at the moment. Although they work just fine...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;ve given <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080211-mailserver.pdf">some</a> <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080915-ISPsecurity.pdf">talks</a> this year about the Internet&#8217;s insecure infrastructure &#8212; stressing that fundamental protocols such as <a href="http://www.bgp4.as/">BGP</a> and <a href="http://oreilly.com/catalog/9780596100575/">DNS</a> cannot really be trusted at the moment. Although they work just fine most of the time, they are susceptible to attacks which can mean, for example, that you visit the wrong website, or your email is intercepted.</p>
<p>Steps are now being taken, <a href="http://voices.washingtonpost.com/securityfix/2008/08/dns_security_mandatory_for_all.html">rather faster</a> since Dan Kaminsky came up with a <a href="http://www.doxpara.com/?p=1185">really effective DNS poisoning attack</a>, to secure DNS by using <a href="http://www.dnssec.net/">DNSSEC</a>.</p>
<p>The basic idea of DNSSEC is that when you get an answer from the DNS it will be signed by someone you trust. At some point the &#8220;trust anchor&#8221; for the system will be &#8220;.&#8221; the DNS root, but for the moment there&#8217;s <a href="http://www.unbound.net/documentation/howto_anchor.html">just a handful of &#8220;trust anchors&#8221; one level down</a> from that. One such anchor is the &#8220;.se&#8221; country code domain for Sweden. Additionally, Brazil (.br), Puerto Rico (.pr), and Bulgaria (.bg) have signed their zones, but that&#8217;s about it for today.</p>
<p>So, wishing to get some experience with the <a href="http://www.sparknotes.com/lit/bravenew/">brave new world</a> of DNSSEC, I decided that Sweden was <a href="http://www.cartoonbank.com/item/25468">the &#8220;in&#8221; place to be</a>, and to purchase &#8220;cloudba.se&#8221; and roll out my first DNSSEC signed domain.</p>
<p>The purchase wasn&#8217;t as easy as it might have been &#8212; when you buy a domain, Sweden <a href="http://www.iis.se/docs/general_conditions.pdf">insists</a> that people provide their <a href="http://www.papersplease.org/id.html">identity numbers</a> (albeit they have absolutely no way of checking if you&#8217;re telling the truth) &#8212; or if a company they want a VAT or registration number (which are checkable, albeit I suspect they didn&#8217;t bother). I also found that they don&#8217;t like spaces in the VAT number &#8212; which held things up for a while!</p>
<p>However, eventually they sent me a PGP signed email to tell me I was now the proud owner of &#8220;cloudba.se&#8221;.  Unfortunately, this email wasn&#8217;t in RFC3156 PGP/MIME format (or any other format that my usually <a href="http://en.wikipedia.org/wiki/Turnpike_(software)">pretty capable email client</a> understood).</p>
<p>The email was signed with key 0xF440EE9B which was reassuring because the <a href="http://www.iis.se/">.se registry</a> gives the fingerprint for this key on their website <a href="https://domainmanager.iis.se/start/customerservice">here</a>. Rather less reassuringly footnote (*) next to the fingerprint says &#8220;<em>.SE signature for outgoing e-mail. (**) June 1 through August 31.</em>&#8221; (the (**) is for a second level of footnote, which is absent &#8212; and of course it is now September).</p>
<p>They also enable you to fetch the key through a link on <a href="http://www.iis.se/support">this page</a> to their &#8220;PGP nyckel-ID&#8221; at <a href="http://subkeys.pgp.net:11371/pks/lookup?op=get&#038;search=0xFCEC5128F440EE9B">http://subkeys.pgp.net</a>.</p>
<p>Unfortunately, fetching the key shows that the signature on the email is invalid.</p>
<p>Since the email seems to have originated in the Windows world, but was signed on a Linux box (giving it a mixture of 0D 0A and 0A line endings), then pushed through a three year old copy of <a href="http://search.cpan.org/dist/MIME-tools/">MIME-tools</a> I suppose the failure isn&#8217;t too surprising. But strictly the invalid signature means that I shouldn&#8217;t trust the email&#8217;s contents at all &#8212; because the contents have definitely been tampered with since the signature was applied.</p>
<p>Since the point of the email was to get me to login for the first time to the registry website and set my password to control the domain, this is a little <a href="http://www.cartoonbank.com/item/32907">unfortunate</a>.</p>
<p>Even if the signature had been correct, then should I trust the PGP key?</p>
<p>Well it is pointed to from the registry website which is a Good Thing. However, they do themselves no favours by referencing a version on <a href="http://www.rossde.com/PGP/pgp_keyserv.html">the public key servers</a>. I checked who had signed the key (which is an <a href="http://www.pgpi.org/doc/pgpintro/#p20">alternative way of trusting its provenance</a> &#8212; since the email had arrived to a non-DNSSEC secured domain). Turned out there was no-one I knew, and of 4 individual signatures, 2 were from expired keys. The other signature was the IIS root key &#8212; which sounds promising. That has 8 signatures, once again not people I know &#8212; but only 1 from a non-expired key, so perhaps I can get to know some of the other 7?</p>
<p>Of course, anyone can sign a key on a public key server, so perhaps it makes sense for .se to suggest that people fetch a key with as many signatures as possible &#8212; there&#8217;s more chance of it being signed by someone they know. Anyway, I have now added my own signature, using an email address at my nice shiny new domain. However, it is possible that I may not have increased the level of trust <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/09/signers.png" alt="" title="Signers of the .se PGP key" class="aligncenter size-full wp-image-381"></p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 14:33:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/public key servers">public key servers</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/iis root key">iis root key</category>
      <category domain="http://securityratty.com/tag/key 0xf440ee9b">key 0xf440ee9b</category>
      <category domain="http://securityratty.com/tag/pgp">pgp</category>
      <category domain="http://securityratty.com/tag/pgp nyckel-id">pgp nyckel-id</category>
      <category domain="http://securityratty.com/tag/public key server">public key server</category>
      <category domain="http://securityratty.com/tag/pgp key">pgp key</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/29/root-of-trust/">Root of Trust ?</source>
    </item>
  </channel>
</rss>
